Community discussions

Search found 890 matches

by Cha0s
Wed Sep 11, 2019 6:46 pm
Forum: General
Topic: RouterOS v7.0beta1 (ARM)
Replies: 167
Views: 28464

Re: RouterOS v7.0beta1 (ARM)

Wait, torrent wasn't a joke?
Torrent is an essential feature of every router!
DNS on the other hand... :lol: :lol:
by Cha0s
Mon Sep 09, 2019 7:44 pm
Forum: General
Topic: Request: FEC tunnel types
Replies: 27
Views: 2909

Re: Request: FEC tunnel types

At the moment there is no fully automated method in ROS to switch from a bad uplink (bad as in slight packet loss or increased latency somewhere between you and the destination - but still functional as far as ROS is concerned) to a backup/good one. You either have to resort to cumbersome scripts a...
by Cha0s
Mon Sep 09, 2019 6:17 pm
Forum: General
Topic: Request: FEC tunnel types
Replies: 27
Views: 2909

Re: Request: FEC tunnel types

I don't know (or care) about how LTE handles loss, etc, but I think we've got offtopic comparing this to LTE. LTE is just one type of Internet access and is irrelevant to the topic at hand IMHO. I can see this technology having significant benefits even if your uplinks are fiber based with 99.999% u...
by Cha0s
Tue Sep 03, 2019 5:52 pm
Forum: Beginner Basics
Topic: Best VPN for Mikrotik / RouterOS
Replies: 12
Views: 1379

Re: Best VPN for Mikrotik / RouterOS

I did Anav. One of the first hits was NordVPN, but I see it doesn't support MikroTik anymore. Hence I'm asking here. Since v6.45 MikroTik can connect to NordVPN without problems. using IKEv2. https://nordvpn.com/tutorials/mikrotik/ikev2/ https://wiki.mikrotik.com/wiki/IKEv2_EAP_between_NordVPN_and_...
by Cha0s
Tue Sep 03, 2019 2:44 pm
Forum: General
Topic: [Feature Request] interface events
Replies: 2
Views: 517

Re: [Feature Request] interface events

+1 :)
by Cha0s
Tue Sep 03, 2019 2:36 pm
Forum: RouterBOARD hardware
Topic: RB4011 Metal temperature is really hot
Replies: 46
Views: 6469

Re: RB4011 Metal temperature is really hot

Yes, ~45 degrees seems to be the norm for this device.
graph.php.png
Here's a comparison between RB3011 and and RB4011 that replaced it around a month ago.
by Cha0s
Mon Sep 02, 2019 11:03 pm
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself
Replies: 229
Views: 26896

Re: RB4011: wlan1 disabling itself

Several days passed, still no replies and not a single email about this issue. Is the RB4011 5GHz issue resolved? The problem still exists. For me it took about 29 days on a brand new RB4011, before it occurred. Since then the wifi gets disabled (stuck in "initializing") in less than a day for 3 da...
by Cha0s
Sat Aug 31, 2019 2:26 pm
Forum: RouterBOARD hardware
Topic: Why Mikrotik block google translate
Replies: 10
Views: 1412

Re: Why Mikrotik block google translate

Mikrotik doesn't block Google Translate, or any other service for that matter. All RouterOS does, is route packets from one network to another, according to however you configure the device to do so. It doesn't take it on itself to decide whether you should be able to access a webservice or not. If ...
by Cha0s
Thu Aug 22, 2019 3:22 pm
Forum: General
Topic: [Feature Request] Winbox and netinstall 64 Bit versions - URGENT
Replies: 21
Views: 3396

Re: [Feature Request] Winbox and netinstall 64 Bit versions - URGENT

Don't touch my WinBox, it's one of the best tools invented by mankind, and it's perfect as it is now. It's like trying to reform hammer, sure you can come up with something else that's not bad either, but it still won't be good replacement for the simple and reliable tool in all cases. Native WinBo...
by Cha0s
Thu Aug 22, 2019 3:09 pm
Forum: Announcements
Topic: v6.46beta [testing] is released!
Replies: 84
Views: 25950

Re: v6.46beta [testing] is released!

*) system - accept only valid string for "name" parameter in "disk" menu (CVE-2019-15055);
I guess asking for more info on that is pointless until you provide an update for stable/long-term channels, right?
by Cha0s
Mon Aug 12, 2019 3:27 pm
Forum: Beginner Basics
Topic: File download block?
Replies: 25
Views: 2273

Re: File download block?

Yes, I am aware of that, but how do the others do it, at train stations, airports ... ? a few weeks ago I set up a WLAN connection at the airport and I couldn't download any files. So there has to be a solution. I doubt they were able to block files download over an HTTPS connection. Only whole dom...
by Cha0s
Mon Aug 12, 2019 3:25 pm
Forum: Beginner Basics
Topic: File download block?
Replies: 25
Views: 2273

Re: File download block?

Strangely enough, URL Block also works for HTTPS pages. This works here, for example: ^.+(youtube.com|facebook.com).*$ Domain block (not URL block) works because the domain is visible (unencrypted) during the TLS session setup between the browser and the server. After that, you cannot see anything ...
by Cha0s
Mon Aug 12, 2019 2:57 pm
Forum: Announcements
Topic: v6.45.3 [stable] is released!
Replies: 90
Views: 24488

Re: v6.45.3 [stable] is released!

This L7 Regexp does not work anymore since update: \.(exe|dmg|cab|msi|flv|mp2|mp3|m4a|mp4|torrent)($|\?) I used this to block file download. I also don't know which MikroTik version I had before. I think it was the 6.43. You do understand that this is useless in an ever growing https world, right?
by Cha0s
Mon Aug 12, 2019 2:55 pm
Forum: General
Topic: Software Download section-Problems
Replies: 1
Views: 314

Re: Software Download section-Problems

Probably something wrong on your side. An antivirus messing up with the downloads maybe?

All links work fine on my end.
by Cha0s
Thu Aug 08, 2019 12:39 pm
Forum: RouterBOARD hardware
Topic: Is RB4011iGS+5HacQ2HnD ready?
Replies: 9
Views: 893

Re: Is RB4011iGS+5HacQ2HnD ready?

I've got a few of the non wifi RB4011 models and I have no issues. In fact I found that RB4011 was the only model that I could saturate the uplink with a single connection over IPsec, while others couldn't go much higher than 150Mbps (and that with multiple connections only). Granted, my configurati...
by Cha0s
Tue Jul 16, 2019 5:10 pm
Forum: General
Topic: TCP SYN Flood attack causing high cpu
Replies: 13
Views: 8679

Re: TCP SYN Flood attack causing high cpu

Almost two years have passed, and absolutely nothing has changed.

CCRs still cannot route (not drop) a moderate flood of SYN packets.
by Cha0s
Tue Jul 09, 2019 10:47 pm
Forum: Announcements
Topic: Winbox v3.19 released!
Replies: 30
Views: 5336

Re: Winbox v3.19 released!

cpu spikes
Huh?..
Do you want to elaborate more? :roll:
by Cha0s
Tue Jul 09, 2019 1:39 pm
Forum: Announcements
Topic: Winbox v3.19 released!
Replies: 30
Views: 5336

Re: Winbox v3.19 released!

Also, Winbox on Linux/Wine is definitely heavier/slower than on windows. Each screen refresh causes cpu spikes when having multiple windows open.
On windows there is no such cpu usage no matter how many windows I have open in winbox.
by Cha0s
Mon Jul 08, 2019 2:15 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 65791

Re: v6.45.1 [stable] is released!

Last Link Up/Down Time botched. It started happening to me (951G-2HnD, 941-2nD) on the latest stable ROS 6.45.1 / WinBox 3.19. Ethernet and ppp links. WinBox Terminal - correct: last-link-down-time=jul/08/2019 12:31:21 WinBox Interface List - wrong: Last Link Down Time: Jul/14/2019 09:44:52 Today i...
by Cha0s
Tue Jul 02, 2019 4:38 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 65791

Re: v6.45.1 [stable] is released!

Everyone who is experiencing problems with Winbox authorization - we will release a new Winbox loader with a fix for this problem as soon as possible. We are very sorry for any inconvenience caused. While you are at it, will you fix the interfaces last up/down times on winbox that are in the future?
by Cha0s
Mon Jul 01, 2019 7:00 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 65791

Re: v6.45.1 [stable] is released!

My configurations use all types of tunnels.

GRE, IPIP, EoIP. All of them, over IPsec without any problems on my end.
by Cha0s
Mon Jul 01, 2019 6:50 pm
Forum: Forwarding Protocols
Topic: BGP load-balance per-packet
Replies: 3
Views: 548

Re: BGP load-balance per-packet

You are looking for ECMP - Equal Cost Multipath. https://wiki.mikrotik.com/wiki/Manual:BGP_Load_Balancing_with_two_interfaces ECMP by default (route cache=on), will load balance per connection and not per packet. By disabling route cache (in IP > Settings) then ECMP load balances per packet on all a...
by Cha0s
Mon Jul 01, 2019 6:43 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 65791

Re: v6.45.1 [stable] is released!

2 Mikrotik Team Do you confirm some troubles with GRE interfaces + IPSec (transport) ? What we have to do in that case? Maybe there is something special with update? For example: We have to update passive sites first to 6.45.1 and after main router to 6.45.1 Or another way? Thanks! I have IPsec tun...
by Cha0s
Mon Jul 01, 2019 3:10 pm
Forum: General
Topic: Forum reliability
Replies: 18
Views: 2603

Re: Forum reliability

I agree with pe1chl. phpBB can also send mails using the native mail() function of PHP, which by default will send mails using sendmail executable to localhost. This can be blazing fast since it doesn't even care if the local MTA is loaded or not or even running at all. It writes directly to the fil...
by Cha0s
Mon Jul 01, 2019 2:55 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 65791

Re: v6.45.1 [stable] is released!

i upgrade my RB433AH after that...i couldn't access with current user and password and with admin???? . My observation is that after a reboot, the first login attempt fails ... subsequent logins are successful. This behavior has been reproducible after every reboot, of the single device I'm testing...
by Cha0s
Mon Jun 24, 2019 10:48 am
Forum: General
Topic: Feature Request: IPv6 NAT66 Support
Replies: 24
Views: 6905

Re: Feature Request: IPv6 NAT66 Support

NETMAP needed.

not nat.
You mean NPT, and both NAT66 and NPT (or netmap) are types of NAT.
by Cha0s
Sat Jun 15, 2019 2:18 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 69797

Re: v6.45beta [testing] is released!

Will it ever be possible to filter ipsec logs by peer? Debugging is pretty much impossible if you have a ton of tunnels active.
+1
by Cha0s
Fri May 31, 2019 5:47 pm
Forum: Beginner Basics
Topic: RB3011 Show LTE in Quickset
Replies: 13
Views: 893

Re: RB3011 Show LTE in Quickset

If you have many custom settings, then you should most definitely not use quickset. If you can still sensibly change settings using quick set, then ... you don't have that many settings after all. I'm sorry but reset is not a solution Then you shouldn't use Quickset. Quickset is only for initial se...
by Cha0s
Fri May 31, 2019 12:45 pm
Forum: Announcements
Topic: v6.44.3 [stable] is released!
Replies: 123
Views: 31054

Re: v6.44.3 [stable] is released!

That wrong time is a "known problem" that was introduced several versions ago, not with this version. It likely is already on the list of things to fix. Also I believe it's a winbox bug and not a ROS bug. CLI shows the correct times. IIRC deleting the session on winbox also shows the correct times ...
by Cha0s
Mon May 20, 2019 3:41 am
Forum: RouterBOARD hardware
Topic: LtAP Kit no registration - Vodafone ES SIM
Replies: 2
Views: 371

Re: LtAP Kit no registration - Vodafone ES SIM

LtAP mini Kit has two SIM slots. Is it possible you are using the wrong SIM slot?

