Community discussions

MikroTik App

Search found 972 matches

by Cha0s
Tue May 26, 2020 3:04 pm
Forum: Announcements
Topic: v6.47rc [testing] is released!
Replies: 23
Views: 3038

Re: v6.47rc [testing] is released!

Frankly since 802.11n, but I am curious what exactly they fixed.
by Cha0s
Tue May 26, 2020 1:33 pm
Forum: Beginner Basics
Topic: Recover admin password [SOLVED]
Replies: 2
Views: 308

Re: Recover admin password [SOLVED]

Open Addresses.CDB with notepad and you will probably be able to find the password in there.
by Cha0s
Tue May 26, 2020 1:30 pm
Forum: General
Topic: My MikroTik is Hacked!!! Found file 7wmp0b4s.rsc [SOLVED]
Replies: 9
Views: 1504

Re: My MikroTik is Hacked!!! Found file 7wmp0b4s.rsc [SOLVED]

[joking]
I am using Windows 95, they have been working great for the last 25 years without any updates!
I've also been using no firewall, since firewalls are for newbs.

But, today I logged in only to find out that they were hacked!

How could this have happened???
[/joking]
by Cha0s
Tue May 26, 2020 1:15 pm
Forum: Announcements
Topic: v6.47rc [testing] is released!
Replies: 23
Views: 3038

Re: v6.47rc [testing] is released!

*) wireless - fixed Nstreme wireless protocol performance decrease;
Can you give more information about this?
by Cha0s
Sun May 24, 2020 2:06 pm
Forum: Beginner Basics
Topic: How to downgrade RouterOS from v6.46.6 to v6.45.1 ? [SOLVED]
Replies: 12
Views: 1443

Re: How to downgrade RouterOS from v6.46.6 to v6.45.1 ? [SOLVED]

@mkx, you seem not to understand the problem.
As I wrote ... waste of my time.
Yeap! Added to foes... can't stand 100 posts per day blaming incompetence as bugs.
by Cha0s
Sat May 23, 2020 8:31 pm
Forum: Beginner Basics
Topic: The extra packages in RouterOS [SOLVED]
Replies: 21
Views: 2011

Re: The extra packages in RouterOS [SOLVED]

You mean constructive, like telling you exactly how to downgrade and you ignoring it?
by Cha0s
Sat May 23, 2020 7:44 pm
Forum: Beginner Basics
Topic: The extra packages in RouterOS [SOLVED]
Replies: 21
Views: 2011

Re: The extra packages in RouterOS [SOLVED]

Like I said: even the standard downgrade function does not work, as the version is the same as before, after the reboot. Then you are doing something wrong. Read the fine manual again and retry until you succeed. Only with exercise you will learn how to properly use ROS. [admin2@CRS125] /ip service...
by Cha0s
Sat May 23, 2020 5:54 pm
Forum: Wireless Networking
Topic: Wireless sniffing - Is this possible
Replies: 1
Views: 270

Re: Wireless sniffing - Is this possible

I believe that Wireless Sniffer uses the same protocol as Packet Sniffer to stream the data to a server. TZSP
by Cha0s
Sat May 23, 2020 5:48 pm
Forum: Beginner Basics
Topic: interface rate-limit on bridge with VLAN
Replies: 2
Views: 434

Re: interface rate-limit on bridge with VLAN

Go to the Switch window and then on the Port tab.

There you can set the Ingress and Egress rate of each interface.
by Cha0s
Sat May 23, 2020 5:44 pm
Forum: Beginner Basics
Topic: DSL Behind Modem
Replies: 1
Views: 251

Re: DSL Behind Modem

You need to either set a different subnet for the modem (or LAN) or bridge ether1 and ether2 so they are both in the same broadcast domain. Right now you've got 10.0.0.0/24 for both the modem (ether1) and your lan (ether2) Also, you probably will need to set up a SNAT rule to be able to access the m...
by Cha0s
Sat May 23, 2020 5:40 pm
Forum: Beginner Basics
Topic: CHR licensing
Replies: 1
Views: 327

Re: CHR licensing

It used to be different (I don't recall when they changed their licensing model) and a license would not cover unlimited major version upgrades. At some point (I think during v5) they changed this model. I've got licenses that I bought in 2005 using v2.9.x and have upgraded them to v3, v4, v5, v6 ov...
by Cha0s
Sat May 23, 2020 5:30 pm
Forum: Beginner Basics
Topic: The extra packages in RouterOS [SOLVED]
Replies: 21
Views: 2011

Re: The extra packages in RouterOS [SOLVED]

Like I said: even the standard downgrade function does not work, as the version is the same as before, after the reboot.
Then you are doing something wrong.
Read the fine manual again and retry until you succeed.

Only with exercise you will learn how to properly use ROS.
by Cha0s
Sat May 23, 2020 4:37 pm
Forum: Beginner Basics
Topic: The extra packages in RouterOS [SOLVED]
Replies: 21
Views: 2011

Re: The extra packages in RouterOS [SOLVED]

To upgrade you can use the System > Packages window and click on "Check for Upgrades". From there you can also change channels (stable, long-term, rc, dev) If you want to downgrade to a specific version, then you have to upload the packages manually to the router and then from the System > Packages ...
by Cha0s
Sat May 23, 2020 3:57 pm
Forum: General
Topic: ECMP LoadBalancing
Replies: 15
Views: 1903

Re: ECMP LoadBalancing

@Cha0s, what you suggest would likely work, but sending individual packets of the same TCP session via different physical paths is what 9 of 10 dentists advice against as that may cause packets to arrive to destination in shuffled order. So a good exercise but a possible headache if deployed in pro...
by Cha0s
Sat May 23, 2020 3:21 am
Forum: General
Topic: ECMP LoadBalancing
Replies: 15
Views: 1903

Re: ECMP LoadBalancing

One way to evenly distribute the traffic among all interfaces with using pure ECMP (no routing marks, etc), is by disabling route cache in IP > Settings. This will make each packet to go through a different interface in round-robin fashion (I think), instead of per src/dst ip. So even a single conne...
by Cha0s
Sat May 16, 2020 6:16 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115448

Re: v6.47beta [testing] is released!

What's broken in beta60? I use it on a lora gateway and I haven't noticed any issues (albeit - it's just a lora gateway). By the way, I kind of gotten used to the new icon-set, but it appears terribly low quality. Like using old gifs (256colors) in 90s web pages and manually setting the dimensions i...
by Cha0s
Sat May 16, 2020 5:43 pm
Forum: RouterBOARD hardware
Topic: hardware idea for a multiport switch
Replies: 59
Views: 24652

Re: hardware idea for a multiport switch

Small DIN switches.. Wide input DC power. It'd be nice to be able to mount small switches on walls in closets, cabinets, backboards, industrial situations, etc... Good idea! Also something like what Nexans is doing with their Microswitches for FTTO. I've used them in a few buldings and while the id...
by Cha0s
Sat May 16, 2020 5:27 pm
Forum: RouterOS v7 BETA
Topic: UI/UX On WinBox
Replies: 16
Views: 2437

Re: UI/UX On WinBox

r00t, you are spot on!

(too bad there isn't a 'hear hear' or 'clapping' emoticon available)
by Cha0s
Sat May 16, 2020 2:12 pm
Forum: RouterOS v7 BETA
Topic: UI/UX On WinBox
Replies: 16
Views: 2437

Re: UI/UX On WinBox

Winbox is more than comfortable. If you don't feel comfortable with the current UI, then Winbox is not for you. You can look into TP-Link or Netgear. I hear their devices are VERY comfortable to use. Hey bro, I think you are too proud with wrong direction, I just suggest to Mikrotik for better user...
by Cha0s
Fri May 15, 2020 9:06 pm
Forum: Announcements
Topic: v6.46.6 [stable] is released!
Replies: 65
Views: 26604

Re: v6.46.6 [stable] is released!

by Cha0s
Thu May 14, 2020 3:39 pm
Forum: RouterOS v7 BETA
Topic: UI/UX On WinBox
Replies: 16
Views: 2437

Re: UI/UX On WinBox

Third, UI/UX dose not harm WinBox, it only interface to make more comfortable look and feel to use network as simple configuration. By definition changing the UI you change the interface . It's the "I" in UI. Winbox is more than comfortable. If you don't feel comfortable with the current UI, then W...
by Cha0s
Sat May 09, 2020 8:40 pm
Forum: Announcements
Topic: Winbox v3.23 released!
Replies: 60
Views: 25723

Re: Winbox v3.23 released!

But now they are aspiring to be in the range of Enterprise hardware/software vendors, so such topics must receive top priority. Unfortunately they are just aspiring to get into the enterprise sector. They don't actually try to. I can't imagine any big enterprise that can wait for over 6 years for f...
by Cha0s
Sat May 09, 2020 12:39 pm
Forum: Announcements
Topic: Updated btest.exe available for download
Replies: 13
Views: 2953

Re: Updated btest.exe available for download

I guess most of you have already noticed that <TAB> key does not move focus from one input field to another.
And double click on an input field does not select the text.
by Cha0s
Fri May 08, 2020 4:58 pm
Forum: Announcements
Topic: Updated btest.exe available for download
Replies: 13
Views: 2953

Re: Updated btest.exe available for download

Also tried using the server feature in btest, but router can't connect to it, no matter if using UDP or TCP. Going to server tab, checking "Enabled" and pressing "Apply settings" does nothing. I don't even see open btest TCP port... Works ok here. Maybe your windows firewall blocks the incoming bte...
by Cha0s
Fri May 08, 2020 4:40 pm
Forum: Beginner Basics
Topic: nslookup on Mikrotik
Replies: 17
Views: 35154

Re: nslookup on Mikrotik

:global dns [:resolve "www.google.com"]     
:put $dns
216.58.212.4
by Cha0s
Fri May 08, 2020 1:08 pm
Forum: RouterOS v7 BETA
Topic: UI/UX On WinBox
Replies: 16
Views: 2437

Re: UI/UX On WinBox

What does SDN have to do with Winbox UI?

I strongly disagree with redesigning the Winbox UI.
by Cha0s
Tue May 05, 2020 6:59 pm
Forum: General
Topic: Bandwidth alert
Replies: 5
Views: 790

Re: Bandwidth alert

I think it's more complicated than that. No matter what method you choose, how would you (automatically/inside ROS only) know that the bottleneck is between you and the ISP (thus the ISP cheating) or somewhere outside your ISP's network (depending on how/with who you perform the tests) ? If the ISP ...
by Cha0s
Tue May 05, 2020 3:29 pm
Forum: Forwarding Protocols
Topic: BGP advertise smaller prefix than /24 [SOLVED]
Replies: 7
Views: 1991

Re: BGP advertise smaller prefix than /24 [SOLVED]

Sure, that's all true (that was implied by my "user defined policy" comment).
But OP didn't mention anything about RIRs or the public internet or any "provider".

Those were your assumptions followed by a false statement about what the protocol can or cannot do.
by Cha0s
Sun May 03, 2020 6:19 pm
Forum: Forwarding Protocols
Topic: BGP advertise smaller prefix than /24 [SOLVED]
Replies: 7
Views: 1991

Re: BGP advertise smaller prefix than /24 [SOLVED]

BGP not allow to announce /24 to provider over eBGP but if you are in your network with iBGP you can do it! This is a false statement. BGP doesn't care about prefix length on its advertisements, regardless of eBGP or iBGP. You are confusing user defined policy (which yes, /24 is usually the smalles...
by Cha0s
Sat May 02, 2020 8:59 pm
Forum: Virtualization
Topic: Docker Mikrotik - In two minutes ( en dos minutos )
Replies: 3
Views: 1775

Re: Docker Mikrotik - In two minutes ( en dos minutos )

So... you are using Docker to run a fully virtualized instance of CHR using qemu.
Meaning this is not a container but a full fledged VM over Docker.

