Community discussions

Search found 148 matches

by kobuki
Sat Oct 05, 2019 9:26 pm
Forum: General
Topic: VLAN between CRS328 and RB1100AHx4 not working [SOLVED]
Replies: 10
Views: 3144

Re: VLAN between CRS328 and RB1100AHx4 not working [SOLVED]

Not all of it, you should keep vlan20 and related L3 setup ... And make sure you firewall VLAN20 from the rest of LANs (and WAN) on your main router. The trouble with (over-configured) L3 devices is that they can become routers between subnets (VLANs) in which they have L3 setup if admin doesn't pr...
by kobuki
Sat Oct 05, 2019 8:05 pm
Forum: General
Topic: VLAN between CRS328 and RB1100AHx4 not working [SOLVED]
Replies: 10
Views: 3144

Re: VLAN between CRS328 and RB1100AHx4 not working [SOLVED]

BTW, if you're trying to ping CRS' address, you can't because br-trunk has to be tagged member of itself. Same goes with RB ... . Thanks. This seems to have been the key... Weird but logical. I'll do some tests and set this thread solved for others if all is fine. Not many live devices on the acces...
by kobuki
Sat Oct 05, 2019 5:14 pm
Forum: General
Topic: VLAN between CRS328 and RB1100AHx4 not working [SOLVED]
Replies: 10
Views: 3144

Re: VLAN between CRS328 and RB1100AHx4 not working [SOLVED]

OK, I changed the bridge/port config per suggestions, but it still doesn't work. By that I mean not a single ping is working between the 2 devices with this setup on neither VLAN. With torch or packet capture it's obvious that the packets are not tagged properly so they don't flow in the right VLAN....
by kobuki
Sat Oct 05, 2019 4:53 pm
Forum: General
Topic: VLAN between CRS328 and RB1100AHx4 not working [SOLVED]
Replies: 10
Views: 3144

Re: VLAN between CRS328 and RB1100AHx4 not working [SOLVED]

Yup, leave pvid set to 1 or whichever vid you're not going to use. How things work: if a port has pvid set, it will add VLAN tag to any untagged packets on ingress. And natural configuration would be to have same port set as untagged member of same VLAN ... so that VLAN tags get stripped on egress....
by kobuki
Sat Oct 05, 2019 4:23 pm
Forum: General
Topic: VLAN between CRS328 and RB1100AHx4 not working [SOLVED]
Replies: 10
Views: 3144

Re: VLAN between CRS328 and RB1100AHx4 not working [SOLVED]

1st rule: don't use pvid on bridge, rather explicitly configure vlan interface with appropriate vid (as you have it later in the config) 2nd rule: don't ever use pvid on trunk interfaces, run them all tagged (right now you have configuration mismatch... ether1 n CRS and ether2 on RB have pvid=10 se...
by kobuki
Sat Oct 05, 2019 3:07 pm
Forum: General
Topic: VLAN between CRS328 and RB1100AHx4 not working [SOLVED]
Replies: 10
Views: 3144

VLAN between CRS328 and RB1100AHx4 not working [SOLVED]

I'd like to achieve a simple network (to be later expanded), where the RB1100AHx4 is the main gateway and the CRS328-24P-4S+ the distribution/access switch. For now, I have 2 VLANs, ID 10 and 20. I want to connect the VLANs between the devices and provide DHCP on VLAN 10, while VLAN 20 is an adminis...
by kobuki
Thu Sep 05, 2019 7:58 pm
Forum: General
Topic: OpenVPN SHA256 + UDP
Replies: 56
Views: 23084

Re: OpenVPN SHA256 + UDP

I already mentioned two of those. Support is in mainline for ages. Both stable, widely used. As for security, both can work unprivileged (no root access at all). A chroot is not a solution. But it's up to MT anyway and I'm not really keeping my hopes up in either subject.
by kobuki
Thu Sep 05, 2019 7:23 pm
Forum: General
Topic: OpenVPN SHA256 + UDP
Replies: 56
Views: 23084

Re: OpenVPN SHA256 + UDP

I know what MR is and I used to use and test it. But it's not supported well and I have no idea what technology it uses. Seems left in ROS as a feature but it's effectively abandoned.
by kobuki
Thu Sep 05, 2019 12:39 pm
Forum: General
Topic: OpenVPN SHA256 + UDP
Replies: 56
Views: 23084

Re: OpenVPN SHA256 + UDP

I don't recall any of the device series released in the last couple of years actively supporting or advertising any kind of virtualization (not talking about x86 solutions here). Only one should be supported, if ever, not 2 or more. That wouldn't make sense. If the technology changes, so be it, but ...
by kobuki
Thu Sep 05, 2019 12:30 pm
Forum: General
Topic: OpenVPN SHA256 + UDP
Replies: 56
Views: 23084

Re: OpenVPN SHA256 + UDP

VIrtualization is a ubiquitous technology nowadays. Almost all x86 and many ARM platforms (and more) are capable of running it. Kernel/cgroup based technologies (eg. Docker, LXC) are practically available anywhere where a Linux kernel is running. It's not rudimentary, it's rock solid (when properly ...
by kobuki
Thu Sep 05, 2019 12:09 pm
Forum: General
Topic: OpenVPN SHA256 + UDP
Replies: 56
Views: 23084

Re: OpenVPN SHA256 + UDP

If at least we had a robust implementation of any virtualization tech in ROS for the lower-end devices, we would be able to add an image with a fully working OVPN implementation. It really baffles me that wherever we use MT devices and use OVPN (much more user friendly and easier to manage, support ...
by kobuki
Wed Sep 04, 2019 10:38 pm
Forum: General
Topic: OpenVPN SHA256 + UDP
Replies: 56
Views: 23084

Re: OpenVPN SHA256 + UDP

this is an issue since 2010 It's almost like a disincentive in spite of other VPN tech like IPSEC which has a quite good implementation that keeps evolving. In retrospect, what we heard in the last 10 years about why NOT implement it properly sound like really bad excuses. Or it's an indisclosable ...
by kobuki
Wed Sep 04, 2019 9:16 pm
Forum: General
Topic: OpenVPN SHA256 + UDP
Replies: 56
Views: 23084

Re: OpenVPN SHA256 + UDP

Something with a proper implementation. Selecting, testing and proof of concept starts within two months.

No further disclosures.
Will you be allowed to tell after final selection is done?
by kobuki
Wed Sep 04, 2019 9:12 pm
Forum: General
Topic: OpenVPN SHA256 + UDP
Replies: 56
Views: 23084

Re: OpenVPN SHA256 + UDP

If nothing changes very very soon, I have to replace my tiks. Talking over 3000 devices. Replaments will come.
May I ask what the replacements will be?
by kobuki
Mon Jul 01, 2019 1:36 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 69342

Re: v6.45.1 [stable] is released!

