Community discussions

MikroTik App

Search found 231 matches

by floaty
Sat Sep 19, 2020 12:01 am
Forum: The Dude
Topic: Feature request - Default SNMP profile for the Map
Replies: 3
Views: 2518

Re: Feature request - Default SNMP profile for the Map

+1 . great I've found your post ! everytime I'm doing a re-discovery (and networks ... ... there arara changing!) ... I give the bold F-word three times, because nothing happens : | ... also a discoverable service-preset would be very sensefull ( ... do not know if this has to be forked into a new ...
by floaty
Sat Aug 22, 2020 8:43 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 285
Views: 71779

Re: v7.1beta2 [development] is released!

L3-offloading is a broad topic ... the prestera-chip also supports "NVGRE, VXLAN-GPE, GENEVE, SPB, and 802.1BR port extender"
... is vxlan-tunneling now also implemented with hardware-flow-support ... or we talking just base L3-forwarding capabilities ( ... for now) ?
by floaty
Fri Aug 21, 2020 3:48 pm
Forum: General
Topic: NetDuma
Replies: 10
Views: 4270

Re: NetDuma

Had a look, to the system ... obviously some fork or kind of open-wrt ... not much functionality left, from what you can get, if ROS or an 'open' OpenWRT is installed. Strolled into the Netduma-forum, where the Netduma-CTO claims, that the machine contains proprietary QoS-functionality, which makes ...
by floaty
Sat Aug 01, 2020 5:09 am
Forum: General
Topic: IPSEC tunnels with failover
Replies: 5
Views: 1212

Re: IPSEC tunnels with failover

so why the effin f'''' did you not started testing yet ?
by floaty
Sat Aug 01, 2020 4:50 am
Forum: General
Topic: Suggestion: redesign Tools-Profile in Winbox
Replies: 2
Views: 753

Re: Suggestion: redesign Tools-Profile in Winbox

.
would horizontalize the problem for tile-cpu's (just a remark ... I'm not an owner ... not now)
.
guess the general possibility to export a table to csv would do it for the relevant horsemen !?
.
( ... as always: just my opinion ... you can do whatever you want ... without affecting my circles)
by floaty
Sat Aug 01, 2020 4:40 am
Forum: Beginner Basics
Topic: VPN Connection to remote Client
Replies: 1
Views: 555

Re: VPN Connection to remote Client

Hi Emmah,

your verbal descrption of your problem is not sufficent to help you.
... if the problem is really bugging you, make a sketch and try to illustrate where you got stuck.
... give the people here an idea what you did on the device !

namaste
by floaty
Sat Aug 01, 2020 4:26 am
Forum: The User Manager
Topic: Does Static DHCP work using UserMan 7.1beta
Replies: 1
Views: 1141

Re: Does Static DHCP work using UserMan 7.1beta

It's a BETA-version ... and exactly meant to reinvent your discovery spirit. UserMan is and was a radius-implemention so adressing for clients, is done with radius-attributes. Not shure which features you are targeting on ... but that worked with a lot of versions before 7.XBETA. So stage your lab ....
by floaty
Sat Aug 01, 2020 4:05 am
Forum: Wireless Networking
Topic: AndroidTV Wifi issue
Replies: 2
Views: 798

Re: AndroidTV Wifi issue

. you failed ... in multiple ways ! . 1st) you failed with laying out your issue and your network design in a reasonable way . 2nd) you brought your personel confusion into this forum . 3rd) you have already a workaround (RBD52G is working pretty, while 951G makes headache*) ... so nobody has motive...
by floaty
Sat Aug 01, 2020 3:37 am
Forum: Beginner Basics
Topic: Installing RouterOS via iPXE to headless Embedded Board x86 & Rant.
Replies: 1
Views: 453

Re: Installing RouterOS via iPXE to headless Embedded Board x86 & Rant.

.
Direct to the point, is it even possible in the first place?
.
a question ...
a question that might also Descartes, Pascal and Heisenberg could have asked that way ...
.
: ) don't bust our nuts ... and post the solution :!:
by floaty
Sat Aug 01, 2020 3:16 am
Forum: RouterBOARD hardware
Topic: Question about IPsec test results
Replies: 4
Views: 1233

Re: Question about IPsec test results

. the question is indeed not fully without cause ... guess you want to connect to another vendor ? ... if not ... ignore my mumble ... not an expert, but in a stream-cipher with an pre-shared or diffie-hellman'ed key, should the cpu-load for de- & encrypt pretty much the same And I guess the referen...
by floaty
Sat Aug 01, 2020 2:50 am
Forum: RouterBOARD hardware
Topic: Issues and questions about forum
Replies: 4
Views: 951

Re: Issues and questions about forum

I'm saving this text in case it will disappear as well.
.
you're safe here :!:
.
you should consider such a task if you're wandering an ubnt-forum .... because it happened to me there ( for minor boldness : )
by floaty
Sat Aug 01, 2020 2:25 am
Forum: General
Topic: DHCP Relay cant access internet
Replies: 1
Views: 456

Re: DHCP Relay cant access internet

. first ! ... you giving us config-data (which is a nice thing) ... you put it in here: . post-cfg.PNG . so nobody gets eye-cancer ! . and I'm not shure if you posted everything from router2 ... but a default-route to router1 would make huge sense .... and I'm missing it ... do you copy ? providing ...
by floaty
Sat Aug 01, 2020 2:00 am
Forum: Virtualization
Topic: MikroTik CHR ARP entry issue
Replies: 2
Views: 685

Re: MikroTik CHR ARP entry issue

. if this is only happens to your aruba-ap's ... not to the rest of your network-equipment (like other cisco, huawei ... juniper, alcatel switches ... ) . it smells to me like something is wrong with your vlan-configuration. . whatever ... your aruba-ap's (instant- or controller-ruled) might have a ...
by floaty
Sat Aug 01, 2020 1:23 am
Forum: RouterBOARD hardware
Topic: Issues and questions about forum
Replies: 4
Views: 951

Re: Issues and questions about forum

.
first post ? ... really ?!
.
I like your style man ! .... somewhat consequently from the start ... keep on rockin!
by floaty
Sat Aug 01, 2020 1:04 am
Forum: Beginner Basics
Topic: portforward not working [SOLVED]
Replies: 4
Views: 1052

Re: portforward not working [SOLVED]

.
not a problem ... had a beer aside ... thats why I'm doing the easy cases ...
... enlarge forum-karma ... drinking beer ... like bodhisattva recommended
by floaty
Sat Aug 01, 2020 12:55 am
Forum: Beginner Basics
Topic: DHCP script not being run
Replies: 6
Views: 1237

Re: DHCP script not being run

.
anyway ... that's a neat thing ... so I'm fishing revenue here too
by floaty
Sat Aug 01, 2020 12:51 am
Forum: Beginner Basics
Topic: DHCP script not being run
Replies: 6
Views: 1237

Re: DHCP script not being run

.
so far with typo's
.
beeing sedulously with screenshots ... is really for the Kimme : |
by floaty
Sat Aug 01, 2020 12:49 am
Forum: Beginner Basics
Topic: DHCP script not being run
Replies: 6
Views: 1237

Re: DHCP script not being run

. the script should start every time, a lease from the related dhcp-service is issued ... so your logs doesn't show any script-activity ... something's wrong (tautologically : |) . even when the script is outdated ... there should be a loggged failure 'bout it ... so check your references and for ty...
by floaty
Sat Aug 01, 2020 12:21 am
Forum: General
Topic: PPPoE Online Games
Replies: 4
Views: 1043

Re: PPPoE Online Games

. and you're not the first when you search the forum, for the keywords in the article below (yes, it's one from our admired market-leader : ) . https://www.cisco.com/c/en/us/support/docs/ip/transmission-control-protocol-tcp/200932-Ethernet-MTU-and-TCP-MSS-Adjustment-Conc.html . homebrewed here: . ht...
by floaty
Sat Aug 01, 2020 12:12 am
Forum: General
Topic: PPPoE Online Games
Replies: 4
Views: 1043

Re: PPPoE Online Games

I mean, yes ... MTU-related ...
by floaty
Sat Aug 01, 2020 12:11 am
Forum: General
Topic: PPPoE Online Games
Replies: 4
Views: 1043

Re: PPPoE Online Games

yes
by floaty
Sat Aug 01, 2020 12:05 am
Forum: Beginner Basics
Topic: portforward not working [SOLVED]
Replies: 4
Views: 1052

Re: portforward not working [SOLVED]

the packets are being shown, ufw is disabled so its not a problem there . shown ... ? where ? . do you wanna say, you were able to see the already DST-NAT'ed packets at the target-system [10.2.1.2] ?? ... if not check first ! . there is a rule to another port on the same system ... do you checked i...
by floaty
Fri Jul 31, 2020 11:48 pm
Forum: Beginner Basics
Topic: DHCP script not being run
Replies: 6
Views: 1237

Re: DHCP script not being run

. first of all ... you could log your point of interest to a destination of your convenience ... guess most convenient, because fastet, is to your console of choice: . system/logging/add topics=script action=echo . trigger a dhcp-event and have a look, if some birdy is flying up in the console ... I...
by floaty
Fri Jul 31, 2020 11:24 pm
Forum: The Dude
Topic: Dude 6.47.1
Replies: 5
Views: 1254

Re: Dude 6.47.1

. Had some spooky moments with the dude myself ... you made quite a step from 6.45.2 to 6.47.1 ... Migrating a database between software-versions is probably not the most beloved homework for a developer. Not shure whether the amount of the data is worth the effort and if you have a db-backup ? I wo...
by floaty
Fri Jul 31, 2020 3:31 am
Forum: Wireless Networking
Topic: USA QRT-5 regulatory selection problem
Replies: 6
Views: 1310

Re: USA QRT-5 regulatory selection problem

thumbs up !
by floaty
Fri Jul 31, 2020 3:27 am
Forum: RouterOS v7 BETA
Topic: Feature Request: GREtap
Replies: 2
Views: 885

Re: Feature Request: GREtap

Please include gretap tunnel in version 7.1. eoip is not vendor neutral. . reviewed the old links in the topic ... maybe it's just the two of us ? : ) , I've tested gretap tunneling with cisco-click-OS-AP's and Alcatel-Stellar-AP's (generic support for the last) I outperformed the alcatel-gtts solu...
by floaty
Fri Jul 31, 2020 2:48 am
Forum: RouterOS v7 BETA
Topic: Feature Request: GREtap
Replies: 2
Views: 885

Re: Feature Request: GREtap

https://forum.mikrotik.com/viewtopic.php?f=1&t=160484 . since I gave already +1 I am at: 2 . I see this more relevant than vxlan ... classical "virtualizers" loosing land ... (Gordon Gecko said: Greed is good ... but some water [and more money] underbridged) so I guess some "unencumbered" protocols...
by floaty
Fri Jul 31, 2020 2:17 am
Forum: SwOS
Topic: Bandwidth Graph
Replies: 1
Views: 701

Re: Bandwidth Graph

. there are rumors, that swos supports snmp ... and than an ocean is cracking open ! https://wiki.mikrotik.com/wiki/File:Swos-statistics2.png . SwOS only supports a partial MIKROTIK-MIB (for health, PoE-out and SFP diagnostics). To monitor interface status and some other counters, you should look fo...
by floaty
Fri Jul 31, 2020 1:52 am
Forum: Wireless Networking
Topic: USA QRT-5 regulatory selection problem
Replies: 6
Views: 1310

Re: USA QRT-5 regulatory selection problem

Thanks, tried the real 24dBi antenna setting, still no love. And as far as PTP set-asides, it appears the FCC has dropped those from the regulations, as far as I can find. . . so maybe an "older" image-version brings your wireless-link to live : | . but you can consider yourself: youre on the 'axe ...
by floaty
Fri Jul 31, 2020 1:47 am
Forum: Wireless Networking
Topic: USA QRT-5 regulatory selection problem
Replies: 6
Views: 1310

Re: USA QRT-5 regulatory selection problem

just had a look into my account ... there's the possibilty to request a country-key-lock for a device . so maybe you can do that (cause the PtP-has default- and permanent license ?!) for your legit serial ?! . maybe you should push again support-side ... your Tik'l comes with a support-period for th...
by floaty
Fri Jul 31, 2020 1:13 am
Forum: Wireless Networking
Topic: USA QRT-5 regulatory selection problem
Replies: 6
Views: 1310

Re: USA QRT-5 regulatory selection problem

. not shure if we're talking the same issue ... but choosing the reg-domain can be sometime kinky for a MTik-Device. Sometimes (or always?) there is a predefined min/max antenna gain to be set, before you can choose the related country-reg-domain and installation-environment*. If there's the wrong v...
by floaty
Sun Jul 26, 2020 3:32 pm
Forum: Announcements
Topic: v6.47.1 [stable] is released!
Replies: 147
Views: 58516

Re: v6.47.1 [stable] is released!

