Community discussions

MikroTik App

Search found 964 matches

by DarkNate
Wed Dec 06, 2023 7:59 pm
Forum: Forwarding Protocols
Topic: Status of ROS V7 for BGP, MPLS, VPLS
Replies: 12
Views: 1189

Re: Status of ROS V7 for BGP, MPLS, VPLS

I am pretty sure it's just a case of "Good things take time" rather than any decision not to support them. Explain to me, how Cumulus, SONiC, OcNOS supports hardware offloading for most of this stuff in 2023 and MikroTik (a company that started in 1996), doesn't? Heck MikroTik's own (pote...
by DarkNate
Wed Dec 06, 2023 7:56 pm
Forum: Forwarding Protocols
Topic: Status of ROS V7 for BGP, MPLS, VPLS
Replies: 12
Views: 1189

Re: Status of ROS V7 for BGP, MPLS, VPLS

Hate to tell you, but your "inside source" is not trustworthy. Ha, what inside source? The last company, I'd want an “inside source” from is MikroTik. I was poking sarcasm at the obvious fact that MikroTik ROSv7 has been a mess, and you're all very slow in bringing the hardware offloading...
by DarkNate
Wed Dec 06, 2023 8:27 am
Forum: Forwarding Protocols
Topic: Status of ROS V7 for BGP, MPLS, VPLS
Replies: 12
Views: 1189

Re: Status of ROS V7 for BGP, MPLS, VPLS

There is no hardware MPLS support in RouterOS v7 at this point.
It's strange, isn't it? The Marvell ASICs that MikroTik uses supports MPLS/VXLAN/EVPN in hardware, but MikroTik decided it was a terrible idea to support these three on the ASICs.
by DarkNate
Mon Nov 20, 2023 2:53 pm
Forum: General
Topic: Vlan/MPLS/VPLS issue V7 ?
Replies: 4
Views: 607

Re: Vlan/MPLS/VPLS issue V7 ?

Right... I have it working in test environment... but there's something (netonix, ubnt, xyz, ...) that's killing the MTU :D I'll have to dig :? P.S. I hope my MTU values are not wrong (1530 for MPLS, 1508 VPLS and I think it's 1600 for the ethernet ... I left VLAN at 1500?) Refer to this: https://f...
by DarkNate
Mon Nov 20, 2023 2:51 pm
Forum: General
Topic: Anyone use LibreNMS?
Replies: 6
Views: 1418

Re: Anyone use LibreNMS?

Hi Nate! What would proper CI/CD look like for a small-ish network, 50-200 devices? The reason I ask is I've struggled with using Ansible—since the extent of ansible "support" is a single CLI wrapper command and you're basically just doing ROS scripting—and like you mention Oxidized seems...
by DarkNate
Fri Nov 17, 2023 9:30 am
Forum: General
Topic: CCR2216 have terrible IO performances, very much worst than CCR10xx! Maybe they have no DMA?
Replies: 31
Views: 1948

Re: CCR2216 have terrible IO performances, very much worst than CCR10xx! Maybe they have no DMA?

This is because in the case of TILE CPU, a lot of operations are done differently. When some tasks have to be divided to many CPU cores, packet loss and out of order packets can occur. The ARM CPU is smarter in this regard, there is a lot more processing done, so that this does not happen. I think ...
by DarkNate
Fri Nov 17, 2023 9:28 am
Forum: General
Topic: CCR2216 have terrible IO performances, very much worst than CCR10xx! Maybe they have no DMA?
Replies: 31
Views: 1948

Re: CCR2216 have terrible IO performances, very much worst than CCR10xx! Maybe they have no DMA?

We are not saying that there is nothing to improve. Software can always be improved. That is a never-ending story for any software, not just RouterOS. But comparing different architectures and drivers simply is not fair. They each have their pros and cons. Normis, I have one question. Why not just ...
by DarkNate
Fri Nov 17, 2023 8:34 am
Forum: General
Topic: CCR2216 have terrible IO performances, very much worst than CCR10xx! Maybe they have no DMA?
Replies: 31
Views: 1948

Re: CCR2216 have terrible IO performances, very much worst than CCR10xx! Maybe they have no DMA?

DarkNate, what's the point of your answer? 1)So if you need or want to use MPLS you have to buy Juniper? And why not Cisco or Huawei or other brands? This is a fanboy position... 2)Is this the game of who's got the longest? 3)Another time you propose a software as solution to all problems... 4)I ca...
by DarkNate
Fri Nov 17, 2023 8:26 am
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 69822

Re: v7.13beta [testing] is released!

WinBox in RouterOS is not just the winbox.exe. WinBox is a protocol that you use to transport RouterOS data from router to application, which includes winbox.exe, mobile applications and tne Dude. WinBox GUI should also match CLI 1:1. Example, why is “Services” (for API, SSH, SNMP etc) inside IPv4 ...
by DarkNate
Fri Nov 17, 2023 8:22 am
Forum: Forwarding Protocols
Topic: Does MTU on LOOPBACK matter?
Replies: 4
Views: 432

Re: Does MTU on LOOPBACK matter?

Yes, it matters. I mean, wireless paths, technically, can do 9k MTU for layer 2 if the vendor supports, like some units from Ubiquiti. But the point is, layer 2 MTU should always be MAXED out on ALL Devices, even if it's different between them. Layer 3 MTU needs to be designed in a way that it ensur...
by DarkNate
Wed Nov 15, 2023 5:45 pm
Forum: General
Topic: CCR2216 have terrible IO performances, very much worst than CCR10xx! Maybe they have no DMA?
Replies: 31
Views: 1948

Re: CCR2216 have terrible IO performances, very much worst than CCR10xx! Maybe they have no DMA?

The problem is NOT the single bridge, we know it. The problem is that Mikrotik has not yet implemented handling of MPLS in HW. We are not talking of "user" router. As we said, there can be many problems: we have more than 500.000 connection, much more than can be handled in HW. Some kind ...
by DarkNate
Wed Nov 15, 2023 10:54 am
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 69822

Re: v7.13beta [testing] is released!

Why is that? I'm running carrier grade NAT on some 2216's for customers and was looking into either the nat-ein or nat-pmp to try to get customers gaming setups happy with NAT types. Just trying to find a way to not get a double NAT for gaming consoles without having to give every customer a public...
by DarkNate
Wed Nov 15, 2023 10:42 am
Forum: General
Topic: CCR2216 have terrible IO performances, very much worst than CCR10xx! Maybe they have no DMA?
Replies: 31
Views: 1948

Re: CCR2216 have terrible IO performances, very much worst than CCR10xx! Maybe they have no DMA?

I don't get the fascination of having two or three beefy routers do everything for the whole network. To me that's a really bad single point of failure. Use each type of router for the things it does best, or design the network around the limitations of each. OP, clearly never read this: https://st...
by DarkNate
Wed Nov 15, 2023 10:41 am
Forum: General
Topic: CCR2216 have terrible IO performances, very much worst than CCR10xx! Maybe they have no DMA?
Replies: 31
Views: 1948

Re: CCR2216 have terrible IO performances, very much worst than CCR10xx! Maybe they have no DMA?

As we already said, we CANNOT use L3HW here: it uses MPLS/VPLS! And there are other cases where L3HW cannot be used: queues, complicate filtering and NAT, etc... Single bridge for MPLS/VPLS with VLAN filtering and segregation using PVID. Read the link I shared and then read MikroTik official docs. ...
by DarkNate
Tue Nov 14, 2023 3:34 pm
Forum: General
Topic: CCR2216 have terrible IO performances, very much worst than CCR10xx! Maybe they have no DMA?
Replies: 31
Views: 1948

Re: CCR2216 have terrible IO performances, very much worst than CCR10xx! Maybe they have no DMA?

100% sure this user failed to properly configure L3 offloading, single bridge config approach with VLAN segregation. So traffic is going via control plane instead of the data plane (ASIC). https://forum.mikrotik.com/viewtopic.php?p=1031313#p1031313 @normis if you read this, I think it's high-time Mi...
by DarkNate
Tue Nov 14, 2023 3:31 pm
Forum: General
Topic: Vlan/MPLS/VPLS issue V7 ?
Replies: 4
Views: 607

Re: Vlan/MPLS/VPLS issue V7 ?

I deploy jumbo frames even on wireless equipment. As long as L2 MTU and L3 is configured correctly across the various paths in the network, there's no issue.

Different wireless equipment have different MTU support, check with the vendor.
by DarkNate
Tue Nov 14, 2023 3:24 pm
Forum: Announcements
Topic: v7.12.1 [stable] is released!
Replies: 243
Views: 63944

Re: v7.12 [stable] is released!

MikroTik's software quality is a very bad joke. Guys should go back to the first chapters of any good book on software engineering. It looks like in the past their software was written by the old timers and then the "young, dynamic, from big cities, who think they know better" came on boa...
by DarkNate
Mon Nov 13, 2023 7:09 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 69822

Re: v7.13beta [testing] is released!

*) firewall - added "nat-pmp" support;
Why? NAT-PMP was already obsoleted by RFC6887. It would've made more sense to implement PCP, which is also usable in 464xlat, NAT64 and MAP-T.
by DarkNate
Mon Nov 13, 2023 7:05 pm
Forum: Announcements
Topic: v7.12.1 [stable] is released!
Replies: 243
Views: 63944

Re: v7.12 [stable] is released!

Of course he did not read what I wrote. I wrote "It is best to update the firmware once after purchase of the device" so you won't have ancient firmware. Bullshit. Buy a device today, netinstall with latest ROS and firmware. Now one year later, ROS version has changed 15 generations and f...
by DarkNate
Mon Nov 13, 2023 4:11 pm
Forum: Announcements
Topic: v7.12.1 [stable] is released!
Replies: 243
Views: 63944

Re: v7.12 [stable] is released!

It really isn't a good idea (anymore) to set automatic firmware upgrade. The reason is that the firmware version now changes every time, it is the same as the RouterOS version. But usually there is no update at all in the firmware. Update just does nothing, but it incurs a small risk of rendering t...
by DarkNate
Sat Nov 11, 2023 8:28 am
Forum: Beginner Basics
Topic: IPv6 Configuration under Router OS 7
Replies: 39
Views: 2329

Re: IPv6 Configuration under Router OS 7

I think it is a mistake to apply techniques developed for business-on-budget applications to prosumer cases which my firewall is for.
Disagree. We route to blackhole even on expensive high-end Juniper MXes and PTXes.
by DarkNate
Fri Nov 10, 2023 9:46 am
Forum: Beginner Basics
Topic: IPv6 Configuration under Router OS 7
Replies: 39
Views: 2329

Re: IPv6 Configuration under Router OS 7

But if I were to nitpick I would criticize blanket drop and blackhole rules: local hosts deserve rejection with appropriate ICMP errors. Note that linked RFCs advocate similarly. That it’s not trivial to configure RouterOS like this is whole other matter. This opens a door for DDoS/DoS of the contr...
by DarkNate
Fri Nov 10, 2023 4:38 am
Forum: Beginner Basics
Topic: IPv6 Configuration under Router OS 7
Replies: 39
Views: 2329

Re: IPv6 Configuration under Router OS 7

@Kentzo your approach has duplicity and redundant config, for example with your “trap”. Why would you increase computation costs? Use Route-To-Blackhole directly. In addition, the content in the article is backed by various RFCs and BCPs and BCOPs, all hyperlinked widely across the article if you bo...
by DarkNate
Thu Nov 09, 2023 6:35 am
Forum: Beginner Basics
Topic: IPv6 Configuration under Router OS 7
Replies: 39
Views: 2329

Re: IPv6 Configuration under Router OS 7

I actually disabled all the other rules as well. Is there a base ruleset I should be using? The implicit drop at the bottom is disabled as well.
viewtopic.php?t=176358#p864371
by DarkNate
Tue Nov 07, 2023 2:25 pm
Forum: Scripting
Topic: Auto Fail over BGP Peers and ports
Replies: 6
Views: 553

Re: Auto Fail over BGP Peers and ports

Or even better, BFD. It was made for this purpose.
When is really ready and works...
Works fine on v7.11.2. No problems here for months/weeks now. Even cross-vendor.
by DarkNate
Tue Nov 07, 2023 12:51 pm
Forum: Scripting
Topic: Auto Fail over BGP Peers and ports
Replies: 6
Views: 553

Re: Auto Fail over BGP Peers and ports

Very few people are really qualified to work with dynamic routing protocols. Maybe MikroTik should make more in-depth content on these.
by DarkNate
Mon Nov 06, 2023 4:58 am
Forum: General
Topic: loud balance 3 starlink
Replies: 19
Views: 1383

Re: loud balance 3 starlink

I thought he's talking about cooling system load distribution or something with “loud balance”… Fans are loud for sure.
by DarkNate
Sun Nov 05, 2023 10:10 am
Forum: Forwarding Protocols
Topic: RPKI & BGP: Is it computationally expensive to set comments on BGP routes?
Replies: 4
Views: 609

Re: RPKI & BGP: Is it computationally expensive to set comments on BGP routes?

