Community discussions

Search found 123 matches

by nostromog
Wed Jul 17, 2019 10:26 am
Forum: General
Topic: IPsec doesn't work after upgrade from 6.43.16 to 6.44 and high
Replies: 4
Views: 360

Re: IPsec doesn't work after upgrade from 6.43.16 to 6.44 and high

I've seen here on the forum a case like this, the solution was to export the ipsec configuration into an external text file, remove it on the machine, upgrade the machine and create the ipsec configuration manually again. There was a significant change in the IPsec configuration structure either be...
by nostromog
Fri Jul 05, 2019 8:25 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 405
Views: 52717

Re: v6.45.1 [stable] is released!

In order to upgrade ROS, your hAP lite needs at least some 14MB RAM free (possibly even more) and around 1MB hdd free. Both are displayed using command /system resource print (fields free-memory and free-hdd-space respectively). If your RAM is low, try to reboot device (in case there are some proce...
by nostromog
Fri Jul 05, 2019 9:31 am
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 405
Views: 52717

Re: v6.45.1 [stable] is released!

It hangs in some initial script that tries to modify ipsec policies depending on dynamic local ip, it hangs on "/ export" or "/ip ipsec <whatever>". I can't generate a supout because it hangs :( Have you tried to reset the machine to defaults before or better after upgrade to 6.45.1 and then manual...
by nostromog
Wed Jul 03, 2019 7:43 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 405
Views: 52717

Re: v6.45.1 [stable] is released!

I upgraded 2 mAP Lite without a single issue, and another old 750GL. Same On the other side, the hAP ac that could not be upgraded/downgraded to 6.44.* or 6.45beta* because it had the 100% looping CPU on ipsec is stil behaving the same. It hangs in some initial script that tries to modify ipsec poli...
by nostromog
Mon Jul 01, 2019 9:07 am
Forum: Wireless Networking
Topic: Number of Wi-Fi connections on hAP mini
Replies: 8
Views: 914

Re: Number of Wi-Fi connections on hAP mini

So hence the reason I was interested in the hAP range. MikroTik are not that well known in the UK but I was interested when I saw them on Broadbandbuyer. It sounds like the mini is a little under powered but I punted out the £20 and bought one anyway. I've on good terms with the cafe I was talking ...
by nostromog
Wed Jun 26, 2019 10:00 pm
Forum: Wireless Networking
Topic: Number of Wi-Fi connections on hAP mini
Replies: 8
Views: 914

Re: Number of Wi-Fi connections on hAP mini

Nostomog, could you tell us why "MIPS" is not good to handle encrypted traffic? It is not a problem of handling encrypted traffic, but of doing encryption. the MIPS CPU has only one core, and does not have hardware support for AES encryption. So, if you are terminating encrypted VPNs in your router...
by nostromog
Sat Jun 22, 2019 2:03 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 66020

Re: v6.45beta [testing] is released!

You can try to manually download the package from download.mikrotik.com - choose extra packages which is a ZIP file. Then extract all the packages (npk files) you need - get the list of installed and enabled packages from router itself. Upload those npk files to router and reboot the router afterwa...
by nostromog
Fri Jun 21, 2019 5:08 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 66020

Re: v6.45beta [testing] is released!

I have two devices upgraded to 6.45beta62, but today I'm seeing this error (several times) while trying to upgrade another one:
 15:04:27 system,error broken package routeros-mipsbe-6.45beta62.npk 
Has the download file became corrupt? Is it some problem in this device?
by nostromog
Fri Jun 21, 2019 4:29 pm
Forum: Wireless Networking
Topic: Number of Wi-Fi connections on hAP mini
Replies: 8
Views: 914

Re: Number of Wi-Fi connections on hAP mini

The main limitation of the hAP mini is its RAM, a bit in the small side with only 32M RAM, which brings one problem that you can search for in the forum: often it is difficult to upgrade, as the upgrade firmware is downloaded in RAM, and depending on your configuration it can get tricky. I have good...
by nostromog
Thu Jun 06, 2019 7:22 pm
Forum: General
Topic: hAP ac² as switch + ap
Replies: 9
Views: 590

Re: hAP ac² as switch + ap

[*] select static ip address or dynamic, as desired It seems like what I want, I'm just not sure if the address you mention here is just to access hAPs configuration or will all wifi clients use this IP to talk with the rest of the network? I want my server to assign each ip. Mikrotik routers are q...
by nostromog
Thu Jun 06, 2019 6:45 pm
Forum: General
Topic: hAP ac² as switch + ap
Replies: 9
Views: 590

