Community discussions

MikroTik App

Search found 1907 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 7
by Larsa
Sat Feb 15, 2025 10:28 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 566
Views: 109717

Re: v7.18beta [testing] is released!

Thanks so much, I completely missed this! Breaking changes like these should come with bold warning signs. It’s also a typical sign that Mikrotik’s developers and managers still don’t get their business customers. Mikrotik could at least try by adding a section called 'Breaking changes' in the relea...
by Larsa
Sat Feb 15, 2025 10:14 am
Forum: RouterBOARD hardware
Topic: Danteswitch
Replies: 12
Views: 638

Re: Danteswitch

When I reread your first post, I realized I totally missed two key details: that you’ll be using the switch standalone and with PoE. With that in mind and since you will only run pure Dante traffic, pretty much any switch with PoE will do.

Ps..
Looks like you’re double-quoting your replies.
by Larsa
Fri Feb 14, 2025 6:27 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 566
Views: 109717

Re: v7.18beta [testing] is released!

It doesn’t necessarily have to be ROS; it could be storage constraints, hardware or network failure, power shutdown, or other environmental issues. So there’s no point in continuing to speculate until you can access the server.
by Larsa
Fri Feb 14, 2025 5:21 pm
Forum: RouterBOARD hardware
Topic: Danteswitch
Replies: 12
Views: 638

Re: Danteswitch

It might work, but if this is for a recording setup and Dante is sharing the network with other bulk traffic, I’d say QoS is essential to maintain audio quality. Dante is pretty sensitive to latency and jitter, so QoS makes sure that Dante streams are prioritized over other types of network traffic....
by Larsa
Fri Feb 14, 2025 5:18 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 566
Views: 109717

Re: v7.18beta [testing] is released!

only have the model, but i canot reach the server x86 Supermicro SYS-530MT-H8TNR Okay, when you have access, please provide the full config, including NICs, storage boards, etc. Btw, it might be worth checking if the setup complies with Mikrotik’s requirements. Just a tip: if the Supermicro is co-l...
by Larsa
Fri Feb 14, 2025 3:38 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 566
Views: 109717

Re: v7.18beta [testing] is released!

@SMARTNETTT – Hopefully just on a lab server then, right? If this is regarding a bare metal x86, provide the manufacturer, model, and full configuration — without that, your warning is pretty useless! If it happens multiple times and your configuration is supported, open a support ticket with Mikrot...
by Larsa
Fri Feb 14, 2025 3:08 pm
Forum: RouterBOARD hardware
Topic: Danteswitch
Replies: 12
Views: 638

Re: Danteswitch

@orfeous, Starting from ROS v7.15, all Mikrotik QoS-capable switches can use Dante. For more info on switches supporting Dante, check out these links: Mikrotik help - Bridging and Switching - MikroTik QoS-Capable devices ("QoS Device Support") Mikrotik help - Bridging and Switching - Appli...
by Larsa
Fri Feb 14, 2025 11:39 am
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 169
Views: 52624

Re: Feature Request: IPSEC Improvements

XFRM has been a part of IPsec since Linux 2.6, released in December 2003.
by Larsa
Thu Feb 13, 2025 6:04 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 49
Views: 2668

Re: Got stuck building IKEv2 w/ MFA for remote client

Here are some other troubleshooting suggestions. Sorry if I misunderstand or missed anything both of you already tried! - Check that Windows trusts the Mikrotik CA Open certmgr.msc. Go to "Trusted Root Certification Authorities". Check that the signing CA of the Mikrotik certificate is the...
by Larsa
Thu Feb 13, 2025 4:30 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 49
Views: 2668

Re: Got stuck building IKEv2 w/ MFA for remote client

Just a long shot, but have you tried checking with extended logging on Windows? 1. "C:\> netsh trace start VpnClient per=yes maxsize=0 filemode=single" 2. Test the VPN connection 3. "C:\> netsh trace stop" 4. Open the .etl file using Event Viewer (eventvwr.msc). The .etl files ar...
by Larsa
Thu Feb 13, 2025 2:26 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 49
Views: 2668

Re: Got stuck building IKEv2 w/ MFA for remote client

@Guscht: Can't help, but a notice: It's 2025, IPsec is an old, outdated overcomplicated, error-prone dinosaur. If possible, use a modern technology like Wireguard. Sure, IPsec is a "dinosaur" — just one that happens to be the standard for countless enterprises, governments, and critical i...
by Larsa
Thu Feb 13, 2025 1:37 pm
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 86
Views: 64280

Re: Newsletter #122 | December 2024

...a fiber socket in each guest room... Even though it sounds a bit unusual to me, it’s possible it exists. But I can’t remember ever seeing it in a hotel, and I’ve traveled quite a bit. I mean, bringing your own fiber optic patch cables plus an SFP/RJ45 Ethernet media converter doesn’t exactly fee...
by Larsa
Wed Feb 12, 2025 12:25 am
Forum: General
Topic: Connecting Mikrotik via openconnect protocol
Replies: 5
Views: 2878

Re: Connecting Mikrotik via openconnect protocol

OpenConnect is already supported as an add-on container app service.
by Larsa
Tue Feb 11, 2025 5:14 pm
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 86
Views: 64280

Re: Newsletter #122 | December 2024

Have you ever seen a hotel or student housing with an SFP port in the wall, or did you mean something else? Usually, when fiber (passive or not) is installed in a property for the end user, it's typically terminated with Ethernet or WiFi.
by Larsa
Tue Feb 11, 2025 12:10 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1917
Views: 616752

Re: 📣 WinBox 4 is here 📣

v3 is already abandoned. They've said many times that there won't be any changes. Only security fixes. I afraid that some day, after updating to new RouterOS, it will show "Protocol is not supported"... And I also feel bad with this stupid design in v4. For me it's like a toy currently, I...
by Larsa
Mon Feb 10, 2025 8:46 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1917
Views: 616752

Re: 📣 WinBox 4 is here 📣

We went from something that worked fine on windows and emulated well on others, most of the time, to something that doesn't work as well as the old one anywhere...

Yeah, I feel the same way. I really hope MT won't retire v3 before everything’s up to par.
by Larsa
Mon Feb 10, 2025 11:33 am
Forum: General
Topic: Externally monitoring OSPF neighbor states?
Replies: 2
Views: 363

Re: Externally monitoring OSPF neighbor states?

We're running a script-based approach since MT hasn't implemented SNMP for OSPF LSA yet (only for BGP). Check out "OSPF SNMP monitoring" in the "Routing Protocol Overview".
by Larsa
Sun Feb 09, 2025 1:45 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 566
Views: 109717

Re: v7.18beta [testing] is released!

WireGuard works well for monitoring and management, but it’s not the best choice for large-scale operations that require many connections and high throughput. In these cases, IPSec is the only real option. If someone finds IPSec tricky to set up, it’s likely more a matter of experience and expertise...
by Larsa
Sat Feb 08, 2025 11:10 pm
Forum: Wireless Networking
Topic: Very slow LTE [SOLVED]
Replies: 46
Views: 3094

Re: Very slow LTE [SOLVED]

My take on this is pretty simple: 1. Carrier aggregation is a must to get decent speeds with CAT6. 2. I'm pretty sure the China box won't do much better than the MT if properly configured. 3. Most built-in external antennas on 4G CPEs are used for Wi-Fi nowadays, not the LTE radio. For example, with...
by Larsa
Sat Feb 08, 2025 9:40 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 60
Views: 4689

Re: New exciting features for storage

@sirbryan, that’s not gonna happen. ROS is designed as an embedded NOS with its own limitations. When it comes to running ROS as CHR, there are way better options. Plus, MT lacks the skill set and experience, and ROS is too unreliable for storage solutions like hyper-convergence.
by Larsa
Sat Feb 08, 2025 8:30 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 566
Views: 109717

Re: v7.18beta [testing] is released!

For RAM I'd say WG definitely ... because IPsec is part of ROS since ages and I'm sure they did whatever possible to reduce its memory footprint. I don't think they put the same amount of energy into WG so far. I'm not saying anything about CPU utilization, but probably WG fares better (everybody's...
by Larsa
Sat Feb 08, 2025 7:04 pm
Forum: General
Topic: Zerotier Struggles on v7.17
Replies: 3
Views: 647

Re: Zerotier Struggles on v7.17

That was a lot to take in and maybe a bit tricky to get a clear picture of. Here are a few things that might help clarify things: What exactly isn’t working? - Are all Zerotier peers unreachable from the LAN, or just some? - Can LAN devices ping any Zerotier IPs, or is all Zerotier traffic failing f...
by Larsa
Sat Feb 08, 2025 1:16 pm
Forum: Forwarding Protocols
Topic: OSPF Fast Reroute on ROS v7
Replies: 3
Views: 3430

Re: OSPF Fast Reroute on ROS v7

OSPF with BFD = fast reroute within a few ms.
by Larsa
Fri Feb 07, 2025 11:35 pm
Forum: Beginner Basics
Topic: Can't figure out recursive routing
Replies: 5
Views: 840

Re: Can't figure out recursive routing

It pretty easy to understand using recursive routing in this simple terms: A → B (A needs to reach B) B → C (B is reachable via C) So, A → C (indirectly via B) Example using recursive routing with ROS: 1. Set A to go via B: /ip route add dst-address=A gateway=B 2. Resolve B via C: /ip route add dst-...
by Larsa
Fri Feb 07, 2025 1:23 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 566
Views: 109717

Re: v7.18beta [testing] is released!

@oreggin, if you're looking for advanced MPLS/BGP solutions, you’ll probably need to consider other brands—but that also comes with additional costs. Since this is just a user forum, if you have a serious business case, you might want to contact MikroTik directly at sales@mikrotik.com or support@mik...
by Larsa
Fri Feb 07, 2025 12:49 pm
Forum: General
Topic: Still fighting with Ecobee (and losing)
Replies: 14
Views: 1443

Re: Still fighting with Ecobee (and losing)

I've also been thinking about getting some Ecobees. Do you use them standalone, or together with something like Home Assistant or another system?
by Larsa
Fri Feb 07, 2025 11:23 am
Forum: General
Topic: OSPF vs CCTV
Replies: 2
Views: 474

Re: OSPF vs CCTV

OSPF only handles routing between nodes in a network and doesn’t impact performance per se. Building your own mesh network works fine with a few nodes, but as the number of nodes increases, the number of tunnels grows exponentially (see below). OSPF is pretty easy to configure, but you have to do it...
by Larsa
Thu Feb 06, 2025 10:15 pm
Forum: General
Topic: ✈️ MTPC 2024 info and my experience
Replies: 3
Views: 638

Re: ✈️ MTPC 2024 info and my experience

@MikroTikMarc, looks like you guys had a great time!

Gotta say, your presentation on YouTube how to build a complex OSPF lab for under $100 using Proxmox and CHR was awesome too! 🚀 Btw, here’s the link to the blog page that was mentioned in the presentation: https://admiralplatform.com/blog-page/
by Larsa
Wed Feb 05, 2025 10:39 pm
Forum: Beginner Basics
Topic: How to run IPv6 from starlink on a mikrotik?
Replies: 36
Views: 13051

Re: How to run IPv6 from starlink on a mikrotik?

