Community discussions

Search found 75 matches

by i4jordan
Wed Mar 28, 2018 11:12 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 105745

Re: Blacklist Filter update script

I also would pay for such a service, no problem.
Maybe you can make something with a pay per device/year option?

In any way thank you for the intrusBL service!
by i4jordan
Wed Mar 07, 2018 10:06 am
Forum: General
Topic: Mikrotik State of the Art Security and Firewalling
Replies: 9
Views: 1031

Re: Mikrotik State of the Art Security and Firewalling

Where are you located? I am experienced in large ‘MikroTik’ networks. And might help you with this.

Which brand of switches are you going to use?
by i4jordan
Tue Jan 09, 2018 11:18 am
Forum: General
Topic: [ATTACHED] Mikrotik Rack-mounted Devices Visio Stencils
Replies: 28
Views: 18623

Re: [ATTACHED] Mikrotik Rack-mounted Devices Visio Stencils

Beutifull work. Very nice made. Thank you very much.
by i4jordan
Wed Nov 30, 2016 12:18 am
Forum: The User Manager
Topic: rb750gr3
Replies: 6
Views: 5602

Re: rb750gr3

The Rb750Gr3 is using a MMPIS cpu, not a MIPSBE!

For the MMIPS cpu there is no user manager package.
The same is for the ARM (RB3011 series).

I have no clue if there wil be a user manager package for the ARM or the MMIPS cpu.
by i4jordan
Wed Jun 15, 2016 11:25 am
Forum: General
Topic: Conditional DNS forwarding
Replies: 17
Views: 35084

Re: Conditional DNS forwarding

I also need conditional forwarding of DNS request.
We are using a lot of Mikrotik products for VPN tunnels for branche office usage. And need DNS forwarding to AD DNS domains to authenticate users on terminals/ client computers.
by i4jordan
Sun May 01, 2016 11:55 am
Forum: General
Topic: Can mikrotik work as Cascaded Proxy
Replies: 9
Views: 1106

Re: Can mikrotik work as Cascaded Proxy

Yes this is possible. I have made such a system, works perfect.
by i4jordan
Sat Apr 30, 2016 4:14 pm
Forum: RouterBOARD hardware
Topic: [SOLVED] Connect CCR1009 with CSR226 over a longer distance than 3 meter
Replies: 8
Views: 1437

Re: Connect CCR1009 with CSR226 over a longer distance than 3 meter

Active DAC 10Gbit is +/- € 120,- excl. VAT.
2x SFP+ incl. 10m LC-LC ONM3 cable is +/- € 150,-

So pricing is comparable.

SFP+ modules plus LC-LC cable gives you more flexibility. Just change the LC-LC cable if you need more or less lenght (up to around 300m).
by i4jordan
Sat Apr 30, 2016 2:53 am
Forum: RouterBOARD hardware
Topic: [SOLVED] Connect CCR1009 with CSR226 over a longer distance than 3 meter
Replies: 8
Views: 1437

Re: Connect CCR1009 with CSR226 over a longer distance than 3 meter

The mentioned SFP+ modules are 310nm versions special for short distance (up to 300 meters). Other modules are for longer distance, like 10km etc.
I am not sure SFP+ modules are compatible with 1Gbit SFP ports.
by i4jordan
Fri Apr 29, 2016 9:22 am
Forum: RouterBOARD hardware
Topic: [SOLVED] Connect CCR1009 with CSR226 over a longer distance than 3 meter
Replies: 8
Views: 1437

Re: Connect CCR1009 with CSR226 over a longer distance than 3 meter

Hello Jeroen, I am also from the Netherlands and can help you with this. Please send me a PM if needed. We are very experienced working with Mikrotik and DAC/SFP+ in combination with a lot of switching brands. For your info DAC is possible up to 10m, but that would require active DAC cables. In esse...
by i4jordan
Mon Apr 18, 2016 8:51 pm
Forum: Beginner Basics
Topic: Why WebProxy requests don't hit dst-nat ?
Replies: 10
Views: 1246

Re: Why WebProxy requests don't hit dst-nat ?

