Community discussions

MikroTik App

Search found 771 matches

by eworm
Fri Mar 05, 2021 1:01 pm
Forum: General
Topic: IKEv2 Can't Get Private Key [SOLVED]
Replies: 3
Views: 138

Re: IKEv2 Can't Get Private Key [SOLVED]

This indicates you selected a certificate without private key.
by eworm
Wed Feb 17, 2021 6:01 pm
Forum: Announcements
Topic: v6.47.9 [long-term] is released!
Replies: 65
Views: 12744

Re: v6.47.9 [long-term] is released!

1. How do you know that this attribute changes on this version? 2. where is the documentation for read it about the changes that affect to the attribute on the new RouterOS version? Just get the column name from CLI, Winbox, Webfig, ... I do not think that the changes are documented. Whenever somet...
by eworm
Wed Feb 17, 2021 3:07 pm
Forum: Announcements
Topic: v6.47.9 [long-term] is released!
Replies: 65
Views: 12744

Re: v6.47.9 [long-term] is released!

The problem is that /ip dns cache does no longer have an attribute "address", it was renamed to "data".
So replace that in the line where tmpAddress is assigned.
by eworm
Wed Feb 17, 2021 2:22 pm
Forum: Announcements
Topic: v6.47.9 [long-term] is released!
Replies: 65
Views: 12744

Re: v6.47.9 [long-term] is released!

For me scripting works just fine. Can you be more precise what you think does not (or no longer) work?
by eworm
Sat Feb 13, 2021 1:09 am
Forum: RouterOS v7 BETA
Topic: v7.1beta4 [development] is released!
Replies: 185
Views: 24119

Re: v7.1beta4 [development] is released!

export hanging is a huge problem to evaluate 7.xy beta

IMHO first priority should be fixing export issue
Full ACK! I do not even consider testing before this is fixed.
by eworm
Tue Feb 09, 2021 1:46 pm
Forum: Announcements
Topic: v6.48.1 [stable] is released!
Replies: 100
Views: 19410

Re: v6.48.1 [stable] is released!

Wouldn't matter if MikroTik configured their domain host/CDN correctly like this:
Image
No. There's nothing Mikrotik can do on their servers. If the attacker is successful no request will ever reach Mikrotik's servers.
by eworm
Tue Feb 09, 2021 10:03 am
Forum: Announcements
Topic: v6.48.1 [stable] is released!
Replies: 100
Views: 19410

Re: v6.48.1 [stable] is released!

BTW, the copyright needs to be updated for 2021... It still reads: MikroTik RouterOS 6.48.1 (c) 1999-2020 http://www.mikrotik.com/ (And when you are at it... How about changing the url to https?) They have enabled HTTPS overwrite on their domain, technically it wouldn't matter. But you'd expect a &...
by eworm
Mon Feb 08, 2021 7:06 pm
Forum: Announcements
Topic: v6.48.1 [stable] is released!
Replies: 100
Views: 19410

Re: v6.48.1 [stable] is released!

BTW, the copyright needs to be updated for 2021... It still reads:
MikroTik RouterOS 6.48.1 (c) 1999-2020       http://www.mikrotik.com/
(And when you are at it... How about changing the url to https?)
by eworm
Thu Feb 04, 2021 1:04 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta4 [development] is released!
Replies: 185
Views: 24119

Re: v7.1beta4 [development] is released!

*) api - added support for REST API;
With this being added... How about a JSON parser within RouterOS? This would allow one device to call another device's REST API.
by eworm
Thu Feb 04, 2021 12:01 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta4 [development] is released!
Replies: 185
Views: 24119

Re: v7.1beta4 [development] is released!

Looks like export still hangs...
by eworm
Mon Feb 01, 2021 6:01 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 62181

Re: v6.48 [stable] is released!

Same here, rock solid on all my devices: [admin@himalia] > :foreach Device in=[ /ip neighbor find where !(version="") ] do={ :put [ /ip neighbor get $Device uptime ]; } 5w5d03:40:30 5w5d03:40:30 5w5d02:35:32 5w5d02:35:39 5w5d03:32:51 5w5d03:33:36 5w5d03:37:38 5w5d03:37:49 5w5d03:37:52 5w5d...
by eworm
Sun Jan 31, 2021 8:25 pm
Forum: General
Topic: 24v 800mA power supply failure
Replies: 3
Views: 286

Re: 24v 800mA power supply failure

At least two of them died for me the last years. But as most devices are powered via POE I have some spare ones.
The power supplies are less reliable than the devices itself, definitely.
by eworm
Tue Jan 26, 2021 5:27 pm
Forum: Scripting
Topic: Script Error
Replies: 3
Views: 264

Re: Script Error

Yes, you are missing a command. 😜

The fourth line should look something like this:
:if ([/ip firewall nat get [find comment="DNS - Redirect all DNS requests to pihole"] disabled] = false) do={
by eworm
Fri Jan 22, 2021 1:22 pm
Forum: Scripting
Topic: Send one email and stop
Replies: 11
Views: 665

Re: Send one email and stop

Eworm, I apologise if you have already written the solution somewhere on your website, I rarely open external links on public forums. I didn't mean to disrespect anyone. :) I have a collection of script, one of them does what plisken wants - and a lot more. But it is complex and depends on other sc...
by eworm
Fri Jan 22, 2021 10:09 am
Forum: Scripting
Topic: Send one email and stop
Replies: 11
Views: 665

Re: Send one email and stop

I do not understand why you do not test or even consider using my scripts.
What's wrong there?
by eworm
Thu Jan 21, 2021 11:17 pm
Forum: Scripting
Topic: Send one email and stop
Replies: 11
Views: 665

Re: Send one email and stop

BTW, this also can send notification to via Telegram. I have messages about temperature alert and recovery in my history, looks like this:
Screenshot_2021-01-21_22-12-50.png
by eworm
Thu Jan 21, 2021 11:12 pm
Forum: Scripting
Topic: Send one email and stop
Replies: 11
Views: 665

Re: Send one email and stop

Well, as for PSU state... You could use my script for this as well.
Notify about health state

Still you need the base installation, follow main README for this.
by eworm
Wed Jan 20, 2021 9:37 pm
Forum: General
Topic: DNSpooq
Replies: 3
Views: 389

Re: DNSpooq

The software dnsmasq is not used in RouterOS, so no.
by eworm
Wed Jan 20, 2021 3:14 pm
Forum: Scripting
Topic: Command to create directory?
Replies: 6
Views: 14300

Re: Command to create directory?

A file name containing just a dot represents the current directory. So you create the directory and try to overwrite it with a file... This results in an error:
  status: failed

failure: cannot open file
With your code you have to catch and ignore the error.
I prefer my clean solution. 😜
by eworm
Wed Jan 20, 2021 2:20 pm
Forum: General
Topic: OpenSSH future RSA host key deprecation
Replies: 9
Views: 4024

Re: OpenSSH future RSA host key deprecation

The problem was solved... So what exactly is your problem?
by eworm
Wed Jan 20, 2021 2:15 pm
Forum: Scripting
Topic: Send email if PSU fails
Replies: 8
Views: 617

Re: Send email if PSU fails

This is fully functional if you do the base installation to meed the requirements. 😜
by eworm
Wed Jan 20, 2021 12:20 pm
Forum: Scripting
Topic: Send email if PSU fails
Replies: 8
Views: 617

Re: Send email if PSU fails

If you are really interested... This is the script source:
https://git.eworm.de/cgit/routeros-scri ... eck-health

But as said... It will not work on its own and has dependencies to other scripts.
by eworm
Wed Jan 20, 2021 9:25 am
Forum: Scripting
Topic: Send email if PSU fails
Replies: 8
Views: 617

Re: Send email if PSU fails

Showing the script source would not help... It depends on other scripts.
As said... Follow the main README, then install the wanted script.
by eworm
Wed Jan 20, 2021 12:43 am
Forum: Scripting
Topic: Send email if PSU fails
Replies: 8
Views: 617

Re: Send email if PSU fails

You can try my script:
Notify about health state
This requires the base installation, see main README.
by eworm
Wed Jan 13, 2021 12:49 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 62181

Re: v6.48 [stable] is released!

reviewed all this, found some problems, where people was wrong setup and using default proposals, and still no answer - in my case PFS group and proposals are setuped correctly, on both sides. If on both sides in proposals PFS group is 2048 and lifetime 30, is it a mistake? Search this thread for p...
by eworm
Tue Jan 12, 2021 1:04 am
Forum: General
Topic: Solved: DNS unable to resolve host
Replies: 10
Views: 3954

Re: Solved: DNS unable to resolve host

Yes, it works. But keep in mind that you have to disable DoH (DNS over HTTPS) for this!
by eworm
Fri Jan 08, 2021 6:28 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 62181

Re: v6.48 [stable] is released!

Best is to open a support ticket with the complains. I did not for 6.47 - in hope anything happens with the details in release thread... Will open a ticket myself soon. I had thought about an extra Raspberry Pi for DNS... But that would be a share for Mikrotik routers. Also this is not an option for...
by eworm
Fri Jan 08, 2021 6:04 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 62181

Re: v6.48 [stable] is released!

It seems static DNS records of type FWD are ignored once a DoH server is added. Is this a design decision or a bug? If this is not going to change, we'll never be able to use it, because we need conditional forwarding. It has been this way since DoH has been introduced in 6.47 - see older release t...
by eworm
Tue Jan 05, 2021 12:14 pm
Forum: General
Topic: IP Cloud
Replies: 71
Views: 30438

Re: IP Cloud

You can not. The device's serial number is used in dynamic DNS name.

If you want a name that does not change on new hardware use a CNAME:
my-static-name.example.com -> serial.sn.mynetname.com.

If you can not reconfigure the clients it is too late, though...
by eworm
Sun Jan 03, 2021 8:30 pm
Forum: General
Topic: [SOLVED] Script does not execute via Scheduler on startup
Replies: 7
Views: 624

Re: Script does not execute via Scheduler on startup

Wondering if your solution is over-complicated... How about something like this? :while ([ :len [ / interface detect-internet state find where state=internet ] ] = 0) do={ :delay 200ms; } # your follow-up code here... If you really have to check for the interface just add name="ether8-gateway&q...
by eworm
Sun Jan 03, 2021 2:31 pm
Forum: General
Topic: [SOLVED] Script does not execute via Scheduler on startup
Replies: 7
Views: 624

Re: Script does not execute via Scheduler on startup

With :local inside the loop you limit the scope of the variable. Initialize it before, then use :set inside loop.

Will have to check this on real hardware, currently typing on my mobile.
by eworm
Sun Jan 03, 2021 1:54 pm
Forum: General
Topic: [SOLVED] Script does not execute via Scheduler on startup
Replies: 7
Views: 624

Re: Script does not execute via Scheduler on startup

Once entered the script will never leave the loop as neither $waniface nor $wangateway is modified inside.

