Community discussions

Search found 191 matches

by dynek
Mon Sep 09, 2019 5:24 pm
Forum: General
Topic: RouterOS v7.0beta1 (ARM)
Replies: 167
Views: 28464

Re: RouterOS v7.0beta1 (ARM)

BTW Wireguard works with 4.14.142 ;-)
by dynek
Fri Sep 06, 2019 7:24 pm
Forum: General
Topic: RouterOS v7.0beta1 (ARM)
Replies: 167
Views: 28464

Re: RouterOS v7.0beta1 (ARM)

No more multiple packages? What if I installed a limit number of them on my HAP AC^2, what happens with this v7 beta1?
by dynek
Mon Sep 02, 2019 5:37 pm
Forum: General
Topic: how to backup router configuration including SSL certificates
Replies: 4
Views: 1610

Re: how to backup router configuration including SSL certificates

Undigging an old thread.

I restored a configuration on one of my HAP AC^2 device and the locally generated cert and its CA, that were both valid until 2028, are now expired since 2011.

Why is that?
by dynek
Tue Aug 06, 2019 9:35 am
Forum: Wireless Networking
Topic: capsman local bridge as datapath
Replies: 12
Views: 3520

Re: capsman local bridge as datapath

Could you please post your script?
Hey,
Not sure I still have it cause either it wasn't required in the first place or RoS evolved enough to tag them correctly (and add them to the bridge mentioned in the caps conf).
Hope this helps otherwise we can go further into the details.
by dynek
Thu May 02, 2019 10:31 am
Forum: Wireless Networking
Topic: hap ac^2 - Group Key Exchange timeout / No Reconnect possible
Replies: 51
Views: 9184

Re: hap ac^2 - Group Key Exchange timeout / No Reconnect possible

That's a pretty weird issue (this one or something related to WiFi) cause everything is working fine but all of a sudden things start disconnecting one after the other. Not sure how to find the root cause / contributing factor but my setup seems to be failing when Sonos speaker need to sync audio. T...
by dynek
Thu Mar 28, 2019 2:18 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 39464

Re: UKNOF 43 CVE

…and sadly @mikrotik_com continue to stonewall me saying this remote unauthenticated denial of service is a “bug” not a “security vulnerability” — which is probably why they haven’t prioritised it for the last 50 weeks.
https://twitter.com/maznu
by dynek
Wed Mar 27, 2019 4:08 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 39464

UKNOF 43 CVE

Hey, Just discovered: https://indico.uknof.org.uk/event/46/contributions/667/ During some research which found CVE-2018-19298 (MikroTik IPv6 Neighbor Discovery Protocol exhaustion), I uncovered a larger problem with MikroTik RouterOS’s handling of IPv6 packets. This led to CVE-2018-19299, an unpubli...
by dynek
Wed Mar 27, 2019 9:55 am
Forum: General
Topic: Feature Request: OpenVPN [ovpn] udp tunnels
Replies: 250
Views: 89238

Re: Feature Request: OpenVPN [ovpn] udp tunnels

WG is making it soon into the kernel:
https://www.phoronix.com/scan.php?page= ... ot-In-4.20

Mtik first have to update the kernel though or run a version that supports WG module.
Just forget about OpenVPN and go straight to WG guys!
by dynek
Sat Mar 23, 2019 8:05 am
Forum: Wireless Networking
Topic: hap ac^2 - Group Key Exchange timeout / No Reconnect possible
Replies: 51
Views: 9184

Re: hap ac^2 - Group Key Exchange timeout / No Reconnect possible

This is a recurring issue I am having at least with Sonos speakers: 2019-03-23T06:48:46+01:00 router 5C - - - 5C:AA:FD:06:00:11@2.4Ghz-ap_1stfloor-1 disconnected, group key timeout 2019-03-23T06:48:46+01:00 router 5C - - - 5C:AA:FD:06:00:22@2.4Ghz-ap_1stfloor-1 disconnected, group key timeout 2019-0...
by dynek
Fri Mar 22, 2019 9:55 am
Forum: Announcements
Topic: Statement on Vault 7 document release
Replies: 92
Views: 45041

Re: Statement on Vault 7 document release

How is that different from /exporting the configuration and git it ?
Then compare different commits?

Cause the video on their homepage just looks like it.
by dynek
Wed Mar 06, 2019 11:11 pm
Forum: Beginner Basics
Topic: RB1100AHx2 link switches
Replies: 0
Views: 187

RB1100AHx2 link switches

Hey, I still have a pre 6.41 VLAN config on my RB1100AHx2 and was reading this page to move it into the new way of bridging ports and setup VLANS in there: https://wiki.mikrotik.com/wiki/Manual:Basic_VLAN_switching and a note states "For devices that have multiple switch chips (for example, RB2011, ...
by dynek
Wed Feb 27, 2019 9:51 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 609
Views: 152045

Re: RouterOS v7.0 beta1 - when?

Forget about OpenVPN, go straight to Wireguard :-)
by dynek
Mon Jan 14, 2019 3:46 pm
Forum: General
Topic: Feature Request: OpenVPN [ovpn] udp tunnels
Replies: 250
Views: 89238

Re: Feature Request: OpenVPN [ovpn] udp tunnels

https://youtu.be/qmKkbuS9gRs TCP or UDP is being mentioned in the second part of the video edit: oh and: https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/cvpn-working-endpoints.html (Optional) By default, the Client VPN server uses the UDP transport protocol. To use the TCP transport protocol ...
by dynek
Sat Oct 13, 2018 8:22 am
Forum: General
Topic: Feature Request: OpenVPN [ovpn] udp tunnels
Replies: 250
Views: 89238

Re: Feature Request: OpenVPN [ovpn] udp tunnels

Aaahhh Wireguard 😍
by dynek
Fri Oct 12, 2018 9:49 am
Forum: General
Topic: Feature Request: OpenVPN [ovpn] udp tunnels
Replies: 250
Views: 89238

Re: Feature Request: OpenVPN [ovpn] udp tunnels

Another solution would be to support and maintain Metarouter.... even on the RB1100AHx2, but that's another story.
by dynek
Sun Jun 17, 2018 3:10 pm
Forum: General
Topic: backup,critical error creating backup file, ROS 6.42.1
Replies: 29
Views: 5869

Re: backup,critical error creating backup file, ROS 6.42.1

In the end, Mikrotik support suggested us to export config using "/export". Note that this is the better advice because export is human readable and compatible between services (minor changes required) and backup is sometimes not, even between same models. Well, it's not compatible between devices ...
by dynek
Sun Jun 17, 2018 9:31 am
Forum: General
Topic: Problem while creating backup
Replies: 25
Views: 6814

Re: Problem while creating backup

Fixed it for my RB1100AHx2 as well. A shame for Mikrotik who suggested to NetInstall the device.

Thank you!
by dynek
Sun Jun 17, 2018 9:30 am
Forum: General
Topic: backup,critical error creating backup file, ROS 6.42.1
Replies: 29
Views: 5869

Re: backup,critical error creating backup file, ROS 6.42.1

Fixed it for my RB1100AHx2 as well. A shame for Mikrotik who suggested to NetInstall the device.

Thank you!
by dynek
Thu Jun 14, 2018 11:28 pm
Forum: General
Topic: Feature Request: OpenVPN [ovpn] udp tunnels
Replies: 250
Views: 89238

Re: Feature Request: OpenVPN [ovpn] udp tunnels

Huh huh what about Metarouter on RB1100AHx2 :-)
by dynek
Thu Jun 14, 2018 7:34 am
Forum: General
Topic: Feature Request: OpenVPN [ovpn] udp tunnels
Replies: 250
Views: 89238

Re: Feature Request: OpenVPN [ovpn] udp tunnels

I very disappointed to read this topic after i brought MikroTik hAP ac². :( :(
Did you really buy an access point to establish OpenVPN connection(s) ?!
by dynek
Tue May 08, 2018 9:15 am
Forum: Announcements
Topic: v6.42.1 [current]
Replies: 272
Views: 44699

Re: v6.42.1 [current]

No one else has this problem?
DHCP does not log to external server any more: viewtopic.php?f=2&t=134092&sid=345291ea ... d0515cef3e
Should I post a support ticket?
Answered your thread - It did work for me.
by dynek
Tue May 08, 2018 9:13 am
Forum: General
Topic: [6.42.1] DHCP does not send log to remote syslog
Replies: 6
Views: 834

Re: [6.42.1] DHCP does not send log to remote syslog

I just tested it on 6.42.1 (remote for dhcp) and I do see logs coming in (syslog)
by dynek
Mon May 07, 2018 9:15 am
Forum: Announcements
Topic: v6.42.1 [current]
Replies: 272
Views: 44699

Re: v6.42.1 [current]

Regarding message poping up when generating a backup file, same problem, same answer (netinstall) but I don't feel like it honestly...
viewtopic.php?f=2&t=73610&p=658544#p658544
by dynek
Mon Apr 30, 2018 8:34 pm
Forum: General
Topic: Problem while creating backup
Replies: 25
Views: 6814

Re: Problem while creating backup

They asked if /export seemed to be complete (it does), then supout.rif and they could not reproduce the issue with it.
So now I am supposed to move the device out of its rack to netinstall it, I feel like it would be done before a couple of weeks, not so easy! :-/
by dynek
Thu Apr 19, 2018 2:59 pm
Forum: General
Topic: Problem while creating backup
Replies: 25
Views: 6814

Re: Problem while creating backup

Undigging an old thread, sorry for that. On a RB1100AHx2 that never had any problem I started seeing "error creating backup file: could not read all configuration file" while creating a backup. No clue if it's related or not but I recently updated to 6.42 and I never saw this message before. Also me...
by dynek
Wed Apr 18, 2018 9:33 pm
Forum: Wireless Networking
Topic: Requests wrong RSN group cipher
Replies: 10
Views: 1219

Requests wrong RSN group cipher

Hello, I have setup capsman with hap ac^2 devices and a couple of devices connect fine to the wireless network(s). However my macbook seems to be triggering one odd thing... "2.4Ghz-AP_Basement-1-1 rejected, requests wrong RSN group cipher". Google doesn't say much about that - what can I do ? Thank...
by dynek
Wed Apr 18, 2018 11:42 am
Forum: Wireless Networking
Topic: capsman local bridge as datapath
Replies: 12
Views: 3520

Re: capsman local bridge as datapath

Thank you for your answers sindy, much appreciated.

