Community discussions

MikroTik App

Search found 235 matches

by smyers119
Tue Dec 19, 2023 12:26 am
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 265967

Re: v7.13 [stable] is released!

After upgrading to 7.12 and 7.13 there seems to be a bug preventing multicast packets coming in on zerotier. I use to have ospf running between hosts over zerotier link that no longer work. when doing a packet capture, the mikrotik does not receive ospf hellos but the other end does. Rulled out fire...
by smyers119
Tue Jun 27, 2023 6:30 am
Forum: General
Topic: option 43 with bluesocket AP
Replies: 2
Views: 435

Re: option 43 with bluesocket AP

You never say what your having a problem with, this is a pretty typical setup. What your trying to do is covered in the mikrotik documentation.
by smyers119
Sat Jun 17, 2023 4:59 pm
Forum: General
Topic: End customer vpls Internet connection from ISP
Replies: 2
Views: 422

Re: End customer vpls Internet connection from ISP

Explain more of what your trying to do. What you showed that the isp gave you, and what your doing in your config does not match up. Where is this vlan 990 coming from?
by smyers119
Thu Jun 15, 2023 6:35 am
Forum: RouterBOARD hardware
Topic: Mlag breaks access to switch *half Solved*
Replies: 15
Views: 5292

Re: Mlag breaks access to switch *half Solved*

Seems you all are being affected from this known bug: viewtopic.php?t=185237
by smyers119
Wed Jun 14, 2023 6:58 am
Forum: General
Topic: Quectel EC25-EUX and Mikrotik
Replies: 2
Views: 521

Re: Quectel EC25-EUX and Mikrotik

Same issue but with EC25 US Version
by smyers119
Wed Jun 14, 2023 4:27 am
Forum: Beginner Basics
Topic: IPv6 Firewall help [SOLVED]
Replies: 3
Views: 783

Re: IPv6 Firewall help [SOLVED]

Check here, this article has a good example for ipv6 firewall, it's geared for isp's but will work fine for your needs. https://www.rfc-editor.org/rfc/rfc4890
by smyers119
Wed Jun 14, 2023 4:20 am
Forum: Beginner Basics
Topic: IPv6 Firewall help [SOLVED]
Replies: 3
Views: 783

Re: IPv6 Firewall help [SOLVED]

If you want to filter icmpv6 then follow this RFC https://www.rfc-editor.org/rfc/rfc4890
by smyers119
Thu Nov 10, 2022 7:15 pm
Forum: General
Topic: using Zerotier to access my entire network [SOLVED]
Replies: 2
Views: 823

Re: using Zerotier to access my entire network [SOLVED]

Think of zerotier like connecting your device to a l2 switch. so if you connect your router to that l2 switch as long as you have routing and the firewall done correctly you can access whatever you need to. your not going to find a big speed difference between the two..
by smyers119
Thu Nov 10, 2022 1:46 pm
Forum: General
Topic: Feature Request to help Iranian
Replies: 4
Views: 1956

Re: Feature Request to help Iranian

have you tried a ssh socks proxy?
by smyers119
Thu Nov 10, 2022 1:42 pm
Forum: General
Topic: I have one way audio issue. Old PBX Panasonic
Replies: 4
Views: 443

Re: I have one way audio issue. Old PBX Panasonic

did you turn SIP helper on/off? That's usually the first thing to try here. I keep all conntrack helpers off so it's less code packets need to be evaluated for which = less cpu
by smyers119
Thu Nov 10, 2022 12:40 am
Forum: Forwarding Protocols
Topic: Route by MAC address on ROS V7.6
Replies: 7
Views: 2316

Re: Route by MAC address on ROS V7.6

you have two isp's coming in on the same interface??
by smyers119
Wed Nov 09, 2022 7:08 pm
Forum: General
Topic: bufferbloat.. again. Help please
Replies: 13
Views: 1518

Re: bufferbloat.. again. Help please

rx pauses on both interfaces watching to tv-s. pfifo should be configured on these interfaces? how big the value should be for start? pfifo starts off at 50. I would double it until there is no pause frames, then drop it by a quarter until there is pause frames. Then you'll have your ideal bucket s...
by smyers119
Wed Nov 09, 2022 6:32 pm
Forum: General
Topic: bufferbloat.. again. Help please
Replies: 13
Views: 1518

Re: bufferbloat.. again. Help please

i see RX pauses only. If i turn off the FC and turn on the HWO, i see RX overflows on uplink
rx pauses on which interface?
by smyers119
Wed Nov 09, 2022 6:31 pm
Forum: General
Topic: bufferbloat.. again. Help please
Replies: 13
Views: 1518

Re: bufferbloat.. again. Help please

I would try and use the pfifo queue and keep upping the bucket size until you get rid of the pause frames.
by smyers119
Wed Nov 09, 2022 6:22 pm
Forum: RouterBOARD hardware
Topic: -48V and AC power supplies in the same router?
Replies: 4
Views: 703

Re: -48V and AC power supplies in the same router?

It show's that combination in the brochure, and even mentions that specific combination in the product description. Did you try it and are having problems?
by smyers119
Wed Nov 09, 2022 5:53 pm
Forum: General
Topic: bufferbloat.. again. Help please
Replies: 13
Views: 1518

Re: bufferbloat.. again. Help please

are you seeing drops/errors on the 100mbps interfaces??
by smyers119
Wed Nov 09, 2022 5:45 pm
Forum: General
Topic: bufferbloat.. again. Help please
Replies: 13
Views: 1518

Re: bufferbloat.. again. Help please

any of the interface queue's should not effect fastrack to anything but that interface
by smyers119
Wed Nov 09, 2022 5:41 pm
Forum: General
Topic: bufferbloat.. again. Help please
Replies: 13
Views: 1518

Re: bufferbloat.. again. Help please

the hardware queues's aka ring buffers work with fastrack. and holds about a 100packets.
by smyers119
Wed Nov 09, 2022 4:46 pm
Forum: General
Topic: bufferbloat.. again. Help please
Replies: 13
Views: 1518

Re: bufferbloat.. again. Help please

Are you running any qos? have you tried turning on the basic queueing for the 100mbps interfaces / bridges?
by smyers119
Mon Nov 07, 2022 11:15 pm
Forum: General
Topic: Formatted Syslog Output [SOLVED]
Replies: 4
Views: 1507

Re: Formatted Syslog Output [SOLVED]

by smyers119
Mon Nov 07, 2022 11:13 pm
Forum: General
Topic: Logging prefix is a mess SUP-105353 SUP-144261
Replies: 34
Views: 10494

Re: Logging prefix is a mess

mikrotik already has a checkbox to enable rfc3164 compatibility.
by smyers119
Mon Nov 07, 2022 10:53 pm
Forum: General
Topic: NetMap Configuration Issue, Need to verify it [SOLVED]
Replies: 7
Views: 1411

Re: NetMap Configuration Issue, Need to verify it [SOLVED]

I've been ignoring this post because this is a good example of the XY problem , Instead of coming here with a problem needing solved, you came with a solution for a unknown problem that you can't make work. And as always with these types of posts you'll never get anywhere until you take a step back ...
by smyers119
Mon Nov 07, 2022 8:15 pm
Forum: Forwarding Protocols
Topic: BGP - VPN4 - RR and routers in RoS6 / 7 : BGP attribute replication problem
Replies: 3
Views: 1484

Re: BGP - VPN4 - RR and routers in RoS6 / 7 : BGP attribute replication problem

Just confirming you have referenced the current documentation and understand the changes that were made with route filters. it's "completely" different in v7.
by smyers119
Mon Nov 07, 2022 7:55 pm
Forum: Beginner Basics
Topic: PPPoE server working in IPv6
Replies: 1
Views: 275

Re: PPPoE server working in IPv6

Have you referenced the help documents?

https://help.mikrotik.com/docs/display/ROS/PPPoE
by smyers119
Mon Nov 07, 2022 7:10 pm
Forum: General
Topic: Formatted Syslog Output [SOLVED]
Replies: 4
Views: 1507

Re: Formatted Syslog Output [SOLVED]

there is also BSD syslog standard RFC3164 <--which mikrotik definitely supports (needs to be enabled)
by smyers119
Mon Nov 07, 2022 6:55 pm
Forum: General
Topic: Formatted Syslog Output [SOLVED]
Replies: 4
Views: 1507

Re: Formatted Syslog Output [SOLVED]

Syslog is a standard, and as such all messages no matter the vender should be in the same generalized format. See RFC 5424
by smyers119
Mon Nov 07, 2022 5:23 pm
Forum: General
Topic: Intermittent packet loss
Replies: 7
Views: 4836

Re: Intermittent packet loss

Any chance of a duplicate ip somewhere?
by smyers119
Mon Nov 07, 2022 2:35 pm
Forum: General
Topic: How to configure a network with VLANs, apartment building
Replies: 2
Views: 732

Re: How to configure a network with VLANs, apartment building

have you already referenced the official resources? if so what specifically do you need help with?
by smyers119
Mon Nov 07, 2022 2:30 pm
Forum: Beginner Basics
Topic: RB750Gr3 - Small ISP setup [SOLVED]
Replies: 2
Views: 749

Re: RB750Gr3 - Small ISP setup [SOLVED]

My ISP router would be connected to ETH1 and each subsequent firewall representing a separate customer would be connected to the next available port, meaning Firewall 1 would go to ETH2, Firewall 2 would go to ETH3, etc.. Each firewall would have its own dedicated public IP address from my /27 ISP ...
by smyers119
Fri Oct 28, 2022 5:43 pm
Forum: Forwarding Protocols
Topic: MPLS redundancy help
Replies: 2
Views: 1325

Re: MPLS redundancy help

Why did you pick MPLS? Is MPLS already used in this network? What features from MPLS are you hoping to use to fix your problem, which you have done a horrible job of describing? My interpretation of the problem: Connect two networks together in a redundant fashion using a layer 3 protocol. Am i right?
by smyers119
Thu Oct 27, 2022 10:46 pm
Forum: General
Topic: VXLAN inside L2TP+IPSec
Replies: 4
Views: 1255

Re: VXLAN inside L2TP+IPSec

Well seems ipsec/l2tp/vxlan = 50Mb, and wireguard/vxlan = 70Mb.

