So I have a device that is a layer2 packet analyses. The issue I have is I have a PAIR of 10gig interfaces that I need to loop though this unit. We have choose to use a CRS317 to do that, so ports 15/16 are plugged into the 10gig layer2 analyses box. The issue, is that I need to take a VLAN, say vla...
What I am unable to do is add a second VPC to my CHR. I want my CHR to handle the firewall and NAT for my servers, but it won't let me add another VPC.. ??
A client has anywhere between 3-10 simple queue targets in each one, when i do a :foreach, i end up getting a array, i either need a way to convert the array to simple text (that would be the simplest) or a way to simply append a new prefix onto the existing target. I.e. just adding blocks and need ...
So I have many dude versions installed, looks like now the rc19 version installed, when i run the dude even from a specific directory, it tries to start the dude server, but it keeps calling the dude vrc19 and it opens again and again. anyone else have this happen?
I like torrents, don't use a script, would be nice to have a RSS feed for torrents then just point our torrent app and let it eat when a new version comes out. .BTW, looks like no full seeds for 6.31
Android lolipop samsug note 3. 1.. When you scroll over in interfaces, to something like traffic, the menu bar does not follow, i.e. you see "General poe sfp" but you are viewing the traffic graph 2. traffi graphi looks good, tx/rx bytes should be translated to mbits etc. 3. opening bgp in...
With IPv4 addresses running out, here is something that we coould do to help with the existing Ipv4 addresses that we have. If we can identify via MAC things like Android phones, iphones ,and other devices that typically do not need a public, it would be nice to say, xyz MACs can get this IP pool, g...
This should not be a problem. Caps man it, bring it all back, vlans, etc, no big deal! would be a fun project to work on! Let me know if you need a bit more professional consulting on it!
This week we will be talking about Credit Card Payments and HotSpot Systems with co-host Dennis Burgess and Host Steven Grabiel . 11am CST, 9am PST ! Don’t forgot you can download the previous episodes to put on your media player and listen while in your car free of charge by going to www.ispradio.c...
Link Technologies, Inc. is looking for a few good engineers to add to our consulting group. If interested, review the PDF and send resume and salary requirements to jobs@linktechs.net
A small network when turning on MPLS Distribute Default Route, all traffic stops going in/out till the check is turned off. While off, outbound traffic does not use MPLS, and the edge router, even though MPLS has a forwarding database does not show any traffic going via MPLS.
A large network that is running VPLS has been working quite well. We currently are not worried about packet fragmentation, however, we can not push the 1500 byte MTU packets though the VPLS in some instances. VPLS circuits are set to 1508 in MTU in case of VLAN information, the VPLS tunnels do come ...
Use your mangle to set priority, that corresponds to the "ampdu". Don't check for latency sensitive applications, as it is possible it would create latency.
How about updating the P-Throughput field to be more accurate and work in all wireless protocols. Then we should have this field update every x often (ability to set the x). Then have that as a $wlan1_pthoughput variable that changes. Then have the ability to set queue tree and simple queues with si...
Export the configuration, clear the user manager, and then update. We have scripts running on very active systems that prevent the logs from filling the drive. we don't need that historical data. I would assume you can also send that data to a "syslog" server as well.
Would assume you would just do it in the command line, by exporting data from one and importing it into the other. Don't know if the payment history and logs would carry over.
The simple answer is yes/yes. lol The RouterBOARD product family simply can't be beat for price/performance. If your needs are that where a RouterBOARD product will work perfectly, then you don't need to invest in a x86 box! However, once you go beyond their capabilities then you will need to go wit...
We have customers running average of 1.2 - 1.5 gig of traffic running 3 full GigE BGP feeds running on a www.mikrotikrouter.com box. The v5 multi-core improvements have helped quite a bit as well!
There are several options, I would recommend that you use something that is built and designed for MikroTik. There are a number of products out there, you can also look at www.mikrotikrouter.com. These units would come with RouterOS on them ready to run.
This depends on your DSL Provider and the MTU they give you. Typically, 1420-1440 works well, but if it is a true bridge DSL then 1500 should be fine. If it is a PPPoE session it would make a difference as well.
