Community discussions

MikroTik App

Search found 83 matches

by felixka
Wed Mar 13, 2024 4:21 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 503
Views: 125969

Re: v7.15beta [testing] is released!

beta6 fixes the bug in VRF routing for me. Nice.
by felixka
Wed Mar 06, 2024 9:46 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 503
Views: 125969

Re: v7.15beta [testing] is released!

Updated my RB5009 today and it's lost it's ability to route certain VLANs out via VPNs from within VRFs. Not sure what's going on exactly yet. But it works fine on 7.13 (didn't try 7.14 as it would break my WAN link due to the VLAN MTU issues).
by felixka
Sat Jan 27, 2024 5:32 am
Forum: Beginner Basics
Topic: CCR2004-16G-2S+ and Downgrade
Replies: 1
Views: 434

Re: CCR2004-16G-2S+ and Downgrade

You will want to use Netinstall to downgrade in this case: https://wiki.mikrotik.com/wiki/Manual:Netinstall

Make sure to backup your config. The device will be completely wiped in the process.
by felixka
Fri Oct 27, 2023 4:17 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93518

Re: v7.12rc is released!

When are you releasing 7.12? I need those IKEv2 rekey fixes in the stable version :)
when its done :)
We all know (and Mikrotik lives by it): Done is better than perfect 😉
by felixka
Thu Oct 19, 2023 4:48 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93518

Re: v7.12rc is released!

*) sfp - fixed link establishment with passive copper cables for RB4011 and CCR2004-16G-2S+ devices (introduced in 7.12rc1); https://mikrotik.com/product/rb4011igs_rm says "Note: Passive DAC (MikroTik S+DA0001/S+DA0003) are not supported." - are they supported now? Or is this a mistake in...
by felixka
Fri Oct 06, 2023 4:09 pm
Forum: Beginner Basics
Topic: use vlan to separate trafic and route on different gateways
Replies: 2
Views: 1089

Re: use vlan to separate trafic and route on different gateways

You could look into VXLAN or EoIP to create an overlay Layer 2 network for your 192.168.50.0/24 and 192.168.51.0/24 subnets over the Layer 3 10.10.0.0/19 network.
by felixka
Fri Oct 06, 2023 3:58 pm
Forum: Beginner Basics
Topic: Moving from USG to Mikrotik
Replies: 7
Views: 3837

Re: Moving from USG to Mikrotik

Can you better explain the shortcomings of the RB5009 you noted. " I don't run DHCP or DNS on RouterOS because it doesn't allow for the flexibility I need and also the DNS implementation in RouterOS 7 is troublesome." Sure: The DHCP implementation of RouterOS can only match one DHCP optio...
by felixka
Fri Oct 06, 2023 5:22 am
Forum: Beginner Basics
Topic: Moving from USG to Mikrotik
Replies: 7
Views: 3837

Re: Moving from USG to Mikrotik

I run UniFi for wireless and video surveillance in my house with a MikroTik router as the gateway. It works without any issues. My UniFi controller runs on a CloudKey. You'll lose visibility into anything WAN related in the UniFi controller but that's about it. You will need to keep using the UniFi ...
by felixka
Sun Oct 01, 2023 5:29 am
Forum: Beginner Basics
Topic: Lots of VLANs need internet access via 1 internet gateway
Replies: 3
Views: 1052

Re: Lots of VLANs need internet access via 1 internet gateway

Regarding your questions: 1. Whether it will improve network security depends on how you configure the switches and routers in the path. If you freely allow routing traffic between VLANs the security benefits are very little. 2. Yes. You would use VLAN interfaces on the Mikrotik side for this. 3. Ye...
by felixka
Sun Sep 17, 2023 4:16 am
Forum: General
Topic: Mikrotik SUCKS
Replies: 82
Views: 12894

Re: Mikrotik SUCKS

Most people I know that have some sort of background in networking and who are trying to make Mikrotik work for them go through this at the beginning. It's a normal part of the process. It takes some time, but you'll learn to love it eventually. Especially if, like you said, you are somehow stuck wi...
by felixka
Sat Aug 19, 2023 1:11 am
Forum: Beginner Basics
Topic: Router/bridge at same time
Replies: 11
Views: 1880

Re: Router/bridge at same time

It can certainly be done but how you'll do it depends on your network topology.
If the servers are directly connected to the router you could remove the server ports from the LAN bridge, create another bridge that includes your WAN port and then add the server ports to that bridge.
by felixka
Wed Aug 09, 2023 7:39 am
Forum: Beginner Basics
Topic: Using static IPs from a pool to connected to devices
Replies: 10
Views: 2594