They way those slots are it's not always clear weather you've inserted the SIM on slot 1 or slot 2 (they call it up/down in System>Routerboard>SIM menu).
by Cha0s
Mon May 20, 2019 3:35 am
Forum: General
Topic: iframe issue at MTU 1500
Replies: 1
Views: 234

Re: iframe issue at MTU 1500

What does the browser's web developer's tools console shows when it cannot load the iframe? If the iframe url can load when accessed directly, then it's almost certain that it is not a networking/MTU/MSS issue. Is it possible that the client's browser is messed up (or some other software is messing ...
by Cha0s
Mon May 20, 2019 3:24 am
Forum: General
Topic: Need help in choosing l3 switch with 10G fiber SFP+ ports
Replies: 2
Views: 280

Re: Need help in choosing l3 switch with 10G fiber SFP+ ports

MikroTik has no L3 switch that can do wirespeed routing. Can can do L3 stuff on MikroTik switches, but the performance will be way lower than 10Gbit (maybe even lower than 1Gbit) since all those functions are done on the CPU and not on the switch chips. The CCR line are not switches but routers. Tha...
by Cha0s
Mon May 20, 2019 3:00 am
Forum: General
Topic: Suggestion: At new releases
Replies: 9
Views: 1060

Re: Suggestion: At new releases

Just got an RB4011iGS+RM. It has 512MB flash, so I might have been interested, but the online documentation states that it's only available for MIPS, TILE and PowerPC. Too bad. RB4011 perfectly supports multiple partitions. I am using it on multiple RB4011s. AFAIK as long as you have >=64MB of flas...
by Cha0s
Fri May 10, 2019 10:01 am
Forum: General
Topic: Feature request: Do not block highlighting/selecting torch table contents
Replies: 5
Views: 944

Re: Feature request: Do not block highlighting/selecting torch table contents

If you double click on the source address it gets copied to the Src. Address Filter field.
Same goes for Destination address.

No the best solution, but it's better than nothing.
by Cha0s
Thu Mar 21, 2019 5:58 pm
Forum: Announcements
Topic: Statement on Vault 7 document release
Replies: 92
Views: 45041

Re: Statement on Vault 7 document release

For Unimus, connect to router periodically (user configured scheduling), and retrieve "/export compact". After that, strip all dynamic content in the output (timestamps, log messages, runtime comments, etc.). Parse the config, check if anything changed against last retrieved config. If a change is ...
by Cha0s
Thu Mar 21, 2019 5:14 pm
Forum: Announcements
Topic: Statement on Vault 7 document release
Replies: 92
Views: 45041

Re: Statement on Vault 7 document release

Does anyone know how to have "Configuration changes notifications" as mentioned in the talk? Is this something that ROS can do natively (or with scripting) or you have to do that using syslog etc? Usually a configuration management system does this for you. Unimus does this out-of-the box and you c...
by Cha0s
Tue Mar 19, 2019 6:47 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 69797

Re: v6.45beta [testing] is released!

In what scenario? If it's road warrior (typical when src is unknown or when src has dynamic IP) then policies should be already auto generated. In the scenario where an ISP doesn't provide a static IP to it's client, instead using Dynamic IP or PPPoE with a dynamic IP. In such cases, a DDNS hostnam...
by Cha0s
Tue Mar 19, 2019 6:44 pm
Forum: Announcements
Topic: Statement on Vault 7 document release
Replies: 92
Views: 45041

Re: Statement on Vault 7 document release

Does anyone know how to have "Configuration changes notifications" as mentioned in the talk?
Is this something that ROS can do natively (or with scripting) or you have to do that using syslog etc?
by Cha0s
Sat Mar 02, 2019 8:49 pm
Forum: General
Topic: Feature Request: TACACS/TACACS+
Replies: 35
Views: 8328

Re: Feature Request: TACACS/TACACS+

+1 for TACACS+ support
by Cha0s
Thu Feb 28, 2019 6:39 pm
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 219
Views: 35358

Re: v6.44 [stable] is released!

Incorrect time is cosmetic Winbox bug noticed when there are multiple Winbox instances open. If you check in terminal, time is reported correctly.
When will it be fixed? This has been reported for many releases by now.
by Cha0s
Mon Feb 18, 2019 12:05 am
Forum: General
Topic: Wrong "Last Link Down Time" in Winbox
Replies: 17
Views: 2562

Re: Wrong "Last Link Down Time" in Winbox

I confirm the problem.
by Cha0s
Wed Feb 13, 2019 3:45 pm
Forum: Forwarding Protocols
Topic: BEST BGP Scneario
Replies: 4
Views: 608

Re: BEST BGP Scneario

by Cha0s
Thu Feb 07, 2019 4:41 pm
Forum: Announcements
Topic: Suggestions requested: general hotspot controller improvements in functionality
Replies: 11
Views: 1692

Re: Suggestions requested: general hotspot controller improvements in functionality

On RB951 and similar boards, I don't expect the best performance and I don't think PHP should be supported at all on these models due to the low power CPU and resources. But for the more capable models, like RB3011, RB4011, CHR and CCR-series, it could be a nice addition. Yeah, but that ain't gonna...
by Cha0s
Wed Feb 06, 2019 4:49 pm
Forum: Announcements
Topic: v6.43.11 [stable] is released!
Replies: 79
Views: 11528

Re: v6.43.11 [stable] is released!

Legal limits are about EIRP. EIRP is not Tx power at transmitter's RF connector, it's power at antenna perimeter. And that value is affected by antenna gain. Which is not how most of WiFi users (and, sadly, WISPs) understood things ... I remember attending a Netgear "seminar" back in 2005-2006ish a...
by Cha0s
Wed Feb 06, 2019 4:38 pm
Forum: Announcements
Topic: Suggestions requested: general hotspot controller improvements in functionality
Replies: 11
Views: 1692

Re: Suggestions requested: general hotspot controller improvements in functionality

PHP Support for webpages. So, that we can make advanced webpages without visible scripts (JavaScript is visible to the user, PHP scripts are not). I know MikroTik's webserver is meant to provide the basics, but you don't always have the space and budget to place an external webserver (and no.... a ...
by Cha0s
Sat Feb 02, 2019 2:10 pm
Forum: RouterBOARD hardware
Topic: Schematics for RB112
Replies: 11
Views: 2231

Re: Schematics for RB112

In year 2019 - this RB belongs to the trash
Besides suggesting putting it in a landfill, polluting the environment for no good reason, do you have anything on-topic to suggest?
Like for example, what is the value of C78?
by Cha0s
Sat Feb 02, 2019 1:41 pm
Forum: RouterBOARD hardware
Topic: Schematics for RB112
Replies: 11
Views: 2231

Re: Schematics for RB112

Those are C67 and C68 and their value is: 560μF 6.3V 105°C

While we are at it, does anyone know the value of C78?
It's right behind the DC barrel connector and it's an SMD one.
ima_82b5a40.jpeg
by Cha0s
Sat Feb 02, 2019 1:29 pm
Forum: General
Topic: Spindown network Disk
Replies: 1
Views: 262

Re: Spindown network Disk

AFAIK there is no such option.

On the other hand, MikroTik is a router, not a NAS device. Don't use it like that.
by Cha0s
Sun Jan 20, 2019 2:53 pm
Forum: Virtualization
Topic: Mikrotik CHR speed performance problem
Replies: 26
Views: 5844

Re: Mikrotik CHR speed performance problem

That (voip) explains the high packet rate but low bandwidth I saw on your screenshots. Unless you use NAT, you don't need the SIP direct media helper (and I think it doesn't even get involved in forwarded traffic when there is no NAT). Also, connection tracking in general, with lots of connections a...
by Cha0s
Fri Jan 18, 2019 4:35 pm
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 82293

Re: v6.44beta [testing] is released!

Same with the web interface.
by Cha0s
Fri Jan 18, 2019 4:24 pm
Forum: General
Topic: [Feature Request] :resolve DNS Client Improvements
Replies: 8
Views: 1560

Re: [Feature Request] :resolve DNS Client Improvements

+1 by me as well.
by Cha0s
Fri Jan 18, 2019 1:56 pm
Forum: Virtualization
Topic: CHR, LACP, and VMware
Replies: 2
Views: 646

Re: CHR, LACP, and VMware

You cannot bond at the CHR level. Right now you are bonding two virtual NICs that connect to a Virtual Switch. Not Nexus. You should do the bonding at the ESXi level. But from there I don't know how you could get more that 10Gbps on the CHR. I've read some posts that the VMXNET3 driver doesn't reall...
by Cha0s
Thu Jan 17, 2019 12:40 pm
Forum: Announcements
Topic: SwOS version 2.9 released!
Replies: 72
Views: 24882

Re: SwOS version 2.9 released!

Upgrading from 2.8 to 2.9 on a CSS106-5G-1S causes severe traffic drop between 1G ports and 100Mbit ports. It's random from 0 to 40Mbps. Reverting back to 2.8 traffic increased back to steady 100Mbps. Are there any errors in interface stats when using v2.8 or v2.9? No errors at all on any port.
by Cha0s
Thu Jan 17, 2019 2:47 am
Forum: Announcements
Topic: SwOS version 2.9 released!
Replies: 72
Views: 24882

Re: SwOS version 2.9 released!

Upgrading from 2.8 to 2.9 on a CSS106-5G-1S causes severe traffic drop between 1G ports and 100Mbit ports. It's random from 0 to 40Mbps.
Reverting back to 2.8 traffic increased back to steady 100Mbps.
by Cha0s
Wed Jan 16, 2019 8:19 pm
Forum: Announcements
Topic: SwOS version 2.9 released!
Replies: 72
Views: 24882

Re: SwOS version 2.9 released!

Same here
by Cha0s
Thu Jan 03, 2019 2:11 pm
Forum: Beginner Basics
Topic: RB4011iGS+5HacQ2HnD-IN-US first time troubles
Replies: 14
Views: 1300

Re: RB4011iGS+5HacQ2HnD-IN-US first time troubles

I did as much reading as I could both with the sparse supplied docs and what was online before and during my efforts!! I have winbox v3.18, I fail to see a safe mode. FWIW, been doing router stuff etc. since 1989 but I am not an "IT Professional" Everything about RouterOS is documented here: https:...
by Cha0s
Thu Jan 03, 2019 11:39 am
Forum: Wireless Networking
Topic: Redirect traffic from specific device to another local ip
Replies: 7
Views: 430

Re: Redirect traffic from specific device to another local ip

Maybe something link this (to accommodate for the time requirements). /ip firewall nat add chain=dstnat src-address=192.168.1.116 time=22h-7h,sun,mon,tue,wed,thu,fri,sat action=dst-nat to-addresses=192.168.1.20 Also, this thread needs to be moved to some other category. It has nothing to do with wir...
by Cha0s
Wed Jan 02, 2019 6:00 pm
Forum: Forwarding Protocols
Topic: BGP aggregation example
Replies: 1
Views: 455

Re: BGP aggregation example

You can add all the prefixes (/22, /23, /24) in Routing > BGP > Networks. And then use separate filters on each peer to filter out which of those prefixes will be announced to each BGP peer. I suggest you first create the filters, apply them to the BGP peers and then add the more specific prefixes t...
by Cha0s
Wed Jan 02, 2019 8:33 am
Forum: RouterBOARD hardware
Topic: CCR-1036 Touchscreen frame break and noisy fan [SOLVED]
Replies: 2
Views: 521

Re: CCR-1036 Touchscreen frame break and noisy fan [SOLVED]

3. Cannot find my router in Netinstall. Ethernet cable to Ether1 slot from my laptop, no other network connection and strictly follow instruction.
Try connecting to port 12 instead of port1.
viewtopic.php?p=399474#p399474
by Cha0s
Mon Dec 31, 2018 9:25 pm
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 32955

Re: v6.43.8 [stable] is released!

Thanks! That resolved the issue!
by Cha0s
Sun Dec 30, 2018 12:23 am
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 32955

Re: v6.43.8 [stable] is released!

Just to clarify (if anyone else wants/can reproduce this), the config regarding the virtual wlan interfaces was, 1 virtual wlan interface per physical wlan (one for 2.4GHz and one for 5GHz) both added to a bridge.
by Cha0s
Sun Dec 30, 2018 12:21 am
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 32955

Re: v6.43.8 [stable] is released!

Symbol: ` in WLAN SSID brake all wlan interfaces. Or even not a symbol, but a virtual WLAN. When I create a virtual WLAN and reboot hap ac^2, I don't see all interfaces and export doesn't work in the console. DimaFIX - Please send supout.rif file from your router to support@mikrotik.com. If I add s...
by Cha0s
Thu Dec 27, 2018 12:24 pm
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 32955

Re: v6.43.8 [stable] is released!

