Community discussions

MikroTik App

Search found 334 matches

  • 1
  • 2
by ayufan
Wed Jul 13, 2022 9:35 pm
Forum: Containers
Topic: v7.1rc3 adds container support
Replies: 493
Views: 162719

Re: v7.1rc3 adds Docker (TM) compatible container support

download directory as .tar.gz and to upload (and unpack) .tar.gz archive.
The layers being pulled from registry of container images are `.tar.gz` and MikroTik unpacks them.
by ayufan
Sat Jun 25, 2022 1:37 pm
Forum: Containers
Topic: v7.1rc3 adds container support
Replies: 493
Views: 162719

Re: v7.1rc3 adds Docker (TM) compatible container support

There's a problem with filesystems mounted with `nosuid` preventing usage of `sudo` (and possibly PTY access). This is also present on all mounted disk. # RouterOS /interface veth add address=172.17.0.3/16 gateway=172.17.0.1 name=ssh-veth /container config set registry-url=https://registry-1.docker....
by ayufan
Sat Jun 25, 2022 1:17 pm
Forum: Containers
Topic: v7.1rc3 adds container support
Replies: 493
Views: 162719

Re: v7.1rc3 adds Docker (TM) compatible container support

That kind of features would always be difficult. How do you want the traffic to be routed? For the static veth interfaces you define that at the RouterOS side during setup of your container, but when the container would be allowed to setup dynamic interfaces (like tunnels), what would they be conne...
by ayufan
Fri Feb 26, 2016 1:21 am
Forum: RouterBOARD hardware
Topic: HAP AC
Replies: 538
Views: 197597

Re: HAP AC

Does anyone know if the replaceable antenna is ufl or mmcx? It's hard to see from the photos.
In docs is written that this is ufl, but only for third chain of 2GHz and 5GHz.
by ayufan
Fri Feb 26, 2016 12:26 am
Forum: RouterBOARD hardware
Topic: HAP AC
Replies: 538
Views: 197597

Re: HAP AC

... Interesting. What actual transfer rates do you see with the Archer C7 when doing a transfer over AC? ... I guess it's not great/excellent as some others, but I believe it's well within line as to what is to be expected for what the device is. If you need that, buy a ~500$ consumer router I gues...
by ayufan
Thu Feb 25, 2016 7:09 pm
Forum: RouterBOARD hardware
Topic: HAP AC
Replies: 538
Views: 197597

Re: HAP AC

I got my hAP AC. The results are not that great. I get around 450Mbps on AC (with MacBook Pro 2015) to LAN. I get around 300-350Mbps with NAT (85% of CPU). What is interesting is the CPU usage when the hAP AC is sending: it's then around 20-30% (50% when doing AC+NAT with 300Mbps TCP), on the other ...
by ayufan
Wed Feb 24, 2016 5:40 pm
Forum: RouterBOARD hardware
Topic: HAP AC
Replies: 538
Views: 197597

Re: HAP AC

Nice results from users on social media:
https://twitter.com/darkmanlv/status/702448475196276737
I'm curious what is the AC+NAT performance :) I'll test it tomorrow. My hAP AC will arrive :)
by ayufan
Tue Feb 23, 2016 11:28 am
Forum: RouterBOARD hardware
Topic: HAP AC
Replies: 538
Views: 197597

Re: HAP AC

Now we have HAP AC released, but I'm still worried reading comments in these thread. So please give me your suggestion or advice how to find my MikroTik device :) Now I have 250 Mbit/s internet, further it may be updated to 500 or 700 Mbit/s. Will these device feet my needs and will it be able to t...
by ayufan
Sun Feb 21, 2016 1:34 am
Forum: RouterBOARD hardware
Topic: Encryption performance on OpenVPN/IPsec VPN
Replies: 32
Views: 22195

Re: Encryption performance on OpenVPN/IPsec VPN

with VPN ? this topic is now about VPN, it got very off topic, so we split it. hAP ac wireless tests we have not published, but I could see what we can do. This guy has excellent results, but I am not sure what he tested and how: https://twitter.com/Janamaja/status/698152711896829953 It's nice, may...
by ayufan
Fri Feb 19, 2016 12:49 pm
Forum: RouterBOARD hardware
Topic: Encryption performance on OpenVPN/IPsec VPN
Replies: 32
Views: 22195

Re: HAP AC

Exactly, this is underpowered low-end home router that can't fully use the AC that have installed in it. It seems that, if you use the SFP with AC radio and you configure it to use a Routing with NAT I expect that you will get no more than 300Mbps on AC radio :( If Fasttrack is turned on it will be...
by ayufan
Thu Feb 18, 2016 5:41 pm
Forum: RouterBOARD hardware
Topic: Encryption performance on OpenVPN/IPsec VPN
Replies: 32
Views: 22195

Re: HAP AC

Shows how slowly the CPU improvements are coming compared to the rest of the hardware and modern broadband speeds. Hopefully MT can come out with a newer series of boards with CPUs that can actually keep up with the hardware! The hAP AC is nice as an access point but if it can easily be overloaded ...
by ayufan
Thu Feb 18, 2016 11:21 am
Forum: RouterBOARD hardware
Topic: Encryption performance on OpenVPN/IPsec VPN
Replies: 32
Views: 22195

Re: HAP AC

I only concern about wireless router with VPN performance (OPVN and IPSEC). Based on these result, WRT1900ACS is better for me ( not hAP ac ) ?? On hAP AC you will get around 10-15Mbps (The OpenVPN performance is limited by CPU), On Turris/1900ACS you will get around 90Mbps. I would wait for Turris...
by ayufan
Thu Feb 18, 2016 12:26 am
Forum: RouterBOARD hardware
Topic: Encryption performance on OpenVPN/IPsec VPN
Replies: 32
Views: 22195

Re: HAP AC

9Mbps TCP UL, OpenVPN on OpenWrt CC, BF-CBC-128bit/SHA1 (one of the fastest combinations), CPU: 75% Which wireless router can provide 50~100 Mbps throughput for OpenVPN ? You should get pretty decent performance with this: https://www.indiegogo.com/projects/turris-omnia-hi-performance-open-source-r...
by ayufan
Tue Feb 16, 2016 3:44 pm
Forum: RouterBOARD hardware
Topic: Encryption performance on OpenVPN/IPsec VPN
Replies: 32
Views: 22195

Re: HAP AC

It is interesting too see the CPU% when doing this 500Mbps. Either way the results are not astonishing. @cpliu903 I expect that you will see no more 30Mbps IPsec md5/aes, and no more than 10-15Mbps OpenVPN sha1/aes. http://www.cisco.com/c/en/us/products/collateral/routers/small-business-rv-series-r...
by ayufan
Tue Feb 16, 2016 11:43 am
Forum: RouterBOARD hardware
Topic: Encryption performance on OpenVPN/IPsec VPN
Replies: 32
Views: 22195

Re: HAP AC

It is interesting too see the CPU% when doing this 500Mbps.

Either way the results are not astonishing.

@cpliu903

I expect that you will see no more 30Mbps IPsec md5/aes, and no more than 10-15Mbps OpenVPN sha1/aes.
by ayufan
Mon Feb 15, 2016 10:24 pm
Forum: RouterBOARD hardware
Topic: HAP AC
Replies: 538
Views: 197597

Re: HAP AC

Yeah. I would like to see the wireless performance :) I know how it works on Archer C7 (the same HW) with OpenWrt. It's interesting to see how it works on MikroTik.
by ayufan
Sat Feb 06, 2016 12:04 pm
Forum: RouterBOARD hardware
Topic: HAP AC
Replies: 538
Views: 197597

Re: HAP AC

then just go for tp-link
I got one, and I got a couple of Routerboards too. I can just argue that for SOHO OpenWrt is simply better, and extra RouterOS (like broken OpenVPN) features doesn't justify buying this device at this price.
by ayufan
Sat Feb 06, 2016 2:24 am
Forum: RouterBOARD hardware
Topic: HAP AC
Replies: 538
Views: 197597

Re: HAP AC

Aerohive and Meraki are far more expensive, and we of course cannot compare RB w/ROS with something like D-Link / Asus / Tp-Link or any other SOHO crap with unusable software. Why? I use TP-Link Archer C7 v2.0 https://wiki.openwrt.org/toh/tp-link/tl-wdr7500 . I'm disappointed. I expected for hAP ac...
by ayufan
Sat Feb 07, 2015 7:36 pm
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 125891

Re: Feature request: OpenVPN compression LZO and UDP

Right now I have had to use MTIK boxes to create TCP OpenVPN Tunnels to a PFSense box at the HQ for a network because I could not find a suitable router that would run PFSense in a small package for the price point MTik offers.
You can always try OpenWrt. It works great.
by ayufan
Mon Sep 29, 2014 2:10 pm
Forum: General
Topic: RoS hacked, device sompromised, http redirected, ports open
Replies: 7
Views: 3327

Re: RoS hacked, device sompromised, http redirected, ports o

For SXT though, I don't think you can dismount the HDD, and as such, that's not really possible anyway.
Is possible as long as you have physical access to the device and you can "netinstall" the device.
by ayufan
Fri Mar 28, 2014 6:55 pm
Forum: General
Topic: Add print server (printer support)
Replies: 145
Views: 102705

Re: Add print server (printer support)

Unfortunately Openwrt not add printer support, using usb printer with OpenWRT not possible now.
Is possible and works, but not in Metarouter. Metarouter doesn't support usb-passthrough.
by ayufan
Mon Mar 24, 2014 8:40 pm
Forum: General
Topic: Add print server (printer support)
Replies: 145
Views: 102705

Re: Add print server (printer support)

+1
On RB951 "home router" it should be one of the main feature...
Then install OpenWrt :) You'll have printer support.
by ayufan
Sat Mar 22, 2014 1:33 am
Forum: Wireless Networking
Topic: CAPs Manager
Replies: 165
Views: 75827

Re: CAPs Manager

I would love to but I can't get excited. Its basically a year after the posted "Wireless Controller". If MT could really come to the party with this, then I could finally stop buying UNIFI Yeah, you're pretty damn right. Even that we still don't have dual-band access points for office, no...
by ayufan
Fri Mar 21, 2014 2:54 pm
Forum: Wireless Networking
Topic: [REQUEST] Raspberry Pi
Replies: 29
Views: 66260

Re: [REQUEST] Raspberry Pi

RPi is not 'old', but it is cheap.

