Community discussions

MikroTik App

Search found 277 matches

by jbl42
Sun Apr 07, 2024 2:23 pm
Forum: Useful user articles
Topic: mDNS between VLANs with just bridge filters - Look Mum, no containers!
Replies: 33
Views: 6244

Re: mDNS between VLANs with just bridge filters - Look Mum, no containers!

In devices supporting l2hw for VLAN filterig, using bridge rules disables l2hw. Depending on the device and network topology, this might be an issue or not. For simple setups were it is only about getting mDNS and/or UPnP passed between two different L3 routed VLANs, switch rules also work and are H...
by jbl42
Tue Mar 05, 2024 2:35 am
Forum: Announcements
Topic: v7.14.3 [stable] is released!
Replies: 610
Views: 149449

Re: v7.14 [stable] is released!

Bought a new Cisco Nexus router/switch a month ago, 48 x 10/25Gbps + 6 40/100Gbps ports. Closest Mikrotik comes is the CRS512 which is more expensive and has less ports. That's interesting. The cheapest Switchzilla Nexus with 48 x 10/25Gbps + 6 40/100Gbps I'm aware of is more than 10'000€... Which ...
by jbl42
Tue Mar 05, 2024 2:21 am
Forum: Announcements
Topic: v7.14.3 [stable] is released!
Replies: 610
Views: 149449

Re: v7.14 [stable] is released!

Updated the RB5009 in my home and several RB4011 in the lab from 7.13.5 to 7.14. No peculiarities so far, except the known bridge-MTU-change-on-reboot fixed in 7.15rc The ccr2004-pcie should not even have been released with a reset button that needs you to open the server up. Yes, a button/switch wo...
by jbl42
Thu Feb 29, 2024 12:29 am
Forum: Announcements
Topic: v7.14rc [testing] is released!
Replies: 176
Views: 49832

Re: v7.14rc [testing] is released!

I'm not sure what's meant with "tailor". It's just about the usual release notes. Something like limitations, resolved issues, known issues, precautions (for ex a warning for configs with non default bridge port MTU in 7.14 to wait for 7.15). With issues having unique IDs so they can be tr...
by jbl42
Wed Feb 28, 2024 10:41 pm
Forum: Announcements
Topic: v7.14rc [testing] is released!
Replies: 176
Views: 49832

Re: v7.14rc [testing] is released!

But many change descriptions are pretty useless: "Improve something with something" No description of the actual problem solved, no description of potential impact on existing configs, backward compatibility, no updates of related documentation etc. We need more details to assess for our s...
by jbl42
Wed Feb 28, 2024 10:20 pm
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 266692

Re: v7.13.5 [stable] is released!

It is also the acknowledging reply from support when they can reproduce an issue: "We are aware of this issue, and we look forward to fixing it on an upcoming RouterOS versions." Breaking MTU handling on bridges should not be a known issues but a showstopper as it has the potential to put...
by jbl42
Tue Feb 27, 2024 3:01 pm
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 266692

Re: v7.13.5 [stable] is released!

As there is obviously not much testing, it is hard for them to know about known issues.
The current history of 7.13.1 to 7.15.5 has 26 (!!) bugs introduced with 7.13.x releases.
by jbl42
Mon Feb 26, 2024 3:48 pm
Forum: General
Topic: Netinstall sending offer, but not installing [SOLVED]
Replies: 30
Views: 25944

Re: Netinstall sending offer, but not installing [SOLVED]

Yes, having the link going up and down on device reboot confuses Windows and/or Netinstall. One way to avoid this is to use a dumb (unmanaged) switch in-between. Another way is to boot your MT device into netboot mode and wait until link is up again before staring netinstall. Once the MT device is i...
by jbl42
Thu Jan 11, 2024 11:07 pm
Forum: Announcements
Topic: WinBox v3.40 released!
Replies: 143
Views: 133069

Re: WinBox v3.40 released!

I'm using wine-8.21-staging on macOS 14.2.1
Of course different macOS and wine versions might have different problems.

PS
I'm not sure what those version numbers in your screenshot are referring to. Current wine version is 8.x (9.0 is in RC state)
by jbl42
Thu Jan 11, 2024 3:39 pm
Forum: Announcements
Topic: WinBox v3.40 released!
Replies: 143
Views: 133069

Re: WinBox v3.40 released!

Winbox with Gcenx built wine has one big problem on Mac which screws up all field entries containing commas and periods
On my Mac (M2Pro, Sonoma), winbox 3.40 runs without issues using Gcenx wine builds available at
https://github.com/Gcenx/macOS_Wine_builds
Even winbox self update works.
by jbl42
Thu Jan 11, 2024 3:14 pm
Forum: RouterBOARD hardware
Topic: Default password Frustration
Replies: 28
Views: 4471

Re: Default password Frustration

The whole MT country specific WIFI regulation thing is currently in a bad state. 7.13.1 just broke it again in a new way. At least they are working on it. It seems confusing to have country settings for VAPs. It makes no sense for VAPs sharing the same channel and radio HW to broadcast different cou...
by jbl42
Wed Jan 10, 2024 11:40 pm
Forum: RouterBOARD hardware
Topic: Default password Frustration
Replies: 28
Views: 4471

Re: Default password Frustration

What does it mean "skip 10 min CAC" , if choosing a wheater radar channel is exactly what the device then does on its own The regulatory Channel Availability Check (CAC) time before an AP is allowed to broadcast beacons on a DFS channel is 1 min. For 5'600 to 5'650 MHz (116 to 128), EU re...
by jbl42
Fri Nov 17, 2023 9:54 pm
Forum: General
Topic: Block Youtube on computers and smartphone apps
Replies: 85
Views: 18907

Re: Block Youtube on computers and smartphone apps

If I have control over my device connected to your network, i just connect to the https based VPN server running on one of my servers.
For your firewall it is just encrypted https traffic on usual dest port 443. For me it is a tunnel to my server from where I can go everywhere. Including youtube.
by jbl42
Fri Nov 17, 2023 6:37 pm
Forum: General
Topic: CCR2216 have terrible IO performances, very much worst than CCR10xx! Maybe they have no DMA?
Replies: 31
Views: 3747

Re: CCR2216 have terrible IO performances, very much worst than CCR10xx! Maybe they have no DMA?

There is a chance this will improve in the future. The switch ASICs in CCR22xx support many HW features not implemented/exposed in ROS. Not only MPLS, also VXLAN and more. (VXLAN currently also lacks HW support on CCR22xx although the ASICs could do it). As you described, with the recent IPv6 l3hw f...
by jbl42
Fri Nov 17, 2023 5:29 pm
Forum: Announcements
Topic: v7.12.1 [stable] is released!
Replies: 252
Views: 95180

Re: v7.12 [stable] is released!

There's another "gem" with regard to firewall: new drop rules only affect new connections This is based on how iptables work: existing connections are in established stated what us usually handled by "established, related, (untracked)" rules before drop rules. So new drop rules ...
by jbl42
Fri Nov 17, 2023 1:12 am
Forum: General
Topic: QoS DSCP for Audio Network (Q-SYS / Q-LAN / Dante)
Replies: 1
Views: 837

Re: QoS DSCP for Audio Network (Q-SYS / Q-LAN / Dante)

This is possible on Mikrotik devices where the switch ASIC supports DSCP to PCP mapping (CRS3xx and upwards)
https://help.mikrotik.com/docs/pages/vi ... S)-DSCPMap
by jbl42
Fri Nov 17, 2023 12:27 am
Forum: General
Topic: VLAN Issues
Replies: 13
Views: 2042

Re: VLAN Issues

This is a Mikrotik specialty: The switch/bridge port towards the CPU has the same name as the bridge itself. Adding this port as tagged makes the CPU facing switch port a tagged member of the VLAN. While adding a VLAN interface to the bridge adds a VLAN (virtual interface) on the CPU Ethernet port g...
by jbl42
Thu Nov 16, 2023 4:18 am
Forum: RouterBOARD hardware
Topic: Mikrotik RB4011
Replies: 7
Views: 2789

Re: Mikrotik RB4011

200 users with ONE-TO-ONE NAT and in total 400 mbps of internet We have RB4011 and RB5009 in production and in our experience both will be able to handle this with reasonable CPU load. For pure NAT/routing, we see both of them maxing out at 1.5-2.5GBit/s. It will be less depending on amount of addi...
by jbl42
Thu Nov 16, 2023 12:45 am
Forum: Announcements
Topic: v7.12.1 [stable] is released!
Replies: 252
Views: 95180

Re: v7.12 [stable] is released!

I would say "unbound", others maybe say "dnsmasq" I would also say "powerdns" ;-) While I agree with your sentiments, at least since we have Docker this can be solved easily. I started to run PowerDns and dnsmasq images, both working with almost no issues. Especially o...
by jbl42
Thu Nov 16, 2023 12:21 am
Forum: Wireless Networking
Topic: RBM11G and Fibocom NL668-LA compatibility [SOLVED]
Replies: 1
Views: 1357

Re: RBM11G and Fibocom NL668-LA compatibility [SOLVED]

This means ROS can see the USB device but does not have a driver to actually use it as a cellular modem.
ROS is limited to a set of supported devices and no additional drivers can be added by the user.
There is a list of supported devices:
https://help.mikrotik.com/docs/display/ROS/Peripherals
by jbl42
Wed Nov 15, 2023 11:47 pm
Forum: General
Topic: CRS354-48P-4S+2Q+ traffic problem on ports 1 to 8
Replies: 428
Views: 124278

Re: CRS354-48P-4S+2Q+ traffic problem on ports 1 to 8

Mikrotik EU Store has 5pcs on stock:
https://www.mikrotik-store.eu/en/mikrot ... 48p-4s2qrm

No need to by from a distributor having them from an importer, both putting their own margin on top of the price for doing nothing else then forwarding your order.
by jbl42
Fri Oct 27, 2023 10:48 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93646

Re: v7.12rc is released!

When are you releasing 7.12? I need those IKEv2 rekey fixes in the stable version :) After the buggy 7.10.0 (breaking OpenVPN on all devices) and 7.11.0 (breaking VLAN filtering on many devices) releases, taking their time to release 7.12 without major regressions and earning the "stable"...
by jbl42
Fri Oct 27, 2023 10:12 pm
Forum: Wireless Networking
Topic: hAP ax2 randomly drops WiFi SSIDs (both 2,4 and 5Ghz)
Replies: 134
Views: 26126

Re: hAP ax2 randomly drops WiFi SSIDs (both 2,4 and 5Ghz)

Many MT WiFi APs occasionally just cease operation in noisy environments. They still broadcast, but do not let stations connect. There is no other way to bring them back to operation than a power cycle. The only improvement is MT stopped denying it, as they did for a long time. The root cause is poo...
by jbl42
Sun Oct 22, 2023 6:19 pm
Forum: General
Topic: RouterOS v7 x86_64 best hdd available? SSD enterprise? nvme ?
Replies: 3
Views: 843

Re: RouterOS v7 x86_64 best hdd available? SSD enterprise? nvme ?

we will be running bare metal x86_64 .. not virtualization CHR May I ask why? We stopped doing this and run all CHRs in VMs. It is so much easier to maintain, and ROS x86_64 constantly lacks behind with support of HW, especially recent network cards. And it can easily be moved from one server to an...
by jbl42
Sun Oct 22, 2023 5:45 pm
Forum: General
Topic: VLAN Issues
Replies: 13
Views: 2042

Re: VLAN Issues

be careful with using .local for your internal domains. .local is reserved for MDNS/Bonjour (RFC6762) used by many Apple Devices, Google Chromecast,Smarthome stuff etc. and using it for your internal domain might cause hard to track issues. https://en.wikipedia.org/wiki/.local If you have an officia...
by jbl42
Sun Oct 22, 2023 4:23 pm
Forum: General
Topic: Cannot flash Mikrotik hAP ac2 with netinstall-cli
Replies: 15
Views: 1714

Re: Cannot flash Mikrotik hAP ac2 with netinstall-cli

Yep. I had a similar issue with RB5009: Netinstall only works on ether1. After the following reboot, the default config is loaded and ether1 becomes the WAN port not allowing Winbox/Webfig connections. So the cable must be changed to one of the LAN ports, in case of RB5009 ether2-8. This should be b...
by jbl42
Mon Sep 25, 2023 11:19 pm
Forum: General
Topic: Creative Way to prevent Users from Playing PUPG Game Using Mikrotik
Replies: 3
Views: 747

Re: Creative Way to prevent Users from Playing PUPG Game Using Mikrotik

That is how to deal with it.......... just need one example be made.......... That's exactly what was meant with "different way than using firewalls" ;-) And blocking in companies depends in my experience on the region. Many US companies have not much filtering in place (if at all mostly ...
by jbl42
Mon Sep 25, 2023 3:02 pm
Forum: General
Topic: Help! IPoE on WAN, how configure?
Replies: 7
Views: 1636

Re: Help! IPoE on WAN, how configure?