Symbol: ` in WLAN SSID brake all wlan interfaces. Or even not a symbol, but a virtual WLAN. When I create a virtual WLAN and reboot hap ac^2, I don't see all interfaces and export doesn't work in the console. DimaFIX - Please send supout.rif file from your router to support@mikrotik.com. If I add s...
by Cha0s
Fri Dec 14, 2018 4:40 pm
Forum: Announcements
Topic: Product comparison matrix
Replies: 30
Views: 4625

Re: Product comparison matrix

The column sorting is done in the browser with Javascript, not in the database. I am just saying that sorting, the way it works now, it's pretty much useless on fields that do not contain plain numbers. If I want to sort by memory or cpu frequency the results are all over the place. Also if that's n...
by Cha0s
Fri Dec 14, 2018 3:19 pm
Forum: Announcements
Topic: Product comparison matrix
Replies: 30
Views: 4625

Re: Product comparison matrix

Very nice!

Column sorting is a bit of a mess (nothing is sorted properly, except for columns with plain numbers), but we can live with it :P
by Cha0s
Thu Dec 06, 2018 9:23 am
Forum: Beginner Basics
Topic: internal server error message and shutdown times
Replies: 1
Views: 268

Re: internal server error message and shutdown times

How long does RouterOS take to shut down typically? I cannot find any indication of the progress once shutdown has been initiated? How vital it is to always shut down a unit properly (referring to SXT-LTE)
It takes just a few seconds. You don't really need to shut it down before removing power.
by Cha0s
Mon Dec 03, 2018 12:31 pm
Forum: General
Topic: IP > Cloud stuck on 'updating'
Replies: 18
Views: 3048

Re: IP > Cloud stuck on 'updating'

The problem occurred on both updated devices with the new cloud service and old devices with the old cloud service.

It just started to work the next day. But only after it caused havoc on vpns and other stuff that were based on ddns.
by Cha0s
Fri Nov 30, 2018 1:14 am
Forum: General
Topic: IP > Cloud stuck on 'updating'
Replies: 18
Views: 3048

Re: IP > Cloud stuck on 'updating'

Yes, I just checked from other locations/ISPs too and it won't update.
by Cha0s
Fri Nov 30, 2018 12:48 am
Forum: General
Topic: IP > Cloud stuck on 'updating'
Replies: 18
Views: 3048

IP > Cloud stuck on 'updating'

After a long lasting power failure at the power company, when the router came back up it will not update its ddns via IP>Cloud. It is stuck on 'updating...' for well over two hours and does not actually ever update its ddns. Screenshot_8.png The router is an hAP ac^2 running v6.43.4 The router can r...
by Cha0s
Mon Nov 26, 2018 12:22 pm
Forum: Beginner Basics
Topic: Advertising with Mikrotik
Replies: 4
Views: 443

Re: Advertising with Mikrotik

For SSL/TLS enabled websites, you definitely cannot inject advertisements (or anything else for that matter).
Regardless of which hotspot vendor you use (thankfully it's a protocol security measure, not a vendor limitation).
by Cha0s
Mon Nov 26, 2018 12:17 pm
Forum: RouterBOARD hardware
Topic: LoRaWAN support
Replies: 42
Views: 7924

Re: LoRaWAN support

those use routeros, https://lorrier.com/ The LoRaWAN part is implemented with BeagleBones using the SPI bus. They use ROS only for the networking part, behind the BeagleBones. The gateway is based on iC880a LoRaWAN™ concentrator by IMST which uses Semtech SX1301 base band processor designed for use...
by Cha0s
Fri Nov 09, 2018 1:41 pm
Forum: General
Topic: SSTP Mikrotik Client / probably bug 6.41.3
Replies: 3
Views: 957

Re: SSTP Mikrotik Client / probably bug 6.41.3

It just happened to me on one of my SSTP VPNs with version 6.34.4.

I get the same error in the logs. 'nonce not matching'
by Cha0s
Mon Oct 22, 2018 5:27 pm
Forum: RouterBOARD hardware
Topic: Wierdly Bricked RB912UAG-2HPnD
Replies: 2
Views: 564

Re: Wierdly Bricked RB912UAG-2HPnD

Try reinstalling the OS by doing a Netinstall.
https://wiki.mikrotik.com/wiki/Manual:Netinstall
by Cha0s
Thu Oct 18, 2018 12:52 pm
Forum: Announcements
Topic: v6.43.4 [stable] is released!
Replies: 78
Views: 22175

Re: v6.43.4 [stable] is released!

*) ipsec - allow multiple peers to the same address with different local-address (introduced in v6.43);
Thanks for including this fix.
It works ok now :)
by Cha0s
Sun Oct 07, 2018 9:54 pm
Forum: General
Topic: Unable to get full gigabit speed on RB750Gr3
Replies: 28
Views: 3847

Re: Unable to get full gigabit speed on RB750Gr3

So now my problem would be whether I need a better model.
No, you don't need a better model. You need to configure FastTrack and you will able to reach 1Gbps.
by Cha0s
Sun Oct 07, 2018 3:10 pm
Forum: General
Topic: Unable to get full gigabit speed on RB750Gr3
Replies: 28
Views: 3847

Re: Unable to get full gigabit speed on RB750Gr3

Hello, Based on your setup, you may get less than gig. If you look at the gr3 specs, you'll see that with filters and bridges, throughput goes down depending on packet size. Regards Sent from Tapatalk Is there anything I can do to get the full speed on RB750Gr3? I am keeping the minimum setting as ...
by Cha0s
Sat Oct 06, 2018 7:22 pm
Forum: General
Topic: FastNetMon Integration with MikroTik (DDoS detection software)
Replies: 38
Views: 12612

Re: FastNetMon Integration with MikroTik (DDoS detection software)

Hi, Which is the best current configuration to the Mikrotik integration with FastNetMon? I'm using those: * Cache entries = 128k * Active Flow Timeout = 00:01:00 * Inactive Flow Timeout = 00:01:00 Netflow version = 9 Template refresh = 30 Template timeout = 30 FastNetMon is receiving data correctly...
by Cha0s
Sat Oct 06, 2018 1:56 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 38275

Re: v6.43.1 [stable] and v6.43.2 [stable] are released!

After upgrading to 6.43.2 from 6.42.7 you can no longer have multiple IPsec peers to the same destination IP but with different source addresses. This regression is said to be fixed in 6.44beta14. Please check the change log in the post here . And I'd expect this kind fix to be merged to 6.42.x lat...
by Cha0s
Fri Oct 05, 2018 10:53 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 38275

Re: v6.43.1 [stable] and v6.43.2 [stable] are released!

After upgrading to 6.43.2 from 6.42.7 you can no longer have multiple IPsec peers to the same destination IP but with different source addresses. Screenshot_17.png This worked fine on 6.42.7. What's the reasoning behind this restriction? I need multiple peers to the same destination but using differ...
by Cha0s
Sat Sep 29, 2018 8:59 pm
Forum: General
Topic: Feature requests
Replies: 1159
Views: 204645

Re: Feature requests

Sure, So next time you login to your web-banking do not check for TLS. Just go blindly with http. Don't even check if you typed the correct domain or weather you got hijacked and redirected to another domain. What's the point anyway? Too many parties involved! :facepalm: People, it's 2018. Not 1996....
by Cha0s
Sat Sep 29, 2018 6:09 pm
Forum: General
Topic: Feature requests
Replies: 1159
Views: 204645

Re: Feature requests

Why shame? Because there is no excuse anymore for any service to run without TLS. Certificates are free (if not dirt cheap for those that don't - for whatever reason - like Let's Encrypt). Why should any entity between the router and the update server even need to know what is being downloaded? TLS...
by Cha0s
Sat Sep 29, 2018 1:47 pm
Forum: General
Topic: Feature requests
Replies: 1159
Views: 204645

Re: Feature requests

Well, as I can see, you just create static DNS entry on the router "upgrade.mikrotik.com" with the IP of your server, then run HTTP server on that IP, serving one-line files "/routeros/LATEST.(6|6fix|6rc|7)" containing "$VERSION $TIMESTAMP" (for example, "1.0 1"). Then create "/routeros/$VERSION" d...
by Cha0s
Tue Sep 25, 2018 2:18 pm
Forum: Beginner Basics
Topic: Block HTTPS [SOLVED]
Replies: 3
Views: 582

Re: Block HTTPS [SOLVED]

There is no way to present your message saying that the page is blocked. Besides encryption, the point of https is authenticity. If you could modify what the user could see then anyone could modify any https page leading to terrible security issues. So, no. Unless you create your own CA and install ...
by Cha0s
Tue Sep 25, 2018 10:52 am
Forum: General
Topic: Feature Request: IPv6 NAT support
Replies: 4
Views: 1359

Re: Feature Request: IPv6 NAT support

And another interesting thread on the subject viewtopic.php?t=110925
by Cha0s
Tue Sep 25, 2018 10:47 am
Forum: General
Topic: Feature Request: IPv6 NAT support
Replies: 4
Views: 1359

Re: Feature Request: IPv6 NAT support

+1
I've requested this back in 2014.
viewtopic.php?f=19&t=90564
by Cha0s
Thu Sep 20, 2018 3:23 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 87466

Re: Winbox vulnerability: please upgrade

So, us, professional users of ROS, that use it every day, should have to get stupid warnings, because of dummy users that mess up their firewall and never even bother to login to their routers ever again. Who exactly will this message be for then? Please. Stop trying to convert RouterOS to a 'DummyO...
by Cha0s
Thu Sep 20, 2018 2:46 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 87466

Re: Winbox vulnerability: please upgrade

Everything outside default protection rules. It should be only warning, nothing else.
So, everyone else that does not use the default firewall will get annoying warnings about a supposedly insecure firewall configuration?
by Cha0s
Thu Sep 20, 2018 12:40 am
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 82293

Re: v6.44beta [testing] is released!

Thanks! :)
by Cha0s
Wed Sep 19, 2018 10:30 am
Forum: General
Topic: NTFS support
Replies: 34
Views: 5503

Re: NTFS support

Stop the use of the bundle package
+1

I don't see any benefit with the bundle package. It only confuses people.
by Cha0s
Wed Sep 19, 2018 10:29 am
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 82293

Re: v6.44beta [testing] is released!

I have set up automated exports and the output is saved in version control system, so I know what exactly changed and when.
Can you give more info on your setup/workflow?
I am interested in implementing something similar.

Thanks.
by Cha0s
Wed Sep 19, 2018 10:27 am
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 87466

Re: Winbox vulnerability: please upgrade

I think its unfair to call Mikrotik bone-heads in this case, as they are also saying no to the automatic upgrades. :lol: I don't think he meant Mikrotik but the likes of Microsoft and their stupid forced updates. Another example is Dropbox. It upgrades whenever it feels like it. No notification, no...
by Cha0s
Tue Sep 18, 2018 5:38 pm
Forum: General
Topic: NTFS support
Replies: 34
Views: 5503

Re: NTFS support

I vote NO NTFS, and I also vote to remove SMB, or at least make it a package that I can remove. Better yet, move all of the "home user" features into a separate package so that us enterprise customers don't have to have that type of stuff in our routers. I vote +1 for making all SOHO features a sep...
by Cha0s
Mon Sep 17, 2018 4:37 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 87466

Re: Winbox vulnerability: please upgrade

Tesla Car should go to a safe place/shop in auto mode, stop, do the critical updade, notify the client and contact tesla support to check with the client has we are talking about a 160.000€ car .... what do you think ? I think that I wouldn't want my 160.000€ car to stop whenever it feels like it s...
by Cha0s
Thu Sep 13, 2018 10:43 am
Forum: General
Topic: [Feature Request] sFlow
Replies: 11
Views: 2562

Re: [Feature Request] sFlow

Not true.

