Community discussions

Search found 43 matches

by Azendale
Thu Mar 28, 2019 4:37 pm
Forum: Forwarding Protocols
Topic: Make OSPFv3 use Global IPv6 addresses instead of LinkLocal? [SOLVED]
Replies: 3
Views: 1392

Re: Make OSPFv3 use Global IPv6 addresses instead of LinkLocal? [SOLVED]

Yes, this is quite common in IPv4 space as well, called a Loopback address. For nice traceroutes, I actually set pref-source on all routes to the loopback address too so you dont have to name / PTR and catalog all the interface addresses. I assume you don't know of any way to use some kind of auto ...
by Azendale
Tue Mar 26, 2019 9:56 pm
Forum: General
Topic: VRRP instability, flapping
Replies: 4
Views: 806

Re: VRRP instability, flapping

I'm still interested in finding a solution for this. (Thanks Kindis for at least trying!)
by Azendale
Tue Mar 26, 2019 9:55 pm
Forum: Forwarding Protocols
Topic: Make OSPFv3 use Global IPv6 addresses instead of LinkLocal? [SOLVED]
Replies: 3
Views: 1392

Re: Make OSPFv3 use Global IPv6 addresses instead of LinkLocal? [SOLVED]

To follow up on this -- I've since learned that your life will be simpler if you don't try to do what I asked. Embrace using link-local addresses (with an interface identifier) as next hops. It makes for super simple configuration of network segments between routers. You mostly just have to decide i...
by Azendale
Tue Mar 26, 2019 9:45 pm
Forum: General
Topic: CoDel support?
Replies: 45
Views: 13460

Re: CoDel support?

Not available (yet) but both SFQ and PCQ can provide a solution if you don't have brand flexibility. Correct me if I'm wrong (and I appreciate that you are trying to find a workaround), but my understanding is those require something with fixed bandwith that you can tune the settings to. Isn't the ...
by Azendale
Tue Mar 26, 2019 9:10 pm
Forum: General
Topic: CRS317 cant even configure simple trunking
Replies: 12
Views: 2395

Re: CRS317 cant even configure simple trunking

I have less then this in the switch. Problems: It shows a flapping link with no cable connected and does not link up with a longer (<100m) installed cable we currently use with 1Gbps. Looks like the SW is not done yet. Is this a Copper Cable (or is it fiber)? Just wondering because I've using all D...
by Azendale
Tue Mar 26, 2019 9:03 pm
Forum: General
Topic: Feature request: Do not block highlighting/selecting torch table contents
Replies: 5
Views: 999

Re: Feature request: Do not block highlighting/selecting torch table contents

And the same goes for the log. Oh my goodness, yes! I totally forgot about that! And yes, a freeze would be nice. I would still be most interested in the web version because that's what our "first line" techs use/have access to. But it certainly can't hurt (or be hard to do!) for both winbox and "w...
by Azendale
Wed Mar 20, 2019 10:45 pm
Forum: General
Topic: VRRP instability, flapping
Replies: 4
Views: 806

VRRP instability, flapping

We recently rolled a couple of Miktrotik routers into a pair of CCR1009-7G-1C-1S+ routers running VRRP. We thought we were doing a good thing for network reliability by implementing VRRP. Instead, it made our network LESS reliable than if we put it all on one router. (Grrr...) On early morning (like...
by Azendale
Tue May 01, 2018 4:23 am
Forum: General
Topic: Feature request: Do not block highlighting/selecting torch table contents
Replies: 5
Views: 999

Feature request: Do not block highlighting/selecting torch table contents

This would make our life way easier -- right now, people screenshot the table and then manually retype an address! I can't figure out a good reason that we should not be able to select something in this table. This is in the web interface. I have tried to debug the problem a bit, it it seems to be r...
by Azendale
Tue Apr 24, 2018 4:45 am
Forum: General
Topic: Feature request: Installation of IPv6 routes for proxied DHCPv6-PD responses
Replies: 1
Views: 429