If there is any authentication required, and if yes it is using DHCP option 82 and if so what to fill in there is something only the provider can tell you.
by jbl42
Mon Sep 25, 2023 2:54 pm
Forum: General
Topic: rb5009 outdoor - tower site - fq-codel
Replies: 1
Views: 563

Re: rb5009 outdoor - tower site - fq-codel

If it is about shaping all traffic, you can attach it to the interface. Interface queues only applies to egress traffic. Shaping ingress traffic is less helpful, as it is already to late. It the upstream device priorities incoming traffic "wrong", there is not much to be done on the WAN in...
by jbl42
Mon Sep 25, 2023 1:09 pm
Forum: General
Topic: Creative Way to prevent Users from Playing PUPG Game Using Mikrotik
Replies: 3
Views: 747

Re: Creative Way to prevent Users from Playing PUPG Game Using Mikrotik

PUPG servers are run in AWS cloud using many IPs, some unofficial lists are around, for ex here https://gist.github.com/0n3la57k155/ce590e8692b9b04a89df42aeeb0d077c Theoretically you could add all of them to an address list and filter them in you firewall. But practically this will hardly work. The ...
by jbl42
Wed Sep 20, 2023 8:37 pm
Forum: RouterBOARD hardware
Topic: RB5009 2,5Gbe problems [SOLVED]
Replies: 22
Views: 8534

Re: RB5009 2,5Gbe problems [SOLVED]

Maybe I'm missing something, but flow control does not change the fact that packets are dropped. It just changes where they are dropped. Without flow control packets are dropped at the receiving end because the RX buffer overruns. With flow control in case of backpressure packets are dropped at the ...
by jbl42
Tue Sep 19, 2023 9:12 pm
Forum: General
Topic: Mikrotik SUCKS
Replies: 82
Views: 12969

Re: Mikrotik SUCKS

I still struggle to understand why so many people fail to understand the MT single bridge VLAN filtering and state it is much more complicated than Cisco etc al. A normal Cisco switch is the same: you have one implicit bridge (the ASIC) and you add VLANs, than add ports to VLANs as tagged or untagge...
by jbl42
Mon Sep 18, 2023 7:10 pm
Forum: RouterBOARD hardware
Topic: RB5009 2,5Gbe problems [SOLVED]
Replies: 22
Views: 8534

Re: RB5009 2,5Gbe problems [SOLVED]

Buffering towards slower interfaces only helps for short bursts. For constant streams like iperf or large file transfers, even large buffers only can help for a short period. If there is more data arriving than possible to output on the egress port, buffers will overflow. Only flow control can help,...
by jbl42
Mon Aug 28, 2023 11:46 pm
Forum: Beginner Basics
Topic: VLAN not working with hw=yes
Replies: 22
Views: 3876

Re: VLAN not working with hw=yes

Can I reasonably extrapolate that into two bridges with RB4011iGS+ as a sound design? The RB4011 is actually a 3-port router: 1x 10GBit Port (SFP+), and 2x 2.5GB Ports with attached extenders(ether1-5/6-10) To take full advantage of l2hw capabilities, there should be one ROS bridge per switch chip....
by jbl42
Fri Aug 25, 2023 11:59 pm
Forum: General
Topic: RouterOS Bridge not forwarding MacSEC
Replies: 3
Views: 1221

Re: RouterOS Bridge not forwarding MacSEC

Independent of protocol reserved multicast bridging, your VLAN should not be in a bridge with a physical interface /interface ethernet set [ find default-name=sfp1 ] comment="1Gbps Ethernet Link to Test CPE" mtu=9192 set [ find default-name=sfp-sfpplus1 ] comment="10Gbps Ethernet Link...
by jbl42
Fri Aug 25, 2023 12:01 am
Forum: Beginner Basics
Topic: VLAN not working with hw=yes
Replies: 22
Views: 3876

Re: VLAN not working with hw=yes

hw=yes in ROS bridging means L2 packet forwarding in HW btw. physical ports of switch ASICs, aka l2hw This is only possible for ports on the same switch chip. RB4001 has two switch chips , one for ether1-5 and one for ether6-10. No HW forwarding is possible ether2 <-> ether9. This is one of the adv...
by jbl42
Thu Aug 24, 2023 5:10 pm
Forum: Beginner Basics
Topic: Do not redirect (NAT) DNS-Requests for specific domain [SOLVED]
Replies: 3
Views: 1887

Re: Do not redirect (NAT) DNS-Requests for specific domain [SOLVED]

If I'm not missing something here, this should be possible using FWD static DNS entries instead of NAT. regex entries are processed before "normal" static entries. If clients use ROS DNS first, adding a regex FWD entry matching urls not going to your internal domain(s) should work /ip/dns/...
by jbl42
Tue Aug 22, 2023 2:53 am
Forum: General
Topic: Bridge two vlan on different segments
Replies: 3
Views: 1057

Re: Bridge two vlan on different segments

I don't know the video, but this forum post

Bridge different VLANs together [SOLVED]
viewtopic.php?t=178614
by jbl42
Tue Aug 22, 2023 1:50 am
Forum: Beginner Basics
Topic: Airplay/Multicast packet not flooding in bridge vlan
Replies: 17
Views: 3179

Re: Airplay/Multicast packet not flooding in bridge vlan

So if even if mDNS reaches a subnet... the AirPlay "client" and "server" must be in same IP address range. My MacBook Pro streams video and audio over airplay to an AppleTV in a different VLAN/subnet without problems. Running an mDNS forwarder for discovery. Don't know about Son...
by jbl42
Mon Aug 21, 2023 10:43 pm
Forum: Beginner Basics
Topic: Router/bridge at same time
Replies: 11
Views: 1896

Re: Router/bridge at same time

Not sure where our disconnect is here. Yes, it is about bridging the IPTV box on L2 to the ISP WAN, same as the dedicated IPTV port of the original ISP CPE would do. Special VLANs or not (of course in case of special tagged VLANs, assuming all tagged VLANs are properly configured to be forwarded btw...
by jbl42
Mon Aug 21, 2023 10:32 pm
Forum: Beginner Basics
Topic: Router/bridge at same time
Replies: 11
Views: 1896

Re: Router/bridge at same time

No. Just different VLANs on the same bridge. One for WAN (10), one for LAN (20). ether1/2 as access (untagged ports) for WAN(10), ether3-8 as access port on LAN (20). With WAN/LAN NAT routing happening btw. CPU bridge interfaces for 10 and 20 VLANs. This works because my ISP uses no special VLANs fo...
by jbl42
Mon Aug 21, 2023 10:03 pm
Forum: Beginner Basics
Topic: Router/bridge at same time
Replies: 11
Views: 1896

Re: Router/bridge at same time

I do something similar on my home RB5009 to directly bridge my ISP's IPTV box to the ISP WAN so I 1) don't have to bother with multicast routing and b) can keep the ISP controlled IPTV box out of my private LAN. I can't not provide a direct config export as my actual setup is more complicated (WAN g...
by jbl42
Mon Aug 21, 2023 9:10 pm
Forum: General
Topic: Static DNS records for DHCP leases - Flash Memory Wear
Replies: 3
Views: 1300

Re: Static DNS records for DHCP leases - Flash Memory Wear

Dynamic DHCP leases are persited to FLASH in a configurable interval (default is 5min) or on proper shutdown/reboot. But static DNS entries, added manual or by a script, are persisted immediately. But still the wear out is negligible for the usual home network's rate of DHCP lease script driven stat...
by jbl42
Mon Aug 21, 2023 8:53 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165667

Re: v7.11 [stable] is released!

As is the case with most software, you will learn that it is usually not a good idea to install a .0 release, at least not immediately. I conquer. With SW, it is usually safe to upgrade from a stable minor release to the next. Like form *stable* 7.10.2 to *stable* 7.11. But with Mikrotik you have t...
by jbl42
Sun Aug 20, 2023 10:27 pm
Forum: Beginner Basics
Topic: Cross VLAN Multicast / PIM Config
Replies: 30
Views: 7825

Re: Cross VLAN Multicast / PIM Config

For each VLAN requiring mDNS "routing" by the container, add a veth and addd it to the bridge with matching PID.
If your main bridge uses default VLAN1 for untagged traffic, add a veth with PID1 to the bridge.
by jbl42
Sun Aug 20, 2023 2:55 pm
Forum: Beginner Basics
Topic: Cross VLAN Multicast / PIM Config
Replies: 30
Views: 7825

Re: Cross VLAN Multicast / PIM Config

While this can be achieved with PIM, it is quite a big gun to get AirPlay/Chrome/IoT working among routed VLANs. All those systems rely on mDNS (a simple multicast based DNS system, aka as Bonjour in the Apple world) for devices to find each other. mDNS is designed to work inside an IP subnet resp. ...
by jbl42
Sat Aug 19, 2023 1:01 pm
Forum: General
Topic: feature request: DHCP lease on option 82 info
Replies: 10
Views: 1931

Re: feature request: DHCP lease on option 82 info

The scripts do NOT receive any of the agent id information I never tried using DHCP options in lease scripts so far, but my understanding of the documentation " lease-options - array of received options" always was lease-options provides an array of DHCP options sent by the client and wou...
by jbl42
Sat Aug 19, 2023 12:42 pm
Forum: Beginner Basics
Topic: MLAG Support On CHR?
Replies: 5
Views: 1821

Re: MLAG Support On CHR?

"All (1) CRS3xx, (2) CRS5xx series switches, and (3) Ccr2116, (4) CCR2216 devices can be configured with MLAG using RouterOS version 7." As far as I understand, MLAG in ROS7 is only available on devices featuring a Marvell Prestera family switch ASIC. There is no protocol standardization ...
by jbl42
Fri Aug 18, 2023 3:16 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165667

Re: v7.11 [stable] is released!

Looks like this is not caused by capsman itself, but handling of dynamic interfaces in bridge. > I have had the issue reported by AdB and eworm that my 5009 running my capsman is "dropping" the VLANs for any VLAN edge ports on the 5009 On my RB5009 running 7.11 it indeed seems like VLAN H...
by jbl42
Wed Aug 16, 2023 10:35 pm
Forum: General
Topic: feature request: DHCP lease on option 82 info
Replies: 10
Views: 1931

Re: feature request: DHCP lease on option 82 info

DHCP server lease scripts receive all necessary information (including the DHCP options sent by the client) to do such things as pseudo global variables. The problem is the script is called *after* the lease is created and the offer is sent to the client. A more flexible way to would be a script hoo...
by jbl42
Sun Aug 13, 2023 4:20 pm
Forum: General
Topic: SFP Temperature is 255C after Router OS upgrade [SOLVED]
Replies: 12
Views: 3249

Re: SFP Temperature is 255C after Router OS upgrade [SOLVED]

There is no standardization on what value modules/DACs without temp sensor return for temperature. Some report 0x00 (0 decimal), some 0x14 (20 decimal), some 0xff (255 decimal) It obviously would make sense for ROS sense to ignore a reported SFP temp of 255 degrees (0xff) for fan control. Yet not im...
by jbl42
Sun Aug 13, 2023 3:25 pm
Forum: RouterBOARD hardware
Topic: Are QSFP28 DACs compatible with QSFP+ Ports? [SOLVED]
Replies: 2
Views: 4139

Re: Are QSFP28 DACs compatible with QSFP+ Ports? [SOLVED]

QSFP28 vs QSFP+ is actually SFP28 vs SFP+ SFP+ is 10G max, QSFP28 is 25G max. Both are electrically and mechanically compatible, but not all (Q)SFP28 ports support 10G. So technically it should work in your case. For cable, also have a look at fs.com, where you can get active optical DACs for less t...
by jbl42
Tue Jul 04, 2023 1:45 am
Forum: RouterBOARD hardware
Topic: RB5009 bridge with l2hw forwards LLDP packets?
Replies: 7
Views: 6929

Re: RB5009 bridge with l2hw forwards LLDP packets?

I'm not really familiar with the CRS326-24G-2S+, but as far as I understand switch rules should work the same way as on RB5009 ROS supports CDP , LLDP and MNDP for discovery protocols. The switch rule only applies for LLDP, as CDP does not use e special EtherType but a reserved multicast dest MAC (0...
by jbl42
Thu Jun 22, 2023 10:26 pm
Forum: Scripting
Topic: get a list of enabled NAT rules with no src address list
Replies: 38
Views: 5210

Re: get a list of enabled NAT rules with no src address list

/ip/firewall/nat/print where disabled=no src-address-list=[:nothing]
by jbl42
Mon Jun 19, 2023 7:23 pm
Forum: SwOS
Topic: Reverse polarity in "Link" tab [SOLVED]
Replies: 3
Views: 3459

Re: Reverse polarity in "Link" tab [SOLVED]

Copper Ethernet is based on differential signals on twisted pairs. Those signals have +/- polarity which is detected between link partners on link establishment. Some chips (like 88E6193X in CSS610 and RB50009) can report the chosen polarity for a link as "normal" or "reversed". ...
by jbl42
Wed Jun 14, 2023 4:00 pm
Forum: Beginner Basics
Topic: help or documentation about bridge vlan filtering
Replies: 8
Views: 1225

Re: help or documentation about bridge vlan filtering

Depending on the packet size the HEX S can reach 1GB for routing with firewalling. I suggest to give it a try for your usage scenario.
Depending on the number of parallel connections and packet sizes, it might be enough or not.
by jbl42
Wed Jun 14, 2023 2:55 pm
Forum: Beginner Basics
Topic: help or documentation about bridge vlan filtering
Replies: 8
Views: 1225

Re: help or documentation about bridge vlan filtering

What I wanted is to isolate VLAN2 and VLAN5 of anyone else. But they need to be able to go to internet. You need to add the CPU port towards the bridge port itself as tagged interface for your VLANs so the switch forwards tagged packets to the CPU. After that, you will be able to enable VLAN filter...
by jbl42
Wed Jun 14, 2023 1:55 am
Forum: General
Topic: rb5009 and hardware offloading confusion
Replies: 9
Views: 1767

Re: rb5009 and hardware offloading confusion

the rb5009 seems to be the lone device that has a capable marvell switch that doesn't seem to have a hardware routing option in routeros. The 88E6393X chip is part of the LinkStreet familiy which is much simpler (and cheaper and cooler) than the Prestera Familiy used in CRS devices. Presteras have ...
by jbl42
Tue Jun 13, 2023 10:42 pm
Forum: General
Topic: rb5009 and hardware offloading confusion
Replies: 9
Views: 1767

Re: rb5009 and hardware offloading confusion

As others have explained, RB5009 switch chip fully supports L2 offloading for VLANs and IGMP/DHCP snooping in HW. (aka L2hw). For routing, there is no HW support (aka L3hw). Fasttrack bypasses parts of ROS. Data is directly passed in low level SW. This is still CPU based, but with less load. Fasttra...
by jbl42
Fri Jun 09, 2023 5:12 pm
Forum: General
Topic: DHCP server update DNS server with client info
Replies: 1
Views: 523

Re: DHCP server update DNS server with client info

The ROS DHCP server can run a script on creation and removal of DHCP leases. Inside those scripts, DNS entries can be added or removed.
Find an example here:
viewtopic.php?t=119469
There are also other similar scripts which you can find using the forum search function.
by jbl42
Wed Jun 07, 2023 10:51 pm
Forum: General
Topic: RB5009 - What USB storage are you using?
Replies: 5
Views: 1268

Re: RB5009 - What USB storage are you using?

Off topic: on which version are your devices ? Since, I think, 7.8 or so, I haven't seen this happening anymore.
I still see this occasionally on 7.9.2. It is much better than it was with 7.7 where it happened on every reboot. But it still happens rarely.
by jbl42
Wed Jun 07, 2023 10:02 pm
Forum: General
Topic: RB5009 - What USB storage are you using?
Replies: 5
Views: 1268

Re: RB5009 - What USB storage are you using?

I use two different USB storage on two RB5009 without problems so far (except the occasional USB drive renaming on reboot breaking containers, but that's a ROS issue): A Startech USB to SATA adapter connected to a Samsung 860 EVO 2.5" 256GB SATA SSD I had lying around from a disfunct notebook P...
by jbl42
Fri May 05, 2023 3:39 am
Forum: General
Topic: pyNetinstall - Free and Open Source netInstall implementation for Flashing Mikrotik RouterBoards
Replies: 7
Views: 35256

Re: pyNetinstall - Free and Open Source netInstall implementation for Flashing Mikrotik RouterBoards

Could this potentially be used to flash a lightweight Linux distro onto an arm-based routerBOARD? No. RouterBOOT (Mikrotik bootloader) only boots up signed Mikrotik SW installed uing NPKs. To boot a 3rd party Linux kernel, you need a modified RouterBOOT. See here for an example on how to install op...
by jbl42
Fri May 05, 2023 3:15 am
Forum: Scripting
Topic: Can't concatenate variable and a string.?!
Replies: 9
Views: 2418

Re: Can't concatenate variable and a string.?!