In the more generic sense, ARM chipsets could be a good addition for a number of different platforms. RPi is just the first example that came to mind.
If you look at used CPU it is old :)
by ayufan
Thu Mar 20, 2014 6:20 pm
Forum: General
Topic: AR8327
Replies: 8
Views: 8632

Re: AR8327

Found this one: http://mum.mikrotik.com/presentations/IT14/starnowski.pdf This presentation is not accurate (or only based on what wiki says), because in reality with the switch chip you can use hybrid ports :) At least it works on RB1100AHx2 and RB951G-2HnD. What I've also discovered that VLAN hea...
by ayufan
Wed Mar 19, 2014 10:46 pm
Forum: Wireless Networking
Topic: [REQUEST] Raspberry Pi
Replies: 29
Views: 66260

Re: [REQUEST] Raspberry Pi

Hi Forum, This is aimed more so at the employees of Mikrotik - how hard would it be to port the code over to ARM architecture for the purpose of running RouterOS on a Raspberry Pi? To be honest - I understand if you feel its not worth it. THe 951-2n is pretty darn cheap and has a lot of power for i...
by ayufan
Wed Feb 26, 2014 9:03 pm
Forum: Wireless Networking
Topic: Case: 500-2000 wireless clients within 50x70 meters
Replies: 6
Views: 2928

Re: Case: 500-2000 wireless clients within 50x70 meters

We recently did wireless installation for conference (around 500 users). We used TP-Link WDR-3600 with OpenWRT. I did great, worked without any problems, stable and very fast. WDR-3600 is pretty cheap and with dual band wireless.
by ayufan
Wed Feb 26, 2014 8:09 pm
Forum: RouterBOARD hardware
Topic: New hardware - mAP
Replies: 155
Views: 98678

Re: New hardware - mAP

16MB flash? is it enough?
by ayufan
Thu Jan 16, 2014 8:31 pm
Forum: Wireless Networking
Topic: RB951G-2HnD wireless channel
Replies: 4
Views: 2080

Re: RB951G-2HnD wireless channel

We need it for HOME AP wifi
What we really need is to have dual-radio SOHO router. I didn't have in years to change once setup wireless.
by ayufan
Mon Jan 13, 2014 9:07 pm
Forum: Scripting
Topic: PHP Notice: Undefined variable: _ in /opt/mikrotik/routeros
Replies: 18
Views: 11429

Re: PHP Notice: Undefined variable: _ in /opt/mikrotik/rout

ayufan's one - There's some value in it. I haven't used it, nor have I seen people in the forum use it, so I can't comment on stability. I don't really like most of the approaches from an "elegance" standpoint, but what constitutes "elegant" is always debatable. In fact, that cl...
by ayufan
Wed Dec 04, 2013 10:53 pm
Forum: General
Topic: Feature Request: DNS Fowarder
Replies: 12
Views: 4271

Re: Feature Request: DNS Fowarder

For long time I were using layer 7 filter which pretty nice handles dns-over-udp.
by ayufan
Thu Nov 21, 2013 12:09 pm
Forum: Wireless Networking
Topic: UniFi or Mikrotik
Replies: 2
Views: 2356

Re: UniFi or Mikrotik

We recently bought 3 UniFis with AC support. No problems at all. Works like a charm. It's generally solution to install and forget. MikroTik's solution looks very promising, but when it will be available, how stable will it be, and what will be HW requirements for Controller.
by ayufan
Sun Sep 08, 2013 2:45 pm
Forum: General
Topic: forum.mikrotik.com
Replies: 2
Views: 1341

Re: forum.mikrotik.com

do you think there is anyone to do cost for sniffing information like these? what is the reason behind this hack?! :shock:
Maybe not, but what bothers to have SSL anyway.
by ayufan
Sun Sep 08, 2013 12:28 pm
Forum: General
Topic: forum.mikrotik.com
Replies: 2
Views: 1341

forum.mikrotik.com

Hey guys,

Do you plan to enable SSL-only access to the community forum? I don't feel good when I know that my password or session tokens fly unencrypted over the Internet.

Kamil
by ayufan
Fri Sep 06, 2013 3:47 pm
Forum: General
Topic: 6.3 Released
Replies: 95
Views: 29126

Re: 6.3 Released

> Ubuntu/Mint
NM in ubuntu lacks L2TP/IPsec support.
https://launchpad.net/~seriy-pr/+archiv ... nager-l2tp
by ayufan
Fri Sep 06, 2013 12:39 pm
Forum: General
Topic: 6.3 Released
Replies: 95
Views: 29126

Re: 6.3 Released

4) Easy to configure. Not IPSec/L2TP, because installing strong/openswan and writing all configs... doh. IPSec/L2TP is fairly easy to configure. You have built-in (or easily installable) support for all the platforms (ex. Windows Phone). We have users using: OSX, Windows 7 and 8, Ubuntu/Mint, Andro...
by ayufan
Sat Aug 24, 2013 6:56 pm
Forum: General
Topic: MikroTik News August 2013 (Issue #50)
Replies: 17
Views: 14884

Re: MikroTik News August 2013 (Issue #50)

Do you plan to release SOHO like router (RB951G) with dual-band wireless?
Surely its only a matter of time
Yes, but it takes an unusually long time. Especially when I had to replace my home RB951G with TL-WDR4300 and switch to OpenWrt (i don't want to have two devices working).
by ayufan
Sat Aug 24, 2013 1:53 am
Forum: General
Topic: MikroTik News August 2013 (Issue #50)
Replies: 17
Views: 14884

Re: MikroTik News August 2013 (Issue #50)

Do you plan to release SOHO like router (RB951G) with dual-band wireless?
by ayufan
Tue Jul 23, 2013 12:20 pm
Forum: Virtualization
Topic: Hyper-V integration components
Replies: 127
Views: 77512

Re: Hyper-V integration components

IManaging the KVM devices is really unpleasant in our environment.
Use the Proxmox VE. Is Open Source Virtualization Platform with support for almost everything what is needed ;) And it support OpenVZ and KVM and plays very nice with MikroTik.
by ayufan
Wed Jul 17, 2013 10:12 pm
Forum: RouterBOARD hardware
Topic: New product - RB951Ui-2HnD
Replies: 25
Views: 18366

Re: New product - RB951Ui-2HnD

@normis:

When we can expect RB951G with dual band wireless?
by ayufan
Thu Jun 20, 2013 10:30 pm
Forum: Forwarding Protocols
Topic: IGMP Proxy issue
Replies: 60
Views: 35354

Re: IGMP Proxy issue

why not switch to OpenWrt? it should be fairly simple to provision devices.
by ayufan
Sat May 25, 2013 4:20 pm
Forum: General
Topic: L2tp/IPSEC performance blows?
Replies: 19
Views: 8051

Re: L2tp/IPSEC performance blows?

Change IPsec proposal to use md5 with aes. It should boost performance significantly. Default sha1 with 3des is very slow on these devices.
by ayufan
Wed May 22, 2013 2:44 pm
Forum: Virtualization
Topic: MetaROUTER stability issues on certain MIPSBE and PPC boards
Replies: 490
Views: 167538

Re: MetaROUTER stability issues on certain MIPSBE and PPC bo

The hypervisor hands out shares of CPU time every 3,33ms if I'm not mistaken, the guests can and do yield back if there is nothing to do. So what fact you claim to know exactly makes you think, there is a penalty of 50%? Ok. I will later today or tomorrow put some tests. So it happens that I have s...
by ayufan
Wed May 22, 2013 12:44 pm
Forum: Virtualization
Topic: MetaROUTER stability issues on certain MIPSBE and PPC boards
Replies: 490
Views: 167538

Re: MetaROUTER stability issues on certain MIPSBE and PPC bo

We are not talking about 50%, we are talking about a factor of 10x or more. BIG DIFFERENCE. If what you say were true, then a task which would normally take about 1 second without a MetaROUTER guest running would take roughly 2 seconds with a MetaROUTER guest. I'm seeing 10-15 seconds! -- Nathan I ...
by ayufan
Thu May 16, 2013 2:06 pm
Forum: Virtualization
Topic: MetaROUTER stability issues on certain MIPSBE and PPC boards
Replies: 490
Views: 167538

Re: MetaROUTER stability issues on certain MIPSBE and PPC bo

New issue: presence of a MetaROUTER on 5.25 can cause host in certain cases to take much longer to complete tasks than it normally would. Example: I added a new MetaROUTER to a 450G that a customer had. Instantly, CPU on 450G shot up to 100% and stayed there until I disabled the MetaROUTER. Profile...
by ayufan
Wed May 15, 2013 2:22 pm
Forum: General
Topic: Policy Routing - L2TP and multiple WANs
Replies: 14
Views: 13565

Re: Policy Routing - L2TP and multiple WANs

Yeah. We have 6.0rc14 and problem still persist. This is especially visible when you use L2TP/IPsec and try to connect from LAN side to external WAN IP address.

So Mikrotik shame on you for such long lasting and easy to fix bug.
by ayufan
Wed May 15, 2013 2:17 pm
Forum: General
Topic: IPSec, AES-128, MD5
Replies: 4
Views: 2473

Re: IPSec, AES-128, MD5

You can get RB951G which is twice as fast as RB751G and in the same price range. It should handle fine 20Mbps half-duplex.

Check performance on RB751G on lower traffic mark, check CPU usage. You will get twice as that on RB951G.
by ayufan
Sun Mar 03, 2013 2:13 pm
Forum: Beginner Basics
Topic: two encryption type for L2TP IPSEC
Replies: 1
Views: 1096

Re: two encryption type for L2TP IPSEC

Disable encryption on L2TP interface. It strictly depends on selected profile. You can check that: PPP -> L2TP server -> Default Profile.

Kamil
by ayufan
Mon Feb 25, 2013 8:30 pm
Forum: Beginner Basics
Topic: Issue with speed on RB751G-2HND
Replies: 16
Views: 4648

Re: Issue with speed on RB751G-2HND

Upgrade to 6.x. It offers much better performance in all areas. And yes, it's pretty much stable. I use it by myself for a few months.

Kamil
by ayufan
Tue Feb 12, 2013 4:31 pm
Forum: The Dude
Topic: Dude for Linux
Replies: 49
Views: 44757

Re: Dude for Linux

more people use windows than linux, it's a fact. we have very few requests like this, less than one per month. use Wine, it works perfect. i agree with you, most people use windows, but if RouterOS is linux based, and it support the dude server, how diffucult its to release a Dude server for linux?...
by ayufan
Mon Feb 11, 2013 6:15 pm
Forum: Scripting
Topic: Date arithmetic?
Replies: 11
Views: 5592

Re: Date arithmetic?

