Community discussions

MikroTik App

Search found 533 matches

  • 1
  • 2
by ConradPino
Wed Mar 26, 2025 12:59 pm
Forum: Beginner Basics
Topic: Can't get VLAN trunk working
Replies: 10
Views: 590

Re: Can't get VLAN trunk working

Iis vlan-filtering=no still in effect?
Remember Safe Mode before make change.
/interface/bridge/set bridge vlan-filtering=yes
by ConradPino
Tue Mar 25, 2025 5:02 am
Forum: Announcements
Topic: New exciting features for storage
Replies: 169
Views: 18058

Re: New exciting features for storage

@sirbryan my hero! Thank you!!
by ConradPino
Mon Mar 24, 2025 8:21 am
Forum: Scripting
Topic: Emailing of Log file not working after latest update
Replies: 4
Views: 345

Re: Emailing of Log file not working after latest update

Showing what you tried is useful even if it fails.
by ConradPino
Mon Mar 24, 2025 12:15 am
Forum: General
Topic: Forum rendering is broken
Replies: 6
Views: 329

Re: Forum rendering is broken

+1 @phascogale same here but thankfully not often.
by ConradPino
Mon Mar 24, 2025 12:08 am
Forum: General
Topic: Forum rendering is broken
Replies: 6
Views: 329

Re: Forum rendering is broken

Other forum posts say MikroTik Forum is targeted by DDOS attacks from time to time.
I often see web proxy report site temporarily unavailable, sometimes repeatedly after refreshing.
Consider possibility main page succeeds but some assets fail such as fonts, images, or JavaScript files.
by ConradPino
Sun Mar 23, 2025 11:42 pm
Forum: MikroTik hardware questions
Topic: S+RJ10 Alternative For CRS309
Replies: 8
Views: 816

Re: S+RJ10 Alternative For CRS309

Thank you! I would appreciate seeing any module information you may have:
/interface/ethernet/monitor sfp-sfpplusN once without-paging
by ConradPino
Sun Mar 23, 2025 11:23 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 169
Views: 18058

Re: New exciting features for storage

+1 @sirbryan Thank you!!
by ConradPino
Fri Mar 21, 2025 7:50 am
Forum: Forwarding Protocols
Topic: SSH and Tunneling
Replies: 2
Views: 384

Re: SSH and Tunneling

IMO @loloski suggestion is simpler than SSH tunnel which require setup to at least one known IP address on either side. Another idea is a firewall destination NAT rule that specifies dst-port but omits dst-address to match any IP address on the router. Combine the above firewall adjustments with dyn...
by ConradPino
Fri Mar 21, 2025 7:30 am
Forum: General
Topic: Configurable (or shorter) negative DNS cache TTL needed
Replies: 10
Views: 8260

Re: Configurable (or shorter) negative DNS cache TTL needed

I suggest every upstream DNS zone thas reasonable minimum TTL: dig www.not-existing.google.com google.com. 60 IN SOA ns1.google.com. dns-admin.google.com. 738736615 900 900 1800 60 dig www.not-existing-site.com com. 900 IN SOA a.gtld-servers.net. nstld.verisign-grs.com. 1742534562 1800 900 604800 90...
by ConradPino
Fri Mar 21, 2025 7:09 am
Forum: General
Topic: Public-Mikrotik-Bandwidth-Test-Server(s) ( shutting down on April 1st 2025 )
Replies: 1080
Views: 1277674

Re: Public-Mikrotik-Bandwidth-Test-Server(s)

I'm sad to see it go but I want you to know I found it useful and am grateful it was there.
Is there anything the user community could offer that might warrant a reconsideration?
by ConradPino
Fri Mar 21, 2025 12:49 am
Forum: MikroTik hardware questions
Topic: S+RJ10 Alternative For CRS309
Replies: 8
Views: 816

Re: S+RJ10 Alternative For CRS309

@jaclaz, yes the price difference and is 1.8 W enough margin? @cstarritt, agreed heatsink should help but how much help? When ambient hits 78F recently, S+RJ10 shutdown at 95C standard limit. When ambient hits 96F as happens several days yearly I need to be up. I pray a proven solution with temperat...
by ConradPino
Fri Mar 21, 2025 12:27 am
Forum: Announcements
Topic: New exciting features for storage
Replies: 169
Views: 18058

Re: New exciting features for storage

@Normis I believe @Larsa makes some good points. I believe MikroTik strengths are: hardware design and manufacturing at excellent pricing value points prior history delivering reliable and stable networking software but recentl RouterOS 7 development has unmasked incompetance managing software devel...
by ConradPino
Thu Mar 20, 2025 11:41 pm
Forum: MikroTik hardware questions
Topic: S+RJ10 Alternative For CRS309
Replies: 8
Views: 816

Re: S+RJ10 Alternative For CRS309

I found claims Broadcom BCM84891L devices are low power like: Built-in Broadcom Chip, Max. Power Consumption 1.8W but at $140.00, more than FTC11XG option which is safest temperature risk. 2.7 Watts for S+RJ10 which idles at 90C at ambient 75F versus 1.8 Watts for new designs leaves me with some roo...
by ConradPino
Thu Mar 20, 2025 5:19 pm
Forum: MikroTik hardware questions
Topic: S+RJ10 Alternative For CRS309
Replies: 8
Views: 816

S+RJ10 Alternative For CRS309

New ISP provides 10G fiber service but ONT is 10GBase-T (RJ45 copper) only. Despite MikroTik S-RJ10 general guidance I tried and also confirmed S+RJ10 is not reliable outside climate controlled environment. While FTC11XG looks viable but has a weatherproof price, I want to exhaust other possibilitie...
by ConradPino
Thu Mar 20, 2025 3:53 pm
Forum: MikroTik hardware questions
Topic: RouterOS questions
Replies: 7
Views: 956

Re: RouterOS questions

The ROSE-storage package supports network mounts potentially useful for container storage. Just a suggestion that I haven't tried myself.
by ConradPino
Thu Mar 20, 2025 3:34 pm
Forum: General
Topic: Weekly VLAN confusion post
Replies: 18
Views: 1201

Re: Weekly VLAN confusion post

Is anyone else's mind blown with the surrealism and irony going on with this thread? I started it to (1) vent and (2) beg for help due to the massive cognitive-pain being caused by VLANs. Now, this thread has evolved to a discussion/argument about minutae I did not know existed. Part of me loves it...
by ConradPino
Thu Mar 20, 2025 2:38 pm
Forum: General
Topic: Weekly VLAN confusion post
Replies: 18
Views: 1201

Re: Weekly VLAN confusion post

So it's very unlikely (but not impossible) to actually see fast-forward in action. Not in context of this thread. Yes, it's quite unlikely indeed but we build VLAN Filtering one command at a time and setting vlan-filtering=yes should occur after defining bridge port and bridge vlan steps otherwise ...
by ConradPino
Thu Mar 20, 2025 8:08 am
Forum: General
Topic: Weekly VLAN confusion post
Replies: 18
Views: 1201

Re: Weekly VLAN confusion post

For this topic, where VLAN Filtering is the goal, Fast Forward's status is irrelevant, it would be inactive anyway.
When omitted from
/interface bridge
the
fast-forward
value defaults to
yes
so adding
fast-forward=no
is at least prudent and sometimes necessary.
by ConradPino
Thu Mar 20, 2025 12:23 am
Forum: General
Topic: Weekly VLAN confusion post
Replies: 18
Views: 1201

Re: Weekly VLAN confusion post

disables ARP? really? haven't seen that ever after and i have setup a lot of bridges... old and new fashioned way arp always working so far with fast-forward set to "yes" Bridging and Switching § Fast Forward says, Fast Forward disables MAC learning, this is by design to achieve faster pa...
by ConradPino
Wed Mar 19, 2025 5:50 pm
Forum: General
Topic: IPv6 vs IPv4 - estimate general performance?
Replies: 2
Views: 419

Re: IPv6 vs IPv4 - estimate general performance?

Agreed with @mkx that IPv4 and IPv6 have independent routing paths but only if both are native implementations. IPv6 encapsulated in IPv4 or IPv4 encapsulated in IPv6 are exceptions and both have larger MTU penalty. While 1.1.1.1 and 2606:4700:4700::1111 have a common PTR value " one.one.one.on...
by ConradPino
Wed Mar 19, 2025 4:35 pm
Forum: General
Topic: Weekly VLAN confusion post
Replies: 18
Views: 1201

Re: Weekly VLAN confusion post

1) Create a bridge (this is a layer 2 and operates on ethernet, also known as MAC address level; this bridge can be conceptualized as a switch within a device such as a router) -- let's name it bridge=TESTBRIDGE Useful MikroTik Help and Forum links: Bridging and Switching § Bridge Interface Setup B...
by ConradPino
Wed Mar 19, 2025 3:25 pm
Forum: General
Topic: Weekly VLAN confusion post
Replies: 18
Views: 1201

Re: Weekly VLAN confusion post

If I understand correctly, what you're saying is that a key to understanding this is to learn it in this specific order: 1) Add a bridge 2) Add bridge ports 3) Add bridge vlans 4) Add interface vlans Correct? Nothing works without (1) the bridge. I put interface vlan last because while they can be ...
by ConradPino
Wed Mar 19, 2025 3:15 pm
Forum: Scripting
Topic: tool fetch - LTE
Replies: 3
Views: 355

Re: tool fetch - LTE

Make sure firewall allows required traffic despite routing changes DHCP client makes as connections go up and down.
by ConradPino
Wed Mar 19, 2025 3:38 am
Forum: General
Topic: Weekly VLAN confusion post
Replies: 18
Views: 1201

Re: Weekly VLAN confusion post

OK, let's do this in correct order and one step at a time. Correct order:
  1. /interface bridge add
  2. /interface bridge port add
  3. /interface bridge vlan add
  4. /interface vlan add
Do we agree on this?
by ConradPino
Wed Mar 19, 2025 3:29 am
Forum: Scripting
Topic: tool fetch - LTE
Replies: 3
Views: 355

Re: tool fetch - LTE

Look at how routing table changes as LTE goes up and down.
by ConradPino
Wed Mar 19, 2025 2:10 am
Forum: MikroTik hardware questions
Topic: RDS2216 Pics and Thoughts
Replies: 1
Views: 805

Re: RDS2216 Pics and Thoughts

Are we having too much fun? :lol:
by ConradPino
Tue Mar 18, 2025 4:30 pm
Forum: MikroTik hardware questions
Topic: RJ45 SFP+ Overheat
Replies: 3
Views: 1587

Re: RJ45 SFP+ Overheat

Adding cable and module part numbers may improve feedback on this topic.
MikroTik is clear their RJ45 module has limits S-RJ10 general guidance
by ConradPino
Tue Feb 25, 2025 9:51 am
Forum: General
Topic: IPSec to AWS
Replies: 1
Views: 2179

Re: IPSec to AWS

What did you provision in AWS VPC Security Groups?
by ConradPino
Wed Feb 19, 2025 2:03 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2130
Views: 1172022

Re: 📣 WinBox 4 is here 📣

Yeah, that also means Winbox 4 won't run on anything older than Windows 10 (ie, no XP, Vista or Win 7/8).
Another strike against Winbox!
by ConradPino
Mon Feb 17, 2025 9:09 pm
Forum: Announcements
Topic: v6.49.18 [long-term] is released!
Replies: 42
Views: 53384

Re: v6.49.18 [stable] is released!

