Community discussions

MikroTik App

Search found 749 matches

by spippan
Wed May 14, 2025 2:38 pm
Forum: Forwarding Protocols
Topic: BGP routing issue
Replies: 16
Views: 1824

Re: BGP routing issue

good to have you here then, to clear everything up
by spippan
Wed May 14, 2025 12:05 am
Forum: Forwarding Protocols
Topic: BGP routing issue
Replies: 16
Views: 1824

Re: BGP routing issue

Wait Are You using Mikrotik's default firewall? The last input rule is /ip/firewall/filter/add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN log=yes Did You put your 172.30.0.0/24 range on the LAN adress list? there is only an INTERFACE LIS...
by spippan
Tue May 13, 2025 1:17 am
Forum: MikroTik hardware questions
Topic: Hardware for x86 (Replacing 2216)
Replies: 38
Views: 14525

Re: Hardware for x86 (Replacing 2216)

maybe is not so simple for a vendor to officially include an x86 cpu embedded in a router, maybe there is some bureaucracy, validation, and costs we as a consumers are not fully aware of I don't know if anyone else here is following the Mono Gateway router project of Tomaž Zaman on Youtube, but he ...
by spippan
Thu May 08, 2025 2:45 am
Forum: General
Topic: Wireguard: Endpoint and Current Endpoint differ
Replies: 15
Views: 1051

Re: Wireguard: Endpoint and Current Endpoint differ

check srcnat config on the client if there are any...
if there are more than 1 IP on an interface you can control the outbound src-ip
by spippan
Mon May 05, 2025 6:02 pm
Forum: General
Topic: Third party x86 hw ROS support
Replies: 26
Views: 1866

Re: Third party x86 hw ROS support

while strictly not vouching for THOSE boxes ... consider installing proxmox on one of them and use virtualized CHR (with PCIe passthrough if supported) to test and after that purchase a P10 or P-unlimited license.

allthough i doubt VT-d is supported on either of those 2 models.
by spippan
Mon May 05, 2025 5:57 pm
Forum: Scripting
Topic: Check if the port is already occupied [SOLVED]
Replies: 14
Views: 1284

Re: Check if the port is already occupied [SOLVED]

beware ... telnet is TCP
wireguard uses UDP

which ROS version are you using?
the latest ROS (7.19rc1) shows used/active ports in
/ip/service print
by spippan
Fri May 02, 2025 11:07 pm
Forum: Announcements
Topic: Question to our users about controllers
Replies: 127
Views: 209153

Re: Question to our users about controllers

Self-hosted (Docker or Linux package) should be the minimum. To be able to be installed/run anywhere - Pi, VPS, CHR, RB5009 etc. A MikroTik cloud redirect for initial provisioning (like Meraki/Fortinet) would be great too. Top features I’d like to see: - Zero-touch provisioning (based on MAC/SN or ...
by spippan
Tue Apr 29, 2025 1:00 am
Forum: Announcements
Topic: Newsletter #124
Replies: 29
Views: 15203

Re: Newsletter #124

likely there will be LHG 5 ax & LHG XL 5 ax up next
by spippan
Fri Apr 18, 2025 4:11 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

Winbox IPv6 connectivity, when?
Its 2025, i shouldn't have to resort to IPv4 to manage an IPv6 forwarding device.
this is already here for ages
by spippan
Fri Apr 18, 2025 4:02 pm
Forum: General
Topic: Reset RouterOS without losing remote access (Winbox/SSH)
Replies: 21
Views: 1755

Re: Reset RouterOS without losing remote access (Winbox/SSH)

First of all, why do you need to do this ?? Workaround: Insert a script and choose Run After Reset. would suggest this approach too. test this on a local MT first and examine if the default configuration can be altered as far as you need to access it remotely. e.g. setup a firewall input allow rule...
by spippan
Tue Apr 15, 2025 8:52 pm
Forum: Announcements
Topic: Question to our users about controllers
Replies: 127
Views: 209153

Re: Question to our users about controllers

or peek over how Ubq... is handling things with their controller in v9 right now (which i just updated today effortlessly)
great visibility and feature set
by spippan
Tue Apr 15, 2025 1:35 pm
Forum: MikroTik hardware questions
Topic: Mikrotik 5G hardware roadmap
Replies: 34
Views: 15828

Re: Mikrotik 5G hardware roadmap

So it's been 4 months since this roadmap was put out and I was told in March that the 5G ATL should be out about now (early April) .. I am under pressure to evaluate 5G outdoor CPEs before June installs so if anyone has a clue when the ATL would be shipping I'd be grateful to know if I should hold ...
by spippan
Mon Apr 14, 2025 2:30 pm
Forum: General
Topic: OVPN in ROS 7.18.2 not showing login name in log attempts
Replies: 3
Views: 792

Re: OVPN in ROS 7.18.2 not showing login name in log attempts

would like to know that too
by spippan
Fri Apr 11, 2025 1:35 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 209410

Re: v7.19beta [testing] is released!

@fischerdouglas

It would be very nice if more people made some proper testing, steps to repeat, etc. as a normal bug tracker requires.
...
What I miss the most are the use cases!...



+1 on that
more use cases/examples would go a long way in the docs
by spippan
Mon Apr 07, 2025 3:13 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 629
Views: 263154

Re: v7.18.2 [stable] is released!

I have multiple VRRP (legacy IP and v6) running on CCR2216 with ROS 7.18.2 without issues. Maybe config related? how did you configure conn-sync? could you provide your config. of those 2216s please? i have 2x2 CCR2004 on 7.14.3 where i depend on a working VRRP setup, so if this works for you, it m...
by spippan
Mon Apr 07, 2025 2:47 pm
Forum: General
Topic: MLAG hopelessly broken?
Replies: 58
Views: 25352

Re: MLAG hopelessly broken?

All switches and routers have been updated to RouterOS 7.18.2 RouterBOARD 7.18.2 L3 HW Offloading is disabled on all switches Bridge VLAN filtering with user vlan and mgmt vlan is configured on the routers and switches The rstp protocol is used (root bridge - gw1) When rebooting the Primary MLAG sw...
by spippan
Mon Apr 07, 2025 2:31 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 209410

Re: v7.19beta [testing] is released!

we tested 7.19beta7 and it is working fine about bgp on x86 and arm64!
thanks Mikrotik.
can confirm too. same for me.

BGP (+BFD) now good again and no odd up to 100% CPU load any longer
by spippan
Mon Apr 07, 2025 12:16 pm
Forum: Beginner Basics
Topic: Best gear to receive 4G/5G signal to a cottage
Replies: 13
Views: 2547

Re: Best gear to receive 4G/5G signal to a cottage

and do not forget to take possible lightning strike in account and plan in an arrestor if the mounting point is one of your highest points out there
by spippan
Fri Apr 04, 2025 5:41 pm
Forum: General
Topic: Mikrotik SUCKS
Replies: 111
Views: 35112

Re: Mikrotik SUCKS

It's different and takes some time to adjust if you're coming from other vendors. Once you do though, it's pretty well laid out. and TBH it is - if one is familiar with cisco, juniper, vyos, etc... - really not that hard to use CLI on ROS EVERY CLI has its own learning curve ... i think that is jus...
by spippan
Fri Apr 04, 2025 5:39 pm
Forum: General
Topic: Mikrotik SUCKS
Replies: 111
Views: 35112

Re: Mikrotik SUCKS

...but when it takes forum searches and video tutorials to setup a plain NAT for a web server then it's a problem. I...ugh. KISS is thrown out the window with these damn things.

well .. do not use advanced stuff then. 🤷‍♂️
no one forces you to use MT anyways i guess
by spippan
Wed Apr 02, 2025 8:00 pm
Forum: Beginner Basics
Topic: Best gear to receive 4G/5G signal to a cottage
Replies: 13
Views: 2547

Re: Best gear to receive 4G/5G signal to a cottage

+1 for ATL LTE18. * assuming you're not in North America ** and it not "5G" And note they have announced, but not released, a few newer 5G models... if there is not urgency, something to consider. +1 if you can wait for the new 5G stuff to be released finally, wait for that. there are als...
by spippan
Mon Mar 31, 2025 2:45 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 209410

Re: v7.19beta [testing] is released!

7.15.x was the last version where BGP worked OK
true.
by spippan
Mon Mar 31, 2025 2:22 am
Forum: General
Topic: Traffic shaping (filter the WhatsApp and TikTok traffic)
Replies: 7
Views: 1361

Re: Traffic shaping (filter the WhatsApp and TikTok traffic)

/ip dns static add address-list=whatsapp_IPs disabled=no forward-to=1.0.0.2 match-subdomain=yes name=whatsapp.net ttl=1d type=FWD add address-list=whatsapp_IPs disabled=no forward-to=1.0.0.2 match-subdomain=yes name=whatsapp.com ttl=1d type=FWD Can you please explain what the purpose of forward-to ...
by spippan
Mon Mar 31, 2025 2:19 am
Forum: General
Topic: Traffic shaping (filter the WhatsApp and TikTok traffic)
Replies: 7
Views: 1361

Re: Traffic shaping (filter the WhatsApp and TikTok traffic)

Sorry sippan, what is BS is false hope and promises.
If you are unable to inspect encrypted traffic, then do pray tell what effing magic do you use........
how do you corelate encrypted traffic in this?

the question was routing-related, wasn't it?
by spippan
Fri Mar 28, 2025 3:27 am
Forum: General
Topic: Traffic shaping (filter the WhatsApp and TikTok traffic)
Replies: 7
Views: 1361

Re: Traffic shaping (filter the WhatsApp and TikTok traffic)

Hello, Good day Team, I want to filter the WhatsApp and TikTok traffic in Mikrotik and route it over a Specific WAN/VPN because WhatsApp and TikTok are blocked somewhere. How can I capture this traffic? (In Firewall Mangle conten t or RAW content ) Which one is most effective? Or please help me wit...
by spippan
Fri Mar 28, 2025 3:26 am
Forum: General
Topic: Traffic shaping (filter the WhatsApp and TikTok traffic)
Replies: 7
Views: 1361

Re: Traffic shaping (filter the WhatsApp and TikTok traffic)

Probably neither you need an expensive router add then pay for subscription services to handle DPI etc.........
BS. -.-
by spippan
Thu Mar 27, 2025 5:21 pm
Forum: General
Topic: DHCP snooping bridge and tagged interfaces
Replies: 3
Views: 1047

Re: DHCP snooping bridge and tagged interafaces

Hi, I'm stuck on a problem with what seems to be simple topic on every other switch I have except Mikrotik :) I have CRS309-1G-8S+ with a number of tagged traffic on each interface. I have sfp-sfpplus1 which is uplink port toward DHCP server. On some sfp-sfpplus2-6 there are devices that are using ...
by spippan
Thu Mar 27, 2025 5:13 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 13650

Re: My recent VLAN fiasco [SOLVED]

Not hyping it down, but its actual use as a data vlan is very niche (rare). yes and no ... in more complex setups - sure. segregation is a plus and in that case, vlan1 should not be used. okay otherwise the use of vlan1 also as a normal data vlan is no problem at all after all. if only for the sake...
by spippan
Thu Mar 27, 2025 2:44 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 13650

Re: My recent VLAN fiasco [SOLVED]

Sorry for blurring the picture for you, my response was mainly triggered by @erlinden as I am kind of tired of everyone treating VLAN 1 as black magic that has to be avoided by all means, hence that approach spreads as a meme (in the meaning of a "human software" virus, not the funny pict...
by spippan
Thu Mar 27, 2025 1:36 pm
Forum: General
Topic: Feature Request: Specify Source Address in DNS Server
Replies: 8
Views: 4570