With IPv6, you get a public IP; with IPv4, only CGNAT
by Larsa
Wed Feb 05, 2025 6:53 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1917
Views: 616752

Re: 📣 WinBox 4 is here 📣

Yeah, and if MT is using their own Layout Manager, scaling might not work as well if DPI awareness isn't handled properly. The built-in Layout Manager scales just fine on high-resolution screens. Try the example app "Thermostat".
by Larsa
Wed Feb 05, 2025 2:45 pm
Forum: Forwarding Protocols
Topic: [OSPF][iBGP] route filtering syntax help [SOLVED]
Replies: 16
Views: 3190

Re: [OSPF][iBGP] route filtering syntax help [SOLVED]

I’m not sure what you mean by “concentrator” in this case so you'll need to be more specific than that. Btw, did you manage to spot the root cause by checking how OSPF adds default routes to the routing table in one of the black nodes? That said, MED is primarily designed to influence inbound traffi...
by Larsa
Wed Feb 05, 2025 10:38 am
Forum: General
Topic: ip cloud ddns-enabled
Replies: 21
Views: 2380

Re: ip cloud ddns-enabled

@JavierCastilla: Which is the support service and how can I register my devices for that?

I was referring to the business impacted by a failing service, not the one that made the equipment.
by Larsa
Tue Feb 04, 2025 11:07 pm
Forum: General
Topic: ip cloud ddns-enabled
Replies: 21
Views: 2380

Re: ip cloud ddns-enabled

@Dida: What difference does it make if 1 or 200 services are down?

Are you being sarcastic? If we’re talking business, there’s a massive difference. One service down is a problem, but 200? That’s a full-blown disaster—support is in for an absolute nightmare of a day!
by Larsa
Tue Feb 04, 2025 10:16 pm
Forum: General
Topic: ip cloud ddns-enabled
Replies: 21
Views: 2380

Re: ip cloud ddns-enabled

@kevag: seems the service is down since yesterday ..200+ routers dont resolve. can this be verified by mikrotik officials ? any news when this will come back in service? MikroTik IP Cloud DDNS is free, which means there’s no SLA. With 200+ routers, I’d definitely start looking into global services ...
by Larsa
Tue Feb 04, 2025 4:16 pm
Forum: General
Topic: ip cloud ddns-enabled
Replies: 21
Views: 2380

Re: ip cloud ddns-enabled

The service might be down at the moment. It happens occasionally...
by Larsa
Tue Feb 04, 2025 3:35 pm
Forum: Forwarding Protocols
Topic: [OSPF][iBGP] route filtering syntax help [SOLVED]
Replies: 16
Views: 3190

Re: [OSPF][iBGP] adding cost on backbone neighbor [SOLVED]

ok now I want to create a iBGP filter rule to execute this...

I thought you were having trouble with OSPF. What are you trying to solve with BGP? Some more background would help.
by Larsa
Tue Feb 04, 2025 3:27 pm
Forum: General
Topic: "Error in Gateway - non zero ip address expected!" when using Quick Set
Replies: 20
Views: 1843

Re: "Error in Gateway - non zero ip address expected!" when using Quick Set

I prefer "auto-mac=smart" because it adapts to new conditions automatically. ;)
by Larsa
Tue Feb 04, 2025 11:53 am
Forum: General
Topic: ATL suddenly says "sim not present"
Replies: 19
Views: 1672

Re: ATL suddenly says "sim not present"

@SiB: I remember that problems on LHGR and some connector spray help or office tape :) And this was a popular problem with fist and second revision of LHGR. Second problems was how exit(take out) a sim card - this was not easy job. Yeah, I remember a few years ago when we switched MNO and had to sw...
by Larsa
Mon Feb 03, 2025 9:45 pm
Forum: 3rd party tools
Topic: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management
Replies: 80
Views: 22940

Re: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management

You can use Docker on Windows with the built-in WSL2, which is a Hyper-V virtual machine where you can run any distro you like, such as Ubuntu. To set up Docker, install either Docker Desktop following this this guide or without Docker Desktop using this tutorial.
by Larsa
Mon Feb 03, 2025 8:18 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 3438

Re: Question on using the Internal Zerotier Controller [SOLVED]

Haha, Anav, I see you're out here securing your files and your finances at the same time! 😂 Maybe if we tweak that command a bit: # chmod +Money Boom! Instant economic growth! 💰💸 As for joining the EU... yeah, I think Canada prefers its maple syrup debts over Mediterranean siestas. But hey, if your ...
by Larsa
Mon Feb 03, 2025 8:10 pm
Forum: General
Topic: "Error in Gateway - non zero ip address expected!" when using Quick Set
Replies: 20
Views: 1843

Re: "Error in Gateway - non zero ip address expected!" when using Quick Set

I know why, but I still think making users set the bridge MAC manually is an ugly kludge.
by Larsa
Mon Feb 03, 2025 7:25 pm
Forum: General
Topic: "Error in Gateway - non zero ip address expected!" when using Quick Set
Replies: 20
Views: 1843

Re: "Error in Gateway - non zero ip address expected!" when using Quick Set

Seriously, I don't know what the admin-mac is or what it is used for. I read some of the threads, faithfully staying in my 20-40% comprehension level, and I see that it is, by default, set to the same mac-address as the lowest numbered eth port, and that there might be a problem is/when restoring f...
by Larsa
Mon Feb 03, 2025 7:07 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 3438

Re: Question on using the Internal Zerotier Controller [SOLVED]

@anav - If I were you, I'd ditch the self-hosted controller and just use the cloud-based one (my.zerotier.com). Regarding your files, just: "# chmod +r *". Fixed! ;)
by Larsa
Mon Feb 03, 2025 6:30 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 3438

Re: Question on using the Internal Zerotier Controller [SOLVED]

Thanks AMMO, so controller is limited to CLI, is there a sense it will migrate to Winbox eventually.

Way too complex, so I don’t think so. But you can add your own web-based manager: ZeroUI.
by Larsa
Mon Feb 03, 2025 6:27 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 3438

Re: Question on using the Internal Zerotier Controller [SOLVED]

Just highlight, once again, an grip of mine is the Mikrotik's ZT client does not support low-bandwidth, bonding, etc. as a "full" ZT client on PC/Mac does. And these restrictions still come in when using the controller, as traffic will go via the interface, not controller. Yeah, unfortuna...
by Larsa
Mon Feb 03, 2025 6:23 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 3438

Re: Question on using the Internal Zerotier Controller [SOLVED]

@NA9D - Unfortunately, you're still a bit limited when it comes to running fully autonomous operations since ROS doesn't let you configure root servers. But with your own ZeroTier controller and ZeroUI , you not only get a slick web interface, but you also have full control over network rules, authe...
by Larsa
Mon Feb 03, 2025 4:51 pm
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 3021

Re: 1.3km Possible?

Here’s a simulation for 2.4 GHz signal loss in a somewhat dense forest using 36 dBm EIRP , with a minimum received power sensitivity of -90 dBm which BTW is extremely weak . You typical need at least -80 dBm for a somewhat stable connection and -67 dBm or better for normal performance. Typical fores...
by Larsa
Mon Feb 03, 2025 1:14 pm
Forum: Forwarding Protocols
Topic: How can I do load balancing in ospf?
Replies: 4
Views: 1197

Re: How can I do load balancing in ospf?

Please don't double-post. I've already answered your question here: viewtopic.php?p=1123269#p1123298
by Larsa
Mon Feb 03, 2025 1:10 pm
Forum: Wireless Networking
Topic: "not responding" - f.k.a. SA Query timeout
Replies: 332
Views: 65726

Re: "not responding" - f.k.a. SA Query timeout

@blondasek, @maigonis - This is just a user forum. If you haven't already, please email a support.rif to support@mikrotik.com.
by Larsa
Mon Feb 03, 2025 12:47 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 3438

Re: Question on using the Internal Zerotier Controller [SOLVED]

I completely agree, especially regarding the steps to establish a good baseline. All major players like as Cisco, Juniper, and others, provide clear guidelines for the initial setup. I mean, how hard can it be? ;) Regarding the handbook (I assume you're referring to a user guide), it's a great idea....
by Larsa
Mon Feb 03, 2025 8:51 am
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 3021

Re: 1.3km Possible?

Unfortunately, you do need line of sight for WiFi to work on 2.4/5 GHz. No amount of dark magic will get through 1.3 km of trees. Check Sindy’s previous answer on this.
by Larsa
Sun Feb 02, 2025 11:28 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 3438

Re: Question on using the Internal Zerotier Controller [SOLVED]

Well, to begin with, the documentation for the controller is a masterpiece of vagueness, to say the least. 😉 Unfortunately, the people who wrote it forgot to include an example of how to add a route to a gateway. The only cryptic and inconsistent explanation you get is: routes (IP@GW; Default: ) Pus...
by Larsa
Sun Feb 02, 2025 7:34 pm
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 3021

Re: 1.3km Possible?

..but I do have some small houses all connected via twisted pair… This is overhead (exposed to UV, cold, rain, etc.)..

Shouldn’t be a problem if you're using a protective conduit or an outdoor-rated cable that’s UV-resistant and built to handle cold, moisture, and all kinds of weather.
by Larsa
Sun Feb 02, 2025 6:28 pm
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 3021

Re: 1.3km Possible?

With the short distance, you can go for a super flexible multimode ... @OP mentioned 1.3km distance ... and that's direct distance. Which is way longer than 550m limit for multimode fiber. So if @OP decides for digging, it should be single-mode ... which is most often laid inside protective tube. D...
by Larsa
Sun Feb 02, 2025 5:17 pm
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 3021

Re: 1.3km Possible?

Talk to Verizon? I can think of any number of forms of torture I'd prefer....

Same here, I’d rather have a dentist appointment without anesthesia! 🤣🤣🤣
by Larsa
Sun Feb 02, 2025 3:44 pm
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 3021

Re: 1.3km Possible?

@Josephny; If you're planning to install fiber yourself and have your own machinery, just go ahead and use a narrow trenching blade. A depth of about 15-16 inches should be enough. There are plenty of reinforced microducts with pre-installed fiber designed for direct burial in the ground for about 2...
by Larsa
Sun Feb 02, 2025 11:31 am
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 3021

Re: 1.3km Possible?

