Community discussions

MikroTik App

Search found 42 matches

by i4ko
Sun Mar 17, 2024 10:38 pm
Forum: General
Topic: A call for a "lite" version of routeros 7 (image size reduction)
Replies: 22
Views: 1632

Re: A call for a "lite" version of routeros 7 (image size reduction)

Ok, good note on pppoe @pe1chl, my reasoning was that it is high time we move away from anything ppp. It is a holdout from the era before ikev2. Only case where you should still use pppoe v.s. ikev2 is devices/modems that have hardware framing based on ppp. The comment was good though, this type of ...
by i4ko
Thu Mar 14, 2024 7:05 am
Forum: General
Topic: A call for a "lite" version of routeros 7 (image size reduction)
Replies: 22
Views: 1632

Re: A call for a "lite" version of routeros 7 (image size reduction)

Bottom line is, you're going to make somebody mad no matter what you cut out. To this point though, the complaining has to be more than the Same Ten People here on the forums. Agree, that is why my suggestion is for a lite version, but in addition to the full version. Lite version prioritizes stabi...
by i4ko
Thu Mar 14, 2024 5:00 am
Forum: General
Topic: A call for a "lite" version of routeros 7 (image size reduction)
Replies: 22
Views: 1632

Re: A call for a "lite" version of routeros 7 (image size reduction)

Of course to save space many utilities are in a somewhat monolithic binaries, even if those are dynamically linked they still contain the code to do all the extra functionality. Separating into extra packages will only add more complexity and may not end up saving any space. That is why my suggestio...
by i4ko
Thu Mar 14, 2024 3:11 am
Forum: General
Topic: Feature requests
Replies: 1742
Views: 637442

Re: Feature requests

A version of routeros 7 that has reduced footprint (and reduced functionality) but works comfortably on 16mb flash devices. I started a separate thread viewtopic.php?t=205735 if anybody wants to comment and discuss what functionality the small flash devices can go without
by i4ko
Wed Mar 13, 2024 11:05 pm
Forum: General
Topic: A call for a "lite" version of routeros 7 (image size reduction)
Replies: 22
Views: 1632

A call for a "lite" version of routeros 7 (image size reduction)

Hi, the MikroTik equipment is really nice, but the increased requirements of version 7 wrt flash space are being a significant blocker on devices that otherwise have enough RAM and CPU but still on 16mb flash. Such devices are sill sold today and the inability to reliably upgrade them without physic...
by i4ko
Tue Sep 05, 2023 9:25 am
Forum: Beginner Basics
Topic: Vlan Translation enquiry [SOLVED]
Replies: 3
Views: 1378

Re: Vlan Translation enquiry [SOLVED]

If you add both vlan interfaces in the same bridge, then the bridge will switch the tags when packets pass though.
This link will help see what devices support what features https://help.mikrotik.com/docs/display/ ... p+Features
by i4ko
Tue Sep 05, 2023 9:05 am
Forum: Beginner Basics
Topic: First time setup (almost) complete, sanity check please?
Replies: 12
Views: 2217

Re: First time setup (almost) complete, sanity check please?

Long time ago for me dhcp server would not work reliably if it was assigned to a subordinate port in a bridge (there was unreliable broadcast packet forwarding), so I had to assign the dhcp server to the root of the bridge. Since then I have mostly been using vlan subinterfaces on the Ethernet inter...
by i4ko
Tue Sep 05, 2023 8:54 am
Forum: Beginner Basics
Topic: Access Webfig in MikroTik Router configured as Switch/Bridge/AP [SOLVED]
Replies: 2
Views: 1478

Re: Access Webfig in MikroTik Router configured as Switch/Bridge/AP [SOLVED]

Is the 192.168.1.149/24 in the same range that the DHCP server will assign to another client connected in that segment - if not - then you need to add secondary address on your machine in the 192.168.1.0/24 network as well. A more easy way would be to set that mikrotik with dhcp-client in the bridge...
by i4ko
Tue Sep 05, 2023 8:45 am
Forum: General
Topic: Dealing with datacaps; can burst help?
Replies: 2
Views: 1018

Re: Dealing with datacaps; can burst help?

