Community discussions

Search found 49 matches

by eternal0
Sat Jun 15, 2019 6:36 pm
Forum: General
Topic: IPv6 support for L2TP/PPTP/SSTP etc.
Replies: 12
Views: 6431

Re: IPv6 support for L2TP/PPTP/SSTP etc.

Still not working now.
by eternal0
Tue Jun 27, 2017 10:59 am
Forum: General
Topic: IPsec Hardware acceleration on CHR?
Replies: 9
Views: 1970

Re: IPsec Hardware acceleration on CHR?

What Hypervisor are you running CHR on ?
Hyperviser is KVM. Hardware acceleration is enabled if we use AES-GCM so that AES-NI is supported by this.
by eternal0
Tue Jun 27, 2017 5:14 am
Forum: General
Topic: IPsec Hardware acceleration on CHR?
Replies: 9
Views: 1970

Re: IPsec Hardware acceleration on CHR?

From v6.39 changelog:

*) ipsec - enable aes-ni on i386 and x64 for cbc, ctr and gcm modes;
That confused me why AES-CBC cannot get accelerated on my CHR host.

The IPsec connection is from RB850Gx2 to CHR with sha256/AES-256-CBC. The hardware acceleration works fine on my RB850Gx2.
by eternal0
Mon Jun 26, 2017 9:03 am
Forum: General
Topic: IPsec Hardware acceleration on CHR?
Replies: 9
Views: 1970

IPsec Hardware acceleration on CHR?

As is well known that only AES-CBC hardware acceleration is supported by specific RouterBoard.
However, I can see the hardware acceleration flag on my CHR host if AES-GCM is used and no hardware acceleration flag if AES-CBC is used.
RouterOS version is 6.39.2
Any idea?
by eternal0
Fri Jan 20, 2017 6:51 am
Forum: General
Topic: Too many "group key timeout" when using CAPSMAN
Replies: 3
Views: 2898

Too many "group key timeout" when using CAPSMAN

I'm using CAPSMAN to provide wifi access. However, many iOS and Android devices disconnect very frequently with "group key timeout" in RouterOS log.
For legacy wireless ap, I can change group-key-update time to a longer one, but there isn't any way to change it in CAPSMAN.
Any solution?
by eternal0
Fri Jan 13, 2017 8:50 am
Forum: Wireless Networking
Topic: SGI w/CapsMan
Replies: 17
Views: 1906

Re: SGI w/CapsMan

Same issue.
It seems like this issue exist for a long time:
http://forum.mikrotik.com/viewtopic.php?t=103679
by eternal0
Thu Jun 23, 2016 6:00 am
Forum: RouterBOARD hardware
Topic: When will be RB3011UiAS-2HnD-IN available?
Replies: 65
Views: 19965

Re: When will be RB3011UiAS-2HnD-IN available?

Still waiting for it.
RB3011UiAS-RM is too big.
RB850Gx2 do not have enough ethernet ports. At least 8.
CRS's performance is poor.
CCR1009-8G-1S-PC is too expensive.
by eternal0
Mon May 23, 2016 4:46 pm
Forum: RouterBOARD hardware
Topic: RouterOS x86 Max Memory
Replies: 9
Views: 4044

Re: RouterOS x86 Max Memory

Probably not the case for the original poster, but I just wanted to mention that CHR uses 64-bit instruction sets and can utilize much more than 2GB: "Minimum 32MB of RAM (maximum supported 2GB, except on Cloud Core devices and CHR installations, where there is no maximum)" I wonder why CHR (IMG) v...
by eternal0
Tue Mar 08, 2016 7:37 am
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 93483

Re: Feature request: OpenVPN compression LZO and UDP

+1 for UDP.
TCP is much slower than UDP at high latency or high packet loss environment.
by eternal0
Sat Mar 05, 2016 3:44 am
Forum: RouterBOARD hardware
Topic: "hAP AC" with 802.3af/at PoE? Enterprise calling...
Replies: 20
Views: 6479

