Community discussions

MikroTik App

Search found 124 matches

by OlofL
Tue Aug 23, 2022 10:22 am
Forum: General
Topic: Feature requests
Replies: 1742
Views: 637563

Re: Feature requests

DHCPv6 server lease sync (with routes automatically added/removed to ia_pd)
DHCPv6 client/server full support (ia_na)
by OlofL
Thu Aug 11, 2022 5:19 pm
Forum: Forwarding Protocols
Topic: Trying to learn ospf-mpls-bgp ipvpn - what am I missing? (no vpnv4 routes in mpls forwarding-table)
Replies: 0
Views: 893

Trying to learn ospf-mpls-bgp ipvpn - what am I missing? (no vpnv4 routes in mpls forwarding-table)

Im trying to learn mpls/ospf/bgp "ipvpn" setup. traffic between PE1 loopback and PE2 loopback is switched through mpls. traffic between ce1 and ce2 doesn't get switched by mpls, so an ip packet reaches P1 and its dropped because it doesnt have route to CE2. What am I missing here? Config: ...
by OlofL
Thu Jul 07, 2022 1:04 pm
Forum: Containers
Topic: Looking for Docker container ideas for RouterOS
Replies: 121
Views: 31642

Re: Looking for Docker container ideas for RouterOS

Stateful DHCPv6 Server? KEA based ?
Please tell if you build this.
Would be nice to have dhcpv6 server sync leases with another router.
by OlofL
Tue Jun 21, 2022 11:59 am
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082270

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

Anyone tested this with 7.4beta4 and containers?
by OlofL
Fri Jun 10, 2022 5:39 pm
Forum: RouterOS beta
Topic: Software life cycle and release management (re: auto upgrade)
Replies: 18
Views: 4088

Re: Software life cycle and release management (re: auto upgrade)

In fact, there does not seem to be any channels - there are only different snapshots of the SAME channel of RouterOS releases. This is obvious and already claimed by Mikrotik staff in forum when 7.3 was released. It would be more optimal to actually have two or more development channels where fixes ...
by OlofL
Fri Jun 10, 2022 5:18 pm
Forum: RouterOS beta
Topic: routeros 7.3.1 - ip ssh not working
Replies: 11
Views: 4343

routeros 7.3.1 - ip ssh not working

after upgrading to 7.3.1 ip ssh is not working... I tried : [*] change any options and press apply [*] press "regenerate host key" [*] import ssh pubkey to user [*] upgrade to 7.4beta, downgrade again [*] export ssh-host-key [*] export host priv+pub files from another mikrotik and import t...
by OlofL
Thu Jun 09, 2022 3:46 pm
Forum: General
Topic: posts not strictly related to: v7.3 and v7.3.1 [stable]
Replies: 52
Views: 5246

Re: v7.3 [stable] is released!

OlofL, 7.3 in general is much better than 7.2.x except this one issue with SFP on RB3011. This sounds so stupid. Its not "much better" for me. It broke everything. So basically you make 7.3 release candidate. Wait a few days and see how much forum is spammed. If less than 5 new angry topi...
by OlofL
Thu Jun 09, 2022 2:10 pm
Forum: General
Topic: posts not strictly related to: v7.3 and v7.3.1 [stable]
Replies: 52
Views: 5246

Re: v7.3 [stable] is released!

There are no changes since rc2. How can you not test the RB3011 SFP bug before releasing this into " stable "? Very fun downgrading routers at remote sites today! How can I go from 6.x to 7.2.x? If I set channel=upgrade it will chose 7.3 as of now. Should I just manually upload 7.2.x NPK ...
by OlofL
Thu Jun 02, 2022 9:57 pm
Forum: Beginner Basics
Topic: How do I specify the first/second... /64 prefix from a /56 pool. (persistent prefix after boot?)
Replies: 3
Views: 665

Re: How do I specify the first/second... /64 prefix som a /56 pool. (persistent prefix after boot?)