But MikroTik script has a syntax all its own. It's certainly not like C or PHP. In some ways its closer to Assembly. Mikrotik scripts is basically shell automation and hence is more similar to bash/zsh (Unix shell) scripts. There you would write "${qplan}M" The difference is MT scripts us...
by jbl42
Sat Apr 29, 2023 7:55 pm
Forum: General
Topic: RB5009UPr+S+IN NAND sufficient for container
Replies: 3
Views: 597

Re: RB5009UPr+S+IN NAND sufficient for container

I'm thinking to put in the unifi controller to control the APS
RB5009 has 1GB RAM in total. A running unifi controller instance requires 1-2GB RAM (can be more depending on number of managed devices), so most likely you will run into out of memory issues.
by jbl42
Fri Apr 21, 2023 2:23 pm
Forum: RouterOS beta
Topic: v7 and BFD, any ETA?
Replies: 149
Views: 28028

Re: v7 and BFD, any ETA?

If you need BFD and BGP, use Cisco or Juniper Yeah, thanks. You must be fun at parties. Same as pe1chl, I really do not get all those stupid comments. There are large installations based of ROS6 using BFD. Without BFD, there is no way to upgrade to ROS7 and most important not possible to use any of...
by jbl42
Sat Mar 04, 2023 1:07 pm
Forum: RouterBOARD hardware
Topic: RouterOS 7.8 bricked cAP XL ac
Replies: 14
Views: 5509

Re: RouterOS 7.8 bricked cAP XL ac

As Ca6ko wrote, it is important that the network interface used for netinstall is the one and only active network interface on the host running netinstall. All others must be disabled before netinstall is started. My usual setup to run netinstall is to run in a virtual machine with an USB Ethernet a...
by jbl42
Wed Feb 01, 2023 10:33 pm
Forum: Announcements
Topic: WinBox v3.37 released!
Replies: 110
Views: 141282

Re: WinBox v3.37 released!

Make sure you specify a session file (e.g. <own>) in your connection.
After wiping out sessions and creating a new one it indeed works.
I'm happy to stand corrected!
by jbl42
Wed Feb 01, 2023 10:24 pm
Forum: General
Topic: Block Youtube on computers and smartphone apps
Replies: 85
Views: 18907

Re: Block Youtube on computers and smartphone apps

I'm not ;-) I only apply such filters for stupid paying customers wanting it. Because they only know YouTube for video and Facebook for social media. So they think trying to block those two sites helps anything. What I sometimes do on sites with low bandwidth uplink is using tls-host rules to apply ...
by jbl42
Wed Feb 01, 2023 9:50 pm
Forum: Announcements
Topic: WinBox v3.37 released!
Replies: 110
Views: 141282

Re: WinBox v3.37 released!

add software-id column in winbox neighbors discovery section. software-id column is available in neighbor window in Show Columns... menu (down looking arrow on the right) But a long standing feature request is that WinBox keeps selected columns and does not set them back to defaults for every new s...
by jbl42
Wed Feb 01, 2023 9:32 pm
Forum: General
Topic: Doesn't RB5009 have a serial port?? [SOLVED]
Replies: 40
Views: 4210

Re: Doesn't RB5009 have a serial port?? [SOLVED]

What I do on "important" RB5009 is to sacrifice ether8 for mgmt port. I make it not part of the main bridge nor part of the LAN interface group and bind a static ip directly to ether8, allow winbox/webui/ssh on it. So if I mess up bridge settings or FW rules in a way not even MAC access is...
by jbl42
Mon Jan 30, 2023 1:20 am
Forum: Announcements
Topic: v7.8beta [testing] is released!
Replies: 307
Views: 76797

Re: v7.8beta [testing] is released!

Beside running services, I can also see value in Docker for testing and debugging: Temporary starting up a minimal Debian or Ubuntu image on a remote router to run tools like flent, cacti or nagios from the router's remote point of view could come in handy.
by jbl42
Mon Jan 30, 2023 12:52 am
Forum: General
Topic: Block Youtube on computers and smartphone apps
Replies: 85
Views: 18907

Re: Block Youtube on computers and smartphone apps

Yes, using tls-host is in my experience the best result with least effort add action=reject chain=forward in-interface-list=LAN protocol=tcp reject-with=tcp-reset tls-host=*.googlevideo.com Plus a rule to block quic. It is resistant to DoHS, but not against VPN. It requires only one simple and easy ...
by jbl42
Sun Jan 29, 2023 12:42 pm
Forum: General
Topic: Block Youtube on computers and smartphone apps
Replies: 85
Views: 18907

Re: Block Youtube on computers and smartphone apps

As always with technical problems: It is not about who is right. It is about what works. In summary: Youtube can be blocked to a certain extend for the average user by forwarding DNS to a commercial DNS service like Cloudflare, Umbrella etc. They have the abilities to track and adapt to the constant...
by jbl42
Sat Jan 28, 2023 11:08 pm
Forum: Announcements
Topic: v7.8beta [testing] is released!
Replies: 307
Views: 76797

Re: v7.8beta [testing] is released!

To add something more constructive to all the complaints: I'm happy with the state of ROS 7.x on RB5009. For heavy SOHO and small branch applications, they work reliable with not much complaints except some SFP+ module issues solvable by using other SFPs. Also Docker is appreciated to run services l...
by jbl42
Sat Jan 28, 2023 11:07 pm
Forum: Announcements
Topic: v7.8beta [testing] is released!
Replies: 307
Views: 76797

Re: v7.8beta [testing] is released!

---
by jbl42
Sat Jan 28, 2023 10:43 pm
Forum: Beginner Basics
Topic: CRS125 forwarding LLDP/CDP/MNDP broadcasts
Replies: 2
Views: 533

Re: CRS125 forwarding LLDP/CDP/MNDP broadcasts

I read something about using switch ACLs but this doesn´t seem to be supported on my switch cpus (QCA 8513L) According to https://help.mikrotik.com/docs/pages/viewpage.action?pageId=103841835 CRS125 should have switch ACLs available in /interface ethernet switch acl At the other hand, LLDP should n...
by jbl42
Tue Jan 24, 2023 10:51 pm
Forum: RouterOS beta
Topic: RB5009 not working with sfp?
Replies: 29
Views: 9126

Re: RB5009 not working with sfp?

I don't think it is the heat in my case. In the interface it shows the temperature of the sfp around 30 celcius while it shuts down at 95 No, it's not. The RB5009 is quite picky with SFP(+) modules. Many do not work, but do work on RB4011 (which also required many ROS upgrades to solve SFP problem ...
by jbl42
Tue Jan 24, 2023 10:35 pm
Forum: Announcements
Topic: v7.8beta [testing] is released!
Replies: 307
Views: 76797

Re: v7.8beta [testing] is released!

Bugs and things like BFD have no "enabled=yes" switch in RouterOS configuration files, sorry Sorry Normis, but writing nonsense like "there is no enabled=true for BFD" after 18+ months of claiming to work on it is just pathetic. If 18 months is not enough for MikroTik to bring B...
by jbl42
Tue Nov 22, 2022 5:14 pm
Forum: Beginner Basics
Topic: problem with my attemps to block youtube users [SOLVED]
Replies: 11
Views: 1402

Re: problem with my attemps to block youtube users [SOLVED]

Eh, Jletti42
My Italian is rusty, but still I think I got that one ;-)
by jbl42
Mon Nov 21, 2022 2:36 pm
Forum: Beginner Basics
Topic: problem with my attemps to block youtube users [SOLVED]
Replies: 11
Views: 1402

Re: problem with my attemps to block youtube users [SOLVED]

Beside protocol issues, the important thing to know is that youtube content is delivered using a world wide CDS (content delivery system). Most of it runs on Google's own infrastructure, part of it is also rented from Akamai and similar. So the list of youtube hosts is a) large and b) constantly cha...
by jbl42
Tue Nov 08, 2022 6:16 pm
Forum: General
Topic: USB storage for rv4011
Replies: 5
Views: 1644

Re: USB storage for rv4011

It's been odd to me that rb4011 sporting a fairly powerful hw lacks usb port and now it's disappointing to know there's no workaround for it either. Yes. Especially regarding the fact the RB4011 SoC features a USB3.0 controller. Still for some reason MikroTik decided not to add a USB port for RB401...
by jbl42
Tue Nov 01, 2022 12:18 pm
Forum: Forwarding Protocols
Topic: RouterOS v7.6 Fail to establish BGP Session
Replies: 2
Views: 1938

Re: RouterOS v7.6 Fail to establish BGP Session

This issue was introduced with 7.5, and still happening with 7.6: https://forum.mikrotik.com/viewtopic.php?t=190072#p964372 It was reported to be fixed, but is still appears in the current 7.7 beta https://forum.mikrotik.com/viewtopic.php?t=190351#p965140 For our three CCR2216, we had to go back to ...
by jbl42
Mon Oct 31, 2022 7:58 pm
Forum: RouterBOARD hardware
Topic: RB5009UG+S+IN availability
Replies: 20
Views: 5393

Re: RB5009UG+S+IN availability

Two pieces of metal, one cast and one sheet, two sets of LAN terminals, an USB, SFP, and some other connectors, plus a printed board with some chips on it. Always funny when some random guys know things better. The shortage affects especially "simple" chips. Like small uCs, voltage contro...
by jbl42
Sun Oct 30, 2022 9:42 pm
Forum: Wireless Networking
Topic: Horribly slow Wi-Fi on Mikrotik network
Replies: 134
Views: 25499

Re: Horribly slow Wi-Fi on Mikrotik network

The UBNT are much more stable (and you have to like the UniFi controller thing), but if you need an AP running reliable in a busy bar or office, with 10+ neighbor SSIDs fighting each other, they still have issues. In such locations, it is worth to spend some £200 - £250 for a lower end professional ...
by jbl42
Sun Oct 30, 2022 9:25 pm
Forum: General
Topic: Is ROS:7.6 ready for real production work?
Replies: 18
Views: 2703

Re: Is ROS:7.6 ready for real production work?

I have a RB5009 in "production" at home running 7.6 (7.5 and 7.4 before). 1Gbit fiber, SFP+ module, NAT, some medium firewalling, 4 VLANs with HW filtering on the bridge, some simple queues and wireguard server. 2 persons frequently working from home, with heavy VPN usage, Teams/Zoom confe...
by jbl42
Sun Oct 30, 2022 7:36 pm
Forum: Announcements
Topic: v7.7beta [testing] is released!
Replies: 322
Views: 124982

Re: v7.7beta [testing] is released!

*) sfp - added 2.5G SFP module support for RB5009;
Thanks. If AutoNeg is disabled and speed fixed to 2.5GB, it works with an ISP provided PON-ONT in RB5009 SFP+ port.
by jbl42
Sun Oct 30, 2022 5:08 pm
Forum: RouterBOARD hardware
Topic: RB5009UG+S+IN availability
Replies: 20
Views: 5393

Re: RB5009UG+S+IN availability

For RB5009, we were able to get our hands on some rb5009upr+s+in. We do not need the PoE, but better than nothing. We also had to bite the bullet and buy some expensive Cisco boxes, because CCR2216 is available nowhere with unknown date of restocking. We still have global chip shortage. My employer ...
by jbl42
Sun Oct 30, 2022 3:46 pm
Forum: Wireless Networking
Topic: Horribly slow Wi-Fi on Mikrotik network
Replies: 134
Views: 25499

Re: Horribly slow Wi-Fi on Mikrotik network

The last email from support... they recommended changing the lease time on the router and Extending the Key Exchange time out to something longer than the 5 min default. This is sheer desperation. There are long standing issues with key exchange on MT WiFi, but this is not related to noise/HD probl...
by jbl42
Fri Oct 28, 2022 9:52 pm
Forum: RouterBOARD hardware
Topic: RB5009UPr+S+IN or hAP ax³
Replies: 11
Views: 3718

Re: RB5009UPr+S+IN or hAP ax³

the fact that Wifi 6 ax is still not fully baked at Mikrotik
WiFi in general at MikroTik is not even closed to be baked.
I'm a MikroTik router proponent, but do yourself a favor and stay away from any MikroTik WiFi.
by jbl42
Tue Oct 25, 2022 11:06 pm
Forum: Containers
Topic: Looking for Docker container ideas for RouterOS
Replies: 121
Views: 31724

Re: Looking for Docker container ideas for RouterOS

I'm going to evaluate for the coming days...luckily an RB5009 has 1Gbytes so there is some headroom ... but stil.... If I read your chart right, the memory consumption increased by about 4MB in about 6h and seems to stabilize towards the end of the available data. PiHole is caching things like reso...
by jbl42
Tue Oct 25, 2022 10:44 pm
Forum: Announcements
Topic: v7.6 [stable] is released!
Replies: 279
Views: 143149

Re: v7.6 [stable] is released!

No, I did not try to disable L3HW.
I don't see any value in running a ROS version with broken L3HW on a CCR2216. As you mentioned, the large scale L3HW capabilities are the reason to pay the extra money for a CCR2216 in the first place.
by jbl42
Tue Oct 25, 2022 12:21 am
Forum: RouterBOARD hardware
Topic: Stability of pwr-line support? Why not advertised on product page?
Replies: 28
Views: 2329

Re: Stability of pwr-line support? Why not advertised on product page?

I think I have to rephrase my question: what´s better in 6.47.9 wifiwise than with 6.49.7 ?
Nothing we know about, and hardly related to TX power.
But everything after 6.47.9 is worse than 6.47.9.
No more details known beyond what is mentioned in the (incomplete and sketchy) ROS release notes.
by jbl42
Mon Oct 24, 2022 11:51 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101764

Re: mDNS repeater feature

Its not MTs fault, its Apple fault to use mDNS. As a hobbyist, this might be a valid point. As a professional: Have you ever tried to sell gear not supporting the managements beloved iThings to a company? Ever tried to explain to a "important" manager that his shiny new iPad Pro cannot co...
by jbl42
Mon Oct 24, 2022 11:29 pm
Forum: RouterBOARD hardware
Topic: Stability of pwr-line support? Why not advertised on product page?
Replies: 28
Views: 2329

Re: Stability of pwr-line support? Why not advertised on product page?

