Community discussions

Search found 4565 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 92
by pe1chl
Tue Aug 14, 2018 11:06 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature requests
Replies: 835
Views: 143932

Re: Feature requests

As was written above, this feature is already available. And has been for as long as I use RouterOS. So "that could be" and "+1" is completely meaningless.
by pe1chl
Tue Aug 14, 2018 11:02 pm
Forum: General
Topic: Line by line config restore from 6.34 to 6.42 firmware
Replies: 13
Views: 370

Re: Line by line config restore from 6.34 to 6.42 firmware

Is this a complex config? How long is it?
by pe1chl
Tue Aug 14, 2018 7:39 pm
Forum: Virtualization
Topic: Metarouter images
Replies: 351
Views: 210703

Re: Metarouter images

I think Metarouter running something else than RouterOS is a long abandoned concept...
by pe1chl
Tue Aug 14, 2018 3:57 pm
Forum: General
Topic: TORCH CONFUSION
Replies: 9
Views: 3391

Re: TORCH CONFUSION

For now I am considering the situation where no matching criteria are specified. Just observing the default output. When looking at the interface TX is seen as the output of the interface. But then the traffic has src-address of the remote side and dst-address of the local side. That I would conside...
by pe1chl
Tue Aug 14, 2018 2:46 pm
Forum: General
Topic: TORCH CONFUSION
Replies: 9
Views: 3391

Re: TORCH CONFUSION

I too think it is confusing. When you Torch an interface you would expect to sit at the router and look at the packet stream going out. So "src" is the local side, "dst" is the remote side, "tx" is traffic transmitted on the interface and "rx" is traffic received on the interface. So as it is now, "...
by pe1chl
Mon Aug 13, 2018 6:09 pm
Forum: Beginner Basics
Topic: google captcha after installing mikrotik
Replies: 4
Views: 194

Re: google captcha after installing mikrotik

Did you add PPPoE according to YouTube video instead of following quickset or manual?
by pe1chl
Mon Aug 13, 2018 6:05 pm
Forum: Beginner Basics
Topic: CCR Cluster
Replies: 1
Views: 111

Re: CCR Cluster

There is no official way, you will have to use tricks with scripts like written in that presentation.
by pe1chl
Mon Aug 13, 2018 2:51 pm
Forum: General
Topic: How to Preserve Source Ip when Port Forwarding [SOLVED]
Replies: 21
Views: 713

Re: How to Preserve Source Ip when Port Forwarding [SOLVED]

You need to delete the first NAT rule. It should not be there.
add action=masquerade chain=srcnat dst-address=192.168.1.0/24 src-address=\
    192.168.1.0/24
by pe1chl
Mon Aug 13, 2018 11:46 am
Forum: RouterBOARD hardware
Topic: RB750 Boot loop - netinstall not working
Replies: 7
Views: 1882

Re: RB750 Boot loop - netinstall not working

Netinstall only works when you read the directions carefully, and even then you need to get the feel of it.
by pe1chl
Sun Aug 12, 2018 8:48 pm
Forum: RouterBOARD hardware
Topic: No VLAN table on Realtek switch chip?
Replies: 9
Views: 466

Re: No VLAN table on Realtek switch chip?

The function of separating different LANs via VLAN is already done by the hardware in this router. You can program individual ports as individual networks or links and inside the router that mechanism is very likely used to get everything to the CPU chip. When you want more ports linked together you...
by pe1chl
Sun Aug 12, 2018 8:43 pm
Forum: General
Topic: Router's temperature
Replies: 6
Views: 345

Re: Router's temperature

Cooler is always better but this temperature is not an immediate danger for the device.
by pe1chl
Sun Aug 12, 2018 8:01 pm
Forum: RouterBOARD hardware
Topic: No VLAN table on Realtek switch chip?
Replies: 9
Views: 466

Re: No VLAN table on Realtek switch chip?

