Community discussions

MikroTik App

Search found 48 matches

by dmfr
Fri Nov 03, 2023 9:06 pm
Forum: RouterOS beta
Topic: Feature Request : IPv6 Fasttrack
Replies: 177
Views: 52779

Re: Feature Request : IPv6 Fasttrack

Speaking about VyOs, old ER-4 can forward established TCP IPv6 at line speed (gigabit) with less than 2% CPU utilization. Too bad their os is abandonware. Old ER-4, and even older ER-Lite, were using Cavium SDK (proprietary) to offload established connections to hardware (Octeon SoC). It isn't pure...
by dmfr
Thu Jun 01, 2023 5:32 am
Forum: RouterOS beta
Topic: Feature Request : IPv6 Fasttrack
Replies: 177
Views: 52779

Re: Feature Request : IPv6 Fasttrack

Maybe some guys should stop waiting and invest on RB5009, or whatever recent device / vendor capable of +1G I am thinking Mikrotik is moving forward to "detach" true L3HW from (software) fasttrack. That's what happened with IPv6. Whatever the benefits once provided, fasttrack sounds like a...
by dmfr
Thu Nov 24, 2022 5:41 pm
Forum: Announcements
Topic: v7.7beta [testing] is released!
Replies: 322
Views: 125217

Re: v7.7beta [testing] is released!

Hi, just noticed that on 7.7beta8 my DNS conditional forwarding config via REGEX stopped working. Please advice! Facing same regression. add forward-to=10.39.1.51 regexp=".*\\.int\\.mydomain\\.com\$" type=FWD Above rule non functional on beta8. Downgraded to 7.7beta6, dns condtional forwa...
by dmfr
Tue Jun 28, 2022 5:34 pm
Forum: RouterOS beta
Topic: posts not strictly related to: v7.4beta [testing]
Replies: 165
Views: 12837

Re: v7.4beta [testing] is released!

It is difficult for me to trace and debug the issue because there is always a lot of background traffic on my router, and also because I really want to trace the traffic coming out of the switchport, not some internal trace that may be leading me to the wrong path. Right it could be anything from t...
by dmfr
Tue Jun 28, 2022 4:49 pm
Forum: RouterOS beta
Topic: posts not strictly related to: v7.4beta [testing]
Replies: 165
Views: 12837

Re: v7.4beta [testing] is released!

/interface/ethernet/switch/rule add switch=switch1 ports=ether8 new-vlan-priority=6 failure: new-vlan-priority not supported for this switch Please support this on RB5009 (SUP-70924 opened accordingly, jan 2022). Many thanks MikroTik dev team ! Recently opened SUP-85256 to request the same. Besides...
by dmfr
Thu Jun 23, 2022 7:58 pm
Forum: RouterOS beta
Topic: Bridge vlan filter breaks Fasttrack in 7.1rc4 (RB4011/RB5009) [SOLVED]
Replies: 10
Views: 7499

Re: Bridge vlan filter breaks Fasttrack in 7.1rc4 (RB4011/RB5009) [SOLVED]

As of 7.4beta / 7.3.1 : NOT SOLVED On my RB5009 and RB4011 the fasttrack is working since the support for it was introduced back on some v7.1.sth. maybe you have something on your config preventing the fasttrack to work. if you could post your config will be easier... Sure, consider simplest : /inte...
by dmfr
Wed Jun 08, 2022 2:23 pm
Forum: Announcements
Topic: v7.3 and v7.3.1 [stable] is released!
Replies: 269
Views: 81564

Re: v7.3 [stable] is released!

Upgraded one RB5009 to 7.3, no immediate issue, export diff clean.

