Community discussions

MikroTik App

Search found 462 matches

  • 1
  • 2
by mikruser
Thu Aug 13, 2020 1:42 pm
Forum: RouterBOARD hardware
Topic: CCR2004 : BGP Benchmarks
Replies: 41
Views: 10195

Re: CCR2004 : BGP Benchmarks

BGP Insertion (4xFullviews, ~3,2M routes) : 1. RB4011 : 3m45s 2. CCR2004 : 5m38s 3. CCR1016 : 10m09s 4. CCR1009 : 10m45s BGP Removal (4xFullviews, ~3,2M routes) : 1. CCR1016 : 3m18s 2. CCR1009 : 3m25s 3. RB4011 : 8m25s 4. CCR2004 : 19m58s SUGGESTION: These numbers also should be published on Test r...
by mikruser
Fri Aug 07, 2020 7:05 pm
Forum: General
Topic: Suggestion: Address List in Routes
Replies: 1
Views: 461

Suggestion: Address List in Routes

Hello,

please add ability to use Address List in Dst.Address in Routes
by mikruser
Wed Aug 05, 2020 2:42 pm
Forum: General
Topic: How does AutoMTU work for VPN tunnels?
Replies: 1
Views: 912

Re: How does AutoMTU work for VPN tunnels?

Any ideas?
by mikruser
Tue Aug 04, 2020 3:48 pm
Forum: General
Topic: What TCP Congestion Control algorithm is used in Bandwidth Test-tcp?
Replies: 0
Views: 335

What TCP Congestion Control algorithm is used in Bandwidth Test-tcp?

Hello,

What TCP Congestion Control algorithm is used in Tools-Bandwidth Test-tcp?
by mikruser
Mon Aug 03, 2020 6:22 pm
Forum: RouterBOARD hardware
Topic: Why Mikrotik puts only 16MB flash on many devices? (not enough space for upgrade)
Replies: 16
Views: 2797

Re: Why Mikrotik puts only 16MB flash on many devices? (not enough space for upgrade)

Paternot
Can you provide proof that chip IPQ-4018 (and other) has a 16MB flash limitation?

krafg
I use System-Packages-Check for updates-Download&install
by mikruser
Mon Aug 03, 2020 5:35 pm
Forum: General
Topic: NetFlow. No longer showing NAT'd destination address - Something chnaged
Replies: 30
Views: 5393

Re: NetFlow. No longer showing NAT'd destination address - Something chnaged

I dont known why Mikrotik support talk about "NAT events". Answer from ManageEngine Netflow Analyzer developers: Hi , Mikrotik device do not send NAT information in the netflow packets. If the device can send NAT information over the flows, we will be able to show you the details. How happy are you ...
by mikruser
Mon Aug 03, 2020 4:35 pm
Forum: RouterBOARD hardware
Topic: Why Mikrotik puts only 16MB flash on many devices? (not enough space for upgrade)
Replies: 16
Views: 2797

Re: Why Mikrotik puts only 16MB flash on many devices? (not enough space for upgrade)

>>If you could remove packages, it means you put them there. Yes, i always install Extra packages zip from https://mikrotik.com/download >>I can just suggest that you do not install extra packages on small NAND devices. In this case remove Extra packages zip for these devices from https://mikrotik....
by mikruser
Mon Aug 03, 2020 12:14 pm
Forum: RouterBOARD hardware
Topic: Why Mikrotik puts only 16MB flash on many devices? (not enough space for upgrade)
Replies: 16
Views: 2797

Re: Why Mikrotik puts only 16MB flash on many devices? (not enough space for upgrade)

I already solving this issue by deleting unused packages via System-Packages-Uninstall.

but that doesn't remove the question of why you're saving 50 cents on the cost of creating problems for users.
by mikruser
Mon Aug 03, 2020 12:00 pm
Forum: General
Topic: NetFlow. No longer showing NAT'd destination address - Something chnaged
Replies: 30
Views: 5393

Re: NetFlow. No longer showing NAT'd destination address - Something chnaged

Chupaka I think you should ask Netflow Analyzer if they support necessary fields I asked Mikrotik support. First they blamed the analyzing software, but then they admitted: we currently don't have NAT events available in current stable/long-term releases. We are working to implement the support for...
by mikruser
Mon Aug 03, 2020 12:17 am
Forum: General
Topic: L2TP not connecting on Windows client
Replies: 4
Views: 1136

Re: L2TP not connecting on Windows client

Set these values:
Proposal: aes-128cbc/sha1/modp1024
Profile: sha1/aes-128/ecp256
by mikruser
Mon Aug 03, 2020 12:01 am
Forum: RouterBOARD hardware
Topic: Why Mikrotik puts only 16MB flash on many devices? (not enough space for upgrade)
Replies: 16
Views: 2797

Why Mikrotik puts only 16MB flash on many devices? (not enough space for upgrade)

32/64MB chips are very very cheap, but Mikrotik puts only 16MB. Why???
On hEX, hAPac2 i get errors:
system, error: not enough space for upgrade
by mikruser
Sat Aug 01, 2020 10:40 pm
Forum: RouterBOARD hardware
Topic: Question about IPsec test results
Replies: 4
Views: 1231

Re: Question about IPsec test results

floaty
in a stream-cipher with an pre-shared or diffie-hellman'ed key, should the cpu-load for de- & encrypt pretty much the same
No. In aes-cbc mode decryption is much faster than encryption.
by mikruser
Sat Aug 01, 2020 5:50 pm
Forum: General
Topic: Suggestion: redesign Tools-Profile in Winbox
Replies: 2
Views: 749

Re: Suggestion: redesign Tools-Profile in Winbox

no problem. this compact table may fit on full-hd screen even with CCR1072.

(currently many-rows table should have 1008 rows for 13 services on 72 cores. it doesn't fit on any monitors)
by mikruser
Sat Aug 01, 2020 4:38 am
Forum: General
Topic: Suggestion: redesign Tools-Profile in Winbox
Replies: 2
Views: 749

Suggestion: redesign Tools-Profile in Winbox

Hello,
Instead of many-rows table
image_profile.png
you can use this compact and more informative table:
image_profile_suggestion.png
by mikruser
Thu Jul 30, 2020 1:56 pm
Forum: RouterBOARD hardware
Topic: Question about IPsec test results
Replies: 4
Views: 1231

Question about IPsec test results

Hello,

https://mikrotik.com/product/RB3011UiAS ... estresults
https://mikrotik.com/product/CCR1009-7G ... estresults

these IPsec test results throughput are for encryption or for decryption?
by mikruser
Wed Jul 22, 2020 3:04 pm
Forum: General
Topic: Rename Address-List
Replies: 4
Views: 2727

Re: Rename Address-List

changeip
your code do not work.

Also have this question - how to rename address list via Winbox?
by mikruser
Sun Jul 19, 2020 1:20 pm
Forum: General
Topic: How to set Pref.Source for dynamic routes?
Replies: 1
Views: 597

How to set Pref.Source for dynamic routes?

Hello,
How to set Pref.Source for dynamic routes type DAS (dynamic active static)? (for example pptp/l2tp/sstp)
by mikruser
Wed Jul 15, 2020 11:29 pm
Forum: General
Topic: Slow speed through gre+ipsec tunnel
Replies: 11
Views: 3778

Re: Slow speed through gre+ipsec tunnel

Issue is still observed on 6.47.1:
image_bwtest_tcp_ccr_6471.png
first graph - test from ccr to chr public ip
second graph - test from ccr to chr private ip (via tunnel)
by mikruser
Tue Jul 14, 2020 7:10 pm
Forum: General
Topic: Why Mikrotik OVPN Server do not support AES-128-GCM cipher?
Replies: 0
Views: 433

Why Mikrotik OVPN Server do not support AES-128-GCM cipher?

Hello,

Why Mikrotik OVPN Server do not support AES-128-GCM cipher?
by mikruser
Mon Jul 13, 2020 12:04 pm
Forum: General
Topic: Feature Request for Bandwidth Test
Replies: 0
Views: 377

Feature Request for Bandwidth Test

Hello,

Please add to Bandwidth Test:

TCP Retransmissions count and %
out-of-order packets count and %
duplicate packets count and %
fix Lost Packets info for correct results
more protocols for test (example: gre, sctp)
interface selection for the test
by mikruser
Fri Jul 10, 2020 1:50 pm
Forum: General
Topic: Why UDP Bandwidth Test always show Lost Packets = 0?
Replies: 4
Views: 707

Re: Why UDP Bandwidth Test always show Lost Packets = 0?

So you say that the mikrotik developers created a fake Bandwidth Test udp with a fake "Lost Packets" field?
by mikruser
Fri Jul 10, 2020 12:11 pm
Forum: General
Topic: Why UDP Bandwidth Test always show Lost Packets = 0?
Replies: 4
Views: 707

Why UDP Bandwidth Test always show Lost Packets = 0?

Hello,

I already tested the channels using tcp test: viewtopic.php?f=2&t=163469
and the results looks like there are packet loss.
But why UDP Bandwidth Test do not show packet loss?
by mikruser
Fri Jul 10, 2020 12:52 am
Forum: General
Topic: Strange TCP Bandwidth Test
Replies: 1
Views: 558

Strange TCP Bandwidth Test

Hello,

Why TCP Bandwidth Test is sawtooth graph?

To 100M ISP1 WAN link:
image_bwtest_tcp_100M.png
To 200M ISP2 WAN link:
image_bwtest_tcp_200M.png

UDP test perfectly smooth with 0 lost packets even at full link speed.
by mikruser
Thu Jul 09, 2020 8:30 pm
Forum: General
Topic: Feature Request: IPerf
Replies: 55
Views: 15237

Re: Feature Request: IPerf

+1 for iperf with charts
by mikruser
Thu Jul 09, 2020 4:36 pm
Forum: General
Topic: Is it possible to use source based routing without Mangle?
Replies: 16
Views: 2454

Re: Is it possible to use source based routing without Mangle?

Now I'm using this Mangle rule:
add action=mark-routing chain=prerouting dst-address-list=!LAN_private new-routing-mark=to_ISP3 passthrough=no src-address=192.168.0.1
by mikruser
Thu Jul 09, 2020 2:55 pm
Forum: General
Topic: Is it possible to use source based routing without Mangle?
Replies: 16
Views: 2454

Re: Is it possible to use source based routing without Mangle?