Re: hAP ac² as switch + ap

EDIT: I think I was wrong, WISP AP is for a station connection on 5GHz band, use instead Home AP Dual. So there is no hidden NAT on the wlan where in the end every device is presented under the same ip to my server like I've read is the problem with some routers? I think that if you upgrade it, sel...
by nostromog
Tue Jun 04, 2019 1:40 pm
Forum: RouterBOARD hardware
Topic: Cheapest router for home use with 1Gb
Replies: 5
Views: 551

Re: Cheapest router for home use with 1Gb

https://mikrotik.com/products/compare/RBD52G-5HacD2HnD-TCr2+RB4011iGSplus5HacQ2HnD-IN Those two models have 1GB network interfaces dual band WiFi 4 cores with good performance for firewalling or VPN at high bandwith If you are looking for a cheap solution, I'm quite happy with the hAP ac^2 I have at...
by nostromog
Sat Jun 01, 2019 2:57 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Please add the ability to choose Proposal
Replies: 11
Views: 1102

Re: Please add the ability to choose Proposal

Why is the use-ipsec=yes a bad thing? It is not a bad thing if you just want to protect a connection. What tomaskir said is that if you want to do an "in-depth IPSec config" it is better not to use this parameters and to create the policies for the tunnels yourself. The solution proposed by emils a...
by nostromog
Sat May 25, 2019 7:49 pm
Forum: General
Topic: Download over xDSL, Upload over 4G LTE
Replies: 10
Views: 593

Re: Download over xDSL, Upload over 4G LTE

(...) In the system perspective, you have the router at the site with poor ADSL upload, let's call it the VPN client for simplicity, and the router with good connectivity and public IP address somewhere else - let's call it the VPN server. There are two VPN tunnels established between the two, one ...
by nostromog
Thu May 16, 2019 2:40 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 66020

Re: v6.45beta [testing] is released!

Hi Mikrotik Are you aware if Router OS is patched for this threat? https://www.tomsguide.com/us/zombieload-attack-intel-what-to-do,news-30082.html I think an accurate answer would be that RouterOS running on a x86 is not itself vulnerable, but the vulnerability could be exploited in the unlatched h...
by nostromog
Sat May 11, 2019 10:05 pm
Forum: Scripting
Topic: ping time script
Replies: 1
Views: 284

Re: ping time script

It is complicated as the ping command does not offer many options in RouterOS. You could do something like :if ([:ping 1.1.1.1 count=10 interval=90ms]<8) do={:put something} This will execute the do= block if less than 8 out of 10 pings arrive in less than 90ms. You could tune: The number of attempt...
by nostromog
Fri May 10, 2019 5:23 pm
Forum: Scripting
Topic: Routing exeptions for connections from the routers itself
Replies: 7
Views: 401

Re: Routing exeptions for connections from the routers itself

Here's a challenge for the routing experts :-) I have a script that uses the Telegram messenger API to notify about logins, errors, etc. on a router; this is done by "/tool fetch url="https://api.telegram.org/bot...." in a script. Since api.telegram.org is blocked in several countries, I want this ...
by nostromog
Tue May 07, 2019 8:11 pm
Forum: Wireless Networking
Topic: MUM Wireless to Wireless
Replies: 6
Views: 525

Re: MUM Wireless to Wireless

https://mum.mikrotik.com/presentations/NL19/presentation_6878_1556787638.pdf Can somebody explain what this chap is doing in basic terms because i find it very confusing and have no idea of any applications for the magic he described. A wireless interface in routeros can be in several modes. Some s...
by nostromog
Tue May 07, 2019 5:21 pm
Forum: General
Topic: MTU "caching"
Replies: 5
Views: 274

Re: MTU "caching"

Routerboard has a linux kernel version 3 underlying it. I don't really remember if linux was having the same behaviour now than then (a few things around route caching have changed), but the current behaviour is: * linux does path MTU discovery as needed (on receipt of ICMP fragmentation needed mess...
by nostromog
Sun May 05, 2019 6:50 pm
Forum: Scripting
Topic: Power out notification
Replies: 11
Views: 767

Re: Power out notification

Detecting incoming power failure looks hard to impossible, but one possible way to very quickly/statelessly delivering a message is sending a ping of a specific size to a given server. Use the size of the ping as a "return code". You could simply execute something like: /ping myserver size=666 count...
by nostromog
Sun May 05, 2019 6:00 pm
Forum: Scripting
Topic: Detecting wireless roaming
Replies: 1
Views: 286