True, for accounting central is the way to go, but that is also overage, and then billing, collection, etc. This is to help give users the ability to enjoy good service when they are a good user, but stop them from blowing though the cap, and only take any action if they are actually over the cap by...
by i4ko
Tue Sep 05, 2023 7:26 am
Forum: General
Topic: Dealing with datacaps; can burst help?
Replies: 2
Views: 1018

Dealing with datacaps; can burst help?

Hi, this is more of a thought exercise. Here is the premise - provider side marketing allows 1250GB data cap a month, anything more is overage. Client (or provider CPE) wants to use Mikrotik device to facilitate easy compliance with the data cap. Here's the though - 1250GB per month are constant loa...
by i4ko
Tue Aug 29, 2023 8:30 am
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165432

Re: v7.11 [stable] is released!

Doesn't seem at all stable to me. On a RBwAPGR-5HacD2HnD with EC25-V LTE modem it was working normally when the lte modem was set to serial (from inside routeros; usbnet mode on the ec25 card is 2). After disabling the ppp interface setting the lte modem mode to mbim (from routeros, no change on the...
by i4ko
Sun Aug 27, 2023 7:08 am
Forum: Announcements
Topic: v6.49.8 [long-term] is released!
Replies: 49
Views: 69332

Re: v6.49.8 [long-term] is released!

Well, I don't agree fully with you pe1chl. Yes, the HEXr3 only has 16mg flash, which is extremely surprising. It is more expensive to buy 16mb flash chips than 128mb flash chips and has been for the last 4 years at least, but even with that: a) after copying the lists from another device that had th...
by i4ko
Sun Aug 20, 2023 5:49 am
Forum: Announcements
Topic: v6.49.8 [long-term] is released!
Replies: 49
Views: 69332

Re: v6.49.8 [long-term] is released!

That was a bust. Upgrading from previous long-term did not go well on a 750gr3. Basically lost all entries in all but one address-lists, and even the one that had entries had been truncated badly after the upgrade (~29000 entries showing only). What is interesting is that the address lists names wer...
by i4ko
Mon Apr 11, 2022 10:32 am
Forum: General
Topic: IKEv2 one way traffic problem [SOLVED]
Replies: 14
Views: 2481

Re: IKEv2 one way traffic problem [SOLVED]

Thanks all who responded. After playing a bit I made it work. Here are the final firewall filter rules. They are not enough! /ip firewall filter add action=accept chain=input in-interface=ether5-wan ipsec-policy=in,ipsec src-address=192.168.223.8 add action=drop chain=input src-address=192.168.223.8...
by i4ko
Mon Apr 11, 2022 12:56 am
Forum: General
Topic: IKEv2 one way traffic problem [SOLVED]
Replies: 14
Views: 2481

Re: IKEv2 one way traffic problem [SOLVED]

No entry in the arp table Maybe there aren't supposed to be, but it would think it'd show up there after the first ping attempt if anything was working. I don't expect it to. the private IP the client receives is not directly connected, not is there interface created for IPSec. I do expect a route ...
by i4ko
Mon Apr 11, 2022 12:24 am
Forum: General
Topic: IKEv2 one way traffic problem [SOLVED]
Replies: 14
Views: 2481

Re: IKEv2 one way traffic problem [SOLVED]

I don't have to have specific rules for DNS< UDP and TCP You're talking about the firewall, but @own3r1138 is talking about the IPsec policy. When the client connects, the policy says how it gets an IP, what DNS it gets, what routes it gets, etc. this is the policy that gets generated when the clie...
by i4ko
Mon Apr 11, 2022 12:15 am
Forum: General
Topic: IKEv2 one way traffic problem [SOLVED]
Replies: 14
Views: 2481

Re: IKEv2 one way traffic problem [SOLVED]

