Community discussions

Search found 99 matches

by ners
Sun Jul 14, 2019 1:46 pm
Forum: General
Topic: What is more efficient for ACL on WAN: conntrack->off or on with established? [SOLVED]
Replies: 5
Views: 669

Re: What is more efficient for ACL on WAN: conntrack->off or on with established? [SOLVED]

Instead of doing the filtering manually, you could also do it through See: https://wiki.mikrotik.com/wiki/Manual:IP/Settings#Properties /ip settings set rp-filter=strict I thought about rp-filter, but it seems I can't. I have two ISPs and two full-view BGP sessions with them, so returning packets m...
by ners
Sun Jul 14, 2019 12:43 pm
Forum: General
Topic: What is more efficient for ACL on WAN: conntrack->off or on with established? [SOLVED]
Replies: 5
Views: 669

Re: What is more efficient for ACL on WAN: conntrack->off or on with established? [SOLVED]

Yes, I currently have connection tracking turned off. I don't need it for anything else.
So I'll stick to my current setup. Thanks!
by ners
Sun Jul 14, 2019 11:35 am
Forum: General
Topic: What is more efficient for ACL on WAN: conntrack->off or on with established? [SOLVED]
Replies: 5
Views: 669

What is more efficient for ACL on WAN: conntrack->off or on with established? [SOLVED]

/ip firewall address-list add address=5.43.16.0/20 list=WAN-IN-FILTER /ip firewall address-list add address=10.0.0.0/8 list=WAN-IN-FILTER /ip firewall address-list add address=172.16.0.0/12 list=WAN-IN-FILTER /ip firewall address-list add address=192.168.0.0/16 list=WAN-IN-FILTER I have such an add...
by ners
Fri Jan 25, 2019 2:56 pm
Forum: Forwarding Protocols
Topic: no enforce-first-as in RouterOS?
Replies: 8
Views: 1047

Re: no enforce-first-as in RouterOS?

Thank you! Got it.
by ners
Sun Dec 23, 2018 9:53 am
Forum: Forwarding Protocols
Topic: failure: only one area is allowed to be NSSA translator... What?
Replies: 2
Views: 613

Re: failure: only one area is allowed to be NSSA translator... What?

Did you get it solved?
No, i included R4 and R5 in OSPF eliminating redistribution (and nssa) altogether.
by ners
Mon Dec 10, 2018 8:33 pm
Forum: Forwarding Protocols
Topic: no enforce-first-as in RouterOS?
Replies: 8
Views: 1047

Re: no enforce-first-as in RouterOS?

Ok, I'll try to explain it in real life terms. I want to connect to an IX which is a shared L2 Domain with a Router Server (running bird: https://bird.network.cz/) and a dozen of other peers each one with their own AS. The direct BGP session will be established with the Router Server (RS) and not wi...
by ners
Mon Dec 10, 2018 5:04 pm
Forum: Forwarding Protocols
Topic: no enforce-first-as in RouterOS?
Replies: 8
Views: 1047

Re: no enforce-first-as in RouterOS?

We don't need to strip our AS from AS_PATH. We want to accept routes from a BGP peer who has their AS stripped from AS_PATH. So if our peer's AS is 43322, and the AS_PATH for a route from that peer is "43322 20324 53221 9098" (our peer's AS first), we want Mikrotik to accept that route if it looked ...
by ners
Mon Dec 10, 2018 3:50 pm
Forum: Forwarding Protocols
Topic: no enforce-first-as in RouterOS?
Replies: 8
Views: 1047

no enforce-first-as in RouterOS?

We need to accept BGP routes with the peer's AS removed from AS_PATH on the peer's side. Will RouterOS accept such routes (without peer's AS) or do we need to configure something to enable acceptance of such routes? I haven't been able to find any relevant settings. In Cisco it's called no enforce-f...
by ners
Mon Nov 26, 2018 9:58 am
Forum: General
Topic: Weird problem: one VLAN in a bridge won't work (others do) [SOLVED]
Replies: 2
Views: 249

Re: Weird problem: one VLAN in a bridge won't work (others do) [SOLVED]


You need to tage VLAN 30 trough the bridge as well, so change from
Your suggestion worked. Thank you very much.
by ners
Mon Nov 26, 2018 9:34 am
Forum: General
Topic: Weird problem: one VLAN in a bridge won't work (others do) [SOLVED]
Replies: 2
Views: 249

Weird problem: one VLAN in a bridge won't work (others do) [SOLVED]

So my settings are as following. VLAN-10 is my home trusted network. VLAN-30 is my guest network. ether2 is a trunk port, goes to a 802.1q aware switch. wlan1 is my home wifi network wlan2 is guest wifi VLAN-10 is working perfectly, Hosts in VLAN-30 can't ping their default gateway (10.29.30.1) - ad...
by ners
Thu Nov 08, 2018 6:57 pm
Forum: Forwarding Protocols
Topic: failure: only one area is allowed to be NSSA translator... What?
Replies: 2
Views: 613

failure: only one area is allowed to be NSSA translator... What?

