Community discussions

MikroTik App

Search found 206 matches

by Apachez
Thu May 01, 2025 10:21 pm
Forum: SwOS
Topic: CRS305-1G-4S+ Requires reboot
Replies: 1
Views: 11659

Re: CRS305-1G-4S+ Requires reboot

How are things physically connected?

Got some loop going on somehwere?

A drawing would be handy (physical network).
by Apachez
Mon Apr 21, 2025 11:22 pm
Forum: General
Topic: Reset RouterOS without losing remote access (Winbox/SSH)
Replies: 21
Views: 1736

Re: Reset RouterOS without losing remote access (Winbox/SSH)

This can be an expensive but sizeoptimized solution to do so :-)

https://www.flexoptix.net/en/t-c12-rs232i.html

Other options are of course to get a proper SCS (serial console server) with dual LAN interfaces so you can go from IP to serial remotely.
by Apachez
Mon Apr 21, 2025 11:14 pm
Forum: General
Topic: Feature Request: Optional ability to restore without keeping MAC addresses
Replies: 18
Views: 1438

Re: Feature Request: Optional ability to restore without keeping MAC addresses

The fix is to use your own rsc files which you use for "reset-configuration". That is one rsc file per device. My scripts include this (based on Mikrotiks original restore): # # Setting static mac-address on bridge1 if ether interface is found # :set myFOUND 0; :foreach i in=[/interface fi...
by Apachez
Mon Apr 21, 2025 11:07 pm
Forum: General
Topic: Need a 12 port 2,5Gbit Switch WITHOUT FANS !
Replies: 9
Views: 10133

Re: Need a 12 port 2,5Gbit Switch WITHOUT FANS !

Looking at competitors there are not many options for a 12-port 2.5G fanless switch. Netgear have a 8-port 2.5G named MS308E: https://www.netgear.com/business/wired/switches/plus/ms308e/ While Trendnet have a few more options: 8x2.5G + 2x10G (SFP+): https://www.trendnet.com/langen/products/2.5g-mana...
by Apachez
Sat Apr 19, 2025 11:26 pm
Forum: General
Topic: Reset RouterOS without losing remote access (Winbox/SSH)
Replies: 21
Views: 1736

Re: Reset RouterOS without losing remote access (Winbox/SSH)

How can I reset RouterOS to factory defaults without losing remote access (Winbox/SSH)?
Can you explain what your real goal is?

The real goal is probably to reset RouterOS to factory defaults without losing remote access (Winbox/SSH)...
by Apachez
Sat Apr 19, 2025 11:25 pm
Forum: General
Topic: Reset RouterOS without losing remote access (Winbox/SSH)
Replies: 21
Views: 1736

Re: Reset RouterOS without losing remote access (Winbox/SSH)

How can you eat an apple but keep it intact ? You can not. In this case you can: /system reset-configuration keep-users=yes no-defaults=yes skip-backup=yes run-after-reset=<rsc-file uploaded to Files-directory> Make sure that this file defines an IP-address for ether1 (or whatever you use for remot...
by Apachez
Sat Apr 19, 2025 2:28 pm
Forum: SwOS
Topic: 5Gbps link speed
Replies: 5
Views: 2422

Re: 5Gbps link speed

Out of the blue, I assume you use the latest 2.17 SWOS.

In the interface tab there is a checkmark for sfp high/low pin, that doesnt affect which speeds gets available of the transceiver?
by Apachez
Wed Apr 16, 2025 9:24 pm
Forum: SwOS
Topic: The future of SWOS?
Replies: 2
Views: 872

Re: The future of SWOS?

Too bad since SWOS is really nice for regular L2-features.

Both maintenance and the learning curve is way lower than with RouterOS.

Not to mention the boot times :-)
by Apachez
Tue Apr 15, 2025 7:03 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 622
Views: 258271

Re: v7.18.2 [stable] is released! /system routerboard settings set silent-boot=yes

Here is a bug?: (maybe) /system routerboard settings set silent-boot=yes does not work any longer (in some cases) So, if you have a HAP2 ac (RB962UiGS-5HacT2HnT) - the unit "beeps" when you reboot it or when it is "booting". There has been an option to disable this in the past a...
by Apachez
Tue Apr 15, 2025 6:58 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 622
Views: 258271

Re: v7.18.2 [stable] is released!

What is "port cost mode" setting set to in bridge STP settings? Newer releases default to long while older releases defaulted to short - and upgraded devices with old config retained setting at short. This option appeared on 7.15 if my memory serves me right. Issue with this is that all n...
by Apachez
Tue Apr 15, 2025 6:51 am
Forum: SwOS
Topic: Which xmit-hash-policy do SWOS use for dynamic LAG?
Replies: 2
Views: 689

Which xmit-hash-policy do SWOS use for dynamic LAG?

Looking through the manual for SWOS I fail to locate what is the xmit-hash-policy that SWOS uses for dynamic LAGs like LACP (802.3ad)?

https://help.mikrotik.com/docs/spaces/S ... Manual-LAG
by Apachez
Mon Apr 14, 2025 11:46 pm
Forum: MikroTik hardware questions
Topic: CRS354-48g-4s+2q+ boot issue [SOLVED]
Replies: 2
Views: 2265

Re: CRS354-48g-4s+2q+ boot issue [SOLVED]

Question is how you ended up with this situation?

I would guess you would need to reformat the nand and perform a netinstall to start over with this box:

https://help.mikrotik.com/docs/spaces/R ... Netinstall
by Apachez
Mon Apr 14, 2025 10:51 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2431

Re: Using CRS326 as a switch

I wouldnt take forum responses personally, they are of no consequence. People here are free to speak their mind, sometimes its refreshing and eye opening and humbling. I make posts based on what I know, and if someone better comes along, who actually knows their stuff, I am all the better for it. (...
by Apachez
Mon Apr 14, 2025 10:50 pm
Forum: General
Topic: Webfig doesn't start properly
Replies: 3
Views: 544

Re: Webfig doesn't start properly

Try the usual suspects: - Clear browser cache. - Shutdown and restart the browser. - Restart the Mikrotik device (at least as a troubleshooting). - Wait a minute or two (or three) before connecting to the Mikrotik device after its been rebooted. - Are you using http or https to access webfig? In cas...
by Apachez
Sun Apr 13, 2025 9:15 pm
Forum: MikroTik hardware questions
Topic: Mikrotik S+RJ10 sfp+ transceiver is not certified by Fortinet Fortigate
Replies: 5
Views: 1696

Re: Mikrotik S+RJ10 sfp+ transceiver is not certified by Fortinet Fortigate

This snakeoil of not allowing 3rd party transceivers is just something retarded that some vendors does (thankfully not Mikrotik and a few others, and with Arista you can get a 3rd party license free of charge to unlock support for 3rd party transceivers). Boils down to public procurements where some...
by Apachez
Sun Apr 13, 2025 6:31 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2431

Re: Using CRS326 as a switch

A router is a device that can forward packets based on layer3 information such as destination IP address. A switch is a device that can forward frames based on layer2 information such as destination MAC address. And then we have L3-switches (layer3-switches) who can do both (depending on how you con...
by Apachez
Sun Apr 13, 2025 4:20 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2431

Re: Using CRS326 as a switch

Using RouterOS can be confusing at times no matter if you have previous experience from networking or not. Common things to screw up is MLAG and VLAN/bridge configuration. Personally I would have prefered if Mikrotik would do the approach of Arista and many others and have a common configuration (sw...
by Apachez
Sun Apr 13, 2025 4:13 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 622
Views: 258271

Re: v7.18.2 [stable] is released!

hmmmmmphh... on smips arch winbox access ( ex open new window terminal ) getting high cpu usage up to 80%
downgrade to v6 then re update ( firmware) to v7 seems to fix cpu hog issue. thank you ..
Isnt this just a case of that you missed to upgrade routerboard which means another reboot?
by Apachez
Sun Apr 13, 2025 2:08 am
Forum: SwOS
Topic: The future of SWOS?
Replies: 2
Views: 872

The future of SWOS?

I have noticed that none of the CRS5xx devices have SwitchOS on its supportlist. What are the odds that SWOS will indeed show up for these devices or are CRS3xx and CSS6xx the last ones to get SWOS support? Im thinking of: - CRS504-4XQ-IN - CRS504-4XQ-OUT - CRS510-8XS-2XQ-IN - CRS518-16XS-2XQ-RM - C...
by Apachez
Sun Apr 13, 2025 12:52 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 208262

Re: v7.19beta [testing] is released!

Isn't vyos open source?
So that's far from "commercial"
Its an opensource project but with commercial licenses:

https://vyos.io/subscriptions/software
by Apachez
Sat Apr 12, 2025 5:49 am
Forum: Announcements
Topic: SwOS version 2.17 released!
Replies: 16
Views: 142242

Re: SwOS version 2.17 released!

SwOS is rock solid as is, I have some CRS317’s with over 500 days of uptime running on our ISP. The only request that many of us have, is to implement basic security prompts. You can easily press a button on the GUI by accident and bring down an entire network. I had an incident with a tech were he...
by Apachez
Sat Apr 12, 2025 5:39 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 208262

Re: v7.19beta [testing] is released!

Can anyone provide an example of another commercial networking vendor with a public bug tracker ? Also not exacly a public bug tracker, but at least they have this: https://arubanetworking.hpe.com/techdocs/ArubaOS/Consolidated_8.x_RN/Content/8.12/05/Known_8.12.0.5.htm But for MikroTik to have even ...
by Apachez
Sat Apr 12, 2025 5:37 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 208262

Re: v7.19beta [testing] is released!

Can anyone provide an example of another commercial networking vendor with a public bug tracker ?
https://vyos.dev/
by Apachez
Sat Apr 12, 2025 5:23 am
Forum: General
Topic: Intermittent Link Drops on Windows Clients – MLAG Stack with CRS354/CRS328
Replies: 1
Views: 463

Re: Intermittent Link Drops on Windows Clients – MLAG Stack with CRS354/CRS328

Try latest 7.19beta8 and see if the error remains? You can also try to for the devices using LAG towards your MLAG Mikrotiks to disconnect one of the cables to find out if the error is physical or logical. Logical as in something getting incorrectly blocked by your MLAG Mikrotiks but will work if th...
by Apachez
Sat Apr 12, 2025 5:13 am
Forum: SwOS
Topic: Feedback on CSS318-16G-2S+IN
Replies: 2
Views: 1266

Re: Feedback on CSS318-16G-2S+IN

File this as a feature request, I already did so recently regarding adding HTTPS-capabilities for management of SWOS devices. Regarding GDPR/NIS2 then make sure that your management network is already properly encrypted using VPN and use physical dedicated devices as adminstations. The thing of unen...
by Apachez
Sat Apr 12, 2025 5:09 am
Forum: SwOS
Topic: SwOS and logging
Replies: 8
Views: 13974

Re: SwOS and logging

Would adding a capability to log remotely via UDP to a syslog daemon be too much to ask in SwOS? I.e. I'd settle for entering the IP address of the loghost, and possibly requiring it is accessible through an ARP request. I assume you have already filed this as a feature request over at https://help...
by Apachez
Fri Apr 11, 2025 4:18 am
Forum: General
Topic: How to manually update SWOS when running RouterOS?
Replies: 0
Views: 500

How to manually update SWOS when running RouterOS?

