Community discussions

MikroTik App

Search found 12725 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 43
by pe1chl
Fri Feb 14, 2025 11:27 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Yes, it should have been added long ago, in v6 even (where separate packages for core functionality still were a thing).
I don't understand what people have against it.
by pe1chl
Thu Feb 13, 2025 9:36 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

I think it only applies to what we now call "old" devices ..[cut].. I solved the issue selecting the 'backup bootloader', rebooting and re-apply the routerboard fw update. Then back to the normal bootloader. Maybe it's not right .. but no more complaint in the log ;-) When that is the sol...
by pe1chl
Thu Feb 13, 2025 5:13 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

I think it only applies to what we now call "old" devices. The RB951G for example, which is MIPSBE. It is apparently assumed that everyone had upgraded to v7 before v7.6 and then could upgrade to that version and upgrade the backup-routerboot with that. In my ticket I explained that I got ...
by pe1chl
Thu Feb 13, 2025 11:48 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Well, the actual whole picture here would be that our support team wanted to find out firstly what is the reason why you "must" upgrade the bootloader and just wanted to look into this deeper and help not just to you but also to others by doing some global changes if necessary. Unfortunat...
by pe1chl
Wed Feb 12, 2025 8:05 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Maybe they have a script that adds this standard reply to every ticket that has been open for some time and does not have a supout.rif attached??
by pe1chl
Wed Feb 12, 2025 6:51 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

I expect @normis to intervene again to steer us at discussion about release-specific issues and I can understand that attitude. Well, the problem is that when you open a topic in another category you will usually not get replies from MikroTik employees, at least in the release topics that is much m...
by pe1chl
Mon Feb 10, 2025 11:49 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

From user's perspective, seeing list of available optional packages on device itself is huge step in right direction. The way it was done until now (downloading separate ZIP file, extracting wanted package, uploading it to device, rebooting) was very error prone ... one had to select correct archit...
by pe1chl
Mon Feb 10, 2025 11:48 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Regarding wifi-qcom-ac: I don't understand why they don't split it into two separate versions: That already happened. We now have wifi-qcom and wifi-qcom-ac. Before that, there was no chance to install on 16MB devices. But maybe the wifi-qcom-ac should instead be two other packages. Unfortunately e...
by pe1chl
Sun Feb 09, 2025 11:54 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

(as new wAP still came with v6 from factory in 2024 it seems) Really struggling how MikroTik gonna stick to their "5 years of upgrades after purchase date" for some of devices released in 2024, because they are already failing on user's desks unable to take any config changes as they ran ...
by pe1chl
Sat Feb 08, 2025 4:26 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Well of course it would be possible to have different routeros base packages, where the kernel modules and userland code for a lot of features are or are not present. I don't see the typical hAP ac2 user use stuff like MPLS, for example. I can understand why MPLS would be difficult to keep in a sepa...
by pe1chl
Sat Feb 08, 2025 11:23 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

On the note of above, can we please separate cloud package from routeros? Well, I really think that all applications should be separated in packages, not only that but also stuff like proxy, smb, hotspot, etc. But as far as I understand the architecture there is some overhead for having a package, ...
by pe1chl
Fri Feb 07, 2025 8:16 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

I do not see how such a messy and convoluted workaround would be the best solution to have connected routes in a second routing table...
I don't want to associate a routing table with interfaces, that is not the goal.
by pe1chl
Fri Feb 07, 2025 8:04 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

What's new in 7.18beta5 (2025-Feb-07 12:25): *) dhcpv4-client - allow selecting to which routing tables add default route (additional fixes); Very welcome!! A long-awaited feature :) It would be nice to allow multiple "routing tables selection" and per routing table "default route di...
by pe1chl
Fri Feb 07, 2025 7:06 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

I have a CHR "free" which I have used a since quite a while for v7 testing and where I always install the betas first. Since this week (when updating to beta4) I found that it has logged: system,error,critical could not save configuration changes, not enough storage space available. and in...
by pe1chl
Fri Feb 07, 2025 3:53 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17.2 [stable] is released!

Can it really be that someone has knowingly opened port 53 to traffic from WAN? That message also occurs when you have correctly opened it only on LAN but have quite some online devices. For us it only happens immediately after upgrade. Probably some devices get impatient because the router is down...
by pe1chl
Fri Feb 07, 2025 2:26 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

IMO such arguments are relevant only to users with physical access to deployed devices and totally in applicable to customers who must roll trucks with such constraints. Care to make a wager about which market has greater sales volume? Well, when we look at newly introduced devices and the kind of ...
by pe1chl
Thu Feb 06, 2025 8:41 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

I think there should be an additional device-mode flag (e.g. named device-mode) which you can enable once and for all to skip all future device-mode flag additions (i.e. automatically enable them).
by pe1chl
Thu Feb 06, 2025 8:22 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

But zerotier has an associated device-mode flag!
by pe1chl
Thu Feb 06, 2025 7:30 pm
Forum: General
Topic: disk backup
Replies: 2
Views: 1374

Re: disk backup

It is difficult because the file management possibilities of RouterOS are limited.
Probably best is to share the disk to a PC on the local network (using IP->SMB or the optional rose-storage package for NFS etc) and then run a backup program on the PC.
by pe1chl
Thu Feb 06, 2025 2:35 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17.1 [stable] is released!

- repartition: I don't understand what the current situation is supposed to fix. Sure I like it that without repartition flag we can now copy and switch partitions, but what attack scenario is now made impossible? - routerboard: It sure would be nice when there was another boot setting that first tr...
by pe1chl
Thu Feb 06, 2025 11:19 am
Forum: RouterBOARD hardware
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 77
Views: 26165

Re: Running out of space on hAP ac2 [SOLVED]

So many people will have to recover bricked router with 0 KiB of free storage, as I had to do today. I feel obliged to write some reviews and warn them. Well, I don't think there is a need to warn MikroTik, they are well aware of the 16MB issue and especially for the hAP ac2. They must have spent c...
by pe1chl
Wed Feb 05, 2025 8:32 pm
Forum: RouterBOARD hardware
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 77
Views: 26165

Re: Running out of space on hAP ac2 [SOLVED]

But it only works on 5GHz. That is not useful for me. Remember that when "wireless" was still in the base package, and wifi-qcom-ac did not yet exist, it was already possible to install wifi-qcom on this. But it would disable the wireless function. Why? I would think wifi-qcom could handle...
by pe1chl
Wed Feb 05, 2025 7:46 pm
Forum: RouterBOARD hardware
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 77
Views: 26165

Re: Running out of space on hAP ac2 [SOLVED]

Old Wi-Fi driver is inferior to new driver. As Normis has written before: this device was sold with the old Wi-Fi driver, it is not necessarily compatible with the new driver. It really is time to bin this thing. Unless indeed (as written by others) you use it only as a router or only as an accessp...
by pe1chl
Wed Feb 05, 2025 4:18 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

It would already be helpful when there was a separate script output by e.g. /system/default-firewall/print, in a way that can be cut/paste. That’s why I established my defconf collection . Cut and paste from any that’s close enough to your use case. Yeah, but what we need is something local to the ...
by pe1chl
Wed Feb 05, 2025 4:10 pm
Forum: General
Topic: how to conquer random mac address?
Replies: 26
Views: 9497

Re: how to conquer random mac address?

Expected much more from VRRP than just the routing function failover. Real (hot or cold) standby for DHCP, User Manager, Hotspot is not easy with MT. Well I am not even looking for a VRRP solution, it is fine for me when I can have two routers at two locations with a tunnel between them, each runni...
by pe1chl
Wed Feb 05, 2025 4:05 pm
Forum: General
Topic: how to conquer random mac address?
Replies: 26
Views: 9497

Re: how to conquer random mac address?

And you cannot combine WPA2-EAP and WPA3-EAP on a single SSID. I don't think that's correct. On my UniFi APs setting Security Protocol to "WPA3 Enterprise" allows both old and new devices to connect to the same access point and same SSID. I have tested that (maybe a year ago) and in WPA3 ...
by pe1chl
Wed Feb 05, 2025 12:35 pm
Forum: RouterBOARD hardware
Topic: cAP lite 802.3af/at PoE support
Replies: 12
Views: 3130

Re: cAP lite 802.3af/at PoE support

I have the same problem, but with a UAP-AC-HD :-)
Without a schematic it is difficult, as PoE has that magic detection/power-up sequence that is difficult to debug.
by pe1chl
Wed Feb 05, 2025 12:27 pm
Forum: General
Topic: how to conquer random mac address?
Replies: 26
Views: 9497

Re: how to conquer random mac address?

I am considering it but it ads another layer of complication as I have three physically separated locations visited by the same users. Radius would be one point of failure if it becomes inaccessible for any reason. I yet have to try setting User Manager on all locations and see if I can set managea...
by pe1chl
Tue Feb 04, 2025 7:41 pm
Forum: General
Topic: how to conquer random mac address?
Replies: 26
Views: 9497

Re: how to conquer random mac address?

I suggested before that the DHCP server should have a pre-lease script that is called when the DISCOVER packet is received and can be used to set DHCP parameters like the pool to be used, the lease time, network parameters, etc. With that it would be possible to put dynamic MAC addresses in a separa...
by pe1chl
Tue Feb 04, 2025 5:37 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

I am still hoping for a solution where defconf for the firewall can be applied to an existing router... some command that removes the firewall config and reloads it from defconf, if only as a commandline script. This can be done very easily - just print defconf and apply what you need. But this sou...
by pe1chl
Tue Feb 04, 2025 5:32 pm
Forum: General
Topic: how to conquer random mac address?
Replies: 26
Views: 9497

Re: how to conquer random mac address?

