Community discussions

MikroTik App

Search found 13352 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 45
by rextended
Sun Feb 16, 2025 4:08 am
Forum: General
Topic: Firewall rules analysis
Replies: 73
Views: 3257

Re: Firewall rules analysis

I hope that my point of view is clear to you.
by rextended
Sun Feb 16, 2025 3:18 am
Forum: General
Topic: Firewall rules analysis
Replies: 73
Views: 3257

Re: Firewall rules analysis

Please define "inverted design", otherwise I can't understand what you mean, it gives rise to too many different interpretations. I hope you don't mean block what you need to block, but allow everything at the end ... It's weakness is novices break it more readily than an inverted design. ...
by rextended
Sun Feb 16, 2025 3:00 am
Forum: General
Topic: Firewall rules analysis
Replies: 73
Views: 3257

Re: Firewall rules analysis

It is used to allow the blind deaf and dumb user to access internet for the most part safely and in this it succeeds. Throw in another subnet, or something else and it quickly falls to pieces and ends up with bloated firewall rules in seconds flat. And here I stop reading, because my previous quest...
by rextended
Sun Feb 16, 2025 1:26 am
Forum: General
Topic: Firewall rules analysis
Replies: 73
Views: 3257

Re: Firewall rules analysis

I'm not referring to @anav but to everyone: I'm still waiting for an answer to the previous question. https://forum.mikrotik.com/viewtopic.php?t=214608#p1126560 @Josephny : It's best to clarify one concept at a time first. All the questions in one post are unmanageable, but we all agree on one very ...
by rextended
Sat Feb 15, 2025 5:53 pm
Forum: General
Topic: Firewall rules analysis
Replies: 73
Views: 3257

Re: Firewall rules analysis

Better to segment the problems first, rather than mix everything together. First question, Where is the default firewall flawed for a very simple standard connection between WAN and LAN? It is intended to consider what attacks could come from the internet and the firewall does not block. Leaving asi...
by rextended
Sat Feb 15, 2025 1:31 pm
Forum: Scripting
Topic: copying files
Replies: 10
Views: 572

Re: copying files

And then some users who feel like they are the second choice after FakeGPT, they are f–g about.
by rextended
Sat Feb 15, 2025 1:18 pm
Forum: General
Topic: Firewall rules analysis
Replies: 73
Views: 3257

Re: Firewall rules analysis

the issues may come the moment you start fiddling with firewall rules without really knowing what you are doing. Precisely, better to leave the defaults, or at least something that resembles them, not something that for you is only subjectively safer and for someone else can give unexpected problem...
by rextended
Thu Feb 13, 2025 6:37 pm
Forum: Scripting
Topic: copying files
Replies: 10
Views: 572

Re: copying files

Image
by rextended
Wed Feb 12, 2025 5:20 pm
Forum: General
Topic: /31 handoff
Replies: 7
Views: 651

Re: /31 handoff

sure we do have a 'CPE NAT' system,

I meant everything except that........
by rextended
Wed Feb 12, 2025 4:40 pm
Forum: General
Topic: Allowing Windows Update through firewall
Replies: 5
Views: 479

Re: Allowing Windows Update through firewall

Without my question, these details would not have come out.

Well it's very simple, configure the server to allow only the windows update and teamviewer services to connect to the public network.

Easy and clear, and in the RIGHT place to do that.

Right?
by rextended
Wed Feb 12, 2025 4:06 pm
Forum: General
Topic: Allowing Windows Update through firewall
Replies: 5
Views: 479

Re: Allowing Windows Update through firewall

What does it matter to you if your time is synchronized and Windows is up to date, if the rest of the world is cut off?
by rextended
Wed Feb 12, 2025 2:27 pm
Forum: General
Topic: Firewall rules analysis
Replies: 73
Views: 3257

Re: Firewall rules analysis

Default firewall rules are still here. https://forum.mikrotik.com/viewtopic.php?p=856824#p856824 drop-all-at-the-end should only be put in the input chain. It is obvious that the router must allow everything between the entire LAN and the external WAN, otherwise why did you put a router and connect ...
by rextended
Wed Feb 12, 2025 2:22 pm
Forum: General
Topic: Firewall rules analysis
Replies: 73
Views: 3257

Re: Firewall rules analysis

Is not present because it is not needed, you must not add random rules without know what you doing...
by rextended
Tue Feb 11, 2025 5:24 pm
Forum: General
Topic: /31 handoff
Replies: 7
Views: 651

Re: /31 handoff

I work for an Instant-Failover/Bonding company called Nepean Networks. One of the things we do, is hand off our Public IPs to clients Mikrotik routers. Who cares what the company name is, and all the other bells and whistles, with the question? It sounds more like an advertisement than a help reque...
by rextended
Tue Feb 11, 2025 4:36 pm
Forum: General
Topic: DoH max concurrent queries reached, ignoring query
Replies: 5
Views: 1254

Re: DoH max concurrent queries reached, ignoring query

doh-timeout=1h23m20s ???????? Who got up in the morning and wrote that b–t? You wait 1 hour and more for a DoH reply? Your ruouter act as DDoS server... Default parameters: address-list-extra-time=0s allow-remote-requests=yes cache-max-ttl=1w cache-size=2048KiB doh-max-concurrent-queries=50 doh-max-...
by rextended
Tue Feb 11, 2025 4:16 pm
Forum: Scripting
Topic: Script to create /tool/graphs/interface - Help for dummy
Replies: 6
Views: 743

Re: Script to create /tool/graphs/interface - Help for dummy

More simple and compatible with v6 and v7 :foreach iface in=[/interface ethernet find] do={ /tool graphing interface add store-on-disk=no interface=[/interface ethernet get $iface name] } :foreach iface in=[/interface find where type~"(ether|vlan|bridge)"] do={ /tool graphing interface add...
by rextended
Tue Feb 11, 2025 3:30 pm
Forum: Scripting
Topic: Script to create /tool/graphs/interface - Help for dummy
Replies: 6
Views: 743

Re: Script to create /tool/graphs/interface - Help for dummy

Since you can not choice the path of the graphs file, if your device use NAND or flash, do not do it...
by rextended
Tue Feb 11, 2025 1:12 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1916
Views: 612125

Re: 📣 WinBox 4 is here 📣

@teslasystems Probably because there are many like me who when they see this new little toy for fun of someone turn away and hope that the v3 lasts as long as possible... The transition from v6 to v7 didn't teach him anything... First you do something identical to v3, with the same features and aspe...
by rextended
Tue Feb 11, 2025 12:07 pm
Forum: General
Topic: BGP advertisement with two different upstreams
Replies: 8
Views: 603

Re: BGP advertisement with two different upstreams

From the descriptions you wrote, nothing is clear. Your connection provider must be informed and can check whether or not they receive publication requests from your router. If you want to publish another prefix, in addition to having the parameters on your correct LIR AFRINIC / APNIC / ARIN / LACNI...
by rextended
Tue Feb 11, 2025 11:27 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1916
Views: 612125

Re: 📣 WinBox 4 is here 📣

v4 Menu on the right, v3 Tabs on top...

v3 is more clear.
For example is clear separation between connection limits and other subsection, on v4 is all grouped together.
by rextended
Tue Feb 11, 2025 11:01 am
Forum: General
Topic: /interface print where [find name=ether2] -- not correct
Replies: 19
Views: 1121

Re: /interface print where [find name=ehter2] -- not correct

(try running "/interface/print where" ) Do error, is not valid. You add a space after where for sure (or more probably you remove all characters of a previous command but not the space). Simply compiler do error if where is not followed by something, and ignore it if is followed with a sp...
by rextended
Tue Feb 11, 2025 10:20 am
Forum: Beginner Basics
Topic: Strange /ip/dhcp-server/network entries [SOLVED]
Replies: 8
Views: 943

Re: Strange /ip/dhcp-server/network entries [SOLVED]

10.1.10.0 is a valid address, until is used inside a "LAN"... If you have, for example, a pool 10.1.10.0/24 (10.1.10.0-10.1.10.255) the pppoe can use 10.1.10.0 and 10.1.10.255 for go out on internet without problems. Then, that some software are badly written and do not work with .0 and .2...
by rextended
Mon Feb 10, 2025 8:57 pm
Forum: RouterBOARD hardware
Topic: CCR1036-12G-4S No boton Reset in motherboard.
Replies: 15
Views: 953

Re: CCR1036-12G-4S No boton Reset in motherboard.

if you don't plan on soldering a button... don't install 7.x or you'll lose a lot of administrative functionality with device-mode everytime..........
by rextended
Mon Feb 10, 2025 8:51 pm
Forum: RouterBOARD hardware
Topic: CCR1036-12G-4S No boton Reset in motherboard.
Replies: 15
Views: 953

Re: CCR1036-12G-4S No boton Reset in motherboard.

You need to be able to make contact between the two closest pieces of solder on the left or the rigth.

You may be able to do this better if you remove the card from the chassis.
by rextended
Mon Feb 10, 2025 8:44 pm
Forum: General
Topic: Firewall rules analysis
Replies: 73
Views: 3257

Re: Firewall rules analysis

Use "VPN" & IP access...

(expanded reply on previous post)


Wait @anav for further help
by rextended
Mon Feb 10, 2025 8:38 pm
Forum: General
Topic: Firewall rules analysis
Replies: 73
Views: 3257

Re: Firewall rules analysis

leave it only on one interface, like ether5 and use ether5 just for admin access, removing it from any bridge or other functions delete ether5 from bridge ports /interface list add name=MGMT /interface list member add interface=ether5 list=MGMT /tool mac-server set allowed-interface-list=MGMT /tool ...
by rextended
Mon Feb 10, 2025 8:27 pm
Forum: RouterBOARD hardware
Topic: CCR1036-12G-4S No boton Reset in motherboard.
Replies: 15
Views: 953

Re: CCR1036-12G-4S No boton Reset in motherboard.