Re: "hAP AC" with 802.3af/at PoE? Enterprise calling...

ok, on it
You mean hAP ac have 802.3af/at PoE in, or other device have this?
by eternal0
Fri Feb 19, 2016 11:16 am
Forum: General
Topic: ECDSA cert support?
Replies: 5
Views: 1435

Re: ECDSA cert support?

bump
by eternal0
Thu Feb 18, 2016 10:36 am
Forum: RouterBOARD hardware
Topic: 256-bit OpenVPN @ 200/200 mbps
Replies: 15
Views: 11748

Re: 256-bit OpenVPN @ 200/200 mbps

I've also just found this thread: https://www.privateinternetaccess.com/forum/discussion/2845/openvpn-router-speeds/p2 By the sounds of it Microtik can do OpenVpn 256-bit @ 7Gbps.. Am I missing something? "Well I am getting a Miktotik CCR1009 now after being sold watching a friend of mine push 7Gbp...
by eternal0
Fri Feb 12, 2016 4:00 am
Forum: RouterBOARD hardware
Topic: Performance on newer Intel Atom boards?
Replies: 1
Views: 719

Re: Performance on newer Intel Atom boards?

In my environment, a 2-core i5-4350U device is more powerful than CCR1009 as a VPN server (EoIP+IPsec, SSTP, OVPN).
by eternal0
Sun Jan 10, 2016 3:32 am
Forum: RouterBOARD hardware
Topic: 256-bit OpenVPN @ 200/200 mbps
Replies: 15
Views: 11748

Re: 256-bit OpenVPN @ 200/200 mbps

OpenSSL is 100% CPU based and single threaded. In order to achieve what you want you will need a high-mhz CPU. X86 is really the only option. Not entirely true. OpenSSL can take advantage of kernel-module based crypto engines (/proc/crypto) Some ARM/MIPS hardware actually has crypto offload hardwar...
by eternal0
Sat Jan 09, 2016 11:11 am
Forum: RouterBOARD hardware
Topic: 256-bit OpenVPN @ 200/200 mbps
Replies: 15
Views: 11748

Re: 256-bit OpenVPN @ 200/200 mbps

1st issue is that RouterOS only supports TCP OpenVPN, that's it. UDP is not supported in any way and they say it won't ever be. OpenVPN? Mikrotik doesn't have one. OpenSSL is 100% CPU based and single threaded. In order to achieve what you want you will need a high-mhz CPU. X86 is really the only o...
by eternal0
Fri Dec 25, 2015 6:02 am
Forum: General
Topic: How to get "avg-rtt" result of "ping" command in scripts
Replies: 1
Views: 1372

How to get "avg-rtt" result of "ping" command in scripts

Hi all,
I need to get "avg-rtt" result of "ping" command in scripts. Is this possible?
Some one suggested "flood-ping" command. However, "flood-ping" will get "system is busy (12)" error if there is another instance running so it is not suitable for monitoring multiple endpoints.
by eternal0
Wed Nov 25, 2015 3:12 pm
Forum: RouterBOARD hardware
Topic: MB+CPU which you recommend for RouterOS? With power like core i3, 2,5ghz?
Replies: 16
Views: 2753

Re: MB+CPU which you recommend for RouterOS? With power like core i3, 2,5ghz?

1037U or J1900 + 1GB RAM + 4GB Flash + 8 or 4 GBE + RouterOS L4 only cost less than 200us.
What is the performance compared with RB850Gx2, RB1100AHx2, CCR1009 and the new RB3011?
by eternal0
Sun Oct 11, 2015 2:00 pm
Forum: RouterBOARD hardware
Topic: RB951G-2HnD CPU speed
Replies: 5
Views: 2771

Re: RB951G-2HnD CPU speed

My RB951G-2HnD can be stable at 700MHz for 1 month, and will be kernel failure every few hours at 750MHz.
by eternal0
Mon Sep 07, 2015 11:30 am
Forum: General
Topic: IPSec Hash and Encryption Algorithms?
Replies: 5
Views: 3170

Re: IPSec Hash and Encryption Algorithms?

