Community discussions

Search found 109 matches

by MrYan
Fri Aug 03, 2018 11:21 pm
Forum: General
Topic: "crs317 - improved transmit performance between 10G and 1G ports"
Replies: 3
Views: 703

Re: "crs317 - improved transmit performance between 10G and 1G ports"

Usually where there is a large mismatch in speed, the issue is down to lack of buffers. If you have packets arriving at 10 Gbps and need to send to a port that is only 1 Gbps you need to absorb the burst to stop TCP slowing down. If I had to guess, this would be the problem that was resolved (or mit...
by MrYan
Tue Feb 13, 2018 8:44 pm
Forum: General
Topic: Connection Tracking - Field Explanation
Replies: 6
Views: 1365

Re: Connection Tracking - Field Explanation

They are timeouts when no further packets are seen. Usually (with 2 way communication) the router would remove the UDP connection from the state table after the (default) 3 minutes of inactivity. With your new setting this would happen after 30 minutes. Beware of filling the connection table with en...
by MrYan
Fri Dec 22, 2017 8:08 pm
Forum: Announcements
Topic: v6.41 [current]
Replies: 304
Views: 76770

Re: v6.41 [current]

Upgrade on RB450G went smoothly. Changes to ethernet removing master-port, interface list adding default lists and then neighbour discovery and mac-server to use the lists.
by MrYan
Tue Oct 24, 2017 1:01 pm
Forum: Forwarding Protocols
Topic: Anybody knows some BGP Blackhole free service?
Replies: 2
Views: 481

Re: Anybody knows some BGP Blackhole free service?

Yeah, there is a definite cost to null routing > 500 Gbps of traffic.
by MrYan
Mon Jan 16, 2017 3:09 pm
Forum: Beginner Basics
Topic: Long output - how to paginate?
Replies: 4
Views: 534

Re: Long output - how to paginate?

Some commands won't page (/log print & /export for example). Does this apply to all commands? What version of ROS are you running?
by MrYan
Mon Jan 16, 2017 11:56 am
Forum: Beginner Basics
Topic: Long output - how to paginate?
Replies: 4
Views: 534

Re: Long output - how to paginate?

By default the CLI paginates - have you got some weird termtype set?
by MrYan
Mon Oct 17, 2016 9:49 am
Forum: General
Topic: CHR PPP MTU
Replies: 2
Views: 463

Re: CHR PPP MTU

The behaviour of dropping MTU from 1500 to 1480 seems to be related to the Mikrotik sending a large LCP Echo packet and not getting a (valid) reply (see my posts here - http://forum.mikrotik.com/viewtopic.php?f=2&t=112520).
by MrYan
Mon Oct 03, 2016 11:37 am
Forum: Scripting
Topic: ppp profile scripts
Replies: 2
Views: 2479

Re: ppp profile scripts

isn't is $"remote-address"?
by MrYan
Mon Sep 26, 2016 2:39 pm
Forum: General
Topic: PPPoE and MTU > 1488
Replies: 7
Views: 2945

Re: PPPoE and MTU > 1488

Yeah, BT do support 1500 byte MTU. It's worked in the past - not sure when it stopped - I only noticed when I upgraded to 6.37 but was the same on downgrade. Most likely, BT have changed something in their network.
by MrYan
Mon Sep 26, 2016 9:53 am
Forum: General
Topic: PPPoE and MTU > 1488
Replies: 7
Views: 2945

Re: PPPoE and MTU > 1488

The VLAN insertion is done on the Vigor (not on the Mikrotik). I've tried with larger MTU (1520 which is the maximum the Vigor supports) with no change to behaviour. I'm sure you are correct - the path between me and the exchange is probably short 4 bytes (most likely a VLAN tag) but getting BT to d...
by MrYan
Sat Sep 24, 2016 2:56 pm
Forum: General
Topic: PPPoE and MTU > 1488
Replies: 7
Views: 2945

Re: PPPoE and MTU > 1488

The interface MTU on the Mikrotik and DSL modem (Vigor 130) is set to 1508 bytes so the path to the BRAS should be capable of sending > 1492 byte packets. I see in the PPPoE discovery that the Mikrotik advertises PPP-Max-Payload for RFC 4638 negotiation (05dc == 1500): Frame 1: 38 bytes on wire (304...
by MrYan
Fri Sep 23, 2016 2:16 pm
Forum: General
Topic: PPPoE and MTU > 1488
Replies: 7
Views: 2945

PPPoE and MTU > 1488

Upgraded to 6.37 this morning and noticed that even with max-mtu=1500 on the pppoe-client interface that the MTU changes to 1480 after between 3-5 seconds (seen using monitor command on interface). Thought it was a problem with 6.37 so downgraded back to 6.36.3 but that exhibited the same problem. T...
by MrYan
Tue Sep 20, 2016 12:15 pm
Forum: General
Topic: Terminal length?
Replies: 1
Views: 755

Re: Terminal length?

Not without adding 'without-paging' to the end of each command to get no more messages.

