Community discussions

Search found 379 matches

  • 1
  • 2
by mikruser
Sat Oct 12, 2019 8:58 pm
Forum: RouterBOARD hardware
Topic: New High Performance Routers ! ?
Replies: 16
Views: 2838

Re: New High Performance Routers ! ?

I am very surprised that Mikrotik does not use hardware NAT'ing.
by mikruser
Wed Aug 28, 2019 12:07 am
Forum: General
Topic: Suggestion: VPN over ICMP
Replies: 2
Views: 545

Suggestion: VPN over ICMP

Hello,
Please implement VPN over ICMP (ICMP Tunnel)
(it can be very useful in some countries with a totalitarian regime)))
by mikruser
Sun Aug 04, 2019 7:41 pm
Forum: RouterBOARD hardware
Topic: GPeR question
Replies: 18
Views: 2301

Re: GPeR question

normis
Tue Jul 30, 2019 9:57 am
The GPER is a passive device that connects wires together, you can call it Layer1. This is not really a hub.

normis
Fri Aug 02, 2019 3:14 pm
Yes, there is a basic switch chip inside.


Two completely different answers.
You are Dr Jekyll and Mr Hyde??
by mikruser
Thu Aug 01, 2019 12:39 pm
Forum: RouterBOARD hardware
Topic: GPeR question
Replies: 18
Views: 2301

Re: GPeR question

If GPER is just a passive device that connects wires together, then the price is perplexing (50% of Raspberry Pi 4 computer)
by mikruser
Mon Jul 29, 2019 10:31 pm
Forum: RouterBOARD hardware
Topic: GPeR question
Replies: 18
Views: 2301

Re: GPeR question

1) Of course it matters (and two port has nothing to do with it)
2) ???
3) Ok
by mikruser
Mon Jul 29, 2019 12:20 pm
Forum: RouterBOARD hardware
Topic: GPeR question
Replies: 18
Views: 2301

GPeR question

Hello,
1) at what OSI layer this device work? at L1 like hub, or at L2 like switch?
2) what delay does this device add?
3) why distance is limited to 1500 m?
by mikruser
Tue Jun 11, 2019 1:03 pm
Forum: General
Topic: SNMP traffic monitoring bug
Replies: 2
Views: 258

SNMP traffic monitoring bug

Hello,

CHR 6.44.2
PRTG Network Monitor SNMP Traffic sensor

When i copy file via gigabit adapter, SNMP sensor show only 430 Mbit/s

This is a bug in Mikrotik SNMP or in PRTG?
Image1_snmp_.png
by mikruser
Tue Apr 23, 2019 1:38 pm
Forum: General
Topic: Suggestion: Protocols for Bandwidth Test
Replies: 0
Views: 327

Suggestion: Protocols for Bandwidth Test

Hello,

please add not only udp and tcp, but also protocols 4, 47, 50.
by mikruser
Fri Mar 22, 2019 12:08 pm
Forum: General
Topic: GRE over IPSEC, CCR, VERY SLOW
Replies: 39
Views: 15704

Re: GRE over IPSEC, CCR, VERY SLOW

GRE+IPsec still slow:
viewtopic.php?f=2&t=146665
by mikruser
Mon Mar 18, 2019 6:49 pm
Forum: General
Topic: Slow speed through gre+ipsec tunnel
Replies: 0
Views: 409

Slow speed through gre+ipsec tunnel

Hello, CHR, 6.44.1, 2 vcpu Xeon Gold CCR1009, 6.44.1 WAN with 45 ms latency [CHR]---wan(tunnel gre+ipsec)wan---[CCR1009] aes128cbc/sha1, Actual MTU = 1426 (Auto) OR aes128ctr/sha1, Actual MTU = 1446 (Auto) Bandwidth Test on CHR to CCR (tcp, receive, 1 connection): between public ip = up to 300 Mbps ...
by mikruser
Mon Mar 18, 2019 5:53 pm
Forum: General
Topic: Please add the ability to choose Proposal
Replies: 11
Views: 1360

Re: Please add the ability to choose Proposal

All my tunnels are configured with IPsec Secret enabled, and I will not change it.

We simply need the ability to choose Proposal for each tunnel.
by mikruser
Mon Mar 18, 2019 4:45 pm
Forum: General
Topic: Please add the ability to choose Proposal
Replies: 11
Views: 1360

Re: Please add the ability to choose Proposal

I still do not see any real benefit of your request. It literally takes 2 seconds to change proposal value for your policies to a different one. /ip ipsec proposal add name=newproposal copy-from=default /ip ipsec policy set [find proposal=default] proposal=newproposal I was just posting this exact ...
by mikruser
Thu Mar 07, 2019 12:19 pm
Forum: General
Topic: Why AES CTR is not hardware accelerated on the CHR?
Replies: 1
Views: 194

Why AES CTR is not hardware accelerated on the CHR?

Hello,

Why AES CTR is not hardware accelerated on the CHR?
Image_chr_.png
by mikruser
Mon Mar 04, 2019 11:58 am
Forum: General
Topic: Does the System\Watchdog on the CHR make sense?
Replies: 0
Views: 184

Does the System\Watchdog on the CHR make sense?

Hello,

Does the System\Watchdog on the CHR make sense?
Can he restart the VM if CHR hangs?
by mikruser
Thu Feb 21, 2019 11:49 am
Forum: General
Topic: vlan question
Replies: 6
Views: 600

Re: vlan question

but I don't want to create additional vlan interfaces
by mikruser
Thu Feb 21, 2019 11:25 am
Forum: General
Topic: vlan question
Replies: 6
Views: 600

Re: vlan question

I can not merge bridges, because bridges have different ip-addresses and dhcp-servers on them.
by mikruser
Wed Feb 13, 2019 6:23 pm
Forum: General
Topic: vlan question
Replies: 6
Views: 600

vlan question

Hello, We have routerboard with ether2 and ether3 - in bridge1 ether4 and ether5 - in bridge2 now we need special port ether6 which should be a member of both bridges, but in bridge1 as untagged default vlan (vlan1), and in bridge2 as tagged vlan2. This is can be done very simply on a managed switch...
by mikruser
Fri Feb 08, 2019 5:01 pm
Forum: General
Topic: Why Fast Path not supported with hardware accelerated IPsec?
Replies: 1
Views: 389

Why Fast Path not supported with hardware accelerated IPsec?

Hello,

Why Fast Path not supported with hardware accelerated IPsec?
by mikruser
Mon Jan 21, 2019 11:12 am
Forum: General
Topic: restore to different hardware
Replies: 5
Views: 510

Re: restore to different hardware

I see a very large number of messages
expected end of command

looking at all, export/import procedure is very bugged on Mikrotik
by mikruser
Mon Jan 21, 2019 10:42 am
Forum: General
Topic: restore to different hardware
Replies: 5
Views: 510

Re: restore to different hardware

but cli command /import do not work:

expected end of command (line 24 column 26)
by mikruser
Fri Jan 18, 2019 6:28 pm
Forum: General
Topic: restore to different hardware
Replies: 5
Views: 510

restore to different hardware

How to copy configuration from router1 to router2 (different hardware)?
I see this post: viewtopic.php?t=115073
My question: how to export and import via Winbox GUI? (not via terminal cli!)
by mikruser
Tue Jan 15, 2019 11:35 am
Forum: General
Topic: Suggestion: drag and drop rules between routers
Replies: 1
Views: 383

Suggestion: drag and drop rules between routers

Hello,

please add the ability to drag and drop (copy) rules (and other stuff) from one Winbox window to another Winbox window.
by mikruser
Thu Dec 27, 2018 11:41 am
Forum: General
Topic: Cannot connect to L2TP server from Windows 7: no suitable proposal found [SOLVED]
Replies: 3
Views: 636

Re: Cannot connect to L2TP server from Windows 7: no suitable proposal found [SOLVED]

in case there is NAT between server and client: google "AssumeUDPEncapsulationContextOnSendRule"
Thanks, it helped!
by mikruser
Thu Dec 27, 2018 10:50 am
Forum: General
Topic: Cannot connect to L2TP server from Windows 7: no suitable proposal found [SOLVED]
Replies: 3
Views: 636

Cannot connect to L2TP server from Windows 7: no suitable proposal found [SOLVED]

Hello, CCR1009, 6.43.8 cannot connect to L2TP server from Windows 7 and Windows 2008 R2. ipsec, error no suitable proposal found. ipsec, error x.x.x.x failed to get valid proposal. ipsec, error x.x.x.x failed to pre-process ph1 packet (side: 1, status 1). ipsec, error x.x.x.x phase1 negotiation fail...
by mikruser
Tue Dec 25, 2018 12:51 pm
Forum: General
Topic: Question about IKE2
Replies: 0
Views: 219

Question about IKE2

What types of authentication does Mikrotik router support with Windows client?
Only "Use machine certificates"? Or also "Use EAP"?
by mikruser
Mon Dec 17, 2018 10:22 am
Forum: General
Topic: Ipsec peers
Replies: 0
Views: 238

Ipsec peers

Hello, I already have several ipsec peers with unique ip addresses (it is used for l2tp/ipsec site-to-site vpn's). Now I need to make a IKEv2 server for incoming connections from remote notebooks. For this i need to create ipsec peer with address 0.0.0.0/0. Is it possible to use this peer with other...
by mikruser
Tue Nov 27, 2018 3:57 pm
Forum: General
Topic: Backup/restore without mac-addresses
Replies: 2
Views: 526

Re: Backup/restore without mac-addresses

My question about Backup/Restore

(Import/Export do not work on my devices)
by mikruser
Tue Nov 27, 2018 3:39 pm
Forum: General
Topic: Backup/restore without mac-addresses
Replies: 2
Views: 526

Backup/restore without mac-addresses

Hello,

How to backup config without mac-addresses?
or how to restore config without changing mac-addresses?
by mikruser
Tue Nov 27, 2018 11:51 am
Forum: General
Topic: Backup/ Restore issue and duplicating Ethernet MAC address [SOLVED]
Replies: 4
Views: 1507

Re: Backup/ Restore issue and duplicating Ethernet MAC address [SOLVED]

But why i do not see Import/Export in Winbox?
by mikruser
Fri Nov 23, 2018 6:57 pm
Forum: General
Topic: After upgrade to 6.41, Ethernet Interface Bandwidth is gone
Replies: 2
Views: 559

Re: After upgrade to 6.41, Ethernet Interface Bandwidth is gone

up!
Why is it removed from Winbox GUI???
(but it is still available from command line: /interface ethernet set ether1 bandwidth=unlimited/unlimited)
by mikruser
Wed Nov 07, 2018 12:20 pm
Forum: General
Topic: Сan't rename interface [SOLVED]
Replies: 3
Views: 379