Edit : had total loss of connectivity some hours after.
Need further check to see if it is related or not.
by dmfr
Sun Apr 10, 2022 7:55 pm
Forum: RouterOS beta
Topic: Bridge vlan filter breaks Fasttrack in 7.1rc4 (RB4011/RB5009) [SOLVED]
Replies: 10
Views: 7499

Re: Bridge vlan filter breaks Fasttrack in 7.1rc4 (RB4011/RB5009) [SOLVED]

Even if there is no vlan filtering, just bridge filter rules, fasttrack doesn't enable on 7.1.x / 7.2 stable, on both RB4011 & RB5009. Well.. it shows enabled (/ip/settings/print), but no packets processed and IPv4 single-thread maxes at 600-700 Mbps on RB4011. Same configuration (bridge filters...
by dmfr
Wed Apr 06, 2022 12:10 pm
Forum: RouterOS beta
Topic: IPIP tunnel perf 7.1.5 vs 7.2rc7
Replies: 3
Views: 2824

Re: IPIP tunnel perf 7.1.5 vs 7.2rc7

We came accross the issue exactly because standard transfers became slower. IPIPv6 tunnel with RB4011 at one end and linux server gateway at the other. Max download speeds : With 7.1.5 : ~ 52 MB/s With 7.2 : ~ 31 MB/s Ipsec encryption or not, it does not make a difference. Seems that downstream inne...
by dmfr
Tue Apr 05, 2022 11:05 pm
Forum: RouterOS beta
Topic: IPIP tunnel perf 7.1.5 vs 7.2rc7
Replies: 3
Views: 2824

Re: IPIP tunnel perf 7.1.5 vs 7.2rc7

Same with 7.2 stable.
Opened ticket SUP-78953
by dmfr
Tue Apr 05, 2022 1:19 am
Forum: RouterOS beta
Topic: IPIP tunnel perf 7.1.5 vs 7.2rc7
Replies: 3
Views: 2824

IPIP tunnel perf 7.1.5 vs 7.2rc7

Hello, Just noticed a severe download speed degradation between 7.1.5 and 7.2rc7 using IPIP tunnel. Tested with RB4011 at both ends, IPIPV6 tunnel, local router running 7.1.5 : tcp-download: 379Mbps local-cpu-load:51% tcp-upload: 334Mbps local-cpu-load:38% remote-cpu-load:57% udp-download: 593Mbps l...
by dmfr
Tue Feb 22, 2022 1:24 am
Forum: RouterOS beta
Topic: Bridge filter rules : set-priority for VLAN non functional
Replies: 15
Views: 10093

Re: Bridge filter rules : set-priority for VLAN non functional

Confirmed fix on ROS v.7.1.3 for RB5009 (arm64).
by dmfr
Mon Jan 31, 2022 12:10 pm
Forum: RouterOS beta
Topic: Bridge filter rules : set-priority for VLAN non functional
Replies: 15
Views: 10093

Re: Bridge filter rules : set-priority for VLAN non functional

Probably you should report this via their support system. In the meantime, you can probably work around this with a mangle rule to get the same result. SUP-71491 on Mikrotik jira. Unfortunately DHCP client make use of raw sockets (at least for DHCPv4) and therefore bypasses IP firewall. Marking pac...
by dmfr
Sun Jan 30, 2022 7:25 pm
Forum: RouterOS beta
Topic: Bridge filter rules : set-priority for VLAN non functional
Replies: 15
Views: 10093

Re: Bridge filter rules : set-priority for VLAN non functional

Seems like this got fixed with 7.2rc3
Still doesn't work with above configuration (first post).
by dmfr
Mon Jan 17, 2022 4:01 pm
Forum: RouterOS beta
Topic: Bridge filter rules : set-priority for VLAN non functional
Replies: 15
Views: 10093

Re: Bridge filter rules : set-priority for VLAN non functional

From support ticket #[SUP-71491], priority has been raised regarding bridge filter rules. First, may they just work, even being CPU bound (like RB4011), it doesn't introduce a large performance cost. Now, if eventually bridge filter rules transparently trigger hardware capabilities when available, i...
by dmfr
Mon Jan 17, 2022 12:13 pm
Forum: RouterOS beta
Topic: Bridge filter rules : set-priority for VLAN non functional
Replies: 15
Views: 10093