Re: Feature Request: Specify Source Address in DNS Server

remember the SRC IP you want to use here has to be a local ip address on the router which can reach the DNS upstream (routing-wise) for the srcNAT to work correctly
by spippan
Thu Mar 27, 2025 1:35 pm
Forum: General
Topic: Feature Request: Specify Source Address in DNS Server
Replies: 8
Views: 4570

Re: Feature Request: Specify Source Address in DNS Server

you might need to use a srcnat rule

something like:
/ip firewall nat add action=src-nat chain=srcnat dst-address={IP adr. of DNS upstream} dst-port=53 protocol=udp to-addresses={SRC IP which you want to use}
by spippan
Wed Mar 26, 2025 4:06 pm
Forum: Wireless Networking
Topic: Cube 60Pro ac WiFi Bridge - Backup Link Configuration
Replies: 11
Views: 1574

Re: Cube 60Pro ac WiFi Bridge - Backup Link Configuration

Okay, thank you very much for your help. I managed to complete the configuration on both antennas. I have a question: When does the antenna switch from the 60 GHz band to the 5 GHz band? What parameters does it check before switching bands? (Signal strength? Tunnel speed? Something else?) >When doe...
by spippan
Wed Mar 26, 2025 3:55 pm
Forum: General
Topic: Feature request: Add Copy functionality for NAT & Firewall rules
Replies: 10
Views: 1392

Re: Feature request: Add Copy functionality for NAT & Firewall rules

does the "Copy" button ( 2 ) on an existing rule not work for you? nat_26-03-2025.png I'm sorry, i didn't see it anyway you could improve the functionality by adding the button also to Firewall and NAT pages, so that it's not needed to open each rule, this will make the job faster thanks ...
by spippan
Wed Mar 26, 2025 3:54 pm
Forum: General
Topic: Feature request: Add Copy functionality for NAT & Firewall rules
Replies: 10
Views: 1392

Re: Feature request: Add Copy functionality for NAT & Firewall rules

In CLI, you can do an export and copy a specific line. If you execute that line (with some adjustments) you can execute it. There is also 'copy-from=' property, and you can modify whatever parameters you want on the new cloned object at the time of creation as well: /ip/firewall/filter/add copy-fro...
by spippan
Wed Mar 26, 2025 2:44 pm
Forum: General
Topic: Feature request: Add Copy functionality for NAT & Firewall rules
Replies: 10
Views: 1392

Re: Feature request: Add Copy functionality for NAT & Firewall rules

does the "Copy" button ( 2 ) on an existing rule not work for you?
nat_26-03-2025.png
by spippan
Wed Mar 26, 2025 2:38 pm
Forum: Wireless Networking
Topic: Cube 60Pro ac WiFi Bridge - Backup Link Configuration
Replies: 11
Views: 1574

Re: Cube 60Pro ac WiFi Bridge - Backup Link Configuration

maybe this helps a little. a 60+5GHz Pair with 60GHz as primary link and automatic 5GHz failover you have to create a bond with the 2 wireless interfaces (60GHz + 5GHz) (mode = active/passive) then add the BOND interface to the bridge additionally to the ethernet interface. optionally disable VLAN f...
by spippan
Mon Mar 24, 2025 2:42 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 26835

Re: New exciting features for storage

Would be interesting to see the same tests run on the RDS2216. Any chance you could try that?
do you mean from RDS2216 <-> RDS2216 ?
by spippan
Sat Mar 22, 2025 5:10 pm
Forum: General
Topic: MT Wireguard over VRRP WAN
Replies: 5
Views: 1414

Re: MT Wireguard over VRRP WAN

Wireguard does not respond an incoming request from the same IP address to which that request has arrived because it is actually not a server in the narrow sense. So it treats any packet it sends as a standalone one rather than a part of some connection. So even though the initial hanshake packet f...
by spippan
Sat Mar 22, 2025 1:04 am
Forum: General
Topic: MT Wireguard over VRRP WAN
Replies: 5
Views: 1414

Re: MT Wireguard over VRRP WAN

Well endpoint has to be a specific WAN for the client to reach the right ROUTER. The VRRP is for the inside facing users from what I understand. But its a good point for discussion. Looking forward to what comes out of this thread. not if you have a public IP (WAN facing) VRRP instance... which in ...
by spippan
Fri Mar 21, 2025 11:25 pm
Forum: General
Topic: MT Wireguard over VRRP WAN
Replies: 5
Views: 1414

Re: MT Wireguard over VRRP WAN

can you show "/ip route print" ?

it might be something with "pref-source" for your def.route/wan-route
had this issue with a VRRP setup some months ago and have it running ever since with WG+openvpn
by spippan
Thu Mar 20, 2025 12:30 pm
Forum: Forwarding Protocols
Topic: AMT - Automatic Multicast Tunneling support
Replies: 51
Views: 18099

Re: AMT - Automatic Multicast Tunneling support

there you have it
What's new in 7.19beta6 (2025-Mar-19 09:56):
*) net - remove support for automatic multicast tunneling (AMT) interface (introduced in v7.18);
by spippan
Wed Mar 19, 2025 11:29 pm
Forum: General
Topic: Weekly VLAN confusion post
Replies: 18
Views: 2293

Re: Weekly VLAN confusion post


...fast-forward=no....
disables ARP? really? haven't seen that ever after
and i have setup a lot of bridges... old and new fashioned way
arp always working so far with fast-forward set to "yes"
by spippan
Wed Mar 19, 2025 11:18 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 629
Views: 263154

Re: v7.18.2 [stable] is released!

netinstall HAS a -v flag on linux
and the problem here is wrong subnetting (/32)
set your interface ip subnet mask at least to /30
by spippan
Wed Mar 19, 2025 1:48 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 209410

Re: v7.19beta [testing] is released!

AD:
i tried it with disabling BFD also (no screenshots) and it did not solve the high cpu load
by spippan
Wed Mar 19, 2025 11:08 am
Forum: General
Topic: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License
Replies: 38
Views: 4486

Re: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License

I mean what NathanA said about NPKs. RouterOS internal security has been changed several times, there are all kinds of internal integrity checks. You can't install self-made NPK files. v7 was a very big change as such, but even during v7 many changes have been made to security in this regard and ot...
by spippan
Wed Mar 19, 2025 11:05 am
Forum: General
Topic: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License
Replies: 38
Views: 4486

Re: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License

None of that is true though, some really old info
what exactly?
by spippan
Wed Mar 19, 2025 11:04 am
Forum: General
Topic: installation of system-7.18.2 failed: disk is too small
Replies: 10
Views: 1825

Re: installation of system-7.18.2 failed: disk is too small



But if you try to write files to flash so that you fill the space, does it work?
very good point !
by spippan
Wed Mar 19, 2025 11:03 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 209410

Re: v7.19beta [testing] is released!

the new bgp implementation in 7.19beta (all betas) seems not working fine on x86 platform, it is overloading the cores with very high routing usage. we experience high (70-90%) on a lot of cores, with normal irq usage where have high cpu. regards oh, i just saw this happens on CHR too below on CHR ...
by spippan
Wed Mar 19, 2025 10:54 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 209410

Re: v7.19beta [testing] is released!

ok then there might be something "new" or maybe it is related to a deeper level problem like offloading of the NIC(s) not working correctly at this point. were you able to reboot the x86 router ? (i know - quite hard when BGP is involved, 'cause it might impact a whole other aspects when ...
by spippan
Wed Mar 19, 2025 10:46 am
Forum: Announcements
Topic: SwOS version 2.17 released!
Replies: 16
Views: 142924

Re: SwOS version 2.17 released!

SwOS is rock solid as is, I have some CRS317’s with over 500 days of uptime running on our ISP. The only request that many of us have, is to implement basic security prompts. You can easily press a button on the GUI by accident and bring down an entire network. I had an incident with a tech were he...
by spippan
Wed Mar 19, 2025 10:34 am
Forum: General
Topic: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License
Replies: 38
Views: 4486

Re: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License

just curious how the plan for that would look like with ROS? NPK packages are signed and i assume also at boot time when kernel is loaded, You might assume wrong. I'm not sure about ROS 7 (haven't dug too deeply into its guts yet), but at least with ROS 6 (or at least for most of its existence...ma...
by spippan
Wed Mar 19, 2025 10:32 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 209410

Re: v7.19beta [testing] is released!

ok then there might be something "new" or maybe it is related to a deeper level problem like offloading of the NIC(s) not working correctly at this point. were you able to reboot the x86 router ? (i know - quite hard when BGP is involved, 'cause it might impact a whole other aspects when a...
by spippan
Wed Mar 19, 2025 10:27 am
Forum: General
Topic: installation of system-7.18.2 failed: disk is too small
Replies: 10
Views: 1825

Re: installation of system-7.18.2 failed: disk is too small

netinstall to the rescue if all other methods fail.
by spippan
Wed Mar 19, 2025 9:37 am
Forum: General
Topic: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License
Replies: 38
Views: 4486

Re: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License

You can recompile the kernel to update or load third-party software and hardware drivers. The initrd.cpio file is extracted from the original BOOTX64.EFI, then compiled into the new kernel. By replacing the BOOTX64.EFI file, the kernel can be updated to enable more features without waiting for upda...
by spippan
Wed Mar 19, 2025 9:19 am
Forum: General
Topic: NetINstall will not work [SOLVED]
Replies: 5
Views: 9229

Re: NetINstall will not work [SOLVED]

also always remember to set the client firewall (windows or linux) to allow netinstall to access the network correctly and just for sake keeping, if possible, only have you ethernet interface active on which the MT device is connected. i often have fallen to that pit in the past (:
by spippan
Wed Mar 19, 2025 9:14 am
Forum: General
Topic: Weekly VLAN confusion post
Replies: 18
Views: 2293

Re: Weekly VLAN confusion post

OK, let's do this in correct order and one step at a time. Correct order: /interface bridge add /interface bridge port add /interface bridge vlan add /interface vlan add Do we agree on this? If I understand correctly, what you're saying is that a key to understanding this is to learn it in this spe...
by spippan
Wed Mar 19, 2025 8:54 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 209410

Re: v7.19beta [testing] is released!

the new bgp implementation in 7.19beta (all betas) seems not working fine on x86 platform, it is overloading the cores with very high routing usage. we experience high (70-90%) on a lot of cores, with normal irq usage where have high cpu. regards BFD active on any bgp session(s) ? that might be the...
by spippan
Thu Mar 13, 2025 5:39 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

if nobody has reported it yet TLDR. the VLAN overview goes crazy with many VLAN interfaces (about 100 in a QinQ setup) (see gif)
WinBox 4.0beta18


Peek 2025-03-13 16-27.gif
on which column do you sort here?
in other words - what is the active sorting criteria in the interface list?
by spippan
Thu Mar 13, 2025 5:37 pm
Forum: General
Topic: Feature request: Add sorting
Replies: 11
Views: 8036

Re: Feature request: Add sorting

...some "sortby=" on a print be helpful.

+1
by spippan
Thu Mar 13, 2025 5:34 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 629
Views: 263154

Re: v7.18.2 [stable] is released!