.
What's new in 6.48beta12 (2020-Jul-06 13:33):
.
*) ike1 - allow using "my-id" parameter with XAuth;
.
SOLVED
by floaty
Sun Jul 26, 2020 2:37 am
Forum: RouterOS v7 BETA
Topic: MTik VPNC-style IPSec-Client with v7.1beta1
Replies: 2
Views: 917

Re: MTik VPNC-style IPSec-Client with v7.1beta1

.
just some illustrations added ....
... coped a while with the ROS-ipsec-template-thing ... doing this config ... I'm happy to understand now what it can be usefull for : )
.
installed-SAs.PNG
.
used-policies.png
by floaty
Sun Jul 26, 2020 12:27 am
Forum: RouterOS v7 BETA
Topic: MTik VPNC-style IPSec-Client with v7.1beta1
Replies: 2
Views: 917

MTik VPNC-style IPSec-Client with v7.1beta1

. recently got the task to provide a VPNC-link to a group of users ... my MTik-arsenal came to mind followed some older posts in the forum and got it running with v7.1beta1 (unforti not with a production-release because of limits in xauth-implementation) *1) . I had no access to the remote-vpn-devic...
by floaty
Sat Jul 25, 2020 10:43 pm
Forum: Announcements
Topic: v6.47.1 [stable] is released!
Replies: 147
Views: 58516

Re: v6.47.1 [stable] is released!

. ran into a problem configuring ROS 6.47.1 as xauth-client: I cannot choose 'key-id' as local-id-source -> error . xauth_6.47.1.PNG . same on CLI [admin@MikroTik] /ip ipsec identity> set 0 my-id=key-id:abcxyz failure: XAuth must use auto my-id [admin@MikroTik] /ip ipsec identity> . according to thi...
by floaty
Tue Jul 21, 2020 4:08 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta1 [development] is released!
Replies: 103
Views: 41234

Re: v7.1beta1 [development] is released!

.
a ball plus : ) vrf-menu has joined ip-context in winbox
.
vrf-menu.png
by floaty
Tue Jul 21, 2020 3:32 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta1 [development] is released!
Replies: 103
Views: 41234

Re: v7.1beta1 [development] is released!

.
"ip route" context is still a CLI-only domain
.
bumms.PNG
by floaty
Sat Jul 11, 2020 12:37 am
Forum: Announcements
Topic: v6.47.1 [stable] is released!
Replies: 147
Views: 58516

Re: v6.47.1 [stable] is released!

must be very annoying to our fellow Mikrotikls, that every new release anouncement is turning into a whining-zone : )
.
so many fashionable new features ... no party : \
... but that's your life jacky brown : |
.
so hopefully my vendor id dhcpd inconvience is handled first : )
by floaty
Sat Jul 11, 2020 12:11 am
Forum: Beginner Basics
Topic: hAP ac^2 | Clients on Switch-Port do not get IP via DHCP
Replies: 22
Views: 4170

Re: hAP ac^2 | Clients on Switch-Port do not get IP via DHCP

...
and I cannot be tired of repeating: "do not bridge so effin much!"
bridging is advanced pharmacy ... you do to much ... it turns to poison !
.
the most wellknown traffic-catastrophes happended in conjunction to bridges and tunnels :shock:
NO JOKE !
by floaty
Sat Jul 11, 2020 12:02 am
Forum: Beginner Basics
Topic: hAP ac^2 | Clients on Switch-Port do not get IP via DHCP
Replies: 22
Views: 4170

Re: hAP ac^2 | Clients on Switch-Port do not get IP via DHCP

revisited ... . in your very well populated bridge: I configured ether2 to 5 to only works with VLAN90 --> to talks with Clients (un-tagged) ... hopefulle correct. you've configured a PVID=90 for eth2-5 but (it seems to me() these ports are intended to be just ethernet -access-port for your clients ...
by floaty
Fri Jul 10, 2020 11:44 pm
Forum: Beginner Basics
Topic: hAP ac^2 | Clients on Switch-Port do not get IP via DHCP
Replies: 22
Views: 4170

Re: hAP ac^2 | Clients on Switch-Port do not get IP via DHCP

booh ... thats rich ... if you have winbox, can you post a screenshot from your "interfaces list"
.
if made a sketch before you started to configure all these ... ? ... can you share ... I'm a picture man.
I can't figure what's the purpose of all this ! : |
by floaty
Fri Jul 10, 2020 11:14 pm
Forum: General
Topic: Setting up LHG behind Hex S with access to it (and a bit more)
Replies: 1
Views: 574

Re: Setting up LHG behind Hex S with access to it (and a bit more)

my opinion ? ... there are two ways to proceed with the issue: 1.st approach: you read the related documentation and then read forward in this forum how to get support - then you formulate a new request in here with the newly learned skills 2.nd approach: youtube yourself an old muppets-show episode...
by floaty
Fri Jul 10, 2020 10:15 pm
Forum: Wireless Networking
Topic: LHG60 bridge - broadcast problem
Replies: 2
Views: 805

Re: LHG60 bridge - broadcast problem

From your decription I figure there are two devices involved ... but your posting is ... blunt ... from which one? . and whats the problem with a little sketch, to let the "free-of-charge-supporters" know, what you are created over there ? ... is this too much ? ... it .. isn't too much ! . end of k...
by floaty
Fri Jul 10, 2020 9:44 pm
Forum: General
Topic: Is DDNS down
Replies: 5
Views: 1225

Re: Is DDNS down

nope ... not down ... keep on investigating. . C:\WINDOWS\system32>ping a815XXX648c.sn.mynetname.net Ping wird ausgeführt für a8150965648c.sn.mynetname.net [78.XX.YY.145] mit 32 Bytes Daten: Antwort von 78.XX.YY.145: Bytes=32 Zeit=28ms TTL=243 Antwort von 78.XX.YY.145: Bytes=32 Zeit=29ms TTL=243 Pin...
by floaty
Fri Jul 10, 2020 9:38 pm
Forum: Beginner Basics
Topic: hAP ac^2 | Clients on Switch-Port do not get IP via DHCP
Replies: 22
Views: 4170

Re: hAP ac^2 | Clients on Switch-Port do not get IP via DHCP

... your snipped configuration does not contain a hint to which interface you're configured dhcp-server is connected to ?! . if you want a common network over multiple (hardware-)interfaces there should be a bridge, where all your intented (hardeware-)interfaces are "a port" [personally not so happy...
by floaty
Fri Jul 10, 2020 8:01 pm
Forum: Announcements
Topic: v6.47.1 [stable] is released!
Replies: 147
Views: 58516

Re: v6.47.1 [stable] is released!

. still no option-set linking to a vendor-class-id possible in dhcpd ... ? it's possible in v7beta8 !? ... is this by intent ?... or a bug ? . . [admin@v6.47.1] /ip dhcp-server vendor-class-id> add Creates new item with specified property values. address-pool -- pool used for this vendor-class-id co...
by floaty
Fri Jul 10, 2020 6:54 pm
Forum: General
Topic: dhcp vendor id
Replies: 0
Views: 373

dhcp vendor id

feature was introduced a while ago in v6.47 and it is also avail in v7beta8 in v7beta8 I am able to link an option-set to a vendor-id (what is obviously the main-purpose), but I cannot do that in v6.47 ( ... our beloved production-release) ?? ... dhcp is application-layer, nothing kernel relevant (i...
by floaty
Fri Jul 03, 2020 11:57 pm
Forum: Beginner Basics
Topic: IPv6 configuration on PPPoE interface
Replies: 31
Views: 6198

Re: IPv6 configuration on PPPoE interface

... who's wondering ? we have IPv6 running for over 10 years in the provider-production-environment ... but who's using ? in EMEA or AMER (without BETA-Feeling) ? Noises heard: it's running big time in the "chinese-internet" (and they wanna be part of the standardization-process ... [they invented t...
by floaty
Mon Jun 29, 2020 10:23 am
Forum: RouterBOARD hardware
Topic: mAP 2nD - What can onboard USB port be used for?
Replies: 7
Views: 1914

Re: mAP 2nD - What can onboard USB port be used for?

thanks ... nice ... will see if I can scramble up some money to become a mAP-owner
by floaty
Sat Jun 27, 2020 2:27 am
Forum: General
Topic: how to disable http(Webfig i mean)
Replies: 2
Views: 674

Re: how to disable http(Webfig i mean)

you're right ... the simplest possibility is far too - ... bloody - simple here. https://mum.mikrotik.com/presentations/VN17/presentation_4493_1494480323.pdf The Technique; Ninja Said This is The Jutsu #joke • Static DNS # ... näh • Web Proxy # ... nope • Route Policy # ... eventually, why not ... i...
by floaty
Sat Jun 27, 2020 12:29 am
Forum: RouterBOARD hardware
Topic: mAP 2nD - What can onboard USB port be used for?
Replies: 7
Views: 1914

Re: mAP 2nD - What can onboard USB port be used for?

.
? someone did this before ? ... looks viable ... but I'm 55-60 bucks away from knowing for shure ...
.
like-that.png
by floaty
Sat Jun 27, 2020 12:19 am
Forum: RouterBOARD hardware
Topic: mAP 2nD - What can onboard USB port be used for?
Replies: 7
Views: 1914

Re: mAP 2nD - What can onboard USB port be used for?

is there some kind of Y-Cable avail to power the mAP via power-bank and use the USB-Host for a serial-USB-adapter at the same time ? . +----+ +----------+ +-----<<----+ | usb/serialadapter | | | +----+ (( | +----------| +----------------------+ ((( | mAP | | | | (( | +------+ +----->>-->| Powerbank ...
by floaty
Tue Jun 23, 2020 8:55 pm
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

. and ...I found the group-feature ... inbetween ... hard to see : ) . /user-manager/user/group . [admin@chr-7-1] /user-manager/user/group> print Flags: * - default 0 * name="default" default-name="default" outer-auths=pap,chap,mschap1,mschap2,eap-tls,eap-ttls,eap-peap,eap-mschap2 inner-auths=ttls-p...
by floaty
Tue Jun 23, 2020 8:27 pm
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

.
you can also add:
Radius:IETF Framed-Pool
to select the IP-Pool
.
and
Radius:IETF Filter-Id
to define a firewall-chain in MTik-ROS
by floaty
Tue Jun 23, 2020 8:11 pm
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

. you should be able to do this by adding the attribute "Mikrotik-Group" to a user (haven't figured if and when if, ... how to add a attribute-set to a profile or user-profile ... like a group-feature ? ... I would like that too) . Mikrotik-Group - Router local user group name (defines in /user grou...
by floaty
Sat Jun 20, 2020 12:35 pm
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 30198

Re: DNS over HTTPS

. not v4 ... right . foo@pike:~# dig -x 2001:4860:4860::64 ; <<>> DiG 9.10.3-P4-Debian <<>> -x 2001:4860:4860::64 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 35978 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION...
by floaty
Sat Jun 20, 2020 12:45 am
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 30198

Re: DNS over HTTPS

. I think it's not possible to use google DoH without DNS name in url. Or do you have a working one with ip address? . same experience here: using the avail v4 adresses gives warnings (maybe a google by-the-side-sausage ??) ... seems there's loadbalancing inbetween, which is fetching "dns.google" [o...
by floaty
Fri Jun 12, 2020 4:12 pm
Forum: RouterOS v7 BETA
Topic: v7.0beta8 [development] is released!
Replies: 180
Views: 65114

Re: v7.0beta8 [development] is released!