Last thing to try is ipsec/gre/vxlan.

then pick whatever is the fastest.
by smyers119
Thu Oct 27, 2022 10:35 pm
Forum: General
Topic: IPsec VPN tunnel established but no communication [SOLVED]
Replies: 6
Views: 2322

Re: IPsec VPN tunnel established but no communication [SOLVED]

Hi Sob, thanks for the reply. Mikrotik-1: [admin@MikroTik] > ip firewall nat print detail Flags: X - disabled, I - invalid, D - dynamic 1 chain=srcnat action=accept src-address=192.168.55.0 dst-address=172.29.20.0/24 log=no log-prefix="" 2 ;;; default configuration chain=srcnat action=mas...
by smyers119
Thu Oct 27, 2022 10:34 pm
Forum: General
Topic: IPsec VPN tunnel established but no communication [SOLVED]
Replies: 6
Views: 2322

Re: IPsec VPN tunnel established but no communication [SOLVED]

This problem is well documenteds in the already available resources
by smyers119
Thu Oct 27, 2022 9:51 pm
Forum: General
Topic: Configuration deployment to a bunch of Mikrotik routers
Replies: 4
Views: 717

Re: Configuration deployment to a bunch of Mikrotik routers

you can look at ansible. same thing as you stated but they dumb the scripting down.
by smyers119
Thu Oct 27, 2022 9:25 pm
Forum: Forwarding Protocols
Topic: ROS Switching backup/active interface
Replies: 1
Views: 1299

Re: ROS Switching backup/active interface

Flex link is still a layer 2 redundancy. I thought you don't have layer 2 control.
by smyers119
Thu Oct 27, 2022 9:06 am
Forum: Scripting
Topic: Can a Tik be used to monitor SFP RX power and create alerts when rx pwr dies?
Replies: 18
Views: 2112

Re: Can a Tik be used to monitor SFP RX power and create alerts when rx pwr dies?

What if you used this or this or this. It's made to receive the correct wavelengths.
by smyers119
Thu Oct 27, 2022 3:06 am
Forum: Beginner Basics
Topic: Firewall seems inactive
Replies: 3
Views: 489

Re: Firewall seems inactive

See this thread for helpful firewall learning links from me and @anav.
by smyers119
Thu Oct 27, 2022 3:05 am
Forum: Beginner Basics
Topic: Firewall seems inactive
Replies: 3
Views: 489

Re: Firewall seems inactive

your source port is never going to be 53 when your doing a dns lookup, therefore it makes sense those 2 bottom rules did not work. and for the first rule the input chain would not be consulted on traffic going through the router.
by smyers119
Wed Oct 26, 2022 11:06 pm
Forum: RouterOS beta
Topic: BGP ROUTER OS 7 community
Replies: 1
Views: 2917

Re: BGP ROUTER OS 7 community

have you reviewed the readily availably docs? Route Filtering had a big logic change from v6 to v7.
by smyers119
Wed Oct 26, 2022 10:42 pm
Forum: Scripting
Topic: Can a Tik be used to monitor SFP RX power and create alerts when rx pwr dies?
Replies: 18
Views: 2112

Re: Can a Tik be used to monitor SFP RX power and create alerts when rx pwr dies?

I want to provide instantaneous response time to any fault wiithin the main interconnecting cables between buildings in the site..., Do you control the devices between the buiildings? If so you can set up snmp monitoring between all the devices and achieve the same result. I personally do not think...
by smyers119
Wed Oct 26, 2022 11:35 am
Forum: General
Topic: Is there any reasoning to pick VxLAN vs VPLS in this config?
Replies: 2
Views: 736

Re: Is there any reasoning to pick VxLAN vs VPLS in this config?

IPSEC/GRE/VXLAN seems like a lot of overhead as well, but it doesn't look like mikrotik supports layer 2 gre. what kind of problems are you having with eoip? I guess if I was having problems with EOIP my next thing to try would be Vxlan as well.
by smyers119
Wed Oct 26, 2022 7:22 am
Forum: General
Topic: Is there any reasoning to pick VxLAN vs VPLS in this config?
Replies: 2
Views: 736

Re: Is there any reasoning to pick VxLAN vs VPLS in this config?

Do you have a MPLS backbone between the two datacenters? If not then why is VPLS even a option? Seems like a lot of overhead for a simple p2p vpn.
by smyers119
Wed Oct 26, 2022 5:55 am
Forum: General
Topic: Roll back to v6.?
Replies: 8
Views: 679

Re: Roll back to v6.?

Probably should of researched the answer to that question before you switched in the first place.
by smyers119
Wed Oct 26, 2022 12:22 am
Forum: The Dude
Topic: Can you set Custom Field 1 value from an oid?
Replies: 1
Views: 1946

Re: Can you set Custom Field 1 value from an oid?

sounds like something you could easily automate with anisble or the likes.
by smyers119
Wed Oct 26, 2022 12:20 am
Forum: General
Topic: Forward several websites to proxy and not ISP
Replies: 1
Views: 385

Re: Forward several websites to proxy and not ISP

if you control dns in this scenario, just have the dns point to your internal proxy for those websites listed.
by smyers119
Wed Oct 26, 2022 12:13 am
Forum: General
Topic: VRRP on VLAN inside EOIP Tunnel
Replies: 4
Views: 564

Re: VRRP on VLAN inside EOIP Tunnel

Maybe a diagram of what your trying to accomplish will help us understand what your trying to do.
by smyers119
Wed Oct 26, 2022 12:04 am
Forum: General
Topic: Teams calls audi/video drops out periodically
Replies: 2
Views: 446

Re: Teams calls audi/video drops out periodically

If the SIP helper ALG is on turn it off, and retest. if it's off then turn it on and retest.
by smyers119
Tue Oct 25, 2022 11:46 pm
Forum: Forwarding Protocols
Topic: How is Higher Admin Distance Preferred [SOLVED]
Replies: 2
Views: 1706

Re: How is Higher Admin Distance Preferred [SOLVED]

Not enough information. :shock:
by smyers119
Tue Oct 25, 2022 11:06 pm
Forum: General
Topic: Two networks thru Layer 2 that doesn't allow vlans
Replies: 1
Views: 266

Re: Two networks thru Layer 2 that doesn't allow vlans

You really have not given us enough information to formulate a helpful response. But in general I would introduce you to the "router", the router was created from the soul need of connecting layer 2 networks together.
by smyers119
Tue Oct 25, 2022 10:17 pm
Forum: General
Topic: Forward Chain Firewall Rules
Replies: 2
Views: 341

Re: Forward Chain Firewall Rules

To understand why you need to understand how the firewall works. you can use the already available to you help documents from mikrotik to find the answer and pay special attention to here.
by smyers119
Tue Oct 25, 2022 7:39 pm
Forum: General
Topic: Router OS and Zerotier Bridges
Replies: 2
Views: 456

Re: Router OS and Zerotier Bridges

post your config. sounds like you've done a lot of wrong stuff. there is no nat or port forwarding involved for zerotier. If you have default firewall rules the easiest way to get this to work would be to add zerotier1 (or whatever you named you zerotier interface) to the LAN interface list.
by smyers119
Mon Oct 24, 2022 3:37 pm
Forum: RouterBOARD hardware
Topic: Stability of pwr-line support? Why not advertised on product page?
Replies: 28
Views: 2316

Re: Stability of pwr-line support? Why not advertised on product page?

Hello, is the pwr-line feature of the hAP lite stable? I'm wondering because I could not find this feature on the product page https://mikrotik.com/product/RB941-2nD-TC . The documentation was not enlightening either https://help.mikrotik.com/docs/display/ROS/PWR+Line . Thanks & best Quote from...
by smyers119
Mon Oct 24, 2022 2:16 am
Forum: General
Topic: Asymmetric and slow throughput
Replies: 3
Views: 758

Re: Asymmetric and slow throughput

first thing i would do is confirm whatever device I am testing from is actually able to create 10Gbps of packets to begin with. Maybe test on a loopbak? or more preferably isolate 2 hosts on 1 switch and test between them Next I would check my STP settings, you have a lot of duplicate pathways betwe...
by smyers119
Sat Oct 22, 2022 1:56 am
Forum: General
Topic: IPsec tunnel via 2nd ISP/WAN
Replies: 4
Views: 1061

Re: IPsec tunnel via 2nd ISP/WAN

Please make sure search current help documents so your not asking questions already answered.

https://help.mikrotik.com/docs/display/ ... figuration
by smyers119
Sat Oct 22, 2022 1:51 am
Forum: General
Topic: IPsec hardware encryption
Replies: 5
Views: 1378

Re: IPsec hardware encryption

please refer to this table

if you use a compatible encryption algorithm and hash then it will be offloaded, if you don't then it won't be.
by smyers119
Sat Oct 22, 2022 1:02 am
Forum: Beginner Basics
Topic: Wireguard Setup Assistance
Replies: 5
Views: 553

Re: Wireguard Setup Assistance

AllowedIPs= 0.0.0.0/24
This means the only allowed ips are 0.0.0.0-0.0.0.255

I doubt that's what you actually meant to restrict it to, as that will not match anything
by smyers119
Sat Oct 22, 2022 12:57 am
Forum: SwOS
Topic: VLAN packets in Wireshark?
Replies: 3
Views: 2688

Re: VLAN packets in Wireshark?

To understand what's going on with this packet you need to understand basic networking.

Here is a video that will hopefully help you, if you still have questions please ask for clarification. (I didn't actually watch it myself)
https://youtu.be/cn8Zxh9bPio
by smyers119
Fri Oct 21, 2022 9:24 am
Forum: General
Topic: STP Help
Replies: 1
Views: 371

Re: STP Help

by smyers119
Tue Oct 18, 2022 6:03 pm
Forum: General
Topic: Substitue Cisco CPE device with Mikrotik
Replies: 2
Views: 381

Re: Substitue Cisco CPE device with Mikrotik

Looking at this further vrf might be easier. Just create a voice vrf and add both eth4.1558 and vlan 58 to the vrf ip vrf add name=voice interfaces=[interfaces] place-before=0 then create your vrf route (EDITED wrong command before) ip route add dst-address=0.0.0.0/0 gateway=10.11.12.19@voice routin...
by smyers119
Tue Oct 18, 2022 4:43 pm
Forum: General
Topic: Substitue Cisco CPE device with Mikrotik
Replies: 2
Views: 381

Re: Substitue Cisco CPE device with Mikrotik

You can accompish the same thing using simple policy based routing in mikrotik. Although with the way you obfuscated ip's both private and public, is the worst way you could possible do, makes it 10x harder to try and follow along and offer help. Please fix if you require further help. https://help....
by smyers119
Wed Jul 27, 2022 5:48 am
Forum: General
Topic: NO OSPF NETWORKS IN VERSION 7
Replies: 1
Views: 581

Re: NO OSPF NETWORKS IN VERSION 7

v7 commands are documented here.
by smyers119
Wed May 04, 2022 7:09 am
Forum: General
Topic: Precision Time Protocol over IPsec tunnel (PTP IEEE 1588)
Replies: 2
Views: 687

Re: Precision Time Protocol over IPsec tunnel (PTP IEEE 1588)

ptp communicates using multicast. ptp is not meant to span across geographic locations. This is against best practice and you are not going to have good results. "care must be taken when extending PTP. Varying latency across a WAN can compromise PTP accuracy as the PTP mean path delay is consta...
by smyers119
Wed May 04, 2022 7:00 am
Forum: General
Topic: dhcp server sending host-name
Replies: 2
Views: 752

Re: dhcp server sending host-name

"This option is only honored if the hostname for the client machine is not set."
by smyers119
Wed May 04, 2022 6:35 am
Forum: Forwarding Protocols
Topic: Route filter ROS7 OSPF
Replies: 1
Views: 682

Re: Route filter ROS7 OSPF

create another instance, filter ospf-in redistribute ospf from first instance
by smyers119
Wed May 04, 2022 4:50 am
Forum: Scripting
Topic: Ruteo IPv6 / IPv6 Routing
Replies: 2
Views: 799

