Community discussions

MikroTik App

Search found 12850 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 43
by pe1chl
Sat Mar 22, 2025 11:36 am
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 88
Views: 83504

Re: Newsletter #122 | December 2024

Well, it is the budget model for home and (very) small office.
When you have other needs there are other models, even the CSS326 is only $20 more.
by pe1chl
Fri Mar 21, 2025 10:48 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

It is a more or less obscure feature, but when you have a use-case and your client supports it, it is very useful. Like so many features, probably a user has suggested it, and it was either quite trivial to implement it or the user had a good sales case. That does not mean it is useful to YOU. (or m...
by pe1chl
Fri Mar 21, 2025 6:26 pm
Forum: General
Topic: PHPbb Prosilver has problem
Replies: 16
Views: 1020

Re: PHPbb Prosilver has problem

Considering how old Mikrotik is, why dont they have a usenet server? With usenet, you do not need a server. You need a newsgroup or set of newsgroups. Others provide the servers. It would have been easy to create a number of alt.mikrotik.subgroup groups similar to what we have on the forum. With mo...
by pe1chl
Fri Mar 21, 2025 10:49 am
Forum: General
Topic: PHPbb Prosilver has problem
Replies: 16
Views: 1020

Re: PHPbb Prosilver has problem

It seems that the forum is under some form of attack... The past few days I regularly got the message that the forum is currently offline, try again in a couple of minutes. As a Prosilver user I tried going to the profile page and selecting the other theme (forgot the name) and it shows a usable lay...
by pe1chl
Fri Mar 21, 2025 10:43 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

I've been checking on the windows 11 client and it doesn't seem to support this option. is there any information on how to reconfigure my devices to support this option? or is there a possible workaround, such as sending a message even if the client does not support the option? Why would you want t...
by pe1chl
Thu Mar 20, 2025 3:38 pm
Forum: General
Topic: IPsec parameter negotiation (and ancient defaults)
Replies: 14
Views: 3465

Re: IPsec parameter negotiation (and ancient defaults)

I tried again today on Windows 11 and now I found (and remembered) what was the problem: When you configure IKEv2 with username/password in Windows VPN the identity of the connecting router is not set to the username, but to the address of the system. Thus it is not possible to match the identity wh...
by pe1chl
Thu Mar 20, 2025 11:46 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

There is a 512Mbit Flash chip from ST on the upper side of the 1100AH board, and RouterBOOT says its 64MB. I went as far back as ROS 6.20 with RouterBOOT 3.18 -- always shows 64MB. Looks like some models shipped with 64MB. No worries - it served long. Greetings - azg As written above, it could be f...
by pe1chl
Wed Mar 19, 2025 7:49 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

Netinstall will for sure allow you to install the current (beta)version, but the question is whether you can upgrade after that... I had the same issue on a CCR1009 with 2 partitions (64MB each), it cannot upgrade anymore in that configuration. One would wish that it is possible to upgrade via a RAM...
by pe1chl
Wed Mar 19, 2025 12:11 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.2 [stable] is released!

When you have gone through so many updates, it is better to do a netinstall of 7.18.2.
Do a "/export show-sensitive file=myconfig" first and download the file, you can later import it to restore the config.
(although there usually are some unexpected hickups doing that)
by pe1chl
Tue Mar 18, 2025 8:56 pm
Forum: General
Topic: renew ssl certificate let's encrypt
Replies: 15
Views: 1005

Re: renew ssl certificate let's encrypt

do you have a list of domains or ip used for renewal? it doesn't seem very professional to expose the port to everyone unless there is a service exposed on it. There is no published list of IP addresses used for renewal. There is some document that says they don't publish it to reduce the risk of m...
by pe1chl
Tue Mar 18, 2025 8:50 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.2 [stable] is released!

I have upgraded a PPC 1100AHx2 router to 7.18.2 from 7.13 and the login page is messed up. Any ideas?
Look on page 1 of this topic!
by pe1chl
Tue Mar 18, 2025 1:44 pm
Forum: RouterOS beta
Topic: Feature Request: GREtap
Replies: 24
Views: 16424

Re: Feature Request: GREtap

Read the above.
Posting here is useless, submit a support ticket or mail to sales@mikrotik.com
by pe1chl
Mon Mar 17, 2025 7:31 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

Well, as you know this problem goes through a cycle. It has happened before that people could no longer upgrade certain devices, and they spent development effort to solve that for that moment. But of course the problem comes back, we all predicted that. Because the effort that was made yielded some...
by pe1chl
Mon Mar 17, 2025 7:26 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.2 [stable] is released!

hAP ac2 without wireless or wifi-qcom-ac is not a reasonably expected use of that device.
Normally you would buy a hEX for that use-case.
by pe1chl
Fri Mar 14, 2025 6:36 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.2 [stable] is released!

Well, there may be an issue with 7.18.2 after all... I netinstalled a wAP ac (old MIPBE version), I could connect it via MAC-TELNET, setup a password for admin (8 ASCII alphanumeric characters), could still login, then I added the wireless package (netinstall was only base package) and did a reset-c...
by pe1chl
Fri Mar 14, 2025 6:31 pm
Forum: MikroTik hardware questions
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 84
Views: 38146

Re: Running out of space on hAP ac2 [SOLVED]

That means you are quite close to problems. Others may already run into problems, e.g. when they have a longer upgrade history, more complicated configuration, history of changes in configuration, etc.
by pe1chl
Fri Mar 14, 2025 6:29 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

Yes, I think that "applications" should all be split off in separate packages. Because there are no inter-dependency issues and often not everyone wants them. And they are now easy to install. That would include such things as: - CAPsMAN - Hotspot - Web Proxy - SMB server / Media server - ...
by pe1chl
Fri Mar 14, 2025 12:33 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

The wAP and cAP lines suffer from the same problem of having little permanent storage space, and they don't have a USB port. Why does the main RouterOS package need to load all the USB device drivers on these devices? Wouldn't it be possible to reduce the size of routeros.npk by about 2MiB if there...
by pe1chl
Fri Mar 14, 2025 12:24 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

AC2 only has 128Mb RAM ??
It's AX2 we're talking about.
Correct, I edited it. I meant ax2.
by pe1chl
Fri Mar 14, 2025 11:20 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.2 [stable] is released!

In any system that involves things like scripting languages, web interfaces, etc I at least avoid these characters all the time:
@ % " $ & # + < > (space)
That never hurts even when it is not really necessary.
by pe1chl
Fri Mar 14, 2025 11:16 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

I have once again log full or red "cache full, not storing" DNS Adlist related messages. My cache size is raised to 8192 KiB and Adlist size was something over the 2000 KiB. I definitely removed the functionality from the router. Ok but why do you use such a tiny amount of storage for the...
by pe1chl
Fri Mar 14, 2025 12:44 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.1 [stable] is released!

2025-03-04T01:01:17+01:00 MikroTik HeadOffice possible SYN flooding on tcp port 53 2025-03-04T06:06:52+01:00 MikroTik Branch3 possible SYN flooding on tcp port 53 2025-03-04T08:24:20+01:00 MikroTik Branch4 possible SYN flooding on tcp port 53 2025-03-04T08:52:10+01:00 MikroTik Branch2 possible SYN ...
by pe1chl
Thu Mar 13, 2025 10:38 pm
Forum: RouterOS beta
Topic: Feature Request: GREtap
Replies: 24
Views: 16424

Re: Feature Request: GREtap

One thing is for sure, posting on the forum will do zero for your request! You can try making a ticket in the support system, that will at least make it end up on the desk of someone considering it. Of course that does not mean it will be implemented, but at least there is a chance. Even better is t...
by pe1chl
Thu Mar 13, 2025 7:25 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.2 [stable] is released!

Windows Update uses http as well... (it uses https to determine what updates to download, and then downloads the actual updates over http)
by pe1chl
Thu Mar 13, 2025 7:14 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

Yes, when you have a hAP ac2 it is better to do a netinstall and also to give up on wifi-qcom-ac.
That simply will not last. Go back to "wireless" and when you want new drivers buy a hAP ax2 or ax3.
by pe1chl
Thu Mar 13, 2025 4:11 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.2 [stable] is released!

Why not? If https is used, then client can verify authenticity of server it's talking to. Yes, npk files do have some verification built in (I believe that packages are digitally signed by MT so it's not trivial to alter the contents). But two layers of security are better than one. And we definite...
by pe1chl
Thu Mar 13, 2025 10:29 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

*) queue - fixed system failure when CAKE kind queue was configured but queue type definition does not exist anymore (introduced in v7.18); Was the instability of CAKE that you previously mentioned really limited to having an interface with a CAKE queue and then deleting the queue type? In the ment...
by pe1chl
Wed Mar 12, 2025 9:01 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

When was that introduced?
by pe1chl
Wed Mar 12, 2025 4:12 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 295
Views: 167710

Re: Advanced Routing Failover without Scripting

Using console code as an example for how it would work in scripts is not good, especially not after you first used "print"!
by pe1chl
Wed Mar 12, 2025 11:19 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.2 [stable] is released!

*) queue - fixed system failure when CAKE kind queue was configured but queue type definition does not exist anymore (introduced in v7.18); Was the instability of CAKE that you previously mentioned really limited to having an interface with a CAKE queue and then deleting the queue type? In the ment...
by pe1chl
Wed Mar 12, 2025 11:16 am
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 295
Views: 167710

Re: Advanced Routing Failover without Scripting

Ok, a difference between your config and the one I use is that I do not use connection marks but I base the route mark on the source address of the packet (for output) and on a "PCC on src address" rule for the forwarded/NATted traffic (for loadbalancing). That selects the particular route...
by pe1chl
Tue Mar 11, 2025 5:03 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.1 [stable] is released!