Unfortunately you cannot, it is an annoying omission from RouterOS. I am pretty sure I have seen a workaround on this before ? Anyways, if I am remembering wrong, how do you make sure clients removes the ipv6 address in the wrong prefix if this happens after reboot? Can mikrotik send old RA with a ...
by OlofL
Thu Jun 02, 2022 9:36 pm
Forum: Beginner Basics
Topic: How do I specify the first/second... /64 prefix from a /56 pool. (persistent prefix after boot?)
Replies: 3
Views: 665

How do I specify the first/second... /64 prefix from a /56 pool. (persistent prefix after boot?)

I have a pool of a /56 network. db8:2001:1128:2400::/56 I want to assign ipv6 addresses from my lan interfaces using only "::1/64" command. add address=::1 from-pool=TT interface=ether5 add address=::1 from-pool=TT interface=ether6 add address=::1 from-pool=TT interface=ether7 But how do I...
by OlofL
Wed Jun 01, 2022 10:16 am
Forum: Announcements
Topic: MikroTik Devices Controller
Replies: 332
Views: 238990

Re: MikroTik Devices Controller

Selective configuration sync between two or more "clustered" devices (firewall/mangle etc)
Some kind of HA...

Container support!

Smart firewall address list support (geoip, Adblock, bad IPs)
by OlofL
Mon May 30, 2022 8:30 pm
Forum: RouterOS beta
Topic: NAT only NAT'ing 99% of packets. [SOLVED]
Replies: 9
Views: 4248

Re: NAT only NAT'ing 99% of packets. [SOLVED]

When the Mikrotik connection tracking sees the end of a TCP conversation (FIN -> ACK+FIN -> ACK) the tracking entry is removed. Any repeated or unsolicited invalid transmissions from a client, e.g. FIN+ACK, RST+ACK or RST will not create a new connection tracking entry so no NAT will be applied. Th...
by OlofL
Mon May 30, 2022 8:28 pm
Forum: RouterOS beta
Topic: NAT only NAT'ing 99% of packets. [SOLVED]
Replies: 9
Views: 4248

Re: NAT only NAT'ing 99% of packets. [SOLVED]

How did you measured that 99.9%?
I didn't. Just a wild guestimate:)
It's probably closer to 99.999%
by OlofL
Mon May 30, 2022 6:04 pm
Forum: RouterOS beta
Topic: NAT only NAT'ing 99% of packets. [SOLVED]
Replies: 9
Views: 4248

Re: NAT only NAT'ing 99% of packets. [SOLVED]

Try adding a firewall rule add action=drop chain=forward connection-state=invalid after the accept established/related.
I can try. But explain please why you think this will help?
Even if packet is "invalid" and accepted by outgoing firewall rule - it should still be NAT'ed - right?
by OlofL
Mon May 30, 2022 5:06 pm
Forum: RouterOS beta
Topic: NAT only NAT'ing 99% of packets. [SOLVED]
Replies: 9
Views: 4248

NAT only NAT'ing 99% of packets. [SOLVED]

Issue: not all packets are NAT'et on the mikrotik router. It seems like 99.9% of packets are NAT'et. But the upstream firewall are seeing lots of martian source packets (rp_filter strict) I have this setup with Mikrotik router. /system/routerboard/print routerboard: yes model: CCR1036-8G-2S+ serial-...
by OlofL
Tue May 03, 2022 12:33 pm
Forum: Forwarding Protocols
Topic: Azure IPSEC tunel with BGP
Replies: 9
Views: 8387

Re: Azure IPSEC tunel with BGP

@hkusulja after 4 hours with Azure Premier support, we were able to get both IPSec tunnels up with Mikrotik and the BGP connection stablished on both tunnels as well Today. I'm receiving the VNet routes advertised by Azure and they appear both in my Routes table. However, None of the routes I'm adv...
by OlofL
Wed Apr 13, 2022 8:40 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 104094

Re: v7.3beta [testing] is released!