Regarding fiber, if you're the landowner and somewhat handy, you can rent a small walk-behind trencher to lay the fiber in a ditch. To terminate it, you can rent a Fusion Splicer and use splice-on connectors, or go with mechanical connectors if you want to skip the splicing. There are also plenty of...
by Larsa
Sun Feb 02, 2025 9:33 am
Forum: Forwarding Protocols
Topic: ospf not doing load balancing
Replies: 2
Views: 1414

Re: ospf not doing load balancing

Unfortunately, OSPF does not perform load balancing by itself; it only sets up routes in the routing table. Instead, you can use bonding, which is explained here: https://help.mikrotik.com/docs/spaces/ROS/pages/8323193/Bonding. If you plan to use the routers at two different locations, set up two Eo...
by Larsa
Sat Feb 01, 2025 11:40 pm
Forum: Beginner Basics
Topic: Multicast UDP over Zerotier
Replies: 3
Views: 1078

Re: Multicast UDP over Zerotier

Check out multicast UDP in the rules engine: https://docs.zerotier.com/rules/
by Larsa
Fri Jan 31, 2025 8:54 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1917
Views: 616752

Re: 📣 WinBox 4 is here 📣

Same here, "Cmd +/-" for zooming on Macs is pure muscle memory these days.
by Larsa
Fri Jan 31, 2025 12:27 pm
Forum: RouterOS beta
Topic: L4S support in routerOS7
Replies: 10
Views: 8891

Re: L4S support in routerOS7

@dtaht - Good summary. Any guess on the current status of L4S among the key stakeholders? Can you picture a real-life scenario where BBRv3 coexists with fq_codel or L4S? And yeah, it would probably be a good idea to switch from in-house queue managers to BQL.
by Larsa
Thu Jan 30, 2025 3:16 pm
Forum: General
Topic: IPSEC multiple policy with p2p
Replies: 15
Views: 2614

Re: IPSEC multiple policy with p2p

@Larsa I am looking what is the best solution for this kind scenario: Secure connection to site to site - IPSEC prefered. Site A: has subnet A1 which has to have access to Site B subnet B1 and B2. Site B: has two subnets B1 and B2 to access from/to Site A subnet A1. Since your setup is a single sit...
by Larsa
Thu Jan 30, 2025 1:08 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1917
Views: 616752

Re: 📣 WinBox 4 is here 📣

Just curious, what is a "normal resolution" nowadays according to MT?
by Larsa
Thu Jan 30, 2025 1:04 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1917
Views: 616752

Re: 📣 WinBox 4 is here 📣

It is impossible to fix all scaling issues in Windows. Windows is very bad at DPI scaling compared to other OS and Winbox is definitely not the only program that has small pixel level issues at these settings. Since Winbox is now made in QT, we will not be able to fix all issues, at this point, mos...
by Larsa
Wed Jan 29, 2025 7:43 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 566
Views: 109717

Re: v7.18beta [testing] is released!

I think it’s a pretty good idea for a lot of reasons.
by Larsa
Wed Jan 29, 2025 12:44 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 566
Views: 109717

Re: v7.18beta [testing] is released!

@fischerdouglas: yeah, plus L3VPN/MPLS-TE, MPLS-MGMT and BGP/MPLS L3 VPN (128)...
by Larsa
Wed Jan 29, 2025 9:21 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 566
Views: 109717

Re: v7.18beta [testing] is released!

…a valid BGP table from them in every single AFI/SAFI…

All SAFIs? Well, then you’re in for a long wait! 😉
by Larsa
Wed Jan 29, 2025 12:04 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 566
Views: 109717

Re: v7.18beta [testing] is released!

I agree, but I also want to stress that loading 4 full tables on an internet border gateway is not the only use-case for BGP. Somewhat OT: I’m not trying to diminish the problems you’re dealing with (and I really hope MT puts some effort into fixing it), but BGP was basically designed for routing b...
by Larsa
Tue Jan 28, 2025 7:45 pm
Forum: General
Topic: Error connecting to L2TP/IPSec server
Replies: 3
Views: 1256

Re: Error connecting to L2TP/IPSec server

Okay, if the VPS is running some kind of Windows, did you restart it after changing the AssumeUDPEncapsulationContextOnSendRule settings? Here are a few more ideas: - Even if the ISAKMP session is established, a firewall or NAT might be blocking the ESP packets between the client and server. Double-...
by Larsa
Tue Jan 28, 2025 4:44 pm
Forum: General
Topic: Winbox 4 does not display system note correctly
Replies: 5
Views: 1205

Re: Winbox 4 does not display system note correctly

Same here, v4 still needs some more work before it’s usable.
by Larsa
Tue Jan 28, 2025 4:37 pm
Forum: General
Topic: Error connecting to L2TP/IPSec server
Replies: 3
Views: 1256

Re: Error connecting to L2TP/IPSec server

Just a guess, but check this out: viewtopic.php?t=175528
by Larsa
Tue Jan 28, 2025 4:19 pm
Forum: General
Topic: Winbox 4 does not display system note correctly
Replies: 5
Views: 1205

Re: Winbox 4 does not display system note correctly

@encrypted - Welcome to the forum! You might get more attention if you post your issue in the dedicated thread: "WinBox 4 is here".
by Larsa
Tue Jan 28, 2025 2:49 pm
Forum: General
Topic: IPSEC multiple policy with p2p
Replies: 15
Views: 2614

Re: IPSEC multiple policy with p2p

I’m not exactly sure what you’re looking for. Are you trying to add more sites or just filter certain types of traffic? It might be helpful if you could clarify your needs with a brief description of what you’re trying to achieve without IPsec-specific terms.
by Larsa
Mon Jan 27, 2025 10:17 pm
Forum: 3rd party tools
Topic: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management
Replies: 80
Views: 22940

Re: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management

No problem, here you are: ;)
C:\> a:install

Jokes aside, you should be able to install Docker on a PC running Windows.
by Larsa
Mon Jan 27, 2025 7:02 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 6073

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan

VLANs should only be chosen between 2 and 1002 (or 1005 depending on the manual or manufacturer)

Well, not really. But only if you use switches in the early Brontosaurus period ie VTPv1/2 ;)
by Larsa
Mon Jan 27, 2025 3:32 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 1730

Re: IPsec tunnels without known remote IP

Well, it might be, but IMO I doubt it, since the core dataplane library, libstrongswan, itself is about 10-15 MB, and that’s without any cryptographic backends at all. Then you need the control plane with all the management tools and user interfaces. On the other hand, MT might have a special stripp...
by Larsa
Mon Jan 27, 2025 2:47 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 1730

Re: IPsec tunnels without known remote IP

If you find a solution using ROS, please share how you fixed it. Otherwise, there's always StrongSwan, which lets you to dynamically configure policies and assign specific IP ranges or subnets based on the peer's identity (like as FQDN or other attributes) similar to how it was done with racoon
by Larsa
Mon Jan 27, 2025 1:16 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 1730

Re: IPsec tunnels without known remote IP

@pe1chl, does it matter which side is the responder or initiator? If not, both ends could act as initiators using DDNS. Regarding dynamic IPs, the same basic issues apply as with WG. Most ISPs don’t change IPs mid-session as long as the traffic is frequent enough, so some kind of keep-alive mechanis...
by Larsa
Mon Jan 27, 2025 10:23 am
Forum: General
Topic: GRE over IPSec tunnel - unusable on RB4011 above 7.15.3
Replies: 6
Views: 1309

Re: GRE over IPSec tunnel - unusable on RB4011 above 7.15.3

@mwisniewski, how do iperf3 tests for UDP or TCP with different packet sizes impact throughput and CPU usage? Have you tried different algorithms for IPsec Hardware acceleration? Is there an RB4011 on both ends?
by Larsa
Sun Jan 26, 2025 7:07 pm
Forum: General
Topic: Implementing QoS on Mikrotik Router
Replies: 1
Views: 1075

Re: Implementing QoS on Mikrotik Router

Check out this example: https://mikrocloud.com/blog/qos/tos-and-dscp. For a more versatile way to prioritize important traffic without specifying traffic types, CAKE might be a better option. Check out this blog: " CAKE Configuration " and this thread: https://forum.mikrotik.com/viewtopic....
by Larsa
Sat Jan 25, 2025 9:43 pm
Forum: Wireless Networking
Topic: Best Way to Wireless Bridge 1st and 3rd Floor in an old apartment building (Thick Floors/Walls)
Replies: 13
Views: 3300

Re: Best Way to Wireless Bridge 1st and 3rd Floor in an old apartment building (Thick Floors/Walls)

Yeah, there are BIMMF fibers (Bend-Insensitive Multimode Fibers) designed for really tight spaces that can be bent with a radius as small as 7.5 mm to 15 mm (depending on the cable specs). BIMMF can be bought pre-terminated in different fixed lengths too. @mmbln - If you can't find a suitable condui...
by Larsa
Fri Jan 24, 2025 11:38 pm
Forum: General
Topic: OSPF ECMP
Replies: 1
Views: 944

Re: OSPF ECMP

What kind of problems are you referring to? Got any good examples? From what I can tell, there’s no direct relationship between OSPF (IP), MLAG (L2), and ECMP (IP) When it comes to your specific issue, it’s hard to follow exactly what’s going on since your description mixes server environments with ...
by Larsa
Fri Jan 24, 2025 10:30 pm
Forum: General
Topic: fq_codel/CAKE stories? [SOLVED]
Replies: 25
Views: 4929

Re: fq_codel/CAKE stories? [SOLVED]

I remain curious as for the reasoning for overriding the default flow mode.

Just trying to follow the reasoning, 'overriding' as in any of the examples in this thread?
by Larsa
Fri Jan 24, 2025 7:59 pm
Forum: General
Topic: IPSEC multiple policy with p2p
Replies: 15
Views: 2614

Re: IPSEC multiple policy with p2p

@dakobg – Since this is just a user forum, you might get more attention by contacting Mikrotik support or sales directly, particularly if you have a business case that requires VTI.
by Larsa
Fri Jan 24, 2025 2:06 pm
Forum: Forwarding Protocols
Topic: [OSPF][iBGP] route filtering syntax help [SOLVED]
Replies: 16
Views: 3190

Re: [OSPF] adding cost on backbone neighbor [SOLVED]

The issue starts when each WAN point learns the OSPF routes via iBGP, My concentrator then sees the routes coming from both WAN points, picks 1 to get to all said routes, and uses the other as a backup to get to all routes. the only logical thing I can think of is to add filters to add a weigh metr...
by Larsa
Thu Jan 23, 2025 8:13 pm
Forum: General
Topic: MikroTik routers Hijacked by botnet
Replies: 9
Views: 1717

Re: MikroTik routers Hijacked by botnet

Yes, that’s the correct understanding. It’s just as protected as a router should be by default. Opening services to the internet involves major risks, bug or not. This applies to all types of routers, not just Mikrotik.
by Larsa
Thu Jan 23, 2025 8:01 pm
Forum: General
Topic: IPSEC multiple policy with p2p
Replies: 15
Views: 2614

Re: IPSEC multiple policy with p2p

@mdd: Do you mean SVI (Switched Virtual Interface) as a VLAN interface?