You could try the '+hN' on the end of your username - http://wiki.mikrotik.com/wiki/Manual:Co ... in_process
by MrYan
Fri Jul 22, 2016 12:03 am
Forum: General
Topic: Replacing config without reboot
Replies: 5
Views: 993

Re: Replacing config without reboot

I've looked into the "diff" option but it's non-trivial - IMHO you need to implement a full parser to do it. For example, if I send the configuration  /interface set loop comment="Test Comment"   what is the diff if the configuration is /interface bridge add name=loop mtu=2000 You also have to cope ...
by MrYan
Thu Jul 21, 2016 10:28 pm
Forum: General
Topic: Replacing config without reboot
Replies: 5
Views: 993

Re: Replacing config without reboot

By replace, I mean clear the existing configuration and apply the new one (the equivalent of configure replace in IOS -  https://supportforums.cisco.com/document/29696/using-configure-replace-command ). My understanding is that the only way to do this would be /system reset-configuration with the ne...
by MrYan
Wed Jul 20, 2016 9:55 am
Forum: General
Topic: Replacing config without reboot
Replies: 5
Views: 993

Replacing config without reboot

I'm working on some code (existing framework) that needs to merge and replace configuration on the router. The merge part is straightforward, but the replace part isn't AFAIK. I've read http://wiki.mikrotik.com/wiki/Manual:Configuration_Management and it offers no solutions. Does anyone have any cle...
by MrYan
Fri May 27, 2016 9:58 pm
Forum: General
Topic: IP Fragments and firewall rules
Replies: 6
Views: 1622

Re: IP Fragments and firewall rules

add chain=input/forward protocol=tcp fragment=yes action=accept
this sounds correct and usable, however wouldn't the implicit rule at the end of the chain just accept them anyhow?

I'd have thought so. I can't see anything that suggests the the implict ACCEPT doesn't accept fragments.
by MrYan
Thu May 26, 2016 2:43 pm
Forum: General
Topic: IP Fragments and firewall rules
Replies: 6
Views: 1622

Re: IP Fragments and firewall rules

add chain=input/forward protocol=tcp fragment=yes action=accept
by MrYan
Sun May 01, 2016 2:54 pm
Forum: General
Topic: IPv6 routes for interfaces in a IPv4 VRF
Replies: 3
Views: 1485

Re: IPv6 routes for interfaces in a IPv4 VRF

No.
by MrYan
Wed Dec 02, 2015 9:23 am
Forum: RouterBOARD hardware
Topic: ROS/SwOS on Whitebox Switches
Replies: 1
Views: 959

Re: ROS/SwOS on Whitebox Switches

Should be easier if Mikrotik targetted something like the Switch Abstraction Interface (SAI) layer from Open Compute - http://www.opencompute.org/wiki/Network ... _Interface
by MrYan
Fri Sep 25, 2015 10:30 am
Forum: General
Topic: v6.33rc release candidate (final testing)
Replies: 203
Views: 36834

Re: v6.33rc release candidate

6.33rc15 will be released today.

*) pppoe - added support for MTU > 1492 on PPPoE;
Hi Strods, can you explain this?
I always used PPPoE at 1500Byte.
Hopefully they mean RFC4638 support.
by MrYan
Wed Sep 23, 2015 3:48 pm
Forum: General
Topic: Advice on bridged VLANs
Replies: 1
Views: 401

Re: Advice on bridged VLANs

I'd say it depends. If you want to bridge all VLANs from ether1 to ether5 then I'd put both interfaces into the bridge. If you want to be more selective than I'd add VLAN interfaces per port and create a bridge per VLAN. Also, unless you want to assign an IP address to the VLAN, I'd not bother creat...
by MrYan
Fri Sep 18, 2015 2:51 pm
Forum: General
Topic: Users connected via Mikrotik-Box can't access github.com?
Replies: 7
Views: 882

Re: Users connected via Mikrotik-Box can't access github.com?

I suspect your problem is not the one you found on Google as that seems to be related to connecting to the Mikrotik itself via SSL and not problems with the Mikrotik forwarding SSL.

Usual problems with SSL is MTU size - can your users access any other SSL enabled sites (MS or eBay for example)?
by MrYan
Fri Sep 18, 2015 2:45 pm
Forum: RouterBOARD hardware
Topic: Real CCR1072 experience?
Replies: 52
Views: 10774

Re: Real CCR1072 experience?

If you put a 2 ms RTT (not unreasonable with a test port on each side of the DUT) into the calculator it gives a max throughput of ~ 58 Gbps at 1500/1460 bytes. Suggests that you don't need to tweak this at least. Might need to up the window size of the tester though (assuming it actually runs a TCP...
by MrYan
Fri Sep 18, 2015 1:36 pm
Forum: RouterBOARD hardware
Topic: Real CCR1072 experience?
Replies: 52
Views: 10774

Re: Real CCR1072 experience?

Described by whom please? I am writing as official representative of MikroTik now, that there is, and never was such limitation. http://forum.mikrotik.com/viewtopic.php?f=1&t=85698 http://forum.mikrotik.com/viewtopic.php?f=3&t=80057#p461377 http://forum.mikrotik.com/viewtopic.php?f=2&t=99402#p49448...
by MrYan
Fri Sep 18, 2015 11:21 am
Forum: RouterBOARD hardware
Topic: Real CCR1072 experience?
Replies: 52
Views: 10774

Re: Real CCR1072 experience?