Besides that, RouterOS already offers a "configure session" in terminal mode! Most people do not know it... When you enter a { in terminal mode, you enter a "block" (as in scripting) and you can enter commands, and when you enter } the block is closed and the commands are execute...
by pe1chl
Tue Mar 11, 2025 3:23 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2091
Views: 1109358

Re: 📣 WinBox 4 is here 📣

Back in those days we lived with having a dark screen with light characters on it. But when I first got a computer (in 1985) that used dark characters on a white background, and a windowing system that did the same thing, I really liked it and I never wanted to go back. Whenever I see a "dark m...
by pe1chl
Tue Mar 11, 2025 3:21 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.1 [stable] is released!

Thanks for the advice, It seems based on this that it would be recommended to netinstall when moving from v6 to v7.
Yes, that certainly is the case. Netinstall and import an export made just before (not a restore of a backup).
That will free up space, and prevent unexplainable problems as well.
by pe1chl
Tue Mar 11, 2025 12:09 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 295
Views: 167710

Re: Advanced Routing Failover without Scripting

When you are facing packet loss in a config like this, try disabling fasttrack.
You can start a "torch" on the internet interface, that will temporarily disable fasttrack.
When it then starts working, fasttrack is your problem.
by pe1chl
Tue Mar 11, 2025 12:02 pm
Forum: General
Topic: IPTV cuts and pixelations with Movistar Spain and HAP ax3/ax2
Replies: 113
Views: 17468

Re: IPTV cuts and pixelations with Movistar Spain and HAP ax3/ax2

Yes, there really should be multicast enhancement in the WiFi driver (multicast to unicast), but as he wrote it also happens with the Asus as an AP (and it undoubtedly has that) and is triggered by having the MikroTik router, it may be that the IGMP querier being buggy is the main cause. Of course I...
by pe1chl
Mon Mar 10, 2025 10:09 pm
Forum: General
Topic: IPTV cuts and pixelations with Movistar Spain and HAP ax3/ax2
Replies: 113
Views: 17468

Re: IPTV cuts and pixelations with Movistar Spain and HAP ax3/ax2

Actually it is not correct to stop a multicast stream immediately when there is no response to a query. I don't know if MikroTik use a well established IGMP implementation or have doctored their own (probably the latter) but the way it should work is: when a query is sent and a response received, th...
by pe1chl
Mon Mar 10, 2025 7:57 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2091
Views: 1109358

Re: 📣 WinBox 4 is here 📣

Please consider to have a settable option (even if only "normal" vs "long") for the connection timeout, i.e. when a device loses connectivity for up to a minute, maintain the connection instead of closing it after a few seconds.
by pe1chl
Mon Mar 10, 2025 7:42 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2091
Views: 1109358

Re: 📣 WinBox 4 is here 📣

When sorting the saved connection list, it can only be sorted on a single column. With v3.41, you can first click the "Note" header ("Comment" in v4) and then "Group" and you will get the list sorted by group first, and within the group sorted by Note. But in v4 for eve...
by pe1chl
Mon Mar 10, 2025 5:19 pm
Forum: Announcements
Topic: Newsletter #121 | October 2024
Replies: 63
Views: 16447

Re: Newsletter #121 | October 2024

When you want to reach the claimed performance of these routers, you need to have "fasttrack". When you removed that (e.g. because you cannot have it co-exist with other config) or you did not yet add it (e.g. IPv6) you will not reach 1Gbit. In general, people expect performance similar to...
by pe1chl
Mon Mar 10, 2025 5:12 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 295
Views: 167710

Re: Advanced Routing Failover without Scripting

Yes, you need to do that. Because the probe packets to check the routes are sent using the main table and your actual traffic is sent via the ISPx table. Unfortunately there is no way to auto-copy some routes between different tables, so you need to do that manually. (MikroTik will tell you to use V...
by pe1chl
Mon Mar 10, 2025 10:19 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

Also, when you are so lucky to have a device like the RB951G-2HnD (low-end router from the good old days when you still got 128MB flash) you should have partitioned it before installing a beta!
by pe1chl
Sun Mar 09, 2025 6:10 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

Everything here requires either time or money, not just keeping the flash size small. Please take a look at the changelog and see where the effort goes in recent versions. The problem is that working on new features and fixing bugs in existing features inevitably leads to code expansion and people ...
by pe1chl
Sun Mar 09, 2025 6:05 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

It's not related to loops and there is an :error command already for that.
:error can only exit with error. what would be useful is an exit that exits without error.
(especially now that every script that exits with an error triggers a log message)
by pe1chl
Sat Mar 08, 2025 4:58 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

Indeed... while that LMP 5G is exactly what I am looking for at one of our locations, and it would be used with an RB5009 as a router so no need for additional packages, I really don't like the idea of having a device with so little flash space. Not only is there a risk of routeros not fitting anymo...
by pe1chl
Sat Mar 08, 2025 11:43 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

We have discovered that CAKE type queue can crash router in v7.18 and v7.19 – we are working on a fix for that. However, it is not as simple as - add queue and router crashes. Seems that a set of events or precise timing is required for the problem to appear. And yes - when your router fits the &qu...
by pe1chl
Sat Mar 08, 2025 11:33 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

For such purposes, you should use "Safe Mode". Very much suggested, especially for new users. https://help.mikrotik.com/docs/spaces/ROS/pages/328155/Configuration+Management#ConfigurationManagement-SafeMode That would only work for mistakes that make the router unreachable (like deleting ...
by pe1chl
Sat Mar 08, 2025 11:29 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

What's new in 7.19beta4 (2025-Mar-06 14:10): *) console - added on-error to "for" and "foreach" loops; Will "break" functionality ever be added for loops? (Don't tell me about workarounds) Or a way to exit from a script midway? ("exit" command with ok/error p...
by pe1chl
Fri Mar 07, 2025 7:06 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

Ok that is great! Is there further indication that they are working on fixing the BGP problems?
by pe1chl
Fri Mar 07, 2025 12:13 pm
Forum: Announcements
Topic: Security announcement blog
Replies: 119
Views: 80967

Re: Security announcement blog

No idea if it was changed by now, but here the link on that page is: https://cdn.mikrotik.com/web-assets/supportsec/rss.xml
by pe1chl
Fri Mar 07, 2025 10:58 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

*) rose-storage - show btrfs balance and scrub errors if any; Well, in the 7.18 topic we discussed a little about whether they would use the "btrfs balance" or the "block-level mdraid" function for the RAID setups, and now we know: it is "balance". May the force be wit...
by pe1chl
Thu Mar 06, 2025 5:20 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.1 [stable] is released!

Assuming this is still about the "possible SYN flooding on tcp port 53": YES. When having hundreds of clients on the local network, there can be enormous bursts of DNS requests. The CCR2004 should be able to handle that. I have configured 10000 concurrent requests and 1000 TCP connections...
by pe1chl
Thu Mar 06, 2025 3:46 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.1 [stable] is released!

A crucial difference between "Safe mode" and also "apply changes only in RAM and require explicit save" and a transaction-like system is that with the latter you can apply a series of configuration changes and do an APPLY at the end of it. It is possible in RouterOS cmdline mode,...
by pe1chl
Thu Mar 06, 2025 11:39 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

Well, in your case it would have been valuable when you were warned because what happened is likely not what you intended! E.g. a device was powercycled without clean shutdown ... Nope, device was cleanly rebooted due to ROS upgrade. I can't explain the few hours jump myself, usually it is, as ever...
by pe1chl
Thu Mar 06, 2025 11:35 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

You still have the same BGP problems on 7.19b2? Do you have a forum post listing them all? I also have BGP with stuck routes on 7.16.1 that drive me crazy. I have not installed 7.19b2 yet. It does not list a fix for any of my problems in the changes list. I have posted several times in release topi...
by pe1chl
Thu Mar 06, 2025 10:39 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

Ok I seemed to remember that you posted it has been a problem for a while...
But indeed there are several BGP problems and the silence from MikroTik is deafening...
However, on my routers (with 7.18 and 7.18.1) there is no CPU usage problem, only the issues I mentioned before.
by pe1chl
Wed Mar 05, 2025 6:45 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

When upgrading my fleet from 7.17.2 to 7.18.1 ... I saw time jump of a few hours after reboot due to upgrade on one of devices. So the "after boot" time jump can be rather large. However I'd say that severity of first time jump (if caused by NTP client) after reboot can be down-tuned to i...
by pe1chl
Wed Mar 05, 2025 6:41 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.1 [stable] is released!

The point is lacking this kind of basic sanity checks on configuration changes. Even if some bug will cause this and there's no sanity check stopping it from happening and you are up to netinstall. It is not as bad as you suggest. Yes, sometimes you can remove an object and leave something else dan...
by pe1chl
Wed Mar 05, 2025 1:56 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

Critically of this action seems for me to be way to high. Exactly Very High :) Well, actually a change of time-of-day is a very critical event, but one could argue that in a device without built-in clock it could be labeled a little less severe when the time adjustment is forward, and less than 5 m...
by pe1chl
Wed Mar 05, 2025 12:40 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.1 [stable] is released!

We have seen this behavior as well with winbox, but port 8291 was only exposed to management vlan and I'm the only one accessing the device during that time so this SYN flooding warning is just a fluke at least for me I don't mind that it logs a bogus message, but I worry that when it detects the c...
by pe1chl
Wed Mar 05, 2025 11:22 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

I isolated the issue to BFD. When enabled it causes high CPU usage. I experience the issue on multiple routers and I set up a new router with empty configuration with just BGP + BFD and the issue still occurs. I reported the bug on ticket #SUP-181114 What parameters do you use for BFD? I have sever...
by pe1chl
Wed Mar 05, 2025 12:49 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.1 [stable] is released!

either way, I'd like to be able to tune this checks. Since they are in place, why not using them directly and tune them for our needs. Assuming this is still about the "possible SYN flooding on tcp port 53": YES. When having hundreds of clients on the local network, there can be enormous ...
by pe1chl
Wed Mar 05, 2025 12:47 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.1 [stable] is released!