. When in WinBox 3.24 I go to IP -> Routes, click "Add" and type "8.8.8.8@" in Dst. Address, WinBox hungs and, a few seconds later, disappears. Is it only me with Wine on MacOS, or the problem is repeatable everywhere? . it's general . Winbox 3.24 crashes after setting up VRF and opening '/IP/routes...
by floaty
Fri Jun 12, 2020 1:22 am
Forum: Wireless Networking
Topic: Cat6 LGH LTE Super bad performance
Replies: 36
Views: 8852

Re: Cat6 LGH LTE Super bad performance

unless this isn't a hardware-related issue ... I see the same odds here on the other side of the pond. . [R11e-LTE-US 13-15 Mb] ?? . This is (my oppinion !) a very sorry performance for the capabilities the standard should be able to serve. so.. (for me very) obviously the providers classify the har...
by floaty
Sat Jun 06, 2020 12:58 am
Forum: RouterOS v7 BETA
Topic: v7.0beta8 [development] is released!
Replies: 180
Views: 65114

Re: v7.0beta8 [development] is released!

sad ... evolution ... in fact ... there's in all times a child behind
I'm a sad mammal to say so ... :shock:
.
I'm great splunk fan !! ... but I'm doing graylog ... until I'm not !
by floaty
Fri Jun 05, 2020 9:25 pm
Forum: RouterOS v7 BETA
Topic: v7.0beta8 [development] is released!
Replies: 180
Views: 65114

Re: v7.0beta8 [development] is released!

yepp: buttercream !
... my doc told me !
by floaty
Fri Jun 05, 2020 5:22 pm
Forum: RouterOS v7 BETA
Topic: v7.0beta8 [development] is released!
Replies: 180
Views: 65114

Re: v7.0beta8 [development] is released!

. user-manager / radiusd: chap-authentication works eap works ! ( : [] ) no logging messages echoed to terminal-session for: . [admin@chr-7-1] > /system/logging/print Flags: X - DISABLED, I - INVALID; * - DEFAULT Columns: TOPICS, ACTION # TOPICS ACTION ### snip ### 4 radius echo
by floaty
Fri Jun 05, 2020 2:47 am
Forum: RouterOS v7 BETA
Topic: v7.0beta8 [development] is released!
Replies: 180
Views: 65114

Re: v7.0beta8 [development] is released!

. Winbox 3.24 crashes after setting up VRF and opening '/IP/routes' dialog ( ...and crashes immediately after trying to reopen) . [admin@chr-7-1] > ip route print Flags: D - DYNAMIC; A - ACTIVE; C - CONNECT, S - STATIC, m - MODEM Columns: DST-ADDRESS, GATEWAY, DISTANCE # DST-ADDRESS GATEWAY D 0 AS 0...
by floaty
Thu Jun 04, 2020 8:58 pm
Forum: RouterOS v7 BETA
Topic: v7.0beta8 [development] is released!
Replies: 180
Views: 65114

Re: v7.0beta8 [development] is released!

. and VRF ! that's rich ! . [admin@chr] > ip vrf add list=vrf-if-list-red name=vrf-red 03:52:05 echo: radvd,debug skip Router Advertisement sending on bridge2: no prefixes to send [admin@chr] > ip vrf add list=vrf-if-list-red name=vrf-red [admin@chr] > 03:52:11 echo: system,info vrf-red added by adm...
by floaty
Thu May 21, 2020 6:33 am
Forum: Scripting
Topic: Neighbor connection with Terminal
Replies: 4
Views: 863

Re: Neighbor connection with Terminal

make yourself acquainted with ssh-key authenticaton !
.
BUT of course you can try ! ... the youngest day ... ? ... is public !
by floaty
Thu May 21, 2020 6:27 am
Forum: Scripting
Topic: Neighbor connection with Terminal
Replies: 4
Views: 863

Re: Neighbor connection with Terminal

the script just fails ...
.
it's a nice "try just at home example" :shock:
by floaty
Thu May 21, 2020 5:49 am
Forum: General
Topic: QinQ trunk port
Replies: 6
Views: 1099

Re: QinQ trunk port

that may or may not be so ...
better you check that out by testing your configuration(s)
.
you should be suspicious, if two versions work : )
.
had QinQ never in production ... but earned all the the time mx'ed emotions, hearing production stories ....
by floaty
Wed May 20, 2020 11:12 pm
Forum: RouterOS v7 BETA
Topic: Feature Request: GREtap
Replies: 9
Views: 2514

Re: Feature Request: GREtap

.
A bit of a pity that MikroTik defined their own protocol type
.
... sometimes it's just about having my own "Jodeldiplom" ?!
.
... but opening a platform for a compatibilty is - of course - always a sometimes hard-to-know business-decision ...
I see more options, than contraints for this case
by floaty
Wed May 20, 2020 10:37 pm
Forum: RouterOS v7 BETA
Topic: Feature Request: GREtap
Replies: 9
Views: 2514

Re: Feature Request: GREtap

. Open vSwitch is using GRETAP as a tunneling option ! ... maybe also an option to terminate MTik-wireless-devices over a distributed-foreign network-infrastructure ?! ... with the new hiperf-switches and 10/25G-routers ... ?! that would be "a feature" also for datacenter-like installations !! ... o...
by floaty
Wed May 20, 2020 10:17 pm
Forum: RouterOS v7 BETA
Topic: Feature Request: GREtap
Replies: 9
Views: 2514

Re: Feature Request: GREtap

.
just to illustrate the issue ( ... opened the archives)
.
diff-is-diff.png
by floaty
Wed May 20, 2020 9:51 pm
Forum: RouterOS v7 BETA
Topic: Feature Request: GREtap
Replies: 9
Views: 2514

Re: Feature Request: GREtap

nope ... tried that ! MTik-EoIP and GRETAP make use of different protocol-types ... so ... the feature-request ... is simply a request for a compatibility-flag . https://tools.ietf.org/html/rfc2784 . 7.2. Protocol Types GRE uses an ETHER Type for the Protocol Type. New ETHER TYPES are assigned by Xe...
by floaty
Wed May 20, 2020 9:32 pm
Forum: Scripting
Topic: Neighbor connection with Terminal
Replies: 4
Views: 863

Re: Neighbor connection with Terminal

stunts like that will not work with user/password-authentication (there is no unattended remote-shell usage which needs interaction for authentication - security-reasons) you need to setup key-authentication between the devices then you can use ... : . [admin@tikki] > system ssh-exec <address> -- <c...
by floaty
Wed May 20, 2020 9:13 pm
Forum: General
Topic: QinQ trunk port
Replies: 6
Views: 1099

Re: QinQ trunk port

in case your netflix is off duty ... surrogate:
https://www.youtube.com/watch?v=C46ISu_T2SE
starting 33:00
by floaty
Wed May 20, 2020 9:09 pm
Forum: General
Topic: QinQ trunk port
Replies: 6
Views: 1099

Re: QinQ trunk port

https://wiki.mikrotik.com/wiki/Manual:I ... LAN#Q-in-Q
.
not 100% posititve about ... but maybe the remote-device uses 802.1ad compliant tagging
then you need to set
use-service-tag = yes
by floaty
Wed May 20, 2020 10:29 am
Forum: RouterOS v7 BETA
Topic: Feature Request: GREtap
Replies: 9
Views: 2514

Re: Feature Request: GREtap

by floaty
Thu May 14, 2020 4:16 pm
Forum: General
Topic: SXT5ac managment VLAN
Replies: 3
Views: 860

Re: SXT5ac managment VLAN

just add a vlan-interface and choose your ethernet-interface as source-interface in case you need this vlan on multiple ports, you have to interconnect the vlan-interface(s) with a bridge ... (there are more options if a hardware-switch in your plattform is involved ... but above option should work ...
by floaty
Wed May 13, 2020 1:34 am
Forum: General
Topic: RB1100AHx4 queries for www.mikrotik.com
Replies: 6
Views: 1498

Re: RB1100AHx4 queries for www.mikrotik.com

As I said: "The DNS on the router is not enabled." . there is no "The DNS" on the router ... there is a dns resolver in the ip stack and a service which you can enable or not. . if there is no dns-server-entry in the /ip/dns-settings ... you can still catch a dns-server address if a dhcp-client is ...
by floaty
Tue May 12, 2020 11:54 pm
Forum: The User Manager
Topic: userman not showing actual user consomption
Replies: 1
Views: 758

Re: userman not showing actual user consomption

In the the communication between a network-access-server (short: nas) aka "your mikrotik hotspot __and__ a radius-server aka "your user-manager" (maybe both functions on the same device), are two different communication-channels defined. One for authentication and one for accounting. Obviously the a...
by floaty
Tue May 12, 2020 11:17 pm
Forum: General
Topic: Multiple Networks accessible from each other
Replies: 2
Views: 783

Re: Multiple Networks accessible from each other

guess you're looking for somewhat of a reprint of the manuals ? ... yeah man I would ! ... but I bruised ma pötchen . but you could search the index for "vlan" "switching" "routing" ... then "firewall" ... and my experience ... once you've started ... you do not stop for a year ! . best you start wi...
by floaty
Tue May 12, 2020 11:02 pm
Forum: General
Topic: RB1100AHx4 queries for www.mikrotik.com
Replies: 6
Views: 1498

Re: RB1100AHx4 queries for www.mikrotik.com

... and you should have blacked out every other url in the screenshot ... so it's an easy guess :)
by floaty
Tue May 12, 2020 10:58 pm
Forum: General
Topic: RB1100AHx4 queries for www.mikrotik.com
Replies: 6
Views: 1498

Re: RB1100AHx4 queries for www.mikrotik.com

- capture some of these packets and have a look inside ... dns is propably good for some information bouta source of these requests
- disable the web-interface (if it's enabled) of the router ... there's a link ... maybe a client is triggering that link (may be you : )
by floaty
Tue May 12, 2020 10:50 pm
Forum: RouterOS v7 BETA
Topic: UI/UX On WinBox
Replies: 23
Views: 4319

Re: UI/UX On WinBox

think we're done here
by floaty
Sat May 09, 2020 12:32 am
Forum: General
Topic: Mikrotik administrator authentication against radius
Replies: 5
Views: 2264

Re: Mikrotik administrator authentication against radius

.
the squirrel may be not really the fastest one on the ash ... but nimble and diligent !
.
cp2.PNG
by floaty
Thu May 07, 2020 4:36 pm
Forum: General
Topic: Mikrotik administrator authentication against radius
Replies: 5
Views: 2264

Re: Mikrotik administrator authentication against radius

.
https://www.open.com.au/radiator/ref/Ra ... ation.html
.
... guess this is the point where I ask for a "generate RADSEC-Cert-pair" button ... ... jeez ... why has it always to be pandemonium ?
by floaty
Thu May 07, 2020 4:25 pm
Forum: General
Topic: Mikrotik administrator authentication against radius
Replies: 5
Views: 2264

Re: Mikrotik administrator authentication against radius

. obviously something odd with the parser in the log-subsystem ... communication is running on port 2083 . [admin@tikki] > 15:05:47 echo: radius,debug new request 0d:5f code=Access-Request service=login 15:05:47 echo: radius,debug sending 0d:5f to 192.168.7.74:8968 15:05:47 echo: radius,debug RADSEC...
by floaty
Thu May 07, 2020 3:12 am
Forum: Beginner Basics
Topic: Intervlan forwarding delay? Slow SSH/https across vlans [SOLVED]
Replies: 3
Views: 1367

