Community discussions

Search found 94 matches

  • 1
  • 2
by kobuki
Sat Mar 31, 2018 2:16 am
Forum: General
Topic: Problems with mynetname.net cloud IP service DNS
Replies: 7
Views: 367

Re: Problems with mynetname.net cloud IP service DNS

I would highly doubt that the existing name servers would be having degradation from legitimate updates or queries.

With 60 sec TTL it's entirely possible, but it was just a guess. If it keeps being DDOS'd, then well, SOL. And yes, using the serial directly in the host name is not a bright idea.
by kobuki
Fri Mar 30, 2018 11:12 pm
Forum: General
Topic: Problems with mynetname.net cloud IP service DNS
Replies: 7
Views: 367

Re: Problems with mynetname.net cloud IP service DNS

I raised my concerns about the built-in function, the thread is not about the alternatives that I know and use as well (dns.he.net or freedns.afraid org are good examples among many). The functionality is a good addition to RouterOS but the backing service is flaky. Mikrotik might have underestimate...
by kobuki
Thu Mar 29, 2018 2:28 pm
Forum: Announcements
Topic: Urgent security advisory
Replies: 110
Views: 40143

Re: Urgent security advisory

(post Removed as others have answered my question)
by kobuki
Wed Mar 28, 2018 11:18 pm
Forum: Announcements
Topic: Urgent security advisory
Replies: 110
Views: 40143

Re: Urgent security advisory

Pardon me, but specifying "www server" is not clear, at all. A serious security vulnerability merits more than vague statements about services. Do the scripts only scan port 80? Are we safe behind HTTPS (which still fall under the "www server" category) or not? Etc. You're obviously not very familia...
by kobuki
Wed Mar 28, 2018 10:40 pm
Forum: Announcements
Topic: Urgent security advisory
Replies: 110
Views: 40143

Re: Urgent security advisory

Just to make it clear: only devices running a not up-to-date RouterOS version are affected, whose HTTP port (TCP/80) are open and provides the login facility and management GUI, right? I never allow unencrypted connections and always disable the HTTP and HTTPS interfaces. Only SSH and Winbox is enab...
by kobuki
Wed Mar 28, 2018 4:19 pm
Forum: General
Topic: Problems with mynetname.net cloud IP service DNS
Replies: 7
Views: 367

Re: Problems with mynetname.net cloud IP service DNS

Nice to know that you take note of the problems, however it's still serviced from a single unicast IPv4 address...
by kobuki
Tue Mar 13, 2018 4:19 pm
Forum: General
Topic: Problems with mynetname.net cloud IP service DNS
Replies: 7
Views: 367

Problems with mynetname.net cloud IP service DNS

See here for an overview: https://intodns.com/mynetname.net One server is not answering, lame delegation, etc, quite a handful. I'm a bit concerned about these DNS servers, there's only 2 of them for the "cloud" dynamic names, apparently no real strong clould backing infrastructure is present. Do yo...
by kobuki
Thu Aug 17, 2017 10:46 pm
Forum: Announcements
Topic: v6.41rc [release candidate] is released! New bridge implementation!
Replies: 561
Views: 95625

Re: v6.41rc [release candidate] is released! New bridge implementation!

With the new bridge implementation using HW offload, will it be possible to use multiple bridges using the offload capability, effectively creating multiple "switch groups" that retain wire speed in the group? It's now possible to do something similar using VLANs where each VLAN has a CPU port besid...
by kobuki
Mon May 23, 2016 4:35 pm
Forum: General
Topic: Using Huawei E3372 3G/4G stick
Replies: 20
Views: 3627

Re: Using Huawei E3372 3G/4G stick

@pe1chl: well, it was my mistake, the ack mail landed in the spam folder after all. It got lost with the junk there but just found it. I hope they can fix the issue. It works for you, it should for me as well. I hope it's not a faulty HAP AC where I tested it.
by kobuki
Mon May 23, 2016 11:22 am
Forum: General
Topic: Using Huawei E3372 3G/4G stick
Replies: 20
Views: 3627

Re: Using Huawei E3372 3G/4G stick

@pe1chl, can you please tell me what version of the srick you use? There're different series, 21.xx, 22.xx. Also, did you make any special settings?