Im in the progress to update the lab so I started by updating to latest RouterOS 7.19beta8. That went smoothly. First download the binary (npk) for the correct CPU arch over at https://mikrotik.com/download and login to the CRS326 switch using webfig and upload the file to the Files (menu option to ...
by Apachez
Fri Apr 11, 2025 4:12 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 208262

Re: v7.19beta [testing] is released!

Using 7.19beta8 on a CRS326 with an older Firefox browser to get to webfig the horisontal menus/tabs at the top seems to be missing & nbsp; or similar so they all becomes like one or two centimeters in width even if the text is much larger (if there would be a proper non breaking space being use...
by Apachez
Wed Jan 29, 2025 11:42 am
Forum: General
Topic: MLAG and frame-types for the bridge-interface?
Replies: 3
Views: 3280

Re: MLAG and frame-types for the bridge-interface?

So something like this should then work? In below example LAG-UPLINK and LAG-DOWNLINK are untagged VLAN100: /interface bridge add frame-types=admit-only-vlan-tagged name=bridge1 vlan-filtering=yes /interface bonding add lacp-rate=1sec mode=802.3ad name=MLAG-PEER slaves=qsfpplus1-1,qsfpplus2-1 transm...
by Apachez
Wed Jan 29, 2025 9:49 am
Forum: General
Topic: MLAG and frame-types for the bridge-interface?
Replies: 3
Views: 3280

MLAG and frame-types for the bridge-interface?

When creating a MLAG on CRS3xx/CRS5xx (using RouterOS v7.15.x or later) series you normally: - Create a bond for the MLAG-PEER. - Configure "bridge mlag" to use the above as peer-port. - Define a pvid (for example 4094) on the MLAG-PEER interface to be used for ICCP traffic. - Define "...
by Apachez
Fri Aug 09, 2024 6:03 am
Forum: General
Topic: Steps to configure CRS326-24S+2Q+RM as a L3 Switch wihtout Router-on-a-stick
Replies: 23
Views: 2996

Re: Steps to configure CRS326-24S+2Q+RM as a L3 Switch wihtout Router-on-a-stick

and the multiple threads about this switch keep on coming......... https://forum.mikrotik.com/viewtopic.php?t=210003 Again this fellow @anav has responded. Told number of times somebody asked me to create new thread, as the title did not meet the content, hence created another thread. Because you s...
by Apachez
Wed Aug 07, 2024 9:48 pm
Forum: Virtualization
Topic: Feature Request - CHR - VPP & ISO version CHR ROS
Replies: 42
Views: 8676

Re: Feature Request - CHR - VPP & ISO version CHR ROS

Sure it works, thats how the others using VPP/DPDK does it.

Edit: But sure, they dont have 16MB of storage for their systems.
by Apachez
Wed Aug 07, 2024 8:28 pm
Forum: General
Topic: VRF routing issue on 7.14 [SOLVED]
Replies: 34
Views: 17346

Re: VRF routing issue on 7.14 [SOLVED]

Do you get the same if you dont use an interface list but like manually add each and every interface to the VRF (lets start with just 2 of them or so)? As a bonus question on similar topic - is it possible to (similar to how you can on Arista and VyOS) get to the bash mode when logged in to a Mikrot...
by Apachez
Tue Aug 06, 2024 6:55 pm
Forum: General
Topic: 100G BiDi ER 40km | FEC 91 | No Link
Replies: 7
Views: 1481

Re: 100G BiDi ER 40km | FEC 91 | No Link

Seems like these FEC values gets common these days: 74, 91 and 108. While Mikrotik currently doesnt seem to support FEC108. In https://forum.mikrotik.com/viewtopic.php?t=209869#p1089639 you wrote that you had the same BiDi on both ends of your cable which will explain why it currently doesnt work ou...
by Apachez
Tue Aug 06, 2024 6:52 pm
Forum: General
Topic: IP Address to the Bridge or to the VLAN1 to access the switch
Replies: 7
Views: 1329

Re: IP Address to the Bridge or to the VLAN1 to access the switch

Personally I would only assign IP to ether1 aka the MGMT/BOOT interface. But if you want mgmt to be rechable from elsewhere I would set it on VLAN level so that you can define where this VLAN is reachable because you probably dont want lets say INTERNET to be able to handshake with the mgmt of your ...
by Apachez
Mon Aug 05, 2024 10:15 pm
Forum: General
Topic: CRS326-24S+2Q+RM showing 2 Switch chips
Replies: 52
Views: 4939

Re: CRS326-24S+2Q+RM showing 2 Switch chips

I think your question(s) are better fitted for its own thread since this is going off topic for the subject of this current thread.
by Apachez
Mon Aug 05, 2024 10:14 pm
Forum: General
Topic: 100G BiDi ER 40km | FEC 91 | No Link
Replies: 7
Views: 1481

Re: 100G BiDi ER 40km | FEC 91 | No Link

Since that is a BiDi interface you must have one downlink variant on one end of the cable and one uplink variant on the other. For example where one of the transceivers RX:1310nm + TX:1550nm then the other one (on the other end of the cable) must be: RX: 1550nm + TX: 1310nm otherwise it wont work. T...
by Apachez
Mon Aug 05, 2024 2:55 pm
Forum: Virtualization
Topic: Feature Request - CHR - VPP & ISO version CHR ROS
Replies: 42
Views: 8676

Re: Feature Request - CHR - VPP & ISO version CHR ROS

They got some metrics available at https://vpp-docs.vyos.dev/performance/ but I think you need to contact them to get access to the VPP addon (I think it will be licensed in future).
by Apachez
Mon Aug 05, 2024 2:49 pm
Forum: General
Topic: CRS326-24S+2Q+RM showing 2 Switch chips
Replies: 52
Views: 4939

Re: CRS326-24S+2Q+RM showing 2 Switch chips

Use Winbox. Winbox can connect not only by IP but also by MAC. With it you can assign an IP address to that port, and then you will be able to access it via Webfig (browser). Not necessarily an issue in your case, but you shouldn't use VLAN 1, as a general rule of the thumb, as before or later it m...
by Apachez
Mon Aug 05, 2024 2:47 pm
Forum: General
Topic: 100G BiDi ER 40km | FEC 91 | No Link
Replies: 7
Views: 1481

Re: 100G BiDi ER 40km | FEC 91 | No Link

The FEC setting is a mess, just an example from various vendors (note that there are updates to this matrix not reflected on this link):

https://www.moduletek.com/en/applicatio ... 00096.html

So what do you have on the other end of this cable?
by Apachez
Sun Aug 04, 2024 4:00 pm
Forum: General
Topic: CRS326-24S+2Q+RM showing 2 Switch chips
Replies: 52
Views: 4939

Re: CRS326-24S+2Q+RM showing 2 Switch chips

The main difference between using a software based router (lets say VyOS) on a x86 vs a hardware offloaded one (lets say Mikrotik CRS326) is number of packets per second (which turns into bandwidth) along with latency. Softwarebased routing will have a limit of approx >250kpps per core using interru...
by Apachez
Sun Aug 04, 2024 3:52 pm
Forum: General
Topic: Increasing security of Mikrotik web page
Replies: 8
Views: 1025

Re: Increasing security of Mikrotik web page

Here you got some tips: viewtopic.php?t=209775
by Apachez
Sun Aug 04, 2024 1:17 pm
Forum: General
Topic: STP with bandwidth-based path selection
Replies: 4
Views: 1019

Re: STP with bandwidth-based path selection

You can manually through portcost select which path should be the prefered one if both exists at the same time. But that wont be able to adjust based on available bandwidth or based on retransmitted packets and such. To do so you need some kind of script thats being fired remotely or locally (throug...
by Apachez
Sun Aug 04, 2024 1:08 pm
Forum: General
Topic: CRS326-24S+2Q+RM showing 2 Switch chips
Replies: 52
Views: 4939

Re: CRS326-24S+2Q+RM showing 2 Switch chips

Regarding winbox there is also the webbased edition named webfig which I prefer over installing a 3rd party software on the mgmt-computer. This way you only need a webbrowser to connect to your Mikrotik and once you get the grip of it start using SSH (and consolebased access) aswell. When you login ...
by Apachez
Sun Aug 04, 2024 12:54 pm
Forum: General
Topic: CRS326-24S+2Q+RM showing 2 Switch chips
Replies: 52
Views: 4939

Re: CRS326-24S+2Q+RM showing 2 Switch chips

Nice ... ... but: "Maximum Firewall Port to Port Throughput" is 21Gbps ... a bit less than wirespeed. You should read the rest of the page aswell: All measurements are based upon TCP traffic unless stated otherwise. Total Firewall Throughput is calculated based on maximum PPS and standard...
by Apachez
Sun Aug 04, 2024 12:31 am
Forum: General
Topic: How to setup 10GBit/s copper TP-Link SFP+ modules for CCR2004-16G-2S+.
Replies: 4
Views: 1223

Re: How to setup 10GBit/s copper TP-Link SFP+ modules for CCR2004-16G-2S+.

Try to plug the transceiver into another interface such as int9 or so.
by Apachez
Sun Aug 04, 2024 12:28 am
Forum: General
Topic: CRS326-24S+2Q+RM showing 2 Switch chips
Replies: 52
Views: 4939

Re: CRS326-24S+2Q+RM showing 2 Switch chips

I don't think that your Opensense router xan toute at 40Gbps (limit of CRS' QSFP ports).
Sure it can, depends on the hardware.

Example:

60Gbps of throughput: https://shop.opnsense.com/dec4200-serie ... appliance/
by Apachez
Sat Aug 03, 2024 9:30 pm
Forum: General
Topic: What are the best practices for securing a MikroTik router from external threats?
Replies: 16
Views: 3357

Re: What are the best practices for securing a MikroTik router from external threats?

Again, disabling not needed features is NOT an "inconvenience" rather the opposite.
by Apachez
Sat Aug 03, 2024 9:29 pm
Forum: General
Topic: /system/upgrade menu [SOLVED]
Replies: 10
Views: 7828

Re: /system/upgrade menu [SOLVED]

Ahh right, copied from another guide I have setup regarding configs which must be placed in /flash otherwise they will be gone after reboot (since the root aka / is just a ramdisk).

