Community discussions

MikroTik App

Search found 66 matches

by Emil66
Mon Feb 26, 2024 11:18 pm
Forum: Wireless Networking
Topic: [Feature Request] Option to disable 802.11b in wifi drivers
Replies: 13
Views: 2084

Re: [Feature Request] Option to disable 802.11b in wifi drivers

Without "b" we could have 4 separate 20MHz channels in 2.4GHz band in Europe. 1-5-9-13. "b" DSSS is 22MHz wide AFAIK. Seconded. 802.11b-channels are too wide for a bandwidth plan with four non-overlapping channels. Please don't use 802.11b and please afford us the ability to exc...
by Emil66
Mon Aug 21, 2023 3:50 pm
Forum: General
Topic: Mikrotik website about ipv6 throughput?
Replies: 47
Views: 5075

Re: Mikrotik website about ipv6 throughput?

So few things to check out
I'm not "holding it wrong".
by Emil66
Mon Aug 21, 2023 12:32 pm
Forum: General
Topic: Mikrotik website about ipv6 throughput?
Replies: 47
Views: 5075

Re: Mikrotik website about ipv6 throughput?

No, but since you came around to discuss things, you could ask about this rule If I could read his mind and see that he meant that as a rule of thumb, I wouldn't need to ask for an explanation, but alas, no mindreading. You fanbois are not helping Mikrotik. Every single buyer who gets a router for ...
by Emil66
Mon Aug 21, 2023 12:11 pm
Forum: General
Topic: Mikrotik website about ipv6 throughput?
Replies: 47
Views: 5075

Re: Mikrotik website about ipv6 throughput?

@anav mentioned the "rule of thumb": when looking at MT official test results, take "Routing -> 25 filter rules -> 512 byte packet size" number ... that one represents real-life performance pretty well (still with a fairly large error margin though). That figure actually represe...
by Emil66
Sun Aug 20, 2023 3:07 pm
Forum: General
Topic: Mikrotik website about ipv6 throughput?
Replies: 47
Views: 5075

Re: Mikrotik website lying about throughput?

You are correct, I was going by memory when I first got mine many years ago. Looking at the website it is revamped, only 385 with 25 filter rules so yes 300-450 is more likely. So clearly not lying.
Playing dumb?
by Emil66
Sun Aug 20, 2023 2:16 pm
Forum: General
Topic: Mikrotik website about ipv6 throughput?
Replies: 47
Views: 5075

Re: Mikrotik website lying about throughput?

somewhere in the vicinity of 600-700 throughput
With ROS6. The current version, ROS7, is slower.
by Emil66
Sat Jul 29, 2023 4:18 pm
Forum: RouterOS beta
Topic: IPv6 Prefix ID per IPv6 enabled interface
Replies: 31
Views: 5244

Re: IPv6 Prefix ID per IPv6 enabled interface

Ah that's typo lol, I edited the comment. add from-pool=global address= ::1 /64 interface=vlan-iot eui-64=no advertise=yes add from-pool=global address= :0:1::1 /64 interface=vlan-work eui-64=no advertise=yes add from-pool=global address= :0:2::1 /64 interface=vlan-tv eui-64=no advertise=yes That's...
by Emil66
Sat Jul 29, 2023 3:30 pm
Forum: RouterOS beta
Topic: IPv6 Prefix ID per IPv6 enabled interface
Replies: 31
Views: 5244

Re: IPv6 Prefix ID per IPv6 enabled interface

add from-pool=global address= ::1 /64 interface=vlan-iot eui-64=no advertise=yes add from-pool=global address= ::2 /64 interface=vlan-work eui-64=no advertise=yes add from-pool=global address= ::3 /64 interface=vlan-tv eui-64=no advertise=yes If RouterOS did at all what you claim, that would produc...
by Emil66
Tue May 16, 2023 11:01 pm
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43022

Re: Newsletter #113 | May 2023

/* edit: off topic */
by Emil66
Tue May 16, 2023 12:01 pm
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43022

Re: Newsletter #113 | May 2023

/* edit: off topic */
by Emil66
Sun Mar 12, 2023 12:42 pm
Forum: General
Topic: ipv6 create pools from pool delegated by ISP [SOLVED]
Replies: 4
Views: 1348