I purchased the CCR1036-12G-4S used and it has an administrator password So, you bought it used, coincidentally the person who sold it to you doesn't have the password, coincidentally you can't return it and coincidentally you are in a hurry... To me it only smells like a stolen routerboard (not di...
by rextended
Mon Feb 10, 2025 8:17 pm
Forum: General
Topic: Firewall rules analysis
Replies: 73
Views: 3257

Re: Firewall rules analysis

just a peek here and there... /interface bridge port add bridge=bridge interface=*B internal-path-cost=10 path-cost=10 add bridge=bridge interface=*C internal-path-cost=10 path-cost=10 unused entries (deleted) still exist on bridge ports /interface list member add interface=ether1 list=TRUSTED Serio...
by rextended
Mon Feb 10, 2025 7:53 pm
Forum: General
Topic: Firewall rules analysis
Replies: 73
Views: 3257

Re: Firewall rules analysis

# Interface not running # disabled # PPTP connections are considered unsafe, it is suggested to use a more modern VPN protocol instead & Co. are present on new version export Graphing causes the internal NAND/flash to wear out unnecessarily. /tool graphing interface add add interface=wireguard1...
by rextended
Mon Feb 10, 2025 7:50 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1916
Views: 612125

Re: 📣 WinBox 4 is here 📣

We went from something that worked fine on windows and emulated well on others, most of the time,
to something that doesn't work as well as the old one anywhere...
by rextended
Mon Feb 10, 2025 7:31 pm
Forum: Beginner Basics
Topic: Strange /ip/dhcp-server/network entries [SOLVED]
Replies: 8
Views: 943

Re: Strange /ip/dhcp-server/network entries [SOLVED]

The first one is "wrong". address=10.1.10.0/32 with netmask=24 makes no sense, but it is strange that it is the result of an upgrade, or, if it is, there may well be other things you have not noticed. Is not wrong, is just for exactly 10.1.10.0 (/32) that is provided dns-server=10.1.10.1 ...
by rextended
Mon Feb 10, 2025 7:26 pm
Forum: Scripting
Topic: DHCP Lease script to assign IP pool
Replies: 8
Views: 581

Re: DHCP Lease script to assign IP pool

I don't want to create 2nd bridge and use 2nd DHCP server so my thought was it was possible through script. Question already closed. There are plenty of ways to do this, but if you don't know a fixed lease from a dynamic one, I think it's extremely difficult to do this by reading here and there on ...
by rextended
Mon Feb 10, 2025 7:18 pm
Forum: Scripting
Topic: DHCP Lease script to assign IP pool
Replies: 8
Views: 581

Re: DHCP Lease script to assign IP pool

You try to set something on a dynamic lease? Are you trying to set (modify / change) something in a dynamic lease? I don't think more or less correct English can make much difference in this question. You haven't answered the question yet. The answer can be yes or no, not a comment. And I already w...
by rextended
Mon Feb 10, 2025 5:36 pm
Forum: Scripting
Topic: Fetch with https is not saving to flash from script
Replies: 2
Views: 315

Re: Fetch with https is not saving to flash from script

I do not read more after mode=https

If you use url you must not use mode
by rextended
Mon Feb 10, 2025 5:32 pm
Forum: Scripting
Topic: DHCP Lease script to assign IP pool
Replies: 8
Views: 581

Re: DHCP Lease script to assign IP pool

In what you wrote I didn't read the answer.

It is implicit that it cannot be done in dynamic leases, but only in static ones.
It is difficult for a smartphone to connect via ethernet,
it is likely that a laptop can connect (but with two different MACs) to both (and even simultaneously)
by rextended
Mon Feb 10, 2025 5:28 pm
Forum: General
Topic: /interface print where [find name=ether2] -- not correct
Replies: 19
Views: 1121

Re: /interface print where [find name=ehter2] -- not correct

Well, ~11 years on 25th have passed since 2014... and I'm not a native English speaker... :roll:
by rextended
Mon Feb 10, 2025 5:23 pm
Forum: General
Topic: /interface print where [find name=ether2] -- not correct
Replies: 19
Views: 1121

Re: /interface print where [find name=ehter2] -- not correct

Leave me the time to check and finish the post... 8) :lol:
by rextended
Mon Feb 10, 2025 4:59 pm
Forum: General
Topic: /interface print where [find name=ether2] -- not correct
Replies: 19
Views: 1121

Re: /interface print where [find name=ehter2] -- not correct

@all do not mix IDs and (print) line number. if you write remove X is readed as remove number= X If X is one ID, is directly removed, If X is one number, is internally converted in one ID first, based on latest "print" provides list of interfaces in format alien to where ... and print simp...
by rextended
Mon Feb 10, 2025 3:35 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

I correct the description, it is misleading... To add default fasttrak when updating from ANY v7 previous version, just paste this into the terminal (barring arbitrary changes to the default configuration already made). New devices netinstalled with beta4 and later, or restored with default configur...
by rextended
Mon Feb 10, 2025 2:51 pm
Forum: Scripting
Topic: pppooe uptime log
Replies: 2
Views: 350

Re: pppooe uptime log

It's full of errors and invented commands. Did you ask StupidGPT for the script??? { /interface :local ifname "pppoe-out1" :local ifget [get $ifname] :local ifdown ($ifget->"last-link-down-time") :local ifup ($ifget->"last-link-up-time") :local ifrun ($ifget->"runn...
by rextended
Mon Feb 10, 2025 2:46 pm
Forum: Scripting
Topic: DHCP Lease script to assign IP pool
Replies: 8
Views: 581

Re: DHCP Lease script to assign IP pool

You try to set something on a dynamic lease?
by rextended
Mon Feb 10, 2025 2:08 pm
Forum: Scripting
Topic: Cleaning script code
Replies: 2
Views: 363

Re: Cleaning script code

https://forum.mikrotik.com/viewtopic.php?p=965180#p965180 Replace with _ any unusable filename characters, this can be applied everywhere before create a filename to be used... Or simply use original ether1 MAC address, as already suggested: :global remdots do={ :local string $1 :if (([:typeof $stri...
by rextended
Mon Feb 10, 2025 1:56 pm
Forum: Scripting
Topic: Log find time - function rOS 7.17
Replies: 1
Views: 370

Re: Log find time - function rOS 7.17

time is a string. [] /log> :put ("A" > "B") Script Error: cannot compare if string is more than string [] /log> :put ("A" < "B") Script Error: cannot compare if string is less than string [] /log> :put ("A" = "B") false [] /log> :put ("...
by rextended
Sat Feb 08, 2025 1:23 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

by rextended
Sat Feb 08, 2025 12:59 pm
Forum: Beginner Basics
Topic: Buying - RB1100AHx4 Dude Edition - Questions about Firewall
Replies: 24
Views: 18701

Re: Buying - RB1100AHx4 Dude Edition - Questions about Firewall

@Jotne yes,

I reorder parameters and align *pure* default items for better readability, but the line is the same, for keep exactly the defaults.
by rextended
Sat Feb 08, 2025 10:07 am
Forum: General
Topic: Blocking admin services - Firewall rules
Replies: 30
Views: 3439

Re: Blocking admin services - Firewall rules

Only service that that you like to have open should be open, all other blocked. That you need to block 53 tells me that your fw are wrongly setup. @Jotne Mikrotik default filters are active I don't believe it. And even if it did, you probably changed something else that made it not work. The firewa...
by rextended
Fri Feb 07, 2025 7:47 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17.2 [stable] is released!

I don't believe it.
And even if it did, you probably changed something else that made it not work.
by rextended
Fri Feb 07, 2025 10:33 am
Forum: Wireless Networking
Topic: Removing Mikrotik elements from beacons
Replies: 6
Views: 1996

Re: Removing Mikrotik elements from beacons

Blinders like on horses...
by rextended
Wed Feb 05, 2025 10:43 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17.1 [stable] is released!

stopped all upgrades in production so we are stucked on 7.16.2 . device-mode is a vendor integrated and forced landmine . Some of operators will left their devices under v7.17 and using them till lifetime replace with another vendor , +∞ I understand the password security required by EU regulation,...
by rextended
Mon Feb 03, 2025 10:38 am
Forum: General
Topic: Classless-Routes not being added by dhcp-client [SOLVED]
Replies: 27
Views: 11332

Re: Classless-Routes not being added by dhcp-client [SOLVED]

:D ... a fresh brew ... is magic ! Using 0x20C0A8640100000000202278FFF40000000000647FFF05 provide not correct, but not wrong, results: 192.168.100.1/32 via 0.0.0.0 -> must be like 192.168.100.1/32 via <DHCP client interface> 34.120.255.244/32 via 0.0.0.0 -> must be like 34.120.255.244/32 via <DHCP ...
by rextended
Sun Feb 02, 2025 12:30 am
Forum: Beginner Basics
Topic: Forum rules
Replies: 39
Views: 152978

Re: Forum rules

¿Che cosa?
Is not Spanish...
by rextended
Sat Feb 01, 2025 1:26 pm
Forum: Beginner Basics
Topic: i need some help
Replies: 2
Views: 875

Re: i need some help

by rextended
Sat Feb 01, 2025 1:06 pm
Forum: General
Topic: Blink command, how to use?
Replies: 2
Views: 2490

Re: Blink command, how to use?

The blinking must be supported from ethernet chipset.
For example, on my CRS112 work.
by rextended
Sat Feb 01, 2025 12:50 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

When you have a special need to have a serial number in messages, why don't you add it to the device identity of your devices? So instead of hAP-test you call it hAP-test-E1548DC8753B Exactly, is wrong call all the devices "hAP ac^2". Every single device on my network have different names...
by rextended
Sat Feb 01, 2025 12:48 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

@Jotne if board-name ~ "x86" use [/system license get software-id] if board-name ~ "CHR" use [/system license get system-id] on other cases use [/system routerboard get serial-number] or simply: [/int eth get ([find]->0) orig-mac-address] since at least all RouterBOARD have one ...
by rextended
Sat Feb 01, 2025 10:59 am
Forum: Scripting
Topic: getting address of veth strips host part of ipv6
Replies: 2
Views: 982

Re: getting address of veth strips host part of ipv6

As usual, you forgot which version you're talking about. I don't see json in the OP. [rex@MATRIX] > :global data ({"extDns"="blabla"; "static"=("172.16.0.2/24","fdc7:affe:affe:1::10/64"); "dyn"=("2a02::10/64")}) [rex@MATRIX] > :pu...
by rextended
Sat Feb 01, 2025 10:33 am
Forum: Beginner Basics
Topic: Forum rules
Replies: 39
Views: 152978

Re: Forum rules

Che differenza fa?
[What difference does it make?]
by rextended
Sat Feb 01, 2025 10:17 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17.1 [stable] is released!

Like I said, I (or MikroTik) would not have deleted it. It was a volunteer mod. IMO @normis is on the best path. What matters most is confidence and trust in the forum process. Forum moderation suggestions: The goal is a transparent audit trail doesn't leave much room for speculation or conspiracy ...
by rextended
Fri Jan 31, 2025 10:29 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17.1 [stable] is released!

Since I saw the OP's screenshot of the deleted post and checked every line, it was all bullshit. The only way to exploit those vulnerabilities in libraries used by RouterOS was to hack RouterOS first, to execute arbitrary commands as super-admin. So, who cares about those problems, if to exploit the...
by rextended
Thu Jan 30, 2025 6:17 pm
Forum: General
Topic: Log: a lot of logs
Replies: 12
Views: 2417

Re: Log: a lot of logs

what yo do not want log anymore?
(screenshot is better to not omit details)
by rextended
Thu Jan 30, 2025 10:03 am
Forum: General
Topic: Log: a lot of logs
Replies: 12
Views: 2417

Re: Log: a lot of garbage

How can I remove unnecessary (garbage) from the log?
You have done what I wrote on post #8?
viewtopic.php?t=214019#p1121110
by rextended
Wed Jan 29, 2025 11:08 pm
Forum: General
Topic: Strange symbol in firmware version 7.17
Replies: 6
Views: 1464

Re: Strange symbol in firmware version 7.17

This is because you do not align the factory firmware, and new firmware have some misalignment... Install exactly 7.6, upgrade the firmware, reboot to be sure current firmware is 7.6 then install this: https://box.mikrotik.com/f/3bd8cc7b2a6545228377/?dl=1 Next you can install correctly 7.17 https://...
by rextended
Tue Jan 28, 2025 8:34 pm
Forum: Scripting
Topic: Is there a Script equivalent of "GoTo"?
Replies: 16
Views: 1700

Re: Is there a Script equivalent of "GoTo"?

In a RouterOS script is there an equivalent to a GoTo statement in Basic?