Will CVE fixes get into the 6.43 LTS version?
by kobuki
Sun Jun 30, 2019 3:20 pm
Forum: General
Topic: OpenVPN SHA256 + UDP
Replies: 56
Views: 23084

Re: OpenVPN SHA256 + UDP

Hello Mikrotik Engineers, I know you have received many requests regarding OpenVPN UDP support, however it is proving almost impossible to get a clear answer. I'm all for Mikrotik and I use a lot of their devices, physical and virtual ROS, and they are mostly great, but I'm afraid proper OVPN suppo...
by kobuki
Tue Jun 18, 2019 5:51 pm
Forum: General
Topic: Linux vulnerabilities: CVE-2019-11477, CVE-2019-11478, CVE-2019-11479
Replies: 15
Views: 3002

Re: Linux vulnerabilities: CVE-2019-11477, CVE-2019-11478, CVE-2019-11479

None of these CVE-s are noted in the MT Security Blog and thus they are not real! ;-) Let's hope they have taken note and will issue an official comment and a patch. It's already in upstream. Yes, I do have some ports forwarded but not in the 0-500 range The TCP MSS is a TCP/IP specific parameter, ...
by kobuki
Tue Jun 18, 2019 12:23 pm
Forum: General
Topic: Linux vulnerabilities: CVE-2019-11477, CVE-2019-11478, CVE-2019-11479
Replies: 15
Views: 3002

Re: Linux vulnerabilities: CVE-2019-11477, CVE-2019-11478, CVE-2019-11479

There are fixes in kernel upstream for these vulnerabilities. Will Mikrotik apply them in a security release?
by kobuki
Fri Feb 08, 2019 1:21 am
Forum: General
Topic: Bridge VLAN filtering blocks all traffic
Replies: 13
Views: 766

Re: Bridge VLAN filtering blocks all traffic

So ether 5 is a TRUNK port and not an access port?????
Yes.
by kobuki
Thu Feb 07, 2019 11:21 pm
Forum: General
Topic: Bridge VLAN filtering blocks all traffic
Replies: 13
Views: 766

Re: Bridge VLAN filtering blocks all traffic

/interface bridge vlan
add bridge=bridge-lan tagged=bridge-lan,ether5 vlan-ids=20
This one solved it, thanks! I know the PVIDs are redundant but they do practically nothing in this setup, so it doesn't hurt either. ROS defaults to PVID 1 and I tend to change it from 1 to one of my VLAN IDs.
by kobuki
Thu Feb 07, 2019 11:04 pm
Forum: General
Topic: Bridge VLAN filtering blocks all traffic
Replies: 13
Views: 766

Re: Bridge VLAN filtering blocks all traffic

@sebastia, @mkx, thanks, one of these might be the overlook, I'll try them and also anav's suggestions. @anav: thanks for the thorough inspection of the export, but please don't mind all the defaults and missing bits (dhcp, pool, etc.), when I'll have the vlan issue fixed, I'll reconfigure the whole...
by kobuki
Thu Feb 07, 2019 9:50 pm
Forum: General
Topic: Bridge VLAN filtering blocks all traffic
Replies: 13
Views: 766

Re: Bridge VLAN filtering blocks all traffic

From the full config you can see that ether5 is added to bridge-lan, and that is the interface connected to a trunk port on a switch with vlan 20 where only tagged packets travel. If I add the vlan on ether5, it starts working, with vlan filtering turned on. It's as if vlan filtering only allows tra...
by kobuki
Thu Feb 07, 2019 9:40 pm
Forum: General
Topic: Bridge VLAN filtering blocks all traffic
Replies: 13
Views: 766

Re: Bridge VLAN filtering blocks all traffic

It's a basic test config not too far from the default one. Thanks.
by kobuki
Thu Feb 07, 2019 9:33 pm
Forum: General
Topic: Bridge VLAN filtering blocks all traffic
Replies: 13
Views: 766

Re: Bridge VLAN filtering blocks all traffic

Thanks, I did that, but it didn't help. It's not an inter-VLAN routing problem, though, since I have only one VLAN. Unless I'm misunderstanding something, of course. /interface bridge vlan add bridge=bridge-lan tagged=bridge-lan vlan-ids=20 /interface bridge vlan print detail Flags: X - disabled, D ...
by kobuki
Thu Feb 07, 2019 8:59 pm
Forum: General
Topic: Bridge VLAN filtering blocks all traffic
Replies: 13
Views: 766

Bridge VLAN filtering blocks all traffic

I'd like to use the VLAN filtering capability on a HAP AC2. No HW chip VLAN settings are used, all are on defaults since I want to use the bridge facility for this entirely. This is the config I'm using: /interface bridge add fast-forward=no frame-types=admit-only-vlan-tagged ingress-filtering=yes n...
by kobuki
Sat Sep 15, 2018 10:37 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88700

Re: Winbox vulnerability: please upgrade

What do you want to say? Have you example of hacked 6.42.7 or are you just guessing and making noise? One of a client's main router with ros 6.42.7 has been compromised and a lot of traffic was beeing generated before i replace it for a new one. Ros 6.42.7 with only winbox port open to web, and the...
by kobuki
Sat Sep 08, 2018 6:08 pm
Forum: General
Topic: IPSEC between public IPs intermittently working
Replies: 1
Views: 342

Re: IPSEC between public IPs intermittently working

I removed the ipsec config for a while since the unsecured connection works between the 2 IPs and we need to do traffic between the peers. However I need the secure the connection, so I added the same config again. When I ping eg. IP2 from IP1, I see egress traffic in Torch on ether1 (the IF with th...
by kobuki
Wed Sep 05, 2018 5:24 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88700

Re: Winbox vulnerability: please upgrade

Currently heise.de writes about attacks on Mikrotik-Devices. Maybe you can correct something on the part of Mikrotik, because the news does not sound good. https://www.heise.de/security/meldung/Spionage-und-Krypto-Mining-MikroTik-Router-angreifbar-4155288.html It looks like a clickbait, smelling pi...
by kobuki
Thu Aug 30, 2018 11:57 pm
Forum: General
Topic: IPSEC between public IPs intermittently working
Replies: 1
Views: 342

IPSEC between public IPs intermittently working

I've set up a tunnel between 2 routers, one RB850Gx2 (6.42.7), and one x86 (6.42.6) in a KVM virtual environment. The connection is established, but it frequently drops the ball and no traffic can pass between them. Sometimes it works for a full day, then drops again for extended periods. There're n...
by kobuki
Thu Aug 23, 2018 4:18 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88700

Re: Winbox vulnerability: please upgrade

They do respond partially on port 80, but act strangely.

What do you mean by that?
by kobuki
Wed Aug 08, 2018 3:00 am
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88700

Re: Winbox vulnerability: please upgrade

Is he trying to use Winbox to connect
No idea, but possible.
how would you route a Winbox connection through a socks proxy?
I assume that's a rhetorical question.
by kobuki
Wed Aug 08, 2018 2:44 am
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88700

Re: Winbox vulnerability: please upgrade

It was empty where I checked, too. It's possibly just a presence indicator in the swarm for the C&C as you also mentioned...
by kobuki
Wed Aug 08, 2018 2:17 am
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88700

Re: Winbox vulnerability: please upgrade

Now I can remote login to the infected router with user "sys" via SOCK
Good! Thanks for the feedback. Your attacker was a particularly malicious one, almost locking you out completely. Almost.
by kobuki
Tue Aug 07, 2018 8:06 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88700

Re: Winbox vulnerability: please upgrade

2. I have try to login to remote mikrotik with that password but no success so I think the problem come from the hacker allow only IP 127.0.0.1 to login with "sys" account. And the hacker use script to disable hard reset, so I just ask can I use the serial cable to login. (infected router is still ...
by kobuki
Mon Aug 06, 2018 12:46 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88700

Re: Winbox vulnerability: please upgrade

We have added more details, so that it is more clear:
https://blog.mikrotik.com/security/winb ... ility.html
It would be really useful to bump that post with today's date and tag with (UPDATED) or something.
by kobuki
Sun Aug 05, 2018 1:09 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88700

Re: Winbox vulnerability: please upgrade

... Create Security mailing list (the Blog you created is a nice step forward, but this is useful for "post event summary" and maybe not exactly for urgent security advisories). ... [/b][/i] I think this one would be very useful. I for one am subscribed to multiple ones already, and do pay attentio...
by kobuki
Fri Aug 03, 2018 8:02 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88700

Re: Winbox vulnerability: please upgrade

So what about version 6.40.8, is vulnerable or not? Could somebody from Mikrotik finally confirm it? Have you read the first post of this thread? EDIT: hmm, now that you asked, and reading the blog post again, it's really not very apparent which version pertains to which release branch at a single ...
by kobuki
Fri Aug 03, 2018 6:03 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88700

Re: Winbox vulnerability: please upgrade

Since the attacker is inserting his script into the targeted routers and changing configuration in them, we recommend to carefully inspect the configuration of your device, restore it from verified backups or export files, and follow generic advice in the above links. What sorts of changes are bein...
by kobuki
Fri Aug 03, 2018 2:41 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88700

