Community discussions

Search found 207 matches

by Kindis
Thu Dec 06, 2018 3:45 pm
Forum: Announcements
Topic: URGENT security reminder
Replies: 84
Views: 16503

Re: URGENT security reminder

No, major misunderstanding :D

Not "it will be fixed in v7", but "It can only be fixed in v7".
So sorry but I could not just contain myself ;-) Not that I'm missing V7 I just follow the forum :-)
by Kindis
Thu Dec 06, 2018 3:40 pm
Forum: Announcements
Topic: URGENT security reminder
Replies: 84
Views: 16503

Re: URGENT security reminder

This sums up how I think ROS 7 is communicated! :-)
Image
by Kindis
Thu Nov 22, 2018 4:20 pm
Forum: General
Topic: Configuration backup encrypted with default password in RouterOS v6.43.4 does not work like other versions of RouterOS
Replies: 6
Views: 487

Re: Configuration backup encrypted with default password in RouterOS v6.43.4 does not work like other versions of Router

@eider Thank you for your post. "In newer version password is no longer stored as plain-text so it can not be used to encrypt backup file without user explicitly providing password." In the newer version, Does it mean that the user password of RouterOS is not used by default for the encryption of a...
by Kindis
Thu Nov 22, 2018 11:46 am
Forum: Virtualization
Topic: CHR disk size
Replies: 6
Views: 372

Re: CHR disk size

Hi! Setup CHR in my VPS. HDD space 50GB. After first boot - router os resize disk, remains 15GB.. Where is the rest of the disk space? Had a vague memory that they limited the size of CHR disk in a release so I made a search in the change logs and I found the following: What's new in v6.40 (2017-Ju...
by Kindis
Tue Nov 20, 2018 7:43 pm
Forum: General
Topic: Configuration backup encrypted with default password in RouterOS v6.43.4 does not work like other versions of RouterOS
Replies: 6
Views: 487

Re: Configuration backup encrypted with default password in RouterOS v6.43.4 does not work like other versions of Router

Could be this.

What's new in 6.43 (2018-Sep-06 12:44):

MAJOR CHANGES IN v6.43:
----------------------
!) backup - do not encrypt backup file unless password is provided;
by Kindis
Tue Nov 20, 2018 9:31 am
Forum: General
Topic: hAP AC - slow eth speed to INET
Replies: 2
Views: 205

Re: hAP AC - slow eth speed to INET

I have not seen this issue in any of my setups but you should consider adding more safety to your setup. Right now you do not drop everything new to efter1 which is you WAN port. I woudl recommend that you do the following: /ip firewall filter add action=fasttrack-connection chain=forward connection...
by Kindis
Fri Nov 09, 2018 11:10 am
Forum: Virtualization
Topic: CHR Performance issues Hyper-V
Replies: 2
Views: 445

Re: CHR Performance issues Hyper-V

What license do you have on the CHR?
by Kindis
Thu Nov 01, 2018 3:25 pm
Forum: General
Topic: Network Printer on the two Subnets
Replies: 2
Views: 286

Re: Network Printer on the two Subnets

I had a similar issue as you. I have my printer, and other devices I do not trust, on a separate subnet at home. Now the client my wife gets from her local IT at work have just started a automatic VPN tunnel that uses forced tunneling. This means she cannot use our printer at all as 0.0.0.0/0 point ...
by Kindis
Tue Oct 30, 2018 11:52 pm
Forum: General
Topic: Strange loop on update from 6.37.3 to 6.43.4
Replies: 5
Views: 351

Re: Strange loop on update from 6.37.3 to 6.43.4

6.37 is vulnerable to a couple of exploits and you may have been compromised.
Export config, review config for any strange scripts and so, netinstall the device and import config. Just to be safe.
by Kindis
Tue Oct 30, 2018 5:34 pm
Forum: General
Topic: A bit confused about RB750 Gr3 IPSec
Replies: 5
Views: 326