The 1 Gbps limit was described as a per CPU forwarding limitation. To get 10 Gbps of throughput, you couldn't just send a single 10 Gbps TCP flow between two ports - you needed to aggregate 10x 1 Gbps TCP flows so that multiple CPUs could get involved in the forwarding to provide the aggregate 10 Gb...
by MrYan
Thu Jul 23, 2015 6:39 pm
Forum: Beginner Basics
Topic: Show NAT translation table
Replies: 5
Views: 8978

Re: Show NAT translation table

Latest RouterOS now shows the NAT status in the /ip firewall connections print output.
by MrYan
Sat Jun 27, 2015 8:43 pm
Forum: General
Topic: Huawei E8278s
Replies: 0
Views: 1101

Huawei E8278s

This dongle presents 4G PCUI (Serial interface) and NCM (Hilink) by default and it seems you can't get it to turn off the serial interface (SETPORT AT command). I also have a Huawei E3131 that presents the NCM/Hilink interface but no serial interface. The E3131 is seen as an LTE interface and works ...
by MrYan
Sat Jun 27, 2015 8:37 pm
Forum: General
Topic: USB 3G modem
Replies: 4
Views: 1823

Re: USB 3G modem

I've noticed that the E3131 in Hilink mode is seen as a LTE interface. This works well if you can live with the fact that the dongle NATs connections - the router doesn't get the external IP address but one allocated from 192.168.1.1 by the dongle.
by MrYan
Tue Jun 16, 2015 10:31 pm
Forum: Beginner Basics
Topic: Show NAT translation table
Replies: 5
Views: 8978

Re: Show NAT translation table

Use /ip firewall connection print detail - if the reply-src-address is different to dst-address (or reply-dst-address is different to src-address) then its NATing.
by MrYan
Sun Apr 26, 2015 4:08 pm
Forum: General
Topic: Sector writes
Replies: 11
Views: 2411

Re: Sector writes

Looks to me like its Winbox3 - I get 2 writes/second using winbox and 0 when using the CLI (via SSH).
by MrYan
Thu Jan 15, 2015 2:13 pm
Forum: General
Topic: Mikrotik Half Bridge PPPoE
Replies: 4
Views: 1070

Re: Mikrotik Half Bridge PPPoE

Poster wants PPP bridged over Ethernet not Ethernet bridged over PPP.
by MrYan
Wed Dec 17, 2014 12:13 pm
Forum: General
Topic: Support for PPPoE MTU > 1492 (via RFC4638 PPP-Max-Payload)
Replies: 18
Views: 5209

Re: Support for PPPoE MTU > 1492 (via RFC4638 PPP-Max-Payloa

In the UK, if your provider uses BT Wholesale you don't need RFC4638 (although it would be better if it were supported). You can negotiate an asymmetric MTU where its 1500 bytes into your router (from the Internet) and 1492 bytes out. This means that sites which filter ICMP Fragmentation Needed mess...
by MrYan
Wed Dec 17, 2014 11:07 am
Forum: General
Topic: RB751G/Router OS 61.9 with Sky Fibre
Replies: 2
Views: 1004

Re: RB751G/Router OS 61.9 with Sky Fibre

Plug the Mikrotik into the OpenReach modem then add configuration something like this: [admin@router] > /interface pppoe-client print detail Flags: X - disabled, R - running 0 R ;;; Sky Fibre name="pppoe-out1" max-mtu=1500 max-mru=1500 mrru=disabled interface=ether1 user="USER_NAME" password="PASS_W...
by MrYan
Thu Dec 11, 2014 12:08 pm
Forum: Beginner Basics
Topic: Disable keepalives from GRE
Replies: 2
Views: 753

Re: Disable keepalives from GRE

set number=X !keepalive
by MrYan
Mon Dec 01, 2014 5:21 pm
Forum: General
Topic: Problem with Huawei E3372 and RouterBOARD 951Ui 2HnD
Replies: 3
Views: 4050

Re: Problem with Huawei E3372 and RouterBOARD 951Ui 2HnD

I don't think you can do the initial change under RouterOS - you need to do it on a Windows/Linux box. Once its changed, it can be used on Mikrotik.
by MrYan
Thu Nov 27, 2014 12:33 pm
Forum: General
Topic: Problem with Huawei E3372 and RouterBOARD 951Ui 2HnD
Replies: 3
Views: 4050

Re: Problem with Huawei E3372 and RouterBOARD 951Ui 2HnD

Have you set it to modem mode? http://askubuntu.com/questions/381970/h ... modem-mode

On my E3131 I have both data-channel and info-channel set to 0.
by MrYan
Tue Nov 04, 2014 12:42 pm
Forum: General
Topic: Bug or feature? \00 in hostnames?
Replies: 7
Views: 1575

Re: Bug or feature? \00 in hostnames?