Re: Ruteo IPv6 / IPv6 Routing

You currently route ipv4 right? It's the same concept. What are you having an issue with?
by smyers119
Wed May 04, 2022 4:49 am
Forum: Beginner Basics
Topic: Route public /24 ip block to clients and no nat
Replies: 3
Views: 715

Re: Route public /24 ip block to clients and no nat

Yes the routers can route.
by smyers119
Thu Apr 28, 2022 8:12 pm
Forum: General
Topic: Platform for BGP & ~45 Gbps (only routing)
Replies: 1
Views: 384

Re: Platform for BGP & ~45 Gbps (only routing)

Did you not look at the test results, which gives you a pretty reliable dataset on what to expect

https://mikrotik.com/product/ccr2216_1g ... estresults
by smyers119
Tue Apr 19, 2022 5:48 pm
Forum: General
Topic: MLAG Issue - MLAG functionality flaps LACP system-id of secondary when primary reboots
Replies: 15
Views: 6364

Re: MLAG Issue - MLAG functionality flaps LACP system-id of secondary when primary reboots

What is your source of this "technically wrong" Because from what I see in the technical standard IEEE 802.1AX-2008, there should be a locally unique identifier That is correct. Locally unique means the SYSTEM ID is unique to the local L2 device. In the case of MLAG, the System is really ...
by smyers119
Tue Apr 19, 2022 12:58 am
Forum: General
Topic: MLAG Issue - MLAG functionality flaps LACP system-id of secondary when primary reboots
Replies: 15
Views: 6364

Re: MLAG Issue - MLAG functionality flaps LACP system-id of secondary when primary reboots

Problem 2. Somewhat related as it helps get you to a solution. You run different LACP system-IDs on every bonding port by default. This is technically wrong. The LACP system-ID should be the same for the entire chassis (And as such, the same for all MLAG peers). It bears no relevance to the underly...
by smyers119
Tue Apr 19, 2022 12:31 am
Forum: RouterOS beta
Topic: feature request: ECMP Settings
Replies: 5
Views: 2702

Re: feature request: ECMP Settings

So.... what do you think ECMP is?
by smyers119
Fri Apr 15, 2022 8:06 am
Forum: Wireless Networking
Topic: FirstNet (Public Safety)
Replies: 1
Views: 655

Re: FirstNet (Public Safety)

Quectel EC25-AF
by smyers119
Fri Apr 15, 2022 7:59 am
Forum: General
Topic: Bandwidth pinched through VxLAN tunnel
Replies: 12
Views: 2856

Re: Bandwidth pinched through VxLAN tunnel

Until you hear back about the speed problem are you interested in alternative solutions to your problem? There is plenty of other ways to extend your layer 2 network that may not take as much of a speed deficit as vxlan, assuming there's nothing you can do about that.
by smyers119
Tue Apr 12, 2022 8:43 pm
Forum: General
Topic: GRE Tunnel and NAT...
Replies: 33
Views: 7396

Re: GRE Tunnel and NAT...

So....based on what you posted You create a ipsec tunnel then created a gre tunnel MT ---------------ipsec tunnel -------------- CISCO \-------------GRE Tunnel -----------------/ I don't think that's what you meant to do. Usually the GRE tunnel is encapsulated with IPSEC so your data is secure. What...
by smyers119
Sun Apr 10, 2022 12:11 pm
Forum: Wireless Networking
Topic: T-Mobile Band 71 (600mhz) & Mikrotik Router?
Replies: 4
Views: 1585

Re: T-Mobile Band 71 (600mhz) & Mikrotik Router?

Quectel EC25-AF
by smyers119
Fri Apr 01, 2022 11:37 pm
Forum: General
Topic: Analysing a new connection and decision-based routing?
Replies: 16
Views: 1239

Re: Analysing a new connection and decision-based routing?

So it just seems Win10Home doesn't have this option at all. Even installing gpedit doesn't give all the full-featured QoS management. I did not know windows 10 home had those limitations. I guess I was wrong and your way as convuluted as it is, is the current best way to deal with this, while using...
by smyers119
Fri Apr 01, 2022 11:34 pm
Forum: Beginner Basics
Topic: Local DNS without FQDN
Replies: 3
Views: 776

Re: Local DNS without FQDN

The software is ClickOnce, this is a deployment technology that enables you to create self-updating Windows-based applications that can be installed and run with minimal user interaction. Applications that are deployed using ClickOnce technology are restricted to a set of permissions and actions th...
by smyers119
Fri Apr 01, 2022 4:26 am
Forum: Beginner Basics
Topic: Local DNS without FQDN
Replies: 3
Views: 776

Re: Local DNS without FQDN

Is this from a windows pc?
by smyers119
Fri Apr 01, 2022 3:34 am
Forum: General
Topic: Analysing a new connection and decision-based routing?
Replies: 16
Views: 1239

Re: Analysing a new connection and decision-based routing?

For desktop. Make a firewall address list of all viper desktops on windows 10 go to group policy editor computer --> windows settings --> Policy based QOS (right click and create new policy) Create a firewall rule that matches your dscp value you put in windows and route it where you want it to go.
by smyers119
Thu Mar 31, 2022 9:00 pm
Forum: General
Topic: Analysing a new connection and decision-based routing?
Replies: 16
Views: 1239

Re: Analysing a new connection and decision-based routing?

The changing destination Ip's have nothing to do with this problem. I don't think you understand how much your over complicating this. This is super easy. For the desktop all you need to do is go into advanced firewalling and change the dscp for that viper application. then you can route based on th...
by smyers119
Thu Mar 31, 2022 3:31 pm
Forum: General
Topic: Analysing a new connection and decision-based routing?
Replies: 16
Views: 1239

Re: Analysing a new connection and decision-based routing?

If Viber is the problem, do not use generic title... https://commons.erau.edu/jdfsl/vol12/iss2/11/ Since @extended made this 10x easier, now you know what to do. Firewall list with Viber users. PBR based on ports from article with source address of firewall list. (I would do a packet capture to con...
by smyers119
Thu Mar 31, 2022 3:20 pm
Forum: General
Topic: Analysing a new connection and decision-based routing?
Replies: 16
Views: 1239

Re: Analysing a new connection and decision-based routing?

If Viber is the problem, do not use generic title...

https://commons.erau.edu/jdfsl/vol12/iss2/11/
Excellent resource. Thank you for your contribution.
by smyers119
Thu Mar 31, 2022 2:04 pm
Forum: General
Topic: Analysing a new connection and decision-based routing?
Replies: 16
Views: 1239

Re: Analysing a new connection and decision-based routing?

I can think of at least two different ways to do this that would be better then your way. Let's get some more information. Is Viber running on phones or desktop?
by smyers119
Sat Mar 26, 2022 5:05 pm
Forum: General
Topic: Analysing a new connection and decision-based routing?
Replies: 16
Views: 1239

Re: Analysing a new connection and decision-based routing?

What problem are you trying to solve? guarantee there's a better way
by smyers119
Tue Mar 15, 2022 7:42 pm
Forum: General
Topic: Strange Issue with IPv6
Replies: 6
Views: 816

Re: Strange Issue with IPv6

WOW just WOW, Did you not even read my post? of course i did the normal troubleshooting how else do you think i zeroed in on the DHCP service. No I will not be posting my configs as the configuration is not the cause of the issue, I will quote Yet again I have Multiple CRS 328's configured the exac...
by smyers119
Tue Mar 15, 2022 2:43 pm
Forum: General
Topic: Strange Issue with IPv6
Replies: 6
Views: 816

Re: Strange Issue with IPv6

Before diving into this can you pick one of the latest stable firmwares (6.48.6, 6.49.4,7.1, 7.1.3) and then get back to us and let us know if it's still a problem.
note (make sure the firmware not just the softrware gets updated!)
by smyers119
Tue Mar 15, 2022 2:32 pm
Forum: The Dude
Topic: Dude monitor RegistrationTable unexpected outcome [SOLVED]
Replies: 3
Views: 4273

Re: Dude monitor RegistrationTable unexpected outcome [SOLVED]

Thanks, that is the trick. Strange this reverse logic. I was trying to find the syntax and/or explanation of the error text line but was not able to find anything. Doesn't have to be I was going off what you already had, below should also work. if(CountRegisteredClientsTable() > 210, "Number o...
by smyers119
Tue Mar 15, 2022 2:02 pm
Forum: The Dude
Topic: Dude monitor RegistrationTable unexpected outcome [SOLVED]
Replies: 3
Views: 4273

Re: Dude monitor RegistrationTable unexpected outcome [SOLVED]

Note: up=no value so it should be:

try:
if(CountRegisteredClientsTable() < 210, "", "Number of WIFI Clients above 210! ")
by smyers119
Tue Mar 15, 2022 10:42 am
Forum: Beginner Basics
Topic: CISCO to Mikrotik IPSEC Configuration Convert
Replies: 4
Views: 1162

Re: CISCO to Mikrotik IPSEC Configuration Convert

It seems some people connect their Mikrotik routers via this configurations that I don't access to them.
:? If you say so. Good luck
by smyers119
Tue Mar 15, 2022 10:19 am
Forum: Beginner Basics
Topic: CISCO to Mikrotik IPSEC Configuration Convert
Replies: 4
Views: 1162

Re: CISCO to Mikrotik IPSEC Configuration Convert

That's a dmvpn, which mikrotik does not support. The only non cisco device that can do that is vyos (that I am aware of)
by smyers119
Tue Mar 15, 2022 4:00 am
Forum: RouterOS beta
Topic: routing tables
Replies: 9
Views: 3413

Re: routing tables

I am on 7.1.3 and both ipv4/6 routes show up in winbox.
by smyers119
Mon Mar 14, 2022 8:32 pm
Forum: General
Topic: VPN Protocol suggested for large Hub and Spoke topology
Replies: 32
Views: 3383

Re: VPN Protocol suggested for large Hub and Spoke topology

zerotier is not available on all models and thus a cautionary offering. ;-)
True, but it can be spun up on, and ran off of almost any linux box. but then your adding complexity, cost and reliability issues.
by smyers119
Mon Mar 14, 2022 7:32 pm
Forum: General
Topic: VPN Protocol suggested for large Hub and Spoke topology
Replies: 32
Views: 3383

Re: VPN Protocol suggested for large Hub and Spoke topology

I would pay the money for zerotier if I were in your shoes. Zerotier can seamlessly use all links and does all the hard work behind the scenes. It's a SD-WAN type solution which is exactly what your looking for.
by smyers119
Sun Mar 13, 2022 11:28 pm
Forum: General
Topic: VPN Protocol suggested for large Hub and Spoke topology
Replies: 32
Views: 3383

Re: VPN Protocol suggested for large Hub and Spoke topology

That sounds like a management nightmare. Most people use dmvpn for such a use case. No matter what you do, your going to want to automate everything. if you can script then use your language of choice, if you can't then look into ansible. good luck, as that's a huge undertaking
by smyers119
Sun Mar 13, 2022 12:42 am
Forum: Scripting
Topic: fetch via 301 redirect
Replies: 12
Views: 6382

Re: fetch via 301 redirect

A 301 is a permanent redirect, why wouldn't you just point to the new url? cause its a script to download script in a case of global updates on many routers. I can change 301 redirect to any hosting I'll get at that time I dont know where download part will be at that time Again a 301 is for permin...
by smyers119
Sat Mar 12, 2022 11:17 pm
Forum: General
Topic: Sip Tracing
Replies: 4
Views: 496

Re: Sip Tracing

What problem are you trying to solve / troubleshoot
by smyers119
Sat Mar 12, 2022 5:59 am
Forum: General
Topic: Classify Layer 2 Traffic For Priority
Replies: 7
Views: 1652

Re: Classify Layer 2 Traffic For Priority

Just an update i found something similiar to what cisco offers in the documentation they may help you. This would only apply to the crs series. https://help.mikrotik.com/docs/pages/viewpage.action?pageId=103841835 priority-to-queue (priority-range:queue; Default: 0-15:0,1:1,2:2,3:3) Internal priorit...
by smyers119
Sat Mar 12, 2022 5:33 am
Forum: RouterOS beta
Topic: redistribute external route
Replies: 1
Views: 814

Re: redistribute external route

how are you sumarizing? with
/ip ospf area range
??