Why not? If https is used, then client can verify authenticity of server it's talking to. Yes, npk files do have some verification built in (I believe that packages are digitally signed by MT so it's not trivial to alter the contents). But two layers of security are better than one. And we definite...
by spippan
Thu Mar 13, 2025 5:12 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

Could you please reimplement "Open in new winbox"? Maybe even as a right-click or shift-click on "Connect" and "Connect to RoMON"? +100 for this I have 271 devices at the moment, it is PITA to always have to scroll to the previous location in history when I have to go ...
by spippan
Thu Mar 13, 2025 3:40 pm
Forum: Wireless Networking
Topic: Unifi access point
Replies: 16
Views: 3779

Re: Unifi access point

.📍.
by spippan
Sun Mar 09, 2025 12:23 am
Forum: MikroTik hardware questions
Topic: Mikrotik SFP/SFP+ Ethernet modules do not meet standard
Replies: 8
Views: 2541

Re: Mikrotik SFP/SFP+ Ethernet modules do not meet standard

...they do

never had any issues
also with plugging them into a Cisco or Ubiquiti
by spippan
Thu Mar 06, 2025 10:47 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

@teslasystems
damn impressive.

hope MT UX designers take notes here!
by spippan
Tue Feb 25, 2025 9:08 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 629
Views: 263154

Re: v7.18 [stable] is released!

thx. BFD in BGP now working again (as it did not work in 7.18beta4 - i don't know if it was addressed in b5, b6, rc1 or rc2)
by spippan
Wed Feb 19, 2025 1:59 pm
Forum: Forwarding Protocols
Topic: VRF suggestions
Replies: 7
Views: 3393

Re: VRF suggestions

also hi from AT
to help the forum understand your setup better:
- provide your configs (sanitized!) ( /export hide-sensitive file=somename )
- a (schematic) network diagram of your setup also helps, if done properly, a lot
by spippan
Wed Feb 19, 2025 1:38 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

Totally agree. And keyboard-shortcuts!!!

as i wanted back in v3 --> viewtopic.php?p=980023#p980023
by spippan
Wed Feb 19, 2025 1:15 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 34874

Re: v7.18rc [testing] is released!

@merkkg
... enumerate valid usernames in Mikrotik routers ...
"enumerate" is a bit of over exaggerated
by spippan
Fri Feb 07, 2025 1:47 am
Forum: Beginner Basics
Topic: How to offer DHCP only on WIFI but not on ether
Replies: 9
Views: 3241

Re: How to offer DHCP only on WIFI but not on ether

...or try to work wiith dhcp matcher options
this maybe could help

https://help.mikrotik.com/docs/spaces/R ... dorClasses
by spippan
Fri Feb 07, 2025 1:41 am
Forum: Beginner Basics
Topic: How to offer DHCP only on WIFI but not on ether
Replies: 9
Views: 3241

Re: How to offer DHCP only on WIFI but not on ether

is every wifi connecting client known? if so, create static leases and set the dhcp server pool to "static only"

so only known wifi clients (MAC addresses of the wifi cards) will be handed a lease.
by spippan
Thu Feb 06, 2025 12:01 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 189193

Re: v7.18beta [testing] is released!

note on container settings in v7.18beta4

had to change the Registry URL from "https://registry-1.docker.io/v2/" --> to --> "https://registry-1.docker.io"
now i can pull containers again
by spippan
Thu Feb 06, 2025 1:40 am
Forum: Forwarding Protocols
Topic: AMT - Automatic Multicast Tunneling support
Replies: 51
Views: 18099

Re: AMT - Automatic Multicast Tunneling support

@teslasystems

this cat always screams and posts in that manner are unfortunately usual. try to not bother to much ... one cannot re-educate or soften a stiff spaghetti even if it is on point

maybe "just roll with it" might be a good option 🤷‍♂️
by spippan
Mon Feb 03, 2025 10:32 pm
Forum: General
Topic: Feature requests
Replies: 1816
Views: 1108019

Re: Feature requests

at least 32MB would be "kind"

oh and on that occasion... static route BFD check would be nice ... viewtopic.php?t=186941#p1073107
by spippan
Sat Feb 01, 2025 6:57 pm
Forum: General
Topic: received NAK from dhcp server
Replies: 7
Views: 6222

Re: received NAK from dhcp server

it is surely the ZTE which does not behave correctly WAN port is not in a bridge. of course not (; i'll see what i could do about it. currently i changed the bridge-mode of the ZTE MC801A back to NAT, deactivated dhcp completely there and assigned a static IP. on the wan port of the MT it is 172.16....
by spippan
Fri Jan 31, 2025 11:56 am
Forum: General
Topic: How to secure DarkFiber between 2 MikroTik
Replies: 17
Views: 7874

Re: How to secure DarkFiber between 2 MikroTik

You can even buy off the shelf dedicated MACSEC media converters now-a-days : https://www.extremenetworks.com/products/adapters-and-converters/switch-adapters-and-converters/lrm-and-macsec-adapter ...which requires an additional license for MACsec operation AND an extreme-networks host switch to ev...
by spippan
Fri Jan 31, 2025 11:48 am
Forum: General
Topic: received NAK from dhcp server
Replies: 7
Views: 6222

Re: received NAK from dhcp server

thx @mkx i know how dhcp works and a renew may occur half of max-lease-time. here it is not the case. given lease is valid for 4h but still there are NAKs way before lease-time ever reaches, for say, 2h left. if there is a release or just a renew, normally it works totally fine. the problem addition...
by spippan
Thu Jan 30, 2025 4:08 pm
Forum: Forwarding Protocols
Topic: How to use "input accept communities" in BGP?
Replies: 14
Views: 13993

Re: How to use "input accept communities" in BGP?

in 7.16.2 (running on a 1100AHx4) it filters out communities which are not in the given list.

what do you expect to happen? that the route would not become active if a given community is not sent with the route-info?
by spippan
Wed Jan 29, 2025 12:24 pm
Forum: General
Topic: received NAK from dhcp server
Replies: 7
Views: 6222

Re: received NAK from dhcp server

same issue on 5G network "3 AT" with a ZTE MC801A in bridge mode every once in a while i receive a NAK from the WAN side (the ether1 which is connected to the ZTE 5G modem in bridge mode) 172.16.88.1 is the local IP of the ZTE device (my MT has 172.16.88.2/26 on ether1-WAN additionally for...
by spippan
Fri Jan 24, 2025 6:10 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 189193

Re: v7.18beta [testing] is released!

*) 60ghz - improved system stability; More details on this please - does it affect all devices, or just the newer 802.11ay ones (the older 802.11ad have been quite stable in my experience, still running 6.49.x on them)? would also love to see more information on that. got about 6 setups with 60GHz ...
by spippan
Fri Jan 24, 2025 6:05 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 189193

Re: v7.18beta [testing] is released!

+1 on nz_monkey regarding VXLAN comments and eVPN. Could I add in( no doubt a new switch chip for future products ), but hardware offloaded MACSEC as part of the underlay. "And include jumbo frames ( aka 9000 byte + frame)" My use case is commercial datacenter/carrier providers(via L2) to...
by spippan
Wed Jan 22, 2025 10:08 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 189193

Re: v7.18beta [testing] is released!

side note

love how engaged MT support is on 7.17 and 7.18bXX forum threads the last days.
feels like things really start to get moving again
by spippan
Wed Jan 22, 2025 9:59 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 189193

Re: v7.18beta [testing] is released!

Feature which will help me considerably are L3HW offloading full vrf support not only the main table As well as Full MPLS Offloading or multicore processing I'm using CCR2216 and i'm happy to do any testing thats needed and provide feedback. i++; on VRF Hardware Offload! L3VPN (over MPLS or over EV...
by spippan
Wed Jan 22, 2025 9:58 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 189193

Re: v7.18beta [testing] is released!

About HW VXLAN. Supported devices are ones that support L3HW offloaded fasttrack/NAT : CRS309-1G-8S+, CRS317-1G-16S+, CRS312-4C+8XG, CRS326-24S+2Q+, CRS326-4C+20G+2Q+, CRS354-48G/P-4S+2Q+, CRS504-4XQ, CRS510-8XS-2XQ, CRS518-16XS-2XQ, CRS520-4XS-16XQ, CCR2116-12G-4S+, CCR2216-1G-12XS-2XQ. The main g...
by spippan
Sat Jan 18, 2025 10:57 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 971954

Re: v7.17 [stable] is released!

do we have any update on [SUP-134566]: BGP-VRF V7?

when that feature will be implemented.
It works perfectly fine on v6

what is the problem here?

cannot find SUP-134566 when i search for it here
by spippan
Sat Jan 18, 2025 10:19 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 971954

Re: v7.17 [stable] is released!

do we have any update on [SUP-134566]: BGP-VRF V7?

when that feature will be implemented.
It works perfectly fine on v6

what is the problem here?

cannot find SUP-134566 when i search for it here
by spippan
Sat Jan 18, 2025 10:16 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 971954

Re: v7.17 [stable] is released!

"Wireless" is fine with 7.17, but "wifi-qcom-ac" is crap, unfortunately. I have had long time open memory leak ticket SUP-147911 for hAP ac^2. This ticket has been closed without solution - but it is bullet proof the leak is related to "wifi-qcom-ac", because "wir...
by spippan
Tue Jan 14, 2025 12:07 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

But the question was about Filter, not about Sort. And there is already a Filter button, that lets you filter by any column, and by multiple columns. My idea is only about usability for filtering: pls. see the image from the post from @mszru. I appreciate that the filter function is implemented. I ...
by spippan
Tue Jan 07, 2025 5:22 pm
Forum: Wireless Networking
Topic: Mikrotik AX PTP Netmetal AX
Replies: 49
Views: 16386

Re: Mikrotik AX PTP Netmetal AX

📍 just reading along - hope to see a solution on that topic as well before i consider switching to AX PtP links
by spippan
Tue Jan 07, 2025 4:46 pm
Forum: General
Topic: Feature Request: Wireguard over VRF
Replies: 12
Views: 8281

Re: Feature Request: Wireguard over VRF

...or if one has "n" customers on a CCR cluster and customers are in their own VRF respectively
so in no case whatsoever it is remotely stupid
by spippan
Tue Jan 07, 2025 2:24 pm
Forum: General
Topic: Feature Request: Wireguard over VRF
Replies: 12
Views: 8281

Re: Feature Request: Wireguard over VRF

so we wait.

cummulus (and therefore linux) is able to do that
by spippan
Tue Jan 07, 2025 12:00 am
Forum: General
Topic: Wireguard - access from VRF [SOLVED]
Replies: 13
Views: 9718

Re: Wireguard - access from VRF [SOLVED]

🤦‍♂️
by spippan
Mon Jan 06, 2025 12:00 pm
Forum: General
Topic: Feature Request: Wireguard over VRF
Replies: 12
Views: 8281

Re: Feature Request: Wireguard over VRF

Why, network better -- dont create overlapping subnets............ Wireguard works just fine, if done properly. (caveat home user, dont support real work) and also here ... it does not have to do something with overlapping networks. don't always assume stuff without properly knowing any background.
by spippan
Mon Jan 06, 2025 11:57 am
Forum: General
Topic: Wireguard - access from VRF [SOLVED]
Replies: 13
Views: 9718

Re: Wireguard - access from VRF [SOLVED]

how does asking for VRF support for wireguard and allegedly "not knowing how to properly use wireguard" relate to each other??
by spippan
Fri Jan 03, 2025 3:46 pm
Forum: General
Topic: Wireguard - access from VRF [SOLVED]
Replies: 13
Views: 9718

Re: Wireguard - access from VRF [SOLVED]

Same issue, very badly waiting for WireGuard vrf support
same.
VRF support for Wireguard Interfaces! => viewtopic.php?p=1117383#p1117383
by spippan
Fri Jan 03, 2025 3:46 pm
Forum: General
Topic: Feature Request: Wireguard over VRF
Replies: 12
Views: 8281

Re: Feature Request: Wireguard over VRF

VRF support for Wireguard Interfaces! Please!
by spippan
Fri Jan 03, 2025 3:42 pm
Forum: General
Topic: Configuring VLAN tagged/untagged
Replies: 11
Views: 3467

Re: Configuring VLAN tagged/untagged

add bridge=BR1 interface=ether3 pvid=187 - if I add this admit-only-vlan-tagged i'm losing access to the other VLAN's
try setting the PVID to 1 (or 4094 when not used otherwise) --> 187 coming in tagged and also PVID set to that VLAN ID does not go well in ROS ... still
by spippan
Fri Jan 03, 2025 3:32 pm
Forum: General
Topic: VRF-support for DNS is broken?
Replies: 21
Views: 13535

Re: VRF-support for DNS is broken?

