Community discussions

MikroTik App

Search found 37 matches

by G00dm4n
Thu Mar 28, 2024 2:59 am
Forum: Scripting
Topic: Future for posibility of moidular setings
Replies: 1
Views: 174

Future for posibility of moidular setings

I am interested if in near future we will have something as UUID on config lines and log state of those. This may provide possibilities for future modular setup where admin can add and remove bunch of rules with activating some module or the things can be managed automatically by event or condition....
by G00dm4n
Tue Nov 22, 2022 12:09 am
Forum: General
Topic: Any way to have defined PORTS/SERVICES List?
Replies: 1
Views: 245

Any way to have defined PORTS/SERVICES List?

Hi Gents, I am thinking... can we have something like ports list or services lists (some services use more than one port). The point is this values can be used in scripting or so. The best option will be list that can be loaded with predefined variables and option to be changed or possibility to add...
by G00dm4n
Mon Sep 26, 2022 12:42 am
Forum: RouterBOARD hardware
Topic: USB or M2 to CCR2004-12s-2xs
Replies: 0
Views: 552

USB or M2 to CCR2004-12s-2xs

Hi guys! I have a bit peculiar question, but just recently I have realized that my CCR2004-12S-2XS do not have any USB. Not that is too much of a problem nut I was thinking to run PiHole or AdGuardHome in docker there or at least some proxy /reverse proxy service. Planning this I would like to have ...
by G00dm4n
Sat Mar 26, 2022 2:57 am
Forum: Announcements
Topic: Newsletter 104
Replies: 54
Views: 26067

Re: Newsletter 104

Still no NGFW functions... this is causes serious client drift to Sophos/pfSense/Fortigate....
Can this be fixed???
by G00dm4n
Sat Mar 05, 2022 4:43 am
Forum: General
Topic: NGFW App and SVC filtering?
Replies: 0
Views: 247

NGFW App and SVC filtering?

Does MT have any plans to create a loadable modules or snippets that can do DPI with TLS 1.2/1.3 screening and something like list of predefined App and Services patterns that can be used to do quicker FW filtering???
by G00dm4n
Sun Feb 28, 2021 3:31 am
Forum: RouterOS beta
Topic: v7.1beta4 [development] is released!
Replies: 211
Views: 57086

Re: v7.1beta4 [development] is released!

Hi Guys,

I do not know if I do something wrong but I cant get to graphs & webfig (even this) on my CCR1009 after upgraded to 7.1b4.
Does any one have similar issues?
by G00dm4n
Sat Feb 13, 2021 11:56 pm
Forum: RouterBOARD hardware
Topic: CCR possibility for plugin card based on Raspberry Pi
Replies: 1
Views: 989

CCR possibility for plugin card based on Raspberry Pi

Hey guys, I see a lot of things can be run over Raspberry Pi. Why not provide options for plugin module which can use some Raspberry Pi for additional options like DPI, additional compute power for traffic analyse or more advanced scripting which corresponds with RouterOS scripts? This may give chan...
by G00dm4n
Sat Feb 13, 2021 11:35 pm
Forum: RouterBOARD hardware
Topic: Successor to CRS210-8G-2S+ desktop switch?
Replies: 9
Views: 6951

Re: Successor to CRS210-8G-2S+ desktop switch?

Up (+1) :-)
Yeah I have moved from CRS210 to CRS610 and was surprised by the SwOS.
I would love to see 310/410 or etc (with maybe more than 2 SFP+)...
Also will be happy if I see 610 with RouterOS.
by G00dm4n
Mon Jan 11, 2021 12:55 pm
Forum: General
Topic: Firewall filtering with L7 or DPI for certain content
Replies: 0
Views: 588

Firewall filtering with L7 or DPI for certain content

Can we expect in the future something more serious as SSL and DPI implementation in the future? Also will be good if there's a service for providing verified filtering lists. I am using currently L7-filtering + ADBlock script + DNS static addresses + Umbrella DNS. I come across this as see L7 filter...
by G00dm4n
Tue Jan 05, 2021 10:28 am
Forum: General
Topic: LAN speed issue
Replies: 15
Views: 2437