Yes, it's obviously computationally expensive. Who the hell else even does this?
by DarkNate
Sat Nov 04, 2023 5:10 pm
Forum: Beginner Basics
Topic: NAT Typ D - Nintendo Switch
Replies: 11
Views: 1040

Re: NAT Typ D - Nintendo Switch

The chances of school or college “network engineers” deploying proper CGNAT with netmap/EIM-NAT is not slim, it is null/non-existent. I've been through college too, and our PhD certified “engineers” ran like 7 layers of NAT before it reached the Dormitory. Best you can do is Cloudflare WARP free pla...
by DarkNate
Sat Nov 04, 2023 5:08 pm
Forum: Forwarding Protocols
Topic: MPLS-TP
Replies: 11
Views: 2579

Re: MPLS-TP

I don't work for a Tier 1 Carrier so I don't know. Yes, Ciena seems to offer it as a high-SLA metro-service concept I guess MPLS-TP makes sense for transport gear. Not networking gear. As it's 100% transport related tech and less of networking/packet switching. MikroTik doesn't sell transport gear,...
by DarkNate
Sat Nov 04, 2023 7:57 am
Forum: General
Topic: Anyone use LibreNMS?
Replies: 6
Views: 1418

Re: Anyone use LibreNMS?

I've used LibreNMS in a large network. No problems with Cisco, Juniper, Arista, MikroTik.

For proper automation, you'd likely need a proper CI/CD pipeline for network-wide and infra-wide automation. Oxidised is there, but it isn't exactly a CI/CD pipeline company-wide.
by DarkNate
Sat Nov 04, 2023 7:55 am
Forum: Beginner Basics
Topic: NAT Typ D - Nintendo Switch
Replies: 11
Views: 1040

Re: NAT Typ D - Nintendo Switch

Use netmap + EIM-NAT on your home MikroTik router and make sure you APs etc are in bridge mode to avoid double/triple NAT.
by DarkNate
Sat Nov 04, 2023 7:51 am
Forum: Forwarding Protocols
Topic: MPLS-TP
Replies: 11
Views: 2579

Re: MPLS-TP

No, it's mainly used for specialized industries like utilities, industrial, military and so on. When were are often talking Megabits but needs to be very reliable and ultra-fast recovery scenarios. But It could be used as a transport for legacy services on a bigger carrier operator. EVPN and MPLS-T...
by DarkNate
Fri Nov 03, 2023 5:38 pm
Forum: Forwarding Protocols
Topic: MPLS-TP
Replies: 11
Views: 2579

Re: MPLS-TP

MPLS-TP is not legacy, but its a niche market.
How small is the market for this? What are some modern-day use-cases for it in carrier networks? I just can't think of any because of EVPN.
by DarkNate
Thu Nov 02, 2023 7:12 pm
Forum: Forwarding Protocols
Topic: MPLS/TE CSPF 7.12rc4
Replies: 1
Views: 395

Re: MPLS/TE CSPF 7.12rc4

Share config example on both sides.
by DarkNate
Thu Nov 02, 2023 7:09 pm
Forum: Forwarding Protocols
Topic: MPLS-TP
Replies: 11
Views: 2579

Re: MPLS-TP

Well, It's often used as a replacement for legacy TDM-like tech, transporting synchronous and latency sensitive applications. Then safe to say MPLS-TP is also legacy. A lot of carriers have removed TDM/SDH/SONET type equipment and replaced with modern-day OTN. Even LTE/5G doesn't use TDM. There's n...
by DarkNate
Tue Oct 31, 2023 10:23 pm
Forum: Forwarding Protocols
Topic: MPLS-TP
Replies: 11
Views: 2579

Re: MPLS-TP

MPLS-TP is a very different concept. It often requires and specialized hardware and provisioning concepts to make any sense of it.
What's the market share of MPLS-TP anyway? I have not seen it in production.
by DarkNate
Tue Oct 31, 2023 10:22 pm
Forum: Forwarding Protocols
Topic: Is it possible to filter specific routes by using NSSA or Stub areas? [SOLVED]
Replies: 11
Views: 1717

Re: Is it possible to filter specific routes by using NSSA or Stub areas? [SOLVED]

I think I might have gotten confused during your follow-up explanation. You mentioned that there are already ISP uplinks at the OFCINA router which are using BGP. Where is the part in which you are moving from static routing to OSPF? Do you have an ISP providing transport for the internal connectio...
by DarkNate
Tue Oct 31, 2023 12:50 pm
Forum: Forwarding Protocols
Topic: BGP between ver 7 and 6
Replies: 4
Views: 812

Re: BGP between ver 7 and 6

Upgrade to ROS v7.11.2 on all devices and move on with your life.
by DarkNate
Tue Oct 31, 2023 11:48 am
Forum: Forwarding Protocols
Topic: Is it possible to filter specific routes by using NSSA or Stub areas? [SOLVED]
Replies: 11
Views: 1717

Re: Is it possible to filter specific routes by using NSSA or Stub areas? [SOLVED]

One more thing do you think is it actually worth implement OSPF in the network with that quantity of routers even if every router knows about each other and does not filter routes like the want it? I've designed a lot of ISP networks using eBGP/iBGP in conjunction with OSPF/is-is. This is what I do...
by DarkNate
Mon Oct 30, 2023 10:21 am
Forum: Forwarding Protocols
Topic: IS-IS
Replies: 120
Views: 45319

Re: IS-IS

If I have to wait to 7.14, 7.16 for a IPv4 is-is implementation.
is-is is not TCP/IP, it's CLNP. Why would it require IPv4 or IPv6 addressing to function?
by DarkNate
Mon Oct 30, 2023 9:14 am
Forum: Forwarding Protocols
Topic: Is it possible to filter specific routes by using NSSA or Stub areas? [SOLVED]
Replies: 11
Views: 1717

Re: Is it possible to filter specific routes by using NSSA or Stub areas? [SOLVED]

OSPF doesn't scale. Because OSPF is designed to be a fast convergence, link-state protocol. It's not designed to be a policy shaping routing protocol like BGP. There are a few guys out there in the market who builds ISP networks using a combination of eBGP and iBGP inspired by this: https://www.rfc-...
by DarkNate
Mon Oct 30, 2023 7:30 am
Forum: General
Topic: ROUTEROS 7 BGP network announcement issue
Replies: 22
Views: 3688

Re: ROUTEROS 7 BGP network announcement issue

Thanks for your answer. Of course, if I restart the router without even doing what you say, I'll also solve my problem (before the routing table fills up, it will already have sent the default route to clients). But the challenge was not to restart the router(in production) because if next time I h...
by DarkNate
Mon Oct 30, 2023 1:09 am
Forum: General
Topic: ROUTEROS 7 BGP network announcement issue
Replies: 22
Views: 3688

Re: ROUTEROS 7 BGP network announcement issue

DarkNate, In the config you had the Hardware model "CCR1072". I had already watched the video but the person in question only has a few prefixes, above I had said that it worked when there were a few prefixes but I have several million prefixes in production and the behavior is random and...
by DarkNate
Mon Oct 30, 2023 12:33 am
Forum: General
Topic: ROUTEROS 7 BGP network announcement issue
Replies: 22
Views: 3688

Re: ROUTEROS 7 BGP network announcement issue

Hi DarkNate, So what do I actually have to do? The reason I sent in the configuration is so that someone can help me, not reproach me. Tell me exactly what I need to configure. Regards. Share your hardware model number. BGP affinity config is dependent on hardware model. https://www.youtube.com/wat...
by DarkNate
Sun Oct 29, 2023 9:35 pm
Forum: General
Topic: ROUTEROS 7 BGP network announcement issue
Replies: 22
Views: 3688

Re: ROUTEROS 7 BGP network announcement issue

Hi Darknet, Enclosed you'll find a small part of the configuration I consider relevant to your analysis. Client sessions with the "eBGP-INA" template caused me a lot of trouble to announce the default route (random behavior). Where is consistent BGP affinity config on ALL peers? Of course...
by DarkNate
Sun Oct 29, 2023 5:34 am
Forum: General
Topic: ROUTEROS 7 BGP network announcement issue
Replies: 22
Views: 3688

Re: ROUTEROS 7 BGP network announcement issue

If you could give me a BGP session configuration that would 100% announce the default route correctly in a routing table already filled with several million routes, I'd love it.
What you should be doing is exporting your /routing config and post it here for people to review.
by DarkNate
Sat Oct 28, 2023 9:21 pm
Forum: RouterOS beta
Topic: Feature Request : IPv6 Fasttrack
Replies: 168
Views: 45544

Re: Feature Request : IPv6 Fasttrack

I did not say, that OSPF is in any way better than ISIS. It is still a fact, that in enterprise networks OSPF is still in use and scaling got much less an issue with as much resources we have today in any router. So probably current support for routing protocols is no reason for MT to get used more...
by DarkNate
Sat Oct 28, 2023 6:49 pm
Forum: General
Topic: ROUTEROS 7 BGP network announcement issue
Replies: 22
Views: 3688

Re: ROUTEROS 7 BGP network announcement issue

Hi all, I have a version of ROS 7.11.2 and I have huge difficulties to send the default-originate to the client routers. Sometimes it works and sometimes it doesn't (most of the time). I've also noticed that when I have almost nothing as a prefix in my routing table, the default route is sent immed...
by DarkNate
Sat Oct 28, 2023 6:46 pm
Forum: General
Topic: Case Study: Disabling NAT and Firewall on LAN Routers
Replies: 11
Views: 936

Re: Case Study: Disabling NAT and Firewall on LAN Routers

It will work, but it's a dumb design. Can I design something better? Of course, but nobody would design for free on a forum. I suggest you reach out to any certified MikroTik consultant for a proper design. If you want to self-learn, then a good starting point here: https://study-ccna.com/collapsed-...
by DarkNate
Sat Oct 28, 2023 6:45 pm
Forum: RouterOS beta
Topic: Feature Request : IPv6 Fasttrack
Replies: 168
Views: 45544

Re: Feature Request : IPv6 Fasttrack

OSPF is a PITA. is-is isn't. OSPF requires operational and configuration overhead when you have 1000 layer 3 devices in a network, to maintain the configuration automation template etc, across IPv4 and IPv6. Whereas with is-is, since it's CLNP, I don't need IP addressing whatsoever for underlay netw...
by DarkNate
Sat Oct 28, 2023 1:09 pm
Forum: Forwarding Protocols
Topic: VPLS fragment reassembly bug only on TILE-arch
Replies: 9
Views: 3702

Re: VPLS fragment reassembly bug only on TILE-arch

I lost any hopes that MPLS related bugs in ROS 7 will be fixed. Started to look for another router brand without success for now. Just use baby jumbo-frames at the least 1600 L2 MTU, 15xx whatever L3 MTU and no fragmentation occurs. But personally, I ensure 9k MTU on L3 and 9216 or more on L2 netwo...
by DarkNate
Sat Oct 28, 2023 11:32 am
Forum: RouterOS beta
Topic: Feature Request : IPv6 Fasttrack
Replies: 168
Views: 45544

Re: Feature Request : IPv6 Fasttrack

If XDP/DPDK is used then x86 is the best choice. XDP does not depend on any special HW: https://www.iovisor.org/technology/xdp All new routerboards have ARM. (OK, there is maybe something I miss, but most of them have ARM.) DPDK: Designed to run on Arm, PowerPC and x86 processors, DPDK runs mostly ...
by DarkNate
Sat Oct 28, 2023 11:30 am
Forum: RouterOS beta
Topic: Feature Request : IPv6 Fasttrack
Replies: 168
Views: 45544

Re: Feature Request : IPv6 Fasttrack

If XDP/DPDK is used then x86 is the best choice. Clearly, you have never spoken with Linux kernel programmers and system programmers to even understand what is XDP or DPDK, and how it is being deployed in the Telecom and data centre industry on all kinds of hardware architectures, ranging from x64 ...
by DarkNate
Sun Oct 22, 2023 2:06 am
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 89333

Re: mDNS repeater feature

I contacted support about this issue and they responded that they will consider improving the behavior for VPLS when they are added to the bridge and VLANs are used. I would like to remove VPLS permanently and replace it with EVPN and make use of Ethernet Segment Identifiers, but alas, MikroTik sup...
by DarkNate
Fri Oct 20, 2023 5:33 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 89333

Re: mDNS repeater feature

Indeed, the single-bridge design cannot be used in conjunction with BGP VPLS ( https://forum.mikrotik.com/viewtopic.php?p=925249#p925249 ). MikroTik needs to give proper solution for this. Maybe contact support? What about option two here: https://forum.mikrotik.com/viewtopic.php?p=925249#p845362
by DarkNate
Fri Oct 20, 2023 4:24 pm
Forum: General
Topic: CCR2116 disappointing can't do >2gbps PPPOE, single CPU >95%
Replies: 3
Views: 717

Re: CCR2116 disappointing can't do >2gbps PPPOE, single CPU >95%

Misconfiguration of bridge/VLAN/L3 offloading is the likely cause, too many Linux DSA expert users in this forum: https://forum.mikrotik.com/viewtopic.php?p=1025418#p1026101 Some common examples: https://help.mikrotik.com/docs/display/ROS/Layer2+misconfiguration If the above don't apply to you, then...
by DarkNate
Thu Oct 19, 2023 5:48 pm
Forum: Forwarding Protocols
Topic: PIM in OS7
Replies: 2
Views: 1960

Re: PIM in OS7

Your configuration is likely the problem.