I am assuming your cisco is the ABR?


You have left out so much information it's impossible to help at this point.
by smyers119
Sat Mar 12, 2022 5:07 am
Forum: RouterBOARD hardware
Topic: CCR1009-7G-1C-1S+ very High CPU usage
Replies: 6
Views: 1555

Re: CCR1009-7G-1C-1S+ very High CPU usage

did you change the default password?
by smyers119
Sat Mar 12, 2022 2:39 am
Forum: Scripting
Topic: fetch via 301 redirect
Replies: 12
Views: 6382

Re: fetch via 301 redirect

A 301 is a permanent redirect, why wouldn't you just point to the new url?
by smyers119
Fri Mar 11, 2022 7:27 am
Forum: General
Topic: CRS212-1G-10S-1S+ SFP a Port down
Replies: 2
Views: 297

Re: CRS212-1G-10S-1S+ SFP a Port down

have you done any troubleshooting? Looked at the logs? If so what is in the logs?
by smyers119
Fri Mar 11, 2022 7:25 am
Forum: Scripting
Topic: Need DHCP Lease Script to limit agent-remote-id (CPE Mac) to 1 IP address
Replies: 4
Views: 905

Re: Need DHCP Lease Script to limit agent-remote-id (CPE Mac) to 1 IP address

so post what you figured out so far, and where your having problems.

The forums are here to help people, If your not looking for help, but instead looking for someone to do it for you then say so. I am sure there is plenty of people willing to do so for the right price.
by smyers119
Fri Mar 11, 2022 7:18 am
Forum: SwOS
Topic: LAG (Bonding) on CRS328-24P-4S+RM
Replies: 12
Views: 4276

Re: LAG (Bonding) on CRS328-24P-4S+RM

did you try a a static lag?
by smyers119
Fri Mar 11, 2022 7:14 am
Forum: General
Topic: Routing over WireGuard
Replies: 6
Views: 788

Re: Routing over WireGuard

windows computers by default block pings that are from different subnets.
by smyers119
Fri Jan 21, 2022 12:19 am
Forum: General
Topic: Files copied have different control sums
Replies: 6
Views: 1348

Re: Files copied have different control sums

Actually L3 checksum is unusable in this scenario. With IPv4 there is checksum, but covers only IP header without payload. In IPv6 checksum is completely omited, L4 is expected to cover it ... indeed TCP and UDP include checksums (UDP checksum in IPv4 is optional but in IPv6 it's mandatory), which ...
by smyers119
Thu Jan 20, 2022 11:31 pm
Forum: General
Topic: Files copied have different control sums
Replies: 6
Views: 1348

Re: Files copied have different control sums

Many L7 protocols rely on the network to properly calculate checksums while sending and receiving individual packets. ....... There is a slim chance that this is a network issue (yes it is possible, but not probable). there is multiple redundanct checks throughout the layers. On Layer 2 you have Cy...
by smyers119
Thu Jan 20, 2022 3:54 am
Forum: General
Topic: Files copied have different control sums
Replies: 6
Views: 1348

Re: Files copied have different control sums

This is not going to be a network problem. Assuming they are not using their own proprietary network stack the most likely source is going to be in layer 7.
by smyers119
Wed Jan 19, 2022 6:21 am
Forum: General
Topic: DHCP-pd for IPv6
Replies: 1
Views: 2257

Re: DHCP-pd for IPv6

On the edgerouter set the router-advert for that interface to advertise as the default route. Then mikrotik will learn it automatically. You should be using the link local address for the default route, that may be why your having a problem, but first way is better solution.
by smyers119
Wed Jan 19, 2022 5:37 am
Forum: RouterBOARD hardware
Topic: RB4011iGS port flapping (Both SFP and Ether)
Replies: 4
Views: 3431

Re: RB4011iGS port flapping (Both SFP and Ether)

version, firmware? try to make sure you are adding all pertinent information for people to troubleshoot.
by smyers119
Tue Jan 18, 2022 9:49 pm
Forum: The User Manager
Topic: v7.1.1 Feature request : routers address use /24
Replies: 6
Views: 4967

Re: v7.1.1 Feature request : routers address use /24

I have 400 APs that need to be connected to the RADIUS SERVER, do you want me to input the IP ADDRESS one by one?
Your the only guy I know that has fit 400 access points in a subnet with 255 ip's. Absolutely Amazing! What's your secret?
by smyers119
Mon Jan 17, 2022 7:22 pm
Forum: General
Topic: CCR2004-1G-12S+2XS CPU Usage High
Replies: 4
Views: 2187

Re: CCR2004-1G-12S+2XS CPU Usage High

you'll want to look into enabling fastpath as well https://wiki.mikrotik.com/wiki/Manual:Fast_Path EDIT: I just seen your using queue's, that's probably the source of your high cpu and limiting your growth. Per specs: Mode Configuration 1518 byte 512 byte 64 byte kpps Mbps kpps Mbps kpps Mbps Routin...
by smyers119
Mon Jan 17, 2022 7:17 pm
Forum: General
Topic: CCR2004-1G-12S+2XS CPU Usage High
Replies: 4
Views: 2187

Re: CCR2004-1G-12S+2XS CPU Usage High

Did you specifically set connection tracking off aka
/ip firewall connection tracking enabled no
if not, adding a firewall rule automatically turns it on.
by smyers119
Mon Jan 17, 2022 7:10 pm
Forum: Beginner Basics
Topic: Bonding
Replies: 1
Views: 815

Re: Bonding

you'll need vrrp with load-balancing (setup in a failover configuration) bundled together with a custom script.
by smyers119
Mon Jan 17, 2022 6:56 pm
Forum: Beginner Basics
Topic: SMB share folder contents not visible on Mac
Replies: 2
Views: 1691

Re: SMB share folder contents not visible on Mac

But when I do the similar process on a Mac
What is that process?

Is there any symbolic links on server or client?
by smyers119
Mon Jan 17, 2022 6:49 pm
Forum: The User Manager
Topic: v7.1.1 Feature request : routers address use /24
Replies: 6
Views: 4967

Re: v7.1.1 Feature request : routers address use /24

I think you need to look up what an ip address is, and then you may understand why that is not valid. specifically you will want to research the difference between a address and a subnet mask
by smyers119
Thu Jan 06, 2022 4:15 pm
Forum: Beginner Basics
Topic: Network Passthrough but block DHCP
Replies: 3
Views: 2751

Re: Network Passthrough but block DHCP

Good Day My customer has a network for their office PC's, Tills, Scales, and Camera systems (10.0.0.8/24) They have most of their Computers static IP, as well as their IP Cameras and NVR's. Their ISP Router supplies the DHCP for any clients with Dynamic IP. However their Camera Provider also has an...
by smyers119
Thu Jan 06, 2022 2:21 pm
Forum: General
Topic: route lookup implicit catch-all not working
Replies: 1
Views: 881

Re: route lookup implicit catch-all not working

That's not how read that article at all. Note this portion: By default (when no routing-mark values are used) all active routes are in the main table, and there is only one hidden implicit rule ("catch all" rule) that uses the main table for all destination lookups. The implicit catch all ...
by smyers119
Wed Jan 05, 2022 1:50 am
Forum: Forwarding Protocols
Topic: OSPF redistribute static works only same area? ROS 7.1.1 [SOLVED]
Replies: 2
Views: 2835

Re: OSPF redistribute static works only same area? ROS 7.1.1 [SOLVED]

Redistribution into an NSSA area creates a special type of link-state advertisement (LSA) known as type 7, which can only exist in an NSSA area.
by smyers119
Mon Jan 03, 2022 5:04 pm
Forum: General
Topic: Mikrotik on x86 sees only 1920Mb of RAM
Replies: 10
Views: 2738

Re: Mikrotik on x86 sees only 1920Mb of RAM

And you are correct, not only did I forget I did not know of that limitation. My first pc ran Windows 3.1, and I had no knowledge what RAM even was / or how it mattered back then. I guess nibble and minesweeper just wasn't that worried about it. I don't even remember when RAM became a issue, but it ...
by smyers119
Mon Jan 03, 2022 4:55 pm
Forum: General
Topic: Mikrotik on x86 sees only 1920Mb of RAM
Replies: 10
Views: 2738

Re: Mikrotik on x86 sees only 1920Mb of RAM

Now that we have 64 Bit systems we have forgotten how it use to be :) The 2 GB limit is a real limit for systems running 32 Bit as is a limitation from the 32 Bit address space. https://en.wikipedia.org/wiki/2_GB_limit So my assumption here is that PAE is not used thus limiting the memory to 2 GB h...
by smyers119
Mon Jan 03, 2022 4:02 pm
Forum: General
Topic: Mikrotik on x86 sees only 1920Mb of RAM
Replies: 10
Views: 2738

Re: Mikrotik on x86 sees only 1920Mb of RAM

CHR supports more RAM and also will work faster in any case. The recommendation is not silly at all. It's silly because the OP came here asking to get his current setup to work better, not asking for recommendations on upgrades. The "upgrading to a better system then it will work better" ...
by smyers119
Sun Jan 02, 2022 11:43 pm
Forum: General
Topic: Mikrotik on x86 sees only 1920Mb of RAM
Replies: 10
Views: 2738

Re: Mikrotik on x86 sees only 1920Mb of RAM

RouterOS 6 x86 is 32-bit only. Use CHR on KVM/VMware/HyperV for running 64-bit. 32bit can handle up to 4gb of ram. why the silly recommendation of going virtual? A 32bit machine can not visualize a 64bit machine. @OP, why leave the most important piece of information out... how much RAM is on the s...
by smyers119
Sun Jan 02, 2022 3:55 pm
Forum: RouterOS beta
Topic: IPv6 SLAAC
Replies: 6
Views: 10779

Re: IPv6 SLAAC

SLAAC works on layer 2, and does not cross routed interfaces. I am not aware of any helper or relay to bypass this limitation, but one may exist. usually people get prefix's delegated for their internal subnet's through a dhcpv6-server.
by smyers119
Sun Jan 02, 2022 1:54 pm
Forum: Beginner Basics
Topic: Enable 803.02ad on RB2011UiAS-RM
Replies: 16
Views: 2688

Re: Enable 803.02ad on RB2011UiAS-RM

As stated above you can NOT do this. (with bonding)
by smyers119
Sat Jan 01, 2022 4:23 am
Forum: General
Topic: Gateway check for /32 Ethernet point to point links - How to ?
Replies: 12
Views: 2667

Re: Gateway check for /32 Ethernet point to point links - How to ?