Re: Winbox vulnerability: please upgrade

Figuratively asking: Are you saying that Mikrotik has hundreds of thousands devices? No, users are owners of them. Should Mikrotik call/inform each user/owner and "persude" to upgrade? What if user says NO? What if admins in DC ignore such info? I'm not "advocatus diaboli" of Mikrotik but you shoul...
by kobuki
Fri Aug 03, 2018 12:55 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88700

Re: Winbox vulnerability: please upgrade

Hopefully the userdb (and every bit doing anything with passwords in ROS) gets hashes for passwords from now on, and hopefully a modern one. From "now on"? Really? Like stated repeatedly, this has been fixed a long time ago. This is just a reminder AGAIN to please upgrade, where all these things ar...
by kobuki
Fri Aug 03, 2018 12:58 am
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88700

Re: Winbox vulnerability: please upgrade

This vulnerablity is from 6.28. I try it: https://github.com/BigNerd95/WinboxExploit https://github.com/BasuCert/WinboxPoC On the first link WinboxExploit.py reveals that the admin password is stored in the clear in the device. It simply requests the userdb and prints stuff found at offset 55. Mind...
by kobuki
Fri Jul 20, 2018 5:31 pm
Forum: Wireless Networking
Topic: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi
Replies: 288
Views: 60797

Re: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi

hi guys considering buying one of these for general home use.. want to use it for wifi & VPN. Would wifi be ok using latest stock f/w for general home use? whats best speed anyones got using VPN single tunnel 256bit? cheers See here . I was able to saturate my 110 Mb downstream using AES-128+SHA256...
by kobuki
Tue Jul 17, 2018 7:34 pm
Forum: RouterBOARD hardware
Topic: CRS354-48P-4S+2Q+ Dimensions
Replies: 5
Views: 1805

Re: CRS354-48P-4S+2Q+ Dimensions

Does anyone have the depth of the new CRS354-48P-4S+2Q+?

I am curious if it will fit into some customer wall mount racks.
Maybe this helps a bit.
by kobuki
Mon Jul 16, 2018 5:12 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 vs RB450Gx4
Replies: 49
Views: 10518

Re: RB850Gx2 vs RB450Gx4

It doesn't work.
Well, I guess that would nail it for @acruhl then.
by kobuki
Mon Jul 16, 2018 5:07 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 vs RB450Gx4
Replies: 49
Views: 10518

Re: RB850Gx2 vs RB450Gx4

Metarouter does not work on RB850Gx2.
The menu is actually there in Winbox, but it doesn't work? Never tried it since I don't need it at that site.
by kobuki
Mon Jul 16, 2018 12:23 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 vs RB450Gx4
Replies: 49
Views: 10518

Re: RB850Gx2 vs RB450Gx4

Why shouldn't I buy the RB850Gx2? ARM SOCs are faster, run a lot colder and more commonplace (~= cheaper). If you don't need the additional speed of IPSEC HW acceleration, there's no real need to consider the outdated RB850Gx2. The new one beats it in every other way. EDIT: oh, and the RB850Gx2 doe...
by kobuki
Mon Jun 25, 2018 8:42 pm
Forum: Announcements
Topic: v6.42.4 [current]
Replies: 93
Views: 16460

Re: v6.42.4 [current]

@mducharme: thanks for the heads-up about STP. I might switch to standard bridge config later, for now it works so I'll just let it be. I need remote hands to power-cycle, so maybe tomorrow. Luckily the SFP cage is vacant.
by kobuki
Mon Jun 25, 2018 8:29 pm
Forum: Announcements
Topic: v6.42.4 [current]
Replies: 93
Views: 16460

Re: v6.42.4 [current]

@mducharme: in the meantime I've "found" the VLAN filtering option (I was in a kind of hurry to bring things back online), so I'll start testing it on the RB2011. I've modified my original post, removing the false info. So it might become possible to use the bridge config and ditch the old switch co...
by kobuki
Mon Jun 25, 2018 7:48 pm
Forum: Announcements
Topic: v6.42.4 [current]
Replies: 93
Views: 16460

Re: v6.42.4 [current]

RB2011 upgrade from 6.34.2. - VLANs are not converted - new bridge is not created but interface master-slave relations removed - after removing all VLANs to re-create the configuration manually using a new bridge, 2 bridges are automagically created somehow (RB2011 has 2 switch groups) and interface...
by kobuki
Mon Jun 25, 2018 3:16 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 vs RB450Gx4
Replies: 49
Views: 10518

Re: RB850Gx2 vs RB450Gx4

I found this page on the HAP AC2 the other day. I thought it's relevant because the CPU is almost the same, barring wlan capabilities in the RB450Gx4. It's mostly throughput tests (including PPPoE over Gbit), in Russian but the screen shots should speak for themselves.
by kobuki
Thu Jun 21, 2018 10:18 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 vs RB450Gx4
Replies: 49
Views: 10518

Re: RB850Gx2 vs RB450Gx4

@chechito: I stated my needs. I don't need a $300 router. Believe me, I don't mix up heavy queues with some NAT or filter rules. I also separate my APs and gateway, though HAP AC^2 and RB450Gx4 use a similar CPU. After reading posts on other forums and also here I concluded that the RB450Gx4 would b...
by kobuki
Tue Jun 19, 2018 7:36 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 vs RB450Gx4
Replies: 49
Views: 10518

Re: RB850Gx2 vs RB450Gx4

@chechito, chanks for the insight, though comparing the devices in itself doesn't tell much. Obviously the RB1100 series is way faster. But many small, cheap routers are capable of what I ask and I think for MT to stay competitive in that price range they should be able to handle that, too. There's ...
by kobuki
Tue Jun 19, 2018 2:22 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 vs RB450Gx4
Replies: 49
Views: 10518

Re: RB850Gx2 vs RB450Gx4

I'm considering the local provider's gigabit GPON offering, which comes with an ONT with AC wifi, but I Want to use the PPPoE pass-through option. Would I be able to saturate Gbit wtih an RB450Gx4 and PPPoE using NAT and around 10 effective FW rules? Has really no one attempted using Gbit PPPoE on ...
by kobuki
Sat Jun 16, 2018 7:21 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 vs RB450Gx4
Replies: 49
Views: 10518

Re: RB850Gx2 vs RB450Gx4

I'm considering the local provider's gigabit GPON offering, which comes with an ONT with AC wifi, but I Want to use the PPPoE pass-through option. Would I be able to saturate Gbit wtih an RB450Gx4 and PPPoE using NAT and around 10 effective FW rules?
by kobuki
Sat Mar 31, 2018 2:16 am
Forum: General
Topic: Problems with mynetname.net cloud IP service DNS
Replies: 7
Views: 3837

Re: Problems with mynetname.net cloud IP service DNS

I would highly doubt that the existing name servers would be having degradation from legitimate updates or queries.