I ended up creating a scheduled job setting "tagged" interfaces on a regular basis - fixed!

Thank you.
by dynek
Wed Apr 18, 2018 8:29 am
Forum: Wireless Networking
Topic: capsman local bridge as datapath
Replies: 12
Views: 3520

Re: capsman local bridge as datapath

I already tried splitting the entry in three different ones for each vlan.
BTW, would you / anyone know the difference between adding them to a single entry vs multiple ones? Is there any?
by dynek
Tue Apr 17, 2018 7:31 pm
Forum: Wireless Networking
Topic: capsman local bridge as datapath
Replies: 12
Views: 3520

Re: capsman local bridge as datapath

OK got it. But it only works if I manually add wlan interfaces into /interface bridge vlan:

add bridge=br0 tagged=br0,ether1-upstream,wlan1,wlan2,wlan3,wlan4,wlan5,wlan6 vlan-ids=100,200,300

wlan[N] have been added manually. Should I expect these interfaces to get into "tagged"?
by dynek
Tue Apr 17, 2018 3:34 pm
Forum: Wireless Networking
Topic: capsman local bridge as datapath
Replies: 12
Views: 3520

Re: capsman local bridge as datapath

Hello,

I have been looking for this solution for quite some time, finally here is the answer, thanks.
However :-) I am unable to add PVID to wlan interface added inside the bridge CAP side.
They always end up untagged with PVID 1.

Any idea?

Cheers
by dynek
Mon Apr 16, 2018 3:51 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 609
Views: 152045

Re: RouterOS v7.0 beta1 - when?

Well if they say they backported most (all ?) v7 functionalities into v6, I don't really see a problem here.
by dynek
Mon Apr 16, 2018 12:20 pm
Forum: General
Topic: [SOLVED] CAPsMan, Local forwarding and VLANs
Replies: 0
Views: 641

[SOLVED] CAPsMan, Local forwarding and VLANs

Hey all, I was wondering if anyone has been implementing local forwarding capsman with VLANs? Got a bridge managing VLANs for physical ports of an HAP ac² and wanted provisioned virtual APs to sit in the same bridge as well as being able to set different APs as "access ports". Doesn't look like CAPs...
by dynek
Tue Mar 27, 2018 11:49 am
Forum: General
Topic: HAP AC Lite bricked (3rd one?)
Replies: 11
Views: 1857

Re: HAP AC Lite bricked (3rd one?)

Oddly enough I just encountered a similar situation, HAP ac^2 running all-in-one 6.41.3 (upgraded through /system packages and rebooted). Later I wanted to get rid of some packages so I scp'ed advanced-tools, dhcp, ipv6, multicast, ntp, routing, security, system & wireless ver. 6.41.3 (ARM) to move ...
by dynek
Wed Dec 20, 2017 9:02 pm
Forum: General
Topic: Routing broadcast between VLANs
Replies: 5
Views: 1594

Re: Routing broadcast between VLANs

Hello,

Nope I did not want to waste too much time.
I installed a raspberry with both vlans trunked and used avahi reflector.

Cheers
by dynek
Fri Sep 08, 2017 2:11 pm
Forum: General
Topic: Feature Request: OpenVPN [ovpn] udp tunnels
Replies: 250
Views: 89238

Re: Feature Request: OpenVPN [ovpn] udp tunnels

Cool thing - Thanks for the info.
by dynek
Sun May 14, 2017 7:46 pm
Forum: General
Topic: CIA exploits against Mikrotik hardware
Replies: 97
Views: 43652

Re: CIA exploits against Mikrotik hardware

Even though a regular firewall (the default config, in fact) will protect you against the CIA malware, this is an excellent guide to follow for any public RouterOS device: https://www.manitonetworks.com/mikrotik/2016/5/24/mikrotik-router-hardening I see you posted a link to one of my articles - if ...
by dynek
Mon May 08, 2017 2:45 pm
Forum: General
Topic: New OID for CPU
Replies: 7
Views: 4444

Re: New OID for CPU

Hello tomaskir and thank you for your answer,

On a RB1100AHx2 .1.3.6.1.2.1.25.3.3.1.2 exposes both CPUs (.1.3.6.1.2.1.25.3.3.1.2.1 and .1.3.6.1.2.1.25.3.3.1.2.2)
However .1.3.6.1.4.1.2021.11.10 only exposes a single value. Would that be the average of both CPUs?

Thank you
by dynek
Sat Apr 01, 2017 2:30 pm
Forum: General
Topic: New OID for CPU
Replies: 7
Views: 4444

Re: New OID for CPU

I don't quite understand what the Mikrotik is exposing via SNMP. There are the regular IF info: http://www.oidview.com/mibs/0/IF-MIB.html Duplicated at a different place? http://www.oidview.com/mibs/14988/MIKROTIK-MIB.html The odd thing is I can find correct values for a bridge & ovpn in IF-MIB but ...
by dynek
Fri Mar 31, 2017 10:44 am
Forum: General
Topic: New OID for CPU
Replies: 7
Views: 4444

Re: New OID for CPU

Hello, Pretty much the same question so I'm exhuming this thread :-) As far as I was able to see on my RB1100AHx2, I can query CPU usage using: - .1.3.6.1.2.1.25.3.3.1.2.1 (cpu1) - .1.3.6.1.2.1.25.3.3.1.2.2 (cpu2) - .1.3.6.1.4.1.2021.11.10.0 (1min average?) However none of this value reports what I ...
by dynek
Thu Mar 30, 2017 9:43 am
Forum: Beginner Basics
Topic: ICMP log always saying it's NATed
Replies: 3
Views: 859

Re: ICMP log always saying it's NATed

Thanks for confirming Sob! Much appreciated.

I just sent their support a mail with a reference to this thread.
by dynek
Thu Mar 30, 2017 12:20 am
Forum: Beginner Basics
Topic: ICMP log always saying it's NATed
Replies: 3
Views: 859

ICMP log always saying it's NATed

Hello all, Today I took some time to review my firewall filtering when I came across something weird. Every time I ping across vlans (going through router), client -> router, router -> client and even router -> router I always see NAT implied: forward: in:bridge-vlan100-management out:bridge-vlan200...
by dynek
Sat Mar 25, 2017 8:58 am
Forum: General
Topic: Feature Request: OpenVPN [ovpn] udp tunnels
Replies: 250
Views: 89238

Re: Feature Request: OpenVPN [ovpn] udp tunnels

Probably because of RouterOS 7.x :-)
by dynek
Wed Mar 15, 2017 2:16 pm
Forum: General
Topic: CIA exploits against Mikrotik hardware
Replies: 97
Views: 43652

Re: CIA exploits against Mikrotik hardware

have you watched the video ? Cracker have logged into ROS via WWW with known password and then issued prepared http string .... Erm, yes. This is what is called a CSRF. What must be assumed here is that the call to change the password is issued by the very same user (the one that logs into the admi...
by dynek
Wed Mar 15, 2017 11:51 am
Forum: General
Topic: CIA exploits against Mikrotik hardware
Replies: 97
Views: 43652

Re: CIA exploits against Mikrotik hardware

2) I would like to see a bug bounty program from MikroTik and crowd source expertise and reward responsible security issue disclosure to MikroTik, How much are you willing to pay for that? Did you notice Mikrotik is really cheap compared to competitors? You can't ask a company to be low-priced and ...
by dynek
Wed Mar 15, 2017 9:56 am
Forum: General
Topic: CIA exploits against Mikrotik hardware
Replies: 97
Views: 43652

Re: CIA exploits against Mikrotik hardware

2) I would like to see a bug bounty program from MikroTik and crowd source expertise and reward responsible security issue disclosure to MikroTik, How much are you willing to pay for that? Did you notice Mikrotik is really cheap compared to competitors? You can't ask a company to be low-priced and ...
by dynek
Fri Feb 10, 2017 4:33 pm
Forum: General
Topic: Weird 129.0.0.x IPs ?
Replies: 30
Views: 4534

Re: Weird 129.0.0.x IPs ?