There is a software implementation that works on Linux.
https://sflow.net/about.php
by Cha0s
Wed Sep 05, 2018 10:44 pm
Forum: General
Topic: IPv6 intermittent timeouts to random IPs
Replies: 9
Views: 827

Re: IPv6 intermittent timeouts to random IPs

Also, after the netinstall, I configured everything manually, I didn't restore the configuration from a backup just to make sure that the 'problem' was not restored with it. But it didn't make any difference.
by Cha0s
Wed Sep 05, 2018 10:33 pm
Forum: General
Topic: IPv6 intermittent timeouts to random IPs
Replies: 9
Views: 827

Re: IPv6 intermittent timeouts to random IPs

I still haven't found any solution. I did a netinstall and the problem persists. As a temporary workaround I've set up a VM with MikroTik which acts as the router for IPv6. So I have a static route from the CCRs to that VM via a physical interface instead of the VLAN interfaces, and then I have the ...
by Cha0s
Fri Aug 31, 2018 12:46 pm
Forum: Scripting
Topic: How to ***really*** block invalid TCP and UDP packet
Replies: 43
Views: 35844

Re: How to ***really*** block invalid TCP and UDP packet

Well,

You are the expert. Why don't you explain it to us then?
by Cha0s
Wed Aug 29, 2018 2:23 am
Forum: RouterBOARD hardware
Topic: Combating Rogue DHCP Servers
Replies: 3
Views: 1319

Re: Combating Rogue DHCP Servers

There's also an "Alerts" section in DHCP Server which can monitor for rogue DHCP servers and alert you. https://wiki.mikrotik.com/wiki/Manual:IP/DHCP_Server#Alerts It also allows for "On Alert" scripting which could be used to disable the offending ports or apply firewall rules. There's a relevant p...
by Cha0s
Wed Aug 29, 2018 2:08 am
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 1116

Re: Suggestion: simple speed limiter

Have you tried TP-Link or D-Link?

I am sure they are much easier with all their wizards whistles and bells.

If you find RouterOS hard, then it's probably not for you.
by Cha0s
Sat Aug 25, 2018 2:11 pm
Forum: General
Topic: Forgot My Mikrotik Winbox Password and Need to Recover it without Backup Configuration File
Replies: 7
Views: 16155

Re: Forgot My Mikrotik Winbox Password and Need to Recover it without Backup Configuration File

If your RouterOS version is between 6.29 and 6.42 you might be able to get a list of all users/passwords using this exploit: https://github.com/BigNerd95/WinboxExploit
by Cha0s
Sat Aug 25, 2018 2:07 pm
Forum: General
Topic: Suggestion for improved ROS update/upgrade process
Replies: 4
Views: 857

Re: Suggestion for improved ROS update/upgrade process

This has been asked many times since the new routerboot firmware versioning but it has been ignored.
by Cha0s
Sat Aug 25, 2018 1:59 pm
Forum: Announcements
Topic: v6.42.7 [current] is released!
Replies: 159
Views: 30437

Re: v6.42.7 [current] is released!

I noticed that interface "last link up/down times" are in the future.
interface up-down wrong time.png
by Cha0s
Thu Aug 23, 2018 12:16 pm
Forum: Announcements
Topic: v6.42.7 [current] is released!
Replies: 159
Views: 30437

Re: v6.42.7 [current] is released!

Sigh.... I give up.
by Cha0s
Thu Aug 23, 2018 12:11 pm
Forum: Announcements
Topic: v6.42.7 [current] is released!
Replies: 159
Views: 30437

Re: v6.42.7 [current] is released!

August 20?

So 6.42.7 does NOT contain a fix? Because the build time is Aug/17/2018 09:48:44.
by Cha0s
Thu Aug 23, 2018 12:07 pm
Forum: Announcements
Topic: v6.42.7 [current] is released!
Replies: 159
Views: 30437

Re: v6.42.7 [current] is released!

I can confirm that the security fixes were added to the notes after the 6.42.7 thread was already posted! Why was this? https://i.imgur.com/dN9k4D4.png This is bad. I check for updates every day on this forum. The day this release was posted, I read the full changelog and there was nothing of conce...
by Cha0s
Wed Aug 15, 2018 4:47 pm
Forum: Beginner Basics
Topic: Understanding Default config: bridge
Replies: 4
Views: 2663

Re: Understanding Default config: bridge

The bridge does what it says. It bridges multiple ports/interfaces together. It's pretty much a "software switch". https://en.wikipedia.org/wiki/Bridging_(networking) In this instance it will take all interfaces (except the first one) and make them act as a switch so all of them can communicate with...
by Cha0s
Wed Aug 15, 2018 4:39 pm
Forum: Beginner Basics
Topic: Cannot block specific website
Replies: 5
Views: 513

Re: Cannot block specific website

Another way would be to create an address list, add there the domains you want to block and then create a drop filter rule using that address list as the destination. I believe this is the less resource hungry solution. No need to open any packet to check anything (TLS or otherwise), and you are act...
by Cha0s
Wed Aug 15, 2018 4:36 pm
Forum: Beginner Basics
Topic: One IP Public Multiple Webserver
Replies: 4
Views: 1125

Re: One IP Public Multiple Webserver

Hi, You just need to write Destination-nat for those servers with different port number and specify the DNS records in your ip/dns/static for those two servers then you can open it from outside with one public ip address. (You just need to know about destination nat and PAT-port address translation...
by Cha0s
Wed Aug 15, 2018 4:27 pm
Forum: Beginner Basics
Topic: Updating old versions of RouterOS [SOLVED]
Replies: 3
Views: 544

Re: Updating old versions of RouterOS [SOLVED]

In my experience, if you upgrade from (much) older versions using System > Packages > 'Check for updates' menu (ie: not manually uploading the packages to the router), it will first upgrade to an intermediate version and then you have to perform another upgrade to get to the latest version. I haven'...
by Cha0s
Wed Aug 15, 2018 4:07 pm
Forum: General
Topic: [Bug] "Interface doesn't exist " error box, but it does.
Replies: 1
Views: 247

Re: [Bug] "Interface doesn't exist " error box, but it does.

Yeap, I've seen this too.

But I think it is solved by 6.42.5. I haven't seen it for a while now.
by Cha0s
Wed Aug 15, 2018 3:55 pm
Forum: General
Topic: New IP cloud is coming.
Replies: 83
Views: 26169

Re: New IP cloud is coming.

Currently is easy to make a brute force search for mikrotik devices using the cloud service as the names follow an simple pattern and is just an DNS query. The serial number consists of 12 hexadecimal characters. I wouldn't call making 184884258895036416 (12^16) dns lookups 'easy'. It's easier to j...
by Cha0s
Tue Aug 14, 2018 5:00 pm
Forum: Announcements
Topic: Security announcement blog
Replies: 120
Views: 38259

Re: Security announcement blog

To go to a HTTPS page you most of the time need a initiate that on http. Those days are almost gone. HSTS Plus, all major browsers have their own predefined list of major websites that support https and will connect only to https even if you only type the domain in the address bar. https://hstsprel...
by Cha0s
Thu Aug 02, 2018 6:49 pm
Forum: Announcements
Topic: Security announcement blog
Replies: 120
Views: 38259

Re: Security announcement blog

Yes we have to start somewhere. How about users start to read how networks work and don't make stupid mistakes like disabling a firewall? Where to start.... You talk about doing MITM essentially to modify forwarded traffic. That's preposterous! And what about TLS? Everything moves to TLS. Doing it o...
by Cha0s
Thu Aug 02, 2018 5:38 pm
Forum: General
Topic: Remove all packages and reinstall [SOLVED]
Replies: 5
Views: 805

Re: Remove all packages and reinstall [SOLVED]

Try downgrading to an older version by manually uploading only the packages you want. After uploading you hit the 'downgrade' button on the Systems > Packages window It should downgrade and remove all other packages. After that, you can then use System > Packages > Check for updates to upgrade to th...
by Cha0s
Thu Aug 02, 2018 3:03 pm
Forum: Announcements
Topic: Security announcement blog
Replies: 120
Views: 38259

Re: Security announcement blog

RouterOS calls home each day or week to check if there is something wrong. If so every http session gets a page displayed that an update is needed because the router is below the minimal required version. If ignored then after two weeks the router only functions when you are initiating an update. A...
by Cha0s
Thu Aug 02, 2018 2:58 pm
Forum: General
Topic: IPv6 intermittent timeouts to random IPs
Replies: 9
Views: 827

Re: IPv6 intermittent timeouts to random IPs

So far I've narrowed down this to VLANs. Using IPv6 on normal interfaces works without any packet lost. Using IPv6 on VLAN interfaces (under an sfp+ interface - if it somehow makes any difference) will cause random packet loss to random IPs. It's like the neighbor solicitation/advertisement packets ...
by Cha0s
Thu Aug 02, 2018 2:22 pm
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 26775

Re: Winbox v3.16 released!

It's monstrous! You're kidding, right? I have never seen people that you say "You have shit on pants" and he said "they are new and clean." I just said about the manufacturer's oversight, and you're proving to me that everything is perfectly well thought out. Hilarious. (On salary in Mikrotik?) In ...
by Cha0s
Wed Aug 01, 2018 3:46 pm
Forum: Announcements
Topic: Security announcement blog
Replies: 120
Views: 38259

Re: Security announcement blog

I also never received an email about the winbox exploit. Mikrotik claims to have sent it, does anyone actually have a copy of it?
Same here. I only got an e-mail on March 29th about the www vulnerability. Never for the winbox vulnerability.
by Cha0s
Fri Jul 27, 2018 6:29 pm
Forum: Forwarding Protocols
Topic: BGP no active routes with low as path
Replies: 4
Views: 503

Re: BGP no active routes with low as path

By default ignore-as-path-len it's enable in instance.
ignore-as-path length is not enabled by default.
by Cha0s
Fri Jul 27, 2018 5:31 pm
Forum: Forwarding Protocols
Topic: BGP no active routes with low as path
Replies: 4
Views: 503

Re: BGP no active routes with low as path

I feel this whole post if out of context.

Post your routing filters (using proper export: /routing filters export - not just print).

And describe your problem more accurately.
What do you expect to happen, and what actually happens.
by Cha0s
Fri Jul 27, 2018 5:24 pm
Forum: Wireless Networking
Topic: Removing Mikrotik elements from beacons
Replies: 15
Views: 2288

Re: Removing Mikrotik elements from beacons

I agree. +1
by Cha0s
Wed Jul 25, 2018 8:59 pm
Forum: General
Topic: FastNetMon Integration with MikroTik (DDoS detection software)
Replies: 38
Views: 12612

Re: FastNetMon Integration with MikroTik (DDoS detection software)

[IP] [data_direction] [pps_as_string] [action]
by Cha0s
Wed Jul 25, 2018 5:07 pm
Forum: General
Topic: FastNetMon Integration with MikroTik (DDoS detection software)
Replies: 38
Views: 12612

Re: FastNetMon Integration with MikroTik (DDoS detection software)

Hi I just try to run ./notify_about_attack.sh and I get the fallowing error on "fastnetmon_mikrotik.php"; MikroTik's API Integration for FastNetMon - Ver: 1.0 missing argumentsphp fastnetmon_mikrotik.php [IP] [data_direction] [pps_as_string] [action] Any idea? You cannot run this script without the...
by Cha0s
Sat Jul 21, 2018 4:43 am
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 1709

Re: Please add numbers on Y-axis in Bandwidth Test

Adding min/max values as shown in the screenshot-mockup on post #9 is easy in principle. They already have all the points drawn in the chart along with each point's value (otherwise we couldn't click on the chart and get each point's value number), so they just need to take the lowest and the highes...
by Cha0s
Sat Jul 21, 2018 4:04 am
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 1709

Re: Please add numbers on Y-axis in Bandwidth Test

It's not a matter of which window. Every window that has a chart is the same. You essentially have minimum and maximum values for all the points in the chart (not points not currently shown in the chart). It's a matter of what you view (range) in the graph at any given moment. That's the data from w...
by Cha0s
Fri Jul 20, 2018 5:06 pm
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 1709

Re: Please add numbers on Y-axis in Bandwidth Test

Firstly, there is no real reason for "min" value as it is always zero. Of course there is a reason for min value. It's not always zero. You are not thinking this through. If for example you have constant traffic between 2 and 10 mbps, then the min value for that traffic at that time will not be zer...
by Cha0s
Thu Jul 19, 2018 7:50 pm
Forum: Forwarding Protocols
Topic: Routing filter order
Replies: 11
Views: 2535

Re: Routing filter order

When you add a new rule it is added at the bottom by default, when you do not want it there (because it has to be processed somewhere between the existing rules) you can move it, but that move will not make the software re-process the filters, as it should. Disable/enable does that. This is the sou...
by Cha0s
Thu Jul 19, 2018 6:04 pm
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 1709

Re: Please add numbers on Y-axis in Bandwidth Test

we need more than one number, we need a few numbers (at least two - at the bottom and at the top)image_bt_num.png
I agree that having the min-max values shown at all times is useful .
by Cha0s
Thu Jul 19, 2018 5:07 pm
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 26775

Re: Winbox v3.16 released!