What exactly is the point of this?
by Cha0s
Wed Apr 29, 2020 4:34 pm
Forum: Announcements
Topic: MikroTik newsletter May 2020 (#95)
Replies: 42
Views: 18445

Re: MikroTik newsletter May 2020 (#95)

Unfortunatley every time MikroTik features in a Linus Tech Tips video he never gives the product the showcase it deserves, makes me wonder if he really understands it! After watching their 10 Gbit home network video a while back and they were having trouble figuring out how to configure it/couldn't...
by Cha0s
Tue Apr 28, 2020 10:42 pm
Forum: RouterOS v7 BETA
Topic: V7 questions?
Replies: 27
Views: 5181

Re: V7 questions?

Do you or anybody else can tell me whether RouterOS can be tested also in an LXC (or LXD) container in Linux as well? ROS cannot work as a container. Do you happen to know whether RouterOS can be installed on the following dual-core ARM device with multiple Gigabit interfaces: http://wiki.banana-pi...
by Cha0s
Tue Apr 28, 2020 7:26 pm
Forum: RouterOS v7 BETA
Topic: V7 questions?
Replies: 27
Views: 5181

Re: V7 questions?

Do you or anybody else can tell me whether RouterOS can be tested also in an LXC (or LXD) container in Linux as well?
ROS cannot work as a container.
by Cha0s
Sat Apr 25, 2020 4:01 pm
Forum: General
Topic: L2TP/IPSEC and Android Disconnect after ~83 seconds
Replies: 13
Views: 3931

Re: L2TP/IPSEC and Android Disconnect after ~83 seconds

So I don't see this one getting fixed any time soon (even if it's fixed, it will probably never make it to each vendor's updates). Wow! Talk about bad prediction! Just today I got an update from Samsung! And while it didn't mention anything in the changelog, it appears that they included a fix for ...
by Cha0s
Sat Apr 25, 2020 2:54 pm
Forum: Forwarding Protocols
Topic: BGP advertise smaller prefix than /24 [SOLVED]
Replies: 7
Views: 1991

Re: BGP advertise smaller prefix than /24 [SOLVED]

BGP can and will announce any prefix length.

Check your filters, you probably discard any prefix smaller than /24.
by Cha0s
Fri Apr 24, 2020 7:52 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115448

Re: v6.47beta [testing] is released!

I was waiting for this much more than for DoH but each has their own preferences I guess.
Yeah, DoH is cool, but DNS forwarding is more essential to me.
I personally had given up on it. So this was a pleasant surprise!
by Cha0s
Fri Apr 24, 2020 3:57 pm
Forum: RouterOS v7 BETA
Topic: Feature Request - Wireguard Protocol
Replies: 82
Views: 21241

Re: Feature Request - Wireguard Protocol

nz_monkey is spot on
Is this an subtle acknowledgement that you are working on it? :D
by Cha0s
Fri Apr 24, 2020 3:51 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115448

Re: v6.47beta [testing] is released!

*) dns - added support for forwarding DNS queries of static entries to specific server (CLI only);
*) dns - added support for multiple type static entries (CLI only);
Finally!!!
Can't wait to test this one out!

Will forwarding be able to match regex entries also?
by Cha0s
Fri Apr 24, 2020 3:25 pm
Forum: General
Topic: L2TP/IPSEC and Android Disconnect after ~83 seconds
Replies: 13
Views: 3931

Re: L2TP/IPSEC and Android Disconnect after ~83 seconds

From what I understand this is an Android bug and it's not specific to MikroTik. So I don't see this one getting fixed any time soon (even if it's fixed, it will probably never make it to each vendor's updates). For the time being I switched to Wireguard, and so far I am very happy with it. I'll pro...
by Cha0s
Fri Apr 24, 2020 3:54 am
Forum: General
Topic: L2TP/IPSEC and Android Disconnect after ~83 seconds
Replies: 13
Views: 3931

Re: L2TP/IPSEC and Android Disconnect after ~83 seconds

Android 9: terminates after about 83 seconds...
Also Android 10 on Samsung Galaxy S9+
Prior to the recent Android 10 upgrade from Android 9, it was definitely working for me without problems.

Has anyone found out any solution?
by Cha0s
Thu Apr 23, 2020 12:03 pm
Forum: General
Topic: Transparent L2 Passthrough [SOLVED]
Replies: 5
Views: 1520

Re: Transparent L2 Passthrough [SOLVED]

That's exactly what EoIP is for.
by Cha0s
Fri Apr 17, 2020 2:55 pm
Forum: RouterBOARD hardware
Topic: The correct scheme for connecting two Mikrotiks to three switches
Replies: 3
Views: 1837

Re: The correct scheme for connecting two Mikrotiks to three switches

Pay attention to the implementation scheme, are there any comments? He just told you. The switches you are using are not routers. You need to put in proper routers if you need to route (not switch) traffic. MikroTik switches, are not L3 switches. They may technically be able to do routing, but not ...
by Cha0s
Sun Mar 29, 2020 6:16 pm
Forum: RouterOS v7 BETA
Topic: FEATURE REQUEST: Add Basic Firewall Rule Wizard
Replies: 41
Views: 6989

Re: FEATURE REQUEST: Add Basic Firewall Rule Wizard

This is certainly true but why not do an identical procedure on ROS via WinBox or WebFig? Because it is a waste of developer resources. MikroTik should focus on fixing bugs and introducing new features. Not cater to noobs that cannot be bothered to read the manual. Seriously, the amount of posts as...
by Cha0s
Fri Mar 27, 2020 12:07 am
Forum: RouterOS v7 BETA
Topic: FEATURE REQUEST: Add Basic Firewall Rule Wizard
Replies: 41
Views: 6989

Re: FEATURE REQUEST: Add Basic Firewall Rule Wizard

This is exactly why I hate the IT community. Simplifying something isn’t going to cost you your job. That's why I hate the non-IT community . Instead of complaining about what you don't know how to use and asking to dumb down things, you should start by RTFM. It doesn't cost your job. It isn't even...
by Cha0s
Wed Mar 25, 2020 5:14 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115448

Re: v6.47beta [testing] is released!

That what you wrote is still in the future. All major web servers support TLS 1.3 already. Browsers too. It is NOT in the future. It's already being rolled out. It has started since 2018. At the moment using DoH is futile if you want to have privacy. I remember back in the non SSL/TLS days, people ...
by Cha0s
Wed Mar 25, 2020 2:30 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115448

Re: v6.47beta [testing] is released!

It is a FALSE assumption, that your traffic (metadata) is invisible when using HTTPS or/and DoH. When TLS 1.3 becomes mainstream, it will no longer be an assumption. Right now even using TLS, the ISP can see the domain you are visiting. After TLS 1.3 that will no longer be possible and the L3-L4 "m...
by Cha0s
Mon Mar 02, 2020 9:18 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115448

Re: v6.47beta [testing] is released!

Agreed. New icon set is horrendous
Those new are just UGLY, one color type.
Yes! Bring our colors back! It is much easier to find something on a glance when it is different from its neighbors...
+1
by Cha0s
Mon Feb 17, 2020 3:14 pm
Forum: Announcements
Topic: Winbox v3.21 released!
Replies: 55
Views: 14444

Re: Winbox v3.21 released!

People who asked to do the interface smaller probably work on a FullHD monitor because on a 4K monitor (3840x2160) the interface looks incredibly small even with the maximal zoom. Please make the interface bigger or add more zoom levels. QHD, and I still prefer it smaller than the default. The more...
by Cha0s
Fri Feb 07, 2020 12:45 pm
Forum: Announcements
Topic: Winbox v3.21 released!
Replies: 55
Views: 14444

Re: Winbox v3.21 released!

I'll go slightly against the flow. Everyone seems to want things bigger, but I'd rather have them smaller. Or maybe better term would be more condensed. It's about one specific thing, line height. +1 Finally I see someone talking about UI efficiency and not looks! I too want to be able to see as mu...
by Cha0s
Tue Jan 28, 2020 3:22 pm
Forum: RouterOS v7 BETA
Topic: Feature Request - BGP RPKI
Replies: 23
Views: 6415

Re: Feature Request - BGP RPKI

ROS didn't use Quagga.
This is not true.
Back in 2.x days ROS was using quagga. And a rather buggy version at that.

But yes, the current implementation AFAIK is not based on quagga.
by Cha0s
Mon Jan 20, 2020 3:37 pm
Forum: Beginner Basics
Topic: ping script
Replies: 5
Views: 1025

Re: ping script

What did you try?
by Cha0s
Mon Jan 20, 2020 12:06 pm
Forum: Beginner Basics
Topic: ping script
Replies: 5
Views: 1025

Re: ping script

by Cha0s
Mon Jan 20, 2020 11:59 am
Forum: Announcements
Topic: v6.46.2 [stable] is released!
Replies: 121
Views: 31049

Re: v6.46.2 [stable] is released!

or use other more reliable ways.
Or just revert it back to how it was...
by Cha0s
Mon Jan 20, 2020 11:57 am
Forum: Announcements
Topic: v6.46.2 [stable] is released!
Replies: 121
Views: 31049

Re: v6.46.2 [stable] is released!

System files have always been hidden / not accessible for a user in RouterOS. Packages are now following the same principle. That is just plain silly! Now when I check for new version and click Download, or after uploading files using FTP, I cannot even check if the files were loaded completely bef...
by Cha0s
Mon Jan 06, 2020 7:25 pm
Forum: Announcements
Topic: v6.46.1 [stable] is released!
Replies: 72
Views: 33749

Re: v6.46.1 [stable] is released!

I'd like to ask the developers if they can, so please kindly fix the bug, according to their natural priority ... It appears that Mikrotik's priority on cosmetic bugs is very very low. This bug has been reported many many times for many many months now and it has been thoroughly ignored by MikroTik...
by Cha0s
Tue Dec 17, 2019 4:31 pm
Forum: Announcements
Topic: v6.44.6 [long-term] is released!
Replies: 54
Views: 44052

Re: v6.44.6 [long-term] is released!

Remove tr069 package, then manually upload the new packages (not the bundle) you need.

Reboot, and you are good to go.
by Cha0s
Tue Dec 10, 2019 4:15 pm
Forum: Virtualization
Topic: proxmox 6.1 with chr - ethernet speed problem
Replies: 6
Views: 2614

Re: proxmox 6.1 with chr - ethernet speed problem

CHR's virtio/vmxnet3 based interfaces seem to always show "Auto Negotiation: Incomplete | Rate: Unknown".
License doesn't matter. You can try it yourself with a P10 demo license and it will still show Incomplete/Unknown.

Regardless of the negotiation status, it does actually work at 10Gbit.
by Cha0s
Tue Dec 10, 2019 3:55 pm
Forum: Forwarding Protocols
Topic: How can I send a received BGP Full table to a peer?
Replies: 2
Views: 1676

Re: How can I send a received BGP Full table to a peer?

What have you tried?
Post you configuration.
by Cha0s
Thu Nov 28, 2019 9:10 pm
Forum: General
Topic: IPv6 feature development speedup.
Replies: 8
Views: 1167

Re: IPv6 feature development speedup.

"my ISP does not offer it" To me this is kind of a chicken and egg problem. If ROS doesn't fully support it, then yes, ISPs based on ROS won't offer it, and then users won't use it, which in turn translates to "low demand" in MUMs, etc. IPv6 doesn't bring much benefit to the end user. Yeah they wil...
by Cha0s
Mon Nov 25, 2019 5:06 pm
Forum: General
Topic: IPv6 feature development speedup.
Replies: 8
Views: 1167

IPv6 feature development speedup.

Today we got this announcement from RIPE. Dear colleagues, Today, at 15:35 UTC+1 on 25 November 2019, we made our final /22 IPv4 allocation from the last remaining addresses in our available pool. We have now run out of IPv4 addresses. Our announcement will not come as a surprise for network operato...
by Cha0s
Mon Nov 25, 2019 4:47 pm
Forum: Forwarding Protocols
Topic: BGP/Routing question
Replies: 5
Views: 1928

Re: BGP/Routing question

I don't think you can do that.

