Community discussions

MikroTik App

Search found 682 matches

by sirbryan
Mon May 19, 2025 7:58 pm
Forum: MikroTik hardware questions
Topic: Cheap 2,5/5/10Gbps ethernet router
Replies: 2
Views: 130

Re: Cheap 2,5/5/10Gbps ethernet router

Yes, it would be nice to see MikroTik come out with something like the Ubiquiti Unifi Cloud Gateway Max (5x2.5G ports) or Cloud Gateway Fiber (3x10G, 4x2.5G). The AX3 with a CRS310-8G+ as a router-on-a-stick, or the RB5009 with a CRS310 would both be good combinations as alternatives. (I really want...
by sirbryan
Wed May 14, 2025 6:47 pm
Forum: General
Topic: rds2216 and Proxmox hypervisors - any ideas
Replies: 3
Views: 416

Re: rds2216 and Proxmox hypervisors - any ideas

You can do either one: export individual disks to the hypervisors, either via nvme or iscsi. Or you could create RAID arrays and export those. Unless you want to run ZFS on the hypervisor, I would think exporting a RAID array would be safer and use less network resources, especially during recovery....
by sirbryan
Sat May 10, 2025 8:24 pm
Forum: MikroTik hardware questions
Topic: Hardware for x86 (Replacing 2216)
Replies: 38
Views: 14915

Re: Hardware for x86 (Replacing 2216)

I am working on a similar Hardware: Supermicro ARS-210M-NR with Altra Max-Prozessor M128 and Connectx-6-DX dual 100G I still get only 64 cores on 7.19rc2. Is there some early access to 7.20ab to check if they fixed the core recognition >64? None of the builds that they sent me have >64-core support...
by sirbryan
Thu May 08, 2025 5:46 pm
Forum: Announcements
Topic: v7.19rc [testing] is released!
Replies: 207
Views: 49419

Re: v7.19rc [testing] is released!

Weirdly enough I do not seem to have this issue. I have an RB4011 with an LHG60 and NB19 link to the same tower, each with their own BGP session (but same local/remote ASN) and prefix counts are identical for both sessions. https://iili.io/3ehedNV.md.png Both BGP sessions terminate on the same loca...
by sirbryan
Thu May 08, 2025 7:11 am
Forum: Beginner Basics
Topic: MLAG/LACP Sample Config?
Replies: 2
Views: 1149

Re: MLAG/LACP Sample Config?

Use the MLAG example in the docs as a starting point. I have multiple MLAG stacks working just fine with 7.15.3 and LACP between them and client devices.
by sirbryan
Wed May 07, 2025 3:59 pm
Forum: General
Topic: Third party x86 hw ROS support
Replies: 26
Views: 1969

Re: Third party x86 hw ROS support

I tested about five different boxes at the time, and so I can't honestly remember which ports worked and which didn't, but suffice it to say, all six did not show up on that box Wait...ALL six did not show up? Perhaps I worded that poorly. Some of them showed up, but not all six of them. Likely the...
by sirbryan
Wed May 07, 2025 7:33 am
Forum: Announcements
Topic: v7.19rc [testing] is released!
Replies: 207
Views: 49419

Re: v7.19rc [testing] is released!

Have you seen that problem where in the session the number of prefixes remains at 0 even though the number of received messages increases as normal? Here that only happens after some uptime (and restart of a session), not immediately after boot. I had not noticed that before, but I pulled up one of...
by sirbryan
Wed May 07, 2025 7:29 am
Forum: General
Topic: Third party x86 hw ROS support
Replies: 26
Views: 1969

Re: Third party x86 hw ROS support

8086:125c Both awesome as well as interesting; thanks much. The only thread I had been able to unearth so far with anybody at all talking about i226-V compatibility with ROS is this one from late 2023, which seems to imply that the interfaces do actually show up for them. In light of your testimony...
by sirbryan
Wed May 07, 2025 6:40 am
Forum: General
Topic: Third party x86 hw ROS support
Replies: 26
Views: 1969

Re: Third party x86 hw ROS support

(I have a box very similar to the one he's looking at buying, and IIRC only the SFP+ worked on ROS7; the 2.5's did not.) Do you happen to know what ethernet chip was being used for the 2.5s (PCI vendor and device IDs would be even cooler)? And curious when was the last time you tried it (what ROS v...
by sirbryan
Tue May 06, 2025 10:38 pm
Forum: General
Topic: Third party x86 hw ROS support
Replies: 26
Views: 1969

Re: Third party x86 hw ROS support

I have read somewhere that Proxmox can not migrate a VM that is using PCI-Passthrough. If this is correct , how do you migrate a ROS ( x86 and/or CHR ) using PCI-Passthrough to another Proxmox ? Is it possible to migrate if the Proxmox servers are identical ? OP was asking about whether ROS support...
by sirbryan
Tue May 06, 2025 6:45 pm
Forum: Announcements
Topic: v7.19rc [testing] is released!
Replies: 207
Views: 49419

Re: v7.19rc [testing] is released!

I had not noticed that before, but I pulled up one of my borders and found this interesting. For all of my peers with redundant connections, the secondary router (that has most recently reconnected) shows a dissimilar number of prefixes received, despite being configured identically. Yes, that is w...
by sirbryan
Tue May 06, 2025 5:45 pm
Forum: Announcements
Topic: v7.19rc [testing] is released!
Replies: 207
Views: 49419

Re: v7.19rc [testing] is released!

Have you seen that problem where in the session the number of prefixes remains at 0 even though the number of received messages increases as normal? Here that only happens after some uptime (and restart of a session), not immediately after boot. I had not noticed that before, but I pulled up one of...
by sirbryan
Tue May 06, 2025 5:30 pm
Forum: General
Topic: Third party x86 hw ROS support
Replies: 26
Views: 1969

Re: Third party x86 hw ROS support

Unless you're going with known-working physical interfaces, as others have already suggested, the only way to know for sure if a particular box would do the job is to buy it and put a hypervisor on it and test with CHR (or x86 ISO as a VM) and PCI passthrough. If all ports are passed through and sho...
by sirbryan
Tue May 06, 2025 5:09 pm
Forum: Announcements
Topic: v7.19rc [testing] is released!
Replies: 207
Views: 49419

Re: v7.19rc [testing] is released!

What is completely broken in BGP? Its stability. I cannot run anything higher than 7.15.x on my border and aggregation routers with more than two peers and thousands of routes, or else routes get "stuck". Traffic goes out the wrong interface despite the FIB showing routes going to the des...
by sirbryan
Tue May 06, 2025 5:00 pm
Forum: General
Topic: RB5009 dropping all traffic for a few seconds
Replies: 23
Views: 2021

Re: RB5009 dropping all traffic for a few seconds

What devices are connected to the router? It could be a grounding issue, or failed cabling to one of the cameras/radios/whatever else you have plugged into it. Or it could be related to a switching loop. Does any of the attached equipment show anything in its logs (besides ports dropping)? Is it bei...
by sirbryan
Thu May 01, 2025 6:00 pm
Forum: Announcements
Topic: v7.19rc [testing] is released!
Replies: 207
Views: 49419

Re: v7.19rc [testing] is released!

I upgraded my RDS2216 to 7.19rc1 for some disk testing. Built-in SMB is still bad for some reason. It works fine on 7.17, but throughput on 7.18-7.19 are horrifically slow. M1 Mac Studio, Sonoma, 25Gbps card -> RDS2216 (2x M.2 SATA drives in MDRAID1 configuration, ext4 format). Built-in SMB, 8-20MB/...
by sirbryan
Thu May 01, 2025 5:13 pm
Forum: Announcements
Topic: v7.19rc [testing] is released!
Replies: 207
Views: 49419

Re: v7.19rc [testing] is released!

As per normis they are working hard on ROSE features/stability on 7.19 and 7.20 so I guess no progress on routing,switching and hwoffload features I hope I'm mistaken This is a silly comment. It's not like they only have five guys that work on all of RouterOS. Some developers work on ROSE and conta...
by sirbryan
Wed Apr 30, 2025 7:20 pm
Forum: MikroTik hardware questions
Topic: RDS2216 Experience
Replies: 27
Views: 9070

Re: RDS2216 Experience

I also had trouble using NFS to be honest, thought from what I can see its implemented more for mikrotik-to-mikrotik use To get NFS to work on macOS took some command-line tweaking; it's possible some of those same arguments (or variations) would be needed on some Linux distributions. I haven't tri...
by sirbryan
Wed Apr 30, 2025 7:18 pm
Forum: Wireless Networking
Topic: 60 Ghz link shows constant traffic
Replies: 4
Views: 2393

Re: 60 Ghz link shows constant traffic

I occasionally see that as well, but closer to 400-600kbps to all clients. It seems to me like it's some kind of broadcast or ARP traffic, but I can't see anything in other systems indicating that it's a problem.
by sirbryan
Wed Apr 30, 2025 6:38 pm
Forum: Containers
Topic: ceph OSD as Container on RDS2216
Replies: 3
Views: 9936

Re: ceph OSD as Container on RDS2216

Thanks for your message! Do you have any idea how to make two or three RDS's as a Cluster, if one device fails or install firmware, the storage is still up? https://forum.mikrotik.com/viewtopic.php?t=215917 At this stage, that is up to the capabilities of your hosts. Since what he's talking about i...
by sirbryan
Mon Apr 28, 2025 8:33 pm
Forum: MikroTik hardware questions
Topic: RDS2216 Experience
Replies: 27
Views: 9070

Re: RDS2216 Experience

What's wrong with testing on NFS, at least unless/until ROSE properly exports iSCSI IQNs? You could surely spin up one or two Promox hosts for testing (which is what I'm doing).

(I'll take it if you don't want it.)
by sirbryan
Mon Apr 28, 2025 8:25 pm
Forum: Beginner Basics
Topic: ROSE-storage – how to add a spare disk to RAID
Replies: 2
Views: 820

Re: ROSE-storage – how to add a spare disk to RAID

Unless you're using BTRFS, ROSE RAID is based on Linux mdraid, so keep that in mind as you experiment with what little documentation and CLI commands are available..
by sirbryan
Fri Apr 25, 2025 3:39 pm
Forum: MikroTik hardware questions
Topic: RDS2216 Experience
Replies: 27
Views: 9070

Re: RDS2216 Experience

This issue is likely unrelated to the IQN naming convention. According to my online research, ESXi NVMe over TCP requires the target must support NVMe fused command , Maybe the RouterOS TCP NVMe Target module (nvmet-tcp) does not support NVMe fused command ? The following article mentions a similar...
by sirbryan
Fri Apr 25, 2025 3:36 pm
Forum: General
Topic: Mikrotik MLAG saga
Replies: 6
Views: 1007

Re: Mikrotik MLAG saga

One thing to note: you've set the MTU (i.e. Layer 3 MTU) on all the ports to maximum. There is no benefit to doing that since they are not routing. Max L2MTU for the switch ports is sufficient. I'd put everything back to 1500 to keep the config as clean and as close to MT's examples as possible. I'...
by sirbryan
Fri Apr 25, 2025 7:48 am
Forum: MikroTik hardware questions
Topic: RDS2216 Experience
Replies: 27
Views: 9070

Re: RDS2216 Experience

Anyone had any luck with getting VMWare to successfully connect to an ISCSI partition on an RDS2216? - it seems as if the LUN being offered is not suitable to complete the connection and the ISX host fails to complete the connection. Any help here would be greatly appreciated MikroTik isn't using t...
by sirbryan
Thu Apr 24, 2025 9:55 pm
Forum: Containers
Topic: ceph OSD as Container on RDS2216
Replies: 3
Views: 9936

Re: ceph OSD as Container on RDS2216

You'd be better off running ceph on a separate Linux box and using iscsi or nvme-over-tcp to export the individual drives to your ceph host(s). MikroTik's container implementation doesn't give the user raw access to drives. But then you'd stand little to gain if the RDS2216 went away (crashes, reboo...
by sirbryan
Thu Apr 24, 2025 9:14 pm
Forum: General
Topic: Mikrotik MLAG saga
Replies: 6
Views: 1007

Re: Mikrotik MLAG saga

Nothing that would break it (that I know of) stands out to me. But I use RSTP, not MSTP, so I've no idea if there's anything going on there. I set both switches to the same RSTP priority, same costs on the ports, etc. on mine and they all work. One thing to note: you've set the MTU (i.e. Layer 3 MTU...
by sirbryan
Wed Apr 23, 2025 3:48 pm
Forum: Beginner Basics
Topic: Correct upgrade/update procedure for mlag connected devices [SOLVED]
Replies: 2
Views: 2485

Re: Correct upgrade/update procedure for mlag connected devices [SOLVED]

Yes, do one switch, then the other. That's how I did my data center stack a couple months ago. If all you need is MLAG out of these switches (no SFP+ firmware or other updates that might have come in recent releases), I wouldn't upgrade past 7.15.3. In other words, if they're working for you now and...
by sirbryan
Tue Apr 22, 2025 6:48 pm
Forum: General
Topic: Mikrotik MLAG saga
Replies: 6
Views: 1007

Re: Mikrotik MLAG saga

OK, I did some more testing. Having more than two links per host works fine with 7.15.3 on the MLAG stack. And recovery is pretty good when you reboot a switch: one or two pings lost when the switch goes away, 4-10 pings lost when it comes back and MLAG is converging. Something broke in MLAG when yo...
by sirbryan
Tue Apr 22, 2025 5:07 pm
Forum: General
Topic: Mikrotik MLAG saga
Replies: 6
Views: 1007

Re: Mikrotik MLAG saga

My experience has been that, at least for now, MLAG only works reliably with a maximum of two ports per "client" server/router, one in each switch. I've tried with four from a CCR2116, as well as four from an RDS 2216, both into a pair of CRS326-24S+'s. While it seems to work for a few min...
by sirbryan
Thu Apr 17, 2025 6:17 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 210904

Re: v7.19beta [testing] is released!

If Mikrotik saw value in this it would have already done something in that direction, so I don't think you could count on their support for this effort. That's not always how things work. Companies that have been doing things a certain way for a long time often get stuck in a "this is how we d...
by sirbryan
Wed Apr 16, 2025 5:15 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 210904

Re: v7.19beta [testing] is released!