When you use it as a router it is quite useful to have a number of ports. Although 13 is a bit of an odd number. You could have 1-3 ISP connections, a couple of wireless links, maybe 2-3 local networks that are physically separate. I use a CCR1009 in two different locations setup like that (with 8 p...
by pe1chl
Sun Aug 12, 2018 4:47 pm
Forum: General
Topic: ISP providing two Public IP segments
Replies: 7
Views: 272

Re: ISP providing two Public IP segments

Put the /30 address on your WAN port and the /29 address on your LAN or DMZ or whatever you want to call it.
When you really want to use it only on the router you could put it on a loopback (a bridge with no ports).
by pe1chl
Sat Aug 11, 2018 3:11 pm
Forum: Beginner Basics
Topic: Add DHCP server to VLAN??? [SOLVED]
Replies: 4
Views: 140

Re: Add DHCP server to VLAN??? [SOLVED]

You should add the bridge1 to the vlan222 as well (tagged). Just like was automatically done for vlan 1, see your picture.
Without that, you cannot connect the vlan222 subinterface to the bridge (you can, but it is not connected to the actual VLAN).
by pe1chl
Sat Aug 11, 2018 3:03 pm
Forum: Beginner Basics
Topic: Block websites http and https without Web Proxy / 100% works.
Replies: 17
Views: 2065

Re: Block websites http and https without Web Proxy / 100% works.

blocking facebook is... well.. it has to be done correctly and still, there is no guarantee it will work. Once you have successfully blocked facebook you will notice that "entirely legitimate for business use" services like "prezi" will suddenly be inaccessible to the users that "use their facebook...
by pe1chl
Sat Aug 11, 2018 10:15 am
Forum: General
Topic: Security breached devices - Port TCP 4145
Replies: 9
Views: 551

Re: Security breached devices - Port TCP 4145

i'm not using google for DNS resolving...neither my clients on the network.. What i mean is that there is no possible way to send dns requests to google ips .. with connection originating from this specific router or any other router in the internal network. Have you explicitly redirected or blocke...
by pe1chl
Fri Aug 10, 2018 5:49 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: CCR & MetaRouter
Replies: 47
Views: 16702

Re: CCR & MetaRouter

any news ? :)
You aren't serious, aren't you?
It was written in 2014 that it was being worked on and that it would take some time.
by pe1chl
Fri Aug 10, 2018 5:32 pm
Forum: Beginner Basics
Topic: CCR stuck on "starting kernel" [SOLVED]
Replies: 5
Views: 200

Re: CCR stuck on "starting kernel" [SOLVED]

Did you try ether12 for netinstall?
And is there any special routerboot setting that would prevent the netinstall?
Well, you solved it using serial... at least that is an option on that device.
by pe1chl
Fri Aug 10, 2018 4:33 pm
Forum: RouterBOARD hardware
Topic: No CRS with redundand power?
Replies: 6
Views: 349

Re: No CRS with redundand power?

What is consuming your CPU? Depending on the task of those routers, you can sometimes optimize firewall rules, decide between connection tracking or not, queuing can also be done in different ways, and when you traffic increases you may be able to have multiple CCR1009 alongside handling part of the...
by pe1chl
Fri Aug 10, 2018 12:17 pm
Forum: General
Topic: [Feature request] Wireguard
Replies: 18
Views: 1968

Re: [Feature request] Wireguard

While it's to late to include into Linux 4.19 which should arrive quite soon, we could see it in the next linux kernel builds. Now the interesting question is when RouterOS gets to use that future kernel with Wireguard. So far it looks like when MikroTik likes a version, they stick with it for quit...
by pe1chl
Fri Aug 10, 2018 11:55 am
Forum: Beginner Basics
Topic: Block websites http and https without Web Proxy / 100% works.
Replies: 17
Views: 2065

Re: Block websites http and https without Web Proxy / 100% works.