Good to hear! Having the same issue on my RB1100AHx2.
by dynek
Mon Jan 30, 2017 11:36 am
Forum: Forwarding Protocols
Topic: Where is this 169.254 IP coming from?
Replies: 4
Views: 1962

Re: Where is this 169.254 IP coming from?

Hello cdiedrich,

Thank you for your message.

Before reading your answer, I tried using packet sniffer to find out the guilty machine but it did not shed a light.
Adding a filter rule as you mentioned it doesn't help either - counter don't increment.

Cheers
by dynek
Fri Jan 27, 2017 5:21 pm
Forum: General
Topic: Bridge IPv6 while routing IPv4
Replies: 16
Views: 6477

Re: Bridge IPv6 while routing IPv4

No more news ? I'm in the same situation and expected to be able to create an IPv6-only bridge.
by dynek
Fri Jan 27, 2017 1:49 pm
Forum: Forwarding Protocols
Topic: Where is this 169.254 IP coming from?
Replies: 4
Views: 1962

Re: Where is this 169.254 IP coming from?

Hello,

I know what these kind of addresses are. I am just wondering what device/interface is using it.
Cause Mikrotik can't ping it.

I don't have a single machine running Windows in my LAN.

Thank you
by dynek
Fri Jan 27, 2017 1:22 pm
Forum: Forwarding Protocols
Topic: Where is this 169.254 IP coming from?
Replies: 4
Views: 1962

Where is this 169.254 IP coming from?

Hello,

I have enabled PIM between two vlans that both have their IP address.
Now log show:

RX IGMP_V2_MEMBERSHIP_REPORT from 169.254.134.72 to 239.255.255.250 on vif vlan100-management: source must be directly connected

Where could this link-local address be coming from?

Thanks
by dynek
Fri Jan 27, 2017 10:21 am
Forum: General
Topic: Feature request: Proxy-ndp alongside proxy-arp
Replies: 3
Views: 2230

Re: Feature request: Proxy-ndp alongside proxy-arp

Hello,

2.5 years later - Has this been taken into account? Is it under evaluation?

Thank you
by dynek
Mon Dec 05, 2016 8:59 pm
Forum: Virtualization
Topic: Metarouter on RB1100AHx2
Replies: 22
Views: 9479

Re: Metarouter on RB1100AHx2

Hello Mikrotik :-)

Still no progress on this?

Thanks!
by dynek
Wed Nov 23, 2016 11:36 pm
Forum: General
Topic: Feature Request: OpenVPN [ovpn] udp tunnels
Replies: 250
Views: 89238

Re: Feature Request: OpenVPN [ovpn] udp tunnels

+100999500100999500100999500100999500100999500 for ovpn udp lzo

pleaz pleaz pleaz pleaz pleaz pleaz pleaz pleaz pleaz pleaz pleaz pleaz pleaz pleaz

ok just kidding. As stated before nobody cares about +1, please, whatsoever.
by dynek
Tue Jul 12, 2016 7:09 pm
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 92849

Re: Feature request: OpenVPN compression LZO and UDP

I honestly do wonder what's so complicated about it... I mean implementation wise.
by dynek
Sat Jul 09, 2016 5:59 pm
Forum: Virtualization
Topic: Metarouter images
Replies: 365
Views: 241494

Re: Metarouter images

I guess you will have to bridge your virtual interfaces with each vlan into which it should belong so avahi can broadcast frames on both vlans.
by dynek
Fri Jul 08, 2016 1:09 pm
Forum: Virtualization
Topic: Metarouter images
Replies: 365
Views: 241494

Re: Metarouter images

One of the funniest answer I have ever read: your time is worth less than mine so please do the searching for me.
by dynek
Wed Apr 20, 2016 4:58 pm
Forum: General
Topic: v6.35 [current] is released!
Replies: 103
Views: 24422

Re: v6.35 [current] is released!

Hello,

I installed v6.35 onto a RB1100AHx2 - Working like a charm.

Thank you
by dynek
Sat Apr 16, 2016 7:22 pm
Forum: General
Topic: Why /file get FILE contents on routeros 6 returns nothing?
Replies: 4
Views: 1742

Re: Why /file get FILE contents on routeros 6 returns nothing?

I wanted to have something standalone on the Mikrotik but I'll use a side device to fetch the file and upload chunks of them and then run a script :shock:
by dynek
Fri Apr 15, 2016 3:11 pm
Forum: Scripting
Topic: Cant read file large then 4085 bytes
Replies: 9
Views: 3913

Re: Cant read file large then 4085 bytes

6 years later, 4kb is still the max size of files that can be read from a Mikrotik's script?
This sounds like April's Fool and makes me go back to what computers used to be 30 years ago.
by dynek
Fri Apr 15, 2016 2:54 pm
Forum: General
Topic: Why /file get FILE contents on routeros 6 returns nothing?
Replies: 4
Views: 1742

Re: Why /file get FILE contents on routeros 6 returns nothing?

Hello, Running 6.34.4 - I am not able to read content of a file with: :put [/file get [/file find where name=ch-aggregated.zone] contents ] The file is coming from http://www.ipdeny.com/ipblocks/data/aggregated/ch-aggregated.zone and has been fetched with /tool fetch Any help will, of course, be app...
by dynek
Tue Mar 22, 2016 4:24 pm
Forum: General
Topic: Is firewall that hungry?
Replies: 11
Views: 865

Re: Is firewall that hungry?

Excellent! Thank you for the information and your time. Should I be able to enable fasttrack for a specific source / destination address ? Or will it be enabled for all the traffic that is forwarded through the router? I'm asking cause I still don't get why I had so many Gb accounted on the dummy ru...
by dynek
Tue Mar 22, 2016 10:20 am
Forum: General
Topic: Is firewall that hungry?
Replies: 11
Views: 865

Re: Is firewall that hungry?

That's because the fasttrack rule only matches the first packet that causes the connection to be fasttracked. After that, fasttrack "warps" the remaining packets through the router without looking at the firewall anymore. The dummy rule counts these packets. Thing is I applied fasttrack on a rule s...
by dynek
Mon Mar 21, 2016 5:41 pm
Forum: General
Topic: Is firewall that hungry?
Replies: 11
Views: 865

Re: Is firewall that hungry?

I tried fasttrack and that really kicks ass! Good point, thanks guys. Now, it created a dummy rule "to show fasttrack counters" but it doesn't seem to match fasttracked connections as I targeted a single host (using dst address). After a few minutes I had a few kb on that rule but +1000Mb on the fas...
by dynek
Mon Mar 21, 2016 5:09 pm
Forum: General
Topic: Is firewall that hungry?
Replies: 11
Views: 865

Re: Is firewall that hungry?

I just tried disabling most of the rules (as default is to accept traffic) and I got a 11Mb/sec increase.

I'll check the custom chains, any howto/manual you know that is worth reading?
by dynek
Mon Mar 21, 2016 4:58 pm
Forum: General
Topic: Is firewall that hungry?
Replies: 11
Views: 865

Is firewall that hungry?

Hello, Running a RB1100AHx2, when I make a transfer between two vlans (reaching CPU), the item that consumes the more CPU is "firewall" according to the profiler. Is that expected for an abt. 100 rules set? I would have guessed that my setup (bonding, bridges and vlan on top) would have consumed mor...
by dynek
Tue Mar 08, 2016 11:28 pm
Forum: General
Topic: RB450G and 802.1q over 802.3ad
Replies: 1
Views: 730

Re: RB450G and 802.1q over 802.3ad

For the record - What should have been spotted here is /interface ethernet switch port set 2 vlan-mode=secure set 3 vlan-mode=secure When set to fallback it works straight away. So I guess LACP packets without VLAN tag should be able to go through the LAG ports (maybe for what regard the L2 negotati...
by dynek
Tue Mar 08, 2016 11:25 pm
Forum: RouterBOARD hardware
Topic: Aluminum rack ears for RB1100AHx2
Replies: 1
Views: 675

Re: Aluminum rack ears for RB1100AHx2

For the records: Mikrotik sells them as "accessories" now.
by dynek
Tue Mar 01, 2016 9:02 am
Forum: RouterBOARD hardware
Topic: Aluminum rack ears for RB1100AHx2
Replies: 1
Views: 675

Aluminum rack ears for RB1100AHx2

Hello, I have just received an RB1100AHx2 but it's not new. It has apparently been purchased around July 2015, used for a proof of concept and then sold at good price. Thing is, I haven't received the rack ears and screws to mount it in my rack - I guess I have little chance to have seller send them...
by dynek
Tue Mar 01, 2016 8:56 am
Forum: General
Topic: v6.33.5 Mess with packages
Replies: 5
Views: 1290

Re:

The best practice according to me is to use individual packages because you spare disk space and memory. And you can freely add or remove whatever package as you wish. OK that's my idea as well and how I was handling them on RB450G. The RB1100AHx2 I just received contains the bundled version. I'll ...
by dynek
Mon Feb 29, 2016 11:58 pm
Forum: General
Topic: v6.33.5 Mess with packages
Replies: 5
Views: 1290

Re: v6.33.5 Mess with packages

Hello,

How would I go about switching from bundled packages to individuals.
Or have bundle packages became the best practice?