Of course you can shape it however you want with MT. Unlike the other boxes though you would need to build your own system, but that should work better for you as you can prioritize that as much as you wish or as little. You can also give bursting abilities if you wish . It may not work 100% like th...
My assumption is still a month or two out at the soonest. I may have a preview copy at the MUM in Budapest. But that would just be that. We currently do offer ibook and Kindle editions, they are both reduced from the list price so, might be a way to get started :) I also have put a call out for any ...
You will have to redesign the login.html to include the signup links etc. That is a manual process, and is not integrated into the user manager system.
In this case, we have a public subnet, some devices are out there on the subnet, but we want to show ALL ips as reachable with pings. I forgot about the ICMP options, in our case I did. add action=redirect chain=dstnat comment="" disabled=no dst-address=x.x.x.0/24 icmp-options=0:8 in-bridg...
Just wondering if someone thought up a way to allow your Router to reply to ALL pings to a subnet routed to the router? tried to do some redirects and such, not much working..
Yep, I am working on a Second Edition. I also wanted to note that there is a iBook and a Kindle version of Learn RouterOS now as well! http://www.amazon.com/Learn-RouterOS-ebook/dp/B003KGBMJO/ref=sr_1_2?ie=UTF8&m=AG56TWVU5XWC2&s=digital-text&qid=1294425953&sr=8-2 That would be the li...
We have a successfully had over 3500 concurrent Hotspot users on some of our systems. We have some hotspot systems that can process over 15,000 logins per week
A few things. 1. I am seeing the L2TP problem on v4.13 as well. Basically it is what you descibe, you can winbox using policy based routing into that IP on the secondary routing table, but not L2TP. I have not been able to try v5rc3 yet, but will if the customer gives permission. So it may be fixed ...
There are also other MikroTik based products available. They have a list on-line as well as you can google! Many people are purchasing PowerRouter 732s cause they are supported, tested, years of reliability, as well as are in-stock.
If you are interested in a stable platform that you don't have to worry about, hit http://www.mikrotkrouter.com. Plenty of options including SFP interfaces as well, and performance testing. Plus you can run v2-v5 on it, so you don't have to run bata software if you do not wish too.
Just a FYI, heading out to the MUM training this week! I hope to see everyone there. I am looking to see if the hotel has a bar, if so, I will be down there this evening. Feel free to contact or watch this forum for updates on time etc.
Could be BUS limitations, or IRQ sharing. Just to name a few. I would recommend ensuing that the hardware is on the ACL and is supported with RouterOS.
Simply put, there is many other things that you have to look at vs, does RouterOS load on my x86 system. Check your bios settings, check to make sure your equipment has proper buss design etc. There are also a number of other x86 based solutions. I actually make one, http://www.mikrotikrouter.com. N...
Do a netinstall or CD based installation, and then you should be good. If the drive is going bad, you can attempt to contact RouterOS, however, it will be quicker to just get another license.
I know you are saying you can guarantee it, but again, there is more factors than # of users. Again, we have a 2282 running 15,000 users! Why, cause of the rest of the rules etc that they put into it. So # of users is really not a good "benchmark".
A Power Router 732 can handle 600 Meg of traffic, it depends on what you are DOING with that, witch will make the difference! DHCP, no prob, DNS, I would think a dedicated DNS server would be better than the simple caching system RouterOS has. Hotspot can take up some CPU, but most people don't know...
Guess I should chime in here. -- The PowerRouter 2282 has been tested with 100 meg circuit and 15,000 PPPoE users.. -- The PowerRouter 732 is NOT a 820 ONLY, we have had a number of people call in with 820s that have crashed. Just cause it may boot up on a 820, does not mean it will RUN on a 820. Th...
Using the latest v5b4 packages .. WE have profiles for users to select. Then we have a Validity and a uptime limit in the limitations. If the profile has a limitation, what is the difference between the validity and uptime limit in this instance? Specifically, I want users time to start NOW, then se...
Now try with High power cards, such as XR2s And as well R52N.. I think the results would be interesting to see.
We always sell 1 radio card in one board on the same freq, we typically don't have much issue with putting a 5 gig and 2.4 gig card in the same box though.
