Community discussions

MikroTik App

Search found 41 matches

by bedior
Sat Jan 04, 2020 3:51 pm
Forum: General
Topic: IPsec-SA expired before finishing rekey
Replies: 0
Views: 1621

IPsec-SA expired before finishing rekey

Hello. I have a Mikrotik connected to StrongSwan by IKE2. But every 30 minutes in log wrote error: "IPsec-SA expired before finishing rekey". Config StrongSwan: config setup charondebug="ike 1, knl 1, cfg 0" uniqueids=no conn ikev2-vpn auto=add compress=no type=tunnel keyexchange...
by bedior
Sat Dec 21, 2019 5:20 pm
Forum: General
Topic: A lot of TCP Retransmission and TCP Dup ACK
Replies: 4
Views: 4571

A lot of TCP Retransmission and TCP Dup ACK

Hello!
Today check Packet Sniffer in RB750Gr3, and found very big quantity of TCP Retransmission and TCP Dup ACK:
lBWtAEKREm.png
How to deal with this?
by bedior
Thu Nov 14, 2019 6:27 am
Forum: General
Topic: Winbox disconnecting CHR
Replies: 2
Views: 1133

Re: Winbox disconnecting CHR

I have installed it on virtual server KVM (https://iphoster.net/tarifs?vid=vds). Export: # nov/14/2019 05:18:44 by RouterOS 6.45.7 # software id = # # # /interface ethernet set [ find default-name=ether1 ] disable-running-check=no /interface wireless security-profiles set [ find default=yes ] suppli...
by bedior
Wed Nov 13, 2019 12:40 pm
Forum: General
Topic: Winbox disconnecting CHR
Replies: 2
Views: 1133

Winbox disconnecting CHR

Hello.
I have install CHR on VDS, with trial license. A few days all work fine, but suddenly Winbox became disconnecting after 0 - 30 seconds after connect. Message: Router IP has been disconnected. How to find problem?
by bedior
Sun Feb 03, 2019 9:45 am
Forum: General
Topic: L2TP - old tunnel is not closed
Replies: 5
Views: 11708

Re: L2TP - old tunnel is not closed

No. :(
by bedior
Mon Oct 29, 2018 7:21 am
Forum: General
Topic: L2TP - old tunnel is not closed
Replies: 5
Views: 11708

L2TP - old tunnel is not closed

Hello! I am working on failover script and found, that after change route distance of my ISP and disable/enable lt2p connection, my l2tp connect much longer. In log I found rows: cvRPhBc9mp.png But, when I disable/enable lt2p connection without change routes, it connect much faster: wVQY3miIBN.png W...
by bedior
Mon Mar 19, 2018 10:52 am
Forum: Scripting
Topic: Run script after DNS resolving
Replies: 4
Views: 1838

Re: Run script after DNS resolving

I understand. But I don't need to execute script for every DNS query. It's enough to run script when resolved IP stored in cache. In average it has on my router 500 entries.
by bedior
Mon Mar 19, 2018 9:49 am
Forum: Scripting
Topic: Run script after DNS resolving
Replies: 4
Views: 1838

Re: Run script after DNS resolving

There are no DNS resolve high load. I mean that my script do high load because need very often check new DNS resolutions. I want add some domains and they subdomains to address list, so I read list of watching domain from file, than find them in DNS cache, and add to address list. If schedule it eve...
by bedior
Mon Mar 19, 2018 8:15 am
Forum: Scripting
Topic: Run script after DNS resolving
Replies: 4
Views: 1838

Run script after DNS resolving

Hello!
Is any possible to run script after DNS server resolve or update DNS cache? Run script every second and check DNS cache is CPU load expensive. Maybe is possibility to run script by Firewall event?
by bedior
Wed Apr 05, 2017 11:07 am
Forum: Wireless Networking
Topic: Mikrotik wi-fi and Iphone = problem
Replies: 104
Views: 124656

Re: Mikrotik wi-fi and Iphone = problem

колбаскин
I think this issue located more deeply, not in settings. Support will not help you, bro. They will be ask you many parameters, all data, maybe even access to device, than connect to it for 2 minutes, and say, that it's ok, try to change iPhone, reinstall Viber...
by bedior
Fri Jan 13, 2017 6:08 pm
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 148
Views: 45601