Regarding IPsec’s built-in "traffic selectors", I agree with Sindy; it can easily become an overcomplicated mess and is better handled using routing or other filtering mechanisms.
by Larsa
Thu Jan 23, 2025 7:47 pm
Forum: General
Topic: Support takes too long to respond to followed-up tickets
Replies: 8
Views: 1576

Re: Support takes too long to respond to followed-up tickets

@nkourtzis - Just curious, why are you using OSPF on top of ZeroTier?
by Larsa
Thu Jan 23, 2025 6:52 pm
Forum: Forwarding Protocols
Topic: [OSPF][iBGP] route filtering syntax help [SOLVED]
Replies: 16
Views: 3190

Re: [OSPF] adding cost on backbone neighbor [SOLVED]

@Byron – I might have missed or misunderstood something, so this is just a guess: I presume you’re advertising default gateways for both "network stacks" through the red (backup) link. To start troubleshooting, try checking one of the nodes and looking at the distance in the routing tables...
by Larsa
Wed Jan 22, 2025 11:19 pm
Forum: General
Topic: Disappointing Wireguard Performance [SOLVED]
Replies: 25
Views: 3275

Re: Disappointing Wireguard Performance [SOLVED]

From a performance perspective WireGuard is far superior … I 100% agree with @CGGXANNX …

Well, let's say it's a very good and performant solution for the prosumer enthusiast that plays well with single connections. :-D
by Larsa
Wed Jan 22, 2025 12:37 pm
Forum: General
Topic: Disappointing Wireguard Performance [SOLVED]
Replies: 25
Views: 3275

Re: Disappointing Wireguard Performance [SOLVED]

You're welcome! :-D I forgot to mention that the same issue with dynamic IP addresses might affect Wireguard too, since it's not just unique to IPsec.
by Larsa
Wed Jan 22, 2025 11:48 am
Forum: General
Topic: Disappointing Wireguard Performance [SOLVED]
Replies: 25
Views: 3275

Re: Disappointing Wireguard Performance [SOLVED]

A dynamic IP address with IPSec generally isn't a problem if you're using DDNS, as long as the IP address doesn't change in the middle of a session. If you're using some sort of keep-alive traffic like IPsec dpd-interval, it's unlikely to happen. In case it does, there are household scripts that can...
by Larsa
Wed Jan 22, 2025 11:21 am
Forum: General
Topic: Disappointing Wireguard Performance [SOLVED]
Replies: 25
Views: 3275

Re: Disappointing Wireguard Performance [SOLVED]

If you were just using GRE, the tunnel wasn’t encrypted, so you’d get speeds pretty close to raw line speed. WireGuard’s encryption is done in software since it doesn’t support hardware acceleration on any platform. If you want a faster encrypted tunnel, go for an IPsec-based one. Just make sure you...
by Larsa
Tue Jan 21, 2025 2:50 pm
Forum: Virtualization
Topic: Why is Zerotier unavailable on X86 CHR?
Replies: 2
Views: 987

Re: Why is Zerotier unavailable on X86 CHR?

You’d probably have to ask Mikrotik directly to get the real reason. Since this is just a user forum, we can only guess, and our opinions probably don’t affect their design decisions anyway. One plus of running ZeroTier externally is that you get full access to all configuration settings, which are ...
by Larsa
Tue Jan 21, 2025 8:38 am
Forum: General
Topic: Is there file system and/or memory encryption system?
Replies: 1
Views: 780

Re: Is there file system and/or memory encryption system?

Intel TME doesn’t add much in a locked-down setup like Mikrotik ROS since the environment is already pretty tightly controlled, leaving little room for the kind of physical memory attacks TME is designed to prevent in servers using Intel processors etc.
by Larsa
Mon Jan 20, 2025 7:36 pm
Forum: Virtualization
Topic: AWS X86 ROS7.17 [SOLVED]
Replies: 4
Views: 1269

Re: AWS X86 ROS7.17 [SOLVED]

AWS Security Groups are pretty much limited to basic Layer 3 stuff.
by Larsa
Sat Jan 18, 2025 10:12 pm
Forum: Containers
Topic: Looking for Docker container ideas for RouterOS
Replies: 125
Views: 45187

Re: Looking for Docker container ideas for RouterOS

FWIW, one should at least be aware that WINS has several security vulnerabilities that Microsoft hasn’t and won’t patch. If possible, I’d avoid WINS altogether. That said, it’s possible to run WINS in parallel while implementing IP-based name resolution using, for example, Samba as an Active Directo...
by Larsa
Sat Jan 18, 2025 10:11 pm
Forum: General
Topic: Feature Request: WINS Server
Replies: 8
Views: 5007

Re: Feature Request: WINS Server

FWIW, one should at least be aware that WINS has several security vulnerabilities that Microsoft hasn’t and won’t patch. If possible, I’d avoid WINS altogether. That said, it’s possible to run WINS in parallel while implementing IP-based name resolution using, for example, Samba as an Active Directo...
by Larsa
Sat Jan 18, 2025 5:37 pm
Forum: Containers
Topic: Looking for Docker container ideas for RouterOS
Replies: 125
Views: 45187

Re: Looking for Docker container ideas for RouterOS

WINS is a 31-year-old, obsolete Microsoft legacy service and an implementation of the NetBIOS Name Service (NBNS) that was needed for MS Windows 95 and earlier versions. Starting with Windows XP in 2001 , newer versions switched to using DNS, so WINS isn’t really necessary anymore. Since it’s no lon...
by Larsa
Sat Jan 18, 2025 5:37 pm
Forum: General
Topic: Feature Request: WINS Server
Replies: 8
Views: 5007

Re: Feature Request: WINS Server

WINS is a 31-year-old, obsolete Microsoft legacy service and an implementation of the NetBIOS Name Service (NBNS) that was needed for MS Windows 95 and earlier versions. Starting with Windows XP in 2001 , newer versions switched to using DNS, so WINS isn’t really necessary anymore. Since it’s no lon...
by Larsa
Fri Jan 17, 2025 2:19 pm
Forum: Wireless Networking
Topic: Perimeter Network Design - Assistance
Replies: 5
Views: 1543

Re: Perimeter Network Design - Assistance

If this installation is for a business, I’d recommend opting for a wired setup with PoE and avoiding Hikvision for obvious reasons.
by Larsa
Thu Jan 16, 2025 1:43 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

Assuming that more than one request comes from each unique IP, implementing rate limits can at least help mitigate the issue. It would require someone with a strong dislike for MikroTik and control over an entire ASN to send, for example, 5000 requests using 5000 unique IPs. You can easily grab che...
by Larsa
Tue Jan 14, 2025 9:26 am
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

It's definitely not a crawler, and it seems like the DDoS attacks are getting worse.
DDoS 01142025.png
by Larsa
Mon Jan 13, 2025 10:54 pm
Forum: General
Topic: Mikrotik for long-haul fiber.
Replies: 15
Views: 1993

Re: Mikrotik for long-haul fiber.

Sorry Sindy, that’s where our opinions go in completely different directions. Heat management is a challenge even in colder climates, so I’m pretty sure you’ll never be able to go fanless in backbone installations in a country like Congo. Also, if you suspect that Mikrotik uses fans with poor bearin...
by Larsa
Mon Jan 13, 2025 8:59 pm
Forum: General
Topic: Mikrotik for long-haul fiber.
Replies: 15
Views: 1993

Re: Mikrotik for long-haul fiber.

The 98DX82xx in the CRS317 supports large packet buffers, just like other high-end switches that come with a large amount of RAM. My guess is we'll see this implemented in the datacenter switches first.
by Larsa
Mon Jan 13, 2025 8:24 pm
Forum: General
Topic: Mikrotik for long-haul fiber.
Replies: 15
Views: 1993

Re: Mikrotik for long-haul fiber.

As I mentioned in my previous post, I think a fanless desktop switch like the CRS309 isn’t a good choice for a climate like Congo’s, especially with 10G SFPs that generate a lot of heat. That said, the CRS317 would probably be a better fit as a backbone switch. It’s a shame MikroTik hasn’t implement...
by Larsa
Mon Jan 13, 2025 6:11 pm
Forum: General
Topic: Mikrotik for long-haul fiber.
Replies: 15
Views: 1993

Re: Mikrotik for long-haul fiber.

The suggested modifications and tips for cabinet ventilation probably work great, but I’d try to avoid DIY solutions as much as possible. When you're building fiber solutions in rural areas with long distances between all tech hubs and distributed switch cabinets, you definitely want everything to b...
by Larsa
Mon Jan 13, 2025 2:51 pm
Forum: General
Topic: Mikrotik for long-haul fiber.
Replies: 15
Views: 1993

Re: Mikrotik for long-haul fiber.

First of all, I don’t think a passive (fanless) switch like the CRS309 is a good choice for a climate like Congo’s, especially with 10G SFPs that can generate a lot of heat. Secondly, you really need to do some serious hands-on testing to ensure those YXFiber China modules actually work with MikroTi...
by Larsa
Mon Jan 13, 2025 11:37 am
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

DDoS again? I'm getting a lot of 500 Internal Server Errors..
by Larsa
Mon Jan 13, 2025 10:45 am
Forum: General
Topic: Mikrotik for long-haul fiber.
Replies: 15
Views: 1993

Re: Mikrotik for long-haul fiber.

You probably need to provide some more details to get a decent answer, such as: Is it for a business case using dark fiber? A single link or an aggregator of multiple 10G links to different locations (how many)? Is there a need for redundancy? Which compatible SFP+ modules? Need L2 filtering?
by Larsa
Mon Jan 13, 2025 9:45 am
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 147968

Re: v7.17rc [testing] is released!

@merkkg - If you’ve got an important business case, you can ask support for a special custom patch to test in the meantime. If you’re just eager for new features, it’s probably better to wait for a stable version.
by Larsa
Mon Jan 13, 2025 9:28 am
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 147968

Re: v7.17rc [testing] is released!

Completely agree. I don't see the point of rushing things for the sake of it!
by Larsa
Thu Jan 09, 2025 4:35 pm
Forum: General
Topic: Question on massive site-to-site VPN implementation
Replies: 13
Views: 2221

Re: Question on massive site-to-site VPN implementation

Jinx is what you say when two people say (or write, in this case) almost the same thing at the same time. Is there a similar saying in Greek?
by Larsa
Thu Jan 09, 2025 3:19 pm
Forum: General
Topic: fq_codel/CAKE stories? [SOLVED]
Replies: 25
Views: 4929

Re: fq_codel/CAKE stories? [SOLVED]

Great summary!
by Larsa
Thu Jan 09, 2025 12:40 pm
Forum: General
Topic: fq_codel/CAKE stories? [SOLVED]
Replies: 25
Views: 4929

Re: fq_codel/CAKE stories? [SOLVED]

Please add a built-in 'auto-rate' that dynamically adjusts Cake's settings to match network speeds when LTE/NR congestion fluctuates.
by Larsa
Thu Jan 09, 2025 11:58 am
Forum: General
Topic: New Mikrotik Visio stencils
Replies: 2
Views: 1788

Re: New Mikrotik Visio stencils

@LFHarada – you could ask sales and marketing for any product brochures at 'sales@mikrotik.com' or use the product galleries to import pics into Visio, for example: https://mikrotik.com/product/crs504_4xq ... tn-gallery.
by Larsa
Thu Jan 09, 2025 8:11 am
Forum: General
Topic: Will MikroTik firewall appliances...
Replies: 4
Views: 1670

Re: Will MikroTik firewall appliances...