My host is not spamming but that's only relevant when sending mails out of it, not when receiving...
by kobuki
Sun May 22, 2016 10:45 pm
Forum: General
Topic: Using Huawei E3372 3G/4G stick
Replies: 20
Views: 3627

Re: Using Huawei E3372 3G/4G stick

I also have a Huawei E3372, it works fine in Hilink mode under Debian Linux 8, kernel 4.2, but I can't make it work on my HAP AC. The modem is stuck in the vendor-id="0x12d1" device-id="0x1508" configuration, which is the "basic" mode without the Hilink interface. Linux can switch it to device-id="0...
by kobuki
Fri Apr 22, 2016 1:54 am
Forum: General
Topic: Regular x86 mikrotik vs CHR with a non-virtualized machine
Replies: 6
Views: 1271

Re: Regular x86 mikrotik vs CHR with a non-virtualized machine

Hi guys, We have bought a 2U Dell Server with 4 Dual 10Gbps ports and we would like to install RouterOS or CHR on it in order to overcome the BGP limitations of our CCR1036. We are not going to install anything else on this server to make sure it has all the power available to handle our multigigab...
by kobuki
Fri Apr 22, 2016 1:48 am
Forum: General
Topic: Regular x86 mikrotik vs CHR with a non-virtualized machine
Replies: 6
Views: 1271

Re: Regular x86 mikrotik vs CHR with a non-virtualized machine

For example x86 don't have virtio drivers, so you can't install RouterOS on a public cloud like Amazon EC2, Azure, or like it.
The installable x86 version does include virtio drivers, I use virtualised ROS instances at multiple places (on KVM, not Xen) with virtio, without problems.
by kobuki
Wed Apr 20, 2016 6:55 pm
Forum: Beginner Basics
Topic: Simple solution for prioritising IPSEC traffic
Replies: 0
Views: 326

Simple solution for prioritising IPSEC traffic

I'm not exactly new to Mikrotik and RouterOS in general, but aside from simple queues for DL/UL limitations, I've worked very little with them. I'd like to employ a simple priority measure for the IPSEC/ESP tunnel we installed between 2 offices. Sometimes the tunnel suffers because of other inetrnet...
by kobuki
Fri Feb 12, 2016 9:28 pm
Forum: RouterBOARD hardware
Topic: HAP AC
Replies: 537
Views: 115482

Re: HAP AC

kobuki product is called hAP AC (the same name as topic). I think it is easy name to remember. RB962UiGS-5HacT2HnT is product code, and it collects all information you need to know about ports and features (if you like). Thanks -- however the post where I noted that it was meant to be a joke and I ...
by kobuki
Wed Feb 10, 2016 2:25 pm
Forum: RouterBOARD hardware
Topic: HAP AC
Replies: 537
Views: 115482

Re: HAP AC

I'm glad it appeared finally. I have the AC Lite and it's fine so far, I'll probably replace an older TP-Link dualband as soon as I can get hold of a HAP AC, for testing.
by kobuki
Mon Dec 14, 2015 1:45 am
Forum: RouterBOARD hardware
Topic: Ubiquiti ERLite3 beats Mikrotik RB1100AHx2 on performance. Can it be possible?
Replies: 18
Views: 3540

Re: Ubiquiti ERLite3 beats Mikrotik RB1100AHx2 on performance. Can it be possible?

My experience...it depends on your understanding of "beating"..... I have just, finally, thanks my God, replaced an ERLITE-3 by an RB/3011 on a 300/300 Mbits PPOE/Nated fiber connection with IPTV and IP phone...unbeliable: back to have a router in a corner of my house acting as a router and not cal...
by kobuki
Wed Dec 02, 2015 11:50 am
Forum: RouterBOARD hardware
Topic: hEX nand size ONLY 16MB !!!!
Replies: 61
Views: 11787

Re: hEX nand size ONLY 16MB !!!!

I'm not very concerned about the problem, but I find it weird that with ever falling flash prices, Mikrotik wants to save the pennies on it. In large volumes, it turns into profit, that's for sure, but still...
by kobuki
Mon Aug 17, 2015 5:34 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 - Release date?
Replies: 193
Views: 43248

Re: RB850Gx2 - Release date?