Please keep in mind that internet detect feature can cause lot of trouble. I would recommend not to use it.
by eworm
Sun Jan 03, 2021 1:35 pm
Forum: General
Topic: [SOLVED] Script does not execute via Scheduler on startup
Replies: 7
Views: 624

Re: Script does not execute via Scheduler on startup

The script is run when the interface is not yet available. Just add a delay.
by eworm
Sun Jan 03, 2021 12:46 am
Forum: Scripting
Topic: How to delete the specified ip connection with a script? [SOLVED]
Replies: 11
Views: 671

Re: How to delete the specified ip connection with a script? [SOLVED]

/ip firewall connection remove [find where reply-dst-address~"1.2.3.4"] This will also remove connections for addresses 11.2.3.4 and 1.2.3.44 ... Better match beginning and end of the address when using regular expressions: /ip firewall connection remove [ find where reply-dst-address~&qu...
by eworm
Mon Dec 28, 2020 11:17 am
Forum: General
Topic: ikev2 2 sessions under one certificate [SOLVED]
Replies: 2
Views: 327

Re: ikev2 2 sessions under one certificate [SOLVED]

You need a dedicated client certificate for every device.
by eworm
Mon Dec 28, 2020 10:52 am
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 62181

Re: v6.48 [stable] is released!

Please help if you experiencing similar issues as I have no idea where to even start troubleshooting.
Have a look above, IPSec issues have been discussed before.
by eworm
Mon Dec 28, 2020 10:47 am
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 62181

Re: v6.48 [stable] is released!

Thats odd - I've got pfs set in phase 2 and the IKEv2 tunnel establishes correctly:
Yes, they establish correctly. But do they rekey without issue? Have a look at your log...
by eworm
Sat Dec 26, 2020 6:48 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 62181

Re: v6.48 [stable] is released!

See this and the following posts from emils about the details:
viewtopic.php?f=2&t=147769#p740153
by eworm
Sat Dec 26, 2020 6:22 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 62181

Re: v6.48 [stable] is released!

Yes, that's what should be set to none IMHO.
Look at first line, dh-group=modp4096 is used for dh in phase 1 and for PFS in phase 2.
by eworm
Sat Dec 26, 2020 4:34 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 62181

Re: v6.48 [stable] is released!

Now on rekey childs mikrotik send and want proposals without pfs despite pfs-group=ecp521 configured. Similar issue has Windows 7 time ago. With IKEv2 the pfs group is inherited from phase 1, have a look at dh group in profiles. Perfect forward secret should be used even if set to none in proposals...
by eworm
Sat Dec 19, 2020 11:22 am
Forum: Scripting
Topic: Removing ip addresses in a list based on another
Replies: 7
Views: 745

Re: Removing ip addresses in a list based on another

Ah, did not know it is documented... Found it the hard way myself. 😆
by eworm
Sat Dec 19, 2020 1:10 am
Forum: Scripting
Topic: Feature request: logical operator "in" for IP ranges
Replies: 1
Views: 450

Re: Feature request: logical operator "in" for IP ranges

Let's have a looks:
[admin@mikrotik] > :put (192.168.0.1-192.168.0.254)
4294967043
The addresses are subtracted, so your original command evaluated to:
[admin@mikrotik] > :put (192.168.0.1 in 4294967043) 
false
Wondering if bitwise operators could help...
by eworm
Sat Dec 19, 2020 12:49 am
Forum: Scripting
Topic: Fail Variable declaration sintax from manual
Replies: 6
Views: 457

Re: Fail Variable declaration sintax from manual

You should use curly brackets, not square brackets. So correct code:
{ :local myVar; :set myVar "my value"; :log info $myVar; }
by eworm
Sat Dec 19, 2020 12:38 am
Forum: Scripting
Topic: Reading POE status with script
Replies: 7
Views: 2456

Re: Reading POE status with script

This looks over complicated... How about this: :global showPoeST do={ :foreach Interface in=[ / interface ethernet poe find ] do={ :local IntVal [ / interface ethernet poe monitor $Interface as-value once ]; :put ($IntVal->"name" . " -> " . $IntVal->"poe-out-status"); }...
by eworm
Sat Dec 19, 2020 12:03 am
Forum: Scripting
Topic: Removing ip addresses in a list based on another
Replies: 7
Views: 745

Re: Removing ip addresses in a list based on another

But next two find 1.0.0.0 in all address lists, so there's some problem with list=$list. But what could it be? Have a look at this commit, it explains the issue: https://git.eworm.de/cgit/routeros-scripts/commit/?id=870f00bb36f5af3088344371764da48bbde9651a Short conclusion: You are safe if your var...
by eworm
Wed Dec 09, 2020 11:49 am
Forum: RouterOS v7 BETA
Topic: ROS V7 for ARM64?
Replies: 9
Views: 1220

Re: ROS V7 for ARM64?

Regarding the topic... LHGG is not ARM64 but ARM, no?
by eworm
Thu Dec 03, 2020 7:16 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta3 [development] is released!
Replies: 262
Views: 42998

Re: v7.1beta3 [development] is released!

Also all free disk space is gone. Right after update it showed 8kB free, then I deleted two autosupouts to get at least something, but instead ended with nothing: free-hdd-space: 0 total-hdd-space: 59.5MiB The CHR images have been 128MB in size for a really long time now. Possibly this is a very ol...
by eworm
Thu Dec 03, 2020 2:33 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta3 [development] is released!
Replies: 262
Views: 42998

Re: v7.1beta3 [development] is released!

Looks like my wireguard tunnel is down after update... Did not check the details, will have to investigate later.
The peer's endpoint-port was set to 0. After setting the correct port everything is back up now.
by eworm
Thu Dec 03, 2020 12:42 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta3 [development] is released!
Replies: 262
Views: 42998

Re: v7.1beta3 [development] is released!

Looks like my wireguard tunnel is down after update... Did not check the details, will have to investigate later.
by eworm
Sun Nov 29, 2020 1:24 am
Forum: Scripting
Topic: Checking the empty value [SOLVED]
Replies: 6
Views: 816

Re: Checking the empty value [SOLVED]

Damn, I've typed this from a mobile without checking... You are right, it does not work. Sorry for the confusion. To go into detail... [admin@MikroTik] > :global z; [admin@MikroTik] > :put [ :typeof $z ] nothing [admin@MikroTik] > :put [ :typeof [] ] nil There's a difference between "nothing&qu...
by eworm
Sun Nov 29, 2020 1:10 am
Forum: Scripting
Topic: Updating CA root certs regularly [SOLVED]
Replies: 9
Views: 725

Re: Updating CA root certs regularly [SOLVED]

Certificates that do not change are untouched. Have a look at the import output, it should give some numbers.
by eworm
Fri Nov 27, 2020 7:10 pm
Forum: Scripting
Topic: Updating CA root certs regularly [SOLVED]
Replies: 9
Views: 725

Re: Updating CA root certs regularly [SOLVED]

No need to remove all certificates... You could just remove the expired ones to clean up.
/certificate remove [ find where authority expired ];
by eworm
Fri Nov 27, 2020 6:12 pm
Forum: Announcements
Topic: v6.47.8 [stable] is released!
Replies: 56
Views: 13200

Re: v6.47.8 [stable] is released!

Oh, is this a winbox issue? I testen via cli (SSH), not winbox.
by eworm
Fri Nov 27, 2020 5:43 pm
Forum: Announcements
Topic: v6.47.8 [stable] is released!
Replies: 56
Views: 13200

Re: v6.47.8 [stable] is released!

Health works on all devices I checked, including these reported with issues before by others:

CCR1036-8G-2S+
CRS328-24P-4S+
by eworm
Fri Nov 27, 2020 4:47 pm
Forum: Announcements
Topic: v6.47.8 [stable] is released!
Replies: 56
Views: 13200

Re: v6.47.8 [stable] is released!

RBD52G-5HacD2HnD (HAP AC2) does not have health information. It just does not have hardware sensors.
by eworm
Sun Nov 22, 2020 6:04 pm
Forum: Scripting
Topic: Removing Certificate [SOLVED]
Replies: 4
Views: 496

Re: Removing Certificate [SOLVED]

You should never ever use index numbers in scripts. These are just temporary and refer to the last print.
To remove all certificates use this:
/certificate remove [ find ];
by eworm
Sun Nov 22, 2020 5:58 pm
Forum: Scripting
Topic: Checking the empty value [SOLVED]
Replies: 6
Views: 816

Re: Checking the empty value [SOLVED]

Because your variable is nothing, but you check for an empty string. That's something different. Try this:
:global z; 
:if ($z=[]) do={:put "hello world";}
by eworm
Mon Nov 16, 2020 3:31 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 387
Views: 97254

Re: v7.1beta2 [development] is released!

I think this is a known problem with TILE, have seen other reports before.
(I do not have beta3, so I can not check there.)
Oh, ignore this post... CCR2004 is ARM64, not TILE.
by eworm
Mon Nov 16, 2020 3:26 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 387
Views: 97254

Re: v7.1beta2 [development] is released!

I think this is a known problem with TILE, have seen other reports before.
(I do not have beta3, so I can not check there.)
by eworm
Wed Nov 11, 2020 10:54 am
Forum: Scripting
Topic: Cant read file large then 4085 bytes
Replies: 15
Views: 5202

Re: Cant read file large then 4085 bytes

Ah, you are right, it did not work back in 2016.
What I described requires fetching to variable, that was introduced with RouterOS 6.43 in late 2018.
by eworm
Wed Nov 11, 2020 10:45 am
Forum: RouterOS v7 BETA
Topic: Wireguard performance???
Replies: 4
Views: 1323

Re: Wireguard performance???

Your problem is fasttrack. Make sure the connections to your vpn are not fasttracked and you are fine.
Search the forum with that keyword, you should find enough information.
by eworm
Wed Nov 11, 2020 10:38 am
Forum: Scripting
Topic: Cant read file large then 4085 bytes
Replies: 15
Views: 5202

Re: Cant read file large then 4085 bytes

Here is where you just kicked the can down the road. The running script can't compare the two script files for same or different because of the variable size limitation -- precisely my original complaint. Please read my post again. The limitation is not the variable size - it is just the reading fr...
by eworm
Tue Nov 10, 2020 9:56 pm
Forum: RouterOS v7 BETA
Topic: Why DNS-record updates not working?
Replies: 16
Views: 774

Re: Why DNS-record updates not working?

But you do not have to manually remove and add the address list entry, no?
So wondering why mutluit has to.
by eworm
Tue Nov 10, 2020 7:26 pm
Forum: RouterOS v7 BETA
Topic: Why DNS-record updates not working?
Replies: 16
Views: 774

Re: Why DNS-record updates not working?

That said I gave it a try myself... Looks like RouterOS actually does update the address list entry when ttl expires: /ip firewall address-list add address=et-contents.s3.eu-west-1.amazonaws.com list=test /ip firewall address-list print interval=5s follow where comment="et-contents.s3.eu-west-1...
by eworm
Tue Nov 10, 2020 7:16 pm
Forum: RouterOS v7 BETA
Topic: Why DNS-record updates not working?
Replies: 16
Views: 774

Re: Why DNS-record updates not working?