Re: Bridge filter rules : set-priority for VLAN non functional

In my experience, bridge filter rules do not work on RB5009 for bridges with L2 hw offload enabled. But adding PCP/802.1p priorites works for me on RB5009 using interface/ethernet/switch/rule with action new-vlan-priority . Special attention has to be paid to keep switch rules and bridge config in ...
by dmfr
Wed Jan 12, 2022 10:54 pm
Forum: RouterOS beta
Topic: Bridge filter rules : set-priority for VLAN non functional
Replies: 15
Views: 10093

Re: Bridge filter rules : set-priority for VLAN non functional

Despite being fixed for RB4011 (arm),

That very issue is still occuring using 7.1.1 on RB5009 (arm64).
VLAN PCP/802.1p is not properly set through bridge filter rule.
by dmfr
Sat Dec 25, 2021 10:07 pm
Forum: Wireless Networking
Topic: Poor performance with 5ghz in CAPsMAN
Replies: 13
Views: 6242

Re: Poor performance with 5ghz in CAPsMAN

You won't ever achieve performance (by 2021 standards) with CAPsMAN. It's not a matter of fine-tuning, it is just by design for now. We recently experienced quite a lot and discovered that CAPsMAN performance (being local forwarding or CAPsMAN encapsulation) is very different (and much worse) than s...
by dmfr
Fri Dec 17, 2021 11:55 pm
Forum: Wireless Networking
Topic: Feedback : CAPSman tests, coming from Unifi
Replies: 19
Views: 6860

Re: Feedback : CAPSman tests, coming from Unifi

I am glad everyone finds the ideal AP seeking for new shiny brands. Ubiquiti was one at some point. Hope Mikrotik does not follow the same marketing / cloud / smartphone-enabled-management way... Back to the original topic, Did we solve the mystery of roaming in Mikrotik ? Genesispro, I had second t...
by dmfr
Fri Dec 17, 2021 3:21 pm
Forum: Wireless Networking
Topic: Feedback : CAPSman tests, coming from Unifi
Replies: 19
Views: 6860

Re: Feedback : CAPSman tests, coming from Unifi

From my experience it's much more efficient to set a standard minimum data rate of 12 or 18M, so clients are at least aware of the limits, and will try on purpose to find nearest AP more aggressively Yes, I do this as well. Difficult to tune, and I miss somewhat the "allow-out-of-range" e...
by dmfr
Fri Dec 17, 2021 1:38 pm
Forum: Wireless Networking
Topic: Feedback : CAPSman tests, coming from Unifi
Replies: 19
Views: 6860

Re: Feedback : CAPSman tests, coming from Unifi

Did you add this for improved roaming?(fine tune the value to your liking) ... add action=reject allow-signal-out-of-range=6s client-to-client-forwarding=yes disabled=no interface=any signal-range=-120..-83 ssid-regexp="" At best it's not any better, at worse in your dark spots clients ge...
by dmfr
Fri Dec 17, 2021 12:51 am
Forum: Wireless Networking
Topic: Feedback : CAPSman tests, coming from Unifi
Replies: 19
Views: 6860

Feedback : CAPSman tests, coming from Unifi

I recently had to decide sourcing wireless equipment for a new site. Site is a warehouse (~12 APs) and adjacent offices (2 floors ~4 APs) On other premises we have been using Unifi gear and kind of satisfied with it, with notable exception of 'new' NanoHD which has been a disaster, due to poor inter...
by dmfr
Mon Nov 22, 2021 2:02 pm
Forum: RouterOS beta
Topic: Bridge Filters Don't Seem to be working
Replies: 14
Views: 8352

Re: Bridge Filters Don't Seem to be working

Interesting.
I've reported same issue for RB4011 as well :
viewtopic.php?t=167633