Has anyone been able to conduct IPSEC throughput tests on the new RB850Gx2 with HW acceleration? My local supplier is already selling them with the new serial but I'm hesitant to buy them for new projects just for this feature yet.
by kobuki
Wed Aug 05, 2015 5:30 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 158089

Re: Cloud Hosted Router

Please consider adding the recognition of extra virtual disks to the appliance. Additional virtual storage space would be very useful for larger web caches, FTP or Samba servers as a simple and easy alternative to other storage appliaces with no fancy requirements. Will this be possible in the fina...
by kobuki
Tue Aug 04, 2015 10:49 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 158089

Re: Cloud Hosted Router

Great Idea. I'm already using several instances of ROS on virtualised platforms for live virtual systems and for testing. When a polished final product, I'm sure it will be a success. Please consider adding the recognition of extra virtual disks to the appliance. Additional virtual storage space wou...
by kobuki
Tue Aug 04, 2015 1:08 am
Forum: General
Topic: Static route and gateway on different subnet not working
Replies: 6
Views: 1755

Re: Static route and gateway on different subnet not working

Shaoranrch, thanks for the extensive answer. Your explanation is of course, logical, and I'm aware of the basics of IP resolution within L2 broadcast domains, but at a point it seems to contradict my findings where I said I could just ping the gateway IP just fine, yet ROS refused to use it. OTOH, I...
by kobuki
Mon Aug 03, 2015 12:59 am
Forum: General
Topic: Static route and gateway on different subnet not working
Replies: 6
Views: 1755

Re: Static route and gateway on different subnet not working

Well, I solved this, kind of. /ip address add address=88.x.x.177 interface=ether2 network=78.y.y.132 /ip route add gateway=78.y.y.132 ROS automatically adds a host route for 78.y.y.132 (main ip of the host machine, outside of the routed /29 subnet) on ether2 and I can use it as gateway for the /29 e...
by kobuki
Sun Aug 02, 2015 3:09 am
Forum: General
Topic: Static route and gateway on different subnet not working
Replies: 6
Views: 1755

Re: Static route and gateway on different subnet not working

Well, I have tried your suggestions, but neither of them is working on RouterOS. I can't make it work, whatever I try. I even enabled proxy arp on the host so the upstream gw appears as directly connected IP, to no avail. If the ROS doesn't have an IP from the same subnet as the gateway, it doesn't ...
by kobuki
Sun Aug 02, 2015 12:06 am
Forum: General
Topic: Static route and gateway on different subnet not working
Replies: 6
Views: 1755

Re: Static route and gateway on different subnet not working

Thanks, pukkita, I'll try this tomorrow and report back.
by kobuki
Sat Aug 01, 2015 7:53 pm
Forum: General
Topic: Static route and gateway on different subnet not working
Replies: 6
Views: 1755

Static route and gateway on different subnet not working

I'm trying to create a simple config at a datacenter where I am allocated a single "main" IP with a default GW on the same subnet. All is fine. Then I requested for an additional subnet which is statically routed to this main IP. It's from a different, arbitrary subnet. This setup is virtualised, wi...
by kobuki
Fri Jun 26, 2015 12:17 am
Forum: General
Topic: Weird IPSEC problem
Replies: 5
Views: 838

Re: Weird IPSEC problem

Well, I actually solved it at last. I don't know what the problem was, I rebuilt the IPSEC config from scratch and poof, it started working. No config difference compared to what I've shown earlier, that I know of. Weird.
by kobuki
Thu Jun 25, 2015 11:09 pm
Forum: General
Topic: Weird IPSEC problem
Replies: 5
Views: 838

Re: Weird IPSEC problem

Oops, my mis-read, sorry. I'm used to mis-configuring it myself where I put the connect-to IP in instead of the remote-LAN IP, glossed over your opening statement, sorry. Do you have a regular client connection that works with these settings? To me, the MT settings look correct and I'd be inclined ...
by kobuki
Thu Jun 25, 2015 10:02 pm
Forum: General
Topic: Weird IPSEC problem
Replies: 5
Views: 838

Re: Weird IPSEC problem

You need your /ip firewall nat rule (the bypass rule) to match the local and remote private networks. So, if the local side is 192.168.1.0/24 and the remote side is 192.168.2.0/24, your NAT bypass rule would be as follows: /ip firewall nat add chain=srcnat src-address=192.168.1.0/24 dst-address=192...
by kobuki
Thu Jun 25, 2015 9:13 pm
Forum: General
Topic: Weird IPSEC problem
Replies: 5
Views: 838

Weird IPSEC problem

I'm trying to create an ipsec tunnel to a host where the destination subnet and remote public endpoint is both the same single public IP address, that is, it's a seemingly simple config where they allow access to a single public address from our small local subnet. The ipsec config looks like this: ...
by kobuki
Thu Jun 25, 2015 12:42 am
Forum: Announcements
Topic: FastTrack - New feature in 6.29
Replies: 236
Views: 114122

Re: FastTrack - New feature in 6.29

Are you really complaining about not getting an answer in a forum within 8 hours?
Check your clock, please. It was about a day later.