So I'm trying to make a Mikrotik RouterOS 6.40.8 a 7/5 translator for two NSSA zones for which it is an ABR. And it won't work for me: whenever I try to change the type of the other zone to NSSA, it rejects my command with the following error message: [admin@R1] /routing ospf area> set 3 type=nssa f...
by ners
Fri Nov 02, 2018 11:18 am
Forum: Forwarding Protocols
Topic: RouterOS 6.40.8 does not support Totally NSSA areas? [SOLVED]
Replies: 4
Views: 641

Re: RouterOS 6.40.8 does not support Totally NSSA areas? [SOLVED]

I will need to redistribute some static routes from area1 to the backbone area, so the area must be nssa to allow for an ASBR.
by ners
Fri Nov 02, 2018 11:03 am
Forum: Forwarding Protocols
Topic: RouterOS 6.40.8 does not support Totally NSSA areas? [SOLVED]
Replies: 4
Views: 641

RouterOS 6.40.8 does not support Totally NSSA areas? [SOLVED]

Hello, I configured an ABR as following: R1: /routing ospf area add area-id=0.0.0.1 inject-summary-lsas=no name=area1 type=nssa Inter-area routes are now suppressed by R1, however I am still seeing AS external routes in area1 injected by R1. How do I configure a totally nssa area where both Type3 an...
by ners
Thu Sep 06, 2018 11:55 am
Forum: General
Topic: [ Bug/Vulnerability] RouterOS requires PIM enabled on subscriber interfaces for IGMP to work
Replies: 0
Views: 289

[ Bug/Vulnerability] RouterOS requires PIM enabled on subscriber interfaces for IGMP to work

/routing pim interface add interface=sfp-sfpplus2 protocols=pim add interface=ether8 protocols=igmp /routing pim rp add address=10.0.1.2 sfp-sfpplus2 is the uplink interface where the RP can be located. ether8 is the client interface the IPTV receiver is connected to. The receiver subscribes to an ...
by ners
Thu Apr 19, 2018 8:58 am
Forum: General
Topic: Is this order of simple queues optimal?
Replies: 0
Views: 261

Is this order of simple queues optimal?

I have the following setup, the goal is to prioritize a particular multicast stream on the link so that in case of congestion it would get through without hiccups: /queue simple add max-limit=190M/190M name=parf_all queue=default/default target=vlan2506 add max-limit=190M/190M name=parf_iptv packet-...
by ners
Mon Apr 16, 2018 12:23 pm
Forum: General
Topic: Is there a way to prioritize traffic without piping everything through queues?
Replies: 5
Views: 484

Re: Is there a way to prioritize traffic without piping everything through queues?

It can, using the queues. DSCP is just a way to convey the information about required priority. Any operating system works the same way - classifies the traffic based on some local criteria or accepts external classification received in L3/DSCP or L2/CoS fields, and then uses a queueing mechanism t...
by ners
Mon Apr 16, 2018 12:09 pm
Forum: General
Topic: Is there a way to prioritize traffic without piping everything through queues?
Replies: 5
Views: 484

Re: Is there a way to prioritize traffic without piping everything through queues?


I's impossible to prioritize something without inspecting it.
So RouterOS is crippled in that regard? It can't do DSCP-based QoS?
by ners
Mon Apr 16, 2018 11:09 am
Forum: General
Topic: Is there a way to prioritize traffic without piping everything through queues?
Replies: 5
Views: 484

Is there a way to prioritize traffic without piping everything through queues?

I want to be able to give a particular multicast stream higher priority from the rest of the traffic on a link so in case of congestion it would still get through without hiccups. Everything I managed to find in the internet about prioritizing traffic on RouterOS deals with putting the traffic in qu...
by ners
Fri Jun 23, 2017 5:45 am
Forum: General
Topic: Neighbor Discovery broken on CRS - all neighbors are. on master-port
Replies: 1
Views: 375

Neighbor Discovery broken on CRS - all neighbors are. on master-port

CRS, 6.38.7

Neighbor discovery shows all neighbors to reside on the master port. This makes the whole thing pointless. How to make it show neighbors on their actual interfaces? Thanks.
by ners
Fri May 12, 2017 1:23 pm
Forum: Forwarding Protocols
Topic: 1072, bgp advertisments print resets BGP seessions
Replies: 1
Views: 468

1072, bgp advertisments print resets BGP seessions

CCR1072-1G-8S+ running on 6.37.5 (bugfix).

I have 5 full-view BGP sessions running on it
Whenever I issue "/routing bgp advertisements print" all BGP sessions go down and get re-established.

What can be done about this?

Thanks.
by ners
Mon Feb 27, 2017 9:23 pm
Forum: General
Topic: How to force RouterOS to not use more specific routes
Replies: 1
Views: 299

How to force RouterOS to not use more specific routes

I have a bunch of /32 routes fed into RouterOS by an OSPF peer. I also have more "general" routes in my routing table installed by BGP. What are some possible ways to force RouterOS NOT to use /32 routes in a specific case (for example based on src-address-list or some packet mark or something?). We...
by ners
Fri Dec 16, 2016 10:17 pm
Forum: General
Topic: Huge bug: Mikrotik allows adding overlapping networks.
Replies: 15
Views: 1622

Re: Huge bug: Mikrotik allows adding overlapping networks.

I love using overlapping subnets. It sometimes eases deployments and avoids weird NAT-scenarios. Also overlapping subnets can solve IPv4 shortage. It is possible to route between mikrotik routers only wasting one public IPv4 address per Router.... Are you saying that assigning 10.7.19.89/29 (the sa...
by ners
Fri Dec 16, 2016 11:34 am
Forum: General
Topic: Huge bug: Mikrotik allows adding overlapping networks.
Replies: 15
Views: 1622

Re: Huge bug: Mikrotik allows adding overlapping networks.

To be serious: You configure the device, so you're in charge to do it right, no? A very immature and irresponsible approach. The human brain has a hard time dealing with numbers so mistakes are always possible and they can cost a lot (financially too). RouterOS must do some kind of verification to ...
by ners
Fri Dec 16, 2016 11:12 am
Forum: General
Topic: Huge bug: Mikrotik allows adding overlapping networks.
Replies: 15
Views: 1622

Huge bug: Mikrotik allows adding overlapping networks.

