Community discussions

MikroTik App

Search found 1000 matches

by NathanA
Mon May 12, 2025 1:47 pm
Forum: Forwarding Protocols
Topic: DSTNAT port forwarding is not working
Replies: 9
Views: 1176

Re: DSTNAT port forwarding is not working

"shared via MAP-T" We might have found our problem. MAP-T is a technology that ISPs can use to route IPv4 traffic over a native IPv6 network statelessly (no tunneling/encapsulation), while also (optionally) allowing one IPv4 address to be shared amongst multiple users (as an alternative t...
by NathanA
Sun May 11, 2025 11:29 pm
Forum: General
Topic: IPv6 link local editing [SOLVED]
Replies: 7
Views: 717

Re: IPv6 link local editing [SOLVED]

There is a better way. You DID read the documentation, didn't You? There is clearly stated "If newly created address is manual link-local address this setting allows to override dynamically created IPv6 link-local address." I literally quoted that exact same sentence from the documentatio...
by NathanA
Sun May 11, 2025 10:22 am
Forum: MikroTik hardware questions
Topic: The big CCR2004 reboot thread (was 2004 hardware issues?)
Replies: 463
Views: 173601

Re: The big CCR2004 reboot thread (was 2004 hardware issues?)

Sorry to dig this fossil of a thread up again... I realize that there were multiple different underlying causes contributing to "the" CCR2004 watchdog reboot problem. There are multiple entries addressing "stability" issues with CCR2004 spread out over various ROS releases. And t...
by NathanA
Sun May 11, 2025 6:27 am
Forum: General
Topic: IPv6 prefix change breaks connectivity: RA lifetime issue
Replies: 3
Views: 444

Re: IPv6 prefix change breaks connectivity: RA lifetime issue

In this monster thread from a couple of years ago where this was discussed ad infinitum , I wrote and posted such a script triggered by DHCPv6 lease changes that seems to be fairly universally applicable and fairly robust. We also relied on this script for a while. But then, as hinted at at the end ...
by NathanA
Sun May 11, 2025 6:04 am
Forum: General
Topic: IPv6 link local editing [SOLVED]
Replies: 7
Views: 717

Re: IPv6 link local editing [SOLVED]

The line /ipv6/address> add address=fe80::230/64 interface=mwahaha auto-link-local=yes Sets the link local address fe80::230/64 to the bridge called mwahahaha I'm starting to think this is a bug.... If you read the documentation for the "auto-link-local" parameter, it does clearly state t...
by NathanA
Sun May 11, 2025 5:51 am
Forum: MikroTik hardware questions
Topic: Hardware for x86 (Replacing 2216)
Replies: 37
Views: 14237

Re: Hardware for x86 (Replacing 2216)

maybe is not so simple for a vendor to officially include an x86 cpu embedded in a router, maybe there is some bureaucracy, validation, and costs we as a consumers are not fully aware of I don't know if anyone else here is following the Mono Gateway router project of Tomaž Zaman on Youtube, but he ...
by NathanA
Sun May 11, 2025 4:58 am
Forum: MikroTik hardware questions
Topic: Hardware for x86 (Replacing 2216)
Replies: 37
Views: 14237

Re: Hardware for x86 (Replacing 2216)

Well the margin is not that wide. Even the most powerful Xeon-E CPU is now only 95W TDP. i think is not that simple i think many people have a limited power, cooling and space available in some places This is jumping back to an older response, but yes, one of the advantages to purpose-built hardwar...
by NathanA
Fri May 09, 2025 5:34 am
Forum: General
Topic: Cannot reach Router via secondary on-link IPv6 address [SOLVED]
Replies: 8
Views: 734

Re: Cannot reach Router via secondary on-link IPv6 address [SOLVED]

Interesting. Again, what ROS ver#? Was just about to respond that I found a 7.18.2 device on our network with a GUA already on the LAN bridge assigned from a pool, and added a ULA to the same interface as a test. No problems detected, and I did not have to reboot it after the add: [admin@MikroTik] >...
by NathanA
Fri May 09, 2025 3:21 am
Forum: General
Topic: Cannot reach Router via secondary on-link IPv6 address [SOLVED]
Replies: 8
Views: 734

Re: Cannot reach Router via secondary on-link IPv6 address [SOLVED]

It seems weird to me that ROS would actually be paying attention to what "class" of address is being assigned to an interface (GUA or ULA)...a client that needs to pay attention to RFCs about network class priorities, sure, but a forwarding router...? So I have a hard time believing that i...
by NathanA
Thu May 08, 2025 3:18 am
Forum: Forwarding Protocols
Topic: DSTNAT port forwarding is not working
Replies: 9
Views: 1176

Re: DSTNAT port forwarding is not working

Being "behind CGNAT" would mean that your ISP is giving you a private IP address on your WAN connection. It sounds like this is clearly not the case. Hopefully this is just a side-effect of you testing random things, but although you said you tried various in-interface or in-interface-list...
by NathanA
Thu May 08, 2025 12:18 am
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 90
Views: 10277

Re: Netinstall on RM3011 Fails need help (technical questions)

The use of netinstall version 6 won't limit you on RouterOS version 6. I think @mkx understands this. What he is responding to is that it seemed like the OP had originally been under the impression that Netinstall version has to match ROS version being installed, if you read earlier posts closely. ...
by NathanA
Wed May 07, 2025 4:51 pm
Forum: General
Topic: Third party x86 hw ROS support
Replies: 26
Views: 1808

Re: Third party x86 hw ROS support

Perhaps I worded that poorly. Some of them showed up, but not all six of them. Likely the SFP+ ports and not the 2.5G ports.

Ahhh. "all six did not" (what was written), vs. "not all six of them did" (what was intended) 😁
by NathanA
Wed May 07, 2025 4:48 pm
Forum: General
Topic: Am I missing something in relation to "Accept Router Advertisements" and Neighbour Discovery?
Replies: 3
Views: 688

Re: Am I missing something in relation to "Accept Router Advertisements" and Neighbour Discovery?

As per the recommendations I've seen on these forums, I did not use the "Add Default Route" setting in the DHCPv6 client, and instead relied on RAs from the ISP (with "accept-router-advertisements=yes" ) to create a default route, which all worked fine. I would not necessarily s...
by NathanA
Wed May 07, 2025 3:11 pm
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 90
Views: 10277

Re: Netinstall on RM3011 Fails need help (technical questions)

Well, I have no different way to write "the issue is not about updating RoS". You wrote: "the issue is not about updating the Ros [...], it is about updating it in such a way that the device after the update behaves like the other one" This is a confusing sentence. When you used...
by NathanA
Wed May 07, 2025 1:21 pm
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 90
Views: 10277

Re: Netinstall on RM3011 Fails need help (technical questions)

5. And use netinstall-cli command. This maybe to get around all obstacles in Windows such as antivirus, firewalls, etc. To get around the problem of "malformed packet". If you actually read through the whole thread (it's long, I know), the "malformed packet" issue is somehow a b...
by NathanA
Wed May 07, 2025 11:15 am
Forum: General
Topic: Why are my static DNS records forwarding upstream?
Replies: 23
Views: 1703

Re: Why are my static DNS records forwarding upstream?

[...] and because I don't want my static records to fail when the internet is down. :lol: Mostly curious: is that actually a side-effect of this bug, though? Will it allow its response to your request to be influenced by any responses it gets from upstream? Does it actually seem to generate delay t...
by NathanA
Wed May 07, 2025 8:59 am
Forum: General
Topic: Third party x86 hw ROS support
Replies: 26
Views: 1808

Re: Third party x86 hw ROS support

I tested about five different boxes at the time, and so I can't honestly remember which ports worked and which didn't, but suffice it to say, all six did not show up on that box Wait...ALL six did not show up? That doesn't make much sense. Now I'm not so sure about this particular anecdote accurate...
by NathanA
Wed May 07, 2025 7:00 am
Forum: General
Topic: Third party x86 hw ROS support
Replies: 26
Views: 1808

Re: Third party x86 hw ROS support

8086:125c Both awesome as well as interesting; thanks much. The only thread I had been able to unearth so far with anybody at all talking about i226-V compatibility with ROS is this one from late 2023, which seems to imply that the interfaces do actually show up for them. In light of your testimony...
by NathanA
Wed May 07, 2025 4:21 am
Forum: General
Topic: Intermittent IPv6 connectivity issue after reboot (RB450Gx4, v7.18.2) [SOLVED]
Replies: 2
Views: 625

Re: Intermittent IPv6 connectivity issue after reboot (RB450Gx4, v7.18.2) [SOLVED]

Curious if you tried changing the gateway of your ::/0 route to the link-local address of the next-hop vs. its GUA? Obviously if the GUA isn't working until you force-clear its entry from the neighbors table, that seems like broken behavior, but I'm mostly curious if this largely "solves" ...
by NathanA
Wed May 07, 2025 4:10 am
Forum: General
Topic: Third party x86 hw ROS support
Replies: 26
Views: 1808

Re: Third party x86 hw ROS support

(I have a box very similar to the one he's looking at buying, and IIRC only the SFP+ worked on ROS7; the 2.5's did not.) Do you happen to know what ethernet chip was being used for the 2.5s (PCI vendor and device IDs would be even cooler)? And curious when was the last time you tried it (what ROS v...
by NathanA
Wed May 07, 2025 4:00 am
Forum: Forwarding Protocols
Topic: Nested /29 within our /24
Replies: 5
Views: 679

Re: Nested /29 within our /24

Depending on your network ... If you have a network that is a /24 ( example 192.168.1.0/24 defined on an ethernet interface example: 192.168.1.1/24 ) then you can not route a /29 from that network and route it somewhere else. I think it should be possible with proxy-arp turned on on the interface t...
by NathanA
Tue May 06, 2025 11:28 am
Forum: General
Topic: Third party x86 hw ROS support
Replies: 26
Views: 1808

Re: Third party x86 hw ROS support

The machine you linked to on Ali appears to be this Topton product . Though I've yet to pull the trigger on any of them, I've been keeping my eye on this and similar boxes by other manufacturers, as I too have a strong interest in good value x86 hardware that can run ROS on it bare-metal. When it co...
by NathanA
Tue May 06, 2025 11:09 am
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 90
Views: 10277

Re: Netinstall on RM3011 Fails need help (technical questions)

Any further thoughts? I had assumed you saw my last responses, where I dug up two 3011s with identical "factory-firmware" versions to your two, and can reproduce the same problem you are experiencing on my one with 3.27. That seemed to settle the matter in my mind, at least as far as any ...
by NathanA
Sun May 04, 2025 4:03 am
Forum: General
Topic: Why are my static DNS records forwarding upstream?
Replies: 23
Views: 1703

Re: Why are my static DNS records forwarding upstream?

What ROS version? I just tested on 6.49.*, and so far I can't reproduce on that version at the very least. If this is happening, you should be able to see the router transmitting the DNS request. So, have you tried running the sniffer with interface=<wan>, ip-proto=udp, port=53, direction=tx, and do...
by NathanA
Sun May 04, 2025 12:21 am
Forum: General
Topic: IPv6 RA Incorrectly Advertising Prefixes from Other Interfaces (v7.18.2, Bridge+VLAN+PD)
Replies: 13
Views: 2359

Re: IPv6 RA Incorrectly Advertising Prefixes from Other Interfaces (v7.18.2, Bridge+VLAN+PD)

Hmm, that mostly looks correct. The other thing that gives me pause is that the 'wireguard' interface wouldn't be a VLAN, and yet you said one of the VLANs on the client was SLAAC'ing from the 'wireguard' prefix. I also failed to notice until just now that you had previously written that the RAs you...
by NathanA
Sat May 03, 2025 9:18 pm
Forum: General
Topic: IPv6 RA Incorrectly Advertising Prefixes from Other Interfaces (v7.18.2, Bridge+VLAN+PD)
Replies: 13
Views: 2359

Re: IPv6 RA Incorrectly Advertising Prefixes from Other Interfaces (v7.18.2, Bridge+VLAN+PD)

Rather than MT RA daemon broadcasting (well, multicasting) out of the wrong interfaces, I would be leaning more in the direction of a possible misconfiguration in your bridge VLAN filtering config that is causing traffic to leak between VLANs. But you didn't include your whole config, so...
by NathanA
Fri May 02, 2025 11:13 pm
Forum: General
Topic: RB850Gx2 RouterOS v7.1.1 no TCP Winbox access
Replies: 4
Views: 1463

Re: RB850Gx2 RouterOS v7.1.1 no TCP Winbox access

I do seem to recall various threads, very similar to this one, that popped up right around the time the 850Gx2 was released, with people experiencing weird management problems to it. The thing is, I've never been able to reproduce any of those issues myself, with any of my 850s. I just took one with...
by NathanA
Fri May 02, 2025 2:07 am
Forum: MikroTik hardware questions
Topic: RouterOS to SwOS
Replies: 2
Views: 572

Re: RouterOS to SwOS

Yes. "device-mode" is set to advanced, but I'm sure "routerboard" under device-mode says "no"; see: the very last line on the help page that @tdw linked to.
by NathanA
Fri May 02, 2025 1:19 am
Forum: General
Topic: Trigger Reboot on Interface Status
Replies: 2
Views: 601

Re: Trigger Reboot on Interface Status

RouterOS has its own bespoke scripting language; see here for documentation. It looks like on RouterOS 7, there is an "inactive" status for LTE interfaces that exists. Looks like this can be checked programmatically with something like... /interface/lte/get lte1 inactive ...which returns a...
by NathanA
Fri May 02, 2025 12:05 am
Forum: General
Topic: Connection tracking table not cleared completely after WAN IP address change
Replies: 38
Views: 13069

Re: Connection tracking table not cleared completely after WAN IP address change

Nathan your hurting my brain, is there any reason to separate connection tracking clearing of change IP and down and change of ISP? and if not, I'm not arguing about that at all. What I'm doing is what people in the industry call "thinking out-loud about a possible workaround". then MT si...
by NathanA
Thu May 01, 2025 3:50 pm
Forum: Beginner Basics
Topic: Help setting up IPv6
Replies: 9
Views: 1630

Re: Help setting up IPv6

So, I am not 100% clear how this is working, but I just ran an experiment with Hurricane Electric Tunnel Broker (which also uses SIT encapsulation, same as 6RD), where instead of using the separate routed prefix they assign to my tunnel, I took the /64 assigned directly on the tunnel itself, and on ...
by NathanA
Thu May 01, 2025 3:29 pm
Forum: General
Topic: Connection tracking table not cleared completely after WAN IP address change
Replies: 38
Views: 13069