GNS3 is not able to simulate a layer 2 link loss. It's not a routeros issue.
by smyers119
Sat Jan 01, 2022 2:41 am
Forum: General
Topic: Gateway check for /32 Ethernet point to point links - How to ?
Replies: 12
Views: 2667

Re: Gateway check for /32 Ethernet point to point links - How to ?

I was able to test this in GNU3 with 7.2r1, and can confirm same results. I researched it on the GNU3 forums and apparently it is a known limitation that even though you disable a interface on 1 router the other router still see's the link as up/up.
by smyers119
Sat Jan 01, 2022 12:32 am
Forum: General
Topic: Gateway check for /32 Ethernet point to point links - How to ?
Replies: 12
Views: 2667

Re: Gateway check for /32 Ethernet point to point links - How to ?

I think that the problem does come from the emulation layer in EVE-NG : I suppose that the layer 1 physical Ethernet protocols are not emulated. (for exemple port speed negociation). This mean that when i disable the ether3 interface on R4, R1 ether3 interface does not see that the Ethernet link is...
by smyers119
Fri Dec 31, 2021 8:29 pm
Forum: General
Topic: Gateway check for /32 Ethernet point to point links - How to ?
Replies: 12
Views: 2667

Re: Gateway check for /32 Ethernet point to point links - How to ?

Confirmed this is against RFC: 5.3.12.3 When an Interface Fails or is Disabled If an interface fails or is disabled a router MUST remove and stop advertising all routes in its forwarding database that make use of that interface. It MUST disable all static routes that make use of that interface. If o...
by smyers119
Fri Dec 31, 2021 8:27 pm
Forum: General
Topic: Gateway check for /32 Ethernet point to point links - How to ?
Replies: 12
Views: 2667

Re: Gateway check for /32 Ethernet point to point links - How to ?

I am going to research this, as I am pretty sure that shouldn't happen and may even be against RFC. That route should be invalid as soon as the interface goes up down. you should not need bfd.

(tested and confirmed that is the way it happens in cisco packet tracer)
by smyers119
Fri Dec 31, 2021 8:03 pm
Forum: General
Topic: Mikrotik DHCP Server over L3 links ---> Conflict!!! [SOLVED]
Replies: 6
Views: 3261

Re: Mikrotik DHCP Server over L3 links ---> Conflict!!! [SOLVED]

as a last note, it can cause problems using public ip's that you do not own in your network. You should only be using RFC1918 ip's in your network.
by smyers119
Fri Dec 31, 2021 8:00 pm
Forum: General
Topic: Mikrotik DHCP Server over L3 links ---> Conflict!!! [SOLVED]
Replies: 6
Views: 3261

Re: Mikrotik DHCP Server over L3 links ---> Conflict!!! [SOLVED]

I would still consider this a bug though as it shouldn't be arping for an ip that is not in a directly connected subnet (IMHO) it should only try icmp.
by smyers119
Fri Dec 31, 2021 7:51 pm
Forum: General
Topic: Mikrotik DHCP Server over L3 links ---> Conflict!!! [SOLVED]
Replies: 6
Views: 3261

Re: Mikrotik DHCP Server over L3 links ---> Conflict!!! [SOLVED]

If I remember correctly cisco enables proxy arp by default. So I suspected that was the issue. disabling it should solve your issue.
by smyers119
Fri Dec 31, 2021 6:52 pm
Forum: General
Topic: Gateway check for /32 Ethernet point to point links - How to ?
Replies: 12
Views: 2667

Re: Gateway check for /32 Ethernet point to point links - How to ?

can you post the route tables in both the failed state and normal state. and also your test configs would help as well.
by smyers119
Fri Dec 31, 2021 3:58 pm
Forum: SwOS
Topic: Restrict SNMP on SwOS?
Replies: 7
Views: 9519

Re: Restrict SNMP on SwOS?

:(

Is it only me who considers this to be a potential security risk, exposing some configuration of the router to every device on the network?
It's only a security risk if you configure it like a security risk
by smyers119
Fri Dec 31, 2021 3:52 pm
Forum: General
Topic: Zerotier very slow speeds
Replies: 45
Views: 16931

Re: Zerotier very slow speeds

I have no idea what those settings are doing on the MT. Remember I have not pushed any traffic yet from any other devices onto the virtual LAN. So its not a concern at the moment. I fully expect that the missing gap MUST be done at the zerotier network level not on my MT devices. For instance lets ...
by smyers119
Fri Dec 31, 2021 3:46 pm
Forum: SwOS
Topic: Restrict SNMP on SwOS?
Replies: 7
Views: 9519

Re: Restrict SNMP on SwOS?

According to the docs it only supports snmpv1.

https://help.mikrotik.com/docs/display/SWOS/SwOS

you may be able to use ACL's to restrict source ip's
by smyers119
Fri Dec 31, 2021 3:41 pm
Forum: Beginner Basics
Topic: basic routing sample 2 (simple) questions
Replies: 6
Views: 2186

Re: basic routing sample 2 (simple) questions

Your looking for a default route or "route of last resort"

/ip route add dst-address=0.0.0.0/0 gateway=1.2.3.1
by smyers119
Fri Dec 31, 2021 2:47 pm
Forum: Beginner Basics
Topic: Enable 803.02ad on RB2011UiAS-RM
Replies: 16
Views: 2688

Re: Enable 803.02ad on RB2011UiAS-RM

....you don't have any config on mikrotik for bonded interfaces.
by smyers119
Fri Dec 31, 2021 2:37 pm
Forum: General
Topic: Zerotier very slow speeds
Replies: 45
Views: 16931

Re: Zerotier very slow speeds

I am thinking I need to go to ZT advanced settings and put in a route. Destination is 0.0.0.0/0 via ZT IP address of the Server ROUTER. However that will send any traffic on the ZT virtual LAN from any other node/device NOT JUST the ServerClient device and its specific subnet traffic to the Server ...
by smyers119
Fri Dec 31, 2021 2:18 pm
Forum: General
Topic: Mikrotik DHCP Server over L3 links ---> Conflict!!! [SOLVED]
Replies: 6
Views: 3261

Re: Mikrotik DHCP Server over L3 links ---> Conflict!!! [SOLVED]

conflict detection sends out a icmp and arp and if it receives a response from either one labels it as a conflict. I would run a packet capture when this happens and find out who is responding,
by smyers119
Fri Dec 31, 2021 2:04 pm
Forum: General
Topic: Zerotier very slow speeds
Replies: 45
Views: 16931

Re: Zerotier very slow speeds

I am thinking I need to go to ZT advanced settings and put in a route. Destination is 0.0.0.0/0 via ZT IP address of the Server ROUTER. However that will send any traffic on the ZT virtual LAN from any other node/device NOT JUST the ServerClient device and its specific subnet traffic to the Server ...
by smyers119
Fri Dec 31, 2021 4:02 am
Forum: General
Topic: Zerotier very slow speeds
Replies: 45
Views: 16931

Re: Zerotier very slow speeds

well, it's definitely not Zerotier then. what's your RouterOS?


My test topology:

PC -->Microtik<-zerotier->opnsense in cloud-->internet

results: (maxed my upload speed)
speedtestzt.PNG
7.1.1 RB4011
by smyers119
Fri Dec 31, 2021 3:38 am
Forum: General
Topic: Zerotier very slow speeds
Replies: 45
Views: 16931

Re: Zerotier very slow speeds

@smyers119 is there a way to test speed only to my mikrotik and not the NAS ? wireguard performance is not that better either. i think something's wrong with the router.. did you test your tunnel? My test topology: PC -->Microtik<-zerotier->opnsense in cloud-->internet results: (maxed my upload spe...
by smyers119
Fri Dec 31, 2021 3:28 am
Forum: General
Topic: Zerotier very slow speeds
Replies: 45
Views: 16931

Re: Zerotier very slow speeds

That sounds all MT and NO ZT for setup. It wont be ip addresses it will be a subnet. No need to mangle, source address is the subnet but will use Table and Route rule. But how to get this subnet via zerotier (from client router) to server Router and to the server routers internet. I know how to man...
by smyers119
Fri Dec 31, 2021 3:16 am
Forum: General
Topic: Zerotier very slow speeds
Replies: 45
Views: 16931

Re: Zerotier very slow speeds

smyers, how do I connect a subnet on one MT router (acting as a client node), to go out the WANIP of another MT router (acting as a server node) through zerotier, That is what I have not been able to figure out? Then I will test that vs a wireguard connection I already have doing the same thing. Th...
by smyers119
Fri Dec 31, 2021 1:31 am
Forum: General
Topic: Zerotier very slow speeds
Replies: 45
Views: 16931

Re: Zerotier very slow speeds

Let me see if i can try and speed test my zerotier tunnel and get back to you, (not that it helps since i am using rb4011)
by smyers119
Fri Dec 31, 2021 1:30 am
Forum: General
Topic: Zerotier very slow speeds
Replies: 45
Views: 16931

Re: Zerotier very slow speeds

I don't see anything that would cause a speed problem in your config. Zerotier support is still in the works, so maybe it's something on mikrotik's end. The only thing I have done different is limit the zerotier instance to running on my WAN, and instead of making specific firewall rules for zerotie...
by smyers119
Fri Dec 31, 2021 1:13 am
Forum: General
Topic: Zerotier very slow speeds
Replies: 45
Views: 16931

Re: Zerotier very slow speeds

Can you post your sanitized config.
by smyers119
Fri Dec 31, 2021 1:06 am
Forum: General
Topic: Zerotier very slow speeds
Replies: 45
Views: 16931

Re: Zerotier very slow speeds

Zerotier goes through the ZT network, if your physical location is remote, and there are no ZT root servers nearby, it can be slower. You can read how it works here: https://docs.zerotier.com/zerotier/manual A wants to send a packet to B, but since it has no direct path it sends it upstream to R (a...
by smyers119
Thu Dec 30, 2021 2:45 pm
Forum: Beginner Basics
Topic: Is L2TP VPN safe for internet traffic?
Replies: 35
Views: 7263

Re: Is L2TP VPN safe for internet traffic?