You can implement a "bridge filter" that drops packets with src MAC 02:00:00:00:00:00 / 03:00:00:00:00:00
(first is the MAC, second is the "mask")
by pe1chl
Tue Feb 04, 2025 11:17 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

My SmokePing shows a +1ms in latency difference since updating to 7.18. That's consistent across all targets. Not a big deal, but it certainly stands out in the graph and exactly coincides with me doing the update. Useless comment when you do not mention compared to what previous version! Maybe you...
by pe1chl
Tue Feb 04, 2025 11:15 am
Forum: General
Topic: Feature requests
Replies: 1807
Views: 700621

Re: Feature requests

I share the same concern. The limited 16MB flash storage has been known for years, yet no new hardware revision of e.g. hap ac2 with more memory has been released. ??? hAP ax2, clearly the successor of hAP ac2, has 128MB flash. Of course it is more expensive and what is puzzling is that hAP ac2 is ...
by pe1chl
Mon Feb 03, 2025 8:14 pm
Forum: General
Topic: Feature requests
Replies: 1807
Views: 700621

Re: Feature requests

I would never buy a new 16MB device. Others can do what they like...
by pe1chl
Mon Feb 03, 2025 6:38 pm
Forum: Beginner Basics
Topic: NTP stuck on Waiting....
Replies: 96
Views: 31753

Re: NTP stuck on Waiting....

Enabled multicast but blocked multicast e.g. in firewall
by pe1chl
Mon Feb 03, 2025 2:50 pm
Forum: General
Topic: Feature requests
Replies: 1807
Views: 700621

Re: Feature requests

That is not possible because those parts are not user-serviceable (they are not socketed and not easy to solder).
Furthermore, hAP ac2 is just a "throwaway device" which users would replace with something like hAP ax2 or hAP ax3 once they find the limits.
by pe1chl
Sun Feb 02, 2025 6:45 pm
Forum: RouterBOARD hardware
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 77
Views: 26165

Re: Running out of space on hAP ac2 [SOLVED]

It depends on your configuration. And also if you installed the new WiFi driver, which really is too big for this device.
On my hAP ac2 with old driver (wireless) I still have 1028kB free.
by pe1chl
Sun Feb 02, 2025 6:32 pm
Forum: RouterBOARD hardware
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 77
Views: 26165

Re: Running out of space on hAP ac2 [SOLVED]

Indeed there should be some way to vacuum the database. Remove all deleted records and undo history. When there is not enough space in the flash it can be done using the ramdisk as temporary storage. (of course with the risk that the config may be lost when the power is interrupted at the wrong mome...
by pe1chl
Sun Feb 02, 2025 12:38 pm
Forum: RouterBOARD hardware
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 77
Views: 26165

Re: Running out of space on hAP ac2 [SOLVED]

Make backup, netinstall 7.17.1 and restore backup.
by pe1chl
Sat Feb 01, 2025 1:33 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

it certainly is related to the configuration as I have a similar network (IPv6 with different /64 on tagged VLANs) running without issue.
so make a new topic including /export of bridge and ipv6.
by pe1chl
Sat Feb 01, 2025 12:04 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

And: only values that are actually modified should be set when hitting OK. Those are the blue-colored fields in winbox3. That should also mean that a value that is inherited from a template (and shown in the edit dialog) is not stored when something else in the dialog is changed. Even better would b...
by pe1chl
Sat Feb 01, 2025 12:01 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

When you have a special need to have a serial number in messages, why don't you add it to the device identity of your devices?
So instead of hAP-test you call it hAP-test-E1548DC8753B
by pe1chl
Fri Jan 31, 2025 11:57 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17.1 [stable] is released!

Does a netinstall with keep-configuration flag effectively to the same as an export to file, then reset-configuration with import from that file?
Or is it more like the restore of a backup?
by pe1chl
Fri Jan 31, 2025 9:05 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

The number after the version string is the "deviceEventClassId" which is supposed to be a unique ID of each message. However, the numbers 10 and 65 are probably not that, it looks like this is still to be implemented... Ok that would be nice for long message that may be splitt to multiple...
by pe1chl
Fri Jan 31, 2025 7:52 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Calm down! Let them debug and finish BASIC FUNCTIONALITY in BGP before starting such things...
by pe1chl
Fri Jan 31, 2025 7:09 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

The number after the version string is the "deviceEventClassId" which is supposed to be a unique ID of each message.
However, the numbers 10 and 65 are probably not that, it looks like this is still to be implemented...
by pe1chl
Fri Jan 31, 2025 6:54 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Settings for neighbor discover LLDP are lost on upgrade to 7.18beta2.
E.g.:
/ip neighbor discovery-settings
set discover-interface-list=discover lldp-mac-phy-config=yes \
    lldp-med-net-policy-vlan=16
After upgrade they can be re-applied and still work.
by pe1chl
Fri Jan 31, 2025 5:40 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17.1 [stable] is released!

Yes, there is an open ticket. Useless to share it here because you cannot access that anyway.
The ticket was made 23/Jul/24 but unfortunately after the usual "please send supout files when the problem occurs" (and doing that) there was no further progress.
by pe1chl
Fri Jan 31, 2025 4:37 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

BTW, when you listed default config, your terminal windows wasn't wide enough, some rules were clipped on the right side (the above written one as well). Well, an irritating problem in printing default-configuration is that it does not wrap the lines and the lines are very long. So you need to prin...
by pe1chl
Fri Jan 31, 2025 4:34 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17.1 [stable] is released!

Thanks for feedback. There was a chance that route process crashed during "/routing/bgp/advertisements/print". Updated the changelog: *) bgp - improved system stability when printing BGP advertisements; Ok that is nice, but I hope that the other BGP instabilities will also be fixed. At le...
by pe1chl
Fri Jan 31, 2025 12:30 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17.1 [stable] is released!

*) bgp - improved stability;
What does it mean exactly? What is the scenario that has been fixed?
by pe1chl
Fri Jan 31, 2025 12:27 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

The "LAN devices receive adversed IPv6 addresses from all VLANs" is that referring to Windows devices that are on ports with tagged VLANs present?
As that is a Windows bug, has nothing to do with RouterOS.
by pe1chl
Thu Jan 30, 2025 10:19 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

You can compare the ipv4 firewall....
by pe1chl
Thu Jan 30, 2025 9:37 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

You can display the defconf using: /system/default-configuration/print
by pe1chl
Thu Jan 30, 2025 5:44 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17 [stable] is released!

The question is: was the method before the "new method" documented? Probably it was a "known" method, apparently someone was able to write an independent mac-telnet program that worked. And now that no longer works. Still, "security by obscurity" is not a method that i...
by pe1chl
Thu Jan 30, 2025 4:25 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17 [stable] is released!

We only make changes that improve security of the users, none of those changes are to actively deny 3rd party OSes @normis! So good to see you out and about. I find your reassurances both credible and compelling. Thank you, Well, "improving security of the users" by making changes and the...
by pe1chl
Wed Jan 29, 2025 7:35 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

I am still hoping for a solution where defconf for the firewall can be applied to an existing router... some command that removes the firewall config and reloads it from defconf, if only as a commandline script. So far none of changes in firewall defconf was ever applied when upgrading ROS. So I do...
by pe1chl
Wed Jan 29, 2025 2:20 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

But noticed "cloud" or "file-share" are not selectable in device-mode. If the whole of idea was minimizing the attack surface, we're already off to some inconsistency ;). I think device-mode was a knee-jerk reaction to some bad publicity about MikroTik routers being compromised ...
by pe1chl
Wed Jan 29, 2025 12:24 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

Please make the setting for "inline comments" a 3-state: either not inline (separate line) or inline with the option to have it either at the beginning (as it is now) or at the end of the line (as it is in winbox 3) by default. Of course one can always move it afterwards, but having to do ...
by pe1chl
Wed Jan 29, 2025 12:16 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Please add fasttrack ipv6 in defconf Not saying it's not already ... but defconf is only applied when device is reset to factory defaults (where "factory" part is a bit misleading because it's not config applied in factory when manufacturing device, it's config set as default in any parti...
by pe1chl
Wed Jan 29, 2025 12:11 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

I believe the snmp error about OID not increasing was occurring a few releases back when snmp routes support was first introduced. Rerunning snmpwalk got stuck and eventually timed out, and rerunning it again it returned the same error. This router and others that have had this behavior are being m...
by pe1chl
Wed Jan 29, 2025 11:54 am
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 1401

Re: IPsec tunnels without known remote IP

Well, in the solution I use now (as suggested above by sindy) that issue doesn't actually occur, because all the policies are configured as templates and they only become active policies when the peer has connected. I think I now have it working correctly and am working with more knowledgeable users...
by pe1chl
Tue Jan 28, 2025 11:42 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

I agree, but I also want to stress that loading 4 full tables on an internet border gateway is not the only use-case for BGP.
by pe1chl
Tue Jan 28, 2025 10:19 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Ok I have been using RouterOS only from version ~6.29 and I was impressed with how BGP/BFD worked back then. With v7 there initially was the problem of "no BFD" and "buggy filters", but that seems to have been resolved by now. Unfortunately it now longer does its basic function: ...
by pe1chl
Tue Jan 28, 2025 5:36 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

That may be true, but before they used a standard BGP implementation and Linux routing, and in v7 it was replaced by in-house written code and frankly for me it has only caused trouble. I can understand how they were motivated by things like having a 72-core flagship router utilizing only a single c...
by pe1chl
Tue Jan 28, 2025 11:19 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Mikrotik have a significantly larger team of developers working on RouterOS core functionality now than they did in the RouterOS v6 to v7 transition phase Where do you have that info from? Has there been some announcement that I missed? I still get the perception that the number of developers limit...
by pe1chl
Mon Jan 27, 2025 11:57 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

You will probably have to do your own tests, as it worked for me in 7.15 already... also make sure your client isn't broken, like WinPE is!
(an issue in that version is that it advertises deprecated prefixes as deprecated forever, did not test that with 7.18beta yet)
by pe1chl
Mon Jan 27, 2025 10:39 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17 [stable] is released!