I can ping the client from the router Are you sure you aren't pinging the VPN interface? Does the output of "/ip/arp/print" include a mapping of the iOS device's MAC to assigned VPN IP? Quite sure. The response from the vpn IP comes back at LTE latencies. The one from the local loopback c...
by i4ko
Sun Apr 10, 2022 11:50 pm
Forum: General
Topic: IKEv2 one way traffic problem [SOLVED]
Replies: 14
Views: 2481

Re: IKEv2 one way traffic problem [SOLVED]

You don't have any allowed rules in the IPsec policy for DNS UDP or TCP, Also try to set a Local DNS server from the same range as the VPN address pool. also, try to remove the src address from your accept rules. do you have any drop rules besides that do you have a fast-track rule? is your WAN IP ...
by i4ko
Sun Apr 10, 2022 6:23 pm
Forum: General
Topic: IKEv2 one way traffic problem [SOLVED]
Replies: 14
Views: 2481

Re: IKEv2 one way traffic problem [SOLVED]

thanks for responding, again for me the rules don't match anything. my first 10 rules are equivalent of your rules 35,36,75 and 76, yet they dont not match. i can ping the client from the router just fine (and traceroute both icmp and udp) since that originates on the router and see a match when the...
by i4ko
Sun Apr 10, 2022 3:52 pm
Forum: General
Topic: IKEv2 one way traffic problem [SOLVED]
Replies: 14
Views: 2481

Re: IKEv2 one way traffic problem [SOLVED]

The setup was done according to that article. Diagram is simple: client(IOS 15.4.1)-LTE(t-mobile)-internet(IPV4)-router config export: /ip ipsec mode-config add address-pool=pool-ike address-prefix-length=32 name="modconf ike" split-include=0.0.0.0/0 static-dns=208.67.220.220 system-dns=no...
by i4ko
Sun Apr 10, 2022 9:50 am
Forum: General
Topic: IKEv2 one way traffic problem [SOLVED]
Replies: 14
Views: 2481

IKEv2 one way traffic problem [SOLVED]

Hi routeros 6.48.6 on 750G r3. IKEv2 setup with certificates with IOS 15.4.1 client. The client connects just fine, I can ping the client from the router, but the client is unable to access anything, even the router itself. Mode config sends default route (0.0.0.0/0). I tried sending just a local su...
by i4ko
Mon Jan 25, 2021 2:30 am
Forum: General
Topic: Decrease in software quality from mikrotik?
Replies: 16
Views: 2810

Decrease in software quality from mikrotik?

These are my observations on the last 2 long-term releases (6.46.7 and 6.46.8), there are things that just break that used to work before, and it is just annoying and frustrating. 1. False positive DFS detections Observed on RB952Ui-5ac2nD that is located on the ground floor of internal courtyard (m...
by i4ko
Sun Nov 01, 2020 8:30 pm
Forum: Announcements
Topic: v6.46.7 [long-term] is released!
Replies: 45
Views: 26562

Re: v6.46.7 [long-term] is released!

This release is BROKEN. Upon upgrade from previous long term on several 750Gr3: [*]Bridge config almost always borked after upgrade: [*][*]certain ports get randomly disabled from the bridge config [*][*]certain bridges and their ports show "unknown/unknown" and are obviously broken - in c...
by i4ko
Sun Mar 29, 2020 4:11 am
Forum: RouterOS beta
Topic: fq_codel or cake in v7
Replies: 68
Views: 41571

Re: fq_codel or cake in v7

-1 I have never had good experience with SQM as implemented in openwrt or ubnt ER. Practically most of the time SQM does hurt performance of TCP connections significantly. Mostly it does is introduce packet loss, and a lot of it. Now, the traffic I deal with is idiotic - sub-second bursts in the ord...
by i4ko
Sun Mar 08, 2020 5:16 am
Forum: RouterOS beta
Topic: Interface MTU has no effect
Replies: 1
Views: 4258

Interface MTU has no effect

7 beta 5, smips. When trying to work around the MTU hole with IPSEC IKEv2 I found out that the new version does NOT process MTU settings at all. The local router IP facing the machine is on a bridge interface. I tried setting MTUs on both the bridge and the actual ethernet port. Even if the MTU is s...
by i4ko
Thu Mar 05, 2020 9:35 am
Forum: RouterOS beta
Topic: MTU blackhole with IKEv2
Replies: 0
Views: 3465