Seeing you asked about a pre-package solution, www.linktechs.net has a PowerSpot 400 based on RouterOS 400 series hardware with everything you need to get started for a automated Hotspot solution.
We did update the version again, you can re-download it. Make sure to uninstall the previous and backup your routers as well. The updated version may work better for you now.
In this case, the DNS was resolving, at least, I am using it to do setup on auth.net. Auth.net works fine, just not paypal.. Maybe paypal onl updates there DNS every so often?
I am getting this error, when paypal tries to post back to user manager a payment. I have searched and did'ent find anything. If I am having this issue I am sure someone else will. Ensured that the public host is setup right, SSL is on, tried with and with Secured Response.
Don't know what you mean by problems with current SMP support. Its not perfect, but with properly designed hardware you should not have any issues with multi-core.
Can you have a OSPF network, with several routers sending the default routes, but have one primary default route running type 2, and the rest type1. So if the type 2 default route goes down, the network will use the type 1 default routes to route traffic out based on cost, but if that type 2 comes b...
PushScript v1 -- A FREE program provided by Link Technologies, Inc will be released this week. This application allows you to push a RSC or TXT script file out to many RouterOS devices quickly, and simply! Be sure to sign up on Link Techs mailing list to get the latest information on it! Visit http:...
You can see our site at http://www.mikrotikrouter.com. We have thousands of installations all over the world doing everything from PPPoE servers, to BGP, and web caching. All based on RouterOS. Several distributors in the US, Europe, and Africa can assist getting your units. Fiber Interfaces are sup...
There is a lot more too just sticking a 4 port NIC card in a PC to get actual throughputs. I have lots of customers call asking why their 4 port NIC in this nice Quad Core system don't give more then 40-50 meg throughput. There is buss limitations, there are irqs and interrupts etc. Making a system ...
There is a supported hardware list. That includes Supported and Tested solutions. so you don't have to just hope, you can purchase a unit, pull it out of the box, plug it in the rack and start configuration. That it. We make some at http://www.mikrotikrouter.com, but it is also listed on the support...
Maybe if everyone nicely posts what they were hoping for, Mikrotik can try and implement these in the next product. I was personally looking for that was not delivered: - Multi-Core PPC processor I would also like to see: - More professional case design, e.g. better fitting ports, consistent colour...
Or, you can just contact us directly at support@linktechs.net with your exact shipping information and we will get a quote for you for shipping via UPS directly to you
You can do this, but not with the proxy system. You can send out specific IPs out specific public IPs, but again, you can't have Proxy enabled to do this.
I would hardware switch them with a TAP or Mirror port for your monitoring. No CPU load then since you are not wishing to do much with the ROuterOS. It will just make it a managed switch then.
Sounds like a firewall or NAT issue. There are a few changes, disable your firewall rules and double check your NAT if you are using that. I bet you will find something in there. Else a MT consultant should be able to help out.
The type of traffic should not affect this, unless there is something wrong with DD-WRT. I would suggest dropping in a MT at the remote site and seeing if it does this too. I have extensive experience with this in business and corporate environments and I know it does work quite well. Without taking...
Don't know what kind of "bridge" you are using. If its not a WDS bridge (the only way to properly bridge a wireless client in 802.11x), then you can see some sort of MAC NATing. If you are using MT, create a WDS bridge and that should fix the issue! This is discussed in the hotspot section...
The information I have is that the proxy system will only use the main routing table, so you can't split proxy traffic over a number of connections. You can split everything else though, and just let your port 80 stuff go out your primary connection.
You may need to havfe a src-nat rule as well for traffic coming from that server to be natted out properly as the old IP. Use a "Private" IP to do the NATing too, this way, you can exclucde traffic going to your new PUblic IP that would be on the server as well.
Other things to note is the connection rate. If the clients all are linked at 54meg then the max possible transmission on a single AP is around 7.5 meg. If clients are linked at lower rates, this will reduce your overall AP thoughput. Assuming that you have ALL of your clents at 54meg only, then fig...
There are a numbger of ways of doing this, typically though, it would be routing issue, i.e. conect to both IPs, keep them alive, perfer one specific one. If that goes down, then it goes though the second. I have done a number of these setups, and I am sure someone on the MT consultant list can help...