Re: Feature Request: IPSEC Improvements

About site-to-site
by bedior
Fri Jan 13, 2017 6:02 pm
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 148
Views: 45601

Re: Feature Request: IPSEC Improvements

How configure it as client?
by bedior
Fri Jan 13, 2017 4:57 pm
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 148
Views: 45601

Re: Feature Request: IPSEC Improvements

Is ability to configure IKEv2 tunnel as client to Strongswan in RouterOS 6.38?
by bedior
Fri Jan 13, 2017 9:54 am
Forum: General
Topic: IKEv2 in RouterOS 6.38
Replies: 0
Views: 872

IKEv2 in RouterOS 6.38

Hello.
Is ability to configure IKEv2 tunnel as client to Strongswan in RouterOS 6.38?
by bedior
Fri Jan 06, 2017 9:17 am
Forum: RouterBOARD hardware
Topic: RB3011UiAS-RM and IPsec
Replies: 0
Views: 1376

RB3011UiAS-RM and IPsec

Hello. I want to replace my slow RB2011UiAS-2HnD-IN with RB3011UiAS-RM. I need to improve VPN (L2TP/IPsec with AES-256). My current give 16 mbit/s DL and 19 mbit/s UL. What speed I can get on RB3011UiAS-RM? It support Hardware Acceleration or not? I want to buy separate Wi-Fi access point. What you ...
by bedior
Thu Nov 24, 2016 9:03 am
Forum: RouterBOARD hardware
Topic: RB2011UiAS-2HnD-IN w/ IPSec?
Replies: 6
Views: 3302

Re: RB2011UiAS-2HnD-IN w/ IPSec?

@bedior did you try using AES128, whats the speed then? If I assume correctly AES256 was faster with an older firmware?
I have tried AES128, but there are very little difference. So I forced to use old firmware.
by bedior
Mon Nov 21, 2016 10:43 am
Forum: RouterBOARD hardware
Topic: RB2011UiAS-2HnD-IN w/ IPSec?
Replies: 6
Views: 3302

Re: RB2011UiAS-2HnD-IN w/ IPSec?

Thanks alot for the swift reply! 24Mbit is sufficient for my needs. So I can use this board as a router/ipsec router providing VLANs and and wifi?
Oh, it's very optimistically... Please, read: http://forum.mikrotik.com/viewtopic.php?t=110714
by bedior
Fri Oct 28, 2016 10:19 am
Forum: RouterBOARD hardware
Topic: When will be RB3011UiAS-2HnD-IN available?
Replies: 65
Views: 26657

Re: When will be RB3011UiAS-2HnD-IN available?


Not until RouterOS v7

So not until next year at the earliest
It mean "Yes, but software not support yet"? Or will be new hardware revision?
by bedior
Fri Oct 28, 2016 9:43 am
Forum: RouterBOARD hardware
Topic: RB750Gr3 - Report and questions
Replies: 113
Views: 53065

Re: RB750Gr3 - Report and questions

Thank you. Not so fast as needed. :(
by bedior
Fri Oct 28, 2016 7:32 am
Forum: RouterBOARD hardware
Topic: When will be RB3011UiAS-2HnD-IN available?
Replies: 65
Views: 26657

Re: When will be RB3011UiAS-2HnD-IN available?

It will support hardware acceleration?
by bedior
Wed Oct 26, 2016 10:14 am
Forum: RouterBOARD hardware
Topic: RB750Gr3 - Report and questions
Replies: 113
Views: 53065

Re: RB750Gr3 - Report and questions

BlackVS, test, please, LT2P/IPsec with AES-256. About your stranges with CPU, I think this is global firmware bug, I found it at all firmwares after 6.34.4: http://forum.mikrotik.com/viewtopic.php?t=110714. Support say, that all is ok, buy more powerful router. As we see, most very powerful routers ...
by bedior
Mon Oct 24, 2016 11:52 am
Forum: RouterBOARD hardware
Topic: RB750Gr3 - Report and questions
Replies: 113
Views: 53065