Re: Сan't rename interface [SOLVED]

After the command /interface ethernet set ether4-local bandwidth=unlimited/unlimited
I was able to rename the interface
by mikruser
Wed Nov 07, 2018 11:57 am
Forum: General
Topic: Сan't rename interface [SOLVED]
Replies: 3
Views: 379

Re: Сan't rename interface [SOLVED]

I have this problem again after restoring the configuration
by mikruser
Wed Nov 07, 2018 11:20 am
Forum: General
Topic: Сan't rename interface [SOLVED]
Replies: 3
Views: 379

Сan't rename interface [SOLVED]

RB750Gr3
ROS 6.43.4
Winbox 3.18

restoring configuration incorrectly restored interfaces, and I need to rename them
but when I try to change the name I get an error: Couldn't change Interface - not supported on this interface (6)
Image_interface.png
by mikruser
Fri Oct 26, 2018 6:44 pm
Forum: RouterBOARD hardware
Topic: New CPU - new product RB750Gr3 - RB750G family - now mmips
Replies: 180
Views: 67363

Re: New CPU - new product RB750Gr3 - RB750G family - now mmips

When will AES-CTR be added to RB750Gr3?
by mikruser
Fri Oct 26, 2018 1:29 pm
Forum: General
Topic: Suggestion: Reconnect action
Replies: 1
Views: 597

Suggestion: Reconnect action

Hello,

Please add "Reconnect" action to Right Click (Context) menu for all interfaces in Winbox
(reconnect = disable+enable)
by mikruser
Fri Oct 19, 2018 12:45 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 4216

Re: Problem with IPsec after update to 6.42

can you explain your setup and logic behind your policy configuration here? I can not think of a single case where responder should generate a dynamic policy with dst-address=0.0.0.0/0. We have a large number of subnets, and instead of creating a separate policy for each subnet, we create one polic...
by mikruser
Thu Oct 18, 2018 7:56 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 4216

Re: Problem with IPsec after update to 6.42

This behavior can be easily reproduced in the test lab.
by mikruser
Thu Oct 18, 2018 4:42 pm
Forum: Announcements
Topic: v6.43.4 [stable] is released!
Replies: 78
Views: 22569

Re: v6.43.4 [stable] is released!

This is not a configuration issue (this configuration worked fine for 7 years)
problem occurs after upgrade to 6.42.x or 6.43.x
by mikruser
Thu Oct 18, 2018 4:22 pm
Forum: Announcements
Topic: v6.43.4 [stable] is released!
Replies: 78
Views: 22569

Re: v6.43.4 [stable] is released!

This IPsec bug still not fixed viewtopic.php?f=2&t=136445
by mikruser
Thu Oct 18, 2018 1:46 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 4216

Re: Problem with IPsec after update to 6.42

6.43.4 also have this issue!
by mikruser
Fri Oct 05, 2018 1:33 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 3622

Re: Please add performance results for IPsec tunnel!

I also tested two hAP ac^2 with 6.43.2

EoIP with IPsec (aes-128 ctr), file copy is only 34 MB/s:
hapac2_eoip_ipsec_ctr.png
EoIP without IPsec, file copy is 68 MB/s:
hapac2_eoip.png
by mikruser
Wed Oct 03, 2018 6:51 pm
Forum: RouterBOARD hardware
Topic: RB751-U-2nHD 100% cpu
Replies: 20
Views: 5349

Re: RB751-U-2nHD 100% cpu

6.43.2 also have this issue
by mikruser
Tue Oct 02, 2018 12:42 pm
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 83730

Re: v6.44beta [testing] is released!

what is "multiple engine"??
by mikruser
Tue Sep 25, 2018 7:55 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 3622

Re: Please add performance results for IPsec tunnel!

You can use minimal (fastest) config, required for EoIP+IPsec or L2TP+IPsec or GRE+IPsec.
by mikruser
Tue Sep 25, 2018 7:47 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 4216

Re: Problem with IPsec after update to 6.42

6.43.2 also have this issue!
by mikruser
Tue Sep 25, 2018 2:06 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 3622

Re: Please add performance results for IPsec tunnel!

>>The throughput results are there for you to evaluate the IPsec crypto engine performance, not to show you throughput results with various different configurations. IPsec crypto engine performance is a "spherical cow in a vacuum", and does not show real life results. >>check for packet fragmentati...
by mikruser
Tue Sep 25, 2018 12:40 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 3622

Re: Please add performance results for IPsec tunnel!

>>Adding or enabling any additional RouterOS feature apart from IPsec policies can reduce the throughput significantly. That's why I already suggested that you also publish the results for some popular tunnels+ipsec (l2tp+ipsec, gre+ipsec, eoip+ipsec) https://forum.mikrotik.com/viewtopic.php?f=3&t=...
by mikruser
Mon Sep 24, 2018 4:53 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 3622

Re: Please add performance results for IPsec tunnel!

I also tested two RB3011 with 6.43.2, connected via EoIP tunnel with IPsec.
They showed an even lower speed, even with hardware acceleration: file copy only 22 MB/s with aes-128 cbc/ctr (this is very far from declared 407.7 Mbps).
Profile:
rb3011_eoip_ipsec.png
by mikruser
Fri Sep 07, 2018 11:42 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 371
Views: 70237

Re: RB4011

Very unbalanced router
https://i.mt.lv/cdn/rb_files/RB4011iGSp ... 135303.png

Each switch have 5*1G port, but only 2.5G link to CPU.

What for this router have 10G sfp+ port? All switches summary have only 5G throughput.
by mikruser
Mon Sep 03, 2018 2:34 pm
Forum: RouterBOARD hardware
Topic: RB751 CPU usage get too high
Replies: 15
Views: 9788

Re: RB751 CPU usage get too high

I found that even just viewing the settings in the Winbox also often causes a 100% CPU load.

I suspect that the developers simply do not test the latest versions ROS/Winbox on RB751U.
Image100cpu.png
by mikruser
Sat Sep 01, 2018 9:05 pm
Forum: RouterBOARD hardware
Topic: When Mikrotik releases router that can handle single IPsec tunnel at 2.5G, 5G, 10G?
Replies: 1
Views: 449

When Mikrotik releases router that can handle single IPsec tunnel at 2.5G, 5G, 10G?

Hello,

When Mikrotik releases a router that can handle single IPsec tunnel (or MACsec) at 2.5G, 5G, 10G?
by mikruser
Thu Aug 30, 2018 10:52 pm
Forum: General
Topic: How to downgrade the ROS below the factory version?
Replies: 5
Views: 645

Re: How to downgrade the ROS below the factory version?

May I ask why downgrade to such a vulnerable version? Wouldn't be better to upgrade the other equipment if having the same version on all hardware is important?
Due to a this bug in 6.42.x:
viewtopic.php?t=136445
by mikruser
Thu Aug 30, 2018 6:43 pm
Forum: General
Topic: How to downgrade the ROS below the factory version?
Replies: 5
Views: 645

Re: How to downgrade the ROS below the factory version?

This is correct behavior.
But why??
We have another hAP ac^2 router and it works fine with version 6.41.4:
Image_hapac2.png
by mikruser
Thu Aug 30, 2018 5:58 pm
Forum: RouterBOARD hardware
Topic: Suggestion: release routers with preinstalled Factory Software from Bugfix release chain
Replies: 6
Views: 661

Suggestion: release routers with preinstalled Factory Software from Bugfix release chain

Hello,

Suggestion: release routers with preinstalled Factory Software only from Bugfix release chain.
by mikruser
Thu Aug 30, 2018 4:59 pm
Forum: General
Topic: How to downgrade the ROS below the factory version?
Replies: 5
Views: 645

How to downgrade the ROS below the factory version?

We have hAP ac^2 with Factory Software 6.42.3
How to downgrade the ROS below the factory version (to 6.41.4)?
After /system package downgrade
we get error
error: omitting package system-6.41.4: min RouterOS version is 6.42.3
by mikruser
Wed Aug 29, 2018 12:55 pm
Forum: General
Topic: PCQ - Queue - where to set limit
Replies: 1
Views: 343

Re: PCQ - Queue - where to set limit

see answer in this topic: viewtopic.php?f=1&t=138427#p682693

Cha0s
Have you tried TP-Link or D-Link?

I am sure they are much easier with all their wizards whistles and bells.

If you find RouterOS hard, then it's probably not for you.
by mikruser
Tue Aug 28, 2018 7:15 pm
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 1146

Re: Suggestion: simple speed limiter

Advanced tab also not enough in this case.
by mikruser
Tue Aug 28, 2018 6:06 pm
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 1146

Re: Suggestion: simple speed limiter

we are talking about only first tab
by mikruser
Tue Aug 28, 2018 12:53 pm
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 1146

Re: Suggestion: simple speed limiter

Simple queue is perfectly adequate for this. Just use the first tab.
With only first tab is impossible to perform an elementary task in one queue:
set summary limit + set per IP limit
by mikruser
Sat Aug 25, 2018 3:09 pm
Forum: General
Topic: Feature requests
Replies: 1159
Views: 207314

Re: Feature requests

Feature request: AES hardware acceleration for OpenVPN
by mikruser
Fri Aug 24, 2018 7:04 pm
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 1146

Suggestion: simple speed limiter

Hello,

current Queues has a very large number of settings and a very complex and confusing.

Please add simple speed limiter.
by mikruser
Thu Aug 23, 2018 5:25 pm
Forum: General
Topic: Please add "Benchmark" button to Winbox IP-IPsec-Proposals
Replies: 1
Views: 473

Please add "Benchmark" button to Winbox IP-IPsec-Proposals

Hello,

Please add "Benchmark" button to Winbox IP-IPsec-Proposals
for benchmark selected algorithms "encryption", "decryption", "encryption+decryption" speed on any platform
(like VeraCrypt Tools-Benchmark):
Image_bench.png
by mikruser
Mon Aug 20, 2018 1:26 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 4216

Re: Problem with IPsec after update to 6.42

6.42.7 also have this issue!
by mikruser
Fri Aug 17, 2018 2:04 pm
Forum: General
Topic: Why Fast Path not active?
Replies: 4
Views: 1342

Re: Why Fast Path not active?

IPv4 fast path is automatically used if following conditions are met:

firewal rules are not configured;


LOL, in this case Fast Path absolutely useless
I do not have routerboards without firewall rules
by mikruser
Fri Aug 17, 2018 1:09 pm
Forum: General
Topic: Why Fast Path not active?
Replies: 4
Views: 1342

Why Fast Path not active?