Here are some sample inputs and the resulting output/errors: > :put ([/system clock get date]) feb/06/2013 > :put ([/system clock get date]+"2d") Script Error: cannot add string to string > :put ([/system clock get date]+"2") Script Error: cannot add string to string > :put ([/s...
by ayufan
Sat Jan 26, 2013 2:36 pm
Forum: General
Topic: RB751G low throughput
Replies: 4
Views: 1835

Re: RB751G low throughput

RB751G will not ever get 500Mbps with NAT and forwarding.
by ayufan
Fri Dec 28, 2012 2:22 am
Forum: General
Topic: Problems virtualizing Mikrotik inside Proxmox
Replies: 2
Views: 1539

Re: Problems virtualizing Mikrotik inside Proxmox

You should try to use virtio devices, not the emulated ones.
by ayufan
Sun Dec 16, 2012 12:35 am
Forum: General
Topic: AR8327
Replies: 8
Views: 8632

Re: AR8327

Nope. No response from support. It is not possible on RouterOS and fairly simple on OpenWrt. So... :)
by ayufan
Mon Dec 03, 2012 11:50 pm
Forum: Beginner Basics
Topic: Bit torrent client force RB751 reboot in a while
Replies: 3
Views: 2551

Re: Bit torrent client force RB751 reboot in a while

Try replacing PSU. It should at least be 12V/1A. If it doesn't give enough power, router can reboot himself.
by ayufan
Sun Dec 02, 2012 3:52 pm
Forum: General
Topic: AR8327
Replies: 8
Views: 8632

AR8327

Why all devices (RB1100AH, RB1100AHx2, RB751G, RB2011) with AR8327 doesn't support port trunking? Just simple case, no hybrid ports: 1. one port as tagged 2. one or more ports as untagged Why there is limitation to one master port per switch group? I'm asking because this is definitely not hardware ...
by ayufan
Thu Nov 29, 2012 10:40 pm
Forum: General
Topic: 6.0rc4 released!
Replies: 101
Views: 26193

Re: 6.0rc4 released!

@hedele
It's there.
by ayufan
Mon Nov 05, 2012 6:14 pm
Forum: RouterBOARD hardware
Topic: RB751U-2hnd + 4G USB modem Huawei E392 low speed
Replies: 3
Views: 10844

Re: RB751U-2hnd + 4G USB modem Huawei E392 low speed

Send supout to support@mikrotik.com. Maybe they can help.
by ayufan
Fri Sep 21, 2012 12:10 pm
Forum: General
Topic: RouterOS v6 release candidate 1
Replies: 96
Views: 39802

Re: RouterOS v6 release candidate 1

Is usb sharing working?
by ayufan
Sun Sep 09, 2012 11:47 pm
Forum: General
Topic: WinBox Lite for Windows Phone 7.5 devices
Replies: 1
Views: 1487

WinBox Lite for Windows Phone 7.5 devices

I have created WinBox application for Windows Phone 7.5 device. More here: http://www.windowsphone.com/pl-PL/apps/ ... 39c0bd8399.
by ayufan
Thu Sep 06, 2012 12:52 am
Forum: General
Topic: Winbox dead in Windows 8
Replies: 13
Views: 9561

Re: Winbox dead in Windows 8

Nope. Everything works as expected since RP. Tried on RP x64 Pro and have it working on latest RTM x64 Pro. All versions are genuine.

Kamil
by ayufan
Tue Aug 21, 2012 11:17 am
Forum: Virtualization
Topic: Metarouter images
Replies: 378
Views: 387750

Re: Metarouter images

You have to mount:
mount /dev/mtd6block /mnt
or
mount /dev/mtd6 /mnt
by ayufan
Mon Aug 20, 2012 11:21 pm
Forum: Virtualization
Topic: Metarouter images
Replies: 378
Views: 387750

Re: Metarouter images

by ayufan
Mon Aug 20, 2012 9:10 pm
Forum: Virtualization
Topic: Metarouter images
Replies: 378
Views: 387750

Re: Metarouter images

I found an image that could netboot my RB450G (http://www.practicaltester.com/store/enlil/openwrt-backfire-1003-stock-ar71xx-vmlinux-initramfs.elf) , I am now in the search of voltage.ko . It would be great if you could provide me with its location. You can try to use my patched netinstall with my ...
by ayufan
Thu Aug 16, 2012 12:17 pm
Forum: General
Topic: Use API over Internet. It is secure?
Replies: 11
Views: 5531

Re: Use API over Internet. It is secure?

Note that even without an SSH tunnel, the RouterOS password is never sent in plain text. The whole procedure is a CHAP challenge, similarly to the one in hotspot. Without a tunnel, all other data is sent and received without any form of encryption though. Whole process uses md5 and someone may try ...
by ayufan
Thu Aug 16, 2012 12:31 am
Forum: General
Topic: Use API over Internet. It is secure?
Replies: 11
Views: 5531

Re: Use API over Internet. It is secure?

Exactly. SSH allows to forward connections both ways. You can always use following scenario: 1. MikroTik API a. ip service enable api b. ip service set api address=127.0.0.1/32 2. PHP Server a. ssh -L 28728:127.0.0.1:8728 <mt-address> - run in background or on screen b. connect to api on: 127.0.0.1:...
by ayufan
Wed Aug 15, 2012 10:11 pm
Forum: General
Topic: Use API over Internet. It is secure?
Replies: 11
Views: 5531

Re: Use API over Internet. It is secure?

Use ssh port forwarding in order to access local (or even remote) API interface. It should help with your security concerns.
by ayufan
Thu Jun 14, 2012 11:27 am
Forum: General
Topic: Feature Request: Please support enterprise virtualization.
Replies: 16
Views: 5034

Re: Feature Request: Please support enterprise virtualizatio

Could you tell me where i can get images for either of these please? Is there anywhere to install VMtools on the VM?
Use ISO to install on guest system. It is just easy as install on PC.
by ayufan
Wed Jun 13, 2012 4:55 pm
Forum: General
Topic: Feature Request: Please support enterprise virtualization.
Replies: 16
Views: 5034

Re: Feature Request: Please support enterprise virtualizatio

@Sanity: The only problem with Microsoft is: why in the end they only implemented some crappy legacy 100Mbps network adapter? why not some e1000 like any virtualization platform do have? Because they want to addict to you to use only theirs software. Hyper-V is good but not the best in performance/s...
by ayufan
Wed Jun 13, 2012 3:50 pm
Forum: General
Topic: VMware ROS, for VPN Server (PPTP/L2TP/SSTP) - viable?
Replies: 7
Views: 2848

Re: VMware ROS, for VPN Server (PPTP/L2TP/SSTP) - viable?

If anyone has been able to KVM ROS in any linux distro could you let me know as this is the only way around the issue I can think of but simply don't have the linux knowledge to do this. ROS in KVM works beatifully, because it includes integrated into kernel virtio drivers. These drivers allow to h...
by ayufan
Sun Jun 10, 2012 11:59 am
Forum: Virtualization
Topic: Hyper-V now totally broken?
Replies: 14
Views: 8309

Re: Hyper-V now totally broken?

Besides not being an answer - but totally useless - will you pay me the about 550 USD MONTHLY that it costs me to rent a second machine (100 USD), the colocation (400 USD) and the backend swtiching (50 USD) that I need to install a second machine in that particular data center? Like "Put your ...
by ayufan
Sun Jun 10, 2012 12:15 am
Forum: Virtualization
Topic: Hyper-V now totally broken?
Replies: 14
Views: 8309

Re: Hyper-V now totally broken?

Just install some linux box with KVM. You can try Proxmox VE - really amazing virtualization environment. Then you can freely install RouterOS and Windows box. RouterOS already has support for VirtIO drivers. Performance on top of such setup is amazing :)
by ayufan
Wed May 30, 2012 11:52 pm
Forum: General
Topic: phpmikbox - the web-based mikrotik management
Replies: 15
Views: 6114

Re: phpmikbox - the web-based mikrotik management

I'm interested in hearing about what problems/limitations people have with Webfig? It's certainly possible that someone could build a better alternative, but it would be a tall order...because Webfig can run natively on top of RouterOS, whereas any other web-based alternative that uses the ROS API ...
by ayufan
Wed May 30, 2012 9:01 pm
Forum: General
Topic: phpmikbox - the web-based mikrotik management
Replies: 15
Views: 6114

Re: phpmikbox - the web-based mikrotik management

Did you try webfig?
by ayufan
Thu May 03, 2012 5:47 pm
Forum: General
Topic: Which free dynamic DNS provider would you recommend?
Replies: 3
Views: 2658

Re: Which free dynamic DSN provider would you recommend?

Try http://freedns.afraid.org/ is definietly free and you can find my script for RouterOS on this forum.
by ayufan
Mon Apr 23, 2012 11:12 pm
Forum: General
Topic: [Feature Request] DNS Slave of a DNS Zone
Replies: 10
Views: 8719

Re: [Feature Request] DNS Slave of a DNS Zone

I think we should get full dns functionality. At least be able to modyfi SOA and add NS, TXT, PTR, CNAME records.
by ayufan
Wed Apr 18, 2012 11:55 pm
Forum: Scripting
Topic: Wget Afraid - FREEDNS script help
Replies: 17
Views: 18751

Re: Wget Afraid - FREEDNS script help

I use this simple own script. Just copy and run in command line. Than you have to update System/Scheduler script with your external interface and update key. This script gets ip address from pppoe-client interface. However, you can easily change that. /system scheduler add disabled=no interval=30s n...
by ayufan
Wed Apr 18, 2012 8:18 pm
Forum: General
Topic: Feature request: NS in static DNS
Replies: 37
Views: 15685

Re: Feature request: NS in static DNS

Howerver, using firewall rules you can simulate behavior of different zones: /ip firewall layer7-protocol add name=home.local regexp="\\x04home\\x05local" /ip firewall nat add action=dst-nat chain=dstnat comment=home.local disabled=no dst-port=53 \ layer7-protocol=home.local protocol=udp t...
by ayufan
Mon Apr 16, 2012 1:00 pm
Forum: General
Topic: Feature request: NS in static DNS
Replies: 37
Views: 15685

Re: Feature request: NS in static DNS

Such meetings never take place (where one feature is put against another). The reason is simple - our home routerboard models, such as RB751G are ideal for using as home file sharing servers. You keep your files there, for everyone else in the home to be able to use. Many other brand routers in thi...
by ayufan
Thu Apr 12, 2012 1:48 pm
Forum: The User Manager
Topic: Script to detect PPPoE Status change
Replies: 5
Views: 15709

Re: Script to detect PPPoE Status change

Just for future reference: / interface pppoe-client { :global ExternalIP :local clientip :local clientstatus monitor External once do={:set clientip $"local-address"; :set clientstatus $status} :if ($clientstatus="connected" and $ExternalIP!=$clientip) do={ :log info "Extern...
by ayufan
Thu Apr 12, 2012 12:56 am
Forum: RouterBOARD hardware
Topic: 751G-2HnD - Alternative Firmare
Replies: 2
Views: 1975

Re: 751G-2HnD - Alternative Firmare

I don't understand why ros sucks? OpenWrt is pretty stable for me, maybe your isp provider needs some special care to get pppoe working? After searching google I found a lot of similar problems to yours, maybe not exactly the same and not on openwrt.
by ayufan
Thu Apr 05, 2012 12:33 am
Forum: RouterBOARD hardware
Topic: 751G-2HnD - Alternative Firmare
Replies: 2
Views: 1975

Re: 751G-2HnD - Alternative Firmare

RB751G is awesome as hardware and works really well with OpenWrt. At home I run NAS with automatic backups and more ;)
by ayufan
Sat Mar 31, 2012 12:53 am
Forum: RouterBOARD hardware
Topic: 751G-2HnD - Alternative Firmare
Replies: 2
Views: 1975