The problem with the address list is that it stores the IP, whereas for my use-case it would suffice if it would operate on domain name only. Somehow... This is an address list, it operates on addresses. Creating dynamic address list entries from domain names is a convenient feature, but it is not ...
by eworm
Tue Nov 10, 2020 6:36 pm
Forum: RouterOS v7 BETA
Topic: Why DNS-record updates not working?
Replies: 16
Views: 774

Re: Why DNS-record updates not working?

There's no need to blame DNS server in RouterOS - that works as expected and is completely unrelated to your problem.
The address list is something completely different, and it can not be use (reliably) the way you expect it.
by eworm
Tue Nov 10, 2020 5:24 pm
Forum: Scripting
Topic: Cant read file large then 4085 bytes
Replies: 15
Views: 5202

Re: Cant read file large then 4085 bytes

And I'm stuck with the conclusion that there is absolutely no other way to do what it is I needed to do. Sure there is. 😜 The only limitation is for file size. This does not apply for script size ( /system script ) for example. So fetch your script to a variable, then store it as script ( /system s...
by eworm
Tue Nov 10, 2020 5:07 pm
Forum: Scripting
Topic: :return not as described?
Replies: 7
Views: 408

Re: :return not as described?

Returning the value and leaving the function is the behavior for every language. Everything else does not make sense: What would you return if the function continues and a second return is executed. How to leave the function early? A beter naming for return would then be exit No, return is to return...
by eworm
Tue Nov 10, 2020 4:58 pm
Forum: RouterOS v7 BETA
Topic: Why DNS-record updates not working?
Replies: 16
Views: 774

Re: Why DNS-record updates not working?

But that is how things work. What do you think this should work like?
by eworm
Tue Nov 10, 2020 4:44 pm
Forum: RouterOS v7 BETA
Topic: Why DNS-record updates not working?
Replies: 16
Views: 774

Re: Why DNS-record updates not working?

Or for details on that specific domain: [admin@MikroTik] > /ip dns cache print where name="consent.youtube.com" Flags: S - static # NAME TYPE DATA TTL 0 consent... A 172.217.17.142 3m8s Note that TTL here is the actual time remaining in cache, not what the upstream server gave.
by eworm
Tue Nov 10, 2020 4:41 pm
Forum: RouterOS v7 BETA
Topic: Why DNS-record updates not working?
Replies: 16
Views: 774

Re: Why DNS-record updates not working?

The domain has a time to live (ttl) of 299 seconds. RouterOS caches the record for this time, see / ip dns cache.
This is correct behavior and should not be changed.
by eworm
Tue Nov 10, 2020 1:41 pm
Forum: RouterOS v7 BETA
Topic: Error: DNS adding domain name with Umlaut [SOLVED]
Replies: 10
Views: 706

Re: Error: DNS adding domain name with Umlaut [SOLVED]

You have to use IDN encoding. Try this: xn--allestrungen-9ib.de
by eworm
Fri Nov 06, 2020 3:26 pm
Forum: Announcements
Topic: MikroTik newsletter November 2020 (#98)
Replies: 64
Views: 13811

Re: MikroTik newsletter November 2020 (#98)

Looks like I bought my LHG LTE6 kit too early... 😝

I had hoped for something like the new wAP ac. But looks like it is missing a POE out or pass through option on the second ethernet port, no? I would like to mount it next to the LHG LTE6 and power that - with just one ethernet cable up to the mast.
by eworm
Fri Nov 06, 2020 9:27 am
Forum: Scripting
Topic: PPPoE access concentrator /users getting no ip until remove from active/
Replies: 4
Views: 381

Re: PPPoE access concentrator /users getting no ip until remove from active/

Regarding your post in general section it should... So try this: :foreach Active in=[ / ppp active find ] do={ :local ActiveVal [ / ppp active get $Active ]; :if ([ :len [ / ip address find where address=($ActiveVal->"address" . "/32") dynamic ] ] = 0) do={ / ppp active remove $A...
by eworm
Fri Nov 06, 2020 8:59 am
Forum: Scripting
Topic: PPPoE access concentrator /users getting no ip until remove from active/
Replies: 4
Views: 381

Re: PPPoE access concentrator /users getting no ip until remove from active/

Yes, all connections are killed because addresses are listed with netmask in / ip address . Given that line: # NAME SERVICE CALLER-ID ADDRESS UPTIME ENCODING 0 xxxxxxxxx... pppoe 00:27:22:24:14:XX 192.168.169.182 10h53... Would this print the matching ip address entry? /ip address print where addres...
by eworm
Thu Nov 05, 2020 10:03 pm
Forum: Scripting
Topic: PPPoE access concentrator /users getting no ip until remove from active/
Replies: 4
Views: 381

Re: PPPoE access concentrator /users getting no ip until remove from active/

I do not have a PPPoE access concentrator around, but something like this could work: :foreach Active in=[ / ppp active find ] do={ :local ActiveVal [ / ppp active get $Active ]; :if ([ :len [ / ip address find where address=($ActiveVal->"address") dynamic ] ] = 0) do={ / ppp active remove...
by eworm
Thu Nov 05, 2020 6:17 pm
Forum: General
Topic: ssh key auth issues between two rOS devices
Replies: 7
Views: 395

Re: ssh key auth issues between two rOS devices

Now these commands are to be used in scripts run by the scheduler - will that be run with the account of the script owner?
Yes.
by eworm
Thu Nov 05, 2020 5:28 pm
Forum: General
Topic: ssh key auth issues between two rOS devices
Replies: 7
Views: 395

Re: ssh key auth issues between two rOS devices

So it's not the user "remote" here?
Import your private key for the standard company-wide admin account, not "remote".
by eworm
Thu Nov 05, 2020 5:02 pm
Forum: General
Topic: ssh key auth issues between two rOS devices
Replies: 7
Views: 395

Re: ssh key auth issues between two rOS devices

The local device running
/sys ssh-exec ...
- what user is running this?
by eworm
Thu Nov 05, 2020 3:52 pm
Forum: General
Topic: ssh key auth issues between two rOS devices
Replies: 7
Views: 395

Re: ssh key auth issues between two rOS devices

Please show your available keys on both sides:
/user ssh-keys print
/user ssh-keys private print
by eworm
Thu Nov 05, 2020 10:27 am
Forum: General
Topic: Netinstall on Linux without root!
Replies: 2
Views: 269

Re: Netinstall on Linux without root!

Glad it works for you. Can't be that wrong then. For me it is not locally/manually installed as I built an Arch Linux package for it. 😜 But I get your point. I think I will polish this a bit and push it to github... The path will be configurable at compile-time only, as granting privileges for a run...
by eworm
Thu Nov 05, 2020 9:24 am
Forum: General
Topic: Netinstall on Linux without root!
Replies: 2
Views: 269

Netinstall on Linux without root!

Netinstall was reported to run on Linux when started as user root. I've never tried - I think starting wine, which is required, as root is a bad idea. With a detailed look the problem seems simple: Netinstall needs to bind to a privileged port, that is port 69 for tftp. All it needs is a special cap...
by eworm
Thu Nov 05, 2020 1:11 am
Forum: General
Topic: Using netinstall from linux [SOLVED]
Replies: 3
Views: 2245

Re: Using netinstall from linux [SOLVED]

I've been struggling with this as well. Looks like netinstall fails to send a reply if the linux host does not have a default route set. After setting a default route everything works just fine.
by eworm
Thu Oct 29, 2020 4:36 pm
Forum: RouterOS v7 BETA
Topic: My Backup to Mail script dont work anymore with ROS7 [SOLVED]
Replies: 4
Views: 590

Re: My Backup to Mail script dont work anymore with ROS7 [SOLVED]

Recently lost my crystal ball...
What does your script look like?
by eworm
Thu Oct 29, 2020 9:39 am
Forum: Announcements
Topic: v6.47.6 [stable] is released!
Replies: 39
Views: 7944

Re: v6.47.6 [stable] is released!

After upgrade from 6.46.3 to 6.47.6 I have error: error while running customized default configuration script: expected end of command (line 1337 column 53) This is a known issue when wireless package is disabled, but nothing to worry about. The default configuration script is an internal one that ...
by eworm
Wed Oct 28, 2020 10:27 pm
Forum: General
Topic: What does factory only release means?
Replies: 3
Views: 283

Re: What does factory only release means?

Are you speaking about 6.47.5? That was run in Mikrotik labs only, but was never released to the public - probably due to issues.
by eworm
Fri Oct 23, 2020 6:09 pm
Forum: General
Topic: Wildcard DNS
Replies: 15
Views: 1366

Re: Wildcard DNS

Same thing happens with international characters, e.g. you can add ěščřžýáíé.example.net, which you might expect to be internally translated to punycode version xn--1caql6dzd0drw5bzo.example.net, because why else would RouterOS accept it, right? But it doesn't happen, it will store exactly what you...
by eworm
Fri Oct 23, 2020 10:38 am
Forum: General
Topic: Error after upgrading to 6.47.6
Replies: 4
Views: 787

Re: Error after upgrading to 6.47.6

There's no impact, just an annoying error message.
by eworm
Thu Oct 22, 2020 6:49 pm
Forum: RouterBOARD hardware
Topic: POE port red on switch, with connected WAP
Replies: 22
Views: 977

Re: POE port red on switch, with connected WAP

The color indicates POE output type. IIRC green is for passive POE and red is for 802.3af/at.
This is not related to the link.
by eworm
Thu Oct 22, 2020 5:41 pm
Forum: General
Topic: Error after upgrading to 6.47.6
Replies: 4
Views: 787

Re: Error after upgrading to 6.47.6

This is a know issue from early 6.48 beta releases... It happens on devices without wireless package.
No idea why they backported the issue but skipped the fix...
by eworm
Thu Oct 22, 2020 2:17 pm
Forum: Announcements
Topic: v6.47.6 [stable] is released!
Replies: 39
Views: 7944

Re: v6.47.6 [stable] is released!

This is now suffering the log messages on default configuration script we had in testing before:
system;error;critical error while running customized default configuration script: expected end of command (line 1337 column 53)
This happens without wireless package only.
by eworm
Mon Oct 19, 2020 10:51 pm
Forum: Scripting
Topic: Log monitor script [SOLVED]
Replies: 5
Views: 3622

Re: Log monitor script [SOLVED]

I think my script log-forward could serve your needs... Though it does not only notify about failed login attempts but everything interesting - configurable with filters.
It depends on other scripts, see the main README on how to install this.
by eworm
Fri Oct 16, 2020 8:13 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 185
Views: 65329

Re: v6.48beta [testing] is released!