It will werk if you add those 'non excisting' IP adresses to a new bridge.
Call this bridge something like nat-bridge or nything you like.
Then add those 2 addresses 192.168.10.80/24 and .90/24 to this bridge.

That will do the job.
by i4jordan
Wed Mar 16, 2016 10:46 am
Forum: Announcements
Topic: v6.35rc [release candidate] is released, new wireless package!
Replies: 537
Views: 105640

Re: v6.35rc [release candidate] is released, new wireless package!

Strange behaviour of a RB3011 with v6.35.RC28 It sometimes reports very high and strange interface usage: [img] RB3011-high-interface-usage.jpg [/img] eth6 is connected to a LTE router (max.150/150Mbps) eth7 is connected to a ADSL2 router (max. 10/1 Mbps) eth8 is connected to a ADSL2 router (max. 10...
by i4jordan
Thu Mar 03, 2016 9:22 pm
Forum: General
Topic: CCR1009-8G-1S Replacement
Replies: 12
Views: 1055

Re: CCR1009-8G-1S Replacement

I think because there is also a CCR1009-8G-1S-1S+ model with 2GB RAM, LCD Screen and 10Gbit for just around $ 50,- more. For me that is the best priced model they offer.
by i4jordan
Thu Jan 21, 2016 10:11 pm
Forum: The Dude
Topic: Feature request: automating configuration backups
Replies: 4
Views: 1769

Re: Feature request: automating configuration backups

I have written a script which makes a backup and a configuration export on a attached USB stick. :global getDateTime do={ :local thisdate [/system clock get date]; :local thistime [/system clock get time]; :local year [:pick $thisdate 7 11]; :local month [:pick $thisdate 0 3]; :if ($month="jan") do=...
by i4jordan
Mon Jan 18, 2016 5:23 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188015

Re: Cloud Hosted Router

@Janisk

For now the 6.34rc39 version is not available. The latest is 6.34rc36.
by i4jordan
Mon Aug 10, 2015 1:04 pm
Forum: RouterBOARD hardware
Topic: CCR IPSec performance
Replies: 40
Views: 15451

Re: CCR IPSec performance

@MRZ Can you give us some good examples with ipSec tunnel and ipSec over GRE/IPIP (transport) to get the optimal best performance? I am dealing with this a lot and I see a lot of articles saying that MSS/packet size should be good to get optimal results, but I do not see any examples with the right ...
by i4jordan
Fri Jul 10, 2015 4:01 pm
Forum: RouterBOARD hardware
Topic: CCR1072 Availability
Replies: 29
Views: 15966

Re: CCR1072 Availability

It has arrived!
http://routerboard.com/CCR1072-1G-8Splus

Pricing is fair US$ 3050
by i4jordan
Fri Jul 10, 2015 4:00 pm
Forum: RouterBOARD hardware
Topic: CCR-1072 release date?
Replies: 71
Views: 13880

Re: CCR-1072 release date?

It has arrived!
http://routerboard.com/CCR1072-1G-8Splus

Pricing is fair US$ 3050
by i4jordan
Wed Feb 25, 2015 6:57 pm
Forum: General
Topic: IPsec encryption
Replies: 2
Views: 712

Re: IPsec encryption

Also the complete line of CCR routers do have hardware encryption.
by i4jordan
Tue Jan 27, 2015 2:46 pm
Forum: General
Topic: Mikrotik and HyperV
Replies: 3
Views: 2744

Re: Mikrotik and HyperV

Hyper-V does not work with the current ROS 6.xx software.

I do think we have to wait for 7.x because this version maybe is based on Linux kernel 3.4 or higher.
Starting with 3.4 Linux kernel there are native Hyper-V virtual device drivers included. Specially for networking you need those.
by i4jordan
Tue Jan 27, 2015 2:43 pm
Forum: Beginner Basics
Topic: WAN Bridge
Replies: 3
Views: 1173

Re: WAN Bridge

Bridging works fine. You can even filter the bridge L2 traffic or apply IP Firewall rules if IP Firewall is enabled on bridging. I have used this in a situation where production servers needed public WAN IP's without any natting. We applied IP filters and IP Firewall rules for security. Used a CCR10...
by i4jordan
Sun Jan 25, 2015 3:56 pm
Forum: General
Topic: Feature Request: DNS package
Replies: 13
Views: 3019