Hello,

Fast Path enabled
But why Fast Path not active?
Image1_fp.png
by mikruser
Thu Aug 16, 2018 1:54 pm
Forum: General
Topic: Suggestion: backup restore wizard
Replies: 0
Views: 333

Suggestion: backup restore wizard

Hello,

Please add to Winbox backup restore wizard:

Interfaces remapping
Interfaces MAC addresses: preserve/reset
DHCP leases: preserve/remove
by mikruser
Wed Aug 08, 2018 4:50 pm
Forum: General
Topic: Please add the ability to choose Proposal
Replies: 11
Views: 1360

Re: Please add the ability to choose Proposal

I already have a configuration with a very large number of Ipsec policies (all these policies use proposal:default).

Now I created a l2tp connection with "Use Ipsec", and i need another custom proposal for this.
by mikruser
Wed Aug 08, 2018 1:11 pm
Forum: General
Topic: Bug after upgrade to 6.42.6
Replies: 4
Views: 779

Re: Bug after upgrade to 6.42.6

After investigation, I found that the bug is in Firewall-Service Ports-sip
After disable this port, 6.42 also works fine
by mikruser
Wed Aug 08, 2018 12:12 pm
Forum: General
Topic: Please add the ability to choose Proposal
Replies: 11
Views: 1360

Please add the ability to choose Proposal

Hello,

Please add the ability to choose Proposal (in L2tp with "Use IPsec")
by mikruser
Wed Aug 08, 2018 1:07 am
Forum: General
Topic: Suggestion: SMB WAN Accelerator
Replies: 0
Views: 380

Suggestion: SMB WAN Accelerator

Hello,

Please add SMB WAN Accelerator (for high latency VPN links)
like this: https://www.silver-peak.com/applications/cifs-smb
by mikruser
Thu Aug 02, 2018 9:51 pm
Forum: General
Topic: Suggestion: add crypto unit % usage
Replies: 0
Views: 528

Suggestion: add crypto unit % usage

Hello,

Some RouterBoard models have encryption engine.
Central Processing Unit (CPU) and Crypto Processing Unit (CrPU)

But currently in Tools-Profile we can see only CPU % Usage.

Suggestion: please add to Profile also CrPU % Usage.
by mikruser
Tue Jul 31, 2018 2:27 pm
Forum: General
Topic: AES-GCM HW acceleration in CCR
Replies: 10
Views: 1424

Re: AES-GCM HW acceleration in CCR

This topic about CCR
by mikruser
Tue Jul 31, 2018 12:14 pm
Forum: General
Topic: AES-GCM HW acceleration in CCR
Replies: 10
Views: 1424

Re: AES-GCM HW acceleration in CCR

There is a plan to make HW acceleration for GCM. 
Thank you for the confirmation Maris.
As it turned out, the confirmation was not true
by mikruser
Fri Jul 27, 2018 6:43 pm
Forum: General
Topic: chr support fast path?
Replies: 6
Views: 678

Re: chr support fast path?

The presentation says the VMXNET3 NIC supports fastpath. Are you using that?
CHR always uses VMXNET3
by mikruser
Fri Jul 27, 2018 6:29 pm
Forum: General
Topic: chr support fast path?
Replies: 6
Views: 678

Re: chr support fast path?

Also have this question.
Any official comments?
Image_chr_fp.png
by mikruser
Fri Jul 27, 2018 3:25 pm
Forum: General
Topic: How to optimize VPN tunnel over high latency link?
Replies: 3
Views: 582

Re: How to optimize VPN tunnel over high latency link?

Yes, Windows share file copy.
I also tried vSphere vMotion, but it did not exceed 60 Mbit/s.
by mikruser
Fri Jul 27, 2018 12:54 pm
Forum: General
Topic: How to optimize VPN tunnel over high latency link?
Replies: 3
Views: 582

How to optimize VPN tunnel over high latency link?

Hello, We have WAN-link with 1Gbit/s throughput, but 40 ms latency. iperf3 UDP test really can do 1Gbit/s almost lossless. We have L2TP IPsec tunnel over this WAN-link: LAN1---[CHR]---(l2tp_ipsec_vpn)---[CCR]---LAN2 Now file copy between LAN1 and LAN2 is only 6 MB/s maximum. I try different aes mode...
by mikruser
Thu Jul 26, 2018 2:27 pm
Forum: General
Topic: Bug after upgrade to 6.42.6
Replies: 4
Views: 779

Re: Bug after upgrade to 6.42.6

I do not see changes in SIP
by mikruser
Thu Jul 26, 2018 11:54 am
Forum: General
Topic: Feature Request: IPerf
Replies: 50
Views: 10988

Re: Feature Request: IPerf

kasparskr

do you can release Traffic Generator for Windows?
by mikruser
Thu Jul 26, 2018 11:35 am
Forum: General
Topic: Bug after upgrade to 6.42.6
Replies: 4
Views: 779

Bug after upgrade to 6.42.6

Hello, We have this setup: [FreePBX]---[CCR1]---(l2tp_ipsec_tunnel)---[CCR2]---[sip_clients] At night I updated ССR from 6.40.8 to 6.42.6. As a result, about half of sip clients/trunks can not register (FreePbx reboot did not help). After downgrade CCR back to 6.40.8 everything again worked fine. Wh...
by mikruser
Thu Jul 26, 2018 5:13 am
Forum: General
Topic: Please add to l2tp client Dial Out page "IPsec proposal" field
Replies: 0
Views: 383

Please add to l2tp client Dial Out page "IPsec proposal" field

Hello,

Please add to l2tp client Dial Out page "IPsec proposal" field
by mikruser
Thu Jul 26, 2018 4:40 am
Forum: General
Topic: "unclassified" cpu usage during btest
Replies: 1
Views: 587

"unclassified" cpu usage during btest

Hello,

What is "unclassified"?
Image1_btest_profile.png
by mikruser
Wed Jul 25, 2018 7:03 pm
Forum: General
Topic: Question about Tools - Bandwidth Test (tcp)
Replies: 0
Views: 220

Question about Tools - Bandwidth Test (tcp)

Hello,

Question about Tools - Bandwidth Test

What TCP Window Size does the test use?
by mikruser
Wed Jul 25, 2018 5:34 pm
Forum: General
Topic: btest - Where Is
Replies: 7
Views: 45963

Re: btest - Where Is

Any official info about Bandwidth Test for Windows?
by mikruser
Sun Jul 22, 2018 12:51 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 903

Re: 2-in-1 ? [SOLVED]

Thanks, it works. You are a genius.
by mikruser
Sat Jul 21, 2018 11:15 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 903

Re: 2-in-1 ? [SOLVED]

>>You may start by removing the additional 2.2.2.x addresses in your current setup

these are the necessary addresses, they must be accessible from the Internet
by mikruser
Sat Jul 21, 2018 11:13 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 903

Re: 2-in-1 ? [SOLVED]

>>simply remove one Ethernet interface from an existing bridge and add IP address 2.2.2.1/27 to that interface.
which Ethernet interface?
from which bridge?
why only 2.2.2.1?

I do not see it in your diagram
by mikruser
Sat Jul 21, 2018 10:40 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 903

Re: 2-in-1 ? [SOLVED]

On your diagram I do not see addresses from 2.2.2.0/24 subnet. (on my diagram these 30 addresses resides on Mikrotik2 <2.2.2.2>interface as additional addresses)
by mikruser
Sat Jul 21, 2018 9:39 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 903

Re: 2-in-1 ? [SOLVED]

Аbsolutely did not understand you.
Could you draw a diagram with addresses from my example?
by mikruser
Sat Jul 21, 2018 6:23 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 903

Re: 2-in-1 ? [SOLVED]

>>what is currently between the two Mikrotiks nothing. direct connection. Post the current configurations of both Mikrotiks For example (Mikrotik #1 is only routing, #2 routing and NAT): (Internet, provider gateway)---(1.1.1.0/30)---<1.1.1.1>[Mikrotik1]<2.2.2.1>---(2.2.2.0/24)---<2.2.2.2>[Mikrotik2...
by mikruser
Sat Jul 21, 2018 6:01 pm
Forum: Virtualization
Topic: CHR and KVM
Replies: 1
Views: 1067

CHR and KVM

Hello,
When i try Make RouterOS Image, i get error:
Couldn't start - this is not a host system
Image_kvm_chr.png
by mikruser
Sat Jul 21, 2018 3:35 pm
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 903

Re: 2-in-1 ? [SOLVED]

How possible create router inside router? Using VRF? KVM? Or more simple solution?
by mikruser
Sat Jul 21, 2018 3:09 am
Forum: General
Topic: 2-in-1 ? [SOLVED]
Replies: 13
Views: 903

2-in-1 ? [SOLVED]

Hello, Currently i have this: (Internet)---(MyPublicSubnet1)---[Mikrotik1]---(MyPublicSubnet2)---[Mikrotik2]---(MyPrivateSubnet) MyPublicSubnet1 with 2 public ip MyPublicSubnet2 with 30 public ip Mikrotik1 is only routing Mikrotik2 is routing, nat, l2tp_ipsec_vpn My question: it is possible to creat...
by mikruser
Thu Jul 19, 2018 12:59 pm
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 1760

Re: Please add numbers on Y-axis in Bandwidth Test

Bandwidth Test shows results every 1 second. Snmp monitoring software can not show so frequently.
by mikruser
Thu Jul 19, 2018 12:35 pm
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 1760

Re: Please add numbers on Y-axis in Bandwidth Test

this is a joke? how do you imagine a bandwidth test through snmp?
by mikruser
Thu Jul 19, 2018 12:15 pm
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 1760

Re: Please add numbers on Y-axis in Bandwidth Test

we need more than one number, we need a few numbers (at least two - at the bottom and at the top)
image_bt_num.png
by mikruser
Thu Jul 19, 2018 12:04 pm
Forum: General
Topic: Feature requests
Replies: 1159
Views: 207314

Re: Feature requests

by mikruser
Thu Jul 19, 2018 11:39 am
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 1760

Re: Please add numbers on Y-axis in Bandwidth Test

We need numbers on the Y-axis so that they can be seen in the screenshots (if you do not understand this from the first message).
by mikruser
Thu Jul 19, 2018 11:09 am
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 1760

Re: Please add numbers on Y-axis in Bandwidth Test

vecernik87
You are troll? Try mouse over my screenshot.
by mikruser
Fri Jul 13, 2018 10:10 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 4216

Re: Problem with IPsec after update to 6.42

>>I am running several IPsec tunnels using various 6.42.x versions and things like this do not happen

You also use 0.0.0.0/0 in Src.Address (and Generate Policy on other side)?
by mikruser
Fri Jul 13, 2018 7:05 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 4216

Re: Problem with IPsec after update to 6.42

I found a bug in the 6.42.x version:
6.42 generate policy with incorrect Dst.Address: instead of 0.0.0.0/0 (in 6.41) i see public ip of remote router (in 6.42)

Mikrotik, please fix this bug ASAP!
by mikruser
Fri Jul 13, 2018 5:08 pm
Forum: General
Topic: Please add numbers on Y-axis in Bandwidth Test
Replies: 24
Views: 1760

Please add numbers on Y-axis in Bandwidth Test

Hello,

Please add numbers on Y-axis in Bandwidth Test
image_bt.png
by mikruser
Fri Jul 06, 2018 5:12 pm
Forum: General
Topic: CHR do not support hardware acceleration (AES-NI)?
Replies: 0
Views: 301

CHR do not support hardware acceleration (AES-NI)?