When containers?
by OlofL
Tue Apr 12, 2022 9:30 pm
Forum: Forwarding Protocols
Topic: Graceful restart
Replies: 10
Views: 8744

Re: Graceful restart

How do I enable this? I cannot see anything in docs nor in CLI. (v7.2 stable)
https://help.mikrotik.com/docs/pages/vi ... eId=328218
by OlofL
Fri Apr 08, 2022 11:44 am
Forum: Announcements
Topic: NEWSLETTER 105
Replies: 56
Views: 46133

Re: NEWSLETTER 105

How about a 100G switch with a few more ports?
This is the perfect switch for a spine and leaf topology ip fabric.
But it needs more ports on the spine layer!
by OlofL
Wed Mar 16, 2022 1:19 pm
Forum: RouterBOARD hardware
Topic: Plan for CCR2116-12G-4S+ alternative?
Replies: 13
Views: 9993

Re: Plan for CCR2116-12G-4S+ alternative?

I would like to see something like CCR2116-4G-12S+, even something without RJ45, just pure SFP+ with 1G management port, like old CCR2004. This is really nice piece of HW, but only 4 SFP+ isn't usable for me. I agree - and sfp28 interfaces aswell :) copper ports are useless now for this type of rou...
by OlofL
Sun Mar 13, 2022 3:16 pm
Forum: RouterOS beta
Topic: [Feature Request] Support for EC-based SSH keys
Replies: 4
Views: 2682

Re: [Feature Request] Support for EC-based SSH keys

Not negating adding a new feature here but what is exactly the problem we're trying to solve here? While ed25519 is newer and has some advantages (e.g. smaller key size, marginally faster authentication) does it really add any significant value to ROS? In Ubuntu 22.04 ssh-rsa is depricated and you ...
by OlofL
Mon Mar 07, 2022 3:03 pm
Forum: RouterOS beta
Topic: CRS318 and L3HW routing
Replies: 26
Views: 9685

Re: CRS318 and L3HW routing

Doesnt it support it in 7.2rc2? Nope, explained here: https://help.mikrotik.com/docs/display/ROS/L3+Hardware+Offloading#L3HardwareOffloading-L3HWDeviceSupport I have read that document, but I still dont understand. To my understanding, it should be able to? I also read https://forum.mikrotik.com/vi...
by OlofL
Mon Mar 07, 2022 12:45 am
Forum: RouterOS beta
Topic: CRS318 and L3HW routing
Replies: 26
Views: 9685

Re: CRS318 and L3HW routing

And for inter-VLAN routing you also need /ip firewall filter add action=fasttrack-connection chain=forward connection-state=established,related hw-offload=yes This device doesn't support hw-offload with fasttrack. :( Doesnt it support it in 7.2rc2? *) l3hw - added HW offloaded FastTrack support for...
by OlofL
Thu Mar 03, 2022 5:24 pm
Forum: General
Topic: How to search a large IP Firewall Address List?
Replies: 8
Views: 3477

Re: How to search a large IP Firewall Address List?

I just want to borrow the thread, how has this affected performance? How much resources do you need for such lists? Im looking to use similar numbers in my firewalls.

@Kelalatir
by OlofL
Tue Feb 22, 2022 3:01 pm
Forum: General
Topic: how does L3HW actually works?
Replies: 128
Views: 33043

Re: how does L3HW actually works?

Good read, is there a way to tweak the max amount of fasttrack connections? For instance less memory for l3hw offload but more memory for fasttrack?
by OlofL
Tue Feb 22, 2022 10:27 am
Forum: RouterBOARD hardware
Topic: Can CCR2116 do HW-offload/fasttrack on LACP interface?
Replies: 0
Views: 694

Can CCR2116 do HW-offload/fasttrack on LACP interface?