Re: Feature Request: DNS package

+1
Would be perfect!
Would make MKT the best branch office router/firewall/VPN device there is.
by i4jordan
Thu Jan 22, 2015 4:54 pm
Forum: General
Topic: RB2011 PPPoE not more than 200 Mbps
Replies: 11
Views: 2474

Re: RB2011 PPPoE not more than 200 Mbps

We tested RB2011 also and do not get more than 270Mbps with routing/nat.

RN850Gx2 http://routerboard.com/RB850Gx2
If you do not need more than 5 Ethernet ports.
or
RB1100Ahx2 http://routerboard.com/RB1100AHx2
or
CCR1009 http://routerboard.com/CCR1009-8G-1S
by i4jordan
Wed Jan 14, 2015 12:29 am
Forum: General
Topic: Sonic wall speed vs. Mikrotik speed
Replies: 8
Views: 1861

Re: Sonic wall speed vs. Mikrotik speed

I work with SonicWall, Mikrotik and some other brands and I do like both brands for different reasons. SonicWall is performing very good (I worked with NSA3500 series) and for sure is the ipsec tunneling very stable and very fast. SonicWall has VTI interfaces with good routing possibilities on ipsec...
by i4jordan
Thu Dec 11, 2014 3:21 pm
Forum: General
Topic: GRE over IPSEC, CCR, VERY SLOW
Replies: 39
Views: 15709

Re: GRE over IPSEC, CCR, VERY SLOW

It looks like Mikrotik has finally improved VPN performance in CCR models. :D Here is the changelog for 6.24rc2 ---- What's new in 6.24rc2 (2014-Dec-10 11:04): *) fixed problem where some of ethernet cards do not work on x86; *) improved CCR ethernet driver (less dropped packets); *) improved queue ...
by i4jordan
Wed Nov 05, 2014 4:07 pm
Forum: General
Topic: GRE over IPSEC, CCR, VERY SLOW
Replies: 39
Views: 15709

Re: GRE over IPSEC, CCR, VERY SLOW

@mrz I am very surprised with you explanation. We bought several CCR models to be able to handle ipsec VPN tunnels at high speed. Also because of the hardware AES support. We build VPN networks for our customers. That's our job. Now you are telling us that the ipsec speed problems (which are mention...
by i4jordan
Fri Oct 10, 2014 2:53 pm
Forum: General
Topic: GRE over IPSEC, CCR, VERY SLOW
Replies: 39
Views: 15709

Re: GRE over IPSEC, CCR, VERY SLOW

I think there is a huge problem with working with GRE tunnels with ipsec on teh CCR series. Also with IPIP + ipsec. We have a RB1100AHx2 connected via a GRE tunnel to a CCR1036. The RB1100AHx2 is connected with cable 120/10Mbit and the CCR with fiber 500/500 Mbit. If we disable ipsec on that tunnel ...
by i4jordan
Sun Sep 21, 2014 8:38 am
Forum: Beginner Basics
Topic: WAN subnet with gateway outside subnet
Replies: 5
Views: 1287

Re: WAN subnet with gateway outside subnet

@sob

Thank you, I am going to try this.
by i4jordan
Sun Sep 21, 2014 12:19 am
Forum: Beginner Basics
Topic: WAN subnet with gateway outside subnet
Replies: 5
Views: 1287

Re: WAN subnet with gateway outside subnet

@docmarius

I tried this. But no result?
First add route 66.159.5.254/32 -> ether1
Then add route 0.0.0.0/0 -> 66.159.5.254 (not reachable)

Also no result :(

Thank you for your suggestion.
by i4jordan
Sat Sep 20, 2014 11:33 pm
Forum: Beginner Basics
Topic: WAN subnet with gateway outside subnet
Replies: 5
Views: 1287

WAN subnet with gateway outside subnet

We have a subnet from our provider stated 66.159.4.104/29 (addresses 66.159.4.104-110) The default gateway is 66.159.5.254 ?? If I enter this in a SonicWall it works. But when I want to program this ISP in a mikrotik it failes. I add address 66.159.4.110/29 to ether1. An add the route to 0.0.0.0/0 t...
by i4jordan
Fri Aug 22, 2014 11:36 am
Forum: General
Topic: Destination NAT via interface instead of specific IP?
Replies: 5
Views: 954

Re: Destination NAT via interface instead of specific IP?