The end result is having a packet mark, however, marking your connection is less CPU intensive. The PROPER or perferred way is the do the connection mark then the packet mark. This does two things, provides a simpler faster way to mark packets once the connection is identified. Two, depending on the...
99% of the time this is a configuration issue. Could be the SIP helper service is on. Could be inbound NAT issues, could be lots of things. I would get a consultant to figure it out.
If one IP phone is not working, then it may be the phone. Hit up http://www.mikrotik.com/consultants.html and I am sure one of those guys can help you troubleshoot.
The trial user feature is what you need. You may wish to run a script at midnight to clear out trial users vs using the trail reset feature. Any MT consulant should be able to do that without an issue. They are listed here at http://www.mikrotik.com/consultants.html
ON non multi-cpu systems this is normal. After reboot the system rebuilds its cache from the disk contents. Don't konw if this cache goes into RAM (very well may) so its not stored, but larger the cache longer times!
I don't see them twice, even though they should be. The BGPlay, is kewl btw, but shows all traffic hopping off of provider B to provider A, and then a bunch of lines go away like prefixes or seomthing is not being annouced, what is happening. I also don't see them twice in the annoucments, remember ...
Intresting action here.. Two ISPs , two MikroTik Routers. Each one is receving one providers full BGP tables. Both routers have 4 differant prefixes listed to advertise (all setup with NO for sync). This works fine, and if you reboot one MT, everything is fine, all traffic hops to second MT, great. ...
Certification really don't make it solid. Only testing, knowledgable Mikoritk Engineers, and acutal production usage. WE have been developing on the PowerRouter 732 platform for almost 4 years now! People ask why don't you put a newer processor than a 3.0 gig Dual Core, simple, reliability, the syst...
Sorry can't tell ya. But I can tell you that there is an extensive amount of time testing and retesting cards using both acutal production units and simulated read/writes and they are NOT your normal 25 buck cards.
You are still proxying traffic. Hence tracking it, etc. So, hence, you have the high cpu count. Think of this. What happens is the MT gets the traffic, and then sends it out, as a client to your parent proxy, and then returns that information to the client. So, yes, this will eat up CPU as it should...
yes all in stores. You should use a better CF card. Most will only run 100,000 writes if that. The PoweRouters (www.mikrotikrouter.com) use industrial cards designed for over 3million writes.
The issue that you have here, is that the needs dont' outweigh the deveopment costs of such of units. MikroTik has said this a numbger of times. I expect to see a many port version of the 1000, but I doubt that you will see a huge CPU unit like the PowerRouters. Also, note that we currently have 224...
What occurs with slow CF cards, and small processors . IN some cases WebProxy will work fine on these, it just depends on the size of the CF etc. With the CF, as soon as you boot, it does a read on all of the files to rebuild the cache etc. SOOO. Thats why it takes a long time on reboot.
Keep in mind that many of those cards have less than 100,000 writes on them. I have seen some cards spec out at 10,000, for camera images etc, that maybe fine, but for an OS that could be running for years, might be bad. I would also always recommend products listed in the HCL on mikrotiks site as w...
The switching capability is limited to hardware with switching chips for one. So you are using CPU. Second, you do not allow direct access to the hardware in question since you are runing virtulized, so you are dedicating the system to RouterOS. Overall, there are quite a bit of resources used by th...
Is there a way to log Ethernet drops? I.e. I have an Ethernet port that drops maybe 1 ping, but the actual Ethernet goes to "NO LINK" Its SO short though, I would rather have something that logs it
the 100s were really underpowered, We get around 30-40meg though most 433s, but really go for the AH versions, much better. It also depends if you are doing connection tracking, firewalling rules etc.
One of hte reasons to buy a supported and tested RouterOS system :) Regardless, it could be lots of things. I would have to look at it, but remember, just cause linux runs on it, don't mean MikroTik will! Check out the http://www.mikrotik.com/consultants.html list, and get someone to take a look .. ...
Just remember, there quite abit more to getting a high-preformance RouterOS system than just slap some NICs in a PC and it will do GigE routing. IRQs, buss limitiations, etc all have to be taken into account!