What type of package manager introduces such a significant storage overhead? OpenWRT has been using "opkg" for years without issues. However, OpenWRT also provides board-specific builds - perhaps this is the key to addressing flash storage limitations on 16MB devices. The "packages&q...
by pe1chl
Tue Mar 04, 2025 7:25 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.1 [stable] is released!

I think the reason this has a high probability of appearing at reboot is because while the router is being rebooted, clients in the network are still firing DNS queries at it ... Yes I think that could be part of the reason, but what I observe is that on our main office network where there is lots ...
by pe1chl
Tue Mar 04, 2025 5:31 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.1 [stable] is released!

It is logged exactly once after every reboot. But I think that is because there is some "one time only" flag in the code to avoid overflowing the log with messages like that. However, I was watching a wireshark capture running on a PC that has "spurious delays when visiting websites&q...
by pe1chl
Tue Mar 04, 2025 4:17 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.1 [stable] is released!

After boot we get this message once: possible SYN flooding on tcp port 53 (I don't know at which version that started, but it was "recently") DNS service is only allowed from the local networks, not from the internet. There are hundreds of clients on the network and "SYN flooding on t...
by pe1chl
Tue Mar 04, 2025 12:12 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.1 [stable] is released!

I think the newly introduced products where it can be expected that users have more than basic needs (i.e. excluding switches) are no longer released with 16MB of flash. But we can all agree it was a stupid move from the beginning. Splitting stuff into packages introduces the issue that merely havin...
by pe1chl
Tue Mar 04, 2025 11:07 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.1 [stable] is released!

Just netinstalled this device. 7.18.1 is now running, but flash-space is tight. version: 7.18.1 (stable) free-hdd-space: 44.0KiB total-hdd-space: 16.0MiB board-name: D53G-5HacD2HnD platform: MikroTik It looks like your use-case is finished, and you need to either remain on a lower version or remove...
by pe1chl
Tue Mar 04, 2025 11:00 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18.1 [stable] is released! Can't update CCR2116-12G-4S+

Just as an fyi for anyone here (I did create a support ticket, SUP-181012). I have a CCR2116-12G-4S+, with two partitions, each running 7.17.2 (they failover to the other if something breaks). When attempting to update to 7.18.1, via the Webfig, the system downloads the update, reboots and after ab...
by pe1chl
Sat Mar 01, 2025 7:53 pm
Forum: Scripting
Topic: Updating CA root certs regularly [SOLVED]
Replies: 46
Views: 24260

Re: Updating CA root certs regularly [SOLVED]

then change the .txt to .pem
by pe1chl
Fri Feb 28, 2025 5:50 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 275
Views: 63463

Re: v7.19beta [testing] is released!

will measures be taken to increase free space on 16mb devices? hardly enough space to save a backup! You are not supposed to save your backup in flash memory! That normally is useless anyway. Make your backup in the RAMdisk (i.e. in the root directory on those 16MB devices), and then download it to...
by pe1chl
Fri Feb 28, 2025 5:07 pm
Forum: General
Topic: PPPoE and MTU > 1488
Replies: 14
Views: 7728

Re: PPPoE and MTU > 1488

It can also be a limitation of the used network card. I remember that my previous PC motherboard, which had 2 network devices on-motherboard, allowed >1500 byte MTU on one port but not on the other. This was with native Linux installed on the PC. I used one port for my LAN (including VLAN tags, it w...
by pe1chl
Fri Feb 28, 2025 2:40 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2091
Views: 1109358

Re: 📣 WinBox 4 is here 📣

There are four FP columns and you likely want to remove them all. That is most conveniently done using the available column selector.
Note that it has been much improved both in winbox 3 and winbox 4. In the old winbox 3 releases it was a multi-click procedure to remove each column.
by pe1chl
Fri Feb 28, 2025 2:17 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2091
Views: 1109358

Re: 📣 WinBox 4 is here 📣

You can remove columns using the widget at the extreme right on a screen. Another request: move the FP columns from the default layout of all interface types. I can understand they were added upon creation of the FP feature and MikroTik being very proud of it, but in general they are not very useful...
by pe1chl
Fri Feb 28, 2025 2:14 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

After the update, openvpn is rebooting the rb on each external connection made.
Please read previous replies to a release thread before adding another.
by pe1chl
Fri Feb 28, 2025 12:27 pm
Forum: MikroTik hardware questions
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 84
Views: 38146

Re: Running out of space on hAP ac2 [SOLVED]

Absolutely the same situation ! It is not normal situation when need to do netinstall after each ROS upgrade. There already was good idea to exclude rarely used features like hotspot/mpls to separate packages !!! The official MikroTik reply is that running wifi-qcom-ac on a hAP ac2 is at your own r...
by pe1chl
Fri Feb 28, 2025 12:23 pm
Forum: General
Topic: PPPoE and MTU > 1488
Replies: 14
Views: 7728

Re: PPPoE and MTU > 1488

No idea why it does not work for you. It works perfectly fine for me.
In the meantime I have changed from a Vigor modem to a ZyXEL modem, do the VLAN tagging in the MikroTik, and it still works fine.
Must be an error on your config or in the network.
by pe1chl
Fri Feb 28, 2025 11:48 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

I have all kinds of BGP issues that were introduced with 7.16, reported, but not yet fixed. In version 7.15.x it worked much better. But I cannot downgrade because I require other fixes. @pe1chl, I have an idea. How many peers do your routers have? My main issues with BGP involve a network within a...
by pe1chl
Thu Feb 27, 2025 7:45 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

But you cannot replace a disk with the same disk, that is the problem.
by pe1chl
Thu Feb 27, 2025 7:03 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

Disadvantage of kernel RAID: when a single block error occurs the entire device is removed from the array and no longer updated. So when you have two disks in RAID-1 each with a block error at a different location, you lose all your data. BTRFS balance raid1 does not have that problem, it keeps both...
by pe1chl
Thu Feb 27, 2025 4:57 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

I have all kinds of BGP issues that were introduced with 7.16, reported, but not yet fixed.
In version 7.15.x it worked much better. But I cannot downgrade because I require other fixes.
by pe1chl
Thu Feb 27, 2025 4:47 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

I wanted to check if anyone else has experienced this issue on their CCR2216 running v7.16.2. Every now and then, routing seems to stop working properly, and when I go to Routing → BGP, the display is completely blank and unresponsive. Please make a support ticket! When the support tickets about BG...
by pe1chl
Thu Feb 27, 2025 2:14 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

No it does not IMHO. Different type of developers so there should be no conflict. I wish it were so, but experience shows that it isn't. If I open a ticket about dynamic routing or MPLS issue, it takes months to react. If I am the only one about this issue then there is not so big the problem is. T...
by pe1chl
Thu Feb 27, 2025 11:42 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

Indeed it already is optional on the router, that is not the issue. What most people worry about is that it takes away development resources from router functionality, e.g. BGP. That is clearly demonstrated by the BGP problems introduced in 7.16 (and not present in 7.15) still not having been fixed ...
by pe1chl
Thu Feb 27, 2025 10:55 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

Prophecy?
Well in the Newsletter #123 topic it already begins... "we want ZFS, not BTRFS".
by pe1chl
Thu Feb 27, 2025 10:46 am
Forum: MikroTik hardware questions
Topic: Precision Time Protocol (PTP, IEEE 1588) Support
Replies: 28
Views: 14379

Re: Precision Time Protocol (PTP, IEEE 1588) Support

PTP is used for DECT-bases to sync them if the area is large or the sync-over-air gests disturbed, so DECT with 3-60 bases can be found in basically every company, especially with a warehouse. We had them 15 years ago. All gone. Everyone uses mobile phones, with VoWIFI when required (e.g. in the wa...
by pe1chl
Wed Feb 26, 2025 9:12 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

Using BTRFS's RAID finctionality in enterprise environment is a kamikaze solution. I'm curious what solution they use if there is any RAID function in it. I hope it is battery backed HW RAID controller... It is unclear if the RAID function uses Linux block-level RAID or the BTRFS balance profile &q...
by pe1chl
Wed Feb 26, 2025 12:29 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

Yes, that would be great! But I fear that once the Rose Data Server really hits the street, we will see lots of requests for (in itself) reasonable requests around data server functionality. (some of them in software not written by MikroTik but becoming their responsibility when used as part of such...
by pe1chl
Wed Feb 26, 2025 12:05 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

Starting from 7.18, this list has both the packages that are installed, and those that are optional to install. Can't imagine people overseeing such a thing, can you? Well, I have often commented that the changelog is inadequate and should be replaced with something that has more info, links to doc...
by pe1chl
Wed Feb 26, 2025 11:43 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

PLEASE PLEASE PLEASE study the matter before you claim that packages get installed.
Starting from 7.18, this list has both the packages that are installed, and those that are optional to install.
by pe1chl
Wed Feb 26, 2025 11:11 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

There are no buffer on logging, All logs that are generated at boot are not sent since there are no network up and running. Logs will only be tried sent once, and if that does not work, they are not sent (UDP/TCP). Yes, and it is not something that can be solved easily. E.g. in our network the bran...
by pe1chl
Tue Feb 25, 2025 11:04 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

There was a firmware change in 7.16 that of course may affect you only later when you do not update firmware every upgrade. I had a CCR1009 go into a bootloop when I changed from 2 to 1 partitions (the first one being active) with 7.18beta4 to beta6 upgrade, and when trying to netinstall it things g...
by pe1chl
Tue Feb 25, 2025 4:29 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

When you require that functionality, instead log to memory (as is default) and retrieve the logs using API from a remote system...
by pe1chl
Tue Feb 25, 2025 11:47 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2091
Views: 1109358

Re: 📣 WinBox 4 is here 📣

Another useful addition would be when the connect-to parameter (router name) is specified without a username and password, it would connect using the username and password stored in the address list, without requiring further click on CONNECT button.
by pe1chl
Tue Feb 25, 2025 11:32 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

Everyone #2 - Please do not turn this version release topic again unrelated to the release itself and talking about how changelogs might be better, testing might be better, etc. Please open new forum topics for such discussions and let us keep these release topics related to RouterOS not management...
by pe1chl
Mon Feb 24, 2025 9:48 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

I upgraded a CHR that is on a local network only (with free license), from version 7.18beta6. After the reboot, 123MB more disk space is used than before. After another reboot, it falls back to 105MB more used. After another reboot with internet access, it returns back to normal. I have seen this be...
by pe1chl
Mon Feb 24, 2025 6:33 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 494
Views: 121231

Re: v7.18 [stable] is released!