Re: Intervlan forwarding delay? Slow SSH/https across vlans [SOLVED]

. First thing that comes to mind is the typical reverse DNS query most linux distros do when accessed via SSH . agreed by the 100% . check /etc/ssh/sshd_config of your containers ...vm's whatsoever ... . #PermitUserEnvironment no #Compression delayed #ClientAliveInterval 0 #ClientAliveCountMax 3 Per...
by floaty
Thu May 07, 2020 2:54 am
Forum: General
Topic: Couldn't change Swithc Port <ether 3> - vlan mode not supported
Replies: 6
Views: 1178

Re: Couldn't change Swithc Port <ether 3> - vlan mode not supported

switching hardware is a "Thing" in ROS ... did you try to change the mode to fallback ? ( ... fallback normally doesn't hurt)
... maybe it's just an unsopported handle in the interface ?! ... best guess.
.
btw. is this a good old XP-box ?
.
xp.PNG
by floaty
Thu May 07, 2020 2:36 am
Forum: General
Topic: High CPU usage
Replies: 6
Views: 1347

Re: High CPU usage

. and ... bringing in the question as accurate as obviously possible ... could have spared IO-ops too : | . I know what's loading the CPU. My question is, why so much? One EPYC Rome core can do 1.7 GBytes/s AES encryption. Two cores can 2*1.7*8=27 Gbits/s My traffic is very small, only 0.5 Gbit/s CP...
by floaty
Thu May 07, 2020 2:31 am
Forum: General
Topic: High CPU usage
Replies: 6
Views: 1347

Re: High CPU usage

. maybe a problem with exposing all your heroic cpu-capabilities to your CHR-vm ?! . ... and why do you give a rotten f**t about your VM-cpu ? ... what's with your host cpu ? . ... and in the end ... being busy its what you paid the cpu for ! . give me your CPU-problems and you can have my IO-ops di...
by floaty
Thu May 07, 2020 2:15 am
Forum: The Dude
Topic: Dude Database Import Problem
Replies: 3
Views: 1297

Re: Dude Database Import Problem

.
call for input !
by floaty
Thu May 07, 2020 2:15 am
Forum: The Dude
Topic: Dude Database Import Problem
Replies: 3
Views: 1297

Re: Dude Database Import Problem

.
do you obeyed orders ? : )
.
https://wiki.mikrotik.com/wiki/Manual:T ... nToNewDude
.
honestly I haven't done it myself ... would be interesting if it is possible to switch a database from x86 to arm ... or reverse ?!
by floaty
Thu May 07, 2020 2:01 am
Forum: Wireless Networking
Topic: Peculiar setup [SOLVED]
Replies: 3
Views: 1644

Re: Peculiar setup [SOLVED]

. route whenever you can route ... bridge only when needed ( I would say: when unavoidable ). . you wanna have control over your traffic flow ? ... separate your interfaces, build up small broadcast-domains ... then you can measure the traffic with fw-rules. . carefull with bridging wireless-interfa...
by floaty
Thu May 07, 2020 1:45 am
Forum: Wireless Networking
Topic: Peculiar setup [SOLVED]
Replies: 3
Views: 1644

Re: Peculiar setup [SOLVED]

. seems everyone is skipping the "keep-it-simple-course" in network-potty-class ... . why ? . fun of administrating one of these devices is knowing what you're doing ... . I also created 3 virtual wireless interfaces (one for each physical wireless one ) and bridged them in bridge 2 . what for ? flo...
by floaty
Thu May 07, 2020 1:11 am
Forum: General
Topic: Mikrotik administrator authentication against radius
Replies: 5
Views: 2264

Re: Mikrotik administrator authentication against radius

.
or maybe "radius" is already sensitive :shock:
.
... it smells sensitive : )
by floaty
Thu May 07, 2020 1:08 am
Forum: General
Topic: Mikrotik administrator authentication against radius
Replies: 5
Views: 2264

Re: Mikrotik administrator authentication against radius

. what*s with good old trust ? . or maybe our MTikl-friends add a radius-tickbox ... end of story ... your complain makes sense ... seems not to be a very big story . tikbox.PNG . other question ... were you able to authenticate against a RADSEC-enabled server ? . have'nt found a success-message on ...
by floaty
Wed May 06, 2020 11:53 pm
Forum: General
Topic: High CPU usage
Replies: 6
Views: 1347

Re: High CPU usage

.
or maybe /tool/profile ... can grow to a friend of yours ?
.
perf-profile.PNG
by floaty
Wed May 06, 2020 11:42 pm
Forum: General
Topic: High CPU usage
Replies: 6
Views: 1347

Re: High CPU usage

by floaty
Wed May 06, 2020 11:35 pm
Forum: General
Topic: High CPU usage
Replies: 6
Views: 1347

Re: High CPU usage

.
my best guess ... calculating encryption ?! ... ... even packet forwarding isn't a "Zuckerschlecken"
switch off IPSec for the tunnel ... check again !?
by floaty
Wed May 06, 2020 11:22 pm
Forum: General
Topic: Wrong traffic reading ccr1072
Replies: 2
Views: 890

Re: Wrong traffic reading ccr1072

when you enable the webinterface of your routers ... you can see the perf graphs for the interfaces there also ...
.
... so when you do, do you have the same FX ?
.
web-perf.PNG
by floaty
Wed May 06, 2020 10:46 pm
Forum: Wireless Networking
Topic: Dude can't SNMP monitor its own host!!
Replies: 1
Views: 729

Re: Dude can't SNMP monitor its own host!!

.
In ROS the SNMP strings are setup the same as all other devices
.
We really want to believe you :!:
... but show us.
.
/snmp export
by floaty
Wed May 06, 2020 10:33 pm
Forum: General
Topic: Split traffic then merge [SOLVED]
Replies: 84
Views: 9341

Re: Split traffic then merge [SOLVED]

I'm not sure that I understand correctly
.
just a side-degression in iperf ... please proceed
by floaty
Wed May 06, 2020 9:50 pm
Forum: General
Topic: Split traffic then merge [SOLVED]
Replies: 84
Views: 9341

Re: Split traffic then merge [SOLVED]

. sorry to interfere only for beeing so nitpicky ... I have to give the tcp-default ... but ... mutiple "routes" ? ... nöh . 39494 39500 39498 39496 . root@badger:~# iperf -c 192.168.67.140 -P 4 ------------------------------------------------------------ Client connecting to 192.168.67.140, TCP por...
by floaty
Wed May 06, 2020 5:17 am
Forum: General
Topic: LoRa Packet forwarding stopps
Replies: 2
Views: 969

Re: LoRa Packet forwarding stopps

after a while (some hours) data is only send to the first server configured, the second and third server does not get data anymore. . since your setup seems to be working for a while ..., but than not ... a bug would come to mind so ... maybe one of your devices are still under support ?! ... try t...
by floaty
Wed May 06, 2020 4:48 am
Forum: General
Topic: Mikrotik log in notifications with exception
Replies: 1
Views: 616

Re: Mikrotik log in notifications with exception

I'm struggeling with my english a life long ... and the english men ... struggle with me ... bouta'länguoch'uff'curse !! . sooo ...? . question: do you use 'dude' for monitoring ? or some other inside-ROS-tool with a script ... . The problem is that my monitoring 10.10.4.180, polls the device, and l...
by floaty
Wed May 06, 2020 4:25 am
Forum: General
Topic: queue pcq , dhcp lease, is posible?
Replies: 2
Views: 784

Re: queue pcq , dhcp lease, is posible?

ooops ... if this is about dhcp-options ?!
... sorry for coming sassy in the first place ...
there are interesting features coming up in the testing- and beta-versions which might raise your interest ...
check out the news-channels ...
by floaty
Wed May 06, 2020 4:13 am
Forum: General
Topic: queue pcq , dhcp lease, is posible?
Replies: 2
Views: 784

Re: queue pcq , dhcp lease, is posible?

1. we are all agree from leasing .. really !
.
since you now may feel a little bit better, you might be able to give us a 'communique' of your sufferings ?!
by floaty
Wed May 06, 2020 3:52 am
Forum: Beginner Basics
Topic: Internet Not Full-Speed [SOLVED]
Replies: 20
Views: 4643

Re: Internet Not Full-Speed [SOLVED]

Lukas 23,34
:shock:
by floaty
Wed May 06, 2020 3:32 am
Forum: Beginner Basics
Topic: Blocking all unused/unneeded protocols, keeping only bare minimum essential ones [SOLVED]
Replies: 24
Views: 4056

Re: Blocking all unused/unneeded protocols, keeping only bare minimum essential ones [SOLVED]

Yeah, can be done, but for the danger of locking myself out of the switch :-)
.
every good network administrator has done this ... like every good sailor has crossed the ... fan :lol:
by floaty
Wed May 06, 2020 3:24 am
Forum: Beginner Basics
Topic: Can't Save OVPN Server
Replies: 2
Views: 993

Re: Can't Save OVPN Server

sometimes ... if ... nothing new appears ... nothing happened ?! . you like to see a new ppp-interface ... why ? if you setup a new (ov)ppp-server ... only the capabiltiy for such an interface is born (goda** I'm biblic today) . good old atheists would check with an "/export" before and after ... if...
by floaty
Wed May 06, 2020 2:58 am
Forum: Beginner Basics
Topic: Blocking all unused/unneeded protocols, keeping only bare minimum essential ones [SOLVED]
Replies: 24
Views: 4056

Re: Blocking all unused/unneeded protocols, keeping only bare minimum essential ones [SOLVED]

you can ! ... all the way ... use the contrary approach ... drop everything, till "your" network works again like expected ...
.
or you do a trip to google ... protocols that should never left my local-LAN ... my local-machine ... ... my Mind ... etc.
by floaty
Wed May 06, 2020 2:52 am
Forum: Beginner Basics
Topic: Blocking all unused/unneeded protocols, keeping only bare minimum essential ones [SOLVED]
Replies: 24
Views: 4056

Re: Blocking all unused/unneeded protocols, keeping only bare minimum essential ones [SOLVED]

A firewall segregates two or more parts of a network, A network is called a functional interaction of items. . Make a packet-trace (only the the headers ... to be wise) on every part of your network(s) AND decide yourself what's needed and what's not ! . You wanna call yourself bible-proof ... so re...
by floaty
Wed May 06, 2020 2:16 am
Forum: RouterOS v7 BETA
Topic: Future request - Configuration propagation similar to CAPsMAN
Replies: 6
Views: 1720

Re: Future request - Configuration propagation similar to CAPsMAN

and sorry I couldn't resist ... let be god a G00dm4n
by floaty
Wed May 06, 2020 2:13 am
Forum: RouterOS v7 BETA
Topic: Future request - Configuration propagation similar to CAPsMAN
Replies: 6
Views: 1720

Re: Future request - Configuration propagation similar to CAPsMAN

not shure you've checked out the TR069 capabilities of ROS yet ? (yepp ... right ... me neither)
.
but since these capabilities are implemented, so you should start to crtitize these functionality ?!
.
you want a bridge ? ... checkout the ferry before !
by floaty
Wed May 06, 2020 1:59 am
Forum: Beginner Basics
Topic: Use hAP ac³ LTE6 kit for LTE redundancy
Replies: 1
Views: 695

Re: Use hAP ac³ LTE6 kit for LTE redundancy

earn a very 'yes' to the provider redundancy part ( and keep studying the relevant forum-posts ) ... and earn a 'maybe' to the WLAN part ... your brandnew hAP ac² should have of "a place" of 'undoubtabletized' LTE-receiving quality ( like blessed mother mary ) ... if this is also the place where you...
by floaty
Wed May 06, 2020 1:31 am
Forum: General
Topic: Split traffic then merge [SOLVED]
Replies: 84
Views: 9341

Re: Split traffic then merge [SOLVED]

can only measure 5MBps from the server->client. But only if I measure with a single thread. If I measure with parallel option of iperf3 (this way it creates multiple connections), the bandwidth can reach the uplink limits (25MBps) even through the abroad ISP. . little bit unclear how long you did t...
by floaty
Wed May 06, 2020 12:46 am
Forum: RouterBOARD hardware
Topic: WAP LTE KIT installation outsite in a hot country. Can be a problem?
Replies: 2
Views: 1075

Re: WAP LTE KIT installation outsite in a hot country. Can be a problem?