Is it related to the TX power setting, which is not available in newer versions? No, it is related to issues with the ROS 7.x WiFi driver for hAP lite and hAP mini. TX power was removed to comply with regulation. But contrary to popular belief, increasing TX power does not help much anyway. WiFi is...
by jbl42
Mon Oct 24, 2022 10:40 pm
Forum: Announcements
Topic: v7.6 [stable] is released!
Replies: 279
Views: 143149

Re: v7.6 [stable] is released!

Installed 7.6 without issues on several RB4011(no WiFi) and R5009. Basic setups (NAT, VLAN filtered bridge, some simple queues, basic firewalling, DHCP client/server), all working fine so far. Different on CCR2216: BPG/OSPF with large (300'000+) tables and L3HW enabled is unstable and peer connectio...
by jbl42
Mon Oct 24, 2022 10:15 pm
Forum: Wireless Networking
Topic: Horribly slow Wi-Fi on Mikrotik network
Replies: 134
Views: 25499

Re: Horribly slow Wi-Fi on Mikrotik network

It is and was a sad story: Never put MT WiFi APs into noisy environments, especially not if you are the one being called if things do not work: The 2.4Ghz Radio will kind of lock up every few hours or days, requiring a reboot to get clients connecting again For 5Ghz, if using DFS channels (what is i...
by jbl42
Tue Oct 11, 2022 1:20 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101764

Re: mDNS repeater feature

Yes, 224.0.0.0/24 addresses shall not be and are not routed by normal routing. That's why an additional mDNS reflector is required in the first place to propagate mDNS among subnets. Technically, it is an odd thing to do. But practically there are many add-on implementations by Cisco et al to make A...
by jbl42
Wed Sep 14, 2022 9:47 pm
Forum: Wireless Networking
Topic: Intra-bss traffic blocking
Replies: 6
Views: 1322

Re: Intra-bss traffic blocking

At least for the Zyxel APs I used so far, intra-bss blocking blocks communication between clients (STAs) on the same AP using the same SSID, independent of 2.4/5GHz band. Other brands calls the same feature client isolation. This is often used for public APs in Hotels, Bars, Shops etc. for security ...
by jbl42
Wed Sep 14, 2022 2:31 pm
Forum: General
Topic: Mikrotik Hardware/RouterOS - NIST Compliant ?
Replies: 5
Views: 824

Re: Mikrotik Hardware/RouterOS - NIST Compliant ?

"NIST compliance" is a very broad term. NIST (National Institute of Standards and Technology, a US Federal Organization) has many different standards in different revisions. Some of them also combine or overlap with US federal standards like FIPS . I suggest to ask for the exact standard n...
by jbl42
Tue Sep 13, 2022 10:07 pm
Forum: General
Topic: 2116 and 2216 differences
Replies: 3
Views: 968

Re: 2116 and 2216 differences

The price difference mainly comes from thw 2216 providing 25GBit local links with 100Gbit uplinks vs. 2116 with 1Gbit local links and 10Gbit uplinks. 25/100 Gbit vs 1/10Gbit switch chip makes a big price difference. If your routing/QOS is CPU based and the load high enough for the CPU being the bott...
by jbl42
Fri Sep 09, 2022 5:28 pm
Forum: RouterBOARD hardware
Topic: CCR-1036-8G-2S+ with SFP 1G on 100 mbps
Replies: 3
Views: 958

Re: CCR-1036-8G-2S+ with SFP 1G on 100 mbps

SFP(+) is an unofficial standard and only specifies the mechanical and electrical interface. There are different protocols possible between the SFP port and the inserted module. Depending on speed and copper vs optical: MII, GMII, SGMII, raw 4b5b, raw 8b10b, and many more. Technically, a SFP(+) host...
by jbl42
Fri Sep 09, 2022 5:03 pm
Forum: RouterBOARD hardware
Topic: RB5009 PoE in doesn't work with Netgear GSM4210P PoE+ switch
Replies: 5
Views: 1616

Re: RB5009 PoE in doesn't work with Netgear GSM4210P PoE+ switch

1. I'm not sure the OP is talking about RB5009UPr. The "normal" RB5009 also has PoE in on ether1 2. The 7.6beta6 release notes do not mention any PoE in related fix 3. Running betas on production devices is a no-go. So are you telling us RB5009UPr is not ready for production yet? An then t...
by jbl42
Mon Sep 05, 2022 12:00 pm
Forum: Announcements
Topic: v7.5 [stable] is released!
Replies: 219
Views: 69675

Re: v7.5 [stable] is released!

Updated two RB4011 and one RB5009 in our testlab and one RB5009 at my home network 7.4.1 -> 7.5 without issues so far. Used features: intra VLAN routing (no BGP/OSPF) with srcNAT towards WAN, bridging 5-7 VLANs with HW filtering, 30-50 FW rules, some simple queues, NTP server/client, DHCP server/cli...
by jbl42
Fri Sep 02, 2022 2:59 pm
Forum: General
Topic: Advertising: "Sharing feedbacks on FlashStart DNS malware & content filtering"
Replies: 54
Views: 3495

Re: Advertising: "Sharing feedbacks on FlashStart DNS malware & content filtering"

As I said before, free filtering platform or software (ex. Pi-Hole) are suitable if the Organization has a skilled admin supporting the service. And if there is no need for enterprise features (such as Active Directory integration, Google workspace synchronization, etc). Most companies using MT equ...
by jbl42
Wed Aug 24, 2022 10:08 pm
Forum: General
Topic: Transport VLANs through masquerade
Replies: 3
Views: 803

Re: Transport VLANs through masquerade

I would like to be able to access the same VLANs of building B, basically as if I were connected directly to the router of building B. How can I go about transporting VLANs through NAT? (The masquerade is involved) VLAN is Layer2, NAT happens on Layer3. You need a L2 over L3 tunnel, like EoIP and s...
by jbl42
Wed Aug 24, 2022 9:34 pm
Forum: General
Topic: Does the RB5009UG supports EEE?
Replies: 1
Views: 939

Re: Does the RB5009UG supports EEE?

RB5009 does support EEE 802.3az on ether1 - ether8. I have several RB5009s connected to Cisco switches and EEE is supported and operational on Cisco <-> RB5009 1GB connections. It is not mentioned in the MT specs, It is not visible, cannot be disabled. But its there and it works. Here an example of ...
by jbl42
Tue Aug 16, 2022 1:47 pm
Forum: RouterBOARD hardware
Topic: RB5009UPr+S+IN - is PoE isolated or not?
Replies: 3
Views: 1188

Re: RB5009UPr+S+IN - is PoE isolated or not?

In general: If the specs of a PoE source device do not explicitly mention galvanic isolation for PoE, there is none. It is quite expensive to build in. Devices like MikroTik, Ubnt, TP etc all miss galvanic isolation on the PoE outs. The PoE GND is directly connected to the power supply ground of the...
by jbl42
Mon Aug 15, 2022 10:49 pm
Forum: RouterBOARD hardware
Topic: CCR2004-1G-2XS-PCIe VMWare 7 Driver
Replies: 3
Views: 1593

Re: CCR2004-1G-2XS-PCIe VMWare 7 Driver

I was able to pass the card through to a Linux VM running ubuntu 20.04 and it shows 1G but I can almost get 10G through it with iperf. I was hoping to be able have the card show up as vmnics. Glad to hear it worked. The AR8151 network chip is actually a 1GB chip, but the virtual chip as emulated by...
by jbl42
Mon Aug 15, 2022 10:14 pm
Forum: RouterBOARD hardware
Topic: CSS610-8P-2S+IN after a few weeks
Replies: 3
Views: 2087

Re: CSS610-8P-2S+IN after a few weeks

The CSS610-8P (and CSS610-8G) is built based on the Marvell 88E6390X switch chip. SwitchOS lite runs on a small CPU integrated into the switch chip, what makes the very low price point possible, compared to other brand's managed PoE 2x10GB switches. But the drawback is it has not enough resources to...
by jbl42
Mon Aug 15, 2022 8:23 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101764

Re: mDNS repeater feature

That's not true. It's called limiting access. For example, say you wanted to expose port 22 to another vlan, but not port 23, you can limit what can communicate. Exactly. Even Enterprise boxes from Cisco, Juniper and the usual suspects provide mDNS proxies to allow AppleTV based screen sharing amon...
by jbl42
Mon Aug 15, 2022 8:05 pm
Forum: RouterBOARD hardware
Topic: CCR2004-1G-2XS-PCIe VMWare 7 Driver
Replies: 3
Views: 1593

Re: CCR2004-1G-2XS-PCIe VMWare 7 Driver

The CCR2004-1G-2XS-PCIe emulates a Atheros 1GB chip towards the host supported by the Linux atl1c driver. It requires a patch added by MikroTik so it is recognized as 10/25GB interface. Currently it is only supported by recent Linux kernels. Not in Windows , FreeBSD (yet) or VMWare7 (I suppose you a...
by jbl42
Sat Jul 16, 2022 9:03 pm
Forum: Beginner Basics
Topic: tools/mac-winbox feature not working
Replies: 10
Views: 1149

Re: tools/mac-winbox feature not working

Also of note, I have spun up a CHR and I am able to connect to it via MAC from a laptop on the same layer 2 but from the Windows 11 machine, I am unable. I have gone so far as to move ports on the CRS305 for this Window 11 machine and still see the same issue. Same here: Winbox-mac can not connect ...
by jbl42
Wed Jul 13, 2022 11:51 pm
Forum: RouterBOARD hardware
Topic: RB5009UP wrong description/datasheet?
Replies: 18
Views: 1915

Re: RB5009UP wrong description/datasheet?

But on CRS-8P that have both 48 and 24, , if I plug non mikrotik device like a PMP450i are provided 48V, if I plug AF5XHD or AF60-LR, are provided 24V without force anything. The handshake do the choice....??? The PMP450i supports 802.at active PoE in. The CRS-8P supports 802.3af/at @48V and passiv...
by jbl42
Wed Jul 13, 2022 9:32 pm
Forum: Containers
Topic: Looking for Docker container ideas for RouterOS
Replies: 121
Views: 31724

Re: Looking for Docker container ideas for RouterOS

https://hub.docker.com/r/andrius/asterisk
should run on RB5009/RB4011 and similar arm/arm64 MT devices, but did not try it yet.
by jbl42
Mon Jul 11, 2022 10:40 pm
Forum: RouterBOARD hardware
Topic: RB5009UPr+S+IN PSU Only 96w!!
Replies: 2
Views: 1041

Re: RB5009UPr+S+IN PSU Only 96w!!

Do we need to buy additional Power Supply? According to specs, RB5009UPr+S+IN reserves 20W for its own usage, leaving max 130W for devices running on PoE supply. Or 76W with the included PSU. So if the total power consumption of attached PoE devices stays below 76W (which is the case for many appli...
by jbl42
Mon Jul 04, 2022 11:05 pm
Forum: Beginner Basics
Topic: Really need help with setup
Replies: 3
Views: 454

Re: Really need help with setup

Ping to the next hop timeout, and ping to any other IP say no route. I have a deadline this week to get it working, so I'm desperate for help! I have a deadline this week to get it working, so I'm desperate for help! No ROS version, no config export, no details on your setup, nothing about what you...
by jbl42
Mon Jul 04, 2022 10:08 pm
Forum: General
Topic: anydesk allow
Replies: 5
Views: 2798

Re: anydesk allow

We have some branches connected through Mikrotik PPTP As others have suggested, you might read about PPTP and consider switching to wireguard: https://en.wikipedia.org/wiki/Point-to-Point_Tunneling_Protocol#Security we have disabled their Internet usage by disabling masquerade nat. Disabling masque...
by jbl42
Mon Jul 04, 2022 9:47 pm
Forum: Wireless Networking
Topic: radar detected problems
Replies: 85
Views: 74322

Re: radar detected problems

Anyway, Mikrotik has worse issues with radars than others, as far as I can tell Absolutely. In noisy environments, MikroTik APs tend to "detect" radars all over the place and constantly jump DFS channels. There are many complaints about this in the forum. If non-DFS schannels are not an o...
by jbl42
Mon Jul 04, 2022 9:26 pm
Forum: Announcements
Topic: v7.4beta [testing] is released!
Replies: 189
Views: 61684

Re: v7.4beta [testing] is released!

I would think the AP would send an appropriate errormessage and the clients would then go through the complete authentication cycle instead of using the fast PMKSA. Yes, obviously that is what's going wrong. According to 802.11r, it is not based on error codes, but by the AP initating a full IEEE 8...
by jbl42
Mon Jul 04, 2022 6:46 pm
Forum: Announcements
Topic: v7.4beta [testing] is released!
Replies: 189
Views: 61684

Re: v7.4beta [testing] is released!

> *) wifiwave2 - added initial support for roaming (802.11r) between local AP interfaces; If 802.11r is enabled (`security.ft=yes`) some devices can't reconnect to an AP after the latter gets rebooted. In my case it was an iPhone with iOS 15.5. Logs show the following: mac-address@wifi2 rejected, c...
by jbl42
Mon Jul 04, 2022 3:18 pm
Forum: RouterBOARD hardware
Topic: Hardware mods RB5009
Replies: 1
Views: 3150

Re: Hardware mods RB5009

I can remember a link to a thread were someone actually did soldering PCIe sockets onto an RB5009 board. It was either on reddit or here, could not find it in a quick search. He could not get it to work. Most likely there are other components in addition to the PCIe sockets required to be soldered. ...
by jbl42
Wed Jun 22, 2022 1:25 am
Forum: RouterOS beta
Topic: RTSP Helper
Replies: 98
Views: 22812

Re: RTSP Helper

Bro, what are you smoking? Grow up. Netmap is NOT stateless. I use it on ISP BNGs and also in my personal home router for /32s and the same thing for normal home users who are my clients. I have given up to ask you how iptables netmap statefuly accepts incoming UDP content streams to a port request...
by jbl42
Tue Jun 21, 2022 1:04 am
Forum: RouterOS beta
Topic: RTSP Helper
Replies: 98
Views: 22812

Re: RTSP Helper

And every freakin distributor loves to lock in the end user with their specific solution aka "triple play" and likes. And besides VLAN and other related stuff, all using specific port numbers, transport initialization, multiple streams using different transports and sometimes even proprie...
by jbl42
Tue Jun 21, 2022 12:16 am
Forum: RouterOS beta
Topic: RTSP Helper
Replies: 98
Views: 22812

Re: RTSP Helper

Repeat after me: There Are No Standards, Not Even for IPTV. :D Sniffing the Transport field in the outgoing RTSP request as defined in RFC2326 is enough to have all those IPTV solutions working. Transport: RTP; unicast;client_port=12345 OpenWRT manages to handle all those IPTV services with just th...
by jbl42
Mon Jun 20, 2022 10:59 pm
Forum: RouterOS beta
Topic: RTSP Helper
Replies: 98
Views: 22812

Re: RTSP Helper

Bottom line, it's virtually impossible to implement a general RTSP "helper" since there isn't just one "standard". Quite the opposite there are many different ones including proprietary solutions and they all differ depending of intended application. While I agree on this, I thi...
by jbl42
Mon Jun 20, 2022 5:44 pm
Forum: Announcements
Topic: v7.3 and v7.3.1 [stable] is released!
Replies: 269
Views: 81392

Re: v7.3 and v7.3.1 [stable] is released!

