Community discussions

MikroTik App

Search found 420 matches

  • 1
  • 2
by mikruser
Tue May 19, 2020 5:23 pm
Forum: General
Topic: Why hashing done in software?
Replies: 0
Views: 249

Why hashing done in software?

Hello,

https://wiki.mikrotik.com/wiki/Manual:I ... celeration
x86 (AES-NI) ***
*** AES-CBC and AES-CTR only encryption is accelerated, hashing done in software.


Why hashing is not hardware accelerated?
AMD CPU support SHA extensions: https://en.wikipedia.org/wiki/Intel_SHA_extensions
by mikruser
Thu May 07, 2020 1:11 am
Forum: General
Topic: High CPU usage
Replies: 6
Views: 1112

Re: High CPU usage

I know what's loading the CPU.
My question is, why so much?
One EPYC Rome core can do 1.7 GBytes/s AES encryption.
Two cores can 2*1.7*8=27 Gbits/s
My traffic is very small, only 0.5 Gbit/s
CPU load caused by encryption should be lower than 2%
by mikruser
Wed May 06, 2020 4:59 pm
Forum: General
Topic: High CPU usage
Replies: 6
Views: 1112

High CPU usage

Hello,

I have ESXi 6.7U3 host with AMD EPYC 7502P processor, and VM (2 vCPU) with CHR 6.45.8
On CHR created vpn-tunnel GRE+IPsec (aes-128 ctr sha1)

When i do vMotion via this tunnel at speed 500 Mbit/s, this cause VM CPU usage 45%

Why CPU usage so high?
by mikruser
Thu Apr 23, 2020 2:06 am
Forum: General
Topic: FEATURE REQUEST: Dynamically created VPN+routes (each to each)
Replies: 1
Views: 739

FEATURE REQUEST: Dynamically created VPN+routes (each to each)

For example - you have multiple offices: HQ-office and branch-offices, each office have piblic IP and private subnet. Very simple solution: HQ-office Mikrotik (master) and branch-offices Mikrotik (slave) have this table: public_ip, private_subnet 1.1.1.1, 192.168.1.0/24 2.2.2.2, 192.168.2.0/24 ........
by mikruser
Thu Feb 13, 2020 7:31 pm
Forum: General
Topic: Suggestion: view packets on Rule
Replies: 0
Views: 1441

Suggestion: view packets on Rule

Hello,

Please add button "View packets" (like Torch or Sniffer) on Rule Statistics tab!
by mikruser
Fri Jan 31, 2020 6:17 pm
Forum: General
Topic: How to disable promiscuous mode?
Replies: 2
Views: 733

How to disable promiscuous mode?

Hello,
How to disable promiscuous mode on ether1?
by mikruser
Wed Jan 29, 2020 12:57 pm
Forum: Announcements
Topic: v6.45.8 [long-term] is released!
Replies: 87
Views: 60475

Re: v6.45.8 [long-term] is released!

there are no other versions between them
Image_.png
by mikruser
Wed Jan 29, 2020 11:48 am
Forum: Announcements
Topic: v6.45.8 [long-term] is released!
Replies: 87
Views: 60475

Re: v6.45.8 [long-term] is released!

>>Changes since 6.45.7
previous version was 6.44.6
by mikruser
Tue Jan 28, 2020 5:53 pm
Forum: General
Topic: NetFlow. No longer showing NAT'd destination address - Something chnaged
Replies: 25
Views: 4072

Re: NetFlow. No longer showing NAT'd destination address - Something chnaged

I have same issue as described in mdpeterman first post.
NetFlow Analyzer -> Inventory -> Devices-> SomeRouter -> InternalInterface -> Destination (OUT)
shows me external public IP instead of internal private ip-addresses
by mikruser
Tue Jan 28, 2020 5:37 pm
Forum: General
Topic: NetFlow. No longer showing NAT'd destination address - Something chnaged
Replies: 25
Views: 4072

Re: NetFlow. No longer showing NAT'd destination address - Something chnaged

maybe you do not understand my message?

I also have this issue
by mikruser
Tue Jan 28, 2020 12:11 pm
Forum: General
Topic: NetFlow. No longer showing NAT'd destination address - Something chnaged
Replies: 25
Views: 4072

Re: NetFlow. No longer showing NAT'd destination address - Something chnaged

all of these items are already selected by default
by mikruser
Mon Jan 27, 2020 1:54 pm
Forum: General
Topic: NetFlow. No longer showing NAT'd destination address - Something chnaged
Replies: 25
Views: 4072

Re: NetFlow. No longer showing NAT'd destination address - Something chnaged

Also have this issue!

6.44.6, Traffic Flow Version: 9

How to fix it?
by mikruser
Tue Jan 21, 2020 4:28 pm
Forum: General
Topic: GRE issues with dual WAN
Replies: 4
Views: 562

Re: GRE issues with dual WAN

why did the router send packets from the wrong interface

I do not see your config.
maybe you do not have the necessary mangle output rules,or maybe you do not have the necessary route rules...
by mikruser
Mon Jan 20, 2020 8:04 pm
Forum: General
Topic: GRE issues with dual WAN
Replies: 4
Views: 562

Re: GRE issues with dual WAN

You should exclude PublicIP-to-PublicIP connections from NAT'ing
by mikruser
Wed Jan 15, 2020 12:31 pm
Forum: General
Topic: TCP congestion Illinos
Replies: 5
Views: 991

Re: TCP congestion Illinos

havrla
illinos is very super for fast and long lines. (VDSL, WIFI, )

"Westwood" is much better:
aed1d4d480366a904cf94a6f3977b383.png
by mikruser
Sun Jan 12, 2020 10:52 pm
Forum: Forwarding Protocols
Topic: TCP port forward doesnt work
Replies: 15
Views: 2772

Re: TCP port forward doesnt work

don't listen to noobs, you no need add public ip to nat rule.

you need add firewall rule:
accept
forward
dst.address=your internal ip
protocol=tcp
dst.port=your internal port
by mikruser
Sun Jan 12, 2020 6:11 pm
Forum: General
Topic: Why MT Wiki contains incomplete information?
Replies: 2
Views: 493

Why MT Wiki contains incomplete information?

for example https://wiki.mikrotik.com/wiki/Manual:IP/Route
do not have information about "Rules" tab settings.
by mikruser
Fri Jan 10, 2020 6:27 pm
Forum: General
Topic: Why gre+ipsec tunnel always use default proposal?
Replies: 3
Views: 457

Re: Why gre+ipsec tunnel always use default proposal?

Because it doesn't work as you think. Proposal is linked to policy and policy is linked to peer. Not the other way around. So what you created just sits there and does nothing, because automatically created peer won't use it. You are wrong. Dynamic policies are generated from a template policy: htt...
by mikruser
Fri Jan 10, 2020 5:49 pm
Forum: General
Topic: Why gre+ipsec tunnel always use default proposal?
Replies: 3
Views: 457

Why gre+ipsec tunnel always use default proposal?

Hello,

I have multiple gre-tunnels with ipsec secret enabled. In gre-tunnel i cannot select custom ipsec proposal.
I created custom IPsec Policy Template (priority#0) for Protocol:47 and custom proposal, but my gre-tunnels still use default proposal.

Why?
by mikruser
Thu Jan 09, 2020 1:33 pm
Forum: General
Topic: ipsec established, but gre tunnel not
Replies: 6
Views: 869

Re: ipsec established, but gre tunnel not

yeahbunin
read my previous message
by mikruser
Thu Jan 02, 2020 8:12 pm
Forum: General
Topic: Port Forwarding doesn't forward
Replies: 4
Views: 452

Re: Port Forwarding doesn't forward

>>add action=accept chain=forward dst-port=65022 protocol=tcp

you need change port to 22
by mikruser
Thu Jan 02, 2020 4:10 pm
Forum: General
Topic: ipsec established, but gre tunnel not
Replies: 6
Views: 869

Re: ipsec established, but gre tunnel not

>>Have you specified local and remote addresses of GRE on both routers?
Yes

>>Do you allow proper protocols to pass firewall?
Yes, full access for these addresses (without "IPsec Secret" gre-tunnel link up successfully).

I think this is a bug in ROS...
by mikruser
Thu Jan 02, 2020 9:09 am
Forum: General
Topic: ipsec established, but gre tunnel not
Replies: 6
Views: 869

ipsec established, but gre tunnel not

Hello, I created GRE tunnel (with IPsec Sercret) between CCR and CHR. (6.44.6) 1) policy created dynamically successfully (ph2 state established) 2) peer created dynamically successfully 3) identities created dynamically successfully 4) remote peers and installed sa created dynamically successfully ...
by mikruser
Thu Dec 26, 2019 6:45 pm
Forum: General
Topic: How to see %lost datagrams of VPN tunnel?
Replies: 0
Views: 609

How to see %lost datagrams of VPN tunnel?

Hello,
Is it possible to see in Winbox %lost datagrams related to outer (connectionless/stateless) protocol of VPN tunnel?
by mikruser
Thu Dec 12, 2019 1:08 pm
Forum: General
Topic: How does AutoMTU work for VPN tunnels?
Replies: 0
Views: 565

How does AutoMTU work for VPN tunnels?

Hello,

How does AutoMTU (Actual MTU) work for VPN tunnels?

For example: i have gre+ipsec tunnels sha1/aes-128 ctr

CCR1009(AMTU1446)----(AMTU1434)RB3011

CCR1009(AMTU1446)----(AMTU1434)hAPac2

Why MTU is different on both sides?
by mikruser
Wed Dec 04, 2019 4:23 pm
Forum: RouterBOARD hardware
Topic: MikroTik MQS
Replies: 34
Views: 8470

Re: MikroTik MQS

Where can I download admin guide with a detailed description of all settings?
by mikruser
Mon Dec 02, 2019 4:37 pm
Forum: General
Topic: How to set priorities for the encryption algorithms in the default IPsec proposal?
Replies: 0
Views: 460

How to set priorities for the encryption algorithms in the default IPsec proposal?

Hello,

How to set priorities for the encryption algorithms in the default IPsec proposal?