This is real, this is a serious issue. Mikrotik allows adding networks which overlap each other. For example: [admin@rt-office] /ip address add address=10.9.17.89/29 interface=vlan33 [admin@rt-office] /ip address add address=10.9.17.93/30 interface=vlan120 [admin@rt-office] /ip address print where n...
by ners
Thu Aug 11, 2016 11:40 am
Forum: General
Topic: What's faster&easier on the CPU: "conntrack off" or "conntrack on + fasttrack"?
Replies: 9
Views: 1351

Re: What's faster&easier on the CPU: "conntrack off" or "conntrack on + fasttrack"?

It is also not as clear cut as the answer suggests. When you have conntrack off but you have a long list of static access list items that needs to be traversed for every packet going through, it might well be slower than having conntrack on and an established/related rule at the top of the list. (e...
by ners
Wed Aug 10, 2016 12:07 pm
Forum: General
Topic: What's faster&easier on the CPU: "conntrack off" or "conntrack on + fasttrack"?
Replies: 9
Views: 1351

What's faster&easier on the CPU: "conntrack off" or "conntrack on + fasttrack"?

SUBJ pretty much says it all. What's better from the performance point of view?
by ners
Mon Nov 23, 2015 12:46 pm
Forum: General
Topic: [Feature suggest] Improve "/ip route check" to show route to be used, not only out-interface
Replies: 0
Views: 672

[Feature suggest] Improve "/ip route check" to show route to be used, not only out-interface

The /ip route check command now only shows the interface which will be used to forward a packet destined for the given ip address. It would be far more useful to include info on the specific route it will use to forward the packet. Right now it's like this: [admin@cr] > /ip route check 8.8.8.8 statu...
by ners
Fri Aug 14, 2015 1:53 pm
Forum: General
Topic: CRS and Q-BRIDGE.MIB
Replies: 0
Views: 365

CRS and Q-BRIDGE.MIB

Do Mikrotik CRS switches support Q-BRIDGE? Right now I'm trying to get:
http://tools.cisco.com/Support/SNMP/do/ ... oidContent

And it returns empty, what can be done here?

I'm on 6.30.2
by ners
Thu Aug 13, 2015 10:42 am
Forum: General
Topic: Now we need RSA support - OpenSSH 7.0 has removed DSA support
Replies: 3
Views: 819

Re: Now we need RSA support - OpenSSH 7.0 has removed DSA support

RSA support is long overdue! I hate having to keep a separate DSA key just for accessing my Mikrotik hardware (which is plenty).
by ners
Thu Aug 13, 2015 10:05 am
Forum: General
Topic: proxy-arp not working when request came from the same interface where target is
Replies: 0
Views: 279

proxy-arp not working when request came from the same interface where target is

Guys, I have a network 10.0.0.0/28, I have a router and a L2 switch, to which 2 hosts are connected. I need the hosts 10.0.0.2 and 10.0.0.3 to access each other. Communications between hosts is blocked on the switch but the hosts can access their default gateway. If I set proxy-arp on the Mikrotik's...
by ners
Thu Aug 06, 2015 10:32 am
Forum: General
Topic: Simple Queue not working when Fasttrack enabled
Replies: 28
Views: 19640

Re:

Then exclude those ips from fasttrack first.
Too much of a hassle, really, not elegant and is just a duct tape solution to a bad design decision.
by ners
Wed Aug 05, 2015 11:19 am
Forum: General
Topic: Simple Queue not working when Fasttrack enabled
Replies: 28
Views: 19640

Re: Simple Queue not working when Fasttrack enabled

Simple queues should override fasttrack for specific IP/Interfaces where it is applicable.
by ners
Sat Aug 01, 2015 2:41 pm
Forum: General
Topic: Simple Queue not working when Fasttrack enabled
Replies: 28
Views: 19640

Re: Simple Queue not working when Fasttrack enabled

The current implementation is not optimal. It should implemented in such a way, that Fasttrack gets disabled only for such traffic which cannot be fasttracked (due to simple queues, firewall rules etc...). The presence of simple queues for certain targets should not disable Fasttrack for everything ...
by ners
Sat Jun 13, 2015 7:53 pm
Forum: General
Topic: Apply IPSec policy to all traffic on GRE tunnel -- impossible?
Replies: 9
Views: 2216

Re: Apply IPSec policy to all traffic on GRE tunnel -- impossible?

In the IPSEC policy just change the protocol from all to GRE . This will then cause only the encryption of GRE packets leaving all other traffic in the clear. Out of curiosity what other traffic are you worried about being encrypted by the more open policy? Wah, I missed that. Thanks, with protocol...
by ners
Sat Jun 13, 2015 12:24 am
Forum: General
Topic: Apply IPSec policy to all traffic on GRE tunnel -- impossible?
Replies: 9
Views: 2216

Re: Apply IPSec policy to all traffic on GRE tunnel -- impossible?

It's basically like this: Two routers: R1 (HQ) <---------GRE----------> R2 (Remote branch) R1 WAN IP: 81.29.10.2 R1 GRE IP: 172.17.1.1/30 R2 WAN IP: 77.232.60.34 R2 GRE IP: 172.17.1.2/30 LAN at remote branch: 10.222.0.0/16 Many different hosts located in different networks are routed through the HQ ...
by ners
Fri Jun 12, 2015 9:52 pm
Forum: General
Topic: Apply IPSec policy to all traffic on GRE tunnel -- impossible?
Replies: 9
Views: 2216

Re: Apply IPSec policy to all traffic on GRE tunnel -- impossible?

[admin@crs] /ip ipsec policy> set 1 tunnel=no failure: transport mode policy must match sa endpoints eh, still no luck. It seems it wants me to make src and sa-src and dst and sa-dst addresses the same. That means that all traffic between the two routers will be matched, not just the GRE tunnel. :-/
by ners
Fri Jun 12, 2015 9:25 pm
Forum: General
Topic: Apply IPSec policy to all traffic on GRE tunnel -- impossible?
Replies: 9
Views: 2216

Re: Apply IPSec policy to all traffic on GRE tunnel -- impossible?

