Community discussions

MikroTik App

Search found 105 matches

by robertpenz
Fri Feb 16, 2024 1:41 pm
Forum: General
Topic: MLAG Issue - MLAG functionality flaps LACP system-id of secondary when primary reboots
Replies: 15
Views: 6355

Re: MLAG Issue - MLAG functionality flaps LACP system-id of secondary when primary reboots

Do you have any comments on how other vendors are dealing with this problem? We might consider improving our implementation or adding new configuration settings, but would like to hear other opinions as well. I'm running MLAG setups for over 15 years and all vendors I used so far do following. ISC ...
by robertpenz
Thu Dec 07, 2023 4:07 pm
Forum: General
Topic: WireGuard multi core support?
Replies: 3
Views: 1649

WireGuard multi core support?

Hi! We're using CCR2116-12G-4S+ and we're able to send about 2,2 Gbit in one direction over a WireGuard tunnel and one core is at almost 100%, but the overall load is at under 20%. We thought that adding another WireGuard tunnel and load balance the traffic over it will use a second core and allow u...
by robertpenz
Mon Jul 31, 2023 2:00 pm
Forum: General
Topic: pyNetinstall - Free and Open Source netInstall implementation for Flashing Mikrotik RouterBoards
Replies: 7
Views: 34907

Re: pyNetinstall - Free and Open Source netInstall implementation for Flashing Mikrotik RouterBoards

Hey, I had face a problem with pynetinstall and i troubled it. so you can give me a some tips and tricks to fix it. Please create a ticket on https://github.com/dvtirol/pynetinstall/issues and we take a look at it Has anyone implemented a plugin to allow automatic detection and uploading of firmwar...
by robertpenz
Thu May 04, 2023 2:50 pm
Forum: General
Topic: pyNetinstall - Free and Open Source netInstall implementation for Flashing Mikrotik RouterBoards
Replies: 7
Views: 34907

pyNetinstall - Free and Open Source netInstall implementation for Flashing Mikrotik RouterBoards

Hi! We're heavy using Mikrotiks in our environment and automation is very important for us. We're generating the configuration for our network equipment via scripts/templates from a source of truth system. To be able to integrate the Mikrotiks better in that workflow (which we use also for enterpris...
by robertpenz
Fri Jun 10, 2022 8:41 am
Forum: Announcements
Topic: MikroTik Devices Controller
Replies: 332
Views: 238780

Re: MikroTik Devices Controller

It should be Web-based and the Server should run also on Linux - we don't have Windows Servers.
by robertpenz
Tue May 03, 2022 8:33 am
Forum: RouterOS beta
Topic: How to show OSPF route costs in RouterOS 7?
Replies: 5
Views: 4108

Re: How to show OSPF route costs in RouterOS 7?

Thx for the reply. Where do I see the costs? The Cost should be 50 and 60. And where do I see the route candidates I get via OSPF? I should see 192.168.76.0/27 2 times. [Mikrotik] > /routing/route/print Flags: A - ACTIVE; c, s, o, y - COPY; H - HW-OFFLOADED Columns: DST-ADDRESS, GATEWAY, AFI, DISTAN...
by robertpenz
Mon May 02, 2022 10:19 pm
Forum: General
Topic: 802.1x (ethernet) Questions
Replies: 9
Views: 2991

Re: 802.1x (ethernet) Questions

1. The documentation states. "An interface where dot1x server is enabled will block all traffic except for EAPOL packets which is used for the authentication." There is no explanation if that means only incoming or also outgoing traffic. The reason I ask is that in enterprise networks, Wa...
by robertpenz
Mon May 02, 2022 10:05 pm
Forum: RouterOS beta
Topic: How to show OSPF route costs in RouterOS 7?
Replies: 5
Views: 4108

How to show OSPF route costs in RouterOS 7?

I've set up my first OSPF on a RouterOS 7 - done a few on previous versions. It works so far for me, but I'm missing a place to see the costs of the route candidates. In RouterOS 6 it was via /routing ospf route print - but that's gone in RouterOS 7 - what's the new way to check that? The new docume...
by robertpenz
Thu Apr 28, 2022 2:32 pm
Forum: RouterOS beta
Topic: Zerotier and VRF
Replies: 3
Views: 2776

Re: Zerotier and VRF

that's correct as far as I know, but the problem is that if you'll try e.g. a SNMP query to the mikrotik via wireguard/zerotier from an IP that's in the subnet the router uses to connect to the internet it does not work - you can't bind the snmpd (and other services to a VRF). As one use case is tha...
by robertpenz
Sun Apr 10, 2022 11:44 pm
Forum: General
Topic: 802.1x (ethernet) Questions
Replies: 9
Views: 2991

Re: 802.1x (ethernet) Questions

Doubtless true, but surely you can try it and get the answer faster than it'll take someone to give a definitive reply. but that way if outgoing traffic is leaking it could be a feature or a bug or the other way round if it does not get out ... as most features got only implemented with 7.2 that qu...
by robertpenz
Sun Apr 10, 2022 11:17 pm
Forum: General
Topic: 802.1x (ethernet) Questions
Replies: 9
Views: 2991

Re: 802.1x (ethernet) Questions

Hi thx for your answer. Yes, I can and will try it out, just thought that I'm not the first one looking into that or maybe someone from Mikrotik reads it and tells us what's the correct meaning of the documentation. About the mac based / port based. No, that has nothing to do with mac-auth. Basicall...
by robertpenz
Sun Apr 10, 2022 9:21 pm
Forum: General
Topic: 802.1x (ethernet) Questions
Replies: 9
Views: 2991