See here, PIM works okay for me, inter-VLAN.

viewtopic.php?p=1029268#p1022915
by DarkNate
Thu Oct 19, 2023 5:45 pm
Forum: General
Topic: RFC 9234 implementation status: Roles, but no OTC!?
Replies: 2
Views: 534

Re: RFC 9234 implementation status: Roles, but no OTC!?

MikroTik RFC9234 is only partial implementation, not full implementation. Check with support.

Meanwhile, Cisco and Juniper don't support it anywhere.
by DarkNate
Wed Oct 18, 2023 8:08 pm
Forum: Scripting
Topic: For ISP: How to ***really*** block invalid ICMP, TCP, UDP packets and others (ver. 2021)
Replies: 21
Views: 67914

Re: For ISP: How to ***really*** block invalid ICMP, TCP, UDP packets and others (ver. 2021)

Yes, but is clearly indicated: Warning: this two rules can break the Path MTU Discovery (PMTUD), use only if your device are sensible to "Large ICMP" or "Ping of Death" attack. On doubt, do not use at all!!! 3) Thanks, added on future update. ICMP Completely removed, to avoid pr...
by DarkNate
Wed Oct 18, 2023 7:32 pm
Forum: General
Topic: CPU Issue when enabling RPKI
Replies: 6
Views: 1069

Re: CPU Issue when enabling RPKI

Thanks for your reply. Unfortunately, the technical article refers to VLANs or ports in bridge mode. On my MikroTik RBs, there are no VLANs or bridges. There are only two network interfaces: one connected to the IXP switch and the other to the our switch, in access mode and not VLAN, connected to o...
by DarkNate
Wed Oct 18, 2023 7:28 pm
Forum: Scripting
Topic: For ISP: How to ***really*** block invalid ICMP, TCP, UDP packets and others (ver. 2021)
Replies: 21
Views: 67914

Re: For ISP: How to ***really*** block invalid ICMP, TCP, UDP packets and others (ver. 2021)

I was hoping rextended removed the ICMP stuff, which is a bad idea to deploy in prod or even for home users. 1. ICMP is rate limited in RouterOS by default, and same on all network vendor OSes, same on Linux vanilla kernel as well 2. Breaks PMTUD and is just stupid, I've seen large-scale networks do...
by DarkNate
Wed Oct 18, 2023 1:19 pm
Forum: General
Topic: "ipv6 address from-pool" lost after reboot
Replies: 9
Views: 882

Re: "ipv6 address from-pool" lost after reboot

Mobile carriers limiting us to ::/64 per SIM card is only one example. So I'd like to stop this discussion here and come back to the question I asked. That's not the problem at all. The issue here is, you aren't aggregating your ULA into a single pool. The mobile carrier's /64, you can just use NAT...
by DarkNate
Wed Oct 18, 2023 12:34 pm
Forum: General
Topic: "ipv6 address from-pool" lost after reboot
Replies: 9
Views: 882

Re: "ipv6 address from-pool" lost after reboot

Using a single pool is not an option here. We have a few thousand devices and each has it's own fd10:x:y:z::/64 prefix. In certain environments, we need an additional network that we can advertise to hosts, and this can't be in the fd10::/16 range. This sounds like a problematic approach, IMO. I'd ...
by DarkNate
Wed Oct 18, 2023 12:21 pm
Forum: General
Topic: "ipv6 address from-pool" lost after reboot
Replies: 9
Views: 882

Re: "ipv6 address from-pool" lost after reboot

Have a single aggregated pool of the entire /56 or whatever, then use the ::1, ::2... On each different VLAN/Interface, that should work fine.
by DarkNate
Wed Oct 18, 2023 1:22 am
Forum: RouterOS beta
Topic: Feature Request : IPv6 Fasttrack
Replies: 168
Views: 45544

Re: Feature Request : IPv6 Fasttrack

@DarkNate: Replace XDP by VPP and keep DPDK, please! Or use all of them! :)) VyOs just transitioned from XDP to VPP and many other projects use it, to support >10G speeds. https://wiki.fd.io/view/VPP/What_is_VPP%3F Still, something should have already be done by MT about IPv6 performance! DPDK/VPP ...
by DarkNate
Tue Oct 17, 2023 8:26 pm
Forum: Forwarding Protocols
Topic: ROS 7.11 OSPF PTP Unnumbered
Replies: 3
Views: 1768

Re: ROS 7.11 OSPF PTP Unnumbered

Unnumbered OSPF or BGP for that matter, does not work on RouterOS, not even on 7.11.2
by DarkNate
Tue Oct 17, 2023 5:58 pm
Forum: Useful user articles
Topic: How to: Edge router and BNG optimization for ISPs Topic is solved
Replies: 53
Views: 84302

Re: How to: Edge router and BNG optimization for ISPs Topic is solved

Speaking of IPv6, it seems the author published one article on it. Definitely not MikroTik specific, so might make more sense to just comment it here instead:
https://www.daryllswer.com/ipv6-archite ... operators/
by DarkNate
Tue Oct 17, 2023 5:56 pm
Forum: Beginner Basics
Topic: L3 Hardware offloading in Mikrotik
Replies: 2
Views: 647

Re: L3 Hardware offloading in Mikrotik

Configure as per your hardware model:
https://help.mikrotik.com/docs/display/ ... +switching
by DarkNate
Tue Oct 17, 2023 5:55 pm
Forum: RouterOS beta
Topic: Feature Request : IPv6 Fasttrack
Replies: 168
Views: 45544

Re: Feature Request : IPv6 Fasttrack

MikroTik should just adopt XDP with hardware offloading to the NIC for packet filtering. To Adopt DPDK (or its derivatives) for packet forwarding, a lot of MikroTik boxes would be able to forward 100Gbps at near line-rate using CPU alone with XDP + DPDK.
by DarkNate
Tue Oct 17, 2023 5:53 pm
Forum: General
Topic: CPU Issue when enabling RPKI
Replies: 6
Views: 1069

Re: CPU Issue when enabling RPKI

Fix your BGP affinity as step 1.

Then make sure your L3 offloading, bridge/VLAN configuration is matching this:
https://help.mikrotik.com/docs/display/ ... +switching
by DarkNate
Tue Oct 17, 2023 5:52 pm
Forum: RouterOS beta
Topic: Feature Request - NAT64/DNS64 CGN
Replies: 27
Views: 20012

Re: Feature Request - NAT64/DNS64 CGN

The problem with this is, it does not scale, not usable for production pumping 100Gbps traffic per nanosecond. MikroTik needs to add proper CLAT, proper 464xlat and NAT64.
by DarkNate
Mon Oct 16, 2023 8:27 pm
Forum: Forwarding Protocols
Topic: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow
Replies: 16
Views: 1748

Re: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow

there is journey remaining towards full ROA compliance
Don't confuse ROA data and ROV data. Even if ROA data is 100% compliance, it is useless if there's no ROV implementation.
by DarkNate
Mon Oct 16, 2023 8:13 pm
Forum: Forwarding Protocols
Topic: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow
Replies: 16
Views: 1748

Re: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow

@DarkNate As far as I know at least in our region (Asia), ROA record is a _must_ now a days if you are advertising your prefix to upstream that's why pe1chl is suggesting that let the upstream handle this RPKI validation, I personally has this mentality too are we really out of touch on reality? Al...
by DarkNate
Mon Oct 16, 2023 6:09 pm
Forum: Forwarding Protocols
Topic: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow
Replies: 16
Views: 1748

Re: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow

I have a few questions regarding the ESXi host and the CHR VM: What CPU is used? Intel Xeon E5-2620? Intel Xeon Gold 5415+? AMD EPYC 7302? Are the vCPU on the same Socket? (think NUMA and accessing RAM from different CPU socket) What setting are you using for the CPU/MMU virtualization? Which physi...
by DarkNate
Mon Oct 16, 2023 6:07 pm
Forum: Forwarding Protocols
Topic: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow
Replies: 16
Views: 1748

Re: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow

i am pretty sure there is a way to give the technical message without going into personal affairs
Nothing personal, at all, from my POV. Strictly business here. And as far as “technical message”, that's what MANRS is for.
by DarkNate
Mon Oct 16, 2023 4:52 pm
Forum: Forwarding Protocols
Topic: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow
Replies: 16
Views: 1748

Re: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow

I don't think you can/should do RPKI validation on a single-peer endpoint. Leave that to your upstream ISP. They can do all the route selection for you and send you only a default route. Are you new to network operations and NOG forums? Do you even know what MANRS is? Very few Tier 1s, Tier 2s and ...
by DarkNate
Sun Oct 15, 2023 1:22 am
Forum: Forwarding Protocols
Topic: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow
Replies: 16
Views: 1748

Re: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow

I don't see how any of that would be an advantage when having only one peer. It's abundantly clear you don't understand how RPKI validation/filtering works and why we should all implemented it. You are under the impression that you need to be multi-homed for RPKI validation to work. Start here: htt...
by DarkNate
Sat Oct 14, 2023 8:05 pm
Forum: General
Topic: Mikrotik SUCKS
Replies: 82
Views: 9699

Re: Mikrotik SUCKS

For example - The VLAN concept used by Cisco is something everyone understands and is widley copied everywhere, and its the same on all devices regardless of underlaying chipsets. However in Mikrotik, it's both very chipset dependent, and you can do wrong in multiple ways both in hardware bridge an...
by DarkNate
Sat Oct 14, 2023 4:02 pm
Forum: General
Topic: Mikrotik SUCKS
Replies: 82
Views: 9699

Re: Mikrotik SUCKS

RouterOS can be, very confusing if you are very in to like Cisco/Juniper for since many years. It also can be very confusning if you are a DIY Linux/OpenWRT person and are looking for files to edit. One "drawback" is that you can accomplish things in different ways, with pros and cons. Th...
by DarkNate
Sat Oct 14, 2023 3:54 pm
Forum: Scripting
Topic: Script to update RouterOS after X days of release
Replies: 44
Views: 4277

Re: Script to update RouterOS after X days of release

Rather than some "script" based in RouterOS itself, something like this calls for real network automation. Use Ansible or something similar, or custom python code that runs on a seperate box.
by DarkNate
Sat Oct 14, 2023 3:49 pm
Forum: Forwarding Protocols
Topic: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow
Replies: 16
Views: 1748

Re: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow

BGP can run multithreaded (see posting above), but when you have only 1 peer there is nothing to gain that way. Is this only a test? Or else, why would you run full-table BGP with only 1 peer? Ask the ISP to send you only a default route... Full table with one peer (or more) ensures this network ca...
by DarkNate
Tue Oct 10, 2023 4:56 pm
Forum: Wireless Networking
Topic: Mikrotik hAP AX3 very bad Wi-Fi performance and coverage
Replies: 31
Views: 4493

Re: Mikrotik hAP AX3 very bad Wi-Fi performance and coverage

And for hAP ax³, why would sticks rotate around second axis, if it's doughnut shape?
Exactly. I don't know how to properly align the antennas on hAP ax3, MikroTik made sure to keep this a secret for reasons I cannot understand.
by DarkNate
Mon Oct 09, 2023 10:06 pm
Forum: Wireless Networking
Topic: Mikrotik hAP AX3 very bad Wi-Fi performance and coverage
Replies: 31
Views: 4493

Re: Mikrotik hAP AX3 very bad Wi-Fi performance and coverage

Not really my expertise but one can assume those antennas on AX3 provide a doughnut shaped radiation pattern perpendicular to the axis of the antenna. For AX2 I think it will be more spherical. Measurement data (from certification ??) might be helpful indeed. I don't know, but a crystal clear docum...
by DarkNate
Mon Oct 09, 2023 10:01 pm
Forum: Wireless Networking
Topic: Mikrotik hAP AX3 very bad Wi-Fi performance and coverage
Replies: 31
Views: 4493

Re: Mikrotik hAP AX3 very bad Wi-Fi performance and coverage

I didn't check the configuration details of OP. But I have a hAP ax2 and hAP ax3, identical config, but ax3 has wireless coverage and performance issues. Maybe it's the way I aligned the antennas or what? Possibly MikroTik can share antenna guide for this model, the blueprints of how the rotational ...
by DarkNate
Mon Oct 09, 2023 9:57 pm
Forum: General
Topic: Why are there no production-grade L3 switches from MikroTik in 2023?
Replies: 26
Views: 3047

Re: Why are there no production-grade L3 switches from MikroTik in 2023?