The way I understand it, if you need a prefix to be passed through the Anti-DDoS ISP, you need to only announce it via them and not any other ISP.
Otherwise, anyone that is closer to that other ISP will choose that path to reach you instead of the Anti DDoS ISP.
by Cha0s
Mon Nov 25, 2019 4:32 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+RM WAN port and LAN switching
Replies: 9
Views: 2584

Re: RB4011iGS+RM WAN port and LAN switching

I've used various SFP+ modules on RB4011 without any issues. CISCO-AVAGO 10Gbase-SR SFBR-709SMZ-CS2 CISCO-AVAGO 10Gbase-LR SFCT-739SMZ FS 10GBase-ER SFP-10GER-31 OPTIC 10Gbase-SR S+85DLC03D MikroTik 10Gbase-SR S+85DLC03D And a few more (mainly 1Gbit) that I don't recall at the moment. As a matter of...
by Cha0s
Mon Nov 25, 2019 4:00 pm
Forum: Forwarding Protocols
Topic: BGP/Routing question
Replies: 5
Views: 1928

Re: BGP/Routing question

I don't know if I fully understand what you ask, but I believe that in order to achieve what you want, you stop announcing your prefixes to the worldwide ISP and only announce them to the Anti-DDoS ISP, and they in turn announce them to the world. This way your incoming world-wide traffic will arriv...
by Cha0s
Thu Nov 14, 2019 5:14 pm
Forum: Announcements
Topic: Newsletter 91
Replies: 25
Views: 27382

Re: Newsletter 91

The next two Mum's are on the 14th of November and the 28-29 of November. My money is on Brazil in two weeks.
It got announced today in Athens' MUM.
https://youtu.be/ZKLtPiFoX4k?t=3514
by Cha0s
Fri Nov 01, 2019 8:12 am
Forum: General
Topic: TCP SYN Flood attack causing high cpu
Replies: 20
Views: 13467

Re: TCP SYN Flood attack causing high cpu

Thank you for your opinion.
by Cha0s
Fri Nov 01, 2019 2:36 am
Forum: General
Topic: TCP SYN Flood attack causing high cpu
Replies: 20
Views: 13467

Re: TCP SYN Flood attack causing high cpu

FastPath needs Route Cache to be enabled.

With route cache enabled, the router becomes almost completely unresponsive during any moderate SYN flood attack.
by Cha0s
Sat Oct 26, 2019 8:12 pm
Forum: Wireless Networking
Topic: WiFi4EU
Replies: 13
Views: 5146

Re: WiFi4EU

They will not get such contracts anyway, and those that do get them generally deliver equipment that is a little more sturdy. At its price, of course. Yeap, I agree. In my country at least, it is certain that the job will go to the company with the worst price and the most kickbacks to the politici...
by Cha0s
Sat Oct 26, 2019 8:06 pm
Forum: General
Topic: Block Anydesk
Replies: 10
Views: 8657

Re: Block Anydesk

I presume if port 80 is blocked, it will also try port 443 and even port 6568 as implied in the FAQ. Here are some logs from a corporate proxy blocking anydesk. 1572105939.836 0 x.x.x.x TCP_DENIED/403 2045 CONNECT 144.76.103.6:80 - NONE/- text/html 1572105941.837 0 x.x.x.x TCP_DENIED/403 2059 CONNE...
by Cha0s
Tue Oct 22, 2019 11:54 am
Forum: Virtualization
Topic: Routeros docker container image
Replies: 9
Views: 6120

Re: Routeros docker container image

This is not a Docker image for ROS but for OpenVPN.

Not to mention that it hasn't been updated for over 4 years.
https://github.com/AlexBeznos/openvpn-mikrotik

IMHO, ROS on Docker (or any other container platform) is a waste of time.
by Cha0s
Mon Oct 21, 2019 4:14 pm
Forum: Virtualization
Topic: Routeros docker container image
Replies: 9
Views: 6120

Re: Routeros docker container image

Docker is a container.
ROS is not just a web server or some app to be run in a container.

It is heavily dependent on its kernel to implement many of its features.

So my guess is that there will never be a docker image for ROS.
by Cha0s
Fri Oct 18, 2019 2:52 pm
Forum: Announcements
Topic: Winbox v3.20 released!
Replies: 42
Views: 20681

Re: Winbox v3.20 released!

could you please consider changing application bar/other WinBOX window component colour while in SafeMode? Regardless of information when exiting the app it would help to identify the current mode.
+1
by Cha0s
Fri Oct 18, 2019 2:51 pm
Forum: RouterBOARD hardware
Topic: New High Performance Routers ! ?
Replies: 48
Views: 10347

Re: New High Performance Routers ! ?

MikroTik routers are fine for many purposes, but when it appears you are pushing the limits it may be time to look at others. Sadly, this is very true. I would love to see higher end models using ASICs (with the appropriate price tag) to be able to use MikroTik hardware for enterprise solutions. CC...
by Cha0s
Wed Oct 16, 2019 12:35 am
Forum: General
Topic: Winbox 3.20 x64 still with bugs from YEARS AGO
Replies: 9
Views: 1428

Re: Winbox 3.20 x64 still with bugs from YEARS AGO

With only 60 routes, it is indeed annoying! If you try to login with a fresh/empty ( <none> ) winbox session, does it change anything? ingdaka on every single router I manage that has more than 1-2 thousands of advertisements, it always occurs. Without exception and regardless of architecture. Proba...
by Cha0s
Tue Oct 15, 2019 1:50 am
Forum: General
Topic: Block Anydesk
Replies: 10
Views: 8657

Re: Block Anydesk

Also you cannot block port 80/443 obviously, so the anydesk client will be able to reach the anydesk servers, and from there I believe if port 7070 is blocked, it will work over 443. I never said blocking ports 80 or 443... in my previous post i said block the listening port which is not 80 or 443 ...
by Cha0s
Mon Oct 14, 2019 11:29 pm
Forum: General
Topic: Block Anydesk
Replies: 10
Views: 8657

Re: Block Anydesk

L7 firewall blocking is not recommended anymore...! Especially when what you want can be achieved by a simple TCP port block..! I don't think that a simple block will do it. https://support.anydesk.com/FAQ Which ports does AnyDesk use? To connect to the AnyDesk network port 80, 443 or 6568 is used....
by Cha0s
Mon Oct 14, 2019 11:16 pm
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself [SOLVED]
Replies: 302
Views: 58748

Re: RB4011: wlan1 disabling itself [SOLVED]

One thing that may help replicate this issue is using the sfp port. Both times I have witnessed this and all times our tech support has witnessed this the sfp port is in use.
Interesting detail.

In my board that the issue occurs, I indeed use the SFP port.
by Cha0s
Thu Oct 10, 2019 10:33 am
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself [SOLVED]
Replies: 302
Views: 58748

Re: RB4011: wlan1 disabling itself [SOLVED]

For the problem to manifest you have to have no device connected to 5GHz wifi for a few hours. Then it "crashes". The title is a bit misleading. The interface doesn't get disabled, in that you don't see it disabled (greyed out) in winbox. It shows up/enabled fine in winbox/cli, but it doesn't trans...
by Cha0s
Wed Oct 09, 2019 11:55 pm
Forum: General
Topic: OpenVPN .ovpn
Replies: 5
Views: 2548

Re: OpenVPN .ovpn

+1 :)
by Cha0s
Tue Oct 08, 2019 9:52 pm
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself [SOLVED]
Replies: 302
Views: 58748

Re: RB4011: wlan1 disabling itself [SOLVED]

For the problem to manifest you have to have no device connected to 5GHz wifi for a few hours. Then it "crashes". The title is a bit misleading. The interface doesn't get disabled, in that you don't see it disabled (greyed out) in winbox. It shows up/enabled fine in winbox/cli, but it doesn't transm...
by Cha0s
Thu Oct 03, 2019 12:06 pm
Forum: RouterBOARD hardware
Topic: As for the equipment purchased in the past two years, it's broken and can't be repaired now.
Replies: 6
Views: 2346

Re: As for the equipment purchased in the past two years, it's broken and can't be repaired now.

"Broken" is rather vague.

Post proper pictures with proper lighting of both sides of all boards so we can see what the damage is exactly.
Posting 3 boards on top of each other, and on their back where there are no components, is just silly.
by Cha0s
Mon Sep 23, 2019 3:10 pm
Forum: RouterOS v7 BETA
Topic: Torrent client
Replies: 40
Views: 13598

Re: Torrent client

Please remove it, or at a minimum put it in a separate .NPK from the base OS. maybe a separate soho.npk that includes the torrent client, kid-control and SMB server.. :)
Amen! :P
by Cha0s
Wed Sep 11, 2019 6:46 pm
Forum: General
Topic: RouterOS v7.0beta1 (ARM)
Replies: 203
Views: 53679

Re: RouterOS v7.0beta1 (ARM)

Wait, torrent wasn't a joke?
Torrent is an essential feature of every router!
DNS on the other hand... :lol: :lol:
by Cha0s
Mon Sep 09, 2019 7:44 pm
Forum: General
Topic: Request: FEC tunnel types
Replies: 29
Views: 5208

Re: Request: FEC tunnel types

At the moment there is no fully automated method in ROS to switch from a bad uplink (bad as in slight packet loss or increased latency somewhere between you and the destination - but still functional as far as ROS is concerned) to a backup/good one. You either have to resort to cumbersome scripts a...
by Cha0s
Mon Sep 09, 2019 6:17 pm
Forum: General
Topic: Request: FEC tunnel types
Replies: 29
Views: 5208

Re: Request: FEC tunnel types

I don't know (or care) about how LTE handles loss, etc, but I think we've got offtopic comparing this to LTE. LTE is just one type of Internet access and is irrelevant to the topic at hand IMHO. I can see this technology having significant benefits even if your uplinks are fiber based with 99.999% u...
by Cha0s
Tue Sep 03, 2019 5:52 pm
Forum: Beginner Basics
Topic: Best VPN for Mikrotik / RouterOS
Replies: 12
Views: 6620

Re: Best VPN for Mikrotik / RouterOS

I did Anav. One of the first hits was NordVPN, but I see it doesn't support MikroTik anymore. Hence I'm asking here. Since v6.45 MikroTik can connect to NordVPN without problems. using IKEv2. https://nordvpn.com/tutorials/mikrotik/ikev2/ https://wiki.mikrotik.com/wiki/IKEv2_EAP_between_NordVPN_and_...
by Cha0s
Tue Sep 03, 2019 2:44 pm
Forum: General
Topic: [Feature Request] interface events
Replies: 2
Views: 980

Re: [Feature Request] interface events

+1 :)
by Cha0s
Tue Sep 03, 2019 2:36 pm
Forum: RouterBOARD hardware
Topic: RB4011 Metal temperature is really hot
Replies: 47
Views: 11618

Re: RB4011 Metal temperature is really hot

Yes, ~45 degrees seems to be the norm for this device.
graph.php.png
Here's a comparison between RB3011 and and RB4011 that replaced it around a month ago.
by Cha0s
Mon Sep 02, 2019 11:03 pm
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself [SOLVED]
Replies: 302
Views: 58748

Re: RB4011: wlan1 disabling itself [SOLVED]

Several days passed, still no replies and not a single email about this issue. Is the RB4011 5GHz issue resolved? The problem still exists. For me it took about 29 days on a brand new RB4011, before it occurred. Since then the wifi gets disabled (stuck in "initializing") in less than a day for 3 da...
by Cha0s
Sat Aug 31, 2019 2:26 pm
Forum: RouterBOARD hardware
Topic: Why Mikrotik block google translate
Replies: 10
Views: 3026

Re: Why Mikrotik block google translate

Mikrotik doesn't block Google Translate, or any other service for that matter. All RouterOS does, is route packets from one network to another, according to however you configure the device to do so. It doesn't take it on itself to decide whether you should be able to access a webservice or not. If ...
by Cha0s
Thu Aug 22, 2019 3:22 pm
Forum: General
Topic: [Feature Request] Winbox and netinstall 64 Bit versions - URGENT
Replies: 21
Views: 4766

Re: [Feature Request] Winbox and netinstall 64 Bit versions - URGENT

Don't touch my WinBox, it's one of the best tools invented by mankind, and it's perfect as it is now. It's like trying to reform hammer, sure you can come up with something else that's not bad either, but it still won't be good replacement for the simple and reliable tool in all cases. Native WinBo...
by Cha0s
Thu Aug 22, 2019 3:09 pm
Forum: Announcements
Topic: v6.46beta [testing] is released!
Replies: 150
Views: 72833

Re: v6.46beta [testing] is released!