I have "aes-128 cbc" and "aes-128 ctr" selected, and need now set priority1 to ctr, and priority2 to cbc.
by mikruser
Thu Nov 28, 2019 2:09 pm
Forum: General
Topic: How to select interface in Bandwidth Test tool?
Replies: 1
Views: 369

How to select interface in Bandwidth Test tool?

Hello,
I have router with 3 WAN interfaces.
How to select interface in Bandwidth Test tool? (like in Traceroute tool)
Image_mikr_bt.png
by mikruser
Wed Nov 27, 2019 5:41 pm
Forum: RouterBOARD hardware
Topic: can't login to MQS [SOLVED]
Replies: 3
Views: 3659

Re: can't login to MQS [SOLVED]

Ok, it works...

but this is a very inconvenient setup method.

please add ability to configure through USB!
by mikruser
Wed Nov 27, 2019 5:30 pm
Forum: RouterBOARD hardware
Topic: can't login to MQS [SOLVED]
Replies: 3
Views: 3659

can't login to MQS [SOLVED]

I'm trying login to MQS as described in https://i.mt.lv/cdn/rb_files/1572339613 ... %20web.pdf
but no success
I can connect to wireless network RBMQS_AP1, but computer can't get ip address.
I'm trying reset MQS, but no success.
by mikruser
Sat Nov 23, 2019 5:43 pm
Forum: General
Topic: Block a huge list of IP-addresses [SOLVED]
Replies: 17
Views: 1840

Re: Block a huge list of IP-addresses [SOLVED]

use blackhole route
by mikruser
Fri Nov 22, 2019 5:33 pm
Forum: General
Topic: Feature request: Virtual Interface
Replies: 36
Views: 6358

Re: Feature request: Virtual Interface

Any news about implementing this feature (VI)?

ISP gave me an additional IP-address on a different subnet.
Now i need create additional (virtual) interface on ether1. MAC address must be different.
by mikruser
Fri Nov 01, 2019 3:10 pm
Forum: General
Topic: Suggestion: VPN over ICMP
Replies: 3
Views: 1068

Re: Suggestion: VPN over ICMP

Absolutely incorrect.
Normal providers do not touch transit icmp traffic.
by mikruser
Fri Oct 25, 2019 5:36 pm
Forum: General
Topic: What type of tunnel should be used in this case?
Replies: 1
Views: 468

What type of tunnel should be used in this case?

Hello, What type of vpn tunnel should be used in this case: 1) server and clients are Mikrotik routers. 2) server have public ip address. 3) all clients have private ip addresses (behind nat). 4) some clients behind same nat (l2tp+ipsec do not work in this case). 5) MPPE encryption or certificates s...
by mikruser
Fri Oct 25, 2019 2:17 pm
Forum: General
Topic: Bug
Replies: 5
Views: 617

Re: Bug

mikrotik's "stable" = beta version in real life
by mikruser
Fri Oct 25, 2019 12:25 pm
Forum: General
Topic: Bug
Replies: 5
Views: 617

Re: Bug

6.44.5
by mikruser
Thu Oct 24, 2019 7:48 pm
Forum: General
Topic: Bug
Replies: 5
Views: 617

Bug

Interface lte1 - General - APN Profile:
this setting is not remembered between reboots
by mikruser
Tue Oct 15, 2019 1:18 pm
Forum: RouterBOARD hardware
Topic: New High Performance Routers ! ?
Replies: 48
Views: 10369

Re: New High Performance Routers ! ?

doneware NAT - is not really a CPU intensive process but in real life author writes something else: doush Router only does NAT and nothing else. CCR1072 CPU consumption is %50 with 18gbit/s total throuput + firewall + NAT plus some cores hitting %80. doneware using a dedicated CPU instruction set (...
by mikruser
Sat Oct 12, 2019 8:58 pm
Forum: RouterBOARD hardware
Topic: New High Performance Routers ! ?
Replies: 48
Views: 10369

Re: New High Performance Routers ! ?

I am very surprised that Mikrotik does not use hardware NAT'ing.
by mikruser
Wed Aug 28, 2019 12:07 am
Forum: General
Topic: Suggestion: VPN over ICMP
Replies: 3
Views: 1068

Suggestion: VPN over ICMP

Hello,
Please implement VPN over ICMP (ICMP Tunnel)
(it can be very useful in some countries with a totalitarian regime)))
by mikruser
Sun Aug 04, 2019 7:41 pm
Forum: RouterBOARD hardware
Topic: GPeR question
Replies: 21
Views: 6300

Re: GPeR question

normis
Tue Jul 30, 2019 9:57 am
The GPER is a passive device that connects wires together, you can call it Layer1. This is not really a hub.

normis
Fri Aug 02, 2019 3:14 pm
Yes, there is a basic switch chip inside.


Two completely different answers.
You are Dr Jekyll and Mr Hyde??
by mikruser
Thu Aug 01, 2019 12:39 pm
Forum: RouterBOARD hardware
Topic: GPeR question
Replies: 21
Views: 6300

Re: GPeR question

If GPER is just a passive device that connects wires together, then the price is perplexing (50% of Raspberry Pi 4 computer)
by mikruser
Mon Jul 29, 2019 10:31 pm
Forum: RouterBOARD hardware
Topic: GPeR question
Replies: 21
Views: 6300

Re: GPeR question

1) Of course it matters (and two port has nothing to do with it)
2) ???
3) Ok
by mikruser
Mon Jul 29, 2019 12:20 pm
Forum: RouterBOARD hardware
Topic: GPeR question
Replies: 21
Views: 6300

GPeR question

Hello,
1) at what OSI layer this device work? at L1 like hub, or at L2 like switch?
2) what delay does this device add?
3) why distance is limited to 1500 m?
by mikruser
Tue Jun 11, 2019 1:03 pm
Forum: General
Topic: SNMP traffic monitoring bug
Replies: 2
Views: 455

SNMP traffic monitoring bug

Hello,

CHR 6.44.2
PRTG Network Monitor SNMP Traffic sensor

When i copy file via gigabit adapter, SNMP sensor show only 430 Mbit/s

This is a bug in Mikrotik SNMP or in PRTG?
Image1_snmp_.png
by mikruser
Tue Apr 23, 2019 1:38 pm
Forum: General
Topic: Suggestion: Protocols for Bandwidth Test
Replies: 0
Views: 480

Suggestion: Protocols for Bandwidth Test

Hello,

please add not only udp and tcp, but also protocols 4, 47, 50.
by mikruser
Fri Mar 22, 2019 12:08 pm
Forum: General
Topic: GRE over IPSEC, CCR, VERY SLOW
Replies: 39
Views: 17059

Re: GRE over IPSEC, CCR, VERY SLOW

GRE+IPsec still slow:
viewtopic.php?f=2&t=146665
by mikruser
Mon Mar 18, 2019 6:49 pm
Forum: General
Topic: Slow speed through gre+ipsec tunnel
Replies: 10
Views: 2797

Slow speed through gre+ipsec tunnel

Hello, CHR, 6.44.1, 2 vcpu Xeon Gold CCR1009, 6.44.1 WAN with 45 ms latency [CHR]---wan(tunnel gre+ipsec)wan---[CCR1009] aes128cbc/sha1, Actual MTU = 1426 (Auto) OR aes128ctr/sha1, Actual MTU = 1446 (Auto) Bandwidth Test on CHR to CCR (tcp, receive, 1 connection): between public ip = up to 300 Mbps ...
by mikruser
Mon Mar 18, 2019 5:53 pm
Forum: General
Topic: Please add the ability to choose Proposal
Replies: 11
Views: 2041

Re: Please add the ability to choose Proposal

All my tunnels are configured with IPsec Secret enabled, and I will not change it.

We simply need the ability to choose Proposal for each tunnel.
by mikruser
Mon Mar 18, 2019 4:45 pm
Forum: General
Topic: Please add the ability to choose Proposal
Replies: 11
Views: 2041

Re: Please add the ability to choose Proposal

I still do not see any real benefit of your request. It literally takes 2 seconds to change proposal value for your policies to a different one. /ip ipsec proposal add name=newproposal copy-from=default /ip ipsec policy set [find proposal=default] proposal=newproposal I was just posting this exact ...
by mikruser
Thu Mar 07, 2019 12:19 pm
Forum: General
Topic: Why AES CTR is not hardware accelerated on the CHR?
Replies: 1
Views: 328

Why AES CTR is not hardware accelerated on the CHR?

Hello,

Why AES CTR is not hardware accelerated on the CHR?
Image_chr_.png
by mikruser
Mon Mar 04, 2019 11:58 am
Forum: General
Topic: Does the System\Watchdog on the CHR make sense?
Replies: 0
Views: 323

Does the System\Watchdog on the CHR make sense?

Hello,

Does the System\Watchdog on the CHR make sense?
Can he restart the VM if CHR hangs?
by mikruser
Thu Feb 21, 2019 11:49 am
Forum: General
Topic: vlan question
Replies: 6
Views: 841

Re: vlan question

but I don't want to create additional vlan interfaces
by mikruser
Thu Feb 21, 2019 11:25 am
Forum: General
Topic: vlan question
Replies: 6
Views: 841

Re: vlan question

I can not merge bridges, because bridges have different ip-addresses and dhcp-servers on them.
by mikruser
Wed Feb 13, 2019 6:23 pm
Forum: General
Topic: vlan question
Replies: 6
Views: 841

vlan question

Hello, We have routerboard with ether2 and ether3 - in bridge1 ether4 and ether5 - in bridge2 now we need special port ether6 which should be a member of both bridges, but in bridge1 as untagged default vlan (vlan1), and in bridge2 as tagged vlan2. This is can be done very simply on a managed switch...
by mikruser
Fri Feb 08, 2019 5:01 pm
Forum: General
Topic: Why Fast Path not supported with hardware accelerated IPsec?
Replies: 1
Views: 544

Why Fast Path not supported with hardware accelerated IPsec?