However, for this device (RB4011) at least, it is now working from rc3.
by dmfr
Wed Nov 10, 2021 8:35 pm
Forum: RouterOS beta
Topic: RB4011iGS+5HacQ2HnD-IN + 7.1rc6 : /system/leds breaks export/import
Replies: 1
Views: 1456

RB4011iGS+5HacQ2HnD-IN + 7.1rc6 : /system/leds breaks export/import

Starting with rc5/6, default configuration includes the following leds config : /system leds add interface=wlan2 leds=wlan2_signal1-led,wlan2_signal2-led,wlan2_signal3-led,wlan2_signal4-led,wlan2_signal5-led type=wireless-signal-strength add interface=wlan2 leds=wlan2_tx-led type=interface-transmit ...
by dmfr
Wed Oct 06, 2021 2:24 am
Forum: RouterOS beta
Topic: (feature request ?) ARP mode : local-proxy-arp + reply-only
Replies: 4
Views: 3811

Re: (feature request ?) ARP mode : local-proxy-arp + reply-only

Opened SUP-62240 to highlight this request.
From an outside point of view, things are always easier... but I trust it would not be big work to implement as the two functions are already operational (for more than a decade).
by dmfr
Sun Oct 03, 2021 4:58 pm
Forum: RouterOS beta
Topic: (feature request ?) ARP mode : local-proxy-arp + reply-only
Replies: 4
Views: 3811

(feature request ?) ARP mode : local-proxy-arp + reply-only

Hello, When configuring ARP mode on any interface (ethernet / vlan / bridge), it would be nice to select both modes : local-proxy-arp reply-only Some kind of : /interface/bridge set [find where name="bridge"] arp=local-proxy-arp,reply-only This behaviour would effectively implement router-...
by dmfr
Sat Oct 02, 2021 7:17 pm
Forum: General
Topic: Guest network as VLAN tagged for one port
Replies: 9
Views: 3997

Re: Guest network as VLAN tagged for one port

Thank you for all helpful answers.
Now I clearly understand how :
/interface/bridge/vlan
has to be used the "right way".

Will eventually redesign our configuration when chance comes!
by dmfr
Fri Oct 01, 2021 1:41 am
Forum: General
Topic: Guest network as VLAN tagged for one port
Replies: 9
Views: 3997

Re: Guest network as VLAN tagged for one port

Thank you for the explanation, things are becoming a bit clearer ! Plus, I now understand your solution is even more "logic" as soon as there are VLANs involved in the bridge. To your end question, attached to ether1 there is a switch, and as non-expert configured that way : port 1 (attach...
by dmfr
Fri Oct 01, 2021 1:07 am
Forum: General
Topic: Guest network as VLAN tagged for one port
Replies: 9
Views: 3997

Re: Guest network as VLAN tagged for one port

Thank you for the link, assuming there's only one bridge so : /interface bridge add name=bridge protocol-mode=none vlan-filtering=yes /interface bridge port add bridge=bridge interface=ether1 add bridge=bridge interface=ether2 add bridge=bridge interface=ether3 add bridge=bridge interface=ether4 /in...
by dmfr
Thu Sep 30, 2021 11:52 pm
Forum: General
Topic: Guest network as VLAN tagged for one port
Replies: 9
Views: 3997

Re: Guest network as VLAN tagged for one port

Thank you for the prompt answer ! May i ask when you say : The correct way would be to have only one bridge, create the VLAN interface on the bridge and configure port1 to have vlan 33 tagged. how would i do this the preferred way ? I'm a bit confused by /interface bridge vlan section, don't know wh...
by dmfr
Thu Sep 30, 2021 10:58 pm
Forum: General
Topic: Guest network as VLAN tagged for one port
Replies: 9
Views: 3997

Guest network as VLAN tagged for one port

Hello, Router (RB4011) is handling two LAN subnets as bridges : /interface bridge add name=bridge protocol-mode=none vlan-filtering=yes add name=bridge-guest protocol-mode=none vlan-filtering=yes /ip address add address=192.168.1.1/24 interface=bridge network=192.168.1.0 add address=192.168.33.1/24 ...
by dmfr
Wed Sep 22, 2021 1:07 am
Forum: RouterOS beta
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 83464

Re: v7.1rc4 [development] is released!

