Community discussions

MUM Europe 2020

Search found 41 matches

by normalcy
Wed Oct 18, 2017 3:55 am
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 27547

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

I've just seen 6.39.3 come into the bugfix train.

Can anyone confirm it includes the fix? Unless I'm blind I didn't see it mentioned in the system -> packages brief release notes.

Out of the office for another week before I can try it on a cloud core.
by normalcy
Fri Jun 23, 2017 4:44 am
Forum: Announcements
Topic: v6.38.7 [bugfix] is released!
Replies: 26
Views: 18524

Re: v6.38.7 [bugfix] is released!

Thanks for this release, but can you add in current bugfix also this -
!) tile - fixed IPSec hardware acceleration out-of-order packet problem, significantly improved performance;
?
I too cannot wait to see this make it to bugfix level of stability.
by normalcy
Sat Apr 01, 2017 12:48 pm
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 27547

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

Thanks for the feedback nathan1 and alexjhart (and for you persistence chasing this!!). My testing CCR1016 has been borrowed by a colleague but I look forward to trying this out on it when I get it back. We have multiple CCR1036 acting as VPN concentrators (never got the chance to swap them out afte...
by normalcy
Wed Mar 22, 2017 4:05 am
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 27547

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

Has anyone tried GRE over IPSec transport? Or SMB traffic on windows clients? That's been what we have had issues with.

Looking forward to this fix filtering down - I'll be sorely tempted to use current rather than waiting for bugfix....
by normalcy
Thu Sep 03, 2015 12:49 am
Forum: Announcements
Topic: v6.32 released [version temporarily removed]
Replies: 116
Views: 30890

v6.32 released [version temporarily removed]

I get the issue that bugfix is not necessarily clear that it means stable. But 'current' is fine for me for the feature branches as this is similar to the FreeBSD release engineering process. There 'current' is the moving target, but they do call their bugfix 'stable' instead. Ultimately it's all se...
by normalcy
Sun Aug 16, 2015 2:35 pm
Forum: General
Topic: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box
Replies: 32
Views: 2240

Re: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box

This might also be a bit of a long shot, but what happens to the speed test if you change the interface queue type of the ethernet ports?
queue interface set [find default-queue="only-hardware-queue"] queue=ethernet-default
by normalcy
Sun Aug 16, 2015 11:41 am
Forum: General
Topic: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box
Replies: 32
Views: 2240

Re: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box

What do you have for:
[admin@MikroTik] > ip firewall connection tracking print
and:
[admin@MikroTik] > ip settings print
Assuming these will be factory default settings.
by normalcy
Sun Aug 16, 2015 9:49 am
Forum: General
Topic: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box
Replies: 32
Views: 2240

Re: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box

There's apparently a lot of things that can cause them as mentioned in that linked article, with the recommendation being that you capture close to the sender. However if you've now used two different mikrotik devices and get the same behaviour that would tend to suggest it's something with them. ma...
by normalcy
Sun Aug 16, 2015 5:58 am
Forum: General
Topic: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box
Replies: 32
Views: 2240

Re: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box

Ok got the second file. Are you performing one or two speed tests during these two captures? Only a couple of things jump out at me on first look. On the failing capture you're getting a lot of 'TCP Spurious Retransmissions' followed by DUP ACKs that could be a symptom or a contributor to the slowdo...
by normalcy
Sat Aug 15, 2015 1:08 pm
Forum: General
Topic: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box
Replies: 32
Views: 2240

Re: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box

Can you re-upload the second link? i think it's expired on me.
by normalcy
Sat Aug 15, 2015 10:09 am
Forum: General
Topic: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box
Replies: 32
Views: 2240

Mikrotik ROS 6.30 - Foxtel IQHD cable settop box

Hi. Back from a break. If your links are still good I'll have a look tomorrow. Hopefully we can find something!
by normalcy
Sat Aug 01, 2015 5:59 am
Forum: General
Topic: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box
Replies: 32
Views: 2240