Thanks
by dynek
Mon Feb 29, 2016 7:33 pm
Forum: RouterBOARD hardware
Topic: microSD compatibility
Replies: 8
Views: 3282

Re: microSD compatibility

Decreased to 16MB on some boards. :D
Great stuff, mine says Size:128 MiB
by dynek
Wed Feb 24, 2016 10:49 pm
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 92849

Re: Feature request: OpenVPN compression LZO and UDP

Seriously guys, don't you want to stop +1 ?

It has no effect, Mikrotik devs aren't counting how many people are incrementing an unexisting counter...
by dynek
Tue Jan 26, 2016 1:39 pm
Forum: RouterBOARD hardware
Topic: microSD compatibility
Replies: 8
Views: 3282

Re: microSD compatibility

So where do we stand 2 years later? Still no compatibility list for what concern microsd ? Not sure it's worth it to have class 10 but I was looking at sandisk, transcend, samsung - 8Gb will be more than fine. Any advise? Thank you btw: it seems storage has increased since few months/years to 128 MB...
by dynek
Tue Jan 12, 2016 10:22 pm
Forum: General
Topic: LACP bonding speed problem with Synology NAS
Replies: 10
Views: 7770

Re: LACP bonding speed problem with Synology NAS

Thank you for your very detailed explanation.

I'm waiting for my RB1100Ahx2 and I'll play with bonding when I get it :-)
by dynek
Wed Jan 06, 2016 10:00 am
Forum: General
Topic: RB1100AHx2 After Upgrading to ROS 6.30.2
Replies: 13
Views: 2468

Re: RB1100AHx2 After Upgrading to ROS 6.30.2

Bump - I thought RB1100AHx2 did not yet support virtualization (MetaRouter).
by dynek
Wed Jan 06, 2016 9:09 am
Forum: Virtualization
Topic: Metarouter on RB1100AHx2
Replies: 22
Views: 9479

Re: Metarouter on RB1100AHx2

I finally gave in and bought the RB1110AHx2. I was kind of hoping that a new version would come out since this model came out long time ago but nothing yet. And I found one for half price, still under warranty. Apparently still no MetaRouter either. That's a long road since when you said you were wo...
by dynek
Wed Jan 06, 2016 12:14 am
Forum: General
Topic: LACP bonding speed problem with Synology NAS
Replies: 10
Views: 7770

Re: LACP bonding speed problem with Synology NAS

That definitely makes sense. Thank you.

Have you implemented bonding on Mikrotik already ?
Just curious to see how I should proceed to configure VLANs over bonding work (still wondering why bridge has been mentioned above).
by dynek
Tue Jan 05, 2016 10:13 pm
Forum: General
Topic: LACP bonding speed problem with Synology NAS
Replies: 10
Views: 7770

Re: LACP bonding speed problem with Synology NAS

Anyone knows if the AR8327 of RB1100AHx2 can do 802.3ad (hardware-based) ? How would I go about creating bonding with vlan on top of it ? Just asking because I tried so with RB450G, I have been unsuccessful until now but I hope to be able with the RB1100AHx2. Also asking because I see people mention...
by dynek
Wed Dec 16, 2015 10:36 pm
Forum: Virtualization
Topic: Metarouter images
Replies: 365
Views: 241494

Re: Metarouter images

My bad, I didn't see you were mentioning a version.
by dynek
Tue Dec 15, 2015 10:23 pm
Forum: Virtualization
Topic: Metarouter images
Replies: 365
Views: 241494

Re: Metarouter images

by dynek
Mon Nov 30, 2015 9:12 pm
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 92849

Re: Feature request: OpenVPN compression LZO and UDP

huuuuh if that's for sure this time I may want to finally buy a RB1100ahx2 :-)
No more need for MetaRouter.
by dynek
Wed Nov 11, 2015 12:59 pm
Forum: General
Topic: RB450G and 802.1q over 802.3ad
Replies: 1
Views: 730

RB450G and 802.1q over 802.3ad

Hello all, I have been using 802.1q between my RB450G and my Zyxel GS1910 switch for quite some months now. Wanted to play with 802.3ad and until now I'm completely unsuccessful. I kind of see the link is trying to establish but it doesn't settle down. Should I be able to do 802.1q over 802.3ad with...
by dynek
Thu Nov 05, 2015 10:49 pm
Forum: Beginner Basics
Topic: Serial console on RB450G
Replies: 6
Views: 2284

Re: Serial console on RB450G

I still did not get the cable to work. No other idea ?

Thanks!
by dynek
Wed Jul 15, 2015 12:05 am
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 92849

Re: Feature request: OpenVPN compression LZO and UDP

Almost. You just have to install the OpenVPN package and configure it.
by dynek
Mon Jun 29, 2015 10:23 pm
Forum: Beginner Basics
Topic: Serial console on RB450G
Replies: 6
Views: 2284

Re: Serial console on RB450G

So I'm using this USB to Serial with a null modem cable (Null Modem Cable DB9F to DB9F RS232 to RS-232 Null cable) and still nothing

/system console says "serial0 vt100"

and port list:

name: serial0
baud rate: 115200
data bits: 8 bits
parity: none
stop bits: 1 bit
flow control: none
by dynek
Wed Jun 03, 2015 12:28 pm
Forum: Announcements
Topic: v6.29 released
Replies: 193
Views: 49306

Re: v6.29 released

Can someone confirm if downgrading is just a matter of putting previous version files in place and reboot the device just like an upgrade ?

Thank you !
by dynek
Wed Jun 03, 2015 8:58 am
Forum: Announcements
Topic: v6.29 released
Replies: 193
Views: 49306

Re: v6.29 released

Which can probably be linked to mine : #2015060266000843
by dynek
Wed Jun 03, 2015 12:07 am
Forum: Announcements
Topic: v6.29 released
Replies: 193
Views: 49306

Re: v6.29 released

dynek - Seems like you will need to open new ticket. I did test with all of these windows opened on Winbox but still did not manage to reproduce problem. Yeah I used Winbox3RC10 closed everything and checked from command line (ssh) and sector writes is still going higher. I sent a mail to the suppo...
by dynek
Tue Jun 02, 2015 3:12 pm
Forum: Announcements
Topic: v6.29 released
Replies: 193
Views: 49306

Re: v6.29 released

dynek - Seems like you will need to open new ticket. I did test with all of these windows opened on Winbox but still did not manage to reproduce problem.
I can't register cause the captcha is not being displayed. Is it the right URL ?
http://bugs.mikrotik-routeros.com/signup_page.php
by dynek
Tue Jun 02, 2015 11:28 am
Forum: Announcements
Topic: v6.29 released
Replies: 193
Views: 49306

Re: v6.29 released

This should probably be investigated and discussed in another thread.
I would be very surprised if what you describes related to a RouterOS update.
by dynek
Tue Jun 02, 2015 10:37 am
Forum: Announcements
Topic: v6.29 released
Replies: 193
Views: 49306

Re: v6.29 released

OK got it - But are you sure ping, http, dns really is going through the tunnel and not through your default gateway which knows the OpenVPN IP of your router ?
Then it might just be an issue of firewall rules
by dynek
Tue Jun 02, 2015 10:20 am
Forum: Announcements
Topic: v6.29 released
Replies: 193
Views: 49306

Re: v6.29 released

OpenVPN on the routerboard (as a client) is working fine for me.
by dynek
Tue Jun 02, 2015 9:37 am
Forum: Announcements
Topic: v6.29 released
Replies: 193
Views: 49306

Re: v6.29 released

We also did see that fix is working in out lab. If you still notice sector writes counter rising without apparent reason, then please write to. Tell us what do you do at the moment when it is happening. Well I was running v.6.27 and updated to v.6.28 two days before updating to v.6.29 so I can't te...
by dynek
Mon Jun 01, 2015 9:21 pm
Forum: Announcements
Topic: v6.29 released
Replies: 193
Views: 49306

Re: v6.29 released

After 96h uptime : 122 284 Sector Writes Since Reboot Total is : 713 917 This router has been running for little bit more than a year so there's really something changed in this version. 17% of sectors writes in 4 days. Anything you can do as I think it does somehow reduce life of the memory chip ? ...
by dynek
Mon Jun 01, 2015 9:12 pm
Forum: Beginner Basics
Topic: Serial console on RB450G
Replies: 6
Views: 2284

Re: Serial console on RB450G

It's this one:
http://www.unitek-products.com/en/produ ... .php?id=12

So I guess it is a TTL version - A null modem cable between this cable and the Mikrotik router should do ?

Thank you
by dynek
Fri May 29, 2015 10:56 pm
Forum: Announcements
Topic: v6.29 released
Replies: 193
Views: 49306

Re: v6.29 released

24h -> 30 978 Sector Writes Since Reboot
by dynek
Fri May 29, 2015 12:04 am
Forum: Announcements
Topic: v6.29 released
Replies: 193
Views: 49306

Re: v6.29 released

I have 190 sector writes since reboot (37 min ago). Isn't that too much?
Updated - Uptime 50 minutes and 1'156 Sector Writes Since Reboot.

Nothing to worry about ?