Re: ipv6 create pools from pool delegated by ISP [SOLVED]

It becomes a bit complicated, or rather impossible, if you have a need for prefixes with different lengths, because the pool can have just one pool-prefix-length and you can't take a chunk out of the pool to create a "sub" pool with a different prefix length. So if you need /60 prefixes fo...
by Emil66
Sun Mar 12, 2023 11:58 am
Forum: General
Topic: ipv6 create pools from pool delegated by ISP [SOLVED]
Replies: 4
Views: 1348

Re: ipv6 create pools from pool delegated by ISP [SOLVED]

The "pool-prefix-length" is meant to be the length of the prefixes which you want to draw from the address pool, not the prefix length that your ISP assigns. Most of the time, you want those address ranges to be significantly smaller (bigger prefix length), so that you have multiple prefix...
by Emil66
Sun Nov 20, 2022 12:13 am
Forum: General
Topic: Tuning IPv6 valid-lifetime and preferred-lifetime
Replies: 5
Views: 1539

Re: Tuning IPv6 valid-lifetime and preferred-lifetime

You can set the default valid and preferred lifetimes which then get applied to dynamic prefixes. In the CLI it's under "/ipv6 nd prefix default" (v6 syntax), in the web GUI it's under "IPv6", "ND", "Prefixes" Tab, "Default" button.
by Emil66
Wed Oct 05, 2022 7:48 pm
Forum: Beginner Basics
Topic: Routerboard hEX S - No Internet with fibre modem [SOLVED]
Replies: 13
Views: 1620

Re: Routerboard hEX S - No Internet with fibre modem [SOLVED]

You had that already, because it's part of the default firewall configuration: /ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN You just need to edit the "WAN" interface list to include your vlan interf...
by Emil66
Wed Oct 05, 2022 1:19 pm
Forum: Beginner Basics
Topic: Routerboard hEX S - No Internet with fibre modem [SOLVED]
Replies: 13
Views: 1620

Re: Routerboard hEX S - No Internet with fibre modem [SOLVED]

Did you update the WAN interface list to include the VLAN interface but not ether1? That interface list is what configures the firewall for NAT to the internet, etc..
by Emil66
Tue Oct 04, 2022 6:05 pm
Forum: Beginner Basics
Topic: Routerboard hEX S - No Internet with fibre modem [SOLVED]
Replies: 13
Views: 1620

Re: Routerboard hEX S - No Internet with fibre modem [SOLVED]

Make the Vlan interface the WAN interface, not the untagged ether1. Put the DHCP client on the Vlan, not the untagged ether1.
by Emil66
Fri Dec 10, 2021 11:47 am
Forum: Beginner Basics
Topic: RB750Gr3 low performance
Replies: 11
Views: 2506

Re: RB750Gr3 low performance

The RB750Gr3 is not fast enough for gigabit internet if you use IPv6 with a firewall (tops out at about 600 Mbit/s without encapsulation). The router is barely fast enough with IPv4 without encapsulation, but PPPoE will drag it below 1 Gbps. You also have to watch out for ports using the same of the...
by Emil66
Wed Nov 24, 2021 1:39 am
Forum: Beginner Basics
Topic: Setting up IPv6 with port forwarding? [SOLVED]
Replies: 4
Views: 3623

Re: Setting up IPv6 with port forwarding? [SOLVED]

How to deal with variable prefixes: viewtopic.php?t=168470
How to set a static interface identifier is device dependent. The key words to search for are EUI-64 or, preferably, "tokenized interface identifier".
by Emil66
Wed Nov 17, 2021 3:12 pm
Forum: Announcements
Topic: v6.49.1 [stable] is released!
Replies: 138
Views: 81052

Re: v6.49.1 [stable] is released!

dhcpv6-server - fixed DUID generation with timestamp;
Is there a way to trigger this without reinstalling the router, or generally to reset the DUID?