802.1x (ethernet) Questions

Hi! I read through the documentation at https://help.mikrotik.com/docs/display/ROS/Dot1X and have some questions. I'm used to configuring 802.1x NAC on major switch brands like, cisco, extreme, hp .... but I don't get some points in the Mikrotik documentation. I hope someone can help me. 1. The docu...
by robertpenz
Sun Apr 10, 2022 8:55 pm
Forum: RouterOS beta
Topic: Zerotier and VRF
Replies: 3
Views: 2776

Re: Zerotier and VRF

No one has an idea? I don't understand that, is that not a classic usecase for zerotier? Put a router anywhere, and it works even on overlapping subnets.
by robertpenz
Thu Mar 31, 2022 2:39 pm
Forum: RouterOS beta
Topic: Zerotier and VRF
Replies: 3
Views: 2776

Zerotier and VRF

Hi! my goal is to have a rb5009, which can be connected to any internet connection (it just needs to be provided an IP via DHCP). The rb5009 establishes a Zerotier connection to the other routers in the same Zerotier network and route clients behind it through it. That's easy, now the more complicat...
by robertpenz
Mon Mar 21, 2022 4:14 pm
Forum: RouterOS beta
Topic: RB5009 reboots itself each 8-10 days (7.2rc3/rc4) [SOLVED]
Replies: 19
Views: 6461

Re: RB5009 reboots itself each 8-10 days (7.2rc3/rc4) [SOLVED]

My 5009 crashed every few days, it stopped only after I upgraded all other mikrotiks in the network to >= 7.1 - in my case I believe it was a bug in the capsman or discovery protocol that went away when all systems used 7.x
by robertpenz
Wed Dec 08, 2021 7:11 pm
Forum: General
Topic: download.mikrotik.com does not work via IPv6
Replies: 3
Views: 1209

download.mikrotik.com does not work via IPv6

Hi! for me download.mikrotik.com resolves do: download.mikrotik.com has address 159.148.172.226 download.mikrotik.com has address 159.148.147.204 download.mikrotik.com has IPv6 address 2a02:610:7501:1000::204 download.mikrotik.com has IPv6 address 2a02:610:7501:4000::226 but the IPv6 addresses don't...
by robertpenz
Wed Dec 08, 2021 9:46 am
Forum: RouterOS beta
Topic: container package missing in 7.1?
Replies: 2
Views: 3656

container package missing in 7.1?

Hi! I've downloaded https://download.mikrotik.com/routeros/7.1/all_packages-arm64-7.1.zip and unzipped it, but I found only following packages: calea-7.1-arm64.npk gps-7.1-arm64.npk iot-7.1-arm64.npk tr069-client-7.1-arm64.npk user-manager-7.1-arm64.npk zerotier-7.1-arm64.npk What I'm doing wrong? T...
by robertpenz
Sat Sep 18, 2021 6:43 pm
Forum: RouterOS beta
Topic: Zerotier to Mipsbe??
Replies: 109
Views: 34563

Re: Zerotier to Mipsbe??

+1 mmips and chr for the central location
by robertpenz
Tue Jul 13, 2021 8:32 am
Forum: RouterOS beta
Topic: IPv6 forwarding not working in 7.1beta6
Replies: 21
Views: 12044

Re: IPv6 forwarding not working in 7.1beta6

I don't have a bridge on my setup, everything is routed. So these seem to be separated problems.
by robertpenz
Tue Jun 08, 2021 9:07 pm
Forum: RouterOS beta
Topic: IPv6 forwarding not working in 7.1beta6
Replies: 21
Views: 12044

Re: IPv6 forwarding not working in 7.1beta6

Thx for the tip - at least for beta4 that also worked for me ... deleted all ipv6 firewall rules and it started working and kept working after appling them again - at least for the last few minutes.
by robertpenz
Thu May 27, 2021 8:18 pm
Forum: RouterOS beta
Topic: v7.1beta6 [development] is released!
Replies: 377
Views: 243472

Re: v7.1beta6 [development] is released!

IPv6 forward is not working on Hex - is this a known problem and is there a workaround for it?
by robertpenz
Wed May 26, 2021 8:37 am
Forum: RouterOS beta
Topic: IPv6 forwarding not working in 7.1beta6
Replies: 21
Views: 12044

Re: IPv6 forwarding not working in 7.1beta6

I'm running a hEX (model: RB750Gr3) - I don't believe it's a connection tracking issue as I don't see matches on the "invalid" rule also. And yes input is working, just forward not.
by robertpenz
Sun May 23, 2021 8:24 pm
Forum: RouterOS beta
Topic: IPv6 forwarding not working in 7.1beta6
Replies: 21
Views: 12044

Re: IPv6 forwarding not working in 7.1beta6

Downgrade to 7.1beta4 makes ping working, but TCP traffic is still not forwarded.
by robertpenz
Sun May 23, 2021 1:41 pm
Forum: RouterOS beta
Topic: IPv6 forwarding not working in 7.1beta6
Replies: 21
Views: 12044

IPv6 forwarding not working in 7.1beta6

Hi! UPDATE: IPv6 forwarding is not working at all - does not matter if I add 2 vlans and I try to ping between them or the below setup. The counters of the ipv6 firewall rules are not incremented (also the invalid drop rules. I've also disabled all queues - so that can't also be the problem. I was r...
by robertpenz
Sun May 23, 2021 11:02 am
Forum: RouterOS beta
Topic: UPS Module Missing in 7.1beta6
Replies: 0
Views: 1395

UPS Module Missing in 7.1beta6

Hi!