Normal: Null + AES-256-GCM
Hardware accelerated RouterBOARD: sha256 + AES-256-CBC
by eternal0
Sun Aug 30, 2015 1:05 pm
Forum: General
Topic: Hardware encryption only support AES-xxx-CBC
Replies: 2
Views: 1848

Hardware encryption only support AES-xxx-CBC

I'm using RB850Gx2 running RouterOS 6.31.
It seems like only AES-xxx-CBC is supported by hardware encrytion, and the other AES-xxx-CTR/AES-xxx-GCM still use software encryption.
Is this real?

Another question is whether to support hardware encryption on SSTP and OVPN?
by eternal0
Wed Aug 26, 2015 5:14 am
Forum: General
Topic: excessive broadcast / loop error message
Replies: 5
Views: 982

Re: excessive broadcast / loop error message

Same problem on RB951G-2HnD ether1 as a LAN port.
by eternal0
Fri Aug 14, 2015 9:17 am
Forum: General
Topic: Now we need RSA support - OpenSSH 7.0 has removed DSA support
Replies: 3
Views: 818

Re: Now we need RSA support - OpenSSH 7.0 has removed DSA support

It seems like RouterOS does not support ECDSA.
by eternal0
Fri Aug 14, 2015 9:09 am
Forum: General
Topic: PPTP and L2TP/IPSec are NOT secure. Use OpenVPN.
Replies: 8
Views: 3543

Re: PPTP and L2TP/IPSec are NOT secure. Use OpenVPN.

Some firewall can identify and block the OpenVPN connection, so I think SSTP is the best.
SSTP client can work on Windows/Linux/OS X/Android.
by eternal0
Thu Jul 23, 2015 9:21 am
Forum: General
Topic: PPTP VPN unstable
Replies: 2
Views: 599

Re: PPTP VPN unstable

Can you try another VPN instead? Such as L2TP, SSTP, and OVPN. If all of your routers have public IP, you can use EoIP, IPIP or GRE.
by eternal0
Thu Jul 23, 2015 9:13 am
Forum: General
Topic: l2tp mtu vs pppoe mtu
Replies: 2
Views: 1032

Re: l2tp mtu vs pppoe mtu

Yes, you can transport 1500 bytes packets across the l2tp tunnel with no fragment. The L2TP packet will be fragmented if the size is over 1480 bytes. The cost is performance.
by eternal0
Thu Jul 23, 2015 9:07 am
Forum: General
Topic: transporting Vlans trough a EOIP tunnel ?
Replies: 3
Views: 1006

Re: transporting Vlans trough a EOIP tunnel ?

How can this be accomplished? 1. Bridge each VLAN to the EoIP tunnel at both ends? (this works with dedicated EoIP tunnels for each VLAN) 2. Bridge each Ethernet Port to the EoIP tunnel at both ends? (this is not working). Please let us know if there is another option where this can be done using a...
by eternal0
Fri Jul 17, 2015 5:49 am
Forum: General
Topic: Bonding ports toghter not getting speed
Replies: 4
Views: 789

Re: Bonding ports toghter not getting speed

When you are running test, please take a look at "Tools -> Profile".
by eternal0
Fri Jul 17, 2015 5:37 am
Forum: General
Topic: ipip tunnel for mikrotik routers in two countries
Replies: 1
Views: 331

Re: ipip tunnel for mikrotik routers in two countries

Set up an ipip tunnel on both routers.
Configure mark routing rule and disable NAT for vpn users on router 1.
Configure NAT on router 2.
by eternal0
Wed Jul 15, 2015 9:55 am
Forum: General
Topic: When will the RB3011 be available?
Replies: 3
Views: 1594

Re: When will the RB3011 be available?