There is a lot more to it than just simple CPU usage. PCI buss design and limitiations, IRQs, testing application, etc. So just buy putting some hardware togeather, don't mean its a good design. There is lots more to it than just build it and it will work!
I would personally stick with what is on the HCL. There are many factors when building your own system, and you never know if there is going to be an incompatability. http://wiki.mikrotik.com/wiki/Supported ... 86_Systems is where you want to look.
We had a config in FreeRadius that never sent a deny. It would send an accept, but if it was not found in the database, it simply would not reply, then it would go on to the next server. Watch your ping times and bw though to the first server, as you will want to keep your timeout value low enough f...
The linksys should have its DHCP server turened off, and the hotspot port should be plugged into the lAN segment of the linksys. Should not use the linksys WAN port.
any PCI slot can handle that as its a "PCI" system, that just gets it power from there. Usually don't turn on and off the system though. Plenty of other options though out there.
The only moving parts are the fans in the unit. We use speicalized CF card for the OS, and if you want a hard drive option for caching, you can choose SSD drives as well
You cna create a rule that matches data coming from the Proxy system. This rule has to say at the top of the list, so you will need a script to do that
They run RouterOS without issues! http://www.mikrotikrouter.com. I have also done quite a few, around 800 on a RB1000... Its also important to note that standard PC hardware is sometimes not the same, as you have changes in drivers, PCI Buss limitations, etc. So, hard to say.
I would assume receiving all of your routes would be the issue rather than the OSPF. I.e. when your BGP peer come up, it consumes 100% cpu during the receive of the routes. This is something that the PowerRouter does (multi-core) much better. Its not really an issue with RouterOS, but more of a sing...
Depends on what you want! lol .. Is a full custom application, so its whatever you wish. I would suggest taking this offlist if you would like to e-mail me at dmburgess@linktechs.net, we can talk more about it.
online users?.. They avg between 1000-3000, it goes up and down as its a univerisity, a number of subnets too. :) The built in system can handle thousands of users, just not well. Its optimized for a VERY few units, 100 or so MAX, we had about 5000 users in it at one time, but even one high end har...
around 100-200 at most with internal auth, with external, we have PowerRouter 732s running 3,000 hotspot users. with 3000 users, what is the cpu level? could suports 10000 users ? Would really depend on other factors, bandwidth, rules etc. If you need more power though, I would not see a reason why...
The CLOSEST you can come to that is a PowerRouter 732, as they are reated up to 120F, the 1000s are only rated for 105F I belive. The 732 has a 2 port Fiber option as well. www.mikrotikrouter.com. However, if you need the fiber but 1000 or smaller board will work, then I would suggest http://www.mik...
Upgrading to user manager will speed things up, as 1/2 of your CPU usage is the database lookups! 100 or so is about the max. I know someone will go SPAM SPAM, but visit http://www.mikrotikrouter.com. The 732 I have seen upwards of 300 meg of traffic and 2800 PPPoE sessions, and the 2200 there is on...
I am wishing to use BGP in place of OSPF. One AS, private for now. If I just simply start adding BGP peers to the network, once I get 3-4 hops out, the IPs start to drop off at the end with TTL issues. Looks like all of the routes are being added at a cost of 200 at every interface vs their internal...
I DO APOLOGIZE FOR THE AD: However, I know there are some people that will find this of interest to them! ss01 Aug. 25 16.37.jpg Link Technologies, Inc, along with the Author, Dennis Burgess, is proud to offer the FIRST, Mikrotik RouterOS book on the market. Learn RouterOS, will take you though Rout...
Simply put, file sharing and print sharing over a PPTP VPN is perfectly fine. THe fact that the admin don't know how to make it work shows this. RouterOS transports the IP network over, no prob. The rest is windows software and systems to make it work right. I have businesses that have 20 sites with...
Remember, that most firewalls can not just be "copied" without at least an understanding of what they are doing. Some common "scripts" that are out there commonly block known good ports, so be careful and if you don't know what they all do, don't load them, or have a consultant h...
Yep, sounds like some little check box or small issue. I would suggest getting a Mikrotik consultant to take a look at the box. http://www.mikrotik.com/consultants.html is a listing
A Consultant could help you best, I would contact one of them. However, all you have to do is create a transparent proxy rule. Its well documented. As far as caching of youTubed, not going to work, as that breaks HTTP standards, again well discussed here on the forums.