So a general remark: I think cases should remain browseable for the submitter, even after they have been closed by MikroTik.
I am pretty sure they are. Log in to the support portal and see your closed cases.
by eworm
Thu Oct 15, 2020 11:27 pm
Forum: Scripting
Topic: Got ip firewall rules state/flag
Replies: 2
Views: 234

Re: Got ip firewall rules state/flag

ok, I already found it.: /put [ip firewall filter get number=1 disabled] You should never use index in scripts, that will break! Instead find the correct rule with whatever criteria it has, for example giving it the comment "first": :put [ /ip firewall filter get [ find where comment=&quo...
by eworm
Thu Oct 15, 2020 11:23 pm
Forum: Scripting
Topic: Generate script from another script [SOLVED]
Replies: 2
Views: 405

Re: Generate script from another script [SOLVED]

Sure it does. In this example you should add quotes I guess...
by eworm
Mon Oct 12, 2020 5:25 pm
Forum: Scripting
Topic: system script error, console OK
Replies: 1
Views: 223

Re: system script error, console OK

Your variable is declared too late. It is valid inside the blocks only. Try this:
:global xc;
:if ([ /ping 192.168.5.54 size=28 interval=30ms count=1 ] = 0) do={
  :set xc 20;
} else={
  :set xc 50;
}
:log warning $xc;
by eworm
Mon Oct 12, 2020 5:18 pm
Forum: Scripting
Topic: script works in terminal windwo but not in scheduler [SOLVED]
Replies: 3
Views: 424

Re: script works in terminal windwo but not in scheduler [SOLVED]

Use this: # we are not interested in output, but print is # required to fetch information from cloud / system backup cloud print as-value; / system backup cloud upload-file action=create-and-upload password=$BackupPassword replace=[ get ([ find ]->0) name ]; If you want this to be fully automated an...
by eworm
Mon Oct 12, 2020 5:13 pm
Forum: Scripting
Topic: external editor syntax highlighting
Replies: 42
Views: 54080

Re: external editor syntax highlighting

My editor of choice is vis - a modern, legacy free, simple yet efficient vim-like editor.
I added a RouterOS script lexer, that is now available in git master.
by eworm
Mon Oct 12, 2020 5:01 pm
Forum: Scripting
Topic: Run "down" scripts only if user does not reconnect within time
Replies: 2
Views: 341

Re: Run "down" scripts only if user does not reconnect within time

Does this have to be associated to the vpn disconnect and (re-)connect? I have a script netwatch-notify that does monitor ip addresses via netwatch. It has a simple state machine to ignore a (configurable) number of failed attempts. (You have to install the base scripts for this to work, see main RE...
by eworm
Mon Oct 12, 2020 3:42 pm
Forum: General
Topic: SFTP uploads to remote SFTP server [SOLVED]
Replies: 6
Views: 635

Re: SFTP uploads to remote SFTP server

The path set in /tool fetch url=... is rather absolute path from server's root (not from users home directory). That depends on the configuration. My sftp accounts are jailed into a chroot and limited to sftp only (with openssh's sftp-server). So for me the path is relative to the chroot directory.
by eworm
Mon Oct 12, 2020 3:12 pm
Forum: General
Topic: SFTP uploads to remote SFTP server [SOLVED]
Replies: 6
Views: 635

Re: SFTP uploads to remote SFTP server

The path on your server exists? You need a subdirectory"ftp" with write permission.
by eworm
Fri Oct 09, 2020 9:50 am
Forum: General
Topic: SSH error "can't agree on KEX algorithms"
Replies: 9
Views: 1205

Re: SSH error "can't agree on KEX algorithms"

Error shows up on 2 routers.
These are the only Mikrotik devices or does it work on others?
by eworm
Fri Oct 09, 2020 9:29 am
Forum: General
Topic: SSH error "can't agree on KEX algorithms"
Replies: 9
Views: 1205

Re: SSH error "can't agree on KEX algorithms"

The error message indicates this is about key exchange algorithms , but following the log it was agreed on diffie-hellman-group-exchange-sha256 . In fact it was not agreed on the host key algorithms . Looks like both support rsa-sha2-256 , no idea why it is not used. BTW, ssh-dss and ssh-rsa are val...
by eworm
Thu Oct 08, 2020 9:52 am
Forum: General
Topic: DoH config ignores local static entries
Replies: 7
Views: 750

Re: DoH config ignores local static entries

Static entries do work, but behavior changed a bit. I've described the issue in v6.47 release thread.

In short:
Without DoH a single A record does cover everything. With DoH enabled it will check for AAAA record upstream.
by eworm
Thu Oct 08, 2020 9:29 am
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 387
Views: 97254

Re: v7.1beta2 [development] is released!

It is just efficient!
Right you are. But it is important to shorten the quote to what you actually intend to quote, just as we both did.
Quoting a post including a quote, including a quote, including a quote .... does not add mutch value.
So I am all for quotes if done right.
by eworm
Tue Oct 06, 2020 2:15 pm
Forum: General
Topic: Problem with SSH Login
Replies: 1
Views: 271

Re: Problem with SSH Login

What ssh client do you use? Can you give the exact error message?

A blind guess if everything else fails: regenerate your host keys:
/ip ssh regenerate-host-key
by eworm
Wed Sep 30, 2020 12:58 am
Forum: Scripting
Topic: Is it possible to make a DHCP lease script which adds a DNS record for a device through its MAC address?
Replies: 1
Views: 294

Re: Is it possible to make a DHCP lease script which adds a DNS record for a device through its MAC address?

Perhaps my script dhcp-to-dns may be of interest... If I got you right it does what you want.
(It depends on more scripts, so see main README for installation.)
by eworm
Fri Sep 18, 2020 9:26 am
Forum: General
Topic: When doh is enabled, DNS Forward will be unavailable
Replies: 1
Views: 249

Re: When doh is enabled, DNS Forward will be unavailable

This is a known problem, look at the release threads.
Mikrotik did not (yet) react on this. No answers, no changes.
by eworm
Thu Sep 17, 2020 10:31 am
Forum: General
Topic: hAP ac2 over heated vent holes mod
Replies: 16
Views: 1201

Re: hAP ac2 over heated vent holes mod

Any details on the temperatures before and after the mod?
by eworm
Thu Sep 17, 2020 1:41 am
Forum: RouterOS v7 BETA
Topic: Wireguard not working behind internet facing router with DSTNAT v7.1beta2
Replies: 57
Views: 6291

Re: Wireguard not working behind internet facing router with DSTNAT v7.1beta2

Does it make a difference if you lower the mtu size on wireguard interfaces?
On Device B?
Yes, on device B and on your client. I think the mtu should match on both sides. No idea what happens if it does not.
by eworm
Thu Sep 17, 2020 1:36 am
Forum: RouterOS v7 BETA
Topic: Wireguard not working behind internet facing router with DSTNAT v7.1beta2
Replies: 57
Views: 6291

Re: Wireguard not working behind internet facing router with DSTNAT v7.1beta2

Does it make a difference if you lower the mtu size on wireguard interfaces?
by eworm
Mon Sep 14, 2020 8:04 pm
Forum: Announcements
Topic: v6.46.7 [long-term] is released!
Replies: 45
Views: 11565

Re: v6.46.7 [long-term] is released!

By the way what does this one mean. *) interface - added new builtin "static" interface list; This is a very interesting changelog item, one that has never been in a stable (or development) release. I find confusing that this comes to the long term release with barely no testing, has been...
by eworm
Sat Sep 12, 2020 6:43 pm
Forum: General
Topic: Announcements of LTE firmware releases
Replies: 5
Views: 579

Re: Announcements of LTE firmware releases

It is part of a bigger collection and requires the base installation at least. See the main README for details. Configuration for e-mail and telegram goes to global configuration.
by eworm
Wed Sep 09, 2020 11:47 pm
Forum: RouterOS v7 BETA
Topic: Wireguard not working behind internet facing router with DSTNAT v7.1beta2
Replies: 57
Views: 6291

Re: Wireguard not working when behind internet facing router with DSTNAT

Is there are firewall rule that does source NAT just after destination NAT for the incoming packet? Possibly that confuses wireguard...
What interfaces are in interface list "WAN"?
by eworm
Wed Sep 09, 2020 5:13 pm
Forum: General
Topic: Announcements of LTE firmware releases
Replies: 5
Views: 579

Re: Announcements of LTE firmware releases

You could can use my script for release notification:
Notify on LTE firmware upgrade

Of course this does not give a hint what changed.
by eworm
Wed Sep 09, 2020 11:33 am
Forum: General
Topic: Reset Button feature not working
Replies: 5
Views: 620

Re: Reset Button feature not working

It is not. But would be nice...
Missing this on some devices, including CCR1009 & mAP (lite). Would have to check all my devices for a complete list.
by eworm
Tue Sep 08, 2020 6:01 pm
Forum: General
Topic: Reset Button feature not working
Replies: 5
Views: 620

Re: Reset Button feature not working

Not all devices support this... Try the following code to check: :if ([ :len [ /system routerboard mode-button print as-value ] ] > 0) do={ :put "Mode button supported."; } :if ([ :len [ /system routerboard reset-button print as-value ] ] > 0) do={ :put "Reset button supported.";...
by eworm
Tue Sep 08, 2020 5:30 pm
Forum: RouterOS v7 BETA
Topic: Wireguard not working behind internet facing router with DSTNAT v7.1beta2
Replies: 57
Views: 6291

Re: Wireguard not working when behind internet facing router with DSTNAT

Ah, I misread and misunderstood some details. So both peers are behind NAT, one is supposed to be reachable via destination NAT.
Never tried that with wireguard, no idea if this should work.
by eworm
Tue Sep 08, 2020 4:30 pm
Forum: RouterOS v7 BETA
Topic: Wireguard not working behind internet facing router with DSTNAT v7.1beta2
Replies: 57
Views: 6291

Re: Wireguard not working when behind internet facing router with DSTNAT

Ok, some questions here:

Why do you configure wireguard on device B, not device A?

What does the other side look like? Does it have a public address without NAT? If it does: Things should work without destination NAT if connection is initiated from device behind NAT.
by eworm
Tue Sep 08, 2020 3:48 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 387
Views: 97254

Re: v7.1beta2 [development] is released!

But Wireguard with Mikrotik behind NAT is not a problem for me.
Share a secret )
I'm sorry, but there's no secret... Just works for me.
Show you configuration export, possibly there's something fishy.
/interface/wireguard/export hide-sensitive
by eworm
Tue Sep 08, 2020 3:15 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 387
Views: 97254

Re: v7.1beta2 [development] is released!

Wireguard does not connect from Mikrotik behind NAT to a Linux server with a white IP.
What is a "white IP"?
But Wireguard with Mikrotik behind NAT is not a problem for me.
by eworm
Tue Sep 08, 2020 2:11 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 185
Views: 65329

Re: v6.48beta [testing] is released!

Not sure this is working ? The DoH server I'm using is https://doh.opendns.com/dns-query , and I see requests to 146.112.41.2 , but none to 2620:119:fc::2
I guess IPv4 is still preferred if a domain resolves with A and AAAA record. Try a domain that has just an AAAA record or use IPv6 address.
by eworm
Thu Sep 03, 2020 12:02 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 387
Views: 97254

Re: v7.1beta2 [development] is released!