On Win7 x64 the problems exist.
by Cha0s
Thu Jul 19, 2018 4:57 pm
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 26775

Re: Winbox v3.16 released!

Yeah, the bug is present in many places. IPv6 static routes with link-local gateways will cause 100% cpu and disconnect. Editing and EoIP tunnel and setting the MTU (when not already set) will cause 100% cpu and disconnect. Copying an SSTP Client interface will cause 100% cpu and disconnect. Copying...
by Cha0s
Tue Jul 17, 2018 5:55 pm
Forum: Beginner Basics
Topic: NetFlow Project
Replies: 2
Views: 419

Re: NetFlow Project

Any xDSL modem that can work in bridge mode, can work with MikroTik.

AFAIK USB modems are not supported.
by Cha0s
Tue Jul 17, 2018 4:32 pm
Forum: General
Topic: Feature requests
Replies: 1159
Views: 204645

Re: Feature requests

Netinstall for Linux, or documentation of the netinstall process so it can be programmed for Linux by someone else.
+1

Also it would be nice if a MikroTik installation itself can be a netinstall server for another RouterBoard.
by Cha0s
Tue Jul 17, 2018 3:39 pm
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 26775

Re: Winbox v3.16 released!

Since v3.15 when opening a static IPv6 route that has a link-local gateway causes 100% cpu usage on winbox using Win7 x64. Have the same symptom here in the CAPsMAN Channel-List. Sometimes when copying channel and editing either frequency name or other items for that channel, the dialog freezes and...
by Cha0s
Mon Jul 16, 2018 7:38 pm
Forum: General
Topic: Dual uplinks means dual public IPs
Replies: 3
Views: 337

Re: Dual uplinks means dual public IPs

Set up a MikroTik (CHR or x86) on a datacenter somewhere, then create tunnels from the location to the datacenter. 1 tunnel per uplink. Then route all the traffic via the tunnels and eventually via the gateway of the datacenter router. If uplink1 is down, then the traffic can failover via uplink2. T...
by Cha0s
Mon Jul 16, 2018 5:10 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 vs RB450Gx4
Replies: 49
Views: 10159

Re: RB850Gx2 vs RB450Gx4

Metarouter does not work on RB850Gx2.
The menu is actually there in Winbox, but it doesn't work? Never tried it since I don't need it at that site.
It doesn't work.
by Cha0s
Mon Jul 16, 2018 3:56 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 vs RB450Gx4
Replies: 49
Views: 10159

Re: RB850Gx2 vs RB450Gx4

I should have said that I'd like to use MetaROUTER, which I think is not possible on arm yet? Does it work on PPC?

You can't always have it all I suppose.
Metarouter does not work on RB850Gx2.
by Cha0s
Sun Jul 15, 2018 10:50 am
Forum: General
Topic: Weird Router RB951 [SOLVED]
Replies: 11
Views: 771

Re: Weird Router RB951 [SOLVED]

I highly doubt that none of them work. You are doing something wrong.
by Cha0s
Sun Jul 15, 2018 5:32 am
Forum: General
Topic: Weird Router RB951 [SOLVED]
Replies: 11
Views: 771

Re: Weird Router RB951 [SOLVED]

Is there any way to make a COMPLETE reset of the router to a REAL factory reset? For a complete re-install of the OS (ie: format) you need to do a netinstall. https://wiki.mikrotik.com/wiki/Manual:Netinstall For a full configuration reset (without re-installing the OS - but it will reset everything...
by Cha0s
Fri Jul 13, 2018 6:30 pm
Forum: General
Topic: IPv6 intermittent timeouts to random IPs
Replies: 9
Views: 827

Re: IPv6 intermittent timeouts to random IPs

So that could be an ND issue... Check what is happening in IPv6->Neighbors (interestingly, the menus "ND" and "Neighbors" are swapped in IPv6) ND is disabled. Neighbors doesn't show anything useful apart from status 'failed' when an IP is not reachable. At the same time, the same exact configuratio...
by Cha0s
Fri Jul 13, 2018 6:12 pm
Forum: General
Topic: IPv6 intermittent timeouts to random IPs
Replies: 9
Views: 827

Re: IPv6 intermittent timeouts to random IPs

When you say "clients cannot ping the router", do you mean clients at your local network or clients elsewhere on the internet?
I mean local clients (servers) behind the router cannot ping the router (gateway).
They can ping each other (those under the same prefix of course).
by Cha0s
Fri Jul 13, 2018 12:57 am
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 557
Views: 111553

Re: v6.43rc [release candidate] is released!

For example, DHCPv6 issue could lead to DHCPv6 service crash (can be seen only by MikroTik staff) and IPv6 services could not work or work incorrectly.
Could this, by any remote chance, be related to the issue described here?
DHCP is installed/enabled but not used at all on both ipv4/ipv6.
by Cha0s
Wed Jul 11, 2018 6:08 pm
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 26775

Re: Winbox v3.16 released!

I would welcome when the winbox-router connection is a little more patient in cases of network loss. With brief network interrups, like an intermediate router rebooting or an access point re-associating or a PPPoE connection being re-made, the open winbox windows all fall back to the connection scr...
by Cha0s
Mon Jul 09, 2018 5:55 pm
Forum: Forwarding Protocols
Topic: Routing filter order
Replies: 11
Views: 2535

Re: Routing filter order

This had me scratching my head for a while. Although you might re-order the rules, the new order is not active. However, if you 'enable' a rule in a filter chain (even if it is already 'enabled') it causes the chain to be flushed and re-applied in the correct (new) order. Maybe Mikrotik can add thi...
by Cha0s
Mon Jul 09, 2018 5:24 pm
Forum: General
Topic: IPv6 intermittent timeouts to random IPs
Replies: 9
Views: 827

IPv6 intermittent timeouts to random IPs

I have a setup in a datacenter running 2 CCR1036 in an active/standby setup. Both CCRs have identical configuration and use VRRP for the failover. This setup has been in use for over 4 years (an I suspect the problem I will describe is that old too) Everything works perfectly fine except IPv6. When ...
by Cha0s
Sun Jul 08, 2018 7:12 pm
Forum: General
Topic: DNSSEC
Replies: 33
Views: 10085

Re: DNSSEC

such as when you need to force some domain resolve into specific IP?
Ever heard of hosts file?
by Cha0s
Thu Jul 05, 2018 3:46 pm
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 26775

Re: Winbox v3.16 released!

Since v3.15 when opening a static IPv6 route that has a link-local gateway causes 100% cpu usage on winbox using Win7 x64. With a global address as gateway there is not cpu usage. In the meantime everything stops updating in Winbox (all other windows don't show new info) If I leave it open for over ...
by Cha0s
Tue Jul 03, 2018 2:46 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 22488

Re: v6.42.5 [current]

And at last.... Before 6.42.1-4, any of hEX has more than 4mb... anyway
I agree. On my devices that have 16MB flash, they have ~7.5MiB free, not 4.8MiB.
by Cha0s
Mon Jul 02, 2018 5:56 pm
Forum: Forwarding Protocols
Topic: BGP Community [SOLVED]
Replies: 2
Views: 694

Re: BGP Community [SOLVED]

/routing bgp advertisements print _PEER_NAME_ detail
You will get output like:
 peer="_PEER_NAME_" prefix=x.x.x.x/y nexthop=.z.z.z.z origin=igp communities=1234:666
Or you can use winbox.
Routing > BGP > Advertisements, and there select the column BGP Communities.
by Cha0s
Sat Jun 30, 2018 6:37 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 22488

Re: v6.42.5 [current]

I have to admit that Nv2 has been improved, but are you going to implement a madder TDMA protocol? I have co-workers that say "If you have 100Mbps on an AP and 100 clients connected, with TDMA you can give 100Mbps to them all simultaneously, slowing latency", I know that this is pure theory, but in...
by Cha0s
Sat Jun 30, 2018 6:03 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 22488

Re: v6.42.5 [current]

Did that Groove have the lost space issue?
Obviously. Why would I try it on a device that has no problem?
by Cha0s
Sat Jun 30, 2018 3:55 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 22488

Re: v6.42.5 [current]

Indeed the patch does not work! I tried it on a 2-partition CCR1009 (before reading other remarks). First copied partition containing 6.42.1, updated it to 6.42.5 which resulted in lost space issue as usual, then uploaded patch and rebooted, router came back but it has switched active partition bac...
by Cha0s
Fri Jun 29, 2018 4:52 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 22488

Re: v6.42.5 [current]

Guys, be careful with this patch!!! I uploaded it to a test CCR1016 and it doesn't come up after reboot! Test it first! I tested it on a Groove and worked. I haven't tried it on any other device. @Mikrotik: will this patch be included automatically on next ROS updates so we can avoid the extra rebo...
by Cha0s
Fri Jun 29, 2018 4:41 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 22488

Re: v6.42.5 [current]

Cha0s - Is it possible that you added EoIP tunnels from old Winbox version? I created the tunnels via CLI. Upgrading or rebooting the router loses the hostname in the remote address field and leaves an old/previously resolved IP. Never mind. It was my mistake. :oops: A combination of a forgotten cu...
by Cha0s
Fri Jun 29, 2018 4:31 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 22488

Re: v6.42.5 [current]

Thank you very much for the reports about issues with space, next RouterOS version will fix the issue. Meanwhile this package can be used to clear space on your router, https://www.mikrotik.com/download/share/fix_space.npk - upload package to your router; - run /system reboot It works on every boar...
by Cha0s
Thu Jun 28, 2018 3:51 pm
Forum: The Dude
Topic: A VPS to run Dude
Replies: 19
Views: 2181

Re: A VPS to run Dude

All major hypervisors support ova templates I was talking about providers. Hypevisors may support a million things. That doesn't mean that all features are exposed to end users by cloud providers. Cloud providers have very restrictive policies as to what you can run and how you can install new OSes...
by Cha0s
Thu Jun 28, 2018 2:38 pm
Forum: The Dude
Topic: A VPS to run Dude
Replies: 19
Views: 2181

Re: A VPS to run Dude

Anyway, if normis or whoever from mikrotik by any chance read this, why there can't be CHR ISO installer? Why is there always another format desired? I am very happy that OVA was added and I installed my Dude test VM from there. (only to play with it, I don't really use it in production) Because wh...
by Cha0s
Thu Jun 28, 2018 2:19 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 22488

Re: v6.42.5 [current]

Cha0s - Is it possible that you added EoIP tunnels from old Winbox version?
I created the tunnels via CLI. Upgrading or rebooting the router loses the hostname in the remote address field and leaves an old/previously resolved IP.
by Cha0s
Wed Jun 27, 2018 5:31 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 22488

Re: v6.42.5 [current]

Again no fix for the diskspace loss when upgrading from 6.42.1 on CCR? (and maybe others) Why are these releases rushed out when known showstopping bugs exist? I can confirm the problem. pe1chl, didn't you get the memo? Kid control fixes are WAY more important than (eventually) "bricking" our route...
by Cha0s
Wed Jun 27, 2018 5:25 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 22488

Re: v6.42.5 [current]

After rebooting, all EoIP tunnels that used dns hostname for remote address were replaced with IPs. I have to manually edit all EoIP tunnels and set the hostnames again. That happened on a couple of RB2011 and a couple of hAP AC^2. On various x86 installations the issue didn't occur. This problem di...
by Cha0s
Wed Jun 27, 2018 5:03 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 22488

Re: v6.42.5 [current]

Again no fix for the diskspace loss when upgrading from 6.42.1 on CCR? (and maybe others) Why are these releases rushed out when known showstopping bugs exist? I can confirm the problem. pe1chl, didn't you get the memo? Kid control fixes are WAY more important than (eventually) "bricking" our route...
by Cha0s
Tue Jun 26, 2018 3:58 pm
Forum: Announcements
Topic: VPNfilter official statement
Replies: 191
Views: 76270

Re: VPNfilter official statement

It's not my method, I just suggested how to make TomjNorthIdaho's rules shorter.
English suck. I didn't mean you as in singular. I meant you as in plural. You and Tom.