Re: Using static IPs from a pool to connected to devices

Is .65 an IP that the ISP uses for the gateway or does the ISP expect you to set up a gateway at that IP address to handle any traffic going to the subnet?
by felixka
Tue Aug 08, 2023 5:20 pm
Forum: Beginner Basics
Topic: Using static IPs from a pool to connected to devices
Replies: 10
Views: 2594

Re: Using static IPs from a pool to connected to devices

If the CRS is already using an IP from the provider does the provider route the /27 to that IP or is the /27 on-link (i.e. not routed to you)? If you do not know how to tell or (test for yourself) the difference it's easiest to ask your ISP how they set this up. Depending on how easy your ISP is to ...
by felixka
Tue Aug 08, 2023 7:04 am
Forum: Beginner Basics
Topic: Using static IPs from a pool to connected to devices
Replies: 10
Views: 2594

Re: Using static IPs from a pool to connected to devices

It'll depend on how your upstream provider routes IPs from this range to you. Do they route the subnet to another IP you have configured on your router? -> Use regular routing. This is the most elegant solution. Does your ISP's router expect all hosts using IPs from the subnet to reply to ARP direct...
by felixka
Fri Jun 16, 2023 6:25 am
Forum: Announcements
Topic: v7.10, 7.10.1 and more [stable] are released!
Replies: 366
Views: 130512

Re: v7.10 [stable] is released!

Hello! Please, beware that some of these improvements make Chinese SFP modules (e.g. ONTi Gigabit RJ45 SFP module from Aliexpress) report temperature of 255 degrees which triggers SFP module disabling (for 10 minutes, but it repeats) since the default SFP shutdown temperature is 95 degrees. Thus, y...
by felixka
Wed Jun 14, 2023 11:37 pm
Forum: Announcements
Topic: v7.10rc is released!
Replies: 183
Views: 53893

Re: v7.10rc is released!

Because so many people have been asking for it for so long, so vehemently. As a result they felt it prudent to add at least four BFD thus far. More to come! Look out for that final release change log.
by felixka
Mon May 22, 2023 4:04 pm
Forum: Announcements
Topic: v7.9.1 [stable] is released!
Replies: 59
Views: 18356

Re: v7.9.1 [stable] is released!

As mentioned in https://forum.mikrotik.com/viewtopic.php?p=1001827#p1001827 I am also seeing a DAC cable between a CCR2004-16G-2S+ and an Aruba 1930 switch no longer being able to connect. That CCR2004 was running 7.6 before and the cable worked just fine for all releases before 7.9 (tested with 7.9...
by felixka
Fri May 05, 2023 5:07 am
Forum: RouterOS beta
Topic: v7 and BFD, any ETA?
Replies: 149
Views: 27887

Re: v7 and BFD, any ETA?

what would prevent us from flashing a lightweight Linux distro onto some of the arm-based routers and just run FRR? Support for MikroTik hardware and the SoCs they use in mainline linux, bootloader peculiarities, to name a few. MikroTik makes it purposely hard for anyone to get current GPL source c...
by felixka
Sun Apr 23, 2023 7:05 am
Forum: RouterOS beta
Topic: v7 and BFD, any ETA?
Replies: 149
Views: 27887

Re: v7 and BFD, any ETA?

Kudos to the MikroTik team for keeping their cool given the tone by a few customers.
Given that we're dealing with humans on either side of the keyboards I don't think they deserve the abuse they are receiving here, regardless of what their employers' strategy, roadmap and quality of delivery may be.
by felixka
Sun Jan 15, 2023 2:11 pm
Forum: RouterOS beta
Topic: CCR2004-16G-2S+PC *HIGH* CPU vs CCR1009-7G-1C-1S+ vs
Replies: 2
Views: 5647

Re: CCR2004-16G-2S+PC *HIGH* CPU vs CCR1009-7G-1C-1S+ vs

What are we missing? How is Mikrotik getting 22Gbps of routing performance through this with no routing rules (512 byte packets)? It's probably in your config. If you post it I can't guarantee I'd see it, but if you don't I will gladly guarantee that I will not see it. When going from Cisco to Mikr...
by felixka
Wed Aug 10, 2022 11:47 pm
Forum: Beginner Basics
Topic: Single DHCP server for multiple VLANs?
Replies: 14
Views: 4304

Re: Single DHCP server for multiple VLANs?