If you're doing NAT, you need to disable the Internet-facing port. Presumably you've done that already for other versions. Do you mean disable the HW offload on the internet facing port on the switch ? The way it's supposed to work for NAT (according to the documentation) is to enable L3HW on the s...
by sirbryan
Mon Apr 14, 2025 8:27 pm
Forum: MikroTik hardware questions
Topic: RDS2216 Experience
Replies: 27
Views: 9070

Re: RDS2216 Experience

I can confirm the Noctua's don't respond to speed control. They stay at 5K RPM and CPU rapidly approaches 60+C. [Edit] Looks like they do respond to fan control, but since the machine was so hot they were running full bore the whole time. I'm testing a half-and-half setup with five Noctuas on the po...
by sirbryan
Mon Apr 14, 2025 4:50 pm
Forum: General
Topic: T1 interface
Replies: 9
Views: 1132

Re: T1 interface

When I was handling T1's and DS3's, we had a few Ethernet-over-switched-circuit devices that we sometimes used, allowing us to plug whatever routers (or switches) on each end into the Ethernet ports, and the device would mux the traffic across a number of T1's (1-4 usually) or a DS3. I actually have...
by sirbryan
Sat Apr 12, 2025 11:38 pm
Forum: MikroTik hardware questions
Topic: RDS2216 Experience
Replies: 27
Views: 9070

Re: RDS2216 Experience

Unfortunately the RDS wont downgrade below 7.18 for me. Try 7.19b if you can live with a beta for a little while. Also a note on SMB performance in container, copy to RDS goes at about 6gbps, copy from is 1gbps, which is faster than built in smb service, but still rather slow which seems to be a re...
by sirbryan
Sat Apr 12, 2025 11:34 pm
Forum: General
Topic: Need a 12 port 2,5Gbit Switch WITHOUT FANS !
Replies: 9
Views: 10182

Re: Need a 12 port 2,5Gbit Switch WITHOUT FANS !

I'm posting this here because, while the Zyxel looks nice, I don't know that it will fit well into an ISP's network, and I know a lot of ISP's looking for a switch that meets your topic and OP. I have a couple of the Hyconext switches. While they have fans, they're pretty quiet unless you're putting...
by sirbryan
Fri Apr 11, 2025 7:45 am
Forum: MikroTik hardware questions
Topic: RDS2216 Experience
Replies: 27
Views: 9070

Re: RDS2216 Experience

There's a fix in 7.19b for SMB shares having issues when backed by BTRFS (to macOS?). I had poor SMB results on 7.18, but downgrading to 7.17.x proved to work just fine. (I had the issues on an ARM CHR VM on 7.18.x as well, so it wasn't specific to the RDS.)
by sirbryan
Thu Apr 10, 2025 5:27 pm
Forum: General
Topic: Configuring MLAG with MikroTik CCR2216-1G-12XS-2XQ on RouterOS 7.18.2 [SOLVED]
Replies: 2
Views: 1702

Re: Configuring MLAG with MikroTik CCR2216-1G-12XS-2XQ on RouterOS 7.18.2 [SOLVED]

Your bond trunk is only allowing untagged frames. You need to "admit all" frames for the VLAN-tagged traffic to traverse the bond.
by sirbryan
Wed Apr 09, 2025 4:54 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 210904

Re: v7.19beta [testing] is released!

If you're doing NAT, you need to disable the Internet-facing port. Presumably you've done that already for other versions.
by sirbryan
Fri Apr 04, 2025 12:39 am
Forum: General
Topic: ISP CCR2216 L3HW-Offloading Issues
Replies: 63
Views: 9271

Re: ISP CCR2216 L3HW-Offloading Issues

OK, for some reason when I tried this before on my RDS2216, it only offloaded some of them on 7.18.2. I downgraded to 7.17.2 to fix some Samba stuff I was seeing, and after reading this went ahead and spooled up the BGP session to an upstream aggregation router. And now it's behaving just as explain...
by sirbryan
Thu Apr 03, 2025 7:20 pm
Forum: Virtualization
Topic: Get rid of "Licensing Error. Cloning a cloned machine is not permitted"
Replies: 8
Views: 10967

Re: Get rid of "Licensing Error. Cloning a cloned machine is not permitted"

Are you trying to restore backup from another CHR? Are you trying to license a CHR that was used for free longer than 60 days? For me I had built the CHR in Proxmox using the raw image converted to qcow (as per MikroTik's documentation). I had it check out a license (which was free, because it was ...
by sirbryan
Tue Apr 01, 2025 10:11 am
Forum: Virtualization
Topic: Get rid of "Licensing Error. Cloning a cloned machine is not permitted"
Replies: 8
Views: 10967

Re: Get rid of "Licensing Error. Cloning a cloned machine is not permitted"

I started seeing this a number of weeks ago too. I'd like to be able to build a CHR on one host, get it working, then convert it to a template for deployment across multiple identical hosts. I tried cloning one that was working and, even after changing its system ID, I couldn't register it with a ne...
by sirbryan
Fri Mar 28, 2025 6:59 am
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 27007

Re: New exciting features for storage

TrueNAS doesn't have an ARM64 variant. Openmediavault might be an option, but at the moment, you can't pass the raw disks through, so at best you'd be giving a container an already assembled array, which defeats the purpose of using one of those solutions as it is. The door is open, however, for som...
by sirbryan
Wed Mar 26, 2025 9:56 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 27007

Re: New exciting features for storage

Can you instead test NFS performance over SMB. At times, Windows SMB has its own performance limitations.
I tested it earlier and I believe I posted some results. It works similarly (i.e. works fine), depending on which machine I'm connected to and which set of drives I'm testing.
by sirbryan
Wed Mar 26, 2025 9:54 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 635
Views: 271304

Re: v7.18.2 [stable] is released!

Can a few people test built-in SMB performance? On two of my devices, SMB to macOS is really bad (11-20MB/s), but on 7.16.2 and 7.17.2 it's fine (200-900MB/s).
by sirbryan
Wed Mar 26, 2025 9:50 pm
Forum: MikroTik hardware questions
Topic: RDS2216 U.2 height
Replies: 11
Views: 5484

Re: RDS2216 U.2 height

You can add Samsung PM963 to that list. I've also got some Micron 7300's coming in for testing.
by sirbryan
Wed Mar 26, 2025 3:05 pm
Forum: General
Topic: CCR2216 L3HW acceptable configuration combinations
Replies: 7
Views: 1993

Re: CCR2216 L3HW acceptable configuration combinations

If I leave all ports in the bridge, the only configuration that works is if i disable L3HW on both sfp28-1 (BGP WAN) and sfp28-8 (LAN port that needs firewalling), but then I don't have l3hw on the basic routing between other ports and WAN port, because I have some public subnets i want to attach t...
by sirbryan
Wed Mar 26, 2025 2:40 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 27007

Re: New exciting features for storage

make sure your macOS computer has correct MTU for the adapter you are using, I know macOS has a bug where you can't set MTU above 8000 and if your adapter says it needs 9000, it will glitch in various ways. I have a Sonnettech Twin25 and have set MTU to 8000 MTU is 1500. But that doesn't appear to ...
by sirbryan
Tue Mar 25, 2025 11:22 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 27007

Re: New exciting features for storage

edit: not sure why are you getting such good results on ampere, but test seems to be running correctly, is it same 960GB disk? larger ones usually have much better performance. 1.92TB disk usually has double performance than 960GB counterpart. I bought 8 960's. Two are in the Ampere and six in the ...
by sirbryan
Tue Mar 25, 2025 6:56 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 27007

Re: New exciting features for storage

OK, I've been doing some math. If these PM963 drives are capable of up to 1800-2000MB/s (14-16Gbps) with 4 PCIe lanes, that means that I should see roughly 7-8Gbps in straight reads from one drive with 2 lanes on the RDS2216. The disk test to a single drive on Ampere (4xPCIe): [admin@rocket80-ros] /...
by sirbryan
Tue Mar 25, 2025 3:12 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 27007

Re: New exciting features for storage

I ran a disk test from the Ampere ROS 7 to the RDS2216, with two disks exported. The results are exactly half of what I get when running it locally. [admin@rocket80-ros] /disk> test block-size=4K direction=read thread-count=2 type=device tcp-raid-1 Flags: R - RUNNING Columns: SEQ, RATE, IOPS, BYTES,...
by sirbryan
Tue Mar 25, 2025 2:46 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 27007

Re: New exciting features for storage

disk test provides similar functionality as dd utility in linux. when testing locally CPU may be a bit capped due to generation of data (random or zeroes) with 6 nvme disks (entry level U.2/U.3 drives Micron_7400 - 960GB): ..... speeds should be around 55Gbps or higher in shorter bursts That's fine...
by sirbryan
Tue Mar 25, 2025 2:28 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 27007

Re: New exciting features for storage

Thank you for the effort, but about the SMB, something is wrong in your setup. Show me your config and I'll show you mine. /ip smb users add name=bscott /ip smb set enabled=yes /ip smb shares add directory=nvme-raid name=Shared valid-users=bscott /disk set nvme5 raid-master=nvme-raid raid-role=0 se...
by sirbryan
Tue Mar 25, 2025 2:36 am
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 27007

Re: New exciting features for storage

Looking through those FIO results can be really daunting, but I figured I'd leave those posts there for the few individuals who like to scour data. There are four Samsung drives in the RDS2216 and two in the Ampere box, and six Micron drives in the Ampere box on an LSI card. All are used enterprise ...
by sirbryan
Mon Mar 24, 2025 10:07 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 27007

Re: New exciting features for storage

FIO tests on Ampere ARM64 ROS 7.18.2 native, same Samsung drives as in RDS2216 in BTRFS RAID 1. Random writes = 425MB/s, or 3.4Gbps on network: /Shared/fiotests # fio --name=fiotest --ioengine=sync --rw=randwrite --bs=4k --numjobs=1 --size=5G --runtime=1m --time_based fiotest: (g=0): rw=randwrite, b...
by sirbryan
Mon Mar 24, 2025 9:43 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 27007

Re: New exciting features for storage

Same tests as previous post, but with a twist. Container is running on Ampere machine running ROS7, talking to two NVMe drives that the 2216 has exported via NVMe over TCP. The Ampere box then puts them in a BTRFS RAID1 configuration and mounts the drives. Random writes = 348MB/s, or 2.784Gbps on th...
by sirbryan
Mon Mar 24, 2025 9:34 pm
Forum: General
Topic: ISP CCR2216 L3HW-Offloading Issues
Replies: 63
Views: 9271

Re: ISP CCR2216 L3HW-Offloading Issues

Maybe the ccr2216 ASIC has something extra not mentioned in the docs, or I'm doing something wrong? :lol: We just deployed them, and didn't give it much thought, I thought this was normal behaviour... This edge is running 7.17.2 which doesn't seem to offer that extra info about the LPM, [@fn.edgemk...
by sirbryan
Mon Mar 24, 2025 8:47 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 27007

Re: New exciting features for storage

FIO tests run in container, with two of the Samsung NVMe drives as BTRFS RAID1 mounted in the container: Random writes = 179MB/s, or 1.432Gbps on the network: /Shared/tests # fio --name=fiotest --ioengine=sync --rw=randwrite --bs=4k --numjobs=1 --size=5G --runtime=1m --time_based fiotest: (g=0): rw=...
by sirbryan
Mon Mar 24, 2025 7:19 pm
Forum: General
Topic: ISP CCR2216 L3HW-Offloading Issues
Replies: 63
Views: 9271

Re: ISP CCR2216 L3HW-Offloading Issues

I sent a BGP feed to my RDS2216 and this is how it's HW offloading is working. Note it has only one BGP peer, and only one way out and still it won't load everything. ipv4-routes-total: 751768 ipv4-routes-hw: 118103 ipv4-routes-cpu: 633664 ipv4-shortest-hw-prefix: 24 ipv4-hosts: 79 route-queue-size:...
by sirbryan
Mon Mar 24, 2025 4:42 pm
Forum: General
Topic: ISP CCR2216 L3HW-Offloading Issues
Replies: 63
Views: 9271

Re: ISP CCR2216 L3HW-Offloading Issues

Here's from one of my 2116's (for comparison). It looks like that chipset has a smaller lpm-cap. ipv4-routes-total: 751578 ipv4-routes-hw: 23930 ipv4-routes-cpu: 727649 ipv4-shortest-hw-prefix: 24 ipv4-hosts: 20 route-queue-size: 0 route-queue-rate: 291691 route-process-rate: 291691 fasttrack-ipv4-c...
by sirbryan
Mon Mar 24, 2025 12:47 am
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 27007

Re: New exciting features for storage

Some more quick tests with Blackmagic Design Disk Speed Test over the network. Ampere ARM64 server booted into RouterOS 7.18.2 bare metal (64 out of 80 x 3GHz cores, 128GB RAM): 2x Samsung MZQLW960HMJP-00003 enterprise NVMe drives via SlimSAS connections, in a BTRFS RAID1 configuration - Samba Conta...
by sirbryan
Sun Mar 23, 2025 7:14 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 27007

Re: New exciting features for storage

Some thoughts after playing with the RDS2216 this weekend. Wow. Ugh. Oof. WIP. Fingers crossed. (My background: 25 years of working in the WISP & telco/ISP industry in general, with lots of time spent managing small data centers and networks, as well as writing mostly web-based applications runn...
by sirbryan
Sat Mar 22, 2025 12:41 am
Forum: General
Topic: ISP CCR2216 L3HW-Offloading Issues
Replies: 63
Views: 9271

Re: ISP CCR2216 L3HW-Offloading Issues

No, it's a 2116. I loaded 7.18.2 on one of my backup routers that participates in ingesting the tables. 24K looks like the middle of 16K and 34K. ipv4-routes-total: 740007 ipv4-routes-hw: 24301 ipv4-routes-cpu: 715706 ipv4-shortest-hw-prefix: 24 ipv4-hosts: 102 route-queue-size: 0 nexthop-cap: 8192 ...
by sirbryan
Fri Mar 21, 2025 11:28 pm
Forum: General
Topic: ISP CCR2216 L3HW-Offloading Issues
Replies: 63
Views: 9271