Wireguard endpoints are set and updated automatically on handshake. Huh. Are you sure that both of endpoint can be updated automatically? Nevertheless, I can't find any example of routeros setup with one of the peers is with endpoint (e.g. "client") and other is without ("server"...
by eworm
Thu Sep 03, 2020 9:39 am
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 387
Views: 97254

Re: v7.1beta2 [development] is released!

Wireguard endpoints are set and updated automatically on handshake.
by eworm
Wed Sep 02, 2020 9:37 pm
Forum: General
Topic: WireGuard Released !
Replies: 41
Views: 28765

Re: WireGuard Released !

So I was going to send the link but thought better of it......... Instead try this www.google.com Are you nuts? I know how to use google and I know the link given by IPANetEngineer. My understanding was that the answer was about connecting to NordVPN via Wireguard, which is not handled by Rick Frey...
by eworm
Wed Sep 02, 2020 4:17 pm
Forum: General
Topic: WireGuard Released !
Replies: 41
Views: 28765

Re: WireGuard Released !

What manual are you speaking about? Can you give a link?
by eworm
Wed Sep 02, 2020 4:06 pm
Forum: Scripting
Topic: Telegram
Replies: 6
Views: 1014

Re: Telegram

The Telegram Bot API documentation regarding sending files is here:
https://core.telegram.org/bots/api#sending-files

Not sure this works with fetch command... Probably not.
by eworm
Wed Sep 02, 2020 12:30 am
Forum: Scripting
Topic: How to check if value is empty?
Replies: 9
Views: 7575

Re: How to check if value is empty?

Answering myself... Looks like this is executing an empty command, which evaluates to "nil":
[admin@mt] > :put [ :typeof [] ]
nil
by eworm
Wed Sep 02, 2020 12:26 am
Forum: Scripting
Topic: How to check if value is empty?
Replies: 9
Views: 7575

Re: How to check if value is empty?

For the inversion you have to use parenthesis:
... where !(comment=[])
Really nice to have this... Is this documented anywhere?
by eworm
Thu Aug 27, 2020 6:48 pm
Forum: RouterOS v7 BETA
Topic: Not a fan of the new (/) slash notation.
Replies: 16
Views: 1161

Re: Not a fan of the new (/) slash notation.

Wait for RouterOS v8 for an answer on that. :D
by eworm
Wed Aug 26, 2020 1:29 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 387
Views: 97254

Re: v7.1beta2 [development] is released!

This is by design. Peers are identified by their public key, changing the endpoint automatically makes it roam seamlessly.
If the peer changes its address the configuration should update again.
by eworm
Tue Aug 25, 2020 4:49 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 387
Views: 97254

Re: v7.1beta2 [development] is released!

Ah, stupid me... Of course it's keepalive.
/ interface gre unset keepalive [ find ]
by eworm
Tue Aug 25, 2020 3:21 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 387
Views: 97254

Re: v7.1beta2 [development] is released!

You have to unset the timeout for GRE interfaces:
/ interface gre unset timeout [ find ]
by eworm
Mon Aug 24, 2020 5:07 pm
Forum: RouterOS v7 BETA
Topic: Feature Request - Wireguard Protocol
Replies: 165
Views: 55469

Re: Feature Request - Wireguard Protocol

Testing on a RB951G (mipsbe with 600MHz single core) with a 100/40 MBit/s uplink: I could do 90/38 MBit/s through the tunnel - with bandwidth-test on the device itself. Pretty impressive given that IPSec barely does 20 MBit/s... So can't wait to see WireGuard in a stable version... I hope it does no...
by eworm
Mon Aug 24, 2020 1:11 pm
Forum: General
Topic: WireGuard Released !
Replies: 41
Views: 28765

Re: WireGuard Released !

NordVPN uses more than just a plain WireGuard connection... This is to make sure an individual can not be associated with public traffic.
I can not give any more detail, though... I would be interested to make this work as well.
by eworm
Fri Aug 21, 2020 11:01 pm
Forum: Announcements
Topic: v6.47.2 [stable] is released!
Replies: 90
Views: 18389

Re: v6.47.2 [stable] is released!

Yes, I got that, and I second your request.
But for now only my method is available. ;)
by eworm
Fri Aug 21, 2020 6:50 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 387
Views: 97254

Re: v7.1beta2 [development] is released!

Wireguard support cool thing, but where is an instruction how to use it?
Configuring wireguard is pretty straight forward. Just look at the options available.
by eworm
Fri Aug 21, 2020 6:22 pm
Forum: Announcements
Topic: v6.47.2 [stable] is released!
Replies: 90
Views: 18389

Re: v6.47.2 [stable] is released!

No, it is not too hard. My scripts collection (see signature) has a function for that. Just run...
$DownloadPackage wireless
... and reboot to install the package. (The also supports downloading packages in other version or for different architecture, for example to use with capsman.)
by eworm
Wed Aug 19, 2020 1:27 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 185
Views: 65329

Re: v6.48beta [testing] is released!

btw.after install I see in log this :
system,error,critical,,, error while running customized default configuration script: expected end of command (line 1315 column 53)
Me too. Reported for 6.47beta12 as SUP-21264, just re-opened.
by eworm
Tue Aug 18, 2020 7:04 pm
Forum: Scripting
Topic: script to check if dns is running
Replies: 5
Views: 727

Re: script to check if dns is running

No... You can do something like this: :local PIHOLEHOST "pihole.example.com" :local PIHOLEHOSTIP [:resolve $PIHOLEHOST] :log info "PI-Hole script started... ($PIHOLEHOSTIP)" :if ([/ping $PIHOLEHOSTIP interval=1 count=1] = 1) do={ :log info "PI-Hole host is UP! (ping)" :...
by eworm
Tue Aug 18, 2020 5:04 pm
Forum: Scripting
Topic: script to check if dns is running
Replies: 5
Views: 727

Re: script to check if dns is running

I guess the script is terminated on error... Try to catch it:
:do {
  :resolve ...
} on-error={
  ...
}
by eworm
Tue Aug 18, 2020 12:19 am
Forum: General
Topic: IKEv2 between MikroTiks, sides switching, initiator <> responder
Replies: 13
Views: 1991

Re: IKEv2 between MikroTiks, sides switching, initiator <> responder

send-initial-contact=yes is not an instruction to act as initiator; it actually means "replace any already existing connection from my IP address, irrespective of port, by this new one", so it is quite dangerous in some scenarios (multiple initiators coming to the responded from behind th...
by eworm
Fri Aug 14, 2020 5:00 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 185
Views: 65329

Re: v6.48beta [testing] is released!

Indeed... We are bored, give us something to play with!
by eworm
Thu Aug 13, 2020 6:06 pm
Forum: General
Topic: How prevent IPSec from adding dynamic DNS servers? [SOLVED]
Replies: 3
Views: 1045

Re: How prevent IPSec from adding dynamic DNS servers? [SOLVED]

IIRC the functionality was added in 6.46, the configuration option in 6.47.
Look up the changelog if you are interested in details.
by eworm
Thu Aug 13, 2020 5:28 pm
Forum: General
Topic: How prevent IPSec from adding dynamic DNS servers? [SOLVED]
Replies: 3
Views: 1045

Re: How prevent IPSec from adding dynamic DNS servers? [SOLVED]

Just disable dns in mode-config:
/ip ipsec mode-config set use-responder-dns=no NordVPN
by eworm
Thu Aug 13, 2020 2:15 pm
Forum: Scripting
Topic: script trigger on interface down
Replies: 1
Views: 439

Re: script trigger on interface down

Sadly there is no functionality to hook into interface events.
You could run a script via scheduler that checks link status for the ports in very short interval.
by eworm
Thu Aug 13, 2020 2:09 pm
Forum: Scripting
Topic: Multi script mode button
Replies: 1
Views: 588

Re: Multi script mode button

I have something very similar in my scripts collection: Mode button with multiple presses
I think it has some advantages and configuration goes to a central script.
by eworm
Tue Aug 11, 2020 10:34 am
Forum: General
Topic: DoH max concurrent queries reached
Replies: 9
Views: 3498

Re: DoH max concurrent queries reached

Looks like there is a hard limit in RouterOS. Only Mikrotik can change that.
Open a support ticket if you want or need this to change.
by eworm
Sat Aug 08, 2020 3:27 pm
Forum: RouterOS v7 BETA
Topic: Feature Request - Wireguard Protocol
Replies: 165
Views: 55469

Re: Feature Request - Wireguard Protocol

Great! Looks like it is about as fast as IPSec...
At least on ARM. Wondering what numbers look like on mipsbe and tile.
by eworm
Wed Jul 29, 2020 5:36 pm
Forum: General
Topic: RouterOS v6.27 SSh Key login problem.
Replies: 2
Views: 783

Re: RouterOS v6.27 SSh Key login problem.

This is your issue:
debug1: Skipping ssh-dss key id_dsa - not in PubkeyAcceptedKeyTypes
You have to extend your configuration even more.

Better solution: Update RouterOS to a recent version and use RSA keys.
by eworm
Wed Jul 29, 2020 1:53 pm
Forum: Announcements
Topic: Photos of towers and masts
Replies: 81
Views: 34825

Re: Photos of towers and masts

Yes, it's a heavy plastic plate. But it has just rubber-feet, no sucker. But I will fasten it with a strong cord and eyelets in keder rails.
It now looks like this. Let's hope it will withstand bad weather and strong wind...
by eworm
Wed Jul 29, 2020 12:10 pm
Forum: General
Topic: Question: How to set a NXDOMAIN entry in RouterOS DNS with 6.47.1 [SOLVED]
Replies: 3
Views: 1013

Re: Question: How to set a NXDOMAIN entry in RouterOS DNS with 6.47.1 [SOLVED]

You could just set a record of type NXDOMAIN... /ip dns static add name=example.com type=NXDOMAIN However this is not specific to IPv6 and could cause clients to ignore the domain completely. I tend to set an AAAA record representing the IPv4 address: /ip dns static add name=example.com type=AAAA ad...
by eworm
Sun Jul 26, 2020 7:22 pm
Forum: Announcements
Topic: Photos of towers and masts
Replies: 81
Views: 34825

Re: Photos of towers and masts

maybe, mounted on a plastic plate (Polyethylenplast) then a rubber-sucker (Saugnapf) in each corner to fasten to roof.
then very portable.
Yes, it's a heavy plastic plate. But it has just rubber-feet, no sucker. But I will fasten it with a strong cord and eyelets in keder rails.
by eworm
Sun Jul 26, 2020 3:56 pm
Forum: Announcements
Topic: Photos of towers and masts
Replies: 81
Views: 34825

Re: Photos of towers and masts

How do you turn antenna, by losening the mount on the pole? What do you do while driving around, take the whole installation (including pole base) down? Yes, this is completely manual. When the caravan has its position I can place the antenna - neither caravan nor lte station will move then. :lol: ...
by eworm
Sun Jul 26, 2020 1:22 pm
Forum: Announcements
Topic: Photos of towers and masts
Replies: 81
Views: 34825

Re: Photos of towers and masts

Mounted this on top of my caravan.
Guess it solves my connectivity issues...
by eworm
Fri Jul 24, 2020 6:06 pm
Forum: General
Topic: doh server connect error network is unreachable
Replies: 9
Views: 2304

Re: doh server connect error network is unreachable

You should ping the host cloudflare-dns.com, not the url.
by eworm
Fri Jul 10, 2020 6:30 pm
Forum: General
Topic: Mikrotik CRS125-24G Speed Problem
Replies: 13
Views: 2435

Re: Mikrotik CRS125-24G Speed Problem

Probably a bad idea. CRS125 is a switch, and in no way it can route a gigabit.
The poster wants fast internet connection, not VLAN.
by eworm
Fri Jul 10, 2020 5:25 pm
Forum: General
Topic: Mikrotik CRS125-24G Speed Problem
Replies: 13
Views: 2435

Re: Mikrotik CRS125-24G Speed Problem

Your Huawei Router is connected to what port?