RB450G
by dynek
Thu May 28, 2015 11:23 pm
Forum: Beginner Basics
Topic: Serial console on RB450G
Replies: 6
Views: 2284

Serial console on RB450G

Hello, I bought a cheap PL2303 cable USB -> COM that I hoped to be able to use to connect to my Mikrotik (and others devices) to recover from stupid mistakes when needed :-) As I was installing 6.29, I decided to plug it into the router, launch screen 115200 8N1 on my Mac and see boot loader to conf...
by dynek
Thu May 28, 2015 9:40 am
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 92849

Re: Feature request: OpenVPN compression LZO and UDP

http://wiki.mikrotik.com/wiki/Manual:Metarouter

It requires some linux knowledge to setup but not so complicated.
by dynek
Wed May 27, 2015 11:58 pm
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 92849

Re: Feature request: OpenVPN compression LZO and UDP

Well as far as I know you can run MetaROUTER on this device.

So creating a simple one with OpenVPN inside is pretty easy and it will fit your needs.
by dynek
Wed May 27, 2015 5:18 pm
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 92849

Re: Feature request: OpenVPN compression LZO and UDP

What Routerboard model do you have ?
by dynek
Wed May 27, 2015 10:43 am
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 92849

Re: Feature request: OpenVPN compression LZO and UDP

Still, I think this kind of functionality does not belong on a router. If you need a VPN concentrator I would install plain linux on a machine and install OpenVPN. You'll have much better performance, scripting is possible (i.e. custom firewall rules per connecting client) etcetera. I do agree on t...
by dynek
Mon May 25, 2015 8:23 pm
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 92849

Re: Feature request: OpenVPN compression LZO and UDP

From a straight forward and quick way to implement, please name them.
by dynek
Mon Feb 23, 2015 4:44 pm
Forum: General
Topic: Routing broadcast between VLANs
Replies: 5
Views: 1594

Re: Routing broadcast between VLANs

Hello, I doubt we're discussing the exact same thing: - Bonjour is working fine with help of avahi reflector as mentioned - Proprietary bjnp protocol (especially discovery frames) is the problem. Frames aren't reaching other vlan(s). I would just need to echo packet in another subnet/vlan. So I gues...
by dynek
Sun Feb 22, 2015 8:34 pm
Forum: General
Topic: Routing broadcast between VLANs
Replies: 5
Views: 1594

Re: Routing broadcast between VLANs

Not a chance to do such a weird thing ?
by dynek
Thu Feb 12, 2015 10:34 pm
Forum: General
Topic: Routing broadcast between VLANs
Replies: 5
Views: 1594

Routing broadcast between VLANs

Hello All, I have a canon printer/scanner in a different subnet that my laptop does. Discovering the printer works, thanks to bonjour frames being relayed by avahi reflector. However scanning doesn't work and I suspect canon's BJNP protocol and their broadcasted frames may be guilty for that. Tcpdum...
by dynek
Fri Feb 06, 2015 9:48 am
Forum: Beginner Basics
Topic: Did anybody get Apple Bonjour to work with RouterOS?
Replies: 14
Views: 9878

Re: Did anybody get Apple Bonjour to work with RouterOS?

As anyone tried using avahi reflector to advertise services of a multifunction printer ? The printer itself advertises bonjour frames and avahi just broadcasts them to other subnets. I have few devices doing the same and the only thing that doesn't work at all is the scanner of the canon printer. It...
by dynek
Thu Jan 22, 2015 2:17 am
Forum: General
Topic: RouterOS v6.25
Replies: 110
Views: 31908

Re: RouterOS v6.25

OK so if that's of interested for you guys @ Mikrotik, I flashed back 6.19 and the router started working again. What a waste of time. Any explanation as to why 6.19 -> 6.25 breaks everything ? Finally I flashed each version from 6.20 to 6.25 and it worked. Also I first did a /system routerboard upg...
by dynek
Thu Jan 22, 2015 12:55 am
Forum: General
Topic: RouterOS v6.25
Replies: 110
Views: 31908

Re: RouterOS v6.25

Try Netinstall to recovery device firmware.
I have netinstall working with wine on OS X. Great stuff.
However, even selecting "Apply default config" doesn't give me 192.168.88.1 on ether1.
And the RB450G still makes this "I am resetting everything" sound each time I put power.
by dynek
Wed Jan 21, 2015 10:58 pm
Forum: General
Topic: RouterOS v6.25
Replies: 110
Views: 31908

Re: RouterOS v6.25

Just updated RB450G from 6.19 to 6.25 it never rebooted so I helped it reboot and now it seems to boot OK (one beep and abt 30 seconds later two beeps) but I'm not assigned an IP anymore, none of my devices is. If I try to set an IP manually, it doesn't work either. I tried to connect to ether1 with...
by dynek
Mon Jan 12, 2015 9:48 am
Forum: General
Topic: RouterOS to act as syslog server ?
Replies: 6
Views: 1573

Re: RouterOS to act as syslog server ?

No. Unless you install the dude. But it has too much problems itself. Thank you for your answer. However, you can install OpenWRT in MetaROUTER. It is possible to run syslog server and many other applications on OpenWRT. Thank you - I did install OpenWRT as a mean to have a full implementation of O...
by dynek
Sat Jan 03, 2015 9:47 am
Forum: General
Topic: RouterOS to act as syslog server ?
Replies: 6
Views: 1573

RouterOS to act as syslog server ?

Hello,

I'm unable to find an answer and all my tests were inconclusive: can RouterOS act as a syslog server ?

Thank you
by dynek
Wed Dec 03, 2014 1:01 pm
Forum: Virtualization
Topic: Metarouter on RB1100AHx2
Replies: 22
Views: 9479

Re: Metarouter on RB1100AHx2

Thank you for the detailed information.

I have so many different on-going things that I think I may want to wait that MetaRouter is natively supported :-)
I'm not in a hurry to acquire the new Routerboard.

Edit: Qemu 2.1, dev team ! :-)
by dynek
Wed Dec 03, 2014 10:36 am
Forum: Beginner Basics
Topic: Make use of switch chip for VLANs
Replies: 5
Views: 1667

Re: Make use of switch chip for VLANs

Well, thank you for your answer. Then I will save few bucks to acquire the new toy I think :-)
by dynek
Wed Dec 03, 2014 10:35 am
Forum: Virtualization
Topic: Metarouter on RB1100AHx2
Replies: 22
Views: 9479

Re: Metarouter on RB1100AHx2

No more news on this?

I'm thinking about switching from my trusted RB450G to RB1100AHx2 but I need MetaRouter or any other yet unrevealed virtualization solution for missing OpenVPN features. Don't feel like having this part split to another piece of hardware.

Cheers
by dynek
Tue Dec 02, 2014 10:38 pm
Forum: Beginner Basics
Topic: Make use of switch chip for VLANs
Replies: 5
Views: 1667

Re: Make use of switch chip for VLANs

Hello All, I've been using Mikrotik for quite some time now and I'm really happy with it. I still own a RB450G. Today I was doing some transfers/iperf to "benchmark" my gigabit network and I noticed that speed were not the ones I expected. Setup is always the same 3 VLANs are declared on the Mikroti...
by dynek
Thu Nov 20, 2014 10:00 am
Forum: Virtualization
Topic: Metarouter images
Replies: 365
Views: 241494

Re: Metarouter images

Hello , Could you please share with me the way you built the image and module? I have been trying with no success for couple of days now. I have only built the SDK to compile packages but this should apply (using menuconfig) to anything else. As I played around for quite a while, it might not be as...
by dynek
Wed Nov 19, 2014 1:40 pm
Forum: Virtualization
Topic: Metarouter images
Replies: 365
Views: 241494

Re: Metarouter images

Hello All, First of all, thanks again liquidcz for the metarouter image. Any chance to see an upgrade to libopenssl ? The provided one is impacted by heartbleed (1.0.1e) and used by OpenVPN. In the meantime I'll try to do it on my side. Thank you Edit: If someone wants it -> https://www.dropbox.com/...
by dynek
Fri Jul 18, 2014 10:17 am
Forum: RouterBOARD hardware
Topic: Testing New MikroTik Hardware on Production Environment
Replies: 45
Views: 7747

Re: Testing New MikroTik Hardware on Production Environment

Being a complete novice in this area:
- Are you doing this personally or for a company ?
- Is it just to share an inet connection over the air ?

Thank you, nice setup.
by dynek
Thu Jul 17, 2014 11:30 am
Forum: General
Topic: how to block teamviewer?
Replies: 12
Views: 10000

Re: how to block teamviewer?

Yes it is.
by dynek
Thu Jul 10, 2014 4:39 pm
Forum: General
Topic: Layer 7
Replies: 3
Views: 722

Re: Layer 7

by dynek
Wed Jul 09, 2014 9:25 am
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 92849

Re: Feature request: OpenVPN compression LZO and UDP

Too bad there's no way to communicate outside the forum. Sorry for polluting.