The problem with device-mode is not that "no router has all features". You can simply enable all features on all your routers. The problem is that it requires physical access to enable a feature, and there is no possibility to enable a feature before you upgrade (and lose access to the fea...
by pe1chl
Mon Jan 27, 2025 9:17 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 1401

Re: IPsec tunnels without known remote IP

Well, it is usually possible to configure the policy, so that should not really be an issue. W.r.t. the routing: unfortunately it is not that simple. I need to announce the active routes (active IPsec tunnels) on BGP. This server is running in a separate CHR from the core router, and the tunnels can...
by pe1chl
Mon Jan 27, 2025 7:15 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 1401

Re: IPsec tunnels without known remote IP

On Mikrotik acting as a server, you can have multiple /ip ipsec identity items attached to a single peer with address=::/0 , one per actual peer, that match by any remote-id other than IP address. For each said identity, you define a separate /ip ipsec policy group and set the policy-template-group...
by pe1chl
Mon Jan 27, 2025 3:11 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 1401

Re: IPsec tunnels without known remote IP

Ok that is good to know, I feared it would be impossible there too because RouterOS probably uses it...
by pe1chl
Mon Jan 27, 2025 2:24 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 1401

Re: IPsec tunnels without known remote IP

I have to try that solution with a group, but I have already tried to have a single defined peer with multiple identities, and that seemed to work but it breaks down when more than one peer connects at the same time. I will try with the group. Normally we use tunnels (either GRE, GRE/IPsec, or L2TP/...
by pe1chl
Mon Jan 27, 2025 1:58 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 1401

Re: IPsec tunnels without known remote IP

No it is not practical to register remote locations in DNS. It is for the hobby network, not for the company, and the remote users are of varying skills. What I need is a solution where the remote can configure their router or Raspberry Pi or whatever and then get their subnet IP-tunneled. This is w...
by pe1chl
Mon Jan 27, 2025 12:04 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 1401

IPsec tunnels without known remote IP

I am trying to setup an IPsec tunnel server that allows remote systems without previously known public IP (or dynamic IP) to connect, and to get a subnet tunneled to them. There may be like 50 remote systems, each with their own fqdn identity and PSK. In the past I got that working using "racoo...
by pe1chl
Mon Jan 27, 2025 11:51 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

I add dummy lines to the firewall this way:
/ip firewall filter
add action=log chain=-------- comment=-------------
(I use these as separators between different chains)
by pe1chl
Mon Jan 27, 2025 10:42 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Yes, there also is a strange problem where on multiple links between the same two routers (e.g. multiple tunnels over different networks) the prefixes received are not stored in the table for all of the links. So it is difficult to achieve redundancy. Sometimes it works, but later when one of the se...
by pe1chl
Sun Jan 26, 2025 8:16 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

It is not the only problem... I upgraded from 7.16 to 7.18beta and I had the default and an additional template for BGP, but there are issues with the default that I could solve by creating an additional template (same settings as the modified default) and using that. I changed the default back to o...
by pe1chl
Sun Jan 26, 2025 7:45 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17 [stable] is released!

The default config creates a bridge and it has the admin-mac set correctly.
You should normally not create any additional bridges! The VLANs can (now) be added on the single bridge.
Open a new topic with your specific requirements and/or look in the existing topics about bridge and VLAN!
by pe1chl
Sun Jan 26, 2025 7:28 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

The whole concept of templates is riddled with bugs. Another one is that winbox will not keep inheritance of parameters from templates, it will just copy them (e.g. into the connection).
It is best to rely as little as possible on them.
by pe1chl
Sun Jan 26, 2025 7:25 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17 [stable] is released!

You need to set the admin-mac= parameter to the MAC of the bridge.
The default config does that automatically but apparently you have tinkered with it.
by pe1chl
Sun Jan 26, 2025 12:17 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

No reason? I show you how must be coded corectly to avoid use scripting style that casually works... The missing "" are not only the problem, expect broken it again on future versions.... Actually I think putting a ; at the end of each line is not "useless" but is a style that p...
by pe1chl
Sat Jan 25, 2025 4:39 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17 [stable] is released!

Well I am not running 7.17 but I am testing 7.18beta2 and it shows that "syn flood" error for port 53 (DNS) once after every reboot, however when I later try the port 53 answers as normal.
So there must be more than that going on.
by pe1chl
Sat Jan 25, 2025 4:25 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17 [stable] is released!

I have a similar issue like i4ko: One device tries to connect to our server with a bunch of packets, because it want to establish a couple of tunnels. The 7.17 (and 7.16.2 too) version detects a TCP syn flood and shuts down any tcp syn ack traffic on that interface (Log message "possible SYN f...
by pe1chl
Sat Jan 25, 2025 1:40 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17 [stable] is released!

OF COURSE that does not work when DHCP Snooping is enabled!
DHCP Snooping is an active technique to avoid the problem of Rogue DHCP servers.
You would not use both at the same time...
by pe1chl
Sat Jan 25, 2025 11:18 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

I am just reporting that route table retrieval via SNMP is broken, not looking for alternative solutions.
by pe1chl
Fri Jan 24, 2025 4:23 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Brilliant support received today from Mikrotik. Problem resolved.
Useless to post that here when you do not include how it was resolved...
by pe1chl
Fri Jan 24, 2025 3:18 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17 [stable] is released!

I have suggested before that the changelog should be changed to a link to a site, where additional info can be provided. E.g. a link to relevant documentation in the manual (help site), a mouseover tip that explains the items in slightly more detail, and information like the release where a fixed pr...
by pe1chl
Fri Jan 24, 2025 3:11 pm
Forum: Announcements
Topic: Newsletter #121 | October 2024
Replies: 58
Views: 12537

Re: Newsletter #121 | October 2024

Also note that "Gigabit PHY" is NOT a switch! It basically is the electronics between a low-level CPU signal and the wires in the UTP. It works at L1.
It does not have any L2 or L3 functionality, as a switch chip may have. Switching is done inside the SoC here (as shown in the diagram).
by pe1chl
Fri Jan 24, 2025 3:08 pm
Forum: General
Topic: Which use cases for CCR2004-1G-2XS-PCIe ?
Replies: 39
Views: 8908

Re: Which use cases for CCR2004-1G-2XS-PCIe ?

Indeed I was once considering to use it in ESXi servers, with a short UTP from the RJ45 to the iLO port and internet feed via the SFP. But no ESXi support (of course we are now phasing out ESXi so that could be replaced with Linux) and also no clarity if it could be powered and running when the main...
by pe1chl
Fri Jan 24, 2025 2:30 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

No, all our monitoring is done using SNMP. I also do not like that each and every poll results in a log line.
by pe1chl
Fri Jan 24, 2025 2:28 pm
Forum: General
Topic: Which use cases for CCR2004-1G-2XS-PCIe ?
Replies: 39
Views: 8908

Re: Which use cases for CCR2004-1G-2XS-PCIe ?

Not much is known about this card... I also asked once if it has to be in a PCIe bus or if you could plug it into an extender card and supply only power.
No answer.
by pe1chl
Fri Jan 24, 2025 2:03 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

On one of our RB5009UPr+S+ I get the following irregular log messages: 2025-01-24T11:22:27+01:00 MikroTik ether1 detected poe-out status: voltage_on_poe-in 2025-01-24T11:22:28+01:00 MikroTik ether1 detected poe-out status: disabled 2025-01-24T11:28:29+01:00 MikroTik ether2 detected poe-out status: v...
by pe1chl
Fri Jan 24, 2025 1:52 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Retrieving route table via SNMP (snmpnetstat -v2c -c public -Cn -Cr router-IP) no longer returns the complete routing table.
Also, when there are multiple routing tables, it still ends up in a loop (existing problem).
by pe1chl
Fri Jan 24, 2025 12:01 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

The BGP situation appears to be improved, but I am still hunting a gremlin. What happened: my home router has 2 templates for 2 different networks (different AS, different routing table, different bgp-networks), one in default and one added template. The routers at work just have the default templat...
by pe1chl
Thu Jan 23, 2025 9:55 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Maybe the statement "Optimal nand stability requires a backup-routerboot upgrade" has to be explained. Given the fact that a backup-routerboot upgrade is impossible, what is the risk? Is there a risk when running, when booting, when using the backup booter, or all of these? I am not going ...
by pe1chl
Thu Jan 23, 2025 9:42 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

That is of course completely impractical. One cannot install an arbitrary RouterBOOT version, and the maintainers decided to change the RouterBOOT version for each and every RouterOS version, for whatever stupid reason... This package has to be updated to current RouterBOOT version (= the current Ro...
by pe1chl
Thu Jan 23, 2025 9:32 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

When upgrading a RB951G-2HnD and logging in to the commandline I got this story: 2025-01-23 20:11:32 system,info,critical Optimal nand stability requires a backup-routerboot upgrade.\r 2025-01-23 20:11:32 system,info,critical Universal package can be found here:\r 2025-01-23 20:11:32 system,info,cri...
by pe1chl
Thu Jan 23, 2025 5:34 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Thanks! What I mean is the deviceEventClassId field that I have seen in some examples, but apparently does not yet exist in RouterOS. It probably requires "changes all over the software" to add that, and it would be nice if it would appear in non-CEF messages as well. (in the text or as a ...
by pe1chl
Thu Jan 23, 2025 3:48 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Also in the "logging" category: could we get a log message when the state of a route with check-gateway option changes (up or down)?
I enabled all "route" messages but there does not appear to be a message for that, other than during initial establishment.
by pe1chl
Thu Jan 23, 2025 3:46 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

I am happy to notice that the "regex" match in Logging Rules was added! (actually in 7.17 but I skipped that release)
In the category "it is never good enough": could we get a "not" option for that (the familiar box in which a ! can be clicked)?
by pe1chl
Thu Jan 23, 2025 2:55 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Well I skipped 7.17 because of that, but now I am testing this beta because it fixes a BGP problem (still have to test if it fixes all problems)... Now I find that by default "partitions" mode is OFF but I still can switch between partitions and copy active to backup, so it is not so bad a...
by pe1chl
Thu Jan 23, 2025 11:17 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

I'm not familiar with that CEF format, but isn't there supposed to be a unique message identifier as well? Or does CEF not specify that?
by pe1chl
Wed Jan 22, 2025 2:19 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

It would be nice to have REST API as a separate service too, that you can enable without allowing webfig...
by pe1chl
Wed Jan 22, 2025 11:53 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

Everything will be back to normal after upgrading RB firmware to 7.18beta. Not possible on CHR. Simple reboot does the trick as well (just verified on wAP AC). There is no "issue", it is the new normal. It says it shows the available packages after a "check for updates", and app...
by pe1chl
Tue Jan 21, 2025 9:14 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

On this above, what modems/devices support these eSIM commands?
Most likely some device that still is in development...
We can still hope there will be more 5G client devices :-)
by pe1chl
Tue Jan 21, 2025 9:10 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17 [stable] is released!