But no. It was merely a rhetorical question, if that helps to satisfy your curiosity (or your feeling of righteousness).
by kobuki
Wed Jun 24, 2015 9:35 pm
Forum: Announcements
Topic: FastTrack - New feature in 6.29
Replies: 236
Views: 114122

Re: FastTrack - New feature in 6.29

I wonder if I ever get an answer...
by kobuki
Wed Jun 24, 2015 1:32 am
Forum: Announcements
Topic: FastTrack - New feature in 6.29
Replies: 236
Views: 114122

Re: FastTrack - New feature in 6.29

I was anticipating this feature and installed 6.29.1 only to find out that it's not supported on my router at home which is an RB450G. It has been one of the most popular ones and there isn't a night and day difference between this and the 750G which is indeed supported. Their hardware is almost ide...
by kobuki
Wed Oct 08, 2014 2:59 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 - Release date?
Replies: 193
Views: 43248

Re: RB850Gx2 - Release date?

KVM is inherently an x86-only technology - so I'd say definitely no. You can already use KVM on RouterOS x86. It started on x86, but it has progressed far beyond that. The code is actively maintained on multiple architectures, see: http://www.linux-kvm.org/page/Status However, it's only considered ...
by kobuki
Wed Oct 08, 2014 1:01 am
Forum: RouterBOARD hardware
Topic: RB850Gx2 - Release date?
Replies: 193
Views: 43248

Re: RB850Gx2 - Release date?

we are actively working on virtualization support for multicore RouterBOARD products.
Any chance of KVM virtualisation on these boards?
by kobuki
Sun Sep 14, 2014 2:39 pm
Forum: General
Topic: Winbox 3 beta
Replies: 243
Views: 106146

Re: Winbox 3

After the announcement that 6.20 will only work with Winbox3, I started testing it a bit. I'm using Windows 7 SP1 x64 and have found that it can only save 5.x window sessions (it might save them but definitely can't load them). 6.x sessions are always started with a blank window, regardless of the s...
by kobuki
Sat Sep 13, 2014 5:01 pm
Forum: General
Topic: v6.19 released
Replies: 256
Views: 86289

Re: v6.19 released

What's new in 6.20rc6 (2014-Sep-08 10:16): *) pppoe client - increase connection timeout to make connection establishment possible on busy pppoe server; *) dhcp server - change default lease time from 3 days to 10 minutes to avoid running out of IPs; *) ipsec - allow binding modeconf address to use...
by kobuki
Thu Aug 21, 2014 2:01 pm
Forum: RouterBOARD hardware
Topic: sxt G-5HPnD-HG r2 1 km linktest results
Replies: 8
Views: 2592

Re: sxt G-5HPnD-HG r2 1 km linktest results

Is the latency of 6-7 ms I see on the images normal? I thought it would be less. Where does it come from? Wifi mod/demod or packet transmission time (not the radio wave speed), inherent device latency, or something else?
by kobuki
Tue Aug 12, 2014 9:29 pm
Forum: Virtualization
Topic: Hyper-V integration components
Replies: 127
Views: 58829

Re: Hyper-V integration components

Some news: http://www.brocade.com/forms/jsp/vyatta-download/index.jsp?src=WS&lsd=Banner&lst=BRCD&cn=SDN-GDG-14Q1-EVAL-WS-Vyatta-Download&intcmp=lp_vyatta_trial_hp_bn_00001&gcn=&ggeo= Brocade make vyatta distrib that makes that what we want from ROS in HyperV\esxi This is in a completely different l...
by kobuki
Fri Aug 08, 2014 4:57 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 - Release date?
Replies: 193
Views: 43248

Re: RB850Gx2 - Release date?

Thanks Quindor. Yes, we encountered an issue that needed to be fixed in the board design before we can start mass production. Sorry that this happened and pushed the previously estimated release date. Ah, good it hasn't been abandoned. You could have told us earlier... such a simple note. Awaiting ...
by kobuki
Thu Jul 03, 2014 9:56 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 - Release date?
Replies: 193
Views: 43248

Re: RB850Gx2 - Release date?