On mine the hostname file looks okay: [duck] Matt>od -c hostname 0000000 d s 1 1 0 j \n 0000007 [duck] Matt>od -c hosts 0000000 1 2 7 . 0 . 0 . 1 \t l o c a l h 0000020 o s t \n 1 9 2 . 1 6 8 . 1 4 4 . 0000040 8 \t d s 1 1 0 j \n \n \n \n \n \n \n \n 0000060 \n \n \n \n \n \n \n \n \n \n \n \n \n \n...
by MrYan
Tue Nov 04, 2014 11:55 am
Forum: General
Topic: Bug or feature? \00 in hostnames?
Replies: 7
Views: 1575

Re: Bug or feature? \00 in hostnames?

I see it with a Synology NAS as well. Don't recall if I saw it with Ubuntu Linux clients. I suspect that the host-name is the client identifier (option) which I don't think is a NULL terminated string. Chances are that the DHCP client is broken on embedded Linux devices.
by MrYan
Tue Oct 28, 2014 1:17 pm
Forum: General
Topic: PPPoE Public Routed subnet config
Replies: 5
Views: 1568

Re: PPPoE Public Routed subnet config

Just configure the public address with a /29 mask on another interface (Ethernet). The router will have the same IP address on two interfaces but will work. Causes issues with multicast but otherwise isn't normally a problem.


Matt.
by MrYan
Wed Oct 22, 2014 10:19 pm
Forum: Beginner Basics
Topic: PPPOE problems
Replies: 2
Views: 663

Re: PPPOE problems

Delayed post?
by MrYan
Wed Oct 15, 2014 10:50 am
Forum: Beginner Basics
Topic: Firewall Mangle rule shows no traffic
Replies: 10
Views: 2297

Re: Firewall Mangle rule shows no traffic

I think your problem is the passthrough=no on the prerouting chain. Put the second part (to mark the packets) in the postrouting chain. You could also change the passthrough to be yes.

I'd also remove the port= part as its not required.
by MrYan
Mon Oct 13, 2014 5:21 pm
Forum: Beginner Basics
Topic: Firewall Mangle rule shows no traffic
Replies: 10
Views: 2297

Re: Firewall Mangle rule shows no traffic

Should it not be:
add action=mark-connection chain=prerouting comment=VPN \
    new-connection-mark=VPN port=1194 protocol=udp
add action=mark-packet chain=prerouting new-packet-mark=VPN connection-mark=VPN \
    passthrough=no

Matt.
by MrYan
Fri Sep 12, 2014 1:00 am
Forum: General
Topic: SSTP tunnel does not detect connection failure
Replies: 6
Views: 1203

Re: SSTP tunnel does not detect connection failure

AIUI, once enabled on the client, the server just responds to the relevant keep alive message.
by MrYan
Thu Sep 11, 2014 1:50 pm
Forum: General
Topic: SSTP tunnel does not detect connection failure
Replies: 6
Views: 1203

Re: SSTP tunnel does not detect connection failure

Do you have a keepalive-timeout set?
by MrYan
Tue Aug 26, 2014 6:11 pm
Forum: General
Topic: How filter output in /ip firewall connection print
Replies: 5
Views: 6006

Re: How filter output in /ip firewall connection print

I know that there's a way to filter the print output of a command and I use this regularly in the /ip route print output. But why it doesn't work on /ip firewall nat? For example when I try to filter out only the connections from a particular source address - it does not work, I've got empty output...
by MrYan
Fri Aug 01, 2014 1:03 pm
Forum: Wireless Networking
Topic: Planning of a inhouse wireless roaming network for a castle
Replies: 6
Views: 1530

Re: Planning of a inhouse wireless roaming network for a cas

If you have power (energy cables I assume is mains power) can you use power line for the backhaul for the access point?


Matt.
by MrYan
Tue Jul 22, 2014 11:19 am
Forum: General
Topic: ATTENTION, DISASTER! V.6.17
Replies: 57
Views: 15108

Re: ATTENTION, DISASTER! V.6.17

My 2011UAS-2HnD upgraded fine to 6.16 and then failed on upgrade (shortly after) to 6.17 with a message about loading kernel from NAND and then hanging. I got it going again using netinstall. No supout unfortunately.
by MrYan
Fri Jul 04, 2014 2:12 pm
Forum: General
Topic: USB 3G modem
Replies: 4
Views: 1823

Re: USB 3G modem

Hello:
Can anyone recommend me a USB 3G modem with connection for an external antenna for use with a router mikrotik RB951Ui-2HnD?
I have a Huawei E3131 that has an external connector. It needs some faffing about to get it into modem mode and didn't dial PPP until 6.15 but now works well.


Matt.
by MrYan
Mon Feb 17, 2014 11:16 pm
Forum: General
Topic: Feature Request TR-069 CPE
Replies: 80
Views: 24459

Re: Feature Request TR-069 CPE

Should be able to base something off this - http://freecwmp.org
by MrYan
Fri Jan 31, 2014 4:28 pm
Forum: General
Topic: 6.9 released!
Replies: 223
Views: 79334

Re: 6.9 released!