@infabo makes an excellent point.
Complete and diligent CVE follow through is critical for maintaining confidence in MikroTik security management process.
by ConradPino
Mon Feb 17, 2025 10:57 am
Forum: General
Topic: [BUG] V7.17.x wrong webfig login page RB750
Replies: 6
Views: 3052

Re: [BUG] V7.17.x wrong webfig login page RB750

I'm holding at 7.16.2 until a consensus emerges that 7.17 or 7.18 are safe for production environments. I can't say I read the RouterOS v7 release topics deeply but I survey all forum topics broadly at least daily. IMO time spent making Webfig look like another application is a sad time waste for no...
by ConradPino
Mon Feb 17, 2025 10:26 am
Forum: General
Topic: [BUG] V7.17.x wrong webfig login page RB750
Replies: 6
Views: 3052

Re: [BUG] V7.17.x wrong webfig login page RB750

An issue may appear in multiple topics; a resolution may not be posted in every topic where issue was posted so vigilance across the multiple topics may pay off.
by ConradPino
Sun Feb 16, 2025 4:14 am
Forum: General
Topic: Firewall rules analysis
Replies: 110
Views: 14586

Re: Firewall rules analysis

I hope that my point of view is clear to you.
I try to pay attention but find that alone doesn't guarantee me success.
I commend your participation and see you as another steady helping hand here.
I find diverse perspectives creative, educational, and frequently useful in shaping mine.
by ConradPino
Sun Feb 16, 2025 4:02 am
Forum: General
Topic: Firewall rules analysis
Replies: 110
Views: 14586

Re: Firewall rules analysis

I hope you don't mean block what you need to block, but allow everything at the end ... I do mean "block then allow" versus "permit then drop" designs. Where is the objective evidence for this statement? (compare straight to inverted?) You're suggesting opinions require a founda...
by ConradPino
Sun Feb 16, 2025 3:14 am
Forum: General
Topic: Firewall rules analysis
Replies: 110
Views: 14586

Re: Firewall rules analysis

Where is the default firewall flawed for a very simple standard connection between WAN and LAN?
It's fine for what it does for it's intended network model.
It's weakness is novices break it more readily than an inverted design.
by ConradPino
Sat Feb 15, 2025 11:06 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 161276

Re: v7.18beta [testing] is released!

@pe1chl IMO repeating suggestions from time to time is worthwhile to demonstrate continued interest and need to MikroTik along with educating new and old forum users which may lead to community consensus formation with more voices advocating their common interests.
by ConradPino
Sat Feb 15, 2025 10:51 pm
Forum: General
Topic: IPv6 Neighbor Discovery broken between Switches ?
Replies: 4
Views: 2051

Re: IPv6 Neighbor Discovery broken between Switches ?

I don't have a solution but noted Proxmox was popping up in topics recently while 7.17 added bugs and features. If your situation and time permits, downgrading RouterOS may or may not help isolate the issue. Polling others for downgrade advice may be worthwhile before experimenting. A forum topic ha...
by ConradPino
Sat Feb 15, 2025 10:20 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 169
Views: 18058

Re: New exciting features for storage

@Cha0s LOL
by ConradPino
Sat Feb 15, 2025 10:17 pm
Forum: General
Topic: Firewall rules analysis
Replies: 110
Views: 14586

Re: Firewall rules analysis

Well, at least I am able to express my ideas without attacking or offending other people. :) You don't have enough new users to shout at today? :?: Sooner or later somebody will come by and take offense to something. Sooner or later everybody will have a bad day and lets it spill out. Welcome to th...
by ConradPino
Sat Feb 15, 2025 1:04 pm
Forum: MikroTik hardware questions
Topic: x86 Mikrotik v7 performance - choosing the x86 CPU
Replies: 19
Views: 15466

Re: x86 Mikrotik v7 performance - choosing the x86 CPU

Wikipedia says, non-uniform memory access (NUMA) is a computer memory design used in multiprocessing, where the memory access time depends on the memory location relative to the processor. Under NUMA, a processor can access its own local memory faster than non-local memory (memory local to another p...
by ConradPino
Sat Feb 15, 2025 12:50 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 161276

Re: v7.18beta [testing] is released!

In most of the software world, there is a clear distinction between breaking changes (incompatible), bug fixes, and new features. However, we have to be fair - MikroTik still uses terms like alpha, beta, and stable, which feels somewhat outdated in modern software development. Let's help MikriTik g...
by ConradPino
Sat Feb 15, 2025 12:10 pm
Forum: General
Topic: Firewall rules analysis
Replies: 110
Views: 14586

Re: Firewall rules analysis

What's going on? So many questions coming out of this Why is one better than the default that comes with Mikrotik? Or more accurately, why is there a lack of understanding in the firewall mechanism? Do people not trust the firewall and temptations to modify and all hell breaks lose when something g...
by ConradPino
Sat Feb 15, 2025 12:01 pm
Forum: General
Topic: Firewall rules analysis
Replies: 110
Views: 14586

Re: Firewall rules analysis

TL;DR Great diversity in networking designs produces a great diversity of related advice. MikroTik provided router default firewall is well designed for it's intended use case: WAN DHCP client public IPv4 address LAN DHCP server private IPv4 subnet Firewall LAN to WAN includes NAT Firewall LAN to W...
by ConradPino
Fri Feb 14, 2025 6:03 pm
Forum: Virtualization
Topic: CHR downgrade on v7
Replies: 8
Views: 2488

Re: CHR downgrade on v7

All current and historical releases
https://mikrotik.com/download/archive
by ConradPino
Thu Feb 13, 2025 9:45 am
Forum: Announcements
Topic: New exciting features for storage
Replies: 169
Views: 18058

Re: New exciting features for storage

Swap is not for the host system. Please read the manual about it before complaining: https://help.mikrotik.com/docs/spaces/R ... -Swapspace
@normis, thank you and please thank Druvis Timma for making that update Feb 07, 2025 10:17. IMO a super addition.
by ConradPino
Thu Feb 13, 2025 9:36 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 161276

Re: v7.18beta [testing] is released!

@strods, thank you and well said. When MikroTik staff can make a forum appearance, many may find it reassuring much as I do.
More information is always better and deft words now and then deflate the speculation space which has typically calming effects.
by ConradPino
Wed Feb 12, 2025 2:50 am
Forum: General
Topic: Firewall rules analysis
Replies: 110
Views: 14586

Re: Firewall rules analysis

Hahaha okay, I will catch a ride the next time the orange drag president flys by in his sleigh......
Fun image, thanks!
IMO "orange president" has clear meaning. How does "orange drag president" alter such?
by ConradPino
Wed Feb 12, 2025 1:50 am
Forum: General
Topic: Secrets in supout.rif
Replies: 16
Views: 4701

Re: Secrets in supout.rif

Recommended procedure for posting configuration includes: Remove serial number comment Remove software license comment Replace sensitive comments language Replace usernames with unique generic names Replace passwords and secret keys with generic descriptions Replace IP address with generic numbers k...
by ConradPino
Wed Feb 12, 2025 1:38 am
Forum: General
Topic: /31 handoff
Replies: 7
Views: 2226

Re: /31 handoff

IMO OP introduced themselves as one professional meeting another in a professional setting and effectively presenting their business card.
by ConradPino
Wed Feb 12, 2025 1:13 am
Forum: Announcements
Topic: Question to our users about controllers
Replies: 116
Views: 164449

Re: Question to our users about controllers

IMO time spent making Webfig look like a desktop or mobile GUI application is wasted time producing bloatware. IMO maintaining parallel menus and functional operations between Webfig and GUI applications is worthwhile. IMO keeping Webfig HTML and CSS simple best uses limited space on storage constra...
by ConradPino
Wed Feb 12, 2025 1:04 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2130
Views: 1172022

Re: 📣 WinBox 4 is here 📣

I started with RouterOS v6 Webfig then CLI and never caught the Winbox or Dude diseases.
If cancelling or postponing Winbox accelerates RouterOS v7 development then I vote so.
by ConradPino
Wed Feb 12, 2025 12:56 am
Forum: Announcements
Topic: Question to our users about controllers
Replies: 116
Views: 164449

Re: Question to our users about controllers

I started with RouterOS v6 Webfig then CLI and never caught the Winbox or Dude diseases. I prefer a tiered Webfig: Basic level for local device management on every device model. Advanced Private level optional package to manage an isolated network. Advanced Cloud level optional package to manage Int...
by ConradPino
Wed Feb 12, 2025 12:39 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17.2 [stable] is released!

I am big Webfig and Let's Encrypt fan. IMO MikroTik did very nice thing adding Let's Encrypt support so I'm biased preferring best HTTPS security as default for new users.
by ConradPino
Wed Feb 12, 2025 12:11 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17.2 [stable] is released!

I did not know ROS uses squashfs. But good to know. But still one observation remains valid: webfig assets are served uncompressed.
Serving compressed assets over HTTPS is the BREACH security vulnerability.
https://en.wikipedia.org/wiki/BREACH
by ConradPino
Tue Feb 11, 2025 11:05 pm
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

Sip, mmmmm ... Cafe is wonderful. Over the weekend I made some progress reading configurations which raised questions best left for later. In the mean time, RB5009 is another bridge switch chip in play and where the root bridge moves when devices go down is critical considerations in what interconne...
by ConradPino
Tue Feb 11, 2025 3:39 am
Forum: General
Topic: Long Term release or new functions?
Replies: 26
Views: 5250

Re: Long Term release or new functions?

@normis, it's so good to see you here! Thank you!! LTS is just a name. If we rename 7.15.1 to long-term, will it become more stable? No, without MikroTik support, of course it won't. IMO this topic arises from inadverantly unmanged expectations that arose prior to RouterOS v7 effort. Over time bug r...
by ConradPino
Mon Feb 10, 2025 10:57 pm
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

A rush project landed on my desk this morning; I will be short on personal time but will add to specific topics as time permits.
by ConradPino
Mon Feb 10, 2025 3:07 am
Forum: General
Topic: Is there a reason the IPv6 subnets are not sequential?
Replies: 10
Views: 4665

Re: Is there a reason the IPv6 subnets are not sequential?

Accidental double post redacted.
by ConradPino
Mon Feb 10, 2025 3:06 am
Forum: General
Topic: Is there a reason the IPv6 subnets are not sequential?
Replies: 10
Views: 4665

Re: Is there a reason the IPv6 subnets are not sequential?

... I just now changed it to static so that should take care of any quirks. Thanks! You're welcome. IPv6 routing with single provider works with just the main routing table. If ISP deploys IPv6 and keeping Hurricane Electric is wanted, 2nd routing table for policy routing works. I use VLAN segmente...
by ConradPino
Mon Feb 10, 2025 2:13 am
Forum: General
Topic: Is there a reason the IPv6 subnets are not sequential?
Replies: 10
Views: 4665

Re: Is there a reason the IPv6 subnets are not sequential?