I mean one solution could be to just bridge VLAN10 and VLAN20 right on the Mikrotik and make them one L2 broadcast domain because it sounds you are handed two VLANs that you actually don't want to be separate in the first place.
by felixka
Wed Aug 10, 2022 6:47 pm
Forum: Beginner Basics
Topic: Single DHCP server for multiple VLANs?
Replies: 14
Views: 4304

Re: Single DHCP server for multiple VLANs?

Why would they need to be in the same IP address range to begin with?
VLANs create a separate Layer 2 domain per VLAN, so trying to overlay a single Layer 3 IP subnet over it sounds like asking for trouble.
by felixka
Wed Aug 10, 2022 1:46 am
Forum: Beginner Basics
Topic: Single DHCP server for multiple VLANs?
Replies: 14
Views: 4304

Re: Single DHCP server for multiple VLANs?

I don't think it's possible and I also don't know why you'd want to do that.

Sounds like an XY Problem.
by felixka
Fri Aug 05, 2022 1:17 am
Forum: Announcements
Topic: not strictly related to v7.5beta
Replies: 30
Views: 5172

Re: v7.5beta [testing] is released!

Why do they stick with kernel 5.6.3? Why not using latest 5.6.19 at least? Makes me really wonder. Mikrotik heavily modifies the Linux Kernel to support all their hardware. For example, the tile architecture (used in CCR1016/1036/1072) was dropped in Kernel 4.17. So Mikrotik has to manually patch i...
by felixka
Wed Jul 27, 2022 9:27 pm
Forum: Announcements
Topic: not strictly related to v7.5beta
Replies: 30
Views: 5172

Re: v7.5beta [testing] is released!

Anyone know which linux kernel version 7.5b is based off of? Looking forward to full NETMAP support in kernels 5.8+.
7.5beta4 is on Kernel 5.6.3.
by felixka
Fri Jul 01, 2022 4:12 am
Forum: Announcements
Topic: v7.3 and v7.3.1 [stable] is released!
Replies: 269
Views: 81228

Re: v7.3 and v7.3.1 [stable] is released!

*) ccr - improved interface link stability on CCR2004-16G-2S+PC;
Updated from 7.0.4 to 7.3.1 today but am still seeing intermittent interface flapping when connected to an AVM Fritz!Box Cable Modem from Vodafone Germany.
by felixka
Mon May 30, 2022 6:24 pm
Forum: Announcements
Topic: MikroTik Devices Controller
Replies: 332
Views: 238904

Re: MikroTik Devices Controller

If there will be a frontend for it other than Winbox or Webfig I think it should retain that Windows 95 look though.
by felixka
Sat May 14, 2022 10:54 pm
Forum: RouterOS beta
Topic: some quick comments on configuring cake
Replies: 285
Views: 103625

Re: some quick comments on configuring cake

What are you talking about? It's been working over here just fine? A developer is me. Things were looking good. They are talking about that Mikrotik decided to limit cake to interface queues only in the latest 7.3beta40 release. Release notes buried here: https://forum.mikrotik.com/viewtopic.php?t=...
by felixka
Fri May 06, 2022 6:22 pm
Forum: RouterOS beta
Topic: Feature Request : IPv6 Fasttrack
Replies: 176
Views: 52255

Re: Feature Request : IPv6 Fasttrack

Has Mikrotik ever provided an answer to this request?
Is it even feasible on the hardware side of things?
They have. It's actually even linked in the very first post.

And yes, some of the SoCs and switch chips Mikrotik uses support IPv6 offloading.
by felixka
Wed May 04, 2022 10:47 pm
Forum: RouterBOARD hardware
Topic: Device request CRS318-16P-2S+RM
Replies: 12
Views: 1647

Re: Device request CRS318-16P-2S+RM

Basically a CCR2004-16G-2S+ but as a pure switch. Not quite. The CCR2004-16G-2S+ does not have PoE Ports. But I, too, would welcome a device like this though I would prefer it in a desktop form factor with optional rack ears and passively cooled. Essentially like a Cisco Catalyst WS-C3560CX-12PD-S.
by felixka
Sun Apr 17, 2022 6:01 am
Forum: RouterOS beta
Topic: Feature request: HSGMII for SFP >1Gbps synchronization. [SOLVED]
Replies: 22
Views: 15644

Re: [SOLVED !!!] Feature request: HSGMII for SFP >1Gbps synchronization. [SOLVED]

I don't get why they can't add the support by the cpu. The switch asic is more "compatible" than the one into the cpu ? idk.... Comes down to the Linux driver support. Most don't have 2500Base-X support, even though the chip may support it. So either Mikrotik goes ahead and implements tha...
by felixka
Tue Apr 12, 2022 12:45 am
Forum: RouterOS beta
Topic: Hardware IPv6 (dedicated thread)
Replies: 6
Views: 4705

Re: Hardware IPv6 (dedicated thread)

Check out this quote from 4 posts up:
Hardware IPv6 routing on Marvell switch chips (CRS3xx, CCR2116) is in development.
by felixka
Fri Apr 08, 2022 6:05 pm
Forum: Announcements
Topic: v7.2 is released!
Replies: 359
Views: 61817

Re: v7.2 is released!