Hello,

Why Fast Path not supported with hardware accelerated IPsec?
by mikruser
Mon Jan 21, 2019 11:12 am
Forum: General
Topic: restore to different hardware
Replies: 5
Views: 776

Re: restore to different hardware

I see a very large number of messages
expected end of command

looking at all, export/import procedure is very bugged on Mikrotik
by mikruser
Mon Jan 21, 2019 10:42 am
Forum: General
Topic: restore to different hardware
Replies: 5
Views: 776

Re: restore to different hardware

but cli command /import do not work:

expected end of command (line 24 column 26)
by mikruser
Fri Jan 18, 2019 6:28 pm
Forum: General
Topic: restore to different hardware
Replies: 5
Views: 776

restore to different hardware

How to copy configuration from router1 to router2 (different hardware)?
I see this post: viewtopic.php?t=115073
My question: how to export and import via Winbox GUI? (not via terminal cli!)
by mikruser
Tue Jan 15, 2019 11:35 am
Forum: General
Topic: Suggestion: drag and drop rules between routers
Replies: 1
Views: 578

Suggestion: drag and drop rules between routers

Hello,

please add the ability to drag and drop (copy) rules (and other stuff) from one Winbox window to another Winbox window.
by mikruser
Thu Dec 27, 2018 11:41 am
Forum: General
Topic: Cannot connect to L2TP server from Windows 7: no suitable proposal found [SOLVED]
Replies: 3
Views: 1643

Re: Cannot connect to L2TP server from Windows 7: no suitable proposal found [SOLVED]

in case there is NAT between server and client: google "AssumeUDPEncapsulationContextOnSendRule"
Thanks, it helped!
by mikruser
Thu Dec 27, 2018 10:50 am
Forum: General
Topic: Cannot connect to L2TP server from Windows 7: no suitable proposal found [SOLVED]
Replies: 3
Views: 1643

Cannot connect to L2TP server from Windows 7: no suitable proposal found [SOLVED]

Hello, CCR1009, 6.43.8 cannot connect to L2TP server from Windows 7 and Windows 2008 R2. ipsec, error no suitable proposal found. ipsec, error x.x.x.x failed to get valid proposal. ipsec, error x.x.x.x failed to pre-process ph1 packet (side: 1, status 1). ipsec, error x.x.x.x phase1 negotiation fail...
by mikruser
Tue Dec 25, 2018 12:51 pm
Forum: General
Topic: Question about IKE2
Replies: 0
Views: 337

Question about IKE2

What types of authentication does Mikrotik router support with Windows client?
Only "Use machine certificates"? Or also "Use EAP"?
by mikruser
Mon Dec 17, 2018 10:22 am
Forum: General
Topic: Ipsec peers
Replies: 0
Views: 355

Ipsec peers

Hello, I already have several ipsec peers with unique ip addresses (it is used for l2tp/ipsec site-to-site vpn's). Now I need to make a IKEv2 server for incoming connections from remote notebooks. For this i need to create ipsec peer with address 0.0.0.0/0. Is it possible to use this peer with other...
by mikruser
Tue Nov 27, 2018 3:57 pm
Forum: General
Topic: Backup/restore without mac-addresses
Replies: 2
Views: 822

Re: Backup/restore without mac-addresses

My question about Backup/Restore

(Import/Export do not work on my devices)
by mikruser
Tue Nov 27, 2018 3:39 pm
Forum: General
Topic: Backup/restore without mac-addresses
Replies: 2
Views: 822

Backup/restore without mac-addresses

Hello,

How to backup config without mac-addresses?
or how to restore config without changing mac-addresses?
by mikruser
Tue Nov 27, 2018 11:51 am
Forum: General
Topic: Backup/ Restore issue and duplicating Ethernet MAC address [SOLVED]
Replies: 4
Views: 2164

Re: Backup/ Restore issue and duplicating Ethernet MAC address [SOLVED]

But why i do not see Import/Export in Winbox?
by mikruser
Fri Nov 23, 2018 6:57 pm
Forum: General
Topic: After upgrade to 6.41, Ethernet Interface Bandwidth is gone
Replies: 2
Views: 745

Re: After upgrade to 6.41, Ethernet Interface Bandwidth is gone

up!
Why is it removed from Winbox GUI???
(but it is still available from command line: /interface ethernet set ether1 bandwidth=unlimited/unlimited)
by mikruser
Wed Nov 07, 2018 12:20 pm
Forum: General
Topic: Сan't rename interface [SOLVED]
Replies: 3
Views: 634

Re: Сan't rename interface [SOLVED]

After the command /interface ethernet set ether4-local bandwidth=unlimited/unlimited
I was able to rename the interface
by mikruser
Wed Nov 07, 2018 11:57 am
Forum: General
Topic: Сan't rename interface [SOLVED]
Replies: 3
Views: 634

Re: Сan't rename interface [SOLVED]

I have this problem again after restoring the configuration
by mikruser
Wed Nov 07, 2018 11:20 am
Forum: General
Topic: Сan't rename interface [SOLVED]
Replies: 3
Views: 634

Сan't rename interface [SOLVED]

RB750Gr3
ROS 6.43.4
Winbox 3.18

restoring configuration incorrectly restored interfaces, and I need to rename them
but when I try to change the name I get an error: Couldn't change Interface - not supported on this interface (6)
Image_interface.png
by mikruser
Fri Oct 26, 2018 6:44 pm
Forum: RouterBOARD hardware
Topic: New CPU - new product RB750Gr3 - RB750G family - now mmips
Replies: 180
Views: 73020

Re: New CPU - new product RB750Gr3 - RB750G family - now mmips

When will AES-CTR be added to RB750Gr3?
by mikruser
Fri Oct 26, 2018 1:29 pm
Forum: General
Topic: Suggestion: Reconnect action
Replies: 1
Views: 765

Suggestion: Reconnect action

Hello,

Please add "Reconnect" action to Right Click (Context) menu for all interfaces in Winbox
(reconnect = disable+enable)
by mikruser
Fri Oct 19, 2018 12:45 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 6730

Re: Problem with IPsec after update to 6.42

can you explain your setup and logic behind your policy configuration here? I can not think of a single case where responder should generate a dynamic policy with dst-address=0.0.0.0/0. We have a large number of subnets, and instead of creating a separate policy for each subnet, we create one polic...
by mikruser
Thu Oct 18, 2018 7:56 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 6730

Re: Problem with IPsec after update to 6.42

This behavior can be easily reproduced in the test lab.
by mikruser
Thu Oct 18, 2018 4:42 pm
Forum: Announcements
Topic: v6.43.4 [stable] is released!
Replies: 78
Views: 28571

Re: v6.43.4 [stable] is released!

This is not a configuration issue (this configuration worked fine for 7 years)
problem occurs after upgrade to 6.42.x or 6.43.x
by mikruser
Thu Oct 18, 2018 4:22 pm
Forum: Announcements
Topic: v6.43.4 [stable] is released!
Replies: 78
Views: 28571

Re: v6.43.4 [stable] is released!

This IPsec bug still not fixed viewtopic.php?f=2&t=136445
by mikruser
Thu Oct 18, 2018 1:46 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 6730

Re: Problem with IPsec after update to 6.42

6.43.4 also have this issue!
by mikruser
Fri Oct 05, 2018 1:33 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 4573

Re: Please add performance results for IPsec tunnel!

I also tested two hAP ac^2 with 6.43.2

EoIP with IPsec (aes-128 ctr), file copy is only 34 MB/s:
hapac2_eoip_ipsec_ctr.png
EoIP without IPsec, file copy is 68 MB/s:
hapac2_eoip.png
by mikruser
Wed Oct 03, 2018 6:51 pm
Forum: RouterBOARD hardware
Topic: RB751-U-2nHD 100% cpu
Replies: 20
Views: 5793

Re: RB751-U-2nHD 100% cpu

6.43.2 also have this issue
by mikruser
Tue Oct 02, 2018 12:42 pm
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 105307

Re: v6.44beta [testing] is released!

what is "multiple engine"??
by mikruser
Tue Sep 25, 2018 7:55 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 4573

Re: Please add performance results for IPsec tunnel!

You can use minimal (fastest) config, required for EoIP+IPsec or L2TP+IPsec or GRE+IPsec.
by mikruser
Tue Sep 25, 2018 7:47 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 6730

Re: Problem with IPsec after update to 6.42

6.43.2 also have this issue!
by mikruser
Tue Sep 25, 2018 2:06 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 4573

Re: Please add performance results for IPsec tunnel!

>>The throughput results are there for you to evaluate the IPsec crypto engine performance, not to show you throughput results with various different configurations. IPsec crypto engine performance is a "spherical cow in a vacuum", and does not show real life results. >>check for packet fragmentati...
by mikruser
Tue Sep 25, 2018 12:40 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 4573

Re: Please add performance results for IPsec tunnel!

>>Adding or enabling any additional RouterOS feature apart from IPsec policies can reduce the throughput significantly. That's why I already suggested that you also publish the results for some popular tunnels+ipsec (l2tp+ipsec, gre+ipsec, eoip+ipsec) https://forum.mikrotik.com/viewtopic.php?f=3&t=...
by mikruser
Mon Sep 24, 2018 4:53 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 4573

Re: Please add performance results for IPsec tunnel!

I also tested two RB3011 with 6.43.2, connected via EoIP tunnel with IPsec.
They showed an even lower speed, even with hardware acceleration: file copy only 22 MB/s with aes-128 cbc/ctr (this is very far from declared 407.7 Mbps).
Profile:
rb3011_eoip_ipsec.png
by mikruser
Fri Sep 07, 2018 11:42 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 371
Views: 88631

Re: RB4011

Very unbalanced router
https://i.mt.lv/cdn/rb_files/RB4011iGSp ... 135303.png

Each switch have 5*1G port, but only 2.5G link to CPU.

What for this router have 10G sfp+ port? All switches summary have only 5G throughput.
by mikruser
Mon Sep 03, 2018 2:34 pm
Forum: RouterBOARD hardware
Topic: RB751 CPU usage get too high
Replies: 15
Views: 10218

Re: RB751 CPU usage get too high

I found that even just viewing the settings in the Winbox also often causes a 100% CPU load.

I suspect that the developers simply do not test the latest versions ROS/Winbox on RB751U.
Image100cpu.png
by mikruser
Sat Sep 01, 2018 9:05 pm
Forum: RouterBOARD hardware
Topic: When Mikrotik releases router that can handle single IPsec tunnel at 2.5G, 5G, 10G?
Replies: 1
Views: 645

When Mikrotik releases router that can handle single IPsec tunnel at 2.5G, 5G, 10G?