Keep in mind that the 1000 is not the only options. We make the PowerRouter 732 and 2200 series units as well. These we can add Fiber interfaces in, as well as we offer fiber conversion products as well. We do quite a bit with the fiber on the 2282 plus it gets you 10 GigE Copper interfaces as well....
So i figured it out.. of course.. :global elseup (((($upspeed*$emu)/100)/1024)."k"); This will use the upspeed times it by the EMU in this case 5, or 5%, divide that by 100 to get 5% of the upseed, then divide that by 1024 to covert to k, then use the ."k" to add the k at the end...
You are saying it has nothing to do with hardware/memory, and yes, i would agree that it "should" work. However, the fact is that it don't with YOUR hardware. So guess what, if you go buy other platforms, i;.e cisco, juniper, you can't put their software on your "DELL". So now yo...
Ya know, you can't make everyone happy. Some people are more than happy to find something that is supported and tested, and others are just offended for someone recommending something other than what they have. But if you will notice, I also saw that they only had a meg of bandwidth, and I recommend...
That depends on many things. YOu can argue that, but it also may have been that there was not a need to enable it. Maybe they did'ent know to enable it. lol You can contact whoever that was.
Two things, The 732 is a Made for Mikrotik Product by Link Technologies, Inc. 1. You have multi-core disabled for one, second, the image you sent shown only 6% load. I would typically not put Dude on a production router, I would put it on another box, like a 433AH with MicroSD card etc.
Keep in mind that we do have a distributor in Africa, so you don't have to ship it form the US. Second, if you are using a 1 meg connection, why have a x86 at all! a 493AH would handle 99% of what you need and its super cheap and stable, vs messing with unsupported systems. You buy Cisco cause you p...
Link Technologies, Inc. is expanding and is looking for experienced network engineers. The day to day duties would be assisting customers with routing, and Mikrotik RouterOS support. Training is offered, but you must be proficient in TCP/IP, Routing, OSI Model, wireless networking, and ports and pro...
There are many things to look at when you are working on firewalling. It depends on what type of traffic you are moving, and what type of traffic you wish to support, as well as many other factors. We have a stock firewall that we use, but we have a set of procedures to discuss with every customer t...
Just a FYI. Link Technologies, Inc, has a programmer doing custom API applications for RouterOS. http://www.linktechs.net. Just in case someone needed custom API RouterOS Applications.
THey always have some neat little box or something kewl out. Looks like one pic is of a 4 port POE Injector unit that has a backup battery in it, rack mountable. Might be useful if there were 12 ports.
the NTP client is already installed with the system package, but the server is a NTP package, you will have to download the all packages from MT and then get the NPK out of there.
The OID of 1.3.6.1.2.1.6.13.1.3 shows all of my TCP Local connections. The Count indicates how many connections their are and what ports they are to by local port. The Value is the local port that it is connected on. What I am looking for is the ability to say, port 80, how many port 80 connections ...
As far as dude creating tickets etc, not really, its not a CRM system, but it can monitor your system. You can though, have DUDE e-mail to a ticketing system, that auto creates tickets Done that! Hit up the dude consultants list!
We have already done several fiber ring and fiber to the business deployments using some of our hardware as well as Routerboard systems. We use the core 2+ gig connections with distance fiber and then drop in smaller units like the 493s right at at the businesses!
no, cause there is no routing in MME/MESH. Its all Layer2 stuffs. Hence, no Layer3 routes. Now can you send layer3 routes over a MME/MESH network, yep!
Yep, you may have blocked the ports that you thought you needed to, but unless the server is setup to be secure or for public access, then it is just waiting to be compromised. Anything from an unpatched system, to crap private code. Once had a customer wonder why their SQL database server (thats no...
Put on 4 extra IPs, one for each xbox. DST nat them in and out on a 1 to 1 basis or configure them with public IPs and route them out (if possible) . Simply put, if you have more than one xbox behind the NAT, only one can function correctly, regardless of UPNP or your dstnat rules. The only way to f...