Try IPv6, not something that's done under fasttrack. My ISP does not offer IPv6. And the HE.net Tunnel I have as an alternative is not fast enough to highlight the problem, if there was one. So I assume I cannot verify the problem you're having, but it sounds logical to me that it could exist under...
by felixka
Fri Apr 08, 2022 5:19 pm
Forum: Announcements
Topic: v7.2 is released!
Replies: 359
Views: 61817

Re: v7.2 is released!

Yes, trust the system!

I like my full speed, thank you! :)
Cannot confirm:
RB5009 ROS7.2 / PPPoE (MTU 1500) on VLAN on Ethernet with MTU 1508

1400 MHz fixed
5009-1400.png
Auto:
5009-auto.png
by felixka
Thu Apr 07, 2022 6:54 pm
Forum: Announcements
Topic: NEWSLETTER 105
Replies: 56
Views: 46111

Re: NEWSLETTER 105

Love the CCR2004-16G-2S+PC!

However, what I really need would probably be a CCR2004-16P-2S+PC
Essentially a Mikrotik version of the Cisco Catalyst 3560CX-12PD-S (12 GigE PoE, 2 GigE and 2 SFP+) or even 3560CX-8XPD-S (6 PoE, 2 mGig (10GbE), 2 SFP+). Powerful but still passively cooled.
by felixka
Thu Mar 24, 2022 10:17 pm
Forum: Announcements
Topic: v7.2rc5 is released!
Replies: 91
Views: 24158

Re: v7.2rc5 is released!

Did you do plain SSH over PPPoE+VLAN? In my case I have a GRE/IPsec tunnel over PPPoE+VLAN and inside that I do SSH or BGP which gets stuck (due to nonzero DSCP). Yes, I do "plain" VLAN+PPPoE. In my case it's the WAN connection and then I access SSH or VoIP resources on the internet. This...
by felixka
Thu Mar 24, 2022 8:43 pm
Forum: Announcements
Topic: v7.2rc5 is released!
Replies: 91
Views: 24158

Re: v7.2rc5 is released!

I can confirm that this also fixes the issue of DSCP marked SSH or VoIP connections when using PPPoE with VLAN tagged interfaces. That is interesting... When reading that I eagerly upgraded my RB4011 but for me this problem has not been fixed. I am on an RB5009, so it may have not been fixed on the...
by felixka
Thu Mar 24, 2022 12:00 am
Forum: RouterOS beta
Topic: Issue with RB5009 ROS v7.1rc1 DHCPv6-PD over pppoe on tagged ethernet link
Replies: 69
Views: 30603

Re: Issue with RB5009 ROS v7.1rc1 DHCPv6-PD over pppoe on tagged ethernet link

Looks resolved to me as well, albeit my issue was with DSCP tagged SSH and VoIP connection. Finally :)
by felixka
Wed Mar 23, 2022 11:59 pm
Forum: Announcements
Topic: v7.2rc5 is released!
Replies: 91
Views: 24158

Re: v7.2rc5 is released!

*) ipv6 - fixed VLAN tagged PPPoE packet receiving on RB5009;
I can confirm that this also fixes the issue of DSCP marked SSH or VoIP connections when using PPPoE with VLAN tagged interfaces.
Also, I finally get an MTU of 1500 if the underlying interface has MTU 1508, as you'd expect with PPPoE.
by felixka
Sun Mar 20, 2022 11:27 pm
Forum: Announcements
Topic: v7.2rc4 is released!
Replies: 143
Views: 42567

Re: v7.2rc4 is released!

I know its only arm yet. Can you post a link to where MT stats that there will be no ZeroTier for other platform?
viewtopic.php?t=178353#p890747
by felixka
Wed Mar 16, 2022 12:10 am
Forum: RouterOS beta
Topic: Is not possible to downgrade beyond the factory installed version 7.1.1
Replies: 9
Views: 2972

Re: How to downgrade beyond the factory installed version 7.1.1

Well I guess it is ok for one's cheap home wifi router.... so nice reminder of where these products are targeted at, thanks for that Tik! In most cases with MikroTik you end up getting much more than what they paid for. That's why we love them so much. But in some cases, and more so lately, you get...
by felixka
Sat Mar 05, 2022 4:54 am
Forum: General
Topic: any 100 Gigabit QSFP28 module for CCR2216?
Replies: 3
Views: 508

Re: any 100 Gigabit QSFP28 module for CCR2216?