With 60 sec TTL it's entirely possible, but it was just a guess. If it keeps being DDOS'd, then well, SOL. And yes, using the serial directly in the host name is not a bright idea.
by kobuki
Fri Mar 30, 2018 11:12 pm
Forum: General
Topic: Problems with mynetname.net cloud IP service DNS
Replies: 7
Views: 3837

Re: Problems with mynetname.net cloud IP service DNS

I raised my concerns about the built-in function, the thread is not about the alternatives that I know and use as well (dns.he.net or freedns.afraid org are good examples among many). The functionality is a good addition to RouterOS but the backing service is flaky. Mikrotik might have underestimate...
by kobuki
Thu Mar 29, 2018 2:28 pm
Forum: Announcements
Topic: Urgent security advisory
Replies: 110
Views: 89605

Re: Urgent security advisory

(post Removed as others have answered my question)
by kobuki
Wed Mar 28, 2018 11:18 pm
Forum: Announcements
Topic: Urgent security advisory
Replies: 110
Views: 89605

Re: Urgent security advisory

Pardon me, but specifying "www server" is not clear, at all. A serious security vulnerability merits more than vague statements about services. Do the scripts only scan port 80? Are we safe behind HTTPS (which still fall under the "www server" category) or not? Etc. You're obviously not very familia...
by kobuki
Wed Mar 28, 2018 10:40 pm
Forum: Announcements
Topic: Urgent security advisory
Replies: 110
Views: 89605

Re: Urgent security advisory

Just to make it clear: only devices running a not up-to-date RouterOS version are affected, whose HTTP port (TCP/80) are open and provides the login facility and management GUI, right? I never allow unencrypted connections and always disable the HTTP and HTTPS interfaces. Only SSH and Winbox is enab...
by kobuki
Wed Mar 28, 2018 4:19 pm
Forum: General
Topic: Problems with mynetname.net cloud IP service DNS
Replies: 7
Views: 3837

Re: Problems with mynetname.net cloud IP service DNS

Nice to know that you take note of the problems, however it's still serviced from a single unicast IPv4 address...
by kobuki
Tue Mar 13, 2018 4:19 pm
Forum: General
Topic: Problems with mynetname.net cloud IP service DNS
Replies: 7
Views: 3837

Problems with mynetname.net cloud IP service DNS

See here for an overview: https://intodns.com/mynetname.net One server is not answering, lame delegation, etc, quite a handful. I'm a bit concerned about these DNS servers, there's only 2 of them for the "cloud" dynamic names, apparently no real strong clould backing infrastructure is present. Do yo...
by kobuki
Thu Aug 17, 2017 10:46 pm
Forum: Announcements
Topic: v6.41rc [release candidate] is released! New bridge implementation!
Replies: 561
Views: 123500

Re: v6.41rc [release candidate] is released! New bridge implementation!

With the new bridge implementation using HW offload, will it be possible to use multiple bridges using the offload capability, effectively creating multiple "switch groups" that retain wire speed in the group? It's now possible to do something similar using VLANs where each VLAN has a CPU port besid...
by kobuki
Mon May 23, 2016 4:35 pm
Forum: General
Topic: Using Huawei E3372 3G/4G stick
Replies: 20
Views: 5872

Re: Using Huawei E3372 3G/4G stick

@pe1chl: well, it was my mistake, the ack mail landed in the spam folder after all. It got lost with the junk there but just found it. I hope they can fix the issue. It works for you, it should for me as well. I hope it's not a faulty HAP AC where I tested it.
by kobuki
Mon May 23, 2016 11:22 am
Forum: General
Topic: Using Huawei E3372 3G/4G stick
Replies: 20
Views: 5872

Re: Using Huawei E3372 3G/4G stick

@pe1chl, can you please tell me what version of the srick you use? There're different series, 21.xx, 22.xx. Also, did you make any special settings?

My host is not spamming but that's only relevant when sending mails out of it, not when receiving...
by kobuki
Sun May 22, 2016 10:45 pm
Forum: General
Topic: Using Huawei E3372 3G/4G stick
Replies: 20
Views: 5872

Re: Using Huawei E3372 3G/4G stick

I also have a Huawei E3372, it works fine in Hilink mode under Debian Linux 8, kernel 4.2, but I can't make it work on my HAP AC. The modem is stuck in the vendor-id="0x12d1" device-id="0x1508" configuration, which is the "basic" mode without the Hilink interface. Linux can switch it to device-id="0...
by kobuki
Fri Apr 22, 2016 1:54 am
Forum: General
Topic: Regular x86 mikrotik vs CHR with a non-virtualized machine
Replies: 6
Views: 2161

Re: Regular x86 mikrotik vs CHR with a non-virtualized machine

Hi guys, We have bought a 2U Dell Server with 4 Dual 10Gbps ports and we would like to install RouterOS or CHR on it in order to overcome the BGP limitations of our CCR1036. We are not going to install anything else on this server to make sure it has all the power available to handle our multigigab...
by kobuki
Fri Apr 22, 2016 1:48 am
Forum: General
Topic: Regular x86 mikrotik vs CHR with a non-virtualized machine
Replies: 6
Views: 2161

Re: Regular x86 mikrotik vs CHR with a non-virtualized machine

For example x86 don't have virtio drivers, so you can't install RouterOS on a public cloud like Amazon EC2, Azure, or like it.
The installable x86 version does include virtio drivers, I use virtualised ROS instances at multiple places (on KVM, not Xen) with virtio, without problems.
by kobuki
Wed Apr 20, 2016 6:55 pm
Forum: Beginner Basics
Topic: Simple solution for prioritising IPSEC traffic
Replies: 0
Views: 465

Simple solution for prioritising IPSEC traffic

I'm not exactly new to Mikrotik and RouterOS in general, but aside from simple queues for DL/UL limitations, I've worked very little with them. I'd like to employ a simple priority measure for the IPSEC/ESP tunnel we installed between 2 offices. Sometimes the tunnel suffers because of other inetrnet...
by kobuki
Fri Feb 12, 2016 9:28 pm
Forum: RouterBOARD hardware
Topic: HAP AC
Replies: 540
Views: 134244

Re: HAP AC

kobuki product is called hAP AC (the same name as topic). I think it is easy name to remember. RB962UiGS-5HacT2HnT is product code, and it collects all information you need to know about ports and features (if you like). Thanks -- however the post where I noted that it was meant to be a joke and I ...
by kobuki
Wed Feb 10, 2016 2:25 pm
Forum: RouterBOARD hardware
Topic: HAP AC
Replies: 540
Views: 134244

Re: HAP AC

I'm glad it appeared finally. I have the AC Lite and it's fine so far, I'll probably replace an older TP-Link dualband as soon as I can get hold of a HAP AC, for testing.
by kobuki
Mon Dec 14, 2015 1:45 am
Forum: RouterBOARD hardware
Topic: Ubiquiti ERLite3 beats Mikrotik RB1100AHx2 on performance. Can it be possible?
Replies: 18
Views: 4138

Re: Ubiquiti ERLite3 beats Mikrotik RB1100AHx2 on performance. Can it be possible?

My experience...it depends on your understanding of "beating"..... I have just, finally, thanks my God, replaced an ERLITE-3 by an RB/3011 on a 300/300 Mbits PPOE/Nated fiber connection with IPTV and IP phone...unbeliable: back to have a router in a corner of my house acting as a router and not cal...
by kobuki
Wed Dec 02, 2015 11:50 am
Forum: RouterBOARD hardware
Topic: hEX nand size ONLY 16MB !!!!
Replies: 61
Views: 16936

Re: hEX nand size ONLY 16MB !!!!

I'm not very concerned about the problem, but I find it weird that with ever falling flash prices, Mikrotik wants to save the pennies on it. In large volumes, it turns into profit, that's for sure, but still...
by kobuki
Mon Aug 17, 2015 5:34 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 - Release date?
Replies: 193
Views: 47457

Re: RB850Gx2 - Release date?