I already wrote what I want - I need the default route for packets from 192.168.0.1
by mikruser
Thu Jul 09, 2020 2:25 pm
Forum: General
Topic: ipv4 neighbor table overflow
Replies: 9
Views: 5292

Re: ipv4 neighbor table overflow

I also have this issuue! (CHR v6.45.9)
by mikruser
Thu Jul 09, 2020 1:23 pm
Forum: General
Topic: Is it possible to use source based routing without Mangle?
Replies: 16
Views: 2454

Re: Is it possible to use source based routing without Mangle?

in this case, the use of Route Rules is not suitable, and I am forced to use the mangle.
by mikruser
Thu Jul 09, 2020 1:13 pm
Forum: General
Topic: Is it possible to use source based routing without Mangle?
Replies: 16
Views: 2454

Re: Is it possible to use source based routing without Mangle?

see my first message with image - I need default route with source based routing.
by mikruser
Thu Jul 09, 2020 12:23 pm
Forum: General
Topic: Is it possible to use source based routing without Mangle?
Replies: 16
Views: 2454

Re: Is it possible to use source based routing without Mangle?

but routing rule doesn't work as expected with the default route (dst.address=0.0.0.0/0). I expected to see specific routes (in Routes tab in main table) first, and only if no specific route is found will the default route rule be used. but this rule sends absolutely all packets from 192.168.0.1 to ...
by mikruser
Wed Jul 08, 2020 11:33 pm
Forum: General
Topic: How to create multichannel VPN tunnel?
Replies: 6
Views: 1206

Re: How to create multichannel VPN tunnel?

In that case, why I do not get a speed boost (through using SMB Multichannel) when I copy a file through a tunnel?
by mikruser
Wed Jul 08, 2020 11:18 pm
Forum: General
Topic: Is it possible to use source based routing without Mangle?
Replies: 16
Views: 2454

Re: Is it possible to use source based routing without Mangle?

Mikrotik Wiki do not have information about "Rules" tab settings for unknown reasons (https://wiki.mikrotik.com/wiki/Manual:IP/Route)
can you give more information?
by mikruser
Wed Jul 08, 2020 10:54 pm
Forum: General
Topic: Is it possible to use source based routing without Mangle?
Replies: 16
Views: 2454

Is it possible to use source based routing without Mangle?

Hello,

Is it possible to use source based routing without Mangle and marking?
I just need to add a field "Src.Address" to the standard Route form:
image_source_based_routing.png
by mikruser
Wed Jul 08, 2020 4:42 pm
Forum: RouterBOARD hardware
Topic: Fancon IRQ
Replies: 0
Views: 413

Fancon IRQ

Hello,

is it normal for a Fancon to generate so many IRQ? ~1400 per "tick".
image_fancon_irq_ccr.png

CCR1009, v6.47
by mikruser
Tue Jul 07, 2020 9:07 pm
Forum: General
Topic: How to create multichannel VPN tunnel?
Replies: 6
Views: 1206

Re: How to create multichannel VPN tunnel?

>>you may try to spread the traffic among multiple tunnels but many tunnels will require many public ip-addresses... and I may need 8 or 16 connections to fully utilize wan link... maybe there's a way to create tunnels not on different ip-addresses, but on different ports of the same address? >>You...
by mikruser
Tue Jul 07, 2020 4:46 pm
Forum: General
Topic: How to create multichannel VPN tunnel?
Replies: 6
Views: 1206

How to create multichannel VPN tunnel?

Hello, We have two offices connected via high latency high speed WAN links. This WAN links show good speed only with multiple connections. Offices connected via GRE+Ipsec tunnel. For file copy we use Windows10 PC's with network adapter that support Receive Side Scaling (RSS) and SMB Multichannel (4 ...
by mikruser
Sat Jul 04, 2020 12:30 am
Forum: Wireless Networking
Topic: hap ac2 do not see my AP in 5GHz band
Replies: 1
Views: 607

hap ac2 do not see my AP in 5GHz band

Hello,
I have WiFi on Ubiquiti AP Pro (one SSID on 2.4 and 5GHz).
Any device work without problem on both band.
But Mikrotik hap ac2 (station mode) do not see my SSID on 5 GHz band.
Why?
by mikruser
Fri Jul 03, 2020 3:51 pm
Forum: General
Topic: Suggestion: Ethernet Cable Test analog signal information
Replies: 0
Views: 348

Suggestion: Ethernet Cable Test analog signal information

Hello,
Please add to Ethernet Cable Test analog signal information like signal strength, signal-to-noise ratio, etc. for each pair. (like Fluke tester)
by mikruser
Thu Jul 02, 2020 7:15 pm
Forum: General
Topic: How do you check some port for availability from a router?
Replies: 8
Views: 1029

Re: How do you check some port for availability from a router?

that you don't understand?
You're on a mikrotik router (for example via winbox).
Now you need to check for port availability at some address (for example 1.2.3.4:945 or 5.6.7.8:1843)
by mikruser
Thu Jul 02, 2020 4:47 pm
Forum: General
Topic: How do you check some port for availability from a router?
Replies: 8
Views: 1029

Re: How do you check some port for availability from a router?

You do not understand the question.
by mikruser
Thu Jul 02, 2020 3:40 pm
Forum: General
Topic: How do you check some port for availability from a router?
Replies: 8
Views: 1029

How do you check some port for availability from a router?

Hello,

how do you check some ip:port for availability from a mikrotik router?
by mikruser
Tue May 19, 2020 5:23 pm
Forum: General
Topic: Why hashing done in software?
Replies: 0
Views: 455

Why hashing done in software?

Hello,

https://wiki.mikrotik.com/wiki/Manual:I ... celeration
x86 (AES-NI) ***
*** AES-CBC and AES-CTR only encryption is accelerated, hashing done in software.


Why hashing is not hardware accelerated?
AMD CPU support SHA extensions: https://en.wikipedia.org/wiki/Intel_SHA_extensions
by mikruser
Thu May 07, 2020 1:11 am
Forum: General
Topic: High CPU usage
Replies: 6
Views: 1343

Re: High CPU usage

I know what's loading the CPU.
My question is, why so much?
One EPYC Rome core can do 1.7 GBytes/s AES encryption.
Two cores can 2*1.7*8=27 Gbits/s
My traffic is very small, only 0.5 Gbit/s
CPU load caused by encryption should be lower than 2%
by mikruser
Wed May 06, 2020 4:59 pm
Forum: General
Topic: High CPU usage
Replies: 6
Views: 1343

High CPU usage

Hello,

I have ESXi 6.7U3 host with AMD EPYC 7502P processor, and VM (2 vCPU) with CHR 6.45.8
On CHR created vpn-tunnel GRE+IPsec (aes-128 ctr sha1)

When i do vMotion via this tunnel at speed 500 Mbit/s, this cause VM CPU usage 45%

Why CPU usage so high?
by mikruser
Thu Apr 23, 2020 2:06 am
Forum: General
Topic: FEATURE REQUEST: Dynamically created VPN+routes (each to each)
Replies: 1
Views: 856

FEATURE REQUEST: Dynamically created VPN+routes (each to each)

For example - you have multiple offices: HQ-office and branch-offices, each office have piblic IP and private subnet. Very simple solution: HQ-office Mikrotik (master) and branch-offices Mikrotik (slave) have this table: public_ip, private_subnet 1.1.1.1, 192.168.1.0/24 2.2.2.2, 192.168.2.0/24 ........
by mikruser
Thu Feb 13, 2020 7:31 pm
Forum: General
Topic: Suggestion: view packets on Rule
Replies: 0
Views: 1547

Suggestion: view packets on Rule

Hello,

Please add button "View packets" (like Torch or Sniffer) on Rule Statistics tab!
by mikruser
Fri Jan 31, 2020 6:17 pm
Forum: General
Topic: How to disable promiscuous mode?
Replies: 2
Views: 877

How to disable promiscuous mode?

Hello,
How to disable promiscuous mode on ether1?
by mikruser
Wed Jan 29, 2020 12:57 pm
Forum: Announcements
Topic: v6.45.8 [long-term] is released!
Replies: 87
Views: 64820

Re: v6.45.8 [long-term] is released!

there are no other versions between them
Image_.png
by mikruser
Wed Jan 29, 2020 11:48 am
Forum: Announcements
Topic: v6.45.8 [long-term] is released!
Replies: 87
Views: 64820

Re: v6.45.8 [long-term] is released!

>>Changes since 6.45.7
previous version was 6.44.6
by mikruser
Tue Jan 28, 2020 5:53 pm
Forum: General
Topic: NetFlow. No longer showing NAT'd destination address - Something chnaged
Replies: 30
Views: 5393

Re: NetFlow. No longer showing NAT'd destination address - Something chnaged

I have same issue as described in mdpeterman first post.
NetFlow Analyzer -> Inventory -> Devices-> SomeRouter -> InternalInterface -> Destination (OUT)
shows me external public IP instead of internal private ip-addresses
by mikruser
Tue Jan 28, 2020 5:37 pm
Forum: General
Topic: NetFlow. No longer showing NAT'd destination address - Something chnaged
Replies: 30
Views: 5393

Re: NetFlow. No longer showing NAT'd destination address - Something chnaged

maybe you do not understand my message?

I also have this issue
by mikruser
Tue Jan 28, 2020 12:11 pm
Forum: General
Topic: NetFlow. No longer showing NAT'd destination address - Something chnaged
Replies: 30
Views: 5393

Re: NetFlow. No longer showing NAT'd destination address - Something chnaged

all of these items are already selected by default
by mikruser
Mon Jan 27, 2020 1:54 pm
Forum: General
Topic: NetFlow. No longer showing NAT'd destination address - Something chnaged
Replies: 30
Views: 5393

Re: NetFlow. No longer showing NAT'd destination address - Something chnaged

Also have this issue!