... and more dangerous ! in dry areas temperatures rise and fall with dust and dawn extremely. brings ... condensed water into the equation !! NO FUN ... had that myself when I found one of our antenna-cables with N-connector drowned ... first I thought it wasn't well enough insulated. But wise-guys...
by floaty
Wed May 06, 2020 12:28 am
Forum: RouterBOARD hardware
Topic: WAP LTE KIT installation outsite in a hot country. Can be a problem?
Replies: 2
Views: 1075

Re: WAP LTE KIT installation outsite in a hot country. Can be a problem?

in summer the temperature in shadows can reach 42ºC . guess you can have such extremes nearly worldwide now (exept really circumpolar) ... WAP LTE is specified (Tested ambient temperature -40°C to 60°C) ... since you have to expose the device with it's internal antennas ... :( . advice ? start with...
by floaty
Sat May 02, 2020 11:58 pm
Forum: Beginner Basics
Topic: Cant get Band 20 4G.....i KNOW ITS THERE
Replies: 5
Views: 1280

Re: Cant get Band 20 4G.....i KNOW ITS THERE

... and ... whenever possible ... recheck with another device, where you can also see the configuration and connection-state ... it's possible your provider does not want you, with your device.(-identifier) on that frequency ( at that time ... with that contract ... whatsoever ) ... it's a policied ...
by floaty
Sat May 02, 2020 11:47 pm
Forum: Beginner Basics
Topic: IPSec IPIP tunnel
Replies: 2
Views: 860

Re: IPSec IPIP tunnel

MTU 1418, while rest of the network and of course internet connection is 1500 . you build a tunnel inside a tunnel ... you build a bridge over a bridge ... this is what happens ! . A fat man creeping though a tunnel, should be aware of the problem, ... before forwarding. . maybe you should check: h...
by floaty
Sat May 02, 2020 11:16 pm
Forum: Beginner Basics
Topic: OPENVPN ppp and no access to LAN
Replies: 1
Views: 716

Re: OPENVPN ppp and no access to LAN

openvpn is very wealthy in it's feature-set ... please give us an "/export/withou... " from your terminal as an attachment to your next post, for further investigations.
.
nice gesture would be, to make a little sketch with relevant links and addresses ... to fetch the issue even faster ...
by floaty
Sat May 02, 2020 11:05 pm
Forum: Virtualization
Topic: Docker Mikrotik - In two minutes ( en dos minutos )
Replies: 3
Views: 2354

Re: Docker Mikrotik - In two minutes ( en dos minutos )

my first guess ?! ...
FF UU NN
:shock:
by floaty
Sat May 02, 2020 10:52 pm
Forum: General
Topic: Book for advanced routing
Replies: 10
Views: 2681

Re: Book for advanced routing

I guess he's offering free outlays for critical assessment ... isn't he ?!
.
who had the boldness :lol: ... ... this is not the place to worship mammon !
by floaty
Sat May 02, 2020 10:20 pm
Forum: General
Topic: SRC_ADDR for PPP VPN
Replies: 2
Views: 765

Re: SRC_ADDR for PPP VPN

! OR ! . if your "two-tunnel-machine" can be the ppp-client in the setup ... you can set that client-interface into a VRF to work-around the "one-IPeed-client" and hence the routing-problem ... ... but as always and before we're opening that barrel: better tell the auditorium about the use-case you ...
by floaty
Sat May 02, 2020 10:12 pm
Forum: General
Topic: SRC_ADDR for PPP VPN
Replies: 2
Views: 765

Re: SRC_ADDR for PPP VPN

can i make 2 PPP VPNs (L2TP) from 2 different WAN ? For ex. LTE + WAN1 , One tunnel connect from LTE , second one from WAN. I see no problem in here ... . Dst. Addr both tunnels are the same. ... this might trigger a routing problem, because your tunnel-client-ip is either reachable over LTE OR ove...
by floaty
Sat May 02, 2020 9:41 pm
Forum: General
Topic: Dot1X authentication with freeradius [SOLVED]
Replies: 2
Views: 1477

Re: Dot1X authentication with freeradius [SOLVED]

Is there an issue I´m mising? ... highly presumable. 1. did you perform a test of your freeradius-server over the network with a tool like radtest ( or similiar ) ? ( ... it's the first thing you would do !) 2. stop your freeradius-(service) and start the server from the command-line in debug-mode ...
by floaty
Wed Apr 29, 2020 3:16 am
Forum: Forwarding Protocols
Topic: Bonding multiple LTE
Replies: 3
Views: 1447

Re: Bonding multiple LTE

so ... first ... I am not catholic ( and 'am spending no sympathies for any tribes ... ) . BUT . Is there an option to bond multiple LTE wan (example 3x LHG LTE6) with two Mikrotik via GRE,EoIP or VPN to reduce broadcasting latency? . you can avoid congestion-related latency by increasing the bandwi...
by floaty
Wed Apr 29, 2020 2:20 am
Forum: Beginner Basics
Topic: Accessing ROS with Winbox over internet
Replies: 6
Views: 1415

Re: Accessing ROS with Winbox over internet

your WAN-interface is: 1. with good reason 2. for your own good 3. and therefore by default not in the fancy roundel for such pieces of lunacy ! . please make your self aquainted with common strategies of internet-security ... and the sophisticated concepts of the before named, which offers the Mikr...
by floaty
Wed Apr 29, 2020 1:46 am
Forum: Beginner Basics
Topic: Did I buy the wrong LTE Router?
Replies: 7
Views: 1843

Re: Did I buy the wrong LTE Router?

... or you catch the guy who's maintaining your local cell-tower by impeding his beer in the local pub, because you instructed the bar-crew before, to do so ... and ask him if it's worth !? .. or you spend then a "beer more" on him ... and he's considering a custom config for your IMEI (please have ...
by floaty
Wed Apr 29, 2020 1:03 am
Forum: Forwarding Protocols
Topic: L3 traffic stops passing on specific interface (OSPF related maybe)
Replies: 5
Views: 1353

Re: L3 traffic stops passing on specific interface (OSPF related maybe)

and maybe it's worth to investigate the "router-isn't-usable-by-IP-anymore*-thing ... on local interface ? no ping ? no arp ? no mac (! see ... you're doing mac-telnet ) ... there is mac-access ! what about arp ? ... so every little step ... like an outsider ( ... maybe like an intruder) . I had thi...
by floaty
Wed Apr 29, 2020 12:52 am
Forum: Forwarding Protocols
Topic: L3 traffic stops passing on specific interface (OSPF related maybe)
Replies: 5
Views: 1353

Re: L3 traffic stops passing on specific interface (OSPF related maybe)

. Main problem is, It's not possible to reproduce the issue with (yet) known tasks or tools ... . graylog is exactly the tool I would use for such investigations ... did you mentioned interface up/downs from one of your routers when you timeframed the occurence of the incident ... any route chances ...
by floaty
Tue Apr 28, 2020 11:57 pm
Forum: General
Topic: Different DHCP pools on ports from 192.168.1.0/21 network
Replies: 18
Views: 2750

Re: Different DHCP pools on ports from 192.168.1.0/21 network

... to give my inside pestalozzi a chance ... All clients see each other, all client can access internet on port1. All clients use same gateway 192.168.1.1 ... why in the name of pestalozzi, do these entities need addresses from different pools for ? ... what is the distinguishable criterion for the...
by floaty
Tue Apr 28, 2020 11:35 pm
Forum: General
Topic: Different DHCP pools on ports from 192.168.1.0/21 network
Replies: 18
Views: 2750

Re: Different DHCP pools on ports from 192.168.1.0/21 network

mmh ... without being rude (trying), I can recommend a link: . http://www.subnet-calculator.com/ . you're switching bits very frequently ... which can you bring in networking-devils kitchen very soon 8) . so ... if I see this right, you have more a DHCP-problem than a networking problem ?! . If you ...
by floaty
Tue Apr 28, 2020 11:06 pm
Forum: Virtualization
Topic: License rent for CHR
Replies: 8
Views: 1975

Re: License rent for CHR

... A A N N D D ... by the way there is a 60 day grace period for every CHR-VM ... fully featured ... so if you do it the very scottish way ... : you rent this one to your customer and after that you can use the money for your nephews christmas CHR ... so you can pour yourself an extra bottle eggnog...
by floaty
Tue Apr 28, 2020 10:55 pm
Forum: Virtualization
Topic: License rent for CHR
Replies: 8
Views: 1975

Re: License rent for CHR

not shure which license do you have in mind ? ... renting ?! ... interesting ! guess you're burning more money to setup the rental-contract and keep your related paperwork tidy, than the license would cost you. but sometimes business-ways are mysterious ways ... ?! so ... do it the scottish way: res...
by floaty
Tue Apr 28, 2020 9:38 pm
Forum: Forwarding Protocols
Topic: L3 traffic stops passing on specific interface (OSPF related maybe)
Replies: 5
Views: 1353

Re: L3 traffic stops passing on specific interface (OSPF related maybe)

Since the problem occures very sparsely, it's not so probable that you catch the trigger for the event by a "lucky punch". Anyway if you haven't yet, setup centralized syslogging and keep all you routers in time-sync. The rough timestamp of the event and the surrounded syslog-events from all other r...
by floaty
Tue Apr 28, 2020 7:26 pm
Forum: General
Topic: Different DHCP pools on ports from 192.168.1.0/21 network
Replies: 18
Views: 2750

Re: Different DHCP pools on ports from 192.168.1.0/21 network

guess you are a little bit out of "usual concept" !? . your interfaces are in the same IP-subnet 192.168.1.1/21 is (192.168.0.1 - 192.168.7.254) so there would be no need to configure different router interfaces BUT if you want it like that: +---+ +---+ +---+ +---+ +---+ +---+ | 1 | | 2 | | 3 | | 4 ...
by floaty
Mon Apr 27, 2020 6:38 pm
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

. just for the completeness of the picture: proxying a request from freeradius-v4 to MTik-UM-v7b5 seems to be a nogo . after setting up a new instance for MTik-UM in new radius_rlm of FRv4; FRv4 tries something like a check or hello or something, before the rlm is fully instantiated ... which fails ...
by floaty
Sat Apr 25, 2020 5:20 pm
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

. just discovered a nice radius testing-tool ... no eap-features ... ,but its possible to save predefined setup's, contains coa-requests, server-stress-testing ,monitoring ... tidy for windows, linux, freebsd ... decent seems ntradping, my convenient good old geezer, is ready for pension :( . https:...
by floaty
Sat Apr 25, 2020 4:00 am
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

. ... while v7 is still cooking ... were stuck with our windows-wlan-clients in the meantime ... and because corona-boreout and freeradius3.0 forming a perfect couple ... we are setting up an EAP-proxy (almost better than sudoku) . ------ ubnt bananapi CHR //// \\\\ +-------+ +-------+ +-------+ | S...
by floaty
Mon Apr 20, 2020 2:55 pm
Forum: RouterOS v7 BETA
Topic: Feature Request - Wireguard Protocol
Replies: 163
Views: 47240

Re: Feature Request - Wireguard Protocol

Mikrotik have the development smarts to cleanly integrate WireGuard into RouterOS, and now that it has been mainlined I would not be surprised if we see it in the very near future.
.
hear hear
by floaty
Fri Mar 20, 2020 1:10 am
Forum: Wireless Networking
Topic: Cat6 LGH LTE Super bad performance
Replies: 36
Views: 8852

