Community discussions

Search found 153 matches

by kamillo
Thu Jul 04, 2019 10:46 am
Forum: General
Topic: Marketing Banana award (by Packetpusher) to MicroTik’s Cloud Router Switch
Replies: 0
Views: 156

Marketing Banana award (by Packetpusher) to MicroTik’s Cloud Router Switch

Greg Ferro of Packetpusher awarded Marketing Banana award to MicroTik’s Cloud Router Switch https://content.blubrry.com/packetpushers/NB_241_Extreme_Buys_Aerohive_Sloppy_BGP_Plumbing_Causes_Route_Leak.mp3 listen from 32:23 https://packetpushers.net/podcast/network-break-241-extreme-buys-aerohive-slo...
by kamillo
Wed Jun 19, 2019 7:59 pm
Forum: Announcements
Topic: MikroTik News June 2019 (Issue #89)
Replies: 36
Views: 7688

Re: MikroTik News June 2019 (Issue #89)

Not a first mistake like this, you should claim your free MUM ticket.
viewtopic.php?f=21&t=135236&p=666260&hi ... et#p666260
by kamillo
Mon May 20, 2019 3:22 pm
Forum: General
Topic: How to log everything and send to remote syslog server?
Replies: 1
Views: 159

Re: How to log everything and send to remote syslog server?

Hi, 1. You could potentially use log action in firewall rules. I would be interested to hear other options/ ideas 2. I personally use Graylog https://www.graylog.org/ , it is free as opposed to Splunk. Can scale (Elasticsearch as search engine), probably you will need to write log parser for easier ...
by kamillo
Sat May 18, 2019 2:37 pm
Forum: General
Topic: IPv6 Address Assignment Hint
Replies: 4
Views: 1768

Re: IPv6 Address Assignment Hint

Sorry to bump the old thread, has this been implemented?
by kamillo
Wed May 15, 2019 11:20 am
Forum: General
Topic: Elasticsearch, Logtash and Kibana Setup Mikrotik ELK Stak
Replies: 3
Views: 299

Re: Elasticsearch, Logtash and Kibana Setup Mikrotik ELK Stak

Hi, I don't think anyone will be able to "just help" you with ELK. This is huge topic. Do you have specific problem or just hoping for "how to- step by step" instruction. There is a topic about Splunk and Mikrotik, you may want to check it if looking for inspiration: https://forum.mikrotik.com/viewt...
by kamillo
Wed Apr 03, 2019 4:52 pm
Forum: Wireless Networking
Topic: Single SSID multiple passwords
Replies: 8
Views: 619

Re: Single SSID multiple passwords

I understand that I will need a guest VLAN, but how can I have two passwords for the same SSID, where each password determines which VLAN the client connects to?
//Nizar
I think this can be achieved with RADIUS authentication.
https://wiki.mikrotik.com/wiki/Manual:RADIUS_Client
by kamillo
Tue Apr 02, 2019 4:18 pm
Forum: General
Topic: Trunk Port on MT4011 (RTL8367)
Replies: 7
Views: 443

Re: Trunk Port on MT4011 (RTL8367)

From the document you posted: Warning: Not all devices with a switch chip are capable of VLAN switching on a hardware level, check the supported features for each switch chip, the compatibility table can be found Here. When you follow the "here" link: You will see that RB4011 doesn't support VLAN ta...
by kamillo
Fri Feb 08, 2019 3:47 pm
Forum: Announcements
Topic: v6.43.11 [stable] is released!
Replies: 79
Views: 10829

Re: v6.43.11 [stable] is released!

Hi 2 all! If I'll upgrade mikrotik from 6.42.1 to 6.43.11 with a lot firewall rules, caps-man and vlan created I will get problem that something will not work ?
No one can possibly answer that question. Start with checking changelogs: https://mikrotik.com/download/changelogs
by kamillo
Tue Feb 05, 2019 9:49 am
Forum: Beginner Basics
Topic: RB4011
Replies: 3
Views: 334

Re: RB4011

Here you will find more some documentation and examples: https://wiki.mikrotik.com/wiki/Manual:TOC
by kamillo
Mon Nov 26, 2018 4:50 pm
Forum: General
Topic: Windows update + Proxy
Replies: 5
Views: 529