6.44.6, Traffic Flow Version: 9

How to fix it?
by mikruser
Tue Jan 21, 2020 4:28 pm
Forum: General
Topic: GRE issues with dual WAN
Replies: 4
Views: 747

Re: GRE issues with dual WAN

why did the router send packets from the wrong interface

I do not see your config.
maybe you do not have the necessary mangle output rules,or maybe you do not have the necessary route rules...
by mikruser
Mon Jan 20, 2020 8:04 pm
Forum: General
Topic: GRE issues with dual WAN
Replies: 4
Views: 747

Re: GRE issues with dual WAN

You should exclude PublicIP-to-PublicIP connections from NAT'ing
by mikruser
Wed Jan 15, 2020 12:31 pm
Forum: General
Topic: TCP congestion Illinos
Replies: 5
Views: 1159

Re: TCP congestion Illinos

havrla
illinos is very super for fast and long lines. (VDSL, WIFI, )

"Westwood" is much better:
aed1d4d480366a904cf94a6f3977b383.png
by mikruser
Sun Jan 12, 2020 10:52 pm
Forum: Forwarding Protocols
Topic: TCP port forward doesnt work
Replies: 15
Views: 3287

Re: TCP port forward doesnt work

don't listen to noobs, you no need add public ip to nat rule.

you need add firewall rule:
accept
forward
dst.address=your internal ip
protocol=tcp
dst.port=your internal port
by mikruser
Sun Jan 12, 2020 6:11 pm
Forum: General
Topic: Why MT Wiki contains incomplete information?
Replies: 2
Views: 575

Why MT Wiki contains incomplete information?

for example https://wiki.mikrotik.com/wiki/Manual:IP/Route
do not have information about "Rules" tab settings.
by mikruser
Fri Jan 10, 2020 6:27 pm
Forum: General
Topic: Why gre+ipsec tunnel always use default proposal?
Replies: 3
Views: 565

Re: Why gre+ipsec tunnel always use default proposal?

Because it doesn't work as you think. Proposal is linked to policy and policy is linked to peer. Not the other way around. So what you created just sits there and does nothing, because automatically created peer won't use it. You are wrong. Dynamic policies are generated from a template policy: htt...
by mikruser
Fri Jan 10, 2020 5:49 pm
Forum: General
Topic: Why gre+ipsec tunnel always use default proposal?
Replies: 3
Views: 565

Why gre+ipsec tunnel always use default proposal?

Hello,

I have multiple gre-tunnels with ipsec secret enabled. In gre-tunnel i cannot select custom ipsec proposal.
I created custom IPsec Policy Template (priority#0) for Protocol:47 and custom proposal, but my gre-tunnels still use default proposal.

Why?
by mikruser
Thu Jan 09, 2020 1:33 pm
Forum: General
Topic: ipsec established, but gre tunnel not
Replies: 6
Views: 1065

Re: ipsec established, but gre tunnel not

yeahbunin
read my previous message
by mikruser
Thu Jan 02, 2020 8:12 pm
Forum: General
Topic: Port Forwarding doesn't forward
Replies: 4
Views: 571

Re: Port Forwarding doesn't forward

>>add action=accept chain=forward dst-port=65022 protocol=tcp

you need change port to 22
by mikruser
Thu Jan 02, 2020 4:10 pm
Forum: General
Topic: ipsec established, but gre tunnel not
Replies: 6
Views: 1065

Re: ipsec established, but gre tunnel not

>>Have you specified local and remote addresses of GRE on both routers?
Yes

>>Do you allow proper protocols to pass firewall?
Yes, full access for these addresses (without "IPsec Secret" gre-tunnel link up successfully).

I think this is a bug in ROS...
by mikruser
Thu Jan 02, 2020 9:09 am
Forum: General
Topic: ipsec established, but gre tunnel not
Replies: 6
Views: 1065

ipsec established, but gre tunnel not

Hello, I created GRE tunnel (with IPsec Sercret) between CCR and CHR. (6.44.6) 1) policy created dynamically successfully (ph2 state established) 2) peer created dynamically successfully 3) identities created dynamically successfully 4) remote peers and installed sa created dynamically successfully ...
by mikruser
Thu Dec 26, 2019 6:45 pm
Forum: General
Topic: How to see %lost datagrams of VPN tunnel?
Replies: 0
Views: 707

How to see %lost datagrams of VPN tunnel?

Hello,
Is it possible to see in Winbox %lost datagrams related to outer (connectionless/stateless) protocol of VPN tunnel?
by mikruser
Thu Dec 12, 2019 1:08 pm
Forum: General
Topic: How does AutoMTU work for VPN tunnels?
Replies: 1
Views: 912

How does AutoMTU work for VPN tunnels?

Hello,

How does AutoMTU (Actual MTU) work for VPN tunnels?

For example: i have gre+ipsec tunnels sha1/aes-128 ctr

CCR1009(AMTU1446)----(AMTU1434)RB3011

CCR1009(AMTU1446)----(AMTU1434)hAPac2

Why MTU is different on both sides?
by mikruser
Wed Dec 04, 2019 4:23 pm
Forum: RouterBOARD hardware
Topic: MikroTik MQS
Replies: 34
Views: 9547

Re: MikroTik MQS

Where can I download admin guide with a detailed description of all settings?
by mikruser
Mon Dec 02, 2019 4:37 pm
Forum: General
Topic: How to set priorities for the encryption algorithms in the default IPsec proposal?
Replies: 0
Views: 568

How to set priorities for the encryption algorithms in the default IPsec proposal?

Hello,

How to set priorities for the encryption algorithms in the default IPsec proposal?

I have "aes-128 cbc" and "aes-128 ctr" selected, and need now set priority1 to ctr, and priority2 to cbc.
by mikruser
Thu Nov 28, 2019 2:09 pm
Forum: General
Topic: How to select interface in Bandwidth Test tool?
Replies: 1
Views: 467

How to select interface in Bandwidth Test tool?

Hello,
I have router with 3 WAN interfaces.
How to select interface in Bandwidth Test tool? (like in Traceroute tool)
Image_mikr_bt.png
by mikruser
Wed Nov 27, 2019 5:41 pm
Forum: RouterBOARD hardware
Topic: can't login to MQS [SOLVED]
Replies: 3
Views: 6579

Re: can't login to MQS [SOLVED]

Ok, it works...

but this is a very inconvenient setup method.

please add ability to configure through USB!
by mikruser
Wed Nov 27, 2019 5:30 pm
Forum: RouterBOARD hardware
Topic: can't login to MQS [SOLVED]
Replies: 3
Views: 6579

can't login to MQS [SOLVED]

I'm trying login to MQS as described in https://i.mt.lv/cdn/rb_files/1572339613 ... %20web.pdf
but no success
I can connect to wireless network RBMQS_AP1, but computer can't get ip address.
I'm trying reset MQS, but no success.
by mikruser
Sat Nov 23, 2019 5:43 pm
Forum: General
Topic: Block a huge list of IP-addresses [SOLVED]
Replies: 17
Views: 2201

Re: Block a huge list of IP-addresses [SOLVED]

use blackhole route
by mikruser
Fri Nov 22, 2019 5:33 pm
Forum: General
Topic: Feature request: Virtual Interface
Replies: 36
Views: 6970

Re: Feature request: Virtual Interface

Any news about implementing this feature (VI)?

ISP gave me an additional IP-address on a different subnet.
Now i need create additional (virtual) interface on ether1. MAC address must be different.
by mikruser
Fri Nov 01, 2019 3:10 pm
Forum: General
Topic: Suggestion: VPN over ICMP
Replies: 3
Views: 1205

Re: Suggestion: VPN over ICMP

Absolutely incorrect.
Normal providers do not touch transit icmp traffic.
by mikruser
Fri Oct 25, 2019 5:36 pm
Forum: General
Topic: What type of tunnel should be used in this case?
Replies: 1
Views: 543

What type of tunnel should be used in this case?

Hello, What type of vpn tunnel should be used in this case: 1) server and clients are Mikrotik routers. 2) server have public ip address. 3) all clients have private ip addresses (behind nat). 4) some clients behind same nat (l2tp+ipsec do not work in this case). 5) MPPE encryption or certificates s...
by mikruser
Fri Oct 25, 2019 2:17 pm
Forum: General
Topic: Bug
Replies: 5
Views: 718

Re: Bug

mikrotik's "stable" = beta version in real life
by mikruser
Fri Oct 25, 2019 12:25 pm
Forum: General
Topic: Bug
Replies: 5
Views: 718

Re: Bug

6.44.5
by mikruser
Thu Oct 24, 2019 7:48 pm
Forum: General
Topic: Bug
Replies: 5
Views: 718

Bug

Interface lte1 - General - APN Profile:
this setting is not remembered between reboots
by mikruser
Tue Oct 15, 2019 1:18 pm
Forum: RouterBOARD hardware
Topic: New High Performance Routers ! ?
Replies: 48
Views: 11368

Re: New High Performance Routers ! ?

doneware NAT - is not really a CPU intensive process but in real life author writes something else: doush Router only does NAT and nothing else. CCR1072 CPU consumption is %50 with 18gbit/s total throuput + firewall + NAT plus some cores hitting %80. doneware using a dedicated CPU instruction set (...
by mikruser
Sat Oct 12, 2019 8:58 pm
Forum: RouterBOARD hardware
Topic: New High Performance Routers ! ?
Replies: 48
Views: 11368

Re: New High Performance Routers ! ?

I am very surprised that Mikrotik does not use hardware NAT'ing.
by mikruser
Wed Aug 28, 2019 12:07 am
Forum: General
Topic: Suggestion: VPN over ICMP
Replies: 3
Views: 1205

Suggestion: VPN over ICMP

Hello,
Please implement VPN over ICMP (ICMP Tunnel)
(it can be very useful in some countries with a totalitarian regime)))
by mikruser
Sun Aug 04, 2019 7:41 pm
Forum: RouterBOARD hardware
Topic: GPeR question
Replies: 23
Views: 7157

Re: GPeR question

normis
Tue Jul 30, 2019 9:57 am
The GPER is a passive device that connects wires together, you can call it Layer1. This is not really a hub.

normis
Fri Aug 02, 2019 3:14 pm
Yes, there is a basic switch chip inside.