Isn't that just "architectures supported by dockerhub"? When you compile your own binaries, you could use any architecture, of course easiest is to use the architectures supported by gcc. Yes. Dockerd and associated utilities can be installed and/or built anywhere a recent enough working ...
by jbl42
Mon Jun 20, 2022 2:52 pm
Forum: Announcements
Topic: v7.3 and v7.3.1 [stable] is released!
Replies: 269
Views: 81392

Re: v7.3 and v7.3.1 [stable] is released!

Only x86, arm and arm64 Architectures supported by Docker are ARM ARM 64 IBM POWER IBM Z PowerPC 64 LE x86 x86-64 Docker does not support MIPS or Tilera (TILE support anyway was removed from official Linux kernels in 2018 ). While technically Docker most likely could be ported to Linux/MIPS or Linu...
by jbl42
Sat Jun 11, 2022 12:03 am
Forum: General
Topic: Cake Queue for Bufferbloat
Replies: 2
Views: 823

Re: Cake Queue for Bufferbloat

Im getting this error in red now which I didn't have before the upgrade anyone know best way to resolve it?
Remove the bandwitdth from the cake queue type and configure traffic limits within the queue itself.
by jbl42
Wed Jun 08, 2022 11:46 pm
Forum: RouterOS beta
Topic: posts not strictly related to: v7.4beta [testing]
Replies: 165
Views: 12771

Re: posts not strictly related to: v7.4beta [testing]

If the users instead to submit problems to support@mikrotilk.com do a mess on user forum So reporting the same issue over and over to support is better than reporting the same issue again in the forum? And why is MT support telling me to report issues with betas in the forum? And how does it come y...
by jbl42
Wed Jun 08, 2022 11:29 pm
Forum: RouterOS beta
Topic: posts not strictly related to: v7.4beta [testing]
Replies: 165
Views: 12771

Re: v7.4beta [testing] is released!

If the user read the whole topic to see if someone has already asked or reported the same thing, instead of making another post virtually identical, there will probably be no errors and everything would be more readable ... Nope, the user is not exepcted to read the whole topic for a (beta) release...
by jbl42
Wed Jun 08, 2022 2:04 pm
Forum: General
Topic: posts not strictly related to: v7.3 and v7.3.1 [stable]
Replies: 52
Views: 5252

Re: v7.3 [stable] is released!

As far as I have tested, this authentication using APP password has limited use. You can not logg inn to an gmail account with it (using web), so you can not change anything. There are (IMHO perfect legitimate) reasons for APP passwords: If it leaks, you just can revoke the APP password using your ...
by jbl42
Wed Jun 08, 2022 12:26 am
Forum: Announcements
Topic: v7.3 and v7.3.1 [stable] is released!
Replies: 269
Views: 81392

Re: v7.3 [stable] is released!

Updated the RB5009 at home (admittedly also kind of YOLO with 3 teenagers ;-) from 7.2.2 to 7.3.
No new issues so far, config export diff is clean.
Same with two lab RB4011 at work.
by jbl42
Tue Jun 07, 2022 11:20 pm
Forum: General
Topic: posts not strictly related to: v7.3 and v7.3.1 [stable]
Replies: 52
Views: 5252

Re: v7.3 [stable] is released!

In both routers
/system routerboard settings set auto-upgrade=yes
was configured and routerboard firmware version was v7.2.3
You have remote routers on auto-upgrade and get them updated at the same day of a new 7.x release?
You seem to be more the YOLO type of admin ¯\_(ツ)_/¯
by jbl42
Fri Jun 03, 2022 1:08 am
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 104217

Re: v7.3rc [testing] is released!

Also, in such cases it will be sufficient to have a simple queue tree with e.g. 4 or 8 priorities derived from DSCP, similar to what you have with WiFi WMM. But it appears that some people really are only satisfied when having CAKE. That's what we did for many years before there was Cake. The beaut...
by jbl42
Thu Jun 02, 2022 11:22 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 104217

Re: v7.3rc [testing] is released!

It's usually pretty hard to saturate >1Gbs connections without proper test equipment so that's probably why you don't see any major difference ie only achieves 10-15 ms latency. Also buffer bloat is usually less of an issue for symetric lines like 1000/1000. In extreme cases like 1000/50 cable inte...
by jbl42
Thu Jun 02, 2022 9:41 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 104217

Re: v7.3rc [testing] is released!

I have a 1Gbit fiber connection over pppoe and when i use these settings ( corrected for 1000mb up and 1000mb down ) this does not improve things, only losing some bandwith. Even when setting bandwith to 900mb up and down, the bufferbloat remains te same ( about +10ms to +15ms on a 2ms unloaded pin...
by jbl42
Wed Jun 01, 2022 6:45 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 104217

Re: v7.3rc [testing] is released!

@nrz If you you deliberately want to missinterpret what I wrote, you can read or that way. Fell free not to listen to your customers, many of them beta testing your stuff and sharing their decades of experience for free. Just continue debating your customers and knowing things better. Luckily my sal...
by jbl42
Wed Jun 01, 2022 5:47 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 104217

Re: v7.3rc [testing] is released!

If you are referring to BFD,. I'm referring to BGP Multipath selection, BGP Aggregation, RFC 6666, RFC 6286,BGP Advertisement monitoring and BGP Prefix limit (prefix limit has "initial support" with 7.3 after having having MT officials here in the forum claiming it is not needed at all). ...
by jbl42
Wed Jun 01, 2022 2:31 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 104217

Re: v7.3rc [testing] is released!

Regarding the non-existing progress on BGP and IPv6 in ROS7, I really wonder to whom MT is planning to sell all the new CCR2000 high-end devices not able to run ROS6. With all the more advanced features missing, who is supposed to buy those devices? They are way overpowered for home applications, an...
by jbl42
Wed Jun 01, 2022 10:57 am
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 104217

Re: v7.3rc [testing] is released!

What's new in 7.3beta40 (2022-May-11 12:18): !) queue - do not allow using CAKE type in simple and tree setups (already configured queues will be disabled); Ok. Cake is not allowed for simple queues and tree queues anymore. Will be disabled. Got it. What's new in 7.3rc1 (2022-May-27 11:50): *) queu...
by jbl42
Tue May 31, 2022 8:42 pm
Forum: Wireless Networking
Topic: RB4011iGS wifi speed.
Replies: 11
Views: 3552

Re: RB4011iGS wifi speed.

The maximal raw WiFi bandwidth with ac2 2x2 Mimo is 866MBit/s (2x433). Connection at the theoretical max rate will only work in the same room a few meters away from the RB4011, if it at all. A room away it will be closer to 200-300MBit raw WiFi rate. The practical per client TCP bandwidth as measuer...
by jbl42
Mon May 30, 2022 11:15 am
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 104217

Re: v7.3beta [testing] is released!

Surely, download is shaped and controlled by the ISP and upload by the client? What am I not understanding here with everyone wanting Cake on Simple Queue? See here for an example were the DL/UL is shaped by the ISP to 500/100 https://forum.mikrotik.com/viewtopic.php?p=935980#p935980 The cake simpl...
by jbl42
Sun May 29, 2022 10:27 pm
Forum: General
Topic: Hex S upgrade from v6.48 to v7.2
Replies: 7
Views: 4292

Re: Hex S upgrade from v6.48 to v7.2

Are there any advantages at the RouterOS v7.2.3? It depends. For the average IPV4 NAT home/smb router, ROS 7 works fine. Plus you get Wireguard and fq_codel/cake queues. For the more advanced stuff (IPv6, "real" routing with BGP/OSPF, advanced queue trees, VXLAN, MLPS, ...) ROS 7 is not y...
by jbl42
Sun May 29, 2022 9:15 pm
Forum: RouterOS beta
Topic: some quick comments on configuring cake
Replies: 285
Views: 103819

Re: some quick comments on configuring cake

To avoid further flooding of the 7.30beta thread with Cake topics, here some results taken from my home network: RB5009, ROS 7.2.2, Fiber uplink at SFP1 using PPPoE with NAT capped at nominal 500/100 by the ISP equipment at the other end of the fiber. The ISP UL shaper does a not so bad job, but the...
by jbl42
Sat May 28, 2022 9:25 pm
Forum: General
Topic: Which use cases for CCR2004-1G-2XS-PCIe ?
Replies: 34
Views: 6155

Re: Which use cases for CCR2004-1G-2XS-PCIe ?

If the rumored price of about 210€ turns out to be true, it is even a very good offer if it is just used as a "normal" 2x SFP28 NIC in pass-through mode for Linux servers.
by jbl42
Sat May 28, 2022 7:31 pm
Forum: General
Topic: When was bridge HW offload with RSTP added for MT7621/RTL8367 (HeX/4011 and others)? --> New/Old wiki conflicting info [SOLVED]
Replies: 2
Views: 1116

Re: When was bridge HW offload with RSTP added for MT7621/RTL8367 (HeX/4011 and others)? --> New/Old wiki conflicting in [SOLVED]

My guess is RSTP on those switch chips was added at the same time as the VLAN-filtering and the footnote can just be updated Yes, for devices using RTL8367 (like RB4011), l2hw offload for STP/RSTP was introduced at the same time as VLAN filtering. And because ether1-5 and ether 6-10 are connected t...
by jbl42
Thu May 26, 2022 11:51 pm
Forum: RouterBOARD hardware
Topic: CCR2004-1G-2XS-PCIe not supported on Windows
Replies: 16
Views: 4185

Re: CCR2004-1G-2XS-PCIe not supported on Windows

I do not have a spare parts to test on win 10, but probably the string is emulated, not real.... (win 10/11 is the same from this point of view) According to the block diagram , the Ethernet controllers exposed to the PCIe host are indeed not "real". They are kind of emulated inside the A...
by jbl42
Mon May 23, 2022 11:07 pm
Forum: General
Topic: CCR2004-16G-2S+PC + POE-IN usage
Replies: 8
Views: 2251

Re: CCR2004-16G-2S+PC + POE-IN usage

Hosts' DHCP times out before router is fully up to hand out IPs.. Hosts pick their own RFC3927 address and remain offline. Some hosts retry the DHCP discovery and come online properly.. Once the router is back, run a script on the switch disabling all client switch ports and reenabling them after s...
by jbl42
Mon May 23, 2022 9:39 pm
Forum: General
Topic: SIP Issues
Replies: 40
Views: 7195

Re: SIP Issues

Looking at the 2nd capture sniff02.png At packet #241-243 the SIP host sends 3x SIP CANCEL, which the MikroTik fails to deliver to the PBX and hence bounce with ICMP code 3 (Host unreachable). After that (starting at #254), the PBX on 192.168.1.252 starts responding again, but never with something e...
by jbl42
Sun May 22, 2022 7:04 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 104217

Re: v7.3beta [testing] is released!

But it works for physical ones, for example, my WAN interface is ether1. I haven't tested if it actually functions properly, but RouterOS let's me assign the queue. In my tests it never was possible to attach cake as interface queues on virtual interfaces. But what works, at least for me up to ROS ...
by jbl42
Thu May 19, 2022 11:09 pm
Forum: General
Topic: SIP Issues
Replies: 40
Views: 7195

Re: SIP Issues

Yes, the Anynode-device is registered to our PBX. And it is registering every 3 minutes. Have you tried to increase the udp-stream-timeout to 5m in /ip/firewall/connection/tracking ? The default value is 3m (minutes), same as your phone's register interval. Maybe the connection times on small inter...
by jbl42
Sat May 14, 2022 1:37 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 104217

Re: v7.3beta [testing] is released!

How do you specify the Cake bandwidth on asymetric links?

limit-at=DOWN/UP ?
There is no limit-at=DOWN/UP for interface queues.
by jbl42
Fri May 13, 2022 7:55 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 104217

Re: v7.3beta [testing] is released!

the cake was a lie all along bros....
:-) memories...
Image
by jbl42
Fri May 13, 2022 7:30 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 104217

Re: v7.3beta [testing] is released!

CAKE type was always meant only for interface queue, it had no effect when used in simple queue. I'm confused. I run 2 cake queue types on my WAN bridge interface in a simple queue and it works without issues. In a WAN interface queue , how do i specify different rates for asymetric lines? Further,...
by jbl42
Thu May 12, 2022 6:59 pm
Forum: General
Topic: network surge protection
Replies: 17
Views: 4679

Re: network surge protection

I see, thanks for the link! That looks like OM3 glass and not plastic to me. 8) But anyway still very cheap. After checking it out: You're right. The "PVC (OFNR)" is bout the coating of the fiber, not the fiber itself. And yes, fs.com is a real price dumper. (I'm not affiliated with fs.co...
by jbl42
Thu May 12, 2022 6:15 pm
Forum: General
Topic: network surge protection
Replies: 17
Views: 4679

Re: network surge protection

@jbl42: you probably just mean multimode fibre (which is glas, but that´s also getting cheaper), or is there really a plastic fibre solution for 1G and for let´s say longer than >30m? We used fs.com OM3 Multimode PVC (OFNR) with success for such applications: https://www.fs.com/products/74385.html?...
by jbl42
Thu May 12, 2022 4:48 pm
Forum: General
Topic: network surge protection
Replies: 17
Views: 4679

Re: network surge protection

Multimode plastic fiber stuff has gotten very cheap. For WAPs exposed on poles, using cheap plastic fiber for the network link solves all problems with EMC, potential differences and surges. If the WAP is missing SFP, use a cheap media converter to convert to copper on top of the pole. The power sup...
by jbl42
Thu May 12, 2022 3:49 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 82073

Re: v7.2.2 [stable] and v7.2.3 [stable] are released!

If we had a public bug tracker / issues list currently known it would be so much easier. If we are at it, proper release notes would make thighs easier too. "fixed an issue with xy" is less than helpful to decide if it is worth to take the risk of an update. Especially nowadays, were ROS ...
by jbl42
Thu May 12, 2022 2:59 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 104217

Re: v7.3beta [testing] is released!

wouldn't it also bottleneck on 1 out of 16 cores with the CCR2116? A single TCP connection is always handled on 1 CPU core. This is required to avoid packet reordering. So if you run a speedtest using only one TCP connection, it will max out 1 core also on CCR2116. But if you run several connection...
by jbl42
Thu May 12, 2022 2:50 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 82073

Re: v7.2.2 [stable] and v7.2.3 [stable] are released!