Has anyone been able to conduct IPSEC throughput tests on the new RB850Gx2 with HW acceleration? My local supplier is already selling them with the new serial but I'm hesitant to buy them for new projects just for this feature yet.
by kobuki
Wed Aug 05, 2015 5:30 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 187951

Re: Cloud Hosted Router

Please consider adding the recognition of extra virtual disks to the appliance. Additional virtual storage space would be very useful for larger web caches, FTP or Samba servers as a simple and easy alternative to other storage appliaces with no fancy requirements. Will this be possible in the fina...
by kobuki
Tue Aug 04, 2015 10:49 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 187951

Re: Cloud Hosted Router

Great Idea. I'm already using several instances of ROS on virtualised platforms for live virtual systems and for testing. When a polished final product, I'm sure it will be a success. Please consider adding the recognition of extra virtual disks to the appliance. Additional virtual storage space wou...
by kobuki
Tue Aug 04, 2015 1:08 am
Forum: General
Topic: Static route and gateway on different subnet not working
Replies: 6
Views: 2541

Re: Static route and gateway on different subnet not working

Shaoranrch, thanks for the extensive answer. Your explanation is of course, logical, and I'm aware of the basics of IP resolution within L2 broadcast domains, but at a point it seems to contradict my findings where I said I could just ping the gateway IP just fine, yet ROS refused to use it. OTOH, I...
by kobuki
Mon Aug 03, 2015 12:59 am
Forum: General
Topic: Static route and gateway on different subnet not working
Replies: 6
Views: 2541

Re: Static route and gateway on different subnet not working

Well, I solved this, kind of. /ip address add address=88.x.x.177 interface=ether2 network=78.y.y.132 /ip route add gateway=78.y.y.132 ROS automatically adds a host route for 78.y.y.132 (main ip of the host machine, outside of the routed /29 subnet) on ether2 and I can use it as gateway for the /29 e...
by kobuki
Sun Aug 02, 2015 3:09 am
Forum: General
Topic: Static route and gateway on different subnet not working
Replies: 6
Views: 2541

Re: Static route and gateway on different subnet not working

Well, I have tried your suggestions, but neither of them is working on RouterOS. I can't make it work, whatever I try. I even enabled proxy arp on the host so the upstream gw appears as directly connected IP, to no avail. If the ROS doesn't have an IP from the same subnet as the gateway, it doesn't ...
by kobuki
Sun Aug 02, 2015 12:06 am
Forum: General
Topic: Static route and gateway on different subnet not working
Replies: 6
Views: 2541

Re: Static route and gateway on different subnet not working

Thanks, pukkita, I'll try this tomorrow and report back.
by kobuki
Sat Aug 01, 2015 7:53 pm
Forum: General
Topic: Static route and gateway on different subnet not working
Replies: 6
Views: 2541

Static route and gateway on different subnet not working

I'm trying to create a simple config at a datacenter where I am allocated a single "main" IP with a default GW on the same subnet. All is fine. Then I requested for an additional subnet which is statically routed to this main IP. It's from a different, arbitrary subnet. This setup is virtualised, wi...
by kobuki
Fri Jun 26, 2015 12:17 am
Forum: General
Topic: Weird IPSEC problem
Replies: 5
Views: 1048

Re: Weird IPSEC problem

Well, I actually solved it at last. I don't know what the problem was, I rebuilt the IPSEC config from scratch and poof, it started working. No config difference compared to what I've shown earlier, that I know of. Weird.
by kobuki
Thu Jun 25, 2015 11:09 pm
Forum: General
Topic: Weird IPSEC problem
Replies: 5
Views: 1048

Re: Weird IPSEC problem

Oops, my mis-read, sorry. I'm used to mis-configuring it myself where I put the connect-to IP in instead of the remote-LAN IP, glossed over your opening statement, sorry. Do you have a regular client connection that works with these settings? To me, the MT settings look correct and I'd be inclined ...
by kobuki
Thu Jun 25, 2015 10:02 pm
Forum: General
Topic: Weird IPSEC problem
Replies: 5
Views: 1048

Re: Weird IPSEC problem

You need your /ip firewall nat rule (the bypass rule) to match the local and remote private networks. So, if the local side is 192.168.1.0/24 and the remote side is 192.168.2.0/24, your NAT bypass rule would be as follows: /ip firewall nat add chain=srcnat src-address=192.168.1.0/24 dst-address=192...
by kobuki
Thu Jun 25, 2015 9:13 pm
Forum: General
Topic: Weird IPSEC problem
Replies: 5
Views: 1048

Weird IPSEC problem

I'm trying to create an ipsec tunnel to a host where the destination subnet and remote public endpoint is both the same single public IP address, that is, it's a seemingly simple config where they allow access to a single public address from our small local subnet. The ipsec config looks like this: ...
by kobuki
Thu Jun 25, 2015 12:42 am
Forum: Announcements
Topic: FastTrack - New feature in 6.29
Replies: 237
Views: 139916

Re: FastTrack - New feature in 6.29

Are you really complaining about not getting an answer in a forum within 8 hours?
Check your clock, please. It was about a day later.

But no. It was merely a rhetorical question, if that helps to satisfy your curiosity (or your feeling of righteousness).
by kobuki
Wed Jun 24, 2015 9:35 pm
Forum: Announcements
Topic: FastTrack - New feature in 6.29
Replies: 237
Views: 139916

Re: FastTrack - New feature in 6.29

I wonder if I ever get an answer...
by kobuki
Wed Jun 24, 2015 1:32 am
Forum: Announcements
Topic: FastTrack - New feature in 6.29
Replies: 237
Views: 139916

Re: FastTrack - New feature in 6.29

I was anticipating this feature and installed 6.29.1 only to find out that it's not supported on my router at home which is an RB450G. It has been one of the most popular ones and there isn't a night and day difference between this and the 750G which is indeed supported. Their hardware is almost ide...
by kobuki
Wed Oct 08, 2014 2:59 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 - Release date?
Replies: 193
Views: 47457

Re: RB850Gx2 - Release date?

KVM is inherently an x86-only technology - so I'd say definitely no. You can already use KVM on RouterOS x86. It started on x86, but it has progressed far beyond that. The code is actively maintained on multiple architectures, see: http://www.linux-kvm.org/page/Status However, it's only considered ...
by kobuki
Wed Oct 08, 2014 1:01 am
Forum: RouterBOARD hardware
Topic: RB850Gx2 - Release date?
Replies: 193
Views: 47457

Re: RB850Gx2 - Release date?

we are actively working on virtualization support for multicore RouterBOARD products.
Any chance of KVM virtualisation on these boards?
by kobuki
Sun Sep 14, 2014 2:39 pm
Forum: General
Topic: Winbox 3 beta
Replies: 243
Views: 119885

Re: Winbox 3

After the announcement that 6.20 will only work with Winbox3, I started testing it a bit. I'm using Windows 7 SP1 x64 and have found that it can only save 5.x window sessions (it might save them but definitely can't load them). 6.x sessions are always started with a blank window, regardless of the s...
by kobuki
Sat Sep 13, 2014 5:01 pm
Forum: General
Topic: v6.19 released
Replies: 256
Views: 93435

Re: v6.19 released

What's new in 6.20rc6 (2014-Sep-08 10:16): *) pppoe client - increase connection timeout to make connection establishment possible on busy pppoe server; *) dhcp server - change default lease time from 3 days to 10 minutes to avoid running out of IPs; *) ipsec - allow binding modeconf address to use...
by kobuki
Thu Aug 21, 2014 2:01 pm
Forum: RouterBOARD hardware
Topic: sxt G-5HPnD-HG r2 1 km linktest results
Replies: 8
Views: 2923

Re: sxt G-5HPnD-HG r2 1 km linktest results

Is the latency of 6-7 ms I see on the images normal? I thought it would be less. Where does it come from? Wifi mod/demod or packet transmission time (not the radio wave speed), inherent device latency, or something else?
by kobuki
Tue Aug 12, 2014 9:29 pm
Forum: Virtualization
Topic: Hyper-V integration components
Replies: 127
Views: 62687

Re: Hyper-V integration components

Some news: http://www.brocade.com/forms/jsp/vyatta-download/index.jsp?src=WS&lsd=Banner&lst=BRCD&cn=SDN-GDG-14Q1-EVAL-WS-Vyatta-Download&intcmp=lp_vyatta_trial_hp_bn_00001&gcn=&ggeo= Brocade make vyatta distrib that makes that what we want from ROS in HyperV\esxi This is in a completely different l...
by kobuki
Fri Aug 08, 2014 4:57 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 - Release date?
Replies: 193
Views: 47457

Re: RB850Gx2 - Release date?