I've upgraded from a 6.x to 7.1beta6, and now I'm missing the /system/ups path. I've looked into the all_packages-mmips-7.1beta6.zip, but there is no ups module. Please advise how to get the ups monitoring going again. Thx.

Regards,
Robert
by robertpenz
Wed Apr 10, 2019 8:44 pm
Forum: General
Topic: [Feature request] Wireguard
Replies: 148
Views: 65821

Re: [Feature request] Wireguard

We did some performance Tests with Wireguard and man it is faster than any other VPN with much less CPU load! And for Android Phones the battery is not used more than without VPN, which is not true for all other VPNs - It makes a VPN almost transparent performance wise. Please implement!!
by robertpenz
Thu Apr 19, 2018 11:40 am
Forum: General
Topic: CHR still communicates with 169.254.169.254
Replies: 8
Views: 2643

Re: CHR still communicates with 169.254.169.254

@sid5632: thx, changed it to your version
by robertpenz
Thu Apr 19, 2018 11:39 am
Forum: General
Topic: CHR still communicates with 169.254.169.254
Replies: 8
Views: 2643

Re: CHR still communicates with 169.254.169.254

no, the CHR is on our own ESX in our datacenter.
by robertpenz
Thu Apr 19, 2018 11:02 am
Forum: General
Topic: CHR still communicates with 169.254.169.254
Replies: 8
Views: 2643

CHR still communicates with 169.254.169.254

I'm seeing on our firewalls that our test CHR is trying to connect to IP 169.254.169.254 with HTTP every few seconds (= over 250.000 connections attempts in 12h) . Google showed some old posts from 2015 where it was described as bug that will be fixed. As we're running 6.41.4, so it seems not. I did...
by robertpenz
Thu Jan 04, 2018 11:08 am
Forum: General
Topic: Meltdown and Spectre Security Vulnerabilities on x86
Replies: 13
Views: 4352

Re: Meltdown and Spectre Security Vulnerabilities on x86

so its not possible to get from a guest down to the host?
by robertpenz
Thu Jan 04, 2018 11:03 am
Forum: General
Topic: Meltdown and Spectre Security Vulnerabilities on x86
Replies: 13
Views: 4352

Re: Meltdown and Spectre Security Vulnerabilities on x86

What about Meta-Router feature? And Spectre is not Intel only, also ARM. https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html These vulnerabilities affect many CPUs, including those from AMD, ARM, and Intel, as well as the devices and operating systems running on them.
by robertpenz
Wed Oct 04, 2017 9:30 am
Forum: General
Topic: RouterOS affected by Dnsmasq security vulnerabilities?
Replies: 1
Views: 1429

RouterOS affected by Dnsmasq security vulnerabilities?

Hi! Is RouterOS (and if yes which versions) affected by the CVE-2017-14491, CVE-2017-14492, CVE-2017-14493, CVE-2017-14494, CVE-2017-14495, CVE-2017-14496, CVE-2017-13704 which where released by Google? https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html I'm asking as I fo...
by robertpenz
Thu Feb 09, 2017 3:12 pm
Forum: General
Topic: Weird 129.0.0.x IPs ?
Replies: 30
Views: 7719

Re: Weird 129.0.0.x IPs ?

I've reported that problem in ticket 2017020822000589, and Sergejs has acknowledged a bug with handling tagged packets and they will fix it.
by robertpenz
Wed Feb 08, 2017 12:13 pm
Forum: General
Topic: Weird 129.0.0.x IPs ?
Replies: 30
Views: 7719

Re: Weird 129.0.0.x IPs ?

I see the same problem with 6.37.4. It seems to be a problem on interfaces which have tagged vlans. As I see the same problem on multiple routers which are not on the same subnet it can't be a damaged NIC or wrong configured client. We've also activated reverse path filtering so its not possible tha...
by robertpenz
Sun Nov 27, 2016 6:54 pm
Forum: RouterBOARD hardware
Topic: hEX mode button/switch next to usb port
Replies: 1
Views: 10620

hEX mode button/switch next to usb port

Hi!

What is the purpose of the mode button/switch next to the USB port as seen on this image. Could not find an answer searching.

Image
by robertpenz
Mon Feb 08, 2016 8:35 am
Forum: General
Topic: Integrate WAN Optimization based on SoloWAN
Replies: 3
Views: 3359

Re: Integrate WAN Optimization based on SoloWAN

With userspace I meant that there is no kernel patching needed as the mikrotik kernel is heavily modified so that would be tricky to apply. A user space program with only a few dependencies should be much easier to integrate. ;-)
by robertpenz
Sun Feb 07, 2016 7:27 pm
Forum: General
Topic: Integrate WAN Optimization based on SoloWAN
Replies: 3
Views: 3359

Integrate WAN Optimization based on SoloWAN

The popular German enterprise IT magazine iX did a big article about WAN optimization in their last issue (2/2016). Part of the article was testing Open Source solutions. The clear winner is SoloWAN (https://github.com/centeropenmiddleware/solowan). They did tests for cifs, nfs, https and http traff...
by robertpenz
Thu Aug 13, 2015 10:03 am
Forum: General
Topic: Now we need RSA support - OpenSSH 7.0 has removed DSA support
Replies: 3
Views: 1567