NO. (dot)

Convert that section on one function and call it only when is needed. Easy.
by rextended
Tue Jan 28, 2025 8:00 pm
Forum: General
Topic: What to buy
Replies: 31
Views: 2483

Re: What to buy

RB1100AHx4 do not have SFP and all ports are only gigabit.
by rextended
Tue Jan 28, 2025 7:49 pm
Forum: Scripting
Topic: Persistent Environment Variables [SOLVED]
Replies: 60
Views: 46304

Re: Persistent Environment Variables [SOLVED]

Some tests on vars that do not have sub-arrays... { :global globalVars [:toarray ""] :put $globalVars :set ($globalVars->"testArray") [:toarray ""] :set ($globalVars->"testArray"->"value") [:toarray "a,b"] :set ($globalVars->"testArray...
by rextended
Tue Jan 28, 2025 5:13 pm
Forum: General
Topic: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?
Replies: 51
Views: 5152

Re: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?

Then in the future, and easily too (given how people with the "security flag" start using DoH, https and other bullshit that worsen management and do not increase security at all), I see that web pages will no longer be rendered by the browser, but interactive images and interactive videos...
by rextended
Tue Jan 28, 2025 5:00 pm
Forum: General
Topic: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?
Replies: 51
Views: 5152

Re: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?

It would be enough for all users to agree and boycott the products in the EXCESSIVE advertising banners, sending protest emails to the companies in question, and they would stop advertising in that way, knowing that it would backfire on them... I understand those who try to earn money with what they...
by rextended
Tue Jan 28, 2025 4:06 pm
Forum: General
Topic: Winbox 4 does not display system note correctly
Replies: 5
Views: 1113

Re: Winbox 4 does not display system note correctly

Why do not post this on dedicated winbox 4 topic instead of uselessly open another topic?
by rextended
Tue Jan 28, 2025 3:38 pm
Forum: Scripting
Topic: First time scripting firewall rules form Mikrotik
Replies: 2
Views: 1142

Re: First time scripting firewall rules form Mikrotik

CRS320-8P-8B-4S+RM is a switch, not a router. Do not expect more speed than aggregated 200/300Mbps... Default firewall rules and config are the best security for who copy & paste other scripts randomly because do not know RouterOS. The first security breach is someone that think that can randoml...
by rextended
Tue Jan 28, 2025 1:15 pm
Forum: Scripting
Topic: Persistent Environment Variables [SOLVED]
Replies: 60
Views: 46304

Re: Persistent Environment Variables [SOLVED]

The function still have problems after 6 years... Refitted to avoid errors. Also added the ability to delete the "variable" if delete=yes is specified as parameter. :global l7var do={ /ip firewall layer7-protocol :local varName [:tostr $1] :local varNewValue [:tostr $2] :local valuePresent...
by rextended
Tue Jan 28, 2025 12:31 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17 [stable] is released!

CCR2004-1G-12S-2XS -------DEAD

You try the upgrade on lab on another CCR2004-1G-12S-2XS with same software and same backup before update?
by rextended
Tue Jan 28, 2025 11:35 am
Forum: Scripting
Topic: Enhanced IP Scan with Vendor and Additional Name Sources
Replies: 26
Views: 5211

Re: Enhanced IP Scan with Vendor and Additional Name Sources

#file
#                here ↓
    :local filename ("IP-Scan_".[/system/identity get value-name=name]."_".$scanInterface."_".$ds."_".$ts)
by rextended
Tue Jan 28, 2025 11:05 am
Forum: Scripting
Topic: not run from Script
Replies: 3
Views: 1062

Re: not run from Script

Leave him alone, he's just taking the piss out of you.
by rextended
Tue Jan 28, 2025 10:23 am
Forum: General
Topic: What to buy
Replies: 31
Views: 2483

Re: What to buy

Yes but, 30 clients, at what speed each? I believe maximum speed will be 250mbps, RB5009 will be capable of that? Math? 30 * 250 = 7500Mbps... Yu have a link at 10Gbps? Official Ethernet test results: Routing 25 simple queues 512 byte 4612 Mbps Since I do not think all clients download 250Mbps cont...
by rextended
Mon Jan 27, 2025 7:03 pm
Forum: Wireless Networking
Topic: Removing Mikrotik elements from beacons
Replies: 6
Views: 1996

Re: Removing Mikrotik elements from beacons

"Rogues are very keen in their profession, and know already much more than we can teach them."
by rextended
Mon Jan 27, 2025 6:37 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5902

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan

@eddieb First, these function will only work on 7.17+ , and must have a /interface/bridge with vlan-filtering=yes enabled. 7.17 is not... uhm..... ***************************** $prettyprint [$pvid2array [:rndnum from=257 to= 4094 ]] I strongly advise against using "random" VLANs. VLANs sh...
by rextended
Mon Jan 27, 2025 5:51 pm
Forum: RouterBOARD hardware
Topic: Bar code with admin pass for new reversions
Replies: 1
Views: 1323

Re: Bar code with admin pass for new reversions

Dozen? (One?)

If you do it for work, is incredible that you do not use already netinstall/flashfig with config scripts where password is not needed at all...
by rextended
Mon Jan 27, 2025 3:06 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17 [stable] is released!

It's like evaluating a restaurant in the center of Rome where in the last few years 10 people have complained that the food was bad...
In comparison to 199990 people who haven't written anything...
by rextended
Mon Jan 27, 2025 2:56 pm
Forum: General
Topic: What to buy
Replies: 31
Views: 2483

Re: What to buy

I believe maximum is 30 clients, the RB5009UG gonna do its job in this situation?
Yes but, 30 clients, at what speed each?
by rextended
Mon Jan 27, 2025 2:51 pm
Forum: General
Topic: What to buy
Replies: 31
Views: 2483

Re: What to buy

Do not buy switch for use it as router. Ooooo, no one mentioned this actually! Im in need for router! All (not really all, but let's ignore this) MikroTik devices, RouterBOARD, have RouterOS inside, even the switches. All RouterOS features are available in all devices (except things that require sp...
by rextended
Mon Jan 27, 2025 2:33 pm
Forum: General
Topic: What to buy
Replies: 31
Views: 2483

Re: What to buy

Do not buy switch for use it as router.
by rextended
Sun Jan 26, 2025 2:41 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

Instead of re-writing my script for no reason No reason? I show you how must be coded corectly to avoid use scripting style that casually works... The missing "" are not only the problem, expect broken it again on future versions.... :local date [/system clock get date]; # on this line: u...
by rextended
Sat Jan 25, 2025 11:49 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

by rextended
Sat Jan 25, 2025 11:38 am
Forum: General
Topic: Default values [SOLVED]
Replies: 15
Views: 2433

Re: Default values [SOLVED]

@anav Where is??? even if you specificaties, the command will reset the whole interface Already wroted, with explanation.... https://forum.mikrotik.com/viewtopic.php?t=214154#p1121429 (obviously MTU and L2MTU are 666 and 777 just for test..........) [rex@edge-MATRIX] /interface/ethernet> export # 2...
by rextended
Fri Jan 24, 2025 11:42 pm
Forum: Scripting
Topic: Garbage collect old routes and duplicate routes
Replies: 21
Views: 2124

Re: Garbage collect old routes and duplicate routes

(when MikroTik have done) generic tip: do not use firewall to do routing job....
by rextended
Fri Jan 24, 2025 8:14 pm
Forum: General
Topic: Best way to disable IPv6 advertisement only to specific clients? [SOLVED]
Replies: 13
Views: 2260

Re: Best way to disable IPv6 advertisement only to specific clients? [SOLVED]

multicast is multicast, not somenotcast..................
by rextended
Fri Jan 24, 2025 8:11 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17 [stable] is released!

Thanks... But for what??? 🤷‍♂️
Helping @evilsabc, a generous and substantial commitment IMO.
Ah, I thought you had a similar problem, but I either didn't read it or inadvertently ignored it.
by rextended
Fri Jan 24, 2025 8:10 pm
Forum: Scripting
Topic: Functions and function parameters
Replies: 69
Views: 128237

Re: Functions and function parameters

(I do not check) Global variables are inside supout???
It's a question. They are not visible in their supout viewer, but who knows...
Reasoning in a similar way, even small files could be sent inside supout... :lol:
by rextended
Fri Jan 24, 2025 8:06 pm
Forum: Scripting
Topic: Functions and function parameters
Replies: 69
Views: 128237

Re: Functions and function parameters

Because MT guys will see them in supout files :lol: . Of course, I'm not blaming them for anything, it's just a normal security measure. Not sure if they can see environment variables, but script code is fully visible, that's why I've placed all sensitive data in the file. (I do not check) Global v...
by rextended
Fri Jan 24, 2025 8:03 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17 [stable] is released!

@rextended Thank you, and well done!
Thanks... But for what??? 🤷‍♂️
by rextended
Fri Jan 24, 2025 7:51 pm
Forum: Scripting
Topic: Functions and function parameters
Replies: 69
Views: 128237

Re: Functions and function parameters

And what's stopping you from using global variables, or better, if username, password, etc. are defined in the script, put them right inside the function.............. ... :local doFetch do={ :local SrvData [:deserialize value=[/file get $auth contents] from=json] :local Dest $path /tool fetch src-p...
by rextended
Fri Jan 24, 2025 7:01 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17 [stable] is released!

The problem is not the configuration, but probably the database files where is wroted the configuration are unreadable from 7.17 for some reason... create supout.rif and send it to mikrotik support with problem description.
by rextended
Fri Jan 24, 2025 6:30 pm
Forum: Scripting
Topic: Functions and function parameters
Replies: 69
Views: 128237

Re: Functions and function parameters

It doesn't make any sense that the function, when declared, sees the local variables... And whatever happens, you wrote it wrong, if the function ever sees local variables.... { :local TestVar "123" :local SomeFunc do={ :local TestVar ; # missing this :log info $TestVar } $SomeFunc } You c...
by rextended
Fri Jan 24, 2025 6:17 pm
Forum: Scripting
Topic: Garbage collect old routes and duplicate routes
Replies: 21
Views: 2124

Re: Garbage collect old routes and duplicate routes

Tip n.1 for tip n.1: Use routing / rules. Each item has it's own tool.... when MikroTik finally add address-lists to routing rules........................
by rextended
Fri Jan 24, 2025 6:12 pm
Forum: General
Topic: Default values [SOLVED]
Replies: 15
Views: 2433

Re: Default values [SOLVED]

I like corerct syntax and avoid shorting for unreadabilty.
I dislike full syntax but not where:
/interface ethernet reset numbers=[/interface ethernet find where default-name=ether1]
by rextended
Fri Jan 24, 2025 6:06 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17 [stable] is released!

DO NOT PUT FILE ON FORUM Well, do one "/export show-sensitive file=myexport" and save the export out of the Router, to program the router once v17 is installed, and resetted to empty default first. If you do not use old CAPsMAN at all, consider uninstall wireless, since CCR2116-12G-4S+ do ...
by rextended
Fri Jan 24, 2025 5:39 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17 [stable] is released!

Ok, also RouterBOOT setttings and packages are ok. You have one backup of the configuration? Old config can not reappear just putting back 7.15.3.... Download those, drag and drop inside winbox, and after that go on system / packages and press downgrade https://download.mikrotik.com/routeros/7.15.3/...
by rextended
Fri Jan 24, 2025 5:32 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17 [stable] is released!

device-mode is Ok, RouterBOOT (firmware) is Ok, Partition is OK, still missing the rest.......................................
if you still do want do it manually one by one....
/system package print detail
/system routerboard settings print
by rextended
Fri Jan 24, 2025 5:26 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17 [stable] is released!

and
/system ; package print detail ; routerboard settings print ; /partition print detail
?
(if I write that line, you must copy and paste all line...)
by rextended
Fri Jan 24, 2025 5:18 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17 [stable] is released!

