Community discussions

MikroTik App

Search found 44 matches

by MichaelHallager
Sat Oct 07, 2023 3:35 pm
Forum: General
Topic: V7.6 VRRP IPv6 interface invalid
Replies: 4
Views: 1211

Re: V7.6 VRRP IPv6 interface invalid

A bit of time has passed so I hope you were able to fix the issue.

IPv6 + ROS7 had all sorts of issues at the time of the original post. This was due to MTU.

These were fixed in ROS 7.9 although at the time of this post ROS 7.11.2 is the latest stable.
by MichaelHallager
Thu Jun 29, 2023 4:50 am
Forum: General
Topic: PTP connection to switch for admin
Replies: 3
Views: 499

Re: PTP connection to switch for admin

Maybe this can be useful Management access configuration https://help.mikrotik.com/docs/display/ROS/Bridging+and+Switching#BridgingandSwitching-Managementaccessconfiguration Thanks very much and I got my answer there. I needed to add the bridge to the list of tagged ports under /interface/bridge/vl...
by MichaelHallager
Thu Jun 29, 2023 1:34 am
Forum: General
Topic: PTP connection to switch for admin
Replies: 3
Views: 499

PTP connection to switch for admin

Running RouterOS 7.10 on a CRS326-24S+2Q+RM, however, this issue has affected different switches and versions of ROS. The purpose of this link is for the switches own connectivity for administration. I can't quite get my head around this. Setting up PTP (trunk) connections are trivial on a router an...
by MichaelHallager
Thu Apr 06, 2023 1:48 pm
Forum: Forwarding Protocols
Topic: ROS7 and IPv6 route reflection [solved]
Replies: 6
Views: 2740

Re: ROS7 and IPv6 route reflection

Its working now and as sometimes happens it was a small oversight.

I had not set the RR peers address families = IPv6. I know this setting well but didn't notice it unset even on multiple look overs. Once set suddenly it works as expected.

Thanks for the help :-)
by MichaelHallager
Thu Apr 06, 2023 7:29 am
Forum: Forwarding Protocols
Topic: ROS7 and IPv6 route reflection [solved]
Replies: 6
Views: 2740

Re: ROS7 and IPv6 route reflection

An example of the RR clients (a border router) 100 ;;; [redacted] chain=bgp-rr-v6-in rule="if (dst in [redacted]/45 and dst-len in 45-48) { accept; }" 101 chain=bgp-rr-v6-in rule="reject;" Explanation: Borders should accept local origin route information from RR 102 X ;;; Filter...
by MichaelHallager
Thu Apr 06, 2023 6:39 am
Forum: Forwarding Protocols
Topic: ROS7 and IPv6 route reflection [solved]
Replies: 6
Views: 2740

Re: ROS7 and IPv6 route reflection

It's working for me. My connections to the RR's are dual-AFI on a single BGP connection, with a route filter to change the gateway of IPv6 routes to the IPv6 loopback of the router. Otherwise it tries to use the IPv4 literal (::ffff:x.x.x.x), which could also work if you add it as a loopback on the...
by MichaelHallager
Wed Apr 05, 2023 4:15 am
Forum: Forwarding Protocols
Topic: ROS7 and IPv6 route reflection [solved]
Replies: 6
Views: 2740

ROS7 and IPv6 route reflection [solved]

Does anyone have this combination working? I am using ROS 7.7. It appears to be unrelated to my other issue* because it affects every router and it has never worked for me. Furthermore, all the necessary PTP, etc, routes are showing in OSPF-v3 at this time. I have a route reflector setup for BGP and...
by MichaelHallager
Wed Apr 05, 2023 4:05 am
Forum: Forwarding Protocols
Topic: ROS7 and OSPF-v3
Replies: 6
Views: 2307