I am not gonna argue with you. Believe what you want about CF.
by Cha0s
Tue Jun 26, 2018 3:41 pm
Forum: The Dude
Topic: A VPS to run Dude
Replies: 19
Views: 2181

Re: A VPS to run Dude

But chr is installable from ISO
Since when?
Where is it?
Screenshot_6.png
by Cha0s
Mon Jun 25, 2018 5:55 pm
Forum: General
Topic: IPv6 problem!!!
Replies: 8
Views: 1959

Re: IPv6 problem!!!

Where's the problem exactly? That's standard behavior in IPv6.
https://en.wikipedia.org/wiki/Link-local_address

If you don't want IPv6, disable the IPv6 package and reboot your router. You cannot not have link-local addresses. That's how the protocol works.
by Cha0s
Mon Jun 25, 2018 5:24 pm
Forum: Announcements
Topic: VPNfilter official statement
Replies: 191
Views: 76270

Re: VPNfilter official statement

You still block CloudFlare and tons of other websites. Well, https cert on this host covers "ssl894059.cloudflaressl.com", "toknowall.com" and "*.toknowall.com" - doesn't look like there are tons of other websites :) Which means absolutely nothing. CF is not a static thing. It is a dynamic system t...
by Cha0s
Mon Jun 25, 2018 4:22 pm
Forum: Announcements
Topic: VPNfilter official statement
Replies: 191
Views: 76270

Re: VPNfilter official statement

/ip firewall address-list add list=toknowall.com address=toknowall.com filter add chain=forward comment="VPNfilter toknowall.com" \ dst-address-list=toknowall.com action=drop log=yes What difference does this make? You still block CloudFlare and tons of other websites. These are just bad suggestion...
by Cha0s
Thu Jun 21, 2018 3:52 pm
Forum: General
Topic: feature request: add Port List to firewall
Replies: 34
Views: 6721

Re: feature request: add Port List to firewall

is this still in the feature request queue ?
There is no "feature request queue".
We just ask for stuff here, and MikroTik usually just implements stuff that nobody asked or cares about (eg: Kids Control, Detect Internet, etc).
by Cha0s
Wed Jun 20, 2018 2:16 pm
Forum: General
Topic: Stability problem of the SSTP/OPENVPN [SOLVED]
Replies: 8
Views: 808

Re: Stability problem of the SSTP/OPENVPN [SOLVED]

I've been using SSTP, OVPN and every other vpn/tunnel that MikroTik supports for well over 10 years. I've never had any issues like the one you describe.

First upgrade to the latest version (if not already) and if the problem persists create a supout and send it to support@mikrotik.com
by Cha0s
Wed Jun 20, 2018 2:10 pm
Forum: Announcements
Topic: v6.42.4 [current]
Replies: 93
Views: 16190

Re: v6.42.4 [current]

rb952ui-5ac2nD hap lite
That refers to the remote side ROS version.
by Cha0s
Sat Jun 16, 2018 5:17 pm
Forum: RouterBOARD hardware
Topic: Is the RB OS a closed system ?
Replies: 6
Views: 831

Re: Is the RB OS a closed system ?

RouterOS is based on the Linux kernel. And that's just about it. Pretty much everything else around the kernel (shell, services, etc) are closed source and written by MikroTik. So, no you cannot run your "library" on ROS. Your only bet would be Metarouter https://wiki.mikrotik.com/wiki/Manual:Metaro...
by Cha0s
Fri Jun 15, 2018 2:20 pm
Forum: General
Topic: TFTP Upload
Replies: 1
Views: 1238

Re: TFTP Upload

There is TFTP on RouterOS https://wiki.mikrotik.com/wiki/Manual:IP/TFTP I've only used it to download files from the router, not upload. But the documentation mentions a 'read only' option, which suggests that you can upload files. read-only (default: no) sets if file can be written to, if set to "n...
by Cha0s
Fri Jun 15, 2018 1:50 pm
Forum: Forwarding Protocols
Topic: BGP Bonding
Replies: 5
Views: 814

Re: BGP Bonding

Why use bonding when you have 2 BGP peers? Keep them both connected and use Routing Filters to manage which BGP peer has priority (or whatever policy you want). If your peers both connect to the same remote AS then you can look into MED (multi exit discriminator). Also no need to check for pings... ...
by Cha0s
Mon Jun 11, 2018 5:36 pm
Forum: General
Topic: More than 254 IPs needed! What options do I have?
Replies: 16
Views: 1166

Re: More than 254 IPs needed! What options do I have?

So basically I would just need to set 192.168.1.0/23 on bridge1, a shorter lease time and restart the DHCP server? I never did this in routeros, seems simple :). You don't even need to restart the DHCP Server. Just change the lease time on IP > DHCP Server. Also you will need to update any referenc...
by Cha0s
Mon Jun 11, 2018 4:56 pm
Forum: General
Topic: More than 254 IPs needed! What options do I have?
Replies: 16
Views: 1166

Re: More than 254 IPs needed! What options do I have?

I fully agree with that. I routinely use /23 /22 and /21 subnets without any issues. Furthermore, when you extend the existing subnet the existing addresses can remain the same. I agree. I've done it numerous times without a hitch. Especially on DHCP-only networks without anything statically config...
by Cha0s
Mon Jun 11, 2018 2:54 pm
Forum: RouterBOARD hardware
Topic: Maximum Routing Throughput for RB2011UAS-2HnD
Replies: 2
Views: 2039

Re: Maximum Routing Throughput for RB2011UAS-2HnD

Just wondering, are these little things purely unable to reach that level of routing performance? Or am I missing something?
Yes, you are missing something. FastTrack.
https://wiki.mikrotik.com/wiki/Manual:IP/Fasttrack

Image
by Cha0s
Thu Mar 22, 2018 5:22 pm
Forum: RouterBOARD hardware
Topic: SFP module is extremely hot
Replies: 35
Views: 10380

Re: SFP module is extremely hot

On a datacenter environment (fixed ambient temperature at 21°C) my Mikrotik S+85DLC03D SFP+ modules run at ~40°C. The router health monitor shows a temperature of ~36°C. On an outdoor installation with an OPTIC-SFP-5324S-20-SC SFP module during winter (outside temperature between 0-15°C) it runs at ...
by Cha0s
Thu Mar 22, 2018 2:27 pm
Forum: Announcements
Topic: Winbox 3.12 released!
Replies: 55
Views: 43003

Re: Winbox 3.12 released!

I recon you have full feed. and single core problem every question you make in cli will take forever. I guess that winbox can't be faster then cli can so..... Or am I missing something? This is a winbox issue. It doesn't have to do with the amount of cores. Even with 4-5k prefixes in the advertisem...
by Cha0s
Wed Mar 21, 2018 6:24 pm
Forum: Announcements
Topic: Winbox 3.12 released!
Replies: 55
Views: 43003

Re: Winbox 3.12 released!

The 'Too Many Advertisements' bug *IS STILL IN WINBOX* after being a known issue for **literally years** now. You just need to remove this code totally. It does not work, and even the MESSAGE is buggy ... 'show them all.nPlease' ... Can you please just remove that entire bit of code? It doesn't wor...
by Cha0s
Mon Mar 19, 2018 8:28 pm
Forum: General
Topic: HELP for not LOG some value
Replies: 8
Views: 656

Re: HELP for not LOG some value

It would be best when MikroTik would assign some more specific topic to this (and some other) log message. E.g. when it would not be logged as info but as info,fetch it would be easy to block this log by adding !fetch on the info topic log, and still log other info. Maybe do a scan of all logging a...
by Cha0s
Mon Mar 19, 2018 11:35 am
Forum: General
Topic: Feature request: Show identity on login page
Replies: 7
Views: 1095

Re: Feature request: Show identity on login page

It would be nice but it wouldn't be secure (information leakage).

So I disagree. I would go as far to ask for the RouterOS version to be removed as well from the login page.
The less identifying information about RouterOS to non-logged in users, the better.
by Cha0s
Sat Mar 17, 2018 3:34 pm
Forum: General
Topic: Urgent request from Mikrotik ... Please
Replies: 24
Views: 3049

Re: Urgent request from Mikrotik ... Please

I am confused about everything the OP posted :P
I couldn't make any sense of what the request is...
by Cha0s
Sat Mar 17, 2018 1:37 pm
Forum: Beginner Basics
Topic: ROS on USB flash
Replies: 2
Views: 332

Re: ROS on USB flash

AFAIK you cannot install ROS onto USB sticks, unless something has changed over the past years (I haven't tried in a long time).

Other than that, ROS will make very few to a lot of writes, depending on your configuration.
by Cha0s
Wed Mar 14, 2018 10:52 am
Forum: General
Topic: Slingshot APT [SOLVED]
Replies: 44
Views: 24320

Re: Slingshot APT, RouterOS spying software [SOLVED]

There should be a native Linux management utility that is open source. But there is. It's called SSH. You can access and manage/configure any RouterOS installation by these five methods: -WinBox (desktop windows App) -WebFig (Web based control panel with and without SSL) - if you can't access it it...
by Cha0s
Tue Mar 13, 2018 3:42 am
Forum: General
Topic: Slingshot APT [SOLVED]
Replies: 44
Views: 24320

Re: Slingshot APT, RouterOS spying software NOT [SOLVED]

Whenever I have read the changelogs for the updated OS I have not seen anything that would affect me or would benefit me. Ever heard of "if it ain't broke, don't fix it!"? Well I am sorry to break it to you but... that sounds like your problem. The changelog DID mention a VULNERABILITY. So it WAS b...
by Cha0s
Mon Mar 12, 2018 11:52 pm
Forum: General
Topic: Slingshot APT [SOLVED]
Replies: 44
Views: 24320

Re: Slingshot APT, RouterOS spying software [SOLVED]

Even worse, it sounds like the issue was fixed over a year ago, but nothing was mentioned about it in any newsletter or email I received from you. This WAS mentioned when it was fixed a year ago. Release 6.38.5 2017-03-09 What's new in 6.38.5 (2017-Mar-09 11:32): !) www - fixed http server vulnerab...
by Cha0s
Tue Mar 06, 2018 2:41 pm
Forum: General
Topic: Connection tracking and changing routes
Replies: 3
Views: 576

Re: Connection tracking and changing routes

Since the rules you describe seem to not need Connection Tracking, then you should probably try first disabling the accept established/related rule and if that doesn't change anything. then move to raw table as you mentioned. I run a similar network to what you describe, with BGP and BFD for rapid c...
by Cha0s
Tue Mar 06, 2018 2:19 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 609
Views: 152045

Re: RouterOS v7.0 beta1 - when?