Thank you for your reply. Yeah, I just need to secure the tunnel itself. In fact I tried to specify tunnel endpoints in src-address and dst-address in policy and set tunnel=yes (afaik transport mode only secures traffic originating and destined to the peers themselves, not other hosts) but it got me...
by ners
Fri Jun 12, 2015 7:13 pm
Forum: General
Topic: Apply IPSec policy to all traffic on GRE tunnel -- impossible?
Replies: 9
Views: 2216

Apply IPSec policy to all traffic on GRE tunnel -- impossible?

Hi, I have a situation where I've got two CCRs with a GRE tunnel between them. The problem is, I need to secure all random traffic which goes over that GRE tunnel with IPSec. In the settings where you define policy, you are only allowed to match packets based on their src/dst-address information, no...
by ners
Wed May 06, 2015 4:13 pm
Forum: General
Topic: CCR1036-8G-2S+EM as a BGP router
Replies: 4
Views: 823

Re: CCR1036-8G-2S+EM as a BGP router

3 full view, 3 gbps, with conntrack enabled 40-50% CPU.
by ners
Tue May 05, 2015 12:54 pm
Forum: General
Topic: CRS documentation
Replies: 79
Views: 30170

Re: CRS documentation

Any plans to introduce support for MST and LACP?
by ners
Mon May 04, 2015 12:58 am
Forum: General
Topic: Possible bug in RouterOS's SSH server
Replies: 3
Views: 566

Re: Possible bug in RouterOS's SSH server

I contacted VanDyke's support and after an investigation they told me the following: > the SSH server is sending a packet with an invalid SFTP request ID. > Here is the malformed packet SecureFX receives from the server: 00 > 00 00 2c 0d 5e 00 00 00 00 00 00 00 15 00 00 00 11 65 73 2d 6d 75 00 > 00 ...
by ners
Fri May 01, 2015 6:52 pm
Forum: General
Topic: Possible bug in RouterOS's SSH server
Replies: 3
Views: 566

Possible bug in RouterOS's SSH server

I am using VanDyke's SecureFX for accessing my boxes via SFTP. However SecureFX fails to connect to a Mikrotik RouterOS device. At some point the connection process just stops. People at VanDyke say there is a bug with Mikrotik's SSH server: it is sending a packet with an invalid "request-id" value....
by ners
Tue Feb 24, 2015 2:48 pm
Forum: General
Topic: How to lookup a route in /ip route table?
Replies: 0
Views: 365

How to lookup a route in /ip route table?

I need to know what interface a certain packet with dst-address set to x.x.x.x will be routed to. How can I do that?
Even /ip route print where ~"x.x.x.x" takes a horribly long time with BGP full view.
by ners
Tue Feb 24, 2015 2:46 pm
Forum: General
Topic: How to display Mikrotik's SSH keys fingerprint.
Replies: 2
Views: 765

How to display Mikrotik's SSH keys fingerprint.

How do I check Mikrotik's SSH keys fingerprint in the RouterOS CLI?
by ners
Fri Dec 12, 2014 9:24 am
Forum: General
Topic: DNAT with dst-address unset not working at all
Replies: 2
Views: 598

Re: DNAT with dst-address unset not working at all

Why do you need mangle in this case? What's the point of marking connections in this particular setup?
by ners
Wed Dec 10, 2014 10:21 am
Forum: General
Topic: DNAT with dst-address unset not working at all
Replies: 2
Views: 598

DNAT with dst-address unset not working at all

Hi, I am trying to redirect all HTTP requests (to any IP address) from users within a specific network to a local web server but apparently my rule is not working. Connection tracking is set to auto , RouterOS version is 6.19, the rule is enabled, no other NAT rules are present in /ip firewall nat M...
by ners
Fri Nov 14, 2014 1:56 pm
Forum: General
Topic: Traffic-flow high CPU usage
Replies: 0
Views: 835

Traffic-flow high CPU usage

RouterOS 6.19, board-name: CCR1036-8G-2S+ Traffic-flow always consumes too much CPU, in the evening it can easily eat up to 70% of the CPU contributing to the lion's share of the total CPU load. What can be done to remedy this? Is there anything? [vysh@crs] > /tool profile NAME CPU USAGE ethernet al...
by ners
Thu May 15, 2014 9:23 am
Forum: General
Topic: v6.12 released
Replies: 237
Views: 57495

Re: v6.12 released

RB2011UAS + ROS 6.12 + Firmware 3.14 09:51:01 l2tp,info first L2TP UDP packet received from xxx.xxx.xxx.xxx 09:51:01 l2tp,ppp,info,account coaxial logged in, 172.16.12.186 09:51:02 l2tp,ppp,info <l2tp-coaxial>: authenticated 09:51:02 l2tp,ppp,info <l2tp-coaxial>: connected 10:16:41 l2tp,ppp,info <l2...
by ners
Wed May 14, 2014 11:05 pm
Forum: General
Topic: v6.12 released
Replies: 237
Views: 57495

Re: v6.12 released

ROS 6.12 RB2011. no buffer space available... Network doesn't work. After reboot everything ok. I tried to update the firmware but does not help. Same problem here as well after uptime of 4 weeks.... Same here, seems to be tied to L2TP/IPSec since I started experiencing this when I set up L2TP/IPSe...
by ners
Wed May 07, 2014 4:32 pm
Forum: General
Topic: Mikrotik L2TP/IPSec as client.
Replies: 5
Views: 2290

Re: Mikrotik L2TP/IPSec as client.