Re: ROS7 and OSPF-v3

On all my routers running 7.7, I switched all my OSPFv3 types to broadcast from PTP. Thanks for the info. This was one suggestion offered in a private conversation with an industry associate. I have also enabled redistribute=connected for OSPF-v3 hence my delay in responding because I wanted to see...
by MichaelHallager
Tue Apr 04, 2023 2:36 pm
Forum: Forwarding Protocols
Topic: BGP peering not working with routeros 7.6
Replies: 4
Views: 2708

Re: BGP peering not working with routeros 7.6

Two possibilities to check: 1. ROS7 requires syncronise unlike ROS6 where it was an option. So therefore you will need to pop a static route entry to blackhole and a high distance (250 will do - as long as its higher then anything else) which equals your route announcements. 2. Some config can get l...
by MichaelHallager
Tue Apr 04, 2023 2:30 pm
Forum: Forwarding Protocols
Topic: Preferred route for multihomed BGP
Replies: 5
Views: 2475

Re: Preferred route for multihomed BGP

You can prefer one provider over another for outgoing traffic with distance or local pref. You can try and tweak incoming traffic via AS prepend but TBH this is pretty hit and miss. Another option could be split announcements if you have sufficient IP space. Whatever you do consider you can not forc...
by MichaelHallager
Sun Apr 02, 2023 2:38 pm
Forum: Forwarding Protocols
Topic: ROS7 and OSPF-v3
Replies: 6
Views: 2307

ROS7 and OSPF-v3

Since upgrading to ROS 7, I have never been able to get OSPFv3 stable. OSPFv2 works as expected and I have deployed a near identical setup for OSPFv3 with the only change specifying interfaces instead of IP ranges. The last time v3 worked as expected was ROS 6. I have waited a while in case its an R...
by MichaelHallager
Sun Jan 22, 2023 4:45 am
Forum: Forwarding Protocols
Topic: ROS 7.6 and OSPFv3
Replies: 1
Views: 1847

ROS 7.6 and OSPFv3

I recently migrated a network to ROS 7.6. IPv6 recursive routing now works, yay. Unfortunately there is now a new issue and that's some PTP links are randomly dropping out of OSPFv3. So this effectively renders IPv6 BGP over OSPFv3 useless. Nothing else has changed. The PTP OSPFv3 routes worked with...
by MichaelHallager
Sat Feb 12, 2022 1:11 pm
Forum: General
Topic: DNS-over-HTTPS and Unbound
Replies: 4
Views: 773

Re: DNS-over-HTTPS and Unbound

Does it work when you configure the DoH server by IP instead of by name?
No.
by MichaelHallager
Sat Feb 12, 2022 12:48 pm
Forum: General
Topic: DNS-over-HTTPS and Unbound
Replies: 4
Views: 773

Re: DNS-over-HTTPS and Unbound

Hello,
Did you add the certificate and NTP?

Yes to both, however, the certificate should only be required with verify-doh-cert=yes and I had it turned off while was trying to resolve this.
by MichaelHallager
Sat Feb 12, 2022 12:44 pm
Forum: General
Topic: DNS-over-HTTPS and Unbound
Replies: 4
Views: 773

DNS-over-HTTPS and Unbound

I have an Unbound DoH server which I have tested working with a web browser and the included dohclient command. But its not working for Mikrotik. Has anyone come across anything incompatible with these? I tried with 2 different devices running 6.48.6 LTS and 7.1 LTS. In all cases it would resolve th...
by MichaelHallager
Mon Jan 17, 2022 9:22 am
Forum: RouterOS beta
Topic: 7.1.x issues with CRS328-24P-4S+RM
Replies: 3
Views: 2047

Re: 7.1.x issues with CRS328-24P-4S+RM

It can be many things (one possibility is that configuration converter barfed at something during upgrade) ... so why don't you post current configuration for review? I spent way too much checking the configuration. It was all still there. Its not like a router where I had to go and setup BGP from ...
by MichaelHallager
Mon Jan 17, 2022 8:19 am
Forum: Forwarding Protocols
Topic: eBGP with two ISP
Replies: 3
Views: 1708

