Community discussions

MikroTik App

Search found 47 matches

by OndrejHolas
Thu May 04, 2023 4:28 pm
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55261

Re: v7.9 [stable] is released!

Some users have bad performances with ipv4 and enabled bridge filters actives. In previous versions (7.7 and 7.8) there was no issue. Since 7.9 (stable) ipv4 bandwith is lower for about 35%. It seems that something in bridging code has indeed been changed - in my case the wired bridge ports on RB95...
by OndrejHolas
Sat May 28, 2022 11:15 am
Forum: RouterBOARD hardware
Topic: RBD52 (hAP ac2) Plastic degradation?
Replies: 3
Views: 1571

RBD52 (hAP ac2) Plastic degradation?

Hi all, I've just discovered, that my 4-year-old RBD52 has its plastic case sticky. Tried to clean it with alcohol, but it helped only a bit. Seems to me like a plastic degradation, especially plastifier migration. Compared to RB952-TC's (hAP ac lite), that have almost the same case, but obviously m...
by OndrejHolas
Wed May 26, 2021 10:57 pm
Forum: Announcements
Topic: v6.48.3 [stable] is released!
Replies: 111
Views: 70534

Re: v6.48.3 [stable] is released!

Upgraded from 6.48.2 to 6.48.3 on all boxes with wireless interfaces, both ROS and then firmware. After firmware upgrade and successfull reboot, the first hAP ac lite (RB952Ui-5ac2nD) suddenly froze (during /export ) and rebooted by watchdog: 21:32:53 system,error,critical router was rebooted withou...
by OndrejHolas
Sat May 22, 2021 9:38 am
Forum: Announcements
Topic: v6.49beta [testing] is released!
Replies: 171
Views: 91437

Re: v6.49beta [testing] is released!

This means you also have the implementation issues and not only the design flaws. According to the paper ( https://papers.mathyvanhoef.com/usenix2021.pdf ): CVE-2020-24587 - section 4, design flaw CVE-2020-24588 - section 3, design flaw CVE-2020-26144, CVE-2020-26146, CVE-2020-26147 - section 6, im...
by OndrejHolas
Thu May 13, 2021 12:10 am
Forum: General
Topic: New WiFi Vulnerabilities - Frag Attacks
Replies: 19
Views: 6199

Re: New WiFi Vulnerabilities - Frag Attacks

...but given Mikrotik uses a very outdated Linux kernel, it is almost certainly susceptible to the OS-level vulnerabilities... The question is whether ROS uses completely its own code for 802.11 or relies on that code from kernel. In the latter case, ROS would be affected - look at the kernel patch...
by OndrejHolas
Wed May 12, 2021 9:58 am
Forum: General
Topic: New Wi-Fi vulnerabilities
Replies: 1
Views: 833

New Wi-Fi vulnerabilities

Hello all, yesterday a few of new Wi-Fi vulnerabilites were announced. Since they are rather protocol- than implementation-specific, they are affecting multiple products from variuos vendors. Release notes for last stable and testing ROS don't mention anything that seems to be related to these vulne...
by OndrejHolas
Mon Mar 01, 2021 5:04 pm
Forum: Announcements
Topic: v6.48.1 [stable] is released!
Replies: 103
Views: 60939

Re: LLDP-MED behavior

...the behavior can be different in different modes of bridge operation (full software bridging, fast path, switchchip aka hardware acceleration)... And indeed it is. I did a quick test on RB750GL (switchip Atheros 8327) and the results are: bridge in full software and fast path modes with protocol...
by OndrejHolas
Mon Mar 01, 2021 2:14 pm
Forum: Announcements
Topic: v6.48.1 [stable] is released!
Replies: 103
Views: 60939

Re: LLDP-MED behavior

[*]bridge forwards LLDP frames Just to be clear - is this true also when protocol-mode differs from none on that bridge? I haven't tried it yet, we do not use bridges in any of the xSTP modes (at the edge APs, where we use bridges, there's really no need to include them in the spanning tree topolog...
by OndrejHolas
Mon Mar 01, 2021 11:29 am
Forum: Announcements
Topic: v6.48.1 [stable] is released!
Replies: 103
Views: 60939