@mbrad thank you. My confusion is why @TrevinLC1997 is using pool when it doesn't provide level of control wanted and static assignment does.
by ConradPino
Sun Feb 09, 2025 10:12 am
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

Sip, mmmmm ... Cafe I'm bring up Spanning Tree Protocol to make clear MikroTik default enables RSTP on all software bridges and switch chips. The switching loops in the current connection topology will not produce broadcast storms while RSTP remains enabled. Spanning Tree Protocol § Summary excerpt:...
by ConradPino
Sun Feb 09, 2025 3:17 am
Forum: General
Topic: Is there a reason the IPv6 subnets are not sequential?
Replies: 10
Views: 4665

Re: Is there a reason the IPv6 subnets are not sequential?

Ahh that's unfortunate, hopefully one day Mikrotik will give us the ability to manually configure subnets or at the very least allow the option for a automatically assigned static subnet. Just color me confused; I manage my Hurricane Electric /48 tunnel with static commands and without an address p...
by ConradPino
Sun Feb 09, 2025 3:09 am
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

Please interpret, "May I suggest ..." as an introduction to further discussion and NOT necessarily a call to action. Thank you for an outstanding reply which I will address in part now as I must attend to my work and will return later to reply in depth. EDIT: VLAN10 has been migrated to VL...
by ConradPino
Sat Feb 08, 2025 9:34 pm
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

It's a small homelab network, not hundreds of machines that have a high amount of packets flowing all the time. Thank you, that's helpful. Can you enumerate how many ports are free and used on current CCR2004, CRS317, and CRS326? @anav suggested firewall and configuration improvements which receive...
by ConradPino
Sat Feb 08, 2025 9:33 pm
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

Yes, it's important and requires an entry for every MAC address a given switch sees. I have about 125-ish devices on the network (though this can sometimes reach 150 when some of my friends come over). I doubt that would be big enough to cause any issues with the CRS309's smaller Unicast FDB? The C...
by ConradPino
Sat Feb 08, 2025 9:11 pm
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

I don't know if the "Unicast FDB" is an important thing?
Unicast FDB (Forwarding Database) is mentioned here: CRS3xx, CRS5xx, CCR2116, CCR2216 switch chip features § Features
Yes, it's important and requires an entry for every MAC address a given switch sees.
by ConradPino
Sat Feb 08, 2025 7:59 am
Forum: Beginner Basics
Topic: Need help with VLAN configuration [SOLVED]
Replies: 1
Views: 2754

Re: Need help with VLAN configuration [SOLVED]

Device management occurs on VLAN 1. Examine which ports on both devices allow VLAN 1 traffic.
by ConradPino
Sat Feb 08, 2025 7:17 am
Forum: Forwarding Protocols
Topic: Two WAN Router with Passing Subnets
Replies: 10
Views: 4121

Re: Two WAN Router with Passing Subnets

Double posting is considered poor form and both lack device configurations.
viewtopic.php?t=214573
by ConradPino
Sat Feb 08, 2025 7:17 am
Forum: General
Topic: I thought I understood it but....
Replies: 2
Views: 1553

Re: I thought I understood it but....

Double posting is considered poor form and both lack device configurations.
posting.php?t=214574
by ConradPino
Sat Feb 08, 2025 3:16 am
Forum: MikroTik hardware questions
Topic: Plans for CCR2004-1G-2XS-PCIe successor?
Replies: 1
Views: 2320

Re: Plans for CCR2004-1G-2XS-PCIe successor?

Accelerating RouterOS boot to complete before host OS startup would be *very nice*.
by ConradPino
Sat Feb 08, 2025 2:58 am
Forum: Containers
Topic: "Docker official image" - can't get installed
Replies: 13
Views: 9049

Re: "Docker official image" - can't get installed

@arainbow, excellent work. Thank you!
by ConradPino
Sat Feb 08, 2025 2:46 am
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

Above table apples to L3 HW Offloading and is irrelevant to Stateless Hardware Firewall and Switch Rules (ACL) whose limits are shown in ACL Rules column: Model SwChip CPU Cores SFP+ ACL Rules Unicast FDB Jumbo Frame CRS310 98DX226S 1 800MHz 4 128 16,000 10218 CRS309 98DX8208 2 800MHz 8 1024 32,000 ...
by ConradPino
Sat Feb 08, 2025 2:29 am
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

Ok so, viewing from the WAN side (incoming from ISP): ISP CCR2004 CRS317 CRS309* + CRS326 I misread diagram device CRS326 as CRS310 and apologize. My suggestion was: ISP CCR2004 CRS317 CRS326 which presumes CRS317 has enough free ports to downstream the CRS326 which I don't know at this time. If no...
by ConradPino
Sat Feb 08, 2025 2:18 am
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

Model SwChip ROS IPv4 Pre IPv4 Host IPv6 Pre IPv4 Host Nexthop Fasttrack NAT VXLAN CRS310 98DX226S 7.1 13312 3328 4K CRS309 98DX8208 7.1 16K-6K 16K 4K-6K 8K 8K 4.5K 3.9K + CRS317 98DX8216 7.1 120K-240K 64K 30K-40K 32K 8K 4.5K 4K + Source: L3 Hardware Offloading § L3HW Device Support
by ConradPino
Sat Feb 08, 2025 1:49 am
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

Oops, I'm late in reading existing device details. Please note CRS317 is more capable than CRS309 which is more capable than CRS310,

Consider moving CRS310 to CCR2004 connections downstream of the CRS317 and deploy L3 HW routing with a Stateless Hardware Firewall on CRS317.
by ConradPino
Sat Feb 08, 2025 12:52 am
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

FastTrack Thank you. Agreed, per CRS3xx: Switch DX3000 and DX2000 Series CRS310 does not hardware offload Fasttrack nor NAT whereas CRS309 per CRS3xx, CRS5xx: Switch DX8000 and DX4000 Series can hardware offloat Fasttrack and NAT but that is not a recommendation as all devices there are TCAM constr...
by ConradPino
Sat Feb 08, 2025 12:01 am
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

Seems like the CRS310 I proposed doesn't support FT offloading, so it seems that that won't do then? Am I correct?
Define FT please.
by ConradPino
Fri Feb 07, 2025 11:41 pm
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

OK, I see enough to draft a CRS309 configuration; that could be a further discussion starting point. But it occurred to me CRS309 has L3HW Offload idiosyncrasies that must be kept front and center for best results. We can work on improving current configurations prior to diving into the future. Do ...
by ConradPino
Fri Feb 07, 2025 6:49 pm
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

OK, I see enough to draft a CRS309 configuration; that could be a further discussion starting point. But it occurred to me CRS309 has L3HW Offload idiosyncrasies that must be kept front and center for best results. We can work on improving current configurations prior to diving into the future. Do y...
by ConradPino
Fri Feb 07, 2025 6:24 pm
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

Definite progress, thank you. By now you've seen this forum is doesn't handle code blocks consistently. Please edit last post to add a blank line or two above code block begin and below code block close. All exports start with comment lines, first is device model (not sensitive) and third is serial ...
by ConradPino
Fri Feb 07, 2025 5:53 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 161276

Re: v7.18beta [testing] is released!

The quality of software development and/or a more thoughtful featureset placing into devices might be more helpful for the vendor as for customers also. The problem is when the management/development shifting to the sandboxer side, when more feature comes into new releases than bugs fixed. My grave...
by ConradPino
Fri Feb 07, 2025 4:57 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 161276

Re: v7.18beta [testing] is released!

All devices upgraded from versions <7.17 will be put in the Enterprise/Advanced device-mode, with only traffic-gen, container, install-any-version, partitions and routerboard (minus auto-upgrade) disabled. No physical access needed unless you want to enable one of those specific features. Have you ...
by ConradPino
Fri Feb 07, 2025 3:52 pm
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

RouterOS documentation Spanning Tree Protocol has multiple flavors. I really mean export the entire CCR2004 configuration (redact only security sensitive items). Failing to fully disclose creates protracted dialogues leading to annoyance and destroying motivation to help. Your choice do you make it ...
by ConradPino
Fri Feb 07, 2025 6:54 am
Forum: General
Topic: Still fighting with Ecobee (and losing)
Replies: 14
Views: 3985

Re: Still fighting with Ecobee (and losing)

Just another taste of blissfully ignorant youth! :lol:
by ConradPino
Fri Feb 07, 2025 6:45 am
Forum: General
Topic: Upgrading from V6 to V7...
Replies: 15
Views: 4015

Re: Upgrading from V6 to V7...

Consider carefully changes in RouterOS 7.17 and 7.18 producing substantial push back which you'll see in respective Announcement topics.
by ConradPino
Fri Feb 07, 2025 5:36 am
Forum: General
Topic: CRS309 behind CCR2004 setup questions
Replies: 38
Views: 5310

Re: CRS309 behind CCR2004 setup questions

Consider posting CCR2004 config after removing sensitive information (serial number, IP addresses, user credentials, etc). /export terse file=ccr2004-FinlayDaG33k.rsc CRS309 can do the job at Layer 2 alone, Layer 3 routing not required but that won't have the LAN independence from CCR2004 downtime y...
by ConradPino
Fri Feb 07, 2025 5:17 am
Forum: Beginner Basics
Topic: Looking for VPN provider suggestion - with PortFWD
Replies: 10
Views: 5395

Re: Looking for VPN provider suggestion - with PortFWD

https://forum.mikrotik.com/viewtopic.php?t=180398 MikriTik forum Propose Mikrotik to adopt TailScale VPN similar to ZeroTierOne VPN https://github.com/Fluent-networks/tailscale-mikrotik GitHub project Tailscale for Mikrotik Container Nothing above is a recommendation; just adding TailScale informati...
by ConradPino
Fri Feb 07, 2025 5:06 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 161276

Re: v7.18beta [testing] is released!

I can sense the idea that someone from some agency whispered in mikrotiks ears "fix it or be regulated" and they came up with this complete overkill bazooka "solution" to shoot their customer's foots with at least they can point and claim that *someone is doing *something But th...
by ConradPino
Fri Feb 07, 2025 3:43 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 161276

Re: v7.18beta [testing] is released!

i understand your discomfort/annoyance with the situation,but i think This situation has other facets, Mikrotik has periodically been targeted by the media in a somewhat exaggerated way, about compromised devices being used in attacks by malicious actors, that put a heavy pressure on MikroTik to ta...
by ConradPino
Fri Feb 07, 2025 3:33 am
Forum: MikroTik hardware questions
Topic: All interfaces shutdown randomly
Replies: 11
Views: 10875

Re: All interfaces shutdown randomly

RouterOS kernel may panic and reboot during which all links are down. Follow logs and serial port output for unexpected reboots.
by ConradPino
Fri Feb 07, 2025 3:30 am
Forum: MikroTik hardware questions
Topic: CRS3/5 packet buffer size
Replies: 15
Views: 4944

Re: CRS3/5 packet buffer size

Consider carefully recent RouterOS 7.17 and 7.18 changes before deploying to locations where physical device access has high labor, time, or travel cost.
by ConradPino
Fri Feb 07, 2025 3:19 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17.2 [stable] is released!

I completely agree with you.
Well said and thank you!
by ConradPino
Fri Feb 07, 2025 3:18 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17.1 [stable] is released!

Let’s go through the device-mode changes one by one. The following features are now turned off by default: - traffic-gen: I don’t think most small business MikroTik professionals need traffic generation tools often. But there might be some use-cases in (automated) big deployments. - repartition: Wh...
by ConradPino
Fri Feb 07, 2025 3:00 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17.1 [stable] is released!