Re: Feature request: Installation of IPv6 routes for proxied DHCPv6-PD responses

Additionally, I see no way to run a script when a DHCPv6 response is proxied, nor variables that contain what address block was delegated to what IPv6 address/gateway, so I see no way to work around this with scripting.
by Azendale
Tue Apr 24, 2018 4:43 am
Forum: General
Topic: Feature request: Installation of IPv6 routes for proxied DHCPv6-PD responses
Replies: 1
Views: 429

Feature request: Installation of IPv6 routes for proxied DHCPv6-PD responses

See: https://forum.mikrotik.com/viewtopic.php?f=2&t=133571 Where it seems you can not configure Mikrotik to service both DHCPv6 address requests and DHCPv6-PD requests on the same interface. Apparently, this is needed to do DOCSIS 3 (cable) IPv6 support as it does not support assigning IPv6 WAN addr...
by Azendale
Tue Apr 24, 2018 4:28 am
Forum: General
Topic: How do you configure routerOS to respond to DHCPv6 requests for both addresses and Prefixes on the same interface?
Replies: 0
Views: 258

How do you configure routerOS to respond to DHCPv6 requests for both addresses and Prefixes on the same interface?

I think to do Prefix delegation, you just set a pool with a smaller prefix than the netmask on the block of addresses given to the prefix. Usually, I would use RA messages to allocate WAN addresses on downstream routers, and then DHCPv6-PD to allocate prefixes for the LAN on those routers (and inser...
by Azendale
Fri Mar 16, 2018 6:00 pm
Forum: General
Topic: DHCP + Radius: Assigning DHCP vivso option from Radius
Replies: 0
Views: 266

DHCP + Radius: Assigning DHCP vivso option from Radius

How can I send a Vendor Specific DHCP option (as assigned by a radius response) when using radius & DHCP? I've tried the Freeradius option DHCP-Vendor-Specific-Information, but a packet capture just doesn't even show the DHCP response being sent. If I set a relay to ISC DHCP, and then set something ...
by Azendale
Sat Feb 17, 2018 7:08 pm
Forum: General
Topic: No activity LEDs for CRS3xx series switches?
Replies: 5
Views: 733

Re: No activity LEDs for CRS3xx series switches?

I have not changed the defaults with LEDs either: /system led print Flags: X - disabled, * - default # TYPE INTERFACE LEDS 0 * interface-activity sfp-sfpplus1 sfp-sfpplus1-led1 1 * interface-speed sfp-sfpplus1 sfp-sfpplus1-led2 2 * interface-activity sfp-sfpplus2 sfp-sfpplus2-led1 3 * interface-spee...
by Azendale
Sat Feb 17, 2018 6:54 am
Forum: General
Topic: No activity LEDs for CRS3xx series switches?
Replies: 5
Views: 733

Re: No activity LEDs for CRS3xx series switches?

Just in case it's something I'm doing with how I configured it, here is a sanitized config: /interface bridge add admin-mac=CC:2D:E0:00:00:01 auto-mac=no name=bridge1 protocol-mode=none pvid=398 vlan-filtering=yes /interface ethernet set [ find default-name=sfp-sfpplus1 ] set [ find default-name=sfp...
by Azendale
Sat Feb 17, 2018 6:02 am
Forum: General
Topic: CCR1072-1G-8S+ PPPoE and bandwidth
Replies: 6
Views: 804

Re: CCR1072-1G-8S+ PPPoE and bandwidth

Just took a peek at a more peak time (see what I did there :).

~25% CPU utilization at around 830 clients and 550 Mbps. This is on the 9 core CCR as mentioned above.
by Azendale
Wed Feb 14, 2018 8:13 pm
Forum: General
Topic: CCR1072-1G-8S+ PPPoE and bandwidth
Replies: 6
Views: 804

Re: CCR1072-1G-8S+ PPPoE and bandwidth

So far, the 9 core CCR1009-7G-1C-1S+ that we are using is serving about 825 clients and 300 Mbps at the moment (that will get higher later in the day), with about 15% CPU usage reported. The profile tool reports that PPP itself is using .5-2%, queueing ~3%, firewall 2-4%, networking ~4%, on each cor...
by Azendale
Wed Feb 14, 2018 3:34 pm
Forum: General
Topic: No activity LEDs for CRS3xx series switches?
Replies: 5
Views: 733

No activity LEDs for CRS3xx series switches?