Responding to my own post, it seems that this is no longer CLI only, I think newer Winbox versions matches this option in DNS, ability to select VRF. Someone please correct me, maybe there is more to it. I would very much like DNS to work on any VRF, not only main or whatever I (single only) select...
by spippan
Fri Jan 03, 2025 3:31 pm
Forum: General
Topic: VRF-support for DNS is broken?
Replies: 21
Views: 13535

Re: VRF-support for DNS is broken?

As for the ticket system: there is a default filter to show only open issues in the list. you need to change the filter to "any status".
bummer ... thanks for the hint.
by spippan
Fri Jan 03, 2025 2:52 pm
Forum: General
Topic: VRF-support for DNS is broken?
Replies: 21
Views: 13535

Re: VRF-support for DNS is broken?

Responding to my own post, it seems that this is no longer CLI only, I think newer Winbox versions matches this option in DNS, ability to select VRF. Someone please correct me, maybe there is more to it. I would very much like DNS to work on any VRF, not only main or whatever I (single only) select...
by spippan
Thu Jan 02, 2025 5:26 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: WinBox 4 Beta 14 Bug Problem

...
@inazmul

why are you using my avatar picture?
by spippan
Thu Jan 02, 2025 5:08 pm
Forum: General
Topic: How to secure DarkFiber between 2 MikroTik
Replies: 17
Views: 7874

Re: How to secure DarkFiber between 2 MikroTik

Not really but Arista, Cisco, Juniper (and many others) all have decent macsec enabled switches.
...
if it is just for MACsec securing dark fibre and need to stay on a budget (sort of) consider a look towards the fs.com S5800-48F4SR
it supports MACsec wirespeed
by spippan
Thu Jan 02, 2025 4:39 pm
Forum: RouterOS beta
Topic: 802.1AE MACsec Progress or Examples ?
Replies: 48
Views: 30677

Re: 802.1AE MACsec Progress or Examples ?

hopefully 2025 will change this and MT decides to enable MACsec hw-offload
by spippan
Wed Dec 25, 2024 4:24 pm
Forum: SwOS
Topic: MLAG in ring topology
Replies: 8
Views: 7367

Re: MLAG in ring topology

hope dies last. we will see. not that i depend on MT for my L2... certainly not.
by spippan
Mon Dec 23, 2024 12:24 pm
Forum: SwOS
Topic: MLAG in ring topology
Replies: 8
Views: 7367

Re: MLAG in ring topology

yes somehow but the switching capacity is very limited VS with real stacking solution on Cisco / Juniper and another pita if my memory serves correctly is MSTP and Double Tag Stacking yep, it's not quite performing in more serious setups unfortunately waiting on v7.18 for more L2 functionality (;
by spippan
Sun Dec 22, 2024 2:32 pm
Forum: SwOS
Topic: MLAG in ring topology
Replies: 8
Views: 7367

Re: MLAG in ring topology

stacking on the other hand can go up to 8 switches with most vendors which support stacking. Another missed opportunity with Mikrotik Stacking / Virtual Chassis in Juniper world is pretty much after sought feature can be done with bridge controller (at least with a "lite" feature set at l...
by spippan
Sun Dec 22, 2024 1:12 pm
Forum: SwOS
Topic: MLAG in ring topology
Replies: 8
Views: 7367

Re: MLAG in ring topology

In the documentation on MLAG only examples with two switches in a MLAG configuration can be found. Is it possible to create a MLAG with 3-4 switches in a ring topology instead of a fully meshed topology? Other vendors like Aruba support stacking in a ring topology. no. stacking and MLAG are differe...
by spippan
Wed Dec 11, 2024 3:28 pm
Forum: General
Topic: IP Cloud (Dynamic DNS) down?
Replies: 101
Views: 20689

Re: IP Cloud (Dynamic DNS) down?

I'd like to suggest a public status page for Mikrotik services. So people don't have to flood forum and support helpdesk with all the same "omg, it is down" reports.
+1
by spippan
Mon Dec 02, 2024 4:19 pm
Forum: General
Topic: Feature requests
Replies: 1816
Views: 1108019

Re: Wake On Lan in winbox leases context menu

something like an entry in the context menu Of which menu? You are surely aware that when device is in sleep mode, it doesn't transmit anything and all caches (e.g. ARP cache, list of DHCP leases, etc.) will forget about it probably long before you'd want to send WoL packet to it, aren't you? Which...
by spippan
Mon Dec 02, 2024 4:18 pm
Forum: General
Topic: Feature requests
Replies: 1816
Views: 1108019

Re: Feature requests

Static DHCP leases have the MAC Address saved, so on that context menu (which seems to be the screenshot from) makes perfect sense.
exactly. thank you sir!
by spippan
Mon Dec 02, 2024 2:29 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

What's new in v4.0beta13: *) implement opened windows list *) implement global menu search *) bump minimal macOS version to 12.0, because 11.0 is EOL and dropped by Qt *) accept button with Enter/Return keys also on Windows and macOS *) fix max u32 value processing on some fields *) fix visual 1px ...
by spippan
Mon Dec 02, 2024 1:49 pm
Forum: General
Topic: Feature requests
Replies: 1816
Views: 1108019

Re: Wake On Lan in winbox leases context menu

...
I think, it will be usefull to have context option "Wake On Lan" in ip / dhcp-server / leases.
...

i just thought this option would come in handy!
something like an entry in the context menu
Screenshot from 2024-12-02 12-15-23.png
by spippan
Thu Nov 28, 2024 2:34 pm
Forum: General
Topic: Disabling system,error,critical login failure for user foobar from so.me.ip.num via ssh
Replies: 9
Views: 1521

Re: Disabling system,error,critical login failure for user foobar from so.me.ip.num via ssh

@matkor

please have a good and thorough read here https://medium.com/@im0nk3yar0und/secur ... cb28161f9e

and reconsider the decision to expose SSH to the internet ... by not even changing the default port tcp/22 to something else!
by spippan
Thu Nov 28, 2024 2:27 pm
Forum: General
Topic: How to block webpages by URL?
Replies: 5
Views: 1414

Re: How to block webpages by URL?

one could use https://help.mikrotik.com/docs/spaces/R ... DNS-Adlist

and specifiy a local file where the unwanted domain/fqdn entries are listed
by spippan
Thu Nov 28, 2024 2:14 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

How do i import saved session to new winbox4
right click the space in "Saved" view
28_11_2024.png
by spippan
Fri Nov 22, 2024 3:06 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

with beta12 WB4 is coming to a useful state more and more. 1 - please change the startup behaviour or save the last state at least to start the " Select from: " menu in the last state or to start in the " Saved " view 2 + 3 - please focus the cursor to the "Password" fi...
by spippan
Tue Nov 19, 2024 10:28 pm
Forum: General
Topic: MLAG hopelessly broken?
Replies: 58
Views: 25352

Re: MLAG hopelessly broken?

as in the latest 7.17beta5 changelog, mikrotik is obviously working on bridge and mlag performance
so hopefully on 7.17 final or 7.18 MLAG is finally USABLE

viewtopic.php?p=1108704#p1109249
by spippan
Tue Nov 12, 2024 4:44 pm
Forum: General
Topic: Why do I (apparently) need to use vrrp interfaces in firewall?
Replies: 6
Views: 1295

Re: Why do I (apparently) need to use vrrp interfaces in firewall?

You can try the reverse thing: create a single VRRP, create VLANs on top of VRRP. This should work, if it's ok that a single VRRP handles all VLANs at once.
tested it in EVE-NG
one VRRP interface and all vlans "under" this VRRP does NOT work ... as i expected
by spippan
Tue Nov 12, 2024 2:39 pm
Forum: General
Topic: Why do I (apparently) need to use vrrp interfaces in firewall?
Replies: 6
Views: 1295

Re: Why do I (apparently) need to use vrrp interfaces in firewall?

You can try the reverse thing: create a single VRRP, create VLANs on top of VRRP. This should work, if it's ok that a single VRRP handles all VLANs at once. how would that look like facing the switch(es) ? that would require the VRRP participating routers to be connected to a full trunk port and th...
by spippan
Mon Nov 11, 2024 5:56 pm
Forum: Wireless Networking
Topic: Frequency issue with Mantbox 15 AX
Replies: 2
Views: 3772

Re: Frequency issue with Mantbox 15 AX

as for now (2024-11-11) nv2 is not available for any AX devices!
by spippan
Sun Nov 10, 2024 10:04 pm
Forum: General
Topic: Allow management only on a specific ethernet port using VRF
Replies: 1
Views: 895

Re: Allow management only on a specific ethernet port using VRF

but be aware, as for now, it would not be possible to resolve DNS queries in the VRF "management" with DNS servers set in "IP > DNS > Servers" (according to MT support this is known and will be addressed somewhen in the future) DNS upstream only resides in the "main" VR...
by spippan
Wed Oct 30, 2024 10:24 pm
Forum: MikroTik hardware questions
Topic: CRS520-4XS-16XQ-RM
Replies: 2
Views: 8291

Re: CRS520-4XS-16XQ-RM

Yes, it looks nice, and will indeed fill in a gap in the market and be good for many "basic" switching applications.. That said, for me : Big talk of future upgrades; sorry, tell me what I am getting now, not what may or may not come.. Will stick with Cisco, as you know what your getting ...
by spippan
Wed Oct 30, 2024 10:19 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225070

Re: v7.17beta [testing] is released!

so, could *) crypto - use hardware accelerator for GCM cipher in TLS connection on Alpine CPUs; ...mean a pathway to use MACsec with hardware offload in the near future? (yeah i know, MACsec and TLS connection does not go along in the same sentence - but the option to use hw-offload for GCM ciphers...
by spippan
Wed Oct 30, 2024 10:12 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225070

Re: v7.17beta [testing] is released!

an that is bad??
But putting myself in their shoes, if every time they release a change a horde of zombies appears shouting (even though it's in testing), it's only natural that they start hiding their actions more.
that's the nature of this community i learnt over the years now. sad.
by spippan
Wed Oct 30, 2024 1:14 am
Forum: General
Topic: DHCP Relay and Redundant DHCP Servers, sync dynamic leases??
Replies: 3
Views: 812

Re: DHCP Relay and Redundant DHCP Servers, sync dynamic leases??

would be like to see a dhcp failover setup on MT too 📌
by spippan
Wed Oct 30, 2024 1:12 am
Forum: Beginner Basics
Topic: What's wrong with my firewall rules? [SOLVED]
Replies: 9
Views: 2732

Re: What's wrong with my firewall rules? [SOLVED]

why deleting the defconf firewal-rules when apparently not really understanding how ROS ("iptables") firewall works essentially?

if not building smth sophisticated or speacial-purposed, take the default FW configuration from routerboard factory configuration and build up from there
by spippan
Tue Oct 29, 2024 12:23 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

WinBox 4 is great in a lot of ways, but in one particular way it is a HUGE regression..... TABS! Can we please have tabs back in all elements of WinBox 4. Not having them makes using WinBox 4 very cumbersome and time consuming SFP Info in WinBox 4 = a lot of wasted space 00MTCapture.PNG SFP Info in...
by spippan
Mon Oct 28, 2024 11:54 pm
Forum: General
Topic: Net Flow Collector NAT
Replies: 6
Views: 1945

Re: Net Flow Collector NAT

@spippan, not sure what you setup is, but you can always look at this https://github.com/netsampler/goflow2 In there is a docker compose that sets everything up including some ready to use grafana charts to see network traffic https://github.com/netsampler/goflow2/tree/main/compose/kcg thanks a lot...
by spippan
Sun Oct 20, 2024 9:11 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225070

Re: v7.17beta [testing] is released!