Translation = F*** I'm Good, Just Ask Me !
Translation = I don't need praise from people in this forum. Money doesn't reach my bank account from here. Some people have appreciated my comments in this forum, some have not, doesn't matter to me either way.
by DarkNate
Sun Oct 08, 2023 2:08 pm
Forum: Beginner Basics
Topic: Cross VLAN Multicast / PIM Config
Replies: 26
Views: 4721

Re: Cross VLAN Multicast / PIM Config

I have a CCR<>ax2 setup, where ax2 is a layer 2 devices only. I never actually see PIM packets on my Wi-Fi clients for some reason, it seems wifiwave2 blocks PIM packets? I am not sure, but the MDB table is properly populated so not sure what's going on. I check with WireShark on client side. I see ...
by DarkNate
Thu Oct 05, 2023 9:08 pm
Forum: Beginner Basics
Topic: Cross VLAN Multicast / PIM Config
Replies: 26
Views: 4721

Re: Cross VLAN Multicast / PIM Config

It is a temporary setup. I'll will set VLANs on the same bridge when I buy another VLAN-capable device to plug to ether 3 (GUEST now) which is going to be set as a trunk port so that I can have multiple VLANs on the new device. You only need to configure access port based VLAN for your current setu...
by DarkNate
Thu Oct 05, 2023 3:55 pm
Forum: Beginner Basics
Topic: Cross VLAN Multicast / PIM Config
Replies: 26
Views: 4721

Re: Cross VLAN Multicast / PIM Config

The IGMP/MLD snooping can be set only for ports on the same bridge, which it doesn't seem to be my case.
You are not supposed to be using multiple bridges, read this:
viewtopic.php?p=1026098#p1026101
by DarkNate
Thu Oct 05, 2023 1:48 pm
Forum: Beginner Basics
Topic: Cross VLAN Multicast / PIM Config
Replies: 26
Views: 4721

Re: Cross VLAN Multicast / PIM Config

I set 3 interfaces in bridge (my main LAN), set also services on it. On another interface I set a different subnet for GUEST. Would your setup work for DLNA discovery too? A device on the GUEST subnet needs to contact a service running on the LAN side. Unfortunately I can't set up VLANs at the mome...
by DarkNate
Mon Oct 02, 2023 9:03 pm
Forum: General
Topic: Why are there no production-grade L3 switches from MikroTik in 2023?
Replies: 26
Views: 3047

Re: Why are there no production-grade L3 switches from MikroTik in 2023?

<rant> Dude, these ad hominem attacks have got to stop . They add absolutely zero value to the conversation, and every disparaging remark you make completely erases any clout or respect you might have earned when sharing your expertise or opinion. I came to this thread expecting to see what users h...
by DarkNate
Mon Oct 02, 2023 11:18 am
Forum: General
Topic: Why are there no production-grade L3 switches from MikroTik in 2023?
Replies: 26
Views: 3047

Re: Why are there no production-grade L3 switches from MikroTik in 2023?

was not sarcasm maybe sometimes the rude tone i perceive on your words is only the result of the translation. but i found your position not very thoughtful neither constructive Yeah, like I care about what some random dude on the internet thinks about it. You can think what you want, we're never cr...
by DarkNate
Sat Sep 30, 2023 12:35 pm
Forum: Forwarding Protocols
Topic: radvd invalid mtu log spam
Replies: 4
Views: 857

Re: radvd invalid mtu log spam

Example from hAP ax3 core router deployment: /ipv6 firewall raw add action=drop chain=prerouting icmp-options=134:0-255 in-interface=vlanIX protocol=icmpv6 Neighbor Discovery packets received from upstream router are dropped. This doesn't solve the issue at scale, the RAs still flood the wire, stil...
by DarkNate
Fri Sep 29, 2023 1:18 pm
Forum: General
Topic: Why are there no production-grade L3 switches from MikroTik in 2023?
Replies: 26
Views: 3047

Re: Why are there no production-grade L3 switches from MikroTik in 2023?

On the other hand - you really can't buy a Nexus or QFX without a pricey support agreement (except for second hand)
Fair argument. MikroTik can sell reasonably priced support agreement. 1/2 the price of Cisco or Juniper.
by DarkNate
Fri Sep 29, 2023 12:19 pm
Forum: Beginner Basics
Topic: Is client isolation worth it? How much does it increase security?
Replies: 3
Views: 714

Re: Is client isolation worth it? How much does it increase security?

For SOHO/Home? I think having VLAN Segregation is sufficient, because each VLAN will have a unique IPv4 and IPv6 subnet, which helps with firewall ACLs, custom policy routing, NAT logging etc. I don't do anything special personally for SOHO/Home, plain VLANs and segregated IPv4/IPv6 subnets and I'm ...
by DarkNate
Fri Sep 29, 2023 12:11 pm
Forum: Forwarding Protocols
Topic: radvd invalid mtu log spam
Replies: 4
Views: 857

Re: radvd invalid mtu log spam

You should contact IXP support and register a ticket. It's against IXP rules to flood RAs. Someone recently posted about it here.
by DarkNate
Fri Sep 29, 2023 12:10 pm
Forum: General
Topic: Why are there no production-grade L3 switches from MikroTik in 2023?
Replies: 26
Views: 3047

Re: Why are there no production-grade L3 switches from MikroTik in 2023?

Even if they made the hardware, the lack of paid software support would limit the market for MikroTik. No serious operator is going to run hardware with no realistic prospect of a fix in a timely manner. I think this is the real issue. Even if MikroTik made a REAL L3 switching box, say a box costs ...
by DarkNate
Thu Sep 28, 2023 11:36 am
Forum: General
Topic: [Question] Does Mikrotik support DOH over IPv6?
Replies: 2
Views: 794

Re: [Question] Does Mikrotik support DOH over IPv6?

IPv6-only DNS on MikroTik has never worked correctly for me.
by DarkNate
Thu Sep 28, 2023 11:32 am
Forum: General
Topic: Mikrotik SUCKS
Replies: 82
Views: 9699

Re: Mikrotik SUCKS

I had no problem setting up my first Mikrotik in 2016 when they barely had any youtube tutorials and I was only taught basic networking for one semester. Every time I see IT """engineer""" I remember that old error "We seem to have encountered some issue but our t...
by DarkNate
Thu Sep 28, 2023 11:26 am
Forum: General
Topic: Why are there no production-grade L3 switches from MikroTik in 2023?
Replies: 26
Views: 3047

Re: Why are there no production-grade L3 switches from MikroTik in 2023?

Some of these would come for free as they can be done in software on the existing hardware, but others such as a larger TCAM come at a cost.
Many people are willing to pay that cost, though, is the point. A MikroTik box won't cost me $400k.
by DarkNate
Thu Sep 28, 2023 11:25 am
Forum: General
Topic: Why are there no production-grade L3 switches from MikroTik in 2023?
Replies: 26
Views: 3047

Re: Why are there no production-grade L3 switches from MikroTik in 2023?

if you see that as an easy task then you are missing a good opportunity, raise some capital and startup your idea i will be expecting that equipment built by your startup to revolutionize the market You have the knowledge and the opportunity so go for it Clearly this is sarcasm, not sure who's fall...
by DarkNate
Thu Sep 28, 2023 11:24 am
Forum: General
Topic: Why are there no production-grade L3 switches from MikroTik in 2023?
Replies: 26
Views: 3047

Re: Why are there no production-grade L3 switches from MikroTik in 2023?

How does a CCR2116 or CCR2216 not achieve what you want. L3 offload on all of the newer Tiks is pretty simple. If the input and output ports both have L3 offload enabled, and it can be routed statelessly, it can be offloaded. Doesn't really matter if it's MPLS, BGP, etc... configuring those routes....
by DarkNate
Tue Sep 26, 2023 11:57 am
Forum: General
Topic: Why are there no production-grade L3 switches from MikroTik in 2023?
Replies: 26
Views: 3047

Re: Why are there no production-grade L3 switches from MikroTik in 2023?

Can you make a business case for a production-grade L3 switch ? If you could make that BC [at a high level] then I suspect that might tweek Tik interetest :D ... Although I do suspect that they already have such BC and have decided that its not worth the investment. Do you have any idea whatsoever ...
by DarkNate
Tue Sep 26, 2023 9:52 am
Forum: General
Topic: Why are there no production-grade L3 switches from MikroTik in 2023?
Replies: 26
Views: 3047

Re: Why are there no production-grade L3 switches from MikroTik in 2023?

You do realize that your question, since asked in an user forum, is more or less a rhetorical one? You're asking about MT's business plans and that question really should be directed towards MT's marketing department directly, ideally backed up by a large past business and prospect of huge future b...
by DarkNate
Tue Sep 26, 2023 6:29 am
Forum: General
Topic: Why are there no production-grade L3 switches from MikroTik in 2023?
Replies: 26
Views: 3047

Why are there no production-grade L3 switches from MikroTik in 2023?

I am writing this post to urge MikroTik to consider producing high-performance, production-grade Layer 3 switches. While MikroTik has somewhat capable Layer 2 switches, its Layer 3 switching capabilities are next to nil. Layer 3 switching has been the de-facto standard in data centres for use-cases ...
by DarkNate
Sat Sep 23, 2023 2:53 pm
Forum: Forwarding Protocols
Topic: v7.10rc1 delayed bgp anouncements?
Replies: 17
Views: 1888

Re: v7.10rc1 delayed bgp anouncements?

Mate, some could find you not only an expert in networking but also in arrogance ... could you stay at networking?
I'm no expert, I'm just educated and literate is all.
by DarkNate
Sat Sep 23, 2023 2:52 pm
Forum: Forwarding Protocols
Topic: v7.10rc1 delayed bgp anouncements?
Replies: 17
Views: 1888

Re: v7.10rc1 delayed bgp anouncements?

work like a charm with BGP :-)
Good luck, have fun.
by DarkNate
Sat Sep 23, 2023 12:53 pm
Forum: Forwarding Protocols
Topic: v7.10rc1 delayed bgp anouncements?
Replies: 17
Views: 1888

Re: v7.10rc1 delayed bgp anouncements?

Hmmmm.... firmware to 1:1 between peers or current-firmware: upgrade-firmware ?
Are you sure you're an engineer, mate? This fundamental stuff in MikroTik.

Obviously current-firmware must match ROS version aka "upgrad-firmware".
by DarkNate
Fri Sep 22, 2023 12:15 pm
Forum: General
Topic: Should moderators redact sensitive info, and how much?
Replies: 49
Views: 2685

Re: Should moderators redact sensitive info, and how much?

Some LLM-based script in the backend could automate that job, auto-scrub passwords, MACs, usernames etc.
by DarkNate
Wed Sep 20, 2023 2:10 pm
Forum: General
Topic: Mikrotik SUCKS
Replies: 82
Views: 9699

Re: Mikrotik SUCKS

My networks work well now, but I think I got it at least a 100 times wrong. Read posts on the forum, read MT wikis, watched videos. Of course many guides and videos are obsolete, some posts are wrong. As an MT beginner it is an exceptionally big hurdle to get things sorted out and to find and under...
by DarkNate
Wed Sep 20, 2023 2:07 pm
Forum: General
Topic: Mikrotik SUCKS
Replies: 82
Views: 9699

Re: Mikrotik SUCKS

Why would de CLI need to have anything to do with your automation? The CLI is for human consumption, the automation isn't. Nobody's talking about automation in that particular context. I clearly replied to this comment by quoting it. I think you're smoking something. They should have copied Cisco's...
by DarkNate
Tue Sep 19, 2023 7:55 pm
Forum: Scripting
Topic: Update firewall list possible?
Replies: 4
Views: 694

Re: Update firewall list possible?

MikroTik firewall address lists, resolves, and updates the FQDNs by default, why do you need a script for a feature that's built-in?

Just enter the DNS hostname in the list and that's it.
by DarkNate
Tue Sep 19, 2023 5:46 pm
Forum: General
Topic: double NAT--> VoIP issues
Replies: 1
Views: 312

Re: double NAT--> VoIP issues

You need to deploy CGNAT correctly on the ISP side, see this:
viewtopic.php?t=176358
by DarkNate
Tue Sep 19, 2023 5:43 pm
Forum: General
Topic: Mikrotik SUCKS
Replies: 82
Views: 9699

Re: Mikrotik SUCKS

I agree. Switching on ROS is not intuitive at all. But still, having the necessary background and with little RTFM you can work your way through. They should have copied Cisco's way of doing switching (in terms of UI/UX/CLI). Much more intuitive and easier to troubleshoot. Hell no, f*ck Cisco CLI a...
by DarkNate
Tue Sep 19, 2023 1:23 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 89333

Re: mDNS repeater feature

I really wouldn't worry about it, if there is a valid use case (practical management is absolutely a viable one) then by all means use multiple bridges. If its just a home based setup with multiple VLAN's sure single bridge is a good idea. However as with everything it depends on the use case. Ofte...
by DarkNate
Tue Sep 19, 2023 1:15 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 89333

Re: mDNS repeater feature

sorry, off-topic but ... an additional empty bridge "Lo0" for example would not violate that, right? (for loopback addressing) Loopback is fine, I have single bridge for physical ports/LACP/The works, and separate bridge with STP disabled for loopback. But in some cases, such as MPLS/VPLS...
by DarkNate
Mon Sep 18, 2023 1:24 am
Forum: General
Topic: Mikrotik SUCKS
Replies: 82
Views: 9699

Re: Mikrotik SUCKS

Most network engineers understand the technology/theory and can navigate easily between different vendors' implementations to achieve the same results. If it takes you days to set up a VLAN, then most likely you are not well-versed with the technology you are trying to use. Just because on other ve...
by DarkNate
Sat Sep 16, 2023 11:31 pm
Forum: RouterBOARD hardware
Topic: Webpage with firmware upgrade changelog
Replies: 3
Views: 1172

Re: Webpage with firmware upgrade changelog

MikroTik removed firmware changelog (not ROS changelog) years ago, no idea why.
by DarkNate
Sat Sep 16, 2023 11:26 pm
Forum: General
Topic: Mikrotik SUCKS
Replies: 82
Views: 9699

Re: Mikrotik SUCKS

The author is clearly a man-child.