Re: Windows update + Proxy

Depending on version and edition of Windows they use, you could look into: Delivery optimization https://docs.microsoft.com/en-gb/windows/deployment/update/waas-delivery-optimization There is also something called BranchCache https://docs.microsoft.com/en-gb/windows/deployment/update/waas-branchcach...
by kamillo
Thu Nov 15, 2018 9:44 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 354
Views: 60680

Re: RB4011

https://linitx.com/search.php?keywords=rb4011 says:
Stock expected 7-Dec-2018
by kamillo
Thu Nov 01, 2018 5:26 pm
Forum: General
Topic: Urgent help for configure
Replies: 2
Views: 350

Re: Urgent help for configure

You don't give too much details to go by...
maybe you should hire consultant: https://mikrotik.com/consultants
by kamillo
Tue Oct 23, 2018 10:39 am
Forum: RouterOS v6 RC and v7 BETA
Topic: v6 RC and v7 BETA
Replies: 126
Views: 22406

Re: v6 RC and v7 BETA

2 years ago the ROS 7.0 was on alpha 134:

Image
https://mobile.twitter.com/mikrotik_com ... 4195920896
by kamillo
Thu Sep 27, 2018 6:21 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 354
Views: 60680

Re: RB4011

cdr.pl initial claimed arrival at the mid September then changed that to "Beginning of October". https://linitx.com has date of 16th of October
by kamillo
Thu Jun 07, 2018 10:16 am
Forum: Beginner Basics
Topic: RB750Gr3 as basic switch
Replies: 12
Views: 1338

Re: RB750Gr3 as basic switch

Be aware of the max speeds you can get. Check the below link

https://mikrotik.com/product/RB750Gr3#fndtn-testresults
by kamillo
Wed Apr 11, 2018 1:15 pm
Forum: Wireless Networking
Topic: wAP AC vs cAP AC
Replies: 8
Views: 3335

Re: wAP AC vs cAP AC

To my understanding it means that traffic will be capped at that speed only if it will have to go through all 25 rules before it is matched. Usually, as the first rule, you would have something to allow all established and related connections. Therefore most of the traffic would be matched by the fi...
by kamillo
Mon Apr 09, 2018 5:44 pm
Forum: Wireless Networking
Topic: wAP AC vs cAP AC
Replies: 8
Views: 3335

Re: wAP AC vs cAP AC

Check https://mikrotik.com/product/RB3011UiAS ... estresults you will see that RB3011 can do 1Gbps but of course it will depend how you use it.
by kamillo
Thu Feb 08, 2018 10:17 am
Forum: General
Topic: Possible to set DHCPv6 option 16?
Replies: 1
Views: 291

Re: Possible to set DHCPv6 option 16?

This feature is now only in RuterOS 6.42 RC
*) dhcpv6-server - added DHCPv4 style user options;
https://mikrotik.com/download/changelog ... lease-tree
by kamillo
Mon Jan 15, 2018 10:58 am
Forum: Announcements
Topic: v6.41 [current]
Replies: 304
Views: 74104

Re: v6.41 [current]

You can try Netinstall to reinstall RouterOS:

https://wiki.mikrotik.com/wiki/Manual:Netinstall
by kamillo
Sat Jan 13, 2018 1:36 pm
Forum: Beginner Basics
Topic: CRS125-24G-1S-RM Fios Gigabit WAN
Replies: 2
Views: 288

Re: CRS125-24G-1S-RM Fios Gigabit WAN

Hi, CRS125 has rather weak CPU so it may not handle all the things you want to do. Saying that I'm using CRS125 as my home switch/ router. I have 70Mbps up and 10Mbps Internet connection, whole bunch of firewall rules and for most of the time CPU usage is around 5%. Use switch chip where you can ins...
by kamillo
Thu Jan 04, 2018 11:29 am
Forum: General
Topic: Meltdown and Spectre Security Vulnerabilities on x86
Replies: 13
Views: 2341

Re: Meltdown and Spectre Security Vulnerabilities on x86

I'm not sure about that, according to "The Register" On a shared system, such as a public cloud server, it is possible, depending on the configuration, for software in a guest virtual machine to drill down into the host machine's physical memory and steal data from other customers' virtual machines....
by kamillo
Wed Dec 27, 2017 11:45 am
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 538
Views: 92436

Re: v6.42rc [release candidate] is released!