Two completely different answers.
You are Dr Jekyll and Mr Hyde??
by mikruser
Thu Aug 01, 2019 12:39 pm
Forum: RouterBOARD hardware
Topic: GPeR question
Replies: 23
Views: 7157

Re: GPeR question

If GPER is just a passive device that connects wires together, then the price is perplexing (50% of Raspberry Pi 4 computer)
by mikruser
Mon Jul 29, 2019 10:31 pm
Forum: RouterBOARD hardware
Topic: GPeR question
Replies: 23
Views: 7157

Re: GPeR question

1) Of course it matters (and two port has nothing to do with it)
2) ???
3) Ok
by mikruser
Mon Jul 29, 2019 12:20 pm
Forum: RouterBOARD hardware
Topic: GPeR question
Replies: 23
Views: 7157

GPeR question

Hello,
1) at what OSI layer this device work? at L1 like hub, or at L2 like switch?
2) what delay does this device add?
3) why distance is limited to 1500 m?
by mikruser
Tue Jun 11, 2019 1:03 pm
Forum: General
Topic: SNMP traffic monitoring bug
Replies: 2
Views: 576

SNMP traffic monitoring bug

Hello,

CHR 6.44.2
PRTG Network Monitor SNMP Traffic sensor

When i copy file via gigabit adapter, SNMP sensor show only 430 Mbit/s

This is a bug in Mikrotik SNMP or in PRTG?
Image1_snmp_.png
by mikruser
Tue Apr 23, 2019 1:38 pm
Forum: General
Topic: Suggestion: Protocols for Bandwidth Test
Replies: 0
Views: 561

Suggestion: Protocols for Bandwidth Test

Hello,

please add not only udp and tcp, but also protocols 4, 47, 50.
by mikruser
Fri Mar 22, 2019 12:08 pm
Forum: General
Topic: GRE over IPSEC, CCR, VERY SLOW
Replies: 39
Views: 17881

Re: GRE over IPSEC, CCR, VERY SLOW

GRE+IPsec still slow:
viewtopic.php?f=2&t=146665
by mikruser
Mon Mar 18, 2019 6:49 pm
Forum: General
Topic: Slow speed through gre+ipsec tunnel
Replies: 11
Views: 3778

Slow speed through gre+ipsec tunnel

Hello, CHR, 6.44.1, 2 vcpu Xeon Gold CCR1009, 6.44.1 WAN with 45 ms latency [CHR]---wan(tunnel gre+ipsec)wan---[CCR1009] aes128cbc/sha1, Actual MTU = 1426 (Auto) OR aes128ctr/sha1, Actual MTU = 1446 (Auto) Bandwidth Test on CHR to CCR (tcp, receive, 1 connection): between public ip = up to 300 Mbps ...
by mikruser
Mon Mar 18, 2019 5:53 pm
Forum: General
Topic: Please add the ability to choose Proposal
Replies: 11
Views: 2453

Re: Please add the ability to choose Proposal

All my tunnels are configured with IPsec Secret enabled, and I will not change it.

We simply need the ability to choose Proposal for each tunnel.
by mikruser
Mon Mar 18, 2019 4:45 pm
Forum: General
Topic: Please add the ability to choose Proposal
Replies: 11
Views: 2453

Re: Please add the ability to choose Proposal

I still do not see any real benefit of your request. It literally takes 2 seconds to change proposal value for your policies to a different one. /ip ipsec proposal add name=newproposal copy-from=default /ip ipsec policy set [find proposal=default] proposal=newproposal I was just posting this exact ...
by mikruser
Thu Mar 07, 2019 12:19 pm
Forum: General
Topic: Why AES CTR is not hardware accelerated on the CHR?
Replies: 1
Views: 422

Why AES CTR is not hardware accelerated on the CHR?

Hello,

Why AES CTR is not hardware accelerated on the CHR?
Image_chr_.png
by mikruser
Mon Mar 04, 2019 11:58 am
Forum: General
Topic: Does the System\Watchdog on the CHR make sense?
Replies: 0
Views: 428

Does the System\Watchdog on the CHR make sense?

Hello,

Does the System\Watchdog on the CHR make sense?
Can he restart the VM if CHR hangs?
by mikruser
Thu Feb 21, 2019 11:49 am
Forum: General
Topic: vlan question
Replies: 6
Views: 956

Re: vlan question

but I don't want to create additional vlan interfaces
by mikruser
Thu Feb 21, 2019 11:25 am
Forum: General
Topic: vlan question
Replies: 6
Views: 956

Re: vlan question

I can not merge bridges, because bridges have different ip-addresses and dhcp-servers on them.
by mikruser
Wed Feb 13, 2019 6:23 pm
Forum: General
Topic: vlan question
Replies: 6
Views: 956

vlan question

Hello, We have routerboard with ether2 and ether3 - in bridge1 ether4 and ether5 - in bridge2 now we need special port ether6 which should be a member of both bridges, but in bridge1 as untagged default vlan (vlan1), and in bridge2 as tagged vlan2. This is can be done very simply on a managed switch...
by mikruser
Fri Feb 08, 2019 5:01 pm
Forum: General
Topic: Why Fast Path not supported with hardware accelerated IPsec?
Replies: 1
Views: 627

Why Fast Path not supported with hardware accelerated IPsec?

Hello,

Why Fast Path not supported with hardware accelerated IPsec?
by mikruser
Mon Jan 21, 2019 11:12 am
Forum: General
Topic: restore to different hardware
Replies: 5
Views: 929

Re: restore to different hardware

I see a very large number of messages
expected end of command

looking at all, export/import procedure is very bugged on Mikrotik
by mikruser
Mon Jan 21, 2019 10:42 am
Forum: General
Topic: restore to different hardware
Replies: 5
Views: 929

Re: restore to different hardware

but cli command /import do not work:

expected end of command (line 24 column 26)
by mikruser
Fri Jan 18, 2019 6:28 pm
Forum: General
Topic: restore to different hardware
Replies: 5
Views: 929

restore to different hardware

How to copy configuration from router1 to router2 (different hardware)?
I see this post: viewtopic.php?t=115073
My question: how to export and import via Winbox GUI? (not via terminal cli!)
by mikruser
Tue Jan 15, 2019 11:35 am
Forum: General
Topic: Suggestion: drag and drop rules between routers
Replies: 1
Views: 677

Suggestion: drag and drop rules between routers

Hello,

please add the ability to drag and drop (copy) rules (and other stuff) from one Winbox window to another Winbox window.
by mikruser
Thu Dec 27, 2018 11:41 am
Forum: General
Topic: Cannot connect to L2TP server from Windows 7: no suitable proposal found [SOLVED]
Replies: 3
Views: 2247

Re: Cannot connect to L2TP server from Windows 7: no suitable proposal found [SOLVED]

in case there is NAT between server and client: google "AssumeUDPEncapsulationContextOnSendRule"
Thanks, it helped!
by mikruser
Thu Dec 27, 2018 10:50 am
Forum: General
Topic: Cannot connect to L2TP server from Windows 7: no suitable proposal found [SOLVED]
Replies: 3
Views: 2247

Cannot connect to L2TP server from Windows 7: no suitable proposal found [SOLVED]

Hello, CCR1009, 6.43.8 cannot connect to L2TP server from Windows 7 and Windows 2008 R2. ipsec, error no suitable proposal found. ipsec, error x.x.x.x failed to get valid proposal. ipsec, error x.x.x.x failed to pre-process ph1 packet (side: 1, status 1). ipsec, error x.x.x.x phase1 negotiation fail...
by mikruser
Tue Dec 25, 2018 12:51 pm
Forum: General
Topic: Question about IKE2
Replies: 0
Views: 431

Question about IKE2

What types of authentication does Mikrotik router support with Windows client?
Only "Use machine certificates"? Or also "Use EAP"?
by mikruser
Mon Dec 17, 2018 10:22 am
Forum: General
Topic: Ipsec peers
Replies: 0
Views: 456

Ipsec peers

Hello, I already have several ipsec peers with unique ip addresses (it is used for l2tp/ipsec site-to-site vpn's). Now I need to make a IKEv2 server for incoming connections from remote notebooks. For this i need to create ipsec peer with address 0.0.0.0/0. Is it possible to use this peer with other...
by mikruser
Tue Nov 27, 2018 3:57 pm
Forum: General
Topic: Backup/restore without mac-addresses
Replies: 2
Views: 1004

Re: Backup/restore without mac-addresses

My question about Backup/Restore

(Import/Export do not work on my devices)
by mikruser
Tue Nov 27, 2018 3:39 pm
Forum: General
Topic: Backup/restore without mac-addresses
Replies: 2
Views: 1004

Backup/restore without mac-addresses

Hello,

How to backup config without mac-addresses?
or how to restore config without changing mac-addresses?
by mikruser
Tue Nov 27, 2018 11:51 am
Forum: General
Topic: Backup/ Restore issue and duplicating Ethernet MAC address [SOLVED]
Replies: 4
Views: 2538

Re: Backup/ Restore issue and duplicating Ethernet MAC address [SOLVED]

But why i do not see Import/Export in Winbox?
by mikruser
Fri Nov 23, 2018 6:57 pm
Forum: General
Topic: After upgrade to 6.41, Ethernet Interface Bandwidth is gone
Replies: 2
Views: 866

Re: After upgrade to 6.41, Ethernet Interface Bandwidth is gone

up!
Why is it removed from Winbox GUI???
(but it is still available from command line: /interface ethernet set ether1 bandwidth=unlimited/unlimited)
by mikruser
Wed Nov 07, 2018 12:20 pm
Forum: General
Topic: Сan't rename interface [SOLVED]
Replies: 3
Views: 871

Re: Сan't rename interface [SOLVED]

After the command /interface ethernet set ether4-local bandwidth=unlimited/unlimited
I was able to rename the interface
by mikruser
Wed Nov 07, 2018 11:57 am
Forum: General
Topic: Сan't rename interface [SOLVED]
Replies: 3
Views: 871

Re: Сan't rename interface [SOLVED]

I have this problem again after restoring the configuration
by mikruser
Wed Nov 07, 2018 11:20 am
Forum: General
Topic: Сan't rename interface [SOLVED]
Replies: 3
Views: 871

Сan't rename interface [SOLVED]

RB750Gr3
ROS 6.43.4
Winbox 3.18

restoring configuration incorrectly restored interfaces, and I need to rename them
but when I try to change the name I get an error: Couldn't change Interface - not supported on this interface (6)
Image_interface.png
by mikruser
Fri Oct 26, 2018 6:44 pm
Forum: RouterBOARD hardware
Topic: New CPU - new product RB750Gr3 - RB750G family - now mmips
Replies: 180
Views: 76380

Re: New CPU - new product RB750Gr3 - RB750G family - now mmips

When will AES-CTR be added to RB750Gr3?
by mikruser
Fri Oct 26, 2018 1:29 pm
Forum: General
Topic: Suggestion: Reconnect action
Replies: 1
Views: 861

Suggestion: Reconnect action

Hello,

Please add "Reconnect" action to Right Click (Context) menu for all interfaces in Winbox
(reconnect = disable+enable)
by mikruser
Fri Oct 19, 2018 12:45 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 7959

Re: Problem with IPsec after update to 6.42

can you explain your setup and logic behind your policy configuration here? I can not think of a single case where responder should generate a dynamic policy with dst-address=0.0.0.0/0. We have a large number of subnets, and instead of creating a separate policy for each subnet, we create one polic...
by mikruser
Thu Oct 18, 2018 7:56 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 7959

Re: Problem with IPsec after update to 6.42

This behavior can be easily reproduced in the test lab.
by mikruser
Thu Oct 18, 2018 4:42 pm
Forum: Announcements
Topic: v6.43.4 [stable] is released!
Replies: 78
Views: 30980

Re: v6.43.4 [stable] is released!