Re: 751G-2HnD - Alternative Firmare

Yes. It's still WIP, but each day it gets better and better ;)

https://forum.openwrt.org/viewtopic.php?id=32320&p=2
by ayufan
Mon Mar 19, 2012 11:53 am
Forum: RouterBOARD hardware
Topic: OpenWRT on RB751
Replies: 4
Views: 8606

Re: OpenWRT on RB751

Great. I'll port them to new release. Just wait few days ;)
by ayufan
Mon Mar 12, 2012 2:31 pm
Forum: General
Topic: Feature: IPsec automatic generate policy security breach
Replies: 0
Views: 732

Feature: IPsec automatic generate policy security breach

Support Ticket: #2012031266000308 Could you allow to specify limits for automatic policy generation rules for IPsec? The most common case is to limit "main l2tp" mode policies only to point-to-point, udp and port 1701. The reason behind that is when the remote attacker knows PSK or has cer...
by ayufan
Fri Feb 10, 2012 1:06 am
Forum: RouterBOARD hardware
Topic: OpenWRT on RB751
Replies: 4
Views: 8606

Re: OpenWRT on RB751

Hi, I fixed patches to work with latest trunk release and added support for WLAN module. Device automatically creates OpenWrt 802.11ng access point and bridges it with LAN. I started working on RB751G-2HnD. However, still had no time to port new switch chip. At least you can connect through WLAN. RB...
by ayufan
Sat Dec 17, 2011 8:46 pm
Forum: General
Topic: MUM Europe 2012 in Poland
Replies: 88
Views: 23083

Re: MUM Europe 2012 in Poland

Presentation saved. Let's hope that will get selected ;)
by ayufan
Fri Dec 16, 2011 12:42 am
Forum: General
Topic: MUM Europe 2012 in Poland
Replies: 88
Views: 23083

Re: MUM Europe 2012 in Poland

Maybe I will make presentation? ;)
by ayufan
Fri Dec 09, 2011 11:24 am
Forum: General
Topic: insecure method to store passwords.
Replies: 5
Views: 2176

Re: insecure method to store passwords.

given enough time, any encryption can be cracked. so use also other methods of protection. normis you're funny ;) how can you say that passwords in routeros are encrypted? no they are not, if by encryption you mean simple xor, then it's not very nice... It wonders me who in your company made such f...
by ayufan
Thu Dec 08, 2011 4:58 pm
Forum: General
Topic: insecure method to store passwords.
Replies: 5
Views: 2176

Re: insecure method to store passwords.

Yes, we are. Problem was told many times before.
by ayufan
Mon Nov 21, 2011 12:34 pm
Forum: RouterBOARD hardware
Topic: RB1100AH - new product
Replies: 101
Views: 35876

Re: RB1100AH - new product

anyone has a benchmark of RB1100AH (no IPSec acceleration) IPSEC tunnel thruput?
i would be interested to compare against older (prototype) RB1100AH (with IPSec) - I could make ~400mbps with it.
I can make it for you later. What configuration?
by ayufan
Sun Nov 20, 2011 4:24 am
Forum: Virtualization
Topic: Metarouter with http, php and sqlite?
Replies: 16
Views: 6827

Re: Metarouter with http, php and sqlite?

You can try making swap file disk. It should help somehow.
by ayufan
Sun Nov 20, 2011 1:28 am
Forum: Virtualization
Topic: Metarouter with http, php and sqlite?
Replies: 16
Views: 6827

Re: Metarouter with http, php and sqlite?

Unfortunately, if I don't find a stable fix for this in the next couple of weeks, I will be shelving the project or moving on to a different hardware platform. Most probably problem is due to small memory footprint (12MB for openwrt is very small). When I was working with OpenWRT 12MB wasn't suffic...
by ayufan
Fri Nov 18, 2011 5:13 pm
Forum: Virtualization
Topic: Metarouter with http, php and sqlite?
Replies: 16
Views: 6827

Re: Metarouter with http, php and sqlite?

Nice. It's pity that RB751U doesn't have more memory, like 48MB or even 64MB. Also It would be nice to have USB sharing to MR. It would make ideal home router with RouterOS as base and OpenWRT as data storage and usb printer sharing.
by ayufan
Fri Nov 18, 2011 3:26 pm
Forum: Virtualization
Topic: Metarouter with http, php and sqlite?
Replies: 16
Views: 6827

Re: Metarouter with http, php and sqlite?

Which packages do you have enabled on ROS? How much memory did you assign to MR? Did you consider making some tutorial?
by ayufan
Fri Nov 18, 2011 2:53 am
Forum: Virtualization
Topic: Metarouter with http, php and sqlite?
Replies: 16
Views: 6827

Re: Metarouter with http, php and sqlite?

It is VERY touchy. You will have to make your own image and really work with it. I've been messing with it for a few days on a RB751 with a small web server and PHP. I may have finally gotten a stable version. I have been keeping some notes as I worked on it and may try to contribute to the wiki if...
by ayufan
Tue Nov 15, 2011 6:45 pm
Forum: General
Topic: OpenVPN - TCP
Replies: 8
Views: 3202

Re: OpenVPN - TCP

no, and no
by ayufan
Thu Nov 03, 2011 3:02 pm
Forum: General
Topic: Dynamic rules
Replies: 4
Views: 3187

Re: Dynamic rules

Clipboard01.gif 1 million writes is too high for 6d uptime. the only reason for writes on this router (I don't believe that graphing with 24h saving period can affect 1 million) is adding/deleting of Address List items. if we can add dynamic entries (so that it won't affect disk), we could decrease...
by ayufan
Mon Oct 31, 2011 6:30 pm
Forum: General
Topic: V5.X is the most bugged version, and the V6.X as it will be?
Replies: 6
Views: 1499

Re: V5.X is the most bugged version, and the V6.X as it will

5.7 on 493G is having CPU issues when hotspot server is setup. DHCP takes %40 CPU and overall is reaching %100 all the time.
There was problem with DHCP server on disconnected/disabled interfaces. Ask support and you will get 5.8 prerelase.
by ayufan
Mon Oct 31, 2011 4:21 pm
Forum: General
Topic: V5.X is the most bugged version, and the V6.X as it will be?
Replies: 6
Views: 1499

Re: V5.X is the most bugged version, and the V6.X as it will

Please improve the quality of RouterOS he is very unstable in all aspects.
Can You describe why? I have been using 5.x for few months without many major issues.
by ayufan
Sun Oct 23, 2011 6:14 pm
Forum: General
Topic: Dynamic rules
Replies: 4
Views: 3187

Dynamic rules

Allow to create through winbox, webfig or api an dynamic firewall rules, dynamic queues, etc. It should work the same way like rules created by connecting ppp client or dhcp lease. We should consider rules like that an non saveable - they should disapper after reboot. Why I need that? For example to...
by ayufan
Thu Oct 13, 2011 1:56 am
Forum: RouterBOARD hardware
Topic: RB751
Replies: 73
Views: 26204

Re: RB751

to make life harder :)
by ayufan
Sun Oct 09, 2011 3:29 pm
Forum: RouterBOARD hardware
Topic: OpenWRT on RB751
Replies: 4
Views: 8606

OpenWRT on RB751

I've made small patch for backfire and trunk which adds support for new MikroTik RB751. I tested and everything except wireless works. I haven't been playing a lot with wireless, so most likely is just selection of valid drivers. Patches can be found here: http://ayufan.eu/local/rb751/ Also there's ...
by ayufan
Mon Sep 26, 2011 2:42 am
Forum: RouterBOARD hardware
Topic: Availability of the RB751G
Replies: 99
Views: 28752

Re: Availability of the RB751G

Will RB751G have USB port? And will have more than 32MB RAM? I need Metarouter.
by ayufan
Tue Aug 16, 2011 7:45 pm
Forum: General
Topic: New Made for MikroTik Product, RB750C
Replies: 3
Views: 2629

Re: New Made for MikroTik Product, RB750C

Nice ;)
by ayufan
Thu Aug 11, 2011 10:56 pm
Forum: RouterBOARD hardware
Topic: Which Routerboard for small office routing?
Replies: 5
Views: 2107

Re: Which Routerboard for small office routing?

ekhoo: it should be noted that using RB750GL don't expect to have ipsec performance better than 8-10Mbps.
by ayufan
Tue Jul 26, 2011 1:03 am
Forum: Virtualization
Topic: Virtualized RouterOS CPU usage
Replies: 9
Views: 6461

Re: Virtualized RouterOS CPU usage

Looks good. Try to virtualize two routers, run bandwidth test between them and post results.
by ayufan
Mon Jul 25, 2011 11:29 pm
Forum: Virtualization
Topic: Virtualized RouterOS CPU usage
Replies: 9
Views: 6461

Re: Virtualized RouterOS CPU usage

I try to use "virtio" (not RTL8139) to have gigabit ethernet, but is the same CPU usage.
Is a mistake to use vlan?
Yes. I'm exactly talking about virtio. Show us from virtualized RouterOS:

/ system resource irq print
by ayufan
Mon Jul 25, 2011 11:04 pm
Forum: Virtualization
Topic: Virtualized RouterOS CPU usage
Replies: 9
Views: 6461

Re: Virtualized RouterOS CPU usage

Instead of emulated nics and block devices try to use virt-based. I got about 6 to 8x better network performance.
by ayufan
Fri Jul 22, 2011 11:29 am
Forum: General
Topic: IPSEC performance MD5 vs SHA
Replies: 6
Views: 6641

Re: IPSEC performance MD5 vs SHA

That rules out 1) and 3) (slower but not terribly) and leaves '2) sha-1 hashing algorithm implementation used is badly optimized for mipsbe' ? It may be. I did test on x86 and difference is not that large. [ayufan@neutron ~] $ openssl speed md5 sha1 OpenSSL 0.9.8o 01 Jun 2010 built on: Thu Feb 10 2...
by ayufan
Fri Jul 22, 2011 1:18 am
Forum: General
Topic: Webfig encryption over HTTP?? How does that work??
Replies: 2
Views: 2326

Re: Webfig encryption over HTTP?? How does that work??

It seems that uses some combination of sha1 hmac as key for rc4 encryptor. For more see http://<router-ip>/webfig/engine.js with sth like this: http://jsbeautifier.org/.
by ayufan
Fri Jul 22, 2011 1:06 am
Forum: General
Topic: IPSEC performance MD5 vs SHA
Replies: 6
Views: 6641

Re: IPSEC performance MD5 vs SHA

Please see attached performance comparision of RB450 and RB450G using openssl test:
http://open-wrt.ru/forum/viewtopic.php?id=22323
by ayufan
Tue Jul 05, 2011 2:17 pm
Forum: RouterBOARD hardware
Topic: OmniTIK and RB711-2n
Replies: 114
Views: 63973

Re: OmniTIK and RB711-2n

normis when we can expect any of RB751?
by ayufan
Thu Jun 30, 2011 2:32 pm
Forum: General
Topic: TACACS
Replies: 4
Views: 7070

Re: TACACS

use radius
by ayufan
Fri Jun 03, 2011 12:19 am
Forum: General
Topic: [SOLVED]An Interesting Challenge... ~or~ Choking Youtube...
Replies: 6
Views: 4059

Re: An Interesting Challenge... ~or~ Choking Youtube Videos

Find packets with content-type: video by using layer7 processing. Then mark connections as "video" and shape them ;)
by ayufan
Wed May 18, 2011 12:57 am
Forum: General
Topic: Shocking performance RB450G as bridge.
Replies: 7
Views: 3258

Re: Shocking performance RB450G as bridge.