Re: eBGP with two ISP

I recently became AS (Autonomus System). As from the beginning I have configured an eBGP Router that announces my Public / 29 network. Is your ASN a private one for routing between you and the ISP or are you intending to announce into the global routing table? If the later, it will only work with a...
by MichaelHallager
Mon Jan 17, 2022 8:14 am
Forum: RouterOS beta
Topic: 7.1.x issues with CRS328-24P-4S+RM
Replies: 3
Views: 2047

7.1.x issues with CRS328-24P-4S+RM

I have a CRS328 PoE switch [1] running a basic port based VLAN with a trunk port to a router and IP access for switch admin purposes. This works fine with ROS 6.48.6 LTS. But I tried an upgrade to ROS 7.1.1 and it did not work. I could SSH into the switch and ping any host on the same subnet/vlan bu...
by MichaelHallager
Wed Dec 22, 2021 3:41 pm
Forum: General
Topic: 6.47.10 to 6.48.6 - what changed for switches?
Replies: 0
Views: 2919

6.47.10 to 6.48.6 - what changed for switches?

After upgrading 2 switches from 6.47.10 to 6.48.6 I had the same issue. The models are: CRS312-4C+8XG-RM CRS326-24S+2Q+RM These are both MIPS architecture. These are both running in a multiple vlan environment with a trunk connection to a router. IP addressing is /30 + /126 over a dedicated vlan wit...
by MichaelHallager
Sun Feb 23, 2020 8:12 am
Forum: General
Topic: PPPoE server with RADIUS, how to add IPv6
Replies: 13
Views: 9270

Re: PPPoE server with RADIUS, how to add IPv6

This can be done the following way: /ipv6 pool add name=text_description prefix=[IPv6 address]/[length] prefix-length=[length] You will need one pool per client if you want to do static assignments. In this case both of the above length attributes would be equal. In Freeradius, etc: attribute = Mikr...
by MichaelHallager
Sun Oct 20, 2019 12:54 am
Forum: Forwarding Protocols
Topic: BGP setup can't route public IPs
Replies: 2
Views: 3495

Re: BGP setup can't route public IPs

Setting up peering by itself isn't enough. Both your uplines and possibly their uplines will need to allow your route announcements through their filters.
by MichaelHallager
Fri Oct 11, 2019 8:15 am
Forum: Forwarding Protocols
Topic: BGP bug report
Replies: 1
Views: 2473

BGP bug report

BGP filters do not accept > 16 bit ASN numbers.

Obviously, this is an issue of importance.

Platform = CCR1009 with 6.45.6
by MichaelHallager
Sun Sep 08, 2019 6:51 am
Forum: Forwarding Protocols
Topic: 2 WAN BGP failover
Replies: 6
Views: 6059

Re: 2 WAN BGP failover

First of all 10.10.... looks like is an Private IP, you cannot advertise them to BGP! Of course you can You probably won't find an ISP willing to take your 10.0.0.0/8 (or other RFC1918 addresses), but if you do then there's nothing to say you can't do it. If you publicly announce RFC1918 space - in...
by MichaelHallager
Fri Sep 06, 2019 3:22 am
Forum: General
Topic: Stability bug report
Replies: 0
Views: 993

Stability bug report

Platform - CCR1009 / ROS 6.45.5

Under interfaces / VLAN -

I accidentally typed "remove 11" instead of "remove numbers=11" and the router became unresponsive and required a reboot.
by MichaelHallager
Fri Sep 06, 2019 3:20 am
Forum: General
Topic: BGP-safety issue
Replies: 2
Views: 1464

BGP-safety issue

Using ROS 6.45.5 on CCR1009 If the admin changes the name of a filter, this does not propagate through to any peers using the filter. What happens is the peer simply starts acting as if there were no filter. Of course, this is an undesirable situation. My suggested behaviour would be for either- 1. ...
by MichaelHallager
Thu Sep 05, 2019 2:15 am
Forum: Forwarding Protocols
Topic: Packet marking by BGP peer
Replies: 2
Views: 2573