Re: Detecting wireless roaming

A tentative solution, the best I could come with: # ensure that registration/dhcp lease are current... do { :local GatewayIP [/ip dhcp-client get [find interface="wan-bridge"] gateway ] :local GatewayMac [/ip arp get [find address=$GatewayIP] mac-address ] :if (([:len [/interface bridge host find ma...
by nostromog
Sat May 04, 2019 5:53 pm
Forum: Useful user articles
Topic: How to opitimize list of IP4 addresses
Replies: 6
Views: 1230

Re: How to opitimize list of IP4 addresses

I think it is not working 100% right. Example. Llet's get all facebook IPv4 address ranges and process them with your program: $ (for orig in AS32934 AS63293 AS54115; do whois -h whois.radb.net -- "-i origin $orig"; done) | grep route: | awk '{print $2}' >facebook4.txt $ gcc -o optimizeip optimizeip...
by nostromog
Wed May 01, 2019 9:38 pm
Forum: Scripting
Topic: Detecting wireless roaming
Replies: 1
Views: 286

Detecting wireless roaming

Hi, I have a problem with a travel router relative to station mode and connect lists I set up a mAP Lite to connect as a station to different wifi APs using a connect list, and bridged it with a virtual AP. /interface wireless security-profiles set [ find default=yes ] group-ciphers="" supplicant-id...
by nostromog
Mon Apr 22, 2019 2:06 pm
Forum: Scripting
Topic: Reading POE status with script
Replies: 5
Views: 415

Re: Reading POE status with script

This works for me:
{
  :local test ([/interface ethernet poe monitor ether5 once as-value ]->"poe-out");
  :put $test
}
It needs once to ensure it finishes, and as-value to return the resulting data structure.
by nostromog
Fri Apr 19, 2019 1:03 am
Forum: General
Topic: IP Cloud
Replies: 37
Views: 6005

Re: IP Cloud

IP Cloud services include: Time-zone detection, that is enabled by default. And fails spectacularly when I'm in London, systematically thinking that I'm in Europe/Tallin: [user@router] > /system clock print time: 00:50:19 date: apr/19/2019 time-zone-autodetect: yes time-zone-name: Europe/Tallinn gm...
by nostromog
Thu Apr 18, 2019 12:32 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 66020

Re: v6.45beta [testing] is released!

Also, I tried to netinstall once and was not working, it seems to be really tricky with linux machines and difficult reset procedures... Connect your machine and router to an switch, then run netinstall with Wine as sudo and will work flawlessly. I have no switch, I connected them straight, which g...
by nostromog
Tue Apr 16, 2019 11:50 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 66020

Re: v6.45beta [testing] is released!

Any way to empty ipsec and upgrade to 6.44.2 or 6.45betas without CPU spinning at 100%? Almost certain way would be netinstall directly to desired ROS version. And then import config from textual export. I'm leaving the place where the machine that failed to upgrade yesterday is in a few hours, not...
by nostromog
Tue Apr 16, 2019 7:06 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 66020

Re: v6.45beta [testing] is released!

After I had big problems with ipsec in 6.44.1/hAP ac I remained using 44.1 for a while. Thinking that beta31 had already those issues fixed, I tried to upgrade with the following IPsec configuration: /ip ipsec peer add exchange-mode=ike2 name=router passive=yes /ip ipsec policy group add name=RoadWa...
by nostromog
Sat Apr 13, 2019 10:16 pm
Forum: Beginner Basics
Topic: Router for my new home!
Replies: 14
Views: 972

Re: Router for my new home!

Hey mate, Greetings to all. I'm a new member in this community. I hope this is the right place to start my issue here. I need a router for my new home with 3 bedrooms. Which one would be reliable? Thank you so much for your reply. Things to consider: How is the upstream: Mikrotik has some routers t...
by nostromog
Mon Apr 08, 2019 7:45 pm
Forum: Wireless Networking
Topic: hAP ac wireless problem
Replies: 8
Views: 670

Re: hAP ac wireless problem

I bought hAP ac router and don't changed default settings. I have problem with wireless. Every time when I measured speed, on laptop result is about 80Mbps, but on mobile devices show about 50Mbps. Why on mobile devices speed flow is not max? I checked here, with different routers, but I find, in r...
by nostromog
Mon Apr 08, 2019 12:27 pm
Forum: General
Topic: [Feature request] Address List extension
Replies: 11
Views: 783

Re: [Feature request] Address List extension

I wish I knew how to deduplicate it.
When I tried ipv4 it was failing due to a duplicate, but changing sort -> sort -u makes it load. I edited the post. Removing entries that fall "inside"other entries, though, is a non-trivial programming problem.
by nostromog
Sun Apr 07, 2019 10:57 am
Forum: General
Topic: [Feature request] Address List extension
Replies: 11
Views: 783