On my X86 core router after upgrade to 5.2 from 4.17 I see a lot of rx drops and much higher cpu usage (mostly two times larger) so definietly is something wrong...
by ayufan
Mon Mar 28, 2011 12:04 am
Forum: General
Topic: No NetCut In Mikrotik any more [easy solution]
Replies: 13
Views: 15933

Re: No NetCut In Mikrotik any more [easy solution]

It's the same behaviour as when you specify Netmask as 32. (Netmask 32 - will block all client-to-client connectivity). And yes it does work only on Windows. On Linux and other Unixes an interface addresses have to be configured statically or dhcp-client has to ignore gateway IP taken from server.
by ayufan
Mon Mar 21, 2011 2:34 am
Forum: General
Topic: I need DATABASE for Status page in MIKROTK
Replies: 3
Views: 1278

Re: I need DATABASE for Status page in MIKROTK

Oh my good. Your english is worse than mine ;) About "the database" i think is not possible, because RouterOS is just router software. The same reply you'll probably get from support.
by ayufan
Thu Mar 10, 2011 2:09 pm
Forum: General
Topic: MUM Hungary newsletter "TEASER"
Replies: 44
Views: 12230

Re: MUM Hungary newsletter "TEASER"

RB751G
RB1100AHx2
release date?
by ayufan
Sun Jan 09, 2011 6:00 pm
Forum: Virtualization
Topic: KVM and "unsupported pcu"
Replies: 5
Views: 3739

Re: KVM and "unsupported pcu"

You need processor with hardware virtualization support, eg. VT-X, AMD-V.
by ayufan
Thu Dec 16, 2010 11:24 am
Forum: General
Topic: Remote scan (site survey)
Replies: 3
Views: 2042

Re: Remote scan (site survey)

You can use my PHP API class which is able to perform remote scan and post results:

http://wiki.mikrotik.com/wiki/RouterOS_PHP_class

Search for function: function scan($id, $duration="00:02:00", $callback = FALSE)

Kamil
by ayufan
Mon Dec 13, 2010 6:21 pm
Forum: General
Topic: Accidentally Locked myself from the router.
Replies: 6
Views: 2161

Re: Accidentally Locked myself from the router.

If only there were safe mode support in API and WinBox it would be really great!
by ayufan
Sun Dec 12, 2010 8:27 pm
Forum: General
Topic: Accidentally Locked myself from the router.
Replies: 6
Views: 2161

Re: Accidentally Locked myself from the router.

use mac telnet, you need to have layer 2 access to router
by ayufan
Fri Dec 03, 2010 9:56 pm
Forum: General
Topic: RouterOS v5.0 RC5
Replies: 41
Views: 11416

Re: RouterOS v5.0 RC5

Hi,
KVM isnt work with Intel E8400 cpu.
Yes, you are right, because E8400 doesn't support hardware wirtualization (VT-x). Change CPU to VT-x capable and KVM will work.
by ayufan
Mon Nov 29, 2010 2:58 pm
Forum: General
Topic: RouterOS v5.0 RC4
Replies: 72
Views: 21072

Re: RouterOS v5.0 RC4

edit: or check your your virtual machine ( as i suspect it could be) try to set other type of interface. I can confirm that 5.0 doesn't work on Hyper-V while 4.x works. Regarding changing interface type. There are only two: - legacy network adapter - emulates network device, uses drivers included i...
by ayufan
Tue Nov 23, 2010 12:59 am
Forum: General
Topic: RouterOS v5.0 RC4
Replies: 72
Views: 21072

Re: RouterOS v5.0 RC4

Yay! Torch fixed!
by ayufan
Wed Nov 17, 2010 12:51 am
Forum: General
Topic: How many IPSEC tunnels can an RB532 handle?
Replies: 2
Views: 1416

Re: How many IPSEC tunnels can an RB532 handle?

There is no limit in number of tunnels, but from my expirence traffic which can be passed through tunnels (on all RB's excluding 1000 and 1100) is relatively small and this is the main limit.
by ayufan
Thu Oct 28, 2010 3:29 am
Forum: General
Topic: RouterOS v5 RC2
Replies: 91
Views: 22278

Re: RouterOS v5 RC2

Yep. From my laptop behind NAT.
I did test it a minute ago and it doesn't work. Neither with nat-t enabled nor disabled ;)
by ayufan
Wed Oct 27, 2010 11:02 pm
Forum: General
Topic: RouterOS v5 RC2
Replies: 91
Views: 22278

Re: RouterOS v5 RC2

I just tried it with a PSK and it worked on my Win7 laptop., Dunno about WinXP. But that is a step in the right direction. Gotta try it with multiple clients/certificates next.
Did you try behind NAT?
by ayufan
Wed Oct 27, 2010 9:20 pm
Forum: General
Topic: RouterOS v5 RC2
Replies: 91
Views: 22278

Re: RouterOS v5 RC2

- bug in torch still present
- nat-t not working with windows xp
by ayufan
Wed Oct 27, 2010 7:05 pm
Forum: General
Topic: RouterOS v4.12 released - comment
Replies: 12
Views: 3267

Re: RouterOS v4.12 released - comment

there's also a firmware upgrade ... at least in the mipsbe
because of new device: RB493G.
by ayufan
Mon Oct 04, 2010 5:31 am
Forum: Wireless Networking
Topic: CQQ=100% but extensive data los - why ?
Replies: 14
Views: 4045

Re: CQQ=100% but extensive data los - why ?

It's done by wireless hardware.
by ayufan
Thu Sep 30, 2010 1:30 am
Forum: Wireless Networking
Topic: CQQ=100% but extensive data los - why ?
Replies: 14
Views: 4045

Re: CQQ=100% but extensive data los - why ?

"Small" loss on VoIP is not a problem as long as you have low jitter.
by ayufan
Wed Sep 29, 2010 10:01 am
Forum: Wireless Networking
Topic: CQQ=100% but extensive data los - why ?
Replies: 14
Views: 4045

Re: CQQ=100% but extensive data los - why ?

3% is safe to work just ok, on wireless links is not that much. Also take in account that you send MTU sized packets, so you check full duplex connectivity ;)
by ayufan
Wed Sep 29, 2010 9:59 am
Forum: General
Topic: feature request : GRE tunnel
Replies: 56
Views: 33535

Re: feature request : GRE tunnel

Normis, Sergejs can You check my ticket status?
[Ticket#2010092166000418] Broken GRE in RC1

I got no reply for a past few days ;)

Kamil
by ayufan
Tue Sep 28, 2010 12:44 pm
Forum: Wireless Networking
Topic: CQQ=100% but extensive data los - why ?
Replies: 14
Views: 4045

Re: CQQ=100% but extensive data los - why ?

SCAN FREQ USE CHANNEL <0~3% - CQQ-100%!!! Mikrotik it's **it, isn't suited for hardware solution. Because CCQ=100% when link is idle is not valid measurement of link quality. That's why I test it from linux: ping -f -s 1400 <ip_address_of_device_on_the_other_side> Stable and efficient link should h...
by ayufan
Sun Sep 26, 2010 2:25 am
Forum: General
Topic: UPnP security options?
Replies: 2
Views: 1986

Re: UPnP security options?

Maybe setting up a config so that UPnP cannot allocate ports below 1024. Ip tracking on what ports were requested at what time and when they were released. IP mask blocking, etc. From what I see UPnP dynamic rules are placed as last in dstnat chain. So You can insert some accept or drop rule before...
by ayufan
Sat Sep 25, 2010 4:32 am
Forum: General
Topic: MK v5 rc1 - bug torch
Replies: 33
Views: 10916

Re: MK v5 rc1 - bug torch

Wow, thanks for that. I didn't expect sha1 vs md5 to make such a huge difference. sha1 is generally slower, but not by a factor of 5. Running checksums on 50MB test file with random data with OpenSSL (so disk IO routines etc are probably the same) have sha1 about 50% slower. Not that that's a parti...
by ayufan
Sat Sep 25, 2010 4:24 am
Forum: Scripting
Topic: Automatically provisioning RBs
Replies: 8
Views: 12609

Re: Automatically provisioning RBs

NAB for my network I'm using my own rosapi. ROSAPI allows to perform configuration synchronization. It mirrors local config stored on main server to devices. ROSAPI allows you to define in script a php function. Function can build a configuration for device using data stored in database. In my setup...
by ayufan
Fri Sep 24, 2010 10:13 pm
Forum: RouterBOARD hardware
Topic: OpenWRT for Routerboard
Replies: 30
Views: 11098

Re: OpenWRT for Routerboard

Can you clarify this ? Is router OS only Linux based, is it OpenWRT based, or is it fully proprietary ? RouterOS is special linux based operating system, and definietly not OpenWRT. It uses own linux kernel (with external kernel modules) and BusyBox compilation. Rest of applications is written or m...
by ayufan
Fri Sep 24, 2010 4:13 am
Forum: General
Topic: MK v5 rc1 - bug torch
Replies: 33
Views: 10916

Re: MK v5 rc1 - bug torch

md5,null - 20Mbps md5,des - 12.5Mbps md5,3des - 6Mbps md5,aes-128 - 15Mbps md5,aes-192 - 14Mbps md5,aes-256 - 13Mbps sha1,null - 2.5Mbps sha1,des - 2Mbps sha1,3des - 1.5Mbps sha1,aes-128 - 2Mbps sha1,aes-192 - 2Mbps sha1,aes-256 - 2Mbps null,null - not working null,des - 13Mbps null,3ds - 5Mbps null...
by ayufan
Fri Sep 24, 2010 3:18 am
Forum: General
Topic: MK v5 rc1 - bug torch
Replies: 33
Views: 10916

Re: MK v5 rc1 - bug torch

I'm suprised, your screenshot shows RB750.
What is your IPSec and Ethernet ports config?
md5, des.
by ayufan
Fri Sep 24, 2010 1:53 am
Forum: General
Topic: MK v5 rc1 - bug torch
Replies: 33
Views: 10916

Re: MK v5 rc1 - bug torch

It shows your CPU usage is %100
maybe it is the causes
plz retry after reboot
That is not a problem. The time when I made screenshot, through router was going heavy ipsec (15Mbps) traffic :)

Kamil
by ayufan
Thu Sep 23, 2010 6:09 am
Forum: General
Topic: MK v5 rc1 - bug torch
Replies: 33
Views: 10916

Re: MK v5 rc1 - bug torch

TOTALLY UPD: yes, I can confirm such behaviour on x86. RBs don't repeat that =)
Image
by ayufan
Wed Sep 22, 2010 12:37 pm
Forum: General
Topic: MK v5 rc1 - bug torch
Replies: 33
Views: 10916

Re: MK v5 rc1 - bug torch

Image

Uploaded with ImageShack.us
by ayufan
Wed Sep 22, 2010 12:15 pm
Forum: General
Topic: MK v5 rc1 - bug torch
Replies: 33
Views: 10916

Re: MK v5 rc1 - bug torch

Normis, yes it works on base installation (installed on VMware) but not on production router.