Re: A bit confused about RB750 Gr3 IPSec

You cannot see the H under installed SA in winbox (bug) [..] Are you sure that Hardware AEAD is greyed out in SA detail screen status bar? Otherwise you can see H flag by enlarging the first grid column. Jesus Christ I use Excel to much. I'm so use to dubbel clicking on the column separator that it...
by Kindis
Tue Oct 30, 2018 9:50 am
Forum: General
Topic: A bit confused about RB750 Gr3 IPSec
Replies: 5
Views: 326

Re: A bit confused about RB750 Gr3 IPSec

I have one RB750Gr3 connecting to a 3011 using L2TP/IPSec and it uses SHA256 and aes-256-cbc. You cannot see the H under installed SA in winbox (bug) but if you use console or webfig I can see that the hardware offload is working. I have a 100 Mbit connection to it and I can easily push that connect...
by Kindis
Thu Oct 25, 2018 4:18 pm
Forum: General
Topic: Redirect request by source IP in a scenario with Server Microsoft (DC)
Replies: 3
Views: 162

Re: Redirect request by source IP in a scenario with Server Microsoft (DC)

No you cannot do that as far as I know on a DC. In this case your best bet is to add a other DNS server that can perform what you want and redirect all clients to this DNS. Make sure DNS for the domain works aswell. Maby a tiny Linux server with BIND could allow you to do what you want? You also get...
by Kindis
Sat Oct 13, 2018 9:24 am
Forum: General
Topic: Severe Performance Drop RB3011 [SOLVED]
Replies: 33
Views: 1248

Re: Severe Performance Drop RB3011 [SOLVED]

I have a 3011 and do not have this issue. Can you export your mangle rule? I can see if I can test it.
by Kindis
Wed Sep 19, 2018 2:57 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 27074

Re: v6.43.1 [stable] is released!

Yesterday upgraded two CCRs from 6.41.3 to 6.43.1 in the hotel I had vacation in Greece :) At least, now it's not vulnerable to WinBox user database reading xD Unfortunately, WinBox access is still allowed for every Free WiFi user in the hotel :( Feel free to add a new title to you business card "K...
by Kindis
Tue Sep 18, 2018 12:38 pm
Forum: Virtualization
Topic: Mikrotik CHR always rebooted at certain time (No irq hander)
Replies: 5
Views: 506

Re: Mikrotik CHR always rebooted at certain time (No irq hander)

We both have the same version of Windows server but I'm on .18970 but I have not had any issues with this on any lower build anyway. So the CHR build in it self should not be the issue. Are you running any other VM in the Hyper-V and do they have any issues? This is a tricky one but I would start w...
by Kindis
Sat Sep 15, 2018 11:01 am
Forum: Virtualization
Topic: Mikrotik CHR always rebooted at certain time (No irq hander)
Replies: 5
Views: 506

Re: Mikrotik CHR always rebooted at certain time (No irq hander)

We both have the same version of Windows server but I'm on .18970 but I have not had any issues with this on any lower build anyway. So the CHR build in it self should not be the issue. Are you running any other VM in the Hyper-V and do they have any issues? This is a tricky one but I would start wi...
by Kindis
Sat Sep 15, 2018 10:51 am
Forum: Announcements
Topic: v6.43 [current] is released!
Replies: 149
Views: 19456

Re: v6.43 [current] is released!

I'm very happy with this build I must say. Must be the best .0 build ever provided. Been running it since launch and a lot of things are better. OSPF is faster for some reason but it may come down to the huge improvements to CHR under Hyper-V. Granted I do not have a advanced environment and do not ...
by Kindis
Fri Sep 14, 2018 12:01 am
Forum: Virtualization
Topic: The CPU has been disabled by the guest operating system
Replies: 26
Views: 2542

Re: The CPU has been disabled by the guest operating system

Many do this and send to mikrotik. So they can troubleshoot.

https://kb.vmware.com/articleview?docid=2000542
by Kindis
Thu Sep 13, 2018 11:55 pm
Forum: Virtualization
Topic: Mikrotik CHR always rebooted at certain time (No irq hander)
Replies: 5
Views: 506

Re: Mikrotik CHR always rebooted at certain time (No irq hander)

What version of Ros are you using and also which version of hyper-v?
by Kindis
Mon Sep 10, 2018 11:56 am
Forum: Announcements
Topic: v6.43 [current] is released!
Replies: 149
Views: 19456

Re: v6.43 [current] is released!