Ill update the post to reflect correct syntax.
by Apachez
Sat Aug 03, 2024 8:55 pm
Forum: General
Topic: How to setup 10GBit/s copper TP-Link SFP+ modules for CCR2004-16G-2S+.
Replies: 4
Views: 1223

Re: How to setup 10GBit/s copper TP-Link SFP+ modules for CCR2004-16G-2S+.

So you have a TL-SM5310-T connected to a Mikrotik CCR2004-16G-2S+. Which interface is that connected to and is that interface enabled and what about the interface vlan configuration (untagged/tagged)? What kind of cable do you have (tried another cable)? What exists on the other end of this cable (v...
by Apachez
Sat Aug 03, 2024 8:52 pm
Forum: General
Topic: What are the best practices for securing a MikroTik router from external threats?
Replies: 16
Views: 3357

Re: What are the best practices for securing a MikroTik router from external threats?

From the previous link: According to MikroTik’s blog, the attackers exploited a vulnerability in the router’s operating system (RouterOS) which enabled attackers to gain unauthenticated remote access to read and write arbitrary files (CVE-2018-14847). RouterOS is the router operating system that’s u...
by Apachez
Sat Aug 03, 2024 8:43 pm
Forum: General
Topic: Issue with Auto Upgrade / packages from another MikroTik device
Replies: 7
Views: 3434

Re: Issue with Auto Upgrade / packages from another MikroTik device

Alternative method using scp instead of ftp is described at: viewtopic.php?f=2&t=203236&p=1047445#p1089258

Also note that the ftp service in ROS (as of writing 7.15.3 stable) doesnt support VRF so if you use VRF's /ip/service/ssh with scp is the way to go.
by Apachez
Sat Aug 03, 2024 8:41 pm
Forum: General
Topic: /system/upgrade menu [SOLVED]
Replies: 10
Views: 7828

Re: /system/upgrade menu [SOLVED]

Not that anyone asked but... Alternative method is to manually download the npk-files from https://mikrotik.com/download And then upload it to your Mikrotik device (example 192.0.2.1) using scp (you must have /ip/service/ssh enabled): > scp ./routeros-7.15.3-mipsbe.npk username@192.0.2.1:/ And then ...
by Apachez
Sat Aug 03, 2024 8:32 pm
Forum: General
Topic: CRS326-24S+2Q+RM showing 2 Switch chips
Replies: 52
Views: 4939

Re: CRS326-24S+2Q+RM showing 2 Switch chips

1. Unfortunately Mikrotik exposes the Linux DSA (the whole bridge stuff, read more at https://www.kernel.org/doc/Documentation/networking/dsa/dsa.txt) towards the admin instead of having a frontend in front of it like other NOS (based on Linux) do. What I do is to only admit tagged frames towards th...
by Apachez
Sat Aug 03, 2024 8:01 pm
Forum: Virtualization
Topic: Feature Request - CHR - VPP & ISO version CHR ROS
Replies: 42
Views: 8676

Re: Feature Request - CHR - VPP & ISO version CHR ROS

@ Tom I hope if you don't mind asking this question do you have current test setup at least with FRR + VPP how's the performance and any gotcha? I don't mind getting my hands dirty again to rollout pure linux solution as long as they are worth it. I'm also eyeing for VyOS but as far as i know they ...
by Apachez
Sat Aug 03, 2024 4:36 pm
Forum: General
Topic: What are the best practices for securing a MikroTik router from external threats?
Replies: 16
Views: 3357

Re: What are the best practices for securing a MikroTik router from external threats?

I find somewhat intriguing how half the new members posts asking how to access the router after having managed to lock themselves out, and the other half posts asking for recipes that ultimately increase the risk of locking oneself out. Seriously, one thing is doing whatever Is possible to prevent ...
by Apachez
Sat Aug 03, 2024 4:32 pm
Forum: General
Topic: What are the best practices for securing a MikroTik router from external threats?
Replies: 16
Views: 3357

Re: What are the best practices for securing a MikroTik router from external threats?

Why?? /tool mac-server mac-winbox set allowed-interface-list= none Its an encrypted protocol/service, what should be said if using winbox, make sure this is set to the TRUSTED subnet/interface. Because: 1) I dont like backdoors. 2) Management of these units should only occur from the management net...
by Apachez
Sat Aug 03, 2024 9:29 am
Forum: General
Topic: STP with bandwidth-based path selection
Replies: 4
Views: 1019

Re: STP with bandwidth-based path selection

Yes, you can add portcosts to various links.

However I doubt that will help in your case unless you manually or by some script disable the path that uses the 60GHz link.
by Apachez
Sat Aug 03, 2024 9:28 am
Forum: General
Topic: CCR2216 CPU UNBALANCED LOAD AFFECTING TRAFFIC
Replies: 29
Views: 6589

Re: CCR2216 CPU UNBALANCED LOAD AFFECTING TRAFFIC

i think you must return to ccr1072, usually newer platforms take months to optimize plus a new operating system version plus a new hardware architecture plus a new hardware offload using ASICs because of all this concurrent aggravating factors we can expect this process to be even more difficult th...
by Apachez
Sat Aug 03, 2024 9:25 am
Forum: General
Topic: UDP faster than TCP - why?
Replies: 11
Views: 6629

Re: UDP faster than TCP - why?

Also UDP is the raw mode of sending and receiving packets on the network. Using TCP the kernel will take congestion control and other stuff into account for you in order for you to not lose packets - with UDP you must do this coding yourself. Lately improvement in such algorithms goes faster than ne...
by Apachez
Sat Aug 03, 2024 9:21 am
Forum: Scripting
Topic: If the uptime was more than 1 minute
Replies: 14
Views: 5361

Re: If the uptime was more than 1 minute

Perhaps a case of asking the same question multiple times until she gets the answer she is looking for?
by Apachez
Fri Aug 02, 2024 8:41 pm
Forum: General
Topic: CSS326-24G-2S+RM really low performance speed [SOLVED]
Replies: 4
Views: 1196

Re: CSS326-24G-2S+RM really low performance speed [SOLVED]

You mean CRS ? CSS is a SWOS only device.

What is your testing method ?
CSS326-24G-2S+RM seems to be a SWOS only device:

https://mikrotik.com/product/CSS326-24G-2SplusRM

While CRS326-24S+2Q+RM can do both SWOS and RouterOS:

https://mikrotik.com/product/crs326_24s_2q_rm
by Apachez
Fri Aug 02, 2024 8:39 pm
Forum: General
Topic: CSS326-24G-2S+RM really low performance speed [SOLVED]
Replies: 4
Views: 1196

Re: CSS326-24G-2S+RM really low performance speed [SOLVED]

That ether1 which is interface labeled mgmt/boot on the device sits on another switchchip (atheros) connected to the mgmt-cpu. Your bridge (and you should only have one) will act on the marvell switchchip to which you must add all interfaces except for that mgmt/boot one. Thats the case on CRS326-24...
by Apachez
Fri Aug 02, 2024 8:33 pm
Forum: General
Topic: What are the best practices for securing a MikroTik router from external threats?
Replies: 16
Views: 3357

Re: What are the best practices for securing a MikroTik router from external threats?

I’ve recently set up a MikroTik router for my home network to play the Nulls Brawl game, and I’m concerned about potential security vulnerabilities. I’ve configured the basic firewall rules and updated the firmware, but I’d like to know more about advanced security measures. What are the best pract...
by Apachez
Fri Aug 02, 2024 8:12 pm
Forum: Scripting
Topic: If the uptime was more than 1 minute
Replies: 14
Views: 5361

Re: If the uptime was more than 1 minute

https://help.mikrotik.com/docs/display/ROS/Scheduler Note: if scheduler item has start-time set to startup, it behaves as if start-time and start-date were set to time 3 seconds after console starts up. It means that all scripts having start-time is startup and interval is 0 will be executed once ea...
by Apachez
Thu Aug 01, 2024 2:28 am
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 139600

Re: v7.16beta [testing] is released!

Yes thats what my (and Mikrotiks) default-configuration script do:
/interface bridge set bridge1 auto-mac=no admin-mac=$tmpMAC;
by Apachez
Thu Aug 01, 2024 2:27 am
Forum: General
Topic: VRF-support for DNS is broken?
Replies: 21
Views: 13515

Re: VRF-support for DNS is broken?

Thanks! So then we can hopefully rule out that this would be some kind of misconfiguration on my side. Question is how the quality assurance works over at Mikrotik or how their config to validate this feature looks like? I have also filed a support ticket SUP-156966 on 24th of june which gives that ...
by Apachez
Wed Jul 31, 2024 9:42 pm
Forum: Scripting
Topic: Disable the prompt from the terminal. [SOLVED]
Replies: 17
Views: 13700

Re: Disable the prompt from the terminal. [SOLVED]

Hi all,

Is it possible to disable the terminal prompt, like in Windows shell with the "echo off" command?

Thanks.

Max
How do you mean?

Like that it should echo back when you type on the keyboard?

You can enable api-ssl instead of using ssh for the scripting.
by Apachez
Wed Jul 31, 2024 9:32 pm
Forum: General
Topic: Mikrotik Rack-mounted Devices Visio Stencils
Replies: 61
Views: 112504

Re: Mikrotik Rack-mounted Devices Visio Stencils

Got a good manual on how to create stencils for more models?
by Apachez
Wed Jul 31, 2024 9:30 pm
Forum: General
Topic: CRS326-24S+2Q+RM showing 2 Switch chips
Replies: 52
Views: 4939

Re: CRS326-24S+2Q+RM showing 2 Switch chips

Also note that except for the limits of when you cant enable L3-offloading (VRF, MLAG etc) once you do the options are limited when it comes to number of routing entries, ACL's and whatelse. So currently I see the CRS series as a L2+ option. Mikrotik never comes anywhere close to lets say Arista in ...
by Apachez
Wed Jul 31, 2024 10:16 am
Forum: Virtualization
Topic: Feature Request - CHR - VPP & ISO version CHR ROS
Replies: 42
Views: 8676

Re: Feature Request - CHR - VPP & ISO version CHR ROS

VPP is just a frontend towards Intel DPDK which means that you set aside cores from your onboard CPU to not be part of the kernel processing. This means that alot of the kernel and userspace overhead is removed for these cores which means that they will maximize performance for a single task such as...
by Apachez
Wed Jul 31, 2024 10:06 am
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 139600

Re: v7.16beta [testing] is released!