Re: LLDP-MED behavior

Interesting. I wonder if this is related to the issue I had found? https://forum.mikrotik.com/viewtopic.php?f=21&t=171035&p=836796#p836789 When looking at the behavior it seems there are three different problems with LLDP: bridge forwards LLDP frames LLDP frames are sent VLAN-tagged and wit...
by OndrejHolas
Sun Feb 28, 2021 5:39 pm
Forum: Announcements
Topic: v6.48.1 [stable] is released!
Replies: 103
Views: 60939

LLDP-MED behavior

Tried to get LLDP-MED working with Cisco and Grandstream IP phones, but the behavior of ROS renders this function unusable. During the first contact, ROS responds to LLDP-MED probe from the phone by burst of LLDP frames that include MED TLVs - this behavior is correct, the phone catches information ...
by OndrejHolas
Mon Feb 22, 2021 10:01 am
Forum: Announcements
Topic: v6.49beta [testing] is released!
Replies: 171
Views: 91437

Re: v6.49beta [testing] is released!

Thanks EdPa, I appreciate your detailed answer. Now the conditions of the problem are clear and the mechanism makes sense. I haven't yet observed those communication drops due to the active hardware acceleration (all bridges I've tried so far were running inside switchchips with HW accel left on), w...
by OndrejHolas
Sat Feb 20, 2021 9:44 pm
Forum: Announcements
Topic: v6.49beta [testing] is released!
Replies: 171
Views: 91437

Re: v6.49beta [testing] is released!

According to this post https://forum.mikrotik.com/viewtopic.php?t=172321#p842428 the version 6.49beta11 contains fix for SIP phone communication problems (Gigaset phones were heavily reported) that started after upgrade to 6.48, but I cannot find any relevant line in the changelog above. Could someo...
by OndrejHolas
Fri Jan 08, 2021 11:30 am
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 295
Views: 128599

Re: v6.48 [stable] is released!

RB750GL with 6.48, directly connected Gigaset A540 IP (with latest firmware 42.248), no problems observed. Also checked with discovery turned on for all interfaces, including LLDP, and cold restart of the VoIP base (to achieve full init). Neither ping losses nor lagged/unreachable messages in Asteri...
by OndrejHolas
Wed Dec 30, 2020 1:46 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 295
Views: 128599

LLDP on RB941-2nD

Also noticed that after upgrade to 6.48 the hAP lite (RB941-2nD - smips) stopped transmitting LLDP frames (neither periodic nor after receiving MED probe from phone), although it still processes received LLDP frames (discovered phones are visible in /ip nei pr); all three discovery protocols are ena...
by OndrejHolas
Tue Dec 29, 2020 11:51 am
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 295
Views: 128599

Re: v6.48 [stable] is released!

LLDP should not be forwarded from port to port under any circumstances Agreed. AFAIK, special L2 control protocols (especially those using multicast addresses 01-80-C2-00-00-00 to 01-80-C2-00-00-0F), including LLDP, are intended to be "bridge-to-bridge" and their frames should not be forw...
by OndrejHolas
Sun Dec 27, 2020 5:55 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 295
Views: 128599

Re: v6.48 [stable] is released!

With IKEv2 the pfs group is inherited from phase 1, have a look at dh group in profiles. Perfect forward secret should be used even if set to none in proposals. Correct me if I am wrong, but I think you should set pfs-group to none in proposals on all devices for IKEv2. Just to clarify, in IKEv2, p...
by OndrejHolas
Sun Dec 27, 2020 12:10 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 295
Views: 128599

Re: v6.48 [stable] is released!

Our 3011 is old but maybe not as old as yours it was shipping with firmware 3.41
Mine is indeed older, factory firmware is 3.27.
Finally, my old 3011 started to flap with another NIC connected, so the problem seems to be dependent on connected NIC (or its PHY?) as well.
by OndrejHolas
Sun Dec 27, 2020 12:08 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 295
Views: 128599

Re: v6.48 [stable] is released!

To someone having problems with SIP phones: Could you please check log of the router with ROS 6.48, whether there are unexpected flapping events (link down/up) or not? Since the linkdowns last between 1 and 2 seconds (as observed in my lab), it could cause "Lagged" state in Asterisk when q...
by OndrejHolas
Sat Dec 26, 2020 9:13 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 295
Views: 128599

Re: v6.48 [stable] is released!

Same on Gigaset S850A. Seems this update breaks SIP on multiple phones... any solution, or is downgrading the only option?
What transport do you use for SIP (UDP, TCP, TLS)?
Is the SIP conntrack helper active? (/ip firewall service-port print)
by OndrejHolas
Sat Dec 26, 2020 4:40 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 295
Views: 128599

Re: v6.48 [stable] is released!