DO NOT POST serial-number!
/system ; package print detail ; device-mode print ; routerboard ; print ; settings print ; /partition print detail
results?
by rextended
Fri Jan 24, 2025 4:59 pm
Forum: General
Topic: Default values [SOLVED]
Replies: 15
Views: 2433

Re: Default values [SOLVED]

Stop suggest using "0" and use interface name. Ignoring the i*** of change randomly the MTU, the correct syntax is set ether1 mtu=1500 and [find] must not be used alone, because change everything, not only that interface. /interface ethernet reset NOT exist on v6 (exist only reset-counters...
by rextended
Fri Jan 24, 2025 4:54 pm
Forum: Scripting
Topic: Garbage collect old routes and duplicate routes
Replies: 21
Views: 2124

Re: Garbage collect old routes and duplicate routes

This produce same output at the end, but is just for progam in "nice" way (avoid duplicates, avoid deleting what must be rewrited, etc.).

Anyway, the important thing is the rest, which I think you understood from my suggestion.
by rextended
Fri Jan 24, 2025 4:50 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17 [stable] is released!

@evilsabc
For use netinstall to reinstall 7.15.3 and reload backup, you must first enable it on device-mode.

press reset button after run this code

/system device-mode update activation-timeout=60s mode=advanced install-any-version=yes partitions=yes routerboard=yes
by rextended
Fri Jan 24, 2025 4:41 pm
Forum: Scripting
Topic: Garbage collect old routes and duplicate routes
Replies: 21
Views: 2124

Re: Garbage collect old routes and duplicate routes

Basically, yes, but for be more "nice" on the point 2: on foreach cycle at the same time you UPDATE the comment if the rule already exist AND add new rules with :timestamp.

This do not delete what already exist (and must be keeped) and do not (temporarly) duplicate rules.
by rextended
Fri Jan 24, 2025 4:05 pm
Forum: Scripting
Topic: Updating CA root certs regularly [SOLVED]
Replies: 37
Views: 16322

Re: Updating CA root certs regularly [SOLVED]

New for Mozilla https://www.ccadb.org ( https://ccadb.my.salesforce-sites.com/mozilla/IncludedRootsPEMTxt?TrustBitsInclude=Websites ) /file print file=ccadb.txt :delay 1s set ccadb.txt content="-----BEGIN CERTIFICATE-----\r\ \nMIIDrzCCApegAwIBAgIQCDvgVpBCRrGhdWrJWZHHSjANBgkqhkiG9w0BAQUFADBh\r\ ...
by rextended
Fri Jan 24, 2025 3:50 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17 [stable] is released!

I'm just wondering if I did something in the past to import all those certs, and I just cannot remember it. 😊 Yes, you read this topic and apply the script. https://forum.mikrotik.com/viewtopic.php?p=1080348#p831111 @CGGXANNX never trust intermediate sites. https://forum.mikrotik.com/viewtopic.php?...
by rextended
Fri Jan 24, 2025 3:38 pm
Forum: Scripting
Topic: Garbage collect old routes and duplicate routes
Replies: 21
Views: 2124

Re: Garbage collect old routes and duplicate routes

I won't write it down, but I'll give you an idea. Scroll through the list of addresses. For each of theroutes you find that are the same as the ones you need, update the comment with a prefix and today's date (for example "$comment 2025/01/24 14:30") add the routes that don't exist, always...
by rextended
Fri Jan 24, 2025 3:25 pm
Forum: Scripting
Topic: simple lan side failover
Replies: 2
Views: 1039

Re: simple lan side failover

Do not duplicate requests.

viewtopic.php?p=1121356#p1121356
by rextended
Thu Jan 23, 2025 10:06 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

Export also the scheduler, how can check if you put all necessary policies? /system clock :local d [get date] :local t [get time] :local z [get time-zone-name] /system identity :local n [get name] /system backup save name=email dont-encrypt=no encryption=aes-sha256 password=pippo :delay 2s /tool e-m...
by rextended
Thu Jan 23, 2025 9:58 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

I think it's actually a data alignment problem in the NAND, since the backup "bios" itself is started only by holding down the reset button before turning on the device, or by selecting "force backup booter" item in system/routerboard/settings. Also old 3.x and 6.x do not longer ...
by rextended
Thu Jan 23, 2025 9:50 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

Only on 5 occasions MikroTik provide packages for change "any" backup version on 6.29.1 for 3.24 backup, on 6.40.7 for 3.41 backup, on 6.43.7 for 6.43.7 backup, on 6.49.7 for 6.43.7 backup, and on 7.6 for 7.6 backup. My 2017 post already explain how... https://forum.mikrotik.com/viewtopic....
by rextended
Thu Jan 23, 2025 9:37 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

What is your backup firmware?? You must install and use 7.6 RouterBOOT and RouterOS do not work with other version of current RouerBOOT (you already know that RouterBOOT is not RouterOS, I write that for the others...) when trying to enable the feature, do the following: a) upgrade or downgrade the ...
by rextended
Thu Jan 23, 2025 9:26 pm
Forum: General
Topic: MikroTik routers Hijacked by botnet
Replies: 9
Views: 1641

Re: MikroTik routers Hijacked by botnet

So, the current version 6.49.17 and 7.17 of ROS are presumably not affected by these previously discovered vulnerabilities assuming the default admin user is disabled and replaced with once with complex password, management access to router restricted to specific private IPs (so no SSH/Winbox from ...
by rextended
Thu Jan 23, 2025 9:18 pm
Forum: The Dude
Topic: Add custom tool for routerboard upgrade
Replies: 6
Views: 1263

Re: Add custom tool for routerboard upgrade

I cannot simply allow routers to auto-update or I would risk one router rebooting while another is still downloading. Understand the point. Yes, you can. The auto-upgrade (of RouterBOOT / firmware / "BIOS") do not cause reboot on any way. Simply next time RouterBOARD reboot for some reaso...
by rextended
Thu Jan 23, 2025 7:07 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17 [stable] is released!

As usually, "you" forget to write history of all previous RouerOS versions installed.
by rextended
Thu Jan 23, 2025 7:04 pm
Forum: The Dude
Topic: Add custom tool for routerboard upgrade
Replies: 6
Views: 1263

Re: Add custom tool for routerboard upgrade

This is not a routerboard / RouterOS upgrade, this is a firmware ("bios" / RouterBOOT) upgrade inside the RouterBOARD. Enable auto-upgrade suffice, is useless upgrade the "bios" because often still the same for years, because inside change only version number for follow RouterOS ...
by rextended
Thu Jan 23, 2025 6:54 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

...
by rextended
Thu Jan 23, 2025 6:32 pm
Forum: General
Topic: MikroTik routers Hijacked by botnet
Replies: 9
Views: 1641

Re: MikroTik routers Hijacked by botnet

Still falling everytime into the same stupid speeches. Are you able to understand well what is written??? MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to supe...
by rextended
Thu Jan 23, 2025 6:23 pm
Forum: General
Topic: PoE status on boot
Replies: 12
Views: 2261

Re: PoE status on boot

It doesn't matter how the relay is connected for be powered from mAP when is forced-on,
but what does it do (the relay)?
Is the contact normally open or normally closed?
What does the contact control?
The relay change power source of the mAP?

Be more specific.
by rextended
Thu Jan 23, 2025 6:20 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17 [stable] is released!

No, what are the certs name (not the issuer, but the name on routeros)?
by rextended
Thu Jan 23, 2025 3:33 pm
Forum: General
Topic: PoE status on boot
Replies: 12
Views: 2261

Re: PoE status

Hi, Can You add option to set PoE status on boot? For example: i have PoE "forced on" on eth2, but when there is a power outage, after restarting the port will be off. (you can set on, off, previous state - on boot). Just like in smart plug :) Never happen to me, hardware and RouterOS use...
by rextended
Thu Jan 23, 2025 2:59 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

Yes, but the first implementations lock "everything", so this caused many testers to skip any testing...
by rextended
Thu Jan 23, 2025 2:46 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

Well, no one reported it for the testing (beta and rc) releases...
Because this time with device-mode s–t no one want lock his devices, so less persons than before do tests...
by rextended
Thu Jan 23, 2025 2:43 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

I AM NOT an expert on the file system used, but in the past updates left space occupied on the disk not assigned to any file. A "fsck" solved it by releasing the space. This happened in x86 and CHR (mounted separately the disk on ubuntu for launch "fsck"), but probably given the ...
by rextended
Thu Jan 23, 2025 2:36 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

If you think about it, it's the only logical solution for those stuck on 7.16.2, which obviously doesn't concern those who have already installed 7.17 or 7.18beta2. What I wonder is why if I think about it in a few moments, that I AM NOT PAID TO DO IT, why those who are paid by MikroTik to do things...
by rextended
Thu Jan 23, 2025 2:27 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

Then original question stands - are there any alternatives to netinstall...
They should make 7.16.3 (which would be the same size as the kernel that goes with it) with the space fix,
mandatory before moving to 7.17.x or 7.18.x
That way you would have the problem already solved.
by rextended
Thu Jan 23, 2025 1:48 pm
Forum: General
Topic: Log: a lot of logs
Replies: 12
Views: 2417

Re: Log: a lot of garbage

Please change the title like "I do not understand correctly how set the logs", is not a RouterOS problem. Now I'm writing you what the others who answered did NOT deduce from your screenshot... @K0NCTANT1N You completely got it all wrong. !ntp also logs literally everything, except ntp... ...
by rextended
Thu Jan 23, 2025 1:42 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

on [successful] upgrade or netinstall


Simply the "fix" is not installed until is not successfully installed the 7.18beta2.
The fix is for future versions, not to fix current.
by rextended
Thu Jan 23, 2025 11:28 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

More CEF features are in development for the next betas
well..
by rextended
Wed Jan 22, 2025 2:30 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

...
by rextended
Wed Jan 22, 2025 1:46 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17 [stable] is released!

Why this do not work since 7.17??? (on all 7.16.2 and less, included v6, work) /sys log action set [find] disk-file-name="/log" (work without the /) Those, and other points where can be set a path, with "/" work correctly: /ip hotspot profile set [find default=yes] html-directory...
by rextended
Wed Jan 22, 2025 1:40 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

Why this do not work since 7.17??? (on all 7.16.2 and less, included v6, work) /sys log action set [find] disk-file-name="/log" (work without the /) Those, and other points where can be set a path, with "/" work correctly: /ip hotspot profile set [find default=yes] html-directory...
by rextended
Wed Jan 22, 2025 1:36 pm
Forum: Scripting
Topic: :execute output to console? Or any other method?
Replies: 17
Views: 3030

Re: :execute output to console? Or any other method?

Whatever happens, this doesn't mean that if you need help, I won't give it to you. Remember that no one is infallible. I often make mistakes too, especially with RouterOS that changes things with each version..... For example... this do NOT work on 7.17+ but work on 7.16.2 and less (also on v6)... ...
by rextended
Wed Jan 22, 2025 1:07 pm
Forum: Scripting
Topic: :execute output to console? Or any other method?
Replies: 17
Views: 3030

Re: :execute output to console? Or any other method?