Auto-mac=on will pick any available mac-address of your device. There is a slight chance/risk that different interfaces will be picked during (re)boots. Which means that your Mikrotik mgmt-interface might have different mac after a (re)boot which might be a bad thing (for example if it sits behind a...
by Apachez
Wed Jul 31, 2024 9:58 am
Forum: Scripting
Topic: add/set parameter without erasing exisiting ones
Replies: 4
Views: 4233

Re: add/set parameter without erasing exisiting ones

That would break the basics of PKI.

Perhaps you can add these as a pool of users?
by Apachez
Wed Jul 31, 2024 2:36 am
Forum: General
Topic: CRS310/309 through CHR - ping packet loss
Replies: 2
Views: 812

Re: CRS310/309 through CHR - ping packet loss

Would be interesting if you got an old backup available to compare what the difference became to your working config?
by Apachez
Wed Jul 31, 2024 2:34 am
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 139600

Re: v7.16beta [testing] is released!

With that being said looking at the restore script from Mikrotik even if they manually set the admin mac they still pick the first available mac from the device itself. Below is my modified edition: :global myFOUND "0"; # # Function to display and log messages # :global debugMSG do={ :put ...
by Apachez
Wed Jul 31, 2024 2:23 am
Forum: Scripting
Topic: add/set parameter without erasing exisiting ones
Replies: 4
Views: 4233

Re: add/set parameter without erasing exisiting ones

Well if you want to have two clients at once using one cert each then you must add it as two different certs.

Running the set command on already existing cert will alter parameters for that cert.
by Apachez
Wed Jul 31, 2024 2:22 am
Forum: Scripting
Topic: A function for url encoding
Replies: 5
Views: 9833

Re: A function for url encoding

Some user write a tons of script for character encoding/decoding and mikrotik add some commands on v7....
v6 seems still to be the LTS edition as of writing so no wonder why people needs to still reinvent the wheel when using RouterOS?
by Apachez
Wed Jul 31, 2024 2:20 am
Forum: Announcements
Topic: v6.49.13 [long-term] is released!
Replies: 27
Views: 60026

Re: v6.49.13 [long-term] is released!

Thats what I like with how VyOS presents changelogs. The userfriendly edition is displayed at their blog, example: https://blog.vyos.io/vyos-1.3.8-maintenance-release https://blog.vyos.io/vyos-project-july-2024-update But each change also points to their repo over at https://vyos.dev where you can f...
by Apachez
Wed Jul 31, 2024 2:12 am
Forum: General
Topic: Hardware offloading
Replies: 3
Views: 3287

Re: Hardware offloading

https://help.mikrotik.com/docs/display/ROS/L3+Hardware+Offloading#L3HardwareOffloading-L3HWFeatureSupport should answer some of your questions. Unless you plan to use VRF, MLAG, VXLAN or Q-in-Q then your CRS switches should be able to offload L3 aswell - otherwise they will just offload L2. In your ...
by Apachez
Wed Jul 31, 2024 1:58 am
Forum: General
Topic: CRS326-24S+2Q+RM showing 2 Switch chips
Replies: 52
Views: 4939

Re: CRS326-24S+2Q+RM showing 2 Switch chips

As you can see on the blockdiagram (go to mikrotik.com, click on hardware then switches then locate your model and finally select Downloads & Documentation and you will see the link to the blockdiagram etc) https://cdn.mikrotik.com/web-assets/product_files/CRS326-24S2Q_230231.png the two "s...
by Apachez
Sat Jul 27, 2024 7:51 pm
Forum: General
Topic: Upgrading Rooterboot factory software
Replies: 25
Views: 10657

Re: Upgrading Rooterboot factory software

Factory firmware is whatever thats available in your device in case you start over. Im not aware if a netinstall can wipe this (it should) but generally speaking when you update the routeros you can do another reboot to have the bootloader updated aswell. The bootloader is like bios if compared to y...
by Apachez
Fri Jul 26, 2024 10:58 am
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 139600

Re: v7.16beta [testing] is released!

*) dns - added support for mDNS proxy;
OK,kill a container mdns-repeater .
Works well
/ip/dns/set mdns-repeat-ifaces=bridge1,vlan1_iot

Tried that when using VRFs?
by Apachez
Fri Jul 26, 2024 9:03 am
Forum: General
Topic: Management Port Route List?
Replies: 6
Views: 859

Re: Management Port Route List?

You really shouldn't add your WAN interface to bridge. Bridge is a switch-like entity and joins all member ports into single ethernet domain ... so in principle traffic can pass between e.g. sfp28-2 and sfp28-1 without ever hitting firewall. And I don't think that's what you want to do. Thats why y...
by Apachez
Fri Jul 26, 2024 9:02 am
Forum: General
Topic: modify user or service allow-address list
Replies: 3
Views: 681

Re: modify user or service allow-address list

Cant you send remove commands at the same time something like (or whatever the syntax will be): /ip/service/xxx remove [find address=x.x.x.x] Im thinking lets say you have in total 5 IP-ranges to deal with but as you said one box will only allow one of these and another will allow three of them. Thi...
by Apachez
Thu Jul 25, 2024 5:54 pm
Forum: General
Topic: CRS328-24P Ports not providing Power
Replies: 3
Views: 850

Re: CRS328-24P Ports not providing Power

At least you got a reply from support...
by Apachez
Wed Jul 24, 2024 10:27 pm
Forum: Announcements
Topic: WinBox v3.41 released!
Replies: 41
Views: 40405

Re: WinBox v3.41 released!

Thanks, but - where to get winbox for mac OS???
Why not use webfig (www-ssl) and ssh?
by Apachez
Fri Jul 19, 2024 8:35 pm
Forum: General
Topic: mikrotik crs326-24s+2q+rm "fixed"?
Replies: 3
Views: 526

Re: mikrotik crs326-24s+2q+rm "fixed"?

What version of SWOS?

Tried latest?

Same with RouterOS, tried latest as in 7.15.2 stable and is it the same issues?

Also what kind of issues?
by Apachez
Fri Jul 19, 2024 11:11 am
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304092

Re: v7.15.2 [stable] is released!

Note that this is a complete mess if you got a multivendor environment and want to use STP: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4000/8-2glx/configuration/guide/spantree.html The IEEE 802.1D specification assigns 16-bit (short) default port cost values to each port that is base...
by Apachez
Thu Jul 18, 2024 5:52 pm
Forum: General
Topic: Error by importing exported config
Replies: 4
Views: 1219

Re: Error by importing exported config

According to the manual setting it to 0 should be allowed so Im guessing Mikrotik have another bug you should report: https://help.mikrotik.com/docs/display/ROS/Wireless+Interface wds-cost-range (start [-end] integer[1..200000000]; Default: 50-150) Bridge port cost of WDS links are automatically adj...
by Apachez
Thu Jul 18, 2024 3:42 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304092

Re: v7.15.2 [stable] is released!

After my move from 7.15 to 7.15.2 I keep seeing LACPtoSwitches: bridge RX looped packet - MAC 18:fd:74:78:3b:9b -> ff:ff:ff:ff:ff:ff VID 80 ETHERTYPE 0x0800 IP UDP 0.0.0.0:68 -> 255.255.255.255:67 LACPtoSwitches is a bond to a set of MLAG switches. 18:fd:74:78:3b:9b is my eth6 on my Router (5009) w...
by Apachez
Wed Jul 17, 2024 6:34 pm
Forum: General
Topic: Configuration Summer cleaning l3hw
Replies: 4
Views: 618

Re: Configuration Summer cleaning l3hw

According to the feature support list over at https://help.mikrotik.com/docs/display/ ... ureSupport the answer is yes and no.

Fasttrack connections will be offloaded but everything else will go to the CPU.
by Apachez
Wed Jul 17, 2024 5:31 pm
Forum: General
Topic: Configuration Summer cleaning l3hw
Replies: 4
Views: 618

Re: Configuration Summer cleaning l3hw

Perhaps someone from Mikrotik can enlighten us but to my knowledge the setting on switchchip level is the global on/off switch. Then when you have that at on you can disable individual interfaces with an on/off at port-level. So if the switchchip have this off and port X have this on the result is o...
by Apachez
Tue Jul 16, 2024 8:52 pm
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 139600

Re: v7.16beta [testing] is released!

Will the same happen if you do something like this instead?

/ipv6 address
add address=::2 from-pool=v6prefix interface=bridge.vlan62
add address=::3 from-pool=v6prefix interface=bridge.vlan64
by Apachez
Tue Jul 16, 2024 3:55 pm
Forum: General
Topic: Help feature no longer working with question mark "?"
Replies: 10
Views: 1069

Re: Help feature no longer working with question mark "?"

At least putting ketchup on your schwarma is forbidden in Canada...
by Apachez
Tue Jul 16, 2024 3:40 pm
Forum: General
Topic: Help feature no longer working with question mark "?"
Replies: 10
Views: 1069

Re: Help feature no longer working with question mark "?"

Why on earth would you assign F1 to something else than to pass to the current window?
by Apachez
Tue Jul 16, 2024 12:52 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304092

Re: v7.15.2 [stable] is released!

Again, to me that sounds like something is REALLY broken with RouterOS if such steps are needed.
by Apachez
Tue Jul 16, 2024 12:17 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304092

Re: v7.15.2 [stable] is released!

I wonder if anybody else tested the speed of ROS 7, and 7.15.2 in particular, compared to ROS 6 (say 6.49.13)? it seems that the "visible config" (as shown by export command) sometimes doesn't correspond with actual hardware config (it seems that there's binary configuration blob which ra...
by Apachez
Tue Jul 16, 2024 12:08 pm
Forum: General
Topic: How can check if a LAN user is sending a large number of emails ?
Replies: 2
Views: 620

Re: How can check if a LAN user is sending a large number of emails ?