Can CCR2116 do HW-offload/fasttrack on LACP interface? With latest RoS 7.1.3 Looking at the block diagram, it has a switch chip connected to the interfaces. https://i.mt.lv/cdn/product_files/CCR2116-12G-4S_211233.png While we're at it, can any of the CCR2004 do the same thing? CCR2004-16G-2S+ has a ...
by OlofL
Sun Feb 20, 2022 8:22 pm
Forum: RouterOS beta
Topic: Feature request: DHCPv6 server leases sync between two routers? (HA setup)
Replies: 3
Views: 2654

Feature request: DHCPv6 server leases sync between two routers? (HA setup)

How can I sync DHCPv6 server leases between two routers? What I like about RouterOS is that it does install a dynamic special route in its route table for the PrefixDelegation. Which means I dont need to use a routing protocol on the clients for my upstream router to reach the prefixes. But, how do ...
by OlofL
Sun Feb 13, 2022 12:58 pm
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082270

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

I have not tested RoS7 and containers since they pulled before hitting stable?

But this seems a bit overkill now that Suricata can be ran inside containers and hopefully containers will be back in RoS7 soon? :)
by OlofL
Sun Feb 06, 2022 1:05 pm
Forum: RouterOS beta
Topic: Feedback on RouterOSv7 route filtering
Replies: 28
Views: 13779

Re: Feedback on RouterOSv7 route filtering

They have said they are in development of a new cross-platform Winbox replacement. Presumably this will allow them to create different GUI designs that will be more suitable for something like this. Source on this? Also why dont they scrap winbox alltogether and just use the web gui with the new AP...
by OlofL
Thu Jan 27, 2022 5:13 pm
Forum: Announcements
Topic: Future of LTE products, user feedback requested
Replies: 208
Views: 102472

Re: Future of LTE products, user feedback requested

I'm interested in 5G/4G LTE data devices WITHOUT Wifi or extra ports, more of a modem/router for cellular to Gigabit+ Ethernet.

1. CAT16+
3. No, 4G LTE/5G Only, minimize the old stuff.
This, and with console port for ease of management.
by OlofL
Thu Jan 20, 2022 4:01 pm
Forum: Forwarding Protocols
Topic: 7.1.1, 7.2rc1, wireguard, ospf, nmba - problem
Replies: 9
Views: 5094

Re: 7.1.1, 7.2rc1, wireguard, ospf, nmba - problem

/routing ospf interface-template
add area=ospf-area-1 networks=192.168.89.0/24 priority=0 type=nbma

change this to:
type=ptp

(and the equivalent on frr side)
:)
by OlofL
Wed Jan 19, 2022 11:31 am
Forum: RouterOS beta
Topic: Feature Request - NAT64/DNS64 CGN
Replies: 27
Views: 22077

Re: Feature Request - NAT64/DNS64 CGN

Agree on all points. I would like to add that ipv6 fasttrack is also very much needed!
by OlofL
Sun Jan 09, 2022 12:21 pm
Forum: RouterOS beta
Topic: Wireguard site to site with OSPF
Replies: 12
Views: 15067

Re: Wireguard site to site with OSPF

Yes, this is how I use it with OSPF. I use it as site2site. The mikrotik side is behind NAT/dynamic IP (it has fiber with 4G failover). Note that you have to allow-address 0.0.0.0/0 if you dont know all networks that should be allowed in the future. The most important part is to add wireguard interf...
by OlofL
Mon Dec 20, 2021 3:16 pm
Forum: RouterOS beta
Topic: /ip/route/check command disappeared?
Replies: 19
Views: 14087

Re: /ip/route/check command disappeared?

What you have shown in your examples is exactly what routing/route/print does. How do I check longer prefixes or resolve a shorter route? It would be nice to resolve 172.23.253.1 to a route in the table. [olof@80003p-cpe002] /ip/route> print where dst-address=172.23.253.0/24 Flags: A - ACTIVE; s, y...
by OlofL
Tue Dec 07, 2021 5:51 pm
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 226812

Re: v7.1 is released!

News letter is not saying this is stable.
Lol
by OlofL
Thu Dec 02, 2021 4:15 pm
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 226812

Re: v7.1 [testing] is released!