Looking away from RouterOS v6.x running IPv6 BGP [tables]? Not being able to verify IPv6 routing table (when not main table!) is really a big deal. (But seeing the routes exists by the number the route counter shows. :sigh:) And doing policy routing rules for anything else than main table in IPv6. ...
by Cha0s
Tue Mar 06, 2018 1:45 pm
Forum: Scripting
Topic: How to ***really*** block invalid TCP and UDP packet
Replies: 43
Views: 35844

Re: How to ***really*** block invalid TCP and UDP packet

I am not sure blocking traffic with port 0 is wise. As far as I know, when the payload of a message is too large to fit in a TCP/UDP packet (see MTU), then it gets split into multiple packets (ie: fragmented packets). The first packet contains the TCP/UDP headers with the source/dest ports but the n...
by Cha0s
Tue Mar 06, 2018 12:58 pm
Forum: Forwarding Protocols
Topic: VRRP suggestion for not showing VRRP information on clients
Replies: 2
Views: 488

Re: VRRP suggestion for not showing VRRP information on clients

I have a similar setup but since VRRP (with VLANs under it) introduced a huge overhead causing high packet drops and lag on high throughput (mainly during DDoS attacks - even if they were much smaller than what the uplink could handle) I reconfigured VRRP so that it's not in the data path but rather...
by Cha0s
Mon Mar 05, 2018 9:07 pm
Forum: Forwarding Protocols
Topic: Strange readings in traffic monitor
Replies: 4
Views: 590

Re: Strange readings in traffic monitor

I have a similar issue but not exactly the same. At random times (I haven't been able to pin down what exactly is causing it) Winbox will show the exact opposite. Instead of the huge-unrealistic values you get, in my case, every 2-3 seconds all interfaces in interface list shows 0bpps/pps. It's not ...
by Cha0s
Fri Mar 02, 2018 5:38 pm
Forum: General
Topic: New router OS
Replies: 46
Views: 12049

Re: New router OS

+1 patric7 & pe1chl After 3+ years of waiting for the new routing engine, I am very skeptical of using CCRs and RouterOS for any other big project that comes to my way... As perfect as RouterOS in terms of usability (which tbh is the only reason I keep sticking to ROS), it's really limiting when use...
by Cha0s
Fri Mar 02, 2018 4:48 pm
Forum: RouterBOARD hardware
Topic: RB1100AHx4 latency spikes
Replies: 18
Views: 1644

Re: RB1100AHx4 latency spikes

How does your monitor system (I can't tell which is it from the screenshot - never seen it before) connect to the router and subsequently reach the uplinks? Is there a switch in between? Do you monitor any other local devices (and the router itself)? Do you see the same latency spikes on local devic...
by Cha0s
Thu Mar 01, 2018 3:24 pm
Forum: Announcements
Topic: Newsletter 79 (MUM EUROPE ANNOUNCED!)
Replies: 33
Views: 12184

Re: Newsletter 79 (MUM EUROPE ANNOUNCED!)

When is RBM33G to be released? My supplier was told that it would arrive in early January, then February and now we are on March and still nothing. This is all de javu of RB3011... I guess I'll have to stop reading any Mikrotik newsletter since they announce stuff that either get super delayed or ne...
by Cha0s
Wed Feb 21, 2018 7:38 pm
Forum: Forwarding Protocols
Topic: RFC 6666
Replies: 3
Views: 602

Re: RFC 6666

Is that due to current RouterOS limitation or Mikrotik not embracing blackhole routing for IPv6?
It's a little bit of both IMHO.
IPv6 in MikroTik is generally very barebones compared to the features they have implemented for IPv4.
by Cha0s
Wed Feb 21, 2018 5:55 pm
Forum: RouterBOARD hardware
Topic: CRS317-1G-16S+RM as a switch to connect storage?
Replies: 2
Views: 1058

Re: CRS317-1G-16S+RM as a switch to connect storage?

A switch is one of those parts that can never go down when used to switch storage traffic. Otherwise you are in for a long day (well... it depends on what you are using the storage for... I assume VMs since this is mostly the case these days). I wouldn't be very confident in using MikroTik switches ...
by Cha0s
Sun Feb 18, 2018 6:35 pm
Forum: General
Topic: Winbox OUI identify
Replies: 30
Views: 3689

Re: Winbox OUI identify

That file is almost 4 Megabytes. Many RouterOS devices have 16MB total storage size. Funny you should say that, we keep telling you that 16MB is not much. :) I was just about to say the exact same thing. 16MB flash is simply a joke in year 2018. It's one of those satisfying moments of ' I told you ...
by Cha0s
Mon Jan 29, 2018 9:24 pm
Forum: Announcements
Topic: Tik App, MikroTik android utility ALPHA test
Replies: 424
Views: 142268

Re: Tik App, MikroTik android utility ALPHA test

If this app is not open source how can one be sure that data and access to routers are not logged, shared, or misused? What is the guarrantee here to expose oneself to a third private party? This is a serious concern. Sniff all the data that come in and out of your android device and see if it trie...
by Cha0s
Wed Jan 24, 2018 5:38 pm
Forum: RouterBOARD hardware
Topic: PCI Express M.2 and Sierra Wireless EM7565 LTE Module
Replies: 2
Views: 1515

Re: PCI Express M.2 and Sierra Wireless EM7565 LTE Module

According to Normis the miniPCIe slots can be used for wireless adapters as well.

viewtopic.php?p=632854#p632854
by Cha0s
Tue Jan 23, 2018 8:46 pm
Forum: General
Topic: RouterBOOT "auto-upgrade"!
Replies: 18
Views: 10916

Re: RouterBOOT "auto-upgrade"!

I don't mind to wait for 2 reboot instead of one, if it'll go automatically. If the second reboot happens automatically before any network connectivity is up, then I don't mind that either. ROS boots rather fast (compared to the likes of Cisco for example). But making the whole network come down an...
by Cha0s
Tue Jan 23, 2018 8:19 pm
Forum: General
Topic: RouterBOOT "auto-upgrade"!
Replies: 18
Views: 10916

Re: RouterBOOT "auto-upgrade"!

Why not make it actually useful so that it will upgrade the firmware along with ROS at the same time with one reboot instead of two?

Having an option like this and still require to have to do another reboot is pretty much useless IMHO.
by Cha0s
Tue Jan 23, 2018 8:18 pm
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 538
Views: 95953

Re: v6.42rc [release candidate] is released!

*) routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required) (CLI only);
What's the point if we have to do an extra reboot?
The whole point of a feature like this would be to update both ROS and RouterBOOT with one reboot.
by Cha0s
Mon Jan 15, 2018 4:50 pm
Forum: General
Topic: FastNetMon Integration with MikroTik (DDoS detection software)
Replies: 38
Views: 12612

Re: FastNetMon Integration with MikroTik (DDoS detection software)

My experience with FNM and ROS is that it will give false positives on long lived TCP connections. When the long lived TCP connection (eg: large http download) completes, then the flow is exported to FNM and it suddenly sees a huge spike which falsely classifies it as an attack. AFAIK this is a ROS ...
by Cha0s
Sat Jan 13, 2018 5:21 pm
Forum: Announcements
Topic: Securing your device is important
Replies: 31
Views: 10186

Re: Securing your device is important

One step to improve RouterOS' security is to finally make IP > Services bind on specific IPs/Interfaces. That way even if someone does not set up their firewall properly, those management services can be configured to not be available on the WAN. It's much simpler for a novice user to set those serv...
by Cha0s
Fri Dec 29, 2017 10:16 pm
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 55
Views: 11984

Re: RB3011 port flopping - bad design

Does anyone know any other devices (routerboards or not) using this specific switch chip? I wonder if we can independently reproduce Mikrotik's claims. I have listed other RouterBOARDs where the same switch chip is used several posts above. They seem to be: hAP ac, OmniTIK 5 ac (including OmniTIK 5...
by Cha0s
Fri Dec 29, 2017 6:20 pm
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 55
Views: 11984

Re: RB3011 port flopping - bad design

I don't know any other switch with L1 disable and enable during buffer overload. I think, there is something bad in ROS a RB3011. Me neither. This is either a bad software design on Mikrotik's part, or bad device design by Mikrotik for using such a switch chip (if indeed the issue is there - any qu...
by Cha0s
Thu Dec 28, 2017 2:37 pm
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 538
Views: 95953

Re: v6.42rc [release candidate] is released!

Cha0s - Before the fix Traffic Flow, for example, instead of reporting 5 packets per flow reported 6 packets. Simply reported one packet more than flow has actually processed; irghost - Can you provide an example of rule which you have tried out and seen that it is not working? /ip firewall filter ...
by Cha0s
Wed Dec 27, 2017 5:31 pm
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 538
Views: 95953

Re: v6.42rc [release candidate] is released!

*) traffic-flow - do not count single extra packet per each flow;
Can you give more details about this?
by Cha0s
Tue Dec 26, 2017 9:16 am
Forum: Announcements
Topic: v6.41 [current]
Replies: 304
Views: 76688

Re: v6.41 [current]

These look like replies your router sends to incoming packets to unreachable hosts. The router generates those ICMP packets to inform the sender that the host is unreachable. https://tools.ietf.org/html/rfc792 ICMP Fields: Type 3 Code 0 = net unreachable; 1 = host unreachable; 2 = protocol unreachab...
by Cha0s
Mon Dec 25, 2017 8:39 pm
Forum: Announcements
Topic: v6.41 [current]
Replies: 304
Views: 76688

Re: v6.41 [current]

Upgraded multiple boards without almost any issues. RB3011 RB850Gx2 hAP-Lite mAP-Lite SEXTANTG RB433AH x86 The only issue I had was some IPsec tunnels (manually configured using keys) would keep establish and then disconnect repeatedly. I couldn't figure out what was causing it. It was happening onl...
by Cha0s
Mon Dec 25, 2017 1:48 am
Forum: Announcements
Topic: v6.41 [current]
Replies: 304
Views: 76688

Re: v6.41 [current]

IP Neighbor Please revert or Alter the NEW functionality of Neighbor discovery. I use specific Bridges/Interfaces ( A management VLAN segment) that see's all devices, but I also have Client Side Bridges/Vlans/Interfaces. I DO NOT want Clients to SEE Discovery Broadcasts. Thus I ask you to Revert to...
by Cha0s
Tue Dec 19, 2017 2:08 pm
Forum: Announcements
Topic: Newsletter 79 (MUM EUROPE ANNOUNCED!)
Replies: 33
Views: 12184

Re: Newsletter 79 (MUM EUROPE ANNOUNCED!)

Thanks for the clarification Normis :)
by Cha0s
Mon Dec 18, 2017 5:39 pm
Forum: Announcements
Topic: Newsletter 79 (MUM EUROPE ANNOUNCED!)
Replies: 33
Views: 12184

Re: Newsletter 79 (MUM EUROPE ANNOUNCED!)

Regarding RBM33G, is it possible to use 2 wireless cards on the 2 miniPCIe slots if someone does not need any 3G/LTE?

It's not clear from the PDF and product page.
by Cha0s
Mon Dec 18, 2017 4:38 pm
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 55
Views: 11984

Re: RB3011 port flopping - bad design

I confirm the issue. I've never experienced the port flappings everyone mentions since RB3011's release.
I now know why. I didn't mix Fast ethernet and Gigabit devices on the same switch group.

I just tried it and indeed after I maxed out a fast ethernet all ports flapped.
by Cha0s
Thu Dec 14, 2017 1:04 pm
Forum: RouterBOARD hardware
Topic: Mikrotik VDSL / DSL Modem?
Replies: 313
Views: 85288

Re: Mikrotik VDSL / DSL Modem?

Thanks for testing this :)
by Cha0s
Mon Dec 11, 2017 4:00 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 609
Views: 152045

Re: RouterOS v7.0 beta1 - when?

Could we expect hardware acceleration AES for RB3011UiAS-RM?
Not before v7. Even after v7 I am not so sure they will add HW AES support. The CPU does support it, but MikroTik don't seem to want to invest in RB3011.
They never released any other model as they did with the various models of RB2011...
by Cha0s
Sat Dec 09, 2017 1:05 am
Forum: General
Topic: BFD over link aggregations
Replies: 1
Views: 449

Re: BFD over link aggregations

+1 :)
by Cha0s
Thu Dec 07, 2017 3:36 pm
Forum: General
Topic: Echo Protocol test
Replies: 1
Views: 245

Re: Echo Protocol test

I may be wrong but I don't thing MikroTik supports this protocol.
by Cha0s
Wed Dec 06, 2017 4:21 pm
Forum: Announcements
Topic: v6.41rc [release candidate] is released! New bridge implementation!
Replies: 561
Views: 122441

Re: v6.41rc [release candidate] is released! New bridge implementation!

or at least make the ROS upgrade process to automatically upgrade Routerboot also.
+1
by Cha0s
Wed Dec 06, 2017 3:44 pm
Forum: Announcements
Topic: v6.41rc [release candidate] is released! New bridge implementation!
Replies: 561
Views: 122441

Re: v6.41rc [release candidate] is released! New bridge implementation!

I agree with upower3. A roadmap for software and hardware development would be most welcome.