Re: LAN speed issue

... you don't need to replace the CRS2xx right now, it is enough to configure the VLAN handling on the switch chip. The right choice depends on the comparison of the price of your time to the price of the new switches. Time is always priceless! You can earn money, but not time. But if you get more ...
by G00dm4n
Tue Jan 05, 2021 3:12 am
Forum: General
Topic: LAN speed issue
Replies: 15
Views: 2437

Re: LAN speed issue

Huh, Sorry fellas! I have felt victim on my own disinformation - i have forget to look the specs of CCR210-8G-2S+. They do not support HW offload for VLANs and this is what was affecting the performance. There a way this to be partially avoided with Switch chip configuration, but this will bring fut...
by G00dm4n
Tue Jan 05, 2021 1:11 am
Forum: General
Topic: LAN speed issue
Replies: 15
Views: 2437

Re: LAN speed issue

If the PC and the NAS discussed above are normally in different IP subnets, it means that the traffic between them must run through the CCR in order to be routed. If the two devices are normally in the same IP subnet, you could connect the switches to each other directly (and only one of them to th...
by G00dm4n
Mon Jan 04, 2021 8:53 pm
Forum: General
Topic: LAN speed issue
Replies: 15
Views: 2437

Re: LAN speed issue

What I was actually interested in was the other part of my post - whether the PC to NAS traffic is bridged via the CCR (or possibly even routed through it if the PC gets its IP from a DHCP server) or whether it can bypass it when the PC and the NAS are connected to different CRS. Consider CCR is De...
by G00dm4n
Mon Jan 04, 2021 4:45 pm
Forum: General
Topic: LAN speed issue
Replies: 15
Views: 2437

Re: LAN speed issue

This is not a bridge port.......... /interface bridge port add bridge=bridge-LAN interface=ether3 add bridge=bridge-LAN interface=ether4 add bridge=bridge-LAN interface=ether5 add bridge=bridge-LAN interface=ether6 add bridge=bridge-LAN interface=ether7 add bridge=bridge-LAN interface=ether8 add br...
by G00dm4n
Mon Jan 04, 2021 4:39 pm
Forum: General
Topic: LAN speed issue
Replies: 15
Views: 2437

Re: LAN speed issue

What is not clear from your OP (at least to me) is the L2 and L3 topology. Since you wrote now that the PC can be connected to the same CRS like the NAS, I assume the PC and the NAS are in the same subnet and (V)LAN, so the traffic between the two is a pure L2 one (need not be routed by the CCR), p...
by G00dm4n
Mon Jan 04, 2021 4:06 pm
Forum: General
Topic: LAN speed issue
Replies: 15
Views: 2437

Re: LAN speed issue

You might want to post your config on the crs210 devices. If you are hitting the cpu, then that would explain the ~300Mbps cap. Yeah I was looking for this too. But I did not changed the config of those devices for a year. Here it is: # jan/04/2021 16:00:18 by RouterOS 6.47.4 # model = CRS210-8G-2S...
by G00dm4n
Mon Jan 04, 2021 3:52 pm
Forum: General
Topic: LAN speed issue
Replies: 15
Views: 2437

Re: LAN speed issue

I think before my systems was on 6.46.5, but since this all start with try to move to 7.1 beta... i moved to most updated stable firmware after the beta have failed. Maybe worth downgrading back there. The test shows that when my PC is on same switch with the NAS (CRS328) then I can achieve 112-114M...
by G00dm4n
Mon Jan 04, 2021 3:09 pm
Forum: General
Topic: LAN speed issue
Replies: 15
Views: 2437

LAN speed issue

Hi Gents, Seems I have strange issue which to be started after I'd upgraded to 6.48. I have small home network containing CCR1009-7G-1C, 2x CRS210-8G-2S+ and CRS 328P-4S+. The CCR is the main router and GW. Anyway - worth mentioning all links are 1Gb or 10Gb. The CCR provides internet to all through...
by G00dm4n
Tue Dec 29, 2020 4:32 pm
Forum: RouterOS beta
Topic: V.7 MULTIWAN from 2 LTE routers
Replies: 3
Views: 1941

Re: V.7 MULTIWAN from 2 LTE routers

Did you manage it?
Do you still need some help?
by G00dm4n
Sun Oct 25, 2020 12:43 am
Forum: General
Topic: CCR 2004 compatibility with SFP 10/100/1000 modules.
Replies: 3
Views: 1733

Re: CCR 2004 compatibility with SFP 10/100/1000 modules.

