Remember Safe Mode before make change.
Code: Select all
/interface/bridge/set bridge vlan-filtering=yes
/interface/bridge/set bridge vlan-filtering=yes
/interface/ethernet/monitor sfp-sfpplusN once without-paging
When omitted fromFor this topic, where VLAN Filtering is the goal, Fast Forward's status is irrelevant, it would be inactive anyway.
/interface bridge
fast-forward
yes
fast-forward=no
Another strike against Winbox!Yeah, that also means Winbox 4 won't run on anything older than Windows 10 (ie, no XP, Vista or Win 7/8).
I try to pay attention but find that alone doesn't guarantee me success.I hope that my point of view is clear to you.
It's fine for what it does for it's intended network model.Where is the default firewall flawed for a very simple standard connection between WAN and LAN?
@normis, thank you and please thank Druvis Timma for making that update Feb 07, 2025 10:17. IMO a super addition.Swap is not for the host system. Please read the manual about it before complaining: https://help.mikrotik.com/docs/spaces/R ... -Swapspace
Fun image, thanks!Hahaha okay, I will catch a ride the next time the orange drag president flys by in his sleigh......
Serving compressed assets over HTTPS is the BREACH security vulnerability.I did not know ROS uses squashfs. But good to know. But still one observation remains valid: webfig assets are served uncompressed.
Unicast FDB (Forwarding Database) is mentioned here: CRS3xx, CRS5xx, CCR2116, CCR2216 switch chip features § FeaturesI don't know if the "Unicast FDB" is an important thing?
Define FT please.Seems like the CRS310 I proposed doesn't support FT offloading, so it seems that that won't do then? Am I correct?
Well said and thank you!I completely agree with you.
Thank you! Please come back and continue stressing what makes MirkoTik products useful.... Please make it possible to upgrade while keeping all features enabled as it was before the upgrade.
The innocent newcomer will be with us forever and they too deserve our best efforts.No need to warn them in 2025...
@normis! So good to see you out and about. I find your reassurances both credible and compelling. Thank you,We only make changes that improve security of the users, none of those changes are to actively deny 3rd party OSes
MikroTik has the choice to make it 3rd party software easy with full hardware disclosure or hard by doing nothing.Not publishing bootloader specs is effectively the same thing as locking out, for as long as somebody from 3rd parties hacks and reverse engineer it at least...
IMO QinQ to any level is supported provided bridge ether-type 0x88a8 (Service VLAN ID) is used.Thank for you answer , apparently there is no way to do that.
@normis this is what the start of MikroTik business failure looks like.... I am already looking for other vendors unfortunately, after 16 years of Mikrotik use.
/system logging print
/system logging remove 4
Helping @evilsabc, a generous and substantial commitment IMO.Thanks... But for what??? 🤷♂️
/interface/ethernet/reset [find] mtu=
/interface/ethernet/set [find] mtu=1500
Thank you for showing your appreciation; IMO Lurker and others add so much here the acknowledgment is well deserved.Lurker888 knows his stuff! Kudos to him!
@normis the link shows Last Update 3 years ago. Has that code changed since then?GPL source code is public, not sure what you are talking about. Last time was when, in 1998?
This is the latest v7 GPL archive: https://box.mikrotik.com/d/81912835977544a291c9/
Given to anyone who needs it.
/ipv6/neighbor/print detail without-paging where mac-address=<MAC>
/system logging action add memory-lines=36 name=mempage target=memory
/system logging add action=mempage topics=stp
/interface bridge filter add action=drop mac-protocol=!arp,ip,0x888E
The questions was "WHY?" What is the chip doing to cause this decision?Due to a chip issue which reports board temperature MikroTik decided to remove this parameter from health.
Assumption is false; make all bridge VLAN untagged. Make exceptions with:Assumption: When running Bridge VLAN setups, the bridge must be a tagged port on the VLAN for Layer 3 services to function through the network.
/interface vlan add interface=bridge name=vlan40 vlan-id=40
Agrees; my bad.You don't need rose package.
/disk add type=smb ...
/ipv6 firewall raw
add action=drop chain=prerouting icmp-options=134:0-255 in-interface=vlanIX protocol=icmpv6
Welcome brother, sorry you hear your escape attempt failed.I only used CLI to export/import large sections of configuration
No, a short explanation is not possible. The solution is Bridge VLAN Filtering.could you just explain your idea please, i try to figure the way
IMO probably nothing. I concluded that function "needs substantial improvement".What I am doing wrong?
Thank you! Can you elaborate on how the above might be done?virtualized radio hardware
Agreed!Well done.
Please educate the uninformed with a brief description or suggest Google Search terms.the effect of USB3 on WiFi 2.4GHz is known and understood,
If the line is drawn at hardware offload or not then I agree.But that still doesn't make these two "not distinct" ...
You are correct; I failed to look further down time table and ignored two other differences.i disagree, the main diferentiator between L5 and L6 is User manager active sessions Limit, Which in L5 is 50, in L6 is Unlimited
I call that one similar but not the same model except for color due to the differing current rating.Literally on the same page https://linitx.com/product/mikrotik-24v ... v1.2/15170
Clear, concise, and so complete. Thank you!There is "zero level" messaging on the forum.
IMO hAP ax3 is a sweet spot and I'm very pleased with mine.Also take into account AX3 costs about 50% for HW and license then L6 license purchased separately.
No, hAP ax3 at L6 is quite nice which makes RB5009 at L5 seem odd.So the problem is hAP ax3 having L6 License,
Thank you; greatly appreciated.No, not so far. Both versions can coexist in same LAN, but on two different devices.
Do you have it in black?We supply the hAP AX3 with the following UK Mikrotik PSU as standard:
Tell us about the pain or absence thereof please.Tell me how foolish this is.