*) system - accept only valid string for "name" parameter in "disk" menu (CVE-2019-15055);
I guess asking for more info on that is pointless until you provide an update for stable/long-term channels, right?
by Cha0s
Mon Aug 12, 2019 3:27 pm
Forum: Beginner Basics
Topic: File download block?
Replies: 25
Views: 4088

Re: File download block?

Yes, I am aware of that, but how do the others do it, at train stations, airports ... ? a few weeks ago I set up a WLAN connection at the airport and I couldn't download any files. So there has to be a solution. I doubt they were able to block files download over an HTTPS connection. Only whole dom...
by Cha0s
Mon Aug 12, 2019 3:25 pm
Forum: Beginner Basics
Topic: File download block?
Replies: 25
Views: 4088

Re: File download block?

Strangely enough, URL Block also works for HTTPS pages. This works here, for example: ^.+(youtube.com|facebook.com).*$ Domain block (not URL block) works because the domain is visible (unencrypted) during the TLS session setup between the browser and the server. After that, you cannot see anything ...
by Cha0s
Mon Aug 12, 2019 2:57 pm
Forum: Announcements
Topic: v6.45.3 [stable] is released!
Replies: 90
Views: 34894

Re: v6.45.3 [stable] is released!

This L7 Regexp does not work anymore since update: \.(exe|dmg|cab|msi|flv|mp2|mp3|m4a|mp4|torrent)($|\?) I used this to block file download. I also don't know which MikroTik version I had before. I think it was the 6.43. You do understand that this is useless in an ever growing https world, right?
by Cha0s
Mon Aug 12, 2019 2:55 pm
Forum: General
Topic: Software Download section-Problems
Replies: 1
Views: 659

Re: Software Download section-Problems

Probably something wrong on your side. An antivirus messing up with the downloads maybe?

All links work fine on my end.
by Cha0s
Thu Aug 08, 2019 12:39 pm
Forum: RouterBOARD hardware
Topic: Is RB4011iGS+5HacQ2HnD ready?
Replies: 9
Views: 2239

Re: Is RB4011iGS+5HacQ2HnD ready?

I've got a few of the non wifi RB4011 models and I have no issues. In fact I found that RB4011 was the only model that I could saturate the uplink with a single connection over IPsec, while others couldn't go much higher than 150Mbps (and that with multiple connections only). Granted, my configurati...
by Cha0s
Tue Jul 16, 2019 5:10 pm
Forum: General
Topic: TCP SYN Flood attack causing high cpu
Replies: 20
Views: 13467

Re: TCP SYN Flood attack causing high cpu

Almost two years have passed, and absolutely nothing has changed.

CCRs still cannot route (not drop) a moderate flood of SYN packets.
by Cha0s
Tue Jul 09, 2019 10:47 pm
Forum: Announcements
Topic: Winbox v3.19 released!
Replies: 33
Views: 17751

Re: Winbox v3.19 released!

cpu spikes
Huh?..
Do you want to elaborate more? :roll:
by Cha0s
Tue Jul 09, 2019 1:39 pm
Forum: Announcements
Topic: Winbox v3.19 released!
Replies: 33
Views: 17751

Re: Winbox v3.19 released!

Also, Winbox on Linux/Wine is definitely heavier/slower than on windows. Each screen refresh causes cpu spikes when having multiple windows open.
On windows there is no such cpu usage no matter how many windows I have open in winbox.
by Cha0s
Mon Jul 08, 2019 2:15 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 111644

Re: v6.45.1 [stable] is released!

Last Link Up/Down Time botched. It started happening to me (951G-2HnD, 941-2nD) on the latest stable ROS 6.45.1 / WinBox 3.19. Ethernet and ppp links. WinBox Terminal - correct: last-link-down-time=jul/08/2019 12:31:21 WinBox Interface List - wrong: Last Link Down Time: Jul/14/2019 09:44:52 Today i...
by Cha0s
Tue Jul 02, 2019 4:38 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 111644

Re: v6.45.1 [stable] is released!

Everyone who is experiencing problems with Winbox authorization - we will release a new Winbox loader with a fix for this problem as soon as possible. We are very sorry for any inconvenience caused. While you are at it, will you fix the interfaces last up/down times on winbox that are in the future?
by Cha0s
Mon Jul 01, 2019 7:00 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 111644

Re: v6.45.1 [stable] is released!

My configurations use all types of tunnels.

GRE, IPIP, EoIP. All of them, over IPsec without any problems on my end.
by Cha0s
Mon Jul 01, 2019 6:50 pm
Forum: Forwarding Protocols
Topic: BGP load-balance per-packet
Replies: 3
Views: 2091

Re: BGP load-balance per-packet

You are looking for ECMP - Equal Cost Multipath. https://wiki.mikrotik.com/wiki/Manual:BGP_Load_Balancing_with_two_interfaces ECMP by default (route cache=on), will load balance per connection and not per packet. By disabling route cache (in IP > Settings) then ECMP load balances per packet on all a...
by Cha0s
Mon Jul 01, 2019 6:43 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 111644

Re: v6.45.1 [stable] is released!

2 Mikrotik Team Do you confirm some troubles with GRE interfaces + IPSec (transport) ? What we have to do in that case? Maybe there is something special with update? For example: We have to update passive sites first to 6.45.1 and after main router to 6.45.1 Or another way? Thanks! I have IPsec tun...
by Cha0s
Mon Jul 01, 2019 3:10 pm
Forum: General
Topic: Forum reliability
Replies: 18
Views: 3284

Re: Forum reliability

I agree with pe1chl. phpBB can also send mails using the native mail() function of PHP, which by default will send mails using sendmail executable to localhost. This can be blazing fast since it doesn't even care if the local MTA is loaded or not or even running at all. It writes directly to the fil...
by Cha0s
Mon Jul 01, 2019 2:55 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 111644

Re: v6.45.1 [stable] is released!

i upgrade my RB433AH after that...i couldn't access with current user and password and with admin???? . My observation is that after a reboot, the first login attempt fails ... subsequent logins are successful. This behavior has been reproducible after every reboot, of the single device I'm testing...
by Cha0s
Mon Jun 24, 2019 10:48 am
Forum: General
Topic: Feature Request: IPv6 NAT66 Support
Replies: 27
Views: 9522

Re: Feature Request: IPv6 NAT66 Support

NETMAP needed.

not nat.
You mean NPT, and both NAT66 and NPT (or netmap) are types of NAT.
by Cha0s
Sat Jun 15, 2019 2:18 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 93038

Re: v6.45beta [testing] is released!

Will it ever be possible to filter ipsec logs by peer? Debugging is pretty much impossible if you have a ton of tunnels active.
+1
by Cha0s
Fri May 31, 2019 5:47 pm
Forum: Beginner Basics
Topic: RB3011 Show LTE in Quickset
Replies: 13
Views: 1643

Re: RB3011 Show LTE in Quickset

If you have many custom settings, then you should most definitely not use quickset. If you can still sensibly change settings using quick set, then ... you don't have that many settings after all. I'm sorry but reset is not a solution Then you shouldn't use Quickset. Quickset is only for initial se...
by Cha0s
Fri May 31, 2019 12:45 pm
Forum: Announcements
Topic: v6.44.3 [stable] is released!
Replies: 123
Views: 41400

Re: v6.44.3 [stable] is released!

That wrong time is a "known problem" that was introduced several versions ago, not with this version. It likely is already on the list of things to fix. Also I believe it's a winbox bug and not a ROS bug. CLI shows the correct times. IIRC deleting the session on winbox also shows the correct times ...
by Cha0s
Mon May 20, 2019 3:41 am
Forum: RouterBOARD hardware
Topic: LtAP Kit no registration - Vodafone ES SIM
Replies: 2
Views: 820

Re: LtAP Kit no registration - Vodafone ES SIM

LtAP mini Kit has two SIM slots. Is it possible you are using the wrong SIM slot?

They way those slots are it's not always clear weather you've inserted the SIM on slot 1 or slot 2 (they call it up/down in System>Routerboard>SIM menu).
by Cha0s
Mon May 20, 2019 3:35 am
Forum: General
Topic: iframe issue at MTU 1500
Replies: 1
Views: 539

Re: iframe issue at MTU 1500

What does the browser's web developer's tools console shows when it cannot load the iframe? If the iframe url can load when accessed directly, then it's almost certain that it is not a networking/MTU/MSS issue. Is it possible that the client's browser is messed up (or some other software is messing ...
by Cha0s
Mon May 20, 2019 3:24 am
Forum: General
Topic: Need help in choosing l3 switch with 10G fiber SFP+ ports
Replies: 2
Views: 575

Re: Need help in choosing l3 switch with 10G fiber SFP+ ports

MikroTik has no L3 switch that can do wirespeed routing. Can can do L3 stuff on MikroTik switches, but the performance will be way lower than 10Gbit (maybe even lower than 1Gbit) since all those functions are done on the CPU and not on the switch chips. The CCR line are not switches but routers. Tha...
by Cha0s
Mon May 20, 2019 3:00 am
Forum: General
Topic: Suggestion: At new releases
Replies: 9
Views: 1645

Re: Suggestion: At new releases

Just got an RB4011iGS+RM. It has 512MB flash, so I might have been interested, but the online documentation states that it's only available for MIPS, TILE and PowerPC. Too bad. RB4011 perfectly supports multiple partitions. I am using it on multiple RB4011s. AFAIK as long as you have >=64MB of flas...
by Cha0s
Fri May 10, 2019 10:01 am
Forum: General
Topic: Feature request: Do not block highlighting/selecting torch table contents
Replies: 5
Views: 1427

Re: Feature request: Do not block highlighting/selecting torch table contents

If you double click on the source address it gets copied to the Src. Address Filter field.
Same goes for Destination address.

No the best solution, but it's better than nothing.
by Cha0s
Thu Mar 21, 2019 5:58 pm
Forum: Announcements
Topic: Statement on Vault 7 document release
Replies: 92
Views: 54465

Re: Statement on Vault 7 document release

For Unimus, connect to router periodically (user configured scheduling), and retrieve "/export compact". After that, strip all dynamic content in the output (timestamps, log messages, runtime comments, etc.). Parse the config, check if anything changed against last retrieved config. If a change is ...
by Cha0s
Thu Mar 21, 2019 5:14 pm
Forum: Announcements
Topic: Statement on Vault 7 document release
Replies: 92
Views: 54465

Re: Statement on Vault 7 document release

Does anyone know how to have "Configuration changes notifications" as mentioned in the talk? Is this something that ROS can do natively (or with scripting) or you have to do that using syslog etc? Usually a configuration management system does this for you. Unimus does this out-of-the box and you c...
by Cha0s
Tue Mar 19, 2019 6:47 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 93038

Re: v6.45beta [testing] is released!

In what scenario? If it's road warrior (typical when src is unknown or when src has dynamic IP) then policies should be already auto generated. In the scenario where an ISP doesn't provide a static IP to it's client, instead using Dynamic IP or PPPoE with a dynamic IP. In such cases, a DDNS hostnam...
by Cha0s
Tue Mar 19, 2019 6:44 pm
Forum: Announcements
Topic: Statement on Vault 7 document release
Replies: 92
Views: 54465

Re: Statement on Vault 7 document release

Does anyone know how to have "Configuration changes notifications" as mentioned in the talk?
Is this something that ROS can do natively (or with scripting) or you have to do that using syslog etc?
by Cha0s
Sat Mar 02, 2019 8:49 pm
Forum: General
Topic: Feature Request: TACACS/TACACS+
Replies: 39
Views: 11833

Re: Feature Request: TACACS/TACACS+

+1 for TACACS+ support
by Cha0s
Thu Feb 28, 2019 6:39 pm
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 219
Views: 48333

Re: v6.44 [stable] is released!