Re: ISP CCR2216 L3HW-Offloading Issues

Fascinating, since the docs state 16-36K for 2116/98DX3255 and 60K-120K for 2216/98DX8525. I'm running 7.15.3 on my BGP borders/aggs (7.16 locked up routes and required a reboot after a few days; I haven't tried 7.17 or 7.18 yet). My busiest border: ipv4-routes-total: 740438 ipv4-routes-hw: 24405 ip...
by sirbryan
Fri Mar 21, 2025 4:01 pm
Forum: General
Topic: ISP CCR2216 L3HW-Offloading Issues
Replies: 63
Views: 9271

Re: ISP CCR2216 L3HW-Offloading Issues

I have a dozen 2116's in production. Three as border routers (two pulling in full tables), two as BGP aggregation, two more for CGNAT, and a handful more as provider edge to downstream BGP customers. While we have a combined 50Gbps available to us (10Gbps to 5 providers), we only use about 5Gbps at ...
by sirbryan
Wed Mar 19, 2025 3:31 am
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 27007

Re: New exciting features for storage

Think low-cost HCI (hyper-converged infrastructure). Most hardware sits there spinning its wheels (figuratively), so why not give it other tasks to do? For smaller routers, it doesn't make much sense, but if you have a USB3 port on the router, you can share an external hard drive with all the comput...
by sirbryan
Wed Mar 19, 2025 1:40 am
Forum: MikroTik hardware questions
Topic: RDS2216 Pics and Thoughts
Replies: 2
Views: 1997

RDS2216 Pics and Thoughts

I got my RDS2216 in today! rose-1.jpg The disk trays are as flimsy as something that came off a 3D printer, so you're not going to be frequently hot-swapping with these. rose-2.jpg rose-3.jpg There's an issue with this side, however. The screws wouldn't go in straight. We loosened a few of them and ...
by sirbryan
Mon Mar 17, 2025 5:47 am
Forum: Forwarding Protocols
Topic: MLAG/MSTP take down entire network, Redundant Links without Loops [SOLVED]
Replies: 14
Views: 10300

Re: MLAG/MSTP take down entire network, Redundant Links without Loops [SOLVED]

Some of the setup is a little fragile, but I'd have to see how you're doing it. Ideally you would turn down or disconnect all ports you're going to be working on, make the changes, then enable them. The bridge does have to figure out loops/STP and MTU settings etc. when you add and remove member por...
by sirbryan
Sat Mar 15, 2025 7:08 pm
Forum: Forwarding Protocols
Topic: MLAG/MSTP take down entire network, Redundant Links without Loops [SOLVED]
Replies: 14
Views: 10300

Re: MLAG/MSTP take down entire network, Redundant Links without Loops [SOLVED]

So if I had to set mlag-id on router on bond that is connected to both switches... then I should do same on client/server? This is a bit strange because documentation is saying that bond should be a simple LACP and client is unaware of mlag setup. You set the MLAG-ID on each switch port that is a p...
by sirbryan
Sat Mar 15, 2025 6:20 pm
Forum: Forwarding Protocols
Topic: MLAG/MSTP take down entire network, Redundant Links without Loops [SOLVED]
Replies: 14
Views: 10300

Re: MLAG/MSTP take down entire network, Redundant Links without Loops [SOLVED]

Edited:
If I do set mlag-id on bond to switches (ether1,2) it looks like the loop is fixed
Yes, this is required to match bond members to each other.
by sirbryan
Sat Mar 15, 2025 5:15 pm
Forum: Forwarding Protocols
Topic: MLAG/MSTP take down entire network, Redundant Links without Loops [SOLVED]
Replies: 14
Views: 10300

Re: MLAG/MSTP take down entire network, Redundant Links without Loops [SOLVED]

Your config shows ether1 as being the slave to both bonds. Is that a typo or accident? It should be ether1 to the router and ether2 to the server (or however you configured those).
by sirbryan
Sat Mar 15, 2025 5:10 pm
Forum: Forwarding Protocols
Topic: MLAG/MSTP take down entire network, Redundant Links without Loops [SOLVED]
Replies: 14
Views: 10300

Re: MLAG/MSTP take down entire network, Redundant Links without Loops [SOLVED]

Yes all VLANs have to be tagged on the peer port on both switches, and then tagged or untagged on the bonds, depending on your choices for each bond.

For example 401 and 905 should be tagged on the router's bond on the switches and on their MLAG peer port.
by sirbryan
Sat Mar 15, 2025 1:56 am
Forum: MikroTik hardware questions
Topic: Hardware for x86 (Replacing 2216)
Replies: 38
Views: 14915

Re: Hardware for x86 (Replacing 2216)

I just built an Ampere 80-core 3GHz machine and, now that I came across this thread, I'll be testing 40Gbps NICs, and eventually 100Gbps (if I can justify the expense; have zero need for it yet). You don’t need an 80-core 3GHz CPU to handle 100Gbps! Less than 16 cores are enough with proper NIC acc...
by sirbryan
Fri Mar 14, 2025 11:48 pm
Forum: Forwarding Protocols
Topic: MLAG/MSTP take down entire network, Redundant Links without Loops [SOLVED]
Replies: 14
Views: 10300

Re: MLAG/MSTP take down entire network, Redundant Links without Loops [SOLVED]

Yes, MLAG is specified on bridge on each switch, with mlag-id being same. It is added with PVID=99, I tried adding vlan tagged as that link. I can try switch to STP, as MSTP (that are on all 3 devices) was just because it was recommended in my setup. There is no MLAG-ID on the bridge's configuratio...
by sirbryan
Fri Mar 14, 2025 11:17 pm
Forum: MikroTik hardware questions
Topic: Hardware for x86 (Replacing 2216)
Replies: 38
Views: 14915

Re: Hardware for x86 (Replacing 2216)

I have tried using version 7.15 but there is no “extra-nics.npk” during the installation process. in the x86 extra package there is also no “extra-nics.npk”. ok then that .npk might only be available vor AMPERE platform. The explanation I got from MikroTik is that, in contrast to x86, some ARM64 sy...
by sirbryan
Fri Mar 14, 2025 11:14 pm
Forum: MikroTik hardware questions
Topic: Hardware for x86 (Replacing 2216)
Replies: 38
Views: 14915

Re: Hardware for x86 (Replacing 2216)

Has anyone had the opportunity to test RouterOS directly on high-capacity ARM64 servers with 2X100Gbps NICs or something similar? Surprised haven't seen anyone try and run ROS on a HoneyComb on here. I did try on the LX2. It doesn't recognize the onboard NICs. I just built an Ampere 80-core 3GHz ma...
by sirbryan
Fri Mar 14, 2025 11:06 pm
Forum: MikroTik hardware questions
Topic: CCR for small ISP
Replies: 1
Views: 1369

Re: CCR for small ISP

Yes, the 2116 should be sufficient. You could also split tasks between the server you have and the router, particularly with regards to rules and shaping queues. You could do it in such a way that you slowly migrate some of those functions off the server to the router and watch the load/performance....
by sirbryan
Fri Mar 14, 2025 11:02 pm
Forum: Forwarding Protocols
Topic: MLAG/MSTP take down entire network, Redundant Links without Loops [SOLVED]
Replies: 14
Views: 10300

Re: MLAG/MSTP take down entire network, Redundant Links without Loops [SOLVED]

I tried adding qsfpplus1-1 to all vlans as tagged, not difference. It's been few days now. And I'm stuck here trying to deploy redundancy. Both switches pass vlans without issue the way it was intended, LACP also works without issue with same server connected just to one switch. The peer link betwe...
by sirbryan
Fri Mar 14, 2025 10:57 pm
Forum: General
Topic: LACP doesn't work in CHR
Replies: 11
Views: 3379

Re: LACP doesn't work in CHR

sadly CHR is missing MLAG support, which cut out many complex setups
I believe that's because MLAG is done in the hardware on CRS300/500 switches and 2x16 routers.
by sirbryan
Fri Mar 14, 2025 5:33 am
Forum: General
Topic: CCR1036 vs CCR2116 CGNAT
Replies: 10
Views: 2268

Re: CCR1036 vs CCR2116 CGNAT

How much bandwidth? I moved to 2116's from 1036's last year and haven't had any issues. Only pushing about 5Gbps at peak, but the 2116's are handling it fine. HW offload for NAT kind of works. The few times I've tried enabling it, I get complaints from customers. I'm also syncing to a second NAT rou...
by sirbryan
Mon Mar 10, 2025 6:05 pm
Forum: Virtualization
Topic:  CHR using Apple Virtualization & QEMU via macOS UTM
Replies: 75
Views: 29574

Re: CHR using Apple Virtualization & QEMU via macOS UTM

Nice work Amm0. I opened the URL on my Mac Studio and it came right up. I'm able to browse into and it works well. Just need to license it for more bandwidth.

Also testing CHR on an Ampere box (Q80-30) and loving all this ARM64 stuff.
by sirbryan
Mon Mar 10, 2025 6:20 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 635
Views: 271304

Re: v7.18.1 [stable] is released!

If someone could hear us out... We are in deep trouble with Mikrotik. We bought 12 CCR2216's to replace our aging 1072 fleet (we are a mid sized FTTH/Wireless ISP). This warrants its own ticket to support and/or its own thread. There's too much to unpack here to address it in the 7.18.1 release thr...
by sirbryan
Fri Mar 07, 2025 11:17 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 210904

Re: v7.19beta [testing] is released!

*) rose-storage - show btrfs balance and scrub errors if any; Well, in the 7.18 topic we discussed a little about whether they would use the "btrfs balance" or the "block-level mdraid" function for the RAID setups, and now we know: it is "balance". You can do either on...
by sirbryan
Sun Mar 02, 2025 4:37 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 635
Views: 271304

Re: v7.18 [stable] is released!

*) chr/x86 - Realtek r8169 updated driver;
Does this include the Realtek 8126 updates to the 8169 driver, from kernel 6.12? I've got a couple of Realtek 5G M.2 NICs that show up in the PCI list, but the driver doesn't load for them.
by sirbryan
Sat Mar 01, 2025 8:42 pm
Forum: General
Topic: Is there a list of drivers supported by x86, CHR-x86, and CHR-ARM64?
Replies: 0
Views: 2634

Is there a list of drivers supported by x86, CHR-x86, and CHR-ARM64?

I'm testing a number of small router options, including Intel N100 and N150 boxes, as well as Raspberry Pi CM5, with 2.5G and 5G interfaces. I have some Realtek 2.5G USB dongles that are recognized and usable from x86 on the N150, but I can't seem to get them to load with USB passthrough on the CHR ...
by sirbryan
Fri Feb 28, 2025 4:52 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 635
Views: 271304

Re: v7.18 [stable] is released!

@pe1chl, I have an idea. How many peers do your routers have? Observations starting from 7.16 but still occurring in 7.18: - the backup paths, that have a route filter that sets local preference 90, are often not stored in the route table at all. This is the other thing that stands out to me. Some ...
by sirbryan
Thu Feb 27, 2025 7:58 pm
Forum: Wireless Networking
Topic: 60Ghz Sectors
Replies: 17
Views: 12107

Re: 60Ghz Sectors

I will say this: I have hundreds of Ubiquiti Wave units deployed. Where possible, I'm replacing my 5GHz UI gear (LTU & AirMax) with Wave. I had quite a bit of MikroTik 60GHz also deployed, but I'm overbuilding and replacing it all (slowly) with Tachyon 30X radios. They use the same Peraso chips ...
by sirbryan
Thu Feb 27, 2025 7:34 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 635
Views: 271304

Re: v7.18 [stable] is released!

I have all kinds of BGP issues that were introduced with 7.16, reported, but not yet fixed. In version 7.15.x it worked much better. But I cannot downgrade because I require other fixes. @pe1chl, I have an idea. How many peers do your routers have? I think some of the BGP bugs in 7.15.x and 7.16.x ...
by sirbryan
Fri Feb 21, 2025 4:44 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 35185

Re: v7.18rc [testing] is released!

You have to make sure you're comparing pears to pears (not going to mention apples ;-) ). ROS in principle does firewalling as well and connection tracking machinery (identifying connections to which each packet belongs) is pretty costly operation. OTOH linux kernel might not be doing it. IIRC conn...
by sirbryan
Fri Feb 21, 2025 5:34 am
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 35185

Re: v7.18rc [testing] is released!

FWIW I'm testing CHR on smaller hardware, such as Intel N100 and N150 4-core machines, as well as a Raspberry Pi CM5. 7.18rc1 performs much better than 7.17 did on both systems. Both devices are able to push 2.5Gbps UDP in both directions, and up to 5Gbps when using a 10G AQC107 NIC. However, the na...
by sirbryan
Thu Feb 20, 2025 6:37 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 35185

Re: v7.18rc [testing] is released!

So if i read it correctly it is CCR2216 basically - cheaper, green, different port set and with drivebays, but still CCR2216, right? Yes, Rose Data Server (RDS2216). I built something similar using a CCR2116. Screenshot 2025-02-20 at 9.32.34 AM.png Here's how it looked racked up as part of the home...
by sirbryan
Thu Feb 20, 2025 6:24 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 35185

Re: v7.18rc [testing] is released!

And honestly, why would I buy this if I can simply buy a supermicro server with 9005 epyc, 20+ nvme gen 5 bays, full PCIe bandwidth on all drives, and I can run ROS in a vm? Not to mention I have a full upgrade path with a dedicated mainstream server that can accept any kind of future implementatio...
by sirbryan
Thu Feb 20, 2025 5:15 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 35185

Re: v7.18rc [testing] is released!

by sirbryan
Wed Feb 19, 2025 4:32 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 35185

Re: v7.18rc [testing] is released!