Re: Packet marking by BGP peer

When you say that you need to "account" for it, what does that mean exactly?
Traffic In and Traffic Out. At present I do this with Firewall / Mangle and connection marking + packet marking. But I am not clear how to do this over an IX interface with multiple bilateral peers.
by MichaelHallager
Wed Sep 04, 2019 1:34 pm
Forum: Forwarding Protocols
Topic: Packet marking by BGP peer
Replies: 2
Views: 2573

Packet marking by BGP peer

I have a CCR1009 and multiple BGP peers. Some I peer with through dedicated interfaces so this is easy to traffic-account for. However, some peers I reach via bilateral-peering through an IX and I need a way to account individually for this traffic. How can this be achieved to the point of the packe...
by MichaelHallager
Mon Apr 01, 2019 12:27 am
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 81347

Re: UKNOF 43 CVE

@bmann has made some very good points which I can relate to. I come from the Cisco camp and I was amazed when I bought my RB1100AHx4 what I was getting for the money... and it's made in Latvia, not China! Personally, I think Mikrotik products are possibly a bit too cheap and I would be happy to pay ...
by MichaelHallager
Sun Mar 31, 2019 11:57 am
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 81347

Re: UKNOF 43 CVE

I have been spreading the word around in other forums.

If it's of any interest / help I am happy to act as a remote test case providing no harm is done.
by MichaelHallager
Sun Mar 31, 2019 11:32 am
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 81347

Re: UKNOF 43 CVE

I can report I had (now disabled) IPv6 connectivity and a few days ago my router rebooted for no obvious reason. A couple of days later I was alerted to this issue.

As a consequence, I am now assuming the exploit is out there in the wild and is being used.
by MichaelHallager
Wed Jan 02, 2019 7:22 am
Forum: General
Topic: IPV6 DHCP client stuck on status "binding" after restarts
Replies: 2
Views: 1032

Re: IPV6 DHCP client stuck on status "binding" after restarts

viewtopic.php?f=2&t=122420

i also submitted a ticket to support. Hope this can be fixed soon.
Thanks for that. Clearly, it's not just me.
by MichaelHallager
Wed Jan 02, 2019 6:02 am
Forum: General
Topic: IPV6 DHCP client stuck on status "binding" after restarts
Replies: 2
Views: 1032

IPV6 DHCP client stuck on status "binding" after restarts

I am running 6.43.8 though this issue has persisted over several previous versions.

On a restart, the IPV6 DHCP client gets stuck on status "binding". I have to manually disable, then enable, and then IPV6 works.

Is there any way to fix this for reliable restarts?
by MichaelHallager
Wed Jun 13, 2018 11:56 am
Forum: Beginner Basics
Topic: Bridging SFP and Eth1
Replies: 2
Views: 1490

Re: Bridging SFP and Eth1

Ok. Worked it out now thanks.

For some reason, SFP was not in the port list so I had to add it.
by MichaelHallager
Mon Jun 11, 2018 12:09 pm
Forum: Beginner Basics
Topic: SSTP 443 port sharing
Replies: 4
Views: 3055

Re: SSTP 443 port sharing

Thinking a bit outside the square - will your ISP offer you a public subnet? There is usually an extra charge for this. $2 per IPV4 address per month is the going rate. So a /29 (8 IP's of which 5 are usable for hosts) would be $16 per month. Otherwise, if you can get IPV6 space and can do end-to-en...
by MichaelHallager
Mon Jun 11, 2018 12:05 pm
Forum: Beginner Basics
Topic: Bridging SFP and Eth1
Replies: 2
Views: 1490

Bridging SFP and Eth1

Can this be done?
by MichaelHallager
Tue Jun 05, 2018 10:44 am
Forum: Beginner Basics
Topic: Feeling overwhelmed setting up hap ac2
Replies: 11
Views: 4044