Thanks Quindor. Yes, we encountered an issue that needed to be fixed in the board design before we can start mass production. Sorry that this happened and pushed the previously estimated release date. Ah, good it hasn't been abandoned. You could have told us earlier... such a simple note. Awaiting ...
by kobuki
Thu Jul 03, 2014 9:56 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 - Release date?
Replies: 193
Views: 47457

Re: RB850Gx2 - Release date?

Haha nice . Didn't even notice the CCR1009 has a switch port , I just assumed it lacked it like all the other CCR's. I think I pretty much found my replacement device for the 2011's now. Yeah. But unfortunately it has active cooling (a fan). Not an ideal choice for a fast broadband connection for a...
by kobuki
Tue Jul 01, 2014 3:23 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 - Release date?
Replies: 193
Views: 47457

Re: RB850Gx2 - Release date?

Maybe they've withdrawn it, not wanting to create an inbreed competition to their own low-end Tilera-based devices... Or are fine-tuning and testing the code to be the finest possible ever made for a MikroTik router :) Anyway I'm also eager to try it and replace one or 2 450G and 2011. Dual-core PPC...
by kobuki
Fri Jun 06, 2014 10:30 pm
Forum: General
Topic: v6.13 released!
Replies: 177
Views: 48922

Re: v6.13 released!

I've upgraded an RB2011L-IN to 6.13 a few days ago, and I' observing a strange CPU behaviour. The average CPU usage is higher by about 2-3% and there are randomly repeating very short 100% usage spikes, without any significant traffic or other measurable activity (in the middle of the night for exam...
by kobuki
Thu Nov 21, 2013 12:13 pm
Forum: Virtualization
Topic: Hyper-V integration components
Replies: 127
Views: 62687

Re: Hyper-V integration components

I'm using an MT5 instance on a VM too (Proxmox PVE, KVM, virtio NICs). It's working fine. Also shortly tested 6, no problems. But I can fully understand that those already having a Hyper-V infrastructure in place, would want to run ROS on it. All that is missing is some modules? And MT is not willin...
by kobuki
Mon Nov 18, 2013 8:22 pm
Forum: General
Topic: RouterOS v6.6 released
Replies: 164
Views: 72647

Re: RouterOS v6.6 released

On RB450G, when I change the MAC of ether1 to match the one required by my ISP, no stats are displayed. "Overall Stats", "Rx Stats", "Tx Stats" windows are empty. Traffic graphs are OK. This error is present since 5.23 as far as can remember, but for all 6.x versions I tried on this router, for sure.
by kobuki
Sun Nov 17, 2013 1:03 pm
Forum: General
Topic: RouterOS v6.6 released
Replies: 164
Views: 72647

Re: RouterOS v6.6 released

i have this issue with certifcates as well. seems winbox thinks its 365 regardless of the actual date
I can also confirm this. Simply forgot to report in my previous post.
by kobuki
Fri Nov 15, 2013 9:17 pm
Forum: General
Topic: RouterOS v6.6 released
Replies: 164
Views: 72647

Re: RouterOS v6.6 released

Certificate export is not working. RB2011LS-IN, Windows 7 SP1 x64 running Winbox. When I press Export in the certificate details window, Winbox exits in an instant and all windows settings since its last start are lost. Also, cannot rename the certificate, it says "certificate subject is read only!"...
by kobuki
Tue May 14, 2013 12:00 am
Forum: General
Topic: v6rc14 released
Replies: 125
Views: 30610

Re: v6rc14 released

RB450G, rc14, WinBox: ethernet interface Overall/Rx/Tx stats are completely empty or partially empty. On my router, ether1 is blank on every stats pages, and ether2 (2-4 ports switched together) is partially blank on the stats pages. ether1 has a changed MAC (ISP MAC restrictions), maybe this has so...
by kobuki
Sat May 11, 2013 3:50 am
Forum: General
Topic: problem with Graphic in router
Replies: 6
Views: 3061

Re: problem with Graphic in router

Same problem on RB450G. 5-minute interval, store on disk for every graph. After reboot, resource graphs are retained, interface graphs are missing. Using RouterOS 6rc14.
by kobuki
Mon May 06, 2013 2:50 pm
Forum: Beginner Basics
Topic: [solved] IPsec doesn't start
Replies: 0
Views: 558

[solved] IPsec doesn't start

EDIT: for a mysterious reason it suddenly started to work. Deja vu... Please help. It's a config that used to work (recreated, but it's along the same principles and the IPs are the same), but now the connection doesn't even start initialising. Enabled the IPsec debug log, but besides config changes...
by kobuki
Mon Oct 01, 2012 11:17 pm
Forum: Wireless Networking
Topic: RB800 3X3 minipci card
Replies: 46
Views: 15130

Re: RB800 3X3 minipci card

Do you think one could use 2.4 and 5 GHz in simultaneous mode on a MikroTik device, using this card?
by kobuki
Sat Sep 29, 2012 4:43 pm
Forum: RouterBOARD hardware
Topic: RB2011UAS-2HnD-IN Questions Topic
Replies: 215
Views: 92378

Re: RB2011UAS-2HnD-IN Questions Topic

It's very nice as a router or AP. But it does not perform well as switch or NAT. On the other hand, Asus RT-N66U has much better performance as gigabit switch or NAT. Well, it has 2 distinct switches, one 5-port Gbit and one 5-port fast ethernet. Switching within one switch or the other is wirespee...
by kobuki
Thu Sep 27, 2012 5:48 pm
Forum: RouterBOARD hardware
Topic: RB2011UAS-2HnD-IN Questions Topic
Replies: 215
Views: 92378

Re: RB2011UAS-2HnD-IN Questions Topic

Could any of you please provide the NAT and Switching performance via iPerf? I tried iPerf on my RB433GL and RB493G. The RB433GL has very poor performance on everything. No wonder it's low cost model. RB493G is alright, but not great! I only only get 2XX Kbps on NAT and 4XX Kbps on switch chip. I d...
by kobuki
Wed Sep 26, 2012 9:53 pm
Forum: Wireless Networking
Topic: Best AP for home use - Dual Band 2.4ghz b/g & 5ghz N
Replies: 7
Views: 12603

Re: Best AP for home use - Dual Band 2.4ghz b/g & 5ghz N

I use an RB411AR w/R52n for my AP. The integrated card for B/G w/WEP for backwards compatibility and R52n for 300Mb @ 5GHz. Works fine, though occasionally I max out the CPU with large transfers, still near 100Mb wire speed most of the time. Sorry for the possibly dumb question, I have no experienc...
by kobuki
Wed Sep 26, 2012 3:31 am
Forum: Wireless Networking
Topic: Best AP for home use - Dual Band 2.4ghz b/g & 5ghz N
Replies: 7
Views: 12603

Re: Best AP for home use - Dual Band 2.4ghz b/g & 5ghz N

I'm considering the purchase of a simultaneous dual-band device myself. Preferably MikroTik, if there's a feasible solution. Have you decided on your solution? I'm curious.
by kobuki
Wed Sep 12, 2012 12:19 am
Forum: RouterBOARD hardware
Topic: v6.0beta3 released!
Replies: 82
Views: 20672

Re: v6.0beta3 released!

You have to sign up for pre-release testing, and have to agree that some of these releases are alpha-quality. They can and will crash. Send email to support if you agree to test this.
Thanks. For a beta/RC it's pretty normal.
by kobuki
Tue Sep 11, 2012 12:51 am
Forum: RouterBOARD hardware
Topic: v6.0beta3 released!
Replies: 82
Views: 20672

Re: v6.0beta3 released!

Please excuse my ignorance, but where can I download RC1 for testing? Public pages show only 6.0b3 download links.
by kobuki
Sun Sep 09, 2012 2:39 pm
Forum: RouterBOARD hardware
Topic: v6.0beta3 released!
Replies: 82
Views: 20672

Re: v6.0beta3 released!