Janisk,

Please reread the post from calvarez. The question is about dst-nat, not src-nat.
by i4jordan
Thu Aug 21, 2014 11:09 pm
Forum: General
Topic: Feature Request: DNS Override for specific subnets
Replies: 19
Views: 5981

Re: Feature Request: DNS Override for specific subnets

+1 for me. We need this for small satellite offices connected via VPN to large main office. You need this kind of DNS lookup in case of Active Directory login. Now we 'solve' this with adding the main office DNS servers in de DHCP options as primary DNS. But this also give a lot of DNS traffic for s...
by i4jordan
Mon Aug 11, 2014 2:29 pm
Forum: General
Topic: IP cloud useless behind NAT
Replies: 29
Views: 18243

Re: IP cloud useless behind NAT

Normis, and what if we use multiple WAN connecties?

Does this also work with the new version of The Mikrotik cloudservices?
by i4jordan
Sat Aug 09, 2014 12:53 pm
Forum: RouterBOARD hardware
Topic: CCR IPSec performance
Replies: 40
Views: 15451

Re: CCR IPSec performance

Normis,

Thank you for the numbers. It helps a lot in designing VPN networks.

Do you also have some numbers on the 'older' RB1100AHx2 models?

I'd like to know speed of the ipsec tunnels and also the GRE+ipsec speed.

Other question, which is fatser: GRE+ipsec or IPIP+ipsec.

Thank you!
by i4jordan
Sat Aug 09, 2014 12:48 pm
Forum: RouterBOARD hardware
Topic: Mikrotik DAC SFP+ Cables compatibility
Replies: 7
Views: 3367

Re: Mikrotik DAC SFP+ Cables compatibility

I am building a large 10Gbit network with Dell PowerConnect equipement. Core switches are 2x Dell PowerConnect 8132F in stack (same as the new N4000 series), field switches are 5548(P) models also stacked. All connections between core switches and field switches are teamed 10Gbit connections. For al...
by i4jordan
Thu Jul 17, 2014 1:28 pm
Forum: General
Topic: Share cable IPTV & Internet RB951G/CRS125
Replies: 18
Views: 11715

Re: Share cable IPTV & Internet RB951G/CRS125

@Etz

I do not say your solution is not working.
It is more that I have not worked with IGMP Proxy. I will take some time to learn more about these features.

Thank you for your explanations.
by i4jordan
Thu Jul 17, 2014 12:59 pm
Forum: General
Topic: Share cable IPTV & Internet RB951G/CRS125
Replies: 18
Views: 11715

Re: Share cable IPTV & Internet RB951G/CRS125

@Etz Yes flat would be perfect but is not working in his situation. The STB's are not using a 'standard' internet connection. They have a separate network on the provider network and should have direct IP's from the provider. So also no NAT. The LAN devices require a 'normal' internet connection and...
by i4jordan
Thu Jul 17, 2014 2:13 am
Forum: General
Topic: Share cable IPTV & Internet RB951G/CRS125
Replies: 18
Views: 11715

Re: Share cable IPTV & Internet RB951G/CRS125

Sharing multiple networks one cable can be done with VLAN's. But you need a VLAN capable device on both sides of the network. There are simple 8 of 16 port switches which support Layer2 VLAN. Like TPLInk TL-SG1016DE ( http://nl.tp-link.com/products/details/?categoryid=&model=TL-SG1016DE#spec ) Prici...
by i4jordan
Thu Jul 17, 2014 2:00 am
Forum: Beginner Basics
Topic: CCR1036+SFP
Replies: 1
Views: 634