Try Optcore. I've used them for all my SFP needs so far, but haven't tested their 100G stuff. At $65 for the SR and $400 for the LR modules it's not too expensive to give it a shot.
by felixka
Sun Feb 27, 2022 9:55 pm
Forum: RouterOS beta
Topic: rb5009 The rate is abnormal after pppoe dialing at the 10 Gigabit negotiation rate or the 2.5g negotiation rate
Replies: 2
Views: 931

Re: rb5009 The rate is abnormal after pppoe dialing at the 10 Gigabit negotiation rate or the 2.5g negotiation rate

Possibly related: viewtopic.php?t=182691
But it could also be something else. Without a full config (/system export hide-sensitive) it's hard to tell.
by felixka
Sat Feb 19, 2022 9:30 pm
Forum: RouterOS beta
Topic: SSH connection issues with "fasttrack" switched off. [SOLVED]
Replies: 33
Views: 13709

Re: SSH connection issues with "fasttrack" switched off. [SOLVED]

Yes, this is a bug and Mikrotik is fixing it in one of the coming releases.
It is also discussed here: viewtopic.php?t=177984
by felixka
Thu Feb 17, 2022 5:33 pm
Forum: General
Topic: RB5009UG+S+ crashes on every reboot, Routeros 7.1.2
Replies: 7
Views: 1019

Re: RB5009UG+S+ crashes on every reboot, Routeros 7.1.2

The RB5009 does not have a console port.
by felixka
Tue Feb 01, 2022 6:26 pm
Forum: RouterOS beta
Topic: convert raw to docker image
Replies: 1
Views: 1478

Re: convert raw to docker image

Docker does not boot anything. It takes an image and runs a command from it in a containerized way. You would need a full- or paravirtualized hypervisor to boot CHR, as the CHR relies on the Kernel it comes with to perform many of the networking functions. Docker is OS-level virtualization and relie...
by felixka
Mon Jan 10, 2022 10:13 pm
Forum: Announcements
Topic: v7.2rc1 is released!
Replies: 240
Views: 161251

Re: v7.2rc1 is released!

I receive roughly 950-980Mbit when I do a SpeedTest on TCP protocol. However, when I use UDP, I only get 15-3 Mbit. Is it because of me? It is likely because of you. UDP speed tests usually test using a pre-set low target bitrate (iperf3 uses 1 Mbit/s, for example). UDP does not have congestion con...
by felixka
Fri Dec 31, 2021 5:06 pm
Forum: Announcements
Topic: v7.2rc1 is released!
Replies: 240
Views: 161251

Re: v7.2rc1 is released!

ATA can register in v6.49.2 without any problems. With V7 everything else on my network works as expected. My setup is a PPPoE internet connection for home use, I followed Mikrotik's first time configuration guide (https://help.mikrotik.com/docs/display/ROS/First+Time+Configuration) doing a clean i...
by felixka
Tue Dec 28, 2021 9:32 pm
Forum: RouterOS beta
Topic: PPPoE CPU utilization
Replies: 1
Views: 2805

Re: PPPoE CPU utilization

Some chipsets support PPPoE hardware acceleration (such as Atheros IPQ806x). Don't know if MikroTik uses it though. Most of the time you're running PPPoE at a payload MTU of 1492 so there will be packet fragmentation occurring on your router. That will be enough to prevent these packets being fasttr...
by felixka
Tue Dec 28, 2021 1:06 am
Forum: RouterOS beta
Topic: Issue with RB5009 ROS v7.1rc1 DHCPv6-PD over pppoe on tagged ethernet link
Replies: 69
Views: 30603

Re: Issue with RB5009 ROS v7.1rc1 DHCPv6-PD over pppoe on tagged ethernet link

Anyone have any information on whether this issue will be resolved in upcoming firmwares or not? :? As far as the erroneous insertion of DSCP flags on VLAN interfaces (which I believe is underlying this issue) is concerned I have confirmation from Mikrotik that the issue will be fixed but that ther...
by felixka
Wed Dec 08, 2021 11:12 pm
Forum: RouterOS beta
Topic: Issue with RB5009 ROS v7.1rc1 DHCPv6-PD over pppoe on tagged ethernet link
Replies: 69
Views: 30603

Re: Issue with RB5009 ROS v7.1rc1 DHCPv6-PD over pppoe on tagged ethernet link

MTU
Interface | MTU  | L2 MTU
br_wan    | 1500 | 1514
vlan_wan  | 1500 | 1510
ppoe_wan6 | 1480 | -
I use the following for Bell Canada and it gives me an MTU of 1500:
Interface  | MTU  | L2 MTU
ether1     | 1520 | 1534
br_wan     | 1520 | 1534
pppoe-out1 | no value set (default)
by felixka
Wed Dec 08, 2021 11:08 pm
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 226792

Re: v7.1 [testing] is released!