Re: Connection tracking table not cleared completely after WAN IP address change

...and the usual userland tools ("conntrack-tools"). That's what I'm talking about: the userland conntrack tools. Yes, I expect ROS is using the same kernel APIs. In the past, though, I have found statically-linked builds of similar tools to be a requirement when trying to run them on top...
by NathanA
Thu May 01, 2025 1:54 pm
Forum: General
Topic: Connection tracking table not cleared completely after WAN IP address change
Replies: 38
Views: 13069

Re: Connection tracking table not cleared completely after WAN IP address change

Because the current way with list building and iteration is really cumbersome, slow and resource intensive." Apologies; I missed that. And yes, in fact the deletions are only performed until the first reference is encountered where the connection has timed out while preparing the list of items...
by NathanA
Thu May 01, 2025 1:46 pm
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 90
Views: 10277

Re: Netinstall on RM3011 Fails need help (technical questions)

also numbering of versions is the third worst in the universe. :lol: Eh. I get it. It's not uncommon to patch an older branch of software, for users who have already confirmed that branch works for them and don't want to take on the risk of regressions in a newer major release. (What MikroTik histo...
by NathanA
Thu May 01, 2025 12:28 pm
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 90
Views: 10277

Re: Netinstall on RM3011 Fails need help (technical questions)

What's difficult to understand here? In meantime try to netinstall the device with netinstall64 7.16.2 Post #26, 8 days ago Except that you're wrong, because Netinstall 7.16.2 ALSO does not work on these early 3011 routers. I just went back from 7.18.2 one version at a time, and discovered that the...
by NathanA
Thu May 01, 2025 12:01 pm
Forum: General
Topic: Connection tracking table not cleared completely after WAN IP address change
Replies: 38
Views: 13069

Re: Connection tracking table not cleared completely after WAN IP address change

I really would like my conntrack -D. I am curious what you are looking for that is not currently possible with /ip/firewall/connection/remove [find where <blah>] ? That slide in the MUM deck talking about masquerade vs. src-nat is interesting, because I have used src-nat before in scenarios with mu...
by NathanA
Thu May 01, 2025 10:05 am
Forum: General
Topic: Some devices didn't get DHCP IP
Replies: 9
Views: 909

Re: Some devices didn't get DHCP IP

You can find it at #4, but at the end of the list, so it's not sorted ;-) D'oh! I know it's not sorted, but I looked for them, I swear! 🤦 Everything works like expected with these parameters: Yes, I suspect that with that set to "1", the VoIP phones are seeing the LLDP-MED advertisement a...
by NathanA
Thu May 01, 2025 9:18 am
Forum: Beginner Basics
Topic: wlan broke after upgrade, and I cant see why
Replies: 7
Views: 1373

Re: wlan broke after upgrade, and I cant see why

4. If I set a manually configured IP+gateway on the client everything worked, connecting to the main router or the extender. I do understand that. However, if broadcast traffic were somehow broken or blocked in only one direction, you could still theoretically get this outcome where a static IP wor...
by NathanA
Thu May 01, 2025 9:07 am
Forum: Beginner Basics
Topic: Help setting up IPv6
Replies: 9
Views: 1630

Re: Help setting up IPv6

Regarding IPv6, there are no other configuration possibilities (enable v6 on LAN -> you see a 6RD prefix assigned, or turn off.) There is no IPv6 static route screen? Are you able to divulge the make and model of this router? I would also be curious who your ISP is... I suppose I was initially expe...
by NathanA
Thu May 01, 2025 9:03 am
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 37
Views: 3646

Re: hEX refresh/ as Switch ->Pros & Cons?

The Reolink has PoE ports for the cameras, and a single LAN line to the Hex or whatever. The Hex does not deal with cameras, only the traffic selected to be obtained from the NVR. Ahh. I allowed myself to jump to conclusions when it was mentioned that there were 4 cameras, and then people started t...
by NathanA
Thu May 01, 2025 8:57 am
Forum: General
Topic: Some devices didn't get DHCP IP
Replies: 9
Views: 909

Re: Some devices didn't get DHCP IP

lldp-med-net-policy-vlan must be " disabled ". But if you go to the WebGUI, it always set the value to "1", even if it is disabled . Nice sleuthing! Can you elaborate on the ROS version you are running where you are seeing this issue? I was going to respond earlier that I was co...
by NathanA
Thu May 01, 2025 8:53 am
Forum: General
Topic: Password recovery with lost stickers [SOLVED]
Replies: 4
Views: 860

Re: Password recovery with lost stickers [SOLVED]

Actually I solved the problem.

You do not need to create a custom script to solve the problem. Simply do NOT check "Apply default config" in Netinstall. Just tested this out on brand-new hAP ax2 to verify. Problem solved.
by NathanA
Thu May 01, 2025 8:39 am
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 90
Views: 10277

Re: Netinstall on RM3011 Fails need help (technical questions)

I already know about previous problems in peripherals that have an old factory bootloader and why. And of course I already expected that the other router that work had bootloader version 3.4x or later. You "knew about previous problems" with "old factory bootloader" and "wh...
by NathanA
Mon Apr 28, 2025 4:59 am
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 90
Views: 10277

Re: Netinstall on RM3011 Fails need help (technical questions)

Here's how they sit right now Okay, good. We already see a difference. Let's pretend for a second that "current-firmware" on both is the same, since you stated that at least at one point in time, they were ("bad" used to also be on 7.18.2), and you saw no change in behavior. We ...
by NathanA
Mon Apr 28, 2025 1:55 am
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 90
Views: 10277

Re: Netinstall on RM3011 Fails need help (technical questions)

Sigh. I fear what we have now is a "too many cooks in the kitchen" problem here, and now you are getting tossed to and fro as if by wind. All of these suggestions about things for you to try were being thrown around here by others because they didn't trust that you had actually tried two d...
by NathanA
Mon Apr 28, 2025 1:15 am
Forum: MikroTik hardware questions
Topic: Request: Separate hardware from RouterOS software licensing to reduce tariffs
Replies: 3
Views: 1721

Re: Request: Separate hardware from RouterOS software licensing to reduce tariffs

Interesting idea, though it assumes that they actually account for a "software license" as part of the total cost of the device. Since MT is the "OEM" in this case, pre-loading their own software onto their own hardware (a-la "Apple"), that might not be the case. If it ...
by NathanA
Mon Apr 28, 2025 1:07 am
Forum: General
Topic: Can not access the CPU via incomming vlan !! :(
Replies: 12
Views: 1660

Re: Can not access the CPU via incomming vlan !! :(

And I did create that route in the ...... routing menu ......
But that is not where it should be ...

The return route should be under IP routes :shock:

And people wonder why we ask for config exports from their routers... 😉
by NathanA
Mon Apr 28, 2025 1:04 am
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 37
Views: 3646

Re: hEX refresh/ as Switch ->Pros & Cons?

I will have 4 PoE cameras connected to the NVR In this case, I'd actually be tempted to get a hEX PoE instead. You get 5 gigabit ports wired up to the internal switch chip instead of 4 on the hEX refresh (plus an SFP port which isn't wired to switch), so you won't have to worry about your uplink po...
by NathanA
Mon Apr 28, 2025 12:43 am
Forum: Beginner Basics
Topic: Help setting up IPv6
Replies: 9
Views: 1630

Re: Help setting up IPv6

Use DHCPv6 client and configure it to receive a prefix on WAN interface. Admittedly OP was a little ambiguous about this, but he did already mention he had tried to set up a DHCPv6 client. The ambiguity is that OP did not make it clear whether this client had been configured to attempt to acquire a...
by NathanA
Sun Apr 27, 2025 11:35 pm
Forum: Beginner Basics
Topic: wlan broke after upgrade, and I cant see why
Replies: 7
Views: 1373

Re: wlan broke after upgrade, and I cant see why

From my point of view DHCP issues could be the pattern. To me, this seems doubtful. According to your description, the problem was linked to particular bridge members (two different wireless interfaces that are members of two different bridges). If this were purely a DHCP issue, then it seems like ...
by NathanA
Sat Apr 26, 2025 4:08 am
Forum: General
Topic: need 16121.1034.00.01.01.09 for hAP ax lite6 [SOLVED]
Replies: 10
Views: 2219

Re: need 16121.1034.00.01.01.09 for hAP ax lite6 [SOLVED]

Okay, I found the answer to why the "latest" file in the .05 directory returns ".04" in the contents, over in this thread . You can read about how people had problems after upgrading to .05. They tried to downgrade themselves, but weren't able to...every image file they grabbed f...
by NathanA
Sat Apr 26, 2025 3:46 am
Forum: General
Topic: need 16121.1034.00.01.01.09 for hAP ax lite6 [SOLVED]
Replies: 10
Views: 2219

Re: need 16121.1034.00.01.01.09 for hAP ax lite6 [SOLVED]

There was some discussion of the scheme here: Binary diffs?? Oooof. If true, and if the only two files that are made available are the last full-flash release + the diff between that base version and the most recent version, then it would suggest that the only two choices that likely remain would b...
by NathanA
Sat Apr 26, 2025 3:21 am
Forum: General
Topic: need 16121.1034.00.01.01.09 for hAP ax lite6 [SOLVED]
Replies: 10
Views: 2219

Re: need 16121.1034.00.01.01.09 for hAP ax lite6 [SOLVED]

exactly I have seen too that the release 3 is working but other are not working. [...] The .9 is not working. I tried updating to the latest beta with no resolution of the issue. Do firmware upgrades of the LTE radio always get downloaded from the internet? If yes, is it still possible for someone ...
by NathanA
Fri Apr 25, 2025 1:45 am
Forum: General
Topic: Is there a faster way to do NAT ? ( SOLVED )
Replies: 17
Views: 1852

Re: Is there a faster way to do NAT ? ** SOLVED **

In my prior posts in this topic , I was using a Hex-Poe I now also have some Hex-S routers. hEX S is of course way faster, since it has a dual-core + hyperthreaded CPU in it @ 880MHz, while the hEX PoE has a single-core, single-threaded CPU @ 800MHz. So not entirely apples-to-apples comparison. My ...
by NathanA
Thu Apr 24, 2025 4:44 am
Forum: Beginner Basics
Topic: Ping 8.8.8.8 gives me timeout
Replies: 6
Views: 772

Re: Ping 8.8.8.8 gives me timeout

Okay so I've tried to find the file of my full config that i got with the export file command, but I can't find it in any of the hyper-v folders, so if there's a specific part of the config you need to see I'll manually check and send it here It doesn't export to "Hyper-V folders". It exp...
by NathanA
Wed Apr 23, 2025 1:32 pm
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 90
Views: 10277

Re: Netinstall on RM3011 Fails need help (technical questions)

What part of, he has tried two 3011s side-by-side multiple times connected to the same PC in each instance, and one ALWAYS works with Netinstall, and the other ALWAYS does not, do people not seem to understand?

Again, could he be leaving out details? Sure. But we're going around in circles, here.
by NathanA
Wed Apr 23, 2025 12:52 pm
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 90
Views: 10277

Re: Netinstall on RM3011 Fails need help (technical questions)

The netinstall process is reported as being extremely fragile[1], so it is hard to say if *anything* can affect it. It's pretty clear how it works. For RouterBOARDs, it's similar to, but not exactly the same as, PXE netboot (and on x86, it *IS* PXE), so, initial stage is BOOTP based, then it downlo...
by NathanA
Wed Apr 23, 2025 8:42 am
Forum: Beginner Basics
Topic: Basic NAT configuration using WebFig
Replies: 3
Views: 678

Re: Basic NAT configuration using WebFig

Just to amend: if your WAN IP address is not truly static (as in: set manually under IP -> address) and the rest of router setup is (more or less) default, then instead of using "dst-address" matcher it's often better to use "in-interface-list=WAN" matcher. Using "in-interf...
by NathanA
Wed Apr 23, 2025 4:49 am
Forum: General
Topic: where is “openflow“ on routeros V7.18?
Replies: 10
Views: 1054

Re: where is “openflow“ on routeros V7.18?

What curious here is they did update the OpenFlow docs pretty recently: [...] Maybe hope it's coming back, but IDK. The command-line examples are clearly from 7.x (having '/' instead of ' ' between each branch of the command tree). Also, from the page update history, it looks like the first version...
by NathanA
Wed Apr 23, 2025 4:11 am
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 90
Views: 10277

Re: Netinstall on RM3011 Fails need help (technical questions)

Then WHY (the heck) is the PC sending requests for 10.73.73.1 and for 10.73.73.31? :?: I do believe these are red herrings. Undoubtedly ARP requests for 10.73.73.1 are being transmitted because I'd imagine that @Michiganbroadband configured the IP address on his ethernet interface in Windows static...
by NathanA
Wed Apr 23, 2025 3:22 am
Forum: General
Topic: Is there a faster way to do NAT ? ( SOLVED )
Replies: 17
Views: 1852

Re: Is there a faster way to do NAT ?