You can already use Snort with ROS. But how were you thinking of implementing IPS/IDS with Snort when almost all traffic is encrypted these days?
by Larsa
Thu Jan 09, 2025 3:21 am
Forum: General
Topic: BFD at ros-7.16.2 dies without any ability to bring it up
Replies: 3
Views: 1431

Re: BFD at ros-7.16.2 dies without any ability to bring it up

Since you didn’t provide an export or details about the virtual environment, here’s a guess: try increasing the RAM for the ROS virtual guest and monitor memory usage after the next restart.
by Larsa
Wed Jan 08, 2025 4:55 pm
Forum: General
Topic: Question on massive site-to-site VPN implementation
Replies: 13
Views: 2221

Re: Question on massive site-to-site VPN implementation

Jinx! But with way better details than I was able to provide. :-D
by Larsa
Wed Jan 08, 2025 4:45 pm
Forum: General
Topic: Question on massive site-to-site VPN implementation
Replies: 13
Views: 2221

Re: Question on massive site-to-site VPN implementation

@nkourtzis: With 60 sites/subnets, it’s hard to recommend anything other than an SD-WAN solution like ZeroTier. It costs around $105/month and requires minimal effort for setup, operations, and management compared to other options. Plus, ZT handles CGNAT and dynamic ip addresses. If high-speed links...
by Larsa
Tue Jan 07, 2025 9:57 pm
Forum: 3rd party tools
Topic: 🚀 RemoteWinBox Admiral centralized MikroTik Management
Replies: 10
Views: 5060

Re: 🚀 RemoteWinBox Admiral centralized MikroTik Management

What about platform security? Not a single word mentioned (unless I missed it).
by Larsa
Tue Jan 07, 2025 1:22 am
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 86
Views: 64280

Re: Newsletter #122 | December 2024

That LTE is supposed to be terribly slow isn’t true.
by Larsa
Fri Dec 20, 2024 7:40 pm
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 86
Views: 64280

Re: Newsletter #122 | December 2024

Happy holidays everyone!
by Larsa
Wed Dec 11, 2024 3:01 pm
Forum: Beginner Basics
Topic: Mikrotik Cloud Router - MGMT IP address issues
Replies: 5
Views: 1781

Re: Mikrotik Cloud Router - MGMT IP address issues

@UltraIsp4883; please don't cross-post (https://forum.mikrotik.com/viewtopic.php?t=213209) And as @Anav pointed out: It’s pretty tough to help out if you don’t explain exactly what’s not working, share a brief overview of the network topology and provide a full config export (minus anything that nee...
by Larsa
Wed Dec 11, 2024 1:53 pm
Forum: Beginner Basics
Topic: Need HELP!!!!!!!!
Replies: 2
Views: 1552

Re: Need HELP!!!!!!!!

It’s pretty tough to help out if you don’t explain exactly what’s not working, share a brief overview of the network topology and provide a full config export (minus anything that needs to be left out for privacy reasons). This migh help: https://forum.mikrotik.com/viewtopic.php?t=203686#p1051720 Ot...
by Larsa
Wed Dec 11, 2024 1:45 pm
Forum: General
Topic: IP Cloud (Dynamic DNS) down?
Replies: 101
Views: 17370

Re: mynetname is down ?

From: @rextended to @jontne
From @normis:
We have identified the issue and a fix is coming shortly.

Yeah, since Normis is not saying the issue has actually been fixed, just that they've identified it. So we’ll have to wait for feedback, hopefully coming when it's done.
by Larsa
Wed Dec 11, 2024 1:27 pm
Forum: Scripting
Topic: [Tutorial] Update Cloudflare DNS record by script.
Replies: 2
Views: 1563

Re: [Tutorial] Update Cloudflare DNS record by script.

You should add a status check for the update API. There are tons of scripts on GitHub you can check out to see how it’s done: "github mikrotik cloudflare ddns script"
by Larsa
Wed Dec 11, 2024 9:42 am
Forum: General
Topic: IP Cloud (Dynamic DNS) down?
Replies: 101
Views: 17370

Re: mynetname is down ?

Is there any alternative solution we can use to ensure a stable connection? We depend on this service for critical operations, so having a reliable alternative or knowing when it will be restored would be greatly appreciated. Pro tip: Don’t use these services for business-critical operations. We’ve...
by Larsa
Wed Dec 11, 2024 8:45 am
Forum: General
Topic: IP Cloud (Dynamic DNS) down?
Replies: 101
Views: 17370

Re: mynetname is down ?

Still down. Likely a DDOS attack on all services since even the forum feels sluggish.
by Larsa
Mon Dec 09, 2024 8:34 am
Forum: RouterOS beta
Topic: CCR2216 + HW Offload + BGP = crash
Replies: 21
Views: 10635

Re: CCR2216 + HW Offload + BGP = crash

@webtelza: This is just a user forum. Please report bugs directly to Mikrotik support: https://mikrotik.com/support.
by Larsa
Fri Dec 06, 2024 4:29 pm
Forum: Scripting
Topic: Layer 7 Regex for Bank websites
Replies: 5
Views: 3715

Re: Layer 7 Regex for Bank websites

You’re aware this comment is from July 26, 2016, right? A true blast from the past, Cheers! ;-)
by Larsa
Wed Dec 04, 2024 4:41 pm
Forum: General
Topic: Really bad queue bug in v7 on x86
Replies: 2
Views: 1360

Re: Really bad queue bug in v7 on x86

This is just a user forum; please report issues directly to Mikrotik support.
by Larsa
Wed Dec 04, 2024 10:33 am
Forum: General
Topic: RDP HELP!
Replies: 31
Views: 5587

Re: RDP HELP!

It doesn't necessarily have to be the router that's the main problem. A tip is to troubleshoot using the Windows Event Log on both the RDP clients and the server. A good place to start is the guide " Microsoft - Troubleshoot Remote Desktop Disconnected Errors ". This might also be useful: ...
by Larsa
Tue Dec 03, 2024 7:06 am
Forum: Beginner Basics
Topic: Port forwarding FQDN
Replies: 3
Views: 1536

Re: Port forwarding FQDN

@AE8U, try to avoid exposing your internal network devices with open ports whenever possible. Instead, consider using VPN like WireGuard or ZeroTier. MikroTik has a built-in DDNS feature for handling dynamic IP changes called IP Cloud.
by Larsa
Fri Nov 29, 2024 8:33 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 39
Views: 4102

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

When I started the thread earlier, the initial handshake had to finish before the connection state became "established"[*] which prevented mangling from working. I see you’re using NAT, which might be affecting things similarly to routing rules. Have you tried running a packet trace (assum...
by Larsa
Fri Nov 29, 2024 7:27 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 39
Views: 4102

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

Perhaps you didn't read the whole thread and might have missed the most crucial parts: 1) During WG's initial handshake, there's no "connection state," so mangle rules can't apply 2) The initial handshake response always egresses through the default gateway unless you trick ROS into using ...
by Larsa
Fri Nov 29, 2024 6:14 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 39
Views: 4102

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

I just tested the rules as I have quoted on an rb5009 running 7.17rc1, and the mangle absolutely works for the initial handshake. Alright, good to know it works with 7.17rc1. Not sure when this changed, but it didn’t work before. If mangle works, that’s a third option along with NAT and routing rul...
by Larsa
Fri Nov 29, 2024 5:32 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 39
Views: 4102

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

@divB, you're absolutely right to point out that this is a flawed implementation of WireGuard and it drove me nuts too before the root cause was identified. The good news is that it’s actually pretty easy for MikroTik to fix if they decide to. WireGuard works perfectly on Linux with the standard too...
by Larsa
Sun Nov 24, 2024 6:00 pm
Forum: General
Topic: AWS Wireguard Slow
Replies: 21
Views: 2149

Re: AWS Wireguard Slow

@Slartybart: Yeah, you’ll probably be just fine sticking with WireGuard. Another reason to go with it is that it’s much easier to manage than IPsec if you’re not experienced. If you somehow need maximum throughput, you might want to look into getting IPsec to work with hardware acceleration. -- @hol...
by Larsa
Sun Nov 24, 2024 9:13 am
Forum: General
Topic: AWS Wireguard Slow
Replies: 21
Views: 2149

Re: AWS Wireguard Slow

Thank you, but yet again, not a single word about IPsec hardware acceleration which WireGuard completely lacks.

Still, it’s always nice to see such enthusiastic contributions from a cheerful enthusiast. :-D
by Larsa
Sun Nov 24, 2024 12:27 am
Forum: General
Topic: AWS Wireguard Slow
Replies: 21
Views: 2149

Re: AWS Wireguard Slow

Haha, yeah, that article was really 'professional,' but hey, not bad for a basement hacker who clearly has no clue whatsoever about AES hardware acceleration. Nice try though! :-D
by Larsa
Sun Nov 24, 2024 12:15 am
Forum: General
Topic: Map Lite - Cant get this thing to work!
Replies: 6
Views: 2094

Re: Map Lite - Cant get this thing to work!

Hey @muaazteladia, welcome to the forum! Great to see more knowledgeable and dedicated people joining us. Have a nice weekend! :-)
by Larsa
Sat Nov 23, 2024 8:24 pm
Forum: General
Topic: AWS Wireguard Slow
Replies: 21
Views: 2149

Re: AWS Wireguard Slow

@holvoetn: When testing Tik to Tik with both devices capable of HW offloading IPSEC, WG is still faster. My view ... Well, I’m not sure what you’re basing your claims on, but IPsec with hardware acceleration is always faster than WireGuard— and that’s a fact! :-D Also, all AWS instance types, like ...
by Larsa
Sat Nov 23, 2024 1:40 pm
Forum: General
Topic: AWS Wireguard Slow
Replies: 21
Views: 2149

Re: AWS Wireguard Slow

@Slartybart: As WireGuard relies entirely on ChaCha20, which is a pure software encryption , throughput depends directly on the CPU power, so a slower CPU means slower throughput. For maximum throughput on AWS, consider using IPSec, though be aware that there might be a throughput cap depending on t...
by Larsa
Fri Nov 22, 2024 5:23 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

You can't just set up one subdomain in cloudflare and keep the rest in another DNS server, the NS servers have to be set to cloudflare, all mikrotik.com DNS will be managed through there. Yes, you can! There are several ways to do this, like DNS subdomain delegation, partial CNAME setups, and more....
by Larsa
Fri Nov 22, 2024 4:40 pm
Forum: Scripting
Topic: Script triggered by SMS: can I use the phone number in the script [SOLVED]
Replies: 8
Views: 2509

Re: Script triggered by SMS: can I use the phone number in the script [SOLVED]

Aha, now I get what you're asking about! We had the exact same thoughts when we first started testing this feature. It’s really an unfortunate combination of poor documentation and a design flaw in the SMS script execution functionality. You don’t get any info about which number triggered the script...
by Larsa
Fri Nov 22, 2024 12:24 am
Forum: Scripting
Topic: Script triggered by SMS: can I use the phone number in the script [SOLVED]
Replies: 8
Views: 2509

Re: Script triggered by SMS: can I use the phone number in the script [SOLVED]

The SMS data contains the phone number of the sender who initiated the script with the ':cmd' syntax. Maybe I'm misunderstanding what you're trying to achieve, but we're using scripts with MT LTE CPEs to perform actions like checking status, reboots, etc, as a last resort if our normal out-of-band m...
by Larsa
Thu Nov 21, 2024 10:58 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

There's no need to fake anything since there are no restrictions on anonymous access (tho creating a post is). Your suggestion might very well work, but it could end up being like robbing Peter to pay Paul. :D
by Larsa
Thu Nov 21, 2024 10:02 pm
Forum: Scripting
Topic: Script triggered by SMS: can I use the phone number in the script [SOLVED]
Replies: 8
Views: 2509

Re: Script triggered by SMS: can I use the phone number in the script [SOLVED]

Long story short, unfortunately you can’t use digits as indexes in scripts, only in the terminal. Instead, you’ll need to use indexes like "id," as shown below, where "id" is just a variable that can be named anything /tool sms :foreach id in=[inbox find where message~"^*.&q...
by Larsa
Thu Nov 21, 2024 6:50 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

Just an example of Cloudflare's pricing model : Pro - for professional websites that aren’t business-critical, $25 /month. Business - for small businesses operating online, $250 /month. All plans come with unmetered DDoS protection, they just differ in uptime SLA and number of rules for advanced set...
by Larsa
Thu Nov 21, 2024 6:03 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

No, just " forum.mikrotik.com ". But don’t take my word for it, call or email some of them and they’ll explain how it works. Btw, here's a list of popular DDoS protection service providers. Most providers have their services spread out across all continents, and in many cases, you can pick...
by Larsa
Thu Nov 21, 2024 5:22 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

Now would be a good time to check the logs for user agents. May come up empty thou since you can use any valid user agents. I’m only gonna say this once: with a proper DDoS firewall that also catches other bad stuff, you don’t have to bother about invalid user agents since they’ll get blocked anywa...
by Larsa
Thu Nov 21, 2024 4:45 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

We have disabled the search robots, except biggest ones, but the attacks are regular DDoS attacks going to different IP every time. We are trying to optimize the forum servers to handle bigger loads, but the attacks keep getting bigger too. Since PHPBB is old software, another option would be to mi...
by Larsa
Thu Nov 21, 2024 1:33 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

Well, here we go again! Now at about 1200 sessions and still climbing. Someone must be really pissed at MT...
by Larsa
Thu Nov 21, 2024 10:49 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1917
Views: 616752

Re: 📣 WinBox 4 is here 📣

No problem. We’ll keep using Winbox 3/Wine for now, since v4 still has too many limitations anyway.
by Larsa
Wed Nov 20, 2024 2:10 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

Since guest session counts are back to normal, I’m guessing MT introduced some kind of measure, but I doubt we’ll ever find out what it was.
by Larsa
Tue Nov 19, 2024 11:33 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

If you need serious DDoS protection as a front-end service, it takes massive computing resources, expert skills, and experience.