What's new in 7.17beta4 (2024-Oct-18 11:32): *) crypto - use hardware accelerator for GCM cipher in TLS connection on Alpine CPUs; *) ssh - added option to configure SSH ciphers (replaced allow-none-crypto parameter); so, could *) crypto - use hardware accelerator for GCM cipher in TLS connection o...
by spippan
Tue Oct 15, 2024 11:36 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225070

Re: v7.17beta [testing] is released!

bridge - added interface-list support for VLAN : the best features!!!!

This will simplify VLAN tables!thank you mikrotik.
is there any docs how we are ablte to use this feature? or best-practice?

EDIT: found it where it is used... (screenshot)
Screenshot from 2024-10-15 23-02-56.png
by spippan
Tue Oct 15, 2024 10:52 pm
Forum: 3rd party tools
Topic: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management
Replies: 82
Views: 32549

Re: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management

No, Fully active, and we are currently updating the software(not pushing to customers for now). As the founder of the software, I am busy with my wedding and the company's establishment and testing the new features, working on the trial and demo possibilities for the pro version ( asked by many cus...
by spippan
Sun Oct 13, 2024 8:23 pm
Forum: General
Topic: SAMBA video streaming interrupted if paused more than 20 seconds
Replies: 9
Views: 1172

Re: SAMBA video streaming interrupted if paused more than 20 seconds

is it working with 7.15.3? maybe stay there a little longer?

one thing you can try additionally now, try to disable the windows client firewall shortly for testing
by spippan
Thu Oct 10, 2024 1:30 pm
Forum: General
Topic: Firmware 7.16 [SOLVED]
Replies: 19
Views: 2449

Re: Firmware 7.16 [SOLVED]

And Mikrotik disrupted my company's work so how did MT do that? was it MT who did not test your setup and your configuration on the applied firmware? was it MT who did not test essential functions of your setup vital to your company working? do not ever apply untested (by yourself in your environme...
by spippan
Wed Oct 09, 2024 3:53 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225070

Re: v7.17beta [testing] is released!

fischerdouglas compilation Have you MikroTik guys considered splitting the DNS service as was done with the Wifi packages? Separating different things of different interest into Packages? .... In regards to have a "more advanced" DNS service in a separate package is not a bad idea at all,...
by spippan
Wed Oct 09, 2024 3:40 pm
Forum: General
Topic: Whats the point of this default FW rule?
Replies: 25
Views: 4079

Re: Whats the point of this default FW rule?

This rule does get hit if you use it as intended, yes. Any NAT rule that you have dst-nat to an internal computer will be on the forward chain. You can use this default rule instead of a default drop-all so that anything dst-natted will be allowed instead of creating both a nat rule and a filter ru...
by spippan
Wed Oct 09, 2024 3:28 pm
Forum: General
Topic: [FEATURE REQUEST] Two Factor Authentication
Replies: 53
Views: 42237

Re: [FEATURE REQUEST] Two Factor Authentication

This works, except when you go to terminal inside winbox, you have to login again with a new otp code because most of the time your 30 second window has already expired before you open the terminal window. the whole point of TOTP add a local user which is only allowed from 127.0.0.1 and use that us...
by spippan
Wed Oct 09, 2024 12:25 am
Forum: General
Topic: Whats the point of this default FW rule?
Replies: 25
Views: 4079

Re: Whats the point of this default FW rule?

Hi all, I'm having a clean out of unused Firewall rules and I can't for the life of me figure out the purpose of this default rule. add chain=forward action=drop connection-state=new connection-nat-state=!dstnat in-interface-list=WAN comment="defconf: drop all from WAN not DSTNATed" As fa...
by spippan
Wed Oct 09, 2024 12:09 am
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 257391

Re: v7.16 [stable] is released!

a quick thought ... is auto-negotiation enabled on those 40G links? is FEC configured on the 40G links on both sides? i'd try to set the link speeds to fixed on both ends and configure FEC accordingly ("fec74" on 40G) Edit: I see FEC74 doesn't have anything to do with forward error correc...
by spippan
Wed Oct 09, 2024 12:04 am
Forum: General
Topic: Can't netinstall hAP ac2
Replies: 17
Views: 1602

Re: Can't netinstall hAP ac2

make sure there is no "ufw" or "firewalld" or "iptables" service active (regardless of rules being present or not) and deaktivate all other interfaces other than the one connecting to your router if nothing of that works, good chance there is something down with the boo...
by spippan
Wed Oct 09, 2024 12:00 am
Forum: General
Topic: SAMBA video streaming interrupted if paused more than 20 seconds
Replies: 9
Views: 1172

Re: SAMBA video streaming interrupted if paused more than 20 seconds

could be a combination of
tcp-close-wait-timeout + tcp-close-timeout
try to look at the ip > firewall > connections section, maybe this will be visible there what is happening.
by spippan
Tue Oct 08, 2024 3:00 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225070

Re: v7.17beta [testing] is released!

a roadmap would be nice (*wishful thinking*)
by spippan
Tue Oct 08, 2024 2:59 pm
Forum: General
Topic: Can't netinstall hAP ac2
Replies: 17
Views: 1602

Re: Can't netinstall hAP ac2

have you checked for any active firewall on your PC?
and why arch? just boot a live iso like debian of fedora, check to see if any firewall is surely disabled and run netinstall on cli

netinstall has never let me down on any of my 3 linux machines
by spippan
Tue Oct 08, 2024 2:04 pm
Forum: General
Topic: SAMBA video streaming interrupted if paused more than 20 seconds
Replies: 9
Views: 1172

Re: SAMBA video streaming interrupted if paused more than 20 seconds

what does "/ip/firewall/connection/tracking/print" show?
by spippan
Tue Oct 08, 2024 1:33 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

Need colors in log. Like Red for errors and other.
+2
still not (re)implemented

and also finally a TIMEOUT when moving the mouse between menu items on the left (like, not instant. a short delay when moving between e.g. MPLS and Routing entries
by spippan
Tue Oct 08, 2024 12:37 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225070

Re: v7.17beta [testing] is released!

wonder if there are any 98DX or other marvell chips in use by MT are able to do this (did not read all whitepapers - maybe someone knows someone who might have some insight 🤷‍♂️ ) https://forum.mikrotik.com/viewtopic.php?t=211511 Unfortunately, L3HW doesn't support VRF yet. The hardware (switch chi...
by spippan
Tue Oct 08, 2024 12:34 pm
Forum: Wireless Networking
Topic: WiFi Wave2 and CAPsMan v3 and VLANs
Replies: 13
Views: 5356

Re: WiFi Wave2 and CAPsMan v3 and VLANs

Please have a good look at this part of the documentation: https://help.mikrotik.com/docs/display/ROS/WiFi#WiFi-CAPusing%22wifi-qcom-ac%22package: Can you share the /interface wifi export of both the CAPsMAN and the CAP? /interface/wifi/export Remove serial and any other private info. I have both a...
by spippan
Tue Oct 08, 2024 12:10 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 257391

Re: v7.16 [stable] is released!

MLAG on 2 x CRS354-48G-2S+2Q+ switches continues to be a problem. MLAG peer link is a 802.3ad (LACP) bond interface utilising two Q+ (40G) ports with MikroTik DACs. We've tried swapping the DACs which made no difference. Bond and slave interface status shows zero 'link down' events but MLAG peer st...
by spippan
Tue Oct 08, 2024 12:05 pm
Forum: MikroTik hardware questions
Topic: Hardware for x86 (Replacing 2216)
Replies: 38
Views: 14525

Re: Hardware for x86 (Replacing 2216)

maybe a bit of a stretch but tried v7.15? also with the "extra-nics.npk" from the ISO file? ( https://download.mikrotik.com/routeros/7.15/CHANGELOG ) not sure if this is even compatible/possible but maybe worth a shot I have tried using version 7.15 but there is no “extra-nics.npk” during...
by spippan
Tue Oct 08, 2024 2:14 am
Forum: Wireless Networking
Topic: cAP AX and Dynamic VLAN assignment [SOLVED]
Replies: 9
Views: 12243

Re: cAP AX and Dynamic VLAN assignment [SOLVED]

there are 3 attributes which come to play here maybe this guide helps or clearifies some stuff -> https://administrator.de/forum/mikrotik-dyn-vlan-und-mac-auth-in-ros-7-2-2466135253.html EDIT: the article shows the mikrotik user-manger radius implementation but the 3 attributes are standardized no m...
by spippan
Tue Oct 08, 2024 2:06 am
Forum: Wireless Networking
Topic: WiFi Wave2 and CAPsMan v3 and VLANs
Replies: 13
Views: 5356

Re: WiFi Wave2 and CAPsMan v3 and VLANs

AFAIK the capsman v3 with wifi-qcom-ac does not play well when it comes to datapaths and VLANs ... never figured it out my own with 2 hap ac²
by spippan
Mon Oct 07, 2024 6:31 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225070

Re: v7.17beta [testing] is released!

From my perspective, VRF Hardware Offload in conjunction with MPLS (i.e. MPLS VPNv4) is the most important functionality that should be added. wonder if there are any 98DX or other marvell chips in use by MT are able to do this (did not read all whitepapers - maybe someone knows someone who might h...
by spippan
Mon Oct 07, 2024 6:21 pm
Forum: MikroTik hardware questions
Topic: Hardware for x86 (Replacing 2216)
Replies: 38
Views: 14525

Re: Hardware for x86 (Replacing 2216)

maybe a bit of a stretch but tried v7.15?
also with the "extra-nics.npk" from the ISO file? (https://download.mikrotik.com/routeros/7.15/CHANGELOG)

not sure if this is even compatible/possible but maybe worth a shot
by spippan
Mon Oct 07, 2024 1:04 am
Forum: General
Topic: Exclude fasttrack from specif ip [SOLVED]
Replies: 4
Views: 848

Re: Exclude fasttrack from specif ip [SOLVED]

Thank you Mkx, I've already try adding a chain forward accept rule with the src address. The result was that some traffic was captured by the rule, but the site still fails. Any ideas? try to add another route below but set the said ip address as dst-address and enable connection-state "establ...
by spippan
Fri Oct 04, 2024 10:27 pm
Forum: MikroTik hardware questions
Topic: Hardware for x86 (Replacing 2216)
Replies: 38
Views: 14525

Re: Hardware for x86 (Replacing 2216)

latest NIC firmware installed? those cards sometimes do not initialize when a boot happens
by spippan
Thu Oct 03, 2024 2:03 pm
Forum: General
Topic: How does disable-ipv6 work?
Replies: 3
Views: 1040

Re: How does disable-ipv6 work?

i assume but cannot verify (not using ipv6 anymore at the moment)

but you can check with a ipv6 drop rule on the '"input" and "forward" chaing with "log=yes" to see what happens (if something happens)
by spippan
Thu Oct 03, 2024 2:01 pm
Forum: MikroTik hardware questions
Topic: Hardware for x86 (Replacing 2216)
Replies: 38
Views: 14525

Re: Hardware for x86 (Replacing 2216)

Hello, have you ever experienced that the nic installed on the Dell server is not detected in Mikrotik? I have this problem, where the nic is detected up on the Dell 630 IDRAC but is not on / running on Mikrotik OS version 7.16 or 7.15.3. When disabled on the other side it turns on, only in the Mik...
by spippan
Wed Oct 02, 2024 12:33 pm
Forum: General
Topic: How does disable-ipv6 work?
Replies: 3
Views: 1040

Re: How does disable-ipv6 work?