Re: CCR1036+SFP

http://www.flexoptix.net/en/sfp-zx-1-gi ... m-dom.html

You can choose a compatibility type in this shop.
Maybe Mikrotik support can help with choosing the right one.
by i4jordan
Tue Jul 08, 2014 10:04 am
Forum: General
Topic: v6.15 released
Replies: 302
Views: 103323

Re: v6.15 released

@nz_monkey Thank you for making this VTI feature more clear for everyone. I was not aware that VTI implementation in the SonicWall is a standard supported by other brands. I hope Mikrotik takes some time to improve IPsec performance and features because the main thing we do is making VPN networks fo...
by i4jordan
Mon Jul 07, 2014 3:45 pm
Forum: General
Topic: v6.15 released
Replies: 302
Views: 103323

Re: v6.15 released

@MRZ On a SonicWall you only provide ipsec settings in the VTI settings dialogs. And yes those are in fact peer/proposal/policy info. But you do not need to make a separate GRE tunnel with the same end-point peer IP addresses. Also in the SW implementation you do not need IP adresses (subnet) for th...
by i4jordan
Mon Jul 07, 2014 2:53 pm
Forum: General
Topic: v6.15 released
Replies: 302
Views: 103323

Re: v6.15 released

@andriys Yes I agree with you that the engineers should fix/improve the speed on the IPIP+ipsec and/or GRE+ipsec implementations. But besides the throughput speed, a IPsec tunnel is less complicated to configure than IPsec (peer/profile/policy) + IPIP/GRE tunnel (tunnel+subnet). At least in the Soni...
by i4jordan
Mon Jul 07, 2014 1:03 pm
Forum: General
Topic: v6.15 released
Replies: 302
Views: 103323

Re: v6.15 released

With IPsec Virtual Interface most people mean an virtual interface like the IPIP or GRE interface. But then with standard IPsec security. SonicWall has a very nice implementation of this kind of interface. Keep in mind SonicWall has a propriety implementation. I do understand we can make this with I...
by i4jordan
Thu May 15, 2014 11:51 pm
Forum: General
Topic: GRE over IPSEC, CCR, VERY SLOW
Replies: 39
Views: 15709

Re: GRE over IPSEC, CCR, VERY SLOW

Today a few CCR and RB1100AHx2 models arrived. I am going to use those to test all kinds of VPN tunnels and will report the measured speeds. I will test: - IPIP + ipsec (transport) - GRE + ipsec (transport) - EOIP + ipsec (transport) - ipsec tunnel Mainly with AES encryption because this should be h...
by i4jordan
Tue Apr 29, 2014 3:00 pm
Forum: General
Topic: GRE over IPSEC, CCR, VERY SLOW
Replies: 39
Views: 15709

Re: GRE over IPSEC, CCR, VERY SLOW

Did you try 2x CCR for the GRE+ipsec setup?

I am planning to buy a second CCR just to test this.
I do not have 2x RB1100AHx2 to test such a setup.

But I indeed do suspect a not optimized piece of code in the CCR firmware.
by i4jordan
Tue Apr 29, 2014 12:10 am
Forum: General
Topic: GRE over IPSEC, CCR, VERY SLOW
Replies: 39
Views: 15709

Re: GRE over IPSEC, CCR, VERY SLOW

No, I do not have a case open for this. But next coming weeks I will spend some time testing all variant of ipsec connections. Strange thing indeed is that ipsec tunnels seems much faster than ipsec over IPIP or GRE tunnels. We have one ipsec tunnel from a SonicWall NSA3500 series to our CCR1036, th...
by i4jordan
Mon Apr 28, 2014 4:49 pm
Forum: General
Topic: GRE over IPSEC, CCR, VERY SLOW
Replies: 39
Views: 15709

Re: GRE over IPSEC, CCR, VERY SLOW

i can second this. GRE (or IPIP) + ipsec seems very slow between CCR and 1100AHx2.
I also tried almost all AES variants. but the performance seems to be limited to around 50Mbps.
by i4jordan
Fri Mar 28, 2014 6:46 pm
Forum: General
Topic: High Speed VPN - 100Mbps +
Replies: 25
Views: 15190