Stable release changelog has always been a list of changes since previous stable - bugs introduced and resolved within beta/rc are not in this list. It would be nice when new bugs introduced in a stable release would be added to the changelog (as a separate section) once they become known, so it is...
by pe1chl
Mon Feb 24, 2025 11:48 am
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 26433

Re: v7.18rc [testing] is released!

Random source port option would be useful in the NTP Client as well...
by pe1chl
Sat Feb 22, 2025 11:03 am
Forum: General
Topic: IPsec parameter negotiation (and ancient defaults)
Replies: 14
Views: 3465

Re: IPsec parameter negotiation (and ancient defaults)

Indeed I should have been more specific, it was about "Windows 10 without additional client software". Of course there is software to use IKEv2 with Windows, but when you just go to networking and choose "add a connection to my work or school" (or whatever it is called today) the...
by pe1chl
Fri Feb 21, 2025 6:45 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 26433

Re: v7.18rc [testing] is released!

I can't find any LTE interface on my dozens of CCRs. CCR owners don't lose your hope and keep your spirits up Of course not... until you plug in a LTE USB stick (when your CCR has an USB port). Unfortunately there is no line with "*) bgp - improved stability;" in sight... that is what CCR...
by pe1chl
Fri Feb 21, 2025 2:57 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17.2 [stable] is released!

It seems that in 7.16 there have been changes in the firmware to allow devices to return to factory state when a reset-configuration is done (either using command or the button) and it apparently sometimes gets invoked incorrectly, blocking a netinstall.
by pe1chl
Fri Feb 21, 2025 2:16 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 26433

Re: v7.18rc [testing] is released!

It has been discussed many times before. The trade-off is always between following the kernel releases and applying your in-house patches to ever changing kernel versions (having to adapt them all the time) or keeping the same kernel version+in-house patches and then following the kernel development...
by pe1chl
Fri Feb 21, 2025 12:13 pm
Forum: General
Topic: IPsec parameter negotiation (and ancient defaults)
Replies: 14
Views: 3465

Re: IPsec parameter negotiation (and ancient defaults)

It isn't an issue for statically defined peers. But those require fixed IP addresses. In this case I want to setup a service without having to worry about the IP addresses of the clients. Those regularly change, and it causes a maintenance nightmare. Also, most IPsec implementations do not backoff w...
by pe1chl
Thu Feb 20, 2025 8:22 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 26433

Re: v7.18rc [testing] is released!

In fact you can already set a lower MTU for IPv6 by configuring it in IPv6->ND. Your end devices which receive IPv6 addresses via SLAAC will pick up the reduced MTU and will use it for their transmitted packets. I have never encountered MTU=1488 on PPPoE over VLAN. Normally the 4 bytes of a VLAN hea...
by pe1chl
Thu Feb 20, 2025 8:06 pm
Forum: General
Topic: IPsec parameter negotiation (and ancient defaults)
Replies: 14
Views: 3465

Re: IPsec parameter negotiation (and ancient defaults)

Well, I crafted this solution as a replacement for an older implementation that was in a plain Debian Linux VM.
The goal was to use RouterOS to get an installation that would be easier to maintain.
Unfortunately until now that isn't the case, but maybe when I have everything finished it is...
by pe1chl
Thu Feb 20, 2025 6:59 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 26433

Re: v7.18rc [testing] is released!

I'm not against storage features or container support, only I think it should be a side project that gets done when the main features like routing and wireless are working OK.
by pe1chl
Thu Feb 20, 2025 6:40 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17.2 [stable] is released!

Most likely the RB952Ui-5ac2nD died due to lack of storage during the upgrade. But netinstall should work. I had to netinstall a CCR1009 and ran into an issue because apparently the bootloader had been set to "flash-boot" and would not netinstall. I think it is due to a change in 7.16 firm...
by pe1chl
Thu Feb 20, 2025 4:31 pm
Forum: General
Topic: IPsec parameter negotiation (and ancient defaults)
Replies: 14
Views: 3465

Re: IPsec parameter negotiation (and ancient defaults)

Yes. I am hoping for one of the other IPsec experts to chime in, after all that worked well for the other question I recently posted.
by pe1chl
Wed Feb 19, 2025 10:53 pm
Forum: General
Topic: IPsec parameter negotiation (and ancient defaults)
Replies: 14
Views: 3465

Re: IPsec parameter negotiation (and ancient defaults)

Yes, I know that issue with EoIP (and also GRE and IPIP) with automatic IPsec configuration.... But in this case I am running an IKE2 server using identities for the different clients, and they all come in on the same "peer". (see the topic "IPsec tunnels without known remote IP"...
by pe1chl
Wed Feb 19, 2025 9:07 pm
Forum: General
Topic: IPsec parameter negotiation (and ancient defaults)
Replies: 14
Views: 3465

IPsec parameter negotiation (and ancient defaults)

I am trying to setup an IPsec server that can accept different parameters, because I have found that defaults used by RouterOS are ancient and no longer supported in some more modern software. E.g. the default phase1 profile uses SHA1 hashing and 3des or aes-128 encryption, the default phase2 propos...
by pe1chl
Wed Feb 19, 2025 4:57 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 26433

Re: v7.18rc [testing] is released!

While this might be true it's still royal PITA to see core functionality of ROS stagnate at some (partially) defunct state while other functionalities (about which some users do care and are enthusiastic while majority of users don't give a s**t) are getting somewhere. Yes, what is so bad about it ...
by pe1chl
Wed Feb 19, 2025 4:46 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2091
Views: 1109358

Re: 📣 WinBox 4 is here 📣

As I wrote before, there should be a separate (portable) application that performs the netinstall function and also can function as an IP->MAC connection relay. You start it when you need MAC connection and then point your browser at some port like localhost:8291 and you get the list of available MA...
by pe1chl
Wed Feb 19, 2025 2:19 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 26433

Re: v7.18rc [testing] is released!

Our production network is on 7.13, and absolute zero issues with BGP. Some 1.9M routes hapily routing Don't upgrade past 7.15! We had to do that for other reasons, we use BGP internally on a small network, not for internet routing. But it now fails to perform is basic task: keeping alternative rout...
by pe1chl
Wed Feb 19, 2025 2:14 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 26433

Re: v7.18rc [testing] is released!

+1, I couldn't agree more. I use those features, and I am happy with the functionalities they provide...
I use BGP routing, and I am sad it no longer works reliably (as it did in v6 and for some time in v7, I would say between 7.10 and 7.15).
by pe1chl
Wed Feb 19, 2025 2:12 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 26433

Re: v7.18rc [testing] is released!

If you don't like/need them, just don't use them, what the problem? I'm 100% sure, there are different developer teams for network features/storage features and they don't affect each other productivity. Well, the problem is that the network developer team fouled up the routing in 7.16 and now in 7...
by pe1chl
Wed Feb 19, 2025 12:14 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2091
Views: 1109358

Re: 📣 WinBox 4 is here 📣

This is why it would be better to get the functionality of winbox integrated into webfig, so there is no issue with "platform" anymore, everyone brings their own modern browser to their own (supported or unsupported) operating system.
by pe1chl
Wed Feb 19, 2025 12:05 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 26433

Re: v7.18rc [testing] is released!

We will look into this, but the route service crashes that you are experienced were also there on your router in v7.16, so they are not introduced in v7.18. It is clear that in 7.16 some breakage was introduced in the routing... and now we cannot assume that it will ever be fixed? I presume the win...
by pe1chl
Wed Feb 19, 2025 12:03 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 26433

Re: v7.18rc [testing] is released!

Heads-up - breaking changes for management and monitoring: *) console - put !empty sentence when API query returns nothing; It's still not in docs, which is annoying since we're now at "rc". IMO docs should be done by a "release candidate" (i.e. theoretically shippable). And dev...
by pe1chl
Tue Feb 18, 2025 3:09 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17.2 [stable] is released!