Now we need RSA support - OpenSSH 7.0 has removed DSA support

Hi! I don't understand why Mikrotik keeps DSA, its insecure (yes, also the 2048bit version), and does not support RSA. Anyway yesterday OpenSSH 7.0 has been released and DSA is not longer supported. So please move to RSA and ECC now - Thx! see also: http://it.slashdot.org/story/15/08/11/2340247/open...
by robertpenz
Sat Jul 11, 2015 1:51 pm
Forum: General
Topic: Feature request: support RSA keys and update DH group support
Replies: 2
Views: 1617

Re: Feature request: support RSA keys and update DH group support

RSA would be great for yubi keys to have two factor authentication (ssh key on the yubi key)
by robertpenz
Sat Jun 27, 2015 6:48 pm
Forum: Announcements
Topic: Dual band AP for home use, SSID same or different?
Replies: 62
Views: 53489

Re: Dual band AP for home use, SSID same or different?

Please make it possible to push certain clients from 2,4 to 5ghz if the same SSID is configured (which should the default mode on shipping). Some devices stay on 2,4 even if they support 5, and the air time in the 2,4 space is valuable.
by robertpenz
Tue Feb 24, 2015 10:59 am
Forum: Forwarding Protocols
Topic: What BGP setups need to be optimized
Replies: 57
Views: 32164

Re: What BGP setups need to be optimized

Answer is per router: * how many peers; 10 * how many routes in routing table; /ip route print count-only 1978010 /ipv6 route print count-only 43565 * is there also OSPF,MPLS, VPLS, RIP etc running on the router; OSPF * what are the hardware specs; CCR1036-8G-2S+ * are there routing filters; yes * a...
by robertpenz
Mon Dec 22, 2014 7:20 pm
Forum: Forwarding Protocols
Topic: ECMP OSFP Routes changes between 5.x and 6.x?
Replies: 0
Views: 1048

ECMP OSFP Routes changes between 5.x and 6.x?

Hi, We've implemented an OSFP ECMP setup with 5.x and for each tcp connection / flow it has been decided which route it takes. For us it seams that this has been changed with 6.x that the same dst-address (of the flow) of multiple clients stay on the same interface. Is this correct? and how can we c...
by robertpenz
Sat Nov 08, 2014 10:50 am
Forum: General
Topic: Feature request: SNMP v3 AES encryption
Replies: 6
Views: 3626

Re: Feature request: SNMP v3 AES encryption

Using 6.18 with snmpv3 and aes for some weeks now ... no problems. it is stable even if queried a lot.
by robertpenz
Mon Oct 06, 2014 6:36 pm
Forum: General
Topic: License Upgrade Restrictions removed?
Replies: 2
Views: 1559

License Upgrade Restrictions removed?

Following text http://wiki.mikrotik.com/index.php?title=Manual:License&curid=1634&diff=26596&oldid=26595 RouterOS upgrade capabilities are not limited by time, but by version, and this depends on the RouterOS license level. For example if you are running RouterOS v5, your license could r...
by robertpenz
Thu Aug 28, 2014 11:01 pm
Forum: Forwarding Protocols
Topic: BGP4-MIB Support
Replies: 5
Views: 2393

Re: BGP4-MIB Support

+1 also
by robertpenz
Thu Jul 31, 2014 9:24 am
Forum: Forwarding Protocols
Topic: {} in BGP AS paths?
Replies: 2
Views: 1475

Re: {} in BGP AS paths?

Is it possible that this are aggregated AS?
by robertpenz
Thu Jul 31, 2014 9:13 am
Forum: Forwarding Protocols
Topic: {} in BGP AS paths?
Replies: 2
Views: 1475

{} in BGP AS paths?

I've found AS paths with { } entries ... does someone know what that means? Here a screenshot
by robertpenz
Sat Jul 05, 2014 5:17 pm
Forum: Forwarding Protocols
Topic: Migrate Vyatta BGP to RouterOS BGP
Replies: 14
Views: 5217

Re: Migrate Vyatta BGP to RouterOS BGP

I replaced 2 Vyatta Routers with Mikrotik ones, the setup is the basis for this blog post: http://robert.penz.name/779/howto-setup ... k-routers/
by robertpenz
Tue Jun 10, 2014 2:59 pm
Forum: General
Topic: OPENSSL 5 june bugs
Replies: 11
Views: 4696

Re: OPENSSL 5 june bugs

What I want to know is, if only the administration (HTTPS, Winbox) is vulnerable, which would be not big problem as we're using dedicated management networks, or production service also external user can reach.
by robertpenz
Tue Jun 10, 2014 2:52 pm
Forum: General
Topic: OPENSSL 5 june bugs
Replies: 11
Views: 4696

Re: OPENSSL 5 june bugs

ok only 6.x gets an security update. so switch services are vulnerable? I need this to compare the the security impact against the time and money the update from 5.x costs.
by robertpenz
Tue Jun 10, 2014 2:20 pm
Forum: General
Topic: OPENSSL 5 june bugs
Replies: 11
Views: 4696

Re: OPENSSL 5 june bugs

With my routers running 6.x thats easy. But we've many 5.x still and a upgrade to 6.14 is not that fast done. So I would like to know which services/protocols are affected. If I don't use them I don't need to upgrade. Or will there be a 5.x security release.
by robertpenz
Fri Jun 06, 2014 5:35 pm
Forum: General
Topic: OPENSSL 5 june bugs
Replies: 11
Views: 4696