Incorrect time is cosmetic Winbox bug noticed when there are multiple Winbox instances open. If you check in terminal, time is reported correctly.
When will it be fixed? This has been reported for many releases by now.
by Cha0s
Mon Feb 18, 2019 12:05 am
Forum: General
Topic: Wrong "Last Link Down Time" in Winbox
Replies: 19
Views: 5093

Re: Wrong "Last Link Down Time" in Winbox

I confirm the problem.
by Cha0s
Wed Feb 13, 2019 3:45 pm
Forum: Forwarding Protocols
Topic: BEST BGP Scneario
Replies: 4
Views: 2045

Re: BEST BGP Scneario

by Cha0s
Thu Feb 07, 2019 4:41 pm
Forum: Announcements
Topic: Suggestions requested: general hotspot controller improvements in functionality
Replies: 11
Views: 6496

Re: Suggestions requested: general hotspot controller improvements in functionality

On RB951 and similar boards, I don't expect the best performance and I don't think PHP should be supported at all on these models due to the low power CPU and resources. But for the more capable models, like RB3011, RB4011, CHR and CCR-series, it could be a nice addition. Yeah, but that ain't gonna...
by Cha0s
Wed Feb 06, 2019 4:49 pm
Forum: Announcements
Topic: v6.43.11 [stable] is released!
Replies: 79
Views: 18416

Re: v6.43.11 [stable] is released!

Legal limits are about EIRP. EIRP is not Tx power at transmitter's RF connector, it's power at antenna perimeter. And that value is affected by antenna gain. Which is not how most of WiFi users (and, sadly, WISPs) understood things ... I remember attending a Netgear "seminar" back in 2005-2006ish a...
by Cha0s
Wed Feb 06, 2019 4:38 pm
Forum: Announcements
Topic: Suggestions requested: general hotspot controller improvements in functionality
Replies: 11
Views: 6496

Re: Suggestions requested: general hotspot controller improvements in functionality

PHP Support for webpages. So, that we can make advanced webpages without visible scripts (JavaScript is visible to the user, PHP scripts are not). I know MikroTik's webserver is meant to provide the basics, but you don't always have the space and budget to place an external webserver (and no.... a ...
by Cha0s
Sat Feb 02, 2019 2:10 pm
Forum: RouterBOARD hardware
Topic: Schematics for RB112
Replies: 11
Views: 2746

Re: Schematics for RB112

In year 2019 - this RB belongs to the trash
Besides suggesting putting it in a landfill, polluting the environment for no good reason, do you have anything on-topic to suggest?
Like for example, what is the value of C78?
by Cha0s
Sat Feb 02, 2019 1:41 pm
Forum: RouterBOARD hardware
Topic: Schematics for RB112
Replies: 11
Views: 2746

Re: Schematics for RB112

Those are C67 and C68 and their value is: 560μF 6.3V 105°C

While we are at it, does anyone know the value of C78?
It's right behind the DC barrel connector and it's an SMD one.
ima_82b5a40.jpeg
by Cha0s
Sat Feb 02, 2019 1:29 pm
Forum: General
Topic: Spindown network Disk
Replies: 1
Views: 487

Re: Spindown network Disk

AFAIK there is no such option.

On the other hand, MikroTik is a router, not a NAS device. Don't use it like that.
by Cha0s
Sun Jan 20, 2019 2:53 pm
Forum: Virtualization
Topic: Mikrotik CHR speed performance problem
Replies: 28
Views: 11761

Re: Mikrotik CHR speed performance problem

That (voip) explains the high packet rate but low bandwidth I saw on your screenshots. Unless you use NAT, you don't need the SIP direct media helper (and I think it doesn't even get involved in forwarded traffic when there is no NAT). Also, connection tracking in general, with lots of connections a...
by Cha0s
Fri Jan 18, 2019 4:35 pm
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 104573

Re: v6.44beta [testing] is released!

Same with the web interface.
by Cha0s
Fri Jan 18, 2019 4:24 pm
Forum: General
Topic: [Feature Request] :resolve DNS Client Improvements
Replies: 8
Views: 2519

Re: [Feature Request] :resolve DNS Client Improvements

+1 by me as well.
by Cha0s
Fri Jan 18, 2019 1:56 pm
Forum: Virtualization
Topic: CHR, LACP, and VMware
Replies: 2
Views: 2229

Re: CHR, LACP, and VMware

You cannot bond at the CHR level. Right now you are bonding two virtual NICs that connect to a Virtual Switch. Not Nexus. You should do the bonding at the ESXi level. But from there I don't know how you could get more that 10Gbps on the CHR. I've read some posts that the VMXNET3 driver doesn't reall...
by Cha0s
Thu Jan 17, 2019 12:40 pm
Forum: Announcements
Topic: SwOS version 2.9 released!
Replies: 72
Views: 34457

Re: SwOS version 2.9 released!

Upgrading from 2.8 to 2.9 on a CSS106-5G-1S causes severe traffic drop between 1G ports and 100Mbit ports. It's random from 0 to 40Mbps. Reverting back to 2.8 traffic increased back to steady 100Mbps. Are there any errors in interface stats when using v2.8 or v2.9? No errors at all on any port.
by Cha0s
Thu Jan 17, 2019 2:47 am
Forum: Announcements
Topic: SwOS version 2.9 released!
Replies: 72
Views: 34457

Re: SwOS version 2.9 released!

Upgrading from 2.8 to 2.9 on a CSS106-5G-1S causes severe traffic drop between 1G ports and 100Mbit ports. It's random from 0 to 40Mbps.
Reverting back to 2.8 traffic increased back to steady 100Mbps.
by Cha0s
Wed Jan 16, 2019 8:19 pm
Forum: Announcements
Topic: SwOS version 2.9 released!
Replies: 72
Views: 34457

Re: SwOS version 2.9 released!

Same here
by Cha0s
Thu Jan 03, 2019 2:11 pm
Forum: Beginner Basics
Topic: RB4011iGS+5HacQ2HnD-IN-US first time troubles
Replies: 14
Views: 2259

Re: RB4011iGS+5HacQ2HnD-IN-US first time troubles

I did as much reading as I could both with the sparse supplied docs and what was online before and during my efforts!! I have winbox v3.18, I fail to see a safe mode. FWIW, been doing router stuff etc. since 1989 but I am not an "IT Professional" Everything about RouterOS is documented here: https:...
by Cha0s
Thu Jan 03, 2019 11:39 am
Forum: Wireless Networking
Topic: Redirect traffic from specific device to another local ip
Replies: 7
Views: 787

Re: Redirect traffic from specific device to another local ip

Maybe something link this (to accommodate for the time requirements). /ip firewall nat add chain=dstnat src-address=192.168.1.116 time=22h-7h,sun,mon,tue,wed,thu,fri,sat action=dst-nat to-addresses=192.168.1.20 Also, this thread needs to be moved to some other category. It has nothing to do with wir...
by Cha0s
Wed Jan 02, 2019 6:00 pm
Forum: Forwarding Protocols
Topic: BGP aggregation example
Replies: 1
Views: 1326

Re: BGP aggregation example

You can add all the prefixes (/22, /23, /24) in Routing > BGP > Networks. And then use separate filters on each peer to filter out which of those prefixes will be announced to each BGP peer. I suggest you first create the filters, apply them to the BGP peers and then add the more specific prefixes t...
by Cha0s
Wed Jan 02, 2019 8:33 am
Forum: RouterBOARD hardware
Topic: CCR-1036 Touchscreen frame break and noisy fan [SOLVED]
Replies: 2
Views: 957

Re: CCR-1036 Touchscreen frame break and noisy fan [SOLVED]

3. Cannot find my router in Netinstall. Ethernet cable to Ether1 slot from my laptop, no other network connection and strictly follow instruction.
Try connecting to port 12 instead of port1.
viewtopic.php?p=399474#p399474
by Cha0s
Mon Dec 31, 2018 9:25 pm
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 44013

Re: v6.43.8 [stable] is released!

Thanks! That resolved the issue!
by Cha0s
Sun Dec 30, 2018 12:23 am
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 44013

Re: v6.43.8 [stable] is released!

Just to clarify (if anyone else wants/can reproduce this), the config regarding the virtual wlan interfaces was, 1 virtual wlan interface per physical wlan (one for 2.4GHz and one for 5GHz) both added to a bridge.
by Cha0s
Sun Dec 30, 2018 12:21 am
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 44013

Re: v6.43.8 [stable] is released!

Symbol: ` in WLAN SSID brake all wlan interfaces. Or even not a symbol, but a virtual WLAN. When I create a virtual WLAN and reboot hap ac^2, I don't see all interfaces and export doesn't work in the console. DimaFIX - Please send supout.rif file from your router to support@mikrotik.com. If I add s...
by Cha0s
Thu Dec 27, 2018 12:24 pm
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 44013

Re: v6.43.8 [stable] is released!

Symbol: ` in WLAN SSID brake all wlan interfaces. Or even not a symbol, but a virtual WLAN. When I create a virtual WLAN and reboot hap ac^2, I don't see all interfaces and export doesn't work in the console. DimaFIX - Please send supout.rif file from your router to support@mikrotik.com. If I add s...
by Cha0s
Fri Dec 14, 2018 4:40 pm
Forum: Announcements
Topic: Product comparison matrix
Replies: 30
Views: 11227

Re: Product comparison matrix

The column sorting is done in the browser with Javascript, not in the database. I am just saying that sorting, the way it works now, it's pretty much useless on fields that do not contain plain numbers. If I want to sort by memory or cpu frequency the results are all over the place. Also if that's n...
by Cha0s
Fri Dec 14, 2018 3:19 pm
Forum: Announcements
Topic: Product comparison matrix
Replies: 30
Views: 11227

Re: Product comparison matrix

Very nice!

Column sorting is a bit of a mess (nothing is sorted properly, except for columns with plain numbers), but we can live with it :P
by Cha0s
Thu Dec 06, 2018 9:23 am
Forum: Beginner Basics
Topic: internal server error message and shutdown times
Replies: 1
Views: 509

Re: internal server error message and shutdown times

How long does RouterOS take to shut down typically? I cannot find any indication of the progress once shutdown has been initiated? How vital it is to always shut down a unit properly (referring to SXT-LTE)
It takes just a few seconds. You don't really need to shut it down before removing power.
by Cha0s
Mon Dec 03, 2018 12:31 pm
Forum: General
Topic: IP > Cloud stuck on 'updating'
Replies: 18
Views: 5594

Re: IP > Cloud stuck on 'updating'

The problem occurred on both updated devices with the new cloud service and old devices with the old cloud service.

It just started to work the next day. But only after it caused havoc on vpns and other stuff that were based on ddns.
by Cha0s
Fri Nov 30, 2018 1:14 am
Forum: General
Topic: IP > Cloud stuck on 'updating'
Replies: 18
Views: 5594

Re: IP > Cloud stuck on 'updating'

Yes, I just checked from other locations/ISPs too and it won't update.
by Cha0s
Fri Nov 30, 2018 12:48 am
Forum: General
Topic: IP > Cloud stuck on 'updating'
Replies: 18
Views: 5594

IP > Cloud stuck on 'updating'

After a long lasting power failure at the power company, when the router came back up it will not update its ddns via IP>Cloud. It is stuck on 'updating...' for well over two hours and does not actually ever update its ddns. Screenshot_8.png The router is an hAP ac^2 running v6.43.4 The router can r...
by Cha0s
Mon Nov 26, 2018 12:22 pm
Forum: Beginner Basics
Topic: Advertising with Mikrotik
Replies: 4
Views: 744

Re: Advertising with Mikrotik

For SSL/TLS enabled websites, you definitely cannot inject advertisements (or anything else for that matter).
Regardless of which hotspot vendor you use (thankfully it's a protocol security measure, not a vendor limitation).
by Cha0s
Mon Nov 26, 2018 12:17 pm
Forum: RouterBOARD hardware
Topic: LoRaWAN support
Replies: 57
Views: 17085

Re: LoRaWAN support

those use routeros, https://lorrier.com/ The LoRaWAN part is implemented with BeagleBones using the SPI bus. They use ROS only for the networking part, behind the BeagleBones. The gateway is based on iC880a LoRaWAN™ concentrator by IMST which uses Semtech SX1301 base band processor designed for use...
by Cha0s
Fri Nov 09, 2018 1:41 pm
Forum: General
Topic: SSTP Mikrotik Client / probably bug 6.41.3
Replies: 3
Views: 1406

Re: SSTP Mikrotik Client / probably bug 6.41.3

It just happened to me on one of my SSTP VPNs with version 6.34.4.