You wont do this unless you do some sort of IDS/IPS interception (or forward the connections through a mailrelay of your own). You would either way need some TLS-interception aswell to inspect the content (most emails these days uses starttls between servers). Sure you could probably get a counter o...
by Apachez
Tue Jul 16, 2024 2:29 am
Forum: General
Topic: Compatibility error? CCR2216-1G-12XS-2XQ with Ubiquiti Modules
Replies: 11
Views: 4908

Re: Compatibility error? CCR2216-1G-12XS-2XQ with Ubiquiti Modules

Technically for RJ45 its mandatory to use autonegotiation according to IEEE standard. So that should NOT be disabled. Also with autoneg disabled the auto mdi/mdix will also get disabled so you are then down to use the correct cable like a straight cable between your device and a host and a crossover...
by Apachez
Tue Jul 16, 2024 2:19 am
Forum: Scripting
Topic: Script for setting Locally Administered MAC Address on bridges
Replies: 15
Views: 5488

Re: Script for setting Locally Administered MAC Address on bridges

You math is a bit broken or you got some other major malfunction going on...
by Apachez
Tue Jul 16, 2024 1:01 am
Forum: General
Topic: DNS Cahe Full/adlist read: max cache size reached
Replies: 14
Views: 9796

Re: DNS Cahe Full/adlist read: max cache size reached

If that pihole install is 3 years old I think you should update it before making a new attempt :-)
by Apachez
Tue Jul 16, 2024 12:33 am
Forum: Scripting
Topic: if router uptime is more
Replies: 16
Views: 4731

Re: if router uptime is more

I fail to see why you are upset that somebody pointed out that your suggestion can be improved. Doing just the if statement as your suggestion will have clear limitations of the script not working as expected. Compared to doing it as a whilte statement. Most optimal is to NOT waste CPU resources and...
by Apachez
Tue Jul 16, 2024 12:28 am
Forum: General
Topic: Compatibility error? CCR2216-1G-12XS-2XQ with Ubiquiti Modules
Replies: 11
Views: 4908

Re: Compatibility error? CCR2216-1G-12XS-2XQ with Ubiquiti Modules

I assume you also tried rebooting the Mikrotik device when setting autoneg=yes but limit the advertised to just 1Gbps/Full Duplex ? Aka "did you turn it off and on again?" :-) I have noticed that even if SFP/SFP+/SFP28 modules are supposed to be hotpluggable thats not always the case speci...
by Apachez
Tue Jul 16, 2024 12:20 am
Forum: Scripting
Topic: Script for setting Locally Administered MAC Address on bridges
Replies: 15
Views: 5488

Re: Script for setting Locally Administered MAC Address on bridges

For reference here is the full default script being used by Mikrotik in 7.15.2 stable when you run a reset-configuration and have "no-defaults=no" being set: [admin@Mikrotik] > /system/default-configuration/script/print without-paging script: #| Welcome to RouterOS! #| 1) Set a strong rout...
by Apachez
Tue Jul 16, 2024 12:15 am
Forum: Scripting
Topic: Script for setting Locally Administered MAC Address on bridges
Replies: 15
Views: 5488

Re: Script for setting Locally Administered MAC Address on bridges

ether1 which often is the MGMT interface On what brand? I never see ether1 as management interface on MikroTik product (on DEFAULT configuration, OBVIOUSLY). (or at least I've never seen one directly before) So the ORIGINAL MikroTik script for the default configuration does what it should. If you d...
by Apachez
Tue Jul 16, 2024 12:06 am
Forum: General
Topic: DNS Cahe Full/adlist read: max cache size reached
Replies: 14
Views: 9796

Re: DNS Cahe Full/adlist read: max cache size reached

Personally I would solve this by running adhome (or pihole) or some other resolver as a container in your Mikrotik or prefered on a dedicated hardware (either as bare metal or as a VM guest). This way you have something that actually work and is not dependent on the lack of quality assurance which M...
by Apachez
Mon Jul 15, 2024 10:24 pm
Forum: General
Topic: Sending an HTTP request as soon as a device in online
Replies: 4
Views: 928

Re: Sending an HTTP request as soon as a device in online

Reason why you failed previously is due to that both ARP and MAC entries are cached by switches and routers. The MAC entries for a particular interface is normally deleted when the interface goes down and same with ARP. But in your case if the interface doesnt go down (on the router) because you for...
by Apachez
Mon Jul 15, 2024 10:20 pm
Forum: General
Topic: Compatibility error? CCR2216-1G-12XS-2XQ with Ubiquiti Modules
Replies: 11
Views: 4908

Re: Compatibility error? CCR2216-1G-12XS-2XQ with Ubiquiti Modules

Do you have the SKU of these particular Ubiquiti transceivers?
by Apachez
Mon Jul 15, 2024 10:03 pm
Forum: General
Topic: DNS Cahe Full/adlist read: max cache size reached
Replies: 14
Views: 9796

Re: DNS Cahe Full/adlist read: max cache size reached

TTL in this case is also questionable (when it comes to caching) if its relative (reset when a new request is made) or absolute (the counter goes down to 0 no matter if there are cache hits or not). When it comes to DNS its often absolute as in the authoritive server defines for how long the resolve...
by Apachez
Mon Jul 15, 2024 2:45 pm
Forum: Scripting
Topic: Script for setting Locally Administered MAC Address on bridges
Replies: 15
Views: 5488

Re: Script for setting Locally Administered MAC Address on bridges

And why should it cause it? The MikroTik script is intended for an unconfigured device, to which the script is applying the default configuration. Because the original script will pick any interface which isnt a slave, passthrough, loopback or contains the name "*bridge*" and if such inte...
by Apachez
Mon Jul 15, 2024 2:40 pm
Forum: Scripting
Topic: if router uptime is more
Replies: 16
Views: 4731

Re: if router uptime is more

You really didnt read the OP (original post) did you? Here is the usecase: Mine is clearly more in line with the (incomplete) request. So what? No "loop" or "wait until" required. Don't make things up. He asked exactly "script that executes commands if router uptime is more...
by Apachez
Mon Jul 15, 2024 2:15 pm
Forum: General
Topic: MLAG hopelessly broken?
Replies: 58
Views: 25294

Re: MLAG hopelessly broken?

if you need reliable MLAG hardware go for cisco, extreme or if you need to be on budget ... fs.com speaking of fs... MLAG featuring switches: N5860-48SC (mlag or stack) S5860-48SC (stack) S5850-48S6Q (mlag) routing ... mikrotik switching ... cisco, fs, aruba, extreme Even if the same name FSOS , di...
by Apachez
Mon Jul 15, 2024 12:36 pm
Forum: Scripting
Topic: if router uptime is more
Replies: 16
Views: 4731

Re: if router uptime is more

What you write is absolutely not in the OP, what are you making up? I need a script that executes commands if router uptime is more than one minute Help me please And on the other post that isa reply to your post: I need checked uptime. If the uptime was less, the command would not be executed This...
by Apachez
Mon Jul 15, 2024 12:35 pm
Forum: Scripting
Topic: Script for setting Locally Administered MAC Address on bridges
Replies: 15
Views: 5488

Re: Script for setting Locally Administered MAC Address on bridges

Speaking of conflicts... how come the original script form Mikrotik picks one of the physical interfaces MAC-address and put it on the bridge - wouldnt this cause a conflict aswell?
by Apachez
Mon Jul 15, 2024 12:05 pm
Forum: Scripting
Topic: if router uptime is more
Replies: 16
Views: 4731

Re: if router uptime is more

Without the loop your script will fail to execute if you read the OP's original intention to have the script being runned 1 minute after boot. The proper solution is to add the script as a scheduled task to be runned at "startup" which by ROS occurs 3 seconds after boot completed and in th...
by Apachez
Mon Jul 15, 2024 11:41 am
Forum: Scripting
Topic: if router uptime is more
Replies: 16
Views: 4731

Re: if router uptime is more

You do not specify RouterOS version. For v7 Simply... { :local ups [:tonum [/system resource get uptime]] :if ($ups > 60) do={ # ...script code... } } if the number is > 60... is more than 1 minutes that the device is up... for v6, since is just a string... { :if ([/system resource get uptime] > &q...
by Apachez
Mon Jul 15, 2024 11:38 am
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304092

Re: v7.15.2 [stable] is released!

Pro tip ... 1. Click "Design Skin" 2. Go to Resources 3. Click triangle button next to Version 4. Select "Add to Status page" Looks promising though I'm unable to locate any tab/menu called "Resources" in Design Skin mode.. Click on System -> Resources first. Then in t...
by Apachez
Mon Jul 15, 2024 11:33 am
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304092

Re: v7.15.2 [stable] is released!

Pro tip ... 1. Click "Design Skin" 2. Go to Resources 3. Click triangle button next to Version 4. Select "Add to Status page" now any variable can be your home screen. Fugly workaround... at least its one click away that way since the naming of the page wont display due to too l...
by Apachez
Mon Jul 15, 2024 11:26 am
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304092

Re: v7.15.2 [stable] is released!

Why is it important? Maybe somebody else has another "very important" variable they need everywhere. We can't cram everything in one screen. You have PLENTY of dead unused space below the button "Make Supout.rif" in the left menu - same with the area where the hostname is being ...
by Apachez
Mon Jul 15, 2024 11:14 am
Forum: General
Topic: VRF.Web-proxy
Replies: 29
Views: 4055

Re: VRF.Web-proxy

Well if you will leak everything between your VRFs anyway then the purpose of using a VRF goes away and you could just have everything in the default vrf=main and call it a day.
by Apachez
Mon Jul 15, 2024 11:12 am
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304092

Re: v7.15.2 [stable] is released!

Its not about that this information is hidden behind 25 clicks in the webfig - its about getting this info in less than 1 click as in no click at all as with when you login through CLI/SSH you get it as the MOTD message.
by Apachez
Mon Jul 15, 2024 10:58 am
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304092

Re: v7.15.2 [stable] is released!

Worst place ever to place that info :D
by Apachez
Mon Jul 15, 2024 9:45 am
Forum: General
Topic: VRF.Web-proxy
Replies: 29
Views: 4055

Re: VRF.Web-proxy

Then it sounds like you have some other malfunctioning going on in your config.
by Apachez
Mon Jul 15, 2024 9:23 am
Forum: General
Topic: VRF.Web-proxy
Replies: 29
Views: 4055

Re: VRF.Web-proxy

Question is what is your purpose of using VRF with all these routeleaks?
by Apachez
Mon Jul 15, 2024 2:44 am
Forum: General
Topic: Restore a CRS328-24P-4S+RM switch
Replies: 2
Views: 1863

Re: Restore a CRS328-24P-4S+RM switch

Try press any key or at least the delete key during the first 2 seconds during boot when connected with a consolecable to the unit.

From there (the bootmanager) you should have options to manually start etherboot or replace the firmware incl formating the storage etc.
by Apachez
Mon Jul 15, 2024 12:57 am
Forum: General
Topic: Can VRF be used to "split" a router?
Replies: 5
Views: 1293

Re: Can VRF be used to "split" a router?

On the other hand RouterOS have existed since 1999 so thats about 25 years this year.

How many more years do you think it should take before RouterOS gets proper VRF support?

As a comparision Arista was launched in 2008 and have had VRF support since day 1...
by Apachez
Mon Jul 15, 2024 12:55 am
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304092

Re: v7.15.2 [stable] is released!