... Please make it possible to upgrade while keeping all features enabled as it was before the upgrade.
Thank you! Please come back and continue stressing what makes MirkoTik products useful.
by ConradPino
Fri Feb 07, 2025 2:49 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 161276

Re: v7.18beta [testing] is released!

... But now it is here to stay I guess. IMO that's giving up too easily. Let's be clear; MikroTik meets customer's needs or MikroTik loses customers. Like it or not, in a free market, the customer always prevails. The only real question is how much pain does MikroTik inflict on users and in turn ex...
by ConradPino
Fri Feb 07, 2025 2:36 am
Forum: MikroTik hardware questions
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 84
Views: 39544

Re: Running out of space on hAP ac2 [SOLVED]

No need to warn them in 2025...
The innocent newcomer will be with us forever and they too deserve our best efforts.
by ConradPino
Thu Feb 06, 2025 2:53 am
Forum: MikroTik hardware questions
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 84
Views: 39544

Re: Running out of space on hAP ac2 [SOLVED]

Disappointment with recent RouterOS updates is now common place but still merits open discussion to help MikroTik improve.
At this time 7.17.x has unpopular changes not yet addressed in 7.18.x; expect risk averse users to hold at 7.16.x for sometime.
by ConradPino
Thu Feb 06, 2025 2:34 am
Forum: General
Topic: Bridge-domain like configuration on CRS3xx switches
Replies: 4
Views: 2142

Re: Bridge-domain like configuration on CRS3xx switches

Suggested MikroTik reading: https://help.mikrotik.com/docs/spaces/ROS/pages/30474317/CRS3xx+CRS5xx+CCR2116+CCR2216+switch+chip+features#CRS3xx,CRS5xx,CCR2116,CCR2216switchchipfeatures-Models CRS3xx, CRS5xx, CCR2116, CCR2216 switch chip features https://help.mikrotik.com/docs/spaces/ROS/pages/6239031...
by ConradPino
Wed Feb 05, 2025 7:16 pm
Forum: General
Topic: Bridge-domain like configuration on CRS3xx switches
Replies: 4
Views: 2142

Re: Bridge-domain like configuration on CRS3xx switches

CRS3xx products have broad range of features depending on CPU and switch chip in specific model. Please enumerate actual part numbers for consideration.
by ConradPino
Wed Feb 05, 2025 10:27 am
Forum: General
Topic: temperature produced CCR 2216
Replies: 4
Views: 2461

Re: temperature produced CCR 2216

1 Watt = 1 Joule / second = 3.41 BTU / hour i.e. energy per unit time.
Can we say, 1 BTU per hour per cubic feet = 10 ° F increase in temperature per hour?
by ConradPino
Sat Feb 01, 2025 12:13 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17.1 [stable] is released!

Like I said, I (or MikroTik) would not have deleted it. It was a volunteer mod. IMO @normis is on the best path. What matters most is confidence and trust in the forum process. Forum moderation suggestions: do not delete bad posts; quote bad information in new post with correct information leave ba...
by ConradPino
Fri Jan 31, 2025 10:07 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17 [stable] is released!

And it doesn't look promising when topics like this quickly gets deleted https://forum.mikrotik.com/viewtopic.php?t=214285 Still indexed by Google https://www.google.com/search?q=%22RouterOS+7.17+Firmware+Vulnerabilities%22 Well, in fairness, they do publish a "responsible disclosure policy&qu...
by ConradPino
Fri Jan 31, 2025 3:30 am
Forum: General
Topic: Do you know what CALEA is?
Replies: 4
Views: 3363

Re: Do you know what CALEA is?

CALEA is United States law, FCC and Wikipedia links follow, 3rd link is recent scope change. https://www.fcc.gov/calea https://en.wikipedia.org/wiki/Communications_Assistance_for_Law_Enforcement_Act https://www.lermansenter.com/fcc-expands-scope-of-calea-obligations/ Lawful Interception is a global ...
by ConradPino
Thu Jan 30, 2025 1:13 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17 [stable] is released!

You could go to the EU Parliament and propose a law requiring all manufacturers to make their devices fully accessible for open-source operating systems, including the publication of specifications and all relevant documentation. I respect everyone's right to petition their governing authority for ...
by ConradPino
Thu Jan 30, 2025 1:07 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17 [stable] is released!

We only make changes that improve security of the users, none of those changes are to actively deny 3rd party OSes
@normis! So good to see you out and about. I find your reassurances both credible and compelling. Thank you,
by ConradPino
Thu Jan 30, 2025 1:04 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17 [stable] is released!

IMO "locking out" is deliberate and active act, "not publishing" can only be called "negligence" towards 3rd parties and is completely normal in normal (i.e. not "free as speach") corporate environments. ... So IMO ROS is MT's strength and they should focus o...
by ConradPino
Thu Jan 30, 2025 12:51 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17 [stable] is released!

Not publishing bootloader specs is effectively the same thing as locking out, for as long as somebody from 3rd parties hacks and reverse engineer it at least...
MikroTik has the choice to make it 3rd party software easy with full hardware disclosure or hard by doing nothing.
by ConradPino
Thu Jan 30, 2025 12:31 pm
Forum: General
Topic: Do you know what CALEA is?
Replies: 4
Views: 3363

Re: Do you know what CALEA is?

While I may not agree with every CALEA provision, I do say the law and it's provisions are not secret. Anybody paying attention knows everybody is subject to traffic analysis and occasionally content inspection. The implication is those that aren't aware they are vulnerable are just not paying atten...
by ConradPino
Thu Jan 30, 2025 12:17 pm
Forum: General
Topic: Bad switch? Crs326-24g-2s+
Replies: 2
Views: 2843

Re: Bad switch? Crs326-24g-2s+

CRS326 can show their uptime since last restart and they log startup events so consider logging setup to remote syslog to overcome limits of default limited memory log. CRS326 has real serial port so keeping device connected to watch CRS326 console activity is another way to observer device restarts...
by ConradPino
Wed Jan 29, 2025 9:59 pm
Forum: General
Topic: VLAN TAG STACKING WITH TAG VLAN
Replies: 6
Views: 2906

Re: VLAN TAG STACKING WITH TAG VLAN

See IEEE 802.1ad on Wikipedia
by ConradPino
Wed Jan 29, 2025 9:47 pm
Forum: General
Topic: MAC address table [SOLVED]
Replies: 6
Views: 5529

Re: MAC address table [SOLVED]

@OptiTech IMO while RouterOS CLI is powerful, it is not at all obvious even to experienced shell users; the where clause in particular.
https://help.mikrotik.com/docs/spaces/R ... alCommands
by ConradPino
Wed Jan 29, 2025 9:39 pm
Forum: General
Topic: VLAN TAG STACKING WITH TAG VLAN
Replies: 6
Views: 2906

Re: VLAN TAG STACKING WITH TAG VLAN

Thank for you answer , apparently there is no way to do that.
IMO QinQ to any level is supported provided bridge ether-type 0x88a8 (Service VLAN ID) is used.
by ConradPino
Wed Jan 29, 2025 1:34 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 161276

Re: v7.18beta [testing] is released!

... As I see there are two type of MTik users. Ones likes playing with new features and the others would likes to serve customers with existing features in a stable environment. Not so easy to make happy both types of users. IMO volume sales are with users needing easy to manage reliable network pe...
by ConradPino
Wed Jan 29, 2025 1:19 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17 [stable] is released!

What would make Mikrotik "special" in any use-worthy way if you would run other software on it? IMO MikroTik has market share by undercutting both enterprise and consumer devices. There is a forever market as the hardware performance value provider. RouterOS v7 changed development model u...
by ConradPino
Wed Jan 29, 2025 12:46 pm
Forum: General
Topic: High CPU usage
Replies: 12
Views: 3835

Re: High CPU usage

What does Profiler show?
by ConradPino
Wed Jan 29, 2025 12:32 pm
Forum: General
Topic: MAC address table [SOLVED]
Replies: 6
Views: 5529

Re: MAC address table [SOLVED]

Thanks for your input! Yeah ip arp is one option but I cannot search based on mac. Anyway my question was a bit off to begin with because routers don't generally build mac tables (ccr1072 doesn't even have a switch chip). /ip/arp/print where mac-address=xx:xx:xx:xx:xx:xx Switch chips have internal ...
by ConradPino
Wed Jan 29, 2025 4:39 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17 [stable] is released!

... I am already looking for other vendors unfortunately, after 16 years of Mikrotik use.
@normis this is what the start of MikroTik business failure looks like.
Bug fix RouterOS before everything else is the best hope.
Alternative is allow third party software on MT hardware.
by ConradPino
Wed Jan 29, 2025 4:19 am
Forum: Beginner Basics
Topic: How to reset logging to default settings? [SOLVED]
Replies: 2
Views: 6452

Re: How to reset logging to default settings? [SOLVED]

/system logging print
/system logging remove 4
by ConradPino
Tue Jan 28, 2025 2:51 am
Forum: Announcements
Topic: MikroTik smartphone app (ex Tik-App)
Replies: 498
Views: 296244

Re: MikroTik smartphone app (ex Tik-App)

@normis, please set this aside and get the RouterOS 7.17+ firestorm under control first.
by ConradPino
Mon Jan 27, 2025 9:38 pm
Forum: General
Topic: What to buy
Replies: 31
Views: 5462

Re: What to buy

IMO @rextended gives good advice; I recently bought RB5009 for router on a stick deployment. CRS305-1G-4S+IN $149.00 CRS326-24G-2S+IN $199.00 RB5009UG+S+IN $219.00 CRS309-1G-8S+IN $269.00 CRS3xx devices support L3 Hardware Offloading which can route and firewall at wire speed for some cases; the lea...
by ConradPino
Mon Jan 27, 2025 11:58 am
Forum: MikroTik hardware questions
Topic: ccr1072 cpu spikes and reboot issues
Replies: 2
Views: 4099

Re: ccr1072 cpu spikes and reboot issues

When reliable hardware starts misbehaving, verify cooling is working; check health (CPU temperature, fans speeds), visually verify fans.
by ConradPino
Sun Jan 26, 2025 4:31 am
Forum: General
Topic: GRE over IPSec tunnel - unusable on RB4011 above 7.15.3
Replies: 6
Views: 2742

Re: GRE over IPSec tunnel - unusable on RB4011 above 7.15.3

When using any tunnel protocol, consider making MTU changes to take tunnel overhead into account for preventing packet fragmentation.
by ConradPino
Sat Jan 25, 2025 1:38 am
Forum: General
Topic: How to monitor Internet (WAN) traffic separately for IPv4 and IPv6
Replies: 3
Views: 2565

Re: How to monitor Internet (WAN) traffic separately for IPv4 and IPv6

IPv4 and IPv6 firewalls are distinct (already split). Every firewall rule counts the bytes and packets it matches. The GUI interfaces have graphs.
by ConradPino
Fri Jan 24, 2025 8:06 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17 [stable] is released!

Thanks... But for what??? 🤷‍♂️
Helping @evilsabc, a generous and substantial commitment IMO.
by ConradPino
Fri Jan 24, 2025 7:44 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17 [stable] is released!