TLDR: ROS DNS forwarder should not switch upstream DNS server just because a single request was answered with status SERVFAIL, because SERVFAIL not necessarily indicates a problem with the specific DNS server. A "good" way to handle this (this is how bind9 does it) is to keep a rolling av...
by pe1chl
Tue Jan 21, 2025 8:25 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 535
Views: 98286

Re: v7.18beta [testing] is released!

*) system - added option to list and install available packages (after using "check-for-updates");
Oh that is great! Have been asking for that / suggesting it for ages...
Now get on with it and split off some niche functions/applications into separate packages again!
by pe1chl
Tue Jan 21, 2025 12:12 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17 [stable] is released!

In CLI Responder parameter for Wireguard peer renamed to "responder" and was "is-responder" in previous versions. So some exported configs will produce syntax error You should understand in general that while RouterOS does automatically convert configuration when you upgrade (an...
by pe1chl
Mon Jan 20, 2025 4:21 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

hI, In dark mode, why text is in gray and not white, it's not enough contrasted for some people. I think, there should be a separate color settings window, that will allow to select a color for each interface element (fonts, backgrounds, lines, headers, window titles and so on). It's hard to fullfi...
by pe1chl
Sun Jan 19, 2025 1:08 pm
Forum: General
Topic: How to perform thorough data link filtering?
Replies: 9
Views: 1209

Re: How to perform thorough data link filtering?

Is anything required for these commands to function after reboot or am I supposed to enter them each time after reboot? I suggest you first use the default settings, make your self familiar with RouterOS a bit more, maybe read some of the docs, and once you know the answer to such generic questions...
by pe1chl
Sat Jan 18, 2025 11:13 am
Forum: General
Topic: How to perform thorough data link filtering?
Replies: 9
Views: 1209

Re: How to perform thorough data link filtering?

It would also be great if there was some layer 2 filtering (aside from ARP) for WAN port, but EBTables is LAN-only and doesn't filter WAN. You can just add another bridge, put your WAN port in it, and move the WAN port config (IP address etc) from the WAN port to that bridge. Then you can apply bri...
by pe1chl
Fri Jan 17, 2025 7:29 pm
Forum: General
Topic: Ether1 (NetInstall) port - danger for WAN?
Replies: 14
Views: 1286

Re: Ether1 (NetInstall) port - danger for WAN?

Yes, but who has installed 7.17? I probably never will...
Before that, an admin user could set the "try ethernet once" mode and reboot, but even then it would not work on a typical internet connection (at least here, it is all PPPoE)
by pe1chl
Fri Jan 17, 2025 6:18 pm
Forum: General
Topic: Ether1 (NetInstall) port - danger for WAN?
Replies: 14
Views: 1286

Re: Ether1 (NetInstall) port - danger for WAN?

Ok but even with a flat L2 network the "hacker" must be in the same L2 space (which means at the ISP or maybe in the same street in some cases) and it cannot be "a Russian hacker" (over here the media think that all hackers are Russian) working from home.
by pe1chl
Fri Jan 17, 2025 4:15 pm
Forum: Scripting
Topic: Copy comments from leases to ARP
Replies: 1
Views: 686

Re: Copy comments from leases to ARP

You can only set comments on static entries.
So that presumes you have entered those ARP entries manually.
Having them set by the DHCP server ("add ARP for leases") does not count, because then the ARP entries are still considered Dynamic even when the lease is static.
by pe1chl
Fri Jan 17, 2025 4:13 pm
Forum: General
Topic: How to perform thorough data link filtering?
Replies: 9
Views: 1209

Re: How to perform thorough data link filtering?

What is wrong with using "bridge filter", which probably indeed will map to ebtables, for that?
by pe1chl
Fri Jan 17, 2025 4:10 pm
Forum: General
Topic: Ether1 (NetInstall) port - danger for WAN?
Replies: 14
Views: 1286

Re: Ether1 (NetInstall) port - danger for WAN?

It can only be an issue when: - your WAN is actually a plain L2 link to the ISP network and there could be someone on the other side who can connect a machine with netinstall to that - they already know your credentials so they can log in to your router and set "boot ethernet once" and the...
by pe1chl
Fri Jan 17, 2025 4:03 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17 [stable] is released!

upgrade failed, free 9 kB of kernel disk space First they have to figure out what does this message actually mean... Maybe on some devices there is a separate partition for /boot ? That used to be required/customary on some Linux filesystems or disk devices, to guarantee that the boot code was alwa...
by pe1chl
Fri Jan 17, 2025 3:20 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17 [stable] is released!

Due to a chip issue which reports board temperature MikroTik decided to remove this parameter from health. The questions was "WHY?" What is the chip doing to cause this decision? Sometimes the reported board temperature is ridiculously high, I have seen that in one of our devices (while o...
by pe1chl
Fri Jan 17, 2025 3:17 pm
Forum: General
Topic: Logging prefix is a mess SUP-105353 SUP-144261. Waiting for MT to support RFC 5424
Replies: 44
Views: 14522

Re: Logging prefix is a mess SUP-105353 SUP-144261. Waiting for MT to support RFC 5424

Well, I still hope there will also be some unique message code ("topic") for each and every different message that can be logged by RouterOS. As it is now, there are too many different messages grouped under the same topic, and filtering is difficult. (also because the system logging rules...
by pe1chl
Thu Jan 16, 2025 9:49 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17 [stable] is released!

Thoughts anyone? EoIP is a connectionless protocol, there is no "connection that is closing". However, as with any tunnel protocol, there is the risk of creating a loop where encapsulated traffic is again encapsulated. Maybe the circumstances have changed due to the version upgrade, like ...
by pe1chl
Thu Jan 16, 2025 9:46 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17 [stable] is released!

Wow... And how about me that, using semantic versioning as a reference, I was thinking that Stable could mean that the software manufacturer should only release as stable code that is free of any known bugs. I think I'll review a little more about versioning standards. It would be desirable when it...
by pe1chl
Thu Jan 16, 2025 8:42 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 587
Views: 124078

Re: v7.17 [stable] is released!

"v7 stable" NOT STABLE. Remember that "stable" in software releases means: "here you have a version that will remain for a while, we will not release a new version every week or two, so you can install this and won't have to update it immediately". The stability refers...
by pe1chl
Thu Jan 16, 2025 8:33 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

Such a message can also mean that the router is very busy doing something else or the link to the router is slow.
Apparently when the connection cannot be established correctly it will issue some generic message.
by pe1chl
Thu Jan 16, 2025 3:43 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 277
Views: 159910

Re: Advanced Routing Failover without Scripting

I tested on a debug router but it isn't really a viable solution. There are messages logged but they all have topic route,debug,calc and there is no specific message about the recursive route that goes up/down, only information about the reachability of a specific address occurring somewhere in a ch...
by pe1chl
Thu Jan 16, 2025 2:22 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

Still I think it is a shame that there is total silence from MikroTik about the BGP issues, both on this topic and from support. (I have an open ticket) I wouldn’t go as far as calling it a shame, but it is certainly irritating. Let’s hope for the best and that it gets fixed soon. Perhaps if someon...
by pe1chl
Thu Jan 16, 2025 11:28 am
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

I backed my most problematic router off from 7.16.2 to 7.15.3 and the BGP problems seem to have stopped. I saw some appear on other routers due to a bouncing session due to faulty BFD, and so I anticipate moving them all to 7.15.3 (BGP cores and reflectors). Thanks for confirming that! I was quite ...
by pe1chl
Wed Jan 15, 2025 7:46 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 277
Views: 159910

Re: Advanced Routing Failover without Scripting

But does that include up/down messages for routes with check-gateway? I am asking this in the context of this topic, i.e. using recursive routes with ping check to implement failover. Failover seems to work but one never knows if it is happening... Indeed I fear that this topic will include all kind...
by pe1chl
Wed Jan 15, 2025 5:07 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

Please consider to offload "filter" to the router instead of handling it in the UI. When selecting a filter, all the items are still downloaded from the router and then locally filtered. Instead, the items could be fetched from the router specifying a filter condition, and only the relevan...
by pe1chl
Wed Jan 15, 2025 12:33 pm
Forum: RouterOS beta
Topic: Process "routing policy configuration" high cpu
Replies: 7
Views: 4850

Re: Process "routing policy configuration" high cpu

There is now a new winbox in betatest but I do not know if it has improvements in this area. I agree with you that the route display in traditional winbox does not work correctly now, not only it can really load the router but also it sometimes lags in what it displays compared to what is really in ...
by pe1chl
Wed Jan 15, 2025 12:06 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

I would like to have logging of state changes of routes with "check-gateway".
I.e. when the state of these routes changes (up to down or down to up) a message is logged with at least the dst-address, gateway, and routing-table.
by pe1chl
Wed Jan 15, 2025 12:01 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 277
Views: 159910

Re: Advanced Routing Failover without Scripting

I would like to have logging of state changes of routes with "check-gateway". I.e. when the state of these routes changes (up to down or down to up) a message is logged with at least the dst-address, gateway, and routing-table. Right now, it is largely invisible how failover solutions like...
by pe1chl
Wed Jan 15, 2025 11:57 am
Forum: General
Topic: Feature requests
Replies: 1807
Views: 700621