Re: High Speed VPN - 100Mbps +

@mrz Wat is the maximum speed the RB1100AHx2 can do with ipsec? And also at what Encr. Algorithms do we get the best speed? Is it AES-cbc 128 or maybe AES-gcm 256 or ...? We are using a lot of ipsec tunnels connected from CCR1036 to RB100AHx2 and we'd like to optimize the ipsec speed. Thank you in a...
by i4jordan
Wed Mar 26, 2014 12:37 am
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 60
Views: 15686

Re: Feature Request: IPSEC Improvements

@jollis

No,
I also have seen that ipsec uses 1 CPU on my CCR1036 :(
So 1 CPU very busy, 35 doing almost nothing.
by i4jordan
Tue Mar 25, 2014 1:46 pm
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 60
Views: 15686

Re: Feature Request: IPSEC Improvements

A good working and simple to setup ipsec VTI would stop us from selling (expensive) SonicWall SRA solutions. The ipsec VTI should be working like an IPIP/GRE tunnel but then with ipsec security. We now use IPIP or GRE tunnels with ipsec transport security. This works but is not easy to setup and spe...
by i4jordan
Mon Mar 24, 2014 5:24 pm
Forum: General
Topic: The proposal to improve the VPN possibilities.
Replies: 9
Views: 4991

Re: The proposal to improve the VPN possibilities.

@mrz, thank you for your quick answer.

I will be patiently waiting for v7.
by i4jordan
Mon Mar 24, 2014 4:37 pm
Forum: General
Topic: The proposal to improve the VPN possibilities.
Replies: 9
Views: 4991

Re: The proposal to improve the VPN possibilities.

StrongSwan looks OK. They implemented IKEv2 and a load of other usable features. http://www.strongswan.org Mikrotik R&D please take a look at this. No response on this subject from Mikrotik development? In short, it would be nice to have IKEv2 implementation in RouterOS. Is this planned for Routers...
by i4jordan
Mon Mar 24, 2014 4:35 pm
Forum: Virtualization
Topic: Hyper-V integration components
Replies: 127
Views: 62693

Re: Hyper-V integration components

I do understand, from reading this forum and also Microsoft/Linux documentation, that Microsoft Hyper-V drivers are included in Linux kernel 3.4 and higher. Mikrotik is using kernel version 3.3.5 So I hope that as soon Mikrotik is implementing kernel 3.4 or higher Hyper-V integration is supported. T...
by i4jordan
Fri Jan 31, 2014 6:17 pm
Forum: General
Topic: 6.9 released!
Replies: 223
Views: 79593

Re: 6.9 released!

Bug in ipsec phase 2 AES-256 on CCR?? I have updated our CCR1036-12G-4EM from 6.7 to 6.9. Al was working fine except for a lot of our VPN tunnels. The standard ipsec tunnels with AES-256 in phase 2 (proposal) all send packages but did not receive. After changing from AES-256 to AES-128 they went fin...
by i4jordan
Fri Jan 31, 2014 12:27 pm
Forum: General
Topic: The proposal to improve the VPN possibilities.
Replies: 9
Views: 4991

Re: The proposal to improve the VPN possibilities.

StrongSwan looks OK. They implemented IKEv2 and a load of other usable features.

http://www.strongswan.org

Mikrotik R&D please take a look at this.
by i4jordan
Fri Jan 31, 2014 12:24 pm
Forum: General
Topic: v6.7 released
Replies: 225
Views: 109436

Re: v6.7 released

Normis,

Why is everybody talking about 6.9 on this forum.
And not 6.9 beta of 6.9rcx.
by i4jordan
Fri Jan 31, 2014 11:58 am
Forum: General
Topic: v6.7 released
Replies: 225
Views: 109436

Re: v6.7 released

Is the 6.9 version publicly available?
I can not find it and also if I use update package it only finds 6.7 which is current version.

I have a CCS running with a lot of ipsec tunnels and are very interested in hardware accelerated aes ipsec.

Thank you.
by i4jordan
Fri Jan 31, 2014 12:30 am
Forum: General
Topic: The proposal to improve the VPN possibilities.
Replies: 9
Views: 4991

Re: The proposal to improve the VPN possibilities.