Hello,

When Mikrotik releases a router that can handle single IPsec tunnel (or MACsec) at 2.5G, 5G, 10G?
by mikruser
Thu Aug 30, 2018 10:52 pm
Forum: General
Topic: How to downgrade the ROS below the factory version?
Replies: 5
Views: 1148

Re: How to downgrade the ROS below the factory version?

May I ask why downgrade to such a vulnerable version? Wouldn't be better to upgrade the other equipment if having the same version on all hardware is important?
Due to a this bug in 6.42.x:
viewtopic.php?t=136445
by mikruser
Thu Aug 30, 2018 6:43 pm
Forum: General
Topic: How to downgrade the ROS below the factory version?
Replies: 5
Views: 1148

Re: How to downgrade the ROS below the factory version?

This is correct behavior.
But why??
We have another hAP ac^2 router and it works fine with version 6.41.4:
Image_hapac2.png
by mikruser
Thu Aug 30, 2018 5:58 pm
Forum: RouterBOARD hardware
Topic: Suggestion: release routers with preinstalled Factory Software from Bugfix release chain
Replies: 6
Views: 951

Suggestion: release routers with preinstalled Factory Software from Bugfix release chain

Hello,

Suggestion: release routers with preinstalled Factory Software only from Bugfix release chain.
by mikruser
Thu Aug 30, 2018 4:59 pm
Forum: General
Topic: How to downgrade the ROS below the factory version?
Replies: 5
Views: 1148

How to downgrade the ROS below the factory version?

We have hAP ac^2 with Factory Software 6.42.3
How to downgrade the ROS below the factory version (to 6.41.4)?
After /system package downgrade
we get error
error: omitting package system-6.41.4: min RouterOS version is 6.42.3
by mikruser
Wed Aug 29, 2018 12:55 pm
Forum: General
Topic: PCQ - Queue - where to set limit
Replies: 1
Views: 496

Re: PCQ - Queue - where to set limit

see answer in this topic: viewtopic.php?f=1&t=138427#p682693

Cha0s
Have you tried TP-Link or D-Link?

I am sure they are much easier with all their wizards whistles and bells.

If you find RouterOS hard, then it's probably not for you.
by mikruser
Tue Aug 28, 2018 7:15 pm
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 1611

Re: Suggestion: simple speed limiter

Advanced tab also not enough in this case.
by mikruser
Tue Aug 28, 2018 6:06 pm
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 1611

Re: Suggestion: simple speed limiter

we are talking about only first tab
by mikruser
Tue Aug 28, 2018 12:53 pm
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 1611

Re: Suggestion: simple speed limiter

Simple queue is perfectly adequate for this. Just use the first tab.
With only first tab is impossible to perform an elementary task in one queue:
set summary limit + set per IP limit
by mikruser
Sat Aug 25, 2018 3:09 pm
Forum: General
Topic: Feature requests
Replies: 1216
Views: 261993

Re: Feature requests

Feature request: AES hardware acceleration for OpenVPN
by mikruser
Fri Aug 24, 2018 7:04 pm
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 1611

Suggestion: simple speed limiter

Hello,

current Queues has a very large number of settings and a very complex and confusing.

Please add simple speed limiter.
by mikruser
Thu Aug 23, 2018 5:25 pm
Forum: General
Topic: Please add "Benchmark" button to Winbox IP-IPsec-Proposals
Replies: 1
Views: 685

Please add "Benchmark" button to Winbox IP-IPsec-Proposals

Hello,

Please add "Benchmark" button to Winbox IP-IPsec-Proposals
for benchmark selected algorithms "encryption", "decryption", "encryption+decryption" speed on any platform
(like VeraCrypt Tools-Benchmark):
Image_bench.png
by mikruser
Mon Aug 20, 2018 1:26 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 6730

Re: Problem with IPsec after update to 6.42

6.42.7 also have this issue!
by mikruser
Fri Aug 17, 2018 2:04 pm
Forum: General
Topic: Why Fast Path not active?
Replies: 4
Views: 2106

Re: Why Fast Path not active?

IPv4 fast path is automatically used if following conditions are met:

firewal rules are not configured;


LOL, in this case Fast Path absolutely useless
I do not have routerboards without firewall rules
by mikruser
Fri Aug 17, 2018 1:09 pm
Forum: General
Topic: Why Fast Path not active?
Replies: 4
Views: 2106

Why Fast Path not active?

Hello,

Fast Path enabled
But why Fast Path not active?
Image1_fp.png
by mikruser
Thu Aug 16, 2018 1:54 pm
Forum: General
Topic: Suggestion: backup restore wizard
Replies: 0
Views: 437

Suggestion: backup restore wizard

Hello,

Please add to Winbox backup restore wizard:

Interfaces remapping
Interfaces MAC addresses: preserve/reset
DHCP leases: preserve/remove
by mikruser
Wed Aug 08, 2018 4:50 pm
Forum: General
Topic: Please add the ability to choose Proposal
Replies: 11
Views: 2041

Re: Please add the ability to choose Proposal

I already have a configuration with a very large number of Ipsec policies (all these policies use proposal:default).

Now I created a l2tp connection with "Use Ipsec", and i need another custom proposal for this.
by mikruser
Wed Aug 08, 2018 1:11 pm
Forum: General
Topic: Bug after upgrade to 6.42.6
Replies: 4
Views: 951

Re: Bug after upgrade to 6.42.6

After investigation, I found that the bug is in Firewall-Service Ports-sip
After disable this port, 6.42 also works fine
by mikruser
Wed Aug 08, 2018 12:12 pm
Forum: General
Topic: Please add the ability to choose Proposal
Replies: 11
Views: 2041

Please add the ability to choose Proposal

Hello,

Please add the ability to choose Proposal (in L2tp with "Use IPsec")
by mikruser
Wed Aug 08, 2018 1:07 am
Forum: General
Topic: Suggestion: SMB WAN Accelerator
Replies: 0
Views: 502

Suggestion: SMB WAN Accelerator

Hello,

Please add SMB WAN Accelerator (for high latency VPN links)
like this: https://www.silver-peak.com/applications/cifs-smb
by mikruser
Thu Aug 02, 2018 9:51 pm
Forum: General
Topic: Suggestion: add crypto unit % usage
Replies: 0
Views: 651

Suggestion: add crypto unit % usage

Hello,

Some RouterBoard models have encryption engine.
Central Processing Unit (CPU) and Crypto Processing Unit (CrPU)

But currently in Tools-Profile we can see only CPU % Usage.

Suggestion: please add to Profile also CrPU % Usage.
by mikruser
Tue Jul 31, 2018 2:27 pm
Forum: General
Topic: AES-GCM HW acceleration in CCR
Replies: 10
Views: 1745

Re: AES-GCM HW acceleration in CCR

This topic about CCR
by mikruser
Tue Jul 31, 2018 12:14 pm
Forum: General
Topic: AES-GCM HW acceleration in CCR
Replies: 10
Views: 1745

Re: AES-GCM HW acceleration in CCR

There is a plan to make HW acceleration for GCM. 
Thank you for the confirmation Maris.
As it turned out, the confirmation was not true
by mikruser
Fri Jul 27, 2018 6:43 pm
Forum: General
Topic: chr support fast path?
Replies: 6
Views: 1016

Re: chr support fast path?

The presentation says the VMXNET3 NIC supports fastpath. Are you using that?
CHR always uses VMXNET3
by mikruser
Fri Jul 27, 2018 6:29 pm
Forum: General
Topic: chr support fast path?
Replies: 6
Views: 1016

Re: chr support fast path?

Also have this question.
Any official comments?
Image_chr_fp.png
by mikruser
Fri Jul 27, 2018 3:25 pm
Forum: General
Topic: How to optimize VPN tunnel over high latency link?
Replies: 3
Views: 929

Re: How to optimize VPN tunnel over high latency link?

Yes, Windows share file copy.
I also tried vSphere vMotion, but it did not exceed 60 Mbit/s.
by mikruser
Fri Jul 27, 2018 12:54 pm
Forum: General
Topic: How to optimize VPN tunnel over high latency link?
Replies: 3
Views: 929

How to optimize VPN tunnel over high latency link?

Hello, We have WAN-link with 1Gbit/s throughput, but 40 ms latency. iperf3 UDP test really can do 1Gbit/s almost lossless. We have L2TP IPsec tunnel over this WAN-link: LAN1---[CHR]---(l2tp_ipsec_vpn)---[CCR]---LAN2 Now file copy between LAN1 and LAN2 is only 6 MB/s maximum. I try different aes mode...
by mikruser
Thu Jul 26, 2018 2:27 pm
Forum: General
Topic: Bug after upgrade to 6.42.6
Replies: 4
Views: 951

Re: Bug after upgrade to 6.42.6

I do not see changes in SIP
by mikruser
Thu Jul 26, 2018 11:54 am
Forum: General
Topic: Feature Request: IPerf
Replies: 50
Views: 13199

Re: Feature Request: IPerf

kasparskr

do you can release Traffic Generator for Windows?
by mikruser
Thu Jul 26, 2018 11:35 am
Forum: General
Topic: Bug after upgrade to 6.42.6
Replies: 4
Views: 951

Bug after upgrade to 6.42.6

Hello, We have this setup: [FreePBX]---[CCR1]---(l2tp_ipsec_tunnel)---[CCR2]---[sip_clients] At night I updated ССR from 6.40.8 to 6.42.6. As a result, about half of sip clients/trunks can not register (FreePbx reboot did not help). After downgrade CCR back to 6.40.8 everything again worked fine. Wh...
by mikruser
Thu Jul 26, 2018 5:13 am
Forum: General
Topic: Please add to l2tp client Dial Out page "IPsec proposal" field
Replies: 0
Views: 502

Please add to l2tp client Dial Out page "IPsec proposal" field

Hello,

Please add to l2tp client Dial Out page "IPsec proposal" field
by mikruser
Thu Jul 26, 2018 4:40 am
Forum: General
Topic: "unclassified" cpu usage during btest
Replies: 1
Views: 875

"unclassified" cpu usage during btest

Hello,

What is "unclassified"?
Image1_btest_profile.png
by mikruser
Wed Jul 25, 2018 7:03 pm
Forum: General
Topic: Question about Tools - Bandwidth Test (tcp)
Replies: 0
Views: 338

Question about Tools - Bandwidth Test (tcp)

Hello,

Question about Tools - Bandwidth Test

What TCP Window Size does the test use?
by mikruser
Wed Jul 25, 2018 5:34 pm
Forum: General
Topic: btest - Where Is
Replies: 7
Views: 63949

Re: btest - Where Is

Any official info about Bandwidth Test for Windows?
by mikruser
Sun Jul 22, 2018 12:51 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 1225

Re: 2-in-1 ? [SOLVED]

Thanks, it works. You are a genius.
by mikruser
Sat Jul 21, 2018 11:15 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 1225

Re: 2-in-1 ? [SOLVED]

>>You may start by removing the additional 2.2.2.x addresses in your current setup

these are the necessary addresses, they must be accessible from the Internet
by mikruser
Sat Jul 21, 2018 11:13 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 1225

Re: 2-in-1 ? [SOLVED]

>>simply remove one Ethernet interface from an existing bridge and add IP address 2.2.2.1/27 to that interface.
which Ethernet interface?
from which bridge?
why only 2.2.2.1?