Re: Feeling overwhelmed setting up hap ac2

First things first -

Did you secure your hAP ac before connecting it to the internet?
by MichaelHallager
Tue May 29, 2018 6:26 am
Forum: Beginner Basics
Topic: IPV6 static addressing
Replies: 5
Views: 4811

Re: IPV6 static addressing

I have fixed the issue by doing both of the following: 1. Disabling auto-addressing on the relevant VLAN 2. Disabling Slackware NetworkManager and setting my IP address manually in rc.inet1 (IPV4) and rc.local (IPV6) as follows: /etc/rc.d/rc.networkmanager stop chmod 600 /etc/rc.d/rc.networkmanager ...
by MichaelHallager
Fri May 25, 2018 12:20 pm
Forum: Beginner Basics
Topic: VDSL config please
Replies: 6
Views: 2803

Re: VDSL config please

The 5311 also suppprts ADSL2/2+ though no mention of ADSL1 support- https://www.metanoia-comm.com/admin/product_en/front/index2.php?id=119&upid=73 Here in New Zealand, most VDSL (strictly speaking it's VDSL2) connections are deployed from fibre-fed cabinets. But ours is a very small rural townsh...
by MichaelHallager
Fri May 25, 2018 3:33 am
Forum: Beginner Basics
Topic: Blocking some ports to access Youtube
Replies: 4
Views: 3582

Re: Blocking some ports to access Youtube

Blocking ports is useless. Youtube and Facebook use the normal ports 80 and 443.
by MichaelHallager
Thu May 24, 2018 2:19 pm
Forum: Beginner Basics
Topic: IPV6 static addressing
Replies: 5
Views: 4811

Re: IPV6 static addressing

are you using Dt. Telekom? You must take care on the dynamic IPv6 prefix change (Zwangstrennung). It's better to internally address via ULA address. Also you must decrease the GUA lifetime by hand as RouterOS does not care about the lifetime given by DHVP6. Thanks for that. I am a customer of Inspi...
by MichaelHallager
Thu May 24, 2018 2:13 pm
Forum: Beginner Basics
Topic: IPV6 static addressing
Replies: 5
Views: 4811

Re: IPV6 static addressing

Prior to doing this I reinstated auto config and ND. IPV6 / Addresses [admin@MikroTik] /ipv6 address> print Flags: X - disabled, I - invalid, D - dynamic, G - global, L - link-local # ADDRESS FROM-POOL INTERFACE ADVERTISE 0 DL fe80::dceb:95ff:fe38:7658/64 bridge-wlan no 1 DL fe80::1c37:82ff:fe40:ebb...
by MichaelHallager
Thu May 24, 2018 1:43 pm
Forum: Beginner Basics
Topic: IPV6 static addressing
Replies: 5
Views: 4811

IPV6 static addressing

I have been allocated a /56 IPV6 from my ISP. I have DHCPv6 setup on the pppoe0 interface (PPPoE over VDSL2) and a /64 from the pool on the LAN interface (Vlan40). When I use address auto config, it works fine. When I try to set a static IP on the host and Vlan40, it works for a few minutes to an ho...
by MichaelHallager
Thu May 24, 2018 1:36 pm
Forum: Beginner Basics
Topic: VDSL config please
Replies: 6
Views: 2803

Re: VDSL config please

Sorry about the delay in responding. I was not aware this site would not email me a reply notification. I eventually tracked the problem to the SFP settings. The 5311 requires the port is set as 1Gbps full duplex. Fibre is popular and we have only few sites still use VDSL It is here as well but cons...
by MichaelHallager
Thu May 17, 2018 2:47 pm
Forum: Beginner Basics
Topic: VDSL config please
Replies: 6
Views: 2803

VDSL config please

Hi all. This is my first post to the Mikrotik forum and I hope to become a regular here. My background is Linux Systems Admin - predominantly using Cisco. When it comes to Miktotik, I will assume I am a beginner. I have a Metanoia VT5311 VDSL SFP and a hAP AC. I am located in New Zealand. If someone...