Thank you for your answer - I'm looking for dual band hardware with case etc. There's none beside building one myself, right ?
by dynek
Tue Jul 08, 2014 10:39 pm
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 92849

Re: Feature request: OpenVPN compression LZO and UDP

I just bought 6 of the 1MW GB AP's for a customer to replace Netopia 3347's[..]
May I ask which hardware/model exactly ?
by dynek
Tue Jul 08, 2014 12:19 pm
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 92849

Re: Feature request: OpenVPN compression LZO and UDP

weeehhh that's great news - as I thought it would never happen.
by dynek
Thu Jun 19, 2014 5:22 pm
Forum: General
Topic: How to mark youtube IPs
Replies: 34
Views: 5307

Re: How to mark youtube IPs

http://linksysinfo.org/index.php?thread ... ost-204861 says:

GET (\/videoplayback\?|\/crossdomain\.xml)

Now if people use HTTPS you're screwed.
by dynek
Wed Jun 18, 2014 12:09 pm
Forum: Beginner Basics
Topic: VLAN basics
Replies: 2
Views: 884

Re: VLAN basics

If client side is not configured for VLAN 10, nothing will happen:
http://www.mytechfetish.com/2010/11/set ... er-in.html

If machine shouldn't be aware of VLAN then you will want to find a way to tag incoming traffic with VLAN 10 and untag outgoing traffic.
by dynek
Tue Jun 10, 2014 10:32 am
Forum: Beginner Basics
Topic: Did anybody get Apple Bonjour to work with RouterOS?
Replies: 14
Views: 9878

Re: Did anybody get Apple Bonjour to work with RouterOS?

Did you configure more than one subnet/vlan ?
No

2 iPads, iPhone, AirPrint, Apple TV's (one wired one wifi) need to work with iTunes on my Hackintosh
Then you shouldn't have any issue in regard to multicast/bonjour.
by dynek
Fri Jun 06, 2014 5:53 pm
Forum: Beginner Basics
Topic: Did anybody get Apple Bonjour to work with RouterOS?
Replies: 14
Views: 9878

Re: Did anybody get Apple Bonjour to work with RouterOS?

Not 100% correct.

Either you flatten your network to one single subnet or if you split it, make use of a raspberry or metarouter to run avahi (advertiser/proxy for mdns).

Did you configure more than one subnet/vlan ?
by dynek
Thu Jun 05, 2014 10:46 am
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 92849

Re: Feature request: OpenVPN compression LZO and UDP

And if you really need OpenVPN, just pick a cheap x86 (atom) machine with linux. It will be faster and more up-to-date than most hardware routers.
Or MetaRouter, works like a charm for me!
Even a cheap and tiny Raspberry PI will do.
by dynek
Thu Jun 05, 2014 10:30 am
Forum: Beginner Basics
Topic: Bonjour/multicast over VPN
Replies: 3
Views: 1903

Re: Bonjour/multicast over VPN

Same here, I went for a Raspberry PI having a leg in both of my vlans and it runs avahi. Working perfectly!
by dynek
Mon May 12, 2014 3:24 pm
Forum: General
Topic: Bonjour multicast - How to do it with VLANs ?
Replies: 12
Views: 7622

Re: Bonjour multicast - How to do it with VLANs ?

Thank you for your answer.

I gave up and I am now running a Raspberry listening and advertising mDNS on both VLANs. Too bad Mikrotik / RouterOS can't do it.

Thanks again.
by dynek
Fri May 02, 2014 9:18 am
Forum: General
Topic: Bonjour multicast - How to do it with VLANs ?
Replies: 12
Views: 7622

Re: Bonjour multicast - How to do it with VLANs ?

Hello jkarras and thank you for your answer! Do you have any firewall rules on these interfaces? I have the default rules that come with RouterOS. So no rule specific to the VLANs. Can you confirm that a device on VLAN 200 can connect to your server device on VLAN 100 via unicast (ping etc...). Yes ...
by dynek
Thu May 01, 2014 11:34 pm
Forum: General
Topic: Bonjour multicast - How to do it with VLANs ?
Replies: 12
Views: 7622

Re: Bonjour multicast - How to do it with VLANs ?

Once more, as it's been a month now that I'm trying to have this setup working I guess I have gone the wrong way. Most likely I don't understand what PIM / IGMP Proxy should be used for and I'm looking for something else. Is there a component in RouterOS that I can use to have Bonjour frames replica...
by dynek
Thu May 01, 2014 11:31 pm
Forum: Beginner Basics
Topic: Did anybody get Apple Bonjour to work with RouterOS?
Replies: 14
Views: 9878

Re: Did anybody get Apple Bonjour to work with RouterOS?

OK that's not good news but at least it is an information I was looking for. I definitely don't get what IGMP-Proxy and PIM are for as, after one month of trying every single thing, it still couldn't get anything going through. I'd be interested if someone could explain what are these for as neither...
by dynek
Wed Apr 30, 2014 10:41 pm
Forum: Virtualization
Topic: Firewall rules for virtual interface / metarouter
Replies: 5
Views: 2697

Re: Firewall rules for virtual interface / metarouter

I was sure I tried to put my rules at the top and bottom of the set and it didn't do anything but now it works :?

So firewall on RouterOS is first-match policy, right ?
by dynek
Wed Apr 30, 2014 10:33 pm
Forum: General
Topic: Bonjour multicast - How to do it with VLANs ?
Replies: 12
Views: 7622

Re: Bonjour multicast - How to do it with VLANs ?

230.255.2.1 being a stream I'm multicasting over udp using VLC [admin@Router] /routing pim> mfc pr de group=230.255.2.1 source=10.1.0.125 rp=10.2.0.1 upstream-interface=vlan100-management downstream-interfaces="" group=239.255.255.250 source=10.1.0.30 rp=10.2.0.1 upstream-interface=vlan100-managemen...
by dynek
Wed Apr 30, 2014 12:50 pm
Forum: General
Topic: Bonjour multicast - How to do it with VLANs ?
Replies: 12
Views: 7622

Re: Bonjour multicast - How to do it with VLANs ?

As far as I remember, I never saw any machine from 10.2.0.0/24 network (vlan200) appears in Joins tab. Should they land here when checking for a Bonjour printer for instance ? I can see some groups related to vlan200 though in IGMP Groups but all of them have state saying exclude (even in vlan100 bt...
by dynek
Wed Apr 30, 2014 11:16 am
Forum: General
Topic: Bonjour multicast - How to do it with VLANs ?
Replies: 12
Views: 7622

Re: Bonjour multicast - How to do it with VLANs ?

As it's been almost a month now that I'm trying to have this setup working I guess I have gone the wrong way. Most likely I didn't understand what PIM / IGMP Proxy should be used for and I'm looking for something else. Is there a component in RouterOS that I can use to have multicast frames (be it B...
by dynek
Wed Apr 30, 2014 9:58 am
Forum: Virtualization
Topic: Firewall rules for virtual interface / metarouter
Replies: 5
Views: 2697

Re: Firewall rules for virtual interface / metarouter

There's a single virtual interface assigned to the MetaRouter, no bridge, no physical interface implied. When torching the virtual interface, I can see traffic going through with source IP being the client's and destination IP being, well, anything in my network. But when I add a rule in filter tabl...
by dynek
Tue Apr 29, 2014 3:58 pm
Forum: Virtualization
Topic: Firewall rules for virtual interface / metarouter
Replies: 5
Views: 2697

Firewall rules for virtual interface / metarouter

Hello All, I have an OpenVPN server running as MetaRouter (OpenWRT). I'd like to implement few firewall rules for clients but even though I can see IPs when torching virtual interface, firewall rules have no effect. Should I be marking packets using mangle rule prior to accept/deny them in filter ta...
by dynek
Thu Apr 17, 2014 12:23 pm
Forum: Virtualization
Topic: MetaRouter eth0 IP
Replies: 12
Views: 3730

Re: MetaRouter eth0 IP

if you sniff packets on incoming (underlying) interface are they correctly tagged, are there join in /routing pim joins I can see igmp packages travelling on vlan100 to 224.x.x.x IPs - Those IPs I can see them in PIM/IGMP Groups. In PIM/Joins I have: - group 224.0.0.0, source 10.1.0.1, RP 10.1.0.1,...
by dynek
Thu Apr 17, 2014 12:06 pm
Forum: Virtualization
Topic: MetaRouter eth0 IP
Replies: 12
Views: 3730

Re: MetaRouter eth0 IP

See: http://forum.mikrotik.com/viewtopic.php?f=14&t=83698 where are the multicast sources Sources are in vlan100 - 10.1.0.0/25 (printers, NAS, etc. - all emitting Bonjour frames) where are multicast destinations Receivers are in vlan200 - 10.2.0.0/24 (laptops, phone, etc.) What groups are used To be...
by dynek
Wed Apr 16, 2014 5:00 pm
Forum: Virtualization
Topic: MetaRouter eth0 IP
Replies: 12
Views: 3730

Re: MetaRouter eth0 IP

I've done so and go rid off the bridge. PIM/IGMP still don't work though.

But at least no more bridge. Thanks.
by dynek
Tue Apr 15, 2014 1:07 pm
Forum: Virtualization
Topic: MetaRouter eth0 IP
Replies: 12
Views: 3730

Re: MetaRouter eth0 IP

OK so I will create a range dedicated to a single MetaRouter instance then :-) What if I split range: vlan100 - 10.1.0.0/24 (IPs 10.1.0.1 - 10.1.0.254 with broadcast 10.1.0.255) into: vlan100 - 10.1.0.0/25 (IPs 10.1.0.1 - 10.1.0.126 with broadcast 10.1.0.127) vif - 10.1.0.128/25 (IPs 10.1.0.129-10.1...
by dynek
Tue Apr 15, 2014 12:46 pm
Forum: Virtualization
Topic: MetaRouter eth0 IP
Replies: 12
Views: 3730

Re: MetaRouter eth0 IP

Hello and thank you for your answer,

That's what I have done so far but now I also need IGMP Proxy / PIM on this bridge because vlan100 contains printers, etc.
But in an exchange we had on support@ you told me bridges can't be used in PIM. I'm trying to find a solution...