Also support for IPsec IKEV2 should be very nice.
by i4jordan
Fri Jan 31, 2014 12:28 am
Forum: General
Topic: The proposal to improve the VPN possibilities.
Replies: 9
Views: 4991

Re: The proposal to improve the VPN possibilities.

+1 for Virtual IPsec Tunnel interfaces. I implement IPsec tunnel interface in SonicWall SRA solutions and those tunnels work superb with a load of (OSPF) routing options. It would be perfect if RouterOS would support a kind of ipsec virtual interface just like IPIP and GRE tunnels but then standard ...
by i4jordan
Wed Dec 25, 2013 3:44 pm
Forum: General
Topic: Why the ROS backup file so big?
Replies: 4
Views: 1018

Re: Why the ROS backup file so big?

I assume that the graphing data also is included in the backups.
So if your router is running a long time with graphing enabled the backups also will grow.
by i4jordan
Wed Dec 11, 2013 9:34 pm
Forum: General
Topic: Multi WAN IP Sec
Replies: 9
Views: 2804

Re: Multi WAN IP Sec

You can 'adjust' mss (MTU -/- protocol overhead) size with MSS Mangle rules. http://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Mangle Look for Basic Examples 'Change MSS' With those you can set the outgoing MSS (and resulting MTU) size for packages passing the ipsec + IPIP tunnel. I always use mtupat...
by i4jordan
Wed Dec 11, 2013 5:09 pm
Forum: General
Topic: Multi WAN IP Sec
Replies: 9
Views: 2804

Re: Multi WAN IP Sec

IPsec + GRE is very nice to make advanced routed private netwerks through VPN. But I have noticed there is a big performance penalty with this combination. If you use IPIP tunnels instead of GRE it is faster, but this gives some MTU challenges. In short: IPsec + GRE, nice for VPN 'tunnels' but slow,...
by i4jordan
Mon Dec 02, 2013 11:46 am
Forum: Beginner Basics
Topic: ccr1036 12g 4s
Replies: 3
Views: 864

Re: ccr1036 12g 4s

There are a lot of examples on how to use multi-wan configs. It is not easy to do on Mikrotik routers, but if you understand routing/firewall rules and mangle in Mikrotik you will manage to do this. Please follow this instructions; http://aacable.wordpress.com/2011/06/04/mikrotik-4-wan-load-balance-...
by i4jordan
Thu Nov 28, 2013 2:19 am
Forum: Beginner Basics
Topic: ccr1036 12g 4s
Replies: 3
Views: 864

Re: ccr1036 12g 4s

I am using 4x ISP (adsl, vdsl, cable and fiber) on a ccr1036, runs very smooth.

Theoretically you can use an almost unlimited amount of ISP's. But practically it is limited by ethernetports and/or VLAN's.
by i4jordan
Sun Nov 24, 2013 8:54 pm
Forum: RouterBOARD hardware
Topic: ADSL modem recommendations
Replies: 3
Views: 1742

Re: ADSL modem recommendations

Or the new A130. This one is also VDSL compatible.

https://www.draytek.com/index.php?optio ... 10&lang=en
by i4jordan
Sun Nov 24, 2013 8:53 pm
Forum: RouterBOARD hardware
Topic: ADSL modem recommendations
Replies: 3
Views: 1742

Re: ADSL modem recommendations

We succesfully use Draytek A120 for these situations.
Put the A120 in bridge mode and the Mikrotik will get the WAN IP, on either DHCP Client/fixed IP/PPPoE.

For info: https://www.draytek.com/index.php?optio ... 51&lang=en
by i4jordan
Sat Nov 16, 2013 1:58 pm
Forum: General
Topic: Hardware NAT at Mikrotik
Replies: 2
Views: 1185

Re: Hardware NAT at Mikrotik

I do not know if any of the Mikrotik routers has Hardware NAT, but a few models are fast enough for 1000Mbps.