1. no your router is not secure

2. l2tp does not provide encryption, so no it is not secure. it is usually tunneled through ipsec. wireguard would be easier then openvpn.
by smyers119
Thu Dec 30, 2021 1:19 am
Forum: RouterOS beta
Topic: IPv6 Link Local Address on IPIPv6 tunnel
Replies: 2
Views: 1947

Re: IPv6 Link Local Address on IPIPv6 tunnel

when you see a ff:fe, that means that it's EUI64 generated from mac. Since this is a layer 3 tunnel it doesn't appear a mac address is generated (I checked by creating a tunnel and using /interface/print) Though it is creating the ipv6 address based off this mac FE:FD:00:00:00:00 (if my math is corr...
by smyers119
Wed Dec 29, 2021 6:28 pm
Forum: General
Topic: Classify Layer 2 Traffic For Priority
Replies: 7
Views: 1652

Re: Classify Layer 2 Traffic For Priority

For some reason routeros does not support something so simple. But you should be able to do something similiar. under bridge filter you can mark the packets, then create a queue that prioritizes those marks. This will probably take some experienting to figure out.
by smyers119
Tue Dec 28, 2021 12:06 am
Forum: RouterOS beta
Topic: Webfig unavailable after update
Replies: 6
Views: 3941

Re: Webfig unavailable after update

I am having the same problem with Webfig going to the terminal after login and giving a 404 error if I click on the Webfig button. Recent changes to my RB3011: - Update to v7.1.1 - Reset the Router - Imported .rsc config file. - Created a skin without the Quick Set button (I would assume that cause...
by smyers119
Mon Dec 27, 2021 11:52 pm
Forum: Beginner Basics
Topic: NTP stuck on Waiting....
Replies: 91
Views: 25179

Re: NTP stuck on Waiting....

remove this rule: add action=drop chain=input comment="Drop everything else" Tried this, but no change. The only other difference I see is that my estab/related rule also allows untracked, which is the default config. Try adding that to your estab/related rule. Also, no change here. I am ...
by smyers119
Mon Dec 27, 2021 11:48 pm
Forum: Beginner Basics
Topic: NTP stuck on Waiting....
Replies: 91
Views: 25179

Re: NTP stuck on Waiting....

Why should he drop that rule? He has all the rules prior to that allowing traffic from the LAN side. He even doesnt need the specific NTP rules because above that rule he has the one that allows all VLANs, FULL ACCESS to the router and all BASE...... your trying to troubleshoot a symptom of the pro...
by smyers119
Mon Dec 27, 2021 11:42 pm
Forum: Beginner Basics
Topic: NTP stuck on Waiting....
Replies: 91
Views: 25179

Re: NTP stuck on Waiting....

The only other difference I see is that my estab/related rule also allows untracked, which is the default config. Try adding that to your estab/related rule.
by smyers119
Mon Dec 27, 2021 11:19 pm
Forum: Beginner Basics
Topic: NTP stuck on Waiting....
Replies: 91
Views: 25179

Re: NTP stuck on Waiting....

remove this rule:

add action=drop chain=input comment="Drop everything else"
by smyers119
Mon Dec 27, 2021 11:14 pm
Forum: Beginner Basics
Topic: NTP stuck on Waiting....
Replies: 91
Views: 25179

Re: NTP stuck on Waiting....

let me browse threw your firewall. stratum 16 means it's not synchronizing.
by smyers119
Mon Dec 27, 2021 11:02 pm
Forum: Beginner Basics
Topic: NTP stuck on Waiting....
Replies: 91
Views: 25179

Re: NTP stuck on Waiting....

what does /system/ntp monitor-peers show?
by smyers119
Mon Dec 27, 2021 10:16 pm
Forum: Beginner Basics
Topic: NTP stuck on Waiting....
Replies: 91
Views: 25179

Re: NTP stuck on Waiting....

I am kind of disappointed I can't set it to pull multiple servers from the pool though
by smyers119
Mon Dec 27, 2021 10:15 pm
Forum: Beginner Basics
Topic: NTP stuck on Waiting....
Replies: 91
Views: 25179

Re: NTP stuck on Waiting....

I am not able to reproduce your problem. It should not be a firewall issue as you don't need to add any extra firewall rules. It would fall uinder estab/related traffic [admin@router1] /system/ntp/client> print enabled: yes mode: unicast servers: time.nist.gov freq-drift: 0 PPM status: synchronized ...
by smyers119
Sun Dec 26, 2021 5:29 pm
Forum: Beginner Basics
Topic: ZeroTier routes?
Replies: 2
Views: 1869

Re: ZeroTier routes?

Adding routes for mikrotik is covered in the help doc's , but I don't think that's what you actually want since the tik already knows about the network. You want to add a route in your zerotier network that points to your tik. If you can't figure out how to do that you may want to ask a zerotier for...
by smyers119
Sun Dec 26, 2021 5:21 pm
Forum: General
Topic: DHCP, ARP, WDS-Bridge
Replies: 2
Views: 963

Re: DHCP, ARP, WDS-Bridge

That sounds correct, your network can not communicate with the device directly, it needs to go through the repeater. So the repeater is the next layer 2 hop before it gets to the destination.
by smyers119
Thu Dec 23, 2021 9:37 pm
Forum: Announcements
Topic: v7.2rc1 is released!
Replies: 240
Views: 161265

Re: v7.2rc1 is released!

OSPF 100% broken after update.

Not seeing neighbors anymore.
Check if you use authentication ..
In my case this was the problem, neighbor is ros6
I just remove it .. for me this was not requirements (legacy config) so i did not do future tests
Thanks, no auth here.
by smyers119
Thu Dec 23, 2021 5:58 pm
Forum: Announcements
Topic: v7.2rc1 is released!
Replies: 240
Views: 161265

Re: v7.2rc1 is released!

I didn't have time to troubleshoot, but on upgrade ospf stopped working. Was unable to view any routes/nexthops from cli or winbox. downgrade to 7.1 fixed the problem.
by smyers119
Wed Dec 22, 2021 10:04 pm
Forum: General
Topic: Zerotier Uses
Replies: 6
Views: 1614

Re: Zerotier Uses

Easiest way to explain zerotier is it's a virtual managed switch. So the possibilities are limited to only your imagination. you can do all the above and then some. I have not had that good success incorporating mobile devices. (I don't have iphones to test just android)
by smyers119
Wed Dec 22, 2021 3:03 am
Forum: General
Topic: CRS328 POE No network
Replies: 1
Views: 873

Re: CRS328 POE No network

I had a similiar problem, upgrading firmware and factory resetting fixed it. In my case it happened after a power outage which i think corrupted the config. It was still reachable by mac on winbox.
by smyers119
Tue Dec 21, 2021 11:32 pm
Forum: General
Topic: SIP-Helper is not working
Replies: 2
Views: 912

Re: SIP-Helper is not working

SIP helper modules are best disabled. SBC is meant to be the outside device, it's the equivelent of a firewall for VOIP. If your filtering traffic going to the SBC I guess that means you don't have any remote-worker phones set up.
by smyers119
Fri Dec 17, 2021 8:15 pm
Forum: General
Topic: I consider ditch mikrotik
Replies: 6
Views: 1326

Re: I consider ditch mikrotik

As a mikrotik enthusiastic and network engineer since 2012 i have setup hundrends of clients with routerboards. I like mikrotik because it has all networking options to touch and configure. Well at 2020 i cant even make a simple pppoe bridge and some bugs which make some configurations to stop work...
by smyers119
Fri Dec 17, 2021 6:57 pm
Forum: General
Topic: Official Support wait times [SOLVED]
Replies: 21
Views: 3088

Re: Official Support wait times [SOLVED]

You are wasting your time, I do this for a living............. A BUG moron! Not YOUR BUGS!! The problem set describes the operational impact to your work due to the bug.......... That provides context to how the feature (singular) is NOT working and how it is preventing your configuration from work...
by smyers119
Fri Dec 17, 2021 5:54 pm
Forum: General
Topic: Official Support wait times [SOLVED]
Replies: 21
Views: 3088

Re: Official Support wait times [SOLVED]

Well the ref quoted does say "your issue" which is singular, not my fault you are illiterate and provided multiple issues on one ticket.
I know your trying to redeem yourself, but your just not there. Maybe next time.

I highlighted the important parts for you.
ticket.PNG
by smyers119
Fri Dec 17, 2021 5:34 pm
Forum: General
Topic: Official Support wait times [SOLVED]
Replies: 21
Views: 3088

Re: Official Support wait times [SOLVED]

The onus is on you to learn how to report issues, not for Normis' team to respond to each ticket and user etc.............. I think the whole point of "support" has eluded you. If there is any type of specific requirements/rule's they need to be told to the end user requesting support bef...
by smyers119
Fri Dec 17, 2021 5:21 pm
Forum: RouterOS beta
Topic: RB3011 7.1 and ZeroTier No discovery
Replies: 5
Views: 3871

Re: RB3011 7.1 and ZeroTier No discovery

(Moved Post) Here is an odd one I am chasing after. My test router at the shop has Zerotier 1.6.5 on it as the RB3011 is running 7.1rc4 The router we put at a the bosses brother's has Zerotier 1.6.6 on it, as the RRB3011 is running 7.1 Both have Zerotier bridged to the bridge The RB3011 with 7.1rc4...
by smyers119
Fri Dec 17, 2021 4:55 pm
Forum: General
Topic: Official Support wait times [SOLVED]
Replies: 21
Views: 3088

Re: Official Support wait times [SOLVED]

Each ticket is assigned a category and then handled by a specific specialist. You can't just dump all kinds of random issues into one complaint, this is why your ticket got stuck in the system. Please report each bug separately. Maybe pointing that out when it was first noticed would of been more p...
by smyers119
Fri Dec 17, 2021 2:33 am
Forum: RouterOS beta
Topic: ZeroTier added to RouterOS v7.1rc2
Replies: 335
Views: 310772

Re: ZeroTier added to RouterOS v7.1rc2

I had issues on the last beta and now again with 7.1 in that Zerotier on my RB3011 becomes unresponsive. Other devices on the same Zerotier network are still contactable. About every 5 days I need to disable the Zerotier interface on my RB3011 and re-enable it again. However my RB3011 is bridged to...
by smyers119
Thu Dec 16, 2021 9:21 pm
Forum: RouterOS beta
Topic: ZeroTier added to RouterOS v7.1rc2
Replies: 335
Views: 310772

Re: ZeroTier added to RouterOS v7.1rc2

Sometimes I can login via Zerotier and sometimes not. This is definitely a bug in Mikrotik ZeroTier. I consider this not reliable. There is still work to be done. I have not had one problem with zerotier. If your on the firewall rule in winbox then you are going to mess the rule up, as zerotier is ...
by smyers119
Thu Dec 16, 2021 9:01 pm
Forum: General
Topic: Official Support wait times [SOLVED]
Replies: 21
Views: 3088

Re: Official Support wait times [SOLVED]

Mention it here. Start a new thread.
Most likely someone encountered the issue as well.
Maybe some even know a work around already...
As you can see in the picture of the ticket, all the issue's started in the forums and went unanswered so they got upgraded to official support.
by smyers119
Thu Dec 16, 2021 8:01 pm
Forum: General
Topic: Official Support wait times [SOLVED]
Replies: 21
Views: 3088

Re: Official Support wait times [SOLVED]

I am not looking for a timeline of a fix, just an acknowledgment of the problem and whether they can reproduce it or if I need to provide more info / try some troubleshooting steps.
by smyers119
Thu Dec 16, 2021 7:05 pm
Forum: General
Topic: Official Support wait times [SOLVED]
Replies: 21
Views: 3088

Official Support wait times [SOLVED]

I am new to official support, It say's 3 business days, but obviously that's wishful thinking. Can someone experienced give me the average wait time for such a request.