The above DNS content is invalid. You cannot have two CNAME records for the same DNS name! But just like many DNS servers will not enforce that or will only issue a warning (and similar for web-based DNS editors), most DNS resolvers will not check for upstream errors and will just cache whatever gar...
by pe1chl
Tue Feb 18, 2025 2:38 pm
Forum: General
Topic: IPTV cuts and pixelations with Movistar Spain and HAP ax3/ax2
Replies: 113
Views: 17468

Re: IPTV cuts and pixelations with Movistar Spain and HAP ax3/ax2

First try it with an ethernet cable instead of WiFi to isolate that issue with multicast over WiFi.
by pe1chl
Sat Feb 15, 2025 1:12 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

MikroTik staff often argues that the importance of each changelog entry varies from person to person, so users should read the entire changelog. I have suggested possible improvements to the whole changlog thing but they are ignored. Changelog lines are too cryptic (you first have to learn a number...
by pe1chl
Sat Feb 15, 2025 1:04 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

This message is there since v7.14. Please stop hijacking version topics with discussions about other features/issues/bugs. We will look into this and will find a solution. Keep this topic related to 7.18 please! I went back to the 7.14 release topic and I see that user "jimmer" at that ti...
by pe1chl
Fri Feb 14, 2025 9:07 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Well, I think there should probably be a "/system/reset-configuration keep-users=yes no-defaults=yes import -after-reset=myconfig.rsc" command that should run the import in verbose mode and log output including errors to a myconfig.log file, and every time there is an error that is not syn...
by pe1chl
Fri Feb 14, 2025 7:24 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

I often had errors while importing, not only with ports. And this is a very good idea! I would suggest to implement it like adding some parameter to import command that will allow to ignore errors. Like /import file=myconfig.rsc ignore-errors=yes Not only with "import" but also with "...
by pe1chl
Fri Feb 14, 2025 6:53 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Today I wanted to load the /export of our router, because there was a change in IP address that occurs in many different places. So I did a /export of the config of our CCR2004-16G-2S+ running 7.18beta2, and it included: /port set 0 name=serial0 set 1 name=serial1 This has always been part of the /e...
by pe1chl
Fri Feb 14, 2025 11:27 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Yes, it should have been added long ago, in v6 even (where separate packages for core functionality still were a thing).
I don't understand what people have against it.
by pe1chl
Thu Feb 13, 2025 9:36 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

I think it only applies to what we now call "old" devices ..[cut].. I solved the issue selecting the 'backup bootloader', rebooting and re-apply the routerboard fw update. Then back to the normal bootloader. Maybe it's not right .. but no more complaint in the log ;-) When that is the sol...
by pe1chl
Thu Feb 13, 2025 5:13 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

I think it only applies to what we now call "old" devices. The RB951G for example, which is MIPSBE. It is apparently assumed that everyone had upgraded to v7 before v7.6 and then could upgrade to that version and upgrade the backup-routerboot with that. In my ticket I explained that I got ...
by pe1chl
Thu Feb 13, 2025 11:48 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Well, the actual whole picture here would be that our support team wanted to find out firstly what is the reason why you "must" upgrade the bootloader and just wanted to look into this deeper and help not just to you but also to others by doing some global changes if necessary. Unfortunat...
by pe1chl
Wed Feb 12, 2025 8:05 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Maybe they have a script that adds this standard reply to every ticket that has been open for some time and does not have a supout.rif attached??
by pe1chl
Wed Feb 12, 2025 6:51 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

I expect @normis to intervene again to steer us at discussion about release-specific issues and I can understand that attitude. Well, the problem is that when you open a topic in another category you will usually not get replies from MikroTik employees, at least in the release topics that is much m...
by pe1chl
Mon Feb 10, 2025 11:49 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

From user's perspective, seeing list of available optional packages on device itself is huge step in right direction. The way it was done until now (downloading separate ZIP file, extracting wanted package, uploading it to device, rebooting) was very error prone ... one had to select correct archit...
by pe1chl
Mon Feb 10, 2025 11:48 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Regarding wifi-qcom-ac: I don't understand why they don't split it into two separate versions: That already happened. We now have wifi-qcom and wifi-qcom-ac. Before that, there was no chance to install on 16MB devices. But maybe the wifi-qcom-ac should instead be two other packages. Unfortunately e...
by pe1chl
Sun Feb 09, 2025 11:54 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

(as new wAP still came with v6 from factory in 2024 it seems) Really struggling how MikroTik gonna stick to their "5 years of upgrades after purchase date" for some of devices released in 2024, because they are already failing on user's desks unable to take any config changes as they ran ...
by pe1chl
Sat Feb 08, 2025 4:26 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Well of course it would be possible to have different routeros base packages, where the kernel modules and userland code for a lot of features are or are not present. I don't see the typical hAP ac2 user use stuff like MPLS, for example. I can understand why MPLS would be difficult to keep in a sepa...
by pe1chl
Sat Feb 08, 2025 11:23 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

On the note of above, can we please separate cloud package from routeros? Well, I really think that all applications should be separated in packages, not only that but also stuff like proxy, smb, hotspot, etc. But as far as I understand the architecture there is some overhead for having a package, ...
by pe1chl
Fri Feb 07, 2025 8:16 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

I do not see how such a messy and convoluted workaround would be the best solution to have connected routes in a second routing table...
I don't want to associate a routing table with interfaces, that is not the goal.
by pe1chl
Fri Feb 07, 2025 8:04 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

What's new in 7.18beta5 (2025-Feb-07 12:25): *) dhcpv4-client - allow selecting to which routing tables add default route (additional fixes); Very welcome!! A long-awaited feature :) It would be nice to allow multiple "routing tables selection" and per routing table "default route di...
by pe1chl
Fri Feb 07, 2025 7:06 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

I have a CHR "free" which I have used a since quite a while for v7 testing and where I always install the betas first. Since this week (when updating to beta4) I found that it has logged: system,error,critical could not save configuration changes, not enough storage space available. and in...
by pe1chl
Fri Feb 07, 2025 3:53 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17.2 [stable] is released!

Can it really be that someone has knowingly opened port 53 to traffic from WAN? That message also occurs when you have correctly opened it only on LAN but have quite some online devices. For us it only happens immediately after upgrade. Probably some devices get impatient because the router is down...
by pe1chl
Fri Feb 07, 2025 2:26 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

IMO such arguments are relevant only to users with physical access to deployed devices and totally in applicable to customers who must roll trucks with such constraints. Care to make a wager about which market has greater sales volume? Well, when we look at newly introduced devices and the kind of ...
by pe1chl
Thu Feb 06, 2025 8:41 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

I think there should be an additional device-mode flag (e.g. named device-mode) which you can enable once and for all to skip all future device-mode flag additions (i.e. automatically enable them).
by pe1chl
Thu Feb 06, 2025 8:22 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

But zerotier has an associated device-mode flag!
by pe1chl
Thu Feb 06, 2025 7:30 pm
Forum: General
Topic: disk backup
Replies: 2
Views: 4144

Re: disk backup

It is difficult because the file management possibilities of RouterOS are limited.
Probably best is to share the disk to a PC on the local network (using IP->SMB or the optional rose-storage package for NFS etc) and then run a backup program on the PC.
by pe1chl
Thu Feb 06, 2025 2:35 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17.1 [stable] is released!

- repartition: I don't understand what the current situation is supposed to fix. Sure I like it that without repartition flag we can now copy and switch partitions, but what attack scenario is now made impossible? - routerboard: It sure would be nice when there was another boot setting that first tr...
by pe1chl
Thu Feb 06, 2025 11:19 am
Forum: MikroTik hardware questions
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 84
Views: 38146

Re: Running out of space on hAP ac2 [SOLVED]

So many people will have to recover bricked router with 0 KiB of free storage, as I had to do today. I feel obliged to write some reviews and warn them. Well, I don't think there is a need to warn MikroTik, they are well aware of the 16MB issue and especially for the hAP ac2. They must have spent c...
by pe1chl
Wed Feb 05, 2025 8:32 pm
Forum: MikroTik hardware questions
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 84
Views: 38146

Re: Running out of space on hAP ac2 [SOLVED]

But it only works on 5GHz. That is not useful for me. Remember that when "wireless" was still in the base package, and wifi-qcom-ac did not yet exist, it was already possible to install wifi-qcom on this. But it would disable the wireless function. Why? I would think wifi-qcom could handle...
by pe1chl
Wed Feb 05, 2025 7:46 pm
Forum: MikroTik hardware questions
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 84
Views: 38146

Re: Running out of space on hAP ac2 [SOLVED]

Old Wi-Fi driver is inferior to new driver. As Normis has written before: this device was sold with the old Wi-Fi driver, it is not necessarily compatible with the new driver. It really is time to bin this thing. Unless indeed (as written by others) you use it only as a router or only as an accessp...
by pe1chl
Wed Feb 05, 2025 4:18 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

It would already be helpful when there was a separate script output by e.g. /system/default-firewall/print, in a way that can be cut/paste. That’s why I established my defconf collection . Cut and paste from any that’s close enough to your use case. Yeah, but what we need is something local to the ...
by pe1chl
Wed Feb 05, 2025 4:10 pm
Forum: General
Topic: how to conquer random mac address?
Replies: 26
Views: 11984

Re: how to conquer random mac address?

Expected much more from VRRP than just the routing function failover. Real (hot or cold) standby for DHCP, User Manager, Hotspot is not easy with MT. Well I am not even looking for a VRRP solution, it is fine for me when I can have two routers at two locations with a tunnel between them, each runni...
by pe1chl
Wed Feb 05, 2025 4:05 pm
Forum: General
Topic: how to conquer random mac address?
Replies: 26
Views: 11984

Re: how to conquer random mac address?

And you cannot combine WPA2-EAP and WPA3-EAP on a single SSID. I don't think that's correct. On my UniFi APs setting Security Protocol to "WPA3 Enterprise" allows both old and new devices to connect to the same access point and same SSID. I have tested that (maybe a year ago) and in WPA3 ...
by pe1chl
Wed Feb 05, 2025 12:35 pm
Forum: MikroTik hardware questions
Topic: cAP lite 802.3af/at PoE support
Replies: 12
Views: 5148

Re: cAP lite 802.3af/at PoE support

I have the same problem, but with a UAP-AC-HD :-)
Without a schematic it is difficult, as PoE has that magic detection/power-up sequence that is difficult to debug.
by pe1chl
Wed Feb 05, 2025 12:27 pm
Forum: General
Topic: how to conquer random mac address?
Replies: 26
Views: 11984

Re: how to conquer random mac address?

I am considering it but it ads another layer of complication as I have three physically separated locations visited by the same users. Radius would be one point of failure if it becomes inaccessible for any reason. I yet have to try setting User Manager on all locations and see if I can set managea...
by pe1chl
Tue Feb 04, 2025 7:41 pm
Forum: General
Topic: how to conquer random mac address?
Replies: 26
Views: 11984

Re: how to conquer random mac address?