Edit: Sorry, I missed that it is just for the server. Question remains: Can the client DUID be reset without reinstalling the router?
by Emil66
Thu Oct 07, 2021 12:48 am
Forum: Beginner Basics
Topic: Yet another hairpin nat question [SOLVED]
Replies: 20
Views: 5591

Re: Yet another hairpin nat question [SOLVED]

/ip address
add address=192.168.0.1/24 comment=defconf interface=ether2 network=\
192.168.0.0

That looks familiar...
by Emil66
Wed Oct 06, 2021 12:58 am
Forum: Beginner Basics
Topic: Yet another hairpin nat question [SOLVED]
Replies: 20
Views: 5591

Re: Yet another hairpin nat question [SOLVED]

Try to understand what you're doing, don't just copy & paste. You need two NAT rules for the server: One destination NAT rule and one source NAT rule. The destination NAT is what's usually called a "port forwarding". It tells the router that incoming connections to a particular port on...
by Emil66
Tue Oct 05, 2021 9:06 pm
Forum: Beginner Basics
Topic: Yet another hairpin nat question [SOLVED]
Replies: 20
Views: 5591

Re: Yet another hairpin nat question [SOLVED]

Details are important. Computers do what you tell them, not necessarily what you mean. If you tell the router to masquerade packets coming from 192.168.0.0, it will masquerade only those packets, not packets from any other address in 192.168.0.0-192.168.0.255 (192.168.0.0/24).
by Emil66
Tue Oct 05, 2021 1:02 pm
Forum: Beginner Basics
Topic: Yet another hairpin nat question [SOLVED]
Replies: 20
Views: 5591

Re: Yet another hairpin nat question [SOLVED]

See the hairpin NAT documentation . Note that the destination address matched in the src-nat rule is not the external address. Source-NAT is performed after the destination-NAT rule has changed the destination address to the internal address of the server. For debugging, keep an eye on the firewall ...
by Emil66
Thu Sep 30, 2021 11:50 pm
Forum: Beginner Basics
Topic: url filtering on ssl traffic through Web Proxy Configuration
Replies: 15
Views: 4517

Re: url filtering on ssl traffic through Web Proxy Configuration

It is (for now) possible to filter based on the "outer" domain name as transmitted in the TLS negotiation. In order to indicate to the server which certificate to use, the clients send the domain name as "server name indication" (SNI). This happens before the certificate is prese...
by Emil66
Wed Jul 28, 2021 10:36 am
Forum: Beginner Basics
Topic: IPv6 for home
Replies: 15
Views: 14194

Re: IPv6 for home

Some things are easier with IPv6, because there is no NAT. Some things are more difficult with IPv6, because there is no NAT.
by Emil66
Wed Jul 28, 2021 12:17 am
Forum: Beginner Basics
Topic: IPv6 for home
Replies: 15
Views: 14194

Re: IPv6 for home

There is no mechanism for prefix delegation in RAs. RAs advertise the router's prefix(es). They are not and indeed cannot be used to delegate prefixes. Conversely there is no mechanism for advertising prefixes in the DHCPv6 standard, just for delegating them. Delegating means assigning an entire pre...
by Emil66
Tue Jul 27, 2021 6:56 pm
Forum: Beginner Basics
Topic: IPv6 for home
Replies: 15
Views: 14194

Re: IPv6 for home

mkx may be dissatisfied with the features supported by the RouterOS DHCPv6 server, but claiming that it can't distribute prefixes is factually incorrect. In a SOHO environment, DHCPv6 is really only needed for prefix delegation and RouterOS can do that.
by Emil66
Tue Jul 27, 2021 5:53 pm
Forum: Beginner Basics
Topic: IPv6 for home
Replies: 15
Views: 14194

Re: IPv6 for home

DHCPv6 server in ROS v6 implements only a fraction of functionality (which doesn't include neither prefix distribution nor end device IPv6 address) and is used only for distributing IPv6 addresses of DNS servers (and perhaps some other minor stuff). Prefix sharing is done through different mechanis...
by Emil66
Sat Jul 24, 2021 11:44 pm
Forum: Beginner Basics
Topic: Allow WAN IP to LAN Client within LAN
Replies: 8
Views: 2058