If it is connected to ether1 your CRS is not working as switch but additional router. Disable DHCP server, plug the Huawei Router to any other port and try again.
by eworm
Fri Jul 10, 2020 2:00 pm
Forum: Announcements
Topic: v6.47.1 [stable] is released!
Replies: 147
Views: 62394

Re: v6.47.1 [stable] is released!

Already reported for 6.48beta, but applies here, too:
*) dns - do not use DoH for local queries when a server is specified;
This is about forwarding? Looks like queries are still sent via DoH for me.
Anybody made this work?
by eworm
Wed Jul 08, 2020 11:57 am
Forum: General
Topic: BUG: DNS USE ONLY DOH
Replies: 8
Views: 2061

Re: BUG: DNS USE ONLY DOH

That is a theory but unfortunately this does not work with DOH right now. Mikrotik staff is aware (reported in [SUP-20565], resolved in v6.48beta12) and hopefully they will soon release fix in stable channel.
Does it work for you with 6.48beta12? To my findings the behavior did not change.
by eworm
Tue Jul 07, 2020 4:39 pm
Forum: General
Topic: SVG of cloud shaped Mikrotik logo
Replies: 0
Views: 439

SVG of cloud shaped Mikrotik logo

Everybody who visited a MUM knows these: the cloud shaped Mikrotik stickers.
Is the cloud shaped Mikrotik logo available, preferably as SVG file? I've searched designs.mikrotik.com and Google, but could not find anything.
Please share if you have it.
by eworm
Tue Jul 07, 2020 4:34 pm
Forum: General
Topic: RouterOS firmware not upgrading [SOLVED]
Replies: 2
Views: 836

Re: RouterOS firmware not upgrading [SOLVED]

Looks like you have a number of packages on our flash storage. Clean these, then try again.
by eworm
Tue Jul 07, 2020 3:30 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 185
Views: 65329

Re: v6.48beta [testing] is released!

*) dns - do not use DoH for local queries when a server is specified; This is about forwarding? Looks like queries are still sent via DoH for me. *) dns - do not use type "A" for static entries with unspecified type; I do not understand that one... How could type be "A" and unsp...
by eworm
Tue Jul 07, 2020 2:52 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 185
Views: 65329

Re: v6.48beta [testing] is released!

msatter Do you have custom set of packages installed and wireless package is not installed?
Correct. My system has system, dhcp, advanced-tools & security installed. Opened SUP-21264 with support output.
by eworm
Tue Jul 07, 2020 2:15 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 185
Views: 65329

Re: v6.48beta [testing] is released!

I wonder what's the real advantage of running my router with ondemand scheduler?
It saves power and runs less hot.
by eworm
Tue Jul 07, 2020 12:51 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 185
Views: 65329

Re: v6.48beta [testing] is released!

Now non-wireless devices have issues with the default configuration script:
system;error;critical;13328;39528;13328 error while running customized default configuration script: expected end of command (line 1310 column 53)
This is on RB750GL.
by eworm
Mon Jul 06, 2020 4:29 pm
Forum: General
Topic: ASK [reset-button]
Replies: 8
Views: 1738

Re: ASK [reset-button]

No idea what you code is supposed to do. Do you want to toggle the interface without my scripts? Use something like this then: :if ([ / caps-man interface get cap1 disabled ] = true) do={ :log info "Enabling..."; / caps-man interface enable cap1; } else={ :log info "Disabling..."...
by eworm
Mon Jul 06, 2020 11:53 am
Forum: General
Topic: ASK [reset-button]
Replies: 8
Views: 1738

Re: ASK [reset-button]

Using my scripts add something like this in configuration: :global ModeButton { 1="/ caps-man interface disable [ find ];"; 2="/ caps-man interface enable [ find ];"; } With one press all interfaces are disabled, with two presses interfaces are enabled. Is that what you want? Of ...
by eworm
Sun Jul 05, 2020 3:32 pm
Forum: General
Topic: SMS receive 'allowed-number' multiple numbers [SOLVED]
Replies: 9
Views: 1997

Re: SMS receive 'allowed-number' multiple numbers [SOLVED]

Version 6.45.1 had this in change log:
*) sms - allow specifying multiple "allowed-number" values;
So it should be possible. Never used it myself, though.
by eworm
Thu Jul 02, 2020 3:11 pm
Forum: General
Topic: Strange Cert. error with some NordVPN connections
Replies: 15
Views: 2254

Re: Strange Cert. error with some NordVPN connections

I have this stored as a script on my devices: :put ([ / tool fetch http-header-field="User-Agent: Mozilla/4.0" "https://api.nordvpn.com/v1/servers/recommendations\?limit=3" output=user as-value ]->"data"); Then from a linux host: % ssh mikrotik / system script run nordv...
by eworm
Thu Jul 02, 2020 1:39 pm
Forum: General
Topic: Strange Cert. error with some NordVPN connections
Replies: 15
Views: 2254

Re: Strange Cert. error with some NordVPN connections

I've seen this myself... Just switched to another server that is currently recommended.
by eworm
Wed Jul 01, 2020 11:48 am
Forum: General
Topic: ASK [reset-button]
Replies: 8
Views: 1738

Re: ASK [reset-button]

This is part of my RouterOS Scripts collection. You can make the device act on multiple presses on mode or reset button. The default is one press to toggle dark mode, two presses for a "Hello World" notification, three presses for shutdown, ... But you can make it do what ever you want.
by eworm
Wed Jul 01, 2020 9:26 am
Forum: General
Topic: ASK [reset-button]
Replies: 8
Views: 1738

Re: ASK [reset-button]

Would you consider this to be useful?
Mode botton with multiple presses
by eworm
Mon Jun 29, 2020 12:15 pm
Forum: RouterOS v7 BETA
Topic: v7.0beta8 [development] is released!
Replies: 180
Views: 69116

Re: v7.0beta8 [development] is released!

It would be like asking MikroTik to make QUIC available. It is already available. Well, RouterOS can be client as well, so for example fetch command could benefit. It's not a big win there, though. But DoH over QUIC or HTTPS/3 could be worth adding one day... No idea if there are endpoints supporti...
by eworm
Wed Jun 24, 2020 4:12 pm
Forum: General
Topic: couldn't add new DHCP client - can not run on slave interface
Replies: 9
Views: 4872

Re: couldn't add new DHCP client - can not run on slave interface

Your port is member of a bridge. Put the dhcp client on the bridge.
by eworm
Wed Jun 24, 2020 12:27 am
Forum: General
Topic: SysLog
Replies: 8
Views: 1795

Re: SysLog

As said before a message has to match all topics given in a rule. So you can use something like this... /system logging add action=remote topics=info,dhcp ... to match all messages that have topic info and dhcp . But there is no message that has topics error and info at the same time. So a rule like...
by eworm
Tue Jun 23, 2020 11:17 pm
Forum: General
Topic: SysLog
Replies: 8
Views: 1795

Re: SysLog

No, this is not a bug. Why do you think so?
by eworm
Tue Jun 23, 2020 11:04 pm
Forum: General
Topic: SysLog
Replies: 8
Views: 1795

Re: SysLog

Rules: topics=info,error,critical,system,event,warning,script,wireless,dhcp,ipsec prefix="" action=remote A message has to contain all topics to match. That's an impossible combination, even info and error are exclusive to each other. Try this: /system logging add action=remote topics=inf...
by eworm
Tue Jun 23, 2020 4:27 pm
Forum: Announcements
Topic: v6.47 [stable] is released!
Replies: 349
Views: 107682

Re: v6.47 [stable] is released!

Please give
/ip firewall filter export
so we can have a look.

There's no (new) breakage in scripting I know of.
by eworm
Tue Jun 23, 2020 2:56 pm
Forum: Scripting
Topic: Telegram notification
Replies: 3
Views: 1861

Re: Telegram notification

Possibly missing the escape for question mark?
by eworm
Fri Jun 19, 2020 5:41 pm
Forum: General
Topic: IPsec (in)security: phase2 pfs-group
Replies: 4
Views: 1237

Re: IPsec (in)security: phase2 pfs-group

I think you see the mismatch only if session key is about to expire and rekeying fails. So did you test for more than just session startup?
by eworm
Fri Jun 19, 2020 12:22 am
Forum: General
Topic: where can I create a script in RouterOS?
Replies: 11
Views: 8439

Re: where can I create a script in RouterOS?

Sure, everything is possible... Run / system script export; to see what the code inside an rsc file should look. To turn an uploaded file into a script: / system script add name=new-script source=[ /file get uploaded-script-file contents ]; You may want to take a look at my signature for an idea wha...
by eworm
Mon Jun 15, 2020 5:00 pm
Forum: Scripting
Topic: Return IP Octet Function
Replies: 11
Views: 4832

Re: Return IP Octet Function

RouterOS supports bitwise operations, so you can calculate IP addresses like this, for example get the first octet:
:put (192.168.10.0 & 255.0.0.0)
192.0.0.0
Possibly useful to shorten your functions even further. :D
by eworm
Mon Jun 15, 2020 4:44 pm
Forum: General
Topic: DNS over HTTPS
Replies: 158
Views: 39847

Re: DNS over HTTPS

Does this work for ipv6?
You could try this address:

https://[2606:4700:4700::1111]/dns-query

But others reported it does not. Have not tried it myself.
by eworm
Wed Jun 10, 2020 9:29 pm
Forum: General
Topic: DoH server connection error, idle time out connecting
Replies: 10
Views: 3318

Re: DoH server connection error, idle time out connecting

It expires nov/10/2031 02:00:00, that's more than 595 weeks from now.
by eworm
Wed Jun 10, 2020 12:22 am
Forum: General
Topic: CRS354 - out of space - RESOLVED
Replies: 5
Views: 1067

Re: CRS354 - out of space

Looks like anybody uploaded all available extra packages to the device to upgrade...
Should be easy to recover with netinstall. Not sure if there is another way... Probably not if you can not uninstall unwanted packages.
by eworm
Wed Jun 10, 2020 12:11 am
Forum: General
Topic: CRS354 - out of space - RESOLVED
Replies: 5
Views: 1067

Re: CRS354 - out of space

What packages are installed? Did you import certificates?
by eworm
Tue Jun 09, 2020 9:48 pm
Forum: General
Topic: Mikrotik DNS cache allocation drive...
Replies: 1
Views: 541

Re: Mikrotik DNS cache allocation drive...