After upgrading my RB4011 home router, SSH sessions to remote servers don't work. To make them work again, I have to set on the SSH client another IPQoS (e.g. cs1). Is it normal? I have a ticket open regarding this: SUP-63430 Support is saying they cannot reproduce it. Support was finally able to r...
by felixka
Wed Dec 08, 2021 11:03 pm
Forum: RouterOS beta
Topic: Issue with RB5009 ROS v7.1rc1 DHCPv6-PD over pppoe on tagged ethernet link
Replies: 69
Views: 30603

Re: Issue with RB5009 ROS v7.1rc1 DHCPv6-PD over pppoe on tagged ethernet link

Just received a reply on my open ticket SUP-63430. This ticket relates to DSCP marked traffic not passing through in the PPPoE/VLAN tagged scenario. Support asked to me to test something and it looks as though I was able to confirm a possible bug they are seeing in their lab now as well. It seems th...
by felixka
Sun Dec 05, 2021 10:40 pm
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 226792

Re: v7.1 is released!

The first new question for the ROS 7 exams is which one of the three legitimate ways to configure the PPPoE client on a VLAN-tagged interface does not trigger a non-reproducible bug regarding not forwarding DSCP marked packets.
by felixka
Fri Dec 03, 2021 2:52 pm
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 226792

Re: v7.1 [testing] is released!

This problem appears to occur only in the ARM architecture, I bet that when you copy your entire config to a RB2011 or CCR1009 it will work just fine. That would have to be both ARM and ARM64 because the RB4011 is 32 bit and the RB5009 is 64 bit. It would be interesting to see if the CR2004-16G is ...
by felixka
Fri Dec 03, 2021 12:06 am
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 226792

Re: v7.1 [testing] is released!

After upgrading my RB4011 home router, SSH sessions to remote servers don't work. To make them work again, I have to set on the SSH client another IPQoS (e.g. cs1). Is it normal? I have a ticket open regarding this: SUP-63430 Support is saying they cannot reproduce it. My debugging so far tells me ...
by felixka
Fri Nov 26, 2021 8:36 pm
Forum: RouterOS beta
Topic: CCR2004-16G-2S+ upgrade or not
Replies: 4
Views: 2440

Re: CCR2004-16G-2S+ upgrade or not

If everything you are doing now is working then I would not recommend to upgrade. I use a CCR2004-16G-2S+ in production with L2TP/IPSec VPN clients and I haven't found a definitive answer in the forum yet if the newest 7.1rc7 does not cause the router to reboot when these VPN clients connect. I also...
by felixka
Fri Nov 26, 2021 6:22 pm
Forum: RouterOS beta
Topic: v7.1rc7 [development] is released!
Replies: 174
Views: 55320

Re: v7.1rc7 [development] is released!

Is AES GCM not being hardware offloaded for IPSec on RB5009 a bug or is this simply not supported? AES CBC is offloaded just fine.
by felixka
Thu Nov 25, 2021 4:31 pm
Forum: RouterOS beta
Topic: RB5009UG+S+IN SFP+ port not working with some switches on firmware up to 7.1.5
Replies: 29
Views: 14029

Re: RB5009UG+S+IN SFP+ port not working with version 7.0.5 or 7.1rc6

For what it's worth, I'm running an Optcore OSP10G-8503DCR on my RB5009 with 7.1rc6 and it works just fine with the default settings.
by felixka
Wed Nov 24, 2021 7:51 pm
Forum: General
Topic: S+85DLC03D OM4 cable question
Replies: 2
Views: 1195

Re: S+85DLC03D OM4 cable question

Yes it is.
by felixka
Wed Nov 03, 2021 5:24 pm
Forum: RouterOS beta
Topic: Wireguard Connection between two sites [SOLVED]
Replies: 22
Views: 10432

Re: Wireguard Connection between two sites [SOLVED]