Our 3011 is old but maybe not as old as yours it was shipping with firmware 3.41
Mine is indeed older, factory firmware is 3.27.

Ondrej
by OndrejHolas
Sat Dec 26, 2020 4:06 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 295
Views: 128599

Re: v6.48 [stable] is released!

Hi all, I have one spare RB3011 in lab, so I tried to upgrade it to 6.48 to see the problem with port flapping others mention here. So I did: upload ROS 6.48 packages to RB3011 with 6.47.7 (both ROS and firmware) sys reb (ROS upgraded) waited 10 minutes, no port flapping occurred upgraded firmware t...
by OndrejHolas
Mon Feb 10, 2020 1:00 am
Forum: Beginner Basics
Topic: Ipsec import issue
Replies: 6
Views: 5204

Re: Ipsec import issue

You didn't have to set peer, but you had to set SA src/dst address for policy. Indeed. But for transport mode, the SA src/dst configuration was removed in 6.38.4: *) ipsec - hide SA address for transport policies The reason for this change was that SA src/dst addresses were not used at all in trans...
by OndrejHolas
Sun Feb 09, 2020 11:55 pm
Forum: Beginner Basics
Topic: Ipsec import issue
Replies: 6
Views: 5204

Re: Ipsec import issue

This is known problem. There were substantial changes in IPSec configuration structure in 6.43 (introduced peer profiles) and in 6.44 (identity). I've also observed the same errors when pasting working IPSec configuration to the new box. For somewhat reason now ROS requires to set the peer at the po...
by OndrejHolas
Fri Feb 07, 2020 10:08 pm
Forum: Announcements
Topic: v6.46.3 [stable] is released!
Replies: 28
Views: 52330

Re: v6.46.3 [stable] is released!

During startup just after upgrade 6.46.2 -> 6.46.3, there are extra two lines in the log: 17:48:27 script,info Defconf(debug): isAp=0;isLte=0;model=cAPGi;numCombo=0;numGig=0;numSfp=0;numSfpPlus=0;other=;prefix=RouterBOARD;wireless= 5acD2nD 17:48:27 script,info Defconf(debug): w1=chains=0,1;frequency...
by OndrejHolas
Fri Jan 03, 2020 2:11 pm
Forum: Wireless Networking
Topic: Audience 5GHz - channel limitation
Replies: 5
Views: 3250

Re: Audience 5GHz - channel limitation

The Audience do have 2 5GHz band, 5GHz1 which is 2x2:2 support channel 36~64, 5GHz2 is 4x4:4 support channel 100~165 Thank you for clear information. So Audience does not meet my requirements and I'll go to RB922UAGS-5HPacD + R11e-5HacD. Hope the information about supported bands/channels will be c...
by OndrejHolas
Fri Jan 03, 2020 12:05 pm
Forum: Wireless Networking
Topic: Audience 5GHz - channel limitation
Replies: 5
Views: 3250

Audience 5GHz - channel limitation

Hi all, I am considering replacing current office AP (hAP ac) with more powerful one. Since there are multiple SSIDs (including one for VoIP), I'd prefer to distribute SSIDs to different channels, thus looking for an AP with multiple 5GHz radios and Audience meets this. Although in specs on the web ...
by OndrejHolas
Sat Dec 28, 2019 9:19 pm
Forum: RouterOS beta
Topic: wireless not working mAP Lite - beta03
Replies: 19
Views: 11184

Re: wireless not working mAP Lite - beta03

RB911-5HnD (mipsbe), RouterOS 7.0 beta4 I tried to test (unrelated) problem with radar false positives (reproducible up to and including 6.46.1) also on ROS7. But after upgrade to 7beta4, the clients are almost unable to connect. I did independent wireless sniff on the same channel and found that AP...
by OndrejHolas
Fri Dec 06, 2019 9:54 pm
Forum: Announcements
Topic: v6.46 [stable] is released!
Replies: 113
Views: 69411

Radar false positives still occuring

Upgraded 2 CAPacs and 3 RB952s from 6.45.7, no issues, all boxes work as before upgrade. Although release notes mention wireless stability fixes and "improved radar detection algorithm", false positive radar detections on DFS channels still occur on 6.46 with the same average rate as in pr...
by OndrejHolas
Wed Oct 23, 2019 5:45 pm
Forum: RouterOS beta
Topic: Bridge - invalid VLAN ethertype
Replies: 2
Views: 4236

Re: Bridge - invalid VLAN ethertype

I've just briefly tested this scenario in beta3 and it seems to be fixed, although changelist does not mention it.