Come on, this has already been discussed 20 times before! YES, the default was changed. YES, devices that were installed from defaults before that change now display a warning. YES, that warning is needlessly alarming. This is ALL already known. This is only known for frequent reader. Known issues ...
by jbl42
Wed May 11, 2022 12:39 pm
Forum: General
Topic: Filter rules performance and ordering strategy ?
Replies: 57
Views: 6269

Re: Filter rules performance and ordering strategy ?

When you have 20 rules that each check different variant of ICMP and you replace that with a jump to a separate chain it will perform a factor of ~20 better. I know ICMP is just an example for the principle here. But if we are at it anyway: I never got why so many people try to tamper with ICMP in ...
by jbl42
Tue May 10, 2022 9:47 pm
Forum: General
Topic: Filter rules performance and ordering strategy ?
Replies: 57
Views: 6269

Re: Filter rules performance and ordering strategy ?

100 total for input + output + forward chain ? Yes, 100 "non raw" rules in total. What happens above those 100 rules ? Is the performance drop linear or exponential ? (I'm asking because I'm interested in the 5009 once PIM-SM is supported) For our uses cases, it is good enough if RB5009 f...
by jbl42
Tue May 10, 2022 9:07 pm
Forum: RouterBOARD hardware
Topic: CCR2216 40G AND 100G [SOLVED]
Replies: 7
Views: 3724

Re: CCR2216 40G AND 100G [SOLVED]

how is possible reach 140G if the max speed of combined port are 100G? (or not?) As I understand it, we are discussing the speed of the established link, not the effective throughput. The CCR2216 block diagram states "2x100 GB full duplex" for the QSFP ports. It should be possible to esta...
by jbl42
Tue May 10, 2022 8:17 pm
Forum: General
Topic: Filter rules performance and ordering strategy ?
Replies: 57
Views: 6269

Re: Filter rules performance and ordering strategy ?

Does anyone have figures showing "when it stops being negligible" ? The impact and scalability of FW rules is depending on device capabilities like number and speed of CPU cores, RAM size and l3hw offload in the switch chip. So it is hard to come up with numbers among different MT devices...
by jbl42
Tue May 10, 2022 8:03 pm
Forum: Beginner Basics
Topic: RB5009 security after quick set
Replies: 5
Views: 911

Re: RB5009 security after quick set

The RB5009 quick set config gives you the equivalent of a normal "dumb" home NAT router: - DHCP client towards WAN - DHCP server for LAN - DNS server for LAN (forwarding to DNS received by DHCP client on WAN) - srcNAT (masquerade) towards LAN - all connections LAN -> WAN allowed - all conn...
by jbl42
Tue May 10, 2022 7:44 pm
Forum: RouterBOARD hardware
Topic: CCR2216 40G AND 100G [SOLVED]
Replies: 7
Views: 3724

Re: CCR2216 40G AND 100G [SOLVED]

however when I plug in my ccr2216 with the 40g transceiver in port qsfp #1, the qsfp port #2 does not show 100G speed available only 40g. For your setup, QSFP-1 should run in 4x10GB mode and QSFP-2 in 4x25GB mode. I seems like running QSFP-1 with 4x10GB somehow disables 4x25GB on QSFP-2. Most likel...
by jbl42
Tue May 03, 2022 1:59 am
Forum: RouterBOARD hardware
Topic: CRS309-1G-8S+: Poor PPPoE performance
Replies: 8
Views: 3498

Re: CRS309-1G-8S+: Poor PPPoE performance

Do you have some kind of evidence to back up the claim that the RB4011, RB5009, etc will do the job? The RB5009 maxes out a 1GB uplink with PPPoE with 10-30% CPU load on all 4 cores in my personal experience. I has a 4x 1.4GHz 64bit Arm Cortex-A72 CPU compared to 2x 800MHz ARMv7 32bit wich is a lot...
by jbl42
Mon May 02, 2022 10:44 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 82073

Re: v7.2.2 [stable] is released!

Hi strods No issue, thanks for your hard work. Normally I'm not the type getting grumpy in vendor forums. The reason I did tis time is the following: *) leds - fixed wireless related LED behavior with WW2 package; *) ww2 - fixed VLAN tag handling; So those two ww2 related fixes were tested on 7.2.2 ...
by jbl42
Mon May 02, 2022 8:03 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 82073

Re: v7.2.2 [stable] is released!

But in case of such a blocking problem I would expect either a delay of the stable version, or a warning "do not upgrade to this version when you use wifiwave2". In the normal world yes. In the world of Mikrotik labels like "stable" and "RC" and are just randomly attac...
by jbl42
Mon May 02, 2022 6:58 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 82073

Re: v7.2.2 [stable] is released!

What's new in 7.3beta37 (2022-Apr-25 15:29): *) system - fixed RouterOS bootup when wifiwave2 package is installed (introduced in v7.3beta34); And the same bug was also introduced in 7.2.2 "stable", which was released later than 7.3beta37... Bugs introduced in v7.3beta34 also appear in 7....
by jbl42
Sun May 01, 2022 6:06 pm
Forum: General
Topic: State of VXLAN on ROS7
Replies: 0
Views: 485

State of VXLAN on ROS7

We use RB5009 and RB4011 as site routers for small branch offices with good success, while we are mostly a Cisco and Juniper shop for HQ and larger sites. Now we started to investigate VXLAN for near-future use, most of our Juniper/Cisco boxes can do VXLAN in HW at full wire speed. I would love to m...
by jbl42
Tue Apr 26, 2022 7:36 pm
Forum: RouterOS beta
Topic: Torch is not working on bridge interface.
Replies: 2
Views: 2883

Re: Torch is not working on bridge interface.

RB5009 supports L2 hw offloading for VLAN filtering. All traffic not addressed to the CPU interface is handled by the switch chip with wire speed and not visible to the CPU, hence it does not appear in torch. To torch bridge traffic with active VLAN filtering, temporarly disable HW offload on all br...
by jbl42
Thu Apr 21, 2022 3:21 pm
Forum: Beginner Basics
Topic: PPP - PPTP brute force attack
Replies: 16
Views: 2940

Re: PPP - PPTP brute force attack

PPTP is inherently unsafe by today standards, see https://en.wikipedia.org/wiki/Point-to-Point_Tunneling_Protocol#Security If you have known IP ranges from were your PTPP users are connecting, you can improve the situation a little bit by restricting source IPs of PPTP clients. But still, if securit...
by jbl42
Wed Apr 20, 2022 1:48 pm
Forum: General
Topic: [RB5009] A weird performance issue when 100m 1000m mix using [SOLVED]
Replies: 3
Views: 1967

Re: [RB5009] A weird performance issue when 100m 1000m mix using [SOLVED]

The RB5009 has issues if the switch traffic ingress port runs at higher rate than the egress port, in your case towards PC2 with 100MBit. There are several topics discussing this, the biggest is this one, discussing the same issue when mixing 2.5GB and 1GB. https://forum.mikrotik.com/viewtopic.php?p...
by jbl42
Tue Apr 19, 2022 5:55 pm
Forum: RouterBOARD hardware
Topic: RB5009 sfp+ connection problem [SOLVED]
Replies: 6
Views: 3778

Re: RB5009 sfp+ connection problem [SOLVED]

According to the 802.3az standard, EEE shall only be enabled if agreed on both ends during link auto negotiation, using a special "next page" for EEE. Some devices allow to force-enable EEE if auto negotiation is disabled, but this is not conforming to the 802.3az spec. So either the RB500...
by jbl42
Thu Mar 31, 2022 10:35 pm
Forum: RouterBOARD hardware
Topic: RB5009 support
Replies: 129
Views: 66029

Re: RB5009 support

This looks like congestion problems if download traffic ingresses with 2.5GB at ether1 and gets bridged (switched) towards the ether2-8 1GB ports. As the bridge ingress port is faster than the egress port, the switch chip queue for the egress port overruns and packets get dropped. This causes packet...
by jbl42
Tue Mar 29, 2022 9:23 pm
Forum: RouterOS beta
Topic: RTSP Helper
Replies: 98
Views: 22812

Re: RTSP Helper

There must be a very good reason why this "basic" feature is not added to the Linux kernel for over 15 years. So there is no simple toggle "enable RTSP helper". While I personaly do not have a need for a RTSP proxy in ROS, there still is a very good reason there is none in the L...
by jbl42
Tue Mar 08, 2022 12:57 am
Forum: Wireless Networking
Topic: 5 GHz WiFi speed [SOLVED]
Replies: 32
Views: 13141

Re: 5 GHz WiFi speed [SOLVED]

Really looks like using a different main router makes both of your smartphones connecting with 20MHz only while the TV stick is able to connect with 80MHz at the same time. Very weird indeed... Looks like an obscure bug only happening for some "special" combination. I suggest to contact Mi...
by jbl42
Tue Mar 08, 2022 12:40 am
Forum: Beginner Basics
Topic: Script for send SMS
Replies: 10
Views: 2541

Re: Script for send SMS

My ISP give me unlimited traffic but after 10GB it droped me download speed to 3Mbs ... How else can you know bandwidth has dropped if not specifically testing for it ? Checking for the total traffic of the interface to reach 10GB? It is available in interface stats and can also be read by scripts....
by jbl42
Tue Mar 08, 2022 12:27 am
Forum: RouterOS beta
Topic: ipv4 LAN activity on WAN port w/o NAT on sniffer??
Replies: 6
Views: 1391

Re: ipv4 LAN activity on WAN port w/o NAT on sniffer??

As far as I can see you are using your local private IP as source for outgoing public internet traffic, because no NAT. Private IPs are not routed in public Internet, so there will never be a resonse from any server with public IP. The outgoing traffic visible in your screenshot is your ping request...
by jbl42
Mon Mar 07, 2022 11:43 pm
Forum: General
Topic: RB5009 SFP+ Flapping on HP Switch
Replies: 5
Views: 881

Re: RB5009 SFP+ Flapping on HP Switch

@jbl42, VLANs 0 and 4095 are reserved and VLAN with id 1 is the default VLAN used by MikroTik and should not be used... It is explained here https://en.wikipedia.org/wiki/IEEE_802.1Q Yep. VLAN1 is used by MT implementation as default PVID for all ports, same as for many other vendors too. But in of...
by jbl42
Sun Mar 06, 2022 10:49 pm
Forum: Wireless Networking
Topic: 5 GHz WiFi speed [SOLVED]
Replies: 32
Views: 13141

Re: 5 GHz WiFi speed [SOLVED]

My problem is, i noticed that when im upstairs i have full net speed and mobile phone says that wifi link speed is 866 mbps. When im downstairs, wifi link speed is 192 mbps and im standing right below the AP. (I checked with winbox in the router to be sure that phone is indeed connected to downstai...
by jbl42
Sun Mar 06, 2022 10:08 pm
Forum: RouterBOARD hardware
Topic: RB4011 sudden death
Replies: 1
Views: 1160

Re: RB4011 sudden death

please advise what went wrong.it is nearly 1 year old.
Obviously some electronics stuff inside broke, overheated and the unit died. Such things happen.
Return it to your retailer and get it replaced. If it is less than a year old, it is most likely replaced under warranty.
by jbl42
Sun Mar 06, 2022 1:26 pm
Forum: General
Topic: Netinstall failing to launch in Windows 10?
Replies: 7
Views: 1231

Re: Netinstall failing to launch in Windows 10?

bind() failed: An attempt was made to access a socket in a way forbidden by its access permissions. [10013] This is an error coming from the windows socket API when netinstall tries to open (bind) the listening port for incoming netinstall boot request. There are usualy two reasons for this: Anothe...
by jbl42
Sat Mar 05, 2022 6:38 pm
Forum: General
Topic: LLDP Issue - See all devices [SOLVED]
Replies: 3
Views: 1840

Re: LLDP Issue - See all devices [SOLVED]

If a bridge has protocol-mode=none it will forward packets with a destination MAC address 01:80:C2:00:00:0x, this is not compliant with 802.1D but has its uses. It not only violates 802.1D, it has the potential to mess up VOIP settings by propagating LLDP-MED to all ports. If you set protocol-mode=...
by jbl42
Sat Mar 05, 2022 3:56 pm
Forum: General
Topic: RB5009 SFP+ Flapping on HP Switch
Replies: 5
Views: 881

Re: RB5009 SFP+ Flapping on HP Switch

VLAN-id=1 should not be used in your configuration... Read here : https://help.mikrotik.com/docs/display/ROS/VLAN " The IEEE 802.1Q standard has reserved VLAN IDs with special use cases, the following VLAN IDs should not be used in generic VLAN setups: 0, 1, 4095" Source: link above... @z...
by jbl42
Wed Feb 16, 2022 2:54 pm
Forum: General
Topic: how does L3HW actually works?
Replies: 128
Views: 33121

Re: how does L3HW actually works?