Brief follow-up: After only looking for a couple of minutes, I wasn't able to round up a hEX PoE or a hAP ac (which has very similar CPU to hEX PoE) to run some really quick tests with. I'm sure we have some around here somewhere so I will look more deeply later for an available one. But I did find ...
by NathanA
Wed Apr 23, 2025 2:46 am
Forum: Beginner Basics
Topic: Ping 8.8.8.8 gives me timeout
Replies: 6
Views: 772

Re: Ping 8.8.8.8 gives me timeout

Ip route has a 0.0.0.0/0 route with gateway being ether3 interface, Don't set "gateway" to an interface. Set it to the next-hop IP address. I'm guessing/assuming this is likely to be 77.88.99.1, but of course that is only a guess...talk to the provider/host and find out what IP they are u...
by NathanA
Wed Apr 23, 2025 2:36 am
Forum: Beginner Basics
Topic: Basic NAT configuration using WebFig
Replies: 3
Views: 678

Re: Basic NAT configuration using WebFig

I configure the src and dst ports to 22, [...] You should not be matching on src-port for a port forward. The host initiating the connection to your SSH server will be sourcing their side of the connection from a random TCP port, not from 22. Only the DESTINATION port is guaranteed to be 22. So one...
by NathanA
Wed Apr 23, 2025 1:40 am
Forum: General
Topic: CCR1036 vs CCR2116 CGNAT
Replies: 10
Views: 2234

Re: CCR1036 vs CCR2116 CGNAT

I posted a different thread about this a few weeks back, but I'm currently tracking an issue with ROS 7.x where connection tracking suddenly breaks the forwarding of IPv4 fragments after some as-yet-undetermined threshold is crossed (can't tell yet if it is throughput, PPS, # of tracked connections,...
by NathanA
Wed Apr 23, 2025 1:07 am
Forum: General
Topic: CCR1036 vs CCR2116 CGNAT
Replies: 10
Views: 2234

Re: CCR1036 vs CCR2116 CGNAT

ccr2116 v7.16.2 [...] cpu 14-15% with offload enabled disabling fasttrack-hw offload leads cpu to 22-24% re-enabling fasttrack-hw offload cpu returns to 14-15% ccr2216 v7.16.2 [...] cpu 16-18% with offload enabled disabling fasttrack-hw offload leads cpu to 33-36% re-enabling fasttrack-hw offload c...
by NathanA
Tue Apr 22, 2025 3:07 pm
Forum: Beginner Basics
Topic: Hairpin NAT with dynamic WAN IP [SOLVED]
Replies: 12
Views: 3061

Re: Hairpin NAT with dynamic WAN IP [SOLVED]

Arguably the simplest way to create dst-nat / port forward rules when you have a dynamic IP is to just match on in-interface=<WAN>, and not try to chase the changing IP address at all. Though of course if you also want to implement hairpin NAT, this won't work, because your LAN-sourced traffic will ...
by NathanA
Tue Apr 22, 2025 10:49 am
Forum: General
Topic: Connectivity Issues after Upgrade 7.17.2 > 7.18 / 7.18.2
Replies: 32
Views: 9367

Re: Connectivity Issues after Upgrade 7.17.2 > 7.18 / 7.18.2

Same here on a Hex S. Had to switch to AES-256 with SHA-256 (SHA-512 not hardware encrypted) or else unit would keep rebooting on phase 2 establishing in 7.19 and just not work in 7.18. Oh. Wild. I was suggesting the OPPOSITE: that the crashing was happening when it was USING hardware encryption of...
by NathanA
Tue Apr 22, 2025 9:14 am
Forum: General
Topic: Looking for advice Hiding my IP to show up other IP [SOLVED]
Replies: 5
Views: 2697

Re: Looking for advice Hiding my IP to show up other IP [SOLVED]

Hello, thank you for your quick response. I appreciate the help provided. My ISP-A has a 150MB bandwidth, and I also have ISP-B with a 4MB bandwidth. I want all client traffic to go through ISP-A, but I want clients to be shown the public IP of ISP-B. Unless you own those IP addresses (guessing not...
by NathanA
Tue Apr 22, 2025 7:52 am
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 90
Views: 10277

Re: Netinstall on RM3011 Fails need help (technical questions)

After all of your tests and answers, I am inclined to think you are right that there is something uniquely wrong with the one 3011 unit. Now the obvious question is, what is it? First, just to clear up a few possible misconceptions: Netinstall does NOT re-flash RouterBOOT. If there is something wron...
by NathanA
Tue Apr 22, 2025 6:15 am
Forum: General
Topic: Is there a faster way to do NAT ? ( SOLVED )
Replies: 17
Views: 1852

Re: Is there a faster way to do NAT ?

On my Hex Poe , I have enabled Fasttrack. Got some increase but not a huge amount. I would be interested in seeing the config. I have personally tested Fasttrack vs. non-Fasttrack on RB951G, which has slower and older CPU in it than hEX PoE does, and can confirm I get results very close to what Mik...
by NathanA
Tue Apr 22, 2025 4:38 am
Forum: General
Topic: Is there a faster way to do NAT ? ( SOLVED )
Replies: 17
Views: 1852

Re: Is there a faster way to do NAT ?

In my LAB , I have a Hex PoE connected to a 1-Gig network. the Hex PoE has a slow CPU and only reaches about 250 to 280 Meg - but a different much faster Mikrotik can allow the same PC to hit near Gig nat speeds. I still don't understand why you don't just implement Fasttrack. You can achieve near-...
by NathanA
Tue Apr 22, 2025 4:36 am
Forum: General
Topic: Is there a faster way to do NAT ? ( SOLVED )
Replies: 17
Views: 1852

Re: Is there a faster way to do NAT ?

I don't know if we are managing to talk past each other, or what. You keep mentioning NAT444. My understanding of the theory behind NAT444 (which perhaps is wrong) is that *something* is still taking up the majority of the connection tracking workload. It's just that if you are having the customer C...
by NathanA
Tue Apr 22, 2025 4:06 am
Forum: General
Topic: Is there a faster way to do NAT ? ( SOLVED )
Replies: 17
Views: 1852

Re: Is there a faster way to do NAT ?

Pretty much the same way regular normal nat works but the port and IP address are both re-mapped.

Then it's not stateless, and thus it's not really saving you any CPU cycles.

I don't see where you think the CPU savings are coming from with the change you are suggesting.
by NathanA
Tue Apr 22, 2025 4:00 am
Forum: General
Topic: Is there a faster way to do NAT ? ( SOLVED )
Replies: 17
Views: 1852

Re: Is there a faster way to do NAT ?

If a customer computer gets an ip address of 192.168.0.10 , then outbound traffic and all 65,535 ports would be CGN-Natted ports 34,500 -through- 34,749 . Which results in a remote located internet server seeing all connections from the this customer LAN PC coming from the live IP address with orig...
by NathanA
Tue Apr 22, 2025 3:48 am
Forum: General
Topic: Public IP pool over pppoe
Replies: 21
Views: 1545

Re: Public IP pool over pppoe

It's either-or: I think you intended to communicate this, but just to be clear: it is possible to selectively NAT traffic sitting behind any given interface, which means you can in fact have both hosts with public IPs and hosts with private IPs sitting on the same LAN/network segment, mingling toge...
by NathanA
Tue Apr 22, 2025 3:41 am
Forum: General
Topic: Feature Request: Optional ability to restore without keeping MAC addresses
Replies: 18
Views: 1438

Re: Feature Request: Optional ability to restore without keeping MAC addresses

Also , what I propose re MAC the address option during a restore could be used on another already configured router ( with other users & passwords & wireless configurations & routes & ... & ... ) and quickly make it an identical clone. With .rcs import files , the .rsc import fi...
by NathanA
Tue Apr 22, 2025 3:29 am
Forum: General
Topic: Is there a faster way to do NAT ? ( SOLVED )
Replies: 17
Views: 1852

Re: Is there a faster way to do NAT ?

My understanding is that this is in fact exactly what "action=netmap" does. I have not, however, benchmarked it against "action=masquerade" or action="src-nat". I suspect any improvement in performance would be negligible, since I'm pretty sure most of the CPU being tak...
by NathanA
Tue Apr 22, 2025 3:01 am
Forum: General
Topic: How to maximize throughput on SSTP
Replies: 11
Views: 2292

Re: How to maximize throughput on SSTP

Whoever uses SSTP needs to understand that it is highly inefficient, by design . Exactly. Whenever I run into this topic, I like to link to this page: Why TCP Over TCP Is A Bad Idea SSTP is a last-ditch, "I'm desperate and literally nothing else will work" VPN protocol. If someone is in t...
by NathanA
Sun Apr 20, 2025 5:15 am
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 90
Views: 10277

Re: Netinstall on RM3011 Fails need help (technical questions)

When you say Netinstall works to one RB3011 but not to this other one, are you actually doing exact apples-to-apples comparison/testing? In other words, you are plugging eth1 of both RB3011s directly into the exact same ethernet port of the exact same PC? It's not like you are physically hooking one...
by NathanA
Sun Apr 20, 2025 5:02 am
Forum: General
Topic: Feature Request: Optional ability to restore without keeping MAC addresses
Replies: 18
Views: 1438

Re: Feature Request: Optional ability to restore without keeping MAC addresses

I'd just add while the simple: /interface/ethernet/reset-mac-address [find] works for ethernet... if you had other types of interfaces, those require additional (and varying script) work to reset OTHER interface types. The only other non-Ethernet hardware interface type I can think of that RouterOS...
by NathanA
Sat Apr 19, 2025 11:27 am
Forum: MikroTik hardware questions
Topic: hAP ac2 revisions
Replies: 11
Views: 1829

Re: hAP ac2 revisions

I just looked at two boxes from ac2 as well as physical stickers on the devices. The international one says "INTL/US", product code RBD52G-5HacD2HnD-TC. The numbers after the serial number are "347/r3". The US one has product code RBD52G-5HacD2HnD-TC-US, the numbers after the se...
by NathanA
Sat Apr 19, 2025 10:36 am
Forum: RouterOS beta
Topic: Feature request: ND Proxy (RFC 4389)
Replies: 24
Views: 14825

Re: Feature request: ND Proxy (RFC 4389)

The problem is of course source address selection. When a host has more than one address, to my knowledge, most hosts that have a direct presence/address-assignment within the same prefix as the destination they are trying to reach will properly source from the address they possess within that same...
by NathanA
Sat Apr 19, 2025 9:05 am
Forum: General
Topic: Public IP pool over pppoe
Replies: 21
Views: 1545

Re: Public IP pool over pppoe

Okay. So the RB will not be (strictly speaking) a bridge but a router. The ISP will send packets for any address from the /29, including the .0 and .7, to the RB, and the RB may attach the whole /29 to its bridge interface, wasting 3 of the total 8 addresses for its own address, the network address...
by NathanA
Sat Apr 19, 2025 8:52 am
Forum: General
Topic: Feature Request: Optional ability to restore without keeping MAC addresses
Replies: 18
Views: 1438

Re: Feature Request: Optional ability to restore without keeping MAC addresses

When we configure a new Mikrotik CPE , we restore a master configuration on the 2'nd Mikrotik - then must perform a /interface ethernet reset-mac-address for each interface. You likely know this, but just in case & for the benefit of everyone else, instead of having to issue separate commands &...
by NathanA
Mon Apr 14, 2025 1:04 am
Forum: RouterOS beta
Topic: Feature request: ND Proxy (RFC 4389)
Replies: 24
Views: 14825

Re: Feature request: ND Proxy (RFC 4389)

With an ipv6 prefix change, my connections fully internal to my network will be broken. My hunch is that even those in the IPv6 idealist camps would say this isn't the case, since if you are using it "as intended", you will have multiple addresses per interface, and that intra-LAN, your h...
by NathanA
Sun Apr 13, 2025 9:32 am
Forum: RouterOS beta
Topic: Feature request: ND Proxy (RFC 4389)
Replies: 24
Views: 14825

Re: Feature request: ND Proxy (RFC 4389)

This is (mostly) solved for RAs. Even if the (I seem to remember 2h) grace period is maintained on end-user devices: * connections still break after that * does the provider side maintain the route for this suggested grace period? * if the provider does not maintain the route, does it (just for fun...
by NathanA
Sun Apr 13, 2025 2:52 am
Forum: RouterOS beta
Topic: Feature request: ND Proxy (RFC 4389)
Replies: 24
Views: 14825

Re: Feature request: ND Proxy (RFC 4389)

Yep. Should have been solved (like there are framed routes in ipcp). IPCP itself doesn't really know about "framed routes", which is just an implementation detail on the PPP server side. (And it actually is a long-standing pity both that IPCP can't tell the connecting client what IPv4 CID...
by NathanA
Sat Apr 12, 2025 4:35 pm
Forum: RouterOS beta
Topic: Feature request: ND Proxy (RFC 4389)
Replies: 24
Views: 14825

Re: Feature request: ND Proxy (RFC 4389)

It turns out that there is a lot that I agree with you on...and some that I don't. 🙂 I'm not sure that treating a mobile device as a singular endpoint is the worst thing. Of course this does not allow for the broadband over 3/4/5G scenario, which should obviously be handled in some other fashion. I ...
by NathanA
Sat Apr 12, 2025 4:35 am
Forum: RouterOS beta
Topic: Feature request: ND Proxy (RFC 4389)
Replies: 24
Views: 14825

Re: Feature request: ND Proxy (RFC 4389)

I just can't understand the reason for all the strange implementations ISPs come up with. (And "strange" barely begins to describe my general annoyance.) At least when it comes to 3GPP networks, changes on such large networks (and the devices that connect to them) seem to move at the Spee...
by NathanA
Sat Apr 12, 2025 3:06 am
Forum: General
Topic: T1 interface
Replies: 9
Views: 1111

Re: T1 interface

You could research on Sangoma that's what we used in the old days I don't know if this works with x86 MikroTik PC never try them :) I believe ROS supported some Sangoma cards waaaaaaaaaaaaaaaaaaaaaaaaaay back in v2.9. In v3, I seem to recall support for all sync serial interface cards was dropped e...
by NathanA
Sat Apr 12, 2025 2:48 am
Forum: General
Topic: CCR2004-16G-2S+ stable?
Replies: 2
Views: 535

Re: CCR2004-16G-2S+ stable?

The 16G-2S+ variant of the CCR2004 was never released running v6, and v6 has no support for its networking hardware. The 12S+2XS variant was initially released with v6, but many people have reported instability with it (though most of those reports seemed to calm down after the release of 6.49+). It...
by NathanA
Sat Apr 12, 2025 2:34 am
Forum: RouterOS beta
Topic: Feature request: ND Proxy (RFC 4389)
Replies: 24
Views: 14825

Re: Feature request: ND Proxy (RFC 4389)

why not just use IPv6 NAT? (With non-ULA internal addressing...)

If not ULA (which is obviously undesirable due to how most client network stacks treat them), then what IP space would you suggest such a set-up use?
by NathanA
Fri Apr 11, 2025 3:20 pm
Forum: RouterOS beta
Topic: Feature request: ND Proxy (RFC 4389)
Replies: 24
Views: 14825

Re: Feature request: ND Proxy (RFC 4389)

I remember doing a bunch of testing of IPv6 over LTE on ROS a year or two ago, and coming away with the distinct impression that it had to be proxying NDP; however, in fairness, at this moment I cannot recall the specifics of how or why I concluded that. I just discovered RFC 7278 , and I suppose it...
by NathanA
Thu Apr 10, 2025 9:37 am
Forum: RouterOS beta
Topic: Feature request: ND Proxy (RFC 4389)
Replies: 24
Views: 14825

Re: Feature request: ND Proxy (RFC 4389)

I remember raising this point before, but apparently it wasn't in my prior reply to this thread (from 3 years ago...). So it bears repeating here: The craziest part of this is, RouterOS actually HAS an NDP Proxy. It's just that it is ONLY available if you configure IPv6 over an LTE connection! If yo...
by NathanA
Mon Apr 07, 2025 5:25 pm
Forum: General
Topic: Device-mode changes hit or miss? Mikrotik strategy?
Replies: 38
Views: 3414

Re: Device-mode changes hit or miss? Mikrotik strategy?