*) ppp - fixed ppp bridging (did not work since v6.6);
This is now working for me again. It would be nice however if the PPP interface added to the bridge didn't show as '(unknown)' in /interface bridge ports however. This did used to work a few version back.
by MrYan
Wed Jan 29, 2014 8:18 pm
Forum: General
Topic: v6.8 pre-release (RC)
Replies: 44
Views: 5348

Re: v 6.8 released

Looks like remote-ipv6-prefix on /ppp secret user doesn't get added to the /ipv6 route list. This worked on 6.7 (old PPP package).
by MrYan
Wed Jan 29, 2014 6:56 pm
Forum: General
Topic: v6.8 pre-release (RC)
Replies: 44
Views: 5348

Re: 6.8

Keep in mind that until v6.8 is present at download page, then it is pre-release version and one should use it with caution. Currently there might be issue with 3.11 RouterBOARD firmware and v6.8 (6.8rc1) version. Perhaps you should pull it so /system package upgrade doesn't download it then (just ...
by MrYan
Thu Jan 09, 2014 5:15 pm
Forum: General
Topic: Feature Request: Encrypted (secret) L2tp Client
Replies: 9
Views: 2461

Re: Feature Request: Encrypted (secret) L2tp Client

*) ipsec - new exchange mode (main-l2tp) for l2tp tunnel users to allow
FQDN as a peer ID with preshared key authorization in main mode;
That's a pre-shared key for IPsec - L2TP is just a wrapper in this case.


Matt.
by MrYan
Thu Jan 09, 2014 4:15 pm
Forum: General
Topic: Feature Request: Encrypted (secret) L2tp Client
Replies: 9
Views: 2461

Re: Feature Request: Encrypted (secret) L2tp Client

Since this is not a standard (if it is, let us know which), it seems your ISP is pushing for a specific brand product. I would object to this.
Isn't it this - http://tools.ietf.org/search/rfc2661#section-5.1.1?


Matt.
by MrYan
Thu Jan 09, 2014 3:04 pm
Forum: General
Topic: /ipv6 firewall filter print stats - RoS 6.7?
Replies: 1
Views: 550

Re: /ipv6 firewall filter print stats - RoS 6.7?

/ipv6 firewall filter print all stats

Why it's different I don't know.


Matt.
by MrYan
Fri Jan 03, 2014 2:33 am
Forum: General
Topic: Strange records in log when enabled SSTP VPN
Replies: 1
Views: 762

Re: Strange records in log when enabled SSTP VPN

Someone scanning for HTTPS probably.
by MrYan
Fri Dec 13, 2013 12:54 pm
Forum: General
Topic: MTU ADSL
Replies: 4
Views: 1101

Re: MTU ADSL

by MrYan
Mon Nov 11, 2013 12:41 pm
Forum: General
Topic: RouterOS v6.6 released
Replies: 164
Views: 72439

Re: RouterOS v6.6 released

Upgraded a router to 6.6 and hit a problem with bridging Ethernet (BCP) over SSTP: 10:39:19 sstp,info <sstp-0>: waiting for call... 10:39:19 sstp,info sstp-in1: authenticated 10:39:19 sstp,info sstp-in1: connected 10:39:19 sstp,info,account door logged in, 0.0.0.0 10:39:19 sstp,error could not add b...
by MrYan
Wed Nov 06, 2013 2:26 pm
Forum: General
Topic: CRS: What makes this device "cloud"?
Replies: 6
Views: 1311

Re: CRS: What makes this device "cloud"?

Hype...
Well, marketing (but the same thing).
by MrYan
Fri Sep 27, 2013 3:25 pm
Forum: General
Topic: Mikrotik SSTP does not work with public VPN providers
Replies: 4
Views: 2234

Re: Mikrotik SSTP does not work with public VPN providers

Works on 6.4 to Strong VPN for me. Perhaps they are TLS 1.0 only.
by MrYan
Fri Sep 27, 2013 3:24 pm
Forum: Forwarding Protocols
Topic: Policy Base Routing problem
Replies: 10
Views: 4746

Re: Policy Base Routing problem

It may be because you need to mark all packets with the routing-mark and context= doesn't do this. Perhaps setting a connection-mark and then applying routing-mark based on this (in the outbound direction only) would help.


Matt.
by MrYan
Sun Sep 08, 2013 4:08 pm
Forum: General
Topic: 6.3 Released
Replies: 95
Views: 20168

Re: 6.3 Released

After upgrading from 6.0 to 6.2 all my INPUT firewall rules disappeared. Is this fixed in 6.3?
I had this also (from 6.1 to 6.2). When I upgraded to 6.3 the rules remained in place.


Matt.
by MrYan
Sat Aug 03, 2013 2:41 pm
Forum: General
Topic: v6.2 released
Replies: 247
Views: 89508

Re: v6.2 released

Looks like the added default-route-distance parameter doesn't set the distance for IPv6 default routes: [admin@mikrotik] /lcd> /ip route print Flags: X - disabled, A - active, D - dynamic, C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme, B - blackhole, U - unreachable, P - prohibit # DS...
by MrYan
Wed Jul 17, 2013 9:33 pm
Forum: General
Topic: [FIXED]firewall mangle broken in ROS V6.1??
Replies: 2
Views: 1275

Re: firewall mangle broken in ROS V6.1??