Kamil
by ayufan
Tue Sep 21, 2010 2:34 am
Forum: General
Topic: RouterOS v5 RC1
Replies: 82
Views: 25745

Re: RouterOS v5 RC1

There is a few bugs. IMHO is to early to deploy this version in production environment. Somehow I'm dissapointed with that RC1 it should be beta7.
by ayufan
Fri Sep 10, 2010 4:10 pm
Forum: General
Topic: feature request : GRE tunnel
Replies: 56
Views: 33535

Re: feature request : GRE tunnel

As did I see on demo.mt.lv there is keepalive support.

normis: When we can expect 5.0beta7?
by ayufan
Wed Sep 08, 2010 10:50 am
Forum: General
Topic: feature request : GRE tunnel
Replies: 56
Views: 33535

Re: feature request : GRE tunnel

finally... so we waiting for new release ;)
by ayufan
Tue Aug 24, 2010 2:01 am
Forum: General
Topic: Mikrotik Management for iPhone Available Now
Replies: 141
Views: 38005

Re: Mikrotik Management for iPhone Available Now

Email me with the email address you used before as a beta tester. Tell me what you liked/disliked about the app and Ill send you a promo code. For the crashes... Yes I would like details on how you made the app crash. If I can recreate it I will definitely fix it for ya. PM me on these boards about...
by ayufan
Thu Aug 05, 2010 5:28 pm
Forum: General
Topic: RouterOS and GRE tap tunnels (aka eoip)
Replies: 6
Views: 4685

Re: RouterOS and GRE tap tunnels (aka eoip)

EoIP works only between two MikroTik routers.

When we add support for pure GRE, then you will be able to make this.
You will? Oh sh*t ;) ETA?
by ayufan
Sun Jul 18, 2010 2:14 am
Forum: Wireless Networking
Topic: WDS performance and best practices
Replies: 11
Views: 8215

Re: WDS performance and best practices

@ayufan: Is it broken only with n cards, or the cost of using it is always that high, no matter what type of cards you use? And, why is the cost so gigh, how does it work, that it is that ineffective?
Only with n. It was pointed by MikroTik some time ago.
by ayufan
Sun Jul 18, 2010 2:12 am
Forum: Scripting
Topic: RouterOS PHP API class
Replies: 36
Views: 16609

Re: RouterOS PHP API class

the source of class has 404 (not found). Where i can find this php class?

M.
Fixed. Try now.
by ayufan
Wed Jul 14, 2010 9:32 pm
Forum: Wireless Networking
Topic: WDS performance and best practices
Replies: 11
Views: 8215

Re: WDS performance and best practices

WDS is somehow broken with n-cards. Try using ap-bridge with station and in top of that use EoIP or VPLS.
by ayufan
Fri Jul 09, 2010 1:01 pm
Forum: RouterBOARD hardware
Topic: Default configuration on RB750
Replies: 27
Views: 18501

Re: Default configuration on RB750

If I could get a wireless RB750 for less than $100 US, I would probably end up buying 10 or 12 a year, just in my little corner of the world.
working on it
any ETA? i would like to buy too :)
by ayufan
Tue Jul 06, 2010 10:43 am
Forum: RouterBOARD hardware
Topic: RB1100 IPSec 3DES perfomance
Replies: 6
Views: 2411

Re: RB1100 IPSec 3DES perfomance

o rely? RB1100?
by ayufan
Mon Jun 28, 2010 5:32 pm
Forum: Beginner Basics
Topic: RouterOS 3.6 password recovery
Replies: 3
Views: 1476

Re: RouterOS 3.6 password recovery

Hi, I have a x86 board running routerOS 3.6 this was taken out of a site where the company who installed it went bust, I don't have the login username or password. Is there any way of getting the password from the CF card when reading it in linux. idealy I would like the configuration and or the li...
by ayufan
Sun Jun 27, 2010 6:44 pm
Forum: General
Topic: feature request : GRE tunnel
Replies: 56
Views: 33535

Re: feature request : GRE tunnel

After fighting more interconnections with GGSN's I had to revert to another CISCO (damn)....

Guys, GRE support (as in direct GRE tunnel compatible with Cisco) would be a life saver....
Most probably they won't add support for pure GRE, because it will confilct with current implementation of EoIP.
by ayufan
Sat Jun 26, 2010 12:03 pm
Forum: General
Topic: RB750 and IPsec throughtput
Replies: 9
Views: 3553

Re: RB750 and IPsec throughtput

On RB750 I got about 8Mbps half-duplex using md5 and des for sha and 3des it will be about 4Mbps - CPU usage 100%. On RB450G I got about 10Mbps half-duplex using sha and 3des - CPU usage 100%. On x86 with Celeron M 600Mhz I got about 10Mbps half-duplex using sha and 3des with cpu usage around 50%. ...
by ayufan
Thu Jun 24, 2010 2:05 am
Forum: General
Topic: IPSEC and NAT-T problem
Replies: 60
Views: 58609

Re: IPSEC and NAT-T problem

The main MikroTik problem is that, they make something good, and astonishing but in the end that new thing doesn't have a "final touch", I mean that we can say is "finished" and ready to be used in production environment.
by ayufan
Tue Jun 22, 2010 4:12 pm
Forum: General
Topic: IPSEC and NAT-T problem
Replies: 60
Views: 58609

Re: IPSEC and NAT-T problem

My preference would be IPSEC/L2TP and that was my plan all along, but it never worked properly in ROS.
Exactly and it is very dissapointing, because there is none properly implemented and fast remote access solution on RouterOS.
by ayufan
Tue Jun 22, 2010 2:17 pm
Forum: General
Topic: IPSEC and NAT-T problem
Replies: 60
Views: 58609

Re: IPSEC and NAT-T problem

Hope it will get fixed soon.
I've written to support about that bug long time ago. Most likely it will not be fixed in any near future. In fact it makes L2TP useless - I had to switch L2TP+IPsec to Windows Server and works without any problem.

Kamil.
by ayufan
Thu May 27, 2010 12:04 am
Forum: General
Topic: IPSec VPN tunnels unstable in RouterOS 3.31?
Replies: 2
Views: 1869

Re: IPSec VPN tunnels unstable in RouterOS 3.31?

1) Check that you have the same lifetime on each router.
2) Try to netwach hosts and flush-sa when host is down.
by ayufan
Mon May 24, 2010 11:13 pm
Forum: Beginner Basics
Topic: RB 450G is hot?
Replies: 35
Views: 24644

Re: RB 450G is hot?

Mine is 68oC in server room... :)
by ayufan
Sat May 22, 2010 6:57 pm
Forum: General
Topic: Lightest VPN for RB450G
Replies: 5
Views: 2939

Re: Lightest VPN for RB450G

Reducing down MTU is not good idea it will not get you down cpu usage. You will see connectivity problems - packet drops.
by ayufan
Wed May 19, 2010 5:35 pm
Forum: General
Topic: feature request : GRE tunnel
Replies: 56
Views: 33535

Re: feature request : GRE tunnel

any news about GRE?
by ayufan
Wed May 05, 2010 1:45 pm
Forum: Scripting
Topic: RouterOS PHP API class
Replies: 36
Views: 16609

Re: RouterOS PHP API class

If any of You produce something useful derived from my scripts - please share it with community ;)
I would be very aprreciated.

Kamil
by ayufan
Thu Apr 29, 2010 7:41 pm
Forum: Scripting
Topic: RouterOS PHP API class
Replies: 36
Views: 16609

Re: RouterOS PHP API class

I didn't have any problem with my PHP API class. I have been using it for about 1 year with simple features as well as with differencing synchronization.
by ayufan
Thu Apr 01, 2010 2:37 pm
Forum: General
Topic: 5.0beta1
Replies: 10
Views: 3186

Re: 5.0beta1

it's turned on by default

check in submenu: / ip ssh
by ayufan
Tue Mar 30, 2010 12:39 pm
Forum: Scripting
Topic: RouterOS PHP API class
Replies: 36
Views: 16609

Re: RouterOS PHP API class

I do have the same problem with 3.28. With never versions everything is OK. If you use connection for example in function: function do_sth() { $conn = RotuerOS::connect("192.168.1.1", "admin", ""); $conn->getall("/interface/wireless"); } PHP will automatically...
by ayufan
Tue Mar 30, 2010 12:37 pm
Forum: General
Topic: ROS v5
Replies: 105
Views: 29684

Re: ROS v5

WOW! WebFig is impressive check this out: http://demo2.mt.lv/webfig/#Wireless.Access-List

Kamil :)
by ayufan
Wed Mar 24, 2010 1:54 am
Forum: Scripting
Topic: RouterOS PHP API class
Replies: 36
Views: 16609

Re: RouterOS PHP API class

for now there is no disconnect method, php recycles all sockets when finishes.
by ayufan
Mon Mar 22, 2010 1:53 pm
Forum: Scripting
Topic: RouterOS PHP API class
Replies: 36
Views: 16609

Re: RouterOS PHP API class

I know that, I use it to, to manage many routerboards :)
Latest version is always on SVN. Check Logs to see what changed.

Updated my original posts and added doxygen documentation.

Kamil
by ayufan
Wed Mar 17, 2010 1:45 pm
Forum: General
Topic: ROS v5
Replies: 105
Views: 29684

Re: ROS v5

yes, the webfig has an issue, we fixed it in the next build.
Is there a new version with webfig fixed? :0
by ayufan
Tue Mar 16, 2010 12:11 pm
Forum: General
Topic: ROS v5
Replies: 105
Views: 29684

Re: ROS v5

don't forget that ending slash. works for me in same browser
did not forget ;)

Browser got 404 for: http://192.168.88.66/webfig/roteros.jg
by ayufan
Tue Mar 16, 2010 11:46 am
Forum: General
Topic: ROS v5
Replies: 105
Views: 29684

Re: ROS v5

did you install it :D ?
I'm pretty sure that I did ;)

After entering address in FireFox I see "WebFig Beta" and browser keeps refreshing over and over...