You will have to understand that there are different agendas here, and the large and powerful companies are working to make it unrealistic to block their services while the small connectivity providers want to block things they don't see as useful or they feel are overloading their limited connectio...
by pe1chl
Thu Aug 09, 2018 10:34 pm
Forum: General
Topic: allow facebook and youtube apps working
Replies: 3
Views: 146

Re: allow facebook and youtube apps working

When you make such blocks, expect problems.
Either remove the blocks and work OK or accept the problems...
by pe1chl
Thu Aug 09, 2018 10:32 pm
Forum: Beginner Basics
Topic: WAN port doesn't work
Replies: 14
Views: 353

Re: WAN port doesn't work

Reset it to defaults, then it should work, then update software and reset it to defaults again.
by pe1chl
Thu Aug 09, 2018 5:33 pm
Forum: Beginner Basics
Topic: CCR stuck on "starting kernel" [SOLVED]
Replies: 5
Views: 200

Re: CCR stuck on "starting kernel" [SOLVED]

CCR netinstall is via the highest port (ether12)
by pe1chl
Thu Aug 09, 2018 4:52 pm
Forum: Beginner Basics
Topic: CCR stuck on "starting kernel" [SOLVED]
Replies: 5
Views: 200

Re: CCR stuck on "starting kernel" [SOLVED]

When it gets as far as "starting kernel" is should certainly be possible to netinstall...
Did you check the serial console?
by pe1chl
Thu Aug 09, 2018 2:48 pm
Forum: General
Topic: Security breached devices - Port TCP 4145
Replies: 9
Views: 551

Re: Security breached devices - Port TCP 4145

Of course when you try to capture traffic "to port 4145" and identify the counterpart as a hacker, you need to make sure that you only identify traffic initiated by the other party and not replies to traffic you make yourself. So when you setup a TCP connection from port 4145 to Google DNS port 53, ...
by pe1chl
Thu Aug 09, 2018 10:09 am
Forum: RouterBOARD hardware
Topic: Mikrotik VDSL / DSL Modem?
Replies: 282
Views: 51931

Re: Mikrotik VDSL / DSL Modem?

xDSL modem from Mikrotik would be great.... No, it would be a can of worms. Every country, every provider uses slightly different setups and wellknown DSL modem manufacturers make different firmware versions for different situations. You see that happening here in this thread, where a German distri...
by pe1chl
Thu Aug 09, 2018 9:38 am
Forum: General
Topic: IntraVLAN speeds
Replies: 12
Views: 416

Re: IntraVLAN speeds

You have to understand that FastTrack is not simply some secret handbrake that gets released, but it operates by removing functionality from the router that not everyone uses. Thus the router has fewer checks to make on each packet and it can operate faster. The good thing is that you can set criter...
by pe1chl
Wed Aug 08, 2018 10:16 pm
Forum: General
Topic: Line by line config restore from 6.34 to 6.42 firmware
Replies: 13
Views: 370

Re: Line by line config restore from 6.34 to 6.42 firmware

Is this a complex config? If not, you might be quicker by just manually configuring everything while having the printed export as a reminder to see what has to be done. You could also check if the new CCR can run 6.40 firmware (see in System->Resources what is the factory software, is it 6.40 or low...
by pe1chl
Wed Aug 08, 2018 8:41 pm
Forum: General
Topic: Line by line config restore from 6.34 to 6.42 firmware
Replies: 13
Views: 370

Re: Line by line config restore from 6.34 to 6.42 firmware

BTW, you said "line by line" but that is not the proper way to do it. You should copy sections of multiple lines. At least when a line ends with \ you should copy and paste the following line with it. The line "rx-flow-control=on tx-flow-control=on" is not an independent line by itself but it belong...
by pe1chl
Wed Aug 08, 2018 7:06 pm
Forum: General
Topic: Line by line config restore from 6.34 to 6.42 firmware
Replies: 13
Views: 370

Re: Line by line config restore from 6.34 to 6.42 firmware

Not that I know of. You should connect to the new CCR by MAC address, erase the config and
paste the exported old config in small sections. When you encounter errors, paste the same
command again omitting the parameter that causes the error.
by pe1chl
Wed Aug 08, 2018 5:04 pm
Forum: RouterBOARD hardware
Topic: No VLAN table on Realtek switch chip?
Replies: 9
Views: 466

Re: No VLAN table on Realtek switch chip?