This is not a configuration issue (this configuration worked fine for 7 years)
problem occurs after upgrade to 6.42.x or 6.43.x
by mikruser
Thu Oct 18, 2018 4:22 pm
Forum: Announcements
Topic: v6.43.4 [stable] is released!
Replies: 78
Views: 30980

Re: v6.43.4 [stable] is released!

This IPsec bug still not fixed viewtopic.php?f=2&t=136445
by mikruser
Thu Oct 18, 2018 1:46 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 7959

Re: Problem with IPsec after update to 6.42

6.43.4 also have this issue!
by mikruser
Fri Oct 05, 2018 1:33 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 5212

Re: Please add performance results for IPsec tunnel!

I also tested two hAP ac^2 with 6.43.2

EoIP with IPsec (aes-128 ctr), file copy is only 34 MB/s:
hapac2_eoip_ipsec_ctr.png
EoIP without IPsec, file copy is 68 MB/s:
hapac2_eoip.png
by mikruser
Wed Oct 03, 2018 6:51 pm
Forum: RouterBOARD hardware
Topic: RB751-U-2nHD 100% cpu
Replies: 20
Views: 6092

Re: RB751-U-2nHD 100% cpu

6.43.2 also have this issue
by mikruser
Tue Oct 02, 2018 12:42 pm
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 112266

Re: v6.44beta [testing] is released!

what is "multiple engine"??
by mikruser
Tue Sep 25, 2018 7:55 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 5212

Re: Please add performance results for IPsec tunnel!

You can use minimal (fastest) config, required for EoIP+IPsec or L2TP+IPsec or GRE+IPsec.
by mikruser
Tue Sep 25, 2018 7:47 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 7959

Re: Problem with IPsec after update to 6.42

6.43.2 also have this issue!
by mikruser
Tue Sep 25, 2018 2:06 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 5212

Re: Please add performance results for IPsec tunnel!

>>The throughput results are there for you to evaluate the IPsec crypto engine performance, not to show you throughput results with various different configurations. IPsec crypto engine performance is a "spherical cow in a vacuum", and does not show real life results. >>check for packet fragmentati...
by mikruser
Tue Sep 25, 2018 12:40 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 5212

Re: Please add performance results for IPsec tunnel!

>>Adding or enabling any additional RouterOS feature apart from IPsec policies can reduce the throughput significantly. That's why I already suggested that you also publish the results for some popular tunnels+ipsec (l2tp+ipsec, gre+ipsec, eoip+ipsec) https://forum.mikrotik.com/viewtopic.php?f=3&t=...
by mikruser
Mon Sep 24, 2018 4:53 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 5212

Re: Please add performance results for IPsec tunnel!

I also tested two RB3011 with 6.43.2, connected via EoIP tunnel with IPsec.
They showed an even lower speed, even with hardware acceleration: file copy only 22 MB/s with aes-128 cbc/ctr (this is very far from declared 407.7 Mbps).
Profile:
rb3011_eoip_ipsec.png
by mikruser
Fri Sep 07, 2018 11:42 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 381
Views: 101972

Re: RB4011

Very unbalanced router
https://i.mt.lv/cdn/rb_files/RB4011iGSp ... 135303.png

Each switch have 5*1G port, but only 2.5G link to CPU.

What for this router have 10G sfp+ port? All switches summary have only 5G throughput.
by mikruser
Mon Sep 03, 2018 2:34 pm
Forum: RouterBOARD hardware
Topic: RB751 CPU usage get too high
Replies: 15
Views: 10529

Re: RB751 CPU usage get too high

I found that even just viewing the settings in the Winbox also often causes a 100% CPU load.

I suspect that the developers simply do not test the latest versions ROS/Winbox on RB751U.
Image100cpu.png
by mikruser
Sat Sep 01, 2018 9:05 pm
Forum: RouterBOARD hardware
Topic: When Mikrotik releases router that can handle single IPsec tunnel at 2.5G, 5G, 10G?
Replies: 1
Views: 765

When Mikrotik releases router that can handle single IPsec tunnel at 2.5G, 5G, 10G?

Hello,

When Mikrotik releases a router that can handle single IPsec tunnel (or MACsec) at 2.5G, 5G, 10G?
by mikruser
Thu Aug 30, 2018 10:52 pm
Forum: General
Topic: How to downgrade the ROS below the factory version?
Replies: 5
Views: 1401

Re: How to downgrade the ROS below the factory version?

May I ask why downgrade to such a vulnerable version? Wouldn't be better to upgrade the other equipment if having the same version on all hardware is important?
Due to a this bug in 6.42.x:
viewtopic.php?t=136445
by mikruser
Thu Aug 30, 2018 6:43 pm
Forum: General
Topic: How to downgrade the ROS below the factory version?
Replies: 5
Views: 1401

Re: How to downgrade the ROS below the factory version?

This is correct behavior.
But why??
We have another hAP ac^2 router and it works fine with version 6.41.4:
Image_hapac2.png
by mikruser
Thu Aug 30, 2018 5:58 pm
Forum: RouterBOARD hardware
Topic: Suggestion: release routers with preinstalled Factory Software from Bugfix release chain
Replies: 6
Views: 1136

Suggestion: release routers with preinstalled Factory Software from Bugfix release chain

Hello,

Suggestion: release routers with preinstalled Factory Software only from Bugfix release chain.
by mikruser
Thu Aug 30, 2018 4:59 pm
Forum: General
Topic: How to downgrade the ROS below the factory version?
Replies: 5
Views: 1401

How to downgrade the ROS below the factory version?

We have hAP ac^2 with Factory Software 6.42.3
How to downgrade the ROS below the factory version (to 6.41.4)?
After /system package downgrade
we get error
error: omitting package system-6.41.4: min RouterOS version is 6.42.3
by mikruser
Wed Aug 29, 2018 12:55 pm
Forum: General
Topic: PCQ - Queue - where to set limit
Replies: 1
Views: 583

Re: PCQ - Queue - where to set limit

see answer in this topic: viewtopic.php?f=1&t=138427#p682693

Cha0s
Have you tried TP-Link or D-Link?

I am sure they are much easier with all their wizards whistles and bells.

If you find RouterOS hard, then it's probably not for you.
by mikruser
Tue Aug 28, 2018 7:15 pm
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 1847

Re: Suggestion: simple speed limiter

Advanced tab also not enough in this case.
by mikruser
Tue Aug 28, 2018 6:06 pm
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 1847

Re: Suggestion: simple speed limiter

we are talking about only first tab
by mikruser
Tue Aug 28, 2018 12:53 pm
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 1847

Re: Suggestion: simple speed limiter

Simple queue is perfectly adequate for this. Just use the first tab.
With only first tab is impossible to perform an elementary task in one queue:
set summary limit + set per IP limit
by mikruser
Sat Aug 25, 2018 3:09 pm
Forum: General
Topic: Feature requests
Replies: 1279
Views: 289728

Re: Feature requests

Feature request: AES hardware acceleration for OpenVPN
by mikruser
Fri Aug 24, 2018 7:04 pm
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 1847

Suggestion: simple speed limiter

Hello,

current Queues has a very large number of settings and a very complex and confusing.

Please add simple speed limiter.
by mikruser
Thu Aug 23, 2018 5:25 pm
Forum: General
Topic: Please add "Benchmark" button to Winbox IP-IPsec-Proposals
Replies: 1
Views: 797

Please add "Benchmark" button to Winbox IP-IPsec-Proposals

Hello,

Please add "Benchmark" button to Winbox IP-IPsec-Proposals
for benchmark selected algorithms "encryption", "decryption", "encryption+decryption" speed on any platform
(like VeraCrypt Tools-Benchmark):
Image_bench.png
by mikruser
Mon Aug 20, 2018 1:26 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 7959

Re: Problem with IPsec after update to 6.42

6.42.7 also have this issue!
by mikruser
Fri Aug 17, 2018 2:04 pm
Forum: General
Topic: Why Fast Path not active?
Replies: 4
Views: 2429

Re: Why Fast Path not active?

IPv4 fast path is automatically used if following conditions are met:

firewal rules are not configured;


LOL, in this case Fast Path absolutely useless
I do not have routerboards without firewall rules
by mikruser
Fri Aug 17, 2018 1:09 pm
Forum: General
Topic: Why Fast Path not active?
Replies: 4
Views: 2429

Why Fast Path not active?

Hello,

Fast Path enabled
But why Fast Path not active?
Image1_fp.png
by mikruser
Thu Aug 16, 2018 1:54 pm
Forum: General
Topic: Suggestion: backup restore wizard
Replies: 0
Views: 521

Suggestion: backup restore wizard

Hello,

Please add to Winbox backup restore wizard:

Interfaces remapping
Interfaces MAC addresses: preserve/reset
DHCP leases: preserve/remove
by mikruser
Wed Aug 08, 2018 4:50 pm
Forum: General
Topic: Please add the ability to choose Proposal
Replies: 11
Views: 2453

Re: Please add the ability to choose Proposal

I already have a configuration with a very large number of Ipsec policies (all these policies use proposal:default).

Now I created a l2tp connection with "Use Ipsec", and i need another custom proposal for this.
by mikruser
Wed Aug 08, 2018 1:11 pm
Forum: General
Topic: Bug after upgrade to 6.42.6
Replies: 4
Views: 1054

Re: Bug after upgrade to 6.42.6

After investigation, I found that the bug is in Firewall-Service Ports-sip
After disable this port, 6.42 also works fine
by mikruser
Wed Aug 08, 2018 12:12 pm
Forum: General
Topic: Please add the ability to choose Proposal
Replies: 11
Views: 2453

Please add the ability to choose Proposal

Hello,

Please add the ability to choose Proposal (in L2tp with "Use IPsec")
by mikruser
Wed Aug 08, 2018 1:07 am
Forum: General
Topic: Suggestion: SMB WAN Accelerator
Replies: 0
Views: 579

Suggestion: SMB WAN Accelerator

Hello,

Please add SMB WAN Accelerator (for high latency VPN links)
like this: https://www.silver-peak.com/applications/cifs-smb
by mikruser
Thu Aug 02, 2018 9:51 pm
Forum: General
Topic: Suggestion: add crypto unit % usage
Replies: 0
Views: 727

Suggestion: add crypto unit % usage

Hello,

Some RouterBoard models have encryption engine.
Central Processing Unit (CPU) and Crypto Processing Unit (CrPU)

But currently in Tools-Profile we can see only CPU % Usage.