When IPv6 fasttrack?
by OlofL
Mon Nov 29, 2021 11:46 pm
Forum: Beginner Basics
Topic: Failover to LTE on ROS7 (with ping-check to remote host) ?? [SOLVED]
Replies: 8
Views: 2705

Re: Failover to LTE on ROS7 (with ping-check to remote host) ?? [SOLVED]

Also, I think you want the "check-gateway" on your 1.1.1.1 route. But not sure if that's the only issue here.
No, the correct way is to "check-gateway" on the gateway. :)

And no, there are no more issues, it works fine this way.
by OlofL
Mon Nov 29, 2021 11:02 pm
Forum: Beginner Basics
Topic: Failover to LTE on ROS7 (with ping-check to remote host) ?? [SOLVED]
Replies: 8
Views: 2705

Re: Failover to LTE on ROS7 (with ping-check to remote host) ?? [SOLVED]

But I found a workaround... I had to disable the mangle rules to get this working, also just enable lte apn to add default route. If your goal is use ether1 as primary (and has static default gateway ** ), and you set the default route distance in the LTE APN, that may enough without any mangle rul...
by OlofL
Mon Nov 29, 2021 10:30 pm
Forum: Beginner Basics
Topic: Failover to LTE on ROS7 (with ping-check to remote host) ?? [SOLVED]
Replies: 8
Views: 2705

Re: Failover to LTE on ROS7 (with ping-check to remote host) ?? [SOLVED]

BTW Right guess it's actually load balance the networks, that's what the "+" means in the route table in v7 – does have A for active on both The nitty gritty is v7 changed routing, thus @avnu's suggestion to post there. But yeah the "v7 docs" suggest distance=2: https://help.mik...
by OlofL
Mon Nov 29, 2021 7:20 pm
Forum: Beginner Basics
Topic: Failover to LTE on ROS7 (with ping-check to remote host) ?? [SOLVED]
Replies: 8
Views: 2705

Failover to LTE on ROS7 (with ping-check to remote host) ?? [SOLVED]

I have an LtAP LTE6 and run ROS v7.1rc7 I have a static default route on ether1 And dynamic IP from LTE with dynamic gateway and higher distance. I want to ping-check a remote host (eg 8.8.8.8/1.1.1.1) via static default route. (because the default gateway can be up, and isp network down) If ping-ch...
by OlofL
Mon Nov 29, 2021 4:01 pm
Forum: RouterBOARD hardware
Topic: LTE router with expandable disk? (for simple tftp server)
Replies: 0
Views: 3413

LTE router with expandable disk? (for simple tftp server)

Can any of the LTAP mini or LtAP LTE6 be installed with an internal disk?

I see LTE6 has "Second miniPCIe slot for expansions".

Its not clear to me searching the forum whether this port can be used for a disk.
by OlofL
Mon Nov 29, 2021 4:00 pm
Forum: RouterBOARD hardware
Topic: The big CCR2004 reboot thread (was 2004 hardware issues?)
Replies: 458
Views: 148858

Re: The big CCR2004 reboot thread (was 2004 hardware issues?)

I have no issues. I run 6.48, and only a small OSPF network.
65 days uptime. I have not seen random reboots at all.
by OlofL
Sat Nov 27, 2021 10:33 pm
Forum: RouterOS beta
Topic: v7.1rc7 [development] is released!
Replies: 174
Views: 55330

Re: v7.1rc7 [development] is released!

When fasttrack for ipv6?
by OlofL
Fri Nov 05, 2021 4:44 pm
Forum: RouterBOARD hardware
Topic: Request: Switch with more 10G RJ45 ports
Replies: 0
Views: 2618

Request: Switch with more 10G RJ45 ports

Use case: office that uses 10G RJ45 ports to edit large media files on local LAN.

I'd love to see a switch with more 10G rj45 ports. 24XG and 48XG with 4SFP+ and/or 2QSFP+ for uplinks.

The CRS12-8XG-4C is great, but I need more ports!
by OlofL
Wed Oct 27, 2021 12:38 am
Forum: RouterOS beta
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 49128

Re: v7.1rc5 [development] is released!