I have the same rule bar its a src-address-list and it works on 6.1 without any problems.
by MrYan
Wed Jul 03, 2013 5:34 pm
Forum: General
Topic: PPP mangle rules
Replies: 1
Views: 1487

PPP mangle rules

On of the changes made in the 6.0 release candidates was this: Only 2 change mss mangle rules are created for all ppp interfaces; I've just added a new PPP interface to a router that has 3 others and this is causing me problems. The initial 3 interfaces all have a 1500 byte MTU but the latest one ne...
by MrYan
Sat Jun 15, 2013 11:24 pm
Forum: General
Topic: Openflow and floodlight: static flow on ARP ether-type 0x806
Replies: 4
Views: 3212

Re: Openflow and floodlight: static flow on ARP ether-type 0

What do you mean they don't catch any flows when pinging? Are you saying you expect to see ARP for the relevant end-point but don't see it or that the ping doesn't work? If the latter, do you have a flow for ICMP?
by MrYan
Thu Jun 13, 2013 10:54 pm
Forum: General
Topic: RouterOS 6.1 released
Replies: 198
Views: 53661

Re: RouterOS 6.1 released

IPv6 link local address for bridge interface seems to be somehow broken. It was also on 6.0. Somehow it worked for the first reboot after upgrade, but the second reboot broke it. The link local address now gets assigned to (unknown) interface. # ADDRESS FROM-... INTERFACE ADV 3 DL fe80::d6ca:6dff:f...
by MrYan
Thu Jun 13, 2013 6:41 pm
Forum: General
Topic: Openflow and floodlight: static flow on ARP ether-type 0x806
Replies: 4
Views: 3212

Re: Openflow and floodlight: static flow on ARP ether-type 0

Do you see the flow in Floodlight?

What does /openflow flow print show?
by MrYan
Fri May 10, 2013 6:54 pm
Forum: General
Topic: Mikrotik + Open NMS
Replies: 1
Views: 1654

Re: Mikrotik + Open NMS

I have tried a test device but it didn't work well. The interface names were missing along with the corresponding IP addresses.
by MrYan
Wed Apr 03, 2013 12:06 pm
Forum: Forwarding Protocols
Topic: Openflow Problem on RB450G
Replies: 10
Views: 3063

Re: Openflow Problem on RB450G

If I disable the Forwarding module in Floodlight then no communication is possible. If the Forwarding module is enabled (the default with floodlightdefault.properties) then as mrz states the controller learns the topology and sets flows for the traffic automatically.
by MrYan
Tue Apr 02, 2013 11:57 am
Forum: Forwarding Protocols
Topic: Openflow Problem on RB450G
Replies: 10
Views: 3063

Re: Openflow Problem on RB450G

Using a mix of 750s and 450s I see statistics on my Floodlight instance (using 6.0rc11). I'm not sure if they are correct, but they are certainly there. I also see hosts on my network and can send traffic between them.
by MrYan
Thu Mar 28, 2013 5:06 pm
Forum: General
Topic: RouterOS v6rc12
Replies: 78
Views: 22790

Re: RouterOS v6rc12

I seem to be having issues with bridge interfaces and dynamic link local IPv6 addresses. They are generated but the interface shows as '(unknown)' in /ipv6 address print. This has the knock on effect of disabling IPv6 RA messages and so my client devices are not getting IPv6 addresses automatically....
by MrYan
Thu Feb 07, 2013 12:14 pm
Forum: General
Topic: PPPoE drops connections when Ethernet port bounces
Replies: 6
Views: 1665

Re: PPPoE drops connections when Ethernet port bounces

Does setting the port to edge=yes-discover help?


Matt.
Where do I set that?
On the bridge or the ethernet ports.
Bridge.
by MrYan
Tue Feb 05, 2013 12:31 pm
Forum: General
Topic: PPPoE drops connections when Ethernet port bounces
Replies: 6
Views: 1665

Re: PPPoE drops connections when Ethernet port bounces

Does setting the port to edge=yes-discover help?


Matt.
by MrYan
Sun Jan 13, 2013 5:47 pm
Forum: General
Topic: RouterOS breadth of features
Replies: 4
Views: 760

Re: RouterOS breadth of features

Hello MrYan, Do you mean the pretty old packages from Debian Linux? The ones without hotfixes and any support, that can causes crashes and able to open bigger whole that can cause many other security problems? I didn't mean anything. I was asked a question and gave an answer to the best of my knowl...
by MrYan
Sun Jan 13, 2013 10:56 am
Forum: General
Topic: RouterOS breadth of features
Replies: 4
Views: 760

Re: RouterOS breadth of features

The EdgeMax allows access to the underlying Debian Linux OS so you can run scripts there. However there is no scripting AFAIK in the CLI/GUI?
by MrYan
Fri Jan 11, 2013 3:50 pm
Forum: General
Topic: RouterOS breadth of features
Replies: 4
Views: 760

RouterOS breadth of features

I've been playing with a device that has been suggested as a Mikrotik killer on these forums (EdgeMax) for a few days now and I have to say it's made me aware of just how much functionality there is in RouterOS that is taken for granted. My main use case is home CPE but even in this role RouterOS is...
by MrYan
Fri Jan 04, 2013 5:12 pm
Forum: General
Topic: XBOX 360 group connection issues
Replies: 13
Views: 2639

Re: XBOX 360 group connection issues

Ypu may not be able to implement it, but the following might help:

http://jakebillo.com/two-xboxes-one-rou ... or-tomato/
by MrYan
Mon Aug 20, 2012 12:23 pm
Forum: General
Topic: /interface ethernet export broken in 5.20?
Replies: 3
Views: 905

Re: /interface ethernet export broken in 5.20?