The 10.255.255.1/30 network essentially provides two IP addresses: 10.255.255.1 and 10.255.255.2. These are there to facilitate the routing between the two endpoints on the tunnel. These should be chosen such that they are "out of the way" of any of the other subnets you're using. You are ...
by felixka
Tue Nov 02, 2021 1:58 am
Forum: RouterOS beta
Topic: SSH connection issues with "fasttrack" switched off. [SOLVED]
Replies: 33
Views: 13709

Re: SSH connection issues with "fasttrack" switched off. [SOLVED]

So I figured out it had something to do with my PPPoE internet link being VLAN tagged in my router. Moved the VLAN tagging out to an external switch and put the PPPoE link directly on the ether1 interface untagged and the problem went away.
by felixka
Fri Oct 29, 2021 5:49 pm
Forum: RouterOS beta
Topic: OSPFv3 over wireguard broken? [SOLVED]
Replies: 11
Views: 4793

Re: OSPFv3 over wireguard broken? [SOLVED]

Maybe fallout from this:
 *) wireguard - do not consider WireGuard interface as ethernet;
by felixka
Sat Oct 23, 2021 2:52 am
Forum: RouterOS beta
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 83158

Re: v7.1rc4 [development] is released!

You can choose to participate (voluntarily) or stick to the older versions and wait for v7.9.4 with fewer bugs and problems.
True for those who own older hardware that supports the 6.x release train. Not true for those who have bought any of the more recent products that will only run 7.x.
by felixka
Wed Oct 20, 2021 5:30 am
Forum: Beginner Basics
Topic: VPN to connect home network to cottage [SOLVED]
Replies: 107
Views: 11384

Re: VPN to connect home network to cottage [SOLVED]

For now, 2 VLANS need to get shoved through a VPN to my cottage somehow. Will it take more than 1 VPN? perhaps 1 VPN per VLAN? I'm just trying to conceptualise this. VLANs are Layer2, IPsec is Layer 3. You can route all your home traffic through one tunnel and then separate it into VLANs again in t...
by felixka
Sat Oct 16, 2021 8:56 pm
Forum: RouterOS beta
Topic: SSH connection issues with "fasttrack" switched off. [SOLVED]
Replies: 33
Views: 13709

Re: SSH connection issues with "fasttrack" switched off. [SOLVED]

Somehow the workarounds do not work for IPsec encapsulated SSH traffic.
by felixka
Sat Oct 16, 2021 10:00 am
Forum: General
Topic: HGSMII for 2.5 Gbps link
Replies: 8
Views: 4237

Re: HGSMII for 2.5 Gbps link

Could you please enable it on RouterOS ? Now its normally included in linux kernel. What do you mean with "its normally included in linux kernel"? Where in the kernel exactly is it "normally included"? Support for 2500Base-X in Linux is mostly ethernet driver specific at this po...
by felixka
Sat Oct 16, 2021 9:17 am
Forum: RouterOS beta
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 83158

Re: v7.1rc4 [development] is released!

My issue of not being able to SSH out seems to be a bug that was fixed in 7.1beta3 but seems to have resurfaced.
viewtopic.php?p=885937#p885937
by felixka
Sat Oct 16, 2021 9:14 am
Forum: RouterOS beta
Topic: SSH connection issues with "fasttrack" switched off. [SOLVED]
Replies: 33
Views: 13709

Re: SSH connection issues with "fasttrack" switched off. [SOLVED]

I'm seeing this issue again on 7.1rc4. SSH works using the -oIPQoS=reliability workaround but not without it.
by felixka
Fri Oct 15, 2021 9:35 pm
Forum: RouterBOARD hardware
Topic: MikroTik RB5009UG+S+IN
Replies: 202
Views: 93020

Re: MikroTik RB5009UG+S+IN

I can confirm that the RB5009 can be powered using the Ubiquiti 802.3af Injectors while still maintaining a 2.5GBase-T link.

I can also confirm that the SFP+ does not support 2500Base-X (relevant for people that use certain GPON SFP ONTs that allow syncing at that rate).
by felixka
Fri Oct 08, 2021 4:39 pm
Forum: RouterOS beta
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 83158

Re: v7.1rc4 [development] is released!

Merely someone here posting a tc -s qdisc show with cake output showing some drops or marks and backlog would make me very happy after waiting all this time for mikrotik to catchup Hi Dave, fancy seeing you around here! Thanks for your work in ridding the world of bufferbloat! Unfortunately, Mikrot...
by felixka
Fri Oct 08, 2021 12:43 am
Forum: RouterOS beta
Topic: Can I trust v7 today?
Replies: 8
Views: 2699

Re: Can I trust v7 today?

It failed me today. So, no.
Maybe tomorrow.
by felixka
Fri Oct 08, 2021 12:29 am
Forum: RouterOS beta
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 83158

Re: v7.1rc4 [development] is released!