Re: OPENSSL 5 june bugs

Which services / protocols on the RouterOS are vulnerable?
by robertpenz
Sun Jun 01, 2014 8:42 pm
Forum: General
Topic: Howto on setup a Mikrotik RouterOS with Suricata as IDS
Replies: 3
Views: 3001

Re: Howto on setup a Mikrotik RouterOS with Suricata as IDS

Because I post in my blog not only Mikrotik stuff (in reality it is only a small part) and I want one central place for all my stuff.
by robertpenz
Sun Jun 01, 2014 5:11 pm
Forum: General
Topic: Howto on setup a Mikrotik RouterOS with Suricata as IDS
Replies: 3
Views: 3001

Howto on setup a Mikrotik RouterOS with Suricata as IDS

I've written a howto on combining Suricata and RouterOs (/tool sniffer) for a SOHO setup as IDS (Intrusion detection system). I link it here, as I've read multiple times people asking for it and today I got some time to write everything down. So here is it: http://robert.penz.name/849/howto-setup-a-...
by robertpenz
Mon May 12, 2014 10:03 pm
Forum: General
Topic: Hotspot Feature via Layer 3 not working with VRRP
Replies: 1
Views: 1368

Re: Hotspot Feature via Layer 3 not working with VRRP

Is nobody running a Layer 3 hotspot network?
by robertpenz
Sun May 04, 2014 10:48 pm
Forum: General
Topic: Feature Requests for 7.x for improved network security
Replies: 11
Views: 6274

Re: Feature Requests for 7.x for improved network security

For authenticating users to login via ssh access onto the router or something like this you're correct. But for authentication devices for network access via 802.1x RADIUS is the only game in town. And the encryption of data is not so important there as EAP-TLS is mostly used (If security is a conce...
by robertpenz
Thu May 01, 2014 12:08 pm
Forum: General
Topic: Hotspot Feature via Layer 3 not working with VRRP
Replies: 1
Views: 1368

Hotspot Feature via Layer 3 not working with VRRP

I have following setup in my lab to reproduce the problem: The Mikrotik has the Internet connection and is running a DHCP Server and Hotspot Server. A layer 3 switch which connects the clients and also provides a DHCP Relay. e.g.: Internet -- Hotspot Mikrotik - (10.0.0.0/24)- Layer3 Switch - (10.0.1...
by robertpenz
Mon Apr 21, 2014 12:45 pm
Forum: General
Topic: Feature Requests for 7.x for improved network security
Replies: 11
Views: 6274

Re: Feature Requests for 7.x for improved network security

What has TACACS (Terminal Access Controller Access-Control System) to do with authenticating network devices? As far as I know TACACS is only used for authenticating users that want to access the router (= the admins) .. it has nothing to do with network security or I'm mistaken?
by robertpenz
Sat Apr 19, 2014 8:26 pm
Forum: General
Topic: Feature Requests for 7.x for improved network security
Replies: 11
Views: 6274

Re: Feature Requests for 7.x for improved network security

Zorro: I believe you misunderstood my feature request. If you use the DHCP Server on the Mikrotik it is possible to add the MAC address of the client which got the lease to the ARP table of the router. If you now disabled ARP learning only Clients with DHCP can talk over the router and ARP spoofing ...
by robertpenz
Tue Apr 08, 2014 3:32 pm
Forum: General
Topic: Heartbleed vulnerability OpenSSL [RouterOS IS NOT affected]
Replies: 9
Views: 10357

Re: Heartbleed vulnerability in OpenSSL - RouterOS affected?

Does this mean 6.x have the vulnerability and 5.x don't?
by robertpenz
Sat Mar 22, 2014 2:54 pm
Forum: Forwarding Protocols
Topic: BGP multicore support
Replies: 4
Views: 2580

Re: BGP multicore support

plus 1
by robertpenz
Sat Mar 22, 2014 2:53 pm
Forum: Forwarding Protocols
Topic: Howto on a redundant and secure BGP (full table) setup
Replies: 1
Views: 1703

Howto on a redundant and secure BGP (full table) setup

Hi! I wanted to write this howto for a long time, but never had the time. But now it happened, a howto called "Howto setup a redundant and secure BGP (full table) Internet connection with Mikrotik Routers" and here is the link: http://robert.penz.name/779/howto-setup-a-redundant-and-secure...
by robertpenz
Fri Feb 28, 2014 11:12 am
Forum: Forwarding Protocols
Topic: show ip bgp summary
Replies: 3
Views: 11490

Re: show ip bgp summary

Big Thx for this script!
by robertpenz
Sat Feb 22, 2014 6:31 pm
Forum: Forwarding Protocols
Topic: BGP4-MIB
Replies: 14
Views: 10002

Re: BGP4-MIB

+1 SNMP Monitoring of BGP
by robertpenz
Sat Feb 22, 2014 6:24 pm
Forum: General
Topic: Feature Requests for 7.x for improved network security
Replies: 11
Views: 6274

Feature Requests for 7.x for improved network security

Hi! I would love following features specially for the CRS. - Wired MAC Authentication against Radius with dynamic VLAN assignment via Radius - Wired 802.1x Authentication against Radius with dynamic VLAN assignment via Radius - Wired Dual (MAC and 802.1x) Authentication against Radius Following for ...
by robertpenz
Sun Jan 26, 2014 6:38 pm
Forum: Forwarding Protocols
Topic: MIkrotik BGP Monitoring
Replies: 64
Views: 38171