Thanks,
tiksupticket.PNG
by smyers119
Wed Dec 15, 2021 10:32 am
Forum: General
Topic: Firewall "Established" rule allowing more than I'd expect.
Replies: 11
Views: 2789

Re: Firewall "Established" rule allowing more than I'd expect.

Reference this article, to hopefully help you better understand what's going on.

https://help.mikrotik.com/docs/display/ ... c+Concepts
by smyers119
Tue Dec 14, 2021 8:50 am
Forum: Beginner Basics
Topic: OpenVPN Connection
Replies: 4
Views: 2444

Re: OpenVPN Connection

do you have a firewall rule allowing the connection? post firewall config
by smyers119
Tue Dec 14, 2021 5:51 am
Forum: General
Topic: Firewall Newb needs help
Replies: 2
Views: 904

Re: Firewall Newb needs help

by smyers119
Tue Dec 14, 2021 5:36 am
Forum: General
Topic: DHCP options in two different tabs
Replies: 1
Views: 879

Re: DHCP options in two different tabs

DHCP Options tab

Is where you add your dhcp options.

DHCP Options set tab

is where you would group options together that are located in dhcp options..

Network/dhcp-options(-set)

Is where you add the options (or sets) you created to the subnet of your choosing.
by smyers119
Mon Dec 13, 2021 9:16 pm
Forum: Forwarding Protocols
Topic: OSPF error
Replies: 5
Views: 2813

Re: OSPF error

Are you stuck at ExStart on the state? I had this issue and did a rollback to get it working again. Created supout and reported it today.
I think OSPF still needs some love to get to a good state.
I have a rb4011 with ospf and ospfv3 running with no hickups.
by smyers119
Sun Dec 12, 2021 7:36 pm
Forum: Forwarding Protocols
Topic: OSPF error
Replies: 5
Views: 2813

Re: OSPF error

I don't see any error's in the log's you posted. How about posting the sanitized configs for the routers your trying to get connected as neighbors.
by smyers119
Sun Dec 12, 2021 7:29 pm
Forum: SwOS
Topic: HA with SwOS ?
Replies: 1
Views: 4545

Re: HA with SwOS ?

To be clear, I'm not asking about RouterOS (I simply dont need most of the RouterOS functionality, so prefer SwOS to keep it lean). What do you think your gaining by "keeping it lean" If you don't need most of the features then don't use them. MLAG is currently only supported in RouterOS,...
by smyers119
Sun Dec 12, 2021 1:16 pm
Forum: Beginner Basics
Topic: CAT6 mikrotiks [SOLVED]
Replies: 10
Views: 2524

Re: CAT6 mikrotiks [SOLVED]

I don't think it's unlikely that your third-grader may have picked up a lot of technical knowledge in passing. You can't expect the whole world that have that knowledge. One may hope that forums like this will spread some of that around. This single option is buried among 25 others, many of which a...
by smyers119
Sun Dec 12, 2021 12:57 pm
Forum: Beginner Basics
Topic: CAT6 mikrotiks [SOLVED]
Replies: 10
Views: 2524

Re: CAT6 mikrotiks [SOLVED]

The "switches" product page on Mikrotik's site currently lists 25 items, of which only one fits, and you're getting upset because the OP didn't find that 1:25 item, belittling him for missing the 4% solution? I'd say we should congratulate him if he did find it! I am not congratulating an...
by smyers119
Sun Dec 12, 2021 3:46 am
Forum: Beginner Basics
Topic: CAT6 mikrotiks [SOLVED]
Replies: 10
Views: 2524

Re: CAT6 mikrotiks [SOLVED]

Hello, I have a question about speeds on mikrotik switches, as i saw on the product pages, only 10gb ports are the sfp+ ones, so my question is if there's a mikrotik switch that can do 10gb with cat 6 on regular rj45? ... Did you even look? https://mikrotik.com/product/crs312_4c_8xg_rm .... And als...
by smyers119
Wed Dec 08, 2021 7:19 pm
Forum: General
Topic: download.mikrotik.com does not work via IPv6
Replies: 3
Views: 1210

Re: download.mikrotik.com does not work via IPv6

Tracing route to download.mikrotik.com [2a02:610:7501:1000::204] over a maximum of 30 hops: 1 <1 ms <1 ms <1 ms 2601:XXXX:XXXX:f06:c6ad:34ff:fef8:d6e0 2 7 ms 7 ms 7 ms 2001:558:4033:74::1 3 8 ms 8 ms 8 ms 2001:558:12:1fd::1 4 8 ms 8 ms 11 ms 2001:558:10:5d6::1 5 * * * Request timed out. 6 38 ms 31 ...
by smyers119
Tue Dec 07, 2021 8:27 pm
Forum: RouterOS beta
Topic: BGP + ECMP
Replies: 16
Views: 9410

Re: BGP + ECMP

On other venders you can increase "maximum-paths" 2, to enable ecmp. I was looking through the options in ROS CLI and could not find something similar.
by smyers119
Tue Dec 07, 2021 4:46 pm
Forum: General
Topic: Mixed /30 and /24 on same subnet
Replies: 18
Views: 3133

Re: Mixed /30 and /24 on same subnet

You are correct that is not how OSPF is supposed to work! But when a Cisco certified network consultant first adds 10.0.0.0/8 in OSPF network and then proceeds to add /30's within that ip range with OSPF interfaces network-type=point-to-point, It had me wondering if this was best network configurat...
by smyers119
Tue Dec 07, 2021 2:08 pm
Forum: RouterOS beta
Topic: OSPF not working on RouterOS v7.1 between 2 routers
Replies: 4
Views: 7870

Re: OSPF not working on RouterOS v7.1 between 2 routers

I am running ospf with no issues over here on 7.1 # dec/07/2021 07:05:32 by RouterOS 7.1 # software id = IZUY-SLWC # # model = RB4011iGS+ # serial number = /routing ospf instance add name=default router-id=10.172.255.1 /routing ospf area add instance=default name=default /routing ospf interface-temp...
by smyers119
Tue Dec 07, 2021 5:09 am
Forum: RouterOS beta
Topic: [ZEROTIER BUG]ARPING for public IP on LAN
Replies: 11
Views: 3437

Re: [ZEROTIER BUG]ARPING for public IP on LAN

You should open a ticket with Mikrotik with the supout.rif, does seem like a bug. Not sure how folks can help if so. I am not clear on bug reporting etiquite in this community, but according to this post, The forum is the correct place for beta releases. Is 7.1 still considered beta? https://forum....
by smyers119
Tue Dec 07, 2021 4:43 am
Forum: RouterOS beta
Topic: [ZEROTIER BUG]ARPING for public IP on LAN
Replies: 11
Views: 3437

Re: [ZEROTIER BUG]ARPING for public IP on LAN

See an ARP with a different IP isn't necessary "wrong" from L3 POV – multihoming. It's only wrong from a ROS "packet flow"/policy prospective. And, how the ZeroTier package approaches discovery on the ROS is not document by Mikrotik & ZT only has a high-level overview of how...
by smyers119
Tue Dec 07, 2021 4:08 am
Forum: RouterOS beta
Topic: [ZEROTIER BUG]ARPING for public IP on LAN
Replies: 11
Views: 3437

Re: [ZEROTIER BUG]ARPING for public IP on LAN

My router appears to be acting appropriate on the WAN [[REDACT]@router1] /tool/sniffer> packet/print detail 0 time=33.477 num=1 direction=rx src-mac=00:01:5C:92:AA:46 dst-mac=FF:FF:FF:FF:FF:FF interface=eth1 protocol=arp size=60 cpu=0 1 time=33.529 num=2 direction=tx src-mac=C4:AD:34:F8:D6:DF dst-ma...
by smyers119
Tue Dec 07, 2021 4:01 am
Forum: RouterOS beta
Topic: [ZEROTIER BUG]ARPING for public IP on LAN
Replies: 11
Views: 3437

Re: [ZEROTIER BUG]ARPING for public IP on LAN

Hi, I haven't tested for this with ZeroTier, but I know that outside of ZeroTier this type of issue can happen with regular RouterOS 6.x if you use an interface as the "gateway" instead of an IP in the case where an interface must be used. For instance you could use ether1 as a gateway fo...
by smyers119
Tue Dec 07, 2021 2:38 am
Forum: RouterOS beta
Topic: Does PIM work AT ALL on 7.1?
Replies: 12
Views: 6679

Re: Does PIM work AT ALL on 7.1?

What a joke. Shows green on the protocol status page, yet clearly isn't implemented! https://help.mikrotik.com/docs/display/ROS/v7+Routing+Protocol+Status That is a interesting link, curious how RIP could be working when you can't even add network statements. https://forum.mikrotik.com/viewtopic.ph...
by smyers119
Tue Dec 07, 2021 12:03 am
Forum: RouterOS beta
Topic: [ZEROTIER BUG]ARPING for public IP on LAN
Replies: 11
Views: 3437

Re: [ZEROTIER BUG]ARPING for public IP on LAN

Might want to also upgrade the firmware. That isn't at 7.1 from your picture. Not saying related, just noticed... I did notice seem ZeroTier seems aggressive, but hadn't studied it. So not sure what "normal" would like for it ;). ARP may one way it figures out it's paths, it's protocol is...
by smyers119
Mon Dec 06, 2021 9:52 pm
Forum: RouterOS beta
Topic: ZeroTier added to RouterOS v7.1rc2
Replies: 335
Views: 310772

Re: ZeroTier added to RouterOS v7.1rc2

@Normis

Please see this thread in reference to possible bug introduced when using zerotier.
viewtopic.php?t=180919

Also if someone else in this thread can confirm the problem, that would be great as well.
by smyers119
Mon Dec 06, 2021 2:33 pm
Forum: General
Topic: Mixed /30 and /24 on same subnet
Replies: 18
Views: 3133

Re: Mixed /30 and /24 on same subnet

Your putting to much faith in a person. ospf does not care whether you have 20 /30 routes or 1 /8 (or any other mask that summarizes the other ones) They do the same exact thing. I hate to tell you, but you can be cisco certified and still not know what your doing (especially at the ccna level), and...
by smyers119
Mon Dec 06, 2021 3:58 am
Forum: General
Topic: Only half bandwidth download with simple NAT setup?
Replies: 9
Views: 1290

Re: Only half bandwidth download with simple NAT setup?

try it without the last part
as below:
add action=fasttrack-connection chain=forward comment="fasttrack" connection-state=established,related
by smyers119
Mon Dec 06, 2021 3:40 am
Forum: General
Topic: Only half bandwidth download with simple NAT setup?
Replies: 9
Views: 1290

Re: Only half bandwidth download with simple NAT setup?

before estab/related on forward you need add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related hw-offload=yes you can also group tour estab/relate: add action=accept chain=forward comment=\ "defconf: accept established,related,...
by smyers119
Sun Dec 05, 2021 11:52 pm
Forum: Beginner Basics
Topic: Mikrotik failover script strange behavior
Replies: 18
Views: 3092