I suggested before that the DHCP server should have a pre-lease script that is called when the DISCOVER packet is received and can be used to set DHCP parameters like the pool to be used, the lease time, network parameters, etc. With that it would be possible to put dynamic MAC addresses in a separa...
by pe1chl
Tue Feb 04, 2025 5:37 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

I am still hoping for a solution where defconf for the firewall can be applied to an existing router... some command that removes the firewall config and reloads it from defconf, if only as a commandline script. This can be done very easily - just print defconf and apply what you need. But this sou...
by pe1chl
Tue Feb 04, 2025 5:32 pm
Forum: General
Topic: how to conquer random mac address?
Replies: 26
Views: 11984

Re: how to conquer random mac address?

You can implement a "bridge filter" that drops packets with src MAC 02:00:00:00:00:00 / 03:00:00:00:00:00
(first is the MAC, second is the "mask")
by pe1chl
Tue Feb 04, 2025 11:17 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

My SmokePing shows a +1ms in latency difference since updating to 7.18. That's consistent across all targets. Not a big deal, but it certainly stands out in the graph and exactly coincides with me doing the update. Useless comment when you do not mention compared to what previous version! Maybe you...
by pe1chl
Tue Feb 04, 2025 11:15 am
Forum: General
Topic: Feature requests
Replies: 1807
Views: 774583

Re: Feature requests

I share the same concern. The limited 16MB flash storage has been known for years, yet no new hardware revision of e.g. hap ac2 with more memory has been released. ??? hAP ax2, clearly the successor of hAP ac2, has 128MB flash. Of course it is more expensive and what is puzzling is that hAP ac2 is ...
by pe1chl
Mon Feb 03, 2025 8:14 pm
Forum: General
Topic: Feature requests
Replies: 1807
Views: 774583

Re: Feature requests

I would never buy a new 16MB device. Others can do what they like...
by pe1chl
Mon Feb 03, 2025 6:38 pm
Forum: Beginner Basics
Topic: NTP stuck on Waiting....
Replies: 98
Views: 35660

Re: NTP stuck on Waiting....

Enabled multicast but blocked multicast e.g. in firewall
by pe1chl
Mon Feb 03, 2025 2:50 pm
Forum: General
Topic: Feature requests
Replies: 1807
Views: 774583

Re: Feature requests

That is not possible because those parts are not user-serviceable (they are not socketed and not easy to solder).
Furthermore, hAP ac2 is just a "throwaway device" which users would replace with something like hAP ax2 or hAP ax3 once they find the limits.
by pe1chl
Sun Feb 02, 2025 6:45 pm
Forum: MikroTik hardware questions
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 84
Views: 38146

Re: Running out of space on hAP ac2 [SOLVED]

It depends on your configuration. And also if you installed the new WiFi driver, which really is too big for this device.
On my hAP ac2 with old driver (wireless) I still have 1028kB free.
by pe1chl
Sun Feb 02, 2025 6:32 pm
Forum: MikroTik hardware questions
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 84
Views: 38146

Re: Running out of space on hAP ac2 [SOLVED]

Indeed there should be some way to vacuum the database. Remove all deleted records and undo history. When there is not enough space in the flash it can be done using the ramdisk as temporary storage. (of course with the risk that the config may be lost when the power is interrupted at the wrong mome...
by pe1chl
Sun Feb 02, 2025 12:38 pm
Forum: MikroTik hardware questions
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 84
Views: 38146

Re: Running out of space on hAP ac2 [SOLVED]

Make backup, netinstall 7.17.1 and restore backup.
by pe1chl
Sat Feb 01, 2025 1:33 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

it certainly is related to the configuration as I have a similar network (IPv6 with different /64 on tagged VLANs) running without issue.
so make a new topic including /export of bridge and ipv6.
by pe1chl
Sat Feb 01, 2025 12:04 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2091
Views: 1109358

Re: 📣 WinBox 4 is here 📣

And: only values that are actually modified should be set when hitting OK. Those are the blue-colored fields in winbox3. That should also mean that a value that is inherited from a template (and shown in the edit dialog) is not stored when something else in the dialog is changed. Even better would b...
by pe1chl
Sat Feb 01, 2025 12:01 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

When you have a special need to have a serial number in messages, why don't you add it to the device identity of your devices?
So instead of hAP-test you call it hAP-test-E1548DC8753B
by pe1chl
Fri Jan 31, 2025 11:57 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17.1 [stable] is released!

Does a netinstall with keep-configuration flag effectively to the same as an export to file, then reset-configuration with import from that file?
Or is it more like the restore of a backup?
by pe1chl
Fri Jan 31, 2025 9:05 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

The number after the version string is the "deviceEventClassId" which is supposed to be a unique ID of each message. However, the numbers 10 and 65 are probably not that, it looks like this is still to be implemented... Ok that would be nice for long message that may be splitt to multiple...
by pe1chl
Fri Jan 31, 2025 7:52 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Calm down! Let them debug and finish BASIC FUNCTIONALITY in BGP before starting such things...
by pe1chl
Fri Jan 31, 2025 7:09 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

The number after the version string is the "deviceEventClassId" which is supposed to be a unique ID of each message.
However, the numbers 10 and 65 are probably not that, it looks like this is still to be implemented...
by pe1chl
Fri Jan 31, 2025 6:54 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Settings for neighbor discover LLDP are lost on upgrade to 7.18beta2.
E.g.:
/ip neighbor discovery-settings
set discover-interface-list=discover lldp-mac-phy-config=yes \
    lldp-med-net-policy-vlan=16
After upgrade they can be re-applied and still work.
by pe1chl
Fri Jan 31, 2025 5:40 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17.1 [stable] is released!

Yes, there is an open ticket. Useless to share it here because you cannot access that anyway.
The ticket was made 23/Jul/24 but unfortunately after the usual "please send supout files when the problem occurs" (and doing that) there was no further progress.
by pe1chl
Fri Jan 31, 2025 4:37 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

BTW, when you listed default config, your terminal windows wasn't wide enough, some rules were clipped on the right side (the above written one as well). Well, an irritating problem in printing default-configuration is that it does not wrap the lines and the lines are very long. So you need to prin...
by pe1chl
Fri Jan 31, 2025 4:34 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17.1 [stable] is released!

Thanks for feedback. There was a chance that route process crashed during "/routing/bgp/advertisements/print". Updated the changelog: *) bgp - improved system stability when printing BGP advertisements; Ok that is nice, but I hope that the other BGP instabilities will also be fixed. At le...
by pe1chl
Fri Jan 31, 2025 12:30 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17.1 [stable] is released!

*) bgp - improved stability;
What does it mean exactly? What is the scenario that has been fixed?
by pe1chl
Fri Jan 31, 2025 12:27 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

The "LAN devices receive adversed IPv6 addresses from all VLANs" is that referring to Windows devices that are on ports with tagged VLANs present?
As that is a Windows bug, has nothing to do with RouterOS.
by pe1chl
Thu Jan 30, 2025 10:19 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

You can compare the ipv4 firewall....
by pe1chl
Thu Jan 30, 2025 9:37 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

You can display the defconf using: /system/default-configuration/print
by pe1chl
Thu Jan 30, 2025 5:44 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17 [stable] is released!

The question is: was the method before the "new method" documented? Probably it was a "known" method, apparently someone was able to write an independent mac-telnet program that worked. And now that no longer works. Still, "security by obscurity" is not a method that i...
by pe1chl
Thu Jan 30, 2025 4:25 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17 [stable] is released!

We only make changes that improve security of the users, none of those changes are to actively deny 3rd party OSes @normis! So good to see you out and about. I find your reassurances both credible and compelling. Thank you, Well, "improving security of the users" by making changes and the...
by pe1chl
Wed Jan 29, 2025 7:35 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

I am still hoping for a solution where defconf for the firewall can be applied to an existing router... some command that removes the firewall config and reloads it from defconf, if only as a commandline script. So far none of changes in firewall defconf was ever applied when upgrading ROS. So I do...
by pe1chl
Wed Jan 29, 2025 2:20 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

But noticed "cloud" or "file-share" are not selectable in device-mode. If the whole of idea was minimizing the attack surface, we're already off to some inconsistency ;). I think device-mode was a knee-jerk reaction to some bad publicity about MikroTik routers being compromised ...
by pe1chl
Wed Jan 29, 2025 12:24 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2091
Views: 1109358

Re: 📣 WinBox 4 is here 📣

Please make the setting for "inline comments" a 3-state: either not inline (separate line) or inline with the option to have it either at the beginning (as it is now) or at the end of the line (as it is in winbox 3) by default. Of course one can always move it afterwards, but having to do ...
by pe1chl
Wed Jan 29, 2025 12:16 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Please add fasttrack ipv6 in defconf Not saying it's not already ... but defconf is only applied when device is reset to factory defaults (where "factory" part is a bit misleading because it's not config applied in factory when manufacturing device, it's config set as default in any parti...
by pe1chl
Wed Jan 29, 2025 12:11 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

I believe the snmp error about OID not increasing was occurring a few releases back when snmp routes support was first introduced. Rerunning snmpwalk got stuck and eventually timed out, and rerunning it again it returned the same error. This router and others that have had this behavior are being m...
by pe1chl
Wed Jan 29, 2025 11:54 am
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 3988

Re: IPsec tunnels without known remote IP

Well, in the solution I use now (as suggested above by sindy) that issue doesn't actually occur, because all the policies are configured as templates and they only become active policies when the peer has connected. I think I now have it working correctly and am working with more knowledgeable users...
by pe1chl
Tue Jan 28, 2025 11:42 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

I agree, but I also want to stress that loading 4 full tables on an internet border gateway is not the only use-case for BGP.
by pe1chl
Tue Jan 28, 2025 10:19 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Ok I have been using RouterOS only from version ~6.29 and I was impressed with how BGP/BFD worked back then. With v7 there initially was the problem of "no BFD" and "buggy filters", but that seems to have been resolved by now. Unfortunately it now longer does its basic function: ...
by pe1chl
Tue Jan 28, 2025 5:36 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

That may be true, but before they used a standard BGP implementation and Linux routing, and in v7 it was replaced by in-house written code and frankly for me it has only caused trouble. I can understand how they were motivated by things like having a 72-core flagship router utilizing only a single c...
by pe1chl
Tue Jan 28, 2025 11:19 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Mikrotik have a significantly larger team of developers working on RouterOS core functionality now than they did in the RouterOS v6 to v7 transition phase Where do you have that info from? Has there been some announcement that I missed? I still get the perception that the number of developers limit...
by pe1chl
Mon Jan 27, 2025 11:57 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

You will probably have to do your own tests, as it worked for me in 7.15 already... also make sure your client isn't broken, like WinPE is!
(an issue in that version is that it advertises deprecated prefixes as deprecated forever, did not test that with 7.18beta yet)
by pe1chl
Mon Jan 27, 2025 10:39 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17 [stable] is released!