Unfortunately true. However, /export show-sensitive terse produces export code that can be imported successfully, for a full config restore. I can not confirm that. If there is a script in the command, as in my example above, it still fails. My mistake. You're right. Didn't test "export terse&...
by dmfr
Tue Sep 21, 2021 5:41 pm
Forum: RouterOS beta
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 83464

Re: v7.1rc4 [development] is released!

Export creates code, that import can not read (starting with 7.1rc3): Unfortunately true. However, /export show-sensitive terse produces export code that can be imported successfully, for a full config restore. On the bright side, such export now works with : /system/reset-configuration keep-users=...
by dmfr
Tue Sep 14, 2021 11:37 pm
Forum: RouterOS beta
Topic: v7.1rc3 [development] is released!
Replies: 172
Views: 50894

Re: v7.1rc3 [development] is released!

Do not use backup, use export for configuration. Thing is, simple export/import is broken in 7.1rc3, "expected end of line error" when line-break inside double-quote, example : /user group set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\ sword,web,sniff...
by dmfr
Fri Sep 03, 2021 5:42 pm
Forum: RouterOS beta
Topic: V7 : Ping return as watchdog / scripting
Replies: 2
Views: 3859

V7 : Ping return as watchdog / scripting

Found a divergence in /ping command output between V6 and V7. Consider an unreachable IP address (10.99.99.99) and script sentence to return TRUE if actually unreachable : [admin@mtk-V6] > :put ([/ping count=4 address=10.99.99.99]=0) true [admin@mtk-V7] > :put ([/ping count=4 address=10.99.99.99]=0)...
by dmfr
Wed Sep 01, 2021 11:30 am
Forum: RouterOS beta
Topic: v7.1rc1 multicast / igmp-proxy
Replies: 12
Views: 6843

Re: v7.1rc1 multicast / igmp-proxy

Unfortunately :
viewtopic.php?f=1&t=178045#p876086
Enabling igmp-proxy brings kernel alert on reboot, though igmp proxy seems functional with no other side effects.
by dmfr
Tue Aug 31, 2021 3:54 pm
Forum: RouterOS beta
Topic: v7.1rc2 [development] is released!
Replies: 194
Views: 44643

Re: v7.1rc2 [development] is released!

Enabling igmp-proxy causes (harmless ?) kernel failure and autosupout.rif
 14:46:49 system,error,critical kernel failure in previous boot
 14:46:53 igmp-proxy,info starting IGMP proxy forwarding
Disabling igmp-proxy (by removing again all interfaces) suppresses that error message.
by dmfr
Thu Aug 26, 2021 3:54 am
Forum: RouterOS beta
Topic: v7.1rc1 multicast / igmp-proxy
Replies: 12
Views: 6843

Re: v7.1rc1 multicast / igmp-proxy

Thank you.
Looking forward to next RC update.
by dmfr
Tue Aug 24, 2021 4:58 pm
Forum: RouterOS beta
Topic: v7.1rc1 multicast / igmp-proxy
Replies: 12
Views: 6843

v7.1rc1 multicast / igmp-proxy

Hello Mikrotik,
Multicast package is still missing from v7.1rc1, I cannot find any option to enable igmp proxying.
Is this feature considered obsolete or still due for final release ?
Thanks,
by dmfr
Tue Aug 10, 2021 2:08 pm
Forum: RouterOS beta
Topic: IPv6 link-local address missing on bridge if auto-mac=no
Replies: 6
Views: 4610

Re: IPv6 link-local address missing on bridge if auto-mac=no

There is definitely a regression from RouterOS v6. Same setup : /interface bridge add admin-mac=48:8F:5A:F9:E9:7D auto-mac=no name=bridge protocol-mode=none /interface bridge port add bridge=bridge comment=defconf interface=ether2 add bridge=bridge comment=defconf interface=ether3 add bridge=bridge ...
by dmfr
Tue Aug 10, 2021 1:08 pm
Forum: RouterOS beta
Topic: Bug: default configuration fails on 7.1beta6
Replies: 2
Views: 2295

Re: Bug: default configuration fails on 7.1beta6

Confirmed. Same hardware, same result.