@rextended Thank you, and well done!
by ConradPino
Fri Jan 24, 2025 2:56 pm
Forum: General
Topic: Default values [SOLVED]
Replies: 15
Views: 5808

Re: Default values [SOLVED]

/interface/ethernet/reset [find] mtu=
Runs with no complaints and chooses 1500 as default with RouterOS 7.16.2.
by ConradPino
Fri Jan 24, 2025 2:49 pm
Forum: General
Topic: DHCPv6 server - assign address based on client MAC only
Replies: 7
Views: 2366

Re: DHCPv6 server - assign address based on client MAC only

Excerpt from RouterOS documenation: https://help.mikrotik.com/docs/spaces/R ... CPv6Server
RouterOS DHCPv6 server can only delegate IPv6 prefixes, not addresses.
I can't say I fully understand but it does raise concerns here.
by ConradPino
Fri Jan 24, 2025 1:34 pm
Forum: General
Topic: Default values [SOLVED]
Replies: 15
Views: 5808

Re: Default values [SOLVED]

/interface/ethernet/set [find] mtu=1500
by ConradPino
Fri Jan 24, 2025 1:22 pm
Forum: Beginner Basics
Topic: Boundary Clocks on CRS317 [SOLVED]
Replies: 10
Views: 6000

Re: Boundary Clocks on CRS317 [SOLVED]

Set priority1 and priority2 based upon what is known of device clock behavior to bias elections towards best known device clock.
by ConradPino
Fri Jan 24, 2025 1:07 pm
Forum: General
Topic: DHCPv6 server - assign address based on client MAC only
Replies: 7
Views: 2366

Re: DHCPv6 server - assign address based on client MAC only

I have a /60 delegation from Comcast: [admin@c53uig] > /ipv6/pool/print detail without-paging Flags: D - dynamic 0 D name="Comcast" prefix=2601:642:xxxx:xxx0::/60 prefix-length=64 expires-after=3d13h41m4s Assign a /64 to four (4) VLAN: /ipv6/address/add interface=vlan20 address=::1/64 from...
by ConradPino
Fri Jan 24, 2025 7:00 am
Forum: SwOS
Topic: sfp-sfpplus1 high temperature warning! [SOLVED]
Replies: 15
Views: 12176

Re: sfp-sfpplus1 high temperature warning! [SOLVED]

Sonic Internet is installing 10G FTTH; their ONT is RJ45 only. *sigh* I learned at 2.5G with CRS326 module shuts down above 87 F ambient; CRS326 CRS309 stacked on solid shelf in still air. I have since come to love SolidRack 10 with 1U separation above and below all networking devices plus external ...
by ConradPino
Fri Jan 24, 2025 1:58 am
Forum: Beginner Basics
Topic: Boundary Clocks on CRS317 [SOLVED]
Replies: 10
Views: 6000

Re: Boundary Clocks on CRS317 [SOLVED]

My PTP reading suggests any PTP enabled device coming online does peer discovery on enabled ports, and if discovered and depending on topology, boundary clocks are chosen if needed, and a grandmaster is found or elected as needed. Which devices become boundary clocks and grandmaster depend on priori...
by ConradPino
Wed Jan 22, 2025 8:14 am
Forum: General
Topic: L3 HW Offloading RB5009
Replies: 96
Views: 9890

Re: L3 HW Offloading RB5009

Lurker888 knows his stuff! Kudos to him!
Thank you for showing your appreciation; IMO Lurker and others add so much here the acknowledgment is well deserved.
by ConradPino
Wed Jan 22, 2025 5:30 am
Forum: General
Topic: Firmware updates (when software updates)
Replies: 4
Views: 3941

Re: Firmware updates (when software updates)

Default is leave firmware (RouterBOOT) as is. RouterBOOT upgrades usually not critical; RoutBOOT does hardware initialization and some changes require firmware upgrade. See https://help.mikrotik.com/docs/spaces/ROS/pages/40992878/RouterBOARD for "auto-upgrade" setting which automates a bit...
by ConradPino
Wed Jan 22, 2025 4:02 am
Forum: General
Topic: Logging Spanning Tree info on switches running RouterOS?
Replies: 7
Views: 2870

Re: Logging Spanning Tree info on switches running RouterOS?

Some "monitor" output follows: [admin@mtrb5009a] > /interface/bridge/monitor [find] once without-paging state: enabled current-mac-address: F4:1E:57:32:23:BD root-bridge: no root-bridge-id: 0x2000.D4:01:C3:99:D9:8E regional-root-bridge-id: 0x2000.D4:01:C3:99:D9:8E root-path-cost: 0 root-po...
by ConradPino
Wed Jan 22, 2025 3:37 am
Forum: General
Topic: Logging Spanning Tree info on switches running RouterOS?
Replies: 7
Views: 2870

Re: Logging Spanning Tree info on switches running RouterOS?

I see STP events only when interface changes state; unplug and replug same follows. [admin@mtrb5009a] /> /system/logging/export terse # 2025-01-21 17:32:30 by RouterOS 7.16.2 # software id = KWPA-GEH1 # # model = RB5009UG+S+ # serial number = XXXXXXXXXXX /system logging action add name=mempage targe...
by ConradPino
Tue Jan 21, 2025 10:33 pm
Forum: MikroTik hardware questions
Topic: CRS310-8G-2S-N All ports dead
Replies: 11
Views: 6127

Re: CRS310-8G-2S-N All ports dead

Serve The Homes does nice job showing the insides:
https://www.servethehome.com/mikrotik-c ... -switch/2/
by ConradPino
Tue Jan 21, 2025 9:13 pm
Forum: General
Topic: DHCPv6 server - assign address based on client MAC only
Replies: 7
Views: 2366

Re: DHCPv6 server - assign address based on client MAC only

2) If I get a prefix e.g. "fd3d:3e86:540f::/48" from my ISP via a DHCPv6 client, I can't create my own IPv6 pool e.g. "fd3d:3e86:540f:ffff::/64" - it prints an error "prefix of two pools cannot overlap!". How can this be solved? Thank you PD creates a dynamic pool that...
by ConradPino
Tue Jan 21, 2025 9:04 pm
Forum: Beginner Basics
Topic: Can the hEX support 2 WANs with IPv6 PD and both prefixes in one VLAN?
Replies: 1
Views: 2363

Re: Can the hEX support 2 WANs with IPv6 PD and both prefixes in one VLAN?

Can't say I've done so but based on reading and my single IPv6 PD experience, I would bet yes.
VLAN interface has dual IPv6 setup, one from each PD with RA enabled; clients see MikroTik as gateway.
Use different DHCP6 client gateway metric / priority setting to prefer a WAN.
by ConradPino
Tue Jan 21, 2025 8:49 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17 [stable] is released!

Here's some advice then, to everybody who complains every time there's a new release, from someone who's been doing this for 20+ years: Don't put brand new releases on your devices unless there's a feature or fix you specifically need, and even then, be prepared for other things to break. With Rout...
by ConradPino
Tue Jan 21, 2025 4:38 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17 [stable] is released!

Maybe you are willing to participate in the beta and rc cycles to identify more bugs, before it gets "stable" like I do? :-) Most users like myself can't afford to duplicate their network. IMO MikroTik is making two (2) mistakes, (A) sub-standard software testing (too many regressions) co...
by ConradPino
Tue Jan 21, 2025 4:15 pm
Forum: MikroTik hardware questions
Topic: Used Mikrotik routers for sale
Replies: 5
Views: 5589

Re: Used Mikrotik routers for sale

Searching forum topic titles for "sale" finds few; most viewed don't get much interest.
MikroTik staff Normis did comment here: viewtopic.php?t=49186&hilit=sale#p249842
by ConradPino
Mon Jan 20, 2025 4:40 pm
Forum: General
Topic: Public-Mikrotik-Bandwidth-Test-Server(s) ( shutting down on April 1st 2025 )
Replies: 1080
Views: 1277674

Re: Public-Mikrotik-Bandwidth-Test-Server(s)

Thank you, very useful to confirm Xfinity service 500/20 plan: 1 minute average was 24.2 Mbps/604.5 Mbps
by ConradPino
Mon Jan 20, 2025 4:15 pm
Forum: Virtualization
Topic: AWS X86 ROS7.17 [SOLVED]
Replies: 5
Views: 6205

Re: AWS X86 ROS7.17 [SOLVED]

Just curious, what makes CHR RouterOS attractive at AWS that VPC Security Groups and ACL don't cover?
by ConradPino
Mon Jan 20, 2025 3:48 pm
Forum: Beginner Basics
Topic: AnotherOS instead than RouterOS [SOLVED]
Replies: 13
Views: 13503

Re: AnotherOS instead than RouterOS [SOLVED]

GPL source code is public, not sure what you are talking about. Last time was when, in 1998?

This is the latest v7 GPL archive: https://box.mikrotik.com/d/81912835977544a291c9/
Given to anyone who needs it.
@normis the link shows Last Update 3 years ago. Has that code changed since then?
by ConradPino
Mon Jan 20, 2025 1:07 pm
Forum: Beginner Basics
Topic: Hardware Switching on CCR2004-16G-2S+
Replies: 6
Views: 3303

Re: Harware switching on CCR2004-16G-2S+

https://cdn.mikrotik.com/web-assets/product_files/CCR2004-16G-2S_240151.png Switch Chip 88E6191X times 2 with 8 ports per switch, supports Bridge VLAN Filtering. No L3 Hardware Offloading. https://help.mikrotik.com/docs/spaces/ROS/pages/15302988/Switch+Chip+Features https://help.mikrotik.com/docs/sp...
by ConradPino
Sun Jan 19, 2025 10:11 pm
Forum: MikroTik hardware questions
Topic: Used Mikrotik routers for sale
Replies: 5
Views: 5589

Re: Used Mikrotik routers for sale

IMO your topic is acceptable here. Consider trying here:
https://www.ebay.ie/sch/i.html?_nkw=Mik ... &_osacat=0
by ConradPino
Sat Jan 18, 2025 9:12 pm
Forum: General
Topic: L3 HW Offloading RB5009
Replies: 96
Views: 9890

Re: L3 HW Offloading

https://help.mikrotik.com/docs/spaces/R ... Offloading
Is Bridge Hardware Offloading enabled?
Swutch Chip model 88E6393X
by ConradPino
Sat Jan 18, 2025 7:47 pm
Forum: General
Topic: Feature Request: WINS Server
Replies: 8
Views: 6054

Re: Feature Request: WINS Server

Cosnider Active Directory, Domain Master Browser service.
https://en.wikipedia.org/wiki/Domain_Master_Browser
by ConradPino
Sat Jan 18, 2025 4:03 pm
Forum: MikroTik hardware questions
Topic: New Custom Enclosure for Mikrotik RBM33G
Replies: 1
Views: 4190

Re: New Custom Enclosure for Mikrotik RBM33G

I like your contribution. Thank you!
by ConradPino
Sat Jan 18, 2025 3:52 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17 [stable] is released!

@wuspmikrotik And yet, it seems that MikroTik is expected to know every possible scenario and real-world setup and perform functional tests to ensure that absolutely no one experiences any problems in their specific environment. MT should be using enterprise software development practices which inc...
by ConradPino
Sat Jan 18, 2025 3:31 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17 [stable] is released!