Re: Allow WAN IP to LAN Client within LAN

Yes, that's the hairpin-NAT rule. The "masquerade" target changes the source address to the address of the egress interface. Use the "src-nat" target instead and set the "to-addresses" in that rule to the WAN-address.
by Emil66
Sat Jul 24, 2021 11:24 pm
Forum: Beginner Basics
Topic: layer 7 port forwarding
Replies: 17
Views: 4602

Re: layer 7 port forwarding

You can match for the SNI host in the firewall by setting the "tls-host" parameter. You can use that to dst-nat towards different backends. Note that this doesn't work for fragmented packets, the QUIC protocol or ESNI. A reverse proxy would be the preferred solution.
by Emil66
Sat Jul 24, 2021 11:00 pm
Forum: Beginner Basics
Topic: Allow WAN IP to LAN Client within LAN
Replies: 8
Views: 2058

Re: Allow WAN IP to LAN Client within LAN

You're seeing the result of a hairpin-NAT-rule. This is explained here: https://help.mikrotik.com/docs/display/ROS/NAT#NAT-HairpinNAT . If you just need to change the address to the WAN IP address of the router instead of its LAN IP address, you can do that by changing the "to-addresses" i...
by Emil66
Sat Jul 24, 2021 9:40 pm
Forum: Beginner Basics
Topic: Which FW rule permits 'services'
Replies: 9
Views: 1518

Re: Which FW rule permits 'services'

The firewall in RouterOS is default-allow. The underlying Linux kernel can set a different default policy per chain, but this is not exposed in RouterOS. So any packet which makes it to the end of a chain is accepted. The rule which is responsible for "allowing" services on the router to b...
by Emil66
Sat Jul 17, 2021 7:53 pm
Forum: RouterOS beta
Topic: Multiple IPv6 Gateways and geo routing on 7.1 Beta 6
Replies: 8
Views: 2196

Re: Multiple IPv6 Gateways and geo routing on 7.1 Beta 6

In that case your ISP may not be doing ingress filtering. That is bad. (HE certainly filters.) You can send packets with alien source addresses through your ISP, but the return traffic to these addresses will still arrive through the HE tunnel, so you've created asymmetric routing. If the router doe...
by Emil66
Sat Jul 17, 2021 11:02 am
Forum: RouterOS beta
Topic: Multiple IPv6 Gateways and geo routing on 7.1 Beta 6
Replies: 8
Views: 2196

Re: Multiple IPv6 Gateways and geo routing on 7.1 Beta 6

As I wrote before, with IPv4 you can do this because NAT changes the source address to the address which is assigned to the interface through which the packets are sent out. It doesn't work with IPv6 because there is no NAT. The packets are sent out exactly how they arrive from the device, so the de...
by Emil66
Fri Jul 16, 2021 6:30 pm
Forum: RouterOS beta
Topic: Multiple IPv6 Gateways and geo routing on 7.1 Beta 6
Replies: 8
Views: 2196

Re: Multiple IPv6 Gateways and geo routing on 7.1 Beta 6

If a host uses a source IPv6 address from the HE prefix, then your router must send that traffic through the HE tunnel, regardless of the destination address, because your ISP will almost certainly drop these packets. If the host uses a source IPv6 address from the provider prefix, then your router ...
by Emil66
Fri Jul 16, 2021 2:55 pm
Forum: RouterOS beta
Topic: Multiple IPv6 Gateways and geo routing on 7.1 Beta 6
Replies: 8
Views: 2196

Re: Multiple IPv6 Gateways and geo routing on 7.1 Beta 6

Unless you have provider-independent address space and an agreement with your provider that allows you to use it, you usually can't send from IP addresses that aren't assigned to you by your provider. The router needs to pick the route based on the source IP address chosen by the device. It can't ju...
by Emil66
Mon Apr 26, 2021 12:12 am
Forum: General
Topic: Seperate DHCP Servers for Trunked VLAN's
Replies: 3
Views: 669

Re: Seperate DHCP Servers for Trunked VLAN's

You need to create VLAN interfaces on the bridge interface, not on interfaces that are part of the bridge. And then you bind the DHCP servers to the VLAN interfaces. So you have for example "ether1", "ether2" and "ether3" in "yourbridge". You configure "e...
by Emil66
Sun Apr 25, 2021 1:09 pm
Forum: General
Topic: Webfig bug? IPv6 dhcp-server can't set pool
Replies: 0
Views: 735