Re: [Feature request] Address List extension

EDIT: Change sort to sort -u so that no full duplicates remain. How could we use this: whois -h whois.radb.net -- '-i origin AS15169' | grep ^route Which gets every IP address range Google uses Into a Mikrotik address list? Those two give separate raw prefix lists, one for IPv4 and another for IPv6...
by nostromog
Fri Apr 05, 2019 2:12 pm
Forum: General
Topic: IPv6 connection attempts on port 35211
Replies: 0
Views: 168

IPv6 connection attempts on port 35211

I'm seeing connection attempts from a growing number of IPv6 addresses to port 35211, both UDP and TCP SYN packets. The connections target sometimes existing addresses but sometimes non-existing internal IPv6 addresses, so I'm not sure if it is an attempt to use me for distributed DoS... I'm using a...
by nostromog
Fri Apr 05, 2019 1:32 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 37837

Re: UKNOF 43 CVE

@pe1chl, question: in your setup externally initiated ipv6 traffic is disallowed right? Yes, externally initiated IPv6 traffic to random addresses is disallowed. I added this when NDP exhaustion attacks were discussed. Due to the address list, only systems that have initiated outbound traffic (with...
by nostromog
Fri Apr 05, 2019 2:05 am
Forum: Announcements
Topic: Tik App, MikroTik android utility ALPHA test
Replies: 410
Views: 136937

Re: Tik App, MikroTik android utility ALPHA test

Just wanted to chime in that the APP is working great ---> Router accessed remotely via IKEv2 connection to get to the router and then access APP once internal to the router. Fully agreed, last versions are good! One nit: I have a mAL Lite as Travel Router, and it has the main wireless interface in...
by nostromog
Wed Apr 03, 2019 4:35 pm
Forum: Scripting
Topic: Write IP to log
Replies: 4
Views: 324

Re: Write IP to log

Hi, Thanks a lot but unfortunately it isn't working. I even put a delay of 45s but no luck :-( #Get Ip And Save it To "RFC_WAN_IP.txt" File In Mikrotik /tool fetch url="http://myip.dnsomatic.com/RFC_WAN_IP.txt" mode=http delay 45s #Save Ip From "RFC_WAN_IP.txt" File To "MyVar" Variable :local myvar...
by nostromog
Sun Mar 31, 2019 9:46 pm
Forum: General
Topic: PPPoE server IP conflict
Replies: 3
Views: 250

Re: PPPoE server IP conflict

My big trouble was: The PPPoE server gave a IP (from pool) to a client that is in use for another client (that have remote address with static IP). On PPP Active Connections have showed 2 clients with same IP. 1) Is that a BUG on RouterOS or does it do this as a feature? My guess is that the remote...
by nostromog
Sat Mar 30, 2019 5:53 pm
Forum: General
Topic: dial-on-demand and /ipv6 settings accept-router-advertisements
Replies: 0
Views: 176

dial-on-demand and /ipv6 settings accept-router-advertisements

I wonder what might be the relation between those two settings, apparently fully unrelated but I have a number of on-demand connection here that stopped to work as soon as I changed the setting from the default value of "yes-if-forwarding-disabled" to "yes", and started working again when I went bac...
by nostromog
Sat Mar 30, 2019 9:19 am
Forum: General
Topic: How to filter internal traffic.
Replies: 3
Views: 277

Re: How to filter internal traffic.

Hi, Is it possible to filter internal traffic? Example - My network ID - 192.168.3.0 HOST A - 192.168.3.10 HOST B - 192.168.3.20 HOST B is listening to pot 22. Now, I want to block HOST A (192.168.3.10) to access HOST B (192.168.3.20) with port 22. Thanks.. I'm not sure if you mean the feature of W...
by nostromog
Fri Mar 29, 2019 1:06 pm
Forum: General
Topic: ikev2 mikrotik to mikrotik strange behaviour
Replies: 8
Views: 430

Re: ikev2 mikrotik to mikrotik strange behaviour

It is precisely this rule that causes the problem. If I disable it, no packet loss, if I enable it, packet loss ~ 40-60% [admin@MikroTik] > /ip firewall filter print where action=fasttrack-connection Flags: X - disabled, I - invalid, D - dynamic 0 X ;;; defconf: fasttrack chain=forward action=fasttr...
by nostromog
Fri Mar 29, 2019 10:34 am
Forum: General
Topic: DHCP keeps broadcasting and can not stop it!
Replies: 5
Views: 732

Re: DHCP keeps broadcasting and can not stop it!