I believe there’s been a misunderstanding. I’m not looking to be a beta tester, as I use RouterOS in a private capacity and don’t have the inclination to take on that additional work. Good to know we are commonly situated. However, in a professional environment with dedicated network administrators...
by ConradPino
Sat Jan 18, 2025 3:21 pm
Forum: General
Topic: How to perform thorough data link filtering?
Replies: 9
Views: 2556

Re: How to perform thorough data link filtering?

Unless operating in SAFE mode, configuration commands are persisted and viewable with export command. Command I supplied is incomplete; and may require "chain=forward" amongst other parameters; I'm just drawing attention to the capability that is there despite the absent documentation. My ...
by ConradPino
Sat Jan 18, 2025 2:55 pm
Forum: General
Topic: STP Logging-How to [SOLVED]
Replies: 5
Views: 3869

Re: STP Logging-How to [SOLVED]

You're welcome. Besides limiting the topics, the distinct action is an isolated view.
by ConradPino
Sat Jan 18, 2025 3:32 am
Forum: General
Topic: STP Logging-How to [SOLVED]
Replies: 5
Views: 3869

Re: STP Logging-How to [SOLVED]

/system logging action add memory-lines=36 name=mempage target=memory
/system logging add action=mempage topics=stp
by ConradPino
Sat Jan 18, 2025 3:15 am
Forum: General
Topic: How to perform thorough data link filtering?
Replies: 9
Views: 2556

Re: How to perform thorough data link filtering?

The command line parser accepts this:
/interface bridge filter add action=drop mac-protocol=!arp,ip,0x888E
Enter that line fragment followed by TAB key to see what else you can add.
by ConradPino
Sat Jan 18, 2025 2:54 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17 [stable] is released!

Yeah and some random guy here dreamed *THIS* will be a long-term, because it took so long... LOL This is a typical MT point-zero release, 3 steps forward and 5 back... The long-term is as far away as with the v7.0 release. This is because many people wait for the final release to pull the trigger: ...
by ConradPino
Fri Jan 17, 2025 3:18 pm
Forum: General
Topic: Help needed. Separate internet access per port in the bridge
Replies: 4
Views: 1868

Re: Help needed. Separate internet access per port in the bridge

Stay with single bridge as switch chip hardware offload is limited to single bridge; added bridges are CPU only. Understand switch chip features: https://help.mikrotik.com/docs/spaces/ROS/pages/15302988/Switch+Chip+Features Use Bridge VLAN Filtering: https://help.mikrotik.com/docs/spaces/ROS/pages/3...
by ConradPino
Fri Jan 17, 2025 3:01 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215430

Re: v7.17 [stable] is released!

Due to a chip issue which reports board temperature MikroTik decided to remove this parameter from health.
The questions was "WHY?" What is the chip doing to cause this decision?
by ConradPino
Fri Jan 17, 2025 5:28 am
Forum: Beginner Basics
Topic: Help Wanted: Best practices to protect router and switch management access with bridge-tagged vlans [SOLVED]
Replies: 10
Views: 6451

Re: Help Wanted: Best practices to protect router and switch management access with bridge-tagged vlans [SOLVED]

You haven't posted your configuration (redact security sensitive values and serial number); don't expect much until you do.
by ConradPino
Fri Jan 17, 2025 2:17 am
Forum: General
Topic: RouterOS 7.16.2 NTP Client
Replies: 3
Views: 1715

Re: RouterOS 7.16.2 NTP Client

Well, now I know disabling every firewall rule has no effect.
by ConradPino
Fri Jan 17, 2025 1:35 am
Forum: General
Topic: RouterOS 7.16.2 NTP Client
Replies: 3
Views: 1715

Re: RouterOS 7.16.2 NTP Client

Bah, humbug! Works when after adding default gateway IP address (hAP ax3 running NTP server). Good enough to move forward.
You know, I should disable the firewall since I just presumed it was not in play. Thanks for the reply, helps the mind work here.
by ConradPino
Thu Jan 16, 2025 8:51 pm
Forum: Beginner Basics
Topic: Help Wanted: Best practices to protect router and switch management access with bridge-tagged vlans [SOLVED]
Replies: 10
Views: 6451

Re: Help Wanted: Best practices to protect router and switch management access with bridge-tagged vlans [SOLVED]

Assumption: When running Bridge VLAN setups, the bridge must be a tagged port on the VLAN for Layer 3 services to function through the network.
Assumption is false; make all bridge VLAN untagged. Make exceptions with:
/interface vlan add interface=bridge name=vlan40 vlan-id=40
by ConradPino
Thu Jan 16, 2025 8:43 pm
Forum: Scripting
Topic: Copy files from the MikroTik router via SMB
Replies: 9
Views: 5848

Re: Copy files from the MikroTik router via SMB

You don't need rose package.
Agrees; my bad.
by ConradPino
Thu Jan 16, 2025 8:36 pm
Forum: General
Topic: RouterOS 7.16.2 NTP Client
Replies: 3
Views: 1715

RouterOS 7.16.2 NTP Client

I'm adding RB5009U to hAP ax3 and CRS3xx fleet. Bridge VLAN Filtering for multiple VLAN/subnets is working; no switching issues IPv4/IPv6 routing and firewall are working; RouterOS package upgrades work. hAP ax3 has WAN interface; all RB5009U ports are on default bridge. All RB5009U interfaces are i...
by ConradPino
Thu Jan 16, 2025 7:20 pm
Forum: Scripting
Topic: Copy files from the MikroTik router via SMB
Replies: 9
Views: 5848

Re: Copy files from the MikroTik router via SMB

Add ROSE-storage package and reboot then create SMB disk:
/disk add type=smb ...
by ConradPino
Thu Jan 16, 2025 7:01 pm
Forum: General
Topic: DMZ Pinhole
Replies: 27
Views: 7409

Re: DMZ Pinhole

There seems to be many ways to configure the RouterOS and your answer seems a bit "my way is best" and misses the question completely. You misunderstand, @anav was polite whereas I will say "your way is worse and you've killed your performance", see Layer2 misconfiguration - Bri...
by ConradPino
Thu Jan 16, 2025 6:39 pm
Forum: General
Topic: Issues when WAN and LAN network are on the same switch
Replies: 4
Views: 2676

Re: Issues when WAN and LAN network are on the same switch

You have switching loops in your broadcast domain: unmanaged switch and MikroTik bridge interface. The Spanning Tree Protocol may block ports.
Placing insecure and secure subnets on same switch is bad practice; just plug modem directly into MT WAN port for security and reliability.
by ConradPino
Wed Jan 15, 2025 10:47 am
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 23598

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

How about Rate Limiting with Nginx? Works well for a customer's Java web application to restrain the crawler bots.
by ConradPino
Mon Jan 13, 2025 4:49 pm
Forum: General
Topic: Mikrotik for long-haul fiber.
Replies: 15
Views: 3197

Re: Mikrotik for long-haul fiber.

For high ambient temperature, CRS309 needs good air flow; assure 1U clearance above and below each unit; consider temperature controlled fan to vent the cabinet. 10G-Base-T modules get quite hot, be prepared to 3D print side fan mount for 120mm x 32mm centrifugal blower to move air sideways through ...
by ConradPino
Tue Jan 07, 2025 6:33 am
Forum: General
Topic: Can somebody help me understand IPv6 subnets?
Replies: 6
Views: 2775

Re: Can somebody help me understand IPv6 subnets?

/ipv6 address add from-pool=test-ipv6 address=::1/64 interface=WIRED_VLAN0 advertise=yes no-dad=yes /ipv6 address add from-pool=test-ipv6 address=::1/64 interface=WIRED_VLAN1 advertise=yes no-dad=yes /ipv6 address add from-pool=test-ipv6 address=::1/64 interface=WIRED_VLAN2 advertise=yes no-dad=yes...
by ConradPino
Tue Feb 06, 2024 3:09 am
Forum: General
Topic: User poll about using Winbox
Replies: 107
Views: 113497

Re: User poll about using Winbox

  • CLI is only built-in script friendly configuration mechanism
  • WebFig and Winbox are both script hostile GUI tools
  • WebFig is built-in and sufficiently useful
  • Winbox is not built-in and superfluous
Winbox has an audience but it's not universal.
by ConradPino
Sat Sep 30, 2023 3:22 am
Forum: Forwarding Protocols
Topic: radvd invalid mtu log spam
Replies: 4
Views: 3872

Re: radvd invalid mtu log spam

Example from hAP ax3 core router deployment:
/ipv6 firewall raw
add action=drop chain=prerouting icmp-options=134:0-255 in-interface=vlanIX protocol=icmpv6
Neighbor Discovery packets received from upstream router are dropped.
by ConradPino
Wed Sep 27, 2023 7:05 am
Forum: Beginner Basics
Topic: My IoT project for my home
Replies: 2
Views: 969

Re: My IoT project for my home

Try these ping tests between the following devices:
  • wlan1 192.168.0.10 and PC 192.168.0.2
  • wlan1 192.168.0.10 and Mobile Phone 192.168.0.n
If wlan1 is reachable from those Clients (PC & Mobile) then adding routes to Client routing tables makes IoT and RP reachable from Clients.
by ConradPino
Sat Sep 23, 2023 11:44 pm
Forum: General
Topic: Should moderators redact sensitive info, and how much?
Replies: 49
Views: 4949

Re: Should moderators redact sensitive info, and how much?

Never infringe the original poster's right to be stupid! :lol:
by ConradPino
Fri Sep 22, 2023 3:34 am
Forum: General
Topic: simple routing problem
Replies: 2
Views: 581

Re: simple routing problem

What are the distance values for all routes?
Try a larger distance value for backup route.
by ConradPino
Fri Sep 22, 2023 2:49 am
Forum: General
Topic: How to merge 2 differents trunk + VLANs to one trunk?
Replies: 18
Views: 2263

Re: How to merge 2 differents trunk + VLANs to one trunk?

@maxspeed this is a classic XY Problem I have better uses for my time.
Disabling Spanning Tree Protocol is an issue; VLAN aware MSTP is best choice.
Parting thought: Layer2 misconfiguration § Bridges on a single switch chip
by ConradPino
Fri Sep 22, 2023 1:30 am
Forum: General
Topic: How to merge 2 differents trunk + VLANs to one trunk?
Replies: 18
Views: 2263

Re: How to merge 2 differents trunk + VLANs to one trunk?

Use one bridge on the CCR2116, not two separate ones, and configure the /interface bridge vlan membership accordingly on the two trunks. General agreement but I suggest holding off on big changes until requirements are completely known. You do not need /interface vlan and /ip address entries for ev...
by ConradPino
Fri Sep 22, 2023 1:20 am
Forum: General
Topic: How to merge 2 differents trunk + VLANs to one trunk?
Replies: 18
Views: 2263

Re: How to merge 2 differents trunk + VLANs to one trunk?

OSPF operates over IP / layer 3, VLANs operate over ethernet /layer 2 - they are completely unrelated to each other. Technically correct. The block on the diagram "OSPF link with 8 subnet with1 Trunk inside of ccr2116 - 8 vlans id:100-107" makes absolutely no sense. One broadcast domain (...
by ConradPino
Thu Sep 21, 2023 2:12 pm
Forum: General
Topic: How to merge 2 differents trunk + VLANs to one trunk?
Replies: 18
Views: 2263

Re: How to merge 2 differents trunk + VLANs to one trunk?