I literally asked you to prove me wrong and i'll happily listen and accept it. You on the other hand aren't listening at all, just preaching pedantic coding Just wait new 7.18... On different devices and different way of update I obtain different results. This is one hAPax² from (??? not remember)-...
by rextended
Wed Jan 22, 2025 11:49 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 597
Views: 130506

Re: v7.17 [stable] is released!

What is the purpose and the use of "authorized-public-key-hash" on device-mode???
by rextended
Tue Jan 21, 2025 11:48 pm
Forum: Scripting
Topic: New command in RouterOs 7
Replies: 37
Views: 14225

Re: New command in RouterOs 7

:lol: 8)
by rextended
Tue Jan 21, 2025 8:19 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

Not installed for test, but this help comparing commands differencies on terminal:
viewtopic.php?p=1047229#p1047229
by rextended
Tue Jan 21, 2025 6:31 pm
Forum: Forwarding Protocols
Topic: BGP receiving the Full internet table to my CCR2216-1G-12XS-2XQ
Replies: 1
Views: 719

Re: BGP receiving the Full internet table to my CCR2216-1G-12XS-2XQ

Do not have any problem at all...

But...
another provider that can give the full routing table only
Filter all and add 0.0.0.0/0 with more weight manually, is easy, and can circumvent provider incapacity...
by rextended
Tue Jan 21, 2025 6:25 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 561
Views: 105927

Re: v7.18beta [testing] is released!

Image

NICE WORK.

I'm undecided on what to report the most beautiful, besides the FastTrak, I should copy half the list...
by rextended
Tue Jan 21, 2025 3:47 pm
Forum: General
Topic: Downloading a Root Cert for DNS over HTTPS Purposes directly onto a MicroTik Router [SOLVED]
Replies: 2
Views: 1252

Re: Downloading a Root Cert for DNS over HTTPS Purposes directly onto a MicroTik Router [SOLVED]

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Fingerprint RouterOS / Firefox: 31ad6648f8104138c738f39ea4320133393e3a18cc02296ef97c2ac9ef6731d0 31:AD:66:48:F8:10:41:38:C7:38:F3:9E:A4:32:01:33:39:3E:3A:18:CC:02:29:6E:F9:7C:2A:C9:EF:67:31:D0 -----BEGIN PGP SIGNATURE----- wsBzBAEBCAAnBYJnj6V4CZDWOsA2...
by rextended
Tue Jan 21, 2025 3:02 pm
Forum: General
Topic: Downloading a Root Cert for DNS over HTTPS Purposes directly onto a MicroTik Router [SOLVED]
Replies: 2
Views: 1252

Re: Downloading a Root Cert for DNS over HTTPS Purposes directly onto a MicroTik Router [SOLVED]

Search on forum, someone have already do that... This download all root certificates. https://forum.mikrotik.com/viewtopic.php?t=169662#p1080456 If you want install only one root cert (DigiCert Global Root G3), use only first part, with correct certificate: /file print file=DigiCertGlobalRootG3.txt ...
by rextended
Mon Jan 20, 2025 3:04 pm
Forum: Forwarding Protocols
Topic: AMT - Automatic Multicast Tunneling support
Replies: 16
Views: 5646

Re: AMT - Automatic Multicast Tunneling support

I won't comment these stupid conclusions. Calm down and don't scream so loud. The conclusion is not stupid, someone passing by, without be one forum admin or post official sources, announces something, it's just bullshit. Not to mention that maybe, as already happened, they remove some features fro...
by rextended
Sun Jan 19, 2025 3:42 pm
Forum: General
Topic: Logging prefix is a mess SUP-105353 SUP-144261. Waiting for MT to support RFC 5424
Replies: 44
Views: 14695

Re: Logging prefix is a mess SUP-105353 SUP-144261. Waiting for MT to support RFC 5424

Why do not Miktotik update my SUP with this information is an outer question.
Probably the SUPs from more than a day ago have already been forgotten...
by rextended
Fri Jan 17, 2025 1:15 pm
Forum: General
Topic: Logging prefix is a mess SUP-105353 SUP-144261. Waiting for MT to support RFC 5424
Replies: 44
Views: 14695

Re: Logging prefix is a mess SUP-105353 SUP-144261. Waiting for MT to support RFC 5424

Yes, some other news (search on help "31 address" or "1000 characters") https://forum.mikrotik.com/viewtopic.php?t=189798#p1119638 @Jotne is happy now for Splunk :lol: :lol: :lol: https://www.splunk.com/en_us/blog/learn/common-event-format-cef.html CEF:0|MikroTik|CHR|1.0|100|Logi...
by rextended
Fri Jan 17, 2025 1:10 pm
Forum: General
Topic: Logging prefix is a mess SUP-105353 SUP-144261. Waiting for MT to support RFC 5424
Replies: 44
Views: 14695

Re: Logging prefix is a mess SUP-105353 SUP-144261. Waiting for MT to support RFC 5424

Only on the official (help) documentation, not on idiotic rumors (I'm referring to another topic).

https://help.mikrotik.com/docs/

Just search "CEF"

Often page # change so direct link is broken, but until still valid:
https://help.mikrotik.com/docs/spaces/R ... og-Summary
by rextended
Fri Jan 17, 2025 11:44 am
Forum: General
Topic: Logging prefix is a mess SUP-105353 SUP-144261. Waiting for MT to support RFC 5424
Replies: 44
Views: 14695

Re: Logging prefix is a mess SUP-105353 SUP-144261. Waiting for MT to support RFC 5424

After 8 years...
From MikroTik RouterOS 7.18 support for CEF (Commont Event Format) logging format is added, as well as timestamp support for milliseconds.
by rextended
Fri Jan 17, 2025 11:38 am
Forum: Forwarding Protocols
Topic: AMT - Automatic Multicast Tunneling support
Replies: 16
Views: 5646

Re: AMT - Automatic Multicast Tunneling support

Strange, in 7.18alpha4 there is not present...

The only things added not for joke are:
Support for CEF (Commont Event Format) logging format and timestamp support for milliseconds.

/31 address support

OpenVPN Password cap increased to 1000 characters
by rextended
Wed Jan 15, 2025 12:51 pm
Forum: Forwarding Protocols
Topic: BGP routes received despite NRLI filter
Replies: 6
Views: 1060

Re: BGP routes received despite NRLI filter

on address list 0.0.0.0/0 = everything... so...
if you want match EXACTLY 0.0.0.0/0 (accept only default route, if is transmitted....), use filter
if (dst == 0.0.0.0/0) { accept }
by rextended
Wed Jan 15, 2025 12:37 pm
Forum: Beginner Basics
Topic: Can't see my mikrotik on winbox
Replies: 1
Views: 839

Re: Can't see my mikrotik on winbox

Which model? Which version of RouterOS? Which version of Winbox? Which computer operating system?
What game is this? Should we pull everything randomly?

Take your hands away from your eyes so you can see it.
You have not changed the computer used.
by rextended
Wed Jan 15, 2025 11:24 am
Forum: Scripting
Topic: [SOLVED] Using Dynamic Variable Names
Replies: 40
Views: 37561

Re: [SOLVED] Using Dynamic Variable Names

You edit your post, but is still full of frills and errors . If you try to correct someone who corrects you, at least make sure you correct well... If 2 is a number there is no need for "" , if instead it is a string, then consistently the 1 must also be quoted... And about \"check$nw...
by rextended
Mon Jan 13, 2025 2:04 pm
Forum: Scripting
Topic: [SOLVED] Using Dynamic Variable Names
Replies: 40
Views: 37561

Re: [SOLVED] Using Dynamic Variable Names

Just necroposting. Nothing usable and full of frills and errors. For example: :if (check$nwsarr must be :if (\$check$nwsarr /system clock :local datetime "$[get date] $[get time]" :local nwshost ("Tes1","Tes2","Tes3","Tes4","Tes5","Tes...
by rextended
Mon Jan 13, 2025 1:49 pm
Forum: Scripting
Topic: Help for block user use netshare
Replies: 22
Views: 6594

Re: Help for block user use netshare

bst ch grd qll gi scrtt.
by rextended
Sat Jan 11, 2025 7:21 pm
Forum: Scripting
Topic: Command execution not working via script [SOLVED]
Replies: 4
Views: 1960

Re: Command execution not working via script [SOLVED]

non interactive is /system ssh-exec
by rextended
Sat Jan 11, 2025 9:21 am
Forum: Scripting
Topic: Date conversion script problem under ROS 7.xx
Replies: 2
Views: 1176

Re: Date conversion script problem under ROS 7.xx

Lazyness... /system identity :local systemName [get name] /system clock :local curDate [get date] :local curTime [get time] :local curYear [:pick $curDate 0 4] :local curMonth [:pick $curDate 5 7] :local curDay [:pick $curDate 8 10] :local curHour [:pick $curTime 0 2] :local curMin [:pick $curTime 3...
by rextended
Sat Jan 11, 2025 9:13 am
Forum: Scripting
Topic: Command execution not working via script [SOLVED]
Replies: 4
Views: 1960

Re: Command execution not working via script [SOLVED]

It's on one line? Can not be on two parts in scripts like that.
by rextended
Fri Jan 10, 2025 3:37 pm
Forum: Beginner Basics
Topic: Struggling to receive IPv6 prefix delegation from ISP [SOLVED]
Replies: 65
Views: 6383

Re: Struggling to receive IPv6 prefix delegation from ISP [SOLVED]

If the network team cannot see the ONT …. ESCALATE TO some one who can … do not give up … this is not rocket science … someone from the NOC should be able to help you to resolve this ….
+100
by rextended
Fri Jan 10, 2025 3:25 pm
Forum: Beginner Basics
Topic: Struggling to receive IPv6 prefix delegation from ISP [SOLVED]
Replies: 65
Views: 6383

Re: Struggling to receive IPv6 prefix delegation from ISP [SOLVED]

added on previous post, if you not notice it: "cryptic box" probably is just configured to do bridging, and the Juniper router of your ISP provide public IPv4 on DHCP and single IPv6... a05:e2 -> 0 a:05:e2 -> 0 8 :05:E2 Juniper https://hwaddress.com/oui-iab/08-05-E2/ f61e:57 -> f6:1e:57 ->...
by rextended
Fri Jan 10, 2025 3:02 pm
Forum: Beginner Basics
Topic: Struggling to receive IPv6 prefix delegation from ISP [SOLVED]
Replies: 65
Views: 6383

Re: Struggling to receive IPv6 prefix delegation from ISP [SOLVED]

Ok, if you can only receive (correctly) one /128 and you can ping correctly 2606:4700:4700::1111 from your router, is meaning that the "cryptic box" probably is just configured to do bridging, and the Juniper router of your ISP provide public IPv4 on DHCP and single IPv6... So you must ask...
by rextended
Fri Jan 10, 2025 2:58 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1916
Views: 612125

Re: 📣 WinBox 4 is here 📣

I love Excel ( 😛 )
by rextended
Fri Jan 10, 2025 2:50 pm
Forum: Beginner Basics
Topic: Struggling to receive IPv6 prefix delegation from ISP [SOLVED]
Replies: 65
Views: 6383

Re: Struggling to receive IPv6 prefix delegation from ISP [SOLVED]

Now is clear that you do not use pppoe or vlan, but just DHCPv4 client. Restart is not needed. try this: /ipv6 address remove [find where dynamic=no] /ipv6 dhcp-client remove [find] add add-default-route=yes disabled=no interface=ether1 rapid-commit=no request=address use-peer-dns=yes If you obtain ...
by rextended
Fri Jan 10, 2025 2:33 pm
Forum: Beginner Basics
Topic: Struggling to receive IPv6 prefix delegation from ISP [SOLVED]
Replies: 65
Views: 6383