Yes, I saw Your link. Am I understand correct L2TP connects before IPSec part? I configured IPSec part also, but first of all I understand that L2TP must be up and running. L2TP will try to iniciate the connection - but will NOT be able to connect before IPSec negotiates security. So L2TP trying to...
by ners
Tue Apr 29, 2014 2:56 pm
Forum: RouterBOARD hardware
Topic: CLOUD CORE ROUTER
Replies: 1374
Views: 1015827

Re: CLOUD CORE ROUTER

Is the inability to queue more than 500 Mbit/s in any plans to be fixed? Right now we have to maintain 5 CCRs 1036 to process about 2Gb/sec of shaped PPPoE traffic (350 Mbit/s each) :-/
by ners
Tue Apr 22, 2014 2:40 pm
Forum: General
Topic: Switching with RouterOS / CRS Questions
Replies: 81
Views: 43611

Re: Switching with RouterOS / CRS Questions

After resetting the configuration and configuring it from scratch it hangs again after issuing /export and also does not pass any traffic: The configuration is as following: /interface ethernet set [ find default-name=sfp1 ] master-port=ether24 set [ find default-name=ether1 ] master-port=ether24 se...
by ners
Tue Apr 22, 2014 2:17 pm
Forum: General
Topic: Switching with RouterOS / CRS Questions
Replies: 81
Views: 43611

Re: Switching with RouterOS / CRS Questions

But my management IPs reside not in a VLAN, but rather in the native VLAN, which is not a 802.1q VLAN at all, it is just normal untagged traffic, this is why I put the IP address on the physical master-port (ether24 in my case). IP address on the master-port is correct for untagged traffic, but in ...
by ners
Tue Apr 22, 2014 12:52 pm
Forum: General
Topic: Switching with RouterOS / CRS Questions
Replies: 81
Views: 43611

Re: Switching with RouterOS / CRS Questions

michaelahess, The follwing Cloud Router Switch configuration should be applied for your setup: 3) For security disable invalid VLAN forwarding globally or on each port separately like this: /interface ethernet switch set drop-if-invalid-or-src-port-not-member-of-vlan-on-ports="ether2-master-local,e...
by ners
Tue Apr 22, 2014 12:49 pm
Forum: General
Topic: Switching with RouterOS / CRS Questions
Replies: 81
Views: 43611

Re: Switching with RouterOS / CRS Questions

ners, You should add a VLAN interface to master-port in RouterOS and add IP address to it. From switch point there is switch1-cpu port, not the master-port. /interface vlan add name=vlan59 vlan-id=59 interface=ether24 /interface ethernet switch egress-vlan-tag add tagged-ports=switch1-cpu vlan-id=5...
by ners
Mon Apr 21, 2014 11:08 am
Forum: General
Topic: Switching with RouterOS / CRS Questions
Replies: 81
Views: 43611

Re: Switching with RouterOS / CRS Questions

Has anyone figured out how to set ip a management IP on a CRS in the native VLAN? Simply adding an IP to the physical master port is not enough, apparently. 172.16.16.8 is unpingable and no other hosts in the network see 172.16.16.8. the ARP table is also empty. /ip address add address=172.16.16.8/2...
by ners
Thu Apr 17, 2014 8:42 am
Forum: General
Topic: v6.12 released
Replies: 237
Views: 57495

Re: v6.12 released

Old VLAN code working on 6.11: /interface ethernet switch ingress-vlan-translation add customer-vid=0 new-customer-vid=701 ports=ether2 sa-learning=yes /interface ethernet switch egress-vlan-translation add customer-vid=701 new-customer-vid=0 ports=ether2 This correctly exports on a CRS still runni...
by ners
Wed Apr 16, 2014 9:57 pm
Forum: General
Topic: v6.12 released
Replies: 237
Views: 57495

Re: v6.12 released

CRS on 6.12, ip addresses on physical interfaces ("native VLAN") stopped working: /ip address add address=172.16.16.8/24 interface=ether24 network=172.16.16.0 /interface ethernet set [ find default-name=sfp1 ] master-port=ether24 set [ find default-name=ether1 ] master-port=ether24 set [ find defaul...
by ners
Tue Apr 15, 2014 9:04 am
Forum: General
Topic: CRS not passing traffic to access ports
Replies: 4
Views: 1028

Re: CRS not passing traffic to access ports

In RouterOS v6.10 configure this without a VLAN table entry:

ros code

/interface ethernet switch vlan
add ports=ether1,ether24 sa-learning=yes vlan-id=59
Thank you, that worked. But how do I restrict which VLANs are allowed on trunk ports and which are not then?
by ners
Tue Apr 15, 2014 8:19 am
Forum: General
Topic: CRS not passing traffic to access ports
Replies: 4
Views: 1028

Re: CRS not passing traffic to access ports

Anyone?
by ners
Mon Apr 14, 2014 8:08 pm
Forum: RouterBOARD hardware
Topic: CLOUD CORE ROUTER
Replies: 1374
Views: 1015827

Re: CLOUD CORE ROUTER

I would like to confirm that the CCR1036 is good and stable for 1Gbit/sec NAT on 6.9. uptime: 5w5d20h25m43s version: 6.9 build-time: Jan/31/2014 11:18:19 free-memory: 3483.3MiB total-memory: 3969.0MiB cpu: tilegx cpu-count: 36 cpu-frequency: 1200MHz cpu-load: 15% free-hdd-space: 903.6MiB total-hdd-s...
by ners
Mon Apr 14, 2014 6:17 pm
Forum: General
Topic: CRS not passing traffic to access ports
Replies: 4
Views: 1028

CRS not passing traffic to access ports

Hi, just got a brand new CRS125-24G-1S and I'm trying to figure out the configuration. Right now I'm attempting to create a simple setup like this: Cisco3550 <-------trunk vlans 1,59--------> CRS125-24G-1S <-----access vlan 59-----> PC ether24 is a trunk port where only VLANs 1 (default) and 59 are ...
by ners
Wed Apr 09, 2014 4:39 pm
Forum: General
Topic: Src NAT with -same rules on 6.x
Replies: 3
Views: 1738

