Community discussions

Search found 112 matches

by mstead
Wed Jul 17, 2019 6:14 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 61039

Re: v6.45.1 [stable] is released!

Is this the new API that sends the password in plain text?? I cannot figure WHY you guys would revert to that way of operation.
by mstead
Mon Apr 01, 2019 7:45 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 38594

Re: UKNOF 43 CVE

where the reporter didn't report it as a security concern and left it for 6 months till he was able to get a CVE The full timeline will be available next week. But when I reported this in April 2018, my request to MikroTik was to plead with support to treat this as a serious security vulnerability,...
by mstead
Sun Mar 31, 2019 11:52 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 38594

Re: UKNOF 43 CVE

Mikrotik have publicly disclosed the details of the vulnerability, on a Sunday, in a way that a child could exploit it - before even providing a fixed beta, let alone a stable release version, let along giving us time to test and deploy it. Truly despicable behaviour there Mikrotik. Do you have no ...
by mstead
Sat Mar 30, 2019 7:17 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 38594

Re: UKNOF 43 CVE

I would make a good guess that the technique involves sending lots and lots of oversized neighbor discovery packets with the target IP of the victim. Easy to craft and while I never tested it, most likely could run the victim out of memory space if done at a high enough rate.
by mstead
Tue Feb 05, 2019 4:58 am
Forum: Wireless Networking
Topic: wAP 60G experience
Replies: 279
Views: 35705

Re: wAP 60G experience

Hello. We have a strange problem. We made a PtMP on wAP 60G (v6.44beta40) with 5 clients (4 LHG and 1 wAP same ROS version). Everything is working fine, but when anyone will shutdown MT (or reboot it) then we get disconnect on all stations and they don't want to connect again. We have to manually d...
by mstead
Wed Dec 12, 2018 4:19 am
Forum: Announcements
Topic: v6.43.7 [stable] is released!
Replies: 53
Views: 11533

Re: v6.43.7 [stable] is released!

Anyone from Ireland should be aware that Europe/Dublin timezone is screwed up in this release and will set your system clock to GMT+2 hours.

I have emailed Mikrotik support so we will see what happens.
by mstead
Thu Aug 02, 2018 8:43 am
Forum: Wireless Networking
Topic: LHG 60G experience
Replies: 542
Views: 57955

Re: LHG 60G experience

we are having loads of disconnects. Up and down constantly signal is solid at -53. If we load 6.43rc5 no disconnects at all. All the newer versions constant disconnects. Any ideas on how to solve this? We are currently on 6.43rc45 Same here. 6.43rc40 and 6.43rc44 both have constant disconnects on l...
by mstead
Wed Jul 04, 2018 4:04 pm
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 557
Views: 109521

Re: v6.43rc [release candidate] is released!

Try to upgrade the 6.40.4 first to the current version (6.42.5) and then upgrade to 6.43rc from there.
I did - and that does work :-D

Well, saying it is not crazy, the fact that it happens for some versions is a different question ;-)
That comment made me smile ;-)
by mstead
Wed Jul 04, 2018 2:16 pm
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 557
Views: 109521

Re: v6.43rc [release candidate] is released!

It has been stated multiple times here that most of the upgrade process is performed by the old version from which you upgrade. So if you in all cases upgraded from 6.40.4., the issue may also be that one, not the 6.43rc40. Yeah well that doesn't change the value of the warning that I am giving - e...
by mstead
Wed Jul 04, 2018 12:22 am
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 557
Views: 109521

Re: v6.43rc [release candidate] is released!

This also may depend on the configuration of the device. That was a valid point - however I just tested another fresh unit from the same batch which was fully reset with no defaults and I can confirm it is also bricked. So once again - BEWARE!!!! v6.43rc40 can brick your device - PLEASE CHECK befor...
by mstead
Tue Jul 03, 2018 9:10 pm
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 557
Views: 109521

Re: v6.43rc [release candidate] is released!

WARNING!!! This version 6.43rc40 just bricked two RBSXTsq5HPnD units I was testing it with. Software upgrade went fine from the factory installed 6.40.4 but then the firmware upgrade bricked the units. Netinstall currently underway. I'm successfully upgraded a hAp ac2. hAp ac2 is not a RBSXTsq5HPnD...
by mstead
Tue Jul 03, 2018 8:01 pm
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 557
Views: 109521

Re: v6.43rc [release candidate] is released!