Re: MIkrotik BGP Monitoring

These 3 would be also my favorites .
by robertpenz
Fri Oct 25, 2013 5:21 pm
Forum: General
Topic: Security: Random cypto generator broken in MIPS Kernel
Replies: 3
Views: 1651

Re: Security: Random problem in MIPS Kernels

Still no answer? I've also sent a mail to the mikrotik support but also no answer there either ....do I need to consider the ipsec part to be brocken for the future?
by robertpenz
Fri Oct 25, 2013 4:50 pm
Forum: General
Topic: MikroTik News October 2013 (Issue #52)
Replies: 27
Views: 14239

Re: MikroTik News October 2013 (Issue #52)

We are working on a new manual, here is a start http://wiki.mikrotik.com/wiki/Manual:CRS_examples The new CRS looks good from the hardware and cost perspective! But if you want to get also in the small remote offices (currently one needs a router, a switch and access point - with CRS only one devic...
by robertpenz
Sun Sep 29, 2013 5:09 pm
Forum: General
Topic: Security: Random cypto generator broken in MIPS Kernel
Replies: 3
Views: 1651

Security: Random cypto generator broken in MIPS Kernel

Some weeks ago a bug in the random function get_cycles() of the Linux kernel for MIPS processors was discovered. e.g. https://lists.openwrt.org/pipermail/openwrt-devel/2013-September/021318.html And 10 days ago a fix was provided for this: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.g...
by robertpenz
Tue Sep 10, 2013 12:11 pm
Forum: General
Topic: QoS Piorities and PCQ
Replies: 3
Views: 1616

Re: QoS Piorities and PCQ

Ok, Thx for your help.
by robertpenz
Mon Sep 09, 2013 10:46 am
Forum: General
Topic: QoS Piorities and PCQ
Replies: 3
Views: 1616

QoS Piorities and PCQ

Hi! I've following queues for my WAN interfaces on both routers and it works as excepted. Now I want to add PCQ to make sure that not one session is filling up the connection if there are other sessions. Where to I need to add the PCQ? with each /queue or is it enough if I set it for the parent? Do ...
by robertpenz
Fri May 31, 2013 12:36 pm
Forum: RouterBOARD hardware
Topic: FAN broken in RB1100AHx2?
Replies: 0
Views: 1366

FAN broken in RB1100AHx2?

I've a question about the fan in a RB1100AHx2. Normally the output looks like this: /system health print fan-mode: auto use-fan: main active-fan: main voltage: 12.3V current: 757mA fan-speed: 1952RPM temperature: 25C cpu-temperature: 35C power-consumption: 9.3W But I've one Router which look like th...
by robertpenz
Tue Feb 19, 2013 8:16 am
Forum: RouterBOARD hardware
Topic: CCR - Secondary PSU
Replies: 58
Views: 32242

Re: CCR - Secondary PSU

+1 for the post from SwissWISP ... that and a paid support subscription are the only parts holding us back in using Mikrotiks more and in more critical areas.
by robertpenz
Sun Feb 17, 2013 10:45 pm
Forum: RouterBOARD hardware
Topic: CCR - Secondary PSU
Replies: 58
Views: 32242

Re: CCR - Secondary PSU

It would be nice to buy the CCR with 2 PSUs in the first place. With the CCR you're moving into the data centers where this is standard.
by robertpenz
Sun Feb 10, 2013 7:46 pm
Forum: Forwarding Protocols
Topic: OSPF Design consideration
Replies: 10
Views: 6052

Re: OSPF Design consideration

Yeah, I would also use only one area for this small setup. Remove the complexity!! >500 routers in one area is no problem today ... Use areas to separate devices with bad ospf implementations from the rest. E.g. loadbalancers or mainframes Or for security reasons ( you want all traffic over some spe...
by robertpenz
Fri Nov 30, 2012 9:47 pm
Forum: General
Topic: simple queues understanding problem
Replies: 5
Views: 3216

Re: simple queues understanding problem

Fixed in rc4
by robertpenz
Fri Nov 30, 2012 5:34 pm
Forum: General
Topic: Please support terminating EoIP and IPIP tunnels on VRRP Int
Replies: 2
Views: 2717

Re: Please support terminating EoIP and IPIP tunnels on VRRP

Why not make 2 ipip tunnels and run ospf over it? I'm running ipsec encrypted ipip tunnels with ospf for a long time without problems .
by robertpenz
Thu Nov 29, 2012 10:09 pm
Forum: General
Topic: USE adsl modem as a bridge
Replies: 1
Views: 1111

Re: USE adsl modem as a bridge

Take a look at this blog entry http://robert.penz.name/484/howto-use-a ... onnection/ ... Different modem but also mikrotik router
by robertpenz
Sun Nov 25, 2012 9:26 am
Forum: General
Topic: simple queues understanding problem
Replies: 5
Views: 3216

Re: simple queues understanding problem

Mikrotik reported back. They could reproduce the bug.
by robertpenz
Sat Nov 24, 2012 8:58 pm
Forum: General
Topic: TCP Connection Reopening Bug in 5.xx?
Replies: 2
Views: 1814

TCP Connection Reopening Bug in 5.xx?