In software, you mean. Yes, certainly.
by pe1chl
Wed Aug 08, 2018 5:02 pm
Forum: General
Topic: Vulnerability CVE-2018-5390
Replies: 6
Views: 787

Re: Vulnerability CVE-2018-5390

That certainly is a risk! Not for the reason mentioned in that CVE but there could certainly be a vulnerability in the SSTP server or the SSL and PPP layers used, and the authentication. Once it is discovered it could mean your router is open to the world. Just like with the webserver and winbox vul...
by pe1chl
Wed Aug 08, 2018 2:19 pm
Forum: General
Topic: Vulnerability CVE-2018-5390
Replies: 6
Views: 787

Re: Vulnerability CVE-2018-5390

We are all waiting for MikroTik to use a 4.9+ kernel!
So far this hasn't happened.
Furthermore this type of vulnerability is not so much of interest for a router.
When you allow untrusted parties to setup TCP connections to your router you a vulnerable for many other reasons, so improve your firewall.
by pe1chl
Wed Aug 08, 2018 11:45 am
Forum: General
Topic: How to Preserve Source Ip when Port Forwarding [SOLVED]
Replies: 21
Views: 713

Re: How to Preserve Source Ip when Port Forwarding [SOLVED]

i'm using this cause what this is what i learned from youtube
Let me tell you 1 thing: NEVER learn how to setup your router using videos from YouTube!!!!
by pe1chl
Wed Aug 08, 2018 11:39 am
Forum: General
Topic: IntraVLAN speeds
Replies: 12
Views: 416

Re: IntraVLAN speeds

20 MB/s is about what you can expect from an RB2011.
Yes, you can try to tweak it using features like FastTrack, when it is worth the trouble.
Otherwise you need to move on to a faster (newer generation) router like a CCR1009.
by pe1chl
Wed Aug 08, 2018 11:34 am
Forum: RouterBOARD hardware
Topic: No VLAN table on Realtek switch chip?
Replies: 9
Views: 466

Re: No VLAN table on Realtek switch chip?

My guess is that the chip supports a VLAN table but the first VLAN layer is used by RouterOS to provide the function of having several independent ports connected to the router. E.g. in RB1100AHx4 to use ports 11 12 and 13 independently to connect to different ISP or similar. When you as a user want...
by pe1chl
Tue Aug 07, 2018 10:16 pm
Forum: General
Topic: Backround upload traffic from google ips 172.217.x.x is saturating my upload speed
Replies: 7
Views: 269

Re: Backround upload traffic from google ips 172.217.x.x is saturating my upload speed

Are you sure it isn't Youtubers uploading their new vlog to their channel??
by pe1chl
Tue Aug 07, 2018 9:28 pm
Forum: General
Topic: Backround upload traffic from google ips 172.217.x.x is saturating my upload speed
Replies: 7
Views: 269

Re: Backround upload traffic from google ips 172.217.x.x is saturating my upload speed

Maybe I have read too many "help! my users are actually making traffic! I want to block block block!" topics...
by pe1chl
Tue Aug 07, 2018 9:02 pm
Forum: General
Topic: Backround upload traffic from google ips 172.217.x.x is saturating my upload speed
Replies: 7
Views: 269

Re: Backround upload traffic from google ips 172.217.x.x is saturating my upload speed

Call the customer and explain why what they are doing is not reasonable.
Prepare for some discussion about what a customer can expect from an ISP and why.
Also consider dropping from the business and finding another way to earn money.
by pe1chl
Tue Aug 07, 2018 1:43 pm
Forum: General
Topic: MOAB mother of all blacklists
Replies: 25
Views: 1241