I get the same error in the logs. 'nonce not matching'
by Cha0s
Mon Oct 22, 2018 5:27 pm
Forum: RouterBOARD hardware
Topic: Wierdly Bricked RB912UAG-2HPnD
Replies: 2
Views: 885

Re: Wierdly Bricked RB912UAG-2HPnD

Try reinstalling the OS by doing a Netinstall.
https://wiki.mikrotik.com/wiki/Manual:Netinstall
by Cha0s
Thu Oct 18, 2018 12:52 pm
Forum: Announcements
Topic: v6.43.4 [stable] is released!
Replies: 78
Views: 28536

Re: v6.43.4 [stable] is released!

*) ipsec - allow multiple peers to the same address with different local-address (introduced in v6.43);
Thanks for including this fix.
It works ok now :)
by Cha0s
Sun Oct 07, 2018 9:54 pm
Forum: General
Topic: Unable to get full gigabit speed on RB750Gr3
Replies: 33
Views: 8214

Re: Unable to get full gigabit speed on RB750Gr3

So now my problem would be whether I need a better model.
No, you don't need a better model. You need to configure FastTrack and you will able to reach 1Gbps.
by Cha0s
Sun Oct 07, 2018 3:10 pm
Forum: General
Topic: Unable to get full gigabit speed on RB750Gr3
Replies: 33
Views: 8214

Re: Unable to get full gigabit speed on RB750Gr3

Hello, Based on your setup, you may get less than gig. If you look at the gr3 specs, you'll see that with filters and bridges, throughput goes down depending on packet size. Regards Sent from Tapatalk Is there anything I can do to get the full speed on RB750Gr3? I am keeping the minimum setting as ...
by Cha0s
Sat Oct 06, 2018 7:22 pm
Forum: General
Topic: FastNetMon Integration with MikroTik (DDoS detection software)
Replies: 41
Views: 17595

Re: FastNetMon Integration with MikroTik (DDoS detection software)

Hi, Which is the best current configuration to the Mikrotik integration with FastNetMon? I'm using those: * Cache entries = 128k * Active Flow Timeout = 00:01:00 * Inactive Flow Timeout = 00:01:00 Netflow version = 9 Template refresh = 30 Template timeout = 30 FastNetMon is receiving data correctly...
by Cha0s
Sat Oct 06, 2018 1:56 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 48244

Re: v6.43.1 [stable] and v6.43.2 [stable] are released!

After upgrading to 6.43.2 from 6.42.7 you can no longer have multiple IPsec peers to the same destination IP but with different source addresses. This regression is said to be fixed in 6.44beta14. Please check the change log in the post here . And I'd expect this kind fix to be merged to 6.42.x lat...
by Cha0s
Fri Oct 05, 2018 10:53 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 48244

Re: v6.43.1 [stable] and v6.43.2 [stable] are released!

After upgrading to 6.43.2 from 6.42.7 you can no longer have multiple IPsec peers to the same destination IP but with different source addresses. Screenshot_17.png This worked fine on 6.42.7. What's the reasoning behind this restriction? I need multiple peers to the same destination but using differ...
by Cha0s
Sat Sep 29, 2018 8:59 pm
Forum: General
Topic: Feature requests
Replies: 1216
Views: 261745

Re: Feature requests

Sure, So next time you login to your web-banking do not check for TLS. Just go blindly with http. Don't even check if you typed the correct domain or weather you got hijacked and redirected to another domain. What's the point anyway? Too many parties involved! :facepalm: People, it's 2018. Not 1996....
by Cha0s
Sat Sep 29, 2018 6:09 pm
Forum: General
Topic: Feature requests
Replies: 1216
Views: 261745

Re: Feature requests

Why shame? Because there is no excuse anymore for any service to run without TLS. Certificates are free (if not dirt cheap for those that don't - for whatever reason - like Let's Encrypt). Why should any entity between the router and the update server even need to know what is being downloaded? TLS...
by Cha0s
Sat Sep 29, 2018 1:47 pm
Forum: General
Topic: Feature requests
Replies: 1216
Views: 261745

Re: Feature requests

Well, as I can see, you just create static DNS entry on the router "upgrade.mikrotik.com" with the IP of your server, then run HTTP server on that IP, serving one-line files "/routeros/LATEST.(6|6fix|6rc|7)" containing "$VERSION $TIMESTAMP" (for example, "1.0 1"). Then create "/routeros/$VERSION" d...
by Cha0s
Tue Sep 25, 2018 2:18 pm
Forum: Beginner Basics
Topic: Block HTTPS [SOLVED]
Replies: 3
Views: 891

Re: Block HTTPS [SOLVED]

There is no way to present your message saying that the page is blocked. Besides encryption, the point of https is authenticity. If you could modify what the user could see then anyone could modify any https page leading to terrible security issues. So, no. Unless you create your own CA and install ...
by Cha0s
Tue Sep 25, 2018 10:52 am
Forum: General
Topic: Feature Request: IPv6 NAT support
Replies: 8
Views: 3804

Re: Feature Request: IPv6 NAT support

And another interesting thread on the subject viewtopic.php?t=110925
by Cha0s
Tue Sep 25, 2018 10:47 am
Forum: General
Topic: Feature Request: IPv6 NAT support
Replies: 8
Views: 3804

Re: Feature Request: IPv6 NAT support

+1
I've requested this back in 2014.
viewtopic.php?f=19&t=90564
by Cha0s
Thu Sep 20, 2018 3:23 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 109982

Re: Winbox vulnerability: please upgrade

So, us, professional users of ROS, that use it every day, should have to get stupid warnings, because of dummy users that mess up their firewall and never even bother to login to their routers ever again. Who exactly will this message be for then? Please. Stop trying to convert RouterOS to a 'DummyO...
by Cha0s
Thu Sep 20, 2018 2:46 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 109982

Re: Winbox vulnerability: please upgrade

Everything outside default protection rules. It should be only warning, nothing else.
So, everyone else that does not use the default firewall will get annoying warnings about a supposedly insecure firewall configuration?
by Cha0s
Thu Sep 20, 2018 12:40 am
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 104573

Re: v6.44beta [testing] is released!

Thanks! :)
by Cha0s
Wed Sep 19, 2018 10:30 am
Forum: General
Topic: NTFS support
Replies: 34
Views: 7816

Re: NTFS support

Stop the use of the bundle package
+1

I don't see any benefit with the bundle package. It only confuses people.
by Cha0s
Wed Sep 19, 2018 10:29 am
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 104573

Re: v6.44beta [testing] is released!

I have set up automated exports and the output is saved in version control system, so I know what exactly changed and when.
Can you give more info on your setup/workflow?
I am interested in implementing something similar.

Thanks.
by Cha0s
Wed Sep 19, 2018 10:27 am
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 109982

Re: Winbox vulnerability: please upgrade

I think its unfair to call Mikrotik bone-heads in this case, as they are also saying no to the automatic upgrades. :lol: I don't think he meant Mikrotik but the likes of Microsoft and their stupid forced updates. Another example is Dropbox. It upgrades whenever it feels like it. No notification, no...
by Cha0s
Tue Sep 18, 2018 5:38 pm
Forum: General
Topic: NTFS support
Replies: 34
Views: 7816

Re: NTFS support

I vote NO NTFS, and I also vote to remove SMB, or at least make it a package that I can remove. Better yet, move all of the "home user" features into a separate package so that us enterprise customers don't have to have that type of stuff in our routers. I vote +1 for making all SOHO features a sep...
by Cha0s
Mon Sep 17, 2018 4:37 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 109982

Re: Winbox vulnerability: please upgrade

Tesla Car should go to a safe place/shop in auto mode, stop, do the critical updade, notify the client and contact tesla support to check with the client has we are talking about a 160.000€ car .... what do you think ? I think that I wouldn't want my 160.000€ car to stop whenever it feels like it s...
by Cha0s
Thu Sep 13, 2018 10:43 am
Forum: General
Topic: [Feature Request] sFlow
Replies: 11
Views: 3356

Re: [Feature Request] sFlow

Not true.

There is a software implementation that works on Linux.
https://sflow.net/about.php
by Cha0s
Wed Sep 05, 2018 10:44 pm
Forum: General
Topic: IPv6 intermittent timeouts to random IPs
Replies: 10
Views: 1963

Re: IPv6 intermittent timeouts to random IPs

Also, after the netinstall, I configured everything manually, I didn't restore the configuration from a backup just to make sure that the 'problem' was not restored with it. But it didn't make any difference.
by Cha0s
Wed Sep 05, 2018 10:33 pm
Forum: General
Topic: IPv6 intermittent timeouts to random IPs
Replies: 10
Views: 1963

Re: IPv6 intermittent timeouts to random IPs

I still haven't found any solution. I did a netinstall and the problem persists. As a temporary workaround I've set up a VM with MikroTik which acts as the router for IPv6. So I have a static route from the CCRs to that VM via a physical interface instead of the VLAN interfaces, and then I have the ...
by Cha0s
Fri Aug 31, 2018 12:46 pm
Forum: Scripting
Topic: How to ***really*** block invalid TCP and UDP packet
Replies: 43
Views: 40424

Re: How to ***really*** block invalid TCP and UDP packet

Well,

You are the expert. Why don't you explain it to us then?
by Cha0s
Wed Aug 29, 2018 2:23 am
Forum: RouterBOARD hardware
Topic: Combating Rogue DHCP Servers
Replies: 3
Views: 1934

Re: Combating Rogue DHCP Servers

There's also an "Alerts" section in DHCP Server which can monitor for rogue DHCP servers and alert you. https://wiki.mikrotik.com/wiki/Manual:IP/DHCP_Server#Alerts It also allows for "On Alert" scripting which could be used to disable the offending ports or apply firewall rules. There's a relevant p...
by Cha0s
Wed Aug 29, 2018 2:08 am
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 1606

Re: Suggestion: simple speed limiter

Have you tried TP-Link or D-Link?

I am sure they are much easier with all their wizards whistles and bells.

If you find RouterOS hard, then it's probably not for you.
by Cha0s
Sat Aug 25, 2018 2:11 pm
Forum: General
Topic: Forgot My Mikrotik Winbox Password and Need to Recover it without Backup Configuration File
Replies: 7
Views: 23285

Re: Forgot My Mikrotik Winbox Password and Need to Recover it without Backup Configuration File

If your RouterOS version is between 6.29 and 6.42 you might be able to get a list of all users/passwords using this exploit: https://github.com/BigNerd95/WinboxExploit
by Cha0s
Sat Aug 25, 2018 2:07 pm
Forum: General
Topic: Suggestion for improved ROS update/upgrade process
Replies: 4
Views: 1258

Re: Suggestion for improved ROS update/upgrade process

This has been asked many times since the new routerboot firmware versioning but it has been ignored.
by Cha0s
Sat Aug 25, 2018 1:59 pm
Forum: Announcements
Topic: v6.42.7 [current] is released!
Replies: 159
Views: 36932

Re: v6.42.7 [current] is released!

I noticed that interface "last link up/down times" are in the future.
interface up-down wrong time.png
by Cha0s
Thu Aug 23, 2018 12:16 pm
Forum: Announcements
Topic: v6.42.7 [current] is released!
Replies: 159
Views: 36932

Re: v6.42.7 [current] is released!

Sigh.... I give up.
by Cha0s
Thu Aug 23, 2018 12:11 pm
Forum: Announcements
Topic: v6.42.7 [current] is released!
Replies: 159
Views: 36932

Re: v6.42.7 [current] is released!

August 20?

So 6.42.7 does NOT contain a fix? Because the build time is Aug/17/2018 09:48:44.
by Cha0s
Thu Aug 23, 2018 12:07 pm
Forum: Announcements
Topic: v6.42.7 [current] is released!
Replies: 159
Views: 36932

Re: v6.42.7 [current] is released!