Additionally, applying previous exported config through :
/system reset-configuration no-defaults=yes run-after-reset=myexport.txt.rsc
fails unless you add
:delay 20
on top of script.
by dmfr
Mon Aug 09, 2021 11:23 pm
Forum: RouterOS beta
Topic: IPv6 link-local address missing on bridge if auto-mac=no
Replies: 6
Views: 4610

IPv6 link-local address missing on bridge if auto-mac=no

Found described issue with v7.1beta6, On bridge interface (LAN type) with auto-mac=no + admin-mac, link-local address is randomly missing after reboot (most of the time but not always). As trivial consequence, prefix ADV and route annonces on LAN are not working. However DHCPv6 address from dhcp6_po...
by dmfr
Mon Aug 09, 2021 11:17 pm
Forum: RouterOS beta
Topic: Bridge filter rules : set-priority for VLAN non functional
Replies: 15
Views: 10093

Re: Bridge filter rules : set-priority for VLAN non functional

Seems fixed in v7.1beta6.
After multiple restores from /export output, bridge filter rules are correctly applied.
by dmfr
Thu Apr 01, 2021 11:06 pm
Forum: General
Topic: Force SFP interface running
Replies: 2
Views: 990

Force SFP interface running

Hello all, I am using RB4011iGS with current ROS 6.48.1 along with some GPON ONU modules, and noticed that SFP interface activates only when FTTH fiber is actually connected (which makes sense on standard tranceivers). However most ONUs (nokia G-010S-A, ZTEs, ... as examples) always expose an intern...
by dmfr
Wed Mar 24, 2021 8:28 pm
Forum: RouterOS beta
Topic: Bridge filter rules : set-priority for VLAN non functional
Replies: 15
Views: 10093

Re: Bridge filter rules : set-priority for VLAN non functional

Same on v7.1beta5. See above. With some interesting fact, Configuration similar to above defined under ROSv6 stays functional after upgrade to ROSv7. However, after /system reset-configuration , identical configuration (typed or restored from a working /export) is non functional. Might be related to...
by dmfr
Thu Jan 21, 2021 3:52 pm
Forum: General
Topic: Route internet through IPsec
Replies: 14
Views: 4387

Re: Route internet through IPsec

IPSEC tunnels are "crypto routed" (maybe this is incorrect term). They are using xfrm tables, not regular routing table in kernel, packet is "stolen" by kernel before it reaches regular routing tables. I am not aware of any trick to manually add other destination(s) or default ro...
by dmfr
Wed Nov 25, 2020 3:40 pm
Forum: RouterBOARD hardware
Topic: Usage GPON module SFP in Spain
Replies: 633
Views: 356508

Re: Usage GPON module SFP in Spain

I've been able to make progress with the UFiber-Instant ONU module: it can definitely reach Operation State (o5) on the Movistar (Huwaei) ONT in Spain However I had to go in the diag system and manually overwrite the PLOAM password, because the flash command limits the GPON_PLOAM_PASSWD to 10 chara...
by dmfr
Thu Oct 15, 2020 11:18 am
Forum: RouterOS beta
Topic: Bridge filter rules : set-priority for VLAN non functional
Replies: 15
Views: 10093

Bridge filter rules : set-priority for VLAN non functional

Hello Mikrotik, Consider following setup to set VLAN 802.1Q priority (PCP) = 6 for DHCP outbound packets. /interface vlan add interface=ether1 name=ether1.832 vlan-id=832 /interface bridge add fast-forward=no name=orange-832 protocol-mode=none /interface bridge filter add action=set-priority chain=o...