The problem with device-mode is not that "no router has all features". You can simply enable all features on all your routers. The problem is that it requires physical access to enable a feature, and there is no possibility to enable a feature before you upgrade (and lose access to the fea...
by pe1chl
Mon Jan 27, 2025 9:17 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 3988

Re: IPsec tunnels without known remote IP

Well, it is usually possible to configure the policy, so that should not really be an issue. W.r.t. the routing: unfortunately it is not that simple. I need to announce the active routes (active IPsec tunnels) on BGP. This server is running in a separate CHR from the core router, and the tunnels can...
by pe1chl
Mon Jan 27, 2025 7:15 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 3988

Re: IPsec tunnels without known remote IP

On Mikrotik acting as a server, you can have multiple /ip ipsec identity items attached to a single peer with address=::/0 , one per actual peer, that match by any remote-id other than IP address. For each said identity, you define a separate /ip ipsec policy group and set the policy-template-group...
by pe1chl
Mon Jan 27, 2025 3:11 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 3988

Re: IPsec tunnels without known remote IP

Ok that is good to know, I feared it would be impossible there too because RouterOS probably uses it...
by pe1chl
Mon Jan 27, 2025 2:24 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 3988

Re: IPsec tunnels without known remote IP

I have to try that solution with a group, but I have already tried to have a single defined peer with multiple identities, and that seemed to work but it breaks down when more than one peer connects at the same time. I will try with the group. Normally we use tunnels (either GRE, GRE/IPsec, or L2TP/...
by pe1chl
Mon Jan 27, 2025 1:58 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 3988

Re: IPsec tunnels without known remote IP

No it is not practical to register remote locations in DNS. It is for the hobby network, not for the company, and the remote users are of varying skills. What I need is a solution where the remote can configure their router or Raspberry Pi or whatever and then get their subnet IP-tunneled. This is w...
by pe1chl
Mon Jan 27, 2025 12:04 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 3988

IPsec tunnels without known remote IP

I am trying to setup an IPsec tunnel server that allows remote systems without previously known public IP (or dynamic IP) to connect, and to get a subnet tunneled to them. There may be like 50 remote systems, each with their own fqdn identity and PSK. In the past I got that working using "racoo...
by pe1chl
Mon Jan 27, 2025 11:51 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2091
Views: 1109358

Re: 📣 WinBox 4 is here 📣

I add dummy lines to the firewall this way:
/ip firewall filter
add action=log chain=-------- comment=-------------
(I use these as separators between different chains)
by pe1chl
Mon Jan 27, 2025 10:42 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Yes, there also is a strange problem where on multiple links between the same two routers (e.g. multiple tunnels over different networks) the prefixes received are not stored in the table for all of the links. So it is difficult to achieve redundancy. Sometimes it works, but later when one of the se...
by pe1chl
Sun Jan 26, 2025 8:16 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

It is not the only problem... I upgraded from 7.16 to 7.18beta and I had the default and an additional template for BGP, but there are issues with the default that I could solve by creating an additional template (same settings as the modified default) and using that. I changed the default back to o...
by pe1chl
Sun Jan 26, 2025 7:45 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17 [stable] is released!

The default config creates a bridge and it has the admin-mac set correctly.
You should normally not create any additional bridges! The VLANs can (now) be added on the single bridge.
Open a new topic with your specific requirements and/or look in the existing topics about bridge and VLAN!
by pe1chl
Sun Jan 26, 2025 7:28 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

The whole concept of templates is riddled with bugs. Another one is that winbox will not keep inheritance of parameters from templates, it will just copy them (e.g. into the connection).
It is best to rely as little as possible on them.
by pe1chl
Sun Jan 26, 2025 7:25 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17 [stable] is released!

You need to set the admin-mac= parameter to the MAC of the bridge.
The default config does that automatically but apparently you have tinkered with it.
by pe1chl
Sun Jan 26, 2025 12:17 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

No reason? I show you how must be coded corectly to avoid use scripting style that casually works... The missing "" are not only the problem, expect broken it again on future versions.... Actually I think putting a ; at the end of each line is not "useless" but is a style that p...
by pe1chl
Sat Jan 25, 2025 4:39 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17 [stable] is released!

Well I am not running 7.17 but I am testing 7.18beta2 and it shows that "syn flood" error for port 53 (DNS) once after every reboot, however when I later try the port 53 answers as normal.
So there must be more than that going on.
by pe1chl
Sat Jan 25, 2025 4:25 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17 [stable] is released!

I have a similar issue like i4ko: One device tries to connect to our server with a bunch of packets, because it want to establish a couple of tunnels. The 7.17 (and 7.16.2 too) version detects a TCP syn flood and shuts down any tcp syn ack traffic on that interface (Log message "possible SYN f...
by pe1chl
Sat Jan 25, 2025 1:40 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17 [stable] is released!

OF COURSE that does not work when DHCP Snooping is enabled!
DHCP Snooping is an active technique to avoid the problem of Rogue DHCP servers.
You would not use both at the same time...
by pe1chl
Sat Jan 25, 2025 11:18 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

I am just reporting that route table retrieval via SNMP is broken, not looking for alternative solutions.
by pe1chl
Fri Jan 24, 2025 4:23 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Brilliant support received today from Mikrotik. Problem resolved.
Useless to post that here when you do not include how it was resolved...
by pe1chl
Fri Jan 24, 2025 3:18 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17 [stable] is released!

I have suggested before that the changelog should be changed to a link to a site, where additional info can be provided. E.g. a link to relevant documentation in the manual (help site), a mouseover tip that explains the items in slightly more detail, and information like the release where a fixed pr...
by pe1chl
Fri Jan 24, 2025 3:11 pm
Forum: Announcements
Topic: Newsletter #121 | October 2024
Replies: 63
Views: 16447

Re: Newsletter #121 | October 2024

Also note that "Gigabit PHY" is NOT a switch! It basically is the electronics between a low-level CPU signal and the wires in the UTP. It works at L1.
It does not have any L2 or L3 functionality, as a switch chip may have. Switching is done inside the SoC here (as shown in the diagram).
by pe1chl
Fri Jan 24, 2025 3:08 pm
Forum: General
Topic: Which use cases for CCR2004-1G-2XS-PCIe ?
Replies: 39
Views: 10822

Re: Which use cases for CCR2004-1G-2XS-PCIe ?

Indeed I was once considering to use it in ESXi servers, with a short UTP from the RJ45 to the iLO port and internet feed via the SFP. But no ESXi support (of course we are now phasing out ESXi so that could be replaced with Linux) and also no clarity if it could be powered and running when the main...
by pe1chl
Fri Jan 24, 2025 2:30 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

No, all our monitoring is done using SNMP. I also do not like that each and every poll results in a log line.
by pe1chl
Fri Jan 24, 2025 2:28 pm
Forum: General
Topic: Which use cases for CCR2004-1G-2XS-PCIe ?
Replies: 39
Views: 10822

Re: Which use cases for CCR2004-1G-2XS-PCIe ?

Not much is known about this card... I also asked once if it has to be in a PCIe bus or if you could plug it into an extender card and supply only power.
No answer.
by pe1chl
Fri Jan 24, 2025 2:03 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

On one of our RB5009UPr+S+ I get the following irregular log messages: 2025-01-24T11:22:27+01:00 MikroTik ether1 detected poe-out status: voltage_on_poe-in 2025-01-24T11:22:28+01:00 MikroTik ether1 detected poe-out status: disabled 2025-01-24T11:28:29+01:00 MikroTik ether2 detected poe-out status: v...
by pe1chl
Fri Jan 24, 2025 1:52 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Retrieving route table via SNMP (snmpnetstat -v2c -c public -Cn -Cr router-IP) no longer returns the complete routing table.
Also, when there are multiple routing tables, it still ends up in a loop (existing problem).
by pe1chl
Fri Jan 24, 2025 12:01 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

The BGP situation appears to be improved, but I am still hunting a gremlin. What happened: my home router has 2 templates for 2 different networks (different AS, different routing table, different bgp-networks), one in default and one added template. The routers at work just have the default templat...
by pe1chl
Thu Jan 23, 2025 9:55 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Maybe the statement "Optimal nand stability requires a backup-routerboot upgrade" has to be explained. Given the fact that a backup-routerboot upgrade is impossible, what is the risk? Is there a risk when running, when booting, when using the backup booter, or all of these? I am not going ...
by pe1chl
Thu Jan 23, 2025 9:42 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