Mikrotik ROS 6.30 - Foxtel IQHD cable settop box

Oh and no you should only need the one CRS and yes you would only want a minimal config (enough to get management access via winbox - lots of wiki/forum threads about that)
by normalcy
Sat Aug 01, 2015 5:57 am
Forum: General
Topic: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box
Replies: 32
Views: 2240

Mikrotik ROS 6.30 - Foxtel IQHD cable settop box

Sorry I'm going away on holiday so won't be here for a while. But basically you want to setup a switch group on the CRS for a few ports between your cable modem and the various downstream routers (maybe another one to plug the Foxtel box in and look at that traffic). Then setup mirroring to send tha...
by normalcy
Fri Jul 31, 2015 2:58 pm
Forum: General
Topic: VRRP and Carp in same network strange behavior.
Replies: 1
Views: 716

VRRP and Carp in same network strange behavior.

I found this old thread via Google. https://groups.google.com/forum/m/#!topic/bit.listserv.openbsd-pf/13gdbhskgE8 Looks like they also had both protocols working on the same segment but one of their vendors gear was also flooded with logs. Although it can work I guess they just don't like having the...
by normalcy
Fri Jul 31, 2015 2:51 pm
Forum: Beginner Basics
Topic: BASIC ROUTER CONFIGURATION
Replies: 2
Views: 577

BASIC ROUTER CONFIGURATION

http://wiki.mikrotik.com/wiki/Manual:Quickset I know it's still the GUI but maybe quickset would get you going. You could then use the cli export command to see the sort of changes it made to the default config. Winbox is overwhelming at the beginning but once you get used to it the ability to have ...
by normalcy
Thu Jul 30, 2015 1:59 pm
Forum: General
Topic: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box
Replies: 32
Views: 2240

Mikrotik ROS 6.30 - Foxtel IQHD cable settop box

You'd be looking for differences in the packets that could be nailed down to the different setups. Eg qos values, MSS, packet size etc. maybe even do the same with that netgear router that worked to see what it might be doing that the 951 isn't. Otherwise I suppose we would just be running through a...
by normalcy
Thu Jul 30, 2015 1:55 pm
Forum: General
Topic: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box
Replies: 32
Views: 2240

Mikrotik ROS 6.30 - Foxtel IQHD cable settop box

I guess the next thing I'd try in this situation is put a managed switch in between the modem and the routers and mirror the traffic to wireshark to look for any differences when it's working vs when it's not. Don't know if your comfortable at that low a level. Eg: cable modem -> mirroring switch ->...
by normalcy
Thu Jul 30, 2015 1:08 am
Forum: General
Topic: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box
Replies: 32
Views: 2240

Mikrotik ROS 6.30 - Foxtel IQHD cable settop box

Did some googling and I'm guessing this is your issue http://forums.whirlpool.net.au/archive/2421925

If so you've already tried a fair bit there. It's a weird issue.
by normalcy
Thu Jul 30, 2015 12:42 am
Forum: General
Topic: Mikrotik ROS 6.30 - Foxtel IQHD cable settop box
Replies: 32
Views: 2240

Mikrotik ROS 6.30 - Foxtel IQHD cable settop box

If you do a regular speed test on a laptop is there also a similar slowdown? Or is it only the Foxtel box? When the cable modem is plugged into the mik is it put in bridge mode or are you double NAT'ing. Nothing really jumped out at me in your config. I guess you've tried with and without the simple...
by normalcy
Sun Jul 26, 2015 3:30 am
Forum: General
Topic: Can anyone point me to how to setup a direct IPSEC tunnel?
Replies: 5
Views: 1043

Can anyone point me to how to setup a direct IPSEC tunnel?

My thought would be configuration (not that there haven't been bugs but basic IPSec is pretty stable in my experience). If you use plain IPSec in tunnel mode you need to ensure that your IPSec policies capture the right traffic (from your local to remote subnet) and your 'NAT bypass' rules are above...
by normalcy
Fri Jul 24, 2015 10:16 am
Forum: General
Topic: ONVIF Camera behind MKT, Can't make the NAT work...
Replies: 6
Views: 2325

ONVIF Camera behind MKT, Can't make the NAT work...