It is very useful. This is what you see when you login through CLI/SSH: MMM MMM KKK TTTTTTTTTTT KKK MMMM MMMM KKK TTTTTTTTTTT KKK MMM MMMM MMM III KKK KKK RRRRRR OOOOOO TTT III KKK KKK MMM MM MMM III KKKKK RRR RRR OOO OOO TTT III KKKKK MMM MMM III KKK KKK RRRRRR OOO OOO TTT III KKK KKK MMM MMM III K...
by Apachez
Mon Jul 15, 2024 12:50 am
Forum: Scripting
Topic: if router uptime is more
Replies: 16
Views: 4731

Re: if router uptime is more

Here is a workaround if you still want to figure out the seconds since boot but again using a "delay 60s;" as first row in your script is much more efficient along with schedule that script as startup-script. :global myUPTIMESEC "0"; :global myTIMEOUT "60"; while ($myUP...
by Apachez
Sun Jul 14, 2024 4:02 pm
Forum: Scripting
Topic: if router uptime is more
Replies: 16
Views: 4731

Re: if router uptime is more

Yes and delay of 3 seconds (once startup-script executes) + 57 seconds within the script before the rest of the script is being runned will give you that more than 1 minute has passed since the device got power on. If you still refuse to take the easy way out you can pick the uptime variable and hav...
by Apachez
Sun Jul 14, 2024 3:58 pm
Forum: Scripting
Topic: Script for setting Locally Administered MAC Address on bridges
Replies: 15
Views: 5488

Re: Script for setting Locally Administered MAC Address on bridges

You can see how Mikrotik prefer to set it using "/system/default-configuration/script/print" (example below is from 7.15.2 stable): /interface bridge add name=bridge disabled=no auto-mac=yes protocol-mode=rstp comment=defconf; :local bMACIsSet 0; :foreach k in=[/interface find where !(slav...
by Apachez
Sun Jul 14, 2024 1:42 pm
Forum: General
Topic: MLAG hopelessly broken?
Replies: 58
Views: 25294

Re: MLAG hopelessly broken?

7.15.2 same problems...
Which is?
by Apachez
Sun Jul 14, 2024 11:19 am
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304092

Re: v7.15.2 [stable] is released!

Oh in webfig? He did not say it was about webfig... in winbox the version is in the title bar for both v6 and v7. In general it is not a good idea to reveal the version on a login page. Scanners and intruders use that to know if you are running a version for which they know how to break in to it. T...
by Apachez
Sun Jul 14, 2024 11:15 am
Forum: General
Topic: Switch Rules working without HW on interface?
Replies: 5
Views: 975

Re: Switch Rules working without HW on interface?

The physical ports on the device are wired to the switch chip so packets will always pass through and be processed by the switch. The underlying architecture has a single interface beween the switch chip and CPU - the ether1..etherX interfaces shown in winbox/CLI are logical interfaces, the driver ...
by Apachez
Sun Jul 14, 2024 11:10 am
Forum: General
Topic: VLAN 1 IP and dedicated MGMT Port IP in same subnet
Replies: 8
Views: 2357

Re: VLAN 1 IP and dedicated MGMT Port IP in same subnet

I wish everytime someone tried to create vlan1 on the router, it would spit out an audio recording of this............
https://www.youtube.com/watch?v=EfYtMLe7gqI
Or like this ;-)

https://www.youtube.com/watch?v=nP_JN6TKQFw&t=37
by Apachez
Sun Jul 14, 2024 11:08 am
Forum: General
Topic: Can VRF be used to "split" a router?
Replies: 5
Views: 1293

Re: Can VRF be used to "split" a router?

Yes, thats how VRF's often are used to setup 2 or more "virtual" routers in the same box or for security reasons where you want to isolate the mgmt-interface as much as possible against the customer traffic or if you want to deal with multiple customers at once in the same box where they a...
by Apachez
Sun Jul 14, 2024 11:00 am
Forum: General
Topic: VRF.Web-proxy
Replies: 29
Views: 4055

Re: VRF.Web-proxy

Normally you dont want leaking of routes between VRF's. Also for this to work the service itself must allow for the leaking syntax as in x.x.x.x@VRF which for example the logging service currently doesnt (I have raised a feature request about this). Another dirty workaround is to use your "main...
by Apachez
Sun Jul 14, 2024 10:56 am
Forum: Scripting
Topic: if router uptime is more
Replies: 16
Views: 4731

Re: if router uptime is more

https://help.mikrotik.com/docs/display/ROS/Scheduler Perhaps add it as a startup-script in the scheduler which will run it 3 seconds after boot but the first line in your script is something like: delay 57s; Then have the rest of your code which gives that the script starts 3 seconds after boot then...
by Apachez
Fri Jul 12, 2024 6:00 pm
Forum: General
Topic: VLAN 1 IP and dedicated MGMT Port IP in same subnet
Replies: 8
Views: 2357

Re: VLAN 1 IP and dedicated MGMT Port IP in same subnet

The way to deal with such scenario is to use VRF's. Note however that VRF's are somewhat broken in ROS 7.x so not all services supports VRF's once you choose to go that path. For example the /ip/dns service doesnt support VRF (it claims it does since 7.15 but its broken), same with ip/ftp (no suppor...
by Apachez
Fri Jul 12, 2024 1:01 pm
Forum: General
Topic: Router has 443 port opened and accepting connections even when www service is stopped [SOLVED]
Replies: 9
Views: 4024

Re: Router has 443 port opened and accepting connections even when www service is stopped [SOLVED]

My bad, checked it on another winbox.

SSTP was enabled. I've disabled it and nmap stopped showing port as open, curl also started refusing connections.

Thank you guys!
Glad that it got resolved :-)
by Apachez
Fri Jul 12, 2024 1:01 pm
Forum: General
Topic: Router has 443 port opened and accepting connections even when www service is stopped [SOLVED]
Replies: 9
Views: 4024

Re: Router has 443 port opened and accepting connections even when www service is stopped [SOLVED]

But you got "enabled=yes" for that SSTP according to the CLI config and I would trust that more than winbox. You could try to enable www-ssl and set that to a different port like 8443 or such and login using https://<mgmt ip of device>:8443 or whatever port you select and see what webfig t...
by Apachez
Fri Jul 12, 2024 12:31 pm
Forum: General
Topic: Router has 443 port opened and accepting connections even when www service is stopped [SOLVED]
Replies: 9
Views: 4024

Re: Router has 443 port opened and accepting connections even when www service is stopped [SOLVED]

Try something like:

/export terse show-sensitive verbose file=flash/custom.rsc

And then download that through webfig or scp and finally search the file for "443".
by Apachez
Fri Jul 12, 2024 3:16 am
Forum: Scripting
Topic: Difference between [ find ] and [ find default=yes ] when trying to set option to all objects?
Replies: 7
Views: 4379

Re: Difference between [ find ] and [ find default=yes ] when trying to set option to all objects?

Well whatever syntax they prefer but its a mess that one line of config use "enabled=no" to disable a feature while the next line uses "disabled=yes" to do the same thing...
by Apachez
Fri Jul 12, 2024 3:14 am
Forum: General
Topic: VRF.Web-proxy
Replies: 29
Views: 4055

Re: VRF.Web-proxy

It matters because the web-proxy wants a layer3 interface to use to listen for incoming connections.

And you configured that to be 192.168.88.0/24 as address which is not valid.

You would also need a routing entry so the webproxy can reach whatever you want it to proxy for the clients.
by Apachez
Fri Jul 12, 2024 2:24 am
Forum: General
Topic: Multiple VLAN Registration Protocol (MVRP) Questions and Comments
Replies: 2
Views: 1602

Re: Multiple VLAN Registration Protocol (MVRP) Questions and Comments

I have never during maaaany years of networking had the need to have MVRP enabled.

Whats your usecase that you want to enable MVRP?
by Apachez
Fri Jul 12, 2024 12:39 am
Forum: General
Topic: What changed with SSH on 6.49?
Replies: 6
Views: 1126

Re: What changed with SSH on 6.49?

It's not a config issue, its something inherent to the 6.49.x firmware If I take a problematic router and downgrade it to 6.48.x or upgrade it to 7.x with no changes to the config at all, it works fine Every single device regardless of what it is or what config is in place it does not work with 6.4...
by Apachez
Fri Jul 12, 2024 12:31 am
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304092

Re: v7.15.2 [stable] is released!

Only way to get proper attention is to create a support ticket.
I have tried... only 1 out of 3 tickets got a reply for the past 3 weeks...
by Apachez
Fri Jul 12, 2024 12:28 am
Forum: Scripting
Topic: Difference between [ find ] and [ find default=yes ] when trying to set option to all objects?
Replies: 7
Views: 4379

Re: Difference between [ find ] and [ find default=yes ] when trying to set option to all objects?

Thanks! In my case I have created a script based on output of "/export terse show-sensitive file=flash/custom.rsc" where I noted during cleanup that some guides (perhaps outdated?) wrote the find the same as the /export (in 7.15.2 stable) do as in "[ find default=yes ]" while som...
by Apachez
Thu Jul 11, 2024 5:57 pm
Forum: Scripting
Topic: Difference between [ find ] and [ find default=yes ] when trying to set option to all objects?
Replies: 7
Views: 4379

Difference between [ find ] and [ find default=yes ] when trying to set option to all objects?

When doing /export one can often see something like (example from 7.15.2 stable): /ip smb users set [ find default=yes ] disabled=yes But the above can also be written without that "default=yes" part like so: /ip smb users set [ find ] disabled=yes But whats the difference? At first I thou...
by Apachez
Wed Jul 10, 2024 9:16 pm
Forum: General
Topic: [bug?] tc-cake supports negative overhead, but RouterOS does not.
Replies: 2
Views: 570

Re: [bug?] tc-cake supports negative overhead, but RouterOS does not.

Whats the purpose of a negative overhead?

Like if your linux kernel have some vlan tagging offloading for the nic so the kernel doesnt handle the vlan at all but the nic will?
by Apachez
Wed Jul 10, 2024 6:20 pm
Forum: General
Topic: vrrp configuration with fully redundant switches
Replies: 15
Views: 2895

Re: vrrp configuration with fully redundant switches

25 seconds is often related to STP so I would call that as a prime suspect.