The thing that angers me the most is, when updating a hap ac2 from a ROS 6 version, to >=7.17.x the cpu-frequency is set to something around 730mhz... Not to derail the conversation too much, but I'm pretty sure that the CPU freq default setting on RouterOS 6 / RouterBOOT 6 was to fix it at 716MHz....
by NathanA
Mon Apr 07, 2025 5:01 pm
Forum: General
Topic: fasttrack x86
Replies: 26
Views: 6284

Re: fasttrack x86

Just to be clear, my post was about fast path via nf_flowtable, not L2MTU. Different features and different context. You were perfectly clear. The context is that of assuming that MT made the seemingly logical choice by choosing a networking feature that might be provided natively in the mainline k...
by NathanA
Mon Apr 07, 2025 12:20 pm
Forum: MikroTik hardware questions
Topic: hAP ac2 revisions
Replies: 11
Views: 1829

Re: hAP ac2 revisions

Is hAP ac2 still being manufactured? I understand the hardware revision might have happened at some point in the past, so all your points are valid regardless. They don't publish any end-of-life dates or even product release dates. The hardware page on the main website only has the archived section...
by NathanA
Mon Apr 07, 2025 12:39 am
Forum: MikroTik hardware questions
Topic: hAP ac2 revisions
Replies: 11
Views: 1829

Re: hAP ac2 revisions

Very often MT will +1 the revision # if they make even the smallest of hardware tweaks (typically as long as that tweak also requires software support). So for example, maybe they had to switch NOR flash vendors for one of their manufacturing runs/batches, and older versions of ROS do not support th...
by NathanA
Mon Apr 07, 2025 12:35 am
Forum: General
Topic: Difference between hAP ac2 RBD52G-5HacD2HnD-TC and RBD52G-5HacD2HnD
Replies: 7
Views: 924

Re: Difference between hAP ac2 RBD52G-5HacD2HnD-TC and RBD52G-5HacD2HnD

I also have a 256MB unit where /system/routerboard reports as "-TC" at the end of the model#. It also reports the same in its MNDP broadcasts (IP > Neighbor table entries on neighboring routers, and also in Winbox Neighbors tab). I had never noticed the -TC before! We have hundreds and hun...
by NathanA
Mon Apr 07, 2025 12:28 am
Forum: General
Topic: L009 crash after upgrading to newer software
Replies: 4
Views: 713

Re: L009 crash after upgrading to newer software

As a first step, could you try downgrading one of your crashing L009s back to 7.16, and see if the crashes stop? That would at least lend more evidence to the theory of a grievous regression in 7.17+ that affects at least this product...
by NathanA
Mon Apr 07, 2025 12:20 am
Forum: General
Topic: fasttrack x86
Replies: 26
Views: 6284

Re: fasttrack x86

I got this info from a friend I met this weekend. Support for " fast path " (aka Linux " flowtables ") is standard functionality in Linux kernel 5.6, which is what ROS v7 runs on. Flowtables were introduced around 2017/2018 with full user-space support in Linux 5.1 and use relat...
by NathanA
Mon Apr 07, 2025 12:11 am
Forum: General
Topic: [Bug-Fix-Request] DHCP-Option 82 on hEX S not disable HW-Forward by default
Replies: 13
Views: 3720

Re: [Bug-Fix-Request] DHCP-Option 82 on hEX S not disable HW-Forward by default

a general one... As i can see, v6.49 uses all 4 CPUs for Download and Upload traffic (sfp1 > ether1 = Download, ether1 > sfp1 = Upload). With v7.x (7.18.2 in my tests, but also other versions act the same) Download is handled by CPU 0 only, while Upload will be handled by 0,1,2,3 so 100%. [...] The...
by NathanA
Fri Apr 04, 2025 5:01 pm
Forum: General
Topic: [Bug-Fix-Request] DHCP-Option 82 on hEX S not disable HW-Forward by default
Replies: 13
Views: 3720

Re: [Bug-Fix-Request] DHCP-Option 82 on hEX S not disable HW-Forward by default

I have no idea why the switching performance without Fast Path and Hardware Offload in RouterOS 6 is much better though. The numbers are lower than RouterOS 7 with Fast Path available though. So even with RouterOS 6 it would be better to not use DHCP Snooping on the hEX / hEX S. I think the conclus...
by NathanA
Fri Apr 04, 2025 10:23 am
Forum: General
Topic: RouterOS License Level 2?
Replies: 8
Views: 2328

Re: RouterOS License Level 2?

The last time I actually checked this field thoroughly (it was a few years ago), MT ceased to support new installs of x86 bare metal devices. I don't know where you came up with that as I'm quite sure that has never been the case. In fact, arguably, with the release of RouterOS 7, it's better than ...
by NathanA
Fri Apr 04, 2025 9:47 am
Forum: General
Topic: Device-mode changes hit or miss? Mikrotik strategy?
Replies: 38
Views: 3414

Re: Device-mode changes hit or miss? Mikrotik strategy?

The dumbest problem was this hidden 1,5mb flash usage. I don't disagree. (Well, maybe that combined with the fact that 16MiB of fixed nonvolatile storage was ever a thing on any model.) Really, though, I was annoyed by the entire problem-set as a whole (and not one any specific part), which is what...
by NathanA
Fri Apr 04, 2025 6:14 am
Forum: General
Topic: RouterOS License Level 2?
Replies: 8
Views: 2328

Re: RouterOS License Level 2?

I was looking at the RouterOS license levels and noticed there’s no level 2. The feature gap between 1 and 3/4 is also pretty extreme. It's a category of question in tech that is as old as time: "What happened to Windows 9?" "Why isn't there IPv5?" 😂 Now, I actually knew the ans...
by NathanA
Fri Apr 04, 2025 4:20 am
Forum: General
Topic: Connectivity Issues after Upgrade 7.17.2 > 7.18 / 7.18.2
Replies: 32
Views: 9367

Re: Connectivity Issues after Upgrade 7.17.2 > 7.18 / 7.18.2

Just tried with an RBwAPGR-5HacD2HnD / 7.18.2 Same Config as above. Ping and Winbox over IPSec works instantly - no Downgrade needed with that device. Seems to be an issue with that hEX S... I do know that different SoCs implement different levels of encryption hardware offload that IPsec on Router...
by NathanA
Fri Apr 04, 2025 4:06 am
Forum: General
Topic: Device-mode changes hit or miss? Mikrotik strategy?
Replies: 38
Views: 3414

Re: Device-mode changes hit or miss? Mikrotik strategy?

Sounds like a kind of "secret key" (rather than a password). Good idea. But won't help for already deployed devices. Not in all scenarios, but definitely in certain ones, it absolutely can. One such scenario would be, as I mentioned earlier, if you have end-to-end control of the network t...
by NathanA
Fri Apr 04, 2025 3:48 am
Forum: General
Topic: X86_64 Building question
Replies: 1
Views: 599

Re: X86_64 Building question

Wow, that's amazing that Getic can sell licenses so cheaply. The wholesale rate they get must be crazy. CHR license keys and "regular" license keys are different and not interchangeable, from the perspective that a CHR key can only be applied to a CHR instance, and a regular key to a bare-...
by NathanA
Thu Apr 03, 2025 3:46 am
Forum: Virtualization
Topic: Get rid of "Licensing Error. Cloning a cloned machine is not permitted"
Replies: 8
Views: 10929

Re: Get rid of "Licensing Error. Cloning a cloned machine is not permitted"

I have a pool of ready to use CHR licenses I can use to activate/build a replacement CHR when it does what you are describing. Is using an extra/different license actually any faster than simply blowing the original one away, spinning up a virgin one, and applying the original license back to it &a...
by NathanA
Thu Apr 03, 2025 3:38 am
Forum: General
Topic: rOS v7.1xxx x86_64 bare metal TX/RX annoying drops
Replies: 7
Views: 3063

Re: rOS v7.1xxx x86_64 bare metal TX/RX annoying drops

I'm starting to think it is just certain packets being sent that the driver doesn't like, I don't think it necessarily means performance is degraded. You may be onto something, and I have suspected something similar for a while. I will note that I have not put ROS 7 on any of our bare-metal x86 rou...
by NathanA
Thu Apr 03, 2025 3:20 am
Forum: General
Topic: Device-mode changes hit or miss? Mikrotik strategy?
Replies: 38
Views: 3414

Re: Device-mode changes hit or miss? Mikrotik strategy?

[...] removed the password label without noting it down, [...] I'm not talking about that (I agree that removing the label is a bad idea). I'm talking about, as I said before, *already deployed* devices. Implying, I am not physically in the same room with said device, nor would it be easy nor conve...
by NathanA
Wed Apr 02, 2025 10:47 pm
Forum: General
Topic: Device-mode changes hit or miss? Mikrotik strategy?
Replies: 38
Views: 3414

Re: Device-mode changes hit or miss? Mikrotik strategy?

As I already suggested, wouldn't it be enough to use the factory password for security? As dang21000 points out, not all devices have default factory password. For the ones that do, if they have already been deployed and the factory password was changed, and we didn't keep a record of the factory p...
by NathanA
Wed Apr 02, 2025 12:15 pm
Forum: General
Topic: Device-mode changes hit or miss? Mikrotik strategy?
Replies: 38
Views: 3414

Re: Device-mode changes are hilarious

My concern is that there will come another media storm, where Mikrotik routers are singled out for being parts of some botnet, and (also in the name of security and with good intentions) another set of features will be restricted by a new device mode. Then at least some people in some situations wi...
by NathanA
Wed Apr 02, 2025 9:49 am
Forum: General
Topic: Device-mode changes hit or miss? Mikrotik strategy?
Replies: 38
Views: 3414

Re: Device-mode changes are hilarious

I agree with most of the complaints about the implementation and how this has been handled; the device-mode restrictions are very annoying to have to deal with, especially when it is a remote device that you have upgraded and that you previously had full control of prior to the upgrade. That said, i...
by NathanA
Wed Apr 02, 2025 9:22 am
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 55
Views: 4165

Re: MikroTik RB5009 setting up remotely first time

we need this setup to access the LAN there are many network enabled device we need to configure noone at that house is able to do so. In your original post, you said this: This means all internet traffic from House 2 should be routed through the RB5009 at House 1. Naturally, this makes it sound lik...
by NathanA
Wed Apr 02, 2025 2:43 am
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 55
Views: 4165

Re: MikroTik RB5009 setting up remotely first time

what uses Intenet the way that needs to be routed via House2? OP hasn't said this explicitly, but what this "smells" like to me is, there is probably some online resource that is geographically restricted to the area where House 2 exists (like maybe video streaming service or something), ...
by NathanA
Tue Apr 01, 2025 11:22 am
Forum: General
Topic: ccr1072 when rebooted gets stuck in reboot loop
Replies: 13
Views: 1510

Re: ccr1072 when rebooted gets stuck in reboot loop

I have a few CCR1xxx at my disposal to do some testing with, so now that I am so invested in understanding the nature of this problem, I'll try to set aside some time to run a few deeper experiments. 😉 Okay, I quickly grabbed a CCR1036-8G-2S+ off of the shelf (I acknowledge this is not the same mod...
by NathanA
Tue Apr 01, 2025 9:51 am
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 55
Views: 4165

Re: MikroTik RB5009 setting up remotely first time

The text diagram appears to show the RB5009 all on its lonesome, nothing downstream. A drawing might have been helpful. He has both explained in the original post & confirmed in follow-ups that the RB5009 is going to be hanging off of a private LAN, sitting behind a NAT, with a single connectio...
by NathanA
Tue Apr 01, 2025 9:45 am
Forum: General
Topic: ccr1072 when rebooted gets stuck in reboot loop
Replies: 13
Views: 1510

Re: ccr1072 when rebooted gets stuck in reboot loop

IIRC there was routerboot change sometime around 6.48, which was (later?) required for proper support of newer kernel, present in v7. Where exactly is this stated or documented? ROS changelogs do include "routerboot" entries in them going back to the 6.x days, and yet I can find no mentio...
by NathanA
Tue Apr 01, 2025 4:19 am
Forum: General
Topic: [Bug-Fix-Request] DHCP-Option 82 on hEX S not disable HW-Forward by default
Replies: 13
Views: 3720

Re: [Bug-Fix-Request] DHCP-Option 82 on hEX S not disable HW-Forward by default

Activating DHCP-Snooping on v6.69.6 does not decrease speed to round about 300M. The 849,70 MBit/s shown on that Screenshot is 100% of ISP-Speed. Do note that it is still true in this screenshot that bridge fast path is not working...fast path counters in Bridge > Settings are all at 0. Also, no po...
by NathanA
Tue Apr 01, 2025 4:03 am
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 55
Views: 4165

Re: MikroTik RB5009 setting up remotely first time

This is what I will try. Actually I noticed yesterday that my house1 isp router though assigns ipv4 to ether1 it does not assign the ipv6. my isp router has ispv6 capability it assigns to other device. Not sure why ether1 of rb5009 does not get one. I do not think that the default config sets up a ...
by NathanA
Tue Apr 01, 2025 3:14 am
Forum: General
Topic: ccr1072 when rebooted gets stuck in reboot loop
Replies: 13
Views: 1510

Re: ccr1072 when rebooted gets stuck in reboot loop

So it appears the mismatch in the routerBOARD firmware and the OS firmware was the issue. or at least it appears to have fixed it for now :) thanks for the help everyone ! I think time will have to tell if this actually fixed the issue. I personally have never seen mismatched RouterOS and RouterBOO...
by NathanA
Tue Apr 01, 2025 1:46 am
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 55
Views: 4165

Re: MikroTik RB5009 setting up remotely first time

Quick addendum to my last post: I did just think of one other possible way you can access WebFig with the default config over the LAN without changing your PC's IP address: if your PC has IPv6 enabled (and if it is anywhere close to recent, it should), you can try to talk to the router via the LAN l...
by NathanA
Tue Apr 01, 2025 1:21 am
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 55
Views: 4165

Re: MikroTik RB5009 setting up remotely first time

2)If I connect the RB5009 to ISP router via ether2 then ISP router do not assign any IP. so cant access RB5009 I did tell you this would be the case. Default config ONLY has DHCP *client* on ether1. ether2-ether8 only run DHCP *server* and has a static private IP of 192.168.88.1. You either need to...
by NathanA
Mon Mar 31, 2025 2:30 pm
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 55
Views: 4165