MTU blackhole with IKEv2

7 beta 5. When creating IPSEC with IKEv2 there appears to be a MTU blackhole. In my particular case the actual MTU that passes is 1422 (ping size 1394), and anything above will just not return or pass. IP firewall does allow the detection of larger packets but there is no action to return fragmentat...
by i4ko
Fri Feb 28, 2020 6:02 am
Forum: RouterOS beta
Topic: V7 modules missing, BGP and mpls missing, ipv6 always enabled.
Replies: 5
Views: 4557

Re: V7 modules missing, BGP and mpls missing, ipv6 always enabled.

As you can know V7 is in Beta testing and modules comes on each beta publish! https://mikrotik.com/download/changelogs/development-release-tree See all change logs ... Before take responsibility to test a development version you should read all information! Re modules - nonsense! I am speaking of h...
by i4ko
Wed Feb 26, 2020 10:48 pm
Forum: RouterOS beta
Topic: V7 modules missing, BGP and mpls missing, ipv6 always enabled.
Replies: 5
Views: 4557

V7 modules missing, BGP and mpls missing, ipv6 always enabled.

Gave beta 5 a test - install is monolithic - packages are gone. :( Not possible to disable stuf fon routers that don't need those and conserve memory for useful things :( - e.g. wireless, ppp, ipv6, advanced tools to free up ram to run iBPG and/or MPLS Why is RIP still there? BGP is gone on those sm...
by i4ko
Thu Feb 28, 2019 12:30 am
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 218
Views: 97070

Re: v6.44 [stable] is released!

major issues upgrading rb952Ui to 6.43.12 and 6.44 The upgrade to 6.43.12 from 6.43.7 went ok, but 6.43.12 caused the device to go into high cpu usage and eventually crash with autosup out being generated. The first 2 times this happened router got rebooted by customer in about 15-20 minutes. The th...
by i4ko
Thu Feb 07, 2019 7:35 am
Forum: Announcements
Topic: v6.43.11 [stable] is released!
Replies: 79
Views: 39501

Re: v6.43.11 [stable] is released!

i4ko , EIRP is not so much about the power as about the density of radiation, so for directional antennas the gain may easily be much higher than 1. Thanks Andriys. But isn't EIRP by definition equal distribution in 360 degree in all 3 directions (sphere), hence being called isotropic. A directiona...
by i4ko
Thu Feb 07, 2019 6:58 am
Forum: Announcements
Topic: v6.43.11 [stable] is released!
Replies: 79
Views: 39501

Re: v6.43.11 [stable] is released!

I put LHG-5HPnD (24.5dBi antenna gain) on one side and SXT Lite5 (16dBi) on the other. Both are elevated. It's only couple of trees in the middle. And it's winter now. I can't believe, respecting all regulations, my signal would be below -80dBm. Not with such high gain antennas on so short distance...
by i4ko
Wed Feb 06, 2019 7:18 am
Forum: Announcements
Topic: v6.43.11 [stable] is released!
Replies: 79
Views: 39501

Re: v6.43.11 [stable] is released!

Memory leak in proxy on HEX r3 still present. Behavior is the same as described in the 6.43.8 thread With proxy disabled the memory usage is around 42mb. If you enable the proxy but don't send any traffic the memory consumption stays at 42mb. As soon as you open the web proxy interface in winbox the...
by i4ko
Tue Feb 05, 2019 8:06 am
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 83147

Re: v6.43.8 [stable] is released!