Thanks
by dynek
Tue Apr 15, 2014 9:41 am
Forum: Virtualization
Topic: MetaRouter eth0 IP
Replies: 12
Views: 3730

Re: MetaRouter eth0 IP

One last try :-) If I want to assign my MetaRouter Virtual Ethernet an IP in one of the ranges declared on the Mikrotik, how would I do it ? I tried to assign the VIF itself an IP manually (IP > Addresses) and manually configured one in the same range on OpenWRT with no luck. For instance: vlan100 :...
by dynek
Thu Apr 10, 2014 10:34 pm
Forum: Virtualization
Topic: MetaRouter eth0 IP
Replies: 12
Views: 3730

Re: MetaRouter eth0 IP

Expected my question to be pretty trivial :?

Maybe asked another way?

If I want my MetaRouter to have an IP in a range that is declared on the Mikrotik, is it only possible using a bridge between the virtual interface and another interface on the Mikrotik corresponding to IP range ?

Thank you
by dynek
Wed Apr 09, 2014 12:11 am
Forum: Virtualization
Topic: MetaRouter eth0 IP
Replies: 12
Views: 3730

MetaRouter eth0 IP

Hello All, How can I have MetaRouter assigned an IP in a VLAN attached to Ether2 ? Until now I have used a bridge between this vlan and the virtual interface with DHCP server targeting the bridge. Is there a way to get rid off the bridge and have MetaRouter request an IP on ether2 with eth0.100 decl...
by dynek
Thu Apr 03, 2014 1:23 am
Forum: General
Topic: Bonjour multicast - How to do it with VLANs ?
Replies: 12
Views: 7622

Bonjour multicast - How to do it with VLANs ?

Hello All, I have tried tons of different things to have Bonjour multicast go through my VLANs with absolutely no success. How should I proceed: PIM or IGMP proxy ? I tried to go with PIM and declared two interfaces: - One is a bridge between a vlan interface and a virtual interface used in MetaRout...
by dynek
Tue Apr 01, 2014 12:07 am
Forum: Beginner Basics
Topic: Reading CPU temperature through serial port ?
Replies: 6
Views: 3550

Re: Reading CPU temperature through serial port ?

I'm using this:
http://arduino.cc/en/Main/USBSerial

And actually it's plugged to my laptop simply reading data off this module, it works fine when connecting to other serial ports (i.e. WNDR3700 for recovery).
by dynek
Mon Mar 31, 2014 11:32 pm
Forum: Beginner Basics
Topic: Reading CPU temperature through serial port ?
Replies: 6
Views: 3550

Re: Reading CPU temperature through serial port ?

I just tried to send text trough serial port but all I get is garbage even though I follow Mikrotik's serial pinout (DB9F) and I configured both ends with same settings (115200 8N1). Calling this script http://wiki.mikrotik.com/wiki/Sending_text_out_over_a_serial_port is seen like this on my machine...
by dynek
Mon Mar 31, 2014 10:15 am
Forum: Beginner Basics
Topic: Reading CPU temperature through serial port ?
Replies: 6
Views: 3550

Re: Reading CPU temperature through serial port ?

Thanks to both of you. I was thinking about "/system health print" in the first place but would you happen to know if TX/RX and GND are enough to send and read data of the Mikrotik using Arduino ? Thank you Edit: Also I'm wondering if this could be a solution as I only want temperature info, not ful...
by dynek
Thu Mar 27, 2014 11:56 pm
Forum: Beginner Basics
Topic: Reading CPU temperature through serial port ?
Replies: 6
Views: 3550

Reading CPU temperature through serial port ?

Hello All,

As anyone tried reading CPU temperature through the serial port using an Arduino ?
I'm trying to find a way to fetch this value.

Thank you
by dynek
Thu Mar 27, 2014 12:41 am
Forum: Beginner Basics
Topic: RB 450G is hot?
Replies: 35
Views: 19432

Re: RB 450G is hot?

82C here and the room is around 20C

edit: after I installed a fan at the top of my rack, temperature went down to 67C
by dynek
Thu Mar 27, 2014 12:26 am
Forum: General
Topic: ups !!!!!!!!!!!!!!!!
Replies: 30
Views: 7555

Re: ups !!!!!!!!!!!!!!!!

Hello All,

I have an SMT750I, is it still the case that RouterOS don't support devices beginning with SMT ?
Can't get it recognized using serial port.

Thank you
by dynek
Wed Mar 26, 2014 9:39 am
Forum: General
Topic: vLAN with Switch chips _ scenario-based solutions
Replies: 33
Views: 6436

Re: vLAN with Switch chips _ scenario-based solutions

Thank you for your answers. I didnt' think I would reach RB450G's limit that quick :-)

Not a real problem though cause TimeMachine backups, etc. won't happen so often.
by dynek
Wed Mar 26, 2014 1:51 am
Forum: General
Topic: vLAN with Switch chips _ scenario-based solutions
Replies: 33
Views: 6436

Re: vLAN with Switch chips _ scenario-based solutions

Fast Path is not available on RB450G as far as I see / understand.

I haven't done anything regarding firewall rules for the moment, they are the default ones.
by dynek
Wed Mar 26, 2014 12:01 am
Forum: General
Topic: vLAN with Switch chips _ scenario-based solutions
Replies: 33
Views: 6436

Re: vLAN with Switch chips _ scenario-based solutions

Would it work to disable the bridge or should I remove it ?
If so, I tried and it doesn't change - See screenshot.
by dynek
Tue Mar 25, 2014 9:47 am
Forum: General
Topic: vLAN with Switch chips _ scenario-based solutions
Replies: 33
Views: 6436

Re: vLAN with Switch chips _ scenario-based solutions

That's a bridge between VLAN100 and MetaRouter's virtual interface.

I need it so my MetaRouter's instance gets an IP in the range of VLAN100.
by dynek
Mon Mar 24, 2014 11:00 pm
Forum: General
Topic: vLAN with Switch chips _ scenario-based solutions
Replies: 33
Views: 6436

Re: vLAN with Switch chips _ scenario-based solutions

OK so I finally went for one master port for WAN/NAT and one for VLANs, does this sound correct ? [MODEM]----(ether1)[RB450G](ether2)----[SWITCH]----[NAS / Computer / ...] However when Computer sends data to NAS, in current case I was synchronizing a 6Gb mailbox and then TimeMachine backup, CPU load...
by dynek
Sat Mar 22, 2014 9:20 pm
Forum: General
Topic: vLAN with Switch chips _ scenario-based solutions
Replies: 33
Views: 6436

Re: vLAN with Switch chips _ scenario-based solutions

RB450G for the moment and RouterOS doesn't complain if I declare:
port 1 as WAN (gateway)

port 2 as master for my VLANs
port 3 as slave for my VLANs

port 4 as master for other IP range
port 5 as slave for other IP range
by dynek
Sat Mar 22, 2014 9:10 pm
Forum: General
Topic: vLAN with Switch chips _ scenario-based solutions
Replies: 33
Views: 6436

Re: vLAN with Switch chips _ scenario-based solutions

Thanks once more for your answer.

Still I am able to have two master ports in the configuration. Now, does it mean that if I do so I am not making use of switch chip to manage vlan traffic ?
by dynek
Fri Mar 21, 2014 9:36 pm
Forum: General
Topic: vLAN with Switch chips _ scenario-based solutions
Replies: 33
Views: 6436

Re: vLAN with Switch chips _ scenario-based solutions

Dasiu, now between "I understood" and "I'm able to apply it", there's a world :-) In your presentation you mention only one master port for a chip. How if I want to have two but only one with switch chip used for vlans? I currently have a RB450G (planning to switch for a 2011UiAS), can you tell me i...
by dynek
Fri Mar 21, 2014 1:54 pm
Forum: General
Topic: vLAN with Switch chips _ scenario-based solutions
Replies: 33
Views: 6436

Re: vLAN with Switch chips _ scenario-based solutions

I have been searching for an explanation for so long and couldn't understand how it all works. So definitely your presentation is the best thing I've seen so far - Mikrotik's team should put it somewhere on the WiKi. I even assume that some people think they are getting the best out of their router ...
by dynek
Fri Mar 21, 2014 12:06 pm
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 92849

Re: Feature request: OpenVPN compression LZO and UDP

Single and only solution is to use MetaRouter and install OpenWRT/OpenVPN for such functionalities.

Mikrotik said it few times: they will never increase number of functionalities or concentrate any effort on OpenVPN implementation.

Time to initiate the grieving process and forget about it.
by dynek
Fri Mar 21, 2014 10:21 am
Forum: RouterBOARD hardware
Topic: 450G vs 2011UiAS-IN/RM
Replies: 12
Views: 5678

Re: 450G vs 2011UiAS-IN/RM

Thank you again for your answer.

As I just need one MetaRouter instance, I think I'm going to try to sell the 450G and the the 2011UiAS.
If I don't succeed I'll keep the 450G.