Reading the tea leaves, it seems as though there are other products that have been in the pipeline for a while that are going to leverage these features in ways that our existing RB- and CCR-whatevers may not. And likely in different directions/verticals than most forum posters are used to. That sai...
by sirbryan
Thu Feb 13, 2025 8:57 pm
Forum: General
Topic: Traffic Shaping for 1000+ users as well as AP & Backhauls
Replies: 5
Views: 2763

Re: Traffic Shaping for 1000+ users as well as AP & Backhauls

MikroTik's implementation of things isn't always a straight copy from Linux. They're working with legacy code of their own, older, customized kernels, and a wide variety of hardware platforms. One limitation, for example, was that you couldn't nest Cake queues. Not sure if that's been resolved or no...
by sirbryan
Sat Feb 08, 2025 7:03 am
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 27007

Re: New exciting features for storage

I, for one, welcome our Storage overlords. Those who are poo-pooing things haven't been paying close attention to the hyper-convergence of functions the last decade or two. Cisco built a virtual router for VMware 15 years ago, and VMware created vSAN shortly thereafter. Now you have Proxmox VE + Cep...
by sirbryan
Thu Jan 30, 2025 10:04 pm
Forum: General
Topic: VXLAN CRS v7.18
Replies: 4
Views: 3834

Re: VXLAN CRS v7.18

but do you think that the VXLAN tunnel, closed over a VLAN, in the tunnel just normal traffic without vlan, would work? The only thing you can do is lab it up and give it a try. EdPa put an example of something that works on the 7.18b2 thread. I tried it on a pair of 309's and it works as described...
by sirbryan
Thu Jan 30, 2025 8:51 pm
Forum: General
Topic: VXLAN CRS v7.18
Replies: 4
Views: 3834

Re: VXLAN CRS v7.18

The HW-offload VXLAN support is very basic right now. I couldn't get it to pass tagged traffic coming into the same VLAN from other switches, only untagged traffic (from another port) tagged into the VLAN that the VXLAN is assigned to. So there's still some work to be done. Having it ride over anoth...
by sirbryan
Thu Jan 30, 2025 8:38 pm
Forum: General
Topic: Do you know what CALEA is?
Replies: 4
Views: 3856

Re: Do you know what CALEA is?

In my 25 years in the industry, and 20 years of knowing of CALEA's existence, and being the guy in charge of the back end for most of that time, I can say, at least in the areas I've worked, I've had exactly 0 CALEA requests. Another ISP shared that he got a contact info update request from the FBI ...
by sirbryan
Mon Jan 27, 2025 5:54 pm
Forum: Wireless Networking
Topic: Unstable connection with pair of nRAYG60ad
Replies: 7
Views: 6804

Re: Unstable connection with pair of nRAYG60ad

They run Version 6.49.17, which seems to be the latest on stable channel. They got license level 3. There are some incremental fixes in various versions of 7, including more in 7.18b2. I wouldn't necessarily recommend 7.18b2 yet, but up to 7.12.1 should work. They are using the lowest channel and d...
by sirbryan
Thu Jan 23, 2025 6:10 pm
Forum: Wireless Networking
Topic: Powering of CubeSA 60Pro ac
Replies: 4
Views: 3888

Re: Powering of CubeSA 60Pro ac

Not generally, no. I run all my sites at or above 48V and all the MikroTik gear seems to be just fine.
by sirbryan
Wed Jan 22, 2025 9:11 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 190282

Re: v7.18beta [testing] is released!

>all of these are for untagged VLANs, but can tagged VLANs be bridged to vxlans? Yes, VLAN can be tagged on the Ethernet side (in the example sfp-sfpplus3 or sfp-sfpplus4). But VXLAN cannot encapsulate VLANs, so it must be configured only for a one untagged VLAN. Ed, the following isn't working. Is...
by sirbryan
Wed Jan 22, 2025 7:30 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 190282

Re: v7.18beta [testing] is released!

A configuration example (using static routing, but could be done through ospf,bgp): sfp-sfpplus1 - upstream (underlay) interface sfp-sfpplus3 - bridged port for untagged VLAN 10 sfp-sfpplus4 - bridged port for untagged VLAN 20 vxlan-1010 - overlay port for untagged VLAN 10 vxlan-1020 - overlay port...
by sirbryan
Tue Jan 21, 2025 6:40 pm
Forum: Wireless Networking
Topic: 60GHZ PTMP Performance on short distance
Replies: 6
Views: 3853

Re: 60GHZ PTMP Performance on short distance

Meanwhile UI Wave released another firmware update supporting up to 31 clients per AP, and nice long range on 69120. But these radios are very damn expensive (only the short-range Wave Pico has reasonable price comparable to MT Cube), it's yet another vendor lock-in (they only talk to their own rad...
by sirbryan
Tue Jan 21, 2025 6:01 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 1206362

Re: v7.17 [stable] is released!

Most users like myself can't afford to duplicate their network. IMO MikroTik is making two (2) mistakes, (A) sub-standard software testing (too many regressions) compared to competition, and (B) releasing new features before fixing old bugs. This release is the worst possible combination, releasing...
by sirbryan
Tue Jan 21, 2025 2:25 am
Forum: Wireless Networking
Topic: 60GHZ PTMP Performance on short distance
Replies: 6
Views: 3853

Re: 60GHZ PTMP Performance on short distance

It sounds like they are working as intended. You could try putting some traffic shaping queues, like fq-codel or cake, on the interfaces, limiting the bandwidth to ~900Mbps (or just a bit less) to keep it from saturating the 60GHz interface. It is WiFi-based, after all. Radio-to-radio TCP tests are ...
by sirbryan
Sun Jan 19, 2025 6:05 pm
Forum: Virtualization
Topic: Router OS 7 on UEFI
Replies: 77
Views: 24922

Re: Router OS 7 on UEFI

I don't really expect to get this functioning without MikroTik's involvement, I'm just hoping that more discussion about the platform will see official arm64 images for the cloud providers, as it's getting more popular. I'd like to run it on smaller but beefy ARM64 gear, like the Honeycomb LX2 boar...
by sirbryan
Sun Jan 19, 2025 5:11 pm
Forum: Wireless Networking
Topic: Unstable connection with pair of nRAYG60ad
Replies: 7
Views: 6804

Re: Unstable connection with pair of nRAYG60ad

I bought a pair of nRAYG60ad dishes and installed them in 20 meters distance That could be contributing to the problem, but I doubt it. The Qualcomm radios (in my experience) seem to adjust power automatically towards the -60's (you can't control that at all). What's the signal level? Closer to the...
by sirbryan
Thu Jan 16, 2025 7:33 am
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 170256

Re: v7.17rc [testing] is released!

But I would like it when it gets released and the 7.18beta versions start appearing with again hope for BGP fixes. This night our internet connection failed but the backup via LTE (auto switched using BGP), which worked perfectly at least until 7.12 or 7.15, don't remember exactly, again failed to ...
by sirbryan
Mon Jan 13, 2025 8:17 pm
Forum: General
Topic: Mikrotik for long-haul fiber.
Replies: 15
Views: 3697

Re: Mikrotik for long-haul fiber.

For the bulk of my fiber cores I will be using EDFAs at 10 points along my 250 kilomiter path, but i will be taking 1 pair of fiber for local distribution along that path. I am planning to use a CRS309 at each relay point with Chinese 10G 80 Kilomiter SFP Transducers. What do you think about the CR...
by sirbryan
Sun Jan 12, 2025 7:32 pm
Forum: Forwarding Protocols
Topic: BGP input filter with single provider
Replies: 4
Views: 4814

Re: BGP input filter with single provider

I was wondering if the routing/forwarding tables are used for each packet to determine the next hop, even if the outcome is known in advance. I can't imagine having hundreds or thousands of routes being helpful. Sure, there are optimizations in the routing tree so that packets aren't compared again...
by sirbryan
Sun Jan 12, 2025 7:24 pm
Forum: General
Topic: MLAG - client device with only one active link
Replies: 4
Views: 2564

Re: MLAG - client device with only one active link

Hi @sirbryan, I was in such a hot mess yesterday, I didn't even properly read your message before just letting everyone know that it now works for me. I have three working MLAG stacks I wonder, which devices do you use and have you managed to get a fast LACP rate? I frankly haven't set the untagged...
by sirbryan
Sun Jan 12, 2025 7:16 pm
Forum: General
Topic: Kernel Failure in Previous Boot on CCR2216 Under High Traffic
Replies: 3
Views: 4424

Re: Kernel Failure in Previous Boot on CCR2216 Under High Traffic

Is L3HW offload enabled, or is everything hitting the CPU?

What kind of firewall rules do you have?

How many total external routes is it ingesting?

Are you graphing memory use and CPU load?
by sirbryan
Fri Jan 10, 2025 8:10 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4810459

Re: 📣 WinBox 4 is here 📣

Just loaded the new beta and this is feeling more comfortable. The quick access buttons on the right instead of tabs for the grouped sections is a good compromise, and the table is much more legible. Are the table columns separators and group-quick-access-buttons-now-placed-above-action-buttons (for...
by sirbryan
Fri Jan 10, 2025 6:13 pm
Forum: General
Topic: MLAG - client device with only one active link
Replies: 4
Views: 2564

Re: MLAG - client device with only one active link

While it's "assumed," you should also specifically untag VLAN 1 to mlagbond1 and untag VLAN 97 to the peer. If nothing else, you know for sure you've configured the VLANs to be where you want them. /interface bridge vlan add bridge=bridge tagged=sfp28-4 untagged=mlagbond1 vlan-ids=1 add br...
by sirbryan
Wed Jan 08, 2025 5:52 pm
Forum: General
Topic: what happens when CHR 60 days trial is expired!
Replies: 8
Views: 10710

Re: what happens when CHR 60 days trial is expired!

That is not true and topic is incorrectly marked as solved If you request a trial of the P1, P10 or PU license, it works with all features for 60 days, but after 60 days, RouterOS upgrade gets disabled. Limits do not get applied, it continues to work with no speed limit. So, to clarify, once the tr...
by sirbryan
Wed Jan 08, 2025 4:50 am
Forum: MikroTik hardware questions
Topic: CCR2004-16G-2S+ with more storage?
Replies: 10
Views: 8993

Re: CCR2004-16G-2S+ with more storage?

The newer 16G-2S+ 2004's have USB3 ports. I happen to have two of them. That's what I would use for storage (that was actually the purpose for getting these two routers--testing containers on them), alongside ROSE options to connect to other machines (SMB, NFS, ISCSI, etc.).
by sirbryan
Wed Jan 08, 2025 4:47 am
Forum: Wireless Networking
Topic: Cube PRO distance [SOLVED]
Replies: 3
Views: 10867

Re: Cube PRO distance [SOLVED]

Ubiquiti AF60LR will get you 2Gbps aggregate (1Gbps "full duplex"), and Wave LR will get you 1500Mbps aggregate (up to 1Gbps each way and 500 the other, or 700-800ish both ways simultaneously). Wave LR has a backup 5GHz radio in case of rain fade, although at that distance both radios shou...
by sirbryan
Wed Jan 08, 2025 4:42 am
Forum: Forwarding Protocols
Topic: ROS7 BGP routing filters
Replies: 3
Views: 4062

Re: ROS7 BGP routing filters

If filters are configured, the default on ROS 7 is to reject, so the additional rejections are unnecessary.

What you could do is change your first rule to
if (dst in 2001:db8:abcd::/48 && dst-len in 32-48) { accept; }
by sirbryan
Fri Jan 03, 2025 5:57 am
Forum: Forwarding Protocols
Topic: BGP and OSPF on the same interface with BFD
Replies: 3
Views: 4630

Re: BGP and OSPF on the same interface with BFD

Of course, you're right about the purpose of the BFD. BGP and OSPF timer tweak - its a bad practice in my opinion. But if BFD is enabled only on OSPF or only on BGP, everything works correctly (BFD session uptime up to 12h). If i enable BFD on both routing protocols, routing stops working suddenly(...
by sirbryan
Thu Jan 02, 2025 6:47 pm
Forum: Forwarding Protocols
Topic: BGP and OSPF on the same interface with BFD
Replies: 3
Views: 4630

Re: BGP and OSPF on the same interface with BFD

Tweak your BFD settings to be more forgiving of the packet loss or jitter detected on the wireguard tunnel, or don't use it at all. Just keep your BGP and OSPF timers down to their minimums, unless you have two or three such links. Why do you need BFD over the wireguard tunnel? It's designed to prov...
by sirbryan
Tue Dec 31, 2024 7:03 pm
Forum: Forwarding Protocols
Topic: Efficient connection between Router an Switch
Replies: 1
Views: 4082

Re: Efficient connection between Router an Switch

The CRS317 can route between VLANs and switch between 10G ports at wire speed. Use it for all your internal VLANs and L3HW offload will work fine. The limitation in your setup will be the 2004's processor. Every connection from the 2004 to the 317, be it Layer 2 or Layer 3, will be CPU-bound. The 20...
by sirbryan
Fri Dec 20, 2024 6:57 am
Forum: General
Topic: Help needed: Choosing an alternative for CCR2216
Replies: 26
Views: 5664

Re: Help needed: Choosing an alternative for CCR2216

L3HW should work if you don't have any VLANs, and simply assign IP's to each port. It is "best practices" to put everything in the bridge, build VLANs on the bridge, tag those VLANs to the bridge ports, create VLAN interfaces on the bridge, and assign IP's to the bridge VLAN interfaces ins...
by sirbryan
Thu Dec 19, 2024 8:10 pm
Forum: RouterOS beta
Topic: MAJOR webfig issues, on ALL versions 7.x
Replies: 10
Views: 7569

Re: MAJOR webfig issues, on ALL versions 7.x

There was RouterOS version number on 6 in webfig on top of the page. Now I have to go system packages to know the version. What happened with the old design?
Yes, that is lame. More easy-to-see useful information gets removed the further we go into 7.
by sirbryan
Thu Dec 19, 2024 6:44 pm
Forum: MikroTik hardware questions
Topic: CCR2216 M.2 slot length
Replies: 5
Views: 7891

Re: CCR2216 M.2 slot length

I'm more concerned about why there are M.2 SATA III slots on the flagship product, whereas the CCR2116 has a proper M.2 PCIex3 slot. The supply of M.2 SATA will eventually die off and now I'll have router with irreplaceable SATA disks.
Buy a few spares.... That should get you a good 10-20 years.
by sirbryan
Thu Dec 19, 2024 6:41 pm
Forum: General
Topic: Help needed: Choosing an alternative for CCR2216
Replies: 26
Views: 5664

Re: Help needed: Choosing an alternative for CCR2216

I have no bridge.