I'm running a CRS317-1G-16S+ and a CRS326-24G-2S+.

They are using ROS, but they are doing switching with a hardware offloaded bridge.

I don't seem to see any activity indication on the LEDs, even though there is 100s of Mb/s of traffic right now. Why?
by Azendale
Tue Feb 13, 2018 9:40 pm
Forum: General
Topic: CCR1072-1G-8S+ PPPoE and bandwidth
Replies: 6
Views: 804

Re: CCR1072-1G-8S+ PPPoE and bandwidth

I can confirm that Freeradius works with Mikrotik's Radius client for PPPoE. Don't know it that helps, but at least you won't have to change as much. I can't give much feedback on the CCR PPP performance, but I'm actually going to be installing a pair of CCR1009 routerboards for PPPoE in our mainten...
by Azendale
Mon Feb 12, 2018 11:49 pm
Forum: General
Topic: RouterOS no longer responds to ff02::1?
Replies: 1
Views: 296

RouterOS no longer responds to ff02::1?

I have used link-local addresses to connect to routerboards without having to use a serial console while configuring them. (This is helpful for things that can't be done with a console, such as routing filters with multiple types of routes to match. Everything, even exports, say you can do protocol=...
by Azendale
Mon Feb 12, 2018 10:50 pm
Forum: General
Topic: CRS317 cant even configure simple trunking
Replies: 12
Views: 2395

Re: CRS317 cant even configure simple trunking

I think this should be doable, I had it working in the lab 2 days ago, I'll see if I can look at this closer later today. Off the top of my head, from skimming this thread, I'll say: Use only one bridge -- only one bridge will get HW acceleration! The end goal should be to have one bridge with vlan ...
by Azendale
Wed Feb 07, 2018 6:06 am
Forum: General
Topic: Assigning multiple IP addresses on different VLANs in a CRS 3xx switch?
Replies: 0
Views: 249

Assigning multiple IP addresses on different VLANs in a CRS 3xx switch?

What is the right way to put multiple management IP addresses on one of the CRS 3xx switches, on different VLANs? Is it right to refer to the link from the switch chip to the CPU as the name of the bridge? Here is the config I have now. I have a packet capture running on the computer connected to th...
by Azendale
Wed Feb 07, 2018 5:52 am
Forum: General
Topic: What is the right way to assign a management IP on a CRS326-24G-2S+RM (or other 3xx series)?
Replies: 0
Views: 346

What is the right way to assign a management IP on a CRS326-24G-2S+RM (or other 3xx series)?

I have two configs that seem to do the same thing. Which one is better? Is setting the bridge interface name as one of the untagged ports in a bridge vlan wrong? It seems to work. I was expirimenting with this because I'm trying to understand how the port between the CPU and switch chip is managed w...
by Azendale
Tue Oct 31, 2017 11:31 pm
Forum: General
Topic: Report "Delegated-IPv6-Prefix" attribute for PPPoE
Replies: 200
Views: 39636

Re: Report "Delegated-IPv6-Prefix" attribute for PPPoE

Mikrotik, what is the status of getting the "Delegated-IPv6-Prefix" attribute reported in radius accounting packets? I just ran into an instance in our production network where I needed this information (which our radius server is not reporting because it can't record what it doesn't get) in our pro...
by Azendale
Sun Oct 09, 2016 10:47 pm
Forum: General
Topic: Suggestions for keeping a historical record of IPv6 Delegated prefixes
Replies: 0
Views: 294

Suggestions for keeping a historical record of IPv6 Delegated prefixes

I work for a smallish ISP. We deliver our service with PPPoE. We currently manage the PPPoE sessions with RADIUS (our server is a Freeradius server). For IPv4, the WAN address is recorded by the freeradius server from the accounting packets sent from the Mikrotik PPPoE servers. If any abuse complain...
by Azendale
Fri Aug 21, 2015 3:26 am
Forum: General
Topic: CRS: Filter packets ingress to an "access" port that are tagged
Replies: 1
Views: 537