I have my problems with MikroTik, but I have a problem with Cisco, Juniper, Arista as well. No vendor is perfect.

As a network engineer, I work multivendor on per use-case and business-case basis. Good luck to the OP.
by DarkNate
Sat Sep 16, 2023 12:17 pm
Forum: Forwarding Protocols
Topic: Routing between bridges on Mikrotik
Replies: 6
Views: 1332

Re: Routing between bridges on Mikrotik

Seriously, why tf are people still doing this dumb double/triple/multiple bridges crap on modern-day Linux DSA? Have they not received basic education and training in Linux networking or something?
by DarkNate
Sat Sep 16, 2023 12:16 pm
Forum: Forwarding Protocols
Topic: v7.10rc1 delayed bgp anouncements?
Replies: 17
Views: 1888

Re: v7.10rc1 delayed bgp anouncements?

That step is optional 😜 Who told you that? It in fact broke SFP interfaces in the past if you failed to ensure 1:1 matching. Just because MikroTik stopped publishing RouterBOARD firmware changelogs years ago, it doesn't mean there's none. I've worked with many ISPs and WISPs globally who complains ...
by DarkNate
Sat Sep 16, 2023 11:34 am
Forum: Forwarding Protocols
Topic: v7.10rc1 delayed bgp anouncements?
Replies: 17
Views: 1888

Re: v7.10rc1 delayed bgp anouncements?

Make sure you did it right:
/system routerboard settings
set auto-upgrade=yes

/system/routerboard> print
routerboard: yes
factory-firmware: 6.45.9
current-firmware: 7.11.2
upgrade-firmware: 7.11.2
by DarkNate
Sat Sep 16, 2023 11:31 am
Forum: General
Topic: a highly sophisticated and persistent DDoS attack. [SOLVED]
Replies: 13
Views: 1237

Re: a highly sophisticated and persistent DDoS attack. [SOLVED]

How's this a network vendor problem?

If you're a network operator, sign up for a DDoS scrubbing provider, if you're a customer of an ISP, ask your ISP to do it.
by DarkNate
Fri Sep 15, 2023 10:44 am
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 89333

Re: mDNS repeater feature

I've been testing with a lab router using a more appropriate config for the actual environments i'd want to use this in, which is a more complicated topology that isn't just VLAN's on a single bridge. You're violating the Linux DSA network stack by having multiple bridges. Multiple bridges is a con...
by DarkNate
Thu Sep 14, 2023 1:20 pm
Forum: Forwarding Protocols
Topic: v7.10rc1 delayed bgp anouncements?
Replies: 17
Views: 1888

Re: v7.10rc1 delayed bgp anouncements?

Ensuring proper BGP affinity input/output on all BGP peers based on this:
https://www.youtube.com/watch?v=py4up-l ... FmZmluaXR5

No problem with BGP advertisement on ROS v7.11.2.
by DarkNate
Thu Sep 14, 2023 1:17 pm
Forum: General
Topic: IPv6 - router1 pingable from PC, not pingable router2
Replies: 3
Views: 702

Re: IPv6 - router1 pingable from PC, not pingable router2

Export /ipv6 config from both routers. This is likely misconfig.
by DarkNate
Thu Sep 14, 2023 1:16 pm
Forum: Forwarding Protocols
Topic: v7.10rc1 delayed bgp anouncements?
Replies: 17
Views: 1888

Re: v7.10rc1 delayed bgp anouncements?

Why the hell are you using v7.10rc1 in the first place? Move to latest stable or latest beta.
by DarkNate
Thu Sep 14, 2023 1:15 pm
Forum: Forwarding Protocols
Topic: PIM in ROSv7 on CRS3xx
Replies: 3
Views: 1466

Re: PIM in ROSv7 on CRS3xx

Might be worth mentioning that PIM-SM isn't listed as functional in the Routing Protocol Overview page. Status is "initial support" https://help.mikrotik.com/docs/display/ROS/Routing+Protocol+Overview It is working with this config, but perhaps not ready for production at scale: https://f...
by DarkNate
Wed Sep 13, 2023 9:32 am
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 89333

Re: mDNS repeater feature

I suspect @DarkNate is right here... I think IGMP Proxy may ignore mDNS's IP 224.0.0.51/24 since defined as "Local Network Control Block" in RFC-5771 It's ironic that PIM is easier, but there be less complex than the ill-defined IGMP Proxy.... IGMP Proxy was never really a “best practices...
by DarkNate
Mon Sep 11, 2023 8:42 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 151116

Re: v7.11, 7.11.1 and more [stable] are released!

... and then there are (probably) thousands of us using RouterOS on dozens of devices from home applications to medium size enterprises and did not encounter any serious issue for years, so we are perfectly fine with calling it "stable" :) RouterOS has so many features, most of the interc...
by DarkNate
Mon Sep 11, 2023 8:39 pm
Forum: General
Topic: About parameter frame-types in bridge
Replies: 7
Views: 1177

Re: About parameter frame-types in bridge

Bridging in ROS is no different from bridging in Debian, RHEL, Cumulus etc. It's Linux DSA. I never get these half-baked explanations on the forums when it comes to Linux networking, which is what ROS is, a Linux-based CLI daemon that abstracts underlay Linux Kernel with ROS v6/v7 CLI/UI configurati...
by DarkNate
Mon Sep 11, 2023 9:39 am
Forum: General
Topic: iOs 16 constantly dropping from hotspot
Replies: 13
Views: 2976

Re: iOs 16 constantly dropping from hotspot

Normis I like you and MT but that`s not true...android phones don`t disconnect from the AP if display is off. How can we got msgs from Viber, Whatsapp, Messnger...etc during the all day? My phone has over 1h uptime in my AP (Ax2) now and his display is black most of the time. 99% of modern day Andr...
by DarkNate
Mon Sep 11, 2023 9:19 am
Forum: Beginner Basics
Topic: L009UiGS cloud change time
Replies: 3
Views: 990

Re: L009UiGS cloud change time

@OP use this:
/system ntp client
set enabled=yes
/system ntp client servers
add address=time.cloudflare.com
by DarkNate
Mon Sep 11, 2023 9:18 am
Forum: Announcements
Topic: Newsletter #114 | September 2023
Replies: 72
Views: 10656

Re: Newsletter #114 | September 2023

We already have this https://mikrotik.com/product/crs312_4c_8xg_rm CPU specs worry me about using this as a layer 3 access switch (or perhaps distribution switch in smaller networks) for running a few thousand/ten thousand BGP routes/OSPF and in future if MikroTik supports VXLAN with EVPN or MPLS/E...
by DarkNate
Mon Sep 11, 2023 9:06 am
Forum: Announcements
Topic: Newsletter #114 | September 2023
Replies: 72
Views: 10656

Re: Newsletter #114 | September 2023

Can you guys clarify the use case of 2.5G ports but with PoE output? I thought this kind of switch was great for high end PC's, not for plugging in more routers? What's the cost difference between 2.5GbE and 10GbE ports (with optional PoE)? I'd really like to see SOHO equipment moving to minimum 10...
by DarkNate
Mon Sep 11, 2023 9:02 am
Forum: Virtualization
Topic: RouterOS CHR 7.11 Wifiwave2 Training
Replies: 4
Views: 2321

Re: RouterOS CHR 7.11 Wifiwave2 Training

hAP ax2 is sufficient for training purposes.
by DarkNate
Mon Sep 11, 2023 9:00 am
Forum: General
Topic: iOs 16 constantly dropping from hotspot
Replies: 13
Views: 2976

Re: iOs 16 constantly dropping from hotspot

all phones have power saving options and go to sleep if display is off. yes, wifi also disconnects. what did you expect? I have a few old iPhones running iOS 16, if battery was 100%, and I leave it unplugged and screen turned off, no apps running, I've seen uptime upto 8 hours on MikroTik AP's regi...
by DarkNate
Mon Sep 11, 2023 3:48 am
Forum: Wireless Networking
Topic: Multiple hap ax2 issues...
Replies: 47
Views: 4513

Re: Multiple hap ax2 issues...

Auto works fine. This is my conf. /interface wifiwave2 set [ find default-name=wifi2 ] channel.band=2ghz-ax .skip-dfs-channels=disabled configuration.chains=0,1 .country=Mars .mode=ap .ssid=1234 .tx-chains=0,1 disabled=no name=2GHz_1 security=VLAN666_Security set [ find default-name=wifi1 ] channel....
by DarkNate
Sun Sep 10, 2023 10:30 pm
Forum: General
Topic: About parameter frame-types in bridge
Replies: 7
Views: 1177

Re: About parameter frame-types in bridge

It's a long explanation that's better explained by a few sources below. In short, this is a feature of modern day VLAN-aware bridging using DSA in Linux networking stack. It allows you to ensure the bridge itself will accept only tagged to prevent possible VLAN leaks due to misconfig and to block na...
by DarkNate
Sun Sep 10, 2023 10:25 pm
Forum: Beginner Basics
Topic: Should I upgrade RouterBOOT on each RouterOS upgrade?
Replies: 8
Views: 1956

Re: Should I upgrade RouterBOOT on each RouterOS upgrade?

I've avoided RouterBOOT firmware problems using this: /system routerboard settings set auto-upgrade=yes Problem solved with double reboots after each ROS upgrade: /system/routerboard> print routerboard: yes factory-firmware: 6.45.9 current-firmware: 7.11.2 upgrade-firmware: 7.11.2 MikroTik should ma...
by DarkNate
Sat Sep 09, 2023 11:28 pm
Forum: Announcements
Topic: MikroTik Devices Controller
Replies: 294
Views: 220856

Re: MikroTik Devices Controller

Before making a big commitment to a new software product; let's get the bread and butter products in order: RouterOS 7 "stable" becomes truly stable ( not just a label ) first and foremost before all else. RouterOS 7 becomes feature complete first and foremost before new software products...
by DarkNate
Sat Sep 09, 2023 3:37 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 151116

Re: v7.11.2 [stable] is released!

I declare 7.11.2 to be long-term release.

Joking obvs. We can keep b**ching in this forum and other forums, but unless MikroTik does something about software stability/quality issues, nothing will change.

They read silently, while we can only hope they are taking actions in the backend.
by DarkNate
Fri Sep 08, 2023 10:18 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 89333

Re: mDNS repeater feature

I stopped using IGMP Proxy. I migrated to PIM, it works and I stopped worrying. You need ROS v7.11.2 in my testing.

Here:
viewtopic.php?t=198798#p1022915
by DarkNate
Wed Sep 06, 2023 3:36 am
Forum: General
Topic: ROSv7, IPv6, Multicast, IGMP snooping & VLAN's [SOLVED]
Replies: 2
Views: 1139

Re: ROSv7, IPv6, Multicast, IGMP snooping & VLAN's [SOLVED]

The bridge configuration is missing some config params: /interface bridge add frame-types=admit-only-vlan-tagged igmp-snooping=yes igmp-version=3 mld-version=2 name=bridge Also remove the VID from /interface bridge mdb , the static MDB entry is to be configured VLAN-neutral aka no VLAN, see official...
by DarkNate
Sun Sep 03, 2023 8:01 am
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 151116

Re: v7.11, 7.11.1 and more [stable] are released!

If ain't broke, don't fix it.
This is an anti-innovation mindset, usually smells of USSR and fascist regimes' origin.

If it ain't broke, improve it, re-architect if needed, re-test and re-validate. That's how network engineering or any branch of engineering should be.
by DarkNate
Sat Sep 02, 2023 3:11 am
Forum: Beginner Basics
Topic: Cross VLAN Multicast / PIM Config
Replies: 26
Views: 4721

Re: Cross VLAN Multicast / PIM Config

I did a netinstall of v7.11.2. PIM seems to be working with early testing. Config example for people: /routing pimsm instance add afi=ipv4 disabled=no name=pimsm-IPv4 vrf=main add afi=ipv6 disabled=no name=pimsm-IPv6 vrf=main /routing pimsm interface-template add disabled=no instance=pimsm-IPv4 inte...
by DarkNate
Sat Sep 02, 2023 2:47 am
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 151116

Re: v7.11, 7.11.1 and more [stable] are released!