Hello,

I create l2tp ipsec tunnel (sha1 aes-128-cbc) Encoding: cbc(aes) + hmac(sha1)
It work, but without hardware acceleration: show E (E-ESP) instead of EH (E-ESP H-Hardware AEAD)

ESXi 6.7, CHR 6.42.5
by mikruser
Wed Jul 04, 2018 3:40 pm
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 4216

Problem with IPsec after update to 6.42

Hello,
After updating from 6.41.4 to 6.42.5 the traffic does not go through the tunnel (tunnel is established, but the traffic does not go).
After downgrade to 6.41.4 everything works fine again.

What changes in 6.42. led to this?
by mikruser
Sun May 27, 2018 11:53 pm
Forum: General
Topic: How to see real (physical) ether interface number?
Replies: 3
Views: 473

How to see real (physical) ether interface number?

Hello,
The interface Name can be anything and does not match the real (physical) number. (for example: ether interface number 2 can have Name 'ether5')
How to see real (physical) ether interface number? (remote, via Winbox)
by mikruser
Wed Mar 21, 2018 1:28 pm
Forum: RouterBOARD hardware
Topic: S+RJ10 question
Replies: 0
Views: 360

S+RJ10 question

Hello,

Is the module S+RJ10 (https://mikrotik.com/product/s_rj10) compatible with other vendor switches (like HPE, Dell, etc)?
by mikruser
Fri Mar 16, 2018 4:09 pm
Forum: General
Topic: Please add ability to connect to neighbors via MAC Winbox
Replies: 6
Views: 1807

Re: Please add ability to connect to neighbors via MAC Winbox

>>Remeber that neighbours seen by the router on the "other end" of interface could not be reachable from your LAN segment.

Router on the "other end" should act as a "proxy for winbox" in this case.
by mikruser
Fri Mar 16, 2018 2:47 pm
Forum: General
Topic: Please add ability to connect to neighbors via MAC Winbox
Replies: 6
Views: 1807

Re: Please add ability to connect to neighbors via MAC Winbox

I do not see "MAC Winbox" in your red circle
by mikruser
Fri Mar 16, 2018 12:50 pm
Forum: General
Topic: Please add ability to connect to neighbors via MAC Winbox
Replies: 6
Views: 1807

Please add ability to connect to neighbors via MAC Winbox

Hello,

Please add ability to connect to remote neighbors via MAC Winbox
(Menu "IP" - "Neighbors")
by mikruser
Tue Mar 13, 2018 6:33 pm
Forum: RouterBOARD hardware
Topic: Overclocking is officially supported?
Replies: 1
Views: 887

Overclocking is officially supported?

Hello,

Some models can be overclocked +25% via System - Routerboard - Settings - CPU Frequency.
Is it officially supported? In this case, do we need special conditions for this (eg additional cooling)?
cpu_rb951.png
cpu_hapac2.png
by mikruser
Mon Mar 12, 2018 9:28 pm
Forum: General
Topic: L2TP VPN Tunnel problem
Replies: 4
Views: 3890

Re: L2TP VPN Tunnel problem

Any answer from Mikrotik?
When will you fix this bug?
This is a very serious problem!
by mikruser
Fri Feb 16, 2018 12:28 pm
Forum: RouterBOARD hardware
Topic: RB750Gr3 with PoE. When?
Replies: 6
Views: 1513

Re: RB750Gr3 with PoE. When?

No, i mean RB750Gr3
by mikruser
Fri Feb 16, 2018 11:38 am
Forum: RouterBOARD hardware
Topic: RB750Gr3 with PoE. When?
Replies: 6
Views: 1513

RB750Gr3 with PoE. When?

Hello,

When we can expect the appearance hEX (RB750Gr3) with PoE out (802.3af/at)?
by mikruser
Wed Feb 14, 2018 11:41 am
Forum: General
Topic: L2TP VPN Tunnel problem
Replies: 4
Views: 3890

Re: L2TP VPN Tunnel problem

Also have this issue CCR1009, 6.39.3 sometime l2tp tunnel cannot connect: l2tp-out1: initializing... l2tp-out1: connecting... l2tp-out1: terminating... - session closed l2tp-out1: disconnected... l2tp-out1: initializing... l2tp-out1: connecting... l2tp-out1: terminating... - old tunnel is not closed...
by mikruser
Sat Feb 10, 2018 9:39 pm
Forum: RouterBOARD hardware
Topic: dual-band access point
Replies: 4
Views: 529

Re: dual-band access point

You can see it on Specifications page for all dual-band AP:

https://mikrotik.com/product/RB962UiGS-5HacT2HnT
https://mikrotik.com/product/cap_ac
https://mikrotik.com/product/hap_ac2
Image_mikr_ap.png
i do not see "a" and "n" for 5 GHz...
by mikruser
Fri Feb 09, 2018 4:58 pm
Forum: RouterBOARD hardware
Topic: dual-band access point
Replies: 4
Views: 529

dual-band access point

Hello,

Mikrotik dual-band SOHO access point really do not support "n" and "a" standards in 5 GHz?
by mikruser
Wed Jan 31, 2018 5:58 pm
Forum: General
Topic: After upgrade to 6.41, Ethernet Interface Bandwidth is gone
Replies: 2
Views: 559

After upgrade to 6.41, Ethernet Interface Bandwidth is gone

Hello, We have many devices with 6.39.3 and use setting in Interfaces - Ethernet - General - Bandwidth (Rx/Tx) (https://wiki.mikrotik.com/wiki/Manual:Interface/Ethernet) After upgrade to 6.41 this option is gone. Changelog do not have any info about this! https://mikrotik.com/download/changelogs/cur...
by mikruser
Thu Jan 25, 2018 2:03 pm
Forum: RouterBOARD hardware
Topic: RB751-U-2nHD 100% cpu
Replies: 20
Views: 5349

Re: RB751-U-2nHD 100% cpu

you do not see first post?
by mikruser
Wed Jan 24, 2018 6:20 pm
Forum: RouterBOARD hardware
Topic: RB751-U-2nHD 100% cpu
Replies: 20
Views: 5349

Re: RB751-U-2nHD 100% cpu

any comments from Mikrotik?
by mikruser
Wed Jan 17, 2018 1:05 pm
Forum: RouterBOARD hardware
Topic: RB1100AHx4 - IPSec/Tunnel speed
Replies: 4
Views: 1067

Re: RB1100AHx4 - IPSec/Tunnel speed

Currently Mikrotik publish only very synthetic UPD test results, and refuses to publish real-life TCP test results.
You can write a petition about adding result for "Single tunnel TCP single thread" viewtopic.php?f=3&t=97880
by mikruser
Fri Jan 12, 2018 4:29 pm
Forum: RouterBOARD hardware
Topic: Test results for wireless
Replies: 1
Views: 348

Test results for wireless

Hello,

Why Test results for wireless devices
https://mikrotik.com/product/RBcAP2nD#tab1_4
have Ethernet test results instead of Wireless test results?
by mikruser
Fri Jan 12, 2018 3:14 pm
Forum: RouterBOARD hardware
Topic: Looking for hardware
Replies: 1
Views: 357

Looking for hardware

Hello,

I'm trying to find hardware with such specs:

1) Router with hardware AES and 802.3af/at PoE output.
2) Dual-band Ceiling AP with 802.3af/at PoE input.

Does Mikrotik plan to produce such devices?
by mikruser
Fri Dec 01, 2017 6:49 pm
Forum: General
Topic: Issue with failover routing
Replies: 4
Views: 635

Re: Issue with failover routing

how to kill all old connections if the failover switching occur?
by mikruser
Tue Nov 21, 2017 5:43 pm
Forum: General
Topic: Best practices for creating ipsec-tunnels on Mikrotik hardware?
Replies: 0
Views: 250

Best practices for creating ipsec-tunnels on Mikrotik hardware?

Hello, We have a central office (Server side) and several branches (Client side), connected via ipsec in tunnel mode. what are the best practices for creating ipsec tunnels? (we need fast tunnel establishment and fast reconnection). three variants are possible: 1) Server side: Manually created polic...
by mikruser
Fri Nov 10, 2017 10:12 am
Forum: RouterBOARD hardware
Topic: RB751-U-2nHD 100% cpu
Replies: 20
Views: 5349

Re: RB751-U-2nHD 100% cpu

ROS 6.39.3
also have this issue:
rb751_6393.png
by mikruser
Fri Oct 27, 2017 10:07 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 3622

Re: Please add performance results for IPsec tunnel!

Windows(192.168.0.1)----()hEX(10.0.0.1)----EoIP+IPsec----(10.0.0.2)hEX()----(192.168.0.2)Windows
by mikruser
Fri Oct 27, 2017 6:59 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 3622

Re: Please add performance results for IPsec tunnel!

didomir
>>You can find information here how the tests has been done: https://wiki.mikrotik.com/wiki/Manual:I ... imizations
This is synthetic UDP test.
True "real life" test its TCP single connection, as i suggested.
by mikruser
Fri Oct 27, 2017 6:32 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 3622

Re: Please add performance results for IPsec tunnel!

Paternot
>>Traffic inside the IPsec tunnel still crosses the forward chain
No
eoip_ipsec.png
>>Just occurred to me: You said the traffic was about 260 Mb/s. It was just download?
Its unidirectional file copy (download or upload)
by mikruser
Fri Oct 27, 2017 5:39 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 3622

Re: Please add performance results for IPsec tunnel!

IPsec use "input" and "output" chain, not "forward".
by mikruser
Fri Oct 27, 2017 5:11 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 3622

Re: Please add performance results for IPsec tunnel!

You do not understand. Its "L2 wire" only. No L3 forward.
by mikruser
Fri Oct 27, 2017 2:09 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 3622

Re: Please add performance results for IPsec tunnel!