That is of course completely impractical. One cannot install an arbitrary RouterBOOT version, and the maintainers decided to change the RouterBOOT version for each and every RouterOS version, for whatever stupid reason... This package has to be updated to current RouterBOOT version (= the current Ro...
by pe1chl
Thu Jan 23, 2025 9:32 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

When upgrading a RB951G-2HnD and logging in to the commandline I got this story: 2025-01-23 20:11:32 system,info,critical Optimal nand stability requires a backup-routerboot upgrade.\r 2025-01-23 20:11:32 system,info,critical Universal package can be found here:\r 2025-01-23 20:11:32 system,info,cri...
by pe1chl
Thu Jan 23, 2025 5:34 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Thanks! What I mean is the deviceEventClassId field that I have seen in some examples, but apparently does not yet exist in RouterOS. It probably requires "changes all over the software" to add that, and it would be nice if it would appear in non-CEF messages as well. (in the text or as a ...
by pe1chl
Thu Jan 23, 2025 3:48 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Also in the "logging" category: could we get a log message when the state of a route with check-gateway option changes (up or down)?
I enabled all "route" messages but there does not appear to be a message for that, other than during initial establishment.
by pe1chl
Thu Jan 23, 2025 3:46 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

I am happy to notice that the "regex" match in Logging Rules was added! (actually in 7.17 but I skipped that release)
In the category "it is never good enough": could we get a "not" option for that (the familiar box in which a ! can be clicked)?
by pe1chl
Thu Jan 23, 2025 2:55 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Well I skipped 7.17 because of that, but now I am testing this beta because it fixes a BGP problem (still have to test if it fixes all problems)... Now I find that by default "partitions" mode is OFF but I still can switch between partitions and copy active to backup, so it is not so bad a...
by pe1chl
Thu Jan 23, 2025 11:17 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

I'm not familiar with that CEF format, but isn't there supposed to be a unique message identifier as well? Or does CEF not specify that?
by pe1chl
Wed Jan 22, 2025 2:19 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

It would be nice to have REST API as a separate service too, that you can enable without allowing webfig...
by pe1chl
Wed Jan 22, 2025 11:53 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

Everything will be back to normal after upgrading RB firmware to 7.18beta. Not possible on CHR. Simple reboot does the trick as well (just verified on wAP AC). There is no "issue", it is the new normal. It says it shows the available packages after a "check for updates", and app...
by pe1chl
Tue Jan 21, 2025 9:14 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

On this above, what modems/devices support these eSIM commands?
Most likely some device that still is in development...
We can still hope there will be more 5G client devices :-)
by pe1chl
Tue Jan 21, 2025 9:10 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17 [stable] is released!

TLDR: ROS DNS forwarder should not switch upstream DNS server just because a single request was answered with status SERVFAIL, because SERVFAIL not necessarily indicates a problem with the specific DNS server. A "good" way to handle this (this is how bind9 does it) is to keep a rolling av...
by pe1chl
Tue Jan 21, 2025 8:25 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 157196

Re: v7.18beta [testing] is released!

*) system - added option to list and install available packages (after using "check-for-updates");
Oh that is great! Have been asking for that / suggesting it for ages...
Now get on with it and split off some niche functions/applications into separate packages again!
by pe1chl
Tue Jan 21, 2025 12:12 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17 [stable] is released!

In CLI Responder parameter for Wireguard peer renamed to "responder" and was "is-responder" in previous versions. So some exported configs will produce syntax error You should understand in general that while RouterOS does automatically convert configuration when you upgrade (an...
by pe1chl
Mon Jan 20, 2025 4:21 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2091
Views: 1109358

Re: 📣 WinBox 4 is here 📣

hI, In dark mode, why text is in gray and not white, it's not enough contrasted for some people. I think, there should be a separate color settings window, that will allow to select a color for each interface element (fonts, backgrounds, lines, headers, window titles and so on). It's hard to fullfi...
by pe1chl
Sun Jan 19, 2025 1:08 pm
Forum: General
Topic: How to perform thorough data link filtering?
Replies: 9
Views: 2471

Re: How to perform thorough data link filtering?

Is anything required for these commands to function after reboot or am I supposed to enter them each time after reboot? I suggest you first use the default settings, make your self familiar with RouterOS a bit more, maybe read some of the docs, and once you know the answer to such generic questions...
by pe1chl
Sat Jan 18, 2025 11:13 am
Forum: General
Topic: How to perform thorough data link filtering?
Replies: 9
Views: 2471

Re: How to perform thorough data link filtering?

It would also be great if there was some layer 2 filtering (aside from ARP) for WAN port, but EBTables is LAN-only and doesn't filter WAN. You can just add another bridge, put your WAN port in it, and move the WAN port config (IP address etc) from the WAN port to that bridge. Then you can apply bri...
by pe1chl
Fri Jan 17, 2025 7:29 pm
Forum: General
Topic: Ether1 (NetInstall) port - danger for WAN?
Replies: 14
Views: 2877

Re: Ether1 (NetInstall) port - danger for WAN?

Yes, but who has installed 7.17? I probably never will...
Before that, an admin user could set the "try ethernet once" mode and reboot, but even then it would not work on a typical internet connection (at least here, it is all PPPoE)
by pe1chl
Fri Jan 17, 2025 6:18 pm
Forum: General
Topic: Ether1 (NetInstall) port - danger for WAN?
Replies: 14
Views: 2877

Re: Ether1 (NetInstall) port - danger for WAN?

Ok but even with a flat L2 network the "hacker" must be in the same L2 space (which means at the ISP or maybe in the same street in some cases) and it cannot be "a Russian hacker" (over here the media think that all hackers are Russian) working from home.
by pe1chl
Fri Jan 17, 2025 4:15 pm
Forum: Scripting
Topic: Copy comments from leases to ARP
Replies: 1
Views: 2219

Re: Copy comments from leases to ARP

You can only set comments on static entries.
So that presumes you have entered those ARP entries manually.
Having them set by the DHCP server ("add ARP for leases") does not count, because then the ARP entries are still considered Dynamic even when the lease is static.
by pe1chl
Fri Jan 17, 2025 4:13 pm
Forum: General
Topic: How to perform thorough data link filtering?
Replies: 9
Views: 2471

Re: How to perform thorough data link filtering?

What is wrong with using "bridge filter", which probably indeed will map to ebtables, for that?
by pe1chl
Fri Jan 17, 2025 4:10 pm
Forum: General
Topic: Ether1 (NetInstall) port - danger for WAN?
Replies: 14
Views: 2877

Re: Ether1 (NetInstall) port - danger for WAN?

It can only be an issue when: - your WAN is actually a plain L2 link to the ISP network and there could be someone on the other side who can connect a machine with netinstall to that - they already know your credentials so they can log in to your router and set "boot ethernet once" and the...
by pe1chl
Fri Jan 17, 2025 4:03 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17 [stable] is released!

upgrade failed, free 9 kB of kernel disk space First they have to figure out what does this message actually mean... Maybe on some devices there is a separate partition for /boot ? That used to be required/customary on some Linux filesystems or disk devices, to guarantee that the boot code was alwa...
by pe1chl
Fri Jan 17, 2025 3:20 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17 [stable] is released!

Due to a chip issue which reports board temperature MikroTik decided to remove this parameter from health. The questions was "WHY?" What is the chip doing to cause this decision? Sometimes the reported board temperature is ridiculously high, I have seen that in one of our devices (while o...
by pe1chl
Fri Jan 17, 2025 3:17 pm
Forum: General
Topic: Logging prefix is a mess SUP-105353 SUP-144261. Waiting for MT to support RFC 5424
Replies: 44
Views: 16405

Re: Logging prefix is a mess SUP-105353 SUP-144261. Waiting for MT to support RFC 5424

Well, I still hope there will also be some unique message code ("topic") for each and every different message that can be logged by RouterOS. As it is now, there are too many different messages grouped under the same topic, and filtering is difficult. (also because the system logging rules...
by pe1chl
Thu Jan 16, 2025 9:49 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17 [stable] is released!

Thoughts anyone? EoIP is a connectionless protocol, there is no "connection that is closing". However, as with any tunnel protocol, there is the risk of creating a loop where encapsulated traffic is again encapsulated. Maybe the circumstances have changed due to the version upgrade, like ...
by pe1chl
Thu Jan 16, 2025 9:46 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17 [stable] is released!

Wow... And how about me that, using semantic versioning as a reference, I was thinking that Stable could mean that the software manufacturer should only release as stable code that is free of any known bugs. I think I'll review a little more about versioning standards. It would be desirable when it...
by pe1chl
Thu Jan 16, 2025 8:42 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 210767

Re: v7.17 [stable] is released!

"v7 stable" NOT STABLE. Remember that "stable" in software releases means: "here you have a version that will remain for a while, we will not release a new version every week or two, so you can install this and won't have to update it immediately". The stability refers...
by pe1chl
Thu Jan 16, 2025 8:33 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2091
Views: 1109358

Re: 📣 WinBox 4 is here 📣

Such a message can also mean that the router is very busy doing something else or the link to the router is slow.
Apparently when the connection cannot be established correctly it will issue some generic message.
by pe1chl
Thu Jan 16, 2025 3:43 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 295
Views: 167710

Re: Advanced Routing Failover without Scripting

I tested on a debug router but it isn't really a viable solution. There are messages logged but they all have topic route,debug,calc and there is no specific message about the recursive route that goes up/down, only information about the reachability of a specific address occurring somewhere in a ch...
by pe1chl
Thu Jan 16, 2025 2:22 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 160890

Re: v7.17rc [testing] is released!

Still I think it is a shame that there is total silence from MikroTik about the BGP issues, both on this topic and from support. (I have an open ticket) I wouldn’t go as far as calling it a shame, but it is certainly irritating. Let’s hope for the best and that it gets fixed soon. Perhaps if someon...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 43