[admin@router] > /interface ethernet export compact
# aug/20/2012 10:21:53 by RouterOS 5.20
# software id = WEY9-YK6I
#
/interface ethernet
set 0 comment=Modem
set 1 comment=Internal
set 2 master-port=ether2
set 3 arp=reply-only comment=Untrusted
set 4 comment=External
[admin@router] >
by MrYan
Wed Jun 27, 2012 1:58 pm
Forum: General
Topic: Static DHCP leases not working
Replies: 2
Views: 587

Re: Static DHCP leases not working

I've not seen this on RB750, RB750UP or RB450 with ROS 5.{11-18} with both statics and pools configured under DHCP.


Matt.
by MrYan
Fri Jun 22, 2012 8:10 pm
Forum: General
Topic: v5.18 released
Replies: 92
Views: 25748

Re: v5.18 released

What's new in 5.18 (2012-Jun-21 17:20): *) dhcp ipv6 pd client - fixed ipv6 pool creation after reboot; Was the change meant to fix this? Flags: X - disabled # NAME VERSION SCHEDULED 0 system 5.18 17:50:57 dhcp,error creating ippool6 failed: prefix of two pools cannot overlap! (6) Matt.
by MrYan
Sat Jun 16, 2012 12:52 am
Forum: Beginner Basics
Topic: RB750 and bandwidth limit
Replies: 3
Views: 3877

Re: RB750 and bandwidth limit

I have a similar requirement, I need to limit traffic on one interface to 5M down. Are simple queues the right tool for this? In webfig the max target download speed seems to be 2M.
Just overtype the 2M with the value you want.


Matt.
by MrYan
Fri Jun 15, 2012 5:54 pm
Forum: General
Topic: Error ? "item changed"
Replies: 8
Views: 1129

Re: Error ? "item changed"

I came across the same problem recently. From what I can tell, these increased in frequency when I lowered my DHCP lease times. Some of the leases set an address-list and I think this is what is causing the message.
by MrYan
Wed Jun 06, 2012 12:18 pm
Forum: General
Topic: Tunnel over TCP - possible ?
Replies: 6
Views: 2364

Re: Tunnel over TCP - possible ?

Assuming support at both ends, then SSTP should do the trick (http://wiki.mikrotik.com/wiki/SSTP). You may however have unexpected performance issues as TCP will wait for retransmits and this may impact the traffic inside the tunnel.
by MrYan
Wed May 30, 2012 9:45 pm
Forum: General
Topic: RouterOS v5.17 released
Replies: 47
Views: 16748

Re: RouterOS v5.17 released

What's new in 5.17 (2012-May-28 12:34):
*) tool email - added starttls option;
Doesn't appear to be a checkbox in Winbox for the email STARTTLS option though it is in the command line.


Matt.
by MrYan
Fri May 11, 2012 9:54 am
Forum: RouterBOARD hardware
Topic: RB750UP + 3G USB = freezes completely
Replies: 31
Views: 17710

Re: RB750UP + 3G USB = freezes completely

The best information I can find on the 3G modem I have (ZTE MF626) is that it draws 100mA idle and maximum of 450mA however it doesn't break it down between 2G and 3G.

http://www.3gmodem.com.hk/ZTE/MF626.html


Matt.
by MrYan
Wed May 09, 2012 11:25 am
Forum: RouterBOARD hardware
Topic: RB750UP + 3G USB = freezes completely
Replies: 31
Views: 17710

Re: RB750UP + 3G USB = freezes completely

I've had a similar problem for the first time with my RB750UP and 3G modem. All the Ethernet LEDs were out so I had no connectivity to the device and had to power cycle it. It's been running for a couple of months without issue before this. No supout.rif file created automatically so I've generated ...
by MrYan
Thu Apr 26, 2012 11:39 pm
Forum: General
Topic: 3G Modem - Signal Strength?
Replies: 8
Views: 3642

Re: 3G Modem - Signal Strength?

The modem is a ZTE MF626 on 5.14 and I tested the command while the PPP session was up.
by MrYan
Thu Apr 26, 2012 9:32 pm
Forum: General
Topic: 3G Modem - Signal Strength?
Replies: 8
Views: 3642

Re: 3G Modem - Signal Strength?

I can get it using this command on my MT:

/interface ppp-client info <3G modem interface>
by MrYan
Mon Apr 16, 2012 11:21 am
Forum: General
Topic: Match 0.0.0.0/32 in address list?
Replies: 2
Views: 1763

Re: Match 0.0.0.0/32 in address list?

DHCP packets are not matched in firewall.
Can you clarify the answer - they obviously are matched as they match the log action and the second firewall entry that doesn't match on src-address-list - do you mean that they are not matched in the address-list?


Matt.
by MrYan
Sat Apr 14, 2012 3:45 pm
Forum: General
Topic: Match 0.0.0.0/32 in address list?
Replies: 2
Views: 1763

Match 0.0.0.0/32 in address list?