Suggested documentation answers questions posed but the experience to recognize them as such suggests appears absent and coming here can help fill that gap. It's not uncommon for users to share a problem and leave with working solution developed from a dialogue between original poster (OP) and forum...
by ConradPino
Wed Sep 20, 2023 3:47 pm
Forum: General
Topic: Webfig Enhancement
Replies: 24
Views: 7689

Re: Webfig Enhancement

Webfig and Winbox are very similar, but Winbox is more user friendly, it has side by side windows and such features. It was an honest question. If one thing has something you need, why keep using the other thing ... Winbox is an extra download an extra installation an extra learning curve an extra ...
by ConradPino
Wed Sep 20, 2023 3:12 pm
Forum: General
Topic: Webfig Enhancement
Replies: 24
Views: 7689

Re: Webfig Enhancement

I only used CLI to export/import large sections of configuration
Welcome brother, sorry you hear your escape attempt failed.
by ConradPino
Mon Sep 18, 2023 11:11 pm
Forum: General
Topic: How to merge 2 differents trunk + VLANs to one trunk?
Replies: 18
Views: 2263

Re: How to join several VLANs from 2 switches to one Bridge?

could you just explain your idea please, i try to figure the way
No, a short explanation is not possible. The solution is Bridge VLAN Filtering.
Start reading here: https://help.mikrotik.com/docs/display/ ... NFiltering
by ConradPino
Mon Sep 18, 2023 11:03 pm
Forum: Virtualization
Topic: Unable to upgrade CHR license
Replies: 2
Views: 4600

Re: Unable to upgrade CHR license

What I am doing wrong?
IMO probably nothing. I concluded that function "needs substantial improvement".
by ConradPino
Mon Sep 18, 2023 10:52 pm
Forum: General
Topic: How to merge 2 differents trunk + VLANs to one trunk?
Replies: 18
Views: 2263

Re: How to join several VLANs from 2 switches to one Bridge?

I would like to know if it's possible to join several VLANs from 2 differents switches to only one Bridge with another switch? Question : is it possible to do that or do you have a better solution TL;DR Yes, IMO it's possible. However a VLAN specification for EVERY PORT on EVERY SWITCH is needed to...
by ConradPino
Mon Sep 18, 2023 10:18 pm
Forum: General
Topic: Webfig Enhancement
Replies: 24
Views: 7689

Re: Webfig Enhancement

Why are you using Webfig and not Winbox? @normis - What an incredibly arrogant question! Worse you've asked this elsewhere with similar tone . Winbox is another learning curve not worth learning when CLI is best tool and Webfig is good visual tool. IMO RouterOS CLI is eventually inescapable and a v...
by ConradPino
Mon Sep 18, 2023 9:25 pm
Forum: MikroTik hardware questions
Topic: CRS309 + Intel X520 no link
Replies: 2
Views: 3305

Re: CRS309 + Intel X520 no link

CRS309-1G-8S+IN operates with eight (8) Arista Networks SFP-10G-SR at 10Gbps.
by ConradPino
Sun Sep 10, 2023 10:54 am
Forum: Scripting
Topic: Traffic-Generator not stopping
Replies: 1
Views: 2159

Re: Traffic-Generator not stopping

The quick command has duration property defined as "how long to run the test".
by ConradPino
Sat Sep 09, 2023 10:31 pm
Forum: Announcements
Topic: Newsletter #114 | September 2023
Replies: 79
Views: 23786

Re: Newsletter #114 | September 2023

Zero PoE please or models with and without like RB5009.
by ConradPino
Sat Sep 09, 2023 9:55 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 190968

Re: v7.11.2 [stable] is released!

From MikroTik Devices Controller topic, post #293 : https://forum.mikrotik.com/viewtopic.php?t=186352#p1023643 Before making a big commitment to a new software product; let's get the bread and butter products in order: RouterOS 7 "stable" becomes truly stable ( not just a label ) first and...
by ConradPino
Sat Sep 09, 2023 10:25 am
Forum: Virtualization
Topic: RouterOS CHR 7.11 Wifiwave2 Training
Replies: 4
Views: 6260

Re: RouterOS CHR 7.11 Wifiwave2 Training

virtualized radio hardware
Thank you! Can you elaborate on how the above might be done?

hAP ax3 is my core router. Is hAP ax2 a suitable configuration testing proxy for ax3?
by ConradPino
Sat Sep 09, 2023 4:10 am
Forum: Wireless Networking
Topic: hAP as Station?
Replies: 5
Views: 2253

Re: hAP as Station?

If Tasmota device has working default gateway then port NAT may be enough. If not then full IP address NAT is the next option I'd consider.
by ConradPino
Sat Sep 09, 2023 3:57 am
Forum: MikroTik hardware questions
Topic: Mikrotik S+RJ10 third party switch compatibility [SOLVED]
Replies: 2
Views: 7044

Re: Mikrotik S+RJ10 third party switch compatibility [SOLVED]

I use one in CRS326-24G-2S+IN (passive cooling) running at 2.5G to hAP ax3. At 86F ambient RouterOS monitor shows 86C : name: sfp-sfpplus1 status: link-ok auto-negotiation: done rate: 2.5Gbps full-duplex: yes tx-flow-control: no rx-flow-control: no advertising: 10M-half,10M-full,100M-half,100M-full,...
by ConradPino
Fri Sep 08, 2023 11:07 pm
Forum: General
Topic: Hardware offloaded vlan traffic counters
Replies: 3
Views: 1628

Re: Hardware offloaded vlan traffic counters

@boydsoftprez Congratulations; I call your research a significant accomplishment. IMO you have the right question but I have no answer. This is a user forum and some user may know. MikroTik staff watch the forum, participate on occasion but make no commitment to do so. Getting a definitive answer fr...
by ConradPino
Fri Sep 08, 2023 9:14 pm
Forum: Beginner Basics
Topic: OS 7.11 and old Mikrotik HAP lite
Replies: 8
Views: 7197

Re: OS 7.11 and old Mikrotik HAP lite

7.11.1 fixed 7.11 bugs but introduced DHCP server bug resolved in 7.11.2 version.
by ConradPino
Fri Sep 08, 2023 9:21 am
Forum: MikroTik hardware questions
Topic: Waiting for wAP ax...
Replies: 4
Views: 4443

Re: Waiting for wAP ax...

Gods punish mortals by granting their prayers. :lol: Be aware of the ongoing Wifiwave2 melodrama.
I'm happy with new hAP ax3 but then my WiFi use is just for the toys; real work happens over cables.
by ConradPino
Fri Sep 08, 2023 7:32 am
Forum: Beginner Basics
Topic: Bridge dst-nat packets disappear
Replies: 4
Views: 2119

Re: Bridge dst-nat packets disappear

Anyway. I wanted to try using layer 2 dst-nat instead of hairpins, like how DSR operates with load balancers: instead of substitution the dst IP address, the dst-nat rule replaces the dst MAC in the packet with that of the server, leaving the dst IP address alone. The server gets the packet, and re...
by ConradPino
Fri Sep 08, 2023 6:18 am
Forum: Forwarding Protocols
Topic: Load Balancing via BGP routes
Replies: 6
Views: 4079

Re: Load Balancing via BGP routes

@silence012 I defer to @clambert advice as better.
by ConradPino
Fri Sep 08, 2023 5:21 am
Forum: Forwarding Protocols
Topic: Load Balancing via BGP routes
Replies: 6
Views: 4079

Re: Load Balancing via BGP routes

Current RougerOS documentation has 11 steps but I don't know the significance. I suggest consult both keeping in mind wiki is deprecated. Also keep in mind current documentation is a work in progress, and sometimes incomplete where the wiki says more. Current RouterOS BGP § Best-Path Selection : htt...
by ConradPino
Fri Sep 08, 2023 3:37 am
Forum: MikroTik hardware questions
Topic: UK Power Supply for hAP AX3
Replies: 20
Views: 5945

Re: UK Power Supply for hAP AX3

@normis I find your and others reassurances credible and apologize for being unclear about what motivated my alarm. US law has product liability provisions that some dumb consumer or a cash hungry litigator might try to exploit. I hope such a thing never happens to my favorite network equipment vend...
by ConradPino
Fri Sep 08, 2023 3:15 am
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 190968

Re: v7.11, 7.11.1 and more [stable] are released!

7.11 or 7.11.1 broke my terminal/console in my RB4011. (Both through terminal in winbox and ssh). But after emailing with support they convinced me to try the latest development version (v7.12beta3 atm). That fixed the problem. Now let's hope it doesn't break other stuff. :) Did 7.11.2 play a part ...
by ConradPino
Fri Sep 08, 2023 3:03 am
Forum: MikroTik hardware questions
Topic: CRS3xx: switching vs bridging ?
Replies: 12
Views: 4744

Re: CRS3xx: switching vs bridging ?

My main conclusion is that, if VLAN features (802.1q) are fully offloaded, I should not care if CRS312 has slower CPU/bridging than CRS309. Generally true if VLAN 802.1Q is the only bridge feature in play, it should be hardware offloaded. Perform due diligence on possible future bridge features fal...
by ConradPino
Thu Sep 07, 2023 9:23 pm
Forum: Wireless Networking
Topic: nvidia shield can't connect to 5 GHz Wi-Fi on hAP ac2
Replies: 8
Views: 4557

Re: nvidia shield can't connect to 5 GHz Wi-Fi on hAP ac2

@mkx Thank you; an excellent response!
by ConradPino
Thu Sep 07, 2023 8:32 pm
Forum: Wireless Networking
Topic: nvidia shield can't connect to 5 GHz Wi-Fi on hAP ac2
Replies: 8
Views: 4557

Re: nvidia shield can't connect to 5 GHz Wi-Fi on hAP ac2

Well done.
Agreed!

the effect of USB3 on WiFi 2.4GHz is known and understood,
Please educate the uninformed with a brief description or suggest Google Search terms.
by ConradPino
Thu Sep 07, 2023 8:23 pm
Forum: MikroTik hardware questions
Topic: CRS3xx: switching vs bridging ?
Replies: 12
Views: 4744

Re: CRS3xx: switching vs bridging ?

But that still doesn't make these two "not distinct" ...
If the line is drawn at hardware offload or not then I agree.
Are these idiomatic distinctions helpful to the OP?
by ConradPino
Thu Sep 07, 2023 7:53 pm
Forum: MikroTik hardware questions
Topic: CRS3xx: switching vs bridging ?
Replies: 12
Views: 4744

Re: CRS3xx: switching vs bridging ?

Since the RouterOS bridge is the management device for the underlying switch chip, that blurs a sharp distinction IMO.
by ConradPino
Thu Sep 07, 2023 7:28 pm
Forum: MikroTik hardware questions
Topic: CRS3xx: switching vs bridging ?
Replies: 12
Views: 4744

Re: CRS3xx: switching vs bridging ?