Let's be clear about where the insanity lays. MikroTik has laid down a consistent track record; they are not an enterprise vendor. Everyone sets their expectation; repeatedly expecting enterprise results from MikroTik is insane. Marry the enterprise vendor that provides what you really want, whatev...
by DarkNate
Fri Sep 01, 2023 10:07 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 151116

Re: v7.11 and 7.11.1 [stable] are released!

= /interface wireless do not exist on wifiwave2 Do not worry, is the same error on defconf I report a year ago the 2022-05-04 17:10:00.... Some spam lines inside the file get-custom-defconf , never removed. Too many lazy programmers to fix something reported dozen of times, with precise indication ...
by DarkNate
Thu Aug 31, 2023 8:45 pm
Forum: General
Topic: ⚠️Security Issue: Changing rights / disable / delete the users has no effect on already logged in users.
Replies: 35
Views: 4742

Re: ⚠️Security Issue: Changing rights / disable / delete the users has no effect on already logged in users.

I've seen this on MikroTik, but what about other vendors?

Plain Debian, or whatever or any big vendor. Do they proactively kill user session upon deletion immediately?
by DarkNate
Thu Aug 31, 2023 8:34 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 151116

Re: v7.11 and 7.11.1 [stable] are released!

After upgrading from v7.11 to v7.11.1 my hAP ax2 throws this error
"error while running customized default configuration script no such item"
by DarkNate
Sun Aug 27, 2023 2:40 am
Forum: Wireless Networking
Topic: WiFi with Apple Products
Replies: 63
Views: 18261

Re: WiFi with Apple Products

Are people still going on about this? Your config export clearly shows you failed to configure the “country” for both bands. Configure the country for both bands to the actual country you bought the iPhones from, reboot the AP.
by DarkNate
Sat Aug 26, 2023 12:44 am
Forum: General
Topic: RouterOS Bridge not forwarding MacSEC
Replies: 3
Views: 1042

Re: RouterOS Bridge not forwarding MacSEC

Why do people still mess up their VLAN/Bridge configuration on MikroTik even though the process is identical on all Linux based NOSes? Read this: https://help.mikrotik.com/docs/display/ROS/Basic+VLAN+switching#BasicVLANswitching-CRS3xx,CRS5xxseriesswitches,CCR2116,CCR2216andRTL8367,88E6393X,88E6191X...
by DarkNate
Wed Aug 23, 2023 7:53 pm
Forum: General
Topic: Mikrotik website about ipv6 throughput?
Replies: 47
Views: 3980

Re: Mikrotik website about ipv6 throughput?

Nobody actually requires XDP or DPDK or VPP or any other acronym.
Yeah keep telling yourself that, good luck, have fun.

https://thebrotherswisp.com/index.php/t ... -hardware/
by DarkNate
Wed Aug 23, 2023 7:30 pm
Forum: General
Topic: New RouterOS theme
Replies: 21
Views: 3299

Re: New RouterOS theme

I'm with patrick7 ; WebFig is valuable and constraining display width in HTML is counter productive. MirkiTik requiring yet another tool like "WinBox" or "The Dude" is unnecessary and not universally wanted. What did MikroTik accomplish besides imposing someone's unwanted concep...
by DarkNate
Wed Aug 23, 2023 12:28 pm
Forum: General
Topic: Mikrotik website about ipv6 throughput?
Replies: 47
Views: 3980

Re: Mikrotik website about ipv6 throughput?

From the results I've seen posted, it's impressive what can be achieved with DPDK/VPP. The VyOS project has replaced the use of XDP with VPP for the data plane. DPDK/VPP and hardware-offloaded XDP can filter/drop/process packets at 100Gbps on commodity hardware including arm64 . I know Fortune 500 ...
by DarkNate
Tue Aug 22, 2023 7:40 pm
Forum: General
Topic: Mikrotik website about ipv6 throughput?
Replies: 47
Views: 3980

Re: Mikrotik website about ipv6 throughput?

On my "modern" router (RB4011), routing IPv6 at 1Gb/s make 1 core being like 95% used. So it's fine for my use case. But it also means it can't do much more, while the router is advertised with a 10Gb/s SFP+ port and a 10Gb/s routing capability... RB4011 was not released in 2022-2023 (mod...
by DarkNate
Tue Aug 22, 2023 7:37 pm
Forum: Beginner Basics
Topic: Cross VLAN Multicast / PIM Config
Replies: 26
Views: 4721

Re: Cross VLAN Multicast / PIM Config

Is this sill the case? I did a lot PIM-routing stuff around 2018/2019 with ROSv6 and it worked really good. Cant believe they still werent able to fix an alredy good working (in v6) feature... It's not working on latest ROS v7.11 stable at least. And MikroTik did not provide PIM config documentatio...
by DarkNate
Tue Aug 22, 2023 11:56 am
Forum: General
Topic: New RouterOS theme
Replies: 21
Views: 3299

Re: New RouterOS theme

The problem with bug reporting on MikroTik is the lack of enterprise SLA and we, your customers, know for a fact, bug reports sit idle on the helpdesk for months, you can find many instances of such examples on MikroTik forums. This means in simple English, there's little to no incentives for custom...
by DarkNate
Tue Aug 22, 2023 11:51 am
Forum: General
Topic: New RouterOS theme
Replies: 21
Views: 3299

Re: New RouterOS theme

@normis I use Linux, Windows 11 and macOS. WINE is “good enough” to run the executable on macOS, but there are UI/UX bugs and glitches especially on Apple Silicon. The experience on WINE vs native Windows 11 for Winbox is just different. In face WINE stopped working on macOS Ventura for a few months...
by DarkNate
Tue Aug 22, 2023 11:27 am
Forum: Beginner Basics
Topic: Cross VLAN Multicast / PIM Config
Replies: 26
Views: 4721

Re: Cross VLAN Multicast / PIM Config

Again, I'm not saying it can't be done, in contrary, it can be done. But, again, for inexperienced user it's only too easy to miss all the points where it has to be done so it's way easier to use other VIDs if there isn't a very good reason to use VID 1 in tagged traffic. We all started from somewh...
by DarkNate
Mon Aug 21, 2023 5:49 pm
Forum: Beginner Basics
Topic: Cross VLAN Multicast / PIM Config
Replies: 26
Views: 4721

Re: Cross VLAN Multicast / PIM Config

To use VLAN 1 in MT world, one has to speak ROSish quite fluently ... it's not a problem of VID itself, the problem is that it's used in ROS as implicit default all over place and one has to know how to look to see it. And then change it according to needs. Which might be too much of a hassle, thus...
by DarkNate
Mon Aug 21, 2023 1:04 pm
Forum: General
Topic: New RouterOS theme
Replies: 21
Views: 3299

Re: New RouterOS theme

Webfig is just a security attack vector.

Disable it, use Winbox. Ask for Dark mode then on Winbox I guess.
by DarkNate
Mon Aug 21, 2023 1:03 pm
Forum: General
Topic: BGP graceful-restart in ROSv6 or ROSv7 [SOLVED]
Replies: 10
Views: 2128

Re: BGP graceful-restart in ROSv6 or ROSv7 [SOLVED]

I don't think it actually does shit. It doesn't seem to work in my testing.

Best you can do on MikroTik is BFD, with BFD, things should converge pretty fast.
by DarkNate
Mon Aug 21, 2023 12:58 pm
Forum: General
Topic: Mikrotik website about ipv6 throughput?
Replies: 47
Views: 3980

Re: Mikrotik website about ipv6 throughput?

On modern MikroTik hardware (2022-2023), I've never seen a massive difference between IPv4 and IPv6, assuming FastTrack isn't in the discussion.

Especially for CCRs, never seen difference in performance with proper config, hardware offloading, FastPath, bridge config etc.
by DarkNate
Mon Aug 21, 2023 12:56 pm
Forum: Beginner Basics
Topic: Cross VLAN Multicast / PIM Config
Replies: 26
Views: 4721

Re: Cross VLAN Multicast / PIM Config

Dont use vlan1 for data, use any other number VLAN1 does not matter in non-Cisco gear. On Linux aka RouterOS, you just need to ensure bridge ingress filtering to drop untagged “native” VLAN. You can use VLAN 1 just like any other VLAN. I use VLAN1 for MGMT traffic, but you can use it for whatever y...
by DarkNate
Sun Aug 20, 2023 11:24 am
Forum: Beginner Basics
Topic: Cross VLAN Multicast / PIM Config
Replies: 26
Views: 4721

Re: Cross VLAN Multicast / PIM Config

PIM is non-functional on RouterOS v7.

You should contact MikroTik support.
by DarkNate
Fri Aug 18, 2023 5:05 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

I don't know, seems flaky. Anyway, personally I use IPv6 everywhere, I stopped caring about NATs.
by DarkNate
Thu Aug 17, 2023 8:50 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

They need a /tool/nat-detect – I'd rather know the situation, before some gamer is screaming about a test on an XBox. I mean this is open source: https://github.com/HMBSbige/NatTypeTester/ The solution is to patch the source code's bugs, and add support for the remaining RFCs to ensure a wholistic ...
by DarkNate
Thu Aug 17, 2023 7:49 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

The only other tool I know of is Xbox networking app. Run the network tests, it'll show you the correct results.
by DarkNate
Thu Aug 17, 2023 3:36 pm
Forum: General
Topic: Multicast flood with IGMP snooping enabled
Replies: 12
Views: 1516

Re: Multicast flood with IGMP snooping enabled

You need to make use of IGMP/MLD Snooping + IGMP Proxy in simple topologies. Or use PIM in advanced topologies. And single bridge only, or you're done for, that's not a MikroTik thing, that's how Linux DSA is designed, if you don't like it then use Juniper which is FreeBSD based, but even Juniper ha...
by DarkNate
Wed Aug 16, 2023 9:08 pm
Forum: General
Topic: feature request: DHCP lease on option 82 info
Replies: 10
Views: 1512

Re: feature request: DHCP lease on option 82 info

Not that I'm aware of.
If the big vendors don't have it, you can't really expect MikroTik to have it, on priority. Not going to happen anytime soon.
by DarkNate
Wed Aug 16, 2023 1:00 am
Forum: Forwarding Protocols
Topic: BGP High CPU Utilization
Replies: 5
Views: 1437

Re: BGP High CPU Utilization

by DarkNate
Wed Aug 16, 2023 12:59 am
Forum: General
Topic: feature request: DHCP lease on option 82 info
Replies: 10
Views: 1512

Re: feature request: DHCP lease on option 82 info

Do we have something similar to this on Juniper or Cisco for reference?
by DarkNate
Tue Aug 15, 2023 4:04 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

I tested, it's port restricted cone. You're seeing "full cone" if you run it twice with a few seconds, the reason for that is the MikroTik box maintains the state for a few tens of seconds and the remote end-point whose source IP is just the same as previous one, will be able to reach your...
by DarkNate
Sun Aug 13, 2023 11:50 am
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 89333

Re: mDNS repeater feature

I guess I don't understand the extent of what the IGMP Proxy can do for IPv4. Will the proxy forward more than just the IGMP report and query messages? It seems to me that IGMP is used to join/leave the multicast groups for mDNS and SSDP/DIAL, but once joined will the proxy also forward the other n...
by DarkNate
Sat Aug 12, 2023 11:40 pm
Forum: General
Topic: Make ICMP replies from ingress interface
Replies: 12
Views: 2475

Re: Make ICMP replies from ingress interface

Pelchi are you saying external ICMP incoming could potentially go back out the wrong router even if we mark the incoming traffic. If we are using static routes and not BGP, then we SHOULD mark incoming traffic to make sure it egresses via the same interface. So I don't see any problems here at all.
by DarkNate
Sat Aug 12, 2023 11:39 pm
Forum: Forwarding Protocols
Topic: IS-IS
Replies: 120
Views: 45319

Re: IS-IS

Maybe, maximal possible throughput at any cost on x86_64 should *not* be Mikrotiks focus since there are so many alternatives already? What are you talking about? I'm talking about CCR, CRS and RB series, arm64 devices. As for x64, that doesn't matter, if it's ASIC, I clearly gave Cisco as example ...
by DarkNate
Sat Aug 12, 2023 5:11 pm
Forum: General
Topic: Make ICMP replies from ingress interface
Replies: 12
Views: 2475

Re: Make ICMP replies from ingress interface

Strange, when I run traceroutes, I see the expect path in the replies. Am I missing something here? Unless you modified pref-src incorrectly via route filters (for BGP full tables) or manually for static routes/double/triple WAN. I always make sure routes learnt via interface A has pref-src matching...
by DarkNate
Sat Aug 12, 2023 5:08 pm
Forum: General
Topic: My WiFi speed reach half of the bandwidth, how to identify to issue?
Replies: 26
Views: 2009

Re: My WiFi speed reach half of the bandwidth, how to identify to issue?

This happened to me randomly on hAP ax2/ax3, on v7.10.2. Not sure why, after a reboot the bandwidth is back to 1Gbps, but after 30mins it drops to max 500Mbps or so.