Re: RB750Gr3 - Report and questions

I more interesting with Softether, how it work with this server, not strongswan.
by bedior
Mon Oct 24, 2016 10:42 am
Forum: RouterBOARD hardware
Topic: RB 850Gx2 vs RB750Gr3 performance
Replies: 10
Views: 10580

Re: RB 850Gx2 vs RB750Gr3 performance

CPU power does not figure, because Mikrotik has not optimized firmware, and don't want accept problems and fix its. See my topic as sample of speed degradation on same device: http://forum.mikrotik.com/viewtopic.php?t=110714
by bedior
Sun Oct 23, 2016 2:17 pm
Forum: RouterBOARD hardware
Topic: RB750Gr3 - Report and questions
Replies: 113
Views: 53065

Re: RB750Gr3 - Report and questions

Can you test with Softether VPN on L2TP/IPsec AES-256?
by bedior
Fri Oct 21, 2016 6:01 pm
Forum: RouterBOARD hardware
Topic: RB750Gr3 - Report and questions
Replies: 113
Views: 53065

Re: RB750Gr3 - Report and questions

Please, test it on Softether (l2tp/ipsec) with AES-256. It seems ipsec became very bugged after 6.34.4: http://forum.mikrotik.com/viewtopic.php?t=11071, so 400 mb/s is very sintetic, imho.
by bedior
Wed Oct 19, 2016 10:59 am
Forum: RouterBOARD hardware
Topic: New CPU - new product RB750Gr3 - RB750G family - now mmips
Replies: 180
Views: 98421

Re: New CPU - new product RB750Gr3 - RB750G family - now mmips

Hej Dual-Core 880 MHz, MIPS1004Kc etc.. similar specification as Ubu EdgeRouter . Hmmm...Interesting. The difference is that EdgeRouter X has 256 MB NAND. EdgeOS might need 256 MB of storage space to fit all applications. :) In your opinion, what better to buy, RB750Gr3 or EdgeRouter X/EdgeRouter L...
by bedior
Tue Oct 18, 2016 7:00 pm
Forum: RouterBOARD hardware
Topic: What hardware select for VPN
Replies: 26
Views: 8615

Re: What hardware select for VPN

So, anybody buy RB750Gr3? Have you tried IPsec?
by bedior
Tue Oct 18, 2016 3:38 pm
Forum: RouterBOARD hardware
Topic: What hardware select for VPN
Replies: 26
Views: 8615

Re: What hardware select for VPN

Let's discuss routers, not nations. A lot of people have troubles with Mikrotik hardware, some things works bad, and I, and maybe колбаскин, wants that our devices works as described. Mikrotik must be interested with this too.
by bedior
Mon Oct 17, 2016 5:42 pm
Forum: RouterBOARD hardware
Topic: What hardware select for VPN
Replies: 26
Views: 8615

Re: What hardware select for VPN

It is quite regular for routers that on firmware updates that add more features, the top speed decreases because CPU overhead for the new features has increased. This happens in all routers, probably not for every upgrade. Of course, if new features is used. But why speed decrease, when new feature...
by bedior
Mon Oct 17, 2016 4:37 pm
Forum: RouterBOARD hardware
Topic: What hardware select for VPN
Replies: 26
Views: 8615

Re: What hardware select for VPN

Maybe speed degradation after firmware updates, is Windows or ISP problem too? :)))
by bedior
Sun Oct 16, 2016 2:52 pm
Forum: RouterBOARD hardware
Topic: What hardware select for VPN
Replies: 26
Views: 8615

Re: What hardware select for VPN

RB750Gr3 is more powerful than RB850Gx2 and EdgeRouter Lite? If i found correctly, RB750Gr3 is equal EdgeRouter X? Which will be faster?
by bedior
Sun Oct 16, 2016 9:09 am
Forum: RouterBOARD hardware
Topic: What hardware select for VPN
Replies: 26
Views: 8615