Firewall is blank
These two Hex is direct connected and used as encrypted wire in LAN
by mikruser
Fri Oct 27, 2017 1:06 pm
Forum: General
Topic: Port flapping on RB750Gr3
Replies: 1
Views: 383

Port flapping on RB750Gr3

RB750Gr3
6.39.3
today I found port flapping:
hex_port_flapping.png
by mikruser
Thu Oct 26, 2017 7:26 pm
Forum: General
Topic: eoip tunnels and bridges mac addresses
Replies: 2
Views: 476

eoip tunnels and bridges mac addresses

Hello, I have RB750Gr3 (6.39.3) with these interfaces: ether1 ether2 ether3 ether4 ether5 eoip-tunnel1 eoip-tunnel2 bridge1 bridge2 ether2, ether3, eoip-tunnel1 is members of bridge1 ether4, ether5, eoip-tunnel2 is members of bridge2 Currently mac-address of bridge1 = mac-address of eoip-tunnel1 mac...
by mikruser
Thu Oct 26, 2017 6:34 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 3622

Re: Please add performance results for IPsec tunnel!

I tested in 1Gbit LAN
by mikruser
Thu Oct 26, 2017 5:57 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 3622

Re: Please add performance results for IPsec tunnel!

I tested two 750G r3 (6.39.3), connected via EoIP tunnel with IPsec.
Windows file copy test show only 33 MB/s (264 Mbps). This is very far from declared 477 Mbps https://mikrotik.com/product/RB750Gr3.

Maybe you add also results for some popular tunnels+ipsec (l2tp+ipsec, gre+ipsec, eoip+ipsec)?
by mikruser
Tue Oct 24, 2017 6:46 pm
Forum: General
Topic: What is "unclassified" cpu usage?
Replies: 3
Views: 3664

What is "unclassified" cpu usage?

Hello,

I have two RB751U (ROS 6.39.3), and EoIP with ipsec tunnel between them.
When i copy file over tunnel, i see 75% "unclassified" cpu usage:
rb751_eoip.png
by mikruser
Tue Oct 24, 2017 4:25 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 3622

Re: Please add performance results for IPsec tunnel!

>>It is stateless traffic, so you could say it is UDP. Please add result for "Single tunnel TCP single thread". Its very useful info, for example as file copying. >>There is no use of testing devices without hardware acceleration, because their performance difference between models is insignificant...
by mikruser
Tue Oct 24, 2017 2:10 pm
Forum: RouterBOARD hardware
Topic: Please add performance results for IPsec tunnel!
Replies: 32
Views: 3622

Re: Please add performance results for IPsec tunnel!

As I see, you added "IPsec test results" for some products, like this https://mikrotik.com/product/CCR1009-7G-1C-1Splus

Some questions:

1) how many threads were used in Single tunnel?
2) it's TCP or UDP throughput?
3) why you publish results only for products with hardware ipsec?
by mikruser
Fri Oct 13, 2017 3:54 pm
Forum: General
Topic: Issue with failover routing
Replies: 4
Views: 635

Re: Issue with failover routing

up.
by mikruser
Wed Oct 11, 2017 7:13 pm
Forum: General
Topic: Winbox cannot connect to mac-address
Replies: 3
Views: 2507

Re: Winbox cannot connect to mac-address

MAC-WinBox service???
by mikruser
Wed Oct 11, 2017 7:09 pm
Forum: General
Topic: Service Ports, SIP Direct Media, SDP
Replies: 10
Views: 8475

Re: Service Ports, SIP Direct Media, SDP

Also have this issue.
But after disable "SIP Direct Media" all works fine.

Why "SIP Direct Media" is enabled by default?
It should be disabled by default!
by mikruser
Wed Oct 11, 2017 5:03 pm
Forum: General
Topic: Winbox cannot connect to mac-address
Replies: 3
Views: 2507

Winbox cannot connect to mac-address

Hello,

Winbox cannot connect to mac-address:
winbox_macaddr.png
why?
by mikruser
Mon Oct 02, 2017 5:38 pm
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 26243

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

But when 6.39 become a bugfix???

very strange situation:

6.41.x = RC
6.40.x = Current
6.39.x = WTF??? Where??? When???
6.38.x = Bugfix
by mikruser
Thu Sep 21, 2017 5:15 pm
Forum: General
Topic: Bug with L2TP Server Binding
Replies: 1
Views: 552

Bug with L2TP Server Binding

CCR1009-8G, 6.39, 6.39.2
I have two interfaces (Type:L2TP Server Binding):
l2tp-in1
l2tp-in2

but sometimes instead of l2tp-in2 i see dynamic interface:
l2tp_sb.png
by mikruser
Wed Aug 09, 2017 12:06 pm
Forum: General
Topic: Suggestion: add route check gateway based on link quality
Replies: 2
Views: 603

Suggestion: add route check gateway based on link quality

Hello,

Currently "Route Check Gateway" based on simply ping.
My suggestion: add check gateway based on link quality (ping jitter and packet loss) for given period of time.
by mikruser
Mon Jul 31, 2017 5:12 pm
Forum: RouterBOARD hardware
Topic: wireless+router device for ipsec
Replies: 2
Views: 350

Re: wireless+router device for ipsec

Do you have any plans to release wireless+router devices with HW-IPsec?
by mikruser
Mon Jul 31, 2017 5:04 pm
Forum: RouterBOARD hardware
Topic: wireless+router device for ipsec
Replies: 2
Views: 350

wireless+router device for ipsec

Hello,

Which wireless+router device (https://mikrotik.com/products/group/wir ... and-office) can handle at least 40Mbit/s ipsec vpn?
by mikruser
Mon Jul 31, 2017 4:51 pm
Forum: RouterBOARD hardware
Topic: hAP lite CPU
Replies: 1
Views: 578

hAP lite CPU

Hello,

Why hAP lite and hAP lite classic have
Product specifications
CPU QCA9533


but have
Ethernet test results
QCA9531 (650Mhz) 100M all port test


???
https://mikrotik.com/product/RB941-2nD-TC
https://mikrotik.com/product/RB941-2nD
by mikruser
Mon Jul 31, 2017 3:57 pm
Forum: RouterBOARD hardware
Topic: RB751 CPU usage get too high
Replies: 15
Views: 9788

Re: RB751 CPU usage get too high

Also have this issue (100% cpu) on some RB751U-2HnD (ROS 6.40):
Image1.png
Image2.png
Image3.png
Image4.png
Image5.png
Image6.png
How to fix this issue?
by mikruser
Tue Jul 18, 2017 4:59 pm
Forum: General
Topic: AVX2 and AVX-512
Replies: 1
Views: 567

AVX2 and AVX-512

Hello,

Can ROS x86 or ROS CHR use AVX2 and AVX-512 instructions from Skylake-X (Core i9 7900X) and Xeon Scalable?
by mikruser
Thu Jul 13, 2017 5:57 pm
Forum: General
Topic: Feature request - DNS names in IPsec
Replies: 7
Views: 1749

Feature request - DNS names in IPsec

Hello,

Please add ability to use DNS names in:

IP-IPsec-Policies-General\Action-Dst.Address
IP-IPsec-Peers-General-Address
by mikruser
Mon Jul 03, 2017 7:42 pm
Forum: RouterBOARD hardware
Topic: CCR manual pdf?
Replies: 3
Views: 921

Re: CCR manual pdf?

Any info?

which led\color for 10 Mbps link?
which led\color for 100 Mbps link?
which led\color for 1000 Mbps link?
which led(s)\color(s) for Full\Half duplex link?
which led\color for activity?
by mikruser
Thu Jun 29, 2017 1:00 pm
Forum: General
Topic: Feaure Request: Watchdog to watch multiple IP addresses
Replies: 7
Views: 1852

Re: Feaure Request: Watchdog to watch multiple IP addresses

UP!
We want multiple IP in Watchdog ASAP!
by mikruser
Thu Jun 29, 2017 12:58 pm
Forum: General
Topic: Feature request: IPMI functionality for CCR
Replies: 7
Views: 1824

Re: Feature request: IPMI functionality for CCR

We again got this issue - CCR1009 "hung" very strange - ping work, but all ppp-tunnels cannot connect, we cannot connect Winbox to ip, and Winbox do not see CCR in Neighbors.
Only manual power cycle help me.
by mikruser
Wed Jun 28, 2017 3:47 pm
Forum: General
Topic: Discussion about bugfix, current and rc versions
Replies: 29
Views: 6683

Re: Discussion about bugfix, current and rc versions

From my experience: 1) "Bugfix" = Final stable version. Only this should be installed on production router. 2) "Current" = Public beta version with bugs for public beta testing, but have official support via support@mikrotik.com. You can install it on own risk. 3) "Release candidate" = beta version ...
by mikruser
Tue Jun 27, 2017 5:33 pm
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 26243

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

I repeat my question:
When we can expect this fix in "bugfix" branch?
by mikruser
Mon Jun 19, 2017 12:22 pm
Forum: General
Topic: Link Downs monitoring
Replies: 2
Views: 1048

Link Downs monitoring

Hello,

We need monitor via SNMP "Interface\ Status \ Link Downs" value, and "Rate" and "Full Duplex" value.
Its possible?
by mikruser
Fri Jun 16, 2017 2:21 pm
Forum: RouterBOARD hardware
Topic: CCR manual pdf?
Replies: 3
Views: 921

Re: CCR manual pdf?

LEDs near ETH ports
by mikruser
Thu Jun 15, 2017 12:08 pm
Forum: RouterBOARD hardware
Topic: CCR manual pdf?
Replies: 3
Views: 921

CCR manual pdf?