Normally, IMO that’s not something a company like MT could manage on-premise by themselves.
by Larsa
Tue Nov 19, 2024 10:00 pm
Forum: Forwarding Protocols
Topic: Wireguard issues with OSPF [SOLVED]
Replies: 9
Views: 3328

Re: Wireguard issues with OSPF [SOLVED]

@anav, it’s your call!

Once you figure out what triggers OSPF LSA state changes on a single WireGuard interface (using OSPF type PTP) connected to multiple peers/subnets, adding two tunnels to your VPS will be a breeze.
by Larsa
Tue Nov 19, 2024 9:27 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

Sorry, my bad!

I meant before MT gives in and adds a third-party DDoS protection service.
by Larsa
Tue Nov 19, 2024 8:06 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

Haha! 😛

Either way, it really doesn’t matter how it’s done, the pikes in guest session count clearly points to a classic DDoS attack (IMO)

It’ll be interesting to see who holds out the longest in this battle, MT or the DDoS drivers. This kind of volume is pretty cheap to buy on the dark web. 
by Larsa
Tue Nov 19, 2024 7:43 pm
Forum: Forwarding Protocols
Topic: Wireguard issues with OSPF [SOLVED]
Replies: 9
Views: 3328

Re: Wireguard issues with OSPF [SOLVED]

Suddenly an OSPF expert!? 😘
by Larsa
Tue Nov 19, 2024 2:24 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

But I always block all search bot and never had an issue with max session limit hit. And yes even Google misbehaves at times. It’s extremely rare nowadays for big companies using index bots to misbehave. If there’s a problem, it’s usually a misconfiguration on your end. Also, legal index bots don’t...
by Larsa
Tue Nov 19, 2024 1:35 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

These “legal” index bots don’t cause spikes in guest session counts, so it’s most likely a DDoS attack going on.

EDIT: I still occasionally get “500 Internal Server Error.”
by Larsa
Tue Nov 19, 2024 7:01 am
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

Yup, seems like there’s still some kind of DDoS attack going on. The session count keeps bouncing between a few hundred and 1200-1300.
by Larsa
Sat Nov 16, 2024 5:38 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

A spike in session counts is usually a good indicator of a DDoS attack.
by Larsa
Sat Nov 16, 2024 3:10 am
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 180196

Re: v7.17beta [testing] is released!

No worries ya all!

Should MT decide to keep device mode in its current glorious form, just remember—we’re always here for you! 😄

Button-pushers.com

IMG_2527.jpeg
by Larsa
Sat Nov 16, 2024 12:57 am
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 773
Views: 180196

Re: v7.17beta [testing] is released!

… Sometimes on obscure places (hard, hard to reach physically). Still they insist on the button push confirmation thing.

There must be an alternative approach.

No worries, we rent out specially trained button-pushers worldwide.
IMG_2529.jpeg
by Larsa
Sat Nov 16, 2024 12:18 am
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

Yeah, that “help” doesn’t do much to stop real DDoS attacks. Pretty sure MT staff mentioned this in the forum too.

A must-read for the MT team: ”Distributed denial-of-service (DDoS) protection
by Larsa
Fri Nov 15, 2024 10:21 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 17513

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

Might be time to try out a frontend like Cloudflare or similar to get rid of the DDoS attacks.
by Larsa
Fri Nov 15, 2024 1:13 pm
Forum: General
Topic: AZURE AD/ Entra ID
Replies: 1
Views: 667

Re: AZURE AD/ Entra ID

I assume you're talking about a radius connection to NPS. If you dont already have it, just set up a tunnel to your Azure AD - oh, sorry, I meant Entra ID ! :wink: Btw, I honestly can’t stand these pointless brand renames.. https://learn.microsoft.com/en-us/azure/vpn-gateway/tutorial-site-to-site-po...
by Larsa
Fri Nov 15, 2024 12:09 am
Forum: Forwarding Protocols
Topic: Wireguard issues with OSPF [SOLVED]
Replies: 9
Views: 3328

Re: Wireguard issues with OSPF [SOLVED]

It’s pretty tough to help out if you don’t explain exactly what’s not working, share a brief overview of the network topology and provide a full config export (minus anything that needs to be left out for privacy reasons). Also, using a single WireGuard interface with multiple active peers can be tr...
by Larsa
Thu Nov 14, 2024 10:56 pm
Forum: General
Topic: 💀⚠️CRITICAL: Never trust who provides scripts containing "/import" from "/tool fetch" from external sources.
Replies: 35
Views: 6049

Re: 💀⚠️CRITICAL: Never trust who provides scripts containing "/import" from "/tool fetch" from external sources.

You’re spot on, it’s exactly the vetting process that’s the weak link! There are plenty of techical tools to lock down a GitHub repo, but it’s up to the owners/admins to decide how to use them. In the case of the XZ backdoor, the attacker got in using social engineering which let the villains access...
by Larsa
Thu Nov 14, 2024 8:37 pm
Forum: General
Topic: 💀⚠️CRITICAL: Never trust who provides scripts containing "/import" from "/tool fetch" from external sources.
Replies: 35
Views: 6049

Re: 💀⚠️CRITICAL: Never trust who provides scripts containing "/import" from "/tool fetch" from external sources.

Probably true, but there’s always a chance of hidden backdoors, like the "XZ backdoor". With popular solutions, it’s easier to spot and handle malicious hacks and put in countermeasures because of the sheer number of people involved. But if you’re using less reliable sources, the risk goes...
by Larsa
Thu Nov 14, 2024 7:10 pm
Forum: General
Topic: 💀⚠️CRITICAL: Never trust who provides scripts containing "/import" from "/tool fetch" from external sources.
Replies: 35
Views: 6049

Re: 💀⚠️CRITICAL: Never trust who provides scripts containing "/import" from "/tool fetch" from external sources.

@LAYERWEB - What rextended is suggesting is that you should avoid trusting or automatically downloading third-party ROS scripts. An untrusted source could include elements that compromise your router’s security. If you want to work with scripts, download only raw data and write your own script direc...
by Larsa
Thu Nov 14, 2024 5:26 pm
Forum: Beginner Basics
Topic: How to configure PBR in CCR2116-12G-4S+ v7.8
Replies: 3
Views: 1437

Re: How to configure PBR in CCR2116-12G-4S+ v7.8

The interweb grinds to a halt, the family descends into chaos, and Koemleang gets verbally roasted! 😆
by Larsa
Thu Nov 14, 2024 7:19 am
Forum: General
Topic: VRRP with single WAN and Single LAN Address
Replies: 34
Views: 3366

Re: VRRP with single WAN and Single LAN Address

Just curious if you happened to check the ESXi logs to find the root cause? Anyway, feel free to get back here if you find anything interesting for future reference.
by Larsa
Wed Nov 13, 2024 5:23 pm
Forum: General
Topic: VRRP with single WAN and Single LAN Address
Replies: 34
Views: 3366

Re: VRRP with single WAN and Single LAN Address

If you don’t find any obvious reason in ROS for the VRRP state change, check the ESXi logs for the virtual NIC (referring to my previous post).
by Larsa
Wed Nov 13, 2024 12:59 am
Forum: Beginner Basics
Topic: Coming from Cisco with a newbie question
Replies: 1
Views: 1271

Re: Coming from Cisco with a newbie question

This might be a good start: ”Using RouterOS to VLAN your network
by Larsa
Wed Nov 13, 2024 12:02 am
Forum: General
Topic: VRRP with single WAN and Single LAN Address
Replies: 34
Views: 3366

Re: VRRP with single WAN and Single LAN Address

After discussing the issue internally with some techs, our best guess at this point is that the flip-flop behavior might be caused by a VMware Virtual Network Adapter 'state change' which can happen for various reasons like network congestion, resource constraints, virtual switch misconfigurations, ...
by Larsa
Tue Nov 12, 2024 7:50 pm
Forum: General
Topic: VRRP with single WAN and Single LAN Address
Replies: 34
Views: 3366

Re: VRRP with single WAN and Single LAN Address

Alright, got it. As for load balancing (ie vrrp load sharing) and grouping, have you checked if the ROS version has what you need? It might be worth a look, since it doesn’t have all the ‘bells and whistles’ of the Cisco IOS XR equivalent.
by Larsa
Tue Nov 12, 2024 6:04 pm
Forum: General
Topic: VRRP with single WAN and Single LAN Address
Replies: 34
Views: 3366

Re: VRRP with single WAN and Single LAN Address

Thanks, but I have to admit I'm pretty confused by the network diagram as the image doesn’t seem to follow a clear visual logic and it’s hard to make sense of it without additional context. For example, how does the red-dashed VRRP relate to the four nodes (VRRP1, VRRP2, CHR1, CHR2)? And what role d...
by Larsa
Tue Nov 12, 2024 12:12 am
Forum: General
Topic: VRRP with single WAN and Single LAN Address
Replies: 34
Views: 3366

Re: VRRP with single WAN and Single LAN Address

Just curious, but why not fully utilize the VSM functionality since you already have a bunch of ASR 9Ks? I mean, why use CHRs as edge routers?