I use FF 3.6
by ayufan
Mon Mar 15, 2010 7:51 pm
Forum: General
Topic: ROS v5
Replies: 105
Views: 29684

Re: ROS v5

Interesting. I got this new pre-release version, but I can't see anything new: like the webbox or ssh forwarding ;)
by ayufan
Thu Mar 04, 2010 7:09 pm
Forum: General
Topic: Package Combiner
Replies: 2
Views: 1061

Re: Package Combiner

http://ayufan.eu/local/combiner/download there is a script I use to download releases. Script is run from local package directory :)

Integrations with other systems are prohibited. Script should be only available from my server!
by ayufan
Thu Mar 04, 2010 1:02 am
Forum: General
Topic: Package Combiner
Replies: 2
Views: 1061

Package Combiner

Hi,

I've made package combiner tool. Allows to create one combined package from custom packages. It doesn't change packages context it simply merges them into one :) Use it at your own risk!

Go there: http://ayufan.eu/local/combiner

Kamil
by ayufan
Thu Feb 25, 2010 5:15 pm
Forum: Beginner Basics
Topic: Max number of VPN IPSec tunnels
Replies: 3
Views: 4794

Re: Max number of VPN IPSec tunnels

from my expirence RB750 can handle up to 9-10Mbps half duplex ;) it's quite small... :)
by ayufan
Thu Feb 25, 2010 12:57 pm
Forum: General
Topic: MUM PL is here
Replies: 11
Views: 1498

Re: MUM PL is here

because he is not the user! :D
by ayufan
Thu Feb 25, 2010 12:36 pm
Forum: General
Topic: Establishing VPN IPSEC with Cisco PIX 7.2.3
Replies: 5
Views: 2552

Re: Establishing VPN IPSEC with Cisco PIX 7.2.3

1) first move srcnat accept rules before masq rule
2) add explicit route with dst-address: 10.10.0.0/16 and your gateway and pref-src of your router from lan side on wan interface, that way i should be able to ping other hosts from your mikrotik
by ayufan
Fri Feb 19, 2010 8:08 pm
Forum: General
Topic: IPSEC and NAT-T problem
Replies: 60
Views: 58609

Re: IPSEC and NAT-T problem

michalciza2, are you able to establish the connect, when host is not behind the NAT?
I do have that same problem when client has public IP it works like charm but when client is not it's stuck in trying to connect to L2TP server.

Kamil
by ayufan
Wed Feb 17, 2010 3:24 am
Forum: General
Topic: MUM Poland 2010 thread
Replies: 113
Views: 32794

Re: PL MUM HOTEL PRICE (sticky please)

in Wroclaw you can find without any problem hostel for about 40-50zl for a night without breakfast ;)
by ayufan
Mon Feb 15, 2010 1:42 pm
Forum: Scripting
Topic: API In C++ Wikied
Replies: 11
Views: 3598

Re: API In C++ Wikied

will it be 3 packets first one with length of command, then command itself and then terminating zero or i am mistaken? it's undefined because socket for tcp connections have receive and send buffer where data is accumulated, so if you invoke 3 times `send` doesn't really mean that there will be 3 p...
by ayufan
Sun Feb 14, 2010 9:36 pm
Forum: Scripting
Topic: API In C++ Wikied
Replies: 11
Views: 3598

Re: API In C++ Wikied

It's almost as good as it should be :) #define NONE 0 #define DONE 1 #define TRAP 2 #define FATAL 3 - change to enumeration - functions like Print, GetMap, Length - all that don't make object context change should be marked as const std::string operator[](int index) { return strWords[index]; } std::...
by ayufan
Sat Feb 13, 2010 12:01 pm
Forum: Scripting
Topic: API In C++ Wikied
Replies: 11
Views: 3598

Re: API In C++ Wikied

Better, but have my ideas: - InitializeSentence, ClearSentence should be removed this is done by ctor and dtor of Sentence class - AddWordToSentence should be method of Sentence class - the same applies to InitializeBlock, ClearBlock - Why there is wordCount and sentenceCount? You have vector length...
by ayufan
Tue Feb 09, 2010 3:08 am
Forum: Scripting
Topic: API In C++ Wikied
Replies: 11
Views: 3598

Re: API In C++ Wikied

Someone should write using "real" C++. Any use of STL (vector, map and string) and even BOOST (async io) would be appreciated and less error-prone ;)
by ayufan
Thu Jan 21, 2010 1:03 pm
Forum: General
Topic: 4 kernels, and work only one!!!
Replies: 12
Views: 3128

Re: 4 kernels, and work only one!!!

One process can use only one core
one process can use many cores with many threads, but one thread can use only one
by ayufan
Thu Jan 21, 2010 12:56 pm
Forum: General
Topic: 4 kernels, and work only one!!!
Replies: 12
Views: 3128

Re: 4 kernels, and work only one!!!

olmi: You can try using "virtual load balancing". Use kvm to create four virtual RouterOS machines where each terminates your tunnels. Then create firewall nat rule which will load balance connections between virtual machines. That way You will be able to use all four cores because each co...
by ayufan
Thu Jan 14, 2010 2:56 am
Forum: General
Topic: feature request : GRE tunnel
Replies: 56
Views: 33535

Re: feature request : GRE tunnel

So what about GRE tunnels? It shouldn't be so hard because is already in kernel source as well as ipip.
by ayufan
Tue Jan 12, 2010 4:22 pm
Forum: Virtualization
Topic: Centos install on KVM
Replies: 54
Views: 31276

Re: Centos install on KVM

use kernel and initrd distributed with installation image
by ayufan
Fri Dec 18, 2009 1:44 pm
Forum: Virtualization
Topic: RB750 is Meta router even possible?
Replies: 5
Views: 4973

Re: RB750 is Meta router even possible?

Create page on server that controls router through API ;)
by ayufan
Tue Dec 08, 2009 2:00 pm
Forum: Wireless Networking
Topic: Wireless channel assignment
Replies: 1
Views: 928

Re: Wireless channel assignment

No one?
by ayufan
Mon Dec 07, 2009 3:04 pm
Forum: Wireless Networking
Topic: Wireless channel assignment
Replies: 1
Views: 928

Wireless channel assignment

Hi, Recently I started working on alghorithm that tries to minimise 2.4GHz channel interference based on signal levels, frequency usage and selected modulations and started looking for materials. Do anyone have any? How alghorithm like that should work? What I've found so far: [1] Effect of adjacent...
by ayufan
Tue Dec 01, 2009 3:57 pm
Forum: Scripting
Topic: RouterOS PHP API class
Replies: 36
Views: 16609

Re: RouterOS PHP API class

I've made my http://ayufan.eu/local/src/rosapi/trunk/btest_example.php even more powerful. It's script that can run many simultaneous bandwidth-tests. It's supports only transmit mechanism, because there is a bug with btest that you cant specify different receive and transmit limits. It can be used ...
by ayufan
Tue Dec 01, 2009 12:46 am
Forum: Scripting
Topic: RouterOS PHP API class
Replies: 36
Views: 16609

Re: RouterOS PHP API class

Version 0.2.
- added callbacks
- simple btest example using callbacks to run many simultaneous tests
- updated documentation
by ayufan
Mon Nov 30, 2009 11:34 am
Forum: Scripting
Topic: RouterOS PHP API class
Replies: 36
Views: 16609

Re: RouterOS PHP API class

by ayufan
Sun Nov 29, 2009 2:20 pm
Forum: Beginner Basics
Topic: WOL via Mirkotik
Replies: 12
Views: 3643

Re: WOL via Mirkotik

I think you forgot the '/'
Nice one :) It's not important, because he was in "main" menu.
by ayufan
Sun Nov 29, 2009 1:45 pm
Forum: Scripting
Topic: RouterOS PHP API class
Replies: 36
Views: 16609

RouterOS PHP API class

I've create Yet Another PHP RouterOS PHP API: http://svn.osk-net.pl/svn/rosapi/trunk Documentation: http://svn.osk-net.pl/svn/rosapi/trunk/documentation.html Doxygen documentation: http://svn.osk-net.pl/svn/rosapi/trunk/doxygen/annotated.html SVN: http://svn.osk-net.pl/svn/rosapi The main purpose of...
by ayufan
Tue Nov 17, 2009 4:21 pm
Forum: General
Topic: Queues No Longer Work In v4.2
Replies: 2
Views: 1083

Re: Queues No Longer Work In v4.2

Maybe it conflicts with imq :)
by ayufan
Fri Oct 09, 2009 3:04 am
Forum: General
Topic: Billing using RouterOS generated Netflows
Replies: 5
Views: 1498

Re: Billing using RouterOS generated Netflows

Try using ip accounting. I use it successfully for about 1000 users.
by ayufan
Tue Sep 22, 2009 11:05 pm
Forum: General
Topic: Need to make bootable USB key to install ROS on a server.
Replies: 11
Views: 8954

Re: Need to make bootable USB key to install ROS on a server.

did you try netinstall?
by ayufan
Wed Sep 16, 2009 11:15 am
Forum: General
Topic: Mikrotik 3.0 is possible TTL Packet mark?
Replies: 7
Views: 8410

Re: Mikrotik 3.0 is possible TTL Packet mark?

I use TTL to hide routers from traceroute ;)
by ayufan
Wed Sep 02, 2009 4:07 pm
Forum: General
Topic: Special needs - Broadcast UDP Packet needs forwarding
Replies: 7
Views: 3306

Re: Special needs - Broadcast UDP Packet needs forwarding

is it possible to route broadcast packets?.. O_o
maybe not simply route, but redirect using dstnat rule ;)
by ayufan
Thu Aug 27, 2009 9:49 pm
Forum: General
Topic: Are there any RouterOS Similators?
Replies: 2
Views: 924

Re: Are there any RouterOS Similators?

VMware, VirtualBox, qemu, MetaROUTER, Xen? :D
by ayufan
Tue Aug 25, 2009 8:58 pm
Forum: General
Topic: dhcp-client and routing-table
Replies: 5
Views: 1473

Re: dhcp-client and routing-table

For now I've following code: :if ([:len [ip dhcp-client get backbone.local gateway]]!=0) do={ :if ([:len [/ ip route find routing-mark=local]]=0) do={ / ip route remove [find routing-mark=local]; / ip route add gateway=[/ ip dhcp-client get backbone.local gateway] routing-mark=local check-gateway=pi...
by ayufan
Tue Aug 25, 2009 4:30 pm
Forum: General
Topic: dhcp-client and routing-table
Replies: 5
Views: 1473

dhcp-client and routing-table

Please add a routing-table for dhcp-client, so that default-route would go to defined routing-table instead of default "main". Something like that should also be available for pppoe-client, pptp-client, etc.