Just upgraded two CHR instances to 6.43 and all worked great but I cannot see Cloud under IP !) cloud - added support for licensed CHR instances (including trial); I do not see it in WinBox or via Webfig. Cleared cache and all that and does not appear. I can see it via console or SSH so I have manag...
by Kindis
Thu Sep 06, 2018 2:54 pm
Forum: Virtualization
Topic: CHR Xen vs VMWare Performance
Replies: 3
Views: 567

Re: CHR Xen vs VMWare Performance

On regards related to hardware choice. Now performance would come down to the choice of testing. AMD CPU has more core and if they are added to CHR it should be able to hold more load but Intel is still king of single threaded performance. Also AMD has more intra core latency and this could also res...
by Kindis
Mon Aug 20, 2018 2:07 pm
Forum: Announcements
Topic: v6.42.7 [current] is released!
Replies: 159
Views: 22798

Re: v6.42.7 [current] is released!

Upgraded two 3011, one 493G, two CHR and two wAP AC. No issues what so ever. Also disabled PMKID for WPA2 and have no issues so far.
by Kindis
Sun Aug 05, 2018 11:54 am
Forum: General
Topic: Not enough disk space to perform update
Replies: 14
Views: 6548

Re: Not enough disk space to perform update

Did you find a solution to the problem? I have a similar problem. I can not upgrade to version 6.42.6 He says: ERROR: not enough disk space, 7.1MiB is required and only 6.7MiB is free How can I clean it? Have you tried this? https://www.mikrotik.com/download/share/fix_space.npk You can read more on...
by Kindis
Thu Aug 02, 2018 9:56 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 275
Views: 41295

Re: Winbox vulnerability: please upgrade

According to changelog it is fixed
What's new in 6.40.8 (2018-Apr-23 11:34):

!) winbox - fixed vulnerability that allowed to gain access to an unsecured router;
by Kindis
Wed Aug 01, 2018 9:51 am
Forum: Announcements
Topic: v6.42.6 [current]
Replies: 102
Views: 22412

Re: v6.42.6 [current]

I've got a CRS125-24G-1S that has Routerboard 3.41 in it and RouterOS is 6.40.4. I've tried several times to upgrade the RouterOS version to 6.42.6 as well as to 6.40.5. Neither will work. After rebooting, the CRS125 still shows RouterOS at 6.40.4. Suggestions? John Rayfield, Jr. What does the log ...
by Kindis
Tue Jul 31, 2018 10:02 pm
Forum: General
Topic: Upgrade from 6.40 to 6.42.6: wAP ac not found in neighbor list in winbox
Replies: 4
Views: 571

Re: Upgrade from 6.40 to 6.42.6: wAP ac not found in neighbor list in winbox

Have you tested a second restart? Updated: I remembered that there where issues with neighbor service after a .0 release but did not remember what release it was. Dug around in the change log and it is 6.41 release that had this issue. A second restart should solve this issue or fixing the interface...
by Kindis
Thu Jul 05, 2018 10:29 am
Forum: General
Topic: Unable to upgrade x86 from 6.34.5 to newer firmware
Replies: 4
Views: 368

Re: Unable to upgrade x86 from 6.34.5 to newer firmware

To which version are you upgrading?
by Kindis
Thu Jul 05, 2018 9:43 am
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 15217

Re: Winbox v3.16 released!

I have a crazy feature request. Abandon the current GUI framework that WinBox is using and move to QT. Yes, I know it will be a LOT of work, but it will make life easier for Mikrotik developers, and allow Mikrotik to add more features in the long run. I would go even further and say please rewrite ...
by Kindis
Fri Jun 29, 2018 12:59 am
Forum: Virtualization
Topic: CHR on Hyper-V - dhcp client unable to take address [SOLVED]
Replies: 3
Views: 448

Re: CHR on Hyper-V - dhcp client unable to take address [SOLVED]

Are you using VLAN? I have two CHR running on this version that have DHCP client working so it should be config.
by Kindis
Fri Jun 15, 2018 9:17 am
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 558
Views: 89909

Re: v6.43rc [release candidate] is released!