CRS3xx devices use the Bridge VLAN Filtering model. I recommend these RouterOS documentation pages: Bridging and Switching - https://help.mikrotik.com/docs/display/ROS/Bridging+and+Switching Bridge VLAN Filtering - https://help.mikrotik.com/docs/display/ROS/Bridging+and+Switching#BridgingandSwitchin...
by ConradPino
Thu Sep 07, 2023 10:25 am
Forum: Beginner Basics
Topic: CRS125-24G-1S and a Dell 6224 managed switch [SOLVED]
Replies: 7
Views: 3312

Re: CRS125-24G-1S and a Dell 6224 managed switch [SOLVED]

Consider CRS125-24G-1S-IN Block Diagram: https://i.mt.lv/cdn/product_files/CRS125-24G-1S-160620160458_160658.png Single 26 port Switch Chip suggests different subnets on different ports requires isolating ports with a VLAN implementation. Review RouterOS CRS1xx/2xx series switches page for design gu...
by ConradPino
Thu Sep 07, 2023 10:10 am
Forum: Beginner Basics
Topic: Lan in bridge2 cannot ping Lan in bridge3 (router is reset no default configuration) [SOLVED]
Replies: 9
Views: 2088

Re: Lan in bridge2 cannot ping Lan in bridge3 (router is reset no default configuration) [SOLVED]

RB951G-2HnD incorporates Atheros8327 switch chip; see Block Diagram: https://i.mt.lv/cdn/product_files/RB951G-150611115818_150618.png Multiple bridges is a documented error; see Bridges on a single switch chip: https://help.mikrotik.com/docs/display/ROS/Layer2+misconfiguration#Layer2misconfiguration...
by ConradPino
Thu Sep 07, 2023 1:50 am
Forum: Beginner Basics
Topic: RB5009 RouterOS License 6 [SOLVED]
Replies: 19
Views: 5441

Re: RB5009 RouterOS License 6 [SOLVED]

i disagree, the main diferentiator between L5 and L6 is User manager active sessions Limit, Which in L5 is 50, in L6 is Unlimited
You are correct; I failed to look further down time table and ignored two other differences.
by ConradPino
Thu Sep 07, 2023 1:44 am
Forum: MikroTik hardware questions
Topic: UK Power Supply for hAP AX3
Replies: 20
Views: 5945

Re: UK Power Supply for hAP AX3

@normis, @mkx is making an excellent point and it's worse than what's said so far. My hAP ax3 US PSU has a 1.3A rating. At 15W typical and 24V the draw is 0.625A. IMO I'm good. But at 38W maximum and 24V, the draw is 1.58A which exceeds 1.2A and 1.5A ratings seen so far. If MikroTik is serious about...
by ConradPino
Wed Sep 06, 2023 10:45 pm
Forum: Beginner Basics
Topic: RB5009 RouterOS License 6 [SOLVED]
Replies: 19
Views: 5441

Re: RB5009 RouterOS License 6 [SOLVED]

Level can be upgraded, it simply cannot be upgraded with discount , but can be purchased for full price. Well, now we know why that doesn't happen very often. Not a good value IMO. Can you clarify (OP) which Level 6 features you need in this device, that are not present in Level 5? I never said I n...
by ConradPino
Wed Sep 06, 2023 10:11 pm
Forum: MikroTik hardware questions
Topic: UK Power Supply for hAP AX3
Replies: 20
Views: 5945

Re: UK Power Supply for hAP AX3

I call that one similar but not the same model except for color due to the differing current rating.
I'm in the United States ... maybe the question was a small troll on a useful marketing message.
by ConradPino
Wed Sep 06, 2023 5:30 pm
Forum: Beginner Basics
Topic: MikroTik Forum Private Messages [SOLVED]
Replies: 2
Views: 1776

Re: MikroTik Forum Private Messages [SOLVED]

There is "zero level" messaging on the forum.
Clear, concise, and so complete. Thank you!
by ConradPino
Wed Sep 06, 2023 5:12 pm
Forum: Beginner Basics
Topic: MikroTik Forum Private Messages [SOLVED]
Replies: 2
Views: 1776

MikroTik Forum Private Messages [SOLVED]

The User Control Panel page, Board preferences tab, has Allow users to send you private messages: options.
phpBB documentation has Communicate with Private Messages page: https://www.phpbb.com/support/docs/en/3 ... e/user_pm/

What level of private messaging is practiced here?
by ConradPino
Wed Sep 06, 2023 4:39 pm
Forum: Beginner Basics
Topic: RB5009 RouterOS License 6 [SOLVED]
Replies: 19
Views: 5441

Re: RB5009 RouterOS License 6 [SOLVED]

L5 and L6 differences are three specialized tunnel protocols I may not use but that's not my topic.

My topic is how do I get a given MT hardware device from L5 to L6 should I ever really need to do so.
by ConradPino
Wed Sep 06, 2023 4:27 pm
Forum: General
Topic: Bridge Ethernet1 Port can set 2 pvid
Replies: 6
Views: 1916

Re: Bridge Ethernet1 Port can set 2 pvid

PVID is the VLAN id
  • assigned to untagged ingress packets
  • allowed to egress as untagged packets
Bridge ports have one and only one PVID.
Second statement is just overriding the first.
by ConradPino
Wed Sep 06, 2023 4:15 pm
Forum: Beginner Basics
Topic: RB5009 RouterOS License 6 [SOLVED]
Replies: 19
Views: 5441

Re: RB5009 RouterOS License 6 [SOLVED]

Also take into account AX3 costs about 50% for HW and license then L6 license purchased separately.
IMO hAP ax3 is a sweet spot and I'm very pleased with mine.
hAP ax3 just lacks dual SFP+ ports to be "perfect".
RB5009 L6 with one SFP+ port is good enough.
by ConradPino
Wed Sep 06, 2023 4:11 pm
Forum: Beginner Basics
Topic: RB5009 RouterOS License 6 [SOLVED]
Replies: 19
Views: 5441

Re: RB5009 RouterOS License 6 [SOLVED]

So the problem is hAP ax3 having L6 License,
No, hAP ax3 at L6 is quite nice which makes RB5009 at L5 seem odd.
by ConradPino
Wed Sep 06, 2023 3:52 pm
Forum: General
Topic: HW3 CCR 2116 Problem
Replies: 9
Views: 2179

Re: HW3 CCR 2116 Problem

I don't have Loop problems, they are different broadcasts, there is no Router bridge. My problem is with the HW3 option Consider that if you were correct you would not be here. Consider that you just destroyed any incentive to help you. Getting the most out of this forum by normis, MikroTik Support
by ConradPino
Wed Sep 06, 2023 3:26 pm
Forum: General
Topic: HW3 CCR 2116 Problem
Replies: 9
Views: 2179

Re: HW3 CCR 2116 Problem

RSTP is not VLAN aware whereas MSTP is: https://help.mikrotik.com/docs/display/ ... eeProtocol
by ConradPino
Wed Sep 06, 2023 3:23 pm
Forum: Beginner Basics
Topic: RB5009 RouterOS License 6 [SOLVED]
Replies: 19
Views: 5441

Re: RB5009 RouterOS License 6 [SOLVED]

The License Levels section is clear enough. The Obtaining Licenses and Working With Them section seems woefully incomplete. Can I upgrade a hardware device license level at all? How is that done without actually doing so? If possible then at what price? I am also advocating the RB5009 standard licen...
by ConradPino
Wed Sep 06, 2023 3:04 pm
Forum: Beginner Basics
Topic: RB5009 RouterOS License 6 [SOLVED]
Replies: 19
Views: 5441

RB5009 RouterOS License 6 [SOLVED]

hAP ax3 at RouterOS License 6 is perfect with current Comcast 1.2G download service. Sonic.com is coming to my street with symmetric 10G fiber service. RB5009 at RouterOS License 6 matches a Sonic future well. I don't understand the product design where better RB5009 is licensed at lower level where...
by ConradPino
Wed Sep 06, 2023 1:51 pm
Forum: Wireless Networking
Topic: PSK2 passphrase based VLANs + capsman
Replies: 6
Views: 2769

Re: dynamic VLANs + capsman

No, not so far. Both versions can coexist in same LAN, but on two different devices.
Thank you; greatly appreciated.
by ConradPino
Wed Sep 06, 2023 1:44 pm
Forum: MikroTik hardware questions
Topic: UK Power Supply for hAP AX3
Replies: 20
Views: 5945

Re: UK Power Supply for hAP AX3

We supply the hAP AX3 with the following UK Mikrotik PSU as standard:
Do you have it in black?
by ConradPino
Wed Sep 06, 2023 1:18 pm
Forum: MikroTik hardware questions
Topic: UK Power Supply for hAP AX3
Replies: 20
Views: 5945

Re: UK Power Supply for hAP AX3

Don't overlook current (Ampere) rating.
by ConradPino
Wed Sep 06, 2023 12:47 pm
Forum: Wireless Networking
Topic: PSK2 passphrase based VLANs + capsman
Replies: 6
Views: 2769

Re: dynamic VLANs + capsman

CapsMAN has split into two branches to follow the WiFi driver split: The Wireless package (legacy driver) The Wifiwave2 package (new hardware) CapsMAN for each driver supports it's driver version alone. I believe but not sure both CapsMAN versions can coexist on same host. Consider describing WiFi d...
by ConradPino
Wed Sep 06, 2023 12:36 pm
Forum: Virtualization
Topic: CHR + ESXi 6.7 U3 tx-drops with VLANs
Replies: 3
Views: 10308

Re: CHR + ESXi 6.7 U3 tx-drops with VLANs

Consider testing with e1000e driver instead of VMXNET3.
by ConradPino
Wed Sep 06, 2023 4:53 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 7436

Re: Multiple Physical Hosts behind Single (dynamic) IP?

https://roll.urown.net/ . Says nothing regarding VLAN or Layer 2 Broadcast Domains ; see: https://en.wikipedia.org/wiki/Broadcast_domain The parapgraphs upto the table of contents are the key points for this topic. Broadcast domains are the IPv4 ARP and IPv6 ND boundaries: https://en.wikipedia.org/...
by ConradPino
Wed Sep 06, 2023 4:44 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 7436

Re: Multiple Physical Hosts behind Single (dynamic) IP?

Google Docs supports these sharing models:
  • Private to Google account owner.
  • Public to anyone and Google Search.
  • Visible to anyone with the obscure link
  • Visible to selected authenticated Google accounts.
I propose the latter and after we're done, redacting for publication is an option.
by ConradPino
Wed Sep 06, 2023 3:05 am
Forum: Announcements
Topic: MikroTik Devices Controller
Replies: 380
Views: 275483

Re: MikroTik Devices Controller

Before making a big commitment to a new software product; let's get the bread and butter products in order: RouterOS 7 "stable" becomes truly stable ( not just a label ) first and foremost before all else. RouterOS 7 becomes feature complete first and foremost before new software products....
by ConradPino
Wed Sep 06, 2023 2:45 am
Forum: MikroTik hardware questions
Topic: x86 Mikrotik v7 performance - choosing the x86 CPU
Replies: 19
Views: 15466

Re: x86 Mikrotik v7 performance - choosing the x86 CPU

I believe this relationship has some merit: 14 * 2.6 = 36.4 22 * 2.2 = 48.4 I expect lower clock speed to affect single packet latency. I expect 22 cores to have more concurrent packets in flight. RouterOS v6 v7 have Linux kernels at differing versions I don't recall. When port speed is the bottlene...
by ConradPino
Wed Sep 06, 2023 2:34 am
Forum: General
Topic: Everything on latest OS version [SOLVED]
Replies: 10
Views: 2653

Re: Everything on latest OS version [SOLVED]

Tell me how foolish this is.
Tell us about the pain or absence thereof please.
  • 1
  • 2