Webfig bug? IPv6 dhcp-server can't set pool

I've been trying for hours to configure a DHCPv6 server for prefix delegation and the server keeps telling the client "no prefix available". I think I found what's wrong: The web configuration interface lets you set the pool from which the prefixes are assigned, and you can apply/ok and se...
by Emil66
Tue Mar 09, 2021 6:05 pm
Forum: Scripting
Topic: cant get X OR Y AND Z properly working
Replies: 4
Views: 1169

Re: cant get X OR Y AND Z properly working

Note that (A || B && C) means (A || (B && C)) due to operator precedence, not ((A || B) && C). If you want the latter, you need to use parentheses as shown. It's like 1+2*3 is 7, not 9.
by Emil66
Wed Mar 03, 2021 11:48 pm
Forum: Scripting
Topic: changing DNS does not work until reboot [Pi-hole related, specific dns for specific ip] [SOLVED]
Replies: 2
Views: 3031

Re: changing DNS does not work until reboot [SOLVED]

The DHCP clients receive the DNS server addresses with their initial DHCP lease. Unless they disconnect from the network and reconnect, they do not get them again. If you want to make the change instantaneous, you can use NAT to redirect DNS requests to your filtering DNS server during the daytime.
by Emil66
Wed Mar 03, 2021 6:01 pm
Forum: Scripting
Topic: Multiple If Statements [SOLVED]
Replies: 2
Views: 1537

Re: Multiple If Statements [SOLVED]

:if ($a=1) do={ :log info "A is definitely 1"} else={ :if ($a=2) do={ :log info "A is definitely 2"} else={ :log info "A is not 1 or 2"} If you fix your formatting, the problem becomes obvious: You're missing a closing brace for the first else. :if ($a=1) do={ :log inf...
by Emil66
Tue Mar 02, 2021 10:32 pm
Forum: Scripting
Topic: array variable defined as local
Replies: 2
Views: 1792

Re: array variable defined as local

See the explanation and a workaround here: viewtopic.php?f=9&t=172125#p843397
by Emil66
Mon Feb 15, 2021 9:51 pm
Forum: Scripting
Topic: How can I sum the limits-at of all child queues?
Replies: 6
Views: 1595

Re: How can I sum the limits-at of all child queues?

You still need to deal with "numbers" like 768k, 3M or 1G.
by Emil66
Mon Feb 15, 2021 9:50 pm
Forum: Announcements
Topic: v6.48.1 [stable] is released!
Replies: 103
Views: 60769

Re: v6.48.1 [stable] is released!

Why do not not see Temperature/Voltage?
I had the same issue. It works again after I clicked "OK" on the empty settings page. (I use the web interface.)
by Emil66
Sat Feb 13, 2021 11:44 am
Forum: Scripting
Topic: Sum values obtained with foreach
Replies: 3
Views: 1555

Re: Sum values obtained with foreach

Sums are obtained by adding stuff up. Computers only do what they're told. Try telling the computer to add something.
by Emil66
Fri Feb 12, 2021 8:47 pm
Forum: Scripting
Topic: local dictionary variable persisting between runs [SOLVED]
Replies: 14
Views: 3427

Re: local dictionary variable persisting between runs [SOLVED]

is this a feature, a known limitation or a bug It's a choice: https://en.wikipedia.org/wiki/Local_variable#Static_local_variables It's a bit weird that scalar variables are not static and arrays are, but the script language is all sorts of weird anyway. I do understand however that ({}) is not the ...
by Emil66
Fri Feb 12, 2021 2:10 am
Forum: Scripting
Topic: local dictionary variable persisting between runs [SOLVED]
Replies: 14
Views: 3427

Re: local dictionary variable persisting between runs [SOLVED]

Mikrotik RouterOS script variables are "static". The value is stored with the function, and as you have seen, this is implemented by rewriting the function whenever the value of a local variable is changed. Assigning an array is done by reference, not by value, which means the variable doe...
by Emil66
Mon Dec 14, 2020 10:47 pm
Forum: Beginner Basics
Topic: How to Stop Brute Force Attacks on HTTP / HTTPS Mikrotik
Replies: 2
Views: 691