For inter vlan routing (aka HW-Offloading Connected Routes). For example if i have two access switch connected to a CRS317. Each access switch is a separate L2 with a /24 subnet. Now if the CRS317 attempts to route between those two networks, two /32 routes a creaded in the routing table of the swi...
by jbl42
Wed Feb 09, 2022 3:30 pm
Forum: RouterBOARD hardware
Topic: RB5009 : all connected ports flap a few times a day
Replies: 33
Views: 14240

Re: RB5009 : all connected ports flap a few times a day

So for now the best workaround is to disable the "Bridge Port" column in winbox, then we can safely enter DHCP leases & ARP list windows again without disrupting router stability.
It is not sure the information is not polled when the column is hidden in Winbox.
by jbl42
Wed Feb 09, 2022 2:12 pm
Forum: RouterBOARD hardware
Topic: RB5009 : all connected ports flap a few times a day
Replies: 33
Views: 14240

Re: RB5009 : all connected ports flap a few times a day

Just advising that this problem is also triggered whenever viewing the “IP → ARP List” Window .. Also, this is not a Winbox problem, as the issue occurs even if you access these menus from Webfig. The IP/Arp window has a column "bridge port", same as the DHCP lease windows. This info is c...
by jbl42
Wed Feb 09, 2022 2:00 pm
Forum: General
Topic: Download Router configuration
Replies: 3
Views: 804

Re: Download Router configuration

that's also why RJ45 console cable is part of the basic toolkit of every network technician. (except that you need multiple adaptors, because various network equipment vendors use diferent pinouts) While MikroTik is using the Cisco pinout which is by far the most common among vendors. But yes, ther...
by jbl42
Wed Feb 09, 2022 1:52 pm
Forum: RouterBOARD hardware
Topic: RB 4011 and RB260GS SFP current (Power consumption)
Replies: 1
Views: 626

Re: RB 4011 and RB260GS SFP current (Power consumption)

3.3V * 700mA = 2.3W The S+RJ10 copper SFP is rated with 2.4W and officially supported for RB4011. So your SFP is OK regarding power consumption for RB4011. Not sure about the RB260GS. But in my experience, the RB4011 in general is a bit picky with SFP support. Especially for "exotic" ones ...
by jbl42
Wed Feb 09, 2022 1:38 pm
Forum: SwOS
Topic: Better switching performace - RouterOS or SwOS
Replies: 2
Views: 2721

Re: Better switching performace - RouterOS or SwOS

Switching performance is depending on the capabilities of the device's switch chip. There might be differences in available features, but the switching throughput ist not depending on ROS vs SwOS. There are some ROS only devices with switch chips not providing l2hw for bridges, so the CPU has to han...
by jbl42
Wed Feb 09, 2022 1:27 pm
Forum: Forwarding Protocols
Topic: multicast specific problem
Replies: 3
Views: 1029

Re: multicast specific problem

The problem is that tv company has multiple streams(10to12) in one multicast ip, where the difference is in the port. Some mikrotiks has eoip connection over internet with the main one, and if a stb connected to these mikrotiks, require one of streams in a ip multicast with multiple streams, all st...
by jbl42
Sun Feb 06, 2022 11:15 pm
Forum: SwOS
Topic: GPON SFP+ 3FE46541AA Negotiating Incorrect Link Speed
Replies: 8
Views: 9408

Re: GPON SFP+ 3FE46541AA Negotiating Incorrect Link Speed

@BettyRNorahDeniels GPON (Gigbabit Passive Optical Network) SFPs in general are different to normal optical transceivers. GPON is a shared medium and requires special encription and time sliceing for media access. GPON SFPs conatain local intelligence handling all this low level stuff autonomiously ...
by jbl42
Sun Feb 06, 2022 3:44 pm
Forum: General
Topic: fq_codel cpu usage (Hex lite/pppoe/capsman)
Replies: 2
Views: 955

Re: fq_codel cpu usage (Hex lite/pppoe/capsman)

am i doing something wrong or is this just a fact of life with the little Hex mips running out of steam? Queues require disabling fastpath so the poor little single core 850MHz MIPS just works it's butt off with routing, NAT and queue ;-) Presumably cake is even more cpu intensive? Efficiency was o...
by jbl42
Sun Feb 06, 2022 3:07 pm
Forum: General
Topic: Download Router configuration
Replies: 3
Views: 804

Re: Download Router configuration

Do you know the user/password to login? If not, there is no way (at least we all hope so ;-). Except doing a factory reset (netinstall) losing everthing. If you have user/pw, you can use serial terminal to access the device and view/export config. RJ45 serial cables are cheap and avaialble everywher...
by jbl42
Sun Feb 06, 2022 2:24 pm
Forum: RouterBOARD hardware
Topic: RB5009 bridge with l2hw forwards LLDP packets?
Replies: 7
Views: 6929

Re: RB5009 bridge with l2hw forwards LLDP packets?

working, but only in CLI
If 88cc is used for mac-protocol, the switch rule can also be set up using Winbox.
The protocoll name lldp (ethertype 0x88cc) is only known on the CLI, not in Winbox.
by jbl42
Fri Feb 04, 2022 9:35 pm
Forum: RouterBOARD hardware
Topic: RB5009 : all connected ports flap a few times a day
Replies: 33
Views: 14240

Re: RB5009 : all connected ports flap a few times a day

A few days with Winbox connected, but showing only the interface table = no flaps and graphs look ok. As soon as I add DHCP server / lease table = gaps started to appear on graphs immediately and all ports flapped after around 2.5 hours. This. I can reproduce this on a RB5009 running 7.1.1: Having ...
by jbl42
Wed Feb 02, 2022 5:02 am
Forum: RouterOS beta
Topic: RB5009 Bridge VLAN access port egress packets tagged
Replies: 1
Views: 1641

Re: RB5009 Bridge VLAN access port egress packets tagged

I could solve similar issues on RB5009 and 7.1.1 by setting frame-types=admit-only-untagged-and-priority-tagged for the untagged access ports. This setting should not be necessary and should have affect on ingress only. But still it helped for me to get rid of wrong egress tags for HW offloaded acce...
by jbl42
Wed Feb 02, 2022 4:07 am
Forum: Wireless Networking
Topic: Band Steering
Replies: 32
Views: 19926

Re: Band Steering

Just give one Band more power, make another one weaker, so devices automaticly will connect to the prefered band, if it is your wish... That's what Mikrotik is telling us for years. But band steering is much more than having different TX power for different bands. This might help if a station newly...
by jbl42
Wed Feb 02, 2022 2:21 am
Forum: RouterBOARD hardware
Topic: Is there a chance for a RB5010UG+2S+IN ?
Replies: 7
Views: 2311

Re: Is there a chance for a RB5010UG+2S+IN ?

This is a Marvell reference design for the 88E6393X switch chip used in RB5009:
E55ndoPUcAAa0gA.jpg
A RB5010UG+2S+IN would not have the leftmost 10G SFP+ cage and use the port towards the CPU. The rest is not much wider than a RB5009.
by jbl42
Tue Feb 01, 2022 9:52 pm
Forum: RouterBOARD hardware
Topic: Is there a chance for a RB5010UG+2S+IN ?
Replies: 7
Views: 2311

Re: Is there a chance for a RB5010UG+2S+IN ?

I do not see much value in the 1/4 of 1U format. Probably this could change if there are future switches etc in the same format combining different devices. Cramming 4 routers in 1U looks nice, but in most practical installation there is no value to have 4 RB5009 type of boxes in 1U. Granted, this m...
by jbl42
Tue Feb 01, 2022 6:19 pm
Forum: Beginner Basics
Topic: Getting a 10 Gbps Connection - router / switch options?
Replies: 9
Views: 3396

Re: Getting a 10 Gbps Connection - router / switch options?

The point of the post you yeah-butted was that the OP can't expect to run a single iperf3 client across the router, all set up with the good strong filtering RouterOS allows, and expect to fill the 10G fiber upstream. Agreed. But often I see setups and bechmarks concentrating on single connection p...
by jbl42
Tue Feb 01, 2022 5:03 pm
Forum: Beginner Basics
Topic: Getting a 10 Gbps Connection - router / switch options?
Replies: 9
Views: 3396

Re: Getting a 10 Gbps Connection - router / switch options?

Single-threaded, as I qualified it, or do you have to get all four cores working to achieve it, as I expect? A single TCP connection is always handled by one thread to avoid packet reordering hampering throughput. In my RB4011 experience, single TCP srcNAT connections max out at 1-3 GB, depending o...
by jbl42
Tue Feb 01, 2022 4:39 pm
Forum: RouterBOARD hardware
Topic: Is there a chance for a RB5010UG+2S+IN ?
Replies: 7
Views: 2311

Is there a chance for a RB5010UG+2S+IN ?

The RB5009 switch chip has 3x10GB and 8x1GB ports. 10GB is used for CPU, SFP+ and 2.5GB on ether1 (dedicated PHY chip), ether2-8 go to 7 of the 1GB port and the 8th 1GB port goes to nowhere (and is also missing in the RB5009 block diagram). This seems like wasting potential for a 2nd SFP+ port and g...
by jbl42
Tue Feb 01, 2022 4:10 pm
Forum: Beginner Basics
Topic: Getting a 10 Gbps Connection - router / switch options?
Replies: 9
Views: 3396

Re: Getting a 10 Gbps Connection - router / switch options?

Worse, in the case of the RB4011, it's tied to the CPU, not to the switch chip so any single-threaded test is likely to choke down to 1-2 Gbit/sec. If this is worse depends on the usage scenarios. Having the SFP+ directly attached to the RB4011 CPU makes it very good for router on a stick applicati...
by jbl42
Tue Feb 01, 2022 3:49 pm
Forum: Beginner Basics
Topic: Getting a 10 Gbps Connection - router / switch options?
Replies: 9
Views: 3396

Re: Getting a 10 Gbps Connection - router / switch options?

Assuming you will do srcNAT towards 10GB WAN, I would recommend to also consider RB5009. It has a SFP+ too and about 30% more CPU power compared to RB4011, but there is no WiFi version (yet?). NAT is handled by the CPU and the RB5009 is capable of NAT routing about 5GB to/from WAN, depending on amou...
by jbl42
Tue Feb 01, 2022 2:59 pm
Forum: Wireless Networking
Topic: 14 years lasting BUG - disconnected, unicast key exchange timeout
Replies: 31
Views: 11751

Re: 14 years lasting BUG - disconnected, unicast key exchange timeout

Switching vendors for wifi was a bitter pill to swallow... But the amount of complaints and trouble tickets made it absolutely essential. This and the simple fact that MT WiFi still lacks MU-MIMO, Bandsteering, 802.11k/v/r mandated for almost all customer installation those days. The "wave2&qu...
by jbl42
Tue Feb 01, 2022 2:16 pm
Forum: Beginner Basics
Topic: Why not a definitive solution to block Youtube?
Replies: 55
Views: 20999

Re: Why not a definitive solution to block Youtube?

replace youtube by pornhub and having kids ;) That's the point: What do you achive with blocking pornhub? There is redtube, xvideos, xhamster and many, many more. They will always find one not on your blocklist, ending in a hare and hedgehog game. And they have friends with parents not caring or la...
by jbl42
Mon Jan 31, 2022 7:22 pm
Forum: Announcements
Topic: v7.2rc2 and v7.2rc3 is released!
Replies: 222
Views: 86442

Re: v7.2rc2 and v7.2rc3 is released!

RB5009 does NOT support l3-hw-offloading (List of supported devices). Setting hw-offload=yes for FastTrack firewall has a recommendatory meaning (i.e., "please offload if you can"). The actual HW offloading state of FastTrack connections appears in the connection list (H flag): I see. Tha...
by jbl42
Mon Jan 31, 2022 3:46 pm
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 225941

Re: v7.1.1 is released!

Consider not upgrading to ROS 7 if you are using a RB4011iGS ... It depends. For serious routing and working IPv6 support, RB4011 better stays on 6.49.2 For more home/small office/lab oriented setups (some VLAN/bridging, some queues for VOIP, some firewalling, outgoing srcNAT, no IPv6) RB4011 works...
by jbl42
Sat Jan 29, 2022 4:27 pm
Forum: Announcements
Topic: v7.2rc2 and v7.2rc3 is released!
Replies: 222
Views: 86442

Re: v7.2rc2 and v7.2rc3 is released!

Weird, checked it again and now l3-hw-offloading is no and I can't set it to yes neither No idea how that worked before, I fiddled around a lot.. However, with v7.2rc3 I have fasttrack forward rules with hw offload working on RB5009. Did not find time for propper testing yet, but a quick ipperf run ...
by jbl42
Sat Jan 29, 2022 3:35 pm
Forum: Announcements
Topic: v7.2rc2 and v7.2rc3 is released!
Replies: 222
Views: 86442

Re: v7.2rc2 and v7.2rc3 is released!

L3 offloading working on 5009 here too, as described by @quotengrote. There is a switch property l3-hw-offloading , which I'm not sure only setting offloading for L3 VLAN routing only or also for L3 fasttrack. I had to set to yes to get everything working. Mine was set to no, can't remember if this ...
by jbl42
Sat Jan 29, 2022 12:48 pm
Forum: RouterBOARD hardware
Topic: RB3011 performance issues
Replies: 9
Views: 7839

Re: RB3011 performance issues

What is the RB3011 CPU load while running speedtests to your ISP? Is the fasttrack rule counting bytes, showing it works? In general, RB3011 strugles with passing 1GBit with NAT and routing doing anything more than simple srcNAT and fasttrack. The offcial RB3011 spec for small packets with NAT routi...
by jbl42
Sat Jan 29, 2022 12:22 pm
Forum: Announcements
Topic: v7.2rc2 and v7.2rc3 is released!
Replies: 222
Views: 86442

Re: v7.2rc2 and v7.2rc3 is released!

2) Major issues with IPv6 in certain scenarios. It seems Linux based hosts (Synology for example) with everything standard, MTU 1500, etc are seeing 25-50% packet loss. On a 10G or 1G link download is around 250Mbps and upload around 25Mbps. The same on macOS 1G link I get gigabit both ways. IPv6 o...
by jbl42
Fri Jan 28, 2022 11:03 pm
Forum: RouterOS beta
Topic: Bridge filter rules : set-priority for VLAN non functional
Replies: 15
Views: 10002

Re: Bridge filter rules : set-priority for VLAN non functional

What's new in 7.2rc3 (2022-Jan-28 16:33):
*) bridge - fixed filter and NAT "set-priority" action;

Seems like this got fixed with 7.2rc3
by jbl42
Thu Jan 27, 2022 7:15 pm
Forum: RouterOS beta
Topic: rv5900 igmp-proxy
Replies: 6
Views: 4540

Re: rv5900 igmp-proxy

Your config looks right. The RB5009 on ROS 7.1.1 and 7.2rc1 has issues with DSCP and VLAN IDs and priorities. The initial report was about troubles with outgoing PPPoE and VLANs. Other users have reported the same also for VLAN ifaces directly attached to physical etherX interfaces, breaking SIP ove...
by jbl42
Thu Jan 27, 2022 6:26 pm
Forum: General
Topic: Confusion on Queue directions: RX/TX in CLI vs. Download/Upload in Winbox
Replies: 0
Views: 1808

Confusion on Queue directions: RX/TX in CLI vs. Download/Upload in Winbox

I have a simple CAKE queue running in the WAN facing bridge interface. It works great, TX bufferbloat goes down from >50ms to ca. 5ms. So funtion-wise nothin to complain. What confuses me is RX/TX in CLI properties [admin@RB5009] > /queue/simple print name="queue1" target=bridge1_vlan2 par...
by jbl42
Thu Jan 27, 2022 2:36 pm
Forum: RouterBOARD hardware
Topic: RB5009 bridge with l2hw forwards LLDP packets?
Replies: 7
Views: 6929

RB5009 bridge with l2hw forwards LLDP packets?