I can confirm that the security fixes were added to the notes after the 6.42.7 thread was already posted! Why was this? https://i.imgur.com/dN9k4D4.png This is bad. I check for updates every day on this forum. The day this release was posted, I read the full changelog and there was nothing of conce...
by Cha0s
Wed Aug 15, 2018 4:47 pm
Forum: Beginner Basics
Topic: Understanding Default config: bridge
Replies: 4
Views: 4641

Re: Understanding Default config: bridge

The bridge does what it says. It bridges multiple ports/interfaces together. It's pretty much a "software switch". https://en.wikipedia.org/wiki/Bridging_(networking) In this instance it will take all interfaces (except the first one) and make them act as a switch so all of them can communicate with...
by Cha0s
Wed Aug 15, 2018 4:39 pm
Forum: Beginner Basics
Topic: Cannot block specific website
Replies: 5
Views: 806

Re: Cannot block specific website

Another way would be to create an address list, add there the domains you want to block and then create a drop filter rule using that address list as the destination. I believe this is the less resource hungry solution. No need to open any packet to check anything (TLS or otherwise), and you are act...
by Cha0s
Wed Aug 15, 2018 4:36 pm
Forum: Beginner Basics
Topic: One IP Public Multiple Webserver
Replies: 4
Views: 2395

Re: One IP Public Multiple Webserver

Hi, You just need to write Destination-nat for those servers with different port number and specify the DNS records in your ip/dns/static for those two servers then you can open it from outside with one public ip address. (You just need to know about destination nat and PAT-port address translation...
by Cha0s
Wed Aug 15, 2018 4:27 pm
Forum: Beginner Basics
Topic: Updating old versions of RouterOS [SOLVED]
Replies: 3
Views: 972

Re: Updating old versions of RouterOS [SOLVED]

In my experience, if you upgrade from (much) older versions using System > Packages > 'Check for updates' menu (ie: not manually uploading the packages to the router), it will first upgrade to an intermediate version and then you have to perform another upgrade to get to the latest version. I haven'...
by Cha0s
Wed Aug 15, 2018 4:07 pm
Forum: General
Topic: [Bug] "Interface doesn't exist " error box, but it does.
Replies: 1
Views: 458

Re: [Bug] "Interface doesn't exist " error box, but it does.

Yeap, I've seen this too.

But I think it is solved by 6.42.5. I haven't seen it for a while now.
by Cha0s
Wed Aug 15, 2018 3:55 pm
Forum: General
Topic: New IP cloud is coming.
Replies: 84
Views: 31911

Re: New IP cloud is coming.

Currently is easy to make a brute force search for mikrotik devices using the cloud service as the names follow an simple pattern and is just an DNS query. The serial number consists of 12 hexadecimal characters. I wouldn't call making 184884258895036416 (12^16) dns lookups 'easy'. It's easier to j...
by Cha0s
Tue Aug 14, 2018 5:00 pm
Forum: Announcements
Topic: Security announcement blog
Replies: 120
Views: 46636

Re: Security announcement blog

To go to a HTTPS page you most of the time need a initiate that on http. Those days are almost gone. HSTS Plus, all major browsers have their own predefined list of major websites that support https and will connect only to https even if you only type the domain in the address bar. https://hstsprel...
by Cha0s
Thu Aug 02, 2018 6:49 pm
Forum: Announcements
Topic: Security announcement blog
Replies: 120
Views: 46636

Re: Security announcement blog

Yes we have to start somewhere. How about users start to read how networks work and don't make stupid mistakes like disabling a firewall? Where to start.... You talk about doing MITM essentially to modify forwarded traffic. That's preposterous! And what about TLS? Everything moves to TLS. Doing it o...
by Cha0s
Thu Aug 02, 2018 5:38 pm
Forum: General
Topic: Remove all packages and reinstall [SOLVED]
Replies: 5
Views: 1475

Re: Remove all packages and reinstall [SOLVED]

Try downgrading to an older version by manually uploading only the packages you want. After uploading you hit the 'downgrade' button on the Systems > Packages window It should downgrade and remove all other packages. After that, you can then use System > Packages > Check for updates to upgrade to th...
by Cha0s
Thu Aug 02, 2018 3:03 pm
Forum: Announcements
Topic: Security announcement blog
Replies: 120
Views: 46636

Re: Security announcement blog

RouterOS calls home each day or week to check if there is something wrong. If so every http session gets a page displayed that an update is needed because the router is below the minimal required version. If ignored then after two weeks the router only functions when you are initiating an update. A...
by Cha0s
Thu Aug 02, 2018 2:58 pm
Forum: General
Topic: IPv6 intermittent timeouts to random IPs
Replies: 10
Views: 1963

Re: IPv6 intermittent timeouts to random IPs

So far I've narrowed down this to VLANs. Using IPv6 on normal interfaces works without any packet lost. Using IPv6 on VLAN interfaces (under an sfp+ interface - if it somehow makes any difference) will cause random packet loss to random IPs. It's like the neighbor solicitation/advertisement packets ...
by Cha0s
Thu Aug 02, 2018 2:22 pm
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 34886

Re: Winbox v3.16 released!

It's monstrous! You're kidding, right? I have never seen people that you say "You have shit on pants" and he said "they are new and clean." I just said about the manufacturer's oversight, and you're proving to me that everything is perfectly well thought out. Hilarious. (On salary in Mikrotik?) In ...
by Cha0s
Wed Aug 01, 2018 3:46 pm
Forum: Announcements
Topic: Security announcement blog
Replies: 120
Views: 46636

Re: Security announcement blog

I also never received an email about the winbox exploit. Mikrotik claims to have sent it, does anyone actually have a copy of it?
Same here. I only got an e-mail on March 29th about the www vulnerability. Never for the winbox vulnerability.
by Cha0s
Fri Jul 27, 2018 6:29 pm
Forum: Forwarding Protocols
Topic: BGP no active routes with low as path
Replies: 4
Views: 824

Re: BGP no active routes with low as path

By default ignore-as-path-len it's enable in instance.
ignore-as-path length is not enabled by default.
by Cha0s
Fri Jul 27, 2018 5:31 pm
Forum: Forwarding Protocols
Topic: BGP no active routes with low as path
Replies: 4
Views: 824

Re: BGP no active routes with low as path

I feel this whole post if out of context.

Post your routing filters (using proper export: /routing filters export - not just print).

And describe your problem more accurately.
What do you expect to happen, and what actually happens.
by Cha0s
Fri Jul 27, 2018 5:24 pm
Forum: Wireless Networking
Topic: Removing Mikrotik elements from beacons
Replies: 15
Views: 3485

Re: Removing Mikrotik elements from beacons

I agree. +1
by Cha0s
Wed Jul 25, 2018 8:59 pm
Forum: General
Topic: FastNetMon Integration with MikroTik (DDoS detection software)
Replies: 41
Views: 17595

Re: FastNetMon Integration with MikroTik (DDoS detection software)

[IP] [data_direction] [pps_as_string] [action]
by Cha0s
Wed Jul 25, 2018 5:07 pm
Forum: General
Topic: FastNetMon Integration with MikroTik (DDoS detection software)
Replies: 41
Views: 17595

Re: FastNetMon Integration with MikroTik (DDoS detection software)

Hi I just try to run ./notify_about_attack.sh and I get the fallowing error on "fastnetmon_mikrotik.php"; MikroTik's API Integration for FastNetMon - Ver: 1.0 missing argumentsphp fastnetmon_mikrotik.php [IP] [data_direction] [pps_as_string] [action] Any idea? You cannot run this script without the...
by Cha0s
Sat Jul 21, 2018 4:43 am
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 2771

Re: Please add numbers on Y-axis in Bandwidth Test

Adding min/max values as shown in the screenshot-mockup on post #9 is easy in principle. They already have all the points drawn in the chart along with each point's value (otherwise we couldn't click on the chart and get each point's value number), so they just need to take the lowest and the highes...
by Cha0s
Sat Jul 21, 2018 4:04 am
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 2771

Re: Please add numbers on Y-axis in Bandwidth Test

It's not a matter of which window. Every window that has a chart is the same. You essentially have minimum and maximum values for all the points in the chart (not points not currently shown in the chart). It's a matter of what you view (range) in the graph at any given moment. That's the data from w...
by Cha0s
Fri Jul 20, 2018 5:06 pm
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 2771

Re: Please add numbers on Y-axis in Bandwidth Test

Firstly, there is no real reason for "min" value as it is always zero. Of course there is a reason for min value. It's not always zero. You are not thinking this through. If for example you have constant traffic between 2 and 10 mbps, then the min value for that traffic at that time will not be zer...
by Cha0s
Thu Jul 19, 2018 7:50 pm
Forum: Forwarding Protocols
Topic: Routing filter order
Replies: 11
Views: 4489

Re: Routing filter order

When you add a new rule it is added at the bottom by default, when you do not want it there (because it has to be processed somewhere between the existing rules) you can move it, but that move will not make the software re-process the filters, as it should. Disable/enable does that. This is the sou...
by Cha0s
Thu Jul 19, 2018 6:04 pm
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 2771

Re: Please add numbers on Y-axis in Bandwidth Test

we need more than one number, we need a few numbers (at least two - at the bottom and at the top)image_bt_num.png
I agree that having the min-max values shown at all times is useful .
by Cha0s
Thu Jul 19, 2018 5:07 pm
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 34886

Re: Winbox v3.16 released!

On Win7 x64 the problems exist.
by Cha0s
Thu Jul 19, 2018 4:57 pm
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 34886

Re: Winbox v3.16 released!

Yeah, the bug is present in many places. IPv6 static routes with link-local gateways will cause 100% cpu and disconnect. Editing and EoIP tunnel and setting the MTU (when not already set) will cause 100% cpu and disconnect. Copying an SSTP Client interface will cause 100% cpu and disconnect. Copying...
by Cha0s
Tue Jul 17, 2018 5:55 pm
Forum: Beginner Basics
Topic: NetFlow Project
Replies: 2
Views: 622

Re: NetFlow Project

Any xDSL modem that can work in bridge mode, can work with MikroTik.

AFAIK USB modems are not supported.
by Cha0s
Tue Jul 17, 2018 4:32 pm
Forum: General
Topic: Feature requests
Replies: 1216
Views: 261745

Re: Feature requests

Netinstall for Linux, or documentation of the netinstall process so it can be programmed for Linux by someone else.
+1

Also it would be nice if a MikroTik installation itself can be a netinstall server for another RouterBoard.
by Cha0s
Tue Jul 17, 2018 3:39 pm
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 34886

Re: Winbox v3.16 released!

Since v3.15 when opening a static IPv6 route that has a link-local gateway causes 100% cpu usage on winbox using Win7 x64. Have the same symptom here in the CAPsMAN Channel-List. Sometimes when copying channel and editing either frequency name or other items for that channel, the dialog freezes and...
by Cha0s
Mon Jul 16, 2018 7:38 pm
Forum: General
Topic: Dual uplinks means dual public IPs
Replies: 3
Views: 578

Re: Dual uplinks means dual public IPs

Set up a MikroTik (CHR or x86) on a datacenter somewhere, then create tunnels from the location to the datacenter. 1 tunnel per uplink. Then route all the traffic via the tunnels and eventually via the gateway of the datacenter router. If uplink1 is down, then the traffic can failover via uplink2. T...
by Cha0s
Mon Jul 16, 2018 5:10 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 vs RB450Gx4
Replies: 50
Views: 15849

Re: RB850Gx2 vs RB450Gx4

Metarouter does not work on RB850Gx2.
The menu is actually there in Winbox, but it doesn't work? Never tried it since I don't need it at that site.
It doesn't work.
by Cha0s
Mon Jul 16, 2018 3:56 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 vs RB450Gx4
Replies: 50
Views: 15849

Re: RB850Gx2 vs RB450Gx4

I should have said that I'd like to use MetaROUTER, which I think is not possible on arm yet? Does it work on PPC?