Re: Mikrotik failover script strange behavior

Thanks for your answer. it seems that you are correct. My guess is that ping somehow causes stack overflow, because the commands return value must be stored on stack. Modern C-like languages compare values on stack, they do not pop off the values into registers. Another thing is that I forgot to me...
by smyers119
Sun Dec 05, 2021 11:05 pm
Forum: Beginner Basics
Topic: Mikrotik failover script strange behavior
Replies: 18
Views: 3092

Re: Mikrotik failover script strange behavior

So it looks like you have some issues upstream, but nothing that would cause your problem. So it appears you only have a problem when this is coming from the router, but not through the router. Still leads me to believe some kind of table / memory limit / something is filling up in the router itself...
by smyers119
Sun Dec 05, 2021 10:14 pm
Forum: RouterOS beta
Topic: Webfig unavailable after update
Replies: 6
Views: 3941

Re: Webfig unavailable after update

That works fine... That's the page it brings me to after webfig error's out when I first login. Sorry if I wasn't clear on that.
by smyers119
Sun Dec 05, 2021 10:05 pm
Forum: RouterOS beta
Topic: Webfig unavailable after update
Replies: 6
Views: 3941

Re: Webfig unavailable after update

I Factory-Reset and updated my RB4011 from 6.49.1 to 7.1 I wasn't able to reproduce the Error. Did you try disabling the Web-Service and restarting the Router (/ip service set www disabled=yes) After the Reboot, try to re-enable the Web-Services and connecting to it. I just tried that and that did ...
by smyers119
Sun Dec 05, 2021 7:38 pm
Forum: General
Topic: Mixed /30 and /24 on same subnet
Replies: 18
Views: 3133

Re: Mixed /30 and /24 on same subnet

No that's not how ospf is suppose to works. If your going to go in and enable and disable routes then you need to go back to static routes. Without seeing the big picture that looks to be someone learning how to use ospf. and was making a network statement for every network until they realized they ...
by smyers119
Sun Dec 05, 2021 6:13 pm
Forum: General
Topic: Mixed /30 and /24 on same subnet
Replies: 18
Views: 3133

Re: Mixed /30 and /24 on same subnet

You only need the network statement once, why are you creating multiple /30 network statements in ospf when you already have it declared with the 1 /8?. MAke sure you summarize routes on area border routers, to prevent flapping

I don't know what you mean they are used for a backup.
by smyers119
Sun Dec 05, 2021 3:16 pm
Forum: RouterOS beta
Topic: [ZEROTIER BUG]ARPING for public IP on LAN
Replies: 11
Views: 3437

[ZEROTIER BUG]ARPING for public IP on LAN

I happened to be running wireshark and noticed my RB4011 is sending ARP's for public IP's on my LAN. I confirmed I do not have proxy-arp running. Version: routerboard: yes model: RB4011iGS+ serial-number: firmware-type: al2 factory-firmware: 6.45.8 current-firmware: 6.47.2 upgrade-firmware: 7.1 ARPS...
by smyers119
Sun Dec 05, 2021 1:53 pm
Forum: General
Topic: Admin password legislation
Replies: 4
Views: 857

Re: Admin password legislation

EDITED **Did not add anything constructive to the discussion**
by smyers119
Sun Dec 05, 2021 4:46 am
Forum: RouterOS beta
Topic: OSPF between v6 and v7
Replies: 5
Views: 6920

Re: OSPF between v6 and v7

It does not appear that my RB4011 sends ospf hello messages out my zerotier interface. # dec/04/2021 11:10:01 by RouterOS 7.1 # software id = IZUY-SLWC # # model = RB4011iGS+ # serial number = /routing ospf instance add name=default router-id=10.17.255.1 /routing ospf area add instance=default name...
by smyers119
Sun Dec 05, 2021 3:42 am
Forum: General
Topic: Admin password legislation
Replies: 4
Views: 857

Re: Admin password legislation

ETSI writes standards, they do not legislate. But i guess in this day and age you can identify as whatever you want.
by smyers119
Sun Dec 05, 2021 3:34 am
Forum: Beginner Basics
Topic: VLAN configuration RB4011IGS+RM once again
Replies: 18
Views: 5074

Re: VLAN configuration RB4011IGS+RM once again

Problem #1:
add port 5 to mngt_vlan interface list
Problem#2:
you need to rule the mikrotik in/out by trying a different switch
by smyers119
Sun Dec 05, 2021 12:29 am
Forum: Beginner Basics
Topic: Mikrotik failover script strange behavior
Replies: 18
Views: 3092

Re: Mikrotik failover script strange behavior

Here is a newer comercialized version of what I am asking you to do.

It's like ping and traceroute all in one, so we will know where the ping fails

https://www.pingplotter.com/products/free.html
by smyers119
Sun Dec 05, 2021 12:24 am
Forum: RouterOS beta
Topic: [BUG] RIP missing networks
Replies: 0
Views: 1602

[BUG] RIP missing networks

Version: routerboard: yes model: RB4011iGS+ serial-number: firmware-type: al2 factory-firmware: 6.45.8 current-firmware: 6.47.2 upgrade-firmware: 7.1 Network sub-menu missing per docs : [admin@router1] /routing/rip> instance interface-template neighbor export interface keys static-neighbor [admin@ro...
by smyers119
Sat Dec 04, 2021 11:43 pm
Forum: Beginner Basics
Topic: Mikrotik failover script strange behavior
Replies: 18
Views: 3092

Re: Mikrotik failover script strange behavior

can you run a mtr for 6 hours at the same 200ms and see what you find out.
by smyers119
Sat Dec 04, 2021 9:41 pm
Forum: Scripting
Topic: Script for auto generated pseudo random passwords for guest Wi-Fi
Replies: 3
Views: 3286

Re: Script for auto generated pseudo random passwords for guest Wi-Fi

Seems like a waist of flash write/erase cycles to me. But cool script, Hope your just using it for learning.
by smyers119
Sat Dec 04, 2021 9:26 pm
Forum: General
Topic: Public ip not accessable
Replies: 1
Views: 998

Re: Public ip not accessable

The way you have phrased your question is very hard to follow. Let's try to clear this up FACTS I'VE GATHERED: * You have a public/29 * You have a radius server * You can not access your radius server from your LAN usinga public IP THINGS WE NEED TO KNOW: *Are you port forwarding to the radius serve...
by smyers119
Sat Dec 04, 2021 6:14 pm
Forum: RouterOS beta
Topic: OSPF between v6 and v7
Replies: 5
Views: 6920

Re: OSPF between v6 and v7

It does not appear that my RB4011 sends ospf hello messages out my zerotier interface. # dec/04/2021 11:10:01 by RouterOS 7.1 # software id = IZUY-SLWC # # model = RB4011iGS+ # serial number = /routing ospf instance add name=default router-id=10.17.255.1 /routing ospf area add instance=default name=...
by smyers119
Sat Dec 04, 2021 5:03 pm
Forum: RouterOS beta
Topic: Webfig unavailable after update
Replies: 6
Views: 3941

Webfig unavailable after update

I am not able access webfig. After login it kicks me right over to console. When clicking back on webfig i get a 404 error. routerboard: yes model: RB4011iGS+ serial-number: D1270B83A96A firmware-type: al2 factory-firmware: 6.45.8 current-firmware: 6.47.2 upgrade-firmware: 7.1 The only log files aft...
by smyers119
Sat Dec 04, 2021 2:41 am
Forum: General
Topic: Transfet DNS requests to l2tp-out1
Replies: 5
Views: 1515

Re: Transfet DNS requests to l2tp-out1

Create a mangle rule in prerouting with action "mark routing"
Use that mangle rule in the routing table to send those packets to your l2tp vpn
by smyers119
Fri Dec 03, 2021 11:16 pm
Forum: Beginner Basics
Topic: Mikrotik failover script strange behavior
Replies: 18
Views: 3092

Re: Mikrotik failover script strange behavior

OK, so there was no unecessary failover at 21:54:06. It seems that fasttrack tracks ICMP packets. So perhaps I can enable fasttrack and delete the route to 1.1.1.1. in /ip routes and also the reject filter to 1.1.1.1. So when you have the interface option set in ping, then you do not need the addit...
by smyers119
Fri Dec 03, 2021 8:47 pm
Forum: Beginner Basics
Topic: Mikrotik failover script strange behavior
Replies: 18
Views: 3092

Re: Mikrotik failover script strange behavior

Is ICMP stateless on the mikrotik? (I know the protocol itself is) Maybe your filling up the table, and if that is the case maybe you can turn tracking off for icmp or reduce the timer for it.
by smyers119
Fri Dec 03, 2021 8:33 pm
Forum: General
Topic: pfSense Behind Mikrotik Router and L2TP VPN
Replies: 2
Views: 1638

Re: pfSense Behind Mikrotik Router and L2TP VPN

So your RDP server is behind the pfsense? Are you double NATTED? Sounds like a MTU problem, can you do a MTU test?
by smyers119
Fri Dec 03, 2021 8:18 pm
Forum: General
Topic: Mixed /30 and /24 on same subnet
Replies: 18
Views: 3133

Re: Mixed /30 and /24 on same subnet

Originally our WISP network was using OSPF but because of adjacency disconnections on wireless interfaces, we had to start using bridged VLAN's for PPPoE , OSPF is now used for management and just wondering if the the original IP's + OSPF network setting were correct ? Example if a one side of PTP ...
by smyers119
Fri Dec 03, 2021 7:44 pm
Forum: Beginner Basics
Topic: Mikrotik failover script strange behavior
Replies: 18
Views: 3092

Re: Mikrotik failover script strange behavior

Does this happen with any destination IP or just 1.1.1.1? Have you tried making the destination ip an array, so you ping a destination every x amount of times. And only fail over if all x destinations come back with no ping. This will help with false positives.
by smyers119
Fri Dec 03, 2021 3:35 am
Forum: General
Topic: RouterOS Port Security Sticky [SOLVED]
Replies: 6
Views: 3015

Re: RouterOS Port Security Sticky [SOLVED]

has nothing to do with the question at hand
Same feature in RouterOS , no ?
.
Klembord-2.jpg
No, that is not the same thing.
by smyers119
Fri Dec 03, 2021 1:01 am
Forum: General
Topic: RouterOS Port Security Sticky [SOLVED]
Replies: 6
Views: 3015

Re: RouterOS Port Security Sticky [SOLVED]

Thanks but that has nothing to do with the question at hand, so not sure why you would post.
by smyers119
Thu Dec 02, 2021 7:17 pm
Forum: General
Topic: RouterOS Port Security Sticky [SOLVED]
Replies: 6
Views: 3015

RouterOS Port Security Sticky [SOLVED]

Hi, We need to restrict learned mac addresses per port on CRS326 using RouterOS. This was a feature in CRS1xx/2xx, and apparently is a feature in CRS326 using SwOS (Port Lock->Lock on first>. However, SwOS is too limited in other areas for us, so we use RouterOS on these devices. Is there no way to...