No fixes in sight.
by DarkNate
Sat Aug 12, 2023 4:48 pm
Forum: Forwarding Protocols
Topic: IS-IS
Replies: 120
Views: 45319

Re: IS-IS

How easy is it, for example, to rip out the RoS routing stack and inject a new one........ is it a modular thing? Would one then have to redefine all the ICDs between modules...... imagine that many are standard so maybe only modify proprietary items? I don't know. But what I do know is the open so...
by DarkNate
Sat Aug 12, 2023 8:01 am
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 89333

Re: mDNS repeater feature

MikroTik IGMP Proxy doesn't support IPv6 it seems, after further PCAPs myself, meaning it isn't performing MLD Proxying in the process, even though you configure it right. I suggest you talk to MikroTik official support about it. If they make it work with IPv6, then all these problems disappear over...
by DarkNate
Wed Aug 09, 2023 1:45 pm
Forum: Forwarding Protocols
Topic: IS-IS
Replies: 120
Views: 45319

Re: IS-IS

...or implement a .npk package of FRRouting This would just add complexity with ASIC/Hardware offloading. What MikroTik can do is build RouterOS's underlying routing stack and possibly other network functions (like BFD) using FRR's latest base code and possibly fork it if required, or use it as is....
by DarkNate
Wed Aug 09, 2023 1:37 pm
Forum: Useful user articles
Topic: How to: Edge router and BNG optimization for ISPs Topic is solved
Replies: 53
Views: 84302

Re: How to: Edge router and BNG optimization for ISPs Topic is solved

I was hoping he was going to tackle endpoint NAT next. :-)
I don't think it's worth anybody's time, we should all just move to native IPv6 and get it over with.
by DarkNate
Wed Aug 09, 2023 1:33 pm
Forum: General
Topic: NPTv6 (RFC 6296): Connection tracking is broken
Replies: 5
Views: 1010

Re: NPTv6 (RFC 6296): Connection tracking is broken

https://www.spinics.net/lists/netfilter/msg56371.html

I certainly don't want NPTv6 traffic being conn_tracked, the whole purpose of NPTv6 is STATELESS. You can mail in IETF mailing lists to verify this.
by DarkNate
Tue Aug 08, 2023 8:48 am
Forum: General
Topic: NPTv6 (RFC 6296): Connection tracking is broken
Replies: 5
Views: 1010

Re: NPTv6 (RFC 6296): Connection tracking is broken

NPTv6 is meant to be stateless aka no connection tracking. That's the whole point of NPTv6, to avoid breaking layer 4 and avoid the requirements of NAT Traversal helpers. Did you even read RFC6296? Do you not see the word "stateless"? You should be firewalling on the hosts. Let the network...
by DarkNate
Fri Aug 04, 2023 2:15 pm
Forum: Forwarding Protocols
Topic: BGP - Taking Long time to Announce Subnets
Replies: 3
Views: 1642

Re: BGP - Taking Long time to Announce Subnets

This happening on certain RouterOS v7 versions, regardless of hardware model.

For me it happens to IPv6, it takes like 10-20 minutes to advertise my prefixes after a reboot.
by DarkNate
Fri Aug 04, 2023 2:14 pm
Forum: Forwarding Protocols
Topic: BGP ver7.10.2 HELP NEEDED receive only default route from ISP
Replies: 3
Views: 1769

Re: BGP ver7.10.2 HELP NEEDED receive only default route from ISP

Use this instead, simpler arithmetical operation.
if (dst==0.0.0.0/0) {accept} else {reject}
by DarkNate
Fri Aug 04, 2023 11:08 am
Forum: Useful user articles
Topic: How to: Edge router and BNG optimization for ISPs Topic is solved
Replies: 53
Views: 84302

Re: How to: Edge router and BNG optimization for ISPs Topic is solved

Time Bump.

The author is still updating and maintaining the article as of now.
by DarkNate
Fri Aug 04, 2023 11:06 am
Forum: Forwarding Protocols
Topic: BGP v7.10.2 readvertisement of ebgp learned routes to ebgp peers stopped working in v7.10
Replies: 2
Views: 1276

Re: BGP v7.10.2 readvertisement of ebgp learned routes to ebgp peers stopped working in v7.10

What are we supposed to debug with?

Share the config of the routing filters.
by DarkNate
Fri Aug 04, 2023 11:01 am
Forum: General
Topic: Multiple bridge with only one bridge hardware offloaded possible?
Replies: 3
Views: 837

Re: Multiple bridge with only one bridge hardware offloaded possible?

What are you talking about? Loopback bridge is harmless, recommended and a good idea. Why tf do you need “hardware offloading” for loopback bridge? You require SINGLE bridge for physical ports/LACP bonding etc, follow the official MikroTik docs on how to configure bridge VLAN filtering. If you are d...
by DarkNate
Sat Jul 29, 2023 3:51 pm
Forum: RouterOS beta
Topic: IPv6 Prefix ID per IPv6 enabled interface
Replies: 31
Views: 3422

Re: IPv6 Prefix ID per IPv6 enabled interface

My comment was for dynamic allocations from an ISP. @DarkNate I can see that your config will work for a static allocation, but not for a dynamic one. I am using Comcast, so not a small ISP by any means. What are you asking lol, if the PD is dynamic, then it will always change. How's this a RouterO...
by DarkNate
Sat Jul 29, 2023 3:50 pm
Forum: RouterOS beta
Topic: IPv6 Prefix ID per IPv6 enabled interface
Replies: 31
Views: 3422

Re: IPv6 Prefix ID per IPv6 enabled interface

If RouterOS did at all what you claim, that would produce a bad configuration
Ah that's typo lol, I edited the comment.
by DarkNate
Sat Jul 29, 2023 9:45 am
Forum: RouterOS beta
Topic: IPv6 Prefix ID per IPv6 enabled interface
Replies: 31
Views: 3422

Re: IPv6 Prefix ID per IPv6 enabled interface

You're both (or all?) configuring it wrong. ISP gives me /48 STATIC PD. DHCPv6 clients injects static /48 into the pool. I manually configure the /64, by ensuring I manually specify the router's IP on each of the VLANs. So it's like this: /ipv6/address add from-pool=global address= ::1 /64 interface...
by DarkNate
Sat Jul 29, 2023 5:47 am
Forum: RouterOS beta
Topic: IPv6 Prefix ID per IPv6 enabled interface
Replies: 31
Views: 3422

Re: IPv6 Prefix ID per IPv6 enabled interface

but from-pool address assignments do get shuffled and optimized whenever DHCPv6 client renews. Consider adding 3 addresses, then remove the 2nd one and finally renew. You will see RouterOS changing subnetID of the 3rd address to be immediately after the 1st Nope, even when the router REBOOTS, which...
by DarkNate
Sat Jul 29, 2023 4:52 am
Forum: RouterOS beta
Topic: IPv6 Prefix ID per IPv6 enabled interface
Replies: 31
Views: 3422

Re: IPv6 Prefix ID per IPv6 enabled interface

First you're doing bridge VLAN filtering incorrectly, only a single bridge should exist to ensure hardware offloading and bridge fastforrward/fastpath works: https://help.mikrotik.com/docs/display/ROS/Basic+VLAN+switching https://help.mikrotik.com/docs/display/ROS/L3+Hardware+Offloading#L3HardwareOf...
by DarkNate
Sun Jul 23, 2023 4:21 am
Forum: Beginner Basics
Topic: Home invasion
Replies: 18
Views: 3325

Re: Home invasion

You need a GPON ONT SFP module i.e. an ONT (PON device) in the form factor of an SFP, you're welcome.
by DarkNate
Sun Jul 23, 2023 4:15 am
Forum: General
Topic: Mikrotik BNG: Issue IPv6 to clients using DHCP and Radius
Replies: 1
Views: 360

Re: Mikrotik BNG: Issue IPv6 to clients using DHCP and Radius

You can directly use DHCPv6 server, to hand PDs to clients with radius + dual stack queues to tie a RADIUS session for both IPv4 and IPv6 together for each server on a given VLAN. It will work, but MikroTik doesn't support ia_na, not mandatory, but it would be good if they did. IPv4 config, similar ...
by DarkNate
Wed Jul 19, 2023 8:40 am
Forum: General
Topic: TCP Reset Attack Mitigation on Router Level [SOLVED]
Replies: 22
Views: 2077

Re: TCP Reset Attack Mitigation on Router Level [SOLVED]

Please.... It was just a provocative thing, otherwise I wouldn't have continued to write the rest too.... Nah, you just caught lacking. You may have some networking knowledge, you may debate on networking stuff, but it's plain as day you're no lawyer, and I wouldn't be taking legal opinions from you.
by DarkNate
Tue Jul 18, 2023 1:25 pm
Forum: Forwarding Protocols
Topic: URPF rp-filter per interface
Replies: 5
Views: 1653

Re: URPF rp-filter per interface

Strict mode never works in large networks. The proper solution is feasible mode.

You can enable global feasible mode and never need to think again per-interface loose vs strict.

https://datatracker.ietf.org/doc/html/rfc8704
by DarkNate
Tue Jul 18, 2023 1:20 pm
Forum: Scripting
Topic: How to reserve an IPv6 prefix and update NPTv6 firewall rules [SOLVED]
Replies: 5
Views: 1920

Re: How to reserve an IPv6 prefix and update NPTv6 firewall rules [SOLVED]

Not sure what you are trying to achieve, but here's some resource.
by DarkNate
Tue Jul 18, 2023 1:16 pm
Forum: General
Topic: TCP Reset Attack Mitigation on Router Level [SOLVED]
Replies: 22
Views: 2077

Re: TCP Reset Attack Mitigation on Router Level [SOLVED]

I'm surprised (not really) to see the “experts” of this forum not understanding how DPI deployments work in the service provider market space, and how authoritative regimes or malicious ones force the SPs to “Block sites” given on a list, who in turn, go to DPI vendors and buy the middle-boxes for M...
by DarkNate
Tue Jul 18, 2023 1:05 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

Currently, endpoint-independent-nat does solve the NAT1 issue for home gaming consoles, eliminating the need for manual UDP NAT configuration for PS5, Xbox, and Switch. However, enabling it is not recommended for now because it can lead to random kernel failures in versions 7.10.x and 7.11betaX. It...
by DarkNate
Mon Jul 17, 2023 6:43 am
Forum: General
Topic: How do we request for an account deletion?
Replies: 24
Views: 1935

Re: How do we request for an account deletion?

I am waiting for MT to actually fix cone nat or whatever the heck it is, so that DarkNate can be vindicated!! Would hate for him to miss that day. I doubt it'll get fixed. They are more concerned about non-networking features like storage (?) than networking, but that's not the problem here. No deb...
by DarkNate
Sun Jul 16, 2023 10:50 pm
Forum: General
Topic: How do we request for an account deletion?
Replies: 24
Views: 1935

Re: How do we request for an account deletion?

I request the mods of this forum, to delete my account here. I have no use being here. I don't want to hear excuses or debate, delete this account or give me option in control panel to delete it myself.
by DarkNate
Sun Jul 16, 2023 10:12 pm
Forum: RouterBOARD hardware
Topic: Most stable CCR2xxx for BGP
Replies: 22
Views: 3421

Re: Most stable CCR2xxx for BGP

Your post is the perfect example why there SHALL TO BE forum rules written down. It's hard to discuss with your wording ... it's way below my standrd. BTW ... it's not me having "hard time" with you ... there are a lot of moderators. Do what you know, you want to do and disable/ban this a...
by DarkNate
Sun Jul 16, 2023 10:11 pm
Forum: Beginner Basics
Topic: Adaptable IPv6 rules according to prefix?
Replies: 4
Views: 864

Re: Adaptable IPv6 rules according to prefix?

I mean, you can surely allow everything through, but expecting everyone to block stuff on the machine itself? Not really viable IMHO. I have a firewall capable router, I prefer handling blocking traffic at first point TBH. Also, the temporary vs permanent, is kind of odd. On my windows machine, I s...
by DarkNate
Sun Jul 16, 2023 8:57 pm
Forum: RouterOS beta
Topic: vxlan performance?
Replies: 28
Views: 16079

Re: vxlan performance?

DarkNate ... seems that Mikrotik is a guilty pleasure for you .... you hate it but you cannot live without it. If you are so disgusted you can just not read, not comment and leave the forum. Please change your attitude ... please do look on the bright side of administrator life. https://forum.mikro...
by DarkNate
Sun Jul 16, 2023 8:55 pm
Forum: RouterBOARD hardware
Topic: Most stable CCR2xxx for BGP
Replies: 22
Views: 3421

Re: Most stable CCR2xxx for BGP

DarkNate ... please stop complaing again and again and again about quality of ROS, quality of devices, quality of everything what does not meet your level of expectations. If you are so disgusted you can just not read, not comment and leave the forum. Please change your attitude ... please do look ...
by DarkNate
Sun Jul 16, 2023 8:52 pm
Forum: Forwarding Protocols
Topic: IPv6 next-hops for IPv4, how-to?
Replies: 2
Views: 1593

Re: IPv6 next-hops for IPv4, how-to?