Re: Feature requests

I would like to have logging of state changes of routes with "check-gateway".
I.e. when the state of these routes changes (up to down or down to up) a message is logged with at least the dst-address, gateway, and routing-table.
by pe1chl
Wed Jan 15, 2025 11:51 am
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

@EdPa is there any chance that SUP-172111 will be fixed before the stable release? hAP ac2 reboots itseft with SMB transfers also with 7.17rc7 ( more info ). Thanks Unfortunately I confirm that it is due to a hardware limit (low RAM) of the hAP ac2 and not a problem of ROS 7.17. SMB works perfectly...
by pe1chl
Mon Jan 13, 2025 7:44 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

Well, there are even bugs in the basic BGP function, confirmed by others and some by MikroTik too: - when a BGP session closes, at random some other (or all) session closes and has to be re-opened - when a BGP session is established, no routes are exchanged until the keepalive timer elapses for the ...
by pe1chl
Mon Jan 13, 2025 4:38 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

/interface bridge
add admin-mac=E1:E1:E1:E1:E1:E1
Your admin-MAC is invalid!
The lower bit of the first byte must be zero.
by pe1chl
Mon Jan 13, 2025 11:58 am
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

@oskarsk is there anyone working on the BGP issues at the moment?
by pe1chl
Mon Jan 13, 2025 11:45 am
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

well it seems we have 2 groups of people... 1 that needs specific features which is only possible in new versions and other group that has all they need and just want stability.... there is no right answer here... Then there is people caught in the middle. We upgraded all our routers to 7.16(.x) an...
by pe1chl
Fri Jan 10, 2025 3:20 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

But on the RB5009 since the beginning I have been unable to turn on the IGMP Snooping feature, and not only because of the VLANs. Turning it on and IPv6 RA/ND stop working. I had such an issue for quite some time on one of my devices, a hAP ac2 used as a second AP in bridge mode, and at some point ...
by pe1chl
Fri Jan 10, 2025 12:43 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

I learned the "monkey test lesson" by enabling IGMP-snooping and multicast querier some months ago. It introduced extreme latency on my whole network I could not explain - just to finally determining these 2 bridge settings as the issue. I configured IGMP snooping on our work network (swi...
by pe1chl
Fri Jan 10, 2025 12:11 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

It could be considered a lesson "do not enable each and every feature just because it looks cool"...
DHCP snooping can be useful in large networks with access for guests and other BYOD equipment, but on a home network it really isn't worth the (potential) trouble.
by pe1chl
Wed Jan 08, 2025 11:24 am
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

I have always wondered why the IP fragmentation code in network stacks splits a too-large packet into a maximal size packet and a small remainder... IMHO that only increases the risk that further fragmentation is required further down the path when another smaller MTU is encountered. Back when I mai...
by pe1chl
Tue Jan 07, 2025 5:13 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

Did you by chance upgrade the Unifi application to version 9.x? I see others reporting RADIUS problems for that version, unclear what the problem is.
by pe1chl
Mon Jan 06, 2025 5:01 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

But as I understand it, this mode is not compatible with wpa3-psk? PPSK functionality relies on a weakness in WPA2. It is not possible in WPA3. (you will find that it is not available on other manufacturer's devices either) A better solution for this functionality, which works with WPA3 as well, is...
by pe1chl
Mon Jan 06, 2025 4:27 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

When tracing to a file in ramdisk, I noticed that in the Files window in winbox the size at some point is shown as 252.6MB and the file date no longer changes, but when stopping the trace and downloading the file it is a 329MB file. It appears it was a "one time" fluke. Probably it would ...
by pe1chl
Mon Jan 06, 2025 3:00 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

When tracing to a file in ramdisk, I noticed that in the Files window in winbox the size at some point is shown as 252.6MB and the file date no longer changes, but when stopping the trace and downloading the file it is a 329MB file. It appears it was a "one time" fluke. Probably it would ...
by pe1chl
Sun Jan 05, 2025 10:50 pm
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 86
Views: 59242

Re: Newsletter #122 | December 2024

As I wrote above, it used to be available but apparently it was pulled. And I can understand why. Fortunately, here the fiber providers mostly provide the PON in a NTU box that converts fiber to RJ45 ethernet. You can connect your own router where you have to configure PPPoE over VLAN. The only thin...
by pe1chl
Sun Jan 05, 2025 4:49 pm
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 86
Views: 59242

Re: Newsletter #122 | December 2024

That is not called asynchronous, that is called asymmetric! No idea why so often people make up the term asynchronous for "different down and up speeds", it really has nothing to do with that. Back to the "MikroTik and PON" topic: there used to be a MikroTik PON SFP, but it is no...
by pe1chl
Mon Dec 30, 2024 5:27 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

When tracing to a file in ramdisk, I noticed that in the Files window in winbox the size at some point is shown as 252.6MB and the file date no longer changes, but when stopping the trace and downloading the file it is a 329MB file. I removed the file and restarted the trace to see if it is reproduc...
by pe1chl
Sun Dec 29, 2024 8:47 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

You need to make room or netinstall that device to clear leftovers from previous versions. Well, "out of memory" probably refers to RAM, not flash. A netinstall can be tried, but it seems more likely there is a memory leak in one of the components he is using. Or due to a script e.g. that...
by pe1chl
Sun Dec 29, 2024 8:43 pm
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 86
Views: 59242

Re: Newsletter #122 | December 2024

PON is used to limit the amount of equipment in street cabinets, which reduces costs. It also allows some overbooking of the local access capacity, e.g. the ISP can offer several multi-GBit user connections over a single XG(S)-PON. PPPoE is often used in networks where the access network allows subs...
by pe1chl
Fri Dec 27, 2024 10:56 pm
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 86
Views: 59242

Re: Newsletter #122 | December 2024

Yes. But highlights the need for better communication about their roadmap. i.e. If they giving up on the US market, that be good to know – none of new LTE products have US variants. The new cAPax+LTE is actually a nice offering – but worthless here, just like all the previous new LTE devices for pa...
by pe1chl
Fri Dec 27, 2024 3:26 pm
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 86
Views: 59242

Re: Newsletter #122 | December 2024

Are we getting yet another offtopic monologue in the Newsletter topic?
by pe1chl
Mon Dec 23, 2024 7:55 pm
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 86
Views: 59242

Re: Newsletter #122 | December 2024

Maybe for some of those fast internet connections a device like the CCR2004-1G-2XS-PCIe as a standalone router (2xSFP28 + 1xGbe) would be useful... could be used with a suitable switch depending on the user's requirements. Unfortunately it is not clear if the CCR2004-1G-2XS-PCIe could function in a ...
by pe1chl
Mon Dec 23, 2024 7:31 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

a hAP AC2 is not a NAS!
by pe1chl
Sat Dec 21, 2024 2:41 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

Ok I just wanted to make sure that it is not a simple issue related to the fragmenting of packets... I use UniFi APs with EAP and RADIUS, but not with MikroTik usermanager (I use FreeRadius). I would not expect that IP fragmentation would be a problem. Long messages are quite usual in these scenario...
by pe1chl
Sat Dec 21, 2024 12:08 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

Make sure that you don't have some firewall somewhere that drops the 2nd fragment of the transmission because it does not have a valid UDP header (with permitted ports in the firewall)....
Can you send a long ping to your APs? (without "do not fragment" option, of course)
by pe1chl
Sat Dec 21, 2024 12:02 pm
Forum: General
Topic: Disappearing IPv6 configuration?
Replies: 5
Views: 1748

Re: Disappearing IPv6 configuration?

Next time, partition the device (2 partitions), and before you upgrade copy the active partition to the other one. When the upgrade fails, select the other partition as active and reboot and you have your original version and config back. (when it does not boot at all, you can powercycle it during b...
by pe1chl
Fri Dec 20, 2024 7:02 pm
Forum: RouterBOARD hardware
Topic: 5009 version with wifi ?
Replies: 63
Views: 7199

Re: 5009 version with wifi ?

When you want the best WiFi performance in a home router, MikroTik is not the place to be. The usual suppliers of ISP routers like AVM have more attractive products for that. Usually the plain (NAT)routing of those devices is faster than all but the most high-end MikroTik routers as well. When you h...
by pe1chl
Fri Dec 20, 2024 2:11 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

It would be nice when there was a list of known problems in a stable release, possibly later updated with new known problems introduced with the release. There could be a link to a webpage that has such info and that is updated when new issues are recognized and planned to be fixed, in what version....
by pe1chl
Fri Dec 20, 2024 11:36 am
Forum: RouterBOARD hardware
Topic: 5009 version with wifi ?
Replies: 63
Views: 7199

Re: 5009 version with wifi ?

Another problem with the ISP's router is that it has no WiFi power management. Normally I set it to the minimum.
MikroTik does not have that either!
In fact TPC (Transmitter Power Control) is mandatory on DFS channels, but almost nobody implements it.
by pe1chl
Thu Dec 19, 2024 3:45 pm
Forum: RouterBOARD hardware
Topic: 5009 version with wifi ?
Replies: 63
Views: 7199

Re: 5009 version with wifi ?

The problem with spectrum is that they don't make it any more. There is a fixed amount, and it has been allocated to all kinds of services. While some services can release it, e.g. where there were microwave links between towers for professional use like telephony and TV distribution that now largel...
by pe1chl
Thu Dec 19, 2024 2:57 pm
Forum: RouterBOARD hardware
Topic: 5009 version with wifi ?
Replies: 63
Views: 7199

Re: 5009 version with wifi ?

The 6GHz band actually is even more troublesome than 5 GHz...
Over here it allows only very low power, outdoor installations are prohibited.
(of course for the same reason: it was already licensed to other users)
by pe1chl
Wed Dec 18, 2024 3:39 pm
Forum: RouterBOARD hardware
Topic: 5009 version with wifi ?
Replies: 63
Views: 7199

Re: 5009 version with wifi ?