Depends a lot on the ip camera brand you use. eg: cheap dahua cameras generally offer port 80 for the web and port 37777 for streaming video over either udp/tcp, you need both. I think a lot of onvif cameras use udp port 514 for transporting the video stream in addition to the web interface on 80 so...
by normalcy
Fri Jul 24, 2015 10:08 am
Forum: General
Topic: ether1 high download rate
Replies: 2
Views: 350

ether1 high download rate

You could also run the torch command on that interface to see the IPs and rates hitting the interface.
by normalcy
Fri Jul 24, 2015 10:06 am
Forum: General
Topic: Can anyone point me to how to setup a direct IPSEC tunnel?
Replies: 5
Views: 1043

Can anyone point me to how to setup a direct IPSEC tunnel?

Some do. Search for virtual tunnel interface (VTI). It's a heavily requested feature for mikrotik. For the moment though it's not supported unless you use another tunnel (GRE/IPIP/EOIP/L2TP) as feklar mentioned.
by normalcy
Fri Jul 24, 2015 9:40 am
Forum: Beginner Basics
Topic: RDP
Replies: 25
Views: 4230

RDP

Do you get no connection occurring at all or a black screen? I had to clear the df bit in a mangle rule to get RDP working across a remote VPN subnet. If I didn't I could ping and portscan but connecting just gave me a black screen. Sounds like you're not quite getting that far though?
by normalcy
Thu Jul 23, 2015 1:01 pm
Forum: General
Topic: Set Admin Password via Config File (Flashfig)
Replies: 8
Views: 1493

Set Admin Password via Config File (Flashfig)

Out of interest how did you generate all the individual script files?

I'm facing something similar with a lot of haps as well. Looking into milliscript and flashfig and all the rest but I can see that you will still need create a per device script to load (for identity etc).
by normalcy
Sun Jul 12, 2015 6:13 am
Forum: General
Topic: Crooks Use Hacked Routers to Aid Cyberheists
Replies: 5
Views: 3463

Crooks Use Hacked Routers to Aid Cyberheists

I know quickset will generally put a deny all filter rule on the wan input if used. But could you also put a security checklist or section for securing router access in quickset too? Something that might let you specify an admin ip/subnet and then automatically populate firewall rules on all input i...
by normalcy
Wed Jun 10, 2015 12:44 pm
Forum: Wireless Networking
Topic: Zero-handoff using CAPsMAN doesn't work
Replies: 10
Views: 6505

Zero-handoff using CAPsMAN doesn't work

Wouldn't mind seeing both ubiquiti and mikrotik support 802.11r in future products as a more standards based method of fast roaming. Although it needs client support as well.
by normalcy
Sun Jun 07, 2015 1:25 am
Forum: Forwarding Protocols
Topic: Encrypt 10Gb/s Links
Replies: 5
Views: 1948

Encrypt 10Gb/s Links

Sounds like you might need something like this.

http://www.senetas.com/encryptors/layer-2-encryptors/

They look reassuringly expensive!
by normalcy
Wed Dec 31, 2014 1:27 am
Forum: General
Topic: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch
Replies: 34
Views: 12562

Re: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch

Yes in fact I created a step by step guide for this specific hardware pairing..... email me at mike(at)43index.com and I will forward you the Word document. I had no problems getting it setup and working just as you are describing. You don't need to tag the VLAN on the Mikrotik end, only on the Edg...
by normalcy
Thu Oct 09, 2014 2:30 pm
Forum: General
Topic: MUM 2014 US Videos and slides
Replies: 5
Views: 1107

Re: MUM 2014 US Videos and slides

Will more of the slides be added to the wiki soon?
by normalcy
Tue Jul 15, 2014 4:56 pm
Forum: General
Topic: CoDel support?
Replies: 45
Views: 13749

Re: CoDel support?