WARNING!!! This version 6.43rc40 just bricked two RBSXTsq5HPnD units I was testing it with. Software upgrade went fine from the factory installed 6.40.4 but then the firmware upgrade bricked the units. Netinstall currently underway.
by mstead
Thu Apr 19, 2018 3:05 am
Forum: General
Topic: MNDP "Hack" - Is This A Bug Or Not?
Replies: 10
Views: 1082

Re: MNDP "Hack" - Is This A Bug Or Not?

I simply do not see this as a problem. A standard firewall config with a default drop resolves any potential issue. Do you disable the DNS, WWW, API, and SSH services, or otherwise block public access to those services on routers you administer? If so, why do you do that? If not, you may want to ch...
by mstead
Wed Apr 04, 2018 12:22 am
Forum: General
Topic: MNDP "Hack" - Is This A Bug Or Not?
Replies: 10
Views: 1082

Re: MNDP "Hack" - Is This A Bug Or Not?

While I am happy to accept those suggestions relating to firewall rules there does seem to be a hint of ignoring the root problem. After all neighbour discovery is exactly that - not for discovering devices halfway around the world!!
by mstead
Tue Apr 03, 2018 10:32 pm
Forum: General
Topic: MNDP "Hack" - Is This A Bug Or Not?
Replies: 10
Views: 1082

Re: MNDP "Hack" - Is This A Bug Or Not?

Sure, Mikrotik could require MNDP to accept only broadcast. There are some benefits to allowing unicast. An administrator might want to poll his entire AS with MNDP for example. I cannot see any place in Winbox where you can set MNDP to work in unicast or any good reason for it to be that way. I ag...
by mstead
Tue Apr 03, 2018 9:32 pm
Forum: General
Topic: MNDP "Hack" - Is This A Bug Or Not?
Replies: 10
Views: 1082

Re: MNDP "Hack" - Is This A Bug Or Not?

What would you have Mikrotik change about MNDP's behavior? Requiring authentication of some kind is counter to the purpose of MNDP.

Well my answer to that question is that MNDP should only respond to broadcast packets and not routed.
by mstead
Tue Apr 03, 2018 9:14 pm
Forum: General
Topic: MNDP "Hack" - Is This A Bug Or Not?
Replies: 10
Views: 1082

Re: MNDP "Hack" - Is This A Bug Or Not?

It is not correct what you write. The default firewall on a small device blocks this traffic. And on a large device (CCR/CHR) it is the full responsibility of the admin to setup a firewall to secure the router. Actually you are correct about the small device and it's defaults. However it is more wo...
by mstead
Tue Apr 03, 2018 8:46 pm
Forum: General
Topic: MNDP "Hack" - Is This A Bug Or Not?
Replies: 10
Views: 1082

MNDP "Hack" - Is This A Bug Or Not?

So I have already reported this directly to Mikrotik and they say it is normal and nothing to worry about. I disagree and would like to know what other people here think. This "bug / hack" allows you to add device(s) to the neighbour list of any Mikrotik device anywhere in the world without knowing ...
by mstead
Sat Feb 10, 2018 9:29 pm
Forum: Announcements
Topic: v6.41.2 [current]
Replies: 125
Views: 27792

Re: v6.41.2 [current]

The ping tool is broken and has been for many versions - I only noticed this tonight. The "timeout" option doesn't change the ping timeout but rather the interval between pings. So this is either a bug or a badly labelled "ping interval" option. However timeout is a crucial parameter for any ping to...
by mstead
Tue May 31, 2016 3:56 pm
Forum: Scripting
Topic: System Scheduler / Move Command Problem
Replies: 0
Views: 419

System Scheduler / Move Command Problem

Hi there, I have studied the wiki page for the system/scheduler which reads: "If more than one script has to be executed simultaneously, they are executed in the order they appear in the scheduler configuration. This can be important if one scheduled script is used to disable another one. The order ...
by mstead
Wed Jul 01, 2015 11:52 am
Forum: General
Topic: Leap second bug present on TILE devices?
Replies: 49
Views: 10097

Re: Leap second bug present on TILE devices?