Re: How to Stop Brute Force Attacks on HTTP / HTTPS Mikrotik

It seems you only need the port open for yourself or a small number of users (because you mention changing the port number regularly). In that case you could use " port knocking " to hide the open port from scanners. Make sure to use an individual sequence of ports, not the ones in the tut...
by Emil66
Sat Dec 05, 2020 1:47 pm
Forum: General
Topic: Firewall oddity
Replies: 10
Views: 1798

Re: Firewall oddity

If you can sell me a couple public IPv4 addresses for less than the cost of a replacement router which handles IPv6 properly, I'm all ears. As it is, I can only recommend against using Mikrotik gear if IPv6 is a requirement. That said, after some more testing it looks like the router doesn't reassem...
by Emil66
Sat Dec 05, 2020 12:31 am
Forum: General
Topic: Firewall oddity
Replies: 10
Views: 1798

Re: Firewall oddity

I've done that. It just tells me that it's a UDP packet with the right properties to be caught by the second rule. That's why I wrote the second rule as the inverse of the first rule: It really should not be possible for a packet to make it past the first and second rule and still match the third ru...
by Emil66
Fri Dec 04, 2020 11:46 pm
Forum: General
Topic: Firewall oddity
Replies: 10
Views: 1798

Re: Firewall oddity

I think it's a connection tracking / SIP helper problem. I can't reproduce it with just ordinary UDP packets that have no prior relation to some other connection. It reliably occurs if the UDP packet is an RTP packet coming in for a SIP "connection". I don't understand how that could make ...
by Emil66
Fri Dec 04, 2020 10:58 pm
Forum: General
Topic: Firewall oddity
Replies: 10
Views: 1798

Re: Firewall oddity

That's not it. I just used the inversion to make sure I cover all ports with the first two rules. The result is the same if I positively check for 10000-65535 in the second rule. The packet with the high port doesn't match that rule and falls through to the third rule, where it matches. It doesn't e...
by Emil66
Fri Dec 04, 2020 10:34 pm
Forum: General
Topic: Firewall oddity
Replies: 10
Views: 1798

Re: Firewall oddity

The three rules are: add action=drop chain=forward dst-address-list=test dst-port=1-9999 protocol=udp add action=accept chain=forward dst-address-list=test dst-port=!1-9999 protocol=udp add action=accept chain=forward dst-address-list=test protocol=udp The ​address list is a single IPv6 address. It ...
by Emil66
Fri Dec 04, 2020 9:39 pm
Forum: General
Topic: Firewall oddity
Replies: 10
Views: 1798

Firewall oddity

If I have three IPv6 firewall rules, that each accept or drop after checking for UDP dst-port 1-9999, UDP dst-port ! 1-9999 and just UDP, I would expect the last rule to never match, because a port is either in that range or not in that range, so either rule one or two should match and end processin...
by Emil66
Wed Aug 21, 2019 5:03 pm
Forum: General
Topic: Slow Gbit speed with Mikrotik hex S
Replies: 15
Views: 8396

Re: Slow Gbit speed with Mikrotik hex S

FYI: You're reading the block diagram wrong. The Hex S is capable of routing a full gigabit one way even on ports which use the same path to the CPU. Each of the two gigabit CPU links is 1 Gbps in and 1 Gbps out. You only need to use ports which are on separate links if you want to route a gigabit i...
by Emil66
Tue Jun 18, 2019 12:31 am
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 10959

Re: single IP constantly trying to log to my Mikrotik

The point was I understand about the order of firewall rules and efficiency of checking packets. What I was questioning and wanted to see a reference about was this line........... " Things like tracked connections (and also address lists) are stored in a clever way so the match can be made mo...
by Emil66
Mon Jun 17, 2019 9:53 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 10959

Re: single IP constantly trying to log to my Mikrotik

@Emil66 It's a forum for technical assistance. Don't be offended when you "waltz in" post "some gut feelings and expectations" without any substations, and someone reacts on that... Your opinions are incorrect. This thread could have been over when vecernik87 correctly informed ...
by Emil66
Sun Jun 16, 2019 8:14 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 10959