I do not see it in your diagram
by mikruser
Sat Jul 21, 2018 10:40 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 1225

Re: 2-in-1 ? [SOLVED]

On your diagram I do not see addresses from 2.2.2.0/24 subnet. (on my diagram these 30 addresses resides on Mikrotik2 <2.2.2.2>interface as additional addresses)
by mikruser
Sat Jul 21, 2018 9:39 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 1225

Re: 2-in-1 ? [SOLVED]

Аbsolutely did not understand you.
Could you draw a diagram with addresses from my example?
by mikruser
Sat Jul 21, 2018 6:23 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 1225

Re: 2-in-1 ? [SOLVED]

>>what is currently between the two Mikrotiks nothing. direct connection. Post the current configurations of both Mikrotiks For example (Mikrotik #1 is only routing, #2 routing and NAT): (Internet, provider gateway)---(1.1.1.0/30)---<1.1.1.1>[Mikrotik1]<2.2.2.1>---(2.2.2.0/24)---<2.2.2.2>[Mikrotik2...
by mikruser
Sat Jul 21, 2018 6:01 pm
Forum: Virtualization
Topic: CHR and KVM
Replies: 1
Views: 2355

CHR and KVM

Hello,
When i try Make RouterOS Image, i get error:
Couldn't start - this is not a host system
Image_kvm_chr.png
by mikruser
Sat Jul 21, 2018 3:35 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 1225

Re: 2-in-1 ? [SOLVED]

How possible create router inside router? Using VRF? KVM? Or more simple solution?
by mikruser
Sat Jul 21, 2018 3:09 am
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 1225

2-in-1 ? [SOLVED]

Hello, Currently i have this: (Internet)---(MyPublicSubnet1)---[Mikrotik1]---(MyPublicSubnet2)---[Mikrotik2]---(MyPrivateSubnet) MyPublicSubnet1 with 2 public ip MyPublicSubnet2 with 30 public ip Mikrotik1 is only routing Mikrotik2 is routing, nat, l2tp_ipsec_vpn My question: it is possible to creat...
by mikruser
Thu Jul 19, 2018 12:59 pm
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 2777

Re: Please add numbers on Y-axis in Bandwidth Test

Bandwidth Test shows results every 1 second. Snmp monitoring software can not show so frequently.
by mikruser
Thu Jul 19, 2018 12:35 pm
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 2777

Re: Please add numbers on Y-axis in Bandwidth Test

this is a joke? how do you imagine a bandwidth test through snmp?
by mikruser
Thu Jul 19, 2018 12:15 pm
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 2777

Re: Please add numbers on Y-axis in Bandwidth Test

we need more than one number, we need a few numbers (at least two - at the bottom and at the top)
image_bt_num.png
by mikruser
Thu Jul 19, 2018 12:04 pm
Forum: General
Topic: Feature requests
Replies: 1216
Views: 261993

Re: Feature requests

by mikruser
Thu Jul 19, 2018 11:39 am
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 2777

Re: Please add numbers on Y-axis in Bandwidth Test

We need numbers on the Y-axis so that they can be seen in the screenshots (if you do not understand this from the first message).
by mikruser
Thu Jul 19, 2018 11:09 am
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 2777

Re: Please add numbers on Y-axis in Bandwidth Test

vecernik87
You are troll? Try mouse over my screenshot.
by mikruser
Fri Jul 13, 2018 10:10 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 6730

Re: Problem with IPsec after update to 6.42

>>I am running several IPsec tunnels using various 6.42.x versions and things like this do not happen

You also use 0.0.0.0/0 in Src.Address (and Generate Policy on other side)?
by mikruser
Fri Jul 13, 2018 7:05 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 6730

Re: Problem with IPsec after update to 6.42

I found a bug in the 6.42.x version:
6.42 generate policy with incorrect Dst.Address: instead of 0.0.0.0/0 (in 6.41) i see public ip of remote router (in 6.42)

Mikrotik, please fix this bug ASAP!
by mikruser
Fri Jul 13, 2018 5:08 pm
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 2777

Please add numbers on Y-axis in Bandwidth Test

Hello,

Please add numbers on Y-axis in Bandwidth Test
image_bt.png
by mikruser
Fri Jul 06, 2018 5:12 pm
Forum: General
Topic: CHR do not support hardware acceleration (AES-NI)?
Replies: 0
Views: 430

CHR do not support hardware acceleration (AES-NI)?

Hello,

I create l2tp ipsec tunnel (sha1 aes-128-cbc) Encoding: cbc(aes) + hmac(sha1)
It work, but without hardware acceleration: show E (E-ESP) instead of EH (E-ESP H-Hardware AEAD)

ESXi 6.7, CHR 6.42.5
by mikruser
Wed Jul 04, 2018 3:40 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 6730

Problem with IPsec after update to 6.42

Hello,
After updating from 6.41.4 to 6.42.5 the traffic does not go through the tunnel (tunnel is established, but the traffic does not go).
After downgrade to 6.41.4 everything works fine again.

What changes in 6.42. led to this?
by mikruser
Sun May 27, 2018 11:53 pm
Forum: General
Topic: How to see real (physical) ether interface number?
Replies: 3
Views: 626

How to see real (physical) ether interface number?

Hello,
The interface Name can be anything and does not match the real (physical) number. (for example: ether interface number 2 can have Name 'ether5')
How to see real (physical) ether interface number? (remote, via Winbox)
by mikruser
Wed Mar 21, 2018 1:28 pm
Forum: RouterBOARD hardware
Topic: S+RJ10 question
Replies: 0
Views: 481

S+RJ10 question

Hello,

Is the module S+RJ10 (https://mikrotik.com/product/s_rj10) compatible with other vendor switches (like HPE, Dell, etc)?
by mikruser
Fri Mar 16, 2018 4:09 pm
Forum: General
Topic: Please add ability to connect to neighbors via MAC Winbox
Replies: 6
Views: 2439

Re: Please add ability to connect to neighbors via MAC Winbox

>>Remeber that neighbours seen by the router on the "other end" of interface could not be reachable from your LAN segment.

Router on the "other end" should act as a "proxy for winbox" in this case.
by mikruser
Fri Mar 16, 2018 2:47 pm
Forum: General
Topic: Please add ability to connect to neighbors via MAC Winbox
Replies: 6
Views: 2439

Re: Please add ability to connect to neighbors via MAC Winbox

I do not see "MAC Winbox" in your red circle
by mikruser
Fri Mar 16, 2018 12:50 pm
Forum: General
Topic: Please add ability to connect to neighbors via MAC Winbox
Replies: 6
Views: 2439

Please add ability to connect to neighbors via MAC Winbox

Hello,

Please add ability to connect to remote neighbors via MAC Winbox
(Menu "IP" - "Neighbors")
by mikruser
Tue Mar 13, 2018 6:33 pm
Forum: RouterBOARD hardware
Topic: Overclocking is officially supported?
Replies: 1
Views: 1440

Overclocking is officially supported?

Hello,

Some models can be overclocked +25% via System - Routerboard - Settings - CPU Frequency.
Is it officially supported? In this case, do we need special conditions for this (eg additional cooling)?
cpu_rb951.png
cpu_hapac2.png
by mikruser
Mon Mar 12, 2018 9:28 pm
Forum: General
Topic: L2TP VPN Tunnel problem
Replies: 4
Views: 4298

Re: L2TP VPN Tunnel problem

Any answer from Mikrotik?
When will you fix this bug?
This is a very serious problem!
by mikruser
Fri Feb 16, 2018 12:28 pm
Forum: RouterBOARD hardware
Topic: RB750Gr3 with PoE. When?
Replies: 6
Views: 1957

Re: RB750Gr3 with PoE. When?

No, i mean RB750Gr3
by mikruser
Fri Feb 16, 2018 11:38 am
Forum: RouterBOARD hardware
Topic: RB750Gr3 with PoE. When?
Replies: 6
Views: 1957

RB750Gr3 with PoE. When?