Hi! I believe I found a bug in at least the 5.xx releases (tested with 5.14 and 5.20). Can someone verify my findings please. Following is the setup: VoIP Phone (h.323) - Switch - Mikrotik Router - Switch - VoIP Gateway Here the packet flow 1. A call (media is initialized by the Gateway to the phone...
by robertpenz
Fri Nov 23, 2012 10:38 pm
Forum: RouterBOARD hardware
Topic: Product idea: cheap and small mikrotik as media converter
Replies: 1
Views: 1218

Product idea: cheap and small mikrotik as media converter

Hi, We sometimes need media converts fibre to copper ... But it would be cool to have something with some management capatilities ..... Let's say a really small mikrotik with one sfp(or even integrated) and one rj45 plug. Just needs to have following features: - ssh login - bridging between both int...
by robertpenz
Wed Nov 14, 2012 11:24 pm
Forum: General
Topic: simple queues understanding problem
Replies: 5
Views: 3216

Re: simple queues understanding problem

Its a bug ... it works in rc2 and rc3 until the pptp connection reconnects than it stops working .. I reported it to mikrotik.
by robertpenz
Wed Nov 14, 2012 6:05 pm
Forum: General
Topic: simple queues understanding problem
Replies: 5
Views: 3216

Re: simple queues understanding problem

thx for your answer

1. I had that already, did remove it as I thought thats maybe the problem .. but I will reinsert it
2. all traffic which the child should get, goes through the DSL Uplink or is there some error in the config so that's not the case?
3. ok
by robertpenz
Tue Nov 13, 2012 10:42 pm
Forum: General
Topic: simple queues understanding problem
Replies: 5
Views: 3216

simple queues understanding problem

Hi! I've installed 6.0rc2 to play with the simple rules, but I don't understand something My test setup is a mikrotik with a DSL uplink and multiple VLANs hind it. I want to shape the traffic from and to the Internet but not between the VLANs. I therefore added following queue /queue simple add max-...
by robertpenz
Sat Nov 10, 2012 12:29 pm
Forum: RouterBOARD hardware
Topic: CLOUD CORE ROUTER
Replies: 1373
Views: 1188623

Re: CLOUD CORE ROUTER

Can you tell me the aes128 performance of the ccr models? Do they have also a special crypto chip?

THX
by robertpenz
Wed Nov 07, 2012 8:58 pm
Forum: Wireless Networking
Topic: USB UMTS Stick (Huawei E170) NO CARRIER
Replies: 1
Views: 3585

USB UMTS Stick (Huawei E170) NO CARRIER

Hi! I've a Huawei E170 USB UMTS Stick which works fine under Linux (Centos 6). Now I wanted to use this stick with a Mikrotik (RB751G-2HnD, running 6.0rc2) but I keep getting "NO CARRIER" with a configuration that I believe matches my Linux box. The LED is on the USB stick shows that it is...
by robertpenz
Sat Jul 21, 2012 11:37 am
Forum: General
Topic: How does the balance-xor bonding exactly work?
Replies: 2
Views: 4552

Re: How does the balance-xor bonding exactly work?

ah thx. the transmit-hash-policy is not only for the 802.3ad - i overlooked that

that means I can use balance-xor with transmit-hash-policy layer-2-and-3 / layer-3-and-4 and arp as link-monitoring over 2 eoip tunnels which is not possible 802.3ad. thats cool thx.
by robertpenz
Fri Jul 20, 2012 2:52 pm
Forum: General
Topic: How does the balance-xor bonding exactly work?
Replies: 2
Views: 4552

How does the balance-xor bonding exactly work?

From the wiki page http://wiki.mikrotik.com/wiki/Manual:Interface/Bonding I get following balance-xor This mode balances outgoing traffic across the active ports based on hashed protocol header information and accepts incoming traffic from any active port. Mode is very similar to LACP except that it...
by robertpenz
Fri Mar 02, 2012 8:16 am
Forum: Virtualization
Topic: MetaRouter and 1100AH on ROS 5.8 not working?
Replies: 36
Views: 23419

Re: MetaRouter and 1100AH on ROS 5.8 not working?

I believe the x2 is a dual core machine, which does not support metarouter.
by robertpenz
Wed Jan 11, 2012 12:43 pm
Forum: Virtualization
Topic: MetaRouter and 1100AH on ROS 5.8 not working?
Replies: 36
Views: 23419

Re: MetaRouter and 1100AH on ROS 5.8 not working?

But often you need something on such a "big device" the mikrotik os does not have, like a real radius server (freeradius) and than a openwrt would be nice. If 60mb more flash would make it 5-10 euro more expensive I believe nobody would mind and it would really open some use cases.
by robertpenz
Wed Jan 11, 2012 12:01 pm
Forum: Virtualization
Topic: MetaRouter and 1100AH on ROS 5.8 not working?
Replies: 36
Views: 23419

Re: MetaRouter and 1100AH on ROS 5.8 not working?

but the new 1100AH has also only 40mb and there it is supported (which is good btw as multiple routing instances is state of the art for better switches/routers)
by robertpenz
Wed Jan 11, 2012 11:32 am
Forum: Virtualization
Topic: MetaRouter and 1100AH on ROS 5.8 not working?
Replies: 36
Views: 23419

Re: MetaRouter and 1100AH on ROS 5.8 not working?

but a router with virtualisation support, which can't be really used with 40mb ;-)
by robertpenz
Thu Dec 15, 2011 9:59 am
Forum: General
Topic: /store add --> input does not match any value of type
Replies: 2
Views: 1517