Re: MikroTik RB5009 setting up remotely first time

Better the naysayers of those who implicitly suggest deleting the default configuration and therefore the firewall with all that it entails because is more easy, creating yet another machine that will cause, in one way or another, DDoS... Did you ACTUALLY read OP's post? Because it was pretty clear...
by NathanA
Mon Mar 31, 2025 12:59 pm
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 55
Views: 4165

Re: MikroTik RB5009 setting up remotely first time

To *directly* answer the OP's main question: Different MikroTik router models come with different default out-of-box configurations. Most home/SOHO models will have a default config that treats first copper ethernet port (ether1) as "WAN", and the remaining ports as a single common switche...
by NathanA
Mon Mar 31, 2025 8:54 am
Forum: General
Topic: ccr1072 when rebooted gets stuck in reboot loop
Replies: 13
Views: 1510

Re: ccr1072 when rebooted gets stuck in reboot loop

I doubt logging to disk is going to reveal anything. It sounds like RouterOS itself is shutting down cleanly and resetting the CPU fine & the problem is not happening until after the bootloader is engaged, so nothing interesting is going to get logged...if it can't get past loading kernel then w...
by NathanA
Sat Mar 29, 2025 1:08 pm
Forum: General
Topic: upgrade from V6 to V7 question for ccr1036
Replies: 3
Views: 915

Re: upgrade from V6 to V7 question for ccr1036

I think Recent versions of Ros V7 don't have the upgrade from V6 conversion functionality any more. I am not sure where you got that idea. Please read the docs , which explicitly state the following: In most RouterOS setups that run fine with the aforementioned v6 versions, no extra steps are requi...
by NathanA
Thu Mar 27, 2025 11:51 pm
Forum: General
Topic: Feature request - add interface Vlans & ports & bridge functions into a single easy Winbox/Web settings page
Replies: 10
Views: 2775

Re: Feature request - add interface Vlans & ports & bridge functions into a single easy Winbox/Web settings page

I am saying it's nearly impossible to configure switchport vlans if you are not already experienced with Mikrotik routers/switches. [...] Mikrotik switchport Vlan documentation is not consistent and not similar to other products ( CLI and/or GUI ). I get the argument. I guess all I was trying to de...
by NathanA
Thu Mar 27, 2025 10:46 pm
Forum: General
Topic: IPv6 Setup Weirdness [SOLVED]
Replies: 25
Views: 10649

Re: IPv6 Setup Weirdness [SOLVED]

Is your "IOT interface" / the VLAN mentioned that "BR1" interface? I missed the 'fdec:<blah>' address on the interface called "IOT" until it was pasted in in the comment posted while I was writing up my last response, heh. Yeah, that's a ULA address, which is basically...
by NathanA
Thu Mar 27, 2025 10:34 pm
Forum: General
Topic: IPv6 Setup Weirdness [SOLVED]
Replies: 25
Views: 10649

Re: IPv6 Setup Weirdness [SOLVED]

1. The weird thing is I am getting a random Dynamic Global address on only one of my VLANs and I have no idea why. I get link-local addresses on each of my interfaces. And a single DG address on a VLAN. [...] 2. Any ideas why I am getting a random address on the IOT interface? Is your "IOT int...
by NathanA
Thu Mar 27, 2025 2:34 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 13628

Re: My recent VLAN fiasco [SOLVED]

So in which way my statement doesn't apply to your example?
Please read my response directly above your last (posted about an hour prior). It explains...well, as much as can possibly be explained, heh. In short, I had a most massive frain bart. 😳
by NathanA
Thu Mar 27, 2025 1:35 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 13628

Re: My recent VLAN fiasco [SOLVED]

I think @mkx was specifically talking about adding the bridge port named "bridge" (as in the CPU-facing port) as a tagged port. Oh my goodness! I think you're right! 🤦‍♂️ And in retrospect when I re-read that part of my reply with that in mind, it doesn't even make sense...yes of course h...
by NathanA
Thu Mar 27, 2025 12:50 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 13628

Re: My recent VLAN fiasco [SOLVED]

Look at the device in the OP of this thread, it's a RB5009, a router. Look at OP's current config that he/she wants to extend with VLAN, it's a ROUTER! Fair point. But then read through the rest of the thread up to this point, where we all kind of got a bit off the beaten path, and the conversation...
by NathanA
Thu Mar 27, 2025 10:55 am
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 13628

Re: My recent VLAN fiasco [SOLVED]

In principle you don't want to set bridge port as tagged member of a VLAN if you don't intend CPU to interact with that VLAN over that bridge. [...] So I'm eager to hear use case for such setup. Huh? That's just not true. Maybe you are assuming that the MT in question is a router that will also be ...
by NathanA
Thu Mar 27, 2025 10:16 am
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 13628

Re: My recent VLAN fiasco [SOLVED]

Since 7.16 we have this: *) bridge - added dynamic tagged entry when VLAN interface is created on vlan-filtering bridge; That removes the risk of forgetting to add the bridge CPU port to the "tagged" list of VLANs (which in older versions means no L3 access to the router through those VLA...
by NathanA
Thu Mar 27, 2025 9:51 am
Forum: General
Topic: Feature request - add interface Vlans & ports & bridge functions into a single easy Winbox/Web settings page
Replies: 10
Views: 2775

Re: Feature request - add interface Vlans & ports & bridge functions into a single easy Winbox/Web settings page

The part I will agree with you on is that I don't understand what is preventing them from unifying the front-end VLAN config interface as much as possible across the different models of switch chips used in the different products. I understand that not all switch chips support all of the same featur...
by NathanA
Thu Mar 27, 2025 8:21 am
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 13628

Re: My recent VLAN fiasco [SOLVED]

I'd just add on routers with a default configuration, enabling vlan-filtering=yes is complete safe to do at the START in RouterOS 7.16+. While, typical advice is to set vlan-filtering=yes last. I'm not sure that the best advice anymore. Since default use VLAN 1, that actually why enabling vlan-filt...
by NathanA
Wed Mar 26, 2025 3:46 pm
Forum: General
Topic: Feature request: Add Copy functionality for NAT & Firewall rules
Replies: 10
Views: 1385

Re: Feature request: Add Copy functionality for NAT & Firewall rules

In CLI, you can do an export and copy a specific line. If you execute that line (with some adjustments) you can execute it. There is also 'copy-from=' property, and you can modify whatever parameters you want on the new cloned object at the time of creation as well: /ip/firewall/filter/add copy-fro...
by NathanA
Tue Mar 25, 2025 11:31 pm
Forum: General
Topic: fasttrack x86
Replies: 26
Views: 6284

Re: fasttrack x86

You only need two back-to-back newlines for all cases. No space needed.

Heh, I swear I have tried that in the past, too. Let's give it a shot (again?)...

Bleh.

Test.

Yep, works (now?); thanks.
by NathanA
Tue Mar 25, 2025 11:26 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 13628

Re: My recent VLAN fiasco [SOLVED]

How is it "reserved"? Or, how is "bridging between access ports to VLAN XYZ" different from "bridging between untagged ports"? What would be the purpose of a managed switch if you could not make an "untagged port" (= access one) a member of whatever VLAN you ...
by NathanA
Tue Mar 25, 2025 10:27 pm
Forum: General
Topic: [Bug-Fix-Request] DHCP-Option 82 on hEX S not disable HW-Forward by default
Replies: 13
Views: 3720

Re: [Bug-Fix-Request] DHCP-Option 82 on hEX S not disable HW-Forward by default

Thank you for that hint on that matrix. Is there also any matrix available where we can see which Mikrotik have which Switch-Chip inside? You can see the list of products that contain each switch chip model, and which particular interfaces/ports are attached to those switch chips, right below the s...
by NathanA
Tue Mar 25, 2025 10:14 pm
Forum: General
Topic: fasttrack x86
Replies: 26
Views: 6284

Re: fasttrack x86

Yeah, but you forgot to add my mighty conclusion: Because I'm not convinced of your conclusion, just as you are not convinced of mine. 😜 You don't need to use a backtick to add an empty new line, just use a space plus newline I swear I've tried that before on previous incarnations of the forum, and...
by NathanA
Tue Mar 25, 2025 9:37 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 13628

Re: My recent VLAN fiasco [SOLVED]

but on many switches [...] vlan 1 is sort of hard coded [for this purpose], so if you have to interoperate with these, vlan 1 should be handled with care. Perhaps this is what you are getting at, but most of these aforementioned switches will reserve VID 1 as an "untagged" VLAN, and likel...
by NathanA
Tue Mar 25, 2025 8:56 pm
Forum: General
Topic: fasttrack x86
Replies: 26
Views: 6284

Re: fasttrack x86

To me, the key question still is: Does FastPath require a hard dependency on patched drivers, or can ROS use skb with standard hooks? ` Yes, of course. That's what we are discussing. Unfortunately, at the moment, I feel that we (on the outside of MT engineering) lack enough evidence to definitively...
by NathanA
Tue Mar 25, 2025 12:11 am
Forum: General
Topic: fasttrack x86
Replies: 26
Views: 6284

Re: fasttrack x86

That said, I’ll concede that “interface driver support” might not necessarily mean modifying the driver. It could just mean that the driver and underlying hardware must not interfere with FastPath requirements ` Eh, maaaaaaybe? But if that were the case, you'd have to validate a lot of things about...
by NathanA
Mon Mar 24, 2025 10:13 pm
Forum: General
Topic: All IPv6 stops working until I manually renew DHCP6 lease from ISP?
Replies: 5
Views: 1512

Re: All IPv6 stops working until I manually renew DHCP6 lease from ISP?

The default 30d / 7d are > of default 3d on server side (not MikroTik problem, are default RFC values...) So for internal network the IPv6 expires 4 day later of what is already expired... ` Sorry, but unless I'm missing something, this theory makes no sense. Even if what you said is true that the ...
by NathanA
Mon Mar 24, 2025 9:37 pm
Forum: General
Topic: fasttrack x86
Replies: 26
Views: 6284

Re: fasttrack x86

Do you know how it actually works under the hood? ` I have not read through the source code, so no. ` My guess is that Mikrotik uses their own attributes (likely within skb->cb[]) to flag packets that can bypass things like firewall, NAT, or queuing. This would work across all architectures, includ...
by NathanA
Mon Mar 24, 2025 8:42 pm
Forum: RouterOS beta
Topic: v7 MPLS hardware offload?
Replies: 39
Views: 21349

Re: v7 MPLS hardware offload?

i think there is no priority for Mikrotik with this matter if it was important they at least will tried to get the old MPLS feature working even being mutually exclusive with l3 hw offload on v7, at least until they can make it work simultaneously, but nothing close to that happened... ` I agree th...
by NathanA
Mon Mar 24, 2025 8:23 pm
Forum: RouterOS beta
Topic: v7 MPLS hardware offload?
Replies: 39
Views: 21349

Re: v7 MPLS hardware offload?

i think v6 MPLS working feature got in the way of L3 hw offload maybe thats the reason to drop the MPLS feature as a temporary measure.. ` Maybe you're right; since we have no visibility into the situation from the outside, we can only speculate. But this just goes back to my concluding point : ` T...
by NathanA
Mon Mar 24, 2025 8:05 pm
Forum: RouterOS beta
Topic: v7 MPLS hardware offload?
Replies: 39
Views: 21349

Re: v7 MPLS hardware offload?

you forgot to mention only worked on some specific devices (CRS317-1G-16S+ and CRS309-1G-8S+) ` I didn't "forget to mention it". The context was, as StubArea51 put it, "day one of the Marvell chips being introduced". The Marvell switch chips are only used in certain products, of...
by NathanA
Mon Mar 24, 2025 11:31 am
Forum: General
Topic: Feature Request : DSCP on DHCP packets
Replies: 24
Views: 11277

Re: Feature Request : DSCP on DHCP packets

I get why it's not an "ideal" solution, but given that the choice is seemingly between waiting for a change to ROS code, using PPPoE, or not using a MT as a CPE when on Orange...why is it not an option to put the WAN interface in a bridge by itself, hang a VLAN interface off of that, and t...
by NathanA
Mon Mar 24, 2025 9:54 am
Forum: General
Topic: PPPoE with forwarding to a Hotspot when user is 'blocked'
Replies: 1
Views: 890

Re: PPPoE with forwarding to a Hotspot when user is 'blocked'

Note, we are then not using the [...] Hotspot Pool to assign a customer a Hotspot IP as we have done that via PPPoE/Radius, [...] Maybe I'm missing something, but why couldn't you create an IP Pool on your BRAS that you assign to Hotspot Server as Address Pool, and then if a subscriber's traffic ne...
by NathanA
Mon Mar 24, 2025 1:59 am
Forum: General
Topic: IPv6 Fastpath on 7.18
Replies: 10
Views: 3614

Re: IPv6 Fastpath on 7.18

I've been pretty negative recently in my posts here (I would argue justifiably, though that's neither here nor there at the moment), but I want to take a moment to offer well deserved praise and give credit where credit is due. So: THANK YOU MikroTik (genuinely) for FINALLY getting around to impleme...
by NathanA
Mon Mar 24, 2025 1:44 am
Forum: General
Topic: fasttrack x86
Replies: 26
Views: 6284

Re: fasttrack x86

Fastpath and Fasttrack generally speaking do NOT work on x86. It is true that these have nothing whatsoever to do with HW offiload. However, both of these features require specific support to be added to the network interface driver (ethernet chip, etc.). MikroTik only bothers to do this for network...
by NathanA
Mon Mar 24, 2025 12:02 am
Forum: General
Topic: Forum rendering is broken
Replies: 6
Views: 1115

Re: Forum rendering is broken

Admittedly the subject is somewhat misleading, but there's already another thread about this. Haven't seen MT address this one way or the other. Hard to believe that they aren't aware of it, though, if they are using the forum at all themselves.
by NathanA
Mon Mar 24, 2025 12:00 am
Forum: General
Topic: PHPbb Prosilver has problem
Replies: 28
Views: 3243

Re: PHPbb Prosilver has problem

Maybe we are the betatesters for the next MikroTik product, a server load balancer? (after the storage server) I too have felt like this is a "CDN"-esque issue. In addition to the "forum not available" errors, the transmission time-outs, pages only loading halfway, etc. the othe...
by NathanA
Sun Mar 23, 2025 9:11 am
Forum: RouterOS beta
Topic: v7 MPLS hardware offload?
Replies: 39
Views: 21349

Re: v7 MPLS hardware offload?