Check the status of /interface detect-internet print

For each interface to be checked it will send a dhcp discover packet per second to peep if it is a lan (it considers lan an interface where a dhcp-server exists).
by nostromog
Thu Mar 28, 2019 8:14 pm
Forum: Wireless Networking
Topic: Home glamourous Mesh Wi-Fi?
Replies: 2
Views: 418

Re: Home glamourous Mesh Wi-Fi?

by nostromog
Thu Mar 28, 2019 7:54 pm
Forum: General
Topic: ikev2 mikrotik to mikrotik strange behaviour
Replies: 8
Views: 430

Re: ikev2 mikrotik to mikrotik strange behaviour

Must be caused by FastTrack. Exclude the traffic subject for IPsec processing from being FastTracked in firewall's forward chain by adding accept rules before the action=fasttrack-connection rule. I'm not sure how to exclude this traffic. I already have firewall rules (this is the beginning of /ip ...
by nostromog
Thu Mar 28, 2019 2:00 pm
Forum: General
Topic: ikev2 mikrotik to mikrotik strange behaviour
Replies: 8
Views: 430

Re: ikev2 mikrotik to mikrotik strange behaviour

Sounds very weird. I would try to locate the issue more precisely with packet sniffer. Ping is bidirectional traffic. With packet sniffer you could verify whether the packet is at least received on the other end. Also verify ESP or UDP/4500 packets are properly sent out and received. Just setting /...
by nostromog
Thu Mar 28, 2019 12:38 pm
Forum: General
Topic: ikev2 mikrotik to mikrotik strange behaviour
Replies: 8
Views: 430

Re: ikev2 mikrotik to mikrotik strange behaviour

What model routers are involved? Is hardware offloading used? Do you see anything suspicious under IPsec statistics? The server is a hAP ac, running 6.44.1. For what I know it does not support hardware offloading. It is in a PPPOE based ISP. Under IPsec statistics there are a few non-zero items, bu...
by nostromog
Wed Mar 27, 2019 6:50 pm
Forum: General
Topic: ikev2 mikrotik to mikrotik strange behaviour
Replies: 8
Views: 430

ikev2 mikrotik to mikrotik strange behaviour

I have set up a ikev2 network between mikrotiks, like this. The server has two networks, one local 192.168.88.0/254 and one for the current vpn: 192.168.89.0/24. I'm setting a new VPN (192.168.90.0/24) and want it to be used to access all three networks, In the server, this is the result of /ip ipse...
by nostromog
Tue Mar 26, 2019 8:08 pm
Forum: Beginner Basics
Topic: How to remove the static switch from this setup ?
Replies: 16
Views: 535

Re: How to remove the static switch from this setup ?

connect isp utp directly to Mikrotik ether1 connect your home router to etherXX (any open port) create a new bridge make ether1 and etherXX part of that bridge. Done You will also have to substitute the new bridge name in the WAN interface list, and anywhere else that ether1 appears. For instance, ...
by nostromog
Thu Mar 21, 2019 10:32 am
Forum: Announcements
Topic: Tik App, MikroTik android utility ALPHA test
Replies: 410
Views: 136937

Re: Tik App, MikroTik android utility ALPHA test

Well the above posters already gave a hint. You have joined a private beta program and installed that invite-only version. You should delete it, delete the "TestFlight" app which manages the Beta programs, and then install the application that is meant for everyone (the one in the AppStore). Probab...
by nostromog
Wed Mar 20, 2019 1:09 pm
Forum: General
Topic: IP IPsec Package missing in router
Replies: 3
Views: 375

Re: IP IPsec Package missing in router

/ip ipsec export --- hangs the router console terminal session. @Mikrotik support, what could be the issue. I had the same thing happening in a machine 100% CPU and unable IPsec. See 6.44 thread. Only solution I found was disable security, reset+restore from backup, re-enable security Sent from my ...
by nostromog
Tue Mar 19, 2019 11:12 pm
Forum: General
Topic: How to replicate home WiFi while staying in a hotel (VPN, capsman)?
Replies: 1
Views: 268

Re: How to replicate home WiFi while staying in a hotel (VPN, capsman)?

It is possible, but in the general case it is very tricky. I'm building myself a travel router with a mAP Lite, mostly following the ideas from Lorenzo Bussatti ( https://www.youtube.com/watch?v=VeZetH9uX_Y ). I have it mostly working with a few VPN networks dialled on demand to route private ranges...