Btw, this is how you add an image to a post:
how to upload an image.png
by Larsa
Mon Nov 11, 2024 11:43 pm
Forum: General
Topic: WireGuard site to site routing help
Replies: 23
Views: 2148

Re: WireGuard site to site routing help

I will definitely look into it, but at the moment I dont understand how it works and how it could possibly add failover to a mesh topology? i dont have any other vpn service or second ISP with enough bandwidth to handle alternative routes Got it. Just want to add that OSPF isn’t really tied to othe...
by Larsa
Mon Nov 11, 2024 10:49 pm
Forum: Forwarding Protocols
Topic: OSPF/MPLS Migrations on 7.16.1
Replies: 5
Views: 2625

Re: OSPF/MPLS Migrations on 7.16.1

@digitallystoned - If you think it might be a bug, it’s probably better to check with Mikrotik Support . Otherwise, I’d suggest coming back with a simple network diagram to make it easier to follow your thought process, plus a full export from both devices (minus anything that needs to be left out f...
by Larsa
Mon Nov 11, 2024 8:50 pm
Forum: Wireless Networking
Topic: iOS 18 Wi-Fi connectivity issue [SOLVED]
Replies: 89
Views: 18043

Re: iOS 18 Wi-Fi connectivity issue [SOLVED]

Well, according to Apple Support 'Forget Network' should clear cached auths. Unless there’s a new flaw in iOS 18 I don’t know about..
by Larsa
Mon Nov 11, 2024 8:44 pm
Forum: General
Topic: SMTP Limiting per Users Per day
Replies: 10
Views: 2290

Re: SMTP Limiting per Users Per day

SMTP is always open for business-grade connections and normally closed for regular consumers. If a botnet manages to steal the username and password for your email account, it’ll use ports 587 or 465.
by Larsa
Mon Nov 11, 2024 8:01 pm
Forum: Wireless Networking
Topic: iOS 18 Wi-Fi connectivity issue [SOLVED]
Replies: 89
Views: 18043

Re: iOS 18 Wi-Fi connectivity issue [SOLVED]

Usually, you just need 'Forget Network' to clear cached auths.
by Larsa
Mon Nov 11, 2024 10:43 am
Forum: Scripting
Topic: "ip route find where' strange behavior
Replies: 10
Views: 2027

Re: "ip route find where' strange behavior

@akliouev - look for ”Reserved variable names” in the link the link that @Infabo just posted.
by Larsa
Sun Nov 10, 2024 7:57 pm
Forum: General
Topic: WireGuard site to site routing help
Replies: 23
Views: 2148

Re: WireGuard site to site routing help

I wouldn’t call it overkill. OSPF is actually pretty easy to set up and used with the BFD option you get quick failover if a link goes down. You can always add OSPF later if you want, and you can run it on top of the static routes, which then act as backup routing.
by Larsa
Sun Nov 10, 2024 7:17 pm
Forum: General
Topic: WireGuard site to site routing help
Replies: 23
Views: 2148

Re: WireGuard site to site routing help

If each of your 4 nodes is connected to all the others (ie 6 tunnels in your config), then the answer is yes. But if the other nodes only connect to a central node, the answer is no.
by Larsa
Sun Nov 10, 2024 5:33 pm
Forum: General
Topic: WireGuard site to site routing help
Replies: 23
Views: 2148

Re: WireGuard site to site routing help

@Usbuild - Once you’ve made some progress and set up your WireGuard tunnels, you can start considering a true "mesh solution" where all nodes connect with each other. This setup makes the network more redundant in case any link goes down. Wireguard Mesh.png To avoid adding static routes, t...
by Larsa
Sun Nov 10, 2024 3:14 pm
Forum: General
Topic: ZeroTier Version Upgrade
Replies: 12
Views: 2516

Re: ZeroTier Version Upgrade

Completely agree! I find it hard to understand why MT doesn’t enable the interface for all standard ZeroTier options that are available on every other platform except ROS.
by Larsa
Sun Nov 10, 2024 10:59 am
Forum: General
Topic: ZeroTier Version Upgrade
Replies: 12
Views: 2516

Re: ZeroTier Version Upgrade

Jinx (well, almost) :D
by Larsa
Sun Nov 10, 2024 8:35 am
Forum: General
Topic: ZeroTier Version Upgrade
Replies: 12
Views: 2516

Re: ZeroTier Version Upgrade

What's new in 7.17beta2 (2024-Sep-27 10:07):
zerotier - upgraded to version 1.14.0
by Larsa
Sat Nov 09, 2024 6:10 pm
Forum: Beginner Basics
Topic: How to change the IMEI of Mikrotik SXT LTE6 kit
Replies: 6
Views: 1823

Re: How to change the IMEI of Mikrotik SXT LTE6 kit

Did you follow the guide? There are about 13 commands listed in the example, which one failed?
by Larsa
Thu Nov 07, 2024 3:48 pm
Forum: General
Topic: how to block youtube shorts?
Replies: 12
Views: 2253

Re: how to block youtube shorts?

Btw. setting up SSL decryption is a very common and easy thing, as long as you control all end devices, so that they trust your certificate authority. The most complex part of setting up SSL decryption at a company is to convince the company lawyers and the workers council. At least in Europe. Yeah...
by Larsa
Thu Nov 07, 2024 12:26 pm
Forum: General
Topic: how to block youtube shorts?
Replies: 12
Views: 2253

Re: how to block youtube shorts?

If this is for parental control, some endpoint protection software can manage it, and there are also paid cloud services available for this purpose. For corporate setups, ng-generation firewalls using the middle-man model require a highly complex and expensive configuration, which involves intervent...
by Larsa
Wed Nov 06, 2024 6:55 pm
Forum: Beginner Basics
Topic: How to change the IMEI of Mikrotik SXT LTE6 kit
Replies: 6
Views: 1823

Re: How to change the IMEI of Mikrotik SXT LTE6 kit

If current IMEI is not accepted by your provider, isn't it more logical to switch provider ? It happens that "obscure" NMOs to try to lock customers into equipment that can only be sold by them through various restrictions. In those cases, you might have change the IMEI to one that unlock...
by Larsa
Wed Nov 06, 2024 6:42 pm
Forum: Beginner Basics
Topic: How to change the IMEI of Mikrotik SXT LTE6 kit
Replies: 6
Views: 1823

Re: How to change the IMEI of Mikrotik SXT LTE6 kit

@zionlook: Check this out: https://gist.github.com/Anime4000/e9213bd4eaef502e4675d736c564fb5c # Query which mode /interface lte at-chat lte1 input="AT*PROD\?" "output: *PROD: 0" = production mode "output: *PROD: 1" = non-production mode # Disable LTE interface /interfac...
by Larsa
Wed Nov 06, 2024 4:47 pm
Forum: General
Topic: PPTP no longer working
Replies: 4
Views: 560

Re: PPTP no longer working

@sambo521: Is your customer really okay with using your own equipment as an in-house, co-located router? TBH, this sounds a bit fishy, especially if it’s a big company that likely already has a remote access VPN solution (probably IPsec-based). I'd recommend using that instead. If possible, please g...
by Larsa
Tue Nov 05, 2024 2:18 pm
Forum: Beginner Basics
Topic: Multiple MikroTik on Zerotier Network
Replies: 5
Views: 2282

Re: Multiple MikroTik on Zerotier Network

I might have missed or misunderstood something when I read the description and checked the config, but it seems like you’re using the same subnet for your local networks and ZeroTier, which can get tricky if you’re not careful. Are you planning to bridge (Layer 2/Ethernet) or route (Layer 3/IP) all ...
by Larsa
Tue Oct 29, 2024 9:35 pm
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 3631

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

I suspect you might have missed something, misunderstood, or simply skipped over some posts, so I’ll graciously ignore the grumbling tone. Mr. Znevna, just tell me how I can help you improve your, let’s say, ‘hat-wagering’ skills. Or perhaps you have anything more intriguing to say besides the whini...
by Larsa
Tue Oct 29, 2024 7:47 pm
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 3631

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

Can you quote any part of it which mentions drivers for the Host OS? I haven't had time to check the actual references, but if you mean the drivers for PCIe IO-SRV support, you might for example checkout the vfio-pci driver for Linux, the FreeBSD ppt driver or the Microsoft Windows Driver Model ( W...
by Larsa
Tue Oct 29, 2024 3:15 pm
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 3631

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

Like addressing a FreeBSD request for the unsupported Bhyve? Why not fix the UEFI Boot issue instead? You guys never stop surprising me! ;-)
by Larsa
Tue Oct 29, 2024 2:58 pm
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 3631

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

Well, @mrz, purely educational as a reply to a previous post. But why do you care? This is a user forum, right?! On a more serious note, though, I genuinely (really!) don’t understand Mikrotik’s priorities here. Why address a FreeBSD request for the unsupported Bhyve when there are more pressing iss...
by Larsa
Tue Oct 29, 2024 12:32 pm
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 3631

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

If you're interested in some technical details on SR-IOV, down below are some solid explanations from Red Hat and Intel about different PCI hardware abstraction layers. I’d especially recommend Red Hat’s intro, which covers PCIe Physical Functions (PFs) and PCIe Virtual Functions (VFs), and Intel’s ...
by Larsa
Tue Oct 29, 2024 10:11 am
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 3631

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

Thanks for making that clear once and for all.

And please tell me you didn’t spend an entire weekend just to enable it for FreeBSD! ;-)
by Larsa
Mon Oct 28, 2024 11:59 pm
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 3631

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

Please stop embarrassing yourselves! My best advice is to start exploring how VM drivers work and the differences between various hypervisors, particularly in handling IO-SRV and how it compares to regular PCI passthrough variants like ESXi DirectPath. And once again, all hypervisors have their own ...
by Larsa
Mon Oct 28, 2024 11:10 pm
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 3631

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

if you really pulled off getting MikroTik to add SR-IOV for the T540 in CHR [...] in such a short time in the past i have often complained, loudly and at length, about my issues with MikroTik support. but this case, i opened the ticket on Saturday, and they provided the new build at 10:30 on Monday...
by Larsa
Mon Oct 28, 2024 6:07 pm
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 3631

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

@crosswind - I’ll be the first to tip my hat and give you a shoutout (maybe even eat the hat) if you really pulled off getting MikroTik to add SR-IOV for the T540 in CHR running on the unsupported FreeBSD Bhyve in such a short time. Ps..If that’s the case, I have a bone to pick with MikroTik for not...
by Larsa
Mon Oct 28, 2024 3:32 pm
Forum: RouterOS beta
Topic: Feature Request - NAT64/DNS64 CGN
Replies: 36
Views: 28920

Re: Feature Request - NAT64/DNS64 CGN

PLAT or CLAT, which runs on the end user’s device, or ROS CLAT for centralized translation, tunneling, or other purposes?