Re: MOAB mother of all blacklists

Though, i still dont think it is good idea to simply block so many IP addresses. Chance of false-positive is too high and it will end up similarly to sorbs.net - easy to get in, hard to get out, legit services blocked, nobody to blame... Of course it has zero functionality. Block some people becaus...
by pe1chl
Tue Aug 07, 2018 10:44 am
Forum: General
Topic: MOAB mother of all blacklists
Replies: 25
Views: 1241

Re: MOAB mother of all blacklists

The idea of a update list of blackholes is interesting! Can I use updatable lists through an external BGP routing server? It is possible, but it is quite impractical because you need another step to transfer the information from the routing table maintained by BGP to a place where you can actually ...
by pe1chl
Tue Aug 07, 2018 10:30 am
Forum: General
Topic: MOAB mother of all blacklists
Replies: 25
Views: 1241

Re: MOAB mother of all blacklists

A blocklist for MikroTik should be distributed using DNS address lists. There are two limitations that limit that method: - when the blocklist contains subnets, there is no efficient method to transfer them. solution: MikroTik should lookup TXT records besides A records, and when they are valid text...
by pe1chl
Mon Aug 06, 2018 10:38 pm
Forum: Beginner Basics
Topic: IPv6 delegation from one router to another
Replies: 6
Views: 196

Re: IPv6 delegation from one router to another

DHCPv6 PD
by pe1chl
Mon Aug 06, 2018 4:50 pm
Forum: General
Topic: How to display full time in the winbox log
Replies: 14
Views: 492

Re: How to display full time in the winbox log

We do know this issue exists and will work on some solution. It seems to me that all what's needed it to take the date string, measure width for current font (I remember there was some Windows API function for it) and adjust column width accordingly. Do it once when WinBox starts and problem solved...
by pe1chl
Mon Aug 06, 2018 3:33 pm
Forum: General
Topic: L2TP "road warriors" and security issue
Replies: 2
Views: 136

Re: L2TP "road warriors" and security issue

The issue with the security of IPsec and allowing access like this is not in the strength of the ciphers, but in any security issues in the implementation. By allowing UDP port 500/4500 access you provide access to the IPsec engine on the router, which could turn out to have security issues similar ...
by pe1chl
Mon Aug 06, 2018 3:08 pm
Forum: General
Topic: CCR1009-7G-1C-1S+ vs CCR1009-7G-1C-1S+PC
Replies: 18
Views: 1012

Re: CCR1009-7G-1C-1S+ vs CCR1009-7G-1C-1S+PC

In my CCR1009-8G models the CPU temp is regulated towards 50 degrees. When the ambient is like 20-25 degrees it can easily achieve this with the original fan. Once the ambient rises the CPU rises to e,g, 58 degrees like you have. So I would say there is something wrong, maybe fans in the wrong orien...
by pe1chl
Mon Aug 06, 2018 10:21 am
Forum: General
Topic: How to display full time in the winbox log
Replies: 14
Views: 492

Re: How to display full time in the winbox log

While I was debugging my problem under Linux/Wine I was searching and asking for the name of the font that winbox uses so I could maybe replace only that font, but nothing came about. It would be best when the used font would be settable somehow, so you could add the correct font to the system and s...
by pe1chl
Sun Aug 05, 2018 1:00 pm
Forum: Scripting
Topic: RouterOS SNMP Get
Replies: 5
Views: 241

Re: RouterOS SNMP Get

You will have to write a script that uses this command and put the output in a variable, then you can write this variable in a file when you like.
You would use the script construct:

:local variable;
:set variable [ /tool snmp-get .... ];
by pe1chl
Sun Aug 05, 2018 12:49 pm
Forum: Beginner Basics
Topic: Unsecured Network after login
Replies: 5
Views: 268

Re: Unsecured Network after login

For you as an end-user the "not secure" means that other users on the same RV park can see what you are doing. The actual content of your traffic will be less and less visible because almost everyone uses https now. However, on a http site they would be able to trace your traffic and extract passwor...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 92