Well,
I have changed the SFPs with Mikrotik ones but I still cannot set them to work on 100MB.
This makes connecting some legacy devices problematic and seems to be an issue - not all legacy devices can be changed due our liking.
Please advice if there's solution for this issue.

Regards, G00dm4n
by G00dm4n
Sun Oct 25, 2020 12:16 am
Forum: RouterOS beta
Topic: Future request - port security & mac-binding & mac limit
Replies: 3
Views: 2607

Re: Future request - port security & mac-binding & mac limit

What about this solution? :
viewtopic.php?t=126351#p689180
It's so-so... solves the issue but in peculiar way.
by G00dm4n
Sat Oct 24, 2020 11:52 pm
Forum: RouterOS beta
Topic: Future request - Configuration propagation similar to CAPsMAN
Replies: 6
Views: 3226

Re: Future request - Configuration propagation similar to CAPsMAN

and sorry I couldn't resist ... let be god a G00dm4n Well I really did not check TR069. And probably more similar products exist. I think MT wants to grow, and have only open source solution which have to be tuned is not enough. Logical answer for this is the CAPsMAN itself - could be used just ano...
by G00dm4n
Fri Oct 16, 2020 12:40 am
Forum: RouterOS beta
Topic: CAPsMAN2 maybe we can have NETsMAN in the future
Replies: 1
Views: 1402

CAPsMAN2 maybe we can have NETsMAN in the future

Hi gents, I was looking some of the competitive products and think Mikrotik have an amazing configuration provisioning tool - CAPsMAN. But maybe this can be extended in the future with abilities to provision configuration to any available Mikrotik device - switch, router, firewall and APs. Yes this ...
by G00dm4n
Sat Jun 20, 2020 4:25 am
Forum: General
Topic: CCR 2004 and other models fan noise
Replies: 5
Views: 3475

Re: CCR 2004 and other models fan noise

I finally have CCR 2004 in my hands and did some tests. The device is pretty neat and really silent while working with load up to 10%. The fans not running at all and just sometimes they go for few seconds. Noise is under 36dbm. Maybe have to check in more hot environment and higher load. There's ot...
by G00dm4n
Sat Jun 20, 2020 4:16 am
Forum: General
Topic: Stop making customers lab rats
Replies: 47
Views: 12802

Re: Stop making customers lab rats

First of all - sorry for your troubles. As a fellow admin - I can feel your pain. How we can help you without knowing your switch configuration and setup? What is connected, how, what brand stays from other side of the link. Can you give more details and send the config? There are issues even betwee...
by G00dm4n
Sat Jun 20, 2020 3:57 am
Forum: General
Topic: CCR 2004 compatibility with SFP 10/100/1000 modules.
Replies: 3
Views: 1733

CCR 2004 compatibility with SFP 10/100/1000 modules.

Hi Gents, I've tried to use Cisco GLC-T SFP's with the new CCR 2004 and faced some issues. The Cisco GLC-T are compatible with Mikrotik routers (I have read it somewhere) and they should be able to work on 10/100/1000. No issue if I set them to 1Gb or use it with auto and 1G link, but they not work ...
by G00dm4n
Sat Jun 20, 2020 3:30 am
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082537

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

Thanks,

I will do some testing when I have time.
In this funny times I have been summoned to join with my team.
After listening that we will start probably at September or so I was requested to join in few days.
Have to put on hold some of my projects for a while.
Will reply ASAP.
by G00dm4n
Sun Jun 14, 2020 12:01 pm
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082537