FYI, most pure IPv6 ISPs support MAP-E (RFC 7597), which can be managed by IPIPv6 in Mikrotik ROS.
by Larsa
Mon Oct 28, 2024 2:58 pm
Forum: Beginner Basics
Topic: Unable to route via VLANs
Replies: 16
Views: 2184

Re: Unable to route via VLANs

Still trying to get to grips with the eccentricities of Mikrotik VLANs (Much more familiar with Cisco's implementation, so this is a bit of an adjustment for me) Yeah, it's because ROS VLAN bridging is based on Linux DSA (Distributed Switch Architecture) which can be pretty tricky to grasp because ...
by Larsa
Sat Oct 26, 2024 11:51 pm
Forum: Beginner Basics
Topic: Secondary WAN and failover setup hap ax2 (7.16) for a beginner [SOLVED]
Replies: 60
Views: 6044

Re: Secondary WAN and failover setup hap ax2 (7.16) for a beginner [SOLVED]

Just keep in mind that Netwatch might be pretty unreliable on LTE when using Carrier Aggregation (CA), which is the default mode for most connections.
by Larsa
Sat Oct 26, 2024 6:52 pm
Forum: General
Topic: Suggestion for 1500+ VPN endpoints
Replies: 6
Views: 1314

Re: Suggestion for 1500+ VPN endpoints

I was a bit unclear - I meant an example use case for the type of work the organization does, like a neighborhood association or a security solution with SLAs for emergency response, or something similar, possibly with redundancy requirements, etc. Yeah, 1.5 Gbit/s requires heavy-duty equipment for ...
by Larsa
Sat Oct 26, 2024 5:13 pm
Forum: General
Topic: Suggestion for 1500+ VPN endpoints
Replies: 6
Views: 1314

Re: Suggestion for 1500+ VPN endpoints

Besides a decent management interface, you will need a proper VPN concentrator that is powerful enough to handle the expected number of concurrent encrypted VPN sessions. What’s the use case?
by Larsa
Sat Oct 26, 2024 3:04 pm
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 3631

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

I did my best to help, but it seems like you’re more interested in semantics and playing the ‘I said, you said’ blame game. Please refer to my previous message regarding supported platforms. Good luck!
by Larsa
Sat Oct 26, 2024 2:52 pm
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 3631

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

RouterOS as a bare metal x86_64 installation might possibly have drivers for the Chelsio T540, but you need to check with support. If you need help to install CHR on FreeBSD, you can refer to this guide: " Creating a Mikrotik CHR - RouterOS 7 - Bhyve VM in FreeBSD " Depending on what you a...
by Larsa
Sat Oct 26, 2024 2:12 pm
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 3631

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

CHR runs fine on FreeBSD as long as you set up the VM with a compatible VF for SR-IOV or configure the standard drivers properly. That said, SR-IOV won’t give you any extra performance unless you’re sharing the NIC with multiple VMs so the easiest way to get started with bhyve with is to bridge a ta...
by Larsa
Sat Oct 26, 2024 11:07 am
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 3631

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

please read my original post, which is about whether RouterOS x86 / CHR has driver for Chelsio T540-CR VF device. i do not get error or warning, but device does not appear in /interface/print. this is nothing to do with FreeBSD - question is whether RouterOS has driver for this device. This is wher...
by Larsa
Sat Oct 26, 2024 10:44 am
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 3631

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

Yep, it’s also up to the host OS drivers to enable SR-IOV support. The virtual machine can check if SR-IOV is available, but if you try to turn it on without driver support, you’ll just get an error or warning. The host OS still needs proper support for everything required by the virtual machine, so...
by Larsa
Sat Oct 26, 2024 9:27 am
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 3631

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

No, virtual machines support only a limited set of virtual drivers required for the virtual guest to function properly. The host OS drivers are responsible for managing this support. You need to configure it properly like: https://forums.freebsd.org/threads/sr-iov-chelsio-error-in-guest.70653/. If y...
by Larsa
Sat Oct 26, 2024 6:36 am
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 3631

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

When using CHR, the NIC drivers must be compatible with and managed by the virtual machine host operating system (ie FreeBSD).

So, MikroTik support won’t really help here - you’ll need to check out the FreeBSD Forums instead.
by Larsa
Fri Oct 25, 2024 7:59 pm
Forum: RouterBOARD hardware
Topic: Recommend router and switch connected with private fiber
Replies: 38
Views: 6103

Re: Recommend router and switch connected with private fiber

He talked about running into a splice tray and pigtail. Yeah, that's pretty much standard procedure. It's usually not a big deal, but if you ask nicely, they might throw in a 30-foot (or even longer) pigtail that you can roll up in the splice tray. That way, you can move it somewhere else if you ne...
by Larsa
Fri Oct 25, 2024 1:04 pm
Forum: General
Topic: S-RJ01 installed in server motherboard - not working
Replies: 2
Views: 406

Re: S-RJ01 installed in server motherboard - not working

Is there any way of knowing if these two are compatible?

When using CHR, the NIC drivers must be compatible with and managed by the virtual machine host operating system. Also make sure to enable SR-IOV.
by Larsa
Fri Oct 25, 2024 11:36 am
Forum: Wireless Networking
Topic: worst performance of NetBox 5AX.. Is there any user who uses this NetBox 5AX??
Replies: 23
Views: 5120

Re: worst performance of NetBox 5AX.. Is there any user who uses this NetBox 5AX??

There’s a chance some mistakes slipped in by accident, so please post the configuration with the latest suggestions.
by Larsa
Thu Oct 24, 2024 10:04 pm
Forum: General
Topic: How to change WG handshake timeout
Replies: 8
Views: 1574

Re: How to change WG handshake timeout

It could be due to several things, like having a WireGuard peer acting as the initiator (ie you have defined the endpoint-address and port) but the receiver isn't responding, or for some reason an established connection has stopped working. An earlier version of Ros logged way too much by mistake bu...
by Larsa
Thu Oct 24, 2024 9:09 pm
Forum: General
Topic: How to change WG handshake timeout
Replies: 8
Views: 1574

Re: How to change WG handshake timeout

Those settings are protocol-defined standard values that are hardcoded at compile time. Check out: WireGuard on GitHub. Also, read my previous post: viewtopic.php?p=1105092#p1058871.

Why do you want to change these values, which would break the protocol definition?
by Larsa
Thu Oct 24, 2024 6:29 pm
Forum: Wireless Networking
Topic: wAP ax?
Replies: 290
Views: 41288

Re: wAP ax?

As an AP, bridging is more than adequate and the routing test results don't really matter much as difference isn't that significant anyway. It's only relevant if you're planning to use the AP as your main router.
by Larsa
Thu Oct 24, 2024 5:51 pm
Forum: Wireless Networking
Topic: Iphone 11 wifi
Replies: 4
Views: 1492

Re: Iphone 11 wifi

Check your iPhone Wi-Fi logs: viewtopic.php?t=211009#p1098002. If you can't figure it out using the logs, post your AP config in this thread.
by Larsa
Thu Oct 24, 2024 8:30 am
Forum: General
Topic: BGP sessions close when another session to the same IP closes
Replies: 8
Views: 2519

Re: BGP sessions close when another session to the same IP closes

@mblfone - This is just a user forum. Please open a bug report with Mikrotik support.
by Larsa
Wed Oct 23, 2024 6:39 pm
Forum: Forwarding Protocols
Topic: BFD, ipv6 & bgp multihop problem
Replies: 3
Views: 2915

Re: BFD, ipv6 & bgp multihop problem

I’d say it’s way too hard to figure out the network topology without a clear network diagram.
by Larsa
Tue Oct 22, 2024 9:18 pm
Forum: General
Topic: 1 Packet over Multiple Routs?
Replies: 14
Views: 1866

Re: 1 Packet over Multiple Routs?

And imagine if top management and all the development gurus were on the crashed airplanes! 🤯🤯🤯
by Larsa
Tue Oct 22, 2024 4:06 pm
Forum: General
Topic: IPsec VPN Mikrotik - Sonicwall not using full internet speed
Replies: 8
Views: 1272

Re: IPsec VPN Mikrotik - Sonicwall not using full internet speed

Hey @ToothyGardener, thanks for that LLM-generated response that was pretty much just a reworded version of my last post, but with some extra fluff thrown in. (## SPAM warning ##)
by Larsa
Tue Oct 22, 2024 2:54 pm
Forum: General
Topic: Mikrotik support please have a look!
Replies: 4
Views: 565

Re: Mikrotik support please have a look!

Or as someone on Reddit put it: "This device is not intended for the average user, so don’t blame the hardware if you have trouble getting it to work. If you're unable to configure it properly, consider buying a consumer-friendly equipment instead."
by Larsa
Tue Oct 22, 2024 10:27 am
Forum: General
Topic: IPsec VPN Mikrotik - Sonicwall not using full internet speed
Replies: 8
Views: 1272

Re: IPsec VPN Mikrotik - Sonicwall not using full internet speed

If using two RB4011s works, check if the TZ500 could be the bottleneck and whether it supports hardware acceleration with AES-256. If not, you’ll need to find an encryption method that both sides can use with hardware acceleration. Take a look at the RB4011s (CPU AL21400) in this table: https://help...
by Larsa
Tue Oct 22, 2024 12:44 am
Forum: General
Topic: l2tp subnet routing router to router
Replies: 11
Views: 820

Re: l2tp subnet routing router to router

I went from openvpn (no udp support in Tik) to ipsec (hardware encryption) to wireguard. Wireguard blows ipsec with hardware encryption out of the water in terms of performance. @NetWorker - WireGuard uses pure software encryption (ChaCha20), so it’ll never beat IPsec when it’s using hardware accel...
by Larsa
Mon Oct 21, 2024 8:51 pm
Forum: Beginner Basics
Topic: RouterOS on Proxmox
Replies: 4
Views: 1352

Re: RouterOS on Proxmox

@FredRoot - You can’t manage USB network devices directly from CHR. You need to set up and manage the TP-Link T4U from the host OS first, then add it to Proxmox like a regular network device. Check this out: add usb network device to proxmox
by Larsa
Mon Oct 21, 2024 6:41 pm
Forum: General
Topic: [Feature Request] Data Center Bridge support
Replies: 29
Views: 6786

Re: [Feature Request] Data Center Bridge support

@galvesribeiro, yeah, this is great news and probably essential for MT if they are aiming to enter the data center market with their new 100G switches. It looks like there's support for both the older v1 L2 and current v2 L3 (UDP), with highly configurable ETS scheduling and bandwidth allocation. Ov...
by Larsa
Mon Oct 21, 2024 4:55 pm
Forum: General
Topic: IPsec VPN Mikrotik - Sonicwall not using full internet speed
Replies: 8
Views: 1272

Re: IPsec VPN Mikrotik - Sonicwall not using full internet speed

You need to use an IPsec encryption setup that matches AES hardware offloading on both sides.
by Larsa
Sun Oct 20, 2024 10:51 pm
Forum: General
Topic: Weird bug 7.15 x86 - NIC stops working until full RouterOS reinstall
Replies: 3
Views: 550

Re: Weird bug 7.15 x86 - NIC stops working until full RouterOS reinstall

The only advice I can give, if you can’t ensure your system is ROS-compliant, is to use CHR. If configured correctly, you won’t notice any difference in performance.
by Larsa
Sun Oct 20, 2024 9:49 pm
Forum: General
Topic: User Manager for 30K Subscribers [SOLVED]
Replies: 19
Views: 1624

Re: User Manager for 30K Subscribers [SOLVED]

I have never used, but I understood that with rose-storage I can fake a disk on RAM, so we could use it to avoid issues on write needs. Just be aware you will lose ALL writes if you are unable to sync a RAM drive to permanent storage. My recommendation is to use at least some kind of delayed-write ...
by Larsa
Sun Oct 20, 2024 7:58 pm
Forum: General
Topic: User Manager for 30K Subscribers [SOLVED]
Replies: 19
Views: 1624

Re: User Manager for 30K Subscribers [SOLVED]

That might be the case, but it really depends on how the developers have set up the SQLite settings, like journal_mode, cache_size, temp_store, synchronous, and how they handle client busy timeouts, etc. And of course, the maximum number of concurrent transactions. If the underlying file system for ...
by Larsa
Sun Oct 20, 2024 6:05 pm
Forum: General
Topic: User Manager for 30K Subscribers [SOLVED]
Replies: 19
Views: 1624

Re: User Manager for 30K Subscribers [SOLVED]

Yeah, the VM should be pretty easy to scale up with standard measures, and depending on how MT implements SQLite caching, you might even be able to use it as an in-memory database if you add a lot of RAM. But since SQLite is single-threaded, how it handles command queuing with a bunch of concurrent ...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 7