Re: Cat6 LGH LTE Super bad performance

. This is a nice thing ... but I have to admit my company plan is not an unlimited one, so while I normally in "the zone" every month, I want avoid any BW-kinkyness. But the test-router is intended as custumers mgmt-backup-line ( F L A T R A T E !) ... then I'm definitly able to flood some statistic...
by floaty
Sat Mar 14, 2020 3:58 am
Forum: Wireless Networking
Topic: Cat6 LGH LTE Super bad performance
Replies: 36
Views: 8852

Re: Cat6 LGH LTE Super bad performance

. some toilet-paperroll-hunters returned to aerie ? ... or power-saving mode ... keeping the shores of kreuzberg-mountain green ? we know only a little ! plz remember ... floaty is YOUR performance leader in tha moment (actual results in post above) ... ... so far ... good night and good luck ! . 13...
by floaty
Fri Mar 13, 2020 11:54 pm
Forum: Wireless Networking
Topic: Cat6 LGH LTE Super bad performance
Replies: 36
Views: 8852

Re: Cat6 LGH LTE Super bad performance

. just found the solution: https://mikrotik.com/product/intercell_10_b38_b39 : ) power up your own cell ... out in the middle ... no interference and with your own iperf-server !! That stops all the yodeling and tells you whats behind that door !! Maybe that beast is excatly intended for that purpos...
by floaty
Fri Mar 13, 2020 11:14 pm
Forum: Wireless Networking
Topic: Cat6 LGH LTE Super bad performance
Replies: 36
Views: 8852

Re: Cat6 LGH LTE Super bad performance

just realized ... broke ma own record ... and still leader of the pack !
H O O K A Y I P P Y J A Y H E Y !!
by floaty
Fri Mar 13, 2020 11:08 pm
Forum: Wireless Networking
Topic: Cat6 LGH LTE Super bad performance
Replies: 36
Views: 8852

Re: Cat6 LGH LTE Super bad performance

.
22:05 (todays watermark ... guess they'r all out there hunting the last shit-paperroll avail in the stetl ?!
.
13mar2020.PNG
.
by floaty
Fri Mar 13, 2020 4:48 am
Forum: Wireless Networking
Topic: Cat6 LGH LTE Super bad performance
Replies: 36
Views: 8852

Re: Cat6 LGH LTE Super bad performance

. and the main problem ... results are totally erratic ... in the middle of the effin night, no lights on in the hood !! ... same config I've used before ... performance is unexplainable like "my ass" . ... who has the guts to explain such B-sheet to a paying customer ? ... are they scrubbing the an...
by floaty
Fri Mar 13, 2020 4:17 am
Forum: Wireless Networking
Topic: Cat6 LGH LTE Super bad performance
Replies: 36
Views: 8852

Re: Cat6 LGH LTE Super bad performance

. It's not as simple as this (but not much more complicated either): users share air-time. The higher number of users, the lower air time and thus lower throughput each gets. . guess this is a verry sensefull statement ! cause good old air is a very democratic medium - shared by all of us. you wanna...
by floaty
Fri Mar 13, 2020 3:25 am
Forum: Beginner Basics
Topic: Recommend way to block Ads with Mikrotik
Replies: 33
Views: 23350

Re: Recommend way to block Ads with Mikrotik

.
If the Force might be with us :shock:
.
by floaty
Thu Mar 12, 2020 12:11 am
Forum: Wireless Networking
Topic: Cat6 LGH LTE Super bad performance
Replies: 36
Views: 8852

Re: Cat6 LGH LTE Super bad performance

. Guess there is enough processing power in such an LTE-pop to force me to whatever channel / config they want, if I do not fit into the "for-the-greater-good-QoS-shaping-policy". And most of the time I'm not in the mood to wardrive the best spot for a high-perf LTE-link around. Good Old G. generall...
by floaty
Wed Mar 11, 2020 1:02 am
Forum: Wireless Networking
Topic: Cat6 LGH LTE Super bad performance
Replies: 36
Views: 8852

Re: Cat6 LGH LTE Super bad performance

.
!!! B O O Y A C A S H A !!!
.
in front of the peloton:
.
!!! FF ... FF ... FF ... F L O A T Y !!!
.
in_front.PNG
.
https://www.speedtest.net/
.
.
.
pop.PNG
.
.
hw-cfg.PNG
.
.
cfg-stat.PNG
by floaty
Wed Mar 11, 2020 12:47 am
Forum: Wireless Networking
Topic: Cat6 LGH LTE Super bad performance
Replies: 36
Views: 8852

Re: Cat6 LGH LTE Super bad performance

.
would be interesting ( ... for me)
which (and where) is the highest speed ever scored to a cellular network with the latest mt-hardware (R11e-LTE6)
...
gentlemen ... start your engines !
:evil:
by floaty
Wed Mar 11, 2020 12:09 am
Forum: Wireless Networking
Topic: Cat6 LGH LTE Super bad performance
Replies: 36
Views: 8852

Re: Cat6 LGH LTE Super bad performance

...
guess it's not that simple ?!
.
... maybe country-specific delicacies ?!
.
skip-b20.PNG
.
b20-disable.PNG
.
by floaty
Tue Mar 10, 2020 11:51 pm
Forum: Wireless Networking
Topic: Cat6 LGH LTE Super bad performance
Replies: 36
Views: 8852

Re: Cat6 LGH LTE Super bad performance

. Again, avoid using B20 and 5Mhz bandwith. ... how ? ... and why ? . This B20 is one of slowest (compare to B3 > B1 > B7 who are THREE KING's of LTE in EMEA and R11e-LTE6 only do 2CA: B3+B7 between them). ... where got that wisdom from ?? . Just tested new delivered RBLtAP-2HnD&R11e-LTE6 ... and so...
by floaty
Sat Jan 25, 2020 9:38 pm
Forum: RouterOS v7 BETA
Topic: Feature Request - Wireguard Protocol
Replies: 163
Views: 47240

Re: Feature Request - Wireguard Protocol

I'm in.
+1 for WireGuard.
by floaty
Sat Jan 18, 2020 3:10 am
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

no ... annoying mischief, because the clock is always working against you ...
but also with the exact clocking the win7-client fails.
by floaty
Sat Jan 18, 2020 2:53 am
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

... while reviewing ... and talking odds ...
.
no_tupi_nix_w7_more_odd.png
.
maybe a clock prob I did run into ...
by floaty
Sat Jan 18, 2020 2:46 am
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

yay: one+ for a radius-eap-debugging option . ... since I found the (or a possible) power-supply for my grand ole 2530p (nice keyboard, btw) -> ... also windows7 is not able to connect to the MT-CHR7-radius. Also for my cross-check-radius-server (zeroshell) I had to install the CA and the server-cer...
by floaty
Mon Jan 13, 2020 2:27 pm
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

some tinkering-time should be integral part of any workday : )
... so if anyone calls you in for another tubby meeting ... say: sorry, I have something of tremendous importance to tinker !
by floaty
Mon Jan 13, 2020 1:16 pm
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

It is possible to define different "customers" (like administrative domains) ... and it's possible to apply different sets of user-profiles (for vouchers, quotas etc.). Not shure about the logo-customization ... If you're already using MTik-devices you can download the usermanager package, install i...
by floaty
Tue Jan 07, 2020 8:20 pm
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

seems that feature isn't so widely implemented (self carved freeradius-installation ... possible ... not exaggerated easy) and until someone put a gracious eye on your feature-request ... you can evaluate here: https://www.kaplansoft.com/tekradius/ ( ... only when you can live with a windows-box) Sh...
by floaty
Sat Dec 28, 2019 4:07 am
Forum: Beginner Basics
Topic: Recommend way to block Ads with Mikrotik
Replies: 33
Views: 23350

Re: Recommend way to block Ads with Mikrotik

just had an over-christmas-discussion with my colleagues over the topic ... . just check !! ... even dns-filtering is a walrus-nipples-thing : . ... ad-content is filtered ... the loaded site(s) seems to be slow ... because the content of interest is placed last ... no effin pictures of socks inbetw...
by floaty
Sat Dec 28, 2019 3:32 am
Forum: General
Topic: Mikortik DHCP Option 43
Replies: 16
Views: 4390

Re: Mikortik DHCP Option 43

... so far as I recall ... it was a thorny way to implement in ISC too ( for me : ) ... but there's lot of time till january 6th :evil: . [admin@homeland-chr] > ip dhcp-server vendor-class-id print Columns: NAME, VID, SERVER, OPTION-SET, ADDRESS-POOL # NAME VID SERVER OPTION-SET ADDRESS-POOL 0 gs820...
by floaty
Sat Dec 28, 2019 3:03 am
Forum: Beginner Basics
Topic: Recommend way to block Ads with Mikrotik
Replies: 33
Views: 23350

Re: Recommend way to block Ads with Mikrotik

btw.
there tons of articles in this forum how to make use of anti-spam-, anti-phishing, - or country-code related community-lists with a MTik-board.
.
add a local anti-virus-proxy ... and your'e good to go
by floaty
Sat Dec 28, 2019 2:50 am
Forum: Beginner Basics
Topic: Recommend way to block Ads with Mikrotik
Replies: 33
Views: 23350

Re: Recommend way to block Ads with Mikrotik

... every filter (dns, av, antispam ... whatsoever) will slow down your secured application ... EVERY ! ... because you delegated sagacity to an entity with more discipline than you own by yourself ... and thats a good thing ... when it comes to computed routines 8) ... but it adds cpu-, asic-, what...
by floaty
Fri Dec 27, 2019 1:09 pm
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

I guess without the ability to debug the radius server side this is as cushy as nosepicking in a hobos schnozzle. We better wait for an "upstream statement" ... Maybe an old windows7-valiant out threre can tell if he's able to connect ... [ ... also the fortiauthenticator spat out my keysize 4096 ce...
by floaty
Fri Dec 27, 2019 1:36 am
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

yeah ... good tool (and as old as methusalix) ... . maybe the binary partly crashed ... it is not showing such behaviour on my machine ... wrong shared secret -> access-reject . . btw. repeated my eap-test with new generated certificates keysize 4096 instead of 2048 ... and then also the android cli...
by floaty
Thu Dec 26, 2019 5:02 am
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

just had a little read-along ... again . 169 Dec/13/2019 00:30:55 memory manager, debug >>> rx Access-Request from [192.168.2.25]:45652, id: 119 170 Dec/13/2019 00:30:55 memory manager, debug <<< tx Access-Challenge to [192.168.2.25]:45652, id: 119 171 Dec/13/2019 00:30:55 memory manager, debug >>> ...
by floaty
Thu Dec 26, 2019 3:49 am
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

so ... for starters ... it seems the problem ist NOT related to the certificates I've generated on the chr-v7-radius-um-machine :!: I've installed these certificates on another radius-machine ... . you may ask: ... what the **ck took him so long ? a.) ... tried that on my production-machine ... whic...
by floaty
Thu Dec 26, 2019 12:31 am
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

indeed ... bootet up another wireshark to free my win10-machine for a test ... seems the setup of the encrypted eap-tunnel fails ... no accept, no reject ... stuck in challenge . so maybe a problem with my server-certificate ... or: https://support.microsoft.com/en-ph/help/3121002/windows-10-devices...
by floaty
Wed Dec 25, 2019 7:39 pm
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 62
Views: 44053

Re: New User Manager in RouterOS v7

guess this feature will make a lot of people very happy ( and of course ... no doubt ... me too)
well done :!:
.
v7-eap-test-ws.png
.
v7-eap-test-rad-debug.png
.
v7-eap-test-um-stat.PNG
.
v7-eap-test-um-sess.PNG
.
v7-eap-test-andr.png
.
.
and unlike me, keep your clocks in sync !
by floaty
Mon Dec 23, 2019 11:44 pm
Forum: General
Topic: Mikortik DHCP Option 43
Replies: 16
Views: 4390