Finally a good update! Lots of work in core protocols and core functionality and not much of the new fancy pancy toys :)
by OlofL
Thu Oct 07, 2021 1:27 pm
Forum: RouterOS beta
Topic: Feature request: DHCP sync
Replies: 0
Views: 1275

Feature request: DHCP sync

Feature request: DHCP sync Now that vrrp and conntrack sync is in v7, it would be nice if DHCP-server could sync its leases aswell. What I particulary like about DHCPv6 in mikrotik is that it dynamically adds a route to the prefix-delegated prefix aswell. So if this request goes through, that is an ...
by OlofL
Fri Oct 01, 2021 10:13 am
Forum: RouterOS beta
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 83175

Re: v7.1rc4 [development] is released!

I tried to upgrade from 6.48.1 to development channel 7.1rc4. I don't know firmware version, but it was probably lower than 6.48.1. Logs hint it is 6.47.7 Seems like I bricked my device (RB4011) Logs from console connection when booting. :00000050 AL31400X-140 RouterBOOT booter 6.47.7 RB4011iGS+ CPU...
by OlofL
Fri Sep 17, 2021 12:22 am
Forum: RouterOS beta
Topic: VRF status with RouterOS v7
Replies: 16
Views: 7962

Re: VRF status with RouterOS v7

Since we now have IPv6 VRF support, I do not see the reason why not.
How about EVPN with vxlan? is that going to be added soon too?
by OlofL
Sun Sep 12, 2021 12:55 am
Forum: RouterOS beta
Topic: Feature Request : IPv6 Fasttrack
Replies: 176
Views: 52288

Re: Feature Request : IPv6 Fasttrack

This is 2021 final quarter. Please implement a proper IPv6 stack. It is till way behind other vendors. Recursive routing is still not implemented. Time for mikrotik to pull up the socks. Docker and stuff can still wait, core functionalities of a router must be the priority. Totally agree. There see...
by OlofL
Wed Sep 01, 2021 12:53 pm
Forum: RouterOS beta
Topic: ZeroTier added to RouterOS v7.1rc2
Replies: 335
Views: 310803

Re: ZeroTier added to RouterOS v7rc2

NO THANKS! I will manage my VPNs on my own, don't need and don't want any external service for that. Wireguard is working perfectly, thank you for that. OpenVPN is still working as it used to for years (slow but reliable). BTW, instead of adding random mostly useless stuff, why first don't make use...
by OlofL
Mon Aug 23, 2021 11:47 pm
Forum: Announcements
Topic: v6.48.4 [stable] is released!
Replies: 68
Views: 72896

Re: v6.48.4 [stable] is released!

Can't believe that "Delegated-IPv6-Prefix" didn't fixed in this release also. How many months do we have to wait to fix this option in stable release? Is it really hard to get fix from 6.49beta and implement it? Unbelievable... What is this bug? Im just trying to implement ipv6 using dhcp...
by OlofL
Mon Aug 23, 2021 1:39 pm
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78115

Re: v7.1rc1 [development] is released!

by OlofL
Mon Aug 16, 2021 11:56 am
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101521

Re: mDNS repeater feature

Yes, the question is, why separate the IoT, if you don't really need to separate ? Because the IOT device might have more than one service that its broadcasting. And with a mDNS repeater function, you could chose which services to rebroadcast on another network. And then firewall to only allow the ...
by OlofL
Thu Jul 15, 2021 10:41 am
Forum: RouterOS beta
Topic: v7 launch date
Replies: 156
Views: 49520

Re: v7 launch date

I'd rather say it's channel=frustrated_support_engineers ... frustrated by incompetent users who can't read warnings, written with letters of usual size and colour. Right, so Mikrotik releases an official "stable" software, that is released... on a forum ... page 10 pages down... in a thr...
by OlofL
Wed Jul 14, 2021 5:20 pm
Forum: RouterOS beta
Topic: v7 launch date
Replies: 156
Views: 49520

Re: v7 launch date

I can put it here too. This is 7.0.3 for Chateau only: https://box.mikrotik.com/f/7e3cad5779804d0b878d/?dl=1 We should put a big disclaimer next to it: DO NOT INSTALL v7.0.3 ON ANYTHING BUT CHATEAU! But I doubt it will solve people's inability to read. What /system/package/update channel is this? c...
by OlofL
Tue Jun 01, 2021 4:52 pm
Forum: RouterOS beta
Topic: Need help configuring a simple bgp filter in ROSv7
Replies: 2
Views: 1830