Right now it can be achieved using scheduler but it's not a very clean way...
by ayufan
Mon Aug 24, 2009 5:17 pm
Forum: The User Manager
Topic: How to create ssl certificate? (https for payapal)
Replies: 7
Views: 6379

Re: How to create ssl certificate? (https for payapal)

You can buy a certificate ;)
by ayufan
Thu Aug 20, 2009 6:33 pm
Forum: Virtualization
Topic: COOVA + Openwrt + Metarouter
Replies: 7
Views: 8824

Re: COOVA + Openwrt + Metarouter

Try latest one ;)
by ayufan
Wed Aug 19, 2009 8:36 pm
Forum: General
Topic: IP - Firewall - Address List bug (v.2.9.7)
Replies: 1
Views: 839

Re: IP - Firewall - Address List bug (v.2.9.7)

update to latest version (legal)
by ayufan
Tue Aug 18, 2009 3:50 pm
Forum: RouterBOARD hardware
Topic: GPS NTP Stratum (6 vs. 2)
Replies: 22
Views: 10169

Re: GPS NTP Stratum (6 vs. 2)

i opt that person who uses RouterOS knows what it does :) it may be a "hidden" option only available through console... :)
by ayufan
Tue Aug 18, 2009 2:59 pm
Forum: RouterBOARD hardware
Topic: GPS NTP Stratum (6 vs. 2)
Replies: 22
Views: 10169

Re: GPS NTP Stratum (6 vs. 2)

or maybe add an option to select desired stratum?
by ayufan
Wed Aug 12, 2009 1:21 am
Forum: Scripting
Topic: API Server crashes
Replies: 12
Views: 3187

Re: API Server crashes

I'm using API to synchronize all routers. But mine script is as you said "synchronous": send command and wait for results. Everything works flawelessly ;)
by ayufan
Mon Aug 10, 2009 5:01 pm
Forum: RouterBOARD hardware
Topic: Default configuration on RB750
Replies: 27
Views: 18501

Re: Default configuration on RB750

or at least add option to /system/routerboard:
boot-device=if-reset-push-boot-from-ethernet
it shouldn't be that hard...
it would help many routerboard administrators
who uses netbooks/notebooks and doesn't have builtin serial port...
by ayufan
Mon Aug 10, 2009 4:47 pm
Forum: RouterBOARD hardware
Topic: Default configuration on RB750
Replies: 27
Views: 18501

Re: Default configuration on RB750

but i thinks is in RouterBOOT, so why you wont add it?
by ayufan
Mon Aug 10, 2009 4:03 pm
Forum: RouterBOARD hardware
Topic: Default configuration on RB750
Replies: 27
Views: 18501

Re: Default configuration on RB750

is that feature already/will be present in other routerboards? it's simplier than using null-modem...:)
by ayufan
Sat Aug 08, 2009 6:57 pm
Forum: RouterBOARD hardware
Topic: Default configuration on RB750
Replies: 27
Views: 18501

Re: Default configuration on RB750

Yes, you will be able to use netinstall.
how? with reset button?
by ayufan
Sat Aug 08, 2009 6:00 pm
Forum: General
Topic: feature request : Delete confirmation
Replies: 7
Views: 3089

Re: feature request : Delete confirmation

you can always use mac-telnet to revert changes ;)
in fact RouterOS is for more advanced users who
should know what they are doing... otherwise, don't touch it
by ayufan
Sat Aug 08, 2009 5:51 pm
Forum: RouterBOARD hardware
Topic: Default configuration on RB750
Replies: 27
Views: 18501

Re: Default configuration on RB750

normis: what about netinstall? will it be possible?
by ayufan
Fri Aug 07, 2009 7:34 pm
Forum: Beginner Basics
Topic: Question: Netwatch
Replies: 2
Views: 1083

Re: Question: Netwatch

try export command or use scripting
by ayufan
Thu Jun 25, 2009 2:06 am
Forum: Scripting
Topic: :if ($traf>1000000000000) is it possibe to make it shorter?
Replies: 2
Views: 1087

Re: :if ($traf>1000000000000) is it possibe to make it shorter?

try, this: ;)
:set kb 1000
:set Mb ($kb*$kb)
:set Gb ($Mb*$kb)
:if ($traf>(100*$Gb)) do={}
by ayufan
Wed Jun 24, 2009 8:13 pm
Forum: Scripting
Topic: API - ACL Control
Replies: 37
Views: 21451

Re: API - ACL Control

no, first you have to getall items
by ayufan
Tue Jun 23, 2009 4:05 pm
Forum: Scripting
Topic: API Links
Replies: 155
Views: 218689

Re: API examples

Use C# code ;)
by ayufan
Tue Jun 23, 2009 3:57 pm
Forum: Scripting
Topic: Feature Request: API Safe Mode
Replies: 1
Views: 1675

Feature Request: API Safe Mode

It would be great to be able to enter safe mode from API before updating settings. It shouldn't be so hard to implement!
by ayufan
Sun Jun 21, 2009 3:41 pm
Forum: Scripting
Topic: [CONTRIB] ssh perl script - automate batch commands *UPDATED
Replies: 41
Views: 28020

Re: [CONTRIB] ssh perl script - automate batch commands *UPDATED

also you may try to use RouterOS API - it's easier than parse SSH output =)
not when you use:
:put [/ interface print as-value]
;)
by ayufan
Sun Jun 21, 2009 1:46 am
Forum: Scripting
Topic: [CONTRIB] ssh perl script - automate batch commands *UPDATED
Replies: 41
Views: 28020

Re: [CONTRIB] ssh perl script - automate batch commands *UPDATED

yes, you can: $conn = ssh2_connect("192.168.0.1", 22, array('kex' => 'diffie-hellman-group1-sha1')) or die("couldn't connect"); ssh2_auth_password($conn, "admin", "password") or die("coudln't auth"); $shell = ssh2_shell($conn, FALSE); stream_set_bloc...
by ayufan
Fri Jun 12, 2009 4:46 pm
Forum: Virtualization
Topic: Metarouter images
Replies: 378
Views: 387750

Re: Metarouter images

when trying to patch openwrt: patching file target/linux/metarouter/base-files/etc/inittab (Stripping trailing CRs from patch.) patching file target/linux/metarouter/base-files/etc/hotplug2-init.rules (Stripping trailing CRs from patch.) patching file target/linux/metarouter/Makefile patch unexpecte...
by ayufan
Fri Jun 12, 2009 3:09 pm
Forum: Virtualization
Topic: Metarouter images
Replies: 378
Views: 387750

Re: Metarouter images

when will be 3.25?
by ayufan
Thu Jun 11, 2009 7:52 pm
Forum: General
Topic: How can I hide proxy headers?
Replies: 27
Views: 9084

Re: How can I hide proxy headers?

it was squid in 2.9.x, 3.x uses mikrotik proxy :)
by ayufan
Tue Jun 09, 2009 3:20 pm
Forum: Virtualization
Topic: RouterOS Licences when virtualized in MetaRouter
Replies: 4
Views: 7496

Re: RouterOS Licences when virtualized in MetaRouter

You inherit licenses from your parent router.
by ayufan
Wed Jun 03, 2009 12:15 pm
Forum: General
Topic: Feature Request: Conntrack connection logging
Replies: 1
Views: 1485

Feature Request: Conntrack connection logging

It would be nice if you could implement conntrack connection logging with automatic gzipping on router: conntrack -e NEW,DESTROY -E -o timestamp It uses less space then and is more informative than iptables LOG target, because it includes src, dest, nat-src, nat-dst, i.e.: information that is really...
by ayufan
Sat May 23, 2009 6:48 pm
Forum: Wireless Networking
Topic: How to manage large number of AP
Replies: 1
Views: 938

Re: How to manage large number of AP

hi,

1) i've created centralized package repository which handles updates
2) using rosinfo and graphs created from snmp
3) configuration is templated to all access points
4) about 30m-1h a day managing over 50 RB and 100 other devices
by ayufan
Mon May 04, 2009 11:59 pm
Forum: General
Topic: IP Pool Server (Feature Request)
Replies: 3
Views: 1713

Re: IP Pool Server (Feature Request)

you can use freeradius managed pool of addresses easily :)
by ayufan
Sun May 03, 2009 9:08 pm
Forum: Beginner Basics
Topic: Specific question on Port forwarding
Replies: 21
Views: 3804

Re: Specific question on Port forwarding

common mistake is to put your dst-nat rules after the masquerade. Make your masquerade rule last on the list. You're wrong ;) It's not important which is first: dst-nat or masquerade. Masquerade can be only put in src-nat chain. So you are talking about two different chains which are processed sepa...
by ayufan
Sat May 02, 2009 6:55 pm
Forum: Wireless Networking
Topic: 802.11 a/n 300mbit/sec minipci card
Replies: 9
Views: 3305

Re: 802.11 a/n 300mbit/sec minipci card

when 802.11n standard is ready :)
by ayufan
Sat May 02, 2009 10:54 am
Forum: Scripting
Topic: AnalizoLOG 1.0 - software for analize mikrotik web proxy
Replies: 6
Views: 3283

Re: AnalizoLOG 1.0 - software for analize mikrotik web proxy

If there's really bug that it can be simple fixed :)
by ayufan
Fri May 01, 2009 9:25 am
Forum: Scripting
Topic: AnalizoLOG 1.0 - software for analize mikrotik web proxy
Replies: 6
Views: 3283

Re: AnalizoLOG 1.0 - software for analize mikrotik web proxy

But proxylizer creates reports automatically without ANY user interaction. You just set-up it and wait for results. By the way 100$ is pretty much for that kind of application, but it's my opinion. ;)
by ayufan
Thu Apr 30, 2009 11:20 am
Forum: Scripting
Topic: AnalizoLOG 1.0 - software for analize mikrotik web proxy
Replies: 6
Views: 3283

Re: AnalizoLOG 1.0 - software for analize mikrotik web proxy

We have almost the same using proxylizer :)
by ayufan
Thu Apr 30, 2009 12:46 am
Forum: General
Topic: v4.0 Feature Request(s)
Replies: 139
Views: 49621

Re: v4.0 Feature Request(s)

You can send a mail with backup.
by ayufan
Mon Apr 27, 2009 3:50 pm
Forum: General
Topic: LOAD BALANCING WITH 3 GW AND FAILOVER
Replies: 8
Views: 3338

Re: LOAD BALANCING WITH 3 GW AND FAILOVER

Wait for 3.24 when you will be able to use new Firewall Matcher: PCC :)

http://forum.mikrotik.com/viewtopic.php?f=2&t=31415
by ayufan
Thu Apr 23, 2009 8:07 pm
Forum: Scripting
Topic: Mikrotik UDP logger for linux
Replies: 5
Views: 2604

Re: Mikrotik UDP logger for linux

you mean syslog remote logging? do it have any features to dynamically format log stream?
by ayufan
Wed Apr 22, 2009 11:52 pm
Forum: The Dude
Topic: 400mb dude export file? wth?
Replies: 3
Views: 1308

Re: 400mb dude export file? wth?

however it would be nice to have some export options :) just to select files, logs, graphs or just fresh config... :)
by ayufan
Wed Apr 22, 2009 10:51 pm
Forum: The Dude
Topic: 400mb dude export file? wth?
Replies: 3
Views: 1308

Re: 400mb dude export file? wth?

maybe logs? maybe files? did you check that?
  • 1
  • 2