Should I create a bridge with all physical ports or bonds that I am using and set up properly in VLAN tab of the bridge?
Double yes.
by sirbryan
Thu Dec 19, 2024 6:37 pm
Forum: Forwarding Protocols
Topic: BGP input filter with single provider
Replies: 4
Views: 4814

Re: BGP input filter with single provider

Or you can use NLRI filtering on the MikroTik to only allow 0.0.0.0/0. There may come a time when you get a second provider and want to start using those BGP routes for egress decisions.
by sirbryan
Tue Dec 17, 2024 6:17 pm
Forum: General
Topic: Help needed: Choosing an alternative for CCR2216
Replies: 26
Views: 5664

Re: Help needed: Choosing an alternative for CCR2216

Any other sugestion? :?: Your question is missing important detail: How many upstream peers? How many downstream peers (if any)? Do you need full BGP tables? Are you using L3HW offload, and if so, is the router configured properly to support hardware offload? What does the profiler say is pegging y...
by sirbryan
Fri Dec 13, 2024 6:49 pm
Forum: General
Topic: CCR2004-1G-12S+2XS - Hardware switching features
Replies: 4
Views: 6232

Re: CCR2004-1G-12S+2XS - Hardware switching features

I bought this thing. It has 25G interfaces to be a typical bridge, but there is no way to transfer even 10G in bridge mode. Is this some kind of joke? You bought router which happens to have 2x 25Gbps ports (and some others). Official test results tell that thing can route at speeds between 5Gbps a...
by sirbryan
Fri Dec 13, 2024 6:24 am
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 258046

Re: v7.16.2 [stable] is released!

No, I don't have a test lab to do that. I do. if you're interested in cloning a sanitized version of your configs, I have four RB5009's and two CCR2004's racked up, with two more 5009's on the shelf. Or we could spin up a bunch of CHR VM's, use GNS3, etc. I backed my 2116 off to 7.15.3 early this m...
by sirbryan
Thu Dec 12, 2024 7:33 pm
Forum: General
Topic: CCR2216 - Issues
Replies: 11
Views: 2812

Re: CCR2216 - Issues

More specifically: I am running L3HW offload on several CRS300's, using them as site or edge (customer-facing) routers. They work great, unless they have diverse routes with equal cost. In that case, they will eventually get confused and routes will get "stuck" going out the wrong port, de...
by sirbryan
Wed Dec 11, 2024 7:36 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 258046

Re: v7.16.2 [stable] is released!

I have seen those issues in 7.16 as well: a single disconnected peer disconnects multiple or all peers at the same time, and routes via disconnected peers still appearing in the table. The first I was able to improve a bit by forcing all BGP handling into a single process (input.affinity=main outpu...
by sirbryan
Wed Dec 11, 2024 7:30 pm
Forum: General
Topic: CCR2216 - Issues
Replies: 11
Views: 2812

Re: CCR2216 - Issues

We enabled "full" L3HW. After ~24 hours, a dozen or so of these customers started calling and complaining they were not getting traffic. On inspection we were seeing something like in main table: DAoH 0.0.0.0 -> sfpA DAoH 10.0.0.0/24 -> sfpA DAoH 10.0.0.42/32 -> sfpB For all these custome...
by sirbryan
Fri Dec 06, 2024 1:53 am
Forum: General
Topic: CRS510-8XS-2XQ-IN High CPU Netwoking process
Replies: 11
Views: 2073

Re: CRS510-8XS-2XQ-IN High CPU Netwoking process

Post your config (sanitized) and one of us can possibly point to what's happening.
by sirbryan
Thu Dec 05, 2024 12:15 am
Forum: General
Topic: Is there a SwOS version compatible with CRS304-4XG-IN?
Replies: 8
Views: 4895

Re: Is there a SwOS version compatible with CRS304-4XG-IN?

Thanks for this topic. Last Friday I bought CRS304-4XG-IN under impression from reviews that it can dual boot RouterOS / SwOS. As I need maximalize switching throughtput and I don't need L3 functions for my use case, ... I'll make some switching throughput tests when the rest of 10 Gbps hardware ar...
by sirbryan
Thu Dec 05, 2024 12:09 am
Forum: General
Topic: CRS510-8XS-2XQ-IN High CPU Netwoking process
Replies: 11
Views: 2073

Re: CRS510-8XS-2XQ-IN High CPU Netwoking process

Hello mkx, I tried activating the L3HW using the following commands: Switch Configuration /interface/ethernet/switch set 0 l3-hw-offloading=yes Switch Port Configuration /interface/ethernet/switch/port set sfp-sfpplus1 l3-hw-offloading=yes But it didn't have a positive impact on the cpu uitilizatio...
by sirbryan
Fri Nov 29, 2024 2:23 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 10294

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

I'm considering the idea of moving all routing away from the WG endpoint, and instead having the work split across two (or more) devices: WG tunnel terminators at each end, and have them hand off EOIP/VXLAN/IPIP/whatever to the next router(s) up/down the line. This way the WG router doesn't get conf...
by sirbryan
Mon Nov 25, 2024 6:39 pm
Forum: Wireless Networking
Topic: Mini ISP Setup, help needed
Replies: 9
Views: 4283

Re: Mini ISP Setup, help needed

My target is like this, probably 10 to 20 house per community, then each house estimate average 5 users, then total probably will be 50 to 100 users, then my concern not for the device but the speed from ISP is it can cater this scope of my Mini WISP, based on all of your guys experience With just ...
by sirbryan
Mon Nov 25, 2024 6:34 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 170256

Re: v7.17rc [testing] is released!

The new webfig has a similar problem to winbox4 where that status/flags are very difficult to interpret. For example, LINK OK and NO LINK are radically different states - yet the only difference is the text inside. Being disabled/reversed is what old webfig did and it was far more readable. Or perh...
by sirbryan
Fri Nov 22, 2024 6:24 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 26821

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

I think MT should speak to Cloudflare bizdev folks about some partnership... they'd might trade figuring out DoH for shipping a native Cloudflare package a la ZeroTier. Noting that despite a range of dozens potential solutions (AWS, Azure, Cisco, PaloAlto, etc etc etc) to the DoS problem... the com...
by sirbryan
Fri Nov 22, 2024 3:15 am
Forum: MikroTik hardware questions
Topic: CRS304-4XG-IN is amazing,and CRS304-8XG-IN will be release?
Replies: 6
Views: 8080

Re: CRS304-4XG-IN is amazing,and CRS304-8XG-IN will be release?

An outdoor version of this with POE (and maybe one SFP+ port), like the outdoor version of the CRS305, would be pretty sweet too.
by sirbryan
Thu Nov 21, 2024 12:12 am
Forum: Containers
Topic: Running GUI apps in container
Replies: 5
Views: 7082

Re: Running GUI apps in container

I got it to work on my home/office 2116. Firefox is responsive enough, although throughput tests leaves a bit to be desired (1Gbps is all). The CPUs were pretty busy, as expected without a dedicated GPU handling things. The first immediately useful thing I can think of would be running The Dude clie...
by sirbryan
Wed Nov 20, 2024 6:51 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225751

Re: v7.17beta [testing] is released!

Thank you for listening.
by sirbryan
Sat Nov 16, 2024 1:32 am
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225751

Re: v7.17beta [testing] is released!

blingblouw2 you can just enable bandwidth test. ask the user to push the button to confirm. it's a one time operation, you don't have to do it every time. You act like it's no big deal, but I have hundreds MikroTik devices to which I run bandwidth tests as part of regular troubleshooting. These are...
by sirbryan
Wed Nov 13, 2024 4:30 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225751

Re: v7.17beta [testing] is released!

I hope that MikroTik will also fix MLAG. In fact, all of us who have purchased the CRS520 and CRS518 are eagerly awaiting ROS 7.17 and stable MLAG. What about MLAG specifically doesn't work for you? I have it working with a 354 and 312 in "lab production" at my desk (runs my home and offi...
by sirbryan
Fri Nov 08, 2024 4:53 am
Forum: General
Topic: 1 Packet over Multiple Routs?
Replies: 14
Views: 2470

Re: 1 Packet over Multiple Routs?

Check my link in my profile. There's a way to contact me...
by sirbryan
Thu Nov 07, 2024 4:58 am
Forum: General
Topic: CCR2216 Poor TCP Performance & Interface Queues (multi-queue-ethernet / mq fifo)
Replies: 7
Views: 2199

Re: CCR2216 Poor TCP Performance & Interface Queues (multi-queue-ethernet / mq fifo)

Update. It's now peak hours and I checked in on one of my BGP core routers. It has no forward firewall rules, only input. It runs at about 10% CPU pushing 3.5-4Gbps, and 400K packets. All RX traffic is hitting FastPath. This is over a bonded pair of SFP+ interfaces. I also looked at the busiest bord...
by sirbryan
Thu Nov 07, 2024 4:40 am
Forum: General
Topic: 1 Packet over Multiple Routs?
Replies: 14
Views: 2470

Re: 1 Packet over Multiple Routs?

Interesting!! Be cool for the sirbryan to conduct single router to single router tests of this tech, comparing zerotier to wireguard performance......... According to the various Reddit posts etc. that I came across when researching my original reply, Wireguard is faster than ZeroTier. And in my ow...
by sirbryan
Wed Nov 06, 2024 6:52 pm
Forum: General
Topic: 1 Packet over Multiple Routs?
Replies: 14
Views: 2470

Re: 1 Packet over Multiple Routs?

Apparently ZeroTier does Multipath. The question remains as to whether or not MikroTik's implementation supports it yet. But on Linux, you have a few options: Standard policies active-backup: Use only one primary link at a time and failover to another designated link. broadcast: Duplicate traffic ac...
by sirbryan
Wed Nov 06, 2024 5:31 pm
Forum: General
Topic: 1 Packet over Multiple Routs?
Replies: 14
Views: 2470

Re: 1 Packet over Multiple Routs?

What you're talking about is called packet duplication and is an SD-WAN vendor technique. Cisco, Fortinet, Velocloud, and so on all use it. From an article by Cisco (their product is Cisco Catalyst SD-WAN): https://learningnetwork.cisco.com/s/article/cisco-catalyst-sd-wan-optimizations-for-starlink ...
by sirbryan
Wed Nov 06, 2024 5:21 pm
Forum: SwOS
Topic: What are the security concerns with using a CRS305-1G-4S+ in front of each of my routers' WAN ports?
Replies: 1
Views: 6562

Re: What are the security concerns with using a CRS305-1G-4S+ in front of each of my routers' WAN ports?

If you put a private IP, they shouldn't be reachable from the world. For that matter, you could use VLANs to encapsulate the traffic, and set up access rules that only allow access from a different VLAN or from a specific (internal) IP. With RouterOS, you could do a couple more fancy tricks with the...
by sirbryan
Wed Nov 06, 2024 5:07 pm
Forum: General
Topic: wAP coverage -- picture included
Replies: 43
Views: 5760

Re: wAP coverage -- picture included

I would love a dual band, 120 to 180 degree azimuth, 10-15dbi gain, dual RP-SMA antenna. That would be fun to play with. They exist, but I think there isn't enough demand for them to keep making them (people want more gain, not to be hampered by dual-band designs). This is one I found at one of my ...
by sirbryan
Wed Nov 06, 2024 4:56 pm
Forum: General
Topic: CCR2216 Poor TCP Performance & Interface Queues (multi-queue-ethernet / mq fifo)
Replies: 7
Views: 2199

Re: CCR2216 Poor TCP Performance & Interface Queues (multi-queue-ethernet / mq fifo)

I haven't noticed similar issues, but then I'm only pushing about 3Gbps of traffic, and at the moment (morning) we're only around 200Kpps. (I haven't looked at PPS during peak hours.) On all but one of my CCR2116's (three as border routers, two as BGP core and two as CGNAT), I created an fq-codel qu...
by sirbryan
Sat Nov 02, 2024 2:56 am
Forum: General
Topic: Controversal - MikroTik state of technology
Replies: 11
Views: 1500

Re: Controversal - MikroTik state of technology

He probably bases it on the fact that the US isn't the world. In Europe, WISPs pretty much don't exist. Wireless PTP links are a niche. Depends on the country. There are several European WISPS on the Facebook WISP Talk group. Some European and Asian countries are so dense, running fiber is consider...
by sirbryan
Fri Nov 01, 2024 10:54 pm
Forum: General
Topic: Controversal - MikroTik state of technology
Replies: 11
Views: 1500

Re: Controversal - MikroTik state of technology

MikroTik 60Ghz is quite good. Much better than their current AX outdoor products. The 60Ghz and 80Ghz market is growing and I feel MikroTik 60Ghz is more stable and reliable than their AX products. I feel they would be better focused and produce better satisfactory response from customers. First wo...
by sirbryan
Thu Oct 31, 2024 4:07 am
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225751

Re: v7.17beta [testing] is released!

It's bad to the extent that all that complaining about changes in device-mode made Mikrotik Guys go back to hiding progress, and stop releasing testing with every possible release. Every company on the planet that releases alphas and betas is doing so for user feedback. With MikroTik, unless you're...
by sirbryan
Fri Oct 25, 2024 6:54 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 258046

Re: v7.16.1 [stable] is released!

My routers do not receive internet routing tables but only a couple of local networks (company networks routed over VPN), but the problem is the same. It for sure is not related to large routing tables. So did you change everything to input=main, output=input? After upgrading my borders and core (5...
by sirbryan
Fri Oct 25, 2024 6:14 pm
Forum: MikroTik hardware questions
Topic: CCR2004-1G-12S+2XS rebooting
Replies: 4
Views: 11223

Re: CCR2004-1G-12S+2XS rebooting

Hello, my CCR2004-1G-12S+2XS is random rebooting aprox. once a day with error in log: Any suggestions to software fix this problem or should I reach my supplier with hardware change or fix? What version of RouterOS is it running? There were known problems with 2004's rebooting, particularly some of...
by sirbryan
Fri Oct 18, 2024 9:36 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225751

Re: v7.17beta [testing] is released!