Hello,

Where can I find the PDF manual with a detailed description of CCR1009 (https://routerboard.com/CCR1009-8G-1S-1Splus)?
For example i cannot find description of eth led's colors value.
by mikruser
Wed Jun 14, 2017 8:01 pm
Forum: General
Topic: Issue with failover routing
Replies: 4
Views: 635

Re: Issue with failover routing

do you have some connection/route marking mangle rules?
No
by mikruser
Tue Jun 13, 2017 6:04 pm
Forum: General
Topic: Issue with failover routing
Replies: 4
Views: 635

Issue with failover routing

Hello,

We use this manual for dual-wan RB:
https://wiki.mikrotik.com/wiki/Advanced ... _Scripting
wan1=cheap unlimited traffic
wan2=expensive limited traffic

But i found this issue: when RB switch back from wan2 to wan1, pptp and sip connections stay on wan2!
by mikruser
Fri Jun 09, 2017 6:24 pm
Forum: General
Topic: ERROR: no roteros.dll found
Replies: 0
Views: 362

ERROR: no roteros.dll found

WinBox 3.11
cannot connect to some RB:

ERROR: no roteros.dll found
by mikruser
Wed May 17, 2017 11:14 pm
Forum: General
Topic: Microtik Hex IPSEC Phase 2 negatiation issue
Replies: 3
Views: 1852

Re: Microtik Hex IPSEC Phase 2 negatiation issue

worldcitizen

Its not Hex issue, its 6.38 and above issue
I write about this issue 4 month ago, but Mikrotik ignore this and release bugged 6.39
viewtopic.php?t=116729
by mikruser
Sat May 13, 2017 12:58 pm
Forum: General
Topic: Feature request: Detect and block Layer3/4 packets/connections with suspicious signatures
Replies: 2
Views: 570

Feature request: Detect and block Layer3/4 packets/connections with suspicious signatures

Hello,

Feature requests:
Detect and block Layer3/4 packets/connections with suspicious signatures.
Centralized updating the database of signatures.
by mikruser
Fri May 12, 2017 12:53 am
Forum: RouterBOARD hardware
Topic: Feature request: hot-swap PSU for 1U models
Replies: 0
Views: 261

Feature request: hot-swap PSU for 1U models

Hello,

Feature request: hot-swap PSU (1+1) for 1U models
by mikruser
Sat Apr 29, 2017 12:39 pm
Forum: Announcements
Topic: v6.39 [current]
Replies: 89
Views: 33793

Re: v6.39 [current]

6.39 - another epic fail bugged version from mikrotik. Kill ipsec, kill sip-trunk.

Downgrade to 6.37.5, and all work fine.
by mikruser
Sat Apr 29, 2017 2:52 am
Forum: General
Topic: 6.36.2 / 6.39 is BUGGED!
Replies: 3
Views: 1026

Re: 6.36.2 / 6.39 is BUGGED!

6.39 also have this issue!

(6.37.5 work fine)
by mikruser
Fri Apr 28, 2017 10:34 pm
Forum: General
Topic: 6.38/6.39 kill ipsec
Replies: 10
Views: 2139

Re: 6.38 kill ipsec

6.39 also have this issue and kill IPsec

Why mikrotik developers release bugged versions?????
by mikruser
Fri Apr 07, 2017 7:48 pm
Forum: General
Topic: Simple Queue - how to limit only LAN-Internet traffic?
Replies: 1
Views: 716

Simple Queue - how to limit only LAN-Internet traffic?

Hello, I have LAN and LAN2 connected via VPN-tunnel: LAN----[eth1 CCR eth5]----((Internet))----[CCR2]---LAN2 now i want limit LAN-to/from-Internet traffic. but when i create Simple Queue with Target=LAN, it limit all traffic (include LAN-LAN2) how to limit only LAN-to/from-Internet traffic (without ...
by mikruser
Wed Apr 05, 2017 11:52 am
Forum: General
Topic: Simple Queue question
Replies: 13
Views: 1424

Re: Simple Queue question

no, you need one simple queue with target=192.168.0.0/24 and max-limit=10M/10M + set queue type=pcq for upload/download and set these with pcq-rate=2M in both 1 client - 2M, up to 5 client - get 2M each. 10 client - 1M each... 1) On which tab i should set queue type=pcq? On "Advanced" tab i do not ...
by mikruser
Tue Apr 04, 2017 5:57 pm
Forum: General
Topic: Simple Queue question
Replies: 13
Views: 1424

Re: Simple Queue question

It is impossible to set per-ip limit in ROS?
I must manually create 253 rules for each ip?
by mikruser
Sun Apr 02, 2017 4:36 pm
Forum: RouterBOARD hardware
Topic: MUM Europe 2017: new hardware incoming!
Replies: 86
Views: 20719

Re: MUM Europe 2017: new hardware incoming!

AHx4 > CCR1009 in single-threaded (one core) tasks, but AHx4 < CCR1009 in a well-parallelizable (multi core) tasks.
by mikruser
Fri Mar 31, 2017 7:52 pm
Forum: General
Topic: Suggestion: more real-life config for "Ethernet test results"
Replies: 0
Views: 327

Suggestion: more real-life config for "Ethernet test results"

Hello,

Currently "Ethernet test results" based on very light configurations.

Suggestion:
1) Add more real-life heavier config (ip firewall filter rules + nat rules + mangle rules + queues + vlan)
2) Add crypto config (L2TP/GRE + IPsec)
by mikruser
Mon Mar 20, 2017 10:45 am
Forum: General
Topic: Feature request : Lightweight crypto for devices not having hardware crypto engine
Replies: 1
Views: 463

Re: Feature request : Lightweight crypto for devices not having hardware crypto engine

+1
Devices like RB751 is too slow with current ROS Ipsec encr. algorithms (~10Mbit/s)
We want fast fast algorithm!
by mikruser
Fri Mar 17, 2017 12:29 pm
Forum: RouterBOARD hardware
Topic: Why Mikrotik does not produce the routers on x86 processors?
Replies: 18
Views: 3608

Re: Why Mikrotik does not produce the routers on x86 processors?

What about using Ryzen? It has incredible crypto performance:
Image
Image
by mikruser
Wed Feb 22, 2017 12:09 pm
Forum: General
Topic: IPSec tunnel in one direction it is very slow
Replies: 6
Views: 1359

Re: IPSec tunnel in one direction it is very slow

Its a well-known problem with mikrotik ipsec tunnels.
Mikrotik ipsec tunnels are not compatible with Windows.
by mikruser
Tue Jan 24, 2017 11:44 pm
Forum: RouterBOARD hardware
Topic: Need router with wifi
Replies: 1
Views: 512

Need router with wifi

Hello,

I need router with features:
1) Hardware encryption (or software can 100 Mbit/s)
2) dual-band 802.11n (minimum 2 spatial stream, but advisable 3)
3) Gigabit ethernet ports

which model you can recommend?
by mikruser
Tue Jan 17, 2017 4:28 pm
Forum: General
Topic: 6.38/6.39 kill ipsec
Replies: 10
Views: 2139

Re: 6.38 kill ipsec

It is almost impossible to guess what ipsec config you have and what might not work.
I have a config that works for many years on any version before 6.38
It is incredible that Mikrotik release such bugged version.
This is absolutely unacceptable for enterprise.
by mikruser
Mon Jan 16, 2017 7:10 pm
Forum: Announcements
Topic: v6.38.1 [current]
Replies: 73
Views: 24037

Re: v6.38.1 [current]

I really hope the 6.38 bugs are squashed :)
No, 6.38.1 also bugged, as 6.38 (ipsec tunnel dont work)
Only downgrade to 6.37.3 can help.
by mikruser
Wed Jan 11, 2017 12:47 pm
Forum: General
Topic: 6.38/6.39 kill ipsec
Replies: 10
Views: 2139

6.38/6.39 kill ipsec

Hello,

After upgrade to 6.38 ipsec tunnel dont work.

I downgrade to 6.37.3 and tunnel work again.
by mikruser
Sat Jan 07, 2017 12:37 am
Forum: General
Topic: Encr. Algorithm field is blank
Replies: 1
Views: 395

Re: Encr. Algorithm field is blank

In 6.38 issue has NOT been fixed!!!
by mikruser
Fri Dec 23, 2016 2:40 pm
Forum: General
Topic: ipsec unstable
Replies: 11
Views: 3916

Re: ipsec unstable

In v6.38 nat-t is enabled by default because many client devices require it
lol wat???
facepalm.jpg
by mikruser
Sat Dec 17, 2016 8:57 pm
Forum: General
Topic: Feature request: Port-based VLAN for routers with switch-chip
Replies: 14
Views: 2303

Re: Feature request: Port-based VLAN for routers with switch-chip

https://community.hpe.com/t5/Switches-Hubs-Modems-Legacy/Overlapping-vlans/td-p/3652542 Here you can find some guy trying to do that on HP switch and it didn't work as expected. HP 2500 switches dont support full featured Port-based Vlan (cannot put one port to two group) and overlapping Vlans supp...
by mikruser
Sat Dec 17, 2016 5:50 pm
Forum: General
Topic: Feature request: Port-based VLAN for routers with switch-chip
Replies: 14
Views: 2303

Re: Feature request: Port-based VLAN for routers with switch-chip

if you assure that currently switch-chip can, please show Winbox screenshots for this:
portbasedvlan.png
by mikruser
Sat Dec 17, 2016 4:59 pm
Forum: General
Topic: Feature request: Port-based VLAN for routers with switch-chip
Replies: 14
Views: 2303

Re: Feature request: Port-based VLAN for routers with switch-chip

read first post link ("Port-based VLAN Overview" from page 151)
currently routers with switch-chip cannot do this.
by mikruser
Sat Dec 17, 2016 2:19 pm
Forum: General
Topic: Feature request: Port-based VLAN for routers with switch-chip
Replies: 14
Views: 2303

Re: Feature request: Port-based VLAN for routers with switch-chip

I'm not sure if I get what you want but afaik ROS supports VLANs on switch chip level.
No, currently routers with switch-chip can only Tagged Vlan (802.1Q).
My suggestion about port-based Vlan.
It two absolutely different types of Vlan.
by mikruser
Thu Dec 15, 2016 3:09 pm
Forum: General
Topic: Feature request: Port-based VLAN for routers with switch-chip
Replies: 14
Views: 2303

Feature request: Port-based VLAN for routers with switch-chip

Like this switch: https://www.alliedtelesis.com/sites/def ... 100a_0.pdf
see "Port-based VLAN Overview" from page 151
In some cases it very useful!
by mikruser
Thu Dec 15, 2016 1:06 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 609
Views: 154577

Re: RouterOS v7.0 beta1 - when?

v7 ?

I think it will be a Christmas gift :-D
I expect v7 immediately after Christ Second Coming
by mikruser
Fri Dec 09, 2016 7:20 pm
Forum: Beginner Basics
Topic: How does "Auto" frequency feature works ?
Replies: 3
Views: 1803

Re: How does "Auto" frequency feature works ?

Why Auto-frequency do not select frequency with best noise floor?
by mikruser
Tue Dec 06, 2016 11:18 am
Forum: General
Topic: IPsec Generate Policy From Template
Replies: 4
Views: 1686

Re: IPsec Generate Policy From Template

ROS 6.x is very bugged and level=unique dont work:
http://forum.mikrotik.com/viewtopic.php ... 2&p=541653
by mikruser
Mon Dec 05, 2016 9:46 pm
Forum: RouterBOARD hardware
Topic: Why Mikrotik does not produce the routers on x86 processors?
Replies: 18
Views: 3608

Re: Why Mikrotik does not produce the routers on x86 processors?