Need help configuring a simple bgp filter in ROSv7

I am trying to redisitribute my connected routes. I have two routes 172.17.10.0/24 and 172.17.2.0/24 that are directly connected. BGP neighborship is up. My attempt: /routing bgp template set default as=65536 redistribute=connected /routing bgp connection add local.role=ebgp name=cust123 output.filt...
by OlofL
Tue May 25, 2021 5:35 pm
Forum: RouterOS beta
Topic: v7.1beta6 [development] is released!
Replies: 377
Views: 243589

Re: v7.1beta6 [development] is released!

Too many complaints about beta or alpha. It is a testing release so bad things happen. Whether it is beta or alpha, I do not see the point, you install it and take the risk of things not working as supposed to. Remember that mikrotik tries to put lot of features in one box so it is not that easy to...
by OlofL
Wed May 19, 2021 2:20 pm
Forum: RouterOS beta
Topic: v7.1beta6 [development] is released!
Replies: 377
Views: 243589

Re: v7.1beta6 [development] is released!

I'm a bit disappointed, would like to see more focus on stability and features that not in V7 but are available in V6 instead of brand new features. Totally agree. Also it would be interesting in seeing progress on protocols here: https://help.mikrotik.com/docs/display/ROS/v7+Routing+Protocol+Statu...
by OlofL
Mon May 10, 2021 1:10 pm
Forum: RouterOS beta
Topic: New User Manager in RouterOS v7
Replies: 211
Views: 81344

Re: New User Manager in RouterOS v7

ability to enter a user password in hashed format is a must have in 2021. one must be able to use scripts to push user passwords, and then i cannot have them stored in clear text.
by OlofL
Fri Apr 30, 2021 10:27 am
Forum: RouterOS beta
Topic: VRRP connection tracking and preemption mode
Replies: 12
Views: 7890

Re: VRRP connection tracking and preemption mode

Moreover, connection sync does not work with the standard VRRP preemption. For example, if the master rebooted and gets back online with a higher VRRP priority value, it becomes the VRRP master again according to the VRRP protocol. But at this moment, the master does not have connections synced fro...
by OlofL
Wed Apr 28, 2021 11:52 am
Forum: Forwarding Protocols
Topic: VRF aware btest
Replies: 3
Views: 3319

Re: VRF aware btest

11 years later - any update on this? i still need this feature.
by OlofL
Tue Mar 23, 2021 4:01 pm
Forum: General
Topic: vrrp ip mask
Replies: 2
Views: 1757

Re: vrrp ip mask

Why do you want to use a /32? Do you want symmetrical routing so that you can do proper conntrack? I did some testing recently, but I did the other way around, I was using /32 on the physical interfaces, and using /24 or whatever on the VRRP interfaces. This way I was able to get symmetrical routing...
by OlofL
Thu Mar 18, 2021 11:07 pm
Forum: RouterOS beta
Topic: Bug: RouterOS beta 7.1beta4 - RFC3021 - does not route out on a /31 - but accepts traffic from a /31
Replies: 15
Views: 4175

Re: Bug: RouterOS beta 7.1beta4 - RFC3021 - does not route out on a /31 - but accepts traffic from a /31

It says that /31 is not supported, so that people stop asking whether /31 is supported or not. What does this even mean? Are you adding features on the v7 status page just to say it's not going to be supported? And why should we stop asking for features that are not supported? Isn't that the whole ...
by OlofL
Thu Mar 18, 2021 4:32 pm
Forum: Announcements
Topic: v6.49beta [testing] is released!
Replies: 171
Views: 90945

Re: v6.49beta [testing] is released!

Bug report:

lacp transmitt has policy layer3 and layer4 does not work on CCR2004.