I'm working on a network with 2 Switchzilla SG250 floor switches connected to a RB5009 acting as router and core switch. switch-sz(gi8) <--> (ether4)RB5009-bridge1-l2hw(ether3) <--> (gi1)switch-wz Very happy with that so far, RB5009 bridge1 bridging, VLAN filtering, STP, IGMP and DHCP snooping is al...
by jbl42
Thu Jan 27, 2022 1:43 pm
Forum: RouterBOARD hardware
Topic: RB5009 support
Replies: 129
Views: 66029

Re: RB5009 support

Does anyone know if the same issue happens on 2.5GB+ LAN connections? In my tests, 2.5GB has isssues on ether1 and also on SFP+. 10GB works fine on SFP+, 1GB works fine on all ports. Never tested 5GB on SFP+ due to lack of a device supporting it. While ether2-8 go to 1GB ports of the switch chip, S...
by jbl42
Tue Jan 18, 2022 9:24 pm
Forum: RouterOS beta
Topic: RB5009 Wireguard only 150 Mbps
Replies: 30
Views: 15756

Re: RB5009 Wireguard only 150 Mbps

Clearly not reading the release notes. What's new in 7.1rc3 (2021-Sep-08 13:29): *) added IPSec hardware acceleration support for RB5009; Good to hear I stand corrected for IPSEC and 7.1. Can't wait to give it a new try. My last tests happend on 7.0.5, and I missed the 7.1rc3 release notes just che...
by jbl42
Tue Jan 18, 2022 3:52 pm
Forum: RouterOS beta
Topic: RB5009 ROS 7.1.1 IGMP Snooping issue with L2 HW offload [SOLVED]
Replies: 7
Views: 8229

Re: RB5009 ROS 7.1.1 IGMP Snooping issue with L2 HW offload [SOLVED]

AFAIK ipv6 RA is using ipv6 mcast group ff02::2. This is link-local and as such according to the docs always flooded, independant of MLD snooping. But still it seems the MLD querier is required to keep the ff02::2 MDB entries alive when L2 hw offload is enabled. With bridge L2 hw offload multicast l...
by jbl42
Tue Jan 18, 2022 3:33 pm
Forum: RouterOS beta
Topic: RB5009 Wireguard only 150 Mbps
Replies: 30
Views: 15756

Re: RB5009 Wireguard only 150 Mbps

Afaik, there is no IPSEC HW acceleration yet on the RB5009. Thus, Wireguard is done in software. Currently not. But the RB5009 SoC supports crypto HW offload for IPSEC, Wireguard etc. MT support told me making it available in future ROS releases is to be expected. Until this happens, the RB4011 is ...
by jbl42
Tue Jan 18, 2022 3:02 pm
Forum: RouterOS beta
Topic: RB5009 ROS 7.1.1 IGMP Snooping issue with L2 HW offload [SOLVED]
Replies: 7
Views: 8229

Re: RB5009 ROS 7.1.1 IGMP Snooping issue with L2 HW offload [SOLVED]

Just be aware that the ROS bridge IGMP querier is not VLAN aware: Only untagged IGMP/MLD general membership queries are generated, IGMP queries are sent with IPv4 0.0.0.0 source address , MLD queries are sent with IPv6 link-local address of the bridge interface. The bridge will not send queries if a...
by jbl42
Mon Jan 17, 2022 2:52 pm
Forum: RouterOS beta
Topic: Bridge filter rules : set-priority for VLAN non functional
Replies: 15
Views: 10002

Re: Bridge filter rules : set-priority for VLAN non functional

Besides, in any circumstances I'm getting new-vlan-priority not supported for this switch while trying to apply switch-rules on Marvell-88E6393X [admin@RB5009] /interface/ethernet/switch> rule add switch=switch1 ports=ether2,ether8 vlan-id=100 new-vlan-id=101 [admin@RB5009] /interface/ethernet/swit...
by jbl42
Mon Jan 17, 2022 1:06 am
Forum: RouterBOARD hardware
Topic: RB5009 : all connected ports flap a few times a day
Replies: 33
Views: 14240

Re: RB5009 : all connected ports flap a few times a day

There is s similar report here
by jbl42
Mon Jan 17, 2022 1:00 am
Forum: RouterOS beta
Topic: Bridge filter rules : set-priority for VLAN non functional
Replies: 15
Views: 10002

Re: Bridge filter rules : set-priority for VLAN non functional

That very issue is still occuring using 7.1.1 on RB5009 (arm64). VLAN PCP/802.1p is not properly set through bridge filter rule. In my experience, bridge filter rules do not work on RB5009 for bridges with L2 hw offload enabled. But adding PCP/802.1p priorites works for me on RB5009 using interface...
by jbl42
Mon Jan 17, 2022 12:27 am
Forum: RouterBOARD hardware
Topic: Port flapping RB5009 + vodafone modem
Replies: 35
Views: 14085

Re: Port flapping RB5009 + vodafone modem

But I don't understand why this would change anything, all ports on the RB5009 are connected to the 88E6393X switch? The 88E6393X is a 11port switch chip: 3x 10GB raw MI and 8x 1GB with integrated PHYs. One 10GB goes to the CPU, one to the SFP+ and the 3rd is connected to a 2.5GB PHY chip ( QCA8081...
by jbl42
Wed Dec 08, 2021 3:03 pm
Forum: General
Topic: S+RJ10 overheating: how to reduce to 5Gbs/s ?
Replies: 3
Views: 1386

Re: S+RJ10 overheating: how to reduce to 5Gbs/s ?

I have the same problem. I have a CRS326-24G-2S+IN with a S+RJ10 and lately the SFP+ module has been hitting about 110C and experiencing high packet loss. Is it possible to manually change the speed to 5 or 2.5GbE to lower the temperature? 10GbE SFP+ modules are in general problematic regarding ove...
by jbl42
Mon Nov 22, 2021 2:38 pm
Forum: Announcements
Topic: v6.49.1 [stable] is released!
Replies: 138
Views: 81123

Re: v6.49.1 [stable] is released!

*)health - improved temperature reporting
We can confirm -274° temp readings in System/Health and SNMP fixed on RB4011 with 6.49.1 (in our case introduced with 6.49.0)
by jbl42
Tue Nov 16, 2021 12:45 pm
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 219
Views: 96790

Re: v6.49 [stable] is released!

Would it be so hard to add a drop box with all the network interfaces in it like TFTP32 and TFTP64 do? That way I dont have to cripple my VPN adapters, bridge devices, VirtualBox, Wifi, WWAN adapters etc and then remember to enable them all again manually. Yes please. I also have >10 network interf...
by jbl42
Tue Oct 19, 2021 12:03 am
Forum: Wireless Networking
Topic: WIFI 6 Roadmap
Replies: 199
Views: 144667

Re: WIFI 6 Roadmap

wifiwave2 supports 802.11w (Management Frame Protection, standardized in 2009) and MU-MIMO (available from other vendors since 2015). At least on the 4 devices were it is supported at all. But not 802.11r, which is required for fast roaming with WPA-Enterprise to allow WiFi roaming without interrupt...
by jbl42
Mon Oct 18, 2021 9:47 pm
Forum: Wireless Networking
Topic: WIFI 6 Roadmap
Replies: 199
Views: 144667

Re: WIFI 6 Roadmap

Seems that the WiFi is godforsaken. No 802.11ax , no wifi 6E. Ok, message undestood, Mikrotik. You have leave us. Much worse: Not even 802.11k/v/r support for WiFi5. meaning it can't beuse outside SOHO applications. MikroTik has obviously given up on WiFi. Use the routers, they are excellent. But d...
by jbl42
Mon Oct 18, 2021 9:34 pm
Forum: Announcements
Topic: v6.48.5 [long-term] is released!
Replies: 167
Views: 107945

Re: v6.48.5 [long-term] is released!

I would like to chime in for all saying Etherboot on the LCD screen == bricked......no. it just means you should backup config before an upgrade. which was mentioned in the very first post on this thread and other recent ROS release announcements. This is commonly called a softbrick, meaning it can...
by jbl42
Sun Oct 10, 2021 9:13 pm
Forum: General
Topic: SFP / Rate Select?
Replies: 5
Views: 8662

Re: SFP / Rate Select?

The SFP rate select signal is on Pin 7/RS0 (RS = Rate Select). The new ROS setting allows to set he state of SFP Pin7/RS0 The SFP specification (not public) says This is an optional input used to control the receiver bandwidth for compatibility with multiple data rates (most likely Fibre Channel 1x ...
by jbl42
Sat Oct 09, 2021 2:04 am
Forum: RouterBOARD hardware
Topic: RB5009 and S-RJ01 SFP speed problem
Replies: 13
Views: 9177

Re: RB5009 and S-RJ01 SFP speed problem

Many 1G SFPs contain a Ethernet Copper/Optical PHY chip talking SGMII to the SFP host. The autoneg is handled by the PHY, not the SFP host. The physical bitrate for SGMII is always 1GB, for 100MB every byte is repeated 10x, for 10MB 100x. Looks like the reported bitrate is the physical SGMII rate be...
by jbl42
Fri Oct 08, 2021 3:18 pm
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 219
Views: 96790

Re: v6.49 [stable] is released!

Yes, this is unlikely a bug in the new version. We regularly see the RB temperature sensors return absolute zero when they cannot get a proper reading, in any version of RouterOS. This might be a coincidence. But checking our SNMP log, we only see occasional -274° temp values on the two RB4011 upda...
by jbl42
Fri Oct 08, 2021 9:44 am
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 219
Views: 96790

Re: v6.49 [stable] is released!

Confirm the temp reading problem in System/Health on RB4011 and 6.49:
The temp changes between -274° and the correct value every 10-15s.
Voltage value is OK.

-274° is probably some internal zero raw value converted to degrees (-273.15° is absolute zero temp).
by jbl42
Tue Oct 05, 2021 9:17 pm
Forum: Announcements
Topic: MikroTik smartphone app (ex Tik-App)
Replies: 487
Views: 272086

Re: MikroTik smartphone app (ex Tik-App)

Yes of course we know MTs are phoning home. And yes we know they stop doing it after after we configured them. And our tight monitoring is nothing special or to be proud of. It's just what is mandated in our highly regulated domain. And all of our competitors do the same. Because they have to. Same ...
by jbl42
Tue Oct 05, 2021 5:17 pm
Forum: Announcements
Topic: MikroTik smartphone app (ex Tik-App)
Replies: 487
Views: 272086

Re: MikroTik smartphone app (ex Tik-App)

Android is "phoning home" all kind of stuff to Google and every other 3rd party willing to pay Google for data. Not to speak of all the ad-tracking networks it talks to all the time. And no, Android is not open source. Big parts are, but the relevant data sensitive bits (Google Play Servic...
by jbl42
Tue Oct 05, 2021 4:52 pm
Forum: Scripting
Topic: how to limit internet download manager, wireless
Replies: 5
Views: 4700

Re: how to limit internet download manager, wireless

The reason you did not get much response is you did not make your researches and did not ask specific questions. "It does not work please tell me what to do without making me educating myself at least a bit" is not what encourage people to help. WiFi for gaming is a bad idea in general and...
by jbl42
Tue Oct 05, 2021 2:11 am
Forum: RouterBOARD hardware
Topic: RB5009 and S-RJ01 SFP speed problem
Replies: 13
Views: 9177

Re: RB5009 and S-RJ01 SFP speed problem

We have seen CRS, RB4011 and RB5009 devices having auto neg issues with fibre and copper 1G SFP modules running in 10G SFP+ ports. Auto neg status never completes, depending on the device at the other end resulting link is reported as none, 100MB or 1GB and is prone to flaps. Connections to media co...
by jbl42
Sun Oct 03, 2021 11:36 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+RM with SFP to RJ45 Copper Transceiver Module
Replies: 8
Views: 3505

Re: RB4011iGS+RM with SFP to RJ45 Copper Transceiver Module

Yes, I sometimes forget the optical stuff has gotten very cheap to... But I think we deviated from the OPs question if an RB4011 can be powered by an active PoE 802.3at or 802.3af switch at ether1 altough not explitly specified. In our experience, it works without problems on 802.3af ports. On 802.3...
by jbl42
Sun Oct 03, 2021 11:03 pm
Forum: RouterBOARD hardware
Topic: RB5009 and S-RJ01 SFP speed problem
Replies: 13
Views: 9177

Re: RB5009 and S-RJ01 SFP speed problem

I had the same issue with an S-RJ01 SFP in a RB4011 running 7.1rc4 and a cable/port working stable with all other tested devices. Sometimes it connects at 1GB with autoneg enabled, when the SFP port is disabled and reenabled some seconds later using Winbox or terminal. What helped to get a stable 1G...
by jbl42
Tue Sep 28, 2021 10:13 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+RM with SFP to RJ45 Copper Transceiver Module
Replies: 8
Views: 3505

Re: RB4011iGS+RM with SFP to RJ45 Copper Transceiver Module

The difference is you can get the 0.5m fs.com DAC for 10€ while 2x SFP+ LC module and a fibre to connect them will be 60-100€. For some unknown reason MikroTik decided not to spend a few bucks to add propper DAC driving circuits to the RB4011 SFP+ port. This makes short distance 10G connections requ...
by jbl42
Tue Sep 21, 2021 3:39 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+RM with SFP to RJ45 Copper Transceiver Module
Replies: 8
Views: 3505

Re: RB4011iGS+RM with SFP to RJ45 Copper Transceiver Module

We have several RB4011 supplied by eth1/802.3at from switches of different brands (Cisco, HPE, Zyxel and others) without any problems. According to the switch logs, the RB4011 properly negotiates af/at on eth1, although not specified. In our experience, the power consumption of a RB4011 with 4 or le...
by jbl42
Mon Sep 06, 2021 10:57 pm
Forum: General
Topic: MikroTik RB4011iGS+RM
Replies: 7
Views: 1037

Re: MikroTik RB4011iGS+RM

1476: -20 IP -4 GRE
After rethinking it, i stand corrected: @xvo is right, the correct value is 1476 (GRE Interface MTU)
by jbl42
Mon Sep 06, 2021 8:41 pm
Forum: General
Topic: MikroTik RB4011iGS+RM
Replies: 7
Views: 1037

Re: MikroTik RB4011iGS+RM

First thing I would recommend is to check is the MTU of the GRE Interface(s). MTU mismatches can cause repacketing ouf outgoing GRE traffic substancialy incerasing the CPU load. If I remember right the MTU for GRE IPv4 interfaces should be 1436 1.436 byte (payload) + 20 byte (TCP header) + 20 byte (...
by jbl42
Mon Aug 23, 2021 9:34 pm
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78220

Re: v7.1rc1 [development] is released!

*) added bridge HW offload support for vlan-filtering on RTL8367 switch chip (RB4011, RB1100AHx4); RB4011 and RB1100AHx4 have more than one RTL8367 chip (one for ports 1-5 and 6-10 on RB4011). HW acceleration for VLAN filtering is obviously only possible on ether ports on the same chip. Question is...