I thought I report this. Happening in a VMWare Workstation 9.0.0 build-812388. See attached screenshots (same error in 2 pics). Fresh install, was just about to set up an IP address. Issued a print statement under /ip address.
by kobuki
Sat Sep 08, 2012 5:36 pm
Forum: Virtualization
Topic: Hyper-V integration components
Replies: 127
Views: 62687

Re: Hyper-V integration components

I'm also evaluating the possibility of using MT in a purely MS environment using Hyper-V as hypervisor. It'd be really nice if I were able to use ROS 6 there.
by kobuki
Tue Jul 24, 2012 12:18 am
Forum: RouterBOARD hardware
Topic: Recommendations for fast cable
Replies: 10
Views: 2764

Re: Recommendations for fast cable

If anyone is interested, I've made a simple test with NAT. An adress on ether1 (representing the wan side), a subnet on ether2 (representing a lan), and a simple TCP forwarding rule from ether1_wan_ip:9999 to a virtual machine on ether2_lan_ip:9999. There is a masquerading srcnat rule for the subnet...
by kobuki
Mon Jul 23, 2012 4:38 am
Forum: RouterBOARD hardware
Topic: Recommendations for fast cable
Replies: 10
Views: 2764

Re: Recommendations for fast cable

Thanks. I've decided to try the RB2011 for the particular task for a start. If it's not a good fit I might go a little higher, maybe try a 450G or use something completely different (not a MikroTik product). RB1200 is out of the current budget. That'd be a shame since I like their products and espec...
by kobuki
Sat Jul 21, 2012 4:10 pm
Forum: RouterBOARD hardware
Topic: Recommendations for fast cable
Replies: 10
Views: 2764

Re: Recommendations for fast cable

As I've already said, I was comparing the two while trying to decide. No NAT figures there, only routred/bridged config with and without conntrack, which is not the same. Actually, far from it. The 450G is capable of a NAT througput at around 200 Mbps (based on others and on my own experience), whil...
by kobuki
Sat Jul 21, 2012 3:28 pm
Forum: RouterBOARD hardware
Topic: Recommendations for fast cable
Replies: 10
Views: 2764

Re: Recommendations for fast cable

Well, i guess so. Compared to the 450G, how are NAT throughput figures? Can the 2011 top the 450G's max througput of about 200 Mbps? This in an information I'm unable to find. I won't actually need more than that, of course, just wondering.
by kobuki
Fri Jul 20, 2012 11:34 pm
Forum: RouterBOARD hardware
Topic: Recommendations for fast cable
Replies: 10
Views: 2764

Re: Recommendations for fast cable

Yeah, comparing the throughput figures, I thought so too. No queues planned so far, however, I'm concerned about the amount of ram. 2011 has 64M, while the 450G has 256M. Although no heavily loaded servers inside with thousands of connections, so it might not be an issue.
by kobuki
Fri Jul 20, 2012 6:22 pm
Forum: RouterBOARD hardware
Topic: Recommendations for fast cable
Replies: 10
Views: 2764

Recommendations for fast cable

What would be the proper choice of a routerboard from the current available lineup of hardware for the following scenario? - BW: about 125 Mbits down / 10 Mbits up, cable - users: about 30 in an office, normal office work, nothing out of the ordinary - a mail server in the office for those users, wi...
by kobuki
Fri Apr 27, 2012 9:21 pm
Forum: General
Topic: Gratuitous ARP to update neighbors' ARP table
Replies: 3
Views: 1947

Re: Gratuitous ARP to update neighbors' ARP table

Well, I seem to have found a solution. I'm posting it in order for others looking for a solution to this problem can find it in the future. The "nemesis" utility needs to be installed. In my case on Debian, it's a simple matter of running "aptitude update; aptitude install nemesis". Then run the fol...
by kobuki
Fri Apr 27, 2012 4:57 pm
Forum: General
Topic: Gratuitous ARP to update neighbors' ARP table
Replies: 3
Views: 1947

Gratuitous ARP to update neighbors' ARP table

I have a RouterOS appliance running in a KVM VPS in a datacenter. I'm moving IP addresses from the hardware interface to the VPS, but run into a problem all the time I do this. The datacenter's uplink switch has a 4-hour eviction policy set on its ARP cache, so I'm guarenteed to have a 4-hour downti...
by kobuki
Thu Mar 29, 2012 10:10 pm
Forum: Virtualization
Topic: RouterOS on Amazon EC2
Replies: 35
Views: 17619

Re: RouterOS on Amazon EC2

Well, this stuff made me curious so I've created a VMWare image of the newest ROS, converted it into the appropriate format, uploaded to S3 (where the C2 cloud can import it)... only to find out in the end that this method only works for Windows operating systems. There is, however, another possibil...
by kobuki
Mon Mar 26, 2012 4:33 pm
Forum: Virtualization
Topic: ROS on KVM on Hosted server issue (Dedibox / Online.net)
Replies: 7
Views: 6058

Re: ROS on KVM on Hosted server issue (Dedibox / Online.net)

Yeah, thanks, that was my plan anyway. Use a ROS installation as gateway/shaper for some of the VPSes and do some testing. If it goes well, I can consider switching the entire HW node. I'll report some of my findings if anyone is interested. Unfortunately not much info is available in this subject (...
by kobuki
Fri Mar 23, 2012 4:31 pm
Forum: Virtualization
Topic: ROS on KVM on Hosted server issue (Dedibox / Online.net)
Replies: 7
Views: 6058

Re: ROS on KVM on Hosted server issue (Dedibox / Online.net)

I'm sorry if it looks as if I wanted to steal this thread, in that case I'm going to open a new one, but my question seems relevant. I'm also thinking of running a MikroTik ROS as a KVM appliance as a cheap and handy alternative to a separate racked product. It's in fact installed and running fine i...
by kobuki
Sun Mar 04, 2012 12:44 pm
Forum: General
Topic: RB450G strange 100% spikes on CPU resource graph
Replies: 3
Views: 1008

Re: RB450G strange 100% spikes on CPU resource graph

Thanks for the replies. I'm using Zabbix for the moment, and it doesn't influence the SNMP readings at all (CPU load or anything else). I'm suspecting RouterOS is misbehaving at certain periods. I might need to forget the built-in graphing completely if it's so unreliable.
by kobuki
Sun Mar 04, 2012 12:23 am
Forum: General
Topic: RB450G strange 100% spikes on CPU resource graph
Replies: 3
Views: 1008

RB450G strange 100% spikes on CPU resource graph

I've employed an RB450G in a datacenter recently, and experiencing strange 100% CPU usage spikes on the CPU graph. They always last a single tick only, and the SNMP monitoring tool sampling the same board (with more frequent, 2-minute intervals) shows no signs of them. There are no other kinds of re...
by kobuki
Sun Dec 11, 2011 6:07 pm
Forum: RouterBOARD hardware
Topic: Published hardware IPSEC performance on RB1100AH/X2 ?
Replies: 4
Views: 1870

Re: Published hardware IPSEC performance on RB1100AH/X2 ?