Big problem...
Updated Mys CCR (to 6,43rc27) an now stucked outside! All is running but cant connect - wrong username or password??? A bit of PANIC!!!

------------------
Sorry! Had two winbox on my pc!! Just need new winbox! Sorry!
You need Winbox 3.14
by Kindis
Tue Jun 05, 2018 4:53 pm
Forum: Virtualization
Topic: Upgrade CHR to 6.42.2 on Hyper-V 2008R2
Replies: 5
Views: 569

Re: Upgrade CHR to 6.42.2 on Hyper-V 2008R2

I Tried 6.42.3 and 6.43rc19, same result New RC release. Test if this will work for you. My guess is they have fixed an issue. *) chr - fixed boot on hosts older than Windows Server 2012 when running CHR on Hyper-V But you might already know this as you might be the one who reported this issue in t...
by Kindis
Mon May 28, 2018 10:34 am
Forum: General
Topic: CRS125 do I dare to upgrade from 6.37.4 to 6.41+ ?
Replies: 10
Views: 588

Re: CRS125 do I dare to upgrade from 6.37.4 to 6.41+ ?

I would upgrade to 6.40.8 (latest bugfix) before upgrading to new bridge. You can always contact MT support and check from which version to new version is best. You have a better bet at upgrading from latest bugfix to latest current. At least my guess is so. As you current version contains some nast...
by Kindis
Mon May 28, 2018 10:28 am
Forum: Virtualization
Topic: Upgrade CHR to 6.42.2 on Hyper-V 2008R2
Replies: 5
Views: 569

Re: Upgrade CHR to 6.42.2 on Hyper-V 2008R2

Contact support and inform them. A year or two ago I had an issue where the router should boot and you could login via console but everything timed out. They told me that it should work and they had no issues. After a while they told me the tested on Windows 10 Hyper-V which is = Server 2016 and I r...
by Kindis
Fri May 25, 2018 3:44 pm
Forum: Announcements
Topic: v6.42.3 [current]
Replies: 80
Views: 17552

Re: v6.42.3 [current]

Upgrades two CHR (running on Hyper-V), two 3011, one 493G and 2 wAP AC without any issues.
by Kindis
Fri May 25, 2018 12:27 pm
Forum: General
Topic: UPGRADING a RB1000 ROS v4.10 to 6.42.2 safely
Replies: 2
Views: 247

Re: UPGRADING a RB1000 ROS v4.10 to 6.42.2 safely

I would export config, netinstall and then import config. You might need to tweek config before import due to version differences.
by Kindis
Tue May 15, 2018 9:38 am
Forum: General
Topic: Warning before installing CHR 6.42.1 on Hyper-V
Replies: 22
Views: 2033

Re: Warning before installing CHR 6.42.1 on Hyper-V

For you that have this issue what guest servies have you activated? Are all activated including Dynamic Memory?
I wonder if this issue goes away if you disable all services including dynamic memory.
by Kindis
Mon Apr 23, 2018 4:24 pm
Forum: Announcements
Topic: v6.42.1 [current]
Replies: 273
Views: 32439

Re: v6.42.1 [current]

I have updated one 3011 and two CHR (Hyper-V) and so far so good. Took the ones that have a public IP first.
Don't think this was a problem for me though as I block anyone, for 30 days, coming from internet trying to connect to Winbox port.
by Kindis
Wed Apr 18, 2018 10:27 pm
Forum: Announcements
Topic: v6.42 [current]
Replies: 147
Views: 20206

Re: v6.42 [current]

When upgrade packages to v6.42 in CHR router (Hyper-V image), after reboot have: Loading system with initrd ERROR: could not find disk! Please attach it somewhere else. System hangs up. When loading blank chr-6.42.vhdx, the same error. Before v6.42 all works fine. Something wrong with .vhdx image? ...
by Kindis
Wed Apr 18, 2018 3:17 pm
Forum: General
Topic: router running 100%
Replies: 3
Views: 319