Try setting "edge=yes" on all interfaces (just as a test) and see if the downtime goes down to below 1 sec ?
by Apachez
Wed Jul 10, 2024 10:54 am
Forum: General
Topic: Problems with VLAN passtrough
Replies: 9
Views: 919

Re: Problems with VLAN passtrough

In that case (again without Q-in-Q config since I have not much experience from that with Mikrotik) something like this: # Create the bridge /interface bridge add arp-timeout=4m frame-types=admit-only-vlan-tagged name=bridge1 vlan-filtering=yes # Add interfaces to bridge /interface bridge port add ...
by Apachez
Wed Jul 10, 2024 10:52 am
Forum: General
Topic: Problems with VLAN passtrough
Replies: 9
Views: 919

Re: Problems with VLAN passtrough

In that case (again without Q-in-Q config since I have not much experience from that with Mikrotik) something like this: # Create the bridge /interface bridge add arp-timeout=4m frame-types=admit-only-vlan-tagged name=bridge1 vlan-filtering=yes # Add interfaces to bridge /interface bridge port add b...
by Apachez
Wed Jul 10, 2024 10:47 am
Forum: General
Topic: vrrp configuration with fully redundant switches
Replies: 15
Views: 2895

Re: vrrp configuration with fully redundant switches

I was referring to R1-R3 (L3/BGP). L2 VRRP/LAG should kick in pretty much instantly. BTW, what do you mean by upstream LAG in this scenario? When I use MLAG I set it up as (example with Rx upstream, SWx being MLAG and FWx being downstream): SW1 connected to R1 with LAG1 (LACP) and R2 with LAG2 (LAC...
by Apachez
Wed Jul 10, 2024 9:46 am
Forum: General
Topic: Problems with VLAN passtrough
Replies: 9
Views: 919

Re: Problems with VLAN passtrough

I havent done Q-in-Q with Mikrotik (yet) but below should work for your first two vlans (regular tagged and untagged): # Create the bridge /interface bridge add arp-timeout=4m frame-types=admit-only-vlan-tagged name=bridge1 vlan-filtering=yes # Add interfaces to bridge /interface bridge port add bri...
by Apachez
Wed Jul 10, 2024 9:32 am
Forum: General
Topic: What changed with SSH on 6.49?
Replies: 6
Views: 1126

Re: What changed with SSH on 6.49?

How is your ssh config of your Mikrotik and how is that client software configured regarding its ssh-client?
by Apachez
Wed Jul 10, 2024 9:31 am
Forum: General
Topic: vrrp configuration with fully redundant switches
Replies: 15
Views: 2895

Re: vrrp configuration with fully redundant switches

I dont know if MLAG with Mikrotik is different from other vendors but point of using MLAG is having 2 physical devices to behave as 1 logical unit. That is with MLAG I would normally just configure IP-addresses on the VLAN-interfaces and have the MLAG-cluster doing regular L3 routing. This way you d...
by Apachez
Wed Jul 10, 2024 9:26 am
Forum: General
Topic: Layer 7 protocol question
Replies: 2
Views: 649

Re: Layer 7 protocol question

Exposing RDP and similar remote desktops over the Internet without any proper encrypted VPN in between is a VERY bad decision to make. Have the clients use wireguard and terminate the encrypted vpn as wireguard on your Mikrotik and then from there let them handshake with the RDP service of the host ...
by Apachez
Wed Jul 10, 2024 2:56 am
Forum: General
Topic: Terminal history clear
Replies: 3
Views: 2589

Re: Terminal history clear

And because of my post I finally find out how to do it:

/console/clear-history 
by Apachez
Wed Jul 10, 2024 2:54 am
Forum: General
Topic: Terminal history clear
Replies: 3
Views: 2589

Re: Terminal history clear

So ehm any progress on this now when we have RouterOS 7.x? Doing a: /system reset-configuration keep-users=yes no-defaults=yes skip-backup=yes run-after-reset=flash/custom.rsc Doesnt seem to erase the terminal history at all which remains as others have noted years ago. On a regular linux system you...
by Apachez
Wed Jul 10, 2024 1:43 am
Forum: General
Topic: VRF-support for DNS is broken?
Replies: 21
Views: 13515

Re: VRF-support for DNS is broken?

The broken VRF-support för /ip/dns have been confirmed for both CRS326-24S+2Q+ and CRS112-8G-4S using both RouterOS 7.15.2 stable and 7.16beta4 testing.

Anyone in here who managed to get it working on these or some other Mikrotik model?
by Apachez
Tue Jul 09, 2024 8:29 pm
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 139600

Re: v7.16beta [testing] is released!

You mean the ISP router waits for RA from your Mikrotik? Another thing to lookup/verify is if your ISP actually sends you a public nexthop to be used as gateway for your Mikrotik or if they rely on linklocal address instead (which lately seems to have become a thing among ISP's)? No, what happens w...
by Apachez
Tue Jul 09, 2024 8:23 pm
Forum: General
Topic: High latency/half bandwidth CRS312-4C+8XG [SOLVED]
Replies: 7
Views: 3764

Re: High latency/half bandwidth CRS312-4C+8XG [SOLVED]

Noone is blaming anyone, only pointing out that the current firewall rules seem incomplete ... You mentioned "compared with default configuration" and I was pointing out that CRS devices don't have any default ... meaning that an unsuspecting fresh ROS user (without experience with MT dev...
by Apachez
Mon Jul 08, 2024 4:33 pm
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 139600

Re: v7.16beta [testing] is released!

Ergo, IPv6 is way borked in 7.16beta4. I have to pull back from this statement until I do further testing. My ISP also changed the way they issue default routes for IPv6 and so I now I don't know if the core issue was 7.16beta4 or the ISP change. This particular ISP now requires that IPv6 DHCP and ...
by Apachez
Mon Jul 08, 2024 12:47 am
Forum: Scripting
Topic: How to print to console while reset-configuration script is being runned?
Replies: 3
Views: 3883

Re: How to print to console while reset-configuration script is being runned?

I found this that can output to a local file but its not really what Im looking for: https://github.com/joncutrer/perfectrestore All I want is to be able to print to the console various stages of my custom.rsc when being runned by reset-configuration. It works when I run it as /import after I have l...
by Apachez
Mon Jul 08, 2024 12:39 am
Forum: General
Topic: SFP port Doesn't work on CCR2004
Replies: 8
Views: 1372

Re: SFP port Doesn't work in CCR2004

In the Switch side the TX Power is -7.146dBm and the RX Power is -40.000dBm and the Router side the TX Power is -5.738 and the RX Power is -40.000dBM Is it mandatory to use a MikroTik SFP in order for the connection to work? Not that I know of. You could try to loop the interface to see if you get ...
by Apachez
Mon Jul 08, 2024 12:32 am
Forum: Scripting
Topic: How to print to console while reset-configuration script is being runned?
Replies: 3
Views: 3883

Re: How to print to console while reset-configuration script is being runned?

How does it write to the terminal, if the script is launched from an internal session? You have to launch it in the terminal yourself, if you want to see the results of the script. Same way as whatever is writing "Resetting configuration..." to the console? After all its a regular linux i...
by Apachez
Sun Jul 07, 2024 10:44 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304092

Re: v7.15.2 [stable] is released!

No, seriously - who asked for DLNA? Who needs DLNA in the main package of the router? Without ability to turn it off? Is it really that hard to keep routers for routing and separate packages for other unnecessary functions? Every single unnecessary feature increases attack surface and helps bad guy...
by Apachez
Sun Jul 07, 2024 4:56 pm
Forum: General
Topic: After trying to reset the router, there is no wireless network
Replies: 16
Views: 3074

Re: After trying to reset the router, there is no wireless network

Thanks.
Connect RJ45 to ether1 and console cable to well CONSOLE and then through the console cable:
I only have 8 RJ45 ports, 1 USB port and 1 SFP port.
Then connect to the first RJ45 interface, that should be refered to as ether1 internally.
by Apachez
Sun Jul 07, 2024 3:33 pm
Forum: Announcements
Topic: Newsletter #119 | July 2024
Replies: 37
Views: 55439

Re: Newsletter #119 | July 2024

I never understand why 24V devices exist... Why not 48V which is standard ? It's PITA when you, for eg., have PoE switch and than PTP antennas are 24V... Because sometimes companies like Mikrotik dont wait until a standard is set through RFC etc and start to use pre-standard setups which later on t...
by Apachez
Sun Jul 07, 2024 3:30 pm
Forum: General
Topic: After trying to reset the router, there is no wireless network
Replies: 16
Views: 3074

Re: After trying to reset the router, there is no wireless network

I found out the router kept my exported config file so restoring should be easy. It even saved a pre-reset backup file but I can't edit that one I would do something like this: Connect RJ45 to ether1 and console cable to well CONSOLE and then through the console cable: /ip address add address=192.1...
by Apachez
Sun Jul 07, 2024 2:35 am
Forum: General
Topic: How to properly move config from one Mikrotik device to another of the same model (and firmware-version)
Replies: 0
Views: 1596

How to properly move config from one Mikrotik device to another of the same model (and firmware-version)

I pasted this previously on reddit but in case somebody else runs into this and are new to Mikrotik devices (and RouterOS). With Arista/Cisco/HPE/Juniper/VyOS and others you can move the config of one device to another by: 1) On the box itself: copy running-config startup-config 2) Then copy startup...
by Apachez
Sun Jul 07, 2024 12:46 am
Forum: Scripting
Topic: How to print to console while reset-configuration script is being runned?
Replies: 3
Views: 3883

How to print to console while reset-configuration script is being runned?

To mimick the behaviour of copying a config from one device to another Im utilizing reset-configuration in Mikrotik like so: /system reset-configuration keep-users=yes no-defaults=yes skip-backup=yes run-after-reset=flash/custom.rsc However I fail to get the script to output info to the console whil...
by Apachez
Fri Jul 05, 2024 10:36 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304092

Re: v7.15.2 [stable] is released!

Please accept my apology. Still unclear if supout.rif was attached to that SUP, but I am sure Mikrotik will request it if missing. Sorry for going slightly offtopic but what is the expected turnaround time to get a response from support? I filed this /ip/dns VRF-failure bugreport almost 2 weeks ago...
by Apachez
Fri Jul 05, 2024 10:30 pm
Forum: General
Topic: Problem with Bonds and Bridging [SOLVED]
Replies: 8
Views: 4010

Re: Problem with Bonds and Bridging [SOLVED]

Delete sfp-sfpplus2 from the /bridge/ports list, then you can create a new bond interface where sfp-sfpplus2 is a member.
by Apachez
Fri Jul 05, 2024 10:02 pm
Forum: General
Topic: Which services/features of Mikrotik (RouterOS) still lacks VRF-support?
Replies: 6
Views: 1085

Re: Which services/features of Mikrotik (RouterOS) still lacks VRF-support?

Ah, before I forget, for the same reason (DNS not working) I couldn't update the RoS from a internet connected VRF and had to go through "main" (that was on 7.12.1, but if things have not changed (yet) with 7.15.x, the issue should remain the same. Yes, that seems related to the broken VR...
by Apachez
Fri Jul 05, 2024 9:05 am
Forum: General
Topic: chr license can't renew
Replies: 1
Views: 435

Re: chr license can't renew

Seems to reply to pings now at 2024-07-05 08:05 CEST.
by Apachez
Fri Jul 05, 2024 8:32 am
Forum: General
Topic: OCHcloud: When Core Routers Turn Evil
Replies: 12
Views: 2189

Re: OCHcloud: When Core Routers Turn Evil

As my comment on similar topic in /r/mikrotik over at reddit: Plenty of CVE score 9+ when it comes to Juniper and Cisco equipment aswell for the past years. Snowden docs was only the top of the iceberg with examples such as: https://www.rapid7.com/blog/post/2015/12/20/cve-2015-7755-juniper-screenos-...
by Apachez
Fri Jul 05, 2024 1:38 am
Forum: General
Topic: Which services/features of Mikrotik (RouterOS) still lacks VRF-support?
Replies: 6
Views: 1085

Re: Which services/features of Mikrotik (RouterOS) still lacks VRF-support?