It's the first RouterBoard based on ARM CPU. Thus it might encounter some problems.
by eternal0
Thu Jul 09, 2015 7:35 am
Forum: General
Topic: TRUNK over Eoip tunnel
Replies: 6
Views: 2833

Re: TRUNK over Eoip tunnel

Just bridge your ethernet and EoIP device on both of your router, it will work. VLAN in VLAN in EoIP also work fine. EoIP can be the same as physical layer-2 network, except the performance. The maximum throughput over an EoIP tunnel is 400Mbps on my two CCR1036 routers because it seems like the tun...
by eternal0
Fri Apr 24, 2015 9:02 am
Forum: General
Topic: Sector writes
Replies: 11
Views: 2449

Re: Sector writes

Same issue after upgraded to RouterOS 6.28 mipsbe.
Reboot can fix this issue on RB951G-2HnD, but make no effect on my RB751G-2HnD.
6 sector writes per second.
by eternal0
Sat Mar 14, 2015 1:51 pm
Forum: General
Topic: Tunnel get only 400Mbps on CCR1036
Replies: 12
Views: 3018

Re: Tunnel get only 400Mbps on CCR1036

2 Bonding tunnels ? No bonding, only 1 EoIP/IPIP/GRE tunnel. We also tested 2 EoIP and 2 EoIP as bonding slave(balance-rr). It seems like all tunnels share 400Mbps throughput. Maybe the tunnel module of RouterOS is single threaded, CCR series is not suitable for VPN tunnel, and we need a x86 device...
by eternal0
Fri Mar 13, 2015 2:44 am
Forum: General
Topic: Tunnel get only 400Mbps on CCR1036
Replies: 12
Views: 3018

Tunnel get only 400Mbps on CCR1036

Two CCR1036 connet directly to each other. 1000Mbps link speed. Bandwith test can get 990Mbps result.
If we set up an EoIP/IPIP/GRE tunnel between them, no encryption, the maximum throughput in tunnel is 400Mbps. The usage of cpu1 is 100% and the others is idle.

Is there any problem?
by eternal0
Thu Mar 05, 2015 8:20 am
Forum: General
Topic: ECDSA cert support?
Replies: 5
Views: 1435

Re: ECDSA cert support?

bump
by eternal0
Thu Mar 05, 2015 8:19 am
Forum: General
Topic: vlan and bridge question
Replies: 0
Views: 367

vlan and bridge question

We need to config vlan and bridge, but I'm confused with two configurations below.
bridge1
|--ether1

1. vlan1 interface=ether1
2. vlan1 interface=bridge1

What's the difference between 1 and 2?
by eternal0
Sun Feb 01, 2015 5:16 pm
Forum: General
Topic: Hardware requirement CPU vs RAM
Replies: 5
Views: 1158

Re: Hardware requirement CPU vs RAM

For most RouterBoard devices: RAM is enough (if you do not use MetaROUTER, and all RouterBoard with multi-core CPU do not have this feature), CPU performance is poor.
by eternal0
Sat Jan 24, 2015 2:27 am
Forum: General
Topic: Mikrotik as an SSTP Client to a Windows 2008 R2 Server
Replies: 1
Views: 771

Re: Mikrotik as an SSTP Client to a Windows 2008 R2 Server

Try "ping 192.168.2.1" on your SSTP server. It seems like your SSTP server doesn't have the proper route for your client's subnet.
by eternal0
Fri Jan 23, 2015 2:44 am
Forum: General
Topic: Dual WAN VPN with failover
Replies: 8
Views: 2365

Re: Dual WAN VPN with failover

But you suggest using SSTP/OVPN as point 1 in your solution. Do I misunderstand?
I suggest it for security(RSA4096+SHA512+AES256).
If you need high performance, use IPIP/PPTP instead. Of course, you still need to configure Mangle Rule and Routing Table.
by eternal0
Thu Jan 22, 2015 5:16 pm
Forum: General
Topic: Dual WAN VPN with failover
Replies: 8
Views: 2365