I'd love to see codel in there too but they may prefer Cisco's PIE instead which is also in the newest kernels.
by normalcy
Tue Jun 10, 2014 6:29 am
Forum: General
Topic: Partitioning a CCR
Replies: 19
Views: 3477

Re: Partitioning a CCR

I'd like to try this feature, but I'm having issues on a CCR1036-12G-4S. I've created 3 partitions, but if I "copy-to" from winbox or the console when I reboot after activating one of the two newly created partitions they fail with the message: kernel not found or data corrupted" and then fall back...
by normalcy
Thu Jun 05, 2014 9:41 am
Forum: General
Topic: Partitioning a CCR
Replies: 19
Views: 3477

Re: Partitioning a CCR

I'd like to try this feature, but I'm having issues on a CCR1036-12G-4S. I've created 3 partitions, but if I "copy-to" from winbox or the console when I reboot after activating one of the two newly created partitions they fail with the message: kernel not found or data corrupted" and then fall back ...
by normalcy
Sat Apr 12, 2014 10:46 am
Forum: General
Topic: New Packet flow diagram
Replies: 103
Views: 73171

Re: New Packet flow diagram

This is fantastic. Thanks for the effort as I think this layout helps you connect the layers together better than the original separated diagrams. Hopefully it becomes the official one.
by normalcy
Mon Jan 20, 2014 3:14 am
Forum: General
Topic: Central Deployment using Infrastructure-as-a-Code?
Replies: 11
Views: 6073

Re: Central Deployment using Infrastructure-as-a-Code?

I'm no programmer myself, but maybe looking at the python code for some of the existing firewalld and google compute engine networking modules might be a starting point for anyone with the skills to pick this up?
by normalcy
Mon Jan 20, 2014 12:47 am
Forum: General
Topic: Central Deployment using Infrastructure-as-a-Code?
Replies: 11
Views: 6073

Re: Central Deployment using Infrastructure-as-a-Code?

I would love to see something like this as well, but I haven't found anything either. I would imagine you could still use a playbook to make raw routeros calls via ssh, similar to what this guy does with iptables . Otherwise, someone would probably have to write a python based ansible module to call...
by normalcy
Thu Jul 11, 2013 11:17 pm
Forum: General
Topic: CoDel support?
Replies: 45
Views: 13749

Re: CoDel support?

Eagerly awaiting some indication that mikrotik will add fq_codel support as another AQM algorithm as it is in the Linux kernel and seems to be a great cpe solution (no manual tuning and fast response for variable wifi links). http://www.bufferbloat.net/projects/cerowrt/wiki/Bloat-videos http://getty...
by normalcy
Sun Nov 18, 2012 10:23 am
Forum: RouterBOARD hardware
Topic: RB493G USB
Replies: 9
Views: 2084

RB493G USB

We had a 493g and a powered USB hub and it still wasn't enough to get the 3G modem recognised. Had to follow the mod suggested in this thread. Has been working fine since.

http://forum.mikrotik.com/viewtopic.php ... 64#p259164
by normalcy
Mon Aug 13, 2012 2:52 pm
Forum: General
Topic: DHCP relay not forwarding requests
Replies: 11
Views: 8847

Re: DHCP relay not forwarding requests

Self inflicted.

Adding a firewall rule to the input chain to allow UDP 67 to router addresses must allow the relay helper to send the dhcp offer back to the clients. Was getting blocked by a drop all filter on the input chain.
by normalcy
Mon Aug 13, 2012 11:03 am
Forum: General
Topic: DHCP relay not forwarding requests
Replies: 11
Views: 8847

Re: DHCP relay not forwarding requests

Did you get a response from mikrotik support on this? I've upgraded a RB1200 to 5.19 and I'm seeing similar behavior as well. Running a dhcp-relay on address 192.168.4.1 vlan4 pointed at a dhcp server at 192.168.0.16. My ISC dhcpd is receiving the discover requests and sending out offers, however th...
by normalcy
Tue Jul 24, 2012 2:48 pm
Forum: General
Topic: IPSec VPN Set-up between Dual WAN & Single WAN for Fail-Over
Replies: 17
Views: 19413

Re: IPSec VPN Set-up between Dual WAN & Single WAN for Fail-

Hi staticjess, I'm a brand new user to mikrotik and just getting started with their equipment, but I plan to create a setup almost exactly the same as yours with the difference that I'll have a 3G USB backup connection at the branch offices on dynamic IPs as well just to make the IPSec failover more...