LL in context of ipv6 is commonly refered to as LinkLocal. it is not too hard to co-relate if ipv6 is disabled completely on ros, no LL adr. generation happens, no ipv6 routing/forwarding accurs, hence ipv6 communication is not active through the router or to the router i terms of ipv6 firewall - ca...
by spippan
Mon Sep 30, 2024 9:53 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 225070

Re: v7.17beta [testing] is released!

some solid work on bridge regarding mlag and VLANs (will have to rework some bridge setups xD )

thanks a lot for the impressive work you doing here! pace is on!! cheers guys
by spippan
Sun Sep 29, 2024 9:07 pm
Forum: MikroTik hardware questions
Topic: Hardware for x86 (Replacing 2216)
Replies: 38
Views: 14525

Re: Hardware for x86 (Replacing 2216)

... The secret that no one will tell you.. either because they have not lost time testing.. is the NIC cards... in order to suceed with Multi-CPU x86_64 on RouterOS v7.15.xx stable version.. is the Network cards... because they are related to IRQ on the CPU.. basically the more IRQs slots available...
by spippan
Sun Sep 29, 2024 8:48 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 257391

Re: v7.16 [stable] is released!

DNS-01 support for LE would be amazing. I’m not punching holes for port 80 from the world to internal gear but I already use DNS-01 to handle internal certificates for k8s. This is definitely the right path forward. DNS-01 with LE would be awesome!! had to setup cloudflare for a nginx reverse wildc...
by spippan
Sun Sep 29, 2024 8:46 pm
Forum: Announcements
Topic: Question to our users about controllers
Replies: 127
Views: 209153

Re: Question to our users about controllers

========== NEW QUESTION ========== Thank you all for input. New question. What specific features would you like to provision in these controller type of setups. What is your #1 use case, which config is most often needed to apply "en masse" or to multiple devices? P.S: it seems nearly all...
by spippan
Sun Sep 29, 2024 8:42 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

@normis Winbox 4 beta 6

Can't add new interface lists. I can create them in the terminal and then add / remove members in Winbox but can't create a new list.
works in beta8
by spippan
Tue Sep 24, 2024 1:38 pm
Forum: Wireless Networking
Topic: Missing wAP ax successor to wAP ac, what are outdoor AX WiFi alternatives?
Replies: 38
Views: 10666

Re: Missing wAP ax successor to wAP ac, what are outdoor AX WiFi alternatives?

...
It appears like a rather compact device, probably around 10x15x3 cm.

I haven't found actual photos, but I only had a quick peek.
https://fccid.io/TV7WAPGR52AX/Test-Repo ... on-7634095 shows a little preview in the antenna radiation pattern exhibits
by spippan
Tue Sep 24, 2024 1:37 pm
Forum: Wireless Networking
Topic: Missing wAP ax successor to wAP ac, what are outdoor AX WiFi alternatives?
Replies: 38
Views: 10666

Re: Missing wAP ax successor to wAP ac, what are outdoor AX WiFi alternatives?

Chateau will likely be "H53UiG-5HaxQ2HaxQ" and probably around 500€
wAP ax will likely be "wAPG-5HaxD2HaxD"

looking forward to wAPax :D :D
by spippan
Mon Sep 23, 2024 1:22 am
Forum: General
Topic: The logic of Filter Rules
Replies: 4
Views: 1079

Re: The logic of Filter Rules

filter rules work on top-down first-match base as a rule of thumb in ROS (and mostly in any OS of other vendors too)
so the first rule a connection matches into will be executed and no following rule for that matched connection
by spippan
Fri Sep 20, 2024 3:28 pm
Forum: Announcements
Topic: Question to our users about controllers
Replies: 127
Views: 209153

Re: Question to our users about controllers

As an internet Service Provider, that also is considering more of a Managed Service Provider role: For my own stuff, locally-hosted servers are a must, and containers (or an NPK on a CCR2xxx/CHR would be cool). I like how Ubiquiti keeps UniFi separate from UISP. I use UniFi to manage customer's int...
by spippan
Thu Sep 19, 2024 11:14 pm
Forum: Announcements
Topic: Question to our users about controllers
Replies: 127
Views: 209153

Re: Question to our users about controllers

1) a + b as maybe 2 seperate installments or a as a subcategory in b 2) self hosted on X86 preferably 3) main features (for a start): firmware revision with up/downgrade of many devices maybe also in groups/sites (like the UISP from U) config push and backup with diff (change management) archive mon...
by spippan
Wed Sep 18, 2024 6:37 pm
Forum: Beginner Basics
Topic: Playing with VRFs - what am I doing wrong?
Replies: 22
Views: 6509

Re: Playing with VRFs - what am I doing wrong?

experiments with VRFs to implement an automatic failover between 2 ISPs Maybe I'm missing something here... But what is the point of using VRF for ISP failover? — VRFs have nothing to do with "automatic failover". Failover works without VRFs, and so layering VRF on top of failover mechani...
by spippan
Wed Sep 18, 2024 5:45 pm
Forum: Beginner Basics
Topic: Playing with VRFs - what am I doing wrong?
Replies: 22
Views: 6509

Re: Playing with VRFs - what am I doing wrong?

thanks @jaclaz i'll go through that ... curious about that.
by spippan
Wed Sep 18, 2024 12:08 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

spippan Are you using 4.0beta6? Could you please create a support ticket regarding the NAT login issue along with supuout.rif file made after the issue appears and other details - what system is the WinBox running on? I tried reproducing the issue, but it seems to work as expected. Is the "aut...
by spippan
Tue Sep 17, 2024 11:13 pm
Forum: Wireless Networking
Topic: CAPsMAN & CAP-AX Wireless issues
Replies: 10
Views: 4680

Re: CAPsMAN & CAP-AX Wireless issues

i do not know for sure but could this interfere somehow? /interface wifi channel add band=5ghz-ax disabled=no name="5 GHz" skip-dfs-channels=all width=20/40mhz /interface wifi configuration add channel="5 GHz" channel.skip-dfs-channels=all country=Romania datapath="VLAN 24&q...
by spippan
Tue Sep 17, 2024 10:51 pm
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 138496

Re: v7.16rc [testing] is released!

Yes, it is like in any other configuration with vrf parameter.
is there a possible solution to resolve to upstream dns from e.g. a management VRF?

unfortunately this is not allowed:
/ip dns set servers=1.1.1.2@management
by spippan
Tue Sep 17, 2024 9:39 pm
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 138496

Re: v7.16rc [testing] is released!

issued SUP-160816 on 2024-07-31 with not a single reaction had the same idea with a mgmt vrf where i needed DNS resolution ... went the "main VRF only it is then.." route This parameter means that DNS listens for queries from the clients in a specified VRF. As far as I understand you have...
by spippan
Tue Sep 17, 2024 9:38 pm
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 138496

Re: v7.16rc [testing] is released!

we discovered that netflows are not generated when they are about inter vlan l3hw accelerated traffic. observing this on CCR2216 where we had spike of traffic (l3hw) on a vlan on these was not reported on our netflow collector. SUP-165456 generated OT: (sorry) @rpingar what netflow solution do you ...
by spippan
Tue Sep 17, 2024 6:23 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

if connection is not on the default port but gets redirected internally to 8291 (def. port) with a NAT redirect i cannot login from the WAN side winbox v3 - no problem winbox v4 - no login possible (tried a static user and a 2FA user - v3 was OK but v4 error on both tries) service itself is running ...
by spippan
Tue Sep 17, 2024 6:07 pm
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 138496

Re: v7.16rc [testing] is released!

Is there any chance of Multicore Processing of Following in ROS v7.x:

1. MPLS + VPLS
2. PPPOE
3. VXLAN
+1 for VXLAN!

also waiting on MACsec in hw-offload
...and wishing on WireGuard to be available for hw-offload but that is a whole different story
by spippan
Tue Sep 17, 2024 6:05 pm
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 138496

Re: v7.16rc [testing] is released!

v7.16rc4 - DNS VRF does not work. When setting: /ip dns set vrf=mgmtvrf the system always sends DNS queries via the main vrf, regardless of this setting. issued SUP-160816 on 2024-07-31 with not a single reaction had the same idea with a mgmt vrf where i needed DNS resolution ... went the "mai...
by spippan
Tue Sep 17, 2024 5:49 pm
Forum: Beginner Basics
Topic: Playing with VRFs - what am I doing wrong?
Replies: 22
Views: 6509

Re: Playing with VRFs - what am I doing wrong?

But don't you already have these as "return routes"?: add disabled=no distance=1 dst-address=192.168.1.0/24 gateway=bridge routing-table=vrf_orange suppress-hw-offload=no add disabled=no distance=1 dst-address=192.168.1.0/24 gateway=bridge routing-table=vrf_starlink suppress-hw-offload=no...
by spippan
Mon Sep 16, 2024 1:47 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣


+1
I also noticed you can't just enter the IP and hit enter like in winbox3, now it's a bit more cumbersome to have to then first click start.
yes the ENTER key functionality has not arrived yet ... same with applying changes
by spippan
Mon Sep 16, 2024 1:23 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

yesterday on linux - today some thoughts on windows beta6 - windows which get dragged inside WBox4 lag behind mouse cursor (knwon bug but on windows VERY sluggish) - missing the "Find" text field to quickly highlight saved routers (patiently we wait :lol: ) - still i think that would be a ...
by spippan
Sun Sep 15, 2024 9:18 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

with beta6 it is getting up quite a notch! tabs+custom tabs+additional windows from same category -> excellent! WBox4 is getting more and more usable! good work mikrotik! few bits and bites which are on my mind immediately - indent for "child interfaces" (VLANs under the parent IF) or &quo...
by spippan
Fri Sep 13, 2024 1:55 am
Forum: Wireless Networking
Topic: One SSID multiple passwords, RADIUS, MAC auth
Replies: 5
Views: 4533

Re: One SSID multiple passwords, RADIUS, MAC auth

have you tried to set this in "MAC mode":
Screenshot from 2024-09-13 00-54-16.png
by spippan
Fri Sep 13, 2024 1:20 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

can we have the "enter" key back for applying and closing a window
e.g. change the name of an interface and just press enter instead of CLICKING on apply/ok ?
by spippan
Fri Sep 13, 2024 12:21 am
Forum: Wireless Networking
Topic: Missing wAP ax successor to wAP ac, what are outdoor AX WiFi alternatives?
Replies: 38
Views: 10666

Re: Missing wAP ax successor to wAP ac, what are outdoor AX WiFi alternatives?

wAP ax will be a very small device and is coming very very soon (question of days or weeks)
Is it nearly ready yet?? Don't we usually find stuff on the FCC websites in advance?
hm https://fccid.io/TV7
by spippan
Mon Sep 09, 2024 7:58 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

Need the group feature back badly. This is a show stopper for us as we sort clients that way.
+1
by spippan
Fri Sep 06, 2024 12:49 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

I'm not sure that any of you know what beta means when developing a GUI application. Please, report bugs that you find while using the app and/or if something doesnt make sense or if you find something to have more sense to be in a certain way. Its a beta for a reason, any missing features need to ...
by spippan
Fri Sep 06, 2024 12:40 am
Forum: Announcements
Topic: SwOS version 2.17 released!
Replies: 16
Views: 142924

Re: SwOS version 2.17 released!

a "no" then
by spippan
Fri Sep 06, 2024 12:40 am
Forum: General
Topic: /31 through a IPSec over GRE tunnel
Replies: 7
Views: 1154

Re: /31 through a IPSec over GRE tunnel

this is considered PtP addressing and works fine
Not everybody knows the name for it ... and certainly not everybody knows how to use it properly ... hence post by @TheCat12 (which is, unlike yours, useful)
now some more know though
by spippan
Wed Sep 04, 2024 5:07 am
Forum: Announcements
Topic: SwOS version 2.17 released!
Replies: 16
Views: 142924