Admire the spirit, Christmas period and you are releasing new (RC) version. But looking at changes 4 out of 6 are fixes so this sounds more like 6.41.1 not 6.42.
by kamillo
Tue Dec 05, 2017 1:27 pm
Forum: Beginner Basics
Topic: CRS125 and InterVlan-Routing
Replies: 8
Views: 540

Re: CRS125 and InterVlan-Routing

Don't use bridges on CRS125. Bridging is done in software therefore uses CPU which is very weak on CRS125. Use switch vlan. https://wiki.mikrotik.com/wiki/Manual:CRS_examples#VLAN The above comment doesn't apply if you are using 6.41RCxx of the RouterOS, they have change how bridges work but this ve...
by kamillo
Tue Dec 05, 2017 12:52 pm
Forum: Beginner Basics
Topic: CRS125 and InterVlan-Routing
Replies: 8
Views: 540

Re: CRS125 and InterVlan-Routing

Hi,

Can you show your interfaces, bridges and vlans config?
by kamillo
Wed Nov 22, 2017 12:44 pm
Forum: General
Topic: ipv6 - unable to reach beyond mikrotik.
Replies: 25
Views: 1385

Re: ipv6 - unable to reach beyond mikrotik.

This is probably long shot but can you check what you have in your mikrotik device in ipv6 settings.
There is setting called "ip-forward", this should be set to yes.

https://wiki.mikrotik.com/wiki/Manual:IPv6/Settings
by kamillo
Tue Nov 21, 2017 4:48 pm
Forum: General
Topic: ipv6 - unable to reach beyond mikrotik.
Replies: 25
Views: 1385

Re: ipv6 - unable to reach beyond mikrotik.

Do you have any rules in the firewall? Maybe traffic gets blocked there.
by kamillo
Wed Nov 15, 2017 8:58 pm
Forum: RouterBOARD hardware
Topic: Hardware recommendation for SOHO environment
Replies: 9
Views: 1137

Re: Hardware recommendation for SOHO environment

Hi, For APs I would go for wAP AC, they can be powered via PoE and they are good looking. Router wise, if he needs at least 8 ports I would say RB2011 or RB3011, depending on a budget and Internet speed connection. They are 2 issues with above routers, RB3011 has got only one PoE out port so you wil...
by kamillo
Fri Nov 10, 2017 1:06 pm
Forum: Announcements
Topic: v6.41rc [release candidate] is released! New bridge implementation!
Replies: 561
Views: 119857

Re: v6.41rc [release candidate] is released! New bridge implementation!

To add to JimmyNyholm's comment: I'm still waiting for LACP hardware support (offload) in CRS125
by kamillo
Tue Oct 31, 2017 3:54 pm
Forum: RouterOS v7
Topic: Mikrotik Cloud Switch
Replies: 1
Views: 692

Re: Mikrotik Cloud Switch

by kamillo
Fri Oct 27, 2017 6:06 pm
Forum: Announcements
Topic: v6.40.4 [current]
Replies: 103
Views: 24463

Re: v6.40.4 [current]

You can try to login to console and see what went wrong....
by kamillo
Thu Oct 26, 2017 3:56 pm
Forum: General
Topic: SFP VDSL2 Modem
Replies: 1
Views: 3967

Re: SFP VDSL2 Modem

There is whole thread RE this: viewtopic.php?f=3&t=104109
by kamillo
Thu Oct 26, 2017 10:29 am
Forum: Beginner Basics
Topic: CRS125 Port Isolation
Replies: 2
Views: 345

Re: CRS125 Port Isolation

Not sure how one would do that but maybe this will help: https://wiki.mikrotik.com/wiki/Manual:C ... #Isolation
by kamillo
Thu Oct 19, 2017 11:03 am
Forum: Announcements
Topic: v6.40.4 [current]
Replies: 103
Views: 24463

Re: v6.40.4 [current]

CPU load on my WAP AC is nearly 0%, also 6.40.4 version (managed by CAPSMAN)
by kamillo
Fri Oct 13, 2017 1:13 pm
Forum: Announcements
Topic: v6.41rc [release candidate] is released! New bridge implementation!
Replies: 561
Views: 119857

Re: v6.41rc [release candidate] is released! New bridge implementation!

How to downgrade to an older rc? I cannot find a download-link.
Go to https://mikrotik.com/download

Grab a link to latest RC for your platform and edit url to the version you want.

https://download2.mikrotik.com/routeros/6.41rc38/routeros-mipsbe-6.41rc38.npk
by kamillo
Fri Oct 13, 2017 10:31 am
Forum: General
Topic: Mikrotik IPV6 Network, IPV4 ISP
Replies: 4
Views: 720

Re: Mikrotik IPV6 Network, IPV4 ISP

On your internal network you can have IPv6 regardless of what your ISP is offering, but you will not be able to communicate to the rest of the world over IPv6.