Ondrej
by OndrejHolas
Thu Sep 26, 2019 6:56 pm
Forum: RouterOS beta
Topic: Bridge - invalid VLAN ethertype
Replies: 2
Views: 4236

Re: Bridge - invalid VLAN ethertype

As 7.0beta2 was released to public moments ago, I've just re-tested scenarios described above on beta2 (ROS and firmware), observed behavior applies to 7.0beta2 as well, no change between beta1 and beta2.

Ondrej
by OndrejHolas
Thu Sep 26, 2019 1:24 pm
Forum: RouterOS beta
Topic: Bridge - invalid VLAN ethertype
Replies: 2
Views: 4236

Bridge - invalid VLAN ethertype

HW: RB 3011UiAS ROS: 7.0beta1 Simple VLAN-aware bridge setup with ether9 as trunk port a ether10 as access port: [admin@rb3011] > /int bri exp /interface bridge add name=bridge0 protocol-mode=none pvid=998 vlan-filtering=yes /interface bridge port add bridge=bridge0 edge=yes frame-types=admit-only-u...
by OndrejHolas
Tue Jul 02, 2019 10:57 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 415
Views: 197968

Re: v6.45.1 [stable] is released!

CCR1009, 6.44.3 -> 6.45.1. After upgrade, bonding interface didn't go up. I use two levels of bonding: two low level bonding interfaces, each consisting of two ethernets, bundled to LACP LAG; and one upper level bonding interface, consisting of the two LAGs: /interface bonding add mode=802.3ad name=...
by OndrejHolas
Mon Jul 01, 2019 10:31 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 415
Views: 197968

Re: v6.45.1 [stable] is released!

It seems that archive all_packages-mmips-6.45.1.zip is truncated on one download server: https://159.148.147.204/routeros/6.45.1/all_packages-mmips-6.45.1.zip https://[2a02:610:7501:1000::196]/routeros/6.45.1/all_packages-mmips-6.45.1.zip Size: 10600448 SHA256: 6c4d219a8e59398c6fe821deec2f12c93bc72a...
by OndrejHolas
Wed Feb 06, 2019 1:19 pm
Forum: Announcements
Topic: v6.43.11 [stable] is released!
Replies: 79
Views: 39624

Re: v6.43.11 [stable] is released!

LHG-5HPnD after upgrade (6.43.8 to 6.43.11) antenna gain has been set to 25dB (minimal value I can set), Rx dropped from -60dBm to -85dBm . If the other side was not upgraded also, Rx signal strength shown here seems to be corrected by antenna gain, but this is just number. The problem causing link...
by OndrejHolas
Sun Sep 23, 2018 11:26 pm
Forum: General
Topic: Feature Request: IPv6 NAT support
Replies: 19
Views: 11928

Re: Feature Request: IPv6 NAT support

+1

Nowadays, IPv6 perimeter firewalls at my customers' networks run on Linux due to the lack of IPv6 NAT (especially prefix translation) support in ROS.

Ondrej
by OndrejHolas
Sun Sep 23, 2018 11:57 am
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 85811

Re: v6.43.1 [stable] and v6.43.2 [stable] is released!

It is probably not the 43 to 43.2 upgrade that did it, but instead, the routerboot firmware upgrade for 43. If you didn't reboot a second time after 6.43, the routerboot upgrade would not take place until the following reboot, which is probably by happenstance when you rebooted to upgrade to 6.43.2...
by OndrejHolas
Mon Sep 10, 2018 12:47 pm
Forum: Announcements
Topic: v6.43 [current] is released!
Replies: 147
Views: 71332

Re: v6.43 [current] is released!

Interface speeds seem to be set explicitly after upgrading, is this related to the SNMP speed report changelog entry? I haven't tried connecting an interface at other speeds yet, but can I assume that this setting, while a part of /export, will change accordingly? I also have exactly the same in di...
by OndrejHolas
Wed Aug 22, 2018 6:14 pm
Forum: General
Topic: POE Problem
Replies: 14
Views: 9332

Re: POE Problem

Ondrej, did you include a supout.rif file taken while the problem was happening? do so... I didn't include supout.rif in the support case, because the displayable PoE status (print/monitor) on hEX S didn't show anything bad and nothing relevant was logged (turned on logging all about "poe-out&...
by OndrejHolas
Tue Aug 21, 2018 4:48 pm
Forum: General
Topic: POE Problem
Replies: 14
Views: 9332

Re: POE Problem

Would try latest 6.42.7 (make sure firmware is updated on System > Routerboard too). Failing that, would write support, linking to this post.