L3 Hardware Offloading L3HW Feature Support VRF N/A Only the main routing table gets offloaded. If VRF is used together with L3HW and packets arrive on a switch port with l3-hw-offloading=yes, packets can be incorrectly routed through the main routing table. To avoid this, disable L3HW on needed sw...
by Apachez
Fri Jul 05, 2024 1:05 am
Forum: General
Topic: Which services/features of Mikrotik (RouterOS) still lacks VRF-support?
Replies: 6
Views: 1085

Re: Which services/features of Mikrotik (RouterOS) still lacks VRF-support?

Only as a note, since dns is not working, also NTP is a problem, as you need DNS resolving to use servers such as pool.ntp.org.
Thanks, added it to the original post.
by Apachez
Thu Jul 04, 2024 6:08 pm
Forum: General
Topic: Which services/features of Mikrotik (RouterOS) still lacks VRF-support?
Replies: 6
Views: 1085

Which services/features of Mikrotik (RouterOS) still lacks VRF-support?

Looking through the list over at https://help.mikrotik.com/docs/pages/viewpage.action?pageId=328206 I have currently located these services as missing proper VRF-support, that is when you for example create a VRF such as "VRF-MGMT" and expect the service to only exist at VRF-MGMT rather th...
by Apachez
Thu Jul 04, 2024 1:50 pm
Forum: General
Topic: Firewall rules with L3 HW offload [SOLVED]
Replies: 6
Views: 4650

Re: Firewall rules with L3 HW offload [SOLVED]

Im not 100% into Mikrotik lingo yet but when speaking about fastpath/fasttrack and firewall (iptables/nftables) thats more about not having to evaluate as many rules as you normally need to. For example having allow estalished/related as the first rule is a "fastpath" setting - but the pac...
by Apachez
Wed Jul 03, 2024 9:21 pm
Forum: General
Topic: VRF-support for DNS is broken?
Replies: 21
Views: 13515

Re: VRF-support for DNS is broken?

Im guessing noone in here are using /ip/dns along with VRF?
by Apachez
Wed Jul 03, 2024 8:16 pm
Forum: General
Topic: Firewall rules with L3 HW offload [SOLVED]
Replies: 6
Views: 4650

Re: Firewall rules with L3 HW offload [SOLVED]

https://help.mikrotik.com/docs/display/ROS/L3+Hardware+Offloading Feature: IPv4 Firewall Support: FW Comments: Users must choose either HW-accelerated routing or firewall. Firewall rules get processed by the CPU. Fasttrack connections get offloaded to HW. Release: 7.1 Feature: IPv4 NAT Support: FW C...
by Apachez
Wed Jul 03, 2024 7:34 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 649
Views: 304092

Re: v7.15.2 [stable] is released!

how to reproduce? If you refer to my comment, there is no step to be taken for reproduction.. it just happens continuously after power on! If possible try to in a lab setup your own authoritive DNS server for the zone lets say "example.com" and then have a client using your Mikrotik as a ...
by Apachez
Wed Jul 03, 2024 11:08 am
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 139600

Re: v7.16beta [testing] is released!

Well, after MikroTik being in the field of router software development for nearly 30 years we could kind of expect that the developers have gotten around to setting up some automated test environment that runs a series of regression tests before even a beta release hits the download servers. They m...
by Apachez
Wed Jul 03, 2024 10:33 am
Forum: General
Topic: Is RouterOS Affected by CVE-2024-6387?
Replies: 9
Views: 3808

Re: Is RouterOS Affected by CVE-2024-6387?

And what would the PoC show do you mean?
by Apachez
Wed Jul 03, 2024 10:28 am
Forum: General
Topic: VRF - probably a bug
Replies: 1
Views: 783

Re: VRF - probably a bug

Most likely due to that the DNS-service that is /ip/dns in Mikrotik have broken VRF support. So it currently only work for VRF=main. It was supposed to have been added in 7.15 stable but the quality assurance over at Mikrotik have work to do (its still broken in 7.15.2 stable and 7.16beta3)... I hav...
by Apachez
Wed Jul 03, 2024 10:24 am
Forum: General
Topic: Securing the switch from untrusted network [SOLVED]
Replies: 6
Views: 2323

Re: Securing the switch from untrusted network [SOLVED]

Except for regular hardening as in disable services not needed (there are a few) and adding firewall rules another option to enhance the security or rather the segmentation is to use VRF's. Unfortunately not all services supports VRF today (as of 7.15.2 stable) such as DNS (currently broken), FTP an...
by Apachez
Wed Jul 03, 2024 10:19 am
Forum: General
Topic: VLANs & DHCP advice needed
Replies: 8
Views: 1390

Re: VLANs & DHCP advice needed

Usually you dont want clients to speak to each other. That is at the layer2 switches you use something called port-isolation (or protected vlan which is a specific subset of private vlan) so the clients can only speak upstream. If that is the case in your case I would just do regular VLANing on the ...
by Apachez
Wed Jul 03, 2024 10:16 am
Forum: General
Topic: Is RouterOS Affected by CVE-2024-6387?
Replies: 9
Views: 3808

Re: Is RouterOS Affected by CVE-2024-6387?

No. Mikrotik is not affected by this vulnerability
An official statement at mikrotik.com would be a better source than some random forum member (no offense but still :-)
by Apachez
Wed Jul 03, 2024 10:14 am
Forum: General
Topic: Any plans to bring back UI for routing filters in v7?
Replies: 5
Views: 1112

Re: Any plans to bring back UI for routing filters in v7?

A workaround would be to at least add it as a textarea so that you can write the stuff through winbox/webfig. Setting up rules through GUI is less efficient and troublesome where copying a single (or multiple) row(s) and do the changes textual is way faster. One could even argue if the admin doesnt ...
by Apachez
Tue Jul 02, 2024 10:56 pm
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 139600

Re: v7.16beta [testing] is released!

But at the same time these "betas" fixes critical errors found in the "stable" releases - which gives? Should I use a "stable" release who is more broken than the "beta" release who is just slightly broken? Which one would you recommend to be used in production?
by Apachez
Tue Jul 02, 2024 11:42 am
Forum: General
Topic: System login
Replies: 23
Views: 13027

Re: System login

If you click on the group tab - whats the difference between full and admin? I would probably try to extract the current config and then import it back with "keep-users=no" (dont forget to add a custom user to your rsc file). Doing a fresh netinstall is probably a safer bet to just wipe th...
by Apachez
Tue Jul 02, 2024 11:40 am
Forum: General
Topic: Loop error even though RSTP is enabled
Replies: 6
Views: 1137

Re: Loop error even though RSTP is enabled

Can you provide the log you are refering to since both screenshots shows the same network diagram?
by Apachez
Tue Jul 02, 2024 10:57 am
Forum: General
Topic: FEATURE REQUEST: Source Interface/Address for system services (Updates, NTP client, etc)
Replies: 1
Views: 519

Re: FEATURE REQUEST: Source Interface/Address for system services (Updates, NTP client, etc)

Somewhat of a workaround is if you use VRF for your MGMT-services then you can define "pref-src" when you define the routing table for that VRF i /ip/route. But I fail to locate any up2date info of that setting at https://help.mikrotik.com Only locate this at https://wiki.mikrotik.com pref...
by Apachez
Tue Jul 02, 2024 10:38 am
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 139600

Re: v7.16beta [testing] is released!

@Apachez are you the same Apachez on VYOS forum, if you are I'm glad you are here too
Yup, thats me! (failed to find how to send you a DM so the reply is public instead).
by Apachez
Tue Jul 02, 2024 10:00 am
Forum: General
Topic: Feature Request: Port-Security & Dynamic Arp Inspection
Replies: 7
Views: 1903

Re: Feature Request: Port-Security & Dynamic Arp Inspection

Sounds like really nice features to have specially on the switch-series. Port-security with both dynamic (that resets when disconnecting interface) aswell as sticky (to be included in the config and survive a reboot) along with DAI (Dynamic ARP Inspection) and IP Source Guard are really nice feature...
by Apachez
Tue Jul 02, 2024 9:48 am
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 139600

Re: v7.16beta [testing] is released!

Static DNS querying will be fixed in the upcoming RouterOS beta release. Please remember - this is beta. Released for testing new features and fixes. Some services might not work properly, and these version should not be used on important routers. As for the DoH - we are looking into this and will ...
by Apachez
Tue Jul 02, 2024 9:34 am
Forum: General
Topic: Loop error even though RSTP is enabled
Replies: 6
Views: 1137

Re: Loop error even though RSTP is enabled

What vendor/model are R1 and R2 and how are they configured? And the switch-core1 and switch-core2 aswell as sw3 what vendor/model are they and how are they configured? For example if R1 and R2 are Cisco routers then you need "l2protocol peer stp" in those routers towards the switch-coreX ...
by Apachez
Tue Jul 02, 2024 2:15 am
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 139600

Re: v7.16beta [testing] is released!

And it seems like making /ip/dns VRF-aware in 7.15 according to https://download.mikrotik.com/routeros/7.15/CHANGELOG is still broken in 7.16beta3 :-(
*) dns - added VRF support;
by Apachez
Tue Jul 02, 2024 1:58 am
Forum: General
Topic: 7.15.x Stable (is really 7.16Alpha)
Replies: 16
Views: 2549

Re: 7.15.x Stable (is really 7.16Alpha)

OP is a pot stirrer who also crossposted this same drivel to Reddit. ChatGPT generated nonsense like this should be stamped out wherever it’s used and the poster banned. So what do you feel is incorrect in that post? I have myself some anger management to deal with when Mikrotik claims that /ip/dns...
by Apachez
Tue Jul 02, 2024 12:03 am
Forum: General
Topic: VRF-support for DNS is broken?
Replies: 21
Views: 13515

VRF-support for DNS is broken?

According to the changelog for 7.15 stable a new feature was finally added to the /ip/dns service in RouterOS: https://download.mikrotik.com/routeros/7.15/CHANGELOG *) dns - added VRF support; However I cant make this to work in 7.15.1 stable nor 7.15.2 stable (or 7.16beta2). I can verify that the V...