What's new in 7.17beta4 (2024-Oct-18 11:32): !) device-mode - after upgrade, mode "enterprise" is renamed to "advanced" and bandwidth-test, traffic-gen, partition (command "repartition"), bootloader and downgrade features will be disabled; Instead of listening to the c...
by sirbryan
Tue Oct 15, 2024 5:22 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225751

Re: v7.17beta [testing] is released!

The problem with a jump version is it leaves the admin with a one time only choice, what options do I set? Now if you want to secure the device in case of possible future exploit you should choose the minimum options required. But what do you do if a year down the track you suddenly discover that a...
by sirbryan
Tue Oct 15, 2024 1:51 am
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225751

Re: v7.17beta [testing] is released!

What is your proposal, to verify ownership of a device in a way, that a remote attacker can't do? Put a QR Code on the router which we can scan and save in our management software before deploying the routers. New deployments aren't as big of a problem as existing deployments, as I can readily enab...
by sirbryan
Fri Oct 04, 2024 5:42 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225751

Re: v7.17beta [testing] is released!

above quoted line from the manual > "you can use the "save config" button to copy it over to other partitions."" this can be done without any device mode changes, limitation only is applied to manual re-booting to other partition, if main one is still working And this is th...
by sirbryan
Thu Oct 03, 2024 9:56 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225751

Re: v7.17beta [testing] is released!

Let me remind you, that if your device has some need to be routinely switched between partitions all the time, send somebody to unplug it from power ONCE in it's lifetime, to enable device mode setting for this. Let me remind you that you guys are adding both fixes and features in RouterOS 7 at a f...
by sirbryan
Wed Oct 02, 2024 5:54 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225751

Re: v7.17beta [testing] is released!

The documentation says: [D]evices running versions prior to RouterOS version 7.17, all devices use the advanced/enterprise mode and: (Disabled features in advanced mode) traffic-gen, container, partitions, bootloader and, as mentioned in another post: container, fetch, scheduler, traffic-gen, ipsec,...
by sirbryan
Tue Oct 01, 2024 7:21 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225751

Re: v7.17beta [testing] is released!

I use and enable partitions remotely ***all the time*** (on anything with large enough flash, particularly RB4011/5009/CCR's). And sometimes I forget to set all the things while I have physical access to it (i.e. on the bench/in the lab) before I deploy the router in the field. Blocking the ability ...
by sirbryan
Fri Sep 20, 2024 7:07 pm
Forum: 3rd party tools
Topic: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management
Replies: 82
Views: 32630

Re: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management

Any reason we couldn't get this to work on a decent-sized CCR with containers? I'm thinking at minimum a CCR2004 4GB RAM and external storage or more likely a CCR2116/2216 with SSD's. Can you please provide more information? Installation method? any errors you face? and which part is not working? P...
by sirbryan
Fri Sep 20, 2024 3:31 am
Forum: Announcements
Topic: Question to our users about controllers
Replies: 127
Views: 210426

Re: Question to our users about controllers

As an internet Service Provider, that also is considering more of a Managed Service Provider role: For my own stuff, locally-hosted servers are a must, and containers (or an NPK on a CCR2xxx/CHR would be cool). I like how Ubiquiti keeps UniFi separate from UISP. I use UniFi to manage customer's inte...
by sirbryan
Thu Sep 19, 2024 5:59 pm
Forum: Wireless Networking
Topic: iOS 18 Wi-Fi connectivity issue [SOLVED]
Replies: 90
Views: 37572

Re: iOS 18 Wi-Fi connectivity issue [SOLVED]

Have those of you having issues tried older versions of RouterOS? I have been running the iOS 18 betas on my phone since WWDC. I have also installed dozens of hAP AX3's since then, which I test from my phone or M1 MacBook Pro (which has been running the Sequoia betas). I netinstall 7.14.x (2 or 3, f...
by sirbryan
Thu Sep 12, 2024 4:46 pm
Forum: MikroTik hardware questions
Topic: CCR2004-1G-12S-2XS - are there any "before you buy" caveats?
Replies: 13
Views: 16819

Re: CCR2004-1G-12S-2XS - are there any "before you buy" caveats?

I am currently looking at the CCR2004-1G-12S-2XS myself, but leaning more towards the CCR2116-12G-4S+. I think it will be a better buy. Just a bit worried about the power consumption. The 2004 12S is probably best suited for someone who needs to have a lot of SFP+ ports connected but only with burs...
by sirbryan
Thu Sep 12, 2024 2:52 am
Forum: 3rd party tools
Topic: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management
Replies: 82
Views: 32630

Re: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management

Any reason we couldn't get this to work on a decent-sized CCR with containers? I'm thinking at minimum a CCR2004 4GB RAM and external storage or more likely a CCR2116/2216 with SSD's.
by sirbryan
Mon Sep 09, 2024 5:40 pm
Forum: General
Topic: CCR2004 as ZeroTier VPN concentrator
Replies: 5
Views: 1304

Re: CCR2004 as ZeroTier VPN concentrator

ZeroTier is Wireguard wrapped up in a nice management package. How much processing power you need boils down to how many clients you plan to have connected to it, and how much traffic (packets per second more than bandwidth) you're going to push. If all you're connecting is a bunch of smart devices ...
by sirbryan
Thu Sep 05, 2024 5:50 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304888

Re: v7.15.3 [stable] is released!

After further inspection, CRS300's (CRS310, NetPower16/CRS318) that are participating in OSPF/BGP had really low RAM available numbers, related to the number of days of uptime (4 days = 64MB of RAM left, 8 days uptime = only 22MB of RAM left), whereas those acting as switches are fine (160-170MB of ...
by sirbryan
Thu Sep 05, 2024 6:52 am
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304888

Re: v7.15.3 [stable] is released!

I've submitted a ticket, but wanted to post here just in case someone else has seen a similar problem. I have five CCR2116's in a full iBGP mesh. Three are peers with other providers, two sit in our core. We take full routes, but filter out AS-PATH's longer than 2 ASN's. For a couple of years this h...
by sirbryan
Mon Sep 02, 2024 11:54 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4810459

Re: 📣 WinBox 4 is here 📣

I feel like the combo box to select what used to be tabs is a regression. It takes up the same about of verticle space but now requires 2+ clicks. I preferred tabs in some of the windows like interface settings/status/traffic for example, now it's on a roll down within the main window. It's ok, may...
by sirbryan
Thu Aug 29, 2024 7:24 pm
Forum: Forwarding Protocols
Topic: BGP Filter Issue Between MikroTik v7 and Cisco Routers
Replies: 9
Views: 6308

Re: BGP Filter Issue Between MikroTik v7 and Cisco Routers

What does your "default" template look like? Does the Cisco VPLS NLRI need to be set (this isn't for VPLS, is it)?
by sirbryan
Thu Aug 29, 2024 7:08 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4810459

Re: 📣 WinBox 4 is here 📣

Props to the developers. This work is not an easy feat to accomplish. Looking forward to the progress in coming releases. I don't want to sound so negatively but some really bad practices (in terms of UI) made it into this new Winbox. Are there any UI/UX designers working for/at Mikrotik? Welcome to...
by sirbryan
Mon Aug 26, 2024 5:30 pm
Forum: Forwarding Protocols
Topic: L3HW: Route HW table FULL
Replies: 5
Views: 5714

Re: L3HW: Route HW table FULL

It means that you've maxed out the L3 HW-offload memory, and any packets destined for routes that aren't in the ASIC will be routed by the CPU like any other CCR or RB device. The only way to "fix" this "problem" is to create filters reducing the amount of routes your router inge...
by sirbryan
Mon Aug 26, 2024 5:19 pm
Forum: General
Topic: l3HW init error CCR2116 packet loss
Replies: 8
Views: 1752

Re: l3HW init error CCR2116 packet loss

Unless (or until) it's been fixed, MPLS is limited to a single CPU core in one direction (encapsulation or decapsulation, I forget which) in RouterOS 7. There's a thread about it on the forums. (I tested it on a pair of 2004's and posted my results there.) Since the 2116 has more slower cores than 2...
by sirbryan
Fri Aug 16, 2024 11:06 pm
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 138639

Re: v7.16rc [testing] is released!

FYI: MLAG issue: two CRS317 in MLAG, with ESX hosts dual connected to CRS317 (not LACP, but having ESX decide which switch to send traffic based on the port up status, and the MAC address of the VM). When switch 1 goes down for firmware upgrade, all is ok, ESX starts using switch 2 for all VMs. Whe...
by sirbryan
Thu Aug 15, 2024 6:51 pm
Forum: Forwarding Protocols
Topic: BGP Filter Issue Between MikroTik v7 and Cisco Routers
Replies: 9
Views: 6308

Re: BGP Filter Issue Between MikroTik v7 and Cisco Routers

Does /routing/bgp/advertisements/print on the ROS7 -> Cisco match what you see on ROS -> ROS?
by sirbryan
Thu Aug 15, 2024 6:05 am
Forum: Wireless Networking
Topic: Mikrotik w60g PTP Config [SOLVED]
Replies: 10
Views: 6544

Re: Mikrotik w60g PTP Config [SOLVED]

Thank you, got your point. What I have done is that although I have enabled bridge vlan filtering but I have tagged all the vlans that would be used by CPE in that region and also few management vlans. What I have understood from your point is that I should create vlan 2003,2004 on bridge interface...
by sirbryan
Wed Aug 14, 2024 5:39 pm
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 138639

Re: v7.16rc [testing] is released!

That's not how the standard works, which is years-old, by the way. (Google for Channel Switch Announcement, 802.11h.) Oh, did not know that there is a separate standard. Thanks for the information. Googled it, should be defined in IEEE 802.11-2012. But when it really is this, I would want Mikrotik ...
by sirbryan
Tue Aug 13, 2024 3:28 am
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 138639

Re: v7.16rc [testing] is released!

But it could also be that the AP just promotes the 2ghz BSSID when the 5ghz BSSID goes down for scanning (or vice versa)...
That's not how the standard works, which is years-old, by the way. (Google for Channel Switch Announcement, 802.11h.)
by sirbryan
Tue Aug 13, 2024 1:10 am
Forum: General
Topic: CCR 1016-12G 2Gbit upgrade recomendation
Replies: 6
Views: 1400

Re: CCR 1016-12G 2Gbit upgrade recomendation

As for the ISP speed that was just what they called it, I would guess it really is 2.5Gb. I will look into the bonded pair, have looked at LACP but as I understand it that only gives 1Gb with redundancy. An ISP can sell whatever they want and call it whatever they want. Comcast/Xfinity out here has...
by sirbryan
Mon Aug 12, 2024 6:27 pm
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 138639

Re: v7.16rc [testing] is released!

But with the change of 7.16 something changed and it may not noticable because anymore: *) wifi - send channel switch announcements to clients when switching channels at requested re-select intervals; But I don't know what it actually does. Mikrotik did not explain it thoroughly. The AP has the abi...
by sirbryan
Sat Aug 10, 2024 3:34 pm
Forum: Wireless Networking
Topic: Cube 60 Pro Series - 802.11ay
Replies: 47
Views: 18885

Re: Cube 60 Pro Series - 802.11ay

Two years later... still no TG, still max 8 stations per AP. Meanwhile the U competitor has increased the number from 15 to 24, and have GPS sync, and channel 6 too (much longer range). The max station per AP limit is a function of the chipset. Qualcomm's limit is at 8. Peraso (Ubiquiti and Tachyon...
by sirbryan
Tue Jul 30, 2024 6:17 pm
Forum: General
Topic: Wi‑Fi 7 / 802.11be
Replies: 118
Views: 52302

Re: Wi‑Fi 7 / 802.11be

Chateau is deployed for LTE or 5G areas. This is what these Chateaus makes expensive: their modems. You can expect which speeds on LTE/5G in real world? And with these tremendous speeds 5G/LTE offer it makes no sense to have an SFP port. It makes even no sense to have more than 2.5g ports. And agai...
by sirbryan
Tue Jul 30, 2024 5:54 pm
Forum: Beginner Basics
Topic: lot of sites dont load on the first try
Replies: 16
Views: 3130

Re: lot of sites dont load on the first try

And thats it? At first glance it might have worked.
Generally, yes. The low number (in your example, 1460) just needs to be below the threshold of whatever is blocking larger packets upstream.
by sirbryan
Tue Jul 30, 2024 5:49 pm
Forum: Wireless Networking
Topic: Mikrotik w60g PTP Config [SOLVED]
Replies: 10
Views: 6544

Re: Mikrotik w60g PTP Config [SOLVED]

Unless you want to keep specific VLANs from going through the link, don't mess with bridge VLAN filtering and don't add them to the bridge VLAN table. For just two radios in a PTP config, it's simply enough to create a VLAN interface (attached to the radio's bridge) with the VLAN tag (2003 or 2004) ...
by sirbryan
Mon Jul 29, 2024 6:37 am
Forum: Beginner Basics
Topic: lot of sites dont load on the first try
Replies: 16
Views: 3130

Re: lot of sites dont load on the first try

This sounds like an MTU problem. Are you using a VPN?