Re: CRS: Filter packets ingress to an "access" port that are tagged

I did some further testing. Removing ether3 from VLAN 300 and putting the port under Switch > Settings > VLAN (tab) > "Drop If Invalid VLAN On Ports" (list) at the same time caused the traffic to get dropped. With some further testing, I realized that this means if you set the "access" port under Sw...
by Azendale
Fri Aug 21, 2015 2:51 am
Forum: General
Topic: CRS: Filter packets ingress to an "access" port that are tagged
Replies: 1
Views: 537

CRS: Filter packets ingress to an "access" port that are tagged

I have attached the config that I see this happening with on a CRS125-24G-1S-RM switch. What I'm seeing is that I have a machine connected to ether3 and to ether1. Both machines can be configured to use VLANs. The machine connected to ether1 has vlans 200,300 configured with 192.168.72.16/24 and 192...
by Azendale
Fri Feb 27, 2015 6:14 pm
Forum: General
Topic: CoDel support?
Replies: 45
Views: 13460

Re: CoDel support?

Firmware/router I was talking about in my last post: http://www.bufferbloat.net/projects/cer ... ease_Notes
by Azendale
Tue Feb 24, 2015 4:21 am
Forum: General
Topic: CoDel support?
Replies: 45
Views: 13460

Re: CoDel support?

I too would like to see CoDel support. This is the kind of stuff customers notice, without ever even having to know how or why its better. (I'm talking about the people that don't realize the traffic they are moving through their home router (say streaming video over tcp/http on multiple devices) an...
by Azendale
Sat Nov 22, 2014 7:10 pm
Forum: General
Topic: Adjust Queues based on volume?
Replies: 1
Views: 739

Adjust Queues based on volume?

I'm trying to implement Mikrotik routers at a University. One feature they want is to have "volume based shaping" as they call it. By that they mean setting a transfer limit after which your bandwidth slows down. What is the best way to do this on a mikrotik? I have seen some things were people writ...
by Azendale
Fri Nov 21, 2014 6:05 pm
Forum: General
Topic: Monitor for rougue DHCP servers with Nagios?
Replies: 0
Views: 672

Monitor for rougue DHCP servers with Nagios?

I know Mikrotik can do rouge DHCP server detection. While you can use the email tool to alert, I would really like this to flow into Nagios. I had two thoughts for how this could be done. First, I can give Nagios a SSH key, let it login to the router, and run a script to check. So, is there a way to...
by Azendale
Mon Nov 10, 2014 5:50 pm
Forum: General
Topic: How do I know what fiber a Mikrotik SFP will work with?
Replies: 7
Views: 2416

Re: How do I know what fiber a Mikrotik SFP will work with?

First you have to know if you have multi ore single mode. orange is normaly multi. I know it's not single mode. I was able to talk to one the of the people there when it was set up, and he says it's 62.5. The thing I'm not sure of is how to know what the various SFP's mikrotik makes are able to be ...
by Azendale
Mon Nov 10, 2014 6:24 am
Forum: General
Topic: How do I know what fiber a Mikrotik SFP will work with?
Replies: 7
Views: 2416

How do I know what fiber a Mikrotik SFP will work with?

How do I know what fiber a Mikrotik SFP will work with? I have some orange and some aqua fiber. From what I've read, the aqua should be able to do 1.25G and 10G. The orange, I'm not so sure. (It's an already installed senario that I've inherited). So, how do I know if an SFP is for 50 or 62.5 core f...
by Azendale
Sat Oct 25, 2014 8:34 pm
Forum: General
Topic: What is the "right" way to do a VPN between to mikrotiks?
Replies: 2
Views: 874

Re: What is the "right" way to do a VPN between to mikrotiks

Bump? Surely I'm not the only one that wants to do a secure VPN between mikrotiks without having TCP inside TCP drawbacks?
by Azendale
Wed Oct 01, 2014 7:45 pm
Forum: General
Topic: What is the "right" way to do a VPN between to mikrotiks?
Replies: 2
Views: 874

What is the "right" way to do a VPN between to mikrotiks?