You cannot make such blanket statements. It entirely depends on the country and the ISPs. In some places that were behind on broadband internet, fiber has been deployed to all homes and sometimes is offered at very low prices to consumers. In other places where broadband was deployed going along the...
by pe1chl
Wed Dec 18, 2024 1:09 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

Hopefully there will be a round of BGP fixes in the 7.18 betas so we have something to look forward to...
(there is of course no hope for the bugs to be fixed in 7.17 as there isn't any bgp changelog line...)
by pe1chl
Tue Dec 17, 2024 10:24 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

While perhaps the older ac chipset cannot directly handle VLAN in hardware... It is a nice try, but the UBNT accesspoints I use at work use the same QCA9984 chip as is used in older MikroTik AC hardware, but it fully supports VLAN assignment per client... and I don't think that would be a software ...
by pe1chl
Tue Dec 17, 2024 10:16 pm
Forum: RouterBOARD hardware
Topic: 5009 version with wifi ?
Replies: 63
Views: 7199

Re: 5009 version with wifi ?

CRS = switch. It has routing capabilities but not much. You're most likely looking for CCR then. And then prices go up up up. E.g. CCR2004-16G-2S+ 16 Gb ethernet ports, 2SFP+ cages, PLENTY of power. No Wifi. No passive cooling. I do have a CCR2004-16G-2S+ in use at work, and maybe I would consider ...
by pe1chl
Tue Dec 17, 2024 5:36 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

The whole VLAN stuff still s*cks! Any reasonable WiFi network has the capability to assign a different VLAN to each client either via RADIUS or via access list rules. The AP network interface has to support tagged VLANs and the connected clients receive the assigned VLAN untagged, and that should no...
by pe1chl
Tue Dec 17, 2024 4:12 pm
Forum: RouterBOARD hardware
Topic: 5009 version with wifi ?
Replies: 63
Views: 7199

Re: 5009 version with wifi ?

First 2.5G switch has been released already a year ago. 8x 2.5Gb ethernet and 2x SFP+ ports. Not fanless though. https://mikrotik.com/product/crs310_8g_2s_in 10G switch, fanless: https://mikrotik.com/product/crs304_4xg_in Well, what I do not like about the switch products is the relatively small nu...
by pe1chl
Tue Dec 17, 2024 12:31 pm
Forum: RouterBOARD hardware
Topic: 5009 version with wifi ?
Replies: 63
Views: 7199

Re: 5009 version with wifi ?

MikroTik isn't really in 2.5G yet. Yes there are some devices with a single 2.5G port and an SFP that can do 2.5G, but what you really would want is a device like the 5009 but with several 2.5G (UTP) ports. And probably some switches too. And then for the router probably with wireless as well. They ...
by pe1chl
Tue Dec 17, 2024 12:27 pm
Forum: General
Topic: When the WAN network card is bound to multiple IPs, there is an issue with the source IP for system remote logging
Replies: 6
Views: 1395

Re: When the WAN network card is bound to multiple IPs, there is an issue with the source IP for system remote logging

That is "source address selection", it applies to outgoing packets (originating from the router) that do not have an explicitly set source address. What the topic is about is "the logging to network ignores the specified source address, that must be a bug". But I agree with @rpla...
by pe1chl
Fri Dec 13, 2024 2:48 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 231953

Re: v7.16.2 [stable] is released!

No, I don't have a test lab to do that. I do. if you're interested in cloning a sanitized version of your configs, I have four RB5009's and two CCR2004's racked up, with two more 5009's on the shelf. The important part of the config is like this: 1 CCR2004, 3 RB5009, 3 RB951G. The latter are leafno...
by pe1chl
Thu Dec 12, 2024 2:13 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 231953

Re: v7.16.2 [stable] is released!

Yes, but not me. Testing this requires a network of like 6 routers with tunnels between them and BGP running on it. So several locations with different IP addresses are required, 2 addresses at each location. We have that in production but we do not have a separate test environment that replicates i...
by pe1chl
Wed Dec 11, 2024 8:09 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 231953

Re: v7.16.2 [stable] is released!

No, I don't have a test lab to do that.
by pe1chl
Tue Dec 10, 2024 4:32 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 231953

Re: v7.16.2 [stable] is released!

Why???
by pe1chl
Mon Dec 09, 2024 11:56 am
Forum: General
Topic: Feature requests
Replies: 1807
Views: 700621

Re: Feature requests

absolutely. that script would need to have the lease variables exposed. The current DHCP scripts dont, you have to let the lease be created then match against it. The current DHCP lease script is called after an address has been assigned, which is fine when you want to use it to create a DNS entry,...
by pe1chl
Sun Dec 08, 2024 10:36 pm
Forum: General
Topic: Feature requests
Replies: 1807
Views: 700621

Re: Feature requests

I suggested that too. In fact I think it would be very nice when a DISCOVER-phase script was added that gets all parameters from the DHCP packet and can decide which lease time, which address pool and which option set are to be used (or "none" to ignore the request). It would cover many sp...
by pe1chl
Sun Dec 08, 2024 11:24 am
Forum: Forwarding Protocols
Topic: BGP ECMP (multipathing)
Replies: 77
Views: 47252

Re: BGP ECMP (multipathing)

It seems like BGP in general is a bit off the current attention hotspot... in 7.17rc there are no announced BGP changes at all, even though there are several new known bugs (introduced over the 7.15 .. 7.16 span) and of course some unimplemented features too.
by pe1chl
Sat Dec 07, 2024 11:10 am
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

Yes, that is quite low, my hAP ac2 runs with 1400 kB free at the moment, but it does not have wifi-qcom-ac installed. I noticed that the "Total HDD size" is now reported as 16.0 MiB while I am sure it was like 15.2 MiB before, so that has changed in some recent release. No idea if they rea...
by pe1chl
Thu Dec 05, 2024 3:09 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

On the other hand, it is not really MikroTik's task to work around the release and support cycle of other equipment... or the fact that people don't have money to renew the equipment they earlier have bought.
by pe1chl
Wed Dec 04, 2024 5:21 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 231953

Re: v7.16.2 [stable] is released!

What you described, would following the dns list by order be somewhat similar? It would be a step in that direction in my opinion Somewhat similar, but not the same. Usually you get several alternative DNS resolver addresses from your ISP, e.g. in my case 4 (2 IPv4, 2 IPv6), and you would want to l...
by pe1chl
Wed Dec 04, 2024 1:47 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 231953

Re: v7.16.2 [stable] is released!

Well, one can always wish for more advanced options. What I would like is to have groups of servers, and then at first the servers from the first group are used in some optimized way like I described, and only when all servers from the first group are failing to respond, servers from the second grou...
by pe1chl
Wed Dec 04, 2024 10:54 am
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

Causing a reboot just by copying a large file via SMB sounds like a big issue that should be fixed before reaching final. Well, for me it sounds like an irrelevant issue because a router is not an SMB server and the whole SMB function should not have been there... For me, the big problems in BGP sh...
by pe1chl
Wed Dec 04, 2024 10:52 am
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 231953

Re: v7.16.2 [stable] is released!

Is there a reason using standard DNS, the in use DNS server always ends up being Cloudflare? No matter which order I put the servers in, the DNS in use always ends up being Cloudflare within a few minutes of arranging them. Or by running the dns leak test. Why is Cloudflare preferred over any other...
by pe1chl
Tue Dec 03, 2024 10:23 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 231953

Re: v7.16.2 [stable] is released!

I have seen those issues in 7.16 as well: a single disconnected peer disconnects multiple or all peers at the same time, and routes via disconnected peers still appearing in the table. The first I was able to improve a bit by forcing all BGP handling into a single process (input.affinity=main output...
by pe1chl
Tue Dec 03, 2024 4:47 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 231953

Re: v7.16.2 [stable] is released!

It seems that in the 7.16 (and 7.16.x) versions BGP has become unreliable. Today we had some internet outages and the backup route config I have used for a long time starting with v6 simply no longer works. I have noticed it before and tried different things but never got it working reliably anymore...
by pe1chl
Tue Dec 03, 2024 4:37 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

it seems that in versions 7.17beta/rc there is some kind of problem that is actively consumes space on a flash on my ac2, I successfully used 7.16rcX for several months without errors, but after updating to 7.17rc2, less than a day later, dozens of saving errors began to appear Did you check space ...
by pe1chl
Sun Dec 01, 2024 1:36 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

Maybe one of the outside-MikroTik users who have found detailed information about how the system works could reveal some detail about that. I would expect that RouterOS has some tables of available commands and options and directives for the GUI (webfig/winbox) which are used by the generic command ...
by pe1chl
Fri Nov 29, 2024 6:27 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

Next time partition the router and copy partition before upgrade, then you can simply revert by switching partitions as long as the device isn't completely corrupted... partitioning is a great thing, but... it is not available everywhere, I wish to have it for CHR, but again... but... but... but......
by pe1chl
Fri Nov 29, 2024 3:24 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 231953

Re: v7.16.2 [stable] is released!

Ok I do not have that many peers on a 7.16 router. but I do see another problem: multiple routes to the same peer over different paths are not stored. do you see that as well? It worked fine before. E.g. we have peers with a GRE/IPsec, a GRE6/IPsec and a L2TP/IPsec tunnel (over LTE) between them for...
by pe1chl
Fri Nov 29, 2024 11:30 am
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 146659

Re: v7.17rc [testing] is released!

Next time partition the router and copy partition before upgrade, then you can simply revert by switching partitions as long as the device isn't completely corrupted...
by pe1chl
Fri Nov 29, 2024 11:27 am
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 231953

Re: v7.16.2 [stable] is released!