Re: Mikortik DHCP Option 43

divide et impera ... I agree by 100% ... but when 2000 ip-phones fresh outta box staring at you, you will beg for your vendor-class-based dhcp-features ... Sometimes you want split the ip-address-space for your VoIP by building ... add 4 types of phones (or AP's) and you will go nuts very soon :shock:
by floaty
Mon Dec 23, 2019 11:12 pm
Forum: General
Topic: Mikortik DHCP Option 43
Replies: 16
Views: 4390

Re: Mikortik DHCP Option 43

to be honest ... hopefully this feature will find it's way into v.6.4.x too ... while v7 is simmering.
... guess we will see (maybe one or another afficionado will give me "a ball plus" here : )
by floaty
Mon Dec 23, 2019 11:00 pm
Forum: General
Topic: Mikortik DHCP Option 43
Replies: 16
Views: 4390

Re: Mikortik DHCP Option 43

just had a look in v7 beta4 ... . [admin@MikroTik] /ip/dhcp-server/vendor-class-id> add Creates new item with specified property values. address-pool -- pool used for this vendor-class-id copy-from -- Item number disabled -- Defines whether item is ignored or used name -- option-set -- server -- glo...
by floaty
Mon Dec 23, 2019 10:08 pm
Forum: General
Topic: Mikortik DHCP Option 43
Replies: 16
Views: 4390

Re: Mikortik DHCP Option 43

For what I see, vendor-class-specific option-43 delivery is not implemented yet ... it's possible to have a specific ip-pool based on the vendor-class-id, but it's neither possible to add an dhcp-option-set to an ip-pool nor is there any matching condition-parm in the option-43-definition. So what's...
by floaty
Mon Dec 23, 2019 8:51 pm
Forum: General
Topic: Vendor-class-id not matching
Replies: 2
Views: 1845

Re: Vendor-class-id not matching

. maybe santa puts "wireshark" under your tree ?! ... you copied the hex-code with delimiters from the log-dump into your data-field ... not very convincing ( if I were a computer and had a saying in here ) . collect your dhcp-packets with -> Tools -> Packet sniffer . read out your vendor-spec data ...
by floaty
Mon Dec 23, 2019 5:38 pm
Forum: RouterBOARD hardware
Topic: RB960 bridge performance sfp -> cu-ethernet
Replies: 0
Views: 2697

RB960 bridge performance sfp -> cu-ethernet

Recently I had to replace a "multi-speed-media-converter" from amazon at a customer-site, because the device failed epicly in terms of performance (it's x-mas time, so the vendor is NOT revealed). The provider-cpe (presumedly set to 100MBit/full-duplex) had to be linked to a gigabit-1000base-sx port...
by floaty
Sat Dec 21, 2019 1:05 am
Forum: RouterBOARD hardware
Topic: Ubiquiti EdgeRouter 6P 'powered' by MikroTik RBGPOE with 4-Pair PoE Injector
Replies: 1
Views: 3118

Re: Ubiquiti EdgeRouter 6P 'powered' by MikroTik RBGPOE with 4-Pair PoE Injector

guess, you should introduce this to an insurance-agent of your trust to get a rate ... a good rate ... !?
... maybe even homeland-security should be asked for any objections
... who wants to be stuck in a guantanamo-style facility over x-mas by accident ? :shock:
by floaty
Wed Dec 18, 2019 3:41 am
Forum: Wireless Networking
Topic: RBwAPG-5HacT2HnD . netinstall . config fail
Replies: 0
Views: 1522

RBwAPG-5HacT2HnD . netinstall . config fail

just a low priority post ... that may ... or may not be of interest: reanimated a 'RBwAPG-5HacT2HnD' which I received as DoA from ebay ... spend 3 hours on it ! :( device came in from a probably failed openwrt-install-session ... no word on ethernet nor wifi ... after a 10sec-reset-button-reset "Old...
by floaty
Sat Oct 26, 2019 6:07 pm
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

yepp, when I got this setup to fly, caribean retirement is on schedule 8)
by floaty
Fri Oct 25, 2019 11:21 pm
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

and in most of the cases a GPeR would make sense ... adding a proper housing for it [GPeR IP67 Case] , would be sensefull too: installation is straight forward ... ... when using ready-made cables you have possibly to shorten the bend relief of the cable . 1_1.jpg . 2_2.jpg . 3_3.jpg . 4_4.jpg . 5_5...
by floaty
Thu Oct 24, 2019 2:28 am
Forum: The Dude
Topic: The Dude 6.40.8 - db failure: database disk image is malformed
Replies: 37
Views: 12620

Re: The Dude 6.40.8 - db failure: database disk image is malformed

At least you can simply replace it in case it breaks . mmh ... doesn't saw that - really good - point :-| Just migrated my busiest-helper-files to the m2 of my "RB1100AHx4 Dude" ... to bad I didn't got attentive of this potential issue before I began to script. Is there a tool to check the health o...
by floaty
Thu Oct 24, 2019 1:37 am
Forum: General
Topic: RAMdisk
Replies: 15
Views: 2889

Re: RAMdisk

+1 . would be a neat thing have a ppp-up (-down) script which needs helper-files to store dialer-states ... that's scratchy ... not so healthy for a flash or even for an usb-disk ... so definitly plus one ( ... even in v6.44+ [letting v7 be a good man] ... ... wanna show this to my colleagues ... .....
by floaty
Tue Oct 22, 2019 3:56 pm
Forum: RouterBOARD hardware
Topic: MikroTik MQS
Replies: 34
Views: 9558

Re: MikroTik MQS

I see
by floaty
Tue Oct 22, 2019 3:34 pm
Forum: RouterBOARD hardware
Topic: MikroTik MQS
Replies: 34
Views: 9558

Re: MikroTik MQS

one more thing:
.
reviewing your quickstart-guide, you can revise below on s.4 to 192.168.8.3 !
.
qs-mqs-s4.png
by floaty
Tue Oct 22, 2019 3:25 pm
Forum: RouterBOARD hardware
Topic: MikroTik MQS
Replies: 34
Views: 9558

Re: MikroTik MQS

What are you guys talking about?
.
bout the Mikrotik MQS Quickstart-Guide ? ... and the recommendations made there (obviously not your recommendations ?!)
...
later is "Operating system support The device software version is 1.2p" mentioned ... which differs to v1.1 :shock:
.
qs-mqs.png
by floaty
Tue Oct 22, 2019 2:28 pm
Forum: RouterBOARD hardware
Topic: MikroTik MQS
Replies: 34
Views: 9558

Re: MikroTik MQS

That's a profound complaint, ... but obviously it is the main purpose of MQS to do so. The cause could be accidental misuse or damage. To distinguish between these two possibilities a more detailed description of your problem would be necessary. :-| MQS quickstart-guide says actual sw-version is 1.2...
by floaty
Tue Oct 22, 2019 1:19 pm
Forum: RouterBOARD hardware
Topic: MikroTik MQS
Replies: 34
Views: 9558

Re: MikroTik MQS

Guess without internet access for the device, you can't. There's no manual download in the moment ... what's wrong with the running image ? . manual download - computer says: no <Error> <Code>AccessDenied</Code> <Message>Access Denied</Message> <RequestId>EFE50D47CE5598D3</RequestId> <HostId> 23YQ6R...
by floaty
Tue Oct 22, 2019 2:40 am
Forum: RouterBOARD hardware
Topic: MikroTik MQS
Replies: 34
Views: 9558

Re: MikroTik MQS

i have error
.
sad, but an error is better than nothing :!:
... would you like to share that error ?
... or a screenshot ?
by floaty
Tue Oct 22, 2019 2:05 am
Forum: RouterBOARD hardware
Topic: MikroTik MQS
Replies: 34
Views: 9558

Re: MikroTik MQS

.
where can i get the latest MQS software ?
.
.
We recommend clicking the “Check for updates” button and updating your system software to the latest
version to ensure the best performance and stability
.
https://i.mt.lv/cdn/rb_files/1568358529 ... %20web.pdf
by floaty
Fri Oct 18, 2019 1:28 pm
Forum: Scripting
Topic: Multiple Files in one e-mail.
Replies: 10
Views: 7479

Re: Multiple Files in one e-mail.

... or just send all files in a specific folder (disk2/sw/*) ...
.
/tool e-mail send  to="rcvr@rcvr.net" from="$sysName@sndr.net" body="disk2/sw-content" subject="disk2/sw-content" file=[:file find where name~"disk2/sw/"]
by floaty
Mon Oct 14, 2019 3:55 pm
Forum: General
Topic: cannot remove directory
Replies: 8
Views: 8893

Re: cannot remove directory

installed dude under dusk1/dude ? ... instead disk1/dude ?
.
obstinate files may be removeable, when logged as admin with a sftp-client (like WinSCP) ... and with circumspection :!:
by floaty
Sat Oct 12, 2019 12:01 am
Forum: The Dude
Topic: The Dude 6.40.8 - db failure: database disk image is malformed
Replies: 37
Views: 12620

Re: The Dude 6.40.8 - db failure: database disk image is malformed

Lucky you. May happen that problems are linked with usb / mSD storage type on routerboards while on CHR this does not apply. . just found, that well aged statement ... sounds like Dude on 'usb / mSD' is not one of the brightest ideas ?! ... should I keep the hands off it ? ... planned to test such,...
by floaty
Wed Oct 09, 2019 9:05 pm
Forum: The User Manager
Topic: RB750GL + Radius
Replies: 1
Views: 2263

Re: RB750GL + Radius

I am not sure if I need a level 5 license to RB750GL where Radius (user-manager) is installed or the hEX where the DHCP is installed
.
https://wiki.mikrotik.com/wiki/Manual:L ... nse_Levels
.
snip.png
.
where Radius (user-manager) is installed
by floaty
Wed Oct 09, 2019 8:05 pm
Forum: The Dude
Topic: how to "memorize" a snmp-function-result
Replies: 0
Views: 1841

how to "memorize" a snmp-function-result

Hello Forum, I am looking for a way to save the result of a function ... "somewhere". My problem: inside my devicelabels the snmp-device-name is dynamically displayed from a function. In case the device isn't responding any longer, I'm loosing the device-name in the label (but I won't !) So what are...
by floaty
Wed Oct 09, 2019 12:33 am
Forum: RouterBOARD hardware
Topic: MikroTik MQS
Replies: 34
Views: 9558

Re: MikroTik MQS

Maybe ... there is no advantage this time (the price eventually or the rugged design ? ... choose ) If I don't miss anything in the spec, it is no full RouterOS running on MQS. It is an AP-bridge only, which delivers passive PoE to a "setup-candidate" [point]. . MQS itself can be configured only in ...
by floaty
Sat Oct 05, 2019 1:05 am
Forum: RouterOS v7 BETA
Topic: adding fib to vrf failed with timeout
Replies: 3
Views: 3452

Re: adding fib to vrf failed with timeout

uuh ... yeah ... tried to push an interface into a VRF ... failed ... pushed harder ... saw the error-message ...
... maybe a little "what's-worth-to-test-and-what's-not-implemented-yet-v7-matrix" could be helpfull in the notes ... to avoid 'early redundancy'
... anyway: thumbs-up !
by floaty
Thu Oct 03, 2019 7:10 pm
Forum: RouterOS v7 BETA
Topic: adding fib to vrf failed with timeout
Replies: 3
Views: 3452