Other solution is to look at IPv6 tunnel, something like this:
https://tunnelbroker.net/
by kamillo
Sat Oct 07, 2017 7:16 pm
Forum: Beginner Basics
Topic: Firewall Rules
Replies: 2
Views: 951

Re: Firewall Rules

Hi, I would suggest to move your allow, fastrack and related/ established rules to the top of the list, otherwise even already established sessions (trusted) will be checked against bogons lists rules etc. Also consider moving rules which check against bogons list to the raw table more about raw tab...
by kamillo
Thu Oct 05, 2017 10:09 am
Forum: Beginner Basics
Topic: Help to understand log - Possible Attack?
Replies: 5
Views: 624

Re: Help to understand log - Possible Attack?

Yes it is possible, if you do something like that:
filter add chain=input src-address=58.218.198.171/32 in-interface=ether1 action=drop log=yes
RouterOS will drop packets from 58.218.198.171 incoming on interface ether1 and will also log an action (you will see an entry in the logs)
by kamillo
Wed Oct 04, 2017 10:04 am
Forum: Beginner Basics
Topic: Help to understand log - Possible Attack?
Replies: 5
Views: 624

Re: Help to understand log - Possible Attack?

Hi, The connections are coming on port ether1 18:30:45 firewall,info input: in:ether1 out:(none), src-mac 58:f3:9c:3d:bb:1a, proto TCP (SYN), 58.218.198.171:60001->myWAN:22, len 60 therefore correct firewall rule should be: filter add chain=input src-address=58.218.198.171/32 in-interface=ether1 act...
by kamillo
Mon Sep 25, 2017 10:38 am
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 15
Views: 6368

Re: Feature request: OpenVPN compression LZO and UDP

According to Normis UDP support is coming in v7:
teaser:

Code: Select all

What's new in 7.0 alpha
*) added support for UDP OpenVPN;
viewtopic.php?f=1&t=26499&hilit=Teaser& ... 00#p617477
by kamillo
Wed Sep 06, 2017 4:50 pm
Forum: General
Topic: IPv6 support
Replies: 5
Views: 886

Re: IPv6 support

Start with this: https://wiki.mikrotik.com/wiki/Manual:IPv6

You will need to enable IPv6 package first.
by kamillo
Fri Aug 25, 2017 11:32 am
Forum: General
Topic: IPv6 and DHCP and DNS
Replies: 65
Views: 10491

Re: IPv6 and DHCP and DNS

The RFC (4941) part you are referring to uses world SHOULD so it is not compulsory to have that. Additionally the same RFC says (note world MUST): Devices implementing this specification MUST provide a way for the end user to explicitly enable or disable the use of temporary addresses. So event if t...
by kamillo
Fri Aug 25, 2017 10:44 am
Forum: General
Topic: IPv6 and DHCP and DNS
Replies: 65
Views: 10491

Re: IPv6 and DHCP and DNS

"Privacy extension" looks like invention for consumer end of the market not enterprise. In enterprise environment you can control your devices and disable "privacy extension".
But I agree with above comments. Proper DHCPv6 server implementation would be very welcome addition to RouterOS
by kamillo
Fri Aug 04, 2017 1:39 pm
Forum: Beginner Basics
Topic: ipV6 dhcp
Replies: 7
Views: 721

Re: ipV6 dhcp

If you need IPv6 only for internal use set pool to something like: name: "pool name" prefix: fd00:9324:28ac::/64 prefix length: 64 next in IPv6 address list add address ::/64 from pool: "pool name" interface: <your internal network interface> tick: advertise this is quick why to configure internal I...
by kamillo
Fri Aug 04, 2017 12:02 pm
Forum: Beginner Basics
Topic: ipV6 dhcp
Replies: 7
Views: 721

Re: ipV6 dhcp

If your ISP does not provide IPv6, you can not access Internet over IPv6. IPv4 and IPv6 are different protocols. If you want to use IPv6 to access the Internet you can use IPv6 tunnel. Do some reading to understand IPv6 better, you can start here: https://wiki.mikrotik.com/wiki/Manual:IPv6/Address h...