Suggestion: please add to Profile also CrPU % Usage.
by mikruser
Tue Jul 31, 2018 2:27 pm
Forum: General
Topic: AES-GCM HW acceleration in CCR
Replies: 10
Views: 1934

Re: AES-GCM HW acceleration in CCR

This topic about CCR
by mikruser
Tue Jul 31, 2018 12:14 pm
Forum: General
Topic: AES-GCM HW acceleration in CCR
Replies: 10
Views: 1934

Re: AES-GCM HW acceleration in CCR

There is a plan to make HW acceleration for GCM. 
Thank you for the confirmation Maris.
As it turned out, the confirmation was not true
by mikruser
Fri Jul 27, 2018 6:43 pm
Forum: General
Topic: chr support fast path?
Replies: 6
Views: 1223

Re: chr support fast path?

The presentation says the VMXNET3 NIC supports fastpath. Are you using that?
CHR always uses VMXNET3
by mikruser
Fri Jul 27, 2018 6:29 pm
Forum: General
Topic: chr support fast path?
Replies: 6
Views: 1223

Re: chr support fast path?

Also have this question.
Any official comments?
Image_chr_fp.png
by mikruser
Fri Jul 27, 2018 3:25 pm
Forum: General
Topic: How to optimize VPN tunnel over high latency link?
Replies: 3
Views: 1104

Re: How to optimize VPN tunnel over high latency link?

Yes, Windows share file copy.
I also tried vSphere vMotion, but it did not exceed 60 Mbit/s.
by mikruser
Fri Jul 27, 2018 12:54 pm
Forum: General
Topic: How to optimize VPN tunnel over high latency link?
Replies: 3
Views: 1104

How to optimize VPN tunnel over high latency link?

Hello, We have WAN-link with 1Gbit/s throughput, but 40 ms latency. iperf3 UDP test really can do 1Gbit/s almost lossless. We have L2TP IPsec tunnel over this WAN-link: LAN1---[CHR]---(l2tp_ipsec_vpn)---[CCR]---LAN2 Now file copy between LAN1 and LAN2 is only 6 MB/s maximum. I try different aes mode...
by mikruser
Thu Jul 26, 2018 2:27 pm
Forum: General
Topic: Bug after upgrade to 6.42.6
Replies: 4
Views: 1054

Re: Bug after upgrade to 6.42.6

I do not see changes in SIP
by mikruser
Thu Jul 26, 2018 11:54 am
Forum: General
Topic: Feature Request: IPerf
Replies: 55
Views: 15237

Re: Feature Request: IPerf

kasparskr

do you can release Traffic Generator for Windows?
by mikruser
Thu Jul 26, 2018 11:35 am
Forum: General
Topic: Bug after upgrade to 6.42.6
Replies: 4
Views: 1054

Bug after upgrade to 6.42.6

Hello, We have this setup: [FreePBX]---[CCR1]---(l2tp_ipsec_tunnel)---[CCR2]---[sip_clients] At night I updated ССR from 6.40.8 to 6.42.6. As a result, about half of sip clients/trunks can not register (FreePbx reboot did not help). After downgrade CCR back to 6.40.8 everything again worked fine. Wh...
by mikruser
Thu Jul 26, 2018 5:13 am
Forum: General
Topic: Please add to l2tp client Dial Out page "IPsec proposal" field
Replies: 0
Views: 585

Please add to l2tp client Dial Out page "IPsec proposal" field

Hello,

Please add to l2tp client Dial Out page "IPsec proposal" field
by mikruser
Thu Jul 26, 2018 4:40 am
Forum: General
Topic: "unclassified" cpu usage during btest
Replies: 1
Views: 1076

"unclassified" cpu usage during btest

Hello,

What is "unclassified"?
Image1_btest_profile.png
by mikruser
Wed Jul 25, 2018 7:03 pm
Forum: General
Topic: Question about Tools - Bandwidth Test (tcp)
Replies: 0
Views: 424

Question about Tools - Bandwidth Test (tcp)

Hello,

Question about Tools - Bandwidth Test

What TCP Window Size does the test use?
by mikruser
Wed Jul 25, 2018 5:34 pm
Forum: General
Topic: btest - Where Is
Replies: 7
Views: 69200

Re: btest - Where Is

Any official info about Bandwidth Test for Windows?
by mikruser
Sun Jul 22, 2018 12:51 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 1452

Re: 2-in-1 ? [SOLVED]

Thanks, it works. You are a genius.
by mikruser
Sat Jul 21, 2018 11:15 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 1452

Re: 2-in-1 ? [SOLVED]

>>You may start by removing the additional 2.2.2.x addresses in your current setup

these are the necessary addresses, they must be accessible from the Internet
by mikruser
Sat Jul 21, 2018 11:13 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 1452

Re: 2-in-1 ? [SOLVED]

>>simply remove one Ethernet interface from an existing bridge and add IP address 2.2.2.1/27 to that interface.
which Ethernet interface?
from which bridge?
why only 2.2.2.1?

I do not see it in your diagram
by mikruser
Sat Jul 21, 2018 10:40 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 1452

Re: 2-in-1 ? [SOLVED]

On your diagram I do not see addresses from 2.2.2.0/24 subnet. (on my diagram these 30 addresses resides on Mikrotik2 <2.2.2.2>interface as additional addresses)
by mikruser
Sat Jul 21, 2018 9:39 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 1452

Re: 2-in-1 ? [SOLVED]

Аbsolutely did not understand you.
Could you draw a diagram with addresses from my example?
by mikruser
Sat Jul 21, 2018 6:23 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 1452

Re: 2-in-1 ? [SOLVED]

>>what is currently between the two Mikrotiks nothing. direct connection. Post the current configurations of both Mikrotiks For example (Mikrotik #1 is only routing, #2 routing and NAT): (Internet, provider gateway)---(1.1.1.0/30)---<1.1.1.1>[Mikrotik1]<2.2.2.1>---(2.2.2.0/24)---<2.2.2.2>[Mikrotik2...
by mikruser
Sat Jul 21, 2018 6:01 pm
Forum: Virtualization
Topic: CHR and KVM
Replies: 1
Views: 2605

CHR and KVM

Hello,
When i try Make RouterOS Image, i get error:
Couldn't start - this is not a host system
Image_kvm_chr.png
by mikruser
Sat Jul 21, 2018 3:35 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 1452

Re: 2-in-1 ? [SOLVED]

How possible create router inside router? Using VRF? KVM? Or more simple solution?
by mikruser
Sat Jul 21, 2018 3:09 am
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 1452

2-in-1 ? [SOLVED]

Hello, Currently i have this: (Internet)---(MyPublicSubnet1)---[Mikrotik1]---(MyPublicSubnet2)---[Mikrotik2]---(MyPrivateSubnet) MyPublicSubnet1 with 2 public ip MyPublicSubnet2 with 30 public ip Mikrotik1 is only routing Mikrotik2 is routing, nat, l2tp_ipsec_vpn My question: it is possible to creat...
by mikruser
Thu Jul 19, 2018 12:59 pm
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 3169

Re: Please add numbers on Y-axis in Bandwidth Test

Bandwidth Test shows results every 1 second. Snmp monitoring software can not show so frequently.
by mikruser
Thu Jul 19, 2018 12:35 pm
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 3169

Re: Please add numbers on Y-axis in Bandwidth Test

this is a joke? how do you imagine a bandwidth test through snmp?
by mikruser
Thu Jul 19, 2018 12:15 pm
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 3169

Re: Please add numbers on Y-axis in Bandwidth Test

we need more than one number, we need a few numbers (at least two - at the bottom and at the top)
image_bt_num.png
by mikruser
Thu Jul 19, 2018 12:04 pm
Forum: General
Topic: Feature requests
Replies: 1279
Views: 289728

Re: Feature requests

by mikruser
Thu Jul 19, 2018 11:39 am
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 3169

Re: Please add numbers on Y-axis in Bandwidth Test

We need numbers on the Y-axis so that they can be seen in the screenshots (if you do not understand this from the first message).
by mikruser
Thu Jul 19, 2018 11:09 am
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 3169

Re: Please add numbers on Y-axis in Bandwidth Test

vecernik87
You are troll? Try mouse over my screenshot.
by mikruser
Fri Jul 13, 2018 10:10 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 7959

Re: Problem with IPsec after update to 6.42

>>I am running several IPsec tunnels using various 6.42.x versions and things like this do not happen

You also use 0.0.0.0/0 in Src.Address (and Generate Policy on other side)?
by mikruser
Fri Jul 13, 2018 7:05 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 7959

Re: Problem with IPsec after update to 6.42

I found a bug in the 6.42.x version:
6.42 generate policy with incorrect Dst.Address: instead of 0.0.0.0/0 (in 6.41) i see public ip of remote router (in 6.42)

Mikrotik, please fix this bug ASAP!
by mikruser
Fri Jul 13, 2018 5:08 pm
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 3169

Please add numbers on Y-axis in Bandwidth Test

Hello,

Please add numbers on Y-axis in Bandwidth Test
image_bt.png
by mikruser
Fri Jul 06, 2018 5:12 pm
Forum: General
Topic: CHR do not support hardware acceleration (AES-NI)?
Replies: 0
Views: 506

CHR do not support hardware acceleration (AES-NI)?

Hello,

I create l2tp ipsec tunnel (sha1 aes-128-cbc) Encoding: cbc(aes) + hmac(sha1)
It work, but without hardware acceleration: show E (E-ESP) instead of EH (E-ESP H-Hardware AEAD)

ESXi 6.7, CHR 6.42.5
by mikruser
Wed Jul 04, 2018 3:40 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 7959

Problem with IPsec after update to 6.42

Hello,
After updating from 6.41.4 to 6.42.5 the traffic does not go through the tunnel (tunnel is established, but the traffic does not go).
After downgrade to 6.41.4 everything works fine again.