Hello,

When we can expect the appearance hEX (RB750Gr3) with PoE out (802.3af/at)?
by mikruser
Wed Feb 14, 2018 11:41 am
Forum: General
Topic: L2TP VPN Tunnel problem
Replies: 4
Views: 4298

Re: L2TP VPN Tunnel problem

Also have this issue CCR1009, 6.39.3 sometime l2tp tunnel cannot connect: l2tp-out1: initializing... l2tp-out1: connecting... l2tp-out1: terminating... - session closed l2tp-out1: disconnected... l2tp-out1: initializing... l2tp-out1: connecting... l2tp-out1: terminating... - old tunnel is not closed...
by mikruser
Sat Feb 10, 2018 9:39 pm
Forum: RouterBOARD hardware
Topic: dual-band access point
Replies: 4
Views: 726

Re: dual-band access point

You can see it on Specifications page for all dual-band AP:

https://mikrotik.com/product/RB962UiGS-5HacT2HnT
https://mikrotik.com/product/cap_ac
https://mikrotik.com/product/hap_ac2
Image_mikr_ap.png
i do not see "a" and "n" for 5 GHz...
by mikruser
Fri Feb 09, 2018 4:58 pm
Forum: RouterBOARD hardware
Topic: dual-band access point
Replies: 4
Views: 726

dual-band access point

Hello,

Mikrotik dual-band SOHO access point really do not support "n" and "a" standards in 5 GHz?
by mikruser
Wed Jan 31, 2018 5:58 pm
Forum: General
Topic: After upgrade to 6.41, Ethernet Interface Bandwidth is gone
Replies: 2
Views: 745

After upgrade to 6.41, Ethernet Interface Bandwidth is gone

Hello, We have many devices with 6.39.3 and use setting in Interfaces - Ethernet - General - Bandwidth (Rx/Tx) (https://wiki.mikrotik.com/wiki/Manual:Interface/Ethernet) After upgrade to 6.41 this option is gone. Changelog do not have any info about this! https://mikrotik.com/download/changelogs/cur...
by mikruser
Thu Jan 25, 2018 2:03 pm
Forum: RouterBOARD hardware
Topic: RB751-U-2nHD 100% cpu
Replies: 20
Views: 5793

Re: RB751-U-2nHD 100% cpu

you do not see first post?
by mikruser
Wed Jan 24, 2018 6:20 pm
Forum: RouterBOARD hardware
Topic: RB751-U-2nHD 100% cpu
Replies: 20
Views: 5793

Re: RB751-U-2nHD 100% cpu

any comments from Mikrotik?
by mikruser
Wed Jan 17, 2018 1:05 pm
Forum: RouterBOARD hardware
Topic: RB1100AHx4 - IPSec/Tunnel speed
Replies: 4
Views: 1376

Re: RB1100AHx4 - IPSec/Tunnel speed

Currently Mikrotik publish only very synthetic UPD test results, and refuses to publish real-life TCP test results.
You can write a petition about adding result for "Single tunnel TCP single thread" viewtopic.php?f=3&t=97880
by mikruser
Fri Jan 12, 2018 4:29 pm
Forum: RouterBOARD hardware
Topic: Test results for wireless
Replies: 1
Views: 472

Test results for wireless

Hello,

Why Test results for wireless devices
https://mikrotik.com/product/RBcAP2nD#tab1_4
have Ethernet test results instead of Wireless test results?
by mikruser
Fri Jan 12, 2018 3:14 pm
Forum: RouterBOARD hardware
Topic: Looking for hardware
Replies: 1
Views: 537

Looking for hardware

Hello,

I'm trying to find hardware with such specs:

1) Router with hardware AES and 802.3af/at PoE output.
2) Dual-band Ceiling AP with 802.3af/at PoE input.

Does Mikrotik plan to produce such devices?
by mikruser
Fri Dec 01, 2017 6:49 pm
Forum: General
Topic: Issue with failover routing
Replies: 4
Views: 808

Re: Issue with failover routing

how to kill all old connections if the failover switching occur?
by mikruser
Tue Nov 21, 2017 5:43 pm
Forum: General
Topic: Best practices for creating ipsec-tunnels on Mikrotik hardware?
Replies: 0
Views: 335

Best practices for creating ipsec-tunnels on Mikrotik hardware?

Hello, We have a central office (Server side) and several branches (Client side), connected via ipsec in tunnel mode. what are the best practices for creating ipsec tunnels? (we need fast tunnel establishment and fast reconnection). three variants are possible: 1) Server side: Manually created polic...
by mikruser
Fri Nov 10, 2017 10:12 am
Forum: RouterBOARD hardware
Topic: RB751-U-2nHD 100% cpu
Replies: 20
Views: 5793

Re: RB751-U-2nHD 100% cpu

ROS 6.39.3
also have this issue:
rb751_6393.png
by mikruser
Fri Oct 27, 2017 10:07 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 4573

Re: Please add performance results for IPsec tunnel!

Windows(192.168.0.1)----()hEX(10.0.0.1)----EoIP+IPsec----(10.0.0.2)hEX()----(192.168.0.2)Windows
by mikruser
Fri Oct 27, 2017 6:59 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 4573

Re: Please add performance results for IPsec tunnel!

didomir
>>You can find information here how the tests has been done: https://wiki.mikrotik.com/wiki/Manual:I ... imizations
This is synthetic UDP test.
True "real life" test its TCP single connection, as i suggested.
by mikruser
Fri Oct 27, 2017 6:32 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 4573

Re: Please add performance results for IPsec tunnel!

Paternot
>>Traffic inside the IPsec tunnel still crosses the forward chain
No
eoip_ipsec.png
>>Just occurred to me: You said the traffic was about 260 Mb/s. It was just download?
Its unidirectional file copy (download or upload)
by mikruser
Fri Oct 27, 2017 5:39 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 4573

Re: Please add performance results for IPsec tunnel!

IPsec use "input" and "output" chain, not "forward".
by mikruser
Fri Oct 27, 2017 5:11 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 4573

Re: Please add performance results for IPsec tunnel!

You do not understand. Its "L2 wire" only. No L3 forward.
by mikruser
Fri Oct 27, 2017 2:09 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 4573

Re: Please add performance results for IPsec tunnel!

Firewall is blank
These two Hex is direct connected and used as encrypted wire in LAN
by mikruser
Fri Oct 27, 2017 1:06 pm
Forum: General
Topic: Port flapping on RB750Gr3
Replies: 1
Views: 494

Port flapping on RB750Gr3

RB750Gr3
6.39.3
today I found port flapping:
hex_port_flapping.png
by mikruser
Thu Oct 26, 2017 7:26 pm
Forum: General
Topic: eoip tunnels and bridges mac addresses
Replies: 2
Views: 641

eoip tunnels and bridges mac addresses

Hello, I have RB750Gr3 (6.39.3) with these interfaces: ether1 ether2 ether3 ether4 ether5 eoip-tunnel1 eoip-tunnel2 bridge1 bridge2 ether2, ether3, eoip-tunnel1 is members of bridge1 ether4, ether5, eoip-tunnel2 is members of bridge2 Currently mac-address of bridge1 = mac-address of eoip-tunnel1 mac...
by mikruser
Thu Oct 26, 2017 6:34 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 4573

Re: Please add performance results for IPsec tunnel!

I tested in 1Gbit LAN
by mikruser
Thu Oct 26, 2017 5:57 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 4573

Re: Please add performance results for IPsec tunnel!

I tested two 750G r3 (6.39.3), connected via EoIP tunnel with IPsec.
Windows file copy test show only 33 MB/s (264 Mbps). This is very far from declared 477 Mbps https://mikrotik.com/product/RB750Gr3.

Maybe you add also results for some popular tunnels+ipsec (l2tp+ipsec, gre+ipsec, eoip+ipsec)?
by mikruser
Tue Oct 24, 2017 6:46 pm
Forum: General
Topic: What is "unclassified" cpu usage?
Replies: 3
Views: 4851

What is "unclassified" cpu usage?

Hello,

I have two RB751U (ROS 6.39.3), and EoIP with ipsec tunnel between them.
When i copy file over tunnel, i see 75% "unclassified" cpu usage:
rb751_eoip.png
by mikruser
Tue Oct 24, 2017 4:25 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 4573

Re: Please add performance results for IPsec tunnel!

>>It is stateless traffic, so you could say it is UDP. Please add result for "Single tunnel TCP single thread". Its very useful info, for example as file copying. >>There is no use of testing devices without hardware acceleration, because their performance difference between models is insignificant...
by mikruser
Tue Oct 24, 2017 2:10 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 4573

Re: Please add performance results for IPsec tunnel!

As I see, you added "IPsec test results" for some products, like this https://mikrotik.com/product/CCR1009-7G-1C-1Splus

Some questions:

1) how many threads were used in Single tunnel?
2) it's TCP or UDP throughput?
3) why you publish results only for products with hardware ipsec?
by mikruser
Fri Oct 13, 2017 3:54 pm
Forum: General
Topic: Issue with failover routing
Replies: 4
Views: 808

Re: Issue with failover routing

up.
by mikruser
Wed Oct 11, 2017 7:13 pm
Forum: General
Topic: Winbox cannot connect to mac-address
Replies: 3
Views: 3218

Re: Winbox cannot connect to mac-address

MAC-WinBox service???
by mikruser
Wed Oct 11, 2017 7:09 pm
Forum: General
Topic: Service Ports, SIP Direct Media, SDP
Replies: 10
Views: 10001

Re: Service Ports, SIP Direct Media, SDP

Also have this issue.
But after disable "SIP Direct Media" all works fine.

Why "SIP Direct Media" is enabled by default?
It should be disabled by default!
by mikruser
Wed Oct 11, 2017 5:03 pm
Forum: General
Topic: Winbox cannot connect to mac-address
Replies: 3
Views: 3218

Winbox cannot connect to mac-address

Hello,

Winbox cannot connect to mac-address:
winbox_macaddr.png
why?
by mikruser
Mon Oct 02, 2017 5:38 pm
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 30756

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

But when 6.39 become a bugfix???

very strange situation:

6.41.x = RC
6.40.x = Current
6.39.x = WTF??? Where??? When???
6.38.x = Bugfix
by mikruser
Thu Sep 21, 2017 5:15 pm
Forum: General
Topic: Bug with L2TP Server Binding
Replies: 1
Views: 700

Bug with L2TP Server Binding

CCR1009-8G, 6.39, 6.39.2
I have two interfaces (Type:L2TP Server Binding):
l2tp-in1
l2tp-in2

but sometimes instead of l2tp-in2 i see dynamic interface:
l2tp_sb.png
by mikruser
Wed Aug 09, 2017 12:06 pm
Forum: General
Topic: Suggestion: add route check gateway based on link quality
Replies: 2
Views: 797

Suggestion: add route check gateway based on link quality

Hello,

Currently "Route Check Gateway" based on simply ping.
My suggestion: add check gateway based on link quality (ping jitter and packet loss) for given period of time.
by mikruser
Mon Jul 31, 2017 5:12 pm
Forum: RouterBOARD hardware
Topic: wireless+router device for ipsec
Replies: 2
Views: 487