Re: single IP constantly trying to log to my Mikrotik

looking for a reference that the router processes filter rules of accepted/related more efficiently than other firewall filter rules in general and specifically better than raw rules. Nobody said anything like that. Each rule that needs to be checked takes some time, When processing a packet that b...
by Emil66
Sat Jun 15, 2019 11:41 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 10959

Re: single IP constantly trying to log to my Mikrotik

I asked for factual info & data, not some gut feelings and expectations! The Linux kernel code is open source. You can look it up yourself. This is the Mikrotik Beginner Basics forum, not a technical debate club. ...to pass many rules before they are accepted, the CPU load will be high... Can y...
by Emil66
Sat Jun 15, 2019 1:29 am
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 10959

Re: single IP constantly trying to log to my Mikrotik

I wouldn't advise to use raw-prerouting rule. It might have negative impact on speed of all (including fasttracked) connections. ... it will have more negative, than positive consequences because ... This is based on what factual info / data? It a rule base system like any other table (filter,nat,m...
by Emil66
Sat Feb 09, 2019 11:43 pm
Forum: General
Topic: [Feature Request] IPv6 Fasttrack
Replies: 39
Views: 16405

Re: [Feature Request] IPv6 Fasttrack

I was not aware that any Mikrotik Products supported DS-Lite, please explain how you support this. They don't support DS-Lite. But DS-Lite is just native IPv6 with an IPIPv6 tunnel to a CGNAT gateway for IPv4. Mikrotik routers can do the tunneling, but lack the automatic configuration and the neces...
by Emil66
Sun Nov 11, 2018 12:25 pm
Forum: General
Topic: [Feature Request] IPv6 Fasttrack
Replies: 39
Views: 16405

[Feature Request] IPv6 Fasttrack

I was led to believe that the Hex S (RB760IGS) achieves full gigabit throughput. This is not the case with IPv6. Due to the lack of IPv6 fasttrack support, IPv6 throughput maxes out at roughly 500 Mbit/s. That alone is bad enough, but on a DS-Lite connection, IPv4 is tunneled via IPv6, so even IPv4 ...
by Emil66
Fri Nov 02, 2018 12:23 am
Forum: General
Topic: [Feature Request] DHCP(v4/v6) client: Make arbitrary option codes requestable and provide their values to the script
Replies: 7
Views: 3909

[Feature Request] DHCP(v4/v6) client: Make arbitrary option codes requestable and provide their values to the script

Motivation: The DHCP server in Mikrotik routers can be configured to supply arbitrary options to clients, and the DHCP client in Mikrotik routers can be configured to add arbitrary options too, but the DHCP client has no method of requesting arbitrary options from the server and does not make values...
by Emil66
Wed Oct 31, 2018 5:33 pm
Forum: Beginner Basics
Topic: DS-Lite (RFC 6333 + RFC 6334)
Replies: 2
Views: 2690

DS-Lite (RFC 6333 + RFC 6334)

I'm trying to configure a Mikrotik router to use a DS-Lite (dual stack lite) internet connection as defined in RFCs 6333 and 6334 . DS-Lite combines a native IPv6 connection with a IPIPv6 tunnel to a CGNAT gateway called AFTR (Address Family Transition Router). The router learns the remote tunnel en...
by Emil66
Tue Aug 28, 2018 1:17 pm
Forum: Beginner Basics
Topic: Bug in default configuration
Replies: 2
Views: 922

Re: Bug in default configuration

This is already the case in default configuration.. Indeed it is. I dug a little deeper, and while the default configuration has the addresses on the bridge, applying the configuration from the "Quick Set" form moves the addresses over to ether2, even if all I change is the password. So t...
by Emil66
Tue Aug 28, 2018 2:35 am
Forum: Beginner Basics
Topic: Bug in default configuration
Replies: 2
Views: 922

Bug in default configuration

Disclaimer: I am an absolute beginner. Got my first Mikrotik router today. Nevertheless, I think there's a problem in the default configuration, but as I'm new to this, I'm not sure. Please enlighten me if this is my mistake. In the default configuration, ports 2 through 5 and the SFP slot are in a ...