There should be a mangle rule that clamps the TCP MSS to the MTU. Sometimes it's automatic if you have a PPP-based link.
by sirbryan
Fri Jul 19, 2024 5:59 pm
Forum: Forwarding Protocols
Topic: OSPF out route filter V7.XX
Replies: 2
Views: 5643

Re: OSPF out route filter V7.XX

If you set up a filter for OSPF out, it will, by default, reject everything and only allow what you want to go out. So, for example, if I want 10.0.0.0/24 to go out, my filter would be: if (dst==10.0.0.0/24) { accept; } In this case, I want to allow any subnets within the 10.0.0.0/8 range. Use "...
by sirbryan
Thu Jul 18, 2024 1:24 am
Forum: General
Topic: Wi‑Fi 7 / 802.11be
Replies: 118
Views: 52302

Re: Wi‑Fi 7 / 802.11be

you must choose: 16mb or SFP+. Can't have both 😅 But joke aside: Chateau line is ISP equipment. Why would one need SFP+ on a consumer device. Because companies like Google are offering 2.5Gbps and 5Gbps service. Even if nobody needs it, an SFP+ port allows the customer (or ISP providing customer eq...
by sirbryan
Wed Jul 17, 2024 2:07 am
Forum: MikroTik hardware questions
Topic: CCR1009 replacement for BGP
Replies: 13
Views: 7112

Re: CCR1009 replacement for BGP

Why do you think badly? It wasn't to contradict you, but to confirm: I also modified my previous post...
OK, that makes more sense.
by sirbryan
Tue Jul 16, 2024 10:43 pm
Forum: MikroTik hardware questions
Topic: CCR1009 replacement for BGP
Replies: 13
Views: 7112

Re: CCR1009 replacement for BGP

I own two of them and have run a series of throughput tests, both bridging across ports and routing across ports. They are lousy at routing much over 3Gbps unless you have zero filters/rules, at which point the CPU can push about 19Gbps in+out (at 99% utilization). By including the diagram, you're p...
by sirbryan
Tue Jul 16, 2024 8:01 pm
Forum: MikroTik hardware questions
Topic: CCR1009 replacement for BGP
Replies: 13
Views: 7112

Re: CCR1009 replacement for BGP

The CCR2004-1G-12S+2XS does not have a switch chip. All ports are bridged to the CPU by way of the PIPE chip thing. The CCR2004-16G-2S+ (and Passively Cooled version) has two 8-port switches. (We're ignoring the PCIe version of the CCR2004.) The RB4011 has two 5-port switches. The SFP+ ports on the ...
by sirbryan
Tue Jul 16, 2024 7:25 pm
Forum: MikroTik hardware questions
Topic: CCR1009 replacement for BGP
Replies: 13
Views: 7112

Re: CCR1009 replacement for BGP

The RB4011, RB5009, and CCR2004 all have relatively the same speed of quad-core processor, with 4011 being arm32 and 5009 and 2004 arm64. The 5009 has three ways to power it (triple redundancy), and has a POE-out option should you need/want it. Heck, you can get two or three RB5009's for $600. The C...
by sirbryan
Mon Jul 15, 2024 7:18 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304888

Re: v7.15.2 [stable] is released!

Why is it important? Maybe somebody else has another "very important" variable they need everywhere. We can't cram everything in one screen. Some of us manually manage hundreds to thousands of devices (radios, routers, switches), and being able to see at a glance (like we used to be able ...
by sirbryan
Thu Jul 11, 2024 5:50 pm
Forum: Wireless Networking
Topic: 60Ghz success
Replies: 25
Views: 8567

Re: 60Ghz success

Good to know, thanks, but in normal operation is 5 GHz completely disabled or - since it is a (useful BTW) sort of failover link - it is in a sort of standby mode (thus consuming anyway some power)? From experience with other devices in "normal operation" devices consume anyway much less ...
by sirbryan
Tue Jul 09, 2024 6:35 pm
Forum: Announcements
Topic: Newsletter #119 | July 2024
Replies: 37
Views: 55471

Re: Newsletter #119 | July 2024

In the meantime, WISPs worldwide wait for a vendor to bump existing 48-57V passive POE switches from 1Gbps to 2.5Gbps ports (and more than four of them) to run their Wave and Tachyon gear, and with 40-90W, it would even support their Cambium and Siklu (and others?) PTP links. The RB5009Pr-outdoor wa...
by sirbryan
Wed Jul 03, 2024 7:39 am
Forum: Beginner Basics
Topic: VRRP bridge in MikroTik
Replies: 11
Views: 2557

Re: VRRP bridge in MikroTik

I made a typo and put 192.168.0.x instead of 192.168.10.x (post edited), but my point still stands. Your vlan10-ether1 interface's IP address is 192.168.1.11x with a network of 192.168.10.0. Your vrrp1-ether2-vlan10 is 192.168.10.254 with a network of 192.168.10.254. The network should match that of...
by sirbryan
Tue Jul 02, 2024 10:15 pm
Forum: Beginner Basics
Topic: VRRP bridge in MikroTik
Replies: 11
Views: 2557

Re: VRRP bridge in MikroTik

If your VRRP interface is using an IP address in the same subnet as the master interface (192.168.10.0/24), then the network (192.168.10.0) and subnet mask (/24 or 255.255.255.0) has to match. The network for the IP address 192.168.10.254 should be 192.168.10.0, not 192.168.10.254. If you were to us...
by sirbryan
Fri Jun 28, 2024 9:11 pm
Forum: Wireless Networking
Topic: WirelessWire Cube Pro Speed
Replies: 3
Views: 1582

Re: WirelessWire Cube Pro Speed


1) Frequency = 62640 or 66960
At 20 feet, these will run pretty hot regardless of the channel.

66960 is best for long range, followed by 64800 and 58320.

62640 or 60480 have the highest oxygen absorption (although at 20 feet it really won't matter).
by sirbryan
Wed Jun 26, 2024 7:02 pm
Forum: Forwarding Protocols
Topic: ECMP not working
Replies: 8
Views: 6732

Re: ECMP not working

You might have to resort to using two VRF's and mangling traffic to split across the two VRF's. It wouldn't be ECMP, but it would accomplish the same purpose. If you really want ECMP, two routers could do it, one in front with two VRF's, each with a PPPoE link and a gigabit port, handing off those t...
by sirbryan
Tue Jun 25, 2024 5:09 pm
Forum: Wireless Networking
Topic: Wifi-qcom / WiFi-qcom-ac inconsistent country code regulations for United Kingdom
Replies: 17
Views: 4833

Re: Wifi-qcom / WiFi-qcom-ac inconsistent country code regulations for United Kingdom

If it's any consolation, the US rules for U-NII-1 and U-NII-3 have allowed for more power for almost a decade, particularly in PTP outdoor mode on the upper end of the band. Yet all of the "designed for outdoor use" radios are arbitrarily limited to 30 or 36dBm for yet-to-be-explained reas...
by sirbryan
Mon Jun 24, 2024 3:36 pm
Forum: MikroTik hardware questions
Topic: ISPs: How do you do unboxing and initial provisioning?
Replies: 5
Views: 7579

Re: ISPs: How do you do unboxing and initial provisioning?

I'm a one-man shop, so this may not be as exciting to you. But I take my hAP's and netinstall them to whatever version I feel most comfortable (presently 7.14.x) with my stock config. When I do the install at the customer, I put on the finishing touches, like AP SSID and WPA password, hostname, etc....
by sirbryan
Mon Jun 24, 2024 3:26 pm
Forum: Wireless Networking
Topic: CubeSA 60Pro ac: 60Ghz clients flapping
Replies: 121
Views: 37256

Re: CubeSA 60Pro ac: 60Ghz clients flapping

I never found a stable PtMP on these but I gave up and went with wave also. Would love to hear someone elses experience with newer firmwares though, did they solve the disconnects? I just looked and realized I have as many people on MikroTik as I do on Wave (around 150 each). As I posted earlier, 6...
by sirbryan
Mon Jun 24, 2024 3:15 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304888

Re: v7.15.1 [stable] is released!

Bump on this please, has everyone else given up on MLAG on the CRS platform? I haven't. CRS312, CRS354 MLAG'd together with a CCR2116 on one side and a pair of MLAG'd CRS317's on the other. The 312 and 354 are running 7.15, tied together on SFP+ ports with a DAC. (The QSFP+ ports on the 354 have br...
by sirbryan
Fri Jun 21, 2024 5:52 pm
Forum: MikroTik hardware questions
Topic: Which router for ~100 clients
Replies: 69
Views: 14091

Re: Which router for ~100 clients

What you can charge is not just dependent on what the market can bear, but what the customer can bear. The market is an average across customers in your demographic (country, region, city, neighborhood, industry). Add to that what the individual customer can handle. A small public school is likely t...
by sirbryan
Thu Jun 20, 2024 5:59 pm
Forum: General
Topic: CCR1036-8G-2S+EM or CCR2116-12G-4S+ ?
Replies: 15
Views: 11829

Re: CCR1036-8G-2S+EM or CCR2116-12G-4S+ ?

Just wondering, what kind of rule do you use for source nat? I'm having issues using srcnat action=src-nat and action=netmap when L3HW offloading is enabled. It only seem to work with masquerading otherwise traffic halts... So what are you using please? When i disable L3HW offloading, everything wo...
by sirbryan
Thu Jun 20, 2024 5:55 pm
Forum: General
Topic: Advice on how to grow an ISP network
Replies: 11
Views: 2538

Re: Advice on how to grow an ISP network

Depending on how large your POPs are determines whether you have one just one router for customers to connect to, or a stack of routers, with one being customer-facing (PE or Provider Edge), and another one at the POP being that POP's core. On small networks, like mine, I have one switch/router faci...
by sirbryan
Thu Jun 20, 2024 3:50 am
Forum: Wireless Networking
Topic: CubeSA 60Pro ac: 60Ghz clients flapping
Replies: 121
Views: 37256

Re: CubeSA 60Pro ac: 60Ghz clients flapping

Has anything improved?
I have no experience with the CubeSA 60 Pro's. The latest 6.49 and 7.9-7.12 have been fine for my wAP 60's and Cube 60's (first and second generation).
by sirbryan
Mon Jun 17, 2024 4:55 pm
Forum: MikroTik hardware questions
Topic: Mikrotik PTP Near-Line-Of-Sight Solution
Replies: 27
Views: 7216

Re: Mikrotik PTP Near-Line-Of-Sight Solution

But we could also discuss other needs, for instance high speed <500m links with full obstruction. Some people may have such usecases as well... Fiber is a great NLOS technology, and you can get amazing speeds...... RF physics is tough to overcome, until we figure out how to harness quantum entangle...
by sirbryan
Sat Jun 08, 2024 8:18 pm
Forum: Wireless Networking
Topic: 3km rural link with hills
Replies: 3
Views: 3899

Re: 3km rural link with hills

If you are fine with the 5GHz equipment and dishes you have, then go for it. 3km should be no problem, and with 40MHz channels, I can't see why you couldn't get 100-200Mbps over that. Same for the 6km link. Personally, I'd use 60GHz radios. Presuming they're available and you can use them in your co...
by sirbryan
Fri Jun 07, 2024 7:12 pm
Forum: Scripting
Topic: TILE verse ARM on different Cloud Core Routers
Replies: 2
Views: 4595

Re: TILE verse ARM on different Cloud Core Routers

What does the script do?

You can likely just copy the script over from the 1016 to the ARM router. You'll have to adjust the script for 7.2 and for the new architecture, regardless of whether you upgrade the one or not.
by sirbryan
Fri Jun 07, 2024 4:59 am
Forum: Forwarding Protocols
Topic: How to prevent advertising routes from another BGP session, ROUTEROSv7?
Replies: 3
Views: 4501

Re: How to prevent advertising routes from another BGP session, ROUTEROSv7?

This is what I use to keep from leaking routes learned from other peers that I don't provide transit for: if (bgp-as-path "(1234|5678|1000)") { reject; } This keeps me from announcing routes learned from AS's 1234, 5678, and 1000, no matter where they are in the AS path. On top of that, I ...
by sirbryan
Thu Jun 06, 2024 7:53 pm
Forum: Wireless Networking
Topic: LHG 60G - very slow speeds
Replies: 4
Views: 1244

Re: LHG 60G - very slow speeds

Don't do a "both" UDP test. Try "send" and then "receive." Your limiting factor will be the CPU's of the radios, so as suggested elsewhere, do your "official" testing with devices on either end of the radios, ideally something with more horsepower like two com...
by sirbryan
Thu Jun 06, 2024 7:47 pm
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 139788

Re: v7.16beta [testing] is released!

My adguard container won't start after update , nothing in log, anyone else has problem with containers ?
No problems here on a CCR2116. Six containers (pihole, open-speedtest, samba, uptime-kuma, home-assistant, esphome).
by sirbryan
Tue Jun 04, 2024 6:11 pm
Forum: General
Topic: CCR1036-8G-2S+EM or CCR2116-12G-4S+ ?
Replies: 15
Views: 11829

Re: CCR1036-8G-2S+EM or CCR2116-12G-4S+ ?

We do not have massive complaints regarding the subscriber experience behind a connection that uses cgnat IP. In addition to CPU usage and traffic, what other variable would you recommend we take into account?. It really depends on how it's connected to the rest of the network, but in theory you sh...
by sirbryan
Tue Jun 04, 2024 5:34 pm
Forum: General
Topic: CCR1036-8G-2S+EM or CCR2116-12G-4S+ ?
Replies: 15
Views: 11829

Re: CCR1036-8G-2S+EM or CCR2116-12G-4S+ ?

Hello, I am from a small ISP in Argentina. I ask you two concerns. What is the private IP to public IP ratio that you are using in CGNAT? How much is the maximum volume you reached in CCR1036/CGNAT? Up to what volume of traffic do you consider it advisable to take it? I've since sold the 1036 and h...
by sirbryan
Mon Jun 03, 2024 5:58 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304888

Re: v7.15 [stable] is released!

ACHTUNG !!! ALERT ! Do not use this version with CRS354 !!! Huge packetloss, huge performance drop, unusable on some ports. Oh darnit. I already upgraded my CRS354. And I'm not seeing what you're seeing. Mine's in an MLAG pair with a CRS312, both connected to a 2116 on one side and another MLAG pai...
by sirbryan
Fri May 31, 2024 5:55 am
Forum: MikroTik hardware questions
Topic: Which router for ~100 clients
Replies: 69
Views: 14091

Re: Which router for ~100 clients

Hmmm, I am aware of ZeroTier but I used to think about it as a VPN for those who don't have a public ip. Correct me if I'm wrong, but the traffic between devices is "coordinated" by a third party? I don't think the actual traffic goes through another server (I hope it doesn't), but there ...
by sirbryan
Fri May 31, 2024 5:51 am
Forum: MikroTik hardware questions
Topic: Which router for ~100 clients
Replies: 69
Views: 14091

Re: Which router for ~100 clients

Larsa Where is the server that these links connect to? And that's the reason you're paying a couple hundred bucks. Someone else has built the solution, hosts stuff in a datacenter, and has bandwidth/power/development costs associated with doing so. I'd view ZeroTier as the tool to build something a...
by sirbryan
Fri May 31, 2024 5:36 am
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304888

Re: v7.15 [stable] is released!