I've advocated for it since day one of the Marvell chips being introduced. My guess is that if it's not added in 7.16 beta, there is prob some blocker they have to work on to get it running/stable/etc. Here's the thing: it EXISTED in RouterOS 6, and works perfectly freaking *fine* on RouterOS 6. Th...
by NathanA
Sun Mar 23, 2025 9:04 am
Forum: MikroTik hardware questions
Topic: high xt_misc CPU Usage on X86
Replies: 5
Views: 5366

Re: high xt_misc CPU Usage on X86

xt_<blah> are typically Linux netfilter modules. xt_misc doesn't seem to appear in Linux mainline releases, but the source code for it is included in MikroTik GPL sources. It's not commented much, but as far as I can tell from a quick glance it adds some of the uniquely-MikroTik firewall/NAT/mangle ...
by NathanA
Sat Mar 22, 2025 6:00 am
Forum: MikroTik hardware questions
Topic: intel x520-sr2 support
Replies: 5
Views: 2560

Re: intel x520-sr2 support

That's bit 0.
Fair point.
by NathanA
Fri Mar 21, 2025 9:52 am
Forum: MikroTik hardware questions
Topic: intel x520-sr2 support
Replies: 5
Views: 2560

Re: intel x520-sr2 support

I know this is a couple weeks old already, but I just noticed it. So allow me to link you to a post I made over on STH about how to patch any X520 EEPROM so that it will accept any SFP module , without needing to modify the kernel driver or pass kernel boot parameters (neither of which you are going...
by NathanA
Thu Mar 20, 2025 10:11 am
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 13628

Re: My recent VLAN fiasco [SOLVED]

You've got the right idea, and are very close. Don't manually set "untagged" ports on your bridge VLANs. When you set a bridge port member PVID, it automatically/dynamically gets added as "untagged". Manually setting "untagged" just lets you force a VLAN to egress a por...
by NathanA
Thu Mar 20, 2025 4:39 am
Forum: General
Topic: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License
Replies: 38
Views: 4459

Re: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License

I did receive some response: https://box.mikrotik.com/d/81912835977544a291c9/ [...] Note, all of the files are 3+ years old. While the kernel is not new, I'm a bit skeptical there are ZERO kernel patches/changes in 3 years.... But in fairness I have not studied the disclosed file yet, so IDK... I h...
by NathanA
Wed Mar 19, 2025 1:34 pm
Forum: General
Topic: installation of system-7.18.2 failed: disk is too small
Replies: 10
Views: 1821

Re: installation of system-7.18.2 failed: disk is too small

i don't believe the issue is the flash, but how the free space is calculated. You could be right, but also, MT has no real incentive to help try to troubleshoot this issue on that particular model with the modification you did, since it would set a precedent for accepting responsibility for things ...
by NathanA
Wed Mar 19, 2025 12:42 pm
Forum: General
Topic: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License
Replies: 38
Views: 4459

Re: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License

I mean what NathanA said about NPKs. RouterOS internal security has been changed several times, there are all kinds of internal integrity checks. You can't install self-made NPK files. v7 was a very big change as such, but even during v7 many changes have been made to security in this regard and ot...
by NathanA
Wed Mar 19, 2025 10:02 am
Forum: General
Topic: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License
Replies: 38
Views: 4459

Re: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License

just curious how the plan for that would look like with ROS? NPK packages are signed and i assume also at boot time when kernel is loaded, You might assume wrong. I'm not sure about ROS 7 (haven't dug too deeply into its guts yet), but at least with ROS 6 (or at least for most of its existence...ma...
by NathanA
Wed Mar 19, 2025 9:42 am
Forum: General
Topic: (broken) IPv4 connection tracking and fragmentation on ROS 7
Replies: 4
Views: 1419

Re: (broken) IPv4 connection tracking and fragmentation on ROS 7

I just ran into this bug a day or two ago while trying to migrate an existing set-up from RouterOS 6 to 7. I have not had a chance to "officially" report it yet, but bug reporting to MT has become useless recently, taking weeks to get a response only to be told that they can't reproduce th...
by NathanA
Wed Mar 19, 2025 9:29 am
Forum: General
Topic: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License
Replies: 38
Views: 4459

Re: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License

In past years, for various versions of RouterOS 5 and 6, I have asked & obtained the kernel sources from MikroTik. At the time, they were usually pleasantly swift to respond; but I did note that there was usually a delay of a few days if I was the first person to ask for the kernel sources to a ...
by NathanA
Wed Mar 19, 2025 8:43 am
Forum: General
Topic: (broken) IPv4 connection tracking and fragmentation on ROS 7
Replies: 4
Views: 1419

Re: (broken) IPv4 connection tracking and fragmentation on ROS 7

I've got good news, and I've got bad news. I have re-tested IPv4 fragmented packets passing through a router running on RouterOS 7 without involving any bridging (just pure L3 forwarding). The "good" news is that if the bridge is not involved, then RouterOS 7 *does* re-assemble IPv4 packet...
by NathanA
Tue Mar 18, 2025 1:54 pm
Forum: General
Topic: (broken) IPv4 connection tracking and fragmentation on ROS 7
Replies: 4
Views: 1419

(broken) IPv4 connection tracking and fragmentation on ROS 7

There seem to be some new problems when connection tracking and forwarding of IPv4 fragments are combined together, on RouterOS 7. I realize that RouterOS 7 uses a much newer version of the Linux kernel underneath the covers, and that a lot changed in the underlying network stack of Linux between Ro...
by NathanA
Fri May 12, 2023 10:52 am
Forum: MikroTik hardware questions
Topic: Problems with X520-DA2
Replies: 2
Views: 12520

Re: Problems with X520-DA2

My org uses X520-DA2 in some x86 routers, and other than a couple of quirks that I haven't gotten around to posting about yet, they have been working surprisingly well for us. The concept of L2MTU is a RouterOS-specific thing, and has to be explicitly supported by the underlying driver for the inter...
by NathanA
Fri Feb 24, 2023 12:08 am
Forum: General
Topic: Changing ipv6 prefix
Replies: 96
Views: 25573

Re: Changing ipv6 prefix

And what in the release notes so far leads you to believe that? Do you have some eye defects? ` Yes, but mostly brain defects! ` I clearly linked to the change log from MikroTik regarding V7.8. ` Sorry, my browser did not jump down to the specific post in that very long thread the first time I clic...
by NathanA
Thu Feb 23, 2023 3:59 pm
Forum: General
Topic: Changing ipv6 prefix
Replies: 96
Views: 25573

Re: Changing ipv6 prefix

There is also tons of philosophy around ` I will definitely cop to personally falling more in the camp of caring about practicality, vs. philosophy. One example is that I'm not about to blame ISPs for not necessarily being able to adhere to people's idealized versions of what they should or shouldn...
by NathanA
Thu Feb 23, 2023 2:41 pm
Forum: General
Topic: Report "Delegated-IPv6-Prefix" attribute for PPPoE
Replies: 261
Views: 109363

Re: Report "Delegated-IPv6-Prefix" attribute for PPPoE

Back on 7 November 2022, I wrote: ` So, I see now after testing a bit more that there is a problem. It's actually not a problem with the 60 seconds, though. The problem is that, 10 seconds after lease renewal happens, the IP addresses assigned from the pool briefly go "invalid" and then ba...
by NathanA
Thu Feb 23, 2023 2:29 pm
Forum: General
Topic: Report "Delegated-IPv6-Prefix" attribute for PPPoE
Replies: 261
Views: 109363

Re: Report "Delegated-IPv6-Prefix" attribute for PPPoE

What is the current status of this long-requested feature in latest ROS 7? ` It works. It even works in ROS v6. So if it's not working for you, then I'm not sure what to tell you...I'd perhaps take the time to perform some packet captures of the exchange between your RADIUS server and your PPPoE se...
by NathanA
Thu Feb 23, 2023 2:24 pm
Forum: General
Topic: Report "Delegated-IPv6-Prefix" attribute for PPPoE
Replies: 261
Views: 109363

Re: Report "Delegated-IPv6-Prefix" attribute for PPPoE

While I agree that is bad behavior, there is a case to be made against using dynamic pools for PD: https://www.ripe.net/publications/docs/ripe-690 ` It's hard to know how to respond to this because it is entirely unclear what part of this very long thread you're responding to, or whether you read t...
by NathanA
Thu Feb 23, 2023 2:07 pm
Forum: General
Topic: Changing ipv6 prefix
Replies: 96
Views: 25573

Re: Changing ipv6 prefix

All, I just edited my previous reply with my DHCPv6 client script in order to replace it with an updated version. The original version of the script that I published here would indiscriminately disable and re-enable the IPv6 address during every lease renewal, in order to force the dynamic ND prefix...
by NathanA
Thu Feb 23, 2023 1:58 pm
Forum: General
Topic: Changing ipv6 prefix
Replies: 96
Views: 25573

Re: Changing ipv6 prefix

I think MikroTik fixed it on 7.8? ` And what in the release notes so far leads you to believe that? ` The solution, but still doesn't solve dynamic crap: https://datatracker.ietf.org/doc/html/rfc8978 ` Please try to keep up. RFC 6204 was published 12 years ago. Many consumer platforms' IPv6 stacks ...
by NathanA
Thu Feb 23, 2023 1:49 pm
Forum: General
Topic: Changing ipv6 prefix
Replies: 96
Views: 25573

Re: Changing ipv6 prefix

I don't have anything set under the DHCPv6 client section. ` LTE does not use DHCPv6 for communicating v6 address assignments. It essentially uses RAs and SLAAC. So it would do you no good to try to set up a DHCPv6 client. The script I wrote that does a "poor man's" implementation of RFC ...
by NathanA
Thu Dec 29, 2022 6:49 pm
Forum: Forwarding Protocols
Topic: BGP add-path
Replies: 2
Views: 3693

Re: BGP add-path

Doesn't seem to do very much, at least not when added to a BGP Connection.
`
From viewtopic.php?t=191693#p972927 --
`
bgp multipath / add-path is not implemented.
by NathanA
Fri Dec 23, 2022 1:24 pm
Forum: MikroTik hardware questions
Topic: RouterOS v7.6 in CCR1072
Replies: 19
Views: 9030

Re: RouterOS v7.6 in CCR1072

If true, still not an excuse for poor post-sale support. If you are going to put it on the market, then you need to be prepared to support it, which includes fixing the broken ones.
by NathanA
Fri Dec 23, 2022 2:31 am
Forum: MikroTik hardware questions
Topic: RouterOS v7.6 in CCR1072
Replies: 19
Views: 9030

Re: RouterOS v7.6 in CCR1072

i have only one case a ccr1072 with showing only 8gb of ram, the interesting thing is that the damn router works ok, but has a light load (6gbps of traffic), no performance problems either ` Yes acknowledged, like I said we have experienced 1072s that sometimes only have faulty memory count (but ar...
by NathanA
Fri Dec 23, 2022 1:44 am
Forum: Virtualization
Topic: CHR 7.6 Driver for Cisco VIC Ethernet NIC (rev: 162)
Replies: 2
Views: 6455

Re: CHR 7.6 Driver for Cisco VIC Ethernet NIC (rev: 162)

It looks like this interface is supported in Linux via a driver called "enic", which I don't believe is included in RouterOS. MikroTik developers would have to be the one to build and include the driver within RouterOS; as elbob2002 mentions, you cannot install 3rd-party drivers on top of ...
by NathanA
Fri Dec 23, 2022 1:09 am
Forum: MikroTik hardware questions
Topic: RouterOS v7.6 in CCR1072
Replies: 19
Views: 9030

Re: RouterOS v7.6 in CCR1072

i think MikroTik Lack of validated network design guidelines is the main reason of ccr1072 deployment miscarriages i have "rescued" several docens of ccr1072 which were at doorstops i think in most cases misconceptions about product scaling drove customers toward flawed network designs ` ...
by NathanA
Thu Dec 22, 2022 4:28 pm
Forum: MikroTik hardware questions
Topic: RouterOS v7.6 in CCR1072
Replies: 19
Views: 9030

Re: RouterOS v7.6 in CCR1072

Has there been some sort of consensus what is actually wrong with some of these ? As you say some from day 1 gave us non stop issues.We had to retire them and replace with ubnts. I have 3x 1072 doorstops at the office. Weird how the 1016's and 1032's just pretty much work forever.Our failure rate o...
by NathanA
Tue Dec 20, 2022 10:39 am
Forum: MikroTik hardware questions
Topic: RouterOS v7.6 in CCR1072
Replies: 19
Views: 9030

Re: RouterOS v7.6 in CCR1072

I concur that if you have a 1072 that you are experiencing frequent reboots on, the hardware is usually faulty. On the 1072 routers we have that work flawlessly, we have no crashing/stability issues that can be traced to RouterOS 6.x. There are a shocking number of faulty 1072s out there. Symptoms a...
by NathanA
Sun Dec 18, 2022 5:38 am
Forum: Forwarding Protocols
Topic: VPLS fragment reassembly bug only on TILE-arch
Replies: 10
Views: 10632

VPLS fragment reassembly bug only on TILE-arch

I just submitted this bug report to MikroTik through their service desk. But I thought I'd also post it here, just in case anybody else has maybe run into weird oddities on their network with random dropped packets and/or stalled or aborted TCP flows that there was seemingly no rhyme or reason for. ...
by NathanA
Mon Nov 07, 2022 1:31 pm
Forum: General
Topic: Very strange (pre-v7) ECMP bug?
Replies: 2
Views: 1068

Re: Very strange (pre-v7) ECMP bug?

FYI IPv6 ECMP in ROSv6 does not exist. RouterOS was able to handle ECMP Ipv6 routes, but actual forwarding can happen only over one gateway. ` You mean "packets with the same source address , destination address , source interface , routing mark and ToS are sent to the same gateway" (http...
by NathanA
Mon Nov 07, 2022 12:36 pm
Forum: General
Topic: Very strange (pre-v7) ECMP bug?
Replies: 2
Views: 1068

Very strange (pre-v7) ECMP bug?