Re: Src NAT with -same rules on 6.x

Try same-not-by-dst=yes, it might help and I consider it to be best practice for batting.
by ners
Tue Mar 25, 2014 10:35 pm
Forum: RouterBOARD hardware
Topic: CLOUD CORE ROUTER
Replies: 1374
Views: 1015827

Re: CLOUD CORE ROUTER

anyone tried 6.11 on ccr? i am still stuck at 6.7 because 6.9 and 6.10 run unstable. max uptime was about 4 days. I did and experienced a very weird bug. Suddenly some vlan interfaces stopped working. They just wouldn't pass traffic at all although shown as running and I could ping their addresses ...
by ners
Wed Mar 12, 2014 12:47 pm
Forum: RouterBOARD hardware
Topic: CLOUD CORE ROUTER
Replies: 1374
Views: 1015827

Re: CLOUD CORE ROUTER

ners , thank you for reply! Could you provide please some more details: 1. What is maximum utime? 2. Current version of ROS. 3. Does NAT utilise multi cores or single core? 1. uptime: 1w14h8m27s (I started using it for NAT a week ago). 2. version: 6.9 3. # CPU LOAD IRQ DISK 0 cpu0 7% 7% 0% 1 cpu1 5...
by ners
Mon Mar 10, 2014 12:41 pm
Forum: RouterBOARD hardware
Topic: CLOUD CORE ROUTER
Replies: 1374
Views: 1015827

Re: CLOUD CORE ROUTER

Does anybody use CCR for NAT?

I need about 1G of NAT.
1Gb/sec NAT is fine for 1036.
by ners
Fri Mar 07, 2014 8:03 am
Forum: RouterBOARD hardware
Topic: CLOUD CORE ROUTER
Replies: 1374
Views: 1015827

Re: CLOUD CORE ROUTER

Looking to understand the impact of the Firewall on high speed routing on a CCR. The benchmark's refer to 25 rules, I assume they are "passing" rules rather than blocks? Ie the traffic is being checked 25 times in a row and passing before being routed on to the end locations. 1. What impact would r...
by ners
Mon Feb 10, 2014 10:14 am
Forum: General
Topic: CCR1036 PPPoE 1000+ clients 400+ Mbit/s degraded perfomance
Replies: 10
Views: 4129

Re: CCR1036 PPPoE 1000+ clients 400+ Mbit/s degraded perfoma

Thanks, I will have to load balance them then.
by ners
Tue Feb 04, 2014 5:22 pm
Forum: General
Topic: CCR1036 PPPoE 1000+ clients 400+ Mbit/s degraded perfomance
Replies: 10
Views: 4129

Re: CCR1036 PPPoE 1000+ clients 400+ Mbit/s degraded perfoma

Still capped at 400-500 Mbit/s, one of the cores is constantly at 100%: ners@aad-rt-nas01] > /sys reso cpu pr interval=1 # CPU LOAD IRQ DISK 0 cpu0 31% 31% 0% 1 cpu1 29% 29% 0% 2 cpu2 32% 32% 0% 3 cpu3 27% 27% 0% 4 cpu4 10% 10% 0% 5 cpu5 44% 43% 0% 6 cpu6 100% 100% 0% 7 cpu7 27% 27% 0% 8 cpu8 0% 0% ...
by ners
Tue Feb 04, 2014 6:12 am
Forum: General
Topic: CCR1036 PPPoE 1000+ clients 400+ Mbit/s degraded perfomance
Replies: 10
Views: 4129

CCR1036 PPPoE 1000+ clients 400+ Mbit/s degraded perfomance

Hi, we are using a CCR1036 RouterOS 6.6 as a PPPoE concentrator with simple queues for shaping. In the evening the number of online PPPoE connections reaches 1500. I started to notice that in the evening when the number of online PPPoE sessions exceeds 1000, clients' throughput starts to degrade. To...
by ners
Mon Dec 09, 2013 2:43 pm
Forum: General
Topic: Queue size for 500Mbit/s
Replies: 1
Views: 868

Queue size for 500Mbit/s

Guys is there a table available for best practice queue size for various speeds? For example I need to limit the WAN interface on my RouterOS 6.7 which is 1Gbit to 500Mbit/sec and I'm puzzled over which queue size would be best for this scenario. 50 packets would be too little, 500 probably too high...
by ners
Thu Dec 05, 2013 8:53 pm
Forum: General
Topic: v6.7 released
Replies: 225
Views: 109518

Re: v6.7 released

ners, open up '/tool profile' to see what is happening. make sure you are running 6.7
Apparently nothing is happening, Idle is 100% or 99,9% and everything else is 0%...
by ners
Thu Dec 05, 2013 2:50 pm
Forum: General
Topic: v6.7 released
Replies: 225
Views: 109518

Re: v6.7 released

My brand new CCR1036-8G-2S+EM arrived today and upgraded from v6.1 to v6.7. Now fans are still spinning up and down, up and down continuously. The fans control mode is set to automatic. Is this normal ? I also have a CCR1036-8G-2S+EM and it exhibits the same behavior on 6.7, the fans are spinning u...
by ners
Wed Dec 04, 2013 5:33 pm
Forum: General
Topic: Bug in ROS 6.7: simple queue ignores unlimited
Replies: 1
Views: 1003

Re: Bug in ROS 6.7: simple queue ignores unlimited

A simple queue with default parameters will not work -- it really is not even created. You should change the type of queue from default-small to default, for example, then it will work.
by ners
Sun Dec 01, 2013 7:02 pm
Forum: General
Topic: ipsec: failure to add policy
Replies: 2
Views: 1232