So my ISP put me out of my misery of using a SFP GPON ONT and gave me an ONT box with RJ45 for the handoff. Yet, the PPPoE on VLAN with MTU 1500 is still not working for me on 7.1rc4, SFP ONT or Ethernet to the ONT box. The PPPoE link comes up with MTU 1500 (outer VLAN interface is MTU 1520 and unde...
by felixka
Wed Sep 08, 2021 5:42 pm
Forum: Containers
Topic: v7.1rc3 adds container support
Replies: 493
Views: 162750

Re: v7.1rc3 adds Docker (TM) compatible container support

Unfortunately the CCR2004 has no USB or SD card interfaces so you cannot expand the storage.
Not entirely true. The CCR2004-16G-2S+ does indeed have a USB 3.0 Type A port. The CCR2004-1G-12S+2XS does not.
by felixka
Wed Sep 08, 2021 5:37 pm
Forum: RouterOS beta
Topic: v7.1rc3 [development] is released!
Replies: 172
Views: 50687

Re: v7.1rc3 [development] is released!

I would like to invoke @msatter for our obligatory PPPoE / SFP+ MTU > 1500 on RB4011 test :P I assume it's still broken unless it's covered under " *) other minor fixes and improvements;"
Would test myself but I just started my workday and can't mess up my Internet right now :D
by felixka
Thu Sep 02, 2021 10:26 pm
Forum: RouterOS beta
Topic: v7.1rc2 [development] is released!
Replies: 194
Views: 44485

Re: v7.1rc2 [development] is released!

The PPPoE through a SFP still drops back to a MTU of 1480...it was fixed in Beta 6.49 so please patch ROS 7.x also.
Just chiming in again that I can second this. Thanks msatter for testing :) I always look for your reports.
by felixka
Mon Aug 02, 2021 12:25 pm
Forum: Beginner Basics
Topic: Can we connect through ipsec VPN Mikrotik RouterBoard hEX to TP-LINK TL-R605 omada
Replies: 6
Views: 3471

Re: Can we connect through ipsec VPN Mikrotik RouterBoard hEX to TP-LINK TL-R605 omada

Got it to work for my setup where the Omada device is on a static IP and the Mikrotik RB4011 is on a dynamic IP, initiating the IPSec tunnel from it's side. TL-R605 Firmware: 1.1.0 RB4011 Firmware: 6.49beta46 Here are my settings: Mikrotik side: /ip ipsec profile add dh-group=ecp521 enc-algorithm=ae...
by felixka
Sat Jul 31, 2021 1:43 am
Forum: Beginner Basics
Topic: Can we connect through ipsec VPN Mikrotik RouterBoard hEX to TP-LINK TL-R605 omada
Replies: 6
Views: 3471

Re: Can we connect through ipsec VPN Mikrotik RouterBoard hEX to TP-LINK TL-R605 omada

I, too, have been unable to make this work between a TL-R605 and an RB4011 running ROSv6.46. The Mikrotik router tries to establish a Phase 2 tunnel but never receives a reply from the TP-Link.
This Omada stuff seems to be very early stage right now.
by felixka
Fri May 28, 2021 7:01 pm
Forum: RouterOS beta
Topic: v7.1beta6 [development] is released!
Replies: 377
Views: 243527

Re: v7.1beta6 [development] is released!

Although I don't know what their priorities are, one issue that i might see with where you place #1 is that to finish porting everything that is in v6 (meaning the various kernel modifications), they would lock themselves down to a particular kernel version. They might have to redo the modification...
by felixka
Fri Apr 30, 2021 9:15 pm
Forum: Announcements
Topic: v6.49beta [testing] is released!
Replies: 171
Views: 90866

Re: v6.49beta [testing] is released!

*) rb4011 - fixed SFP+ port MTU setting after link state change; *) rb4011 - improved SFP+ port stability after boot-up; I can confirm that I can now reboot my router and have full MTU 1500 PPPoE internet without having to: Manually unplug and re-plug the GPON ONT SFP Manually fiddle with the MTU o...
by felixka
Thu Dec 03, 2020 10:13 pm
Forum: RouterOS beta
Topic: v7.1beta3 [development] is released!
Replies: 261
Views: 79863

Re: v7.1beta3 [development] is released!

Hope this will also stop the router crashing when you change the MTU of an interface. I appreciate your test reports as we seem to be having the same issues. I'm with Bell in Canada and they also use baby jumbo frames on a SFP ONT with PPPoE. So I see the same crashing and MTU issues you are seeing.