Re: wireless+router device for ipsec

Do you have any plans to release wireless+router devices with HW-IPsec?
by mikruser
Mon Jul 31, 2017 5:04 pm
Forum: RouterBOARD hardware
Topic: wireless+router device for ipsec
Replies: 2
Views: 487

wireless+router device for ipsec

Hello,

Which wireless+router device (https://mikrotik.com/products/group/wir ... and-office) can handle at least 40Mbit/s ipsec vpn?
by mikruser
Mon Jul 31, 2017 4:51 pm
Forum: RouterBOARD hardware
Topic: hAP lite CPU
Replies: 1
Views: 700

hAP lite CPU

Hello,

Why hAP lite and hAP lite classic have
Product specifications
CPU QCA9533


but have
Ethernet test results
QCA9531 (650Mhz) 100M all port test


???
https://mikrotik.com/product/RB941-2nD-TC
https://mikrotik.com/product/RB941-2nD
by mikruser
Mon Jul 31, 2017 3:57 pm
Forum: RouterBOARD hardware
Topic: RB751 CPU usage get too high
Replies: 15
Views: 10218

Re: RB751 CPU usage get too high

Also have this issue (100% cpu) on some RB751U-2HnD (ROS 6.40):
Image1.png
Image2.png
Image3.png
Image4.png
Image5.png
Image6.png
How to fix this issue?
by mikruser
Tue Jul 18, 2017 4:59 pm
Forum: General
Topic: AVX2 and AVX-512
Replies: 1
Views: 749

AVX2 and AVX-512

Hello,

Can ROS x86 or ROS CHR use AVX2 and AVX-512 instructions from Skylake-X (Core i9 7900X) and Xeon Scalable?
by mikruser
Thu Jul 13, 2017 5:57 pm
Forum: General
Topic: Feature request - DNS names in IPsec
Replies: 7
Views: 2199

Feature request - DNS names in IPsec

Hello,

Please add ability to use DNS names in:

IP-IPsec-Policies-General\Action-Dst.Address
IP-IPsec-Peers-General-Address
by mikruser
Mon Jul 03, 2017 7:42 pm
Forum: RouterBOARD hardware
Topic: CCR manual pdf?
Replies: 3
Views: 1084

Re: CCR manual pdf?

Any info?

which led\color for 10 Mbps link?
which led\color for 100 Mbps link?
which led\color for 1000 Mbps link?
which led(s)\color(s) for Full\Half duplex link?
which led\color for activity?
by mikruser
Thu Jun 29, 2017 1:00 pm
Forum: General
Topic: Feaure Request: Watchdog to watch multiple IP addresses
Replies: 7
Views: 2158

Re: Feaure Request: Watchdog to watch multiple IP addresses

UP!
We want multiple IP in Watchdog ASAP!
by mikruser
Thu Jun 29, 2017 12:58 pm
Forum: General
Topic: Feature request: IPMI functionality for CCR
Replies: 7
Views: 2226

Re: Feature request: IPMI functionality for CCR

We again got this issue - CCR1009 "hung" very strange - ping work, but all ppp-tunnels cannot connect, we cannot connect Winbox to ip, and Winbox do not see CCR in Neighbors.
Only manual power cycle help me.
by mikruser
Wed Jun 28, 2017 3:47 pm
Forum: General
Topic: Discussion about bugfix, current and rc versions
Replies: 29
Views: 7824

Re: Discussion about bugfix, current and rc versions

From my experience: 1) "Bugfix" = Final stable version. Only this should be installed on production router. 2) "Current" = Public beta version with bugs for public beta testing, but have official support via support@mikrotik.com. You can install it on own risk. 3) "Release candidate" = beta version ...
by mikruser
Tue Jun 27, 2017 5:33 pm
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 30756

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

I repeat my question:
When we can expect this fix in "bugfix" branch?
by mikruser
Mon Jun 19, 2017 12:22 pm
Forum: General
Topic: Link Downs monitoring
Replies: 2
Views: 1378

Link Downs monitoring

Hello,

We need monitor via SNMP "Interface\ Status \ Link Downs" value, and "Rate" and "Full Duplex" value.
Its possible?
by mikruser
Fri Jun 16, 2017 2:21 pm
Forum: RouterBOARD hardware
Topic: CCR manual pdf?
Replies: 3
Views: 1084

Re: CCR manual pdf?

LEDs near ETH ports
by mikruser
Thu Jun 15, 2017 12:08 pm
Forum: RouterBOARD hardware
Topic: CCR manual pdf?
Replies: 3
Views: 1084

CCR manual pdf?

Hello,

Where can I find the PDF manual with a detailed description of CCR1009 (https://routerboard.com/CCR1009-8G-1S-1Splus)?
For example i cannot find description of eth led's colors value.
by mikruser
Wed Jun 14, 2017 8:01 pm
Forum: General
Topic: Issue with failover routing
Replies: 4
Views: 808

Re: Issue with failover routing

do you have some connection/route marking mangle rules?
No
by mikruser
Tue Jun 13, 2017 6:04 pm
Forum: General
Topic: Issue with failover routing
Replies: 4
Views: 808

Issue with failover routing

Hello,

We use this manual for dual-wan RB:
https://wiki.mikrotik.com/wiki/Advanced ... _Scripting
wan1=cheap unlimited traffic
wan2=expensive limited traffic

But i found this issue: when RB switch back from wan2 to wan1, pptp and sip connections stay on wan2!
by mikruser
Fri Jun 09, 2017 6:24 pm
Forum: General
Topic: ERROR: no roteros.dll found
Replies: 0
Views: 469

ERROR: no roteros.dll found

WinBox 3.11
cannot connect to some RB:

ERROR: no roteros.dll found
by mikruser
Wed May 17, 2017 11:14 pm
Forum: General
Topic: Microtik Hex IPSEC Phase 2 negatiation issue
Replies: 3
Views: 2226

Re: Microtik Hex IPSEC Phase 2 negatiation issue

worldcitizen

Its not Hex issue, its 6.38 and above issue
I write about this issue 4 month ago, but Mikrotik ignore this and release bugged 6.39
viewtopic.php?t=116729
by mikruser
Sat May 13, 2017 12:58 pm
Forum: General
Topic: Feature request: Detect and block Layer3/4 packets/connections with suspicious signatures
Replies: 2
Views: 770

Feature request: Detect and block Layer3/4 packets/connections with suspicious signatures

Hello,

Feature requests:
Detect and block Layer3/4 packets/connections with suspicious signatures.
Centralized updating the database of signatures.
by mikruser
Fri May 12, 2017 12:53 am
Forum: RouterBOARD hardware
Topic: Feature request: hot-swap PSU for 1U models
Replies: 0
Views: 352

Feature request: hot-swap PSU for 1U models

Hello,

Feature request: hot-swap PSU (1+1) for 1U models
by mikruser
Sat Apr 29, 2017 12:39 pm
Forum: Announcements
Topic: v6.39 [current]
Replies: 89
Views: 38402

Re: v6.39 [current]

6.39 - another epic fail bugged version from mikrotik. Kill ipsec, kill sip-trunk.

Downgrade to 6.37.5, and all work fine.
by mikruser
Sat Apr 29, 2017 2:52 am
Forum: General
Topic: 6.36.2 / 6.39 is BUGGED!
Replies: 3
Views: 1186

Re: 6.36.2 / 6.39 is BUGGED!

6.39 also have this issue!

(6.37.5 work fine)
by mikruser
Fri Apr 28, 2017 10:34 pm
Forum: General
Topic: 6.38/6.39 kill ipsec
Replies: 10
Views: 2531

Re: 6.38 kill ipsec

6.39 also have this issue and kill IPsec

Why mikrotik developers release bugged versions?????
by mikruser
Fri Apr 07, 2017 7:48 pm
Forum: General
Topic: Simple Queue - how to limit only LAN-Internet traffic?
Replies: 1
Views: 850

Simple Queue - how to limit only LAN-Internet traffic?

Hello, I have LAN and LAN2 connected via VPN-tunnel: LAN----[eth1 CCR eth5]----((Internet))----[CCR2]---LAN2 now i want limit LAN-to/from-Internet traffic. but when i create Simple Queue with Target=LAN, it limit all traffic (include LAN-LAN2) how to limit only LAN-to/from-Internet traffic (without ...
by mikruser
Wed Apr 05, 2017 11:52 am
Forum: General
Topic: Simple Queue question
Replies: 13
Views: 1733

Re: Simple Queue question

no, you need one simple queue with target=192.168.0.0/24 and max-limit=10M/10M + set queue type=pcq for upload/download and set these with pcq-rate=2M in both 1 client - 2M, up to 5 client - get 2M each. 10 client - 1M each... 1) On which tab i should set queue type=pcq? On "Advanced" tab i do not ...
by mikruser
Tue Apr 04, 2017 5:57 pm
Forum: General
Topic: Simple Queue question
Replies: 13
Views: 1733

Re: Simple Queue question

It is impossible to set per-ip limit in ROS?
I must manually create 253 rules for each ip?
by mikruser
Sun Apr 02, 2017 4:36 pm
Forum: RouterBOARD hardware
Topic: MUM Europe 2017: new hardware incoming!
Replies: 86
Views: 22282

Re: MUM Europe 2017: new hardware incoming!

AHx4 > CCR1009 in single-threaded (one core) tasks, but AHx4 < CCR1009 in a well-parallelizable (multi core) tasks.
by mikruser
Fri Mar 31, 2017 7:52 pm
Forum: General
Topic: Suggestion: more real-life config for "Ethernet test results"
Replies: 0
Views: 414

Suggestion: more real-life config for "Ethernet test results"

Hello,

Currently "Ethernet test results" based on very light configurations.

Suggestion:
1) Add more real-life heavier config (ip firewall filter rules + nat rules + mangle rules + queues + vlan)
2) Add crypto config (L2TP/GRE + IPsec)
by mikruser
Mon Mar 20, 2017 10:45 am
Forum: General
Topic: Feature request : Lightweight crypto for devices not having hardware crypto engine
Replies: 1
Views: 588

Re: Feature request : Lightweight crypto for devices not having hardware crypto engine

+1
Devices like RB751 is too slow with current ROS Ipsec encr. algorithms (~10Mbit/s)
We want fast fast algorithm!
by mikruser
Fri Mar 17, 2017 12:29 pm
Forum: RouterBOARD hardware
Topic: Why Mikrotik does not produce the routers on x86 processors?
Replies: 18
Views: 4170

Re: Why Mikrotik does not produce the routers on x86 processors?