Re: Struggling to receive IPv6 prefix delegation from ISP [SOLVED]

while waiting for /interface print test this: /ipv6 settings set accept-redirects=yes-if-forwarding-disabled accept-router-advertisements=yes-if-forwarding-disabled forward=yes max-neighbor-entries=32768 set multipath-hash-policy=l3 ; # this line do error if not used on v7.16.2 and up /ipv6 dhcp-cli...
by rextended
Fri Jan 10, 2025 2:30 pm
Forum: Beginner Basics
Topic: Struggling to receive IPv6 prefix delegation from ISP [SOLVED]
Replies: 65
Views: 6383

Re: Struggling to receive IPv6 prefix delegation from ISP [SOLVED]

I do not see any pppoe interface in routes...

also /int pri please?
by rextended
Fri Jan 10, 2025 2:25 pm
Forum: Beginner Basics
Topic: Struggling to receive IPv6 prefix delegation from ISP [SOLVED]
Replies: 65
Views: 6383

Re: Struggling to receive IPv6 prefix delegation from ISP [SOLVED]

you use pppoe???? problably is pppoe that provide you the IP connectivity, not the dhcp on ether1... I can fail on this because I do not understand correctly how you have setup yout router... The first user that reply you on this topic must ask first how is configured and attached your router... put...
by rextended
Fri Jan 10, 2025 2:05 pm
Forum: Beginner Basics
Topic: Struggling to receive IPv6 prefix delegation from ISP [SOLVED]
Replies: 65
Views: 6383

Re: Struggling to receive IPv6 prefix delegation from ISP [SOLVED]

you use pppoe or vlan?
the dhcpv4 is directly over ether1?
what is your LAN interface?
by rextended
Fri Jan 10, 2025 1:06 pm
Forum: Forwarding Protocols
Topic: How to connect WAN directly to some port, bypassing NAT
Replies: 13
Views: 3550

Re: How to connect WAN directly to some port, bypassing NAT

Put a switch on the WAN and attach the gateway WANs to it... What use would the second gateway have if it doesn't have to do anything? Forum users, often, do not do illogical things. Explain correctly what you want to achieve in the end, not the intermediate steps that seem absurd, even if they seem...
by rextended
Thu Jan 09, 2025 11:41 am
Forum: Scripting
Topic: :execute output to console? Or any other method?
Replies: 17
Views: 3030

Re: :execute output to console? Or any other method?

I literally asked you to prove me wrong and i'll happily listen and accept it. I've already written the reason twice, it's you who comes out with this defiant air. What do you expect me to write same thing "prove me wrong" and start a game of morons? The other people on the forum will jud...
by rextended
Thu Jan 09, 2025 11:31 am
Forum: Scripting
Topic: :execute output to console? Or any other method?
Replies: 17
Views: 3030

Re: :execute output to console? Or any other method?

With you what I write are empty words. I have already made it clear that it is not a competition of style, or of right and wrong, but of not leaving wrong examples on the forum. Of course it works if a package is installed, it is also easy to generate a problem, mixing packages of different versions...
by rextended
Thu Jan 09, 2025 11:21 am
Forum: Scripting
Topic: :execute output to console? Or any other method?
Replies: 17
Views: 3030

Re: :execute output to console? Or any other method?

This is not the specific case, which may or may not work, and it's not even a question of code beauty or not (but why did you change it from the first post?) but you absolutely must not use hardcoded numbers or .id to obtain values. There are dozens and dozens of posts where users, copyng these erro...
by rextended
Thu Jan 09, 2025 10:29 am
Forum: Scripting
Topic: :execute output to console? Or any other method?
Replies: 17
Views: 3030

Re: :execute output to console? Or any other method?

So here is the version agnostic command for anyone else who is interested [...] /system package get 0 version [...] No this is not agnostic, this is wrong . 2022-02-26 https://forum.mikrotik.com/viewtopic.php?p=915725#p915725 /system resource :if ([get version]~"^7") do={ [:parse "/e...
by rextended
Thu Jan 09, 2025 10:12 am
Forum: Scripting
Topic: Script to connect to Apartment wifi AP
Replies: 5
Views: 1672

Re: Script to connect to Apartment wifi AP

I'm new to MikroTik and scripting and wanted to get a basis to start off of.
So if you need to learn Italian, start by looking at examples of Swahili?


That obviously didn't work.
So, obviously is lost time. This forum is full of correct examples.
by rextended
Wed Jan 08, 2025 6:21 pm
Forum: Scripting
Topic: verify update RouterOS, with memory
Replies: 11
Views: 2466

Re: verify update RouterOS, with memory

No need to run the script more often than once a week or even month. Or better... If the scheduler name is checkVersion , simply disable it once send the email... { /system package update :local test [check-for-updates as-value] :local installed ($test->"installed-version") :local latest ...
by rextended
Wed Jan 08, 2025 6:16 pm
Forum: General
Topic: what happens when CHR 60 days trial is expired!
Replies: 7
Views: 6163

Re: what happens when CHR 60 days trial is expired!

Simple reply to OP post: Unable to upgrade/update, and nothing else.
by rextended
Wed Jan 08, 2025 6:03 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1916
Views: 612125

Re: 📣 WinBox 4 is here 📣

@normis and others working on Winbox 4 should prioritize SUP-175441
And for what reason?
by rextended
Wed Jan 08, 2025 5:23 pm
Forum: Scripting
Topic: :execute output to console? Or any other method?
Replies: 17
Views: 3030

Re: :execute output to console? Or any other method?

Detecting which command based on version is doable. I've already posted on these forums on how to detect and run version specific commands without failure, Already done that before, but I can also make this for check what commands are supported and what parameters https://forum.mikrotik.com/viewtop...
by rextended
Wed Jan 08, 2025 5:05 pm
Forum: Scripting
Topic: verify update RouterOS, with memory
Replies: 11
Views: 2466

Re: verify update RouterOS, with memory

{ :global vCheck /system package update :local test [check-for-updates as-value] :local installed ($test->"installed-version") :local latest ($test->"latest-version") :if (($installed!=$latest) and ($vCheck!=$latest)) do={ :log warning "Is installed RouterOS $installed but ...
by rextended
Wed Jan 08, 2025 10:16 am
Forum: Scripting
Topic: Script to connect to Apartment wifi AP
Replies: 5
Views: 1672

Re: Script to connect to Apartment wifi AP

You guys need to stop messing around with ChatGPT and the like. It makes you all dumber. For example, if you were to use even a little bit of the intellect that all normal people have, how can the rest of the code be executed after the reset command reboots the device? Also, if the config is really ...
by rextended
Tue Jan 07, 2025 2:11 pm
Forum: Wireless Networking
Topic: mANTBox ax 15s
Replies: 2
Views: 1507

Re: mANTBox ax 15s

SXTsq 5 ac on nv2 or nstreme? ax do not support at all nv2 or nstreme
by rextended
Tue Jan 07, 2025 10:23 am
Forum: Scripting
Topic: verify update RouterOS, with memory
Replies: 11
Views: 2466

Re: verify update RouterOS, with memory

The best idea is to test RouterOS separately, and when in the lab it seems to work correctly at least for 3 months, apply it to a small part in production, for testing, and if it goes well plan the update everywhere. So it doesn't matter to be notified when there is a new version of RouterOS, just l...
by rextended
Sat Jan 04, 2025 11:44 am
Forum: Forwarding Protocols
Topic: AMT - Automatic Multicast Tunneling support
Replies: 16
Views: 5646

Re: AMT - Automatic Multicast Tunneling support

or do you just write because you don't know what to write? I think it's about you. Already second post in this topic without any sense... Just wait until 7.18. The problem is you. Why necroposting on a topic from 2022 without the official source where it is written that probably they add the functi...
by rextended
Sat Jan 04, 2025 9:55 am
Forum: Forwarding Protocols
Topic: AMT - Automatic Multicast Tunneling support
Replies: 16
Views: 5646

Re: AMT - Automatic Multicast Tunneling support

Probably it will be added soon (7.18)
More or less reliable sources, or do you just write because you don't know what to write?
by rextended
Sat Jan 04, 2025 1:02 am
Forum: Scripting
Topic: Capsman scheduler
Replies: 24
Views: 10359

Re: Capsman scheduler

It's a necroposting from 2018.
v7 do not exist on 2018...

Ignoring the logging, is all useless, just simply
/caps-man interface disable [find where name~"^AP-1stFloor-.*"]
by rextended
Sat Jan 04, 2025 12:23 am
Forum: Scripting
Topic: Persistent Environment Variables [SOLVED]
Replies: 60
Views: 46304

Re: Persistent Environment Variables [SOLVED]

I also thought about using json, but... Put in a table: on the right the variable types that RouterOS supports (array,bool,id,ip,ip6,num,str,time,ip-prefix,ip6-prefix,nil,nothing), (ignoring unexportable types code, function, lookup, op, apireq, exclamation, cmd, iterator, backreference) on the left...
by rextended
Thu Jan 02, 2025 6:46 pm
Forum: Scripting
Topic: Unable to Disable Static Routes from Script or CLI
Replies: 6
Views: 2276

Re: Unable to Disable Static Routes from Script or CLI

I don't think this is a problem that forum users can address.

Contact directly MikroTik support@mikrotik.com providing Supout.rif and detailed description.
And please update this topic with results/given answers.

Do NOT post Supout.rif to any forum members.

Thanks.
by rextended
Thu Jan 02, 2025 1:27 pm
Forum: Scripting
Topic: script problem
Replies: 4
Views: 2508

Re: script problem

What could be causing this problem? The answer is simple: You. You haven't read the basic scripting guides. They aren't complete, but it's clearly stated not to use numbers in scripts. Numbers are for "on the fly" use in the terminal, nothing fixed. There is only one DHCP client configure...
by rextended
Mon Dec 30, 2024 2:30 pm
Forum: Scripting
Topic: Script to find IPv6 address dynamically assigned to known MAC address on LAN?
Replies: 5
Views: 1914

Re: Script to find IPv6 address dynamically assigned to known MAC address on LAN?

Nextgentel use 2a04:980::/29 that go from 2a04:980::/29 to 2a04:987:..../29 so is coherent. If you log the array, winbox or webfig can't show correct hex values. Try to use this for log: :log info "na-prefix $[:convert $"na-prefix" from=raw to=hex]" WARNING: Do not publish result...
by rextended
Mon Dec 30, 2024 10:13 am
Forum: Scripting
Topic: Script to find IPv6 address dynamically assigned to known MAC address on LAN?
Replies: 5
Views: 1914

Re: Script to find IPv6 address dynamically assigned to known MAC address on LAN?