CHR is OS for virtual machine.
My question about hardware router in 1U rackmount formfactor
by mikruser
Mon Dec 05, 2016 6:04 pm
Forum: RouterBOARD hardware
Topic: Why Mikrotik does not produce the routers on x86 processors?
Replies: 18
Views: 3608

Why Mikrotik does not produce the routers on x86 processors?

Hello,
Why Mikrotik does not produce the routers on x86 processors?
Dual-core Skylake can handle 10Gbit/s aes-gcm ipsec tunnel (CCR cannot).
by mikruser
Thu Dec 01, 2016 12:06 pm
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 26243

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

Why reordering issue occurs with hardware multicore, but not occurs with software multicore?
by mikruser
Thu Dec 01, 2016 12:03 pm
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 26243

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

I understand that Mikrotik says the ordering problem is being fixed (but when? ROS v7?). But can we temporarily get an option in the v6.x version to disable HW acceleration on the CCR platform, so that we can do software CBC on the CCR and hardware CBC on the hex 3r? I vote for that as well! it has...
by mikruser
Wed Nov 30, 2016 4:54 pm
Forum: RouterBOARD hardware
Topic: Which wireless protocol has the highest goodput?
Replies: 0
Views: 462

Which wireless protocol has the highest goodput?

Hello,

Which wireless protocol has the highest goodput?
Is there a wireless protocol with goodput >50%?
by mikruser
Fri Nov 18, 2016 11:38 am
Forum: General
Topic: Bandwidth test tool for Windows cause 100% core usage
Replies: 2
Views: 752

Re: Bandwidth test tool for Windows cause 100% core usage

TomjNorthIdaho

You can post screenshot with "Bandwidth test tool for Windows" window and "Windows Task Manager" window in one screenshot?
I should see 19000 Mbit tcp send and CPU per core usage.
by mikruser
Thu Nov 17, 2016 11:55 am
Forum: General
Topic: Bandwidth test tool for Windows cause 100% core usage
Replies: 2
Views: 752

Bandwidth test tool for Windows cause 100% core usage

Bandwidth test tool for Windows (tcp send) cause 100% core usage (3.5 GHz).
I can get only 165 Mbit/s with test to CCR
this test is absolutely unoptimized and do not use tcp offload?
by mikruser
Thu Nov 10, 2016 7:02 pm
Forum: General
Topic: What is "unclassified" cpu usage?
Replies: 1
Views: 1152

What is "unclassified" cpu usage?

What is "unclassified" cpu usage?
profile_unclassified.png
by mikruser
Sat Oct 29, 2016 8:39 pm
Forum: General
Topic: Problem Intel I350 t4
Replies: 10
Views: 3280

Re: Problem Intel I350 t4

Fri Apr 24, 2015 only in v7 beta that will be released soon
Mikrotik team is a bunch of liars.
by mikruser
Wed Oct 26, 2016 4:28 pm
Forum: General
Topic: Which encryption method (in software) is the fastest on CCR?
Replies: 0
Views: 321

Which encryption method (in software) is the fastest on CCR?

Hello,

Which encryption method (in software) is the fastest on CCR?
by mikruser
Wed Oct 26, 2016 4:23 pm
Forum: General
Topic: Suggestion: "Use HW accel" checkbox
Replies: 1
Views: 1031

Suggestion: "Use HW accel" checkbox

suggestion:
add "Use HW accel" checkbox to IP - IPsec - Proposals
(its need to disable hw accel with aes-cbc on CCR)
by mikruser
Mon Oct 10, 2016 11:51 am
Forum: General
Topic: Feature request: IPMI functionality for CCR
Replies: 7
Views: 1824

Re: Feature request: IPMI functionality for CCR

600$? really? its joke? oh lol
IPMI functionality should add to CCR price no more than 30$
by mikruser
Mon Oct 10, 2016 11:24 am
Forum: General
Topic: Encr. Algorithm field is blank
Replies: 1
Views: 395

Encr. Algorithm field is blank

I change Proposal Encr. Algorithm from aes-cbc to aes-gcm.
Tunnel work, but in Installed SAs tab Encryption\Encr. Algorithm field is blank.
Why?
by mikruser
Fri Oct 07, 2016 2:27 pm
Forum: General
Topic: PCC side effect on Mikrotik Forum
Replies: 4
Views: 863

Re: PCC side effect on Mikrotik Forum

please fix it asap!
currently your forum do not support posting from dual-wan balanced routerboard
by mikruser
Fri Oct 07, 2016 2:24 pm
Forum: General
Topic: Very slow file copy over IPsec tunnel in one direction
Replies: 2
Views: 466

Very slow file copy over IPsec tunnel in one direction

Hello,
I have ipsec tunnel between CCR1009 (WAN 100Mbit) and RB751 (WAN 20Mbit)
File copy over tunnel from RB751 side is normal (1.8 megabytes/s)
But file copy over tunnel to RB751 side is only ~150 kilobytes/sec
Why so slow?
by mikruser
Thu Oct 06, 2016 12:43 pm
Forum: General
Topic: Upgrading to latest ROS "destroy" some firewall rules
Replies: 1
Views: 521

Upgrading to latest ROS "destroy" some firewall rules

Hello, All my configs have 4 rules: accept for Connection State = established accept for Connection State = related (for input and forward chains respectively) after upgrade to latest ROS (for example 6.33.1 -> 6.37.1), I discovered that these rules now without any "Connection State" value! now its ...
by mikruser
Tue Oct 04, 2016 7:19 pm
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 26243

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

>>Is your L2TP/IPSec tunnel is using hardware accelerated crypto? Yes >>The Mikrotik is load balancing on a per packet basis, which effectively will distribute the load randomly across some set of cores. Ok, how can i change this to per-connection basis? One core should be enough to handle 100Mbit/s
by mikruser
Tue Oct 04, 2016 6:48 pm
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 26243

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

Even if RouterOS somehow forced all of the packets for a single IPSec session (not per inner flow) to hit a single core so they remain ordered then the performance would still be better than the software encryption workaround, at least in many use cases. I'd even be happy to designate a single core...
by mikruser
Tue Oct 04, 2016 6:41 pm
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 26243

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

In my opinion it will never be fixed. This is a problem in hardware (tilera). Mikrotik has already agreed to fix it and have discussed possible solutions with me. I don't think this is an if, but when. Unfortunately, they won't commit to a timeline, so I'm not sure when it will be. Look at the date...
by mikruser
Mon Oct 03, 2016 9:29 pm
Forum: General
Topic: Feaure Request: Watchdog to watch multiple IP addresses
Replies: 7
Views: 1852

Re: Feaure Request: Watchdog to watch multiple IP addresses

script = software
watchdog = hardware
by mikruser
Mon Oct 03, 2016 12:15 am
Forum: General
Topic: Feaure Request: Watchdog to watch multiple IP addresses
Replies: 7
Views: 1852

Re: Feaure Request: Watchdog to watch multiple IP addresses

UP!
Multiple IP in Watchdog should be implemented ASAP!!!
by mikruser
Fri Sep 30, 2016 3:15 pm
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 26243

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

In my opinion it will never be fixed.
This is a problem in hardware (tilera).
by mikruser
Fri Sep 30, 2016 2:15 pm
Forum: General
Topic: Feature request: IPMI functionality for CCR
Replies: 7
Views: 1824

Feature request: IPMI functionality for CCR

Hello,

Feature request: IPMI functionality for CCR. I need remotely power cycle.

(recently my CCR "hung" very strange - ping work, but all ppp-tunnels cannot connect and cannot connect via Winbox. Only manual power cycle help me.)
by mikruser
Mon Aug 29, 2016 6:44 pm
Forum: General
Topic: 6.36.2 / 6.39 is BUGGED!
Replies: 3
Views: 1026

Re: 6.36.2 is BUGGED!

No. Before upgrading CCR have 6.35.2, and calls also work fine.
by mikruser
Mon Aug 29, 2016 3:43 pm
Forum: General
Topic: 6.36.2 / 6.39 is BUGGED!
Replies: 3
Views: 1026

6.36.2 / 6.39 is BUGGED!

Hello, I have two office, connected via two CCR (L2TP/IPSEC tunnel), and FreePBX in each office (192.168.1.10 and 192.168.2.10, connected via SIP trunk). After upgrade to 6.36.2 i cannot call from one office to another. In FreePBX log i see: VERBOSE[29520][C-000000b3] pbx.c: Executing [s@from-sip-ex...
by mikruser
Tue Aug 23, 2016 11:18 am
Forum: General
Topic: How to synchronize configuration between two devices
Replies: 2
Views: 2485

Re: How to synchronize configuration between two devices

I already suggested the idea of the two routers with automatic synchronization:
http://forum.mikrotik.com/viewtopic.php?f=1&t=110690
by mikruser
Fri Jul 29, 2016 3:20 pm
Forum: General
Topic: Suggestion: Completely virtual router based on two physical routers
Replies: 135
Views: 16951

Suggestion: Completely virtual router based on two physical routers

Hello,

Currently, with VRRP, we have manual edit config on each physical router.