What about using Ryzen? It has incredible crypto performance:
Image
Image
by mikruser
Wed Feb 22, 2017 12:09 pm
Forum: General
Topic: IPSec tunnel in one direction it is very slow
Replies: 6
Views: 1619

Re: IPSec tunnel in one direction it is very slow

Its a well-known problem with mikrotik ipsec tunnels.
Mikrotik ipsec tunnels are not compatible with Windows.
by mikruser
Tue Jan 24, 2017 11:44 pm
Forum: RouterBOARD hardware
Topic: Need router with wifi
Replies: 1
Views: 669

Need router with wifi

Hello,

I need router with features:
1) Hardware encryption (or software can 100 Mbit/s)
2) dual-band 802.11n (minimum 2 spatial stream, but advisable 3)
3) Gigabit ethernet ports

which model you can recommend?
by mikruser
Tue Jan 17, 2017 4:28 pm
Forum: General
Topic: 6.38/6.39 kill ipsec
Replies: 10
Views: 2531

Re: 6.38 kill ipsec

It is almost impossible to guess what ipsec config you have and what might not work.
I have a config that works for many years on any version before 6.38
It is incredible that Mikrotik release such bugged version.
This is absolutely unacceptable for enterprise.
by mikruser
Mon Jan 16, 2017 7:10 pm
Forum: Announcements
Topic: v6.38.1 [current]
Replies: 73
Views: 27379

Re: v6.38.1 [current]

I really hope the 6.38 bugs are squashed :)
No, 6.38.1 also bugged, as 6.38 (ipsec tunnel dont work)
Only downgrade to 6.37.3 can help.
by mikruser
Wed Jan 11, 2017 12:47 pm
Forum: General
Topic: 6.38/6.39 kill ipsec
Replies: 10
Views: 2531

6.38/6.39 kill ipsec

Hello,

After upgrade to 6.38 ipsec tunnel dont work.

I downgrade to 6.37.3 and tunnel work again.
by mikruser
Sat Jan 07, 2017 12:37 am
Forum: General
Topic: Encr. Algorithm field is blank
Replies: 1
Views: 498

Re: Encr. Algorithm field is blank

In 6.38 issue has NOT been fixed!!!
by mikruser
Fri Dec 23, 2016 2:40 pm
Forum: General
Topic: ipsec unstable
Replies: 11
Views: 4631

Re: ipsec unstable

In v6.38 nat-t is enabled by default because many client devices require it
lol wat???
facepalm.jpg
by mikruser
Sat Dec 17, 2016 8:57 pm
Forum: General
Topic: Feature request: Port-based VLAN for routers with switch-chip
Replies: 14
Views: 2654

Re: Feature request: Port-based VLAN for routers with switch-chip

https://community.hpe.com/t5/Switches-Hubs-Modems-Legacy/Overlapping-vlans/td-p/3652542 Here you can find some guy trying to do that on HP switch and it didn't work as expected. HP 2500 switches dont support full featured Port-based Vlan (cannot put one port to two group) and overlapping Vlans supp...
by mikruser
Sat Dec 17, 2016 5:50 pm
Forum: General
Topic: Feature request: Port-based VLAN for routers with switch-chip
Replies: 14
Views: 2654

Re: Feature request: Port-based VLAN for routers with switch-chip

if you assure that currently switch-chip can, please show Winbox screenshots for this:
portbasedvlan.png
by mikruser
Sat Dec 17, 2016 4:59 pm
Forum: General
Topic: Feature request: Port-based VLAN for routers with switch-chip
Replies: 14
Views: 2654

Re: Feature request: Port-based VLAN for routers with switch-chip

read first post link ("Port-based VLAN Overview" from page 151)
currently routers with switch-chip cannot do this.
by mikruser
Sat Dec 17, 2016 2:19 pm
Forum: General
Topic: Feature request: Port-based VLAN for routers with switch-chip
Replies: 14
Views: 2654

Re: Feature request: Port-based VLAN for routers with switch-chip

I'm not sure if I get what you want but afaik ROS supports VLANs on switch chip level.
No, currently routers with switch-chip can only Tagged Vlan (802.1Q).
My suggestion about port-based Vlan.
It two absolutely different types of Vlan.
by mikruser
Thu Dec 15, 2016 3:09 pm
Forum: General
Topic: Feature request: Port-based VLAN for routers with switch-chip
Replies: 14
Views: 2654

Feature request: Port-based VLAN for routers with switch-chip

Like this switch: https://www.alliedtelesis.com/sites/def ... 100a_0.pdf
see "Port-based VLAN Overview" from page 151
In some cases it very useful!
by mikruser
Thu Dec 15, 2016 1:06 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 179321

Re: RouterOS v7.0 beta1 - when?

v7 ?

I think it will be a Christmas gift :-D
I expect v7 immediately after Christ Second Coming
by mikruser
Fri Dec 09, 2016 7:20 pm
Forum: Beginner Basics
Topic: How does "Auto" frequency feature works ?
Replies: 3
Views: 1930

Re: How does "Auto" frequency feature works ?

Why Auto-frequency do not select frequency with best noise floor?
by mikruser
Tue Dec 06, 2016 11:18 am
Forum: General
Topic: IPsec Generate Policy From Template
Replies: 4
Views: 2118

Re: IPsec Generate Policy From Template

ROS 6.x is very bugged and level=unique dont work:
http://forum.mikrotik.com/viewtopic.php ... 2&p=541653
by mikruser
Mon Dec 05, 2016 9:46 pm
Forum: RouterBOARD hardware
Topic: Why Mikrotik does not produce the routers on x86 processors?
Replies: 18
Views: 4170

Re: Why Mikrotik does not produce the routers on x86 processors?

CHR is OS for virtual machine.
My question about hardware router in 1U rackmount formfactor
by mikruser
Mon Dec 05, 2016 6:04 pm
Forum: RouterBOARD hardware
Topic: Why Mikrotik does not produce the routers on x86 processors?
Replies: 18
Views: 4170

Why Mikrotik does not produce the routers on x86 processors?

Hello,
Why Mikrotik does not produce the routers on x86 processors?
Dual-core Skylake can handle 10Gbit/s aes-gcm ipsec tunnel (CCR cannot).
by mikruser
Thu Dec 01, 2016 12:06 pm
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 30756

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

Why reordering issue occurs with hardware multicore, but not occurs with software multicore?
by mikruser
Thu Dec 01, 2016 12:03 pm
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 30756

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

I understand that Mikrotik says the ordering problem is being fixed (but when? ROS v7?). But can we temporarily get an option in the v6.x version to disable HW acceleration on the CCR platform, so that we can do software CBC on the CCR and hardware CBC on the hex 3r? I vote for that as well! it has...
by mikruser
Wed Nov 30, 2016 4:54 pm
Forum: RouterBOARD hardware
Topic: Which wireless protocol has the highest goodput?
Replies: 0
Views: 564

Which wireless protocol has the highest goodput?

Hello,

Which wireless protocol has the highest goodput?
Is there a wireless protocol with goodput >50%?
by mikruser
Fri Nov 18, 2016 11:38 am
Forum: General
Topic: Bandwidth test tool for Windows cause 100% core usage
Replies: 2
Views: 879

Re: Bandwidth test tool for Windows cause 100% core usage

TomjNorthIdaho

You can post screenshot with "Bandwidth test tool for Windows" window and "Windows Task Manager" window in one screenshot?
I should see 19000 Mbit tcp send and CPU per core usage.
by mikruser
Thu Nov 17, 2016 11:55 am
Forum: General
Topic: Bandwidth test tool for Windows cause 100% core usage
Replies: 2
Views: 879

Bandwidth test tool for Windows cause 100% core usage

Bandwidth test tool for Windows (tcp send) cause 100% core usage (3.5 GHz).
I can get only 165 Mbit/s with test to CCR
this test is absolutely unoptimized and do not use tcp offload?
by mikruser
Thu Nov 10, 2016 7:02 pm
Forum: General
Topic: What is "unclassified" cpu usage?
Replies: 1
Views: 1316

What is "unclassified" cpu usage?

What is "unclassified" cpu usage?
profile_unclassified.png
by mikruser
Sat Oct 29, 2016 8:39 pm
Forum: General
Topic: Problem Intel I350 t4
Replies: 10
Views: 3765

Re: Problem Intel I350 t4

Fri Apr 24, 2015 only in v7 beta that will be released soon
Mikrotik team is a bunch of liars.
by mikruser
Wed Oct 26, 2016 4:28 pm
Forum: General
Topic: Which encryption method (in software) is the fastest on CCR?
Replies: 0
Views: 400

Which encryption method (in software) is the fastest on CCR?

Hello,

Which encryption method (in software) is the fastest on CCR?
by mikruser
Wed Oct 26, 2016 4:23 pm
Forum: General
Topic: Suggestion: "Use HW accel" checkbox
Replies: 1
Views: 1257

Suggestion: "Use HW accel" checkbox

suggestion:
add "Use HW accel" checkbox to IP - IPsec - Proposals
(its need to disable hw accel with aes-cbc on CCR)
by mikruser
Mon Oct 10, 2016 11:51 am
Forum: General
Topic: Feature request: IPMI functionality for CCR
Replies: 7
Views: 2226

Re: Feature request: IPMI functionality for CCR

600$? really? its joke? oh lol
IPMI functionality should add to CCR price no more than 30$
by mikruser
Mon Oct 10, 2016 11:24 am
Forum: General
Topic: Encr. Algorithm field is blank
Replies: 1
Views: 498

Encr. Algorithm field is blank

I change Proposal Encr. Algorithm from aes-cbc to aes-gcm.
Tunnel work, but in Installed SAs tab Encryption\Encr. Algorithm field is blank.
Why?
by mikruser
Fri Oct 07, 2016 2:27 pm
Forum: General
Topic: PCC side effect on Mikrotik Forum
Replies: 4
Views: 1151

Re: PCC side effect on Mikrotik Forum

please fix it asap!
currently your forum do not support posting from dual-wan balanced routerboard
  • 1
  • 2