I think dns cache goes to RAM and does not cause flash writes...
by eworm
Tue Jun 09, 2020 12:49 am
Forum: Scripting
Topic: How to set the same field of all list members to the same value? [SOLVED]
Replies: 5
Views: 1608

Re: How to set the same field of all list members to the same value? [SOLVED]

This should do:
:foreach i in=[find] do={set $i address=192.168.20.2/32}
or since its just one IP and no subnet:
:foreach i in=[find] do={set $i address=192.168.20.2}
Why do you run this in a loop? Just set the value for all at a time:
set [ find ] address=192.168.20.2;
by eworm
Mon Jun 08, 2020 12:47 pm
Forum: General
Topic: Very strange environment variables. Did I get hacked?
Replies: 19
Views: 7472

Re: Very strange environment variables. Did I get hacked?

Yes, except that you do not need to update. Just a reboot is sufficient.
by eworm
Sun Jun 07, 2020 11:06 pm
Forum: Announcements
Topic: v6.47 [stable] is released!
Replies: 349
Views: 107682

Re: v6.47 [stable] is released!

To solve this issue First you have to change your Wireless Interface(s) name to the pre-set. wlan1,wlan2,wlan3.... And finally you must Reboot your device, after this your problem will be solved forever And after that you can personalize and change their name. That does the trick, thanks a lot for ...
by eworm
Fri Jun 05, 2020 6:15 pm
Forum: Announcements
Topic: v6.47 [stable] is released!
Replies: 349
Views: 107682

Re: v6.47 [stable] is released!

It would be nice when it first checked for exact matches of static records before it tried the regexp.
Exactly what I described above with my issue. So +1!
by eworm
Fri Jun 05, 2020 5:15 pm
Forum: Announcements
Topic: v6.47 [stable] is released!
Replies: 349
Views: 107682

Re: v6.47 [stable] is released!

To get DoH working I need to use all 3 certificate from dns.google
Depends on whether or not the server ships the intermediate certificate. Then looks like Google server does not.
by eworm
Thu Jun 04, 2020 1:54 pm
Forum: General
Topic: RPKI
Replies: 48
Views: 14787

Re: RPKI

What's new in 7.0beta7 (2020-Jun-3 16:31):
[...]
!) enabled BGP support with multicore peer processing (CLI only);
!) enabled RPKI support (CLI only);
[...]
by eworm
Thu Jun 04, 2020 1:53 pm
Forum: RouterOS v7 BETA
Topic: Enable BGP on ROSv7
Replies: 14
Views: 4851

Re: Enable BGP on ROSv7

What's new in 7.0beta7 (2020-Jun-3 16:31):
[...]
!) enabled BGP support with multicore peer processing (CLI only);
!) enabled RPKI support (CLI only);
[...]
by eworm
Thu Jun 04, 2020 11:37 am
Forum: General
Topic: Add DNS over HTTPS (DoH) support
Replies: 135
Views: 101832

Re: Add DNS over HTTPS (DoH) support

Just want to share to all people, if you want to verify the DoH server, you can go to https://1.1.1.1/dns-query using the web browser and download the the 3 certificates from the server site. Only two certificates are required, use the two with "DigiCert" in name. The "cloudflare-dns...
by eworm
Thu Jun 04, 2020 11:13 am
Forum: Announcements
Topic: v6.47 [stable] is released!
Replies: 349
Views: 107682

Re: v6.47 [stable] is released!

Just found another hiccup with DNS and DoH... Let's assume I have a domain eworm.de (I do! :D ), which has A and AAAA records. My router has a record router.eworm.de , using *.router.eworm.de as local zone: /ip dns static add address=10.0.0.1 name=router.eworm.de add address=10.0.0.10 name=host.rout...
by eworm
Thu Jun 04, 2020 10:35 am
Forum: Announcements
Topic: v6.47 [stable] is released!
Replies: 349
Views: 107682

Re: v6.47 [stable] is released!

It seems to me that DNS FWD does not work if there is DoH set up. I can imagine people who want to FWD their internal domain zones while securing all external/public requests. (If you want to test it, remember to flush cache before every request) I brought this topic up for beta and rc releases... ...
by eworm
Thu May 28, 2020 7:54 pm
Forum: General
Topic: Lots of global variables on hAP ac2
Replies: 5
Views: 1417

Re: Lots of global variables on hAP ac2

BTW, is this log message related?
system;error;critical error while running customized default configuration script: no such item
by eworm
Thu May 28, 2020 6:36 pm
Forum: General
Topic: Lots of global variables on hAP ac2
Replies: 5
Views: 1417

Re: Lots of global variables on hAP ac2

Several of my devices show this as well.
With reset you reference
/system reset-configuration
?
Will this be fixed in a future version without reset?
by eworm
Thu May 28, 2020 5:50 pm
Forum: General
Topic: DHCP Client Script when provider renews lease
Replies: 8
Views: 2198

Re: DHCP Client Script when provider renews lease

I do not see anything wrong with that call. Perhaps it's a race condition because resolving is not yet available? You can try to catch runtime error: :local ipddns; :do { :set ipddns [:resolve $ddnsbase]; } on-error={ :log warning "Resolving failed."; } Or try to wait... :local ipddns &quo...
by eworm
Thu May 28, 2020 1:39 pm
Forum: RouterBOARD hardware
Topic: Running hardware portably using DC battery power
Replies: 14
Views: 3036

Re: Running hardware portably using DC battery power

That's awesome! What a snug fit. Does the PD source always rise to 20V? I don't own a wAP... yet, but this definitely makes me want one. You can configure the voltage (or voltage range with preference) your PD buddy delivers. It also depends on your power source, some do not support 20V... The PD b...
by eworm
Thu May 28, 2020 12:59 pm
Forum: General
Topic: DNS Failover
Replies: 20
Views: 8258

Re: DNS Failover

Set the Mikrotik to use a DNS other than piehole... Like 8.8.8.8, 1.1.1.1. Then in your DHCP server... Set the DNS value under network to be piehole, Mikrotik. If piehole doesn't work... The client will ask the Mikrotik. That does not work. The client will use piehole and Mikrotik simultaneously.
by eworm
Thu May 28, 2020 12:06 pm
Forum: General
Topic: implicit firewal rules
Replies: 4
Views: 1044

Re: implicit firewal rules

I guess that would result in a lot of locked devices. So bad idea.
Unless your first rule is to allow administrative access you would no longer be able to log in to your device.
by eworm
Thu May 28, 2020 12:00 pm
Forum: Scripting
Topic: Question related with ROS client ssh w/o Pass
Replies: 2
Views: 807

Re: Question related with ROS client ssh w/o Pass

RouterOS can import keys in PEM format only. Convert the key and you are fine.
by eworm
Thu May 28, 2020 11:53 am
Forum: RouterOS v7 BETA
Topic: Feature Request: ACL Compare User Defined Bytes
Replies: 3
Views: 1160

Re: Feature Request: ACL Compare User Defined Bytes

The firewall has a lot of attributes to filter on:
/ip firewall filter add protocol=tcp connection-state=new ...
by eworm
Wed May 27, 2020 11:56 pm
Forum: RouterBOARD hardware
Topic: Running hardware portably using DC battery power
Replies: 14
Views: 3036

Re: Running hardware portably using DC battery power

I use a power bank with USB-C power delivery output. Combine that with a PD Buddy Sink and you are done.

The PD Buddy Sink even fits into a wAP (LTE) case - resulting in a powerful mobile access point.
photo_2020-05-27_22-53-20.jpg
by eworm
Wed May 27, 2020 4:42 pm
Forum: Announcements
Topic: v6.47rc [testing] is released!
Replies: 63
Views: 17268

Re: v6.47rc [testing] is released!

Setting attributes for static DNS records changes other attributes unintentionally: [admin@mt] /ip dns static> add forward-to=10.0.0.1 regexp="example.com" type=FWD [admin@mt] /ip dns static> set regexp="example\\.com\$" [ find where regexp="example.com" ] [admin@mt] /i...
by eworm
Tue May 26, 2020 10:50 pm
Forum: General
Topic: MTU troubles using IKEv2 providers like NordVPN [work around]
Replies: 43
Views: 10993

Re: MTU troubles using IKEv2 providers like NordVPN [work around]

I did fear the same, but looks like everything still works as expected.
Not sure what this change is supposed to do.
by eworm
Tue May 26, 2020 9:21 pm
Forum: Announcements
Topic: v6.47rc [testing] is released!
Replies: 63
Views: 17268

Re: v6.47rc [testing] is released!

+1. I'd like to forward internal zones via VPN to an organization DNS and all the rest - to 1.1.1.1 via DoH
Exactly my use case.
Two great now features - would be frustrating to have to choose between them.
by eworm
Tue May 26, 2020 8:06 pm
Forum: General
Topic: DNS over HTTPS
Replies: 158
Views: 39847

Re: DNS over HTTPS

This is not supposed in 6.46.6. You have to use 6.47 for that feature.
by eworm
Tue May 26, 2020 2:22 pm
Forum: Announcements
Topic: v6.47rc [testing] is released!
Replies: 63
Views: 17268

Re: v6.47rc [testing] is released!

eworm Currently DoH will be prioritized over all other DNS configuration. Not sure if this will change any time soon.
In general this makes sense. But I vote for an excepting with conditional forwarding of DNS queries.
by eworm
Tue May 26, 2020 2:21 pm
Forum: Announcements
Topic: v6.47rc [testing] is released!
Replies: 63
Views: 17268

Re: v6.47rc [testing] is released!

On boot system logs:
system;error;critical error while running customized default configuration script: no such item
Is this expected? (If it is I would like to see the severity reduced. "error" and "critical" raise alerts here.)
by eworm
Tue May 26, 2020 1:45 pm
Forum: Announcements
Topic: v6.47rc [testing] is released!
Replies: 63
Views: 17268

Re: v6.47rc [testing] is released!

This has... *) dns - added support for multiple type static entries; ... but is missing from 6.47beta60... *) dns - added support for forwarding DNS queries of static entries to specific server (CLI only); This can still be configured, but still does not work when DNS over HTTPS is enabled. I would ...
by eworm
Mon May 25, 2020 6:50 pm
Forum: RouterBOARD hardware
Topic: new hardware Wireless Wire nRAY 60 ghz
Replies: 68
Views: 10842

Re: new hardware Wireless Wire nRAY 60 ghz

Interesting device...