What is that BGP+BFD problem? I have some BGP problems but not BFD related...
by pe1chl
Fri Nov 22, 2024 5:01 pm
Forum: Forwarding Protocols
Topic: BGP Aggregate-Address alternative in Mikrotik
Replies: 18
Views: 7290

Re: BGP Aggregate-Address alternative in Mikrotik

Indeed. But of course you can write a script, and run it at the interval you like, that checks if your smaller subnet is reachable in the route table, and when it is not it disables the blackhole route. That will cause the aggregated route to no longer be advertised. It was possible to do that witho...
by pe1chl
Thu Nov 21, 2024 6:58 pm
Forum: Announcements
Topic: Newsletter #121 | October 2024
Replies: 58
Views: 12537

Re: Newsletter #121 | October 2024

Price Reduction Overhaul ??
by pe1chl
Thu Nov 21, 2024 12:20 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

Before I have suggested that sessions (now workspaces) would optionally be stored on the router itself. Of course there is the issue that the workspace is optimized for the resolution of the device and thus may be incompatible with another device, but still I think it would be useful when there is s...
by pe1chl
Wed Nov 20, 2024 6:01 pm
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 169
Views: 52201

Re: Feature Request: IPSEC Improvements

I can't imagine any major internet operators and distributors that MK has never discussed with them about VTI support.
Well, I can understand that. VTI is not something that internet operators would use.
It is something for customers. To connect to their cloud virtual machines, for example.
by pe1chl
Wed Nov 20, 2024 2:21 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 178246

Re: v7.17beta [testing] is released!

Why is BGP not getting any love?
There are several known problems in BGP yet no release notes about improvements...
by pe1chl
Fri Nov 15, 2024 4:36 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 178246

Re: v7.17beta [testing] is released!

Yes of course it should only update to versions that have been "stable" for a long time, and without modifying them. At the moment, a "beta" is promoted to "stable" and that is when everyone starts installing it and the bugs appear all over the place. So such a "cr...
by pe1chl
Fri Nov 15, 2024 2:16 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 178246

Re: v7.17beta [testing] is released!

even in this forum there are people who are asking why they have unrecognized accounts and unrecognized scripts in their devices, that are calling traffic generator, configuring proxy etc. even forum users make mistakes and let in people they did not intend to let in. I still wonder how many of the...
by pe1chl
Thu Nov 14, 2024 5:19 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

As I wrote above, I would like some new "save as new item" which is easier to use than first COPY, save that copy, and then still have the original open. E.g. in PHPMyAdmin, which performs similar actions as modifying a RouterOS config, you can select a database row, do "edit", y...
by pe1chl
Thu Nov 14, 2024 4:18 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

But just editing the copied rule, and saving it directly as active without prompt, is one of the great attractors of the "oh no" events. Those, when we click the "ok" button and immediately think "oh, no". That would not be a problem because the copied rule is the same...
by pe1chl
Thu Nov 14, 2024 12:17 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

I don't see the advantage of creating an entry in disabled status. You can always click DISABLE when that is what you want. Main advantage is that when duplicate is created in disabled state, there's no way that it could disrupt anything. You can edit it and then enable. It cannot disrupt anything ...
by pe1chl
Wed Nov 13, 2024 7:06 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

I don't see the advantage of creating an entry in disabled status. You can always click DISABLE when that is what you want.
by pe1chl
Wed Nov 13, 2024 12:20 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

Maybe a nice new feature in winbox would be a "save as new item" button which allows you to start editing something (not only a firewall rule) and then at the end decide that you in fact wanted to do a COPY, edit, and APPLY/SAVE instead?
by pe1chl
Wed Nov 13, 2024 12:17 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

Duplicating same rule below the original would hardly disrupt anything. Other choice would be to make duplicate initially disabled. Actually, COPY does not create a new rule at all. It only copies the data from an existing rule in a new form, where you can edit it, and only when you click OK or APP...
by pe1chl
Tue Nov 12, 2024 7:38 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

+1... just generate a .png and display it.
by pe1chl
Tue Nov 12, 2024 6:14 pm
Forum: General
Topic: Cannot mark routing for outgoing IPsec ISAKMP traffic
Replies: 0
Views: 1152

Cannot mark routing for outgoing IPsec ISAKMP traffic

I have a router with two internet connections, ISP1 and ISP2. There is a default route towards ISP1 in the main table, and additionally there are separate route tables for ISP1 and ISP2 with each a default route. There are mangle rules for prerouting and output which match on the statically assigned...
by pe1chl
Tue Nov 12, 2024 2:55 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

On Mac - If I copy an existing firewall rule, it is putting the copied rule right to the bottom of the list and not directly below it. I'm sire the previous v3 behaviour was to put it underneath but v4 is putting to the bottom. didn't half make me question myself earlier. Is this expected behaviour...
by pe1chl
Tue Nov 12, 2024 10:54 am
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 178246

Re: v7.17beta [testing] is released!

Up to a point. The botnet on that article was composed by high end routers (CCR1036, CCR1072, CCR2004, CCR2116). Those have no firewall or protections whatsoever - since they are professional models. Yeah, that's makes the focus on device-mode so ridiculous - when devices use insecure protocols by ...
by pe1chl
Sat Nov 09, 2024 11:03 am
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 178246

Re: v7.17beta [testing] is released!

Well, one thing is obvious: the issue you describe affects only you. Or else we would have seen many reports. I can only suggest that you /export your configuration ("/export show-sensitive file=anyname") and netinstall the router without default config and import that export connected via...
by pe1chl
Fri Nov 08, 2024 7:23 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 178246

Re: v7.17beta [testing] is released!

I think the intention was that with the new devicemode settings it would no longer be possible to change the "Boot device", not that an upgrade of the firmware would be blocked. Maybe auto-upgrade setting would need to be blocked, I'm not certain of that. But it isn't a good idea anymore t...
by pe1chl
Thu Nov 07, 2024 10:04 pm
Forum: General
Topic: Feature requests
Replies: 1807
Views: 700621

Re: Feature requests

I agree, it would certainly be useful when there was some location (MikroTik or not) where one could pull ready-made containers for RouterOS for often requested additions! Especially when Docker containers are often only available for amd64 architecture, and may not be tailored to RouterOS use. Ther...
by pe1chl
Thu Nov 07, 2024 1:56 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 178246

Re: v7.17beta [testing] is released!

When you have advanced requirements you may want to consider winbox v3.
by pe1chl
Thu Nov 07, 2024 12:23 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 178246

Re: v7.17beta [testing] is released!

Incompatibilities between WiFi access points and clients are something that every manufacturer is fighting with... The users ask for new features, better performance, more security, etc etc but expect that all their equipment, no matter if it is a brand new smartphone or a simple IoT device with an ...
by pe1chl
Wed Nov 06, 2024 2:18 pm
Forum: General
Topic: Loopback interface sending DHCP broadcasts [SOLVED]
Replies: 7
Views: 968

Re: Loopback interface sending DHCP broadcasts [SOLVED]

The addition of "detect internet" was an unfortunate decision some time ago, probably made in an attempt to make MikroTik routers easier to config (or even do full out-of-the-box automatic config). It basically failed to do so, and now what remains is mainly a nuisance. Unfortunately we ca...
by pe1chl
Tue Nov 05, 2024 5:25 pm
Forum: Beginner Basics
Topic: Why is there no decent security on FTP Server on MK?
Replies: 22
Views: 2230

Re: Why is there no decent security on FTP Server on MK?

They can easily roll out a OS version for the router and say that OS version xyz is the only OS supported for that specific device and the newer generations can use the NEWER versions of the OS that DOES include a SIMPLE feature like directory restrictions. I'd say that one of the very strong point...
by pe1chl
Tue Nov 05, 2024 5:11 pm
Forum: Beginner Basics
Topic: Testing mikrotik rb951g-2hnd with jperf and wifi Download over wifi is much slower than the upload
Replies: 4
Views: 1927

Re: Testing mikrotik rb951g-2hnd with jperf and wifi Download over wifi is much slower than the upload

The speeds shown in that screenshot are quite typical for the RB951G-2HnD.
When you are looking for high performance, get a new router with 2G+5G and AC or AX WiFi.
by pe1chl
Tue Nov 05, 2024 5:06 pm
Forum: Beginner Basics
Topic: Why is there no decent security on FTP Server on MK?
Replies: 22
Views: 2230

Re: Why is there no decent security on FTP Server on MK?

It's an easy excuse say "MT does not deal in file services" but the reality is that they DO offer File services on the router through the USB port and therefore if one service like SMB can implement it and PureFTP or ProFTP can all implement something like this, it stands to reason that c...
by pe1chl
Tue Nov 05, 2024 2:01 pm
Forum: General
Topic: CCR2004-1G-2XS-PCIe causes INSTANT host crash when it's rebooted
Replies: 24
Views: 5103

Re: CCR2004-1G-2XS-PCIe causes INSTANT host crash when it's rebooted

In that machine, can you turn power off in the server via ILO with the CCR2004 still powered via standby power?
by pe1chl
Mon Nov 04, 2024 5:21 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 178246

Re: v7.17beta [testing] is released!

This kind if "invalid" packets is caused by the connection tracking entry in the router already removed, and the system (or the remote) still sending related traffic. It can even cause leaking of internal addresses because in that case the corresponding NAT action isn't performed either. I...
by pe1chl
Mon Nov 04, 2024 2:29 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 178246

Re: v7.17beta [testing] is released!

Due to the number of fixes I updated from latest release 16.x to 17beta4. I am now seeing a lot (like thousands) of 'invalid' dropped packets on the firewall.
It helps to show a couple of example log lines. There are some different reasons why these appear.
by pe1chl
Mon Nov 04, 2024 2:28 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

For Mac users it started with macOS 11 about 4 years ago when this drastic "aesthetic user experience" change was introduced - item spacing on main menu bar and most window toolbars increased by almost 50%, most UI buttons lost their borders and all UI items lost their contrast. How this ...
by pe1chl
Sun Nov 03, 2024 11:54 am
Forum: General
Topic: IPSec VTI
Replies: 62
Views: 27212

Re: IPSec VTI

Any new information/feedback from mikrotik regarding this?
Yes, they told me it is not planned.
At the moment, there is no plan to add this functionality,., but we will see if it can be supported in the future.