+1

I'm also curious about these figures. But I guess until at least IKEv2 and UDP support for OpenVPN is implemented it has not much use for me.
by kobuki
Wed Oct 12, 2011 9:49 am
Forum: Beginner Basics
Topic: IPsec connection problem with FTP
Replies: 6
Views: 873

Re: IPsec connection problem with FTP

No, unfortunatey no fiddling with the MTU helps. One direction is working OK, the other isn't.
by kobuki
Tue Oct 11, 2011 10:07 pm
Forum: Beginner Basics
Topic: IPsec connection problem with FTP
Replies: 6
Views: 873

Re: IPsec connection problem with FTP

Well, I tried to lower the MTU on the WAN side, it did not help. It's as if conntracking didn't kick in or something. The first packet is fine, the rest is lost. My other suspicion is that the ADSL modem's buggy firmware doesn't forward the IPsec packets correctly in both directions, although IPsec ...
by kobuki
Tue Oct 11, 2011 10:37 am
Forum: Beginner Basics
Topic: IPsec connection problem with FTP
Replies: 6
Views: 873

Re: IPsec connection problem with FTP

So no one has an idea?
by kobuki
Sun Oct 09, 2011 10:55 pm
Forum: Beginner Basics
Topic: IPsec connection problem with FTP
Replies: 6
Views: 873

Re: IPsec connection problem with FTP

Some additional info. It seems I'm able to download small files, but not larger ones. My guess is that the file must fit in a single packet or there's some relation to the packet size. I can download a 1300 bytes file, but not a 1400 bytes file... Uploading arbitrary files is still not a problem. It...
by kobuki
Sun Oct 09, 2011 9:20 pm
Forum: Beginner Basics
Topic: IPsec connection problem with FTP
Replies: 6
Views: 873

IPsec connection problem with FTP

I can't figure out a probably simple situation, please give me some advices, I'm not experienced with MikroTik IPsec. I've successfully connected 2 endpoints. I can ping the remote end, but no equip to serve on the remote side yet so I cannot test that direction but i suppose it works. The 2.2.2.x i...
by kobuki
Sat Sep 17, 2011 7:06 pm
Forum: General
Topic: Does Mikrotik utilize AES-NI instructions and max encr speed
Replies: 8
Views: 2084

Re: Does Mikrotik utilize AES-NI instructions and max encr s

I think it's a general enough question to be answered here on the forums. I might additionally send a support query though.
by kobuki
Fri Sep 16, 2011 11:59 pm
Forum: Beginner Basics
Topic: RB 450G upgrade failure
Replies: 5
Views: 812

Re: RB 450G upgrade failure

Well, as 5.7 is out I've done a quick upgrade. For previous upgrades, it seems I've done a very simple mistake... This time I had the idea of waiting a lot more before declaring my router unresponsive and surprise, surprise - it rebooted after like a minute or so and is back online, upgraded. It's s...
by kobuki
Fri Sep 16, 2011 8:46 pm
Forum: General
Topic: Does Mikrotik utilize AES-NI instructions and max encr speed
Replies: 8
Views: 2084

Re: Does Mikrotik utilize AES-NI instructions and max encr s

I'm also interested in this. I'm planning on using an x86 ROS as VPN GW, and was wondering about the same thing. It would be nice if 5.x already supported AES-NI.
by kobuki
Tue Sep 13, 2011 3:58 pm
Forum: Beginner Basics
Topic: RB 450G upgrade failure
Replies: 5
Views: 812

Re: RB 450G upgrade failure

Thanks. As I've mentioned I don't have the proper serial cable at the moment, so I can't use that for now. I've managed to flash a working 5.6 onto the device, but as soon as I do a "/system reset-configuration" the connection is lost and all I can do is re-flash the device via netinstall. It causes...
by kobuki
Tue Sep 13, 2011 5:40 am
Forum: Beginner Basics
Topic: RB 450G upgrade failure
Replies: 5
Views: 812

Re: RB 450G upgrade failure

Alright, to answer my own question. It's possible to make the RB450G boot via the network basically the same way as the RB750G, using the reset button. I was succesfully able to flash 5.6 with netinstall, but the problem remains: it cannot be flashed using the normal WinBox method. Do I miss somethi...
by kobuki
Tue Sep 13, 2011 5:04 am
Forum: Beginner Basics
Topic: RB 450G upgrade failure
Replies: 5
Views: 812

RB 450G upgrade failure

Please help. I've upgraded my 450G from 4.15 to 5.6 via the WinBox method. The update itself went fine. It was previously accessible via the LAN IP of 192.168.0.192, and via MAC address. After the upgrade it's not accessible any more at all, with either method. Since I don't have the proper serial c...
by kobuki
Tue Apr 26, 2011 6:07 pm
Forum: Beginner Basics
Topic: snmp configuration ok, but what about firewall rules?
Replies: 9
Views: 15627

Re: snmp configuration ok, but what about firewall rules?

After having found the problem myself, let me phrase in simple words what I wanted to achieve, we might still find a fault, and others may be able to learn from it. x.x.139.66 is router public gateway address on ether1, 192.168.88.1 is internal LAN address on ether2, x.x.35.229 is the remote managem...
by kobuki
Tue Apr 26, 2011 5:44 pm
Forum: Beginner Basics
Topic: snmp configuration ok, but what about firewall rules?
Replies: 9
Views: 15627

Re: snmp configuration ok, but what about firewall rules?

I have basically the same problem. I've set up the SNMP service, firewall input and NAT rules, yet it doesn't work. Port 161 is also filtered, so I needed the NAT rule. Other NAT rules are happily working, this one doesn't. Using torch I can see incoming traffic from the management machine to UDP po...
by kobuki
Tue Apr 26, 2011 3:07 pm
Forum: Beginner Basics
Topic: Router recommendation needed
Replies: 10
Views: 1318

Re: Router recommendation needed

Yeah, I have to agree for the most part, but this customer gets his 120 Mb line for not significantly more than their old 16 Mb DSL line... I can hardly sell them a router costing around $600... I guess at the end they'll have tu put up with the simple CPE the ISP installed ATM. We'll see.
by kobuki
Tue Apr 26, 2011 1:44 am
Forum: Beginner Basics
Topic: Router recommendation needed
Replies: 10
Views: 1318

Re: Router recommendation needed

Yeah, I've already checked out the r0c-n0c routers, but I think that compared to a ~$130 RB450G, a $600 appliance is a little more than an "upgrade" :) They don't really seem to be in the same league...
by kobuki
Mon Apr 25, 2011 7:50 pm
Forum: Beginner Basics
Topic: Router recommendation needed
Replies: 10
Views: 1318

Re: Router recommendation needed

Heck, there are parts of the world people would laugh at you for a mikrotik... because you get internet via 1gbit connection as part of your appartement rent ;) No joke ;) A poor 450 would probably melt. Not literally. Well, Mikrotik routers are practically unbeatable in price/performance ratio. Bu...
by kobuki
Mon Apr 25, 2011 6:08 pm
Forum: Beginner Basics
Topic: Router recommendation needed
Replies: 10
Views: 1318

Re: Router recommendation needed

Alright, thanks. I have a 450G at hand to toy with so I'll do some testing. I'm hoping it might still be enough, altho the device should be chosen for the theoretical maximum load, with all possible circumstances taken into consideration.
by kobuki
Mon Apr 25, 2011 4:10 pm
Forum: Beginner Basics
Topic: Router recommendation needed
Replies: 10
Views: 1318

Re: Router recommendation needed

Hm, thank you for the insightful answer. So the theoretical/advertised routing performance of several hundred megabits of the most common MT routers won't suffice for such a connection? I'm rather surprised. We've measured a 4-5% CPU load on a 750G for a 10/10 Mbits connection saturated in one direc...
by kobuki
Mon Apr 25, 2011 2:12 am
Forum: Beginner Basics
Topic: Router recommendation needed
Replies: 10
Views: 1318

Router recommendation needed

Sorry if this question has been answered before already, search didn't really help me in this case. We're about to install a new router at a customer's office next week. They have a 120 Mbps connection at the local cable company, and we're looking for recommendations on a specific routerboard model....
by kobuki
Wed Apr 13, 2011 2:21 am
Forum: Beginner Basics
Topic: OS v5.1
Replies: 8
Views: 1137

Re: OS v5.1

You need to reinstall RouterOS. http://wiki.mikrotik.com/wiki/Netinstall http://routerboard.com/pricelist/download_file.php?file_id=123 HTH, Well, thanks. In the meantime I've also found the proper method for reflashing via netboot. Although encountered a few problems. 1. Unfortunately updating did...
by kobuki
Tue Apr 12, 2011 4:51 pm
Forum: Beginner Basics
Topic: OS v5.1
Replies: 8
Views: 1137

Re: OS v5.1

After upgrading an RB750G from 4.17 to 5.1 the router seems bricked, connection is dead. How can I downgrade? Is it possible to access the router after a failed upgrede at all? The upgrade process didn't indicate any error.