Already at 6.42.7 (both ROS and firmware). I've just sent mail to support with details and link to this topic.
by OndrejHolas
Mon Aug 20, 2018 4:56 pm
Forum: General
Topic: POE Problem
Replies: 14
Views: 9332

Re: POE Problem

Did you force poe to on on the hEX S when powering the hAP ac2 or left it on auto? On hEX S there are only two PoE-out modes - off and forced-on. Auto mode is not configurable: /interface ethernet poe> set ether5 poe-out=auto-on failure: This model does not support poe-out auto-on mode Ondrej
by OndrejHolas
Mon Aug 20, 2018 4:45 pm
Forum: General
Topic: POE Problem
Replies: 14
Views: 9332

Re: POE Problem

Hi, I use mikrotik hex s and hap ac2 ( hap ac2 - poe in ). hex s has 24V 1,2A power supply, but hap ac2 works unstable - I think it does not have enough power. What do I need to do - replace the power supply with a more powerful one? Hi, I have similar problem here with these two boxes, but my hAP ...
by OndrejHolas
Mon Aug 20, 2018 4:25 pm
Forum: General
Topic: Hex S SFP no link
Replies: 22
Views: 17477

Re: Hex S SFP no link

Received new hEX S today and SFP works fine with 6.42.6 and 6.42.7. The only combination I was able achieve the "no-link" status on SFP was with 6.42.6, coldbooted without SFP module and then inserted the module when RouterOS was already running. After warm reboot with module inserted, the...
by OndrejHolas
Mon Aug 20, 2018 11:15 am
Forum: General
Topic: ECDSA cert support?
Replies: 5
Views: 3326

Re: ECDSA cert support?

Still exactly the same situation with 6.42.6 - unknown key size and imported key is not paired with its certificate. Lack of ECC support is quite big disadvantage, since many customers require ECC support (in certificate- and other contexts) for years. Libraries have support for EC certificates read...
by OndrejHolas
Sun Aug 12, 2018 2:06 pm
Forum: Wireless Networking
Topic: wAP ac compatibility issues intel wifi
Replies: 10
Views: 4760

Re: wAP ac compatibility issues intel wifi

In some situations, Intel 7260 ac adapters suffer firmware crashes. Typical combination of conditions is 5GHz band, >20MHz channel width and >1 chain. Setting AP to use 20MHz wide channel or to use only one chain helps. Also disabling 11n at the client side prevents firmware crashes. Tried latest fi...
by OndrejHolas
Sun Aug 12, 2018 1:50 pm
Forum: Wireless Networking
Topic: wAP ac compatibility issues intel wifi
Replies: 10
Views: 4760

Re: wAP ac compatibility issues intel wifi

Once you've found a machine you can physically fit it in to, it will work with the ath10k driver. R11e-5xxx adapters work with ath10k driver, but based on my experience with kernels 4.9+, you'll probably need some patches for the driver to work properly, notable problems are: - The EEPROM in the ad...
by OndrejHolas
Tue Jul 31, 2018 1:23 pm
Forum: General
Topic: Hex S SFP no link
Replies: 22
Views: 17477

Re: Hex S SFP no link

I've done dozens of tests so far. Following steps: - downgrading packages to 6.42.5 - reboot - downgrading firmware to 6.42.5 - shutdown - remove power, wait 10s - restore power and let the router boot with inserted SFP module (this seems to be important) can quite reliably make sfp1 work again. Als...
by OndrejHolas
Mon Jul 30, 2018 6:18 pm
Forum: General
Topic: Hex S SFP no link
Replies: 22
Views: 17477

Re: Hex S SFP no link

I've just observed exactly the same behavior on hEX S (6.42.6) with different SFP modules, including officially supported S-85DLC05D and Mikrotik's 3m DAC, and many setups (RB2011, RB3011, TP-Link MC220) - when one party is hEX S, link is down (nego done, rx power -15, but no-link); any other two bo...