My 750Gr3s seem to show a memory leak in the proxy. With proxy disabled the memory usage is around 42mb. If you enable the proxy but don't send any traffic the memory consumption stays at 42mb. As soon as you open the web proxy interface in winbox the memory consumption jumps to 64mb (still no traff...
by i4ko
Wed Feb 14, 2018 6:46 am
Forum: Announcements
Topic: v6.41.2 [current]
Replies: 124
Views: 52597

Re: v6.41.2 [current]

i4ko - Most likely you will need to re-install devices by using Netinstall. However, I recommend that you send supout file from one of your routers to support. We might see in supout file what is filling up the space. Finally manged to update remotely. While on 6.41.1 disabled all packages except f...
by i4ko
Tue Feb 13, 2018 6:18 am
Forum: Announcements
Topic: v6.41.2 [current]
Replies: 124
Views: 52597

Re: v6.41.2 [current]

After upgrading from version 6.39.3 [BugFix] to 6.41.1 and then to 6.41.2, my device [RB751U-2HnD] presented wireless connectivity problems. I also upgraded the firmware, leaving it equivalent to the ROS. The causes of the problem could not be identified in the logs. Even after resetting and redoin...
by i4ko
Sun Feb 11, 2018 7:30 pm
Forum: Announcements
Topic: v6.41.2 [current]
Replies: 124
Views: 52597

Re: v6.41.2 [current]

i4ko - Have you had other RouterOS packages installed on the device in the past? If you reboot router is space freed up? No and No What I noticed is that config backup usually used to take shy of 500kb. After the 6.41.1 upgrade, the config backup right now takes shy of 700kb, and there isn't that m...
by i4ko
Sat Feb 10, 2018 10:06 pm
Forum: Announcements
Topic: v6.41.2 [current]
Replies: 124
Views: 52597

Re: v6.41.2 [current]

None of my 941-2nDs are able to upgrade. I have no files in files menu in winbox besides the regular ones. Yet the available space is only 6.9mb. The winbox will not start downloading the update, nor it is possible to upload a complete update file manually. I've tried recreating the flash folder an...
by i4ko
Sat Feb 10, 2018 5:42 am
Forum: Announcements
Topic: v6.41.2 [current]
Replies: 124
Views: 52597

Re: v6.41.2 [current]

None of my 941-2nDs are able to upgrade. I have no files in files menu in winbox besides the regular ones. Yet the available space is only 6.9mb. The winbox will not start downloading the update, nor it is possible to upload a complete update file manually. I've tried recreating the flash folder and...
by i4ko
Fri Feb 10, 2017 12:03 am
Forum: General
Topic: QoS - video stream buffering
Replies: 1
Views: 12996

Re: QoS - video stream buffering

Disclaimer: I don't run a WISP (or work for any other IPS type organization in that matter any more), but do IT work for a bunch of old people and small businesses. Since you mention Netflix initially, while I'm not good at QoS on Mikrotik myself, I don't think this script will help. Or other L7 cla...
by i4ko
Sat Jan 14, 2017 4:30 am
Forum: RouterBOARD hardware
Topic: New product : HAP Mini (RB931-2ND)
Replies: 15
Views: 11047

Re: New product : HAP Mini (RB931-2ND)

Sure, but is that a market suitable for MikroTik? Well, something has to come up for replacing all the hap lites with their defective low-quality usb power sockets. I have another one (hap lite) where the power socket just came off the board, and this in not at a customer's location. So what does a...
by i4ko
Mon Nov 23, 2015 1:09 am
Forum: General
Topic: peculiar failure after 6.32.2 upgrade, possibly an arp issue on bridge interface?
Replies: 1
Views: 995

Re: peculiar failure after 6.32.2 upgrade, possibly an arp issue on bridge interface?

I am still having the same failure after 6.33 and 6.33.1. Tried different combinations of arp settings on the wan bridge and on the wifi both on and proxy, but the traffic still does not leave the wifi interface.
by i4ko
Sat Sep 26, 2015 9:49 pm
Forum: General
Topic: peculiar failure after 6.32.2 upgrade, possibly an arp issue on bridge interface?
Replies: 1
Views: 995

peculiar failure after 6.32.2 upgrade, possibly an arp issue on bridge interface?

I have a somewhat unusual config - a hap lite, with wireless in station mode, part of a bridge (call it wan-bridge) with eth1. Then there is a second bridge (call it lan-bridge), that has eth2 configured master, and then eth3 and eth4 are slaves. There is a nat running between the bridges, and eth1 ...