Re: router running 100%

Regarding upgrading to BugFix Only. It should be safe but it all comes down to config. I run everything on Current but in your case I would upgrade first to Bugfix channel. All changes from the release you are on can be viewed here, it a long read. https://mikrotik.com/download/changelogs/bugfix-rel...
by Kindis
Wed Apr 18, 2018 10:52 am
Forum: Announcements
Topic: v6.42 [current]
Replies: 147
Views: 20206

Re: v6.42 [current]

Install and upgrade via packages menu option crashed my 3011. Anyone else have issues. Now in constant boot loop. Cannot launch kernel. Any recommended next steps ?
I have updated two 3011 without issues. My guess is netinstall for you.
from which version did you upgrade? I want from 6.41.4
by Kindis
Wed Apr 18, 2018 9:45 am
Forum: General
Topic: router running 100%
Replies: 3
Views: 319

Re: router running 100%

Hi I have RB450G (mipsbe) version (6.34.1) which is shown as 100% CPU, I noticed that the profile is shown as 95% for unclassified. Has anyone had this issues ands what is inside of unclassified. You are on a very old build. Update to 6.40.7 (Bugfix only) and see if the issues goes away. Make sure ...
by Kindis
Tue Apr 10, 2018 10:15 am
Forum: Announcements
Topic: v6.41.4 [current]
Replies: 37
Views: 7214

Re: v6.41.4 [current]

Updated two 3011, two wAP AC, one CHR running on Hyper-V and also a 493G without any issues.
Are there any official plan to fix the firmware so it auto upgrades so I do not have to restart each machine twice every time? By offical plan I mean when this will be solved and not Yes it will be solved.
by Kindis
Wed Apr 04, 2018 11:28 pm
Forum: General
Topic: CRS 317 CPU LOAD
Replies: 2
Views: 335

Re: CRS 317 CPU LOAD

The test is singel threaded and only uses one core which is 100 % load which is 50 % in total as there are 2 cores.
You should test the throughput of the router/switch from a machine attached to the router/switch.
by Kindis
Wed Mar 28, 2018 12:25 am
Forum: General
Topic: High CPU on CCR1072 every pppoe-client go down
Replies: 13
Views: 912

Re: High CPU on CCR1072 every pppoe-client go down

This is a quote from the thread I linked, please read it. It doesn't matter if the user has public or private IP, it's about interfaces. When interfaces connect/disconnect, with combination with NAT, it gives you high CPU usage. So simply eliminate NAT from that router. Have a separate router "in fr...
by Kindis
Mon Mar 26, 2018 10:29 am
Forum: General
Topic: RouterOS making unaccounted outbound winbox connections [SOLVED]
Replies: 63
Views: 18499

Re: RouterOS making unaccounted outbound winbox connections [SOLVED]

Would it be possible for MT staff to create a pinned thread about this. With info about what attack vector was used, from what version of ROS are you safe and how to mitigate if you are effected. I know you can read all here, if HTTP vulnerability is confirmed to be used, but it would be great to h...
by Kindis
Mon Mar 26, 2018 10:15 am
Forum: General
Topic: RouterOS making unaccounted outbound winbox connections [SOLVED]
Replies: 63
Views: 18499

Re: RouterOS making unaccounted outbound winbox connections [SOLVED]

Would it be possible for MT staff to create a pinned thread about this. With info about what attack vector was used, from what version of ROS are you safe and how to mitigate if you are effected. I know you can read all here, if HTTP vulnerability is confirmed to be used, but it would be great to ha...
by Kindis
Sun Mar 18, 2018 12:59 am
Forum: Wireless Networking
Topic: 5GHz Wi-Fi problem on hAP ac lite [SOLVED]
Replies: 10
Views: 1935

Re: 5GHz Wi-Fi problem on hAP ac lite [SOLVED]

Had simular issues with my wAP AC but noticed in the log after a while that it said radar detect and tried another channel and then loop. Added a channel that does not require radar scan here. This made 5 Ghz stabil for me.