I can't believe that this has been around for as long as it has, and nobody ever noticed it? I tested from latest 6.49.x back to RouterOS 5.x, but it probably has existed for much much longer? In short, if the route to reach a particular recursively-looked-up ECMP gateway disappears, and if the part...
by NathanA
Mon Nov 07, 2022 12:04 pm
Forum: General
Topic: Report "Delegated-IPv6-Prefix" attribute for PPPoE
Replies: 261
Views: 109363

Re: Report "Delegated-IPv6-Prefix" attribute for PPPoE

I see the same thing: lease time is only 60 seconds long. It would be nice to be able to adjust it, but in practice it doesn't seem to be causing any problems. Client has to renew every 30 seconds, but oh well... ` So, I see now after testing a bit more that there is a problem. It's actually not a ...
by NathanA
Wed Aug 17, 2022 11:12 am
Forum: General
Topic: NPTv6 / RFC 6296 Support?
Replies: 53
Views: 18916

Re: NPTv6 / RFC 6296 Support?

One thing that may have gotten lost in the shuffle (and because of the horrible forum software's way of formatting quote-replies): my initial response here was not to pawlisko, whose response just happened to get in between me and the one I was really responding to, which was pe1chl's comment that &...
by NathanA
Wed Aug 17, 2022 8:10 am
Forum: General
Topic: NPTv6 / RFC 6296 Support?
Replies: 53
Views: 18916

Re: NPTv6 / RFC 6296 Support?

I just love that analogy, and exactly the same all Telecom were saying going against MNP. Oh - thousands lines of code, databases, who will be responsible, etc. My number started years ago with Sprint, then it went to T-Mobile, than to At&T, to now Verizon. As a consumer I don't care. It has to...
by NathanA
Wed Aug 17, 2022 4:06 am
Forum: General
Topic: NPTv6 / RFC 6296 Support?
Replies: 53
Views: 18916

Re: NPTv6 / RFC 6296 Support?

There is significant pushback on address translation in the IPv6 standard bodies. Maybe they can make it formally forbidden to issue dynamic IPv6 prefixes to fixed line consumers. ` Strongly, strongly disagree. Having think tanks...err, "standards bodies" dictate how operators that are ac...
by NathanA
Wed Aug 17, 2022 3:26 am
Forum: General
Topic: Report "Delegated-IPv6-Prefix" attribute for PPPoE
Replies: 261
Views: 109363

Re: Report "Delegated-IPv6-Prefix" attribute for PPPoE

Hi there. Yeah 6.48.1 Works, BUT you can't have 2 customers with this attribute, as far I tested. [...] BUT the second customer is refused to connect with this message: "pppoe,ppp,error could not add dhcpv6 server with pool : server with such name already exists (7)" ` I can't reproduce t...
by NathanA
Mon Aug 15, 2022 12:08 pm
Forum: RouterOS beta
Topic: Feature request: ND Proxy (RFC 4389)
Replies: 24
Views: 14825

Re: Feature request: ND Proxy (RFC 4389)

advertise-dns=yes option on IPv6 ND is already present from years... ` You don't understand the original question. User's ISP only gives out /64, via SLAAC. But ISP RAs do not contain DNS information. Instead, ISP offers DNS information via DHCPv6 info. Since RouterOS does not have ND-Proxy, user i...
by NathanA
Mon Aug 15, 2022 2:45 am
Forum: General
Topic: Report "Delegated-IPv6-Prefix" attribute for PPPoE
Replies: 261
Views: 109363

Re: Report "Delegated-IPv6-Prefix" attribute for PPPoE

Delegated-IPv6-Prefix RADIUS attribute support for PPPoE server still not working in 6.49.6? [...] I'm not brave enough to try ROS v7 yet - or should I? Even ROSv7 is not supporting... :lol: ` Passing Delegated-IPv6-Prefix attribute in RADIUS Access-Accept reply works perfectly for me in 6.49.x. I ...
by NathanA
Thu Aug 11, 2022 11:05 pm
Forum: General
Topic: Changing ipv6 prefix
Replies: 96
Views: 25573

Re: Changing ipv6 prefix

EDIT : Note that the script code in this post was last updated on 23 February 2023 Sorry for the thread bump, but this seemed the best place to put this. Inspired by previous postings here, I have taken a swing at implementing RFC6204/RFC7084/RFC9096 via scripting. But this time, in such a way that...
by NathanA
Mon May 02, 2022 12:06 pm
Forum: Scripting
Topic: Searching multidimensional arrays
Replies: 2
Views: 1033

Searching multidimensional arrays

Because dynamic interfaces can come and go, I have a need to make a snapshot of what interfaces exist at a given point in time, and then search through the snapshot rather than do a real-time search. For example, instead of... /interface find name~"ether" ...I want to first capture & s...
by NathanA
Tue Jan 19, 2021 1:55 pm
Forum: General
Topic: Disable PPP IPCP client-side??
Replies: 1
Views: 908

Disable PPP IPCP client-side??

I'm trying to set up a single L2TP server on RouterOS that can negotiate IPCP, BCP, or both. This part works. What I can't figure out is how to get a RouterOS L2TP *client* to *only* request BCP on an L2TP connection. I can make it request IPCP-only (by not specifying "bridge port" in the ...
by NathanA
Sat Oct 19, 2019 12:12 pm
Forum: General
Topic: Multiple concurrent PPPoE over single ethernet [SOLVED]
Replies: 18
Views: 16254

Re: Multiple concurrent PPPoE over single ethernet [SOLVED]

As I said before, I would guess you can use clever rules under "/interface bridge filter" and "/interface bridge nat" to do what you want, but that would probably get very complicated to maintain. I have not sat down and tried to work out how exactly to do this (maybe create VLAN...
by NathanA
Fri Oct 18, 2019 7:47 pm
Forum: General
Topic: Is there an new exploit going around?
Replies: 57
Views: 25186

Re: Is there an new exploit going around?

To test some of the theories in this thread, I netinstalled 6.45.6 on a spare board, with default config and then exposed SSH to the internet after setting a strong admin password. So far while there are plenty of brute force attempts, there is no sign of an exploit that can bypass authentication. ...
by NathanA
Fri Oct 18, 2019 9:14 am
Forum: General
Topic: Multiple concurrent PPPoE over single ethernet [SOLVED]
Replies: 18
Views: 16254

Re: Multiple concurrent PPPoE over single ethernet [SOLVED]

I haven't tested this, but I suspect your problem is likely that all of your PPPoE connections are coming from the same MAC address. When that is the case, the server won't know how to address the individual clients (that all share same MAC, since it is transmitting to that one MAC for both of the c...
by NathanA
Thu Oct 17, 2019 8:52 pm
Forum: General
Topic: Is there an new exploit going around?
Replies: 57
Views: 25186

Re: Is there an new exploit going around?

No, but people write those exploit kits that a script kiddie can use to quicky distribute his desired attack code to many different types of router. Of course it will use a different method for different routers. ` Of course, but the implication of the post that R1CH was responding to is that there...
by NathanA
Thu Oct 17, 2019 7:53 pm
Forum: General
Topic: Is there an new exploit going around?
Replies: 57
Views: 25186

Re: Is there an new exploit going around?

so from what has been posted above it seams like some kind of ssh authentication bypass. it seams also that at least the user name must be known. ` Either SSH bypass somehow (though some sort of exploit in-band within SSH, or by first exploiting something outside of SSH, like through API etc.), or ...
by NathanA
Thu Oct 17, 2019 6:56 pm
Forum: General
Topic: Is there an new exploit going around?
Replies: 57
Views: 25186

Re: Is there an new exploit going around?

Was there anyone here using SSH keys to log in instead of passwords? For anyone exploited, did the bot add any keys for any users? ` Please read my earlier, detailed post. It itemizes exactly what got changed in the router, which *only* includes the addition of 2 new NAT rules at the very end of th...
by NathanA
Thu Oct 17, 2019 6:02 pm
Forum: General
Topic: Is there an new exploit going around?
Replies: 57
Views: 25186

Re: Is there an new exploit going around?

Normis et al., Just to make it clear: All of our clients' routers that got hit, they all got hit at virtually the exact same time, and all from the same source IP. They did admittedly all have an "admin" user, and they all obviously had SSH enabled, so that's admittedly a problem. However,...
by NathanA
Wed Oct 16, 2019 11:45 pm
Forum: General
Topic: Is there an new exploit going around?
Replies: 57
Views: 25186

Re: Is there an new exploit going around?

I know Tim & I have been discussing this elsewhere but good to see a thread started here. I'll share what I know so far, having had some of our own clients' routers experience the same attack last night. The attacker is managing to log in via SSH as user 'admin'. There were zero failed login att...
by NathanA
Fri Jul 05, 2019 11:15 am
Forum: General
Topic: Bridge is resetting CoS to 0 (was: Setting CoS from DSCP on PPPoE server)
Replies: 8
Views: 4714

Re: Bridge is resetting CoS to 0 (was: Setting CoS from DSCP on PPPoE server)

Logically setting priority from ingress would make more sense as a default action to me too...... ` I'd go a step farther. "Setting priority from ingress" shouldn't be a default action. How about NOT TOUCHING THE CONTENTS OF THE FRAME AT ALL UNLESS OTHERWISE REQUESTED is the "default...
by NathanA
Fri Jul 05, 2019 11:05 am
Forum: General
Topic: Changing MTU on PPPoE Client corrupts dial password
Replies: 2
Views: 1073

Re: Changing MTU on PPPoE Client corrupts dial password

I have never encountered this, and we have a lot of ROS deployed client-side.

If PPPoE client in question is authing with plaintext PAP, you should be able to see what password it is sending to the NAS (via verbose logs on the RADIUS server), and thus see exactly how it is being changed.

-- Nathan
by NathanA
Wed Jul 03, 2019 10:33 am
Forum: General
Topic: Bridge is resetting CoS to 0 (was: Setting CoS from DSCP on PPPoE server)
Replies: 8
Views: 4714

Bridge is resetting CoS to 0

...however, if I find that it's another MikroTik on the network that is responsible for stripping the CoS value as VLANs pass through, I'll be sure to hit you up again. :mrgreen: ` So. Turns out the device responsible for stripping the CoS was another MikroTik on the network. After poking at this o...
by NathanA
Wed Jun 26, 2019 12:29 pm
Forum: General
Topic: Bridge is resetting CoS to 0 (was: Setting CoS from DSCP on PPPoE server)
Replies: 8
Views: 4714

Re: Setting CoS from DSCP on PPPoE server

NEVER MIND. This actually works exactly the way you would expect it to: create the appropriate mangle rule on the router running the PPPoE server and voila. No need to involve bridges at all. The reason I was not seeing what I expected to see is because there is apparently a device somewhere in the ...
by NathanA
Tue Jun 25, 2019 4:03 am
Forum: General
Topic: Bridge is resetting CoS to 0 (was: Setting CoS from DSCP on PPPoE server)
Replies: 8
Views: 4714

Re: Setting CoS from DSCP on PPPoE server

I haven't tried this myself, but is your setup a bridge with a VLAN on it, or is it a bridge where there is a VLAN interface as the port of the bridge? There is sometimes a difference in behavior between the two - we do some QoS stuff with bridge filters that works only with the VLAN interface as a...
by NathanA
Tue Jun 25, 2019 12:28 am
Forum: General
Topic: Bridge is resetting CoS to 0 (was: Setting CoS from DSCP on PPPoE server)
Replies: 8
Views: 4714

Bridge is resetting CoS to 0 (was: Setting CoS from DSCP on PPPoE server)

(3 July 2019 update and TL;DR: the PPPoE server wasn't the problem; see my most recent post where I discuss MT bridges secretly resetting CoS on forwarded VLAN frames) 'lo all, Let's hypothesize that I am running a PPPoE server on a 802.1q (ethertype 0x8100) VLAN. So, IP packets to be forwarded over...
by NathanA
Wed Apr 10, 2019 7:52 am
Forum: MikroTik hardware questions
Topic: R11e-4G vs R11e-LTE
Replies: 5
Views: 3772

Re: R11e-4G vs R11e-LTE

[...] ` For what it's worth, the R11e-4G appears to be Altair ALT3800-based. I'm guessing that it's being paired with the ALT6300 transceiver in order to support all of those bands. Although it's too bad that this is CAT4 (in the year 2019), we have deployed other ALT3800 UEs in TDD mode and had pr...
by NathanA
Wed Apr 10, 2019 12:53 am
Forum: The Dude
Topic: Dude Installation instructions don't work
Replies: 6
Views: 6203

Re: Dude Installation instructions don't work

If you drag an NPK into the Files window of a router you are connected to with Winbox, it should show up as a file in the file list. Once you reboot the router, the NPK will be installed, at which point it will no longer show up in Files if you look there. But if you look in System > Packages after ...
by NathanA
Fri Apr 05, 2019 12:17 am
Forum: The Dude
Topic: Programmatically adjust devices?
Replies: 8
Views: 5287

Re: Programmatically adjust devices?

I’m working on a little tool that can bulk execute any command that you would be able to execute in the CLI. ` ...but isn't the exact problem being talked about here that The Dude has virtually no CLI access whatsoever? So what good would this do? For example, try "/dude device print detail&qu...
by NathanA
Fri Mar 01, 2019 5:08 am
Forum: The Dude
Topic: Pulling data direct from Dude database -- proof-of-concept
Replies: 4
Views: 14654

Pulling data direct from Dude database -- proof-of-concept

We have slowly begun to rely more and more on The Dude (which some might argue is maybe a mistake?), and one of the things that is still clearly lacking (in a "big E on the eyechart" sense) is programmatic access to the data. The CLI support for Dude access on RouterOS is basically useless...
by NathanA
Fri Mar 01, 2019 2:26 am
Forum: The Dude
Topic: The Dude IS Dead, really, isn't it?
Replies: 50
Views: 35392

Re: The Dude IS Dead, really, isn't it?