I have set up an address list for DHCPv4 with 0.0.0.0/32 in it as this is the source address for (initial) DHCP requests. I have a input filter that uses this address list but it doesn't seem to match: [admin@router] > /ip firewall address-list print where list =dhcp-clients_v4 Flags: X - disabled, ...
by MrYan
Sat Apr 14, 2012 3:29 pm
Forum: General
Topic: v6.0beta1 released!
Replies: 35
Views: 13685

Re: v6.0beta1 released!

still no "routing mark" in firewall ipv6. why? but i have upgraded my device to v6. :) And if you put an interface into a VRF under /ip route vrf it doesn't display the IPv6 route associated with the interface (as per my post here - http://forum.mikrotik.com/viewtopic.php?f=2&t=60574): /interface e...
by MrYan
Sun Apr 08, 2012 2:05 pm
Forum: Beginner Basics
Topic: No advertise based IPv6 address assignmets anymore?
Replies: 3
Views: 590

Re: No advertise based IPv6 address assignmets anymore?

It works for me on 5.14 - what I have noticed however is that the default ra-interval is too long for Linux clients - I just set it to a lower value (15-20s) and that does the trick.


Matt.
by MrYan
Mon Mar 26, 2012 9:20 pm
Forum: General
Topic: IPv6 routes for interfaces in a IPv4 VRF
Replies: 3
Views: 1485

IPv6 routes for interfaces in a IPv4 VRF

Should have put in the version I tried this on - 5.14 I have an interface in a IPv4 VRF and the IPv4 routes are show with the correct routing mark and in the correct VRF. However, IPv6 routes on the same interface are not shown as /ipv6 route has no concept of the VRF. If I remove the interface from...
by MrYan
Fri Feb 17, 2012 11:54 am
Forum: General
Topic: v5.13 released
Replies: 64
Views: 8193

Re: v5.13 released

If you add ARP entries via DHCP and look at the result using /ip arp print then they are correctly marked as being allocated via DHCP - 'H' rather than 'D' (dynamic). However, Winbox and Webfig both show them incorrectly as 'D'. Not sure if this is 5.13 specific as I've only just enabled the feature.
by MrYan
Thu Jan 26, 2012 3:32 pm
Forum: General
Topic: Cannot see log via WebFig
Replies: 2
Views: 386

Re: Cannot see log via WebFig

I found changing from 'All' to 'Memory' seemed to help (it worked still when set back to 'All').
by MrYan
Thu Jan 12, 2012 11:12 pm
Forum: General
Topic: Logging multiple topics to remote syslog
Replies: 2
Views: 917

Re: Logging multiple topics to remote syslog

Makes sense - thanks for taking the time to answer my question.
by MrYan
Thu Jan 12, 2012 12:28 pm
Forum: General
Topic: Logging multiple topics to remote syslog
Replies: 2
Views: 917

Logging multiple topics to remote syslog

Any reason why this doesn't work: [admin@mikrotik] /system logging> print Flags: X - disabled, I - invalid # TOPICS ACTION PREFIX 0 info memory 1 error memory 2 warning memory 3 critical echo 4 info remote error warning critical But this does? [admin@mikrotik] /system logging> print Flags: X - disab...
by MrYan
Wed Dec 28, 2011 1:21 pm
Forum: Beginner Basics
Topic: How to set up RB750 for home asterisk server?
Replies: 2
Views: 1530

Re: How to set up RB750 for home asterisk server?

NAT SIP port (5060) as well from outside.
by MrYan
Wed Dec 14, 2011 10:08 pm
Forum: Forwarding Protocols
Topic: IGMP Proxy issue
Replies: 60
Views: 28277

Re: IGMP Proxy issue

I had similar problems and error messages until I ran /routing igmp-proxy interface print status and noticed that the source-ip-address for the upstream and downstream interfaces were the same. This was due to me having a 1.2.3.4/29 address on ether2 and also 1.2.3.4/32 on pptp-out1 (pseudo unnumber...
by MrYan
Mon Feb 21, 2011 5:11 pm
Forum: General
Topic: Mikrotik IPv6 addresses
Replies: 33
Views: 2948

Re: Mikrotik IPv6 addresses

Have the DNS records been pulled now? Prompt>telnet -6 forum.mikrotik.com telnet: could not resolve forum.mikrotik.com/telnet: No address associated with hostname Prompt>tracepath6 2a02:610:7501:1000::2 1?: [LOCALHOST] pmtu 1500 1: gw.banana.org.uk 0.616ms 1: gw.banana.org.uk 0.564ms 2: gw.banana.or...
by MrYan
Wed Oct 20, 2010 12:10 pm
Forum: General
Topic: DSL Fail over
Replies: 2
Views: 484

Re: DSL Fail over

People report success with these - http://www.draytek.co.uk/products/vigor120.html
by MrYan
Sat Feb 27, 2010 6:15 pm
Forum: General
Topic: RouterOS v4.6 released
Replies: 80
Views: 12346

Re: RouterOS v4.6 released

Problems for me as well.

Firstly, the download from USA failed MD5 but the one from Latvia was okay.

Upgraded to 4.6 and lost the ability to bridge between a VLAN tagged interface and the internal switch on a RB750. Downgrade to 4.5 made it work again.