Re: SwOS version 2.17 released!

css610 host mac addresses per vlan? anytime soon?
by spippan
Wed Sep 04, 2024 12:25 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

This looks lovely, and I'll check it out. Windows, MacOS, and Linux. However, one killer bit I'd love to see added to Winbox: public key auth. We have an ongoing war internally about killing off winbox because it means our techs are storing passwords in their laptops. Personally, I use SSH at least...
by spippan
Wed Sep 04, 2024 12:00 am
Forum: General
Topic: /31 through a IPSec over GRE tunnel
Replies: 7
Views: 1154

Re: /31 through a IPSec over GRE tunnel

There is a small hack to use /31 addresses - one address to be the local address and the remote one to be specified as the network. For example, site 1 - address=192.168.1.0 & network=192.168.1.1 , site 2 - address=192.168.1.1 & network=192.168.1.0 this is considered PtP addressing and work...
by spippan
Tue Sep 03, 2024 3:26 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

People are so gotten used to grey XP style interface, but are not used to the name? We call it winbox, because is easy to say and everyone knows what it is
why is this even a ef'ing thing? i do not get it

e.g. "rOSbox" would sound somewhat silly IMO
by spippan
Tue Sep 03, 2024 3:04 am
Forum: General
Topic: Which firmware is better, V6 or V7
Replies: 4
Views: 3071

Re: Which firmware is better, V6 or V7

first, v7 has a newer and more feature rich kernel

but as always - it depends.

e.g. i am running v7 and v6 in prod environments depending on the situation. dependent on where which device gets deployed. (60/5GHz PtP backup link for example runs v6 on to occasions)
by spippan
Tue Sep 03, 2024 3:01 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

did not see it being mentioned but: -> if you are in IP > Firewall > Filter Rules (or > NAT) and copy a rule and create it by clicking apply and/or OK the rule does not get positioned under the rule from which it has been copied from. instead it gets created on the end of the list -> how can there b...
by spippan
Mon Sep 02, 2024 11:01 pm
Forum: General
Topic: VRRP on Hyper-V instance ROS 7.15.3 not working (MAC Spoofing enabled)
Replies: 11
Views: 2338

Re: VRRP on Hyper-V instance ROS 7.15.3 not working (MAC Spoofing enabled)

is there maybe anything which disallows or filters 00-00-5E-00-01-.. mac addresses? vrrp interfaces use those No such things. I had no success at all until I googled for esxi that mac spoofing should be enabled and found where to fix that for hyper-v. Now it's this. Gonna give it a try on a sr-iov ...
by spippan
Mon Sep 02, 2024 10:42 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

We are certainly looking into better options for distributing on linux Please, PLEASE, not flatpak or Snap. Pretty please? 10/10 -> Make one tar.gz, static linked with whatever You used to build it. Everything is userland, everything is run from the /home/$USER. Just extract to <wherever>, and run/...
by spippan
Mon Sep 02, 2024 9:54 pm
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 138496

Re: v7.16rc [testing] is released!

TIL: there is
/ip/dns/cache/all/print
which shows you really all cache entries.

Unlike
/ip/dns/cache/print
thanks ... didn't know about that or at least never realized this was there
by spippan
Mon Sep 02, 2024 9:31 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

********** STATUS UPDATE *************** ********** STATUS UPDATE *************** Known issues to be addressed: ... ********** STATUS UPDATE *************** ********** STATUS UPDATE *************** if in the next 2 betas all those points are addressed ... boy, oh boy are we up to a good start for R...
by spippan
Mon Sep 02, 2024 9:02 pm
Forum: General
Topic: VRRP on Hyper-V instance ROS 7.15.3 not working (MAC Spoofing enabled)
Replies: 11
Views: 2338

Re: VRRP on Hyper-V instance ROS 7.15.3 not working (MAC Spoofing enabled)

is there maybe anything which disallows or filters 00-00-5E-00-01-.. mac addresses? vrrp interfaces use those
by spippan
Mon Sep 02, 2024 4:05 am
Forum: General
Topic: VRRP on Hyper-V instance ROS 7.15.3 not working (MAC Spoofing enabled)
Replies: 11
Views: 2338

Re: VRRP on Hyper-V instance ROS 7.15.3 not working (MAC Spoofing enabled)

you should run VRRPs inside each VLAN if you are working with group-authority on one VRRP (and there only can be one if there are multiple VRRPs) the vrrp group-authority only works correct on the lowest VLAN ID (found that one out last week after about 2h of "wiresharking" and eliminating...
by spippan
Mon Sep 02, 2024 2:22 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

I like how an extra folder containing a single image file needed to be packed for distribution :P
maybe there will be more assets in the future?
by spippan
Mon Sep 02, 2024 2:21 am
Forum: Wireless Networking
Topic: Wireless interference between devices in close vicinity
Replies: 17
Views: 5892

Re: Wireless interference between devices in close vicinity

what protocol settings are you using? is NV/NV2 deactivated so both APs only use 802.11?
if not, try to lock all wifi interfaces to only use 802.11
by spippan
Thu Aug 29, 2024 3:50 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

suggestion/idea to show currently opened windows -> "macOS expose"-like tiled overview of all opened windows
by spippan
Thu Aug 29, 2024 3:46 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2226
Views: 4724974

Re: 📣 WinBox 4 is here 📣

nice new look some first impressions and short-commings: EDIT : - how do we activate SAFE MODE O.O ?? - windows which get dragged inside WBox4 lag behind mouse cursor - missing the "Open In New Window" option - missing the "Find" text field to quickly highlight saved routers - mi...
by spippan
Wed Aug 28, 2024 3:53 am
Forum: General
Topic: when to use "pref-src"?
Replies: 4
Views: 11117

Re: when to use "pref-src"?

also useful on a VRRP setup to use the vIP address and not the vrrp member ip address for NAT to WAN for example.

EDIT because of typos
by spippan
Mon Aug 26, 2024 12:23 am
Forum: 3rd party tools
Topic: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management
Replies: 82
Views: 32549

Re: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management

could this also be self-hosted on premise?

EDIT: yes ... reading helps. it is a docker install essentially
by spippan
Sun Aug 25, 2024 9:38 pm
Forum: General
Topic: CA CRL OPENVPN
Replies: 8
Views: 1492

Re: CA CRL OPENVPN

OT: @Antho01010 did you come by other MT forum users yet? sindy is one of the members really taking time and care of explaining points - jump around this forum and look out for "the cat" and i wonder how you would react to some of that answers ... this forum has some helpful and really val...
by spippan
Thu Aug 22, 2024 3:15 pm
Forum: General
Topic: Feature requests
Replies: 1816
Views: 1108019

Re: Feature requests

3) Logs - Show the action taken on a firewall rule. The current format is esoteric and needs you to rely on giving meaningful log prefixes so that you know if it was dropped, accepted, whatever True. I don't mind that much that you need to put the action taken in a log prefix, but I do want to have...
by spippan
Thu Aug 22, 2024 1:39 am
Forum: General
Topic: Feature requests
Replies: 1816
Views: 1108019

Re: Feature requests


It would be a useful feature to be able to make a backup that is portable to a different replacement Mikrotik device.

that's what i meant
by spippan
Thu Aug 22, 2024 12:49 am
Forum: General
Topic: Feature requests
Replies: 1816
Views: 1108019

Re: Feature requests

3) Logs - Show the action taken on a firewall rule. The current format is esoteric and needs you to rely on giving meaningful log prefixes so that you know if it was dropped, accepted, whatever 4) I find that I can't really trust exports & backups. Just today I noticed user accounts missing whi...
by spippan
Thu Aug 22, 2024 12:42 am
Forum: Wireless Networking
Topic: VLAN Trunk over WiFi for SOHO networks - use EoIP or else?
Replies: 7
Views: 4736

Re: VLAN Trunk over WiFi for SOHO networks - use EoIP or else?

it is a bit of a "misuse" for VxLAN but you create a VXLAN, a VTEP between the 2 APs and add the vxlan to the bridge and configure the vlans tagged on that vxlan bridge port
i do not have a finished setup running anymore but maybe i can stitch something together in eve-ng the other day
by spippan
Tue Aug 20, 2024 6:21 pm
Forum: Wireless Networking
Topic: Missing wAP ax successor to wAP ac, what are outdoor AX WiFi alternatives?
Replies: 38
Views: 10666

Re: Missing wAP ax successor to wAP ac, what are outdoor AX WiFi alternatives?

wAP ax will be a very small device and is coming very very soon (question of days or weeks)
well that would then finally be the end for my hAP ac² devices and the migration to CAPsMAN! :)
by spippan
Tue Aug 20, 2024 5:32 pm
Forum: General
Topic: MikroTik CHR P1 Licence
Replies: 2
Views: 731

Re: MikroTik CHR P1 Licence

normally the cpu core count does not affect your P1 license
as long as the License Software ID does not change (which only occurs if you setup chr on another VM or forcefully refresh/regenerate the SOFTWARE ID on a CHR installation)
by spippan
Tue Aug 20, 2024 5:01 pm
Forum: General
Topic: Feature requests
Replies: 1816
Views: 1108019

Re: Feature requests

On the Products page ....


what also would be a convenience on the "Specifications" Page -> Link the Row "License Level" direktly to the License Levels Help Pages
by spippan
Fri Aug 16, 2024 12:54 pm
Forum: Useful user articles
Topic: WinBox for MacOS ??
Replies: 51
Views: 29914

Re: WinBox for MacOS ??

WinBox can be run on M3 via CrossOver (24.04 - latest for today), but after some time, it just stop to react to any clicks. You have to close it, or even CrossOver, and start again, which is very inconvenient. Maybe some special CrossOver setting? But in general, it is better than nothing. does thi...
by spippan
Wed Aug 07, 2024 6:42 pm
Forum: General
Topic: Is there a way to install RouterOS on a ARMv8-A non-mikrotik hardware?
Replies: 6
Views: 1559

Re: Is there a way to install RouterOS on a ARMv8-A non-mikrotik hardware?

RouterOS can be installed on AMPERE(TM) ARM systems (bare metal), and on ARM powered cloud services via CHR image.
is there a list of AMPERE devices which are ensured/trusted to work with ROS?
by spippan
Mon Aug 05, 2024 11:51 pm
Forum: General
Topic: Is there a way to install RouterOS on a ARMv8-A non-mikrotik hardware?
Replies: 6
Views: 1559

Re: Is there a way to install RouterOS on a ARMv8-A non-mikrotik hardware?

maybe some luck with ampera hardware ... would not count on that for "home/soho" use (in that case, every routerboard turns out cheaper/more price efficient)
by spippan
Mon Aug 05, 2024 11:36 pm
Forum: General
Topic: Net Flow Collector NAT
Replies: 6
Views: 1945

Re: Net Flow Collector NAT

oh ok

still searching for a reliable and easy to implement (best case, free/open source) NetFlow solution with graphing an analizing
by spippan
Mon Aug 05, 2024 5:51 pm
Forum: Beginner Basics
Topic: tagged and untagged in one vlan table
Replies: 10
Views: 1381

Re: tagged and untagged in one vlan table

ROS cannot handle a port with a tagged VLAN and also untagged in that same VLAN e.g.: eth1 is untagged 10 and also tagged VLAN 10 on that bridge: 05-08-2024.png EDIT: (second part got lost on first post; sorry) but you can set the PVID (untagged traffic) in the port menu itself for that port in the ...
by spippan
Mon Aug 05, 2024 1:25 pm
Forum: The User Manager
Topic: Separate set of users depending on called-station-id?
Replies: 1
Views: 9435

Re: Separate set of users depending on called-station-id?

i also tried something like that but until now, no look

i posted my request here -> viewtopic.php?p=1089523#p1089523
by spippan
Mon Aug 05, 2024 1:24 pm
Forum: The User Manager
Topic: User Manager Feature request - sticky please?
Replies: 194
Views: 82248

Re: User Manager Feature request - sticky please?