Is it just me or is Normis incapable of say "sorry - we screwed up"?? I have read through all his replies and I don't see the apology anywhere - but frankly I am not in the least bit surprised....
by mstead
Wed Jul 01, 2015 4:14 am
Forum: RouterBOARD hardware
Topic: all CCR crashed
Replies: 40
Views: 7878

Re: all CCR crashed

Can people please edit their posts to include ROS version and if BGP, NTP server etc was running?
by mstead
Wed Jul 01, 2015 4:00 am
Forum: RouterBOARD hardware
Topic: all CCR crashed
Replies: 40
Views: 7878

Re: all CCR crashed

I can confirm all my border CCR crashed at 01:00BST. The common factor was BGP and NTP server. All other CCR in my network were just using OSPF and NTP client. What a pile of shite - seriously!!!!

All running v6.27 and were CCR1036-8G-1S
by mstead
Sun Nov 30, 2014 2:35 pm
Forum: RouterBOARD hardware
Topic: Warning!! - NetMETAL 5 2xRPSMA, 2000mW Are NOT Weatherproof
Replies: 31
Views: 6887

Re: Warning!! - NetMETAL 5 2xRPSMA, 2000mW Are NOT Weatherpr

So I just got time to examine a third unit which I withdrew from service at the same location as a precaution - the attached photos speak for themselves. The serial number is shown in one of the pictures as requested by Normis. These pictures clearly show a manufacturing error and obviously is not g...
by mstead
Wed Nov 26, 2014 1:21 pm
Forum: RouterBOARD hardware
Topic: Warning!! - NetMETAL 5 2xRPSMA, 2000mW Are NOT Weatherproof
Replies: 31
Views: 6887

Re: Warning!! - NetMETAL 5 2xRPSMA, 2000mW Are NOT Weatherpr

I just want to add a comment from one of my technicians who has many years of experience in the field of electrical and electronic engineering. I instructed him to remove the LED sticker and fill the holes with clear silicone. He was expecting the sticker to be difficult to remove but found it came ...
by mstead
Fri Nov 14, 2014 5:49 am
Forum: RouterBOARD hardware
Topic: Warning!! - NetMETAL 5 2xRPSMA, 2000mW Are NOT Weatherproof
Replies: 31
Views: 6887

Re: Warning!! - NetMETAL 5 2xRPSMA, 2000mW Are NOT Weatherpr

Today I had to replace a NetMetal. It went out of service after 3 days (2 with rain) from installation. I found it full of water. I have several other installed and only this one was affected, so I suppose it's something like an assembling error more than a design flaw. Will see what happens to the...
by mstead
Fri Nov 14, 2014 2:40 am
Forum: RouterBOARD hardware
Topic: Warning!! - NetMETAL 5 2xRPSMA, 2000mW Are NOT Weatherproof
Replies: 31
Views: 6887

Re: Warning!! - NetMETAL 5 2xRPSMA, 2000mW Are NOT Weatherpr

Attached are two pictures which clearly show the water damage is localised around the LED window. This is a ridiculous design flaw which I am certain other users will suffer from at some stage. In general the NetMETAL unit is a very good design - however to have a cheap sticker acting as a window fo...
by mstead
Tue Nov 11, 2014 5:21 pm
Forum: RouterBOARD hardware
Topic: Warning!! - NetMETAL 5 2xRPSMA, 2000mW Are NOT Weatherproof
Replies: 31
Views: 6887

Warning!! - NetMETAL 5 2xRPSMA, 2000mW Are NOT Weatherproof

This is why I despair with Mikrotik. They make equipment that functions quite well yet neglect to make the kit properly waterproof. Just had two NetMETAL 5 2xRPSMA, 2000mW fail last night due to rainwater getting in the window where the LED's are visible. I had numerous Groove units fail this way an...
by mstead
Mon May 20, 2013 4:43 am
Forum: General
Topic: Verified By Visa and other Walled Garden Nightmares
Replies: 2
Views: 745

Re: Verified By Visa and other Walled Garden Nightmares

Hi

Did anyone figure a good solution to this question because I am running into the same problems as well.

Anyone??

Thanks in advance
by mstead
Fri Dec 14, 2012 8:53 am
Forum: RouterBOARD hardware
Topic: Groove 5Hn - Large number damaged!!
Replies: 5
Views: 1394

Re: Groove 5Hn - Large number damaged!!