It doesn't work on MikroTik for now, using BGP.
by DarkNate
Sun Jul 16, 2023 8:39 pm
Forum: RouterOS beta
Topic: vxlan performance?
Replies: 28
Views: 16079

Re: vxlan performance?

VXLAN on Tik is useless for professional use, as it doesn't support EVPN. Hardware/CPU or not.
by DarkNate
Sun Jul 16, 2023 8:38 pm
Forum: RouterBOARD hardware
Topic: Most stable CCR2xxx for BGP
Replies: 22
Views: 3421

Re: Most stable CCR2xxx for BGP

This seems a curious comment, given that a previous poster commented on having issues with BFD and L3HW. What CCR2xxx are you running, which ROS, how many PPS/Mbps and how long has it been stable? Full tables/BGP works fine on CCR2ks with proper BGP affinity config. However, you are correct, BFD<>L...
by DarkNate
Sun Jul 16, 2023 8:35 pm
Forum: Beginner Basics
Topic: Adaptable IPv6 rules according to prefix?
Replies: 4
Views: 864

Re: Adaptable IPv6 rules according to prefix?

When you use SLAAC, your hosts will get a "permanent" address and a "temporary" one. You allow the traffic on the forward chain towards the "permanent" address, and you also create a DNS record based on the "permanent" address. Allow all traffic, you perform f...
by DarkNate
Sat Jul 15, 2023 9:21 am
Forum: Announcements
Topic: v7.10, 7.10.1 and more [stable] are released!
Replies: 369
Views: 120807

Re: v7.10, 7.10.1 and more [stable] are released!

I do not see anything critical...if you are not able to work around you should not be providing any network.... <edited>? Do you not understand how critical BFD is in production networks? What kind of network engineer are you, to think that BFD is not “critical”? Do some reading here: https://en.wi...
by DarkNate
Sat Jul 15, 2023 3:49 am
Forum: RouterBOARD hardware
Topic: Most stable CCR2xxx for BGP
Replies: 22
Views: 3421

Re: Most stable CCR2xxx for BGP

BGP full tables (multiple) will work fine on CCR2ks as long as you correctly configure BGP affinity and also handle the layer 3 offloading/single bridge configuration stuff.

https://youtu.be/py4up-lO8zY
by DarkNate
Sat Jul 15, 2023 3:42 am
Forum: Announcements
Topic: v7.10, 7.10.1 and more [stable] are released!
Replies: 369
Views: 120807

Re: v7.10, 7.10.1 and more [stable] are released!

You should firstly learn how to proper answer simple question.... I didn't ask for your shity network but WHAT IS NOT WORKING FOR YOU? I will say it again, are you blind? Learn to firstly use your eyes. And clearly, you're just some small-time home user, who thinks he/she knows what they are talkin...
by DarkNate
Fri Jul 14, 2023 6:15 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 255
Views: 40422

Re: MikroTik hAP ax3 poor WiFi performance

Belgium
Italy
2 examples right out of my head.

For Belgium, check site of bipt.be (and it's even in English !!)
Theory, yes. What about practice? Did someone's grandson go to jail for increasing Wi-Fi power output using hAP ax3?
by DarkNate
Fri Jul 14, 2023 6:01 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 255
Views: 40422

Re: MikroTik hAP ax3 poor WiFi performance

Usual disclaimer: it is the user's responsibility to make sure his device is in accordance with local regulations. There are countries were quite heave fines are in place when they catch you. If you decide to go around those restrictions, that's your own responsibility. Having said that... Mikrotik...
by DarkNate
Fri Jul 14, 2023 5:57 pm
Forum: Announcements
Topic: v7.10, 7.10.1 and more [stable] are released!
Replies: 369
Views: 120807

Re: v7.10, 7.10.1 and more [stable] are released!

7.10.2 seems stable to me, what is not working for you? Are you blind? Read this whole thread again, and deploy large scale networks using Juniper, Arista, Huawei like me and come back to me and say “7.10.2 is stable”. Currently working with rural WISPs to secure funding to dump MikroTik and switch...
by DarkNate
Fri Jul 14, 2023 1:37 am
Forum: Announcements
Topic: v7.10, 7.10.1 and more [stable] are released!
Replies: 369
Views: 120807

Re: v7.10, 7.10.1 and more [stable] are released!

wow...this is cool update...we can say 7.10.2 is almost long term release :) I did not know what wifi "stable" ROS to use and now I can use 7.10.2 and 7.11beta4 and I do not know which version to use now :) After few months I can finally use stable version :) Thank you It seems MikroTik d...
by DarkNate
Thu Jul 13, 2023 2:24 am
Forum: Announcements
Topic: v7.10, 7.10.1 and more [stable] are released!
Replies: 369
Views: 120807

Re: v7.10 and 7.10.1 [stable] is released!

So 7.10 introduced BFD but broke OpenVPN, 7.10.1/2 fixed OpenVPN but broke BFD.

Amazing “stability” for production, MikroTik team, just amazing.

So now I'm stuck between choosing BFD over OpenVPN in the network.
by DarkNate
Mon Jul 10, 2023 12:37 am
Forum: Forwarding Protocols
Topic: VXLAN vs MPLS(vpls) MTU and Performance
Replies: 4
Views: 1870

Re: VXLAN vs MPLS(vpls) MTU and Performance

I worked for an org that deployed VXLAN/EVPN underlay for L2 over L3 transport and for providing L2 adjacency over different racks/sites. We used Juniper/Cumulus/Nokia, and we used 9216 L2 MTU and L3 MTU as 9000, network-wide. So we never had MTU problems, all hosts can talk to each other at 9000 MT...
by DarkNate
Sun Jul 02, 2023 1:26 am
Forum: General
Topic: Hide IPv6 host behind router like port forward [SOLVED]
Replies: 13
Views: 1356

Re: Hide IPv6 host behind router like port forward [SOLVED]

When you want to rely on DNS but your delegated IPv6 prefix is unstable, NAT66 is fewer steps if all you want is SSH access to that one machine. For dynamic IPv6 PD. Use NPTv6 instead of NAT66, NPTv6 doesn't break end to end principle and is natively supported on ROSv7. Use a script to update the e...
by DarkNate
Sat Jul 01, 2023 5:51 pm
Forum: General
Topic: Hide IPv6 host behind router like port forward [SOLVED]
Replies: 13
Views: 1356

Re: Hide IPv6 host behind router like port forward [SOLVED]

Why would you break the end-to-end principle, create a network that now needs to rely on STUN/TURN to function in the application layer and defeat the purpose of IPv6 by using NAT66? What you should be doing is plain stateful firewalling, each host/device in the network has a /128 GUA, and it can be...
by DarkNate
Sat Jul 01, 2023 12:51 am
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

I've tested it in my home lab without the dst-address param. No changes visible. I still see port-restricted cone as the end-result. The port is not reachable from ANY, only reachable by peers that have been solicited outbound. I found the issue in your implementation, probably. Whilst the mapping b...
by DarkNate
Fri Jun 30, 2023 4:21 pm
Forum: Wireless Networking
Topic: ax series lineup WiFi issues
Replies: 340
Views: 34908

Re: ax series lineup WiFi issues

I've seen zero disconnections since 7.10 on my ax2. Seems stable to me for the last many days.
by DarkNate
Fri Jun 30, 2023 4:20 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

try to remove dst-address param from rule in dstnat chain. I can't do that, as I have multiple public IPs from “interface list WAN” coming in to the BNG and specifically perform the mapping to specific RFC1918 ranges or 100.64/0 ranges. dst-address param is required for correct mapping. I will try ...
by DarkNate
Fri Jun 30, 2023 2:40 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

If there is indeed deep and long investigation then there should be no problems to create a support ticket and provide that detailed info. A supout file isn't going to give you any special info, the configuration is dead simple, I've shared the sample. I've even shared an OPEN SOURCE tool that test...
by DarkNate
Thu Jun 29, 2023 3:56 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

We implemented exactly what was asked by the OP, who confirmed that feature he asked works. Yet you do not provide any useful info no configuration no setup in which it is not working, nothing, just some screenshot by some tool which shows "moderate", which is completely useless to identi...
by DarkNate
Thu Jun 29, 2023 1:51 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

@pe1chl I hope this situation will be improved in the future, because ROS is not a toy lots of people depends on it every day to deliver what's being advertise, specially in the ISP space this is the part where our management didn't see (hidden cost), In as much as I loved MikroTik for what it's wo...
by DarkNate
Thu Jun 29, 2023 1:49 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

There is no rocket science: Open connection from local client over EIM enabled router to public IP. Then open connection from other public IP to the same port and observe the flow over the router. Flows gets mapped properly and forwarded to correct local client and port. Does not work in my testing...
by DarkNate
Thu Jun 29, 2023 2:27 am
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

In plain and simple English.

On MikroTik, Full-Cone NAT + EIM-NAT does NOT work properly, as of ROSv7.10.

I tested again on a Juniper and Huawei NAT box, and it works fine there, so problem as usual, is MikroTik.
by DarkNate
Thu Jun 29, 2023 2:25 am
Forum: Announcements
Topic: v7.10, 7.10.1 and more [stable] are released!
Replies: 369
Views: 120807

Re: v7.10 [stable] is released!

What does link has to do with your problem? Please post config. On ROSv 7.10 , neither method works. Downgraded to ROSv 7.9.2 and method 2 works fine. #Method 1# add action=endpoint-independent-nat chain=srcnat out-interface-list=WAN protocol=udp randomise-ports=no src-address=192.168.0.0/24 to-add...
by DarkNate
Mon Jun 26, 2023 10:53 pm
Forum: Announcements
Topic: v7.10, 7.10.1 and more [stable] are released!
Replies: 369
Views: 120807

Re: v7.10 [stable] is released!

UDP port forwarding (manual dst-nat/netmap or UPnP or new EIM-NAT) is completely broken on ROSv7.10.

I downgraded to ROSv7.9.2 and it worked fine again.

viewtopic.php?t=165060#p1009730
by DarkNate
Mon Jun 26, 2023 10:50 pm
Forum: Beginner Basics
Topic: radvd invalid MTU
Replies: 9
Views: 3117

Re: radvd invalid MTU

That is your ISP's BNG router. They forgot to suppress IPv6 RAs from their side, and it seems they are using jumbo frames on their side. Which of course won't work for you "9192" as cable modems can't vary that kind of packet size. You can try contacting the ISP and ask them to stop sendin...
by DarkNate
Mon Jun 26, 2023 10:48 pm
Forum: General
Topic: Forum moderation volunteers
Replies: 214
Views: 25328

Re: Forum moderation volunteers

In fact, when I was the moderator they took it out on me, but then things continued the same even when I wasn't anymore, it couldn't have been me... If you know what I mean... Anyway I understand what you're referring to, but it seems to me that lately it has stopped ... It did not stop. My comment...
by DarkNate
Sun Jun 25, 2023 9:41 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

The so called "EIM-NAT" implementation of MikroTik does not work, even on consoles, I still see "moderate" NAT aka port-restricted cone and similar.
Image

We still need manual port forwarding or UPnP.
by DarkNate
Sun Jun 25, 2023 1:46 pm
Forum: Forwarding Protocols
Topic: BGP: filter prefixes based on AS path
Replies: 6
Views: 1885

Re: BGP: filter prefixes based on AS path

You should be using BGP communities + RFC9234 to prevent route leaks. Not via AS-PATH.
by DarkNate
Sun Jun 25, 2023 1:35 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

When using Endpoint-Independent NAT currently, there is a kernel failure after creating a large number of UDP connections.
Lol, what did you expect from MikroTik software quality assurance team? Of course there's kernel failure.
by DarkNate
Fri Jun 23, 2023 9:12 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

There are RFCs for it, but I'm not going to find them all. Here's some more. Point is MikroTik should support both TCP/UDP properly. TCP is easy for them, just permit ANY external IP once SYN has been initiated behind the NAT. https://datatracker.ietf.org/doc/html/rfc7350 https://datatracker.ietf.or...
by DarkNate
Fri Jun 23, 2023 3:25 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

That RFC is specifically for STUN, however that's also ancient. In 2023, STUN servers supports TCP/UDP and any other protocol that you want. TCP NAT punching is a very real thing, that EIM-NAT/Full Cone NAT should fully support: https://datatracker.ietf.org/doc/html/rfc7857#section-2 https://en.wiki...
by DarkNate
Thu Jun 22, 2023 7:20 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

In my test any external IP address can reach the port, I haven't used that testing tool, just directly opened connections.
Please share your testing methodology with us that confirms ANY external IP can reach. And why isn't TCP also supported?
by DarkNate
Wed Jun 21, 2023 7:49 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: full cone NAT
Replies: 278
Views: 31913

Re: FEATURE REQUEST: full cone NAT

Thank you for bringing Endpoint-Independent NAT through RouterOS 7.10.
It allows game consoles to support Full Cone NAT through simple configuration.
It's broken, it's not full-cone, it's port restricted cone with EIM.
viewtopic.php?t=197095#p1008596