Re: ipsec: failure to add policy

Why can't the client find any policies?
Probably because you have not defined any.
Using 'generate-policy' on client side does not make any sense to me.
Mikrotik is not the client, it's the concentrator (server)
by ners
Sat Nov 30, 2013 5:50 pm
Forum: General
Topic: ipsec: failure to add policy
Replies: 2
Views: 1232

ipsec: failure to add policy

Hello, I'm trying to setup IPSec on Mikrotik RouterOS 6.6 but it isn't coming up, what is wrong with my setup? Why can't the client find any policies? /ip ipsec mode-cfg add address-pool=vpn-pool name=home-vpn /ip ipsec proposal set [ find default=yes ] enc-algorithms=aes-128 /ip ipsec peer add auth...
by ners
Thu Nov 28, 2013 1:58 pm
Forum: General
Topic: iPhone's Cisco VPN without split-tunneling not working
Replies: 1
Views: 1268

iPhone's Cisco VPN without split-tunneling not working

Hello guys, Two scenarios, one works, the other doesn't. I'm trying to connect to my home LAN based on RouterOS 6.6 (RB751G-2HnD) from my iPhone with iOS 7.0.4 using "Cisco VPN" and from my Mac with OS X 10.9 When I have split-include enabled, I can successfully connect and access my home LAN. All o...
by ners
Sat Nov 23, 2013 10:51 pm
Forum: General
Topic: Overriding simple queues applied to interfaces?
Replies: 4
Views: 1082

Re: Overriding simple queues applied to interfaces?

Thanks, I've done that and it seems to be working: /queue simple add dst=10.10.10.10/32 name=ftp-unlimited-4nat queue=default/default target=192.168.0.0/16 add dst=10.10.10.10/32 name=ftp-unlimited-4real queue=default/default target=192.0.2.0/24 However I still see queued and even dropped packets: [...
by ners
Sat Nov 23, 2013 5:56 pm
Forum: General
Topic: Overriding simple queues applied to interfaces?
Replies: 4
Views: 1082

Overriding simple queues applied to interfaces?

Is it possible to make a simple queue or a mangle rule/tree queue which would override any other simple queues which are dynamically created by Mikrotik-Rate-Limit RADIUS attribute and applied to the user's interface in RouterOS 6.x? For example RADIUS sends Mikrotik-Rate-Limit 2048k for a user, a d...
by ners
Thu Nov 21, 2013 10:55 am
Forum: General
Topic: only-one is ignored when radius auth is used
Replies: 2
Views: 619

only-one is ignored when radius auth is used

I am running a PPPoE server on a CCR-1036. My /ppp profile is: /ppp profile add dns-server=192.168.2.2 local-address=192.168.255.1 name=my-pppoe only-one=yes use-compression=no use-encryption=no use-vj-compression=no I use RADIUS for authentication. I see that the only-one parameter is ignored and o...
by ners
Mon Oct 07, 2013 12:18 pm
Forum: RouterBOARD hardware
Topic: CLOUD CORE ROUTER
Replies: 1374
Views: 1015827

Re: CLOUD CORE ROUTER

Can anyone tell if CCR1036-8G-2S+ will accept SFP modules in its SFP+ slots? I couldn't find any relevant info in the brochure.
by ners
Thu Aug 29, 2013 9:04 am
Forum: General
Topic: How to NOT shape traffic to certain blocks, simple queues
Replies: 0
Views: 362

How to NOT shape traffic to certain blocks, simple queues

Hi, I'm running a PPPoE server on Mikrotik 1100AHx2 ROS 6.2 Users authenticate via RADIUS, the RADIUS sends Mikrotik-Rate-Limit attribute to shape user's traffic, thus creating a dynamic simple queue tied to user's virtual interface. However I need to NOT shape traffic to certain IP blocks. How can ...
by ners
Thu Jul 25, 2013 3:46 pm
Forum: General
Topic: How to Block PPTP Traffic
Replies: 6
Views: 3426

Re: How to Block PPTP Traffic

ros code

/ip firewall filter add chain=forward protocol=gre action=reject reject-with=icmp-protocol-unreachable
Should block GRE protocol which is used by PPTP for data transfer, no other traffic should be affected.
by ners
Thu Jul 25, 2013 3:31 pm
Forum: General
Topic: How to Block PPTP Traffic
Replies: 6
Views: 3426

Re: How to Block PPTP Traffic

Block destination port TCP 1723 in the forward chain, or better block protocol type 47 (GRE) which is used by PPTP. That way you will also block PPTP services on non-standard ports.
by ners
Thu Jul 25, 2013 1:19 pm
Forum: General
Topic: ROS 6.x how to stop simple queues mess with queue tree
Replies: 0
Views: 734

ROS 6.x how to stop simple queues mess with queue tree

I am testing a PPPoE NAS on Mikrotik 1100AHx2, ROS 6.1 Radius sends Mikrotik-Rate-Limit attribute for each newly connected user. A dynamic simple queue is created like this: 0 D name="<pppoe-mikrotik_4m>" target=<pppoe-mikrotik_4m> parent=none packet-marks="" priority=8/8 queue=default-small/default...
by ners
Tue Jul 23, 2013 6:03 pm
Forum: General
Topic: IPSec succeeds but L2TP fails to establish - client lonely
Replies: 13
Views: 9005

IPSec succeeds but L2TP fails to establish - client lonely

Hi, i'm having rouble setting up L2TP+IPSec on RouterOS 6.1 I've been banging my head against a wall over the past couple of days. Please tell me what is wrong with my setup? As I see it, the client does not get any L2TP control responses from the server. My configs: /ip ipsec peer add exchange-mode...
by ners
Fri Mar 29, 2013 4:45 pm
Forum: General
Topic: Any way to filter routes by gateway address?
Replies: 0
Views: 323

Any way to filter routes by gateway address?