Also nice to see that more devices are equipped with ARM 64bit CPUs (just like new CCR).
by eworm
Fri May 22, 2020 3:28 pm
Forum: RouterOS v7 BETA
Topic: How to read also the flags of a data record? (bug in beta5?) [SOLVED]
Replies: 5
Views: 1736

Re: How to read also the flags of a data record? (bug in beta5?) [SOLVED]

I do not, and here is why:
If you have complex code depending on relative paths it tends to break if you move fragments of code up or down.
by eworm
Fri May 22, 2020 2:57 pm
Forum: RouterOS v7 BETA
Topic: How to read also the flags of a data record? (bug in beta5?) [SOLVED]
Replies: 5
Views: 1736

Re: How to read also the flags of a data record? (bug in beta5?) [SOLVED]

IMHO it is very intuitive if you are used to it. Scripting is one of the reasons I do love RouterOS.
by eworm
Fri May 22, 2020 1:44 pm
Forum: General
Topic: Mikrotik Audience Poe IN [SOLVED]
Replies: 1
Views: 727

Re: Mikrotik Audience Poe IN [SOLVED]

No setting, it will just work.
by eworm
Fri May 22, 2020 10:44 am
Forum: RouterOS v7 BETA
Topic: How to read also the flags of a data record? (bug in beta5?) [SOLVED]
Replies: 5
Views: 1736

Re: How to read also the flags of a data record? (bug in beta5?) [SOLVED]

The command print is (mostly) for terminal output.

Does something like this work for you?
:foreach i in=[ /interface bridge host find ] do={ :put [ /interface bridge host get $i ]; }
BTW, why do you expect everything to be a bug?
by eworm
Mon May 18, 2020 12:01 am
Forum: Scripting
Topic: How to auto-start a script at interface link up / down ? [SOLVED]
Replies: 30
Views: 6509

Re: How to auto-start a script at interface link up / down ? [SOLVED]

You initialize the variable inside a block, thus it's not visible outside. But it's a global variable :-) Sure, it is. But even global variables are accessible only... ... when used directly from command line (without block!) or... ... when initialized properly. So when ever you want to access $gAr...
by eworm
Sun May 17, 2020 11:46 pm
Forum: General
Topic: Solution needed: router PoE + WIreless
Replies: 6
Views: 1464

Re: Solution needed: router PoE + WIreless

The RB750UPr2 does passive POE only, so your 802.3af devices will not receive power, even if the power supply matches your voltage requirements. I guess you have to go with one of these: https://mikrotik.com/product/crs112_8p_4s_in (requires additional power supply for 48V!) https://mikrotik.com/pro...
by eworm
Sun May 17, 2020 11:25 pm
Forum: Scripting
Topic: sms to telegram
Replies: 8
Views: 1845

Re: sms to telegram

I guess you have to do some urlencoding for your sms message...

If you want a working solution have a look at this:
RouterOS Scripts - Forward received SMS
This requires the installation of global scripts on top, see main README.
by eworm
Sun May 17, 2020 11:16 pm
Forum: Scripting
Topic: Tool Fetch Scripting - HotSpot Telegram QRCode
Replies: 1
Views: 732

Re: Tool Fetch Scripting - HotSpot Telegram QRCode

Not sure I got this right, but looks like you have a nested url inside url? Try to urlencode the characters there, specifically replace '&' with '%26'.
by eworm
Sun May 17, 2020 11:09 pm
Forum: Scripting
Topic: How to auto-start a script at interface link up / down ? [SOLVED]
Replies: 30
Views: 6509

Re: How to auto-start a script at interface link up / down ? [SOLVED]

You initialize the variable inside a block, thus it's not visible outside.
by eworm
Fri May 15, 2020 6:54 pm
Forum: General
Topic: OpenSSH future RSA host key deprecation
Replies: 9
Views: 4024

Re: OpenSSH future RSA host key deprecation

No progress, no reaction on ed25519 keys from Mikrotik.
by eworm
Fri May 15, 2020 11:38 am
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 130887

Re: v6.47beta [testing] is released!

Good question... Wondering myself.
Time for a new release anyway, the last one is three weeks old already.
by eworm
Thu May 14, 2020 10:55 pm
Forum: General
Topic: promiscue mode - what does it let pass?
Replies: 2
Views: 785

Re: promiscue mode - what does it let pass?

Most of your packets go fast path, missing the IPSec tunnel. Make sure all your IPSec traffic does not go fast path.
by eworm
Thu May 14, 2020 9:48 pm
Forum: General
Topic: Cloud backup needs a static token through time for downloading
Replies: 1
Views: 788

Re: Cloud backup needs a static token through time for downloading

I solved this with a backup script that sends notification via e-mail and/or Telegram message including the secret download key. Just look up your mailbox and you are fine.

You need the basic installation and this script:
routeros-scripts - Upload backup to Mikrotik cloud
by eworm
Mon May 11, 2020 9:43 pm
Forum: General
Topic: CCR2004 w/ARM64 : Where to download packages ? [SOLVED]
Replies: 7
Views: 2169

Re: CCR2004 w/ARM64 : Where to download packages ? [SOLVED]

I guess the build process for arm64 works, but the release process has been enabled just before recent long term release.
Be patient and wait for the next testing and stable releases, I think they will include arm64 builds.
by eworm
Sat May 09, 2020 1:04 pm
Forum: General
Topic: 6.46 for arm64?
Replies: 1
Views: 712

Re: 6.46 for arm64?

I guess the release process had not been prepared. Expect version 6.46.7 to have arm64 build...
by eworm
Wed May 06, 2020 11:31 am
Forum: General
Topic: Add DNS over HTTPS (DoH) support
Replies: 135
Views: 101832

Re: Add DNS over HTTPS (DoH) support

There is information when the DoH function will go from beta to release?
When version 6.47 is released to stable channel. There's no date for that, though.
by eworm
Mon May 04, 2020 7:02 pm
Forum: RouterOS v7 BETA
Topic: UDP OpenVPN tunnel same speed as TCP
Replies: 7
Views: 4106

Re: UDP OpenVPN tunnel same speed as TCP

I guess the device's CPU is the limiting factor here.
by eworm
Mon May 04, 2020 2:33 pm
Forum: General
Topic: How to replicate home WiFi while staying in a hotel (VPN, capsman)?
Replies: 9
Views: 2180

Re: How to replicate home WiFi while staying in a hotel (VPN, capsman)?

You can't do that. You have either local wireless configuration or device is connected to capsman. Both is not possible, at least not with a single band device.
You could use wAP ac (or similar dual band device), connect 2.4GHz to hotel wifi und use 5GHz for your SSID via capsman.
by eworm
Wed Apr 29, 2020 11:51 pm
Forum: General
Topic: WireGuard Released !
Replies: 41
Views: 28765

Re: WireGuard Released !

Internal builds with wireguard support are rumored to exist.
Search the v7 section for details.
by eworm
Wed Apr 29, 2020 2:40 pm
Forum: Announcements
Topic: MikroTik newsletter May 2020 (#95)
Replies: 50
Views: 28832

Re: MikroTik newsletter May 2020 (#95)

Do you have more information about that Annapurna AL32400? E.g. how many cores?
It has four cores. See here for details of CCR2004:
https://mikrotik.com/product/ccr2004_1g_12s_2xs
by eworm
Tue Apr 28, 2020 5:48 pm
Forum: Announcements
Topic: v6.46.6 [stable] is released!
Replies: 68
Views: 35397

Re: v6.46.6 [stable] is released!

Why you don't fix OSPF ? :?
Possibly because they could not reproduce. Did you open a support ticket?
by eworm
Mon Apr 27, 2020 7:33 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 130887

Re: v6.47beta [testing] is released!

Sure, just configure it properly:
/ip dns set verify-doh-cert=yes
by eworm
Mon Apr 27, 2020 12:31 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 130887

Re: v6.47beta [testing] is released!

Im currently testing DoH on my HAP Lite, which is working great. But I have few questions. I got some Dynamic NS Servers supplied by my ISP and thus they are automatically added to Mikrotik DNS server list (read-only). I also put some static NS records (e.g dns.cloudflare 1.1.1.1) as Static list. S...
by eworm
Sun Apr 26, 2020 10:06 am
Forum: General
Topic: RouterOS Scheduler unreliable by default?
Replies: 1
Views: 859

Re: RouterOS Scheduler unreliable by default?

The scheduler is perfectly reliable in my experience. Note that a script (and thus scheduler) is stopped on first error, though. Possibly your scripts terminate with error?
by eworm
Fri Apr 24, 2020 10:35 pm
Forum: General
Topic: Feature request: per-domain forwarding in DNS
Replies: 21
Views: 19634

Re: Feature request: per-domain forwarding in DNS

This is available now in RouterOS 6.47beta60!
by eworm
Fri Apr 24, 2020 10:32 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 130887

Re: v6.47beta [testing] is released!

That is a chicken and egg problem. Neither chicken nor egg is involved. Let's assume I add something like this: /ip dns static add forward-to=10.0.0.1 regexp="(.*\\.)\?example\\.com" type=FWD This will make all requests for example.com and its subdomains go to nameserver 10.0.0.1 . Works ...
by eworm
Fri Apr 24, 2020 4:42 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 130887

Re: v6.47beta [testing] is released!

Version 6.47beta60 has reset my settings for mode button.
by eworm
Fri Apr 24, 2020 4:24 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 130887

Re: v6.47beta [testing] is released!

Yes! Mikrotik, you made my day!

One thing, though: Looks like DNS forwarding does not work if DoH configuration is active. I think the forwarding should have priority over DoH.
by eworm
Fri Apr 24, 2020 9:18 am
Forum: General
Topic: CCR1009 High CPU Load
Replies: 10
Views: 2996

Re: CCR1009 High CPU Load

I think a CCR1009 should be capable of doing this... Are you really using packet marking? Why not mark connection?

Have a look a profiling to see what process uses the cpu most:
/tool profile
by eworm
Fri Apr 24, 2020 9:07 am
Forum: General
Topic: CapsMan - pass Comments to RegistrationTable
Replies: 5
Views: 2220

Re: CapsMan - pass Comments to RegistrationTable

Works for me... Checked on two CAPsMAN devices (CCR & RB3011) with 6.46.5.
by eworm
Thu Apr 23, 2020 8:59 am
Forum: General
Topic: FEATURE REQUEST: Dynamically created VPN+routes (each to each)
Replies: 1
Views: 921

Re: FEATURE REQUEST: Dynamically created VPN+routes (each to each)

Sounds like you want a routing protocol. Ever thought about ospf or similar?
by eworm
Wed Apr 22, 2020 1:21 pm
Forum: General
Topic: DNS over HTTPS
Replies: 158
Views: 39847

Re: DNS over HTTPS

Yes, that's true in general and for Cloudflare. But google does not allow to use https://8.8.8.8/dns-query directly. It sends a redirect in HTTP header to https://dns.google/dns-query. Well, checking again... It does send a redirect, but the dns response is contained as well... % curl -I 'https://8....
by eworm
Wed Apr 22, 2020 1:08 pm
Forum: Scripting
Topic: Function: IP to Decimal
Replies: 10
Views: 3407

Re: Function: IP to Decimal

For me it works. Do you have IPv6 disabled (or not installed at all)?