What changes in 6.42. led to this?
by mikruser
Sun May 27, 2018 11:53 pm
Forum: General
Topic: How to see real (physical) ether interface number?
Replies: 3
Views: 719

How to see real (physical) ether interface number?

Hello,
The interface Name can be anything and does not match the real (physical) number. (for example: ether interface number 2 can have Name 'ether5')
How to see real (physical) ether interface number? (remote, via Winbox)
by mikruser
Wed Mar 21, 2018 1:28 pm
Forum: RouterBOARD hardware
Topic: S+RJ10 question
Replies: 0
Views: 575

S+RJ10 question

Hello,

Is the module S+RJ10 (https://mikrotik.com/product/s_rj10) compatible with other vendor switches (like HPE, Dell, etc)?
by mikruser
Fri Mar 16, 2018 4:09 pm
Forum: General
Topic: Please add ability to connect to neighbors via MAC Winbox
Replies: 6
Views: 2718

Re: Please add ability to connect to neighbors via MAC Winbox

>>Remeber that neighbours seen by the router on the "other end" of interface could not be reachable from your LAN segment.

Router on the "other end" should act as a "proxy for winbox" in this case.
by mikruser
Fri Mar 16, 2018 2:47 pm
Forum: General
Topic: Please add ability to connect to neighbors via MAC Winbox
Replies: 6
Views: 2718

Re: Please add ability to connect to neighbors via MAC Winbox

I do not see "MAC Winbox" in your red circle
by mikruser
Fri Mar 16, 2018 12:50 pm
Forum: General
Topic: Please add ability to connect to neighbors via MAC Winbox
Replies: 6
Views: 2718

Please add ability to connect to neighbors via MAC Winbox

Hello,

Please add ability to connect to remote neighbors via MAC Winbox
(Menu "IP" - "Neighbors")
by mikruser
Tue Mar 13, 2018 6:33 pm
Forum: RouterBOARD hardware
Topic: Overclocking is officially supported?
Replies: 1
Views: 1697

Overclocking is officially supported?

Hello,

Some models can be overclocked +25% via System - Routerboard - Settings - CPU Frequency.
Is it officially supported? In this case, do we need special conditions for this (eg additional cooling)?
cpu_rb951.png
cpu_hapac2.png
by mikruser
Mon Mar 12, 2018 9:28 pm
Forum: General
Topic: L2TP VPN Tunnel problem
Replies: 4
Views: 4546

Re: L2TP VPN Tunnel problem

Any answer from Mikrotik?
When will you fix this bug?
This is a very serious problem!
by mikruser
Fri Feb 16, 2018 12:28 pm
Forum: RouterBOARD hardware
Topic: RB750Gr3 with PoE. When?
Replies: 6
Views: 2162

Re: RB750Gr3 with PoE. When?

No, i mean RB750Gr3
by mikruser
Fri Feb 16, 2018 11:38 am
Forum: RouterBOARD hardware
Topic: RB750Gr3 with PoE. When?
Replies: 6
Views: 2162

RB750Gr3 with PoE. When?

Hello,

When we can expect the appearance hEX (RB750Gr3) with PoE out (802.3af/at)?
by mikruser
Wed Feb 14, 2018 11:41 am
Forum: General
Topic: L2TP VPN Tunnel problem
Replies: 4
Views: 4546

Re: L2TP VPN Tunnel problem

Also have this issue CCR1009, 6.39.3 sometime l2tp tunnel cannot connect: l2tp-out1: initializing... l2tp-out1: connecting... l2tp-out1: terminating... - session closed l2tp-out1: disconnected... l2tp-out1: initializing... l2tp-out1: connecting... l2tp-out1: terminating... - old tunnel is not closed...
by mikruser
Sat Feb 10, 2018 9:39 pm
Forum: RouterBOARD hardware
Topic: dual-band access point
Replies: 4
Views: 834

Re: dual-band access point

You can see it on Specifications page for all dual-band AP:

https://mikrotik.com/product/RB962UiGS-5HacT2HnT
https://mikrotik.com/product/cap_ac
https://mikrotik.com/product/hap_ac2
Image_mikr_ap.png
i do not see "a" and "n" for 5 GHz...
by mikruser
Fri Feb 09, 2018 4:58 pm
Forum: RouterBOARD hardware
Topic: dual-band access point
Replies: 4
Views: 834

dual-band access point

Hello,

Mikrotik dual-band SOHO access point really do not support "n" and "a" standards in 5 GHz?
by mikruser
Wed Jan 31, 2018 5:58 pm
Forum: General
Topic: After upgrade to 6.41, Ethernet Interface Bandwidth is gone
Replies: 2
Views: 866

After upgrade to 6.41, Ethernet Interface Bandwidth is gone

Hello, We have many devices with 6.39.3 and use setting in Interfaces - Ethernet - General - Bandwidth (Rx/Tx) (https://wiki.mikrotik.com/wiki/Manual:Interface/Ethernet) After upgrade to 6.41 this option is gone. Changelog do not have any info about this! https://mikrotik.com/download/changelogs/cur...
by mikruser
Thu Jan 25, 2018 2:03 pm
Forum: RouterBOARD hardware
Topic: RB751-U-2nHD 100% cpu
Replies: 20
Views: 6092

Re: RB751-U-2nHD 100% cpu

you do not see first post?
by mikruser
Wed Jan 24, 2018 6:20 pm
Forum: RouterBOARD hardware
Topic: RB751-U-2nHD 100% cpu
Replies: 20
Views: 6092

Re: RB751-U-2nHD 100% cpu

any comments from Mikrotik?
by mikruser
Wed Jan 17, 2018 1:05 pm
Forum: RouterBOARD hardware
Topic: RB1100AHx4 - IPSec/Tunnel speed
Replies: 4
Views: 1533

Re: RB1100AHx4 - IPSec/Tunnel speed

Currently Mikrotik publish only very synthetic UPD test results, and refuses to publish real-life TCP test results.
You can write a petition about adding result for "Single tunnel TCP single thread" viewtopic.php?f=3&t=97880
by mikruser
Fri Jan 12, 2018 4:29 pm
Forum: RouterBOARD hardware
Topic: Test results for wireless
Replies: 1
Views: 538

Test results for wireless

Hello,

Why Test results for wireless devices
https://mikrotik.com/product/RBcAP2nD#tab1_4
have Ethernet test results instead of Wireless test results?
by mikruser
Fri Jan 12, 2018 3:14 pm
Forum: RouterBOARD hardware
Topic: Looking for hardware
Replies: 1
Views: 616

Looking for hardware

Hello,

I'm trying to find hardware with such specs:

1) Router with hardware AES and 802.3af/at PoE output.
2) Dual-band Ceiling AP with 802.3af/at PoE input.

Does Mikrotik plan to produce such devices?
by mikruser
Fri Dec 01, 2017 6:49 pm
Forum: General
Topic: Issue with failover routing
Replies: 4
Views: 906

Re: Issue with failover routing

how to kill all old connections if the failover switching occur?
by mikruser
Tue Nov 21, 2017 5:43 pm
Forum: General
Topic: Best practices for creating ipsec-tunnels on Mikrotik hardware?
Replies: 0
Views: 386

Best practices for creating ipsec-tunnels on Mikrotik hardware?

Hello, We have a central office (Server side) and several branches (Client side), connected via ipsec in tunnel mode. what are the best practices for creating ipsec tunnels? (we need fast tunnel establishment and fast reconnection). three variants are possible: 1) Server side: Manually created polic...
by mikruser
Fri Nov 10, 2017 10:12 am
Forum: RouterBOARD hardware
Topic: RB751-U-2nHD 100% cpu
Replies: 20
Views: 6092

Re: RB751-U-2nHD 100% cpu

ROS 6.39.3
also have this issue:
rb751_6393.png
by mikruser
Fri Oct 27, 2017 10:07 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 5212

Re: Please add performance results for IPsec tunnel!

Windows(192.168.0.1)----()hEX(10.0.0.1)----EoIP+IPsec----(10.0.0.2)hEX()----(192.168.0.2)Windows
by mikruser
Fri Oct 27, 2017 6:59 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 5212

Re: Please add performance results for IPsec tunnel!

didomir
>>You can find information here how the tests has been done: https://wiki.mikrotik.com/wiki/Manual:I ... imizations
This is synthetic UDP test.
True "real life" test its TCP single connection, as i suggested.
by mikruser
Fri Oct 27, 2017 6:32 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 5212

Re: Please add performance results for IPsec tunnel!

Paternot
>>Traffic inside the IPsec tunnel still crosses the forward chain
No
eoip_ipsec.png
>>Just occurred to me: You said the traffic was about 260 Mb/s. It was just download?
Its unidirectional file copy (download or upload)
by mikruser
Fri Oct 27, 2017 5:39 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 5212

Re: Please add performance results for IPsec tunnel!

IPsec use "input" and "output" chain, not "forward".
by mikruser
Fri Oct 27, 2017 5:11 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 5212

Re: Please add performance results for IPsec tunnel!

You do not understand. Its "L2 wire" only. No L3 forward.
by mikruser
Fri Oct 27, 2017 2:09 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 5212

Re: Please add performance results for IPsec tunnel!

Firewall is blank
These two Hex is direct connected and used as encrypted wire in LAN
by mikruser
Fri Oct 27, 2017 1:06 pm
Forum: General
Topic: Port flapping on RB750Gr3
Replies: 1
Views: 565

Port flapping on RB750Gr3

RB750Gr3
6.39.3
today I found port flapping:
hex_port_flapping.png
by mikruser
Thu Oct 26, 2017 7:26 pm
Forum: General
Topic: eoip tunnels and bridges mac addresses
Replies: 2
Views: 721

eoip tunnels and bridges mac addresses

Hello, I have RB750Gr3 (6.39.3) with these interfaces: ether1 ether2 ether3 ether4 ether5 eoip-tunnel1 eoip-tunnel2 bridge1 bridge2 ether2, ether3, eoip-tunnel1 is members of bridge1 ether4, ether5, eoip-tunnel2 is members of bridge2 Currently mac-address of bridge1 = mac-address of eoip-tunnel1 mac...
by mikruser
Thu Oct 26, 2017 6:34 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 5212

Re: Please add performance results for IPsec tunnel!

I tested in 1Gbit LAN
by mikruser
Thu Oct 26, 2017 5:57 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 5212

Re: Please add performance results for IPsec tunnel!