[..] DHCPv6 script section the global variable is not created nor set [..] If you read changelogs, help and forum, you learn that actually, on actual stable version, netwatch dhcp, ppp, etc. sciripts are runned on different user that can't interac with global variables, and other restricted permiss...
by rextended
Fri Dec 27, 2024 12:46 pm
Forum: Scripting
Topic: Address List Sending Email
Replies: 1
Views: 1788

Re: Address List Sending Email

All this: # Initialize the content with a header :if ([/file find where name=$filename] != "") do={ /file remove $filename :log info "Removed existing file $filename." } simply: /file remove [find where name=$filename] Why uselessly do same test again and again? # Log file creati...
by rextended
Thu Dec 26, 2024 1:21 pm
Forum: Beginner Basics
Topic: Help needed - How to mitigate DDOS atacks with dns
Replies: 21
Views: 3641

Re: Help needed - How to mitigate DDOS atacks with dns

For remember what I wrote on post #5:
(And if you had an ISP that knows how to do its job, there wasn't one)...
by rextended
Thu Dec 26, 2024 2:43 am
Forum: Scripting
Topic: Script copy route table to another one route table
Replies: 1
Views: 1535

Re: Script copy route table to another one route table

And in case is already present on destination route table, but have another gateway? Wrong for various reasons. Also superfluos ; , unconsistent variables name, etc. Duplicated :: at start probably for copy-paste. Also on the description missing that not only copy, but also change gateway. { :local ...
by rextended
Thu Dec 26, 2024 2:24 am
Forum: Scripting
Topic: Script for make Address List from route table
Replies: 1
Views: 1539

Re: Script for make Address List from route table

Wrong for various reasons. Also superfluos ; , unconsistent variables name, etc. For example, one above all, if on the foreach checkIP is set to 2, then it will never return to 0. { :local routingTable "6G" :local addressList "BGP_YOUTUBE" :local dstAddress 0.0.0.0 /ip route :for...
by rextended
Mon Dec 23, 2024 3:59 pm
Forum: Scripting
Topic: Scripting error
Replies: 3
Views: 1803

Re: Scripting error

The title is wrong, the correct title is "fix for me SchaitGPT script"

Why don't you ask ChatGPT for help?

First you get a dog and take it out to s—t on the street, then you ask pedestrians who pass by to clean it up?
by rextended
Mon Dec 23, 2024 3:29 pm
Forum: Beginner Basics
Topic: Help needed - How to mitigate DDOS atacks with dns
Replies: 21
Views: 3641

Re: Help needed - How to mitigate DDOS atacks with dns

This is not the case, but sometimes it is a really bad idea to log in case of DDoS, it takes up a lot of CPU.

This is not the case, but sometimes it is also a really bad idea to create an address list in case of DDoS,
it takes up a lot of CPU and in a short time it runs out of RAM...
by rextended
Sun Dec 22, 2024 11:39 pm
Forum: Beginner Basics
Topic: Help needed - How to mitigate DDOS atacks with dns
Replies: 21
Views: 3641

Re: Help needed - How to mitigate DDOS atacks with dns

Surely this is something the ISP should be fixing rather than you at the edge of their network?

(And if you had an ISP that knows how to do its job, there wasn't one)...
by rextended
Sun Dec 22, 2024 11:35 pm
Forum: Scripting
Topic: Script to auto create address-list from plain ip-ranges URLs
Replies: 10
Views: 2301

Re: Script to auto create address-list from plain ip-ranges URLs

Thanks for the confirmation you missed the point. My bad for not including a :wink: at the end.
Oops, sorry, I actually meant it as a serious question...
Now I understand...
by rextended
Sat Dec 21, 2024 12:33 pm
Forum: Scripting
Topic: Script to auto create address-list from plain ip-ranges URLs
Replies: 10
Views: 2301

Re: Script to auto create address-list from plain ip-ranges URLs

You are missing the point, in order for this to be of any use you must trust the source. No, sorry, but you missed the point: Anyone can make mistakes (and, also, the list provider can change the format without warning). Regarding 0.0.0.0/0, or 8.0.0.0/8 being wrong on an address list, did I miss t...
by rextended
Fri Dec 20, 2024 7:14 pm
Forum: Scripting
Topic: Script to auto create address-list from plain ip-ranges URLs
Replies: 10
Views: 2301

Re: Script to auto create address-list from plain ip-ranges URLs

:if ($ip ~ "^[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}") do={ :do { # Try to add the IP to the address list add list=$listName address=$ip comment=$description timeout=0 dynamic=no } on-error={ # Update the existing entry if it already exists set [find list=$listName address=$ip] ...
by rextended
Fri Dec 20, 2024 7:07 pm
Forum: Beginner Basics
Topic: Help needed - How to mitigate DDOS atacks with dns
Replies: 21
Views: 3641

Re: Help needed - How to mitigate DDOS atacks with dns

It always means the complete configuration (purged from sensitive data censoring it, not cleaning the lines....), not just a little piece where YOU think is the problem.
by rextended
Fri Dec 20, 2024 6:59 pm
Forum: General
Topic: Problems with empty pppoe MTU
Replies: 2
Views: 1315

Re: Problems with empty pppoe MTU

Last stable version is 7.16.2
Try that version if already fix the problem.
by rextended
Fri Dec 20, 2024 6:50 pm
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 86
Views: 62893

Re: Newsletter #122 | December 2024

Bravi!
by rextended
Fri Dec 20, 2024 6:33 pm
Forum: Beginner Basics
Topic: Help needed - How to mitigate DDOS atacks with dns
Replies: 21
Views: 3641

Re: Help needed - How to mitigate DDOS atacks with dns

This is like worrying needlessly about a trifle. As for this request, the firewall is configured correctly , and the number of packets, if I interpreted correctly what you wrote (1000000 in 2/3 days), is perfectly normal these days , for the moron ISPs . If you really had a DDoS they were 1000000 p...
by rextended
Wed Dec 18, 2024 9:03 pm
Forum: Scripting
Topic: Using :return from :onerror in= command block
Replies: 13
Views: 2222

Re: Using :return from :onerror in= command block

https://forum.mikrotik.com/viewtopic.php?p=1047480#p1046897 There are situations where currently "on-error-resume-next" must be used because it is poorly managed by RouterOS , such as ":resolve", for everything else, error-proof scripts must be written, preventing any errors that...
by rextended
Wed Dec 18, 2024 10:53 am
Forum: Scripting
Topic: Using :return from :onerror in= command block
Replies: 13
Views: 2222

Re: Using :return from :onerror in= command block

this makes updating old scripts much complicated.

But old method still works, so, why update uselessly?
by rextended
Wed Dec 18, 2024 10:46 am
Forum: Scripting
Topic: GET DHCP Leases, JSON parse problem
Replies: 2
Views: 1747

Re: GET DHCP Leases, JSON parse problem

using the JSON Parse :parse command
:parse command cannot properly process the incoming data
I don't know where you read this, but change your dealer...
:parse have nothing to do with JSON, and :parse accept on input only (valid) RouterOS script.
by rextended
Mon Dec 16, 2024 9:25 pm
Forum: Scripting
Topic: exit or break a loop statement
Replies: 15
Views: 21848

Re: exit or break a loop statement

by rextended
Mon Dec 16, 2024 8:42 pm
Forum: Scripting
Topic: exit or break a loop statement
Replies: 15
Views: 21848

Re: exit or break a loop statement

The topic was created 15 years ago and still no "break" functionality for loops

Are you sure?
by rextended
Mon Dec 16, 2024 8:40 pm
Forum: Scripting
Topic: executing script from net failed
Replies: 35
Views: 4201

Re: executing script from net failed

:lol: never mind, but I already understood the type... 8)
by rextended
Mon Dec 16, 2024 8:28 pm
Forum: Scripting
Topic: V6.44.5
Replies: 2
Views: 1404

Re: V6.44.5

TWO BAD ADVICES (intended or not): 1) Go straight to 7.15.x without passing to 6.49.x, 7.12.x etc. 2) For solve one problem, can broke everything if use 6.x scripting and go to 7.x.... Hint: Go at least to last long-term 6.49.13 and use correct version-less syntax.... :if ([:len [/ip route find wher...
by rextended
Mon Dec 16, 2024 8:21 pm
Forum: Scripting
Topic: executing script from net failed
Replies: 35
Views: 4201

Re: executing script from net failed

23 other posts (+1) for NOTHING . Post #3 is still valid, all the other posts are just garbage. If the user doesn't cooperate, there's no point in wasting time, leave it alone with support. You didn't provide even one detail, search the internet to see if there is any "fortune teller" ava...
by rextended
Sat Dec 14, 2024 11:58 pm
Forum: Scripting
Topic: IPV6 ROUTE REMOVE DYNAMC ROUTES
Replies: 1
Views: 1273

Re: IPV6 ROUTE REMOVE DYNAMC ROUTES

Simply remove the cause that add the dynamic rule, and you do not need any script...
by rextended
Sat Dec 14, 2024 11:55 pm
Forum: Scripting
Topic: executing script from net failed
Replies: 35
Views: 4201

Re: executing script from net failed

You didn't provide even one detail, search the internet to see if there is any "fortune teller" available.

no details = no reply

Ask support@mikrotik.com if you do not want share your config and scripts.
by rextended
Thu Dec 12, 2024 10:14 am
Forum: Scripting
Topic: Has the variable size become larger ?
Replies: 1
Views: 1242

Re: Has the variable size become larger ?

What is the purpose of this useless thread/topic/post? Read from remote file on the past RouterOS versions are limited to 64512 bytes at time (my idea from 2021) https://forum.mikrotik.com/viewtopic.php?f=9&t=177530 Variable sizes have always been "infinite" as long as there is free me...
by rextended
Wed Dec 11, 2024 1:27 pm
Forum: General
Topic: IP Cloud (Dynamic DNS) down?
Replies: 101
Views: 17299

Re: mynetname is down ?

@Jotne

From @normis:
We have identified the issue and a fix is coming shortly.
by rextended
Wed Dec 11, 2024 11:19 am
Forum: General
Topic: IP Cloud (Dynamic DNS) down?
Replies: 101
Views: 17299

Re: mynetname is down ?

No need for +1 comments. You already have the attention by Mikrotik.
We have identified the issue and a fix is coming shortly.

I'm sorry, but people are lazy & lazy, they don't read what is written before.
by rextended
Wed Dec 11, 2024 10:26 am
Forum: General
Topic: IP Cloud (Dynamic DNS) down?
Replies: 101
Views: 17299

Re: mynetname is down ?

None of you can complain about anything, since the service is not paid,
it is not included in the RuterOS license,
it is just a free courtesy that MikroTik does.

Relying on it for work is crazy.
by rextended
Tue Dec 10, 2024 3:13 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 232650

Re: v7.16.2 [stable] is released!

It looks like it was written by ChatGPT rather than a person, and it probably is.
by rextended
Mon Dec 09, 2024 11:12 pm
Forum: Beginner Basics
Topic: Can't create script [SOLVED]
Replies: 4
Views: 2312

Re: Can't create script [SOLVED]

they?

what video?
by rextended
Mon Dec 09, 2024 10:55 pm
Forum: Scripting
Topic: concatenate variable names
Replies: 11
Views: 2027

Re: concatenate variable names

For do the same with a variable called 123456 (ignoring the : that is a typo for sure...) { :local variables {"hello"="123"} :put "current content of hello variable is >$($variables->"hello")<" :local newvarname (($variables->"hello") . "456&quo...
by rextended
Mon Dec 09, 2024 12:21 pm
Forum: Beginner Basics
Topic: Can't create script [SOLVED]
Replies: 4
Views: 2312

Re: Can't create script [SOLVED]

You press <TAB> after edit 0.
So?