Haha nice . Didn't even notice the CCR1009 has a switch port , I just assumed it lacked it like all the other CCR's. I think I pretty much found my replacement device for the 2011's now. Yeah. But unfortunately it has active cooling (a fan). Not an ideal choice for a fast broadband connection for a...
by kobuki
Tue Jul 01, 2014 3:23 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 - Release date?
Replies: 193
Views: 43248

Re: RB850Gx2 - Release date?

Maybe they've withdrawn it, not wanting to create an inbreed competition to their own low-end Tilera-based devices... Or are fine-tuning and testing the code to be the finest possible ever made for a MikroTik router :) Anyway I'm also eager to try it and replace one or 2 450G and 2011. Dual-core PPC...
by kobuki
Fri Jun 06, 2014 10:30 pm
Forum: General
Topic: v6.13 released!
Replies: 177
Views: 41651

Re: v6.13 released!

I've upgraded an RB2011L-IN to 6.13 a few days ago, and I' observing a strange CPU behaviour. The average CPU usage is higher by about 2-3% and there are randomly repeating very short 100% usage spikes, without any significant traffic or other measurable activity (in the middle of the night for exam...
by kobuki
Thu Nov 21, 2013 12:13 pm
Forum: Virtualization
Topic: Hyper-V integration components
Replies: 127
Views: 58829

Re: Hyper-V integration components

I'm using an MT5 instance on a VM too (Proxmox PVE, KVM, virtio NICs). It's working fine. Also shortly tested 6, no problems. But I can fully understand that those already having a Hyper-V infrastructure in place, would want to run ROS on it. All that is missing is some modules? And MT is not willin...
by kobuki
Mon Nov 18, 2013 8:22 pm
Forum: General
Topic: RouterOS v6.6 released
Replies: 164
Views: 67961

Re: RouterOS v6.6 released

On RB450G, when I change the MAC of ether1 to match the one required by my ISP, no stats are displayed. "Overall Stats", "Rx Stats", "Tx Stats" windows are empty. Traffic graphs are OK. This error is present since 5.23 as far as can remember, but for all 6.x versions I tried on this router, for sure.
by kobuki
Sun Nov 17, 2013 1:03 pm
Forum: General
Topic: RouterOS v6.6 released
Replies: 164
Views: 67961

Re: RouterOS v6.6 released

i have this issue with certifcates as well. seems winbox thinks its 365 regardless of the actual date
I can also confirm this. Simply forgot to report in my previous post.
by kobuki
Fri Nov 15, 2013 9:17 pm
Forum: General
Topic: RouterOS v6.6 released
Replies: 164
Views: 67961

Re: RouterOS v6.6 released

Certificate export is not working. RB2011LS-IN, Windows 7 SP1 x64 running Winbox. When I press Export in the certificate details window, Winbox exits in an instant and all windows settings since its last start are lost. Also, cannot rename the certificate, it says "certificate subject is read only!"...
by kobuki
Tue May 14, 2013 12:00 am
Forum: General
Topic: v6rc14 released
Replies: 125
Views: 27569

Re: v6rc14 released

RB450G, rc14, WinBox: ethernet interface Overall/Rx/Tx stats are completely empty or partially empty. On my router, ether1 is blank on every stats pages, and ether2 (2-4 ports switched together) is partially blank on the stats pages. ether1 has a changed MAC (ISP MAC restrictions), maybe this has so...
by kobuki
Sat May 11, 2013 3:50 am
Forum: RouterOS v6 RC and v7 BETA
Topic: problem with Graphic in router
Replies: 6
Views: 2827

Re: problem with Graphic in router

Same problem on RB450G. 5-minute interval, store on disk for every graph. After reboot, resource graphs are retained, interface graphs are missing. Using RouterOS 6rc14.
by kobuki
Mon May 06, 2013 2:50 pm
Forum: Beginner Basics
Topic: [solved] IPsec doesn't start
Replies: 0
Views: 464

[solved] IPsec doesn't start

EDIT: for a mysterious reason it suddenly started to work. Deja vu... Please help. It's a config that used to work (recreated, but it's along the same principles and the IPs are the same), but now the connection doesn't even start initialising. Enabled the IPsec debug log, but besides config changes...
  • 1
  • 2