Suggestion: completely virtual router, visible in Winbox as one router (like RAID1(mirror) volume based on two HDD)
by mikruser
Fri Jul 08, 2016 7:50 pm
Forum: RouterBOARD hardware
Topic: RB3011UiAS-RM and POE injector
Replies: 9
Views: 2109

RB3011UiAS-RM and POE injector

Hello,


We purchased a RB3011UiAS-RM

In Quick Setup Guide i see:
Powering
.....
A 110/220V PSU and a PoE injector is included

but, i cannot find any POE injector in a box...
Why?
by mikruser
Mon Jul 04, 2016 10:52 am
Forum: General
Topic: Suggestion: add "Filter rule #" to "Connections" tab
Replies: 0
Views: 512

Suggestion: add "Filter rule #" to "Connections" tab

Hello,

Suggestion:
add "Filter rule number"(#) to "Connections" tab
(to see through what rule passed each connection)
by mikruser
Thu Jun 30, 2016 6:06 pm
Forum: General
Topic: Simple Queue question
Replies: 13
Views: 1424

Re: Simple Queue question

Target = 192.168.0.0/24
Max limit = 10M
Limit at = 2M
How it should work?
I need 2M limit, but in your example I see 2M reservation.
by mikruser
Thu Jun 30, 2016 6:04 pm
Forum: General
Topic: Simple Queue question
Replies: 13
Views: 1424

Re: Simple Queue question

Target = 192.168.0.0/24
Max limit = 10M
Limit at = 2M
Queue type = PCQ-UPLOAD-DEFAULT and also PCQ-DOWNLOAD-DEFAULT


I have one for the ISPQueue connection /16 and one for each smaller /24 group. These smaller groups has the main ISP queue linked using the PARENT=ISPQueue setting
by mikruser
Mon Jun 27, 2016 3:58 pm
Forum: General
Topic: Suggestion: more friendly and intuitive Firewall in Winbox
Replies: 33
Views: 3633

Re: Suggestion: more user-friendly and intuitive Firewall in Winbox

Mikrotik's firewall is simply awesome! It's the most intuitive UI I've ever used for iptables and it uses the correct terminology to describe fields/options.
It's just your habit.
Try firewall with two fields "Source" and "Destination" - it's really convenient.
by mikruser
Mon Jun 27, 2016 3:35 pm
Forum: General
Topic: Suggestion: more friendly and intuitive Firewall in Winbox
Replies: 33
Views: 3633

Re: Suggestion: more friendly and intuitive Firewall in Winbox

First, any change you've suggested would break a lot of existing scripts, make various examples obsolete and I even don't want to imagine what would happen when you would try to upgrade (or worse - downgrade) machine running complex fw system. Now then, combining various fields into input/output so...
by mikruser
Mon Jun 27, 2016 3:34 pm
Forum: General
Topic: Suggestion: more friendly and intuitive Firewall in Winbox
Replies: 33
Views: 3633

Re: Suggestion: more user-friendly and intuitive Firewall in Winbox

Can you give examples of rules that can not be implemented with my suggestion? Why multitools are so usable ? Who are Swiss Army Knives for ?  Surely we could have simple flint axe .... what couldn't be done with it ? I always use the principle of Occam's razor: "Entities must not be multiplied bey...
by mikruser
Fri Jun 24, 2016 6:15 pm
Forum: General
Topic: PCC side effect on Mikrotik Forum
Replies: 4
Views: 863

PCC side effect on Mikrotik Forum

Hello,
I use the PCC with two providers.
When I click "Submit" button, opens a page for entering the user name and password.

Maybe it can be fixed on the forum engine side?
by mikruser
Fri Jun 24, 2016 4:44 pm
Forum: General
Topic: Suggestion: more friendly and intuitive Firewall in Winbox
Replies: 33
Views: 3633

Re: Suggestion: more user-friendly and intuitive Firewall in Winbox

It's already intuitive and admin-friendly, and very much at that.
write at least one reason why I should use the 7(!) fields, if the same thing I do with two fields?
by mikruser
Fri Jun 24, 2016 4:35 pm
Forum: General
Topic: Suggestion: more friendly and intuitive Firewall in Winbox
Replies: 33
Views: 3633

Re: Suggestion: more user-friendly and intuitive Firewall in Winbox

But the interface is something absolutely different and all other suggestions in original post are not acceptable. Why absolutely different? See simple one-rule example: source=ether1-lan destination=ether8-wan action=accept translation=snat or another one-rule example: source=ether8-wan destinatio...
by mikruser
Fri Jun 24, 2016 4:23 pm
Forum: General
Topic: Suggestion: more friendly and intuitive Firewall in Winbox
Replies: 33
Views: 3633

Re: Suggestion: more user-friendly and intuitive Firewall in Winbox

I know it Do you? Do you also know what rules with action=jump do? What should such rules do in case chains are eliminated? Please carefully read my previous messages. I suggest remove Chain field only from FirewallRule/General in Winbox GUI. You can use jump to chain in Action. Ok, for a rare crea...
by mikruser
Fri Jun 24, 2016 3:30 pm
Forum: General
Topic: Suggestion: more friendly and intuitive Firewall in Winbox
Replies: 33
Views: 3633

Re: Suggestion: more user-friendly and intuitive Firewall in Winbox

>>Do you suggest to get rid of the action=jump rules altogether?
My suggestion is for FirewallRule/General, not for Action
action is a mandatory property of each firewall rule.
I know it
by mikruser
Fri Jun 24, 2016 2:14 pm
Forum: General
Topic: Suggestion: more friendly and intuitive Firewall in Winbox
Replies: 33
Views: 3633

Re: Suggestion: more user-friendly and intuitive Firewall in Winbox

Chain can be automatically determined based on the source and destination. Only the standard firewall chains can be determined automatically. Do you suggest to get rid of the action=jump rules altogether? Also chains in mangle can not be determined automatically (think of input/forward vs preroutin...
by mikruser
Fri Jun 24, 2016 2:01 pm
Forum: General
Topic: Suggestion: more friendly and intuitive Firewall in Winbox
Replies: 33
Views: 3633

Re: Suggestion: more user-friendly and intuitive Firewall in Winbox

Remove:
Chain
WAT?
Chain can be automatically determined based on the source and destination.
by mikruser
Fri Jun 24, 2016 1:45 pm
Forum: General
Topic: Suggestion: more friendly and intuitive Firewall in Winbox
Replies: 33
Views: 3633

Re: Suggestion: more user-friendly and intuitive Firewall in Winbox

I'm sorry but I have to contradict this wish. It's not only me loving the fine grnularity of routerOS' firewall. All fields and options precisely describe their purpose. But talking about feature requests for the firewall, I'd vote for protocol and port groups :-) -Chris Can you give examples of ru...
by mikruser
Fri Jun 24, 2016 1:07 pm
Forum: General
Topic: Suggestion: more friendly and intuitive Firewall in Winbox
Replies: 33
Views: 3633

Suggestion: more friendly and intuitive Firewall in Winbox

Hello, My suggestion: Remove: Chain Src.Address Dst.Address Src.Address List Dst.Address List In.Interface Out.Interface Instead use: Source Destination Source and Destination can be: Addresses and Address Groups, Interfaces and Interfaces Groups, Router itself (all router addresses); with AND/OR/NO...
by mikruser
Thu Jun 23, 2016 4:33 pm
Forum: General
Topic: Simple Queue question
Replies: 13
Views: 1424

Simple Queue question

Hello,

I have network 192.168.0.0/24
I need these limits:
1) Summary Limit (for entire network) = 10 Mbit/s
2) Individual limit for each IP-addresses = 2 Mbit/s

how to do it?
by mikruser
Wed Jun 22, 2016 6:53 pm
Forum: General
Topic: Incomplete manual (PCC and Passthrough)
Replies: 1
Views: 340

Incomplete manual (PCC and Passthrough)

Hello,

I found this manual http://wiki.mikrotik.com/wiki/Manual:PCC
but it does not have value for Passthrough.
Passthrough cannot be "undefined" in Winbox.
In which value should I set Passthrough in this case? Yes or No?
by mikruser
Tue Jun 21, 2016 1:24 pm
Forum: General
Topic: Feature request: Active Directory integration for RB management
Replies: 3
Views: 920

Re: Feature request: Active Directory integration for RB management

I do not have Radius and do not plan to install it.
by mikruser
Tue Jun 21, 2016 11:55 am
Forum: General
Topic: Feature request: Active Directory integration for RB management
Replies: 3
Views: 920

Feature request: Active Directory integration for RB management

Hello,

I have Active Directory with "Admin" and "Support" groups.
I want to give Full rights to RB management for all users in "Admin" group, and Read-only rights for all users in "Support" group.
by mikruser
Thu Jun 16, 2016 11:58 am
Forum: General
Topic: Very low TCP transfer speed on IPIP+IPsec on CCR1009 and CCR1036
Replies: 11
Views: 4075

Re: Very low TCP transfer speed on IPIP+IPsec on CCR1009 and CCR1036

My last update was June 10th: We are working on the problem. It will be in one of the upcoming releases. You  will definitely see it in changelog. I fear we could be waiting a very long time. CCR is manufactured already for 4 years. 4 years, Carl! You think they did not have time to work on the pro...
by mikruser
Mon Jun 13, 2016 3:57 pm
Forum: General
Topic: Mikrotik do not inherit DF bit!
Replies: 8
Views: 2436

Re: Mikrotik do not inherit DF bit!

Support recommendation works without inheriting DF bit. When you send ping to internal interface with DF, interface cannot send such packet and sends back response that packet is too large. You are wrong. When I send a packet with DF-bit (ping -f .....), it passes the internal interface, and fragme...
by mikruser
Sun Jun 12, 2016 1:00 pm
Forum: General
Topic: Mikrotik do not inherit DF bit!
Replies: 8
Views: 2436

Re: Mikrotik do not inherit DF bit!

Its citation from Mikrotik support answer: "Make sure there is no fragmentation, L2TP + IpSec can make up to 70B of overhead. You can run packet sniffer on the interface to detect packet fragmentation when doing file transfer. You can also try to ping using do-not-fragment and size parameters ." ve...
by mikruser
Sat Jun 11, 2016 4:56 pm
Forum: General
Topic: Mikrotik do not inherit DF bit!
Replies: 8
Views: 2436

Re: Mikrotik do not inherit DF bit!

Its citation from Mikrotik support answer: "Make sure there is no fragmentation, L2TP + IpSec can make up to 70B of overhead. You can run packet sniffer on the interface to detect packet fragmentation when doing file transfer. You can also try to ping using do-not-fragment and size parameters ." ver...
by mikruser
Fri Jun 10, 2016 7:55 pm
Forum: General
Topic: Mikrotik do not inherit DF bit!
Replies: 8
Views: 2436

Mikrotik do not inherit DF bit!

Hello, After some investigations with L2TP+IPSEC i found, that RB do not inherit "Don't fragment" bit from inner header! This strange behavior causes fragmentation issues - you cannot find problems with ping -f inside tunnel! My suggestion: this should be changed, or should be added manual selection...
by mikruser
Fri Jun 10, 2016 7:22 pm
Forum: General
Topic: How to clear captured packets from Packet Sniffer?
Replies: 0
Views: 575

How to clear captured packets from Packet Sniffer?

Hello,

How to clear captured packets from Packet Sniffer?
I do not see any "Clear" button...
by mikruser
Fri Jun 10, 2016 5:53 pm
Forum: General
Topic: Suggestion: "Fragmented Packet" counter to Interface/Traffic tab
Replies: 2
Views: 821

Suggestion: "Fragmented Packet" counter to Interface/Traffic tab

Hello,

Suggestion:
Add to Interface/Traffic tab
"Fragmented Packet" counter for monitor oversized packets and fragmentation events
by mikruser
Thu Jun 09, 2016 9:04 pm
Forum: General
Topic: How to change defaults for auto-generated ipsec policies?
Replies: 4
Views: 944

Re: How to change defaults for auto-generated ipsec policies?

Any comments, emils?

Your suggestion not work - dynamic policies always created with "Level: require".

Maybe, its bug in ROS?
  • 1
  • 2