On every business day of the week I get a default route via DHCP which looks like 0.0.0.0/0 via 209.165.200.1 which gives full access, and on every weekend I get 0.0.0.0/0 via 10.120.0.1 instead which enables limited access. Also I have a static default route via a PPPoE link which is always active....
by ners
Sat Mar 23, 2013 9:03 am
Forum: RouterBOARD hardware
Topic: CLOUD CORE ROUTER
Replies: 1374
Views: 1015827

Re: CLOUD CORE ROUTER

I'm very disappointed with the CCR-1036, it is being advertised as a carrier grade router, yet it cannot do NAT more than 250Mbit/sec (around 30k packets/sec) without falling throughput :(
This is probably enough for a small business, but certainly not for anything serious.
by ners
Wed Mar 20, 2013 7:50 pm
Forum: General
Topic: Upload suffers greatly when download is active
Replies: 10
Views: 1192

Re: Upload suffers greatly when download is active

Odd.. Ive used plain jane PCQ via simple rules minus the mangle rules with speeds as low as 512k/256k before without issue... someone else will have to chime in, im totally stumped. Yes, minus the mangle rules. Something tells me this problem is related to packet marking. Something in that departme...
by ners
Wed Mar 20, 2013 7:24 pm
Forum: General
Topic: Upload suffers greatly when download is active
Replies: 10
Views: 1192

Re: Upload suffers greatly when download is active

Hmmm, was just reading through mikrotik wiki looking for info on simple queues and noticed this: Flow Identifiers target-addresses (multiple choice: IP address/netmask) : list of IP address ranges that will be limited by this queue. interface (Name of the interface, or all) : identifies interface th...
by ners
Wed Mar 20, 2013 6:52 pm
Forum: General
Topic: Upload suffers greatly when download is active
Replies: 10
Views: 1192

Re: Upload suffers greatly when download is active

The other thing you could do since you are using PPPOE... what does your pppoe authentication, radius? you can set user speeds via radius attributes too. All they do is dynamically create a simple queue tho. Yes, I authenticate users via RADIUS. Right now RADIUS supplies MT-Address-List attribute w...
by ners
Wed Mar 20, 2013 9:37 am
Forum: General
Topic: Upload suffers greatly when download is active
Replies: 10
Views: 1192

Re: Upload suffers greatly when download is active

Thank you, derr12 . I'll try your suggestion with queues as soon as I complete testing of NAT performance. Ultimately, I'm afraid simple queues are not an option for me, since I expect the amount of as many as 1000+ pppoe users to be connected to the NAS at the same time. I read somewhere here a pos...
by ners
Mon Mar 18, 2013 9:23 am
Forum: General
Topic: Upload suffers greatly when download is active
Replies: 10
Views: 1192

Upload suffers greatly when download is active

I use dynamic address-lists (radius sends attribute MT-address-list when a client connects which puts the client's address into an address list). Users connect as PPPoE clients to my Mikrotik which acts as a PPPoE server. My Mikrotik is the 36 core CCR, RouterOS is 6.0rc11. Well, everything works fi...
by ners
Mon Mar 18, 2013 9:06 am
Forum: General
Topic: PCQ-rate is divided between all users regardless of max-limi
Replies: 5
Views: 3778

Re: PCQ-rate is divided between all users regardless of max-

Thnks, derr12 :) I got it sorted out. However there's still one problem left. I guess a new thread is needed.
by ners
Sat Mar 16, 2013 10:05 am
Forum: General
Topic: PCQ-rate is divided between all users regardless of max-limi
Replies: 5
Views: 3778

Re: PCQ-rate is divided between all users regardless of max-

Thank you, derr12. I've altered my configuration and now it seems to be working as needed (two users get 1Mbit each). I have eliminated connection marking completely, still not sure why it was needed in the first place, and also in the queue tree I changed parent interface from "ether2" to "global"....
by ners
Fri Mar 15, 2013 12:46 pm
Forum: General
Topic: PCQ-rate is divided between all users regardless of max-limi
Replies: 5
Views: 3778

PCQ-rate is divided between all users regardless of max-limi

I'm trying to set up a PPPoE server on a Mikrotik router, 6.0rc11 I'm using PCQ queues to limit traffic for each separate user. For example, let's take the queue "TEST_1MB_DOWNLOAD". All users which are processed by this queue should receive 1 Megabit/sec download. However it's not working as expect...
by ners
Tue Mar 12, 2013 5:53 pm
Forum: General
Topic: Per connection limit per time interval with burst on Mikroti
Replies: 5
Views: 2404

Re: Per connection limit per time interval with burst on Mik

hm, do I understand this correctly, that this rule: add action=jump chain=forward connection-state=new dst-port=80 jump-target=anti-ddos protocol=tcp add action=return chain=anti-ddos dst-limit=40/5s,70,src-and-dst-addresses/1h will match from a single IP up to 70 new connections (burst) and then 40...
by ners
Tue Mar 12, 2013 5:15 pm
Forum: General
Topic: Per connection limit per time interval with burst on Mikroti
Replies: 5
Views: 2404

Re: Per connection limit per time interval with burst on Mik

http://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Filter Read about 'dst-limit' matcher. HTH, I read about it, but it does not solve my problem since it doesn't differentiate between separate source IPs. I mean it doesn't support a separate counter for each source IP, it's a global counter. And also...
by ners
Tue Mar 12, 2013 4:34 pm
Forum: General
Topic: Per connection limit per time interval with burst on Mikroti
Replies: 5
Views: 2404

Per connection limit per time interval with burst on Mikroti

Hello, i'm moving from a FreeBSD-based router to a RouterBoard. I'm currently on 6.0rc11 I've been trying to implement anti-ddos protection for my servers, but I can't quite figure it out. Is there a way to mimic this set of PF rules?: # anti ddos from 80 port table <ddos80> persist block in quick f...