It will be good to add optional feature: if User Manager can chech Calling-statuin-id attribute beffore allow user to log-in. It can be interested when dial-up users are allowed to log-in only from specific phone numbers and for ADSL ( all adsl from Huawei have specific firmware and default user gu...
by spippan
Wed Jul 31, 2024 11:09 am
Forum: General
Topic: VRF-support for DNS is broken?
Replies: 21
Views: 13535

Re: VRF-support for DNS is broken?

exact same problem here on 2 CCR2004-16G-2S+ on latest stable ROSv7.15.3 as soon as DNS is put in a VRF other than "main" resolving gets broken and stops to work, despite VRF routing table is set properly and a "ping vrf=vrfXYZ IP.of.DNS.Srv" is working and shows reachability cre...
by spippan
Wed Jul 31, 2024 12:40 am
Forum: Beginner Basics
Topic: Need help
Replies: 2
Views: 805

Re: Need help

might get some basics like knowledge on routing, firewalling, what-not and concerns on infrastructure to serve customers first i suggest
by spippan
Wed Jul 31, 2024 12:28 am
Forum: General
Topic: Net Flow Collector NAT
Replies: 6
Views: 1945

Re: Net Flow Collector NAT

We ended up using Graylog and the IPFIX endpoint. Only tracking NAT translations for CALEA requirements.
is graylog a tool to graph and report netflow data? interessted in that TBH
by spippan
Fri Jul 26, 2024 4:04 pm
Forum: General
Topic: Bridging a WAN Interface Used for BGP [SOLVED]
Replies: 8
Views: 7178

Re: Bridging a WAN Interface Used for BGP [SOLVED]

you could insert a switch in between to use another device with another public ip from your carrier until you get your bridge setup figured out correctly. IF that is an option you could do. but be aware - if there is a managed switch, the uplink port (to your carrier) and the WAN port(s) of your CCR...
by spippan
Wed Jul 24, 2024 3:44 pm
Forum: General
Topic: One dock with two computers & two VLANs
Replies: 4
Views: 688

Re: One dock with two computers & two VLANs

If I get this right, this particular kind of dock is connected via thunderbolt and has an internal NIC (with its own MAC address). So the router (or any other device on the network connected to it) has no way to see which computer is connected via thunderbolt, it will always see the MAC of the dock...
by spippan
Wed Jul 24, 2024 1:00 am
Forum: General
Topic: One dock with two computers & two VLANs
Replies: 4
Views: 688

Re: One dock with two computers & two VLANs

also a good read maybe https://administrator.de/en/nps-802-1x-radius-authentication-with-eap-tls-and-strong-certificate-mapping-for-non-domain-joined-devices-9670013529.html https://forum.mikrotik.com/viewtopic.php?t=174977 https://help.mikrotik.com/docs/display/ROS/Dot1X https://wiki.mikrotik.com/w...
by spippan
Wed Jul 24, 2024 12:58 am
Forum: General
Topic: One dock with two computers & two VLANs
Replies: 4
Views: 688

Re: One dock with two computers & two VLANs

you would need something like user-manager (mikrotik's implementation of RADIUS server) and some kind of (basic) dot1x setup to evaluate (and authenticate) the device/user connecting to the network you could try to do basic mac-authentication and then set the PVID of that port to your desired VLAN a...
by spippan
Tue Jul 23, 2024 1:58 pm
Forum: General
Topic: [FEATURE REQUEST] Two Factor Authentication
Replies: 53
Views: 42237

Re: [FEATURE REQUEST] Two Factor Authentication

Does anyone have a solution to make the static-challenge setting work with OpenVPN? Or something that asks for the password and the OTP in 2 text fields? +1 would also need that kind of setup for a client EDIT: can be done quite easy with mikrotik user-manager (additional package) as local radius s...
by spippan
Tue Jul 23, 2024 1:56 pm
Forum: General
Topic: what options for 2 factor authentication for VPN access [SOLVED]
Replies: 21
Views: 22764

Re: what options for 2 factor authentication for VPN access [SOLVED]

I confirm, usermanager works with Google Authenticator. tested and working perfectly.
https://foisfabio.it/index.php/2024/04/ ... ik-otp-vpn
confirming this also.
tested it also as "login" provider - so AAA users for device login (e.g. a network admin) working without issues
by spippan
Mon Jul 22, 2024 4:16 pm
Forum: General
Topic: Allow access to wildcard URL [SOLVED]
Replies: 6
Views: 6426

Re: Allow access to wildcard URL [SOLVED]

i'm curious, could you post a sanitized version of your DNS configuration please?
might have some cases where i'd like to implement something similar
by spippan
Mon Jul 22, 2024 4:14 pm
Forum: General
Topic: Allow access to wildcard URL [SOLVED]
Replies: 6
Views: 6426

Re: Allow access to wildcard URL [SOLVED]

That is soooo cool... So just to make it more clear for the next person asking :P You have to use your Mikrotik router as the DNS-server for your clients, otherwise this won't work. I have set my DHCP to provide all my clients with the router IP-address as DNS server. I have also set my domain serv...
by spippan
Mon Jul 22, 2024 1:52 pm
Forum: General
Topic: Feature Request - Custom options for DHCPv6 client requests
Replies: 1
Views: 1292

Re: Feature Request - Custom options for DHCPv6 client requests

Please add the possibility to add custom options to the client request. This is required for ISPs which tend to force you to use a specific router. My ISP requires specific options for my voip IP connection to be establisched which I can accomodate with the DHCP client custom options in ipv6. Recen...
by spippan
Mon Jul 22, 2024 1:07 pm
Forum: General
Topic: most "cold" RJ45 SFP+ modules
Replies: 5
Views: 1373

Re: most "cold" RJ45 SFP+ modules

fs.com have a few rj45 sfp+ modules. They range in power consumption from 1.8W to 2.9W Apparently the S+RJ10s is around 2.7W, so the 1.8W one might be good. (but quite pricey) Sorry I don't know how well or hot it works, or if it will work with a Mikrotik. though fs is usually well supported FS.com...
by spippan
Mon Jul 22, 2024 12:36 pm
Forum: Wireless Networking
Topic: Multi AP Home Setup Examples with CAPsMAN v2
Replies: 9
Views: 3589

Re: Multi AP Home Setup Examples with CAPsMAN v2

would like to achieve the same with 2 APs (hap ac2) and capsman v2 on a RB1100x4AH with the only addition of 3 SSIDs (where each SSID belongs to a different VLAN)
hopefully i gain some advice here by a basic setup solved
by spippan
Sun Jul 21, 2024 1:43 pm
Forum: General
Topic: Why do I see google attempting to connect to my router on the input chain?
Replies: 6
Views: 861

Re: Why do I see google attempting to connect to my router on the input chain?

but that would be on a FWD chain, wouldn't it? Not really - such a packet comes to the WAN IP of the router, and since it does not match the original connection as the latter has timed out in the meantime, it does not get "un-src-nated" in prerouting, so its destination address remains th...
by spippan
Fri Jul 19, 2024 4:35 pm
Forum: General
Topic: Why do I see google attempting to connect to my router on the input chain?
Replies: 6
Views: 861

Re: Why do I see google attempting to connect to my router on the input chain?

Or those packets are actually coming from Google but they may be perfectly legitimate, like late responses to e.g. DNS requests that came after the pinhole created by a request from your internal network has timed out. QUIC also uses UDP as transport so even a late QUIC response may cause the same ...
by spippan
Wed Jul 17, 2024 6:29 pm
Forum: General
Topic: Which VPN to connect 2 MikroTiks overe WAN?
Replies: 15
Views: 1727

Re: Which VPN to connect 2 MikroTiks overe WAN?

I spent some time testing 3 alternatives, - EoIP, MTU 1500, interface added to the Bridge, not sure if interface should be considered edge=no / point-to-point=yes but the interface became "root port", for me was the slowest solution. - GRE, MTU 1418, speedtest is around 50Mbps Down / 60Mb...
by spippan
Tue Jul 16, 2024 7:57 pm
Forum: Beginner Basics
Topic: Port forwarding with hairpin NAT and dynamic IP combo
Replies: 12
Views: 1924

Re: Port forwarding with hairpin NAT and dynamic IP combo

The best is use seriously IPv6: no needed any form of NAT.
but OP asked for help with port forwarding with hairpin NAT and dynamic IP combo 🤷‍♂️
by spippan
Tue Jul 16, 2024 4:03 pm
Forum: MikroTik hardware questions
Topic: CCR1009 replacement for BGP
Replies: 13
Views: 7094

Re: CCR1009 replacement for BGP

replaced 4 cisco 3925/k9 with CCR2004-1G-12S+2XS
working flawless with iBGP and eBGP running as it was on the 3925 units
with way less power consumption

i presume CCR2004 would be a valid option to replace CCR1009 in your case
by spippan
Tue Jul 16, 2024 12:32 am
Forum: General
Topic: Which VPN to connect 2 MikroTiks overe WAN?
Replies: 15
Views: 1727

Re: Which VPN to connect 2 MikroTiks overe WAN?

and in case you are using EoIP be VERY careful adding it to a bridge with active (R)STP - could mess up things really fast
by spippan
Mon Jul 15, 2024 11:47 pm
Forum: General
Topic: Compatibility error? CCR2216-1G-12XS-2XQ with Ubiquiti Modules
Replies: 11
Views: 4910

Re: Compatibility error? CCR2216-1G-12XS-2XQ with Ubiquiti Modules

tried disabling auto-negotiation and fixed it to 1G/FDX ?
fixed it 90% of the time i had UBNT SFPs in my 2004s and 2116s (never got auto-neg. working below 10G with mixed/non-MT SFP modules on SFP+ and SFP28 ports)

EDIT:
do you have a screenshot of winbox showing SFP tab details of the port?
by spippan
Mon Jul 15, 2024 1:55 pm
Forum: General
Topic: MLAG hopelessly broken?
Replies: 58
Views: 25352

Re: MLAG hopelessly broken?

if you need reliable MLAG hardware go for cisco, extreme or if you need to be on budget ... fs.com speaking of fs... MLAG featuring switches: N5860-48SC (mlag or stack) S5860-48SC (stack) S5850-48S6Q (mlag) routing ... mikrotik switching ... cisco, fs, aruba, extreme Even if the same name FSOS , di...
by spippan
Fri Jul 12, 2024 12:55 pm
Forum: General
Topic: Any plans to bring back UI for routing filters in v7?
Replies: 5
Views: 1115

Re: Any plans to bring back UI for routing filters in v7?

Setting up rules through GUI is less efficient and troublesome where copying a single (or multiple) row(s) and do the changes textual is way faster. What is really inefficient is smashing your head against a wall due to typo's or not fully understanding the syntax The GUI shows you every potential ...
by spippan
Wed Jun 26, 2024 2:49 pm
Forum: Beginner Basics
Topic: Why so hard to give friendly name to a client?
Replies: 48
Views: 18489

Re: Why so hard to give friendly name to a client?

maybe the arp list might be of help
if you set a comment to a dhcp-server lease it shows up here in "host name"

arplist_26-06-2024.png
by spippan
Wed Jun 26, 2024 11:59 am
Forum: Forwarding Protocols
Topic: ECMP not working
Replies: 8
Views: 6621

Re: ECMP not working

so is ECMP working in v7 yet or not?