What mean edit 0? what is 0?


edit test source
by rextended
Mon Dec 09, 2024 12:02 pm
Forum: Scripting
Topic: concatenate variable names
Replies: 11
Views: 2027

Re: concatenate variable names

Just use a 2nd variable. But this is not what OP ask: concatenate variable names Your example is not concatenate variable names , but concatenate values ... Is better define the problem: Define a variable whose name is the concatenation of the content of another two variables parts . And the soluti...
by rextended
Mon Dec 09, 2024 11:47 am
Forum: Scripting
Topic: PPPoE Failover Script Enhancement - Adding Internet Connectivity Verification
Replies: 4
Views: 1693

Re: PPPoE Failover Script Enhancement - Adding Internet Connectivity Verification

Hypothesis 1: The pppoe-client does not work, fine, what do you have in reserve? It is all automatic, if configured, if the reserve is a DHCP-client, static route, or another pppoe-client. Hypothesis 2: The pppoe-client works, but the ISP does not work, what do you have in reserve? as above, with ne...
by rextended
Mon Dec 09, 2024 11:38 am
Forum: Scripting
Topic: system backup save output is causing snmpget triggered script not to run
Replies: 1
Views: 1357

Re: system backup save output is causing snmpget triggered script not to run

Useless words, without the script to check.

If the mechanic has to check the engine of your car,
do you describe to him what color the car is over the phone,
without taking the car to it to him to check it?
Does he fix it over the phone?
by rextended
Mon Dec 09, 2024 11:34 am
Forum: Scripting
Topic: PPPoE Failover Script Enhancement - Adding Internet Connectivity Verification
Replies: 4
Views: 1693

Re: PPPoE Failover Script Enhancement - Adding Internet Connectivity Verification

It's a failure from the start using detect-internet, so I don't even finish reading it, I don't waste time on it.
It's clear from the start that even using detect-internet successfully for this purpose, it ruins the functioning of other parts.
Sources: the forum.
by rextended
Mon Dec 09, 2024 11:24 am
Forum: Scripting
Topic: concatenate variable names
Replies: 11
Views: 2027

Re: concatenate variable names

Completely useless or poorly engineered problem.


There are already dozens of posts, many of which I wrote, that explain the exact same thing, use the search function.
by rextended
Wed Dec 04, 2024 10:31 am
Forum: General
Topic: Random reboots on RB4011 since 7.13/7.14
Replies: 22
Views: 4212

Re: Random reboots on RB4011 since 7.13/7.14

Maybe try adding a second power supply by connecting it through a POE injector? That doesn't make sense to me. "The hAP ax³ can be powered via DC plug or passive PoE." Do not hijack other topic, this is about RB4011. I have dozen of ax devices, none do that problem, do not lost time, neti...
by rextended
Mon Dec 02, 2024 5:56 pm
Forum: General
Topic: am i using SOHO Firewall or not?
Replies: 38
Views: 4392

Re: am i using SOHO Firewall or not?

From post #7
If the RB951Ui-2HnD does indeed have a public IP, I highly recommend updating it to 6.49.17 and then resetting it to default settings.
This will reset the firewall and everything else you need to the correct defaults.
by rextended
Mon Dec 02, 2024 9:58 am
Forum: RouterOS beta
Topic: Feature Request : IPv6 Fasttrack [SOLVED]
Replies: 216
Views: 69303

Re: Feature Request : IPv6 Fasttrack [SOLVED]

I would like to clarify, however, to avoid misunderstandings,
that I am interested.

Regardless of the logical considerations that I make above.
by rextended
Mon Dec 02, 2024 1:19 am
Forum: Scripting
Topic: Running a script from Netwatch doesn't work
Replies: 14
Views: 2374

Re: Running a script from Netwatch doesn't work

can be saved also as json... ***************************************** If I may suggest, this idea could go to your “Rextended Fragments of Snippets” thread, it could help many people who always ask the same question (until Mikroltik implements a way to change policies or rights in Netwatch). On som...
by rextended
Mon Dec 02, 2024 1:08 am
Forum: RouterOS beta
Topic: Feature Request : IPv6 Fasttrack [SOLVED]
Replies: 216
Views: 69303

Re: Feature Request : IPv6 Fasttrack [SOLVED]

from poll result, depending how much is needed by community, MT can decide if feature will be considered for implementation and in which priority Deeply wrong way of thinking : Those who don't need it... don't waste time registering on the forum for vote no ... Of course the yes will always win bec...
by rextended
Sat Nov 30, 2024 2:30 pm
Forum: RouterOS beta
Topic: Feature Request : IPv6 Fasttrack [SOLVED]
Replies: 216
Views: 69303

Re: Feature Request : IPv6 Fasttrack [SOLVED]

+1 what?

The time wasted adding "+1" posts on the user forum is completely useless and foolish.

Instead, write directly to support@mikrotik.com and complain there...
by rextended
Sat Nov 30, 2024 2:14 pm
Forum: General
Topic: am i using SOHO Firewall or not?
Replies: 38
Views: 4392

Re: am i using SOHO Firewall or not?

yes its the main router, i mean there is another one for the ISP router connected to the radio antenna but i don't have access to that one. is it or is it not the main router? From what you described it is not and it is right that there is no internal configuration, but everything is transparent to...
by rextended
Sat Nov 30, 2024 2:02 pm
Forum: Scripting
Topic: Running a script from Netwatch doesn't work
Replies: 14
Views: 2374

Re: Running a script from Netwatch doesn't work

The problem is the misleading name: "global" is a user session. ideal => actual :global => <NOT EXIST>, but a file content in store, json, or parameters in layer7 and similar can be used for store simple values. <user> => :global <MISLEADING NAME> <session> => :local at the script start :l...
by rextended
Sat Nov 30, 2024 1:51 pm
Forum: Scripting
Topic: First script problem - just won't execute
Replies: 10
Views: 1877

Re: First script problem - just won't execute

b.2 EXACT, if is wrong... But the rute must not be uselessly removed. The route (ALL THE ROUTES created with DHCP) must be removed from netwatch script that activate/deactivate DHCP-Client both on up and on down. else connections are destroyed every time the lease are renewed. and if is =1 delete on...
by rextended
Sat Nov 30, 2024 1:33 pm
Forum: Scripting
Topic: Running a script from Netwatch doesn't work
Replies: 14
Views: 2374

Re: Running a script from Netwatch doesn't work

Each user has it's own environment, no matter of policy, each run of netwatch script have it's own environment, no matter of policy Notice: >>>probably is fixed on some new RouterOS version<<< /system script add dont-require-permissions=no name=testScript owner=admin policy=reboot,read,write,test so...
by rextended
Sat Nov 30, 2024 12:54 pm
Forum: Scripting
Topic: Running a script from Netwatch doesn't work
Replies: 14
Views: 2374

Re: Running a script from Netwatch doesn't work

see next post
by rextended
Sat Nov 30, 2024 11:52 am
Forum: Scripting
Topic: First script problem - just won't execute
Replies: 10
Views: 1877

Re: First script problem - just won't execute

Ignoring the Copilot crap, the script is useless, just use "Add Default Route" and choose rigtly "Default Route Distance", and default route distance and everything works automagically without bothering with scripts. At that point, when the mechanism (elsewhere) that automaticall...
by rextended
Fri Nov 29, 2024 5:16 pm
Forum: Scripting
Topic: PPP Secrets Disabled date comments
Replies: 6
Views: 1599

Re: PPP Secrets Disabled date comments

I tried to insert the script and activated it every 10s. Activated 6 times, but users did not turn off. I write comments in different ways, but none of them turned off. 1. abzalieva Disable dec/28/2022 2. abzalieva disable dec/28/2022 3. Disable 2023-01-02 4. disable 2023-01-02 5. Svetlana Disable ...
by rextended
Fri Nov 29, 2024 1:09 pm
Forum: Scripting
Topic: PPP Secrets Disabled date comments
Replies: 6
Views: 1599

Re: PPP Secrets Disabled date comments

required code

:foreach item in=[/ppp secret find where $comment~[/system clock get date]] do={
    /ppp secret disable $item
    /ppp active remove [find where name=[/ppp secret get $item name]]
}
by rextended
Thu Nov 28, 2024 5:58 pm
Forum: General
Topic: fingerprinting
Replies: 8
Views: 1598

Re: fingerprinting

Yes and no. <insert here the classic explanation of how this thing introduced for a false privacy (the apps on the phone do more of your business than those who provide Wi-Fi with MAC) then prevents abuses from the standard and not-so-standard users, even involuntarily, of a free service> Of course,...
by rextended
Thu Nov 28, 2024 5:09 pm
Forum: General
Topic: fingerprinting
Replies: 8
Views: 1598

Re: fingerprinting

Forbid access of fake MAC (no matter explain here how, already present on forum), and standard user are forced to use real MAC. /interface wifi access-list add action=reject disabled=no mac-address=02:00:00:00:00:00 mac-address-mask=02:00:00:00:00:00 For v6 there is not a mask on access list, but yo...
by rextended
Thu Nov 28, 2024 10:18 am
Forum: Wireless Networking
Topic: Any reason not use 20Mhz channel on AX devices, if stability is preferred over max speed?
Replies: 11
Views: 3259

Re: Any reason not use 20Mhz channel on AX devices, if stability is preferred over max speed?

Actualy ax hardware I tested on 7.16.2 on MikroTik have only fixed channels, example 5500 but not 5510, and work ony on 20MHz or consecutive 20+20 or 20+20+20+20 channels. (hAP ax², hAP ax³, wAP ax, cAP ax, mANTBox ax 15s) 2412,2417,2422,2427,2432,2437,2442,2447,2452,2457,2462,2467,2472 5180,5200,52...
by rextended
Thu Nov 28, 2024 10:13 am
Forum: General
Topic: Ticket not being responded to
Replies: 9
Views: 1497

Re: Ticket not being responded to

This is user forum, do not post only ticket number, for us is useless, describe also the problem....
by rextended
Wed Nov 27, 2024 9:58 pm
Forum: Beginner Basics
Topic: routing in mikrotik
Replies: 3
Views: 1393

Re: routing in mikrotik

What does this have to do with scripting section?
by rextended
Wed Nov 27, 2024 6:33 pm
Forum: General
Topic: Complaints from v7.17rc [testing]
Replies: 45
Views: 6125

Re: Complaints from v7.17rc [testing]

install- any -version it's misleading, it should be install- unsecure -version For what I understand till now, 7.17rc has internal databases of compromised versions that do not accept to downgrade. So far, all good and correct. But how does it work with versions that are NOT in the database of compr...
by rextended
Wed Nov 27, 2024 1:38 pm
Forum: General
Topic: Complaints from v7.17rc [testing]
Replies: 45
Views: 6125

Re: Complaints from v7.17rc [testing]

I don't use netinstall remotely often, but that's okay...
by rextended
Wed Nov 27, 2024 1:30 pm
Forum: General
Topic: Complaints from v7.17rc [testing]
Replies: 45
Views: 6125

Re: Complaints from v7.17rc [testing]

It is still possible to downgrade ROS as normis already explained. Honestly, in 17rc, I have never read or noticed it anywhere. install- any -version it's misleading, it should be install- unsecure -version Well, this time I was wrong , about RouterOS version, I read and interpreted badly. I hope y...
by rextended
Wed Nov 27, 2024 1:17 pm
Forum: General
Topic: Complaints from v7.17rc [testing]
Replies: 45
Views: 6125

Re: Complaints from v7.17rc [testing]

@infabo Is not a point on traffic-gen or repartition. I, for first, have never spoken of install insecure versions of RouterOS. It means installing a previous version of RouterOS, which perhaps does not have the bugs of the next version, as often happens. No matter how many tests you do in the lab,...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 45