I have had the same problem and am about to RMA a whole load of them back to the distributor. This is a faulty batch in my opinion.

To be honest the Groove has been a design disaster for Mikrotik. They are very prone to flooding when the wind blows rain into the back of them.
by mstead
Mon May 09, 2011 5:29 pm
Forum: RouterBOARD hardware
Topic: New Products
Replies: 188
Views: 28368

Re: New Products

Groove is still on track, for this month.
Thank you for that. I will keep my eyes open.
by mstead
Sat May 07, 2011 7:40 pm
Forum: RouterBOARD hardware
Topic: New Products
Replies: 188
Views: 28368

Re: New Products

Can we get a status update on the Groove please. What is the estimated timescale on this product and will it have a similar price model to the Ubiquiti Bullet.

Thanks
by mstead
Wed May 04, 2011 4:35 am
Forum: Wireless Networking
Topic: What would happen if...
Replies: 20
Views: 4190

What would happen if...

Hi. Can anyone tell me what would be the result of connecting an SR-71 802.11n card with two dishes (one per chain) and pointing them in different directions. My intention would be to hook up two remote 802.11n sites using one frequency only. Will the two chains work independently and give me a reas...
by mstead
Tue Mar 22, 2011 2:02 am
Forum: Beginner Basics
Topic: Automatic RoS reboot at a specifit time
Replies: 31
Views: 5374

Re: Automatic RoS reboot at a specifit time

The reboot problem still exists in v4.17. I can confirm that with RB493AH.
by mstead
Tue Mar 22, 2011 2:01 am
Forum: General
Topic: rb450 reboot problem
Replies: 50
Views: 8963

Re: rb450 reboot problem

I can confirm the reboot problem on v4.17 with RB493AH. Reboot makes the board shutdown instead.
by mstead
Sat Feb 19, 2011 10:46 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: UPGRADE F'in FAILGREAT for SXT and 802.11N - CRAPPY FOR ELSE
Replies: 3
Views: 1102

Re: UPGRADE F'in FAILGREAT for SXT and 802.11N - CRAPPY FOR

Why is this forum filled with people who insist on upgrading every board in their network 24 hours after a new (and probably buggy) release comes out? So xlteks while I cannot answer the hard drive cleanup question I can provide a reasonable solution to your main problem - your a fool!!! I'm sorry i...
by mstead
Mon Sep 06, 2010 5:18 am
Forum: The User Manager
Topic: User Manager Problem When Using Multiple Interfaces
Replies: 2
Views: 938

User Manager Problem When Using Multiple Interfaces

Hi, Has anyone else noticed that if the radius request comes in one interface of a user manager and back via a different one (circular routing) it is rejected no matter what? To explain I have two RB1000's running v4.10 with the standard user manager. They are linked directly together and have two b...
by mstead
Sun Nov 15, 2009 8:44 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature request
Replies: 12
Views: 2007

Re: Feature request

Add my name to the list of people who would like CoA for pppoe!!

Malcolm
by mstead
Sat Oct 03, 2009 5:31 am
Forum: Scripting
Topic: Script To Add Hotspot IP Binding
Replies: 2
Views: 1524

Re: Script To Add Hotspot IP Binding

For anyone else with this problem - here is the reply from MT support: >Hello, >Try to put following line at the beginning of the script >/ip hotspot ip-binding print >This will save into buffer item numbers ad script will be able to use >place-before=0 >Regards, >Maris It still is a pain in the ass...
by mstead
Thu Oct 01, 2009 5:02 am
Forum: Scripting
Topic: Script To Add Hotspot IP Binding
Replies: 2
Views: 1524

Re: Script To Add Hotspot IP Binding

ok. This seems to be yet another stupid Mikrotik coding mistake. If I change my command to: /ip hotspot ip-binding add address=192.168.100.24 place-before= 1 then it works in a script. It will fail in the terminal, which at least means I can work around the problem. But frankly just goes to show the...
by mstead
Thu Oct 01, 2009 2:24 am
Forum: Scripting
Topic: Script To Add Hotspot IP Binding
Replies: 2
Views: 1524

Script To Add Hotspot IP Binding

Hi, I cannot get the following single line to work in a script: /ip hotspot ip-binding add address=192.168.100.24 place-before=0 I already have an ip binding that is a pass-all rule in case anyone is curious about the place-before command. I am running v3.30. If I run this from the command line it w...
by mstead
Sat Jul 25, 2009 4:31 am
Forum: The User Manager
Topic: How to assign profiles to users in 4.04b
Replies: 4
Views: 997

Re: How to assign profiles to users in 4.04b

I am also trying to figure this out!!