You can't always have it all I suppose.
Metarouter does not work on RB850Gx2.
by Cha0s
Sun Jul 15, 2018 10:50 am
Forum: General
Topic: Weird Router RB951 [SOLVED]
Replies: 11
Views: 1317

Re: Weird Router RB951 [SOLVED]

I highly doubt that none of them work. You are doing something wrong.
by Cha0s
Sun Jul 15, 2018 5:32 am
Forum: General
Topic: Weird Router RB951 [SOLVED]
Replies: 11
Views: 1317

Re: Weird Router RB951 [SOLVED]

Is there any way to make a COMPLETE reset of the router to a REAL factory reset? For a complete re-install of the OS (ie: format) you need to do a netinstall. https://wiki.mikrotik.com/wiki/Manual:Netinstall For a full configuration reset (without re-installing the OS - but it will reset everything...
by Cha0s
Fri Jul 13, 2018 6:30 pm
Forum: General
Topic: IPv6 intermittent timeouts to random IPs
Replies: 10
Views: 1963

Re: IPv6 intermittent timeouts to random IPs

So that could be an ND issue... Check what is happening in IPv6->Neighbors (interestingly, the menus "ND" and "Neighbors" are swapped in IPv6) ND is disabled. Neighbors doesn't show anything useful apart from status 'failed' when an IP is not reachable. At the same time, the same exact configuratio...
by Cha0s
Fri Jul 13, 2018 6:12 pm
Forum: General
Topic: IPv6 intermittent timeouts to random IPs
Replies: 10
Views: 1963

Re: IPv6 intermittent timeouts to random IPs

When you say "clients cannot ping the router", do you mean clients at your local network or clients elsewhere on the internet?
I mean local clients (servers) behind the router cannot ping the router (gateway).
They can ping each other (those under the same prefix of course).
by Cha0s
Fri Jul 13, 2018 12:57 am
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 557
Views: 132652

Re: v6.43rc [release candidate] is released!

For example, DHCPv6 issue could lead to DHCPv6 service crash (can be seen only by MikroTik staff) and IPv6 services could not work or work incorrectly.
Could this, by any remote chance, be related to the issue described here?
DHCP is installed/enabled but not used at all on both ipv4/ipv6.
by Cha0s
Wed Jul 11, 2018 6:08 pm
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 34886

Re: Winbox v3.16 released!

I would welcome when the winbox-router connection is a little more patient in cases of network loss. With brief network interrups, like an intermediate router rebooting or an access point re-associating or a PPPoE connection being re-made, the open winbox windows all fall back to the connection scr...
by Cha0s
Mon Jul 09, 2018 5:55 pm
Forum: Forwarding Protocols
Topic: Routing filter order
Replies: 11
Views: 4489

Re: Routing filter order

This had me scratching my head for a while. Although you might re-order the rules, the new order is not active. However, if you 'enable' a rule in a filter chain (even if it is already 'enabled') it causes the chain to be flushed and re-applied in the correct (new) order. Maybe Mikrotik can add thi...
by Cha0s
Mon Jul 09, 2018 5:24 pm
Forum: General
Topic: IPv6 intermittent timeouts to random IPs
Replies: 10
Views: 1963

IPv6 intermittent timeouts to random IPs

I have a setup in a datacenter running 2 CCR1036 in an active/standby setup. Both CCRs have identical configuration and use VRRP for the failover. This setup has been in use for over 4 years (an I suspect the problem I will describe is that old too) Everything works perfectly fine except IPv6. When ...
by Cha0s
Sun Jul 08, 2018 7:12 pm
Forum: General
Topic: DNSSEC
Replies: 33
Views: 13149

Re: DNSSEC

such as when you need to force some domain resolve into specific IP?
Ever heard of hosts file?
by Cha0s
Thu Jul 05, 2018 3:46 pm
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 34886

Re: Winbox v3.16 released!

Since v3.15 when opening a static IPv6 route that has a link-local gateway causes 100% cpu usage on winbox using Win7 x64. With a global address as gateway there is not cpu usage. In the meantime everything stops updating in Winbox (all other windows don't show new info) If I leave it open for over ...
by Cha0s
Tue Jul 03, 2018 2:46 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 29229

Re: v6.42.5 [current]

And at last.... Before 6.42.1-4, any of hEX has more than 4mb... anyway
I agree. On my devices that have 16MB flash, they have ~7.5MiB free, not 4.8MiB.
by Cha0s
Mon Jul 02, 2018 5:56 pm
Forum: Forwarding Protocols
Topic: BGP Community [SOLVED]
Replies: 2
Views: 1039

Re: BGP Community [SOLVED]

/routing bgp advertisements print _PEER_NAME_ detail
You will get output like:
 peer="_PEER_NAME_" prefix=x.x.x.x/y nexthop=.z.z.z.z origin=igp communities=1234:666
Or you can use winbox.
Routing > BGP > Advertisements, and there select the column BGP Communities.
by Cha0s
Sat Jun 30, 2018 6:37 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 29229

Re: v6.42.5 [current]

I have to admit that Nv2 has been improved, but are you going to implement a madder TDMA protocol? I have co-workers that say "If you have 100Mbps on an AP and 100 clients connected, with TDMA you can give 100Mbps to them all simultaneously, slowing latency", I know that this is pure theory, but in...
by Cha0s
Sat Jun 30, 2018 6:03 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 29229

Re: v6.42.5 [current]

Did that Groove have the lost space issue?
Obviously. Why would I try it on a device that has no problem?
by Cha0s
Sat Jun 30, 2018 3:55 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 29229

Re: v6.42.5 [current]

Indeed the patch does not work! I tried it on a 2-partition CCR1009 (before reading other remarks). First copied partition containing 6.42.1, updated it to 6.42.5 which resulted in lost space issue as usual, then uploaded patch and rebooted, router came back but it has switched active partition bac...
by Cha0s
Fri Jun 29, 2018 4:52 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 29229

Re: v6.42.5 [current]

Guys, be careful with this patch!!! I uploaded it to a test CCR1016 and it doesn't come up after reboot! Test it first! I tested it on a Groove and worked. I haven't tried it on any other device. @Mikrotik: will this patch be included automatically on next ROS updates so we can avoid the extra rebo...
by Cha0s
Fri Jun 29, 2018 4:41 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 29229

Re: v6.42.5 [current]

Cha0s - Is it possible that you added EoIP tunnels from old Winbox version? I created the tunnels via CLI. Upgrading or rebooting the router loses the hostname in the remote address field and leaves an old/previously resolved IP. Never mind. It was my mistake. :oops: A combination of a forgotten cu...
by Cha0s
Fri Jun 29, 2018 4:31 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 29229

Re: v6.42.5 [current]

Thank you very much for the reports about issues with space, next RouterOS version will fix the issue. Meanwhile this package can be used to clear space on your router, https://www.mikrotik.com/download/share/fix_space.npk - upload package to your router; - run /system reboot It works on every boar...
by Cha0s
Thu Jun 28, 2018 3:51 pm
Forum: The Dude
Topic: A VPS to run Dude
Replies: 19
Views: 4349

Re: A VPS to run Dude

All major hypervisors support ova templates I was talking about providers. Hypevisors may support a million things. That doesn't mean that all features are exposed to end users by cloud providers. Cloud providers have very restrictive policies as to what you can run and how you can install new OSes...
by Cha0s
Thu Jun 28, 2018 2:38 pm
Forum: The Dude
Topic: A VPS to run Dude
Replies: 19
Views: 4349

Re: A VPS to run Dude

Anyway, if normis or whoever from mikrotik by any chance read this, why there can't be CHR ISO installer? Why is there always another format desired? I am very happy that OVA was added and I installed my Dude test VM from there. (only to play with it, I don't really use it in production) Because wh...
by Cha0s
Thu Jun 28, 2018 2:19 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 29229

Re: v6.42.5 [current]

Cha0s - Is it possible that you added EoIP tunnels from old Winbox version?
I created the tunnels via CLI. Upgrading or rebooting the router loses the hostname in the remote address field and leaves an old/previously resolved IP.
by Cha0s
Wed Jun 27, 2018 5:31 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 29229

Re: v6.42.5 [current]

Again no fix for the diskspace loss when upgrading from 6.42.1 on CCR? (and maybe others) Why are these releases rushed out when known showstopping bugs exist? I can confirm the problem. pe1chl, didn't you get the memo? Kid control fixes are WAY more important than (eventually) "bricking" our route...
by Cha0s
Wed Jun 27, 2018 5:25 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 29229

Re: v6.42.5 [current]

After rebooting, all EoIP tunnels that used dns hostname for remote address were replaced with IPs. I have to manually edit all EoIP tunnels and set the hostnames again. That happened on a couple of RB2011 and a couple of hAP AC^2. On various x86 installations the issue didn't occur. This problem di...
by Cha0s
Wed Jun 27, 2018 5:03 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 29229

Re: v6.42.5 [current]

Again no fix for the diskspace loss when upgrading from 6.42.1 on CCR? (and maybe others) Why are these releases rushed out when known showstopping bugs exist? I can confirm the problem. pe1chl, didn't you get the memo? Kid control fixes are WAY more important than (eventually) "bricking" our route...
by Cha0s
Tue Jun 26, 2018 3:58 pm
Forum: Announcements
Topic: VPNfilter official statement
Replies: 191
Views: 90463

Re: VPNfilter official statement

It's not my method, I just suggested how to make TomjNorthIdaho's rules shorter.
English suck. I didn't mean you as in singular. I meant you as in plural. You and Tom.

I am not gonna argue with you. Believe what you want about CF.
by Cha0s
Tue Jun 26, 2018 3:41 pm
Forum: The Dude
Topic: A VPS to run Dude
Replies: 19
Views: 4349

Re: A VPS to run Dude

But chr is installable from ISO
Since when?
Where is it?
Screenshot_6.png
by Cha0s
Mon Jun 25, 2018 5:55 pm
Forum: General
Topic: IPv6 problem!!!
Replies: 8
Views: 3508

Re: IPv6 problem!!!

Where's the problem exactly? That's standard behavior in IPv6.
https://en.wikipedia.org/wiki/Link-local_address

If you don't want IPv6, disable the IPv6 package and reboot your router. You cannot not have link-local addresses. That's how the protocol works.
by Cha0s
Mon Jun 25, 2018 5:24 pm
Forum: Announcements
Topic: VPNfilter official statement
Replies: 191
Views: 90463

Re: VPNfilter official statement

You still block CloudFlare and tons of other websites. Well, https cert on this host covers "ssl894059.cloudflaressl.com", "toknowall.com" and "*.toknowall.com" - doesn't look like there are tons of other websites :) Which means absolutely nothing. CF is not a static thing. It is a dynamic system t...
by Cha0s
Mon Jun 25, 2018 4:22 pm
Forum: Announcements
Topic: VPNfilter official statement
Replies: 191
Views: 90463

Re: VPNfilter official statement

/ip firewall address-list add list=toknowall.com address=toknowall.com filter add chain=forward comment="VPNfilter toknowall.com" \ dst-address-list=toknowall.com action=drop log=yes What difference does this make? You still block CloudFlare and tons of other websites. These are just bad suggestion...
by Cha0s
Thu Jun 21, 2018 3:52 pm
Forum: General
Topic: feature request: add Port List to firewall
Replies: 35
Views: 9055

Re: feature request: add Port List to firewall

is this still in the feature request queue ?
There is no "feature request queue".
We just ask for stuff here, and MikroTik usually just implements stuff that nobody asked or cares about (eg: Kids Control, Detect Internet, etc).
by Cha0s
Wed Jun 20, 2018 2:16 pm
Forum: General
Topic: Stability problem of the SSTP/OPENVPN [SOLVED]
Replies: 8
Views: 1331

Re: Stability problem of the SSTP/OPENVPN [SOLVED]

I've been using SSTP, OVPN and every other vpn/tunnel that MikroTik supports for well over 10 years. I've never had any issues like the one you describe.

First upgrade to the latest version (if not already) and if the problem persists create a supout and send it to support@mikrotik.com
by Cha0s
Wed Jun 20, 2018 2:10 pm
Forum: Announcements
Topic: v6.42.4 [current]
Replies: 93
Views: 20905

Re: v6.42.4 [current]

rb952ui-5ac2nD hap lite
That refers to the remote side ROS version.