I've heard some concerns about the security of some protocols (I think it was l2tp that I heard that wasn't that good unless you use specific settings (I think MSCHAP or something like that)). I would tend to be looking for something with a layer2 level, but layer 3 could also work. I thought openvp...
by Azendale
Wed Oct 01, 2014 7:34 pm
Forum: General
Topic: Report "Delegated-IPv6-Prefix" attribute for PPPoE
Replies: 200
Views: 39636

Re: Report "Delegated-IPv6-Prefix" attribute for PPPoE

I'm sorry, I read your response but just didn't get exactly what you are saying. You mention setting up a PD-client on the PPPoE server? this attribute is not working. Idea is - you set up DHCP-PD-client on your PPPoE server and get dynamic pool. Then you can set pool name in RADIUS from where prefi...
by Azendale
Tue Sep 23, 2014 2:35 am
Forum: General
Topic: Report "Delegated-IPv6-Prefix" attribute for PPPoE
Replies: 200
Views: 39636

Report "Delegated-IPv6-Prefix" attribute for PPPoE

See http://forum.mikrotik.com/viewtopic.php?f=2&t=85454&p=428369&hilit=DHCPv6+pppoe+prefix#p428369 I have also confirmed with a Packet Capture between the routerboard and radius server that that attribute (Delegated-IPv6-Prefix) is not sent, even though the pool on the Routerboard does show that a p...
by Azendale
Tue Sep 23, 2014 2:27 am
Forum: General
Topic: Got fq_codel yet?
Replies: 36
Views: 10979

Re: Got fq_codel yet?

I too would be quite interested in this.
by Azendale
Tue Sep 09, 2014 10:33 pm
Forum: General
Topic: Feauture request: OSPFv3 authentication
Replies: 0
Views: 503

Feauture request: OSPFv3 authentication

See http://forum.mikrotik.com/viewtopic.php ... 23#p419211 (and the thread it belongs to). It says that this is not supported.

Can we get OSPFv3 (OSPF for IPv6) authentication?
by Azendale
Wed Apr 02, 2014 9:03 am
Forum: Forwarding Protocols
Topic: Make OSPFv3 use Global IPv6 addresses instead of LinkLocal? [SOLVED]
Replies: 3
Views: 1392

Make OSPFv3 use Global IPv6 addresses instead of LinkLocal? [SOLVED]

Is there a way to make it so the router addresses used for the routes created by OSPFv3 is the global address of the router on that interface instead of the router's link local address?
by Azendale
Tue Apr 01, 2014 7:18 pm
Forum: General
Topic: OSPFv3 Authentication
Replies: 2
Views: 691

Re: OSPFv3 Authentication

I'm also interested in knowing if (how?) you can do OSPFv3 authentication in Mikrotik. If you can't, is there a place to request this feature?
by Azendale
Tue Apr 01, 2014 7:15 pm
Forum: Forwarding Protocols
Topic: OSPFv3 authentication with cisco
Replies: 4
Views: 2448

Re: OSPFv3 authentication with cisco

I think you can configure OSPF authetication as below /routing ospf interface add authentication=md5 authentication-key=1234 authentication-key-id=1 cost=\ 10 dead-interval=40s disabled=no hello-interval=10s instance-id=0 \ interface=all network-type=default passive=no priority=1 \ retransmit-interv...
by Azendale
Thu Feb 06, 2014 8:59 pm
Forum: General
Topic: Set Reset defaults for CPE senario?
Replies: 2
Views: 698

Set Reset defaults for CPE senario?

We (an ISP) are considering using Mikrotik routers for home (CPE) routers for our customers. Is there a way to control what default settings a routerboard goes to when it is reset? Would there be a way to set it so that the user can press a physical button if they end up locking themselves out, and ...