Malcolm
by mstead
Thu Jul 09, 2009 11:26 pm
Forum: RouterBOARD hardware
Topic: 411R disappointment?
Replies: 36
Views: 6112

Re: 411R disappointment?

Well Poland is Poland, in some countries 5GHz is not even an option You can also add Ireland to the list of countries which will not be buying this board in huge numbers. I can speak for most of the WISP's in my area who will say exactly the same. Ubiquiti are on the right road - pity MT are lost i...
by mstead
Fri May 08, 2009 10:21 pm
Forum: The User Manager
Topic: Can A PPPOE Client View Their Own Stats?
Replies: 3
Views: 1059

Re: Can A PPPOE Client View Their Own Stats?

Thanks for the reply sergejs. I did closely read that wiki page but am still stuck. I go to http://Router_IP_address/user (I only have one subscriber setup). There I see the normal user manager login page - so I tried one of the pppoe username/password but that is an invalid login. Sorry if I'm miss...
by mstead
Thu May 07, 2009 7:51 pm
Forum: The User Manager
Topic: Can A PPPOE Client View Their Own Stats?
Replies: 3
Views: 1059

Can A PPPOE Client View Their Own Stats?

I am trying out user manager and would like to know if its possible for a pppoe client to be able to view their own stats? I have looked through the MT wiki and searched the forum but cannot see the answer I'm looking for. I tried logging into user manager with the pppoe username/pass but that did n...
by mstead
Sat May 02, 2009 6:15 am
Forum: RouterOS v6 RC and v7 BETA
Topic: pppoe-relay
Replies: 29
Views: 18008

Re:

If you have an wireless link to an AP with mode=station and no WDS it's almost imposible. I've managed to workaroun with those rules: / interface bridge nat add chain=dstnat in-interface=wireless-client mac-protocol=0x8863 action=dst-nat \ to-dst-mac-address=MAC-OF-REMOTE-PPPOE-SERVER comment="" di...
by mstead
Thu Apr 23, 2009 12:05 am
Forum: RouterOS v6 RC and v7 BETA
Topic: Where Is Routing Test 3.23 For PPC?
Replies: 3
Views: 922

Re: Where Is Routing Test 3.23 For PPC?

Hi, Thanks for the reply. However if you click on the "view content" link for the above named file it clearly mentions routing-test as one of the contained packages. Can you see a separate link for routing-test-3.23-ppc.npk as I cannot? Malcolm Just to add - I did a bit of detective work and found i...
by mstead
Wed Apr 22, 2009 11:41 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Where Is Routing Test 3.23 For PPC?
Replies: 3
Views: 922

Where Is Routing Test 3.23 For PPC?

Hi,

Am I blind or is the routing-test package v3.23 missing from the PPC download. I am downloading the file all_packages-ppc-3.23.zip from MT.

Regards,

Malcolm
by mstead
Sun Mar 29, 2009 5:39 am
Forum: RouterOS v6 RC and v7 BETA
Topic: l2tp bridge
Replies: 5
Views: 3275

Re: l2tp bridge

Interesting thread.

I'm trying to create an L2TP tunnel where the client end is bridged to a real interface - ether1.

Can someone tell me if this is actually possible?

Thanks in advance

Malcolm
by mstead
Fri Jan 02, 2009 3:12 am
Forum: General
Topic: 133c & v3.17/3.16/3.14 Firewall NAT Failure
Replies: 27
Views: 2978

Re: 133c & v3.17/3.16/3.14 Firewall NAT Failure

jcremin - I feel your pain here. I had a few stressful days dealing with this problem. I feel that I am justified in getting very annoyed with Mikrotik in this matter as they have failed to address this problem in a professional and timely manner. Christmas came and went and there is still no fix. T...