Re: /store add --> input does not match any value of type

I formated it and than I got the status "ready" otherwise it would be not ready. I also did a check-drive. But I'll try an other microsd card, maybe it is incompatible.
by robertpenz
Wed Dec 14, 2011 5:12 pm
Forum: General
Topic: /store add --> input does not match any value of type
Replies: 2
Views: 1517

/store add --> input does not match any value of type

Hi! I'm trying following on an 450g with 5.9 and 5.11 software: > /store disk print detail Flags: S - system 0 S name="system" total-space=520192KiB free-space=483996KiB status=ready 1 name="micro-sd" total-space=7639928KiB free-space=7491668KiB status=ready > /store print detail...
by robertpenz
Wed Dec 07, 2011 7:11 pm
Forum: RouterBOARD hardware
Topic: 1100AH and IPsec performance
Replies: 8
Views: 3737

Re: 1100AH and IPsec performance

We've 100Mbit-200Mbit Traffic so it is a problem for us. We are at 90% CPU with 10Mbyte/sec (100Mbit) (ftp server and ftp client, not to the mikrotik) but we need more and the data sheets said AES chip, but I guess that where the old sheets .... Really bad to name a device as a old one but to have o...
by robertpenz
Wed Dec 07, 2011 8:30 am
Forum: RouterBOARD hardware
Topic: 1100AH and IPsec performance
Replies: 8
Views: 3737

Re: 1100AH and IPsec performance

oh, thats not good ... as its the main feature for us
by robertpenz
Mon Dec 05, 2011 7:33 pm
Forum: RouterBOARD hardware
Topic: 1100AH and IPsec performance
Replies: 8
Views: 3737

1100AH and IPsec performance

Hi! I've a setup where two 1100AH are connected via 100Mbit and I'm using IPsec with /ip ipsec proposal add auth-algorithms=null disabled=no enc-algorithms=aes-128 lifetime=30m name=IPSec pfs-group=modp1024 And I'm getting 10mbyte/sec through the tunnel, but I don't understand following (during copi...
by robertpenz
Mon Dec 05, 2011 7:18 pm
Forum: Virtualization
Topic: MetaRouter and 1100AH on ROS 5.8 not working?
Replies: 36
Views: 23419

Re: MetaRouter and 1100AH on ROS 5.8 not working?

We've a testversion of a software upgrade which seems to be stable in our tests with metarouter, but we're still testing it. Don't know if other customers are testing it.

Edit: Just found out that RouterOS v5.9 has been released ... we needed to flash our test version via netinstall to make it work.
by robertpenz
Wed Nov 30, 2011 5:44 pm
Forum: Virtualization
Topic: Metarouter on microSD, will it be ever supported ?
Replies: 20
Views: 21370

Re: Metarouter on microSD, will it be ever supported ?

@janisk: You asked why someone whats to have OpenWRT. We need it in our small remote locations for a Radius Server that can perform 802.1x and MAC authentication. We're replicating the data from the central server and the switches have both server configured. so if there is a problem with one server...
by robertpenz
Wed Nov 23, 2011 2:10 pm
Forum: RouterBOARD hardware
Topic: 1100AH power POE and normal at the same time?
Replies: 4
Views: 2287

1100AH power POE and normal at the same time?

Hi!

I've connected the 1100AH to the normal power (230V) and connected Eth13 to a POE injector. If I removed one of the two power connections the Mikrotik kept running. Has this setup any bad side effects?

Is there a possibility to monitor if one of the 2 "power supplies" goes down?
by robertpenz
Fri Nov 18, 2011 3:24 pm
Forum: Virtualization
Topic: MetaRouter and 1100AH on ROS 5.8 not working?
Replies: 36
Views: 23419

Re: MetaRouter and 1100AH on ROS 5.8 not working?

We've the same problem, just bought four 1100AH with the explicit purpose to use them with MetaRouter, as MetaRouter is not stable on e.g 450G. We really need a fast feedback/solution as otherwise we'll send them back as not working, which we can't do if we keep it longer than for a few days. We bou...
by robertpenz
Sat Oct 15, 2011 2:14 pm
Forum: Virtualization
Topic: RB450G + openwrt Metarouter strange problem
Replies: 221
Views: 95549

Re: RB450G + openwrt Metarouter strange problem

I also would be really interested in the progress .....
by robertpenz
Tue Oct 11, 2011 8:51 am
Forum: General
Topic: IPsec with multiple subnets on both sides
Replies: 3
Views: 9422

Re: IPsec with multiple subnets on both sides

Ah thx I overlooked the "none" part ... thx About the IP scheme .. it looks not good in this example but if you've > 100 locations and need separate subnets for different devices it gets quit easy in the data center to sort out the devices as e.g. device class 1 is always with 10.1.x.x and...
by robertpenz
Mon Oct 10, 2011 9:56 am
Forum: General
Topic: IPsec with multiple subnets on both sides
Replies: 3
Views: 9422

IPsec with multiple subnets on both sides

Hi! I've following setup: Subnets - Router 1 - IPsec - Router2 - Subnets and Internet Following subnets are directly connected to the router1 10.1.99.0/24 10.2.99.0/24 10.3.99.0/24 10.4.99.0/24 and the router routes between them. The Subnet used for connecting router 1 and 2 is 10.4.254.0/24 Behind ...