Thanks again!
by dynek
Thu Mar 20, 2014 6:46 pm
Forum: General
Topic: vLAN with Switch chips _ scenario-based solutions
Replies: 33
Views: 6436

Re: vLAN with Switch chips _ scenario-based solutions

So I can have switch chip declarations and beside this declare VLANs as interface as well ?
by dynek
Thu Mar 20, 2014 5:58 pm
Forum: General
Topic: vLAN with Switch chips _ scenario-based solutions
Replies: 33
Views: 6436

Re: vLAN with Switch chips _ scenario-based solutions

You can check my MUM presentation about the switch chip: http://mum.mikrotik.com/presentations/IT14/starnowski.pdf I read, re-read and re-re-read until I (think I) understood everything. Based on your presentation, I now assume that VLAN interface(s) aren't required at all to manage VLANs if switch...
by dynek
Thu Mar 20, 2014 5:39 pm
Forum: General
Topic: AR8327
Replies: 8
Views: 6146

Re: AR8327

by dynek
Thu Mar 20, 2014 2:40 pm
Forum: RouterBOARD hardware
Topic: 450G vs 2011UiAS-IN/RM
Replies: 12
Views: 5678

Re: 450G vs 2011UiAS-IN/RM

Hello, and thank you for your answer. I am using MetaRouter to fill the gaps regarding OpenVPN. So I will only run a single guest for VPN purposes. So I'd guess it won't require much RAM / disk space but rather CPU power and according to: http://forum.mikrotik.com/viewtopic.php?f=3&t=74145 AR9344 is...
by dynek
Thu Mar 20, 2014 12:48 pm
Forum: RouterBOARD hardware
Topic: 450G vs 2011UiAS-IN/RM
Replies: 12
Views: 5678

450G vs 2011UiAS-IN/RM

Hello guys, I just bought for testing purposes a 450G - For the moment I only created VLANs and trying to use MetaRouter to run OpenWRT (OpenVPN). It runs well! Later, while making a few searches about Mikrotik on Google, I fell on routerboard.com page describing 2011UiAS-IN/RM. I checked the differ...
by dynek
Thu Mar 20, 2014 11:46 am
Forum: Beginner Basics
Topic: Make use of switch chip for VLANs
Replies: 5
Views: 1667

Re: Make use of switch chip for VLANs

OK I think I got it. My understanding of this switch cpu thing and wire-speeds, etc. was wrong and is not applicable in my case because I am not using the Mikrotik to pass traffic from an untagged interface to a tagged one. My VLAN are "created" on the Mikrotik and trunked onto a switch which makes ...
by dynek
Thu Mar 20, 2014 12:42 am
Forum: Virtualization
Topic: Metarouter images
Replies: 365
Views: 241494

Re: Metarouter images

liquidcz, hehey!!! it work!!! DHCP not work again, but i configure interface manualy.
Check your DHCP server: most likely there will be a red line mentioning that wrong interface is selected.
Choose your bridge instead of the ether interface.
Once changed it will work.
by dynek
Wed Mar 19, 2014 8:58 pm
Forum: Beginner Basics
Topic: Make use of switch chip for VLANs
Replies: 5
Views: 1667

Make use of switch chip for VLANs

Hey guys, Just wanted to ensure that following setup is using switch chip for VLANs to reach near wire speed and doesn't use the CPU on the box: /interface ethernet set [ find default-name=ether1 ] mac-address=00:0C:42:BD:D3:F7 name=\ ether1-gateway set [ find default-name=ether2 ] mac-address=00:0C...
by dynek
Thu Feb 20, 2014 5:38 pm
Forum: Beginner Basics
Topic: Trunk VLAN to switch
Replies: 18
Views: 4999

Re: Trunk VLAN to switch

Thank you for all your answers guys!
by dynek
Thu Feb 20, 2014 4:03 pm
Forum: Beginner Basics
Topic: Trunk VLAN to switch
Replies: 18
Views: 4999

Re: Trunk VLAN to switch

But I'm wondering anyway if I should keep going this way. Only reason why I want to have both tagged and untagged frames go through is to have my switches and access point get an address on same range as router itself. I went for a management vlan and both of my switch are getting IP on this vlan no...
by dynek
Thu Feb 20, 2014 11:05 am
Forum: Beginner Basics
Topic: Trunk VLAN to switch
Replies: 18
Views: 4999

Re: Trunk VLAN to switch

OpenWRT: The switch chipset (Atheros AR8316) however does not provide support for mixing tagged and untagged VLAN's on the same port. Jeroen1000: If you read around a bit, you will see that ROS cannot support tagged and untagged frames on the same interface (supposedly a hardware limitation). I prac...
by dynek
Wed Feb 19, 2014 3:58 pm
Forum: Beginner Basics
Topic: Trunk VLAN to switch
Replies: 18
Views: 4999

Re: Trunk VLAN to switch

You don't need a default gateway if the target address is within the range of a connected interface. My Raspberry PI is connected straight to the Mikrotik ether5 and I configured both eth0 and eth0.100 onto the rpi. If I ping 10.0.0.1 while specifying eth0.100 as source interface it doesn't work. D...
by dynek
Tue Feb 18, 2014 11:47 pm
Forum: Beginner Basics
Topic: Trunk VLAN to switch
Replies: 18
Views: 4999

Re: Trunk VLAN to switch

6.7 apparently Edit 1: After upgrade to 6.10, results are the same. Edit 2: OK so as far as I was able to read, having both tagged and untagged packets going through a port is not possible (at least with the 450G). So that clears one of my questions. I think the way to go is to then create a managem...
by dynek
Tue Feb 18, 2014 10:33 pm
Forum: Beginner Basics
Topic: Trunk VLAN to switch
Replies: 18
Views: 4999

Re: Trunk VLAN to switch

Here you go - Note that Mikrotik manages the VLANs and trunk them onto a single port. There's no vlan 100 / 200 or whatever connected directly to any of its port as mentioned in your code. I can't find anybody explain how this would work... It's Mikrotik with vlan declared locally -> trunked or what...
by dynek
Tue Feb 18, 2014 11:33 am
Forum: Beginner Basics
Topic: Trunk VLAN to switch
Replies: 18
Views: 4999

Re: Trunk VLAN to switch

efaden, thanks a bunch for your answer, really appreciated! 1/ So port has to be a master port (and use a bridge) and not slave, correct ? 2/ How can the switch get its own IP address for management ? It won't "see" regular network anymore, right ? CelticComms, thanks as well for your answer - PVID ...
by dynek
Mon Feb 17, 2014 11:42 pm
Forum: Beginner Basics
Topic: Trunk VLAN to switch
Replies: 18
Views: 4999

Trunk VLAN to switch

Hello Guys, I decided to give Mikrotik hardware / OS a try to include it in my network and I recently started to play with a 450G. Before anything, I'd like to mention that I read lots of different things about following question and I'm not able to find an answer. Setup is: RB450G --> Netgear Manag...
by dynek
Thu Feb 13, 2014 2:03 pm
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 92849

Re: Feature request: OpenVPN compression LZO and UDP

Source: https://www.bestvpn.com/blog/4147/pptp-vs-l2tp-vs-openvpn-vs-sstp/ - OpenVPN is easily best all round VPN solution despite needing third party software on all platforms. It is reliable, fast, and (most importantly) secure (even against the NSA), although it usually needs a bit more setting u...
by dynek
Thu Jan 23, 2014 1:47 pm
Forum: General
Topic: Feature Request: OpenVPN [ovpn] udp tunnels
Replies: 250
Views: 89238

Re: Feature Request: OpenVPN [ovpn] udp tunnels

Is it possible create virtual network interfaces on RouterOS that could be used from within openwrt for incoming and outcoming data ?

Anyway, all information/logs/graphs/users currently logged in, ... won't be there
by dynek
Thu Jan 23, 2014 12:28 pm
Forum: General
Topic: OVPN on new versoins ROS 6.0 and 5.1...
Replies: 61
Views: 19477

Re: OVPN on new versoins ROS 6.0 and 5.1...

I'm sure they are losing few bucks because of this. Products page shows SoHo devices as well as professional devices, right ? SoHo users make use of solution such as OpenVPN, not IPsec (at least, not always). In another post, somebody from Mikrotik answered some user that creation of package for Rou...
by dynek
Wed Jan 22, 2014 11:16 pm
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 92849

Re: Feature request: OpenVPN compression LZO and UDP

comp-lzo support
auth-user-pass not required
tls-auth key support
udp support
by dynek
Wed Jan 22, 2014 11:12 pm
Forum: General
Topic: Feature Request: OpenVPN [ovpn] udp tunnels
Replies: 250
Views: 89238

Re: Feature Request: OpenVPN [ovpn] udp tunnels

Is there a way for the community to create packages that could be use within RouterOS ?

Could be a solution to create one package with full OpenVPN support, cause that's the only thing that makes me refrain from buying a MikroTik device :-(
by dynek
Wed Jan 22, 2014 11:04 pm
Forum: General
Topic: Feature Request: OpenVPN [ovpn] udp tunnels
Replies: 250
Views: 89238

Re: Feature Request: OpenVPN [ovpn] udp tunnels

if mikrotik added these openvpn client features it would be able to connect to 99% of "standard" servers, no raw configuration needed: comp-lzo support some way to disable auth-user-pass (the servers i configure to have mikrotik clients must have a dummy auth script, what a joke!) tls-auth key supp...