Re: Dual WAN VPN with failover

Hi eteranl, thank you for sharing this solution. As I have read EoIP suffers performance, is there a better alternative? Would this work? 1. SSTP/OVPN to connect each WAN to each pper 2. MPLS/VPLS over VPN tunnel If you can accept tcp connection reset on failover, just use any Tunnel is OK. EoIP an...
by eternal0
Thu Jan 15, 2015 6:43 am
Forum: General
Topic: Reboot The Router. When and Why?
Replies: 6
Views: 1179

Re: Reboot The Router. When and Why?

Some packages is not stable.
For example, sstp, ovpn and dns server often crash in some 6.x version, you must reboot your router if it doesn't work.

If you use it only for static routing, bridging, and firewall, RouterOS can work for several months without reboot.
by eternal0
Fri Jan 09, 2015 2:39 pm
Forum: General
Topic: Dual WAN VPN with failover
Replies: 8
Views: 2365

Re: Dual WAN VPN with failover

1.Use SSTP/OVPN to connect to each IP. You need to configure Mangle Rule and Routing Table to make the network flow using proper WAN connection.
2.Set up EoIP tunnel for each SSTP/OVPN.
3.Set up bonding for each pair of EoIP tunnel. In your case you need 3 bonding.
4.Enjoy!
by eternal0
Thu Jan 08, 2015 5:06 pm
Forum: General
Topic: Sonic wall speed vs. Mikrotik speed
Replies: 8
Views: 1869

Re: Sonic wall speed vs. Mikrotik speed

Which model?
CCR1036 is much powerful than my old H3C F1000, and very cheap. However, MikroTik doesn't support HA. VRRP failover is too slow in some cases.
by eternal0
Sun Jan 04, 2015 1:52 pm
Forum: General
Topic: RouterOS to act as syslog server ?
Replies: 6
Views: 1592

Re: RouterOS to act as syslog server ?

You can't use RouterOS as a syslog server.
However, you can install OpenWRT in MetaROUTER. It is possible to run syslog server and many other applications on OpenWRT.
by eternal0
Sun Jan 04, 2015 1:44 pm
Forum: General
Topic: changeip.com script for ver 6.24
Replies: 4
Views: 5276

Re: changeip.com script for ver 6.24

I think old script works well in 6.24. :local ddnsuser "username@changeip" :local ddnspass "password@changeip" :local ddnshost "domain@changeip" :local ddnsinterface "interface_name" :global ddnslastip :local ddnsip [ /ip address get [/ip address find interface=$ddnsinterface] address ] :if ([ :type...
by eternal0
Thu Jan 01, 2015 4:18 pm
Forum: General
Topic: ECDSA cert support?
Replies: 5
Views: 1435

ECDSA cert support?

It seems ECDSA certificate cannot work on RouterOS. The key size is "unknown", and I can't import private key to the router.
by eternal0
Tue Dec 09, 2014 3:58 pm
Forum: RouterBOARD hardware
Topic: CCR1036-8G-2S+ SFP Problems
Replies: 48
Views: 38165

Re: CCR1036-8G-2S+ SFP Problems

Same problem in CCR1036-8G-2S+EM.
10G SFP+ module works well on both side. But with 1G SFP module, the router show link OK on the status and no link on the switch at the other end.
by eternal0
Fri Jun 20, 2014 6:08 pm
Forum: General
Topic: WNA1100(AR9271) doesn't work in ROS v6
Replies: 1
Views: 607

WNA1100(AR9271) doesn't work in ROS v6

Hello.
I use ROS 6.15 x86 and plug a WNA1100(AR9271)
It appears in reosurces->USB, but there is no interface in wlan interfaces.
If I use ROS 5.20, it works fine!
Why?

I also tested WNA1100 on RB751G-2HnD and RB951G-2HnD running ROS 6.15, it doesn't work as on x86 platform.