That was in june 2024.
And that has been the status for at least 10 years now.
by pe1chl
Sat Nov 02, 2024 3:49 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

Current situation is not usable for people doing mobile work on laptops - not even when laptop has high resolution screen. Ruining exsiting well-designed GUIs to unusable low-contrast no-borders style is the hype of today's design. Winbox is not even the worst example of that. And probably the moti...
by pe1chl
Sat Nov 02, 2024 3:47 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

I'm just getting very frustrated with the numberpad enter key being some sort of a clear command instead of enter. 'ping 192.168.1.5 numbpad-enter' clears the command 'ping 192.168.1.5 reguar-enter' works fine. PLEASE FIX It works OK here (on Linux). It may depend on the OS or the configuration. I ...
by pe1chl
Fri Nov 01, 2024 4:27 pm
Forum: Beginner Basics
Topic: How to add automatic address range from single IP
Replies: 12
Views: 2345

Re: How to add automatic address range from single IP

Unless you have a fast internet connection with a large subnet and a slow network behind that, it is mostly a waste of time.
You better spend your time on securing your services e.g. not putting services like SSH, telnet, RDP, winbox etc open on internet.
by pe1chl
Fri Nov 01, 2024 12:24 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

... or get a wider screen. On my 2560x1440 screen where I run winbox 3 at about 80% of the screen width, I have no issues with log messages.
And of course, it is always best to put log messages in files and/or on a syslog server as well, where you can go back in history, use grep to find things, etc.
by pe1chl
Thu Oct 31, 2024 8:04 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 178246

Re: v7.17beta [testing] is released!

Did you ever test that working on older releases?
by pe1chl
Thu Oct 31, 2024 3:18 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 231953

Re: v7.16.1 [stable] is released!

How can i check the process tree to see what is taking up memory ? Unfortunately there is no user-level tool to show that (like there is for processor usage). MikroTik claim that they can see it in a supout.rif. Of course you can upload a supout.rif to your account at mikrotik.com to show the conte...
by pe1chl
Tue Oct 29, 2024 8:30 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

Instead of all these attempts to let the user find a clear spot, it would be better to have a spectrum analyzer that indicates signal and noise as function of the frequency (channel) and time, with some automated way to find the optimal channel.
(the competitor has it...)
by pe1chl
Mon Oct 28, 2024 5:28 pm
Forum: RouterBOARD hardware
Topic: CCR2004-1G-2XS-PCIe Feature Request
Replies: 7
Views: 4793

Re: CCR2004-1G-2XS-PCIe Feature Request

Well, at some point I would have been very interested when this router provided: - running independently from the host box (i.e. RouterOS can be rebooted without host reboot, host can be rebooted and even shut down without effect on CCR) - support for VMware ESXi. At that time the intention was to p...
by pe1chl
Mon Oct 28, 2024 2:34 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

For this functionality to work completely reliable and predictable, you would want to have a "reload" function for the workspaces. As it is now, when you have two simultaneous sessions sharing the same session/workspace file, and you make changes in one session, it is somewhat unpredictabl...
by pe1chl
Mon Oct 28, 2024 2:25 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 231953

Re: v7.16.1 [stable] is released!

Yes bgp loaded with large routes can make the whole router get stuck (freeze) , even supout failed to be created, so its hard to explain this situation with MT, happen in 7. 16.1 and ticket has been created and still no answer. To be clear: my issues have nothing to do with large route tables. They...
by pe1chl
Sat Oct 26, 2024 4:27 pm
Forum: Announcements
Topic: Newsletter #121 | October 2024
Replies: 58
Views: 12537

Re: Newsletter #121 | October 2024

Would be nice if Mikrotik develops something like RB5009 but with only 2 SFP+ ports, one for Internet and other for local net that could be attached to SFP+ switch
Maybe a CCR2004-1G-2XS-PCIe in a case? (not sure if that board would work without being in a PCIe slot)
by pe1chl
Sat Oct 26, 2024 11:39 am
Forum: General
Topic: How to block YouTube effectively
Replies: 44
Views: 24664

Re: How to block YouTube effectively

The best solution for blocking sites is to realize that it isn't possible to do it at the technical level and has to be done at user policy level. "you get internet on your workplace and you are not allowed to use it to stream youtube for background music and video, if we find you doing that yo...
by pe1chl
Fri Oct 25, 2024 11:12 pm
Forum: Announcements
Topic: Newsletter #121 | October 2024
Replies: 58
Views: 12537

Re: Newsletter #121 | October 2024

I have encountered a case before where the Qualcomm datasheets indicates a capability for a chip, but the MikroTik product using the chip does not offer it. The "LHG 5 ac" uses the IPQ4018 which according to https://www.qualcomm.com/products/internet-of-things/networking/wi-fi-networks/ipq...
by pe1chl
Fri Oct 25, 2024 11:05 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 231953

Re: v7.16.1 [stable] is released!

Yes there sure are terrible issues with BGP in current releases, but it is difficult to debug them. This week I had a case where one BGP peer connects, routes are received OK (remote is RouterOS v6 so none of that stupid "routes are sent only after one keepalive timer" rubbish), then after...
by pe1chl
Fri Oct 25, 2024 6:46 pm
Forum: Announcements
Topic: Newsletter #121 | October 2024
Replies: 58
Views: 12537

Re: Newsletter #121 | October 2024

Block Diagram is available:
It was added after the above remarks were made... but IPsec test results not yet, maybe they appear next week.
by pe1chl
Fri Oct 25, 2024 6:44 pm
Forum: Announcements
Topic: Newsletter #121 | October 2024
Replies: 58
Views: 12537

Re: Newsletter #121 | October 2024

Stretching for a use case, I suppose you could use this to create semi-airgapped small LANs off a big PoE core switch, as in a hotel where you want a small number of wired ports at the work table, without letting each room's users see devices in other rooms. THAT is their use case! Pop-and-Mom ISPs...
by pe1chl
Fri Oct 25, 2024 2:06 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1911
Views: 604512

Re: 📣 WinBox 4 is here 📣

Not too long ago, I had the opportunity to visit Mikrotik's office in Latvia on behalf of my company. I was welcomed by an official representative of Mikrotik, and the first thing he asked was about what we needed, what equipment we would like to see on the market, and what suggestions or ideas we ...
by pe1chl
Fri Oct 25, 2024 11:55 am
Forum: Announcements
Topic: Newsletter #121 | October 2024
Replies: 58
Views: 12537

Re: Newsletter #121 | October 2024

The "hEX refresh" does not have IPsec test results, ... Not to downplay the importance of publishing IPsec results ... but lately they are becoming increasingly irrelevant. Most people are moving towards wireguard (and alikes), which AFAIK doesn't use IPsec HW offload. Maybe you and most ...
by pe1chl
Thu Oct 24, 2024 10:20 pm
Forum: Announcements
Topic: Newsletter #121 | October 2024
Replies: 58
Views: 12537

Re: Newsletter #121 | October 2024

The "hEX refresh" does not have IPsec test results, unlike its predecessor the RB750Gr3 which had quite impressive IPsec performance for its price and position in the product line. Does this mean "hEX refresh" does not have IPsec acceleration, and the "twice the performance ...
by pe1chl
Thu Oct 24, 2024 2:01 pm
Forum: General
Topic: BGP sessions close when another session to the same IP closes
Replies: 8
Views: 2502

Re: BGP sessions close when another session to the same IP closes

I have a ticket open since Jul 23 with ID SUP-159987 so you can also refer to that.
by pe1chl
Wed Oct 23, 2024 4:00 pm
Forum: General
Topic: Feature requests
Replies: 1807
Views: 700621

Re: Feature requests

Please add the source IP to the message "ipsec,error payload missing: SA".
(the address where the packet was sent from that triggers the message)
by pe1chl
Wed Oct 23, 2024 4:00 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 178246

Re: v7.17beta [testing] is released!

Please add the source IP to the message "ipsec,error payload missing: SA".
(the address where the packet was sent from that triggers the message)
by pe1chl
Wed Oct 23, 2024 3:59 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 178246

Re: v7.17beta [testing] is released!

So I wanted to add WPA3 to SSID 01 for testing. I tried to apply WPA3 via sec1 to it but for some reason it wouldn't apply the setting, i tried several times and restarted the router a few times as well. In the end the only way the WPA3 setting would apply was by doing it via each wifi interface ma...
by pe1chl
Wed Oct 23, 2024 12:52 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 178246

Re: v7.17beta [testing] is released!

t will override the selected security item. Some day I am going to file a feature request at Mikrotik support: "highlight overriden config values in export in different color". Or as a dedicated option in "print detail" or something. I've seen so many exports and always there ar...
by pe1chl
Wed Oct 23, 2024 12:45 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 178246

Re: v7.17beta [testing] is released!

It seems that there is difference between security. And SSID (on purpose?). I would always make one item (per SSID) in /interface/wifi/security and use that on all interfaces. Because when specifying security items on /interface/wifi explicitely, it will override the selected security item. When yo...
by pe1chl
Wed Oct 23, 2024 11:55 am
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 169
Views: 52201

Re: Feature Request: IPSEC Improvements

You do not need VTI to solve that problem! Simple GRE/IPsec tunnels and automatic routing will do it. Yes, and when you want to buy a new car, don´t do it. Buy an horse-drawn carriage you can reach your destination also. Sorry, but it makes no sense to always repeat 'use GRE/IPSec' when remote site...
by pe1chl
Wed Oct 23, 2024 11:03 am
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 231953

Re: v7.16.1 [stable] is released!

Well, it is not surprising (to me) that it does not work. Maybe there has been a strange workaround in the network code that made it work before and is now removed? It is completely normal in Linux that the byte order is "wrong" when you look at the bare 32-bit address that way, at least w...
by pe1chl
Tue Oct 22, 2024 5:41 pm
Forum: Announcements
Topic: v7.16.2 [stable] is released!
Replies: 506
Views: 231953

Re: v7.16.1 [stable] is released!

I did not test that yet, but is it really so that in the $ip variable a 32-bit numeric value is returned instead of a dotted quad string? And you could convert that to a string by adding 0.0.0.0 to it? I would expect a function like inet_ntoa() to be required for that conversion. The IP address will...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 43