I would advice the RB1100AHx2 because this one is for sure fast enough and at this moment very afordable.
Or else the Tilera CPU routers (CCR series) are for sure fast enough.
by i4jordan
Tue Nov 12, 2013 11:54 pm
Forum: General
Topic: Send DHCP request over VPN
Replies: 6
Views: 2559

Re: Send DHCP request over VPN

@feklar

Yes indeed with an EoIP tunnel you would actually get a Layer2 connected tunnel.
And then also DHCP request would broadcast through this L@ tunnel and get a reply from the DHCP server.
by i4jordan
Tue Nov 12, 2013 5:25 pm
Forum: General
Topic: Multi-site IPSec VPN - Confusion
Replies: 1
Views: 1138

Re: Multi-site IPSec VPN - Confusion

You need to add the not routed subnets on the ipsec proposals. For example in a 2 site and 1 HQ setup HQ has 192.168.100.0/24 Site 1 has 192.168.101.0/24 Site 2 has 192.168.101.0/24 On HQ you define 2x peers for the sites + 2x ipsec proposals per peer to connect HQ-site1, HQ-site2, HQ-site3 Peer Sit...
by i4jordan
Tue Nov 12, 2013 5:01 pm
Forum: General
Topic: Send DHCP request over VPN
Replies: 6
Views: 2559

Re: Send DHCP request over VPN

'Seeing' computers on side A from side B has nothing to do with your split subnet. But everything with DNS setup and of course if the subnets are defined well on the VPN tunnel. In DHCP Relay option you put the interface which needs to be monitored for DHCP requests, mostly this is the interface whi...
by i4jordan
Mon Nov 11, 2013 9:58 pm
Forum: General
Topic: VLAN + PPoE on one port ?
Replies: 2
Views: 1328

Re: VLAN + PPoE on one port ?

connect the ISP connection to (example) eth1 and call this interface 'eth1-ISP' Then make a VLAN virtual interface with VLAN ID 835 based on interface 'eth1-ISP', and call this one 'eth1-ISP-VLAN835' Then make a PPPoE client interface based on interface 'eth1-ISP-VLAN835' and call this 'WAN-PPPoE' W...
by i4jordan
Thu Oct 31, 2013 9:46 pm
Forum: General
Topic: Send DHCP request over VPN
Replies: 6
Views: 2559

Re: Send DHCP request over VPN

If you have a DHCP server on the 'other' side. You can simple use DHCP relay for relaying DHCP request from your side of the to the IP of the DHCP server. Please note that you need to have 2 IP pools on that DHCP server! one pool for the 'other' side and one for your side of the VPN. This because yo...
by i4jordan
Thu Oct 24, 2013 3:37 pm
Forum: General
Topic: IPSEC very SLOW on router boards? High CPU
Replies: 7
Views: 2776

Re: IPSEC very SLOW on router boards? High CPU

Normis,

Does the tile series (CCR1036) also have hardware accelerated ipsec?
by i4jordan
Tue Oct 22, 2013 2:57 pm
Forum: General
Topic: Layer2 GRE tunnel
Replies: 4
Views: 7626

Re: Layer2 GRE tunnel

Thank you. Yes, I am aware of dhcp-relay, I am actually using it in my network but it still isn't an option as this customer requires L2 not just for DHCP. So in theory I could be doing: 1. L3 with GRE 2. Routing (OSPF/...) over GRE 3. MPLS/VPLS L2 Tunnel over GRE Indeed if both sides support MPLS ...
by i4jordan
Tue Oct 22, 2013 1:37 pm
Forum: General
Topic: Layer2 GRE tunnel
Replies: 4
Views: 7626

Re: Layer2 GRE tunnel

GRE is a routing protocol. On Layer 3, Not Layer 2. It is compatible with Cisco GRE. Actually Mikrotik GRE is compatible with Cisco GRE, because Cisco developed this protocol. For Layer2 tunnels you need 2x Mikrotik because they have EoIP tunnel interface as option. So if you have any other brand th...
by i4jordan
Mon Sep 02, 2013 3:15 pm
Forum: General
Topic: ROS 6.2 and 6.3 +Winbox + Quickset = self country change
Replies: 29
Views: 15435

Re: ROS 6.2 + WINDOWS 8 +Winbox + Quickset = self country ch

Disabling Quickset in Designer mode also resolved my problem with 'magically' changed settings.