What hardware select for VPN

Hello. Currently I'am using VPN as client on Mikrotik RB2011UiAS-2HnD-IN, it's giving me speed 23 mbit/s downloading and 20 mbit/s uploading on old firmware, new firmware give 16/20. My WAN give 30/100. If i connect to VPN by Windows client, it give 30/80 mbit. I think to replace it with EdgeRouter ...
by bedior
Tue Aug 02, 2016 6:30 pm
Forum: General
Topic: Decreasing inbound speed on L2TP/IPsec
Replies: 11
Views: 4558

Re: Decreasing inbound speed on L2TP/IPsec

I checked older versions and found, that last working version was 6.34.4. Video:
6.34.4: https://www.youtube.com/watch?v=-NlQYavQ78Y
6.35: https://www.youtube.com/watch?v=J0WTUJFkRJ0
by bedior
Sun Jul 31, 2016 11:04 am
Forum: General
Topic: Decreasing inbound speed on L2TP/IPsec
Replies: 11
Views: 4558

Re: Decreasing inbound speed on L2TP/IPsec

I make video demonstration:
In my logic if decryption need less CPU power, it must pass more data. :)
About FastTrack - where I can tune it?
by bedior
Sun Jul 31, 2016 10:45 am
Forum: General
Topic: Decreasing inbound speed on L2TP/IPsec
Replies: 11
Views: 4558

Re: Decreasing inbound speed on L2TP/IPsec

Thank you. But why an old version of firmware it work with AES-256 on 24 mbps, but on current 14 mbps? Why downloading doesn't load fully CPU, when uploading do that? If CPU weak why uploading with AES-256 give 20 mbps?
by bedior
Sun Jul 31, 2016 8:42 am
Forum: General
Topic: Decreasing inbound speed on L2TP/IPsec
Replies: 11
Views: 4558

Re: Decreasing inbound speed on L2TP/IPsec

I have 1 client (on router), VPN server is VDS with Softether. Devices in local network 3, but if all devices except one is powered off, than nothing change.
by bedior
Sun Jul 31, 2016 6:03 am
Forum: General
Topic: Decreasing inbound speed on L2TP/IPsec
Replies: 11
Views: 4558

Re: Decreasing inbound speed on L2TP/IPsec

Downloading:
8k3POSM1qX.png
Uploading:
rv3jgA8Jod.png
by bedior
Sat Jul 30, 2016 6:48 pm
Forum: General
Topic: Decreasing inbound speed on L2TP/IPsec
Replies: 11
Views: 4558

Decreasing inbound speed on L2TP/IPsec

Hello. After update RB2011UiAS-2HnD-IN on 6.35.2 or 6.36 inbound speed became slower at L2TP/IPsec (AES256 + SHA1): http://www.speedtest.net/result/5349439075.png  (CPU 60% when downloading) On version 6.32.2: http://www.speedtest.net/result/5349455563.png  (CPU 100% when downloading) Any ideas why ...
by bedior
Wed Jun 08, 2016 8:46 am
Forum: Announcements
Topic: v6.35.2 [current] is released!
Replies: 64
Views: 36507

Re: v6.35.2 [current] is released!

What about LT2P speed? This is connected with Fasttrack?
by bedior
Sat May 28, 2016 7:41 pm
Forum: Announcements
Topic: v6.35.2 [current] is released!
Replies: 64
Views: 36507

Re: v6.35.2 [current] is released!

RB2011UiAS-2HnD-IN on 6.35.2 give slower L2TP/IPsec (AES256 + SHA1):
http://www.speedtest.net/result/5349439075.png (CPU 60% on download)
On version 6.32.2:
http://www.speedtest.net/result/5349455563.png (CPU 100% on download)

Why?
by bedior
Sat Jan 31, 2015 5:21 pm
Forum: General
Topic: Throw p2p traffic to another interface
Replies: 0
Views: 621

Throw p2p traffic to another interface

Hello. I have a pppoe connection to my ISP and LT2P/IPsec connection to my VPN server. I have a mangle that mark all my traffic as L2TP and a route, that transfer it to lt2p interface. I want use torrents over my ISP not over VPN, I have disabled uTP and encryption in uTorrent and in mangle set &quo...