Knowing where MikroTik is heading is essential when investing in their hardware (and subsequently in their software).
by Cha0s
Tue Dec 05, 2017 4:20 pm
Forum: RouterBOARD hardware
Topic: RB2011UiAS-RM bricked after power loss
Replies: 4
Views: 779

Re: RB2011UiAS-RM bricked after power loss

I suggest you configure a scheduled backup to be sent on an email address so that even if you have similar problems in the future you won't have to re-configure the whole router from scratch.

https://wiki.mikrotik.com/wiki/Send_Backup_email
by Cha0s
Mon Dec 04, 2017 5:43 pm
Forum: General
Topic: Forum troubles
Replies: 39
Views: 2651

Re: Forum troubles

It may not be you as a poster, but that you can Subscribe on threads. So Mikrotik need to turn Subscribe of globally so no email goes out when you reply to a topic. This is not a solution. I do want to receive mail notifications when someone replies on threads I subscribe to. I use many phpBB forum...
by Cha0s
Mon Dec 04, 2017 3:08 pm
Forum: General
Topic: Feature request: Add "Port ID" to serial terminal sessions.
Replies: 1
Views: 410

Re: Feature request: Add "Port ID" to serial terminal sessions.

Sounds useful +1

Btw I am doing the same thing. Really cool indeed :)
by Cha0s
Sun Dec 03, 2017 2:04 am
Forum: General
Topic: Forum troubles
Replies: 39
Views: 2651

Re: Forum troubles

Another major disadvantage I just noticed with this theme is that quotes do not show the usernames. So quotes are essentially useless right now. You can't figure out in a glance who said what and you have to scroll back to find out. Terrible!
by Cha0s
Sun Dec 03, 2017 2:01 am
Forum: General
Topic: Forum troubles
Replies: 39
Views: 2651

Re: Forum troubles

Another issue I noticed is that some (or all? I don't know) user uploaded images and files are missing. Those are visible when are logged in and we are already pleased that active topics are selectable if you not logged in. Being logged in doesn't change anything. The files I am talking about retur...
by Cha0s
Sat Dec 02, 2017 4:05 pm
Forum: RouterBOARD hardware
Topic: Less than 2000 Mbps on 10GB link
Replies: 15
Views: 3528

Re: Less than 2000 Mbps on 10GB link

You don't need to change the MTU to 9000 or anything. Keep the default at 1500. Changing the MTU because you read it in some forum will most likely cause many more problems than it will solve. Higher than 1500 MTU is for edge cases. For most traffic types 9000 MTU won't give any considerable advanta...
by Cha0s
Sat Dec 02, 2017 3:48 pm
Forum: General
Topic: Forum style for Mikrotik phpBB forum problem.
Replies: 7
Views: 689

Re: Forum style for Mikrotik phpBB forum problem.

Yes. Bring back prosilver.
by Cha0s
Sat Dec 02, 2017 3:39 pm
Forum: General
Topic: Forum troubles
Replies: 39
Views: 2651

Re: Forum troubles

Another issue I noticed is that some (or all? I don't know) user uploaded images and files are missing.
by Cha0s
Sat Dec 02, 2017 3:26 pm
Forum: General
Topic: Forum troubles
Replies: 39
Views: 2651

Re: Forum troubles

Getting a lot of errors. General Error SQL ERROR [ mysqli ] Connection refused [2002] An sql error occurred while fetching this page. Please contact an administrator if this problem persists. This, or error 2006 mysql server has gone. 504 Gateway Time-out nginx WHOA, SERVICE UNAVAILABLE! Hey, speedy...
by Cha0s
Fri Dec 01, 2017 6:21 pm
Forum: Announcements
Topic: Winbox 3.11 released!
Replies: 94
Views: 283718

Re: Winbox 3.11 released!

The title bar of the winbox window already contains the username@IP, hostname(identity), RB model and architecture and finally the ROS version.
by Cha0s
Wed Nov 29, 2017 12:34 pm
Forum: Beginner Basics
Topic: Pro's & Cons GRE-IPIP-EoIP
Replies: 5
Views: 1897

Re: Pro's & Cons GRE-IPIP-EoIP

The security is the same. Non-existent.

If you need security you need to use IPsec bellow whichever tunnel you choose.
by Cha0s
Tue Nov 28, 2017 12:26 pm
Forum: Announcements
Topic: Winbox 3.11 released!
Replies: 94
Views: 283718

Re: Winbox 3.11 released!

freemannnn wrote:
can you make right click "copy" able in tools ip scan. i want to copy mac addresses and i have to do it by hand one by one.

+1
by Cha0s
Mon Nov 27, 2017 5:40 pm
Forum: Forwarding Protocols
Topic: Can i Use Perfix-list in bgp filters [SOLVED]
Replies: 4
Views: 539

Re: Can i Use Perfix-list in bgp filters [SOLVED]

You can create a routing filter chain that will contain all the prefixes you want to allow.

And then from each peer's filter you jump to that chain.

Pretty much the same principle as with firewall chains and jumps.
by Cha0s
Mon Nov 27, 2017 1:36 pm
Forum: General
Topic: Windowed tabs suggestion for Winbox 3.1X
Replies: 3
Views: 290

Re: Windowed tabs suggestion for Winbox 3.1X

Can you post a screenshot/mockup of what you propose? I am not sure I understand what you mean when you say 'tabs'. My first instinct is something like browser tabs, but what I read does not seem to be that type of tabs. In other words I am confused :P Maybe others too, that's why you haven't gotten...
by Cha0s
Mon Nov 27, 2017 1:21 pm
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6598

Re: NAT table not cleared correctly [SOLVED]

What happens if you disable connection tracking and then re-enable it? /ip firewall connection tracking set enabled=no /ip firewall connection tracking set enabled=yes From what you wrote I understand that you manually (or with scripting) clear the connections in connection tracking but not disablin...
by Cha0s
Mon Nov 27, 2017 12:20 pm
Forum: Wireless Networking
Topic: Nv2 limitations??
Replies: 23
Views: 2044

Re: Nv2 limitations??

In which version did this start (if anyone knows). Would love to downgrade to a version where this isn't an issue. This has always been that way. At least since v2.9.x. There's a perfectly good explanation in the manual why it works that way . https://wiki.mikrotik.com/wiki/Manual:Wireless_FAQ#What...
by Cha0s
Sun Nov 26, 2017 12:23 pm
Forum: RouterBOARD hardware
Topic: RBM33G IPsec?
Replies: 2
Views: 868

Re: RBM33G IPsec?

It does support HW IPSEC. That's awesome! I wonder why they don't mention it anywhere. Also, looking into the MT7621A datasheet it mentions another cool feature (though I don't know if ROS makes use of it). https://www.mediatek.com/products/homeNetworking/mt7621n-a Network Accelerator: 2Gbps IPv4/6...
by Cha0s
Sat Nov 25, 2017 1:54 pm
Forum: General
Topic: Mikrotik Forum has gotten quite slow
Replies: 15
Views: 1664

Re: Mikrotik Forum has gotten quite slow

Another observation that backs up my theory about bad mail configuration (or something related to that) on the forum. Posting a new thread (which obviously no one is subscribed to) takes 2-3seconds. Posting a reply to a thread with other replies (and quite possibly people subscribed to) takes 10-20s...
by Cha0s
Sat Nov 25, 2017 1:50 pm
Forum: RouterBOARD hardware
Topic: RBM33G IPsec?
Replies: 2
Views: 868

RBM33G IPsec?

I noticed RBM33G uses the same CPU as RB750Gr3 which supports IPsec Hardware Encryption. Does RBM33G also support IPsec Hardware Encryption? There's no mention here https://mikrotik.com/product/rbm33g or in the PDF brochure. Also anyone knows what are all those pins and jumpers on the RBM33G PCB for?
by Cha0s
Fri Nov 24, 2017 4:27 pm
Forum: Announcements
Topic: v6.41rc [release candidate] is released! New bridge implementation!
Replies: 561
Views: 122441

Re: v6.41rc [release candidate] is released! New bridge implementation!

*) firewall - added "tls-host" firewall matcher (CLI only); Sweet. No more Layer 7 for HTTPS blocking :) How it works? Which packet matches? Does it support wildcards? I presume this is just a special case of a Layer 7 with some pre-defined pattern, and only works when SNI is used. It could be an i...
by Cha0s
Fri Nov 24, 2017 3:24 pm
Forum: General
Topic: Support for ACME/Let's Encrypt certificate management [SOLVED]
Replies: 93
Views: 35193

Re: Support for ACME/Let's Encrypt certificate management [SOLVED]

Unfortunately metarouter is pretty much a forgotten feature by MikroTIk. Currently MetaRouter can be used on RB400, RB700 series except models with SPI flash, RB900 series except models with SPI flash, RB2011 boards Listed PPC boards: RB1000, RB1100, RB1100AH and RB800. In other words, CCR, RB3011, ...
by Cha0s
Wed Nov 22, 2017 9:59 am
Forum: Announcements
Topic: v6.40.5 [current]
Replies: 82
Views: 24947

Re: v6.40.5 [current]

increase in cpu usage to 16% from 1% on RB3011UiAS
I've also noticed a slight cpu (not as much as yours) increase on CCR1036 after upgrading to 6.40.5 from 6.38.x.
by Cha0s
Mon Nov 20, 2017 7:21 pm
Forum: Beginner Basics
Topic: HTTPS traffic redirect problem
Replies: 8
Views: 1634

Re: HTTPS traffic redirect problem

Right... except the fact that OP asked for redirect not blocking or logging...
by Cha0s
Mon Nov 20, 2017 5:09 pm
Forum: Beginner Basics
Topic: HTTPS traffic redirect problem
Replies: 8
Views: 1634

Re: HTTPS traffic redirect problem

Both methods require to install custom root CA cert on the clients. There's is no way to not get browser warnings unless the client installs your certificate. Which is not a very good practice anyway both from security and management point of view. So not viable for most out there. Not to mention it...
by Cha0s
Mon Nov 20, 2017 4:54 pm
Forum: Forwarding Protocols
Topic: Show Aspath For prefix
Replies: 1
Views: 270

Re: Show Aspath For prefix

/ip route print detail where dst-address=PREFIX Eg: > /ip route print detail where dst-address=10.19.143.0/24 Flags: X - disabled, A - active, D - dynamic, C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme, B - blackhole, U - unreachable, P - prohibit 0 ADb dst-address=10.19.143.0/24 gat...
by Cha0s
Sat Nov 18, 2017 2:13 pm
Forum: General
Topic: Mikrotik Switches Vs Cisco Switches
Replies: 20
Views: 4549

Re: Mikrotik Switches Vs Cisco Switches

The CPU on both Cisco and Mikrotik switches is used for management purposes (snmp stats, cli management, etc) and does not affect the data path. Switching is not done in CPU. Neither on Cisco/Dell nor on Mikrotik. Switching is done on dedicated ASIC chips specifically designed for this job (thus giv...
by Cha0s
Wed Nov 15, 2017 7:21 pm
Forum: Forwarding Protocols
Topic: IPv4 and IPv6 on a single BGP peer
Replies: 3
Views: 958

Re: IPv4 and IPv6 on a single BGP peer

I would be very cautious mixing IPv4 and IPv6 peers together into one session. Zerobyte has mentioned some caveats. https://forum.mikrotik.com/viewtopic.php?p=609944#p609944 I agree with savage, though - create a peering session for IPv6 using the ISP's IPv6 address and do IPv4 peering over IPv4, an...
by Cha0s
Tue Nov 14, 2017 11:28 am
Forum: RouterBOARD hardware
Topic: RBGPOE and short circuit
Replies: 2
Views: 549

Re: RBGPOE and short circuit

I think that it's the PSU's job to handle a short circuit.

Most switching PSU's nowadays have all sorts of protections, so I wouldn't worry that much. Especially about a cable fire :P
by Cha0s
Mon Nov 13, 2017 8:41 pm
Forum: General
Topic: x86 mainboard for MikroTik server
Replies: 4
Views: 571

Re: x86 mainboard for MikroTik server

I do, but only as VM on top of ESXi. I haven't installed RouterOS on baremetal for ages. I don't know what's supported and what not nowadays. Maybe you should send a ticket at support@mikrotik.com to let you know about the latest supported hardware since they completely deleted the supported hardwar...