Last, and it's hard to say without sounding like I'm insinuating something bad, who knows how the code looks like, i.e. if someone else would be able to do anything useful with it. It doesn't have to be bad, even some unique style can be a problem. ` I think the biggest roadblock to making Dude ope...
by NathanA
Thu Jan 24, 2019 8:50 pm
Forum: MikroTik hardware questions
Topic: InterCell
Replies: 46
Views: 19084

Re: InterCell

Another request for the CBRS band here in the US. Right now it's Telrad, Cambium or Baicells. ` Technically Cambium's 3.6GHz LTE product is not shipping yet, and is still a ways out (especially the 8x8 MIMO version where the Medusa is used as a radio head...that's even farther out than B48 support ...
by NathanA
Thu Jan 24, 2019 8:37 pm
Forum: MikroTik hardware questions
Topic: InterCell
Replies: 46
Views: 19084

Re: InterCell

Unfortunately we can't make the Product that supports both B43 and B48 so you would need to choose which one you would need. ` This doesn't make sense to me. The two bands overlap and all of your competitors who have beaten you to market already manufacture such base stations that support both band...
by NathanA
Fri Oct 05, 2018 4:55 pm
Forum: General
Topic: IPsec Mode Config and iPhone6 [SOLVED]
Replies: 11
Views: 4044

Re: IPsec Mode Config and iPhone6 [SOLVED]

... only change is firmware updates for CCR009. and IOS updates for iPhone. ` So how do you know that the fault is with RouterOS 6.43.x and not with iOS 12? If you try a device with iOS 11 still on it, does it do the same thing? What happens if you try to use the VPN over Wi-Fi instead of over Roge...
by NathanA
Thu Oct 04, 2018 4:21 pm
Forum: MikroTik hardware questions
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 68258

Re: RB3011 port flopping - bad design

Hello, RB3011 Port Flapping problem is addressed by means of a new CPU Flow Control setting in RouterOS v6.43. If you have experienced this problem, it is recommended to upgrade to the v6.43 and apply following RouterOS command to prevent lockups between RB3011 switch chips and CPU. /interface ethe...
by NathanA
Thu Oct 04, 2018 1:10 pm
Forum: General
Topic: SIP client cannot re-register in the SIP server after switching ISP (different NAT) [SOLVED]
Replies: 58
Views: 33438

Re: SIP client cannot re-register in the SIP server after switching ISP (different NAT) [SOLVED]

It would be nice when NAT entries in general (and for SIP in particular) were more aware of interfaces going down/up, routing to change, etc. ` Your version of the issue sounds like the "dual WAN" scenario, and the previous explanations for the underlying cause of that variant of the prob...
by NathanA
Thu Oct 04, 2018 12:02 pm
Forum: General
Topic: SIP client cannot re-register in the SIP server after switching ISP (different NAT) [SOLVED]
Replies: 58
Views: 33438

Re: SIP client cannot re-register in the SIP server after switching ISP (different NAT) [SOLVED]

Though i have to say, the issue doesn't always come up, what seems to happen (for us) is if there is only a brief disconnection of PPoE (like really quickly, [...]). I think your disconnections are long enough, thats why the issue doesn't happen, [...] ` No, ours tend to happen after brief disconne...
by NathanA
Thu Oct 04, 2018 11:09 am
Forum: General
Topic: SIP client cannot re-register in the SIP server after switching ISP (different NAT) [SOLVED]
Replies: 58
Views: 33438

Re: SIP client cannot re-register in the SIP server after switching ISP (different NAT) [SOLVED]

Chupaka wrote: In Terminal - yep, but when you paste the script via WinBox - nope :) ` Maybe I am misunderstanding you, but what you say does not appear to be true: if I take this script WITHOUT escaping the $, add it to System > Scripts in Winbox, and then highlight it and click the "Run Scrip...
by NathanA
Wed Oct 03, 2018 12:01 pm
Forum: General
Topic: SIP client cannot re-register in the SIP server after switching ISP (different NAT) [SOLVED]
Replies: 58
Views: 33438

Re: SIP client cannot re-register in the SIP server after switching ISP (different NAT) [SOLVED]

I would use 'dst-address~":5060$"' form: it doesn't touch ports 50600-50609 and it should be a bit faster :)
`
Good point. Though it apparently needs to be ":5060\$" because MikroTik CLI will try to parse $ (even when in quotes!) if it isn't escaped. :)

-- Nathan
by NathanA
Wed Oct 03, 2018 7:19 am
Forum: General
Topic: Mikrotik Router SIP Connection Blocked.
Replies: 79
Views: 66203

Re: Mikrotik Router SIP Connection Blocked.

Since I see people have still been posting in this thead, and some of the more recent responses have mentioned that they are using PPPoE, I thought I'd stop by to let people here know that as of RouterOS 6.33, if you are using PPPoE on your WAN and suffering from this problem, you can use the "...
by NathanA
Wed Oct 03, 2018 7:09 am
Forum: General
Topic: SIP client cannot re-register in the SIP server after switching ISP (different NAT) [SOLVED]
Replies: 58
Views: 33438

Re: SIP client cannot re-register in the SIP server after switching ISP (different NAT) [SOLVED]

I just realized/discovered today that IF you are using a PPPoE client on WAN (as I mentioned I was in my earlier post), then detecting the change (down/up event) and automatically acting on it is super-easy, and you don't have to fire off a scheduled script every 60 seconds to do it, either. In 6.33...
by NathanA
Wed Sep 26, 2018 2:33 am
Forum: MikroTik hardware questions
Topic: NetInstall Instructions
Replies: 17
Views: 26889

Re: NetInstall Instructions

NetInstall could find my router. I selected the proper ROS version. Clicking INSTALL did nothing. No formatting - no progress bar, just nothing. Trying the process again from scratch sometimes produced slightly different results - the 'ready' notation in the Hardware window would disappear for 5 se...
by NathanA
Tue Sep 25, 2018 3:10 pm
Forum: MikroTik hardware questions
Topic: NetInstall Instructions
Replies: 17
Views: 26889

Re: NetInstall Instructions

It boggles the mind how many people do not understand the principles on which Netinstall works. Perhaps the Wiki documentation is not well-written, and I am just blind to it because I understand it and have been using it for so long... "Net Booting – Change IP address back to client address: 19...
by NathanA
Thu Sep 20, 2018 1:30 am
Forum: MikroTik hardware questions
Topic: RB1100 dead
Replies: 12
Views: 7707

Re: RB1100 dead

Based on this topic it seems the bootloader is damaged. You may find more advice here: https://forum.mikrotik.com/viewtopic.php?t=133750 ` That's an interesting thread; thanks for unearthing it. Regardless, there should always be a backup bootloader even if the main one is damaged. That is what is ...
by NathanA
Wed Sep 19, 2018 2:24 pm
Forum: MikroTik hardware questions
Topic: RB1100 dead
Replies: 12
Views: 7707

Re: RB1100 dead

I don't think it is a hardware problem. It is a pure software problem. ` You may be right. But you also passed by all advice and requests for further information. The answers to the questions I asked would have taken 5 minutes at most for you to collect and then post here, but you decided instead t...
by NathanA
Wed Sep 19, 2018 6:16 am
Forum: MikroTik hardware questions
Topic: RB1100 dead
Replies: 12
Views: 7707

Re: RB1100 dead

Annapurna Labs stage 2: stage2_eth3_ram_loader v1.65.1 main.c:000001E9 ` Is that the only thing you see on serial console? Did you have it plugged in before powering it up, and when you powered it up it only printed those 2 lines on the console and nothing else? You said in your original post that ...
by NathanA
Mon Sep 17, 2018 2:15 pm
Forum: MikroTik hardware questions
Topic: How to set RB750Gr3 DHCP to not push Gateway address [SOLVED]
Replies: 5
Views: 2469

Re: How to set RB750Gr3 DHCP to not push Gateway address [SOLVED]

It's pretty simple: just don't fill in the spaces for gateway or DNS...
mt-dhcp.png
-- Nathan
by NathanA
Mon Sep 17, 2018 2:08 pm
Forum: MikroTik hardware questions
Topic: boot problems
Replies: 6
Views: 2866

Re: boot problems

Start the router with the reset button.

Once it is running, use "/system routerboard upgrade"

Then try reboot again.

-- Nathan
by NathanA
Fri Sep 14, 2018 12:59 pm
Forum: MikroTik hardware questions
Topic: Help me revive my RB2011UiAS-2HnD-IN [SOLVED]
Replies: 8
Views: 5251

Re: Help me revive my RB2011UiAS-2HnD-IN [SOLVED]

More so, both SW-ID & license key were visible in Netinstall too. ` ...earlier... ` [...]Netinstall still has connection to the router, but now the license key field is blank . ` I'm genuinely super happy for you, but also super confused. In your first post, you said that when you ran Netinstal...
by NathanA
Fri Sep 14, 2018 2:36 am
Forum: MikroTik hardware questions
Topic: RB450Gx4 "kernel not found or data is corrupted", re-install OS didn't help
Replies: 12
Views: 6726

Re: RB450Gx4 "kernel not found or data is corrupted", re-install OS didn't help

To be clear, the only thing that you did was to update the bootloader firmware, right? You didn't have to re-Netinstall after the firmware update? It just instantly "found" the copy of RouterOS that was already on there from previous Netinstall attempts and it started right up? The backup ...
by NathanA
Thu Sep 13, 2018 9:48 am
Forum: MikroTik hardware questions
Topic: Help me revive my RB2011UiAS-2HnD-IN [SOLVED]
Replies: 8
Views: 5251

Re: Help me revive my RB2011UiAS-2HnD-IN [SOLVED]

I have the dime problem. I reset and after brick https://youtu.be/vBAgbNVZngs ` Sorry, but that doesn't look or sound like the same problem to me. Yours is not finishing booting, though the bootloader is definitely working (as evidenced by the fact that it beeps a single time, which means it found ...
by NathanA
Wed Sep 12, 2018 5:58 pm
Forum: MikroTik hardware questions
Topic: bricked RB435G netinstall stop at Formatting Harddrive
Replies: 20
Views: 8243

Re: bricked RB435G netinstall stop at Formatting Harddrive

Wow, that is crazy! If the NAND wasn't defective, the only theory I can come up with is that there is something else physically wrong with the board. Maybe one of the PCB traces between the CPU/SoC and the flash chip is faulty or broken? If your friend is as good with electronics repair as he sounds...
by NathanA
Wed Sep 12, 2018 5:54 pm
Forum: MikroTik hardware questions
Topic: RB450Gx4 "kernel not found or data is corrupted", re-install OS didn't help
Replies: 12
Views: 6726

Re: RB450Gx4 "kernel not found or data is corrupted", re-install OS didn't help

Cool beans, though updating the firmware really shouldn't have been "necessary" per-se. If that fixed it, that tells me that either there was a bug in the older bootloader that you somehow managed to trip and which was fixed in the updated loader, or there was actually some change in how s...
by NathanA
Tue Sep 11, 2018 1:59 am
Forum: MikroTik hardware questions
Topic: Help me revive my RB2011UiAS-2HnD-IN [SOLVED]
Replies: 8
Views: 5251

Re: Help me revive my RB2011UiAS-2HnD-IN [SOLVED]

I believe I'm engaging 2 different bootloaders because that's how I interpret the documentation. To engage main bootloader - apply power AND THEN press RESET, wait for bootloader to kick in. To engage the backup one - press RESET BEFORE applying power. Or so I thought. ` Actually, now that I stop t...
by NathanA
Mon Sep 10, 2018 3:51 pm
Forum: MikroTik hardware questions
Topic: Help me revive my RB2011UiAS-2HnD-IN [SOLVED]
Replies: 8
Views: 5251

Re: Help me revive my RB2011UiAS-2HnD-IN [SOLVED]

That you seem to know which bootloader is being used would seem to imply that you have a serial cable hooked up to the RJ45 RS232 console port. (If you were engaging Netinstall with the reset button every time instead of via RouterBOOT console menu, then I think you would always be using the backup ...
by NathanA
Mon Sep 10, 2018 3:34 pm
Forum: MikroTik hardware questions
Topic: bricked RB435G netinstall stop at Formatting Harddrive
Replies: 20
Views: 8243

Re: bricked RB435G netinstall stop at Formatting Harddrive

Did you mean the license will be lost if I replace the NAND chip. ` I am sorry if I did not explain this clearly before. If my understanding of where the license is stored is correct, then in theory, you will NOT lose the license by replacing the NAND chip. NAND chip only stores your copy of Router...
by NathanA
Mon Sep 10, 2018 9:57 am
Forum: MikroTik hardware questions
Topic: bricked RB435G netinstall stop at Formatting Harddrive
Replies: 20
Views: 8243

Re: bricked RB435G netinstall stop at Formatting Harddrive

Do you have a micro SD card in the board? 2048MB seems suspiciously like a card may be present. ` NAND specifically refers to on-board NAND. If the microSD slot is populated, RouterBOOT will not mention it. The number that is shown for NAND size by the bootloader should never change from what it sh...
by NathanA
Sat Sep 08, 2018 9:01 am
Forum: MikroTik hardware questions
Topic: RB4011
Replies: 387
Views: 209358

Re: RB4011

And putting 4011 label on it doesn't make it any more x011 series than any other random 10 port router ` Oh come now. You can't be serious. The 3011 and 4011 have more in common with each other than an IBM-era ThinkPad and a modern Lenovo-era ThinkPad...sheesh. :roll: I think the most strange omiss...
by NathanA
Sat Sep 08, 2018 1:41 am
Forum: MikroTik hardware questions
Topic: RB450Gx4 "kernel not found or data is corrupted", re-install OS didn't help
Replies: 12
Views: 6726

Re: RB450Gx4 "kernel not found or data is corrupted", re-install OS didn't help

Nathan ... Question for ya .... If you have created a primary and fallback partition, would this suspect RouterBOOT issue affect the booting of both partitions, being a low level operation? Or would just one be impacted and the other will boot normally? ` Good question, since I am mainly basing my ...
by NathanA
Fri Sep 07, 2018 4:00 pm
Forum: MikroTik hardware questions
Topic: bricked RB435G netinstall stop at Formatting Harddrive
Replies: 20
Views: 8243

Re: bricked RB435G netinstall stop at Formatting Harddrive

I was wondering, if I swap a new NAND chip in place of the defective one, after I do that, can I use Netinstall to install the RouterOS? If not, what should I do after I swap that NAND chip. Is that the booter will gone after I replace the NAND chip? if it's gone, is it possible for me to make it i...
by NathanA
Fri Sep 07, 2018 3:42 pm
Forum: MikroTik hardware questions
Topic: RB450Gx4 "kernel not found or data is corrupted", re-install OS didn't help
Replies: 12
Views: 6726

Re: RB450Gx4 "kernel not found or data is corrupted", re-install OS didn't help

It's possible that your flash did indeed fail and is physically defective. But it's also possible that this is a RouterBOOT bug...it's not exactly the same, but it is similar enough to what some CRS317 owners reported here to make me suspicious: thread link CRS3xx and RB450Gx4 are both ARM-based, so...
by NathanA
Fri Sep 07, 2018 3:30 pm
Forum: General
Topic: RB450Gx4 WAN throughput decreases
Replies: 7
Views: 3112

Re: RB450Gx4 WAN throughput decreases

...and also changed IP > Address > Interface to bridge from ether2. ` Guaranteed this wasn't the issue. Although it can "work" (depending), assigning an IP address to an interface that is a member of a bridge makes no sense. Once an interface is a bridge member, it should not be individua...