Re: adding fib to vrf failed with timeout

Version number 7.0beta2 Router's model CHR . [admin@CHRv7] > ip vrf add name=vrf10 [admin@CHRv7] > /routing table add fib name=main-fib vrf=main [admin@CHRv7] > [admin@CHRv7] > /routing table print Flags: D - dynamic; X - disabled, I - invalid; U - used 0 name="main-fib" vrf=main fib [admin@CHRv7] >...
by floaty
Thu Oct 03, 2019 6:56 pm
Forum: RouterOS v7 BETA
Topic: adding fib to vrf failed with timeout
Replies: 3
Views: 3452

adding fib to vrf failed with timeout

Version number 7.0beta2 Router's model model: RouterBOARD 3011UiAS firmware-type: ipq8060 factory-firmware: 6.42.12 current-firmware: 7.0beta2 upgrade-firmware: 7.0beta2 Steps to reproduce the issue [admin@RB3011] > ip vrf add name=vrf10 [admin@RB3011] > ip vrf add name=vrf20 [admin@RB3011] > ip vrf...
by floaty
Thu Oct 03, 2019 2:58 am
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

last advise !
while editing your posting ... and going lazy ...
... don't become sloppy with your GPER-jumpers ... :shock:

(stock your tools ... and keep hoover and cat away :!: )
.
jumper.png
by floaty
Thu Oct 03, 2019 12:38 am
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

guess this behaviour is related to PoE-detection in the switch ... no passive PoE-adapter in the arsenal to verify ... so check, before climb ! Normis explained that 802.3af/at powering only works when there's a compliant device down the line ... if there isn't one, passive PoE injector should be u...
by floaty
Wed Oct 02, 2019 11:48 pm
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

... so far ... my request for clearance at marvell ... stuck in spam ?! ... ignored ?! ... I don't give a schattenriss ... we proceed ! ... todays setup is able to escalate things to mtu-size 9216 byte ... and is able to do a perf-test too I added a PoE-injector and removed the GPER-jumper on PoE-ou...
by floaty
Sun Sep 22, 2019 12:47 am
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

when I got my 'security cleareance' ... I will find a way, to leak in between the lines, while telling noomp :wink: . Dear floaty, We have received your registration request for use of the Marvell Extranet. You indicated on the registration form that you either don't have a Marvell Non-Disclosure Ag...
by floaty
Sat Sep 21, 2019 2:10 am
Forum: Virtualization
Topic: why a CHR can be the best friend of an ESXi-admin
Replies: 0
Views: 2067

why a CHR can be the best friend of an ESXi-admin

It may or may not occur to you, that the use of serial-console to a virtual machine on an ESXi-host could be conveniant for you ?! ... this presumption turns into pain in the a*s, when a serial console is MANDATORY :twisted: ... for me ? ... yesterday ! There might be a bunch of fun-seeking network-...
by floaty
Fri Sep 20, 2019 11:22 pm
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

I think its a 2port switch with Poe in to power it and Poe pass-through . @chechito seems you were right by first best-guess-attempt ... btw. ... ... were you able to exactly identify, whether the marvell-chip is a 88E8040 or a 88E8042 ?? even when it is a: Marvell® Yukon 88E8040 Gigabit Ethernet C...
by floaty
Fri Sep 20, 2019 7:25 pm
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

sooo ... hopefully without being to much over the railing, we can say: . GPER is 802.1at-PoE-powered two-port switch, which is capable to deliver 802.1at-PoE-power to a client-device and it is transparent for every Layer2-protocol*), while it supports a mtu-size of at least 9014 bytes ?! *) in a mor...
by floaty
Fri Sep 20, 2019 6:59 pm
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

because it is my responsability to keep the readers tight and greedy ... now ... at very last ... the gretchen-question: ? MTU ? for starters: it was not so easy to find the proper equipment for the mtu-tests here at homeland-labs :? While the "wuhan-sw" supports a max. frame-size of 9600 bytes (gue...
by floaty
Fri Sep 20, 2019 3:04 pm
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

side-note: when plugging in a GPER into my PoE-switch like that: . #1.png . ... and than add a PoE-Client behind the GPER, like that: . #2.png . ... or that: . #3.png . . ... the PoE-Client is not powered up ... I had to disconnect and reconnect the cable at PoE-Switch before power is delivered ( I ...
by floaty
Fri Sep 20, 2019 2:29 pm
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

since we were able to add an OSPF-Router in Vlan11 on a "wuhan-sw"-port ... we can mark tickbox "multicast" as 'checked'
.
802.##4.PNG
.
802.##5.png
by floaty
Fri Sep 20, 2019 1:59 pm
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

and not so surprising anymore: . wuhan-sw# show run --- snip --- ! interface GigabitEthernet 1/1 switchport mode trunk poe mode plus poe power limit 30.0 ! --- snip --- wuhan-sw# show vlan VLAN Name Interfaces ---- -------------------------------- ---------- 1 default Gi 1/1,3-10 11 nubecula Gi 1/1-...
by floaty
Fri Sep 20, 2019 1:42 pm
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

... yepp ... the discourse had a little drift :wink: ... so ... STP, 802.1q: Setup: PoE-Switch<-->GPER<-->passivePoEconv<-->mapLite . 802.##1.png . . wuhan-sw# show spanning-tree active CIST Bridge STP Status Bridge ID : 32768.9A-86-03-28-05-01 Root ID : 32768.9A-86-03-28-05-01 Root Port : - Root Pa...
by floaty
Wed Sep 18, 2019 1:54 am
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

https://en.wikipedia.org/wiki/Shannon_limit
.
interesting article indeed ... and crazy numbers:
.
tönn.PNG
by floaty
Wed Sep 18, 2019 1:35 am
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

1) at what OSI layer this device work? at L1 like hub, or at L2 like switch? 2) what delay does this device add? 3) why distance is limited to 1500 m? . 1) ... the DEVICE (aka GPeR [thats from the birth-certificate] acts obviously like a switch ... different ether-speeds ... with full-duplex on bot...
by floaty
Wed Sep 18, 2019 12:03 am
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

would be good to identify the switch chip . Yeah I know ... but this reminds of christmas, when I was a child ... my sister got a new watch ... and I got lot of trouble ... and she would not accept 'my fireforce-truck' ! as compensation. To be honest ... I already tried, but my little iPhone-crowba...
by floaty
Tue Sep 17, 2019 11:27 pm
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

oncho.png
.
... yepp ... I thought so ... ... guess I was to hasty to shoot a bundle :shock:
by floaty
Tue Sep 17, 2019 10:06 pm
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

most fun is always testing new stuff 8) ... guess we can skip the 'unboxing part', because this is obviously the wysiwyg-approach ... no knives ... no scissors ... no violence needed ... and I aggree 100% with it . 1st.png . first test ... brute force ! the big buddy in the foreground is a wireless-...
by floaty
Fri Sep 13, 2019 1:21 am
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

"Yes, it will effectively extend your cable and will pass any data you transmit" data ... yep, data is a lot ... so let us concatenate which questions: - ether-speed negotiation bursts (and the results ... we all now: it's standard ... but it's not golden in functionality ... nowhere ) - lldp-behavi...
by floaty
Fri Sep 13, 2019 12:57 am
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

a switch with 2 ports doesn't need to learn no MAC addresses of cause there would be no need, neither would be a need for that in a linux-bridge which contains two logical interfaces by my command or a 24-port switch where I only plugged two cables in ... ... but they do ! ... threrefore my questio...
by floaty
Wed Sep 11, 2019 12:34 am
Forum: RouterBOARD hardware
Topic: GPER usage questions
Replies: 34
Views: 7345

Re: GPER usage questions

It's like putting a switch in between
mmh, thats a delphi-oracle term ...
a switch learns mac-adresses ... a switch ages mac-adresses !?
so question is: is this a switch, like a two-port-bridge or is it just like patch-port in OVS which says "<->" ?
by floaty
Wed Sep 04, 2019 6:29 pm
Forum: The Dude
Topic: [BUG] Images and icons disapearing
Replies: 26
Views: 8586

Re: [BUG] Images and icons disapearing

adding ftp-rights to the user-group solved the issue for me - just like dasiu wrote

dude-read.PNG
by floaty
Fri Aug 30, 2019 5:04 pm
Forum: The Dude
Topic: using ROS-device as remote-poller for smokeping
Replies: 0
Views: 2035

using ROS-device as remote-poller for smokeping

As a big-fan of smokeping for debugging routing-issues and monitoring routing-performance I was recently kind of dejected when my ROS-remote-poller stopped working. I upgraded my central monitoring-machine to debian buster and smokeping 2.7.3-2. Everything worked out, except the mikrotik-remote-poll...
by floaty
Thu Aug 29, 2019 7:52 pm
Forum: The Dude
Topic: Feature request - Sending Reports
Replies: 4
Views: 3147

Re: Feature request - Sending Reports

Definitly joining the club, ... would be a nice thing for networks where you can only send status mails out or only dial-in access is avail ! Tried to build a script which fetches the netmap-status via https from it's own webfig and sends out a mail ... failed ... seems this is for grown up's. In ad...
by floaty
Mon Jun 10, 2019 11:35 am
Forum: General
Topic: EoIP / gretap compatibility
Replies: 1
Views: 1160

EoIP / gretap compatibility

Not shure if this feature is under consideration ... ? Would be a big gain being able to terminate a gretap-tunnel to a RB-device. As far as I understand the protocol-numbers used in the header are different in Linux-gretap and RB-EoIP. Since newadays a lot of wireless-devices using gretap-bridging ...
by floaty
Thu Nov 22, 2018 1:12 am
Forum: General
Topic: L2TP server interface in VRF?
Replies: 2
Views: 1082

Re: L2TP server interface in VRF?

I'm not really an english-teacher ... but ... I can still ping stuff in SYSTEM2 vrf or the main routing table. when we examine the word 'or' in the quote above , it is not possible to bring the described failure in compliance to master George Boole ... aren't we ? ... so: first check if the setup yo...
by floaty
Wed Nov 21, 2018 11:27 pm
Forum: General
Topic: Place pppoe session in VRF
Replies: 2
Views: 1027

Re: Place pppoe session in VRF

Maybe you should have a look to this thread, where I've posted a couple of hints ... not shure if splynx have or allows full access to dictionaries of their radius service. I've build something like that for my customer-service-gateway ... not fully productive yet, but I'm pretty happy with it till ...
by floaty
Mon Nov 05, 2018 7:30 pm
Forum: Forwarding Protocols
Topic: PPPoE & VRF
Replies: 4
Views: 3042

Re: PPPoE & VRF

Just learned, that the radius-attribute "Mikrotik-Group" is 'ppp-aware'. So ... it seems Santa stays frosty up in Lappland this year, because you can (if you want) realize a radius-based VRF-selection with "Mikrotik-Group". You have to skip the user-decidable realm-selection in the ppp-up/down scrip...
by floaty
Sat Nov 03, 2018 2:23 pm
Forum: Forwarding Protocols
Topic: PPPoE & VRF
Replies: 4
Views: 3042

Re: PPPoE & VRF

Testing with pppoe was not so golden ... the session-setup and close in pppoe is to fast to grab the named interface-name. Figured that it's better to put a delay before reading the interface-name on a ppp-down-event and then to kill the whole shebang in the name of the zombie. If you wanna use pppo...
by floaty
Thu Nov 01, 2018 3:43 pm
Forum: Forwarding Protocols
Topic: OpenVPN + VRF
Replies: 2
Views: 2461

Re: OpenVPN + VRF

you need kind of a "crime scene cleaner" ppp-up: :local localAddr $"local-address" :local remoteAddr $"remote-address" :local callerId $"caller-id" :local calledId $"called-id" :local interfaceName [/interface get $interface name] :local calledRealm [:pick $user ([:find $user "@" ]+1) 60] :local vrf...
by floaty
Thu Nov 01, 2018 3:08 pm
Forum: Forwarding Protocols
Topic: PPPoE & VRF
Replies: 4
Views: 3042

Re: PPPoE & VRF

Yepp, were still waiting for a mikrotik radius-attribute like 'mikrotik-user-vrf' ... Till santa puts that under the tree, we can try with these humble scripts I've tweaked. Made these with open-vpn, but it should also work with other ppp-based stuff To get it work you will need a couple helper file...