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

Hi TomFisk, I see your point. Maybe you can help me to do step-by-step list what and how to use your methid with SELKS. As you pointed additional components in SELKS really add lot of load. I am also interested to use minimum install - just Suricata + necessary interfaces so this can be implemented ...
by G00dm4n
Sun Jun 14, 2020 3:17 am
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082537

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

Hi guys, I find here some info for using Suricata IDS/IPS with Mikrotik. I also found there's a good build from Stamus Networks who is good and stable - SELKS. Can someone post more straight and updated manual of using Microtik together with SELKS5 or SELKS6 RC1. I prefer we get straight to latest -...
by G00dm4n
Sat May 30, 2020 9:37 pm
Forum: General
Topic: CCR 2004 and other models fan noise
Replies: 5
Views: 3475

Re: CCR 2004 and other models fan noise

Thanks archerious!
I was just thinking if worth upgrading CCR1009 to CCR2004.
With this noise data I can think if will fit in my place and if I would have any noise to deal with.
This is really helpful info.
I hope Mikrotik to start adding this info too.

Best regards!
by G00dm4n
Fri May 29, 2020 1:22 am
Forum: General
Topic: CCR 2004 and other models fan noise
Replies: 5
Views: 3475

CCR 2004 and other models fan noise

Hi Gents,

Just asking if anyone of you can share some info for the noise factor of some of the routers.
First and most I am interested of the newest CCR2004.
Also will be good if someone post for CCR1016, 1036 and 1072.
Thanks in advance.
by G00dm4n
Thu May 28, 2020 9:23 am
Forum: RouterOS beta
Topic: Modem doesn't work in LtAP LTE6 kit
Replies: 7
Views: 2593

Re: Modem doesn't work in LtAP LTE6 kit

I was doing some tests and face same issues.
The question is when will be issued next version/build :-)
by G00dm4n
Wed May 27, 2020 12:23 pm
Forum: RouterOS beta
Topic: Future request - port security & mac-binding & mac limit
Replies: 3
Views: 2607

Future request - port security & mac-binding & mac limit

Hi Gentleman, I think is time to put some effort over such basic functionality as portswitch port security. In general this is what mac-learning+mac-binding+interface-set can do together and in addition have to recognize associated MAC address in the table by the originated interface. Well I know th...
by G00dm4n
Wed May 27, 2020 12:01 pm
Forum: General
Topic: Do we have something like port security available???
Replies: 3
Views: 3752

Re: Do we have something like port security available???

Hi MutluIT (hope I recognise proper spelling), I know what is the backside of the port security by MAC and that this identity can be easily changed. However is basic security future in the enterprise networking - mostly because there other measures preventing changing the MAC and monitoring connecti...
by G00dm4n
Wed May 27, 2020 4:29 am
Forum: General
Topic: Do we have something like port security available???
Replies: 3
Views: 3752

Do we have something like port security available???

Hi Gents,
Sorry for this maybe stupid question but while i was dealing with request to set something I could not find something as a port security and limitation of MAC addresses per interface.
Can you guide me if I am missing something?
by G00dm4n
Wed May 06, 2020 1:48 am
Forum: RouterOS beta
Topic: Future request - Configuration propagation similar to CAPsMAN
Replies: 6
Views: 3226

Future request - Configuration propagation similar to CAPsMAN

Hi Gents, I am thinking if there are some chances of creating option similar to CAPsMAN which can propagate specific configurations via profiles to MT routers/switches in the network on its initial boot. My idea is that if this can be done its possible to have central configuration with files for ea...
by G00dm4n
Sun Apr 26, 2020 4:17 am
Forum: Announcements
Topic: Future of LTE products, user feedback requested
Replies: 208
Views: 102658

Re: Future of LTE products, user feedback requested

We would like to know our customer wishes and use cases on what kind of future LTE technology would be interested in? 1. Which LTE Category you are interested in most - CAT6, CAT7, CAT9, CAT11, CAT12, CAT16 or some other? 2. Which LTE bands and which Carrier Aggregation combinations should be suppor...