I tested two 750G r3 (6.39.3), connected via EoIP tunnel with IPsec.
Windows file copy test show only 33 MB/s (264 Mbps). This is very far from declared 477 Mbps https://mikrotik.com/product/RB750Gr3.

Maybe you add also results for some popular tunnels+ipsec (l2tp+ipsec, gre+ipsec, eoip+ipsec)?
by mikruser
Tue Oct 24, 2017 6:46 pm
Forum: General
Topic: What is "unclassified" cpu usage?
Replies: 3
Views: 5876

What is "unclassified" cpu usage?

Hello,

I have two RB751U (ROS 6.39.3), and EoIP with ipsec tunnel between them.
When i copy file over tunnel, i see 75% "unclassified" cpu usage:
rb751_eoip.png
by mikruser
Tue Oct 24, 2017 4:25 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 5212

Re: Please add performance results for IPsec tunnel!

>>It is stateless traffic, so you could say it is UDP. Please add result for "Single tunnel TCP single thread". Its very useful info, for example as file copying. >>There is no use of testing devices without hardware acceleration, because their performance difference between models is insignificant...
by mikruser
Tue Oct 24, 2017 2:10 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 5212

Re: Please add performance results for IPsec tunnel!

As I see, you added "IPsec test results" for some products, like this https://mikrotik.com/product/CCR1009-7G-1C-1Splus

Some questions:

1) how many threads were used in Single tunnel?
2) it's TCP or UDP throughput?
3) why you publish results only for products with hardware ipsec?
by mikruser
Fri Oct 13, 2017 3:54 pm
Forum: General
Topic: Issue with failover routing
Replies: 4
Views: 906

Re: Issue with failover routing

up.
by mikruser
Wed Oct 11, 2017 7:13 pm
Forum: General
Topic: Winbox cannot connect to mac-address
Replies: 3
Views: 3536

Re: Winbox cannot connect to mac-address

MAC-WinBox service???
by mikruser
Wed Oct 11, 2017 7:09 pm
Forum: General
Topic: Service Ports, SIP Direct Media, SDP
Replies: 10
Views: 10833

Re: Service Ports, SIP Direct Media, SDP

Also have this issue.
But after disable "SIP Direct Media" all works fine.

Why "SIP Direct Media" is enabled by default?
It should be disabled by default!
by mikruser
Wed Oct 11, 2017 5:03 pm
Forum: General
Topic: Winbox cannot connect to mac-address
Replies: 3
Views: 3536

Winbox cannot connect to mac-address

Hello,

Winbox cannot connect to mac-address:
winbox_macaddr.png
why?
by mikruser
Mon Oct 02, 2017 5:38 pm
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 33249

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

But when 6.39 become a bugfix???

very strange situation:

6.41.x = RC
6.40.x = Current
6.39.x = WTF??? Where??? When???
6.38.x = Bugfix
by mikruser
Thu Sep 21, 2017 5:15 pm
Forum: General
Topic: Bug with L2TP Server Binding
Replies: 1
Views: 787

Bug with L2TP Server Binding

CCR1009-8G, 6.39, 6.39.2
I have two interfaces (Type:L2TP Server Binding):
l2tp-in1
l2tp-in2

but sometimes instead of l2tp-in2 i see dynamic interface:
l2tp_sb.png
by mikruser
Wed Aug 09, 2017 12:06 pm
Forum: General
Topic: Suggestion: add route check gateway based on link quality
Replies: 2
Views: 895

Suggestion: add route check gateway based on link quality

Hello,

Currently "Route Check Gateway" based on simply ping.
My suggestion: add check gateway based on link quality (ping jitter and packet loss) for given period of time.
by mikruser
Mon Jul 31, 2017 5:12 pm
Forum: RouterBOARD hardware
Topic: wireless+router device for ipsec
Replies: 2
Views: 565

Re: wireless+router device for ipsec

Do you have any plans to release wireless+router devices with HW-IPsec?
by mikruser
Mon Jul 31, 2017 5:04 pm
Forum: RouterBOARD hardware
Topic: wireless+router device for ipsec
Replies: 2
Views: 565

wireless+router device for ipsec

Hello,

Which wireless+router device (https://mikrotik.com/products/group/wir ... and-office) can handle at least 40Mbit/s ipsec vpn?
by mikruser
Mon Jul 31, 2017 4:51 pm
Forum: RouterBOARD hardware
Topic: hAP lite CPU
Replies: 1
Views: 749

hAP lite CPU

Hello,

Why hAP lite and hAP lite classic have
Product specifications
CPU QCA9533


but have
Ethernet test results
QCA9531 (650Mhz) 100M all port test


???
https://mikrotik.com/product/RB941-2nD-TC
https://mikrotik.com/product/RB941-2nD
by mikruser
Mon Jul 31, 2017 3:57 pm
Forum: RouterBOARD hardware
Topic: RB751 CPU usage get too high
Replies: 15
Views: 10529

Re: RB751 CPU usage get too high

Also have this issue (100% cpu) on some RB751U-2HnD (ROS 6.40):
Image1.png
Image2.png
Image3.png
Image4.png
Image5.png
Image6.png
How to fix this issue?
by mikruser
Tue Jul 18, 2017 4:59 pm
Forum: General
Topic: AVX2 and AVX-512
Replies: 1
Views: 831

AVX2 and AVX-512

Hello,

Can ROS x86 or ROS CHR use AVX2 and AVX-512 instructions from Skylake-X (Core i9 7900X) and Xeon Scalable?
by mikruser
Thu Jul 13, 2017 5:57 pm
Forum: General
Topic: Feature request - DNS names in IPsec
Replies: 7
Views: 2464

Feature request - DNS names in IPsec

Hello,

Please add ability to use DNS names in:

IP-IPsec-Policies-General\Action-Dst.Address
IP-IPsec-Peers-General-Address
by mikruser
Mon Jul 03, 2017 7:42 pm
Forum: RouterBOARD hardware
Topic: CCR manual pdf?
Replies: 3
Views: 1179

Re: CCR manual pdf?

Any info?

which led\color for 10 Mbps link?
which led\color for 100 Mbps link?
which led\color for 1000 Mbps link?
which led(s)\color(s) for Full\Half duplex link?
which led\color for activity?
by mikruser
Thu Jun 29, 2017 1:00 pm
Forum: General
Topic: Feaure Request: Watchdog to watch multiple IP addresses
Replies: 7
Views: 2321

Re: Feaure Request: Watchdog to watch multiple IP addresses

UP!
We want multiple IP in Watchdog ASAP!
by mikruser
Thu Jun 29, 2017 12:58 pm
Forum: General
Topic: Feature request: IPMI functionality for CCR
Replies: 7
Views: 2488

Re: Feature request: IPMI functionality for CCR

We again got this issue - CCR1009 "hung" very strange - ping work, but all ppp-tunnels cannot connect, we cannot connect Winbox to ip, and Winbox do not see CCR in Neighbors.
Only manual power cycle help me.
by mikruser
Wed Jun 28, 2017 3:47 pm
Forum: General
Topic: Discussion about bugfix, current and rc versions
Replies: 29
Views: 8375

Re: Discussion about bugfix, current and rc versions

From my experience: 1) "Bugfix" = Final stable version. Only this should be installed on production router. 2) "Current" = Public beta version with bugs for public beta testing, but have official support via support@mikrotik.com. You can install it on own risk. 3) "Release candidate" = beta version ...
by mikruser
Tue Jun 27, 2017 5:33 pm
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 33249

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

I repeat my question:
When we can expect this fix in "bugfix" branch?
by mikruser
Mon Jun 19, 2017 12:22 pm
Forum: General
Topic: Link Downs monitoring
Replies: 2
Views: 1580

Link Downs monitoring

Hello,

We need monitor via SNMP "Interface\ Status \ Link Downs" value, and "Rate" and "Full Duplex" value.
Its possible?
by mikruser
Fri Jun 16, 2017 2:21 pm
Forum: RouterBOARD hardware
Topic: CCR manual pdf?
Replies: 3
Views: 1179

Re: CCR manual pdf?

LEDs near ETH ports
by mikruser
Thu Jun 15, 2017 12:08 pm
Forum: RouterBOARD hardware
Topic: CCR manual pdf?
Replies: 3
Views: 1179

CCR manual pdf?

Hello,

Where can I find the PDF manual with a detailed description of CCR1009 (https://routerboard.com/CCR1009-8G-1S-1Splus)?
For example i cannot find description of eth led's colors value.
by mikruser
Wed Jun 14, 2017 8:01 pm
Forum: General
Topic: Issue with failover routing
Replies: 4
Views: 906

Re: Issue with failover routing

do you have some connection/route marking mangle rules?
No
by mikruser
Tue Jun 13, 2017 6:04 pm
Forum: General
Topic: Issue with failover routing
Replies: 4
Views: 906

Issue with failover routing

Hello,

We use this manual for dual-wan RB:
https://wiki.mikrotik.com/wiki/Advanced ... _Scripting
wan1=cheap unlimited traffic
wan2=expensive limited traffic

But i found this issue: when RB switch back from wan2 to wan1, pptp and sip connections stay on wan2!
by mikruser
Fri Jun 09, 2017 6:24 pm
Forum: General
Topic: ERROR: no roteros.dll found
Replies: 0
Views: 546

ERROR: no roteros.dll found

WinBox 3.11
cannot connect to some RB:

ERROR: no roteros.dll found
by mikruser
Wed May 17, 2017 11:14 pm
Forum: General
Topic: Microtik Hex IPSEC Phase 2 negatiation issue
Replies: 3
Views: 2416

Re: Microtik Hex IPSEC Phase 2 negatiation issue

worldcitizen

Its not Hex issue, its 6.38 and above issue
I write about this issue 4 month ago, but Mikrotik ignore this and release bugged 6.39
viewtopic.php?t=116729
by mikruser
Sat May 13, 2017 12:58 pm
Forum: General
Topic: Feature request: Detect and block Layer3/4 packets/connections with suspicious signatures
Replies: 2
Views: 895

Feature request: Detect and block Layer3/4 packets/connections with suspicious signatures

Hello,

Feature requests:
Detect and block Layer3/4 packets/connections with suspicious signatures.
Centralized updating the database of signatures.
by mikruser
Fri May 12, 2017 12:53 am
Forum: RouterBOARD hardware
Topic: Feature request: hot-swap PSU for 1U models
Replies: 0
Views: 399

Feature request: hot-swap PSU for 1U models

Hello,

Feature request: hot-swap PSU (1+1) for 1U models
  • 1
  • 2