??? How not distributing 127.0.0.1 address is "stripping functionality"? It does not even make sense to distribute 127.0.0.1, it is called "localhost" for a reason. as others have said, if the changelog entry really means "we won't redistribute 127.0.0.1 as a connected rout...
by sirbryan
Wed May 29, 2024 5:28 pm
Forum: Announcements
Topic: Long range wireless links - share your experience
Replies: 65
Views: 97329

Re: Long range wireless links - share your experience

What’s the SUP for this so we can reference it? This seems like a critical bug that should hopefully be easy for them to address, hopefully in time for 7.15 if treated as urgently as it likely should be. Not a bug. It's by design. See the FCC paperwork for these radios. They would have to get it ce...
by sirbryan
Tue May 28, 2024 4:12 pm
Forum: General
Topic: Advice on how to grow an ISP network
Replies: 11
Views: 2538

Re: Advice on how to grow an ISP network

Looking at your design, here's what I'd do pretty quickly. ISP A -> 2216 no. 1 ISP B -> 2216 no. 2 Customers -> 2216 no. 3 (& 4?) 2216 nos. 1, 2, & 3 (& 4) all connected via backbone. ----- Internet comes into border routers. Borders may aggregate all routes between each other, or may fe...
by sirbryan
Tue May 28, 2024 3:44 pm
Forum: General
Topic: Advice on how to grow an ISP network
Replies: 11
Views: 2538

Re: Advice on how to grow an ISP network

Provision customers with Q-in-Q, strip the outer VLAN on the aggregation switch, and trunk the inner VLAN back to the BGP kit. You want to allow your customers to pick the outer VLAN ID (the outer VLAN ID can be decided by the customer; it makes no difference to you. The inner VLAN ID is picked by ...
by sirbryan
Sat May 25, 2024 11:07 pm
Forum: Announcements
Topic: Long range wireless links - share your experience
Replies: 65
Views: 97329

Re: Long range wireless links - share your experience

OK, I received my two NetBox 5 AX's and installed them at 19.3km with 26dBi 2'/600mm antennas (Siklu dual-band 5GHz/80GHz). I expected to be able to get a decent amount of throughput based on MikroTik's link calculator, but with the way MikroTik "nerfs" the radio TX power, it's no wonder t...
by sirbryan
Fri May 24, 2024 6:46 pm
Forum: General
Topic: MLAG breaks STP? CRS326 7.14.3
Replies: 9
Views: 2555

Re: MLAG breaks STP? CRS326 7.14.3

I don't see where you specified an STP mode on the bridge...I'm not sure what that defaults to...But you need to define that for "proper" operation. It defaults to RSTP. Again...Just "labbing" up the connections and seeing the "state" as "up" isn't enough to ...
by sirbryan
Fri May 24, 2024 2:57 am
Forum: Beginner Basics
Topic: MLAG issues
Replies: 3
Views: 1269

Re: MLAG issues

Has anyone had any issues with MLAG between 4 RouterOS systems? I want to form two mlag-ids, one per two devices and those would link together, via LACP. Thoughts? Something like this: Sw01 ---- peer-link ---- Sw02 | | | | Sw03 ---- peer-link ---- Sw04 I would have MLAG between Sw01 and Sw02 with m...
by sirbryan
Thu May 23, 2024 6:39 pm
Forum: General
Topic: MLAG breaks STP? CRS326 7.14.3
Replies: 9
Views: 2555

Re: MLAG breaks STP? CRS326 7.14.3

That's too bad. I just got it working. In this lab, I have two CRS326's that have been reset to defaults and upgraded to 7.14.3. There is no configuration, which means no bridge and no IP addresses. This way all ports are disconnected from each other, ensuring no bridge loops or other oddities durin...
by sirbryan
Thu May 23, 2024 5:02 am
Forum: General
Topic: MLAG breaks STP? CRS326 7.14.3
Replies: 9
Views: 2555

Re: MLAG breaks STP? CRS326 7.14.3

Thanks for replying and including detailed config. Yes, this is the config without MLAG active as doing so breaks STP. Yes, my MLAG peer port is sfp-sfpplus1 and I'd set its PVID to 999 which was to be my dedicated ICCP VLAN. I'd tagged VLAN1 as one of the guides I was following said it was require...
by sirbryan
Wed May 22, 2024 6:13 pm
Forum: General
Topic: MLAG breaks STP? CRS326 7.14.3
Replies: 9
Views: 2555

Re: MLAG breaks STP? CRS326 7.14.3

A bunch of your relevant config is missing. But the PVID of your MLAG port has to be a different VLAN. You're tagging VLAN 1 across what I assume is supposed to be your MLAG port (your MLAG line is missing), and that won't work. Here is the relevant (scrubbed) config from one of my working MLAG setu...
by sirbryan
Mon May 20, 2024 5:26 am
Forum: General
Topic: RB5009 and 2Gb/s internet speed [SOLVED]
Replies: 19
Views: 6167

Re: RB5009 and 2Gb/s internet speed [SOLVED]

So the assumption is that: ISP comes into RB5009's 2.5G port SFP+ on RB5009 goes into one of CRS310's SFP+ ports (using a cheap DAC) All 2.5Gbps devices go into CRS310 All remaining devices can go into RB5009's ports 2-8 or CRS310's remaining 3 ports This gives you the most LAN throughput from any d...
by sirbryan
Sun May 19, 2024 3:42 pm
Forum: Wireless Networking
Topic: Netbox 5 AX, L11UG-5HaxD wont send data
Replies: 15
Views: 6076

Re: Netbox 5 AX, L11UG-5HaxD wont send data

How many of you who are still complaining have read all the thread entries, particularly the one pointing out the release notes from 7.14.2/7.15rc1: "wifi-qcom - added configuration.distance setting to enable operation over multi-kilometer distances" ...and actually applied the setting via...
by sirbryan
Wed May 15, 2024 5:36 pm
Forum: Announcements
Topic: Newsletter #118 | May 2024
Replies: 30
Views: 43773

Re: Newsletter #118 | May 2024

no, there are very few antenas on the market. I would by NetBox 5 AX if there was small 20cm omnidirectional anntena

That's a pretty uninformed statement. What kind of antenna do you want?

(The following is just from one distributor.)
Screenshot 2024-05-15 at 8.33.11 AM.png
by sirbryan
Fri May 10, 2024 5:56 pm
Forum: General
Topic: CRS310-8G+2S+IN Stuck on 100 Mbps on all ports
Replies: 2
Views: 1004

Re: CRS310-8G+2S+IN Stuck on 100 Mbps on all ports

Just unboxed and installed this switch, but I'm getting only 100 Mbps on all the ports? Is there a default setting that needs to be changed upon startup? This is a replacement unit for a different switch, all Cat6 cabling, so it's definitely the Mikrotik. ISP service is 1Gbps. Tested on direct conn...
by sirbryan
Thu May 09, 2024 6:45 pm
Forum: Announcements
Topic: Long range wireless links - share your experience
Replies: 65
Views: 97329

Re: Long range wireless links - share your experience

My current 27km AirFiber 5XHD link on 3' (1m) 34dBi antennas and 100MHz of spectrum ... This setup hardly qualifies as "wifi based link". While it does use frequency from U-NII-3 band, it obviously doesn't use 802.11-compliant channel width (which would be either 80MHz or 160MHz) ... and ...
by sirbryan
Thu May 09, 2024 6:04 am
Forum: MikroTik hardware questions
Topic: HAP AC3 not performing well (Can't reach max WiFi) [SOLVED]
Replies: 8
Views: 22346

Re: HAP AC3 not performing well (Can't reach max WiFi) [SOLVED]

Install the wifi-qcom-ac drivers on them, set one up as an AP, one as a station bridge. On the bench, I get 600-700Mbps on hAP AC3's to my newer devices that support WiFi5 Wave 2 (i.e. iPhone, MacBook Pro). The hAP AX3's get closer to actual 800Mbps of throughput on AX capable devices. On AC and lat...
by sirbryan
Thu May 09, 2024 5:22 am
Forum: Announcements
Topic: Long range wireless links - share your experience
Replies: 65
Views: 97329

Re: Long range wireless links - share your experience

I did a quick google search and it says 60GHz 1Gbit device. Sorry I'm not an expert in other brands, but in 5GHz you can't get 1Gbit over 30+ KM AirFiber is a line of devices, in 4.9GHz, 5GHz, 11GHz, 24GHz, and 60GHz. The 4/5 GHz radios can get around 500-700Mbps aggregate, 11GHz about 550Mbps full...
by sirbryan
Thu May 09, 2024 5:17 am
Forum: Announcements
Topic: Long range wireless links - share your experience
Replies: 65
Views: 97329

Re: Long range wireless links - share your experience

Mind you, other than non-standard illegal amateur work, you can't expect anything good in terms of bandwidth from a 30km 5GHz link. This is why the maximum connection distance I make is less than 16km. My current 27km AirFiber 5XHD link on 3' (1m) 34dBi antennas and 100MHz of spectrum (US UNII-3 58...
by sirbryan
Thu May 02, 2024 5:19 pm
Forum: Wireless Networking
Topic: Cube60SA - Woeful end-client performance
Replies: 1
Views: 1013

Re: Cube60SA - Woeful end-client performance

The Cube60SA has always seemed to have problems. I use wAP 60's as AP's and the original Cube 60's, LHG60's, and Cube 60 Pro's as CPE, and regularly get 300-700Mbps through them (straight Layer 2, DHCP). Is the MTU 1600 to allow for PPPoE and VLAN overhead? Are all the Cube60's on the latest RouterO...
by sirbryan
Wed May 01, 2024 10:02 pm
Forum: General
Topic: iperf3 in docker container not showing 10Gb/sec speed
Replies: 13
Views: 3141

Re: iperf3 in docker container not showing 10Gb/sec speed

I second what @mkx said, as that echoes my experience. You've hit the limit of what the quad-core CPUs' can handle on RB5009, RB4011, and CCR2004. The ports are fine, and if you're able to come up with a scenario where you're just switching or bridging, then more of it hits the hardware. But speed t...
by sirbryan
Wed Apr 17, 2024 9:54 pm
Forum: MikroTik hardware questions
Topic: Infrastructure design help
Replies: 9
Views: 5178

Re: Infrastructure design help

Either way, no. You have to balance the traffic at one point only (e.g one main router) but the CRS326 is a bad router for this purpose. The other option is to staticly balance the users/switches between the four RB5009 (that then will balance the connections between the four 5G-modems) From the de...
by sirbryan
Wed Apr 17, 2024 6:58 pm
Forum: MikroTik hardware questions
Topic: Infrastructure design help
Replies: 9
Views: 5178

Re: Infrastructure design help

It looks like four 5G connections coming into each 5009, and each of the four 5009's is feeding a number of VLANs to which the WiFi AP's will be attached. What throughput are the 16 routers going to give you that 4 couldn't? Does the service provider 1) throttle throughput to 100-500Mbps per 5G rout...
by sirbryan
Wed Apr 17, 2024 6:40 pm
Forum: Wireless Networking
Topic: Dante Audio over 60GHz
Replies: 9
Views: 6529

Re: Dante Audio over 60GHz

I was using a pair of UBNT AF60LR (with a 300mt link), so no 5Ghz backup. Latecy point to point was 0.8-0.9 ms. Do you think a pair of RBLHGG-60ad or nRAYG-60ad could perform better? Generally I've seen more jitter on MikroTik's and Ubiquiti's Qualcomm-based radios than on Tachyon and Ubiquiti's Pe...
by sirbryan
Mon Apr 15, 2024 7:56 pm
Forum: General
Topic: CRS317 - No hardware offloading on WAN port when using fast-track
Replies: 2
Views: 1294

Re: CRS317 - No hardware offloading on WAN port when using fast-track

You can either have hardware-accelerated connection tracking (FW/NAT) or routing, but not both at the same time.

Try disabling HWoffload on all the ports, but leave it on for the switch, and see if that fixes anything performance-wise.
by sirbryan
Sun Apr 14, 2024 12:24 am
Forum: Announcements
Topic: Long range wireless links - share your experience
Replies: 65
Views: 97329

Re: Long range wireless links - share your experience

He said 30km or longer, guys. I had a pair of dual-band LHG XL's at 32km, from the valley floor to a mountain top, but both the 5GHz and 2.4GHz links were pretty weak and we only got about 10-20Mbps out of it after maxing everything that we could (for US region). I don't think the noise floor helped...
by sirbryan
Wed Apr 10, 2024 11:31 pm
Forum: General
Topic: RouterOS v7 best route selection problems
Replies: 8
Views: 4754

Re: RouterOS v7 best route selection problems

I haven't dug into that myself. I'm still figuring out how to best leverage all these BGP knobs.
by sirbryan
Wed Apr 10, 2024 6:11 pm
Forum: Beginner Basics
Topic: Unable to breakup IP range with /24 BGP to ISP
Replies: 2
Views: 970

Re: Unable to breakup IP range with /24 BGP to ISP

Without posting some of your config, it's hard to know how you're doing things. But it sounds like what's happening is if you don't put the /24 somewhere on your router, it stops announcing it to your upstream provider. You need to at least blackhole route the /24 to the router itself so the BGP ann...
by sirbryan
Wed Apr 10, 2024 4:18 pm
Forum: General
Topic: RouterOS v7 best route selection problems
Replies: 8
Views: 4754

Re: RouterOS v7 best route selection problems

Specificity always trumps almost anything else. If provider Z doesn't give you anything but the default route, then you'll need to filter out everything from the other providers except for the default route. With your use case, unless you're saturating one of your providers on outbound, slurping in ...