RouterOS only sends out traffic on ONE member on 6.x

I tried:
6.48.1 doesnt work
6.49beta27 doesnt work
7.1beta5 does work - send traffic out of all lacp members.
by OlofL
Thu Mar 11, 2021 12:54 am
Forum: RouterOS beta
Topic: Bug: RouterOS beta 7.1beta4 - RFC3021 - does not route out on a /31 - but accepts traffic from a /31
Replies: 15
Views: 4175

Re: Bug: RouterOS beta 7.1beta4 - RFC3021 - does not route out on a /31 - but accepts traffic from a /31

/31 is officially unsupported.
Can you support it in v7 please? :) Since it's supported (works) one way already :)
by OlofL
Wed Mar 10, 2021 9:17 pm
Forum: Announcements
Topic: Newsletter March 2021 (#99)
Replies: 38
Views: 25372

Re: Newsletter March 2021 (#99)

Great news! Great work on the 5G and IOT stuff lately.

I was hoping for some more love and update on routeros v7 and more CCR routers with more than 4 or more SFP+ interfaces :)
by OlofL
Wed Mar 10, 2021 9:04 pm
Forum: RouterOS beta
Topic: Bug: RouterOS beta 7.1beta4 - RFC3021 - does not route out on a /31 - but accepts traffic from a /31
Replies: 15
Views: 4175

Bug: RouterOS beta 7.1beta4 - RFC3021 - does not route out on a /31 - but accepts traffic from a /31

Bug: RouterOS beta 7.1beta4 - RFC3021 - does not route out on a /31 - but accepts traffic from a /31 I heard rumours on RouterOS v7 will support RFC3021, which is great. Comparing to v6, it will atleast accept traffic from a /31 IP. Ping from "north" with source address 10.0.2.3 - Can ping...
by OlofL
Mon Mar 08, 2021 11:29 am
Forum: RouterOS beta
Topic: Chateau LTE12 - dropping LTE interface/connection
Replies: 13
Views: 5540

Re: Chateau LTE12 - dropping LTE interface/connection

hello, do you know if this was related to when you put some bandwidth on the router?
i had a similar issue, where LTE interface was dropping as soon as I actually got some real traffic on it with a few 10s of megabits...
by OlofL
Fri Mar 05, 2021 9:06 pm
Forum: Forwarding Protocols
Topic: resolve ibgp routes recursively from ebgp? [SOLVED]
Replies: 1
Views: 2812

resolve ibgp routes recursively from ebgp? [SOLVED]

I have a eBGP peer, and one iBGP peer [my router] <-linknetwork1-> [eBGP peer] <- linknetwork2(172.31.23.8/30) -> [my iBGP peer](192.168.13.0/24) My eBGP peer advertises linknetwork2 to my router. (172.31.23.8/30) and is Active My iBGP peer advertises 192.168.13.0/24 with nexthop linknetwork2. My ro...
by OlofL
Wed Mar 03, 2021 10:15 pm
Forum: RouterBOARD hardware
Topic: The big CCR2004 reboot thread (was 2004 hardware issues?)
Replies: 458
Views: 148858

Re: The big CCR2004 reboot thread (was 2004 hardware issues?)

I now have one CCR2004 in prod. Uptime only 10 days, but no issues so far.
Running 6.48.1.
Very simple configuration-
Only two static routes, some mangle rules and a few firewall rules.
by OlofL
Wed Mar 03, 2021 9:04 pm
Forum: General
Topic: CCR2004 vs. CRS317 for 10Gb home lab /w routing
Replies: 5
Views: 2416

Re: CCR2004 vs. CRS317 for 10Gb home lab /w routing

What hardware offload does CCR2004 have?
Can it do L3 offload on LACP link?
by OlofL
Thu Feb 18, 2021 7:34 pm
Forum: General
Topic: Can someone quickly quality assurance my Dual WAN, Dual LAN setup?
Replies: 0
Views: 642

Can someone quickly quality assurance my Dual WAN, Dual LAN setup?

I have mostly copied the ideas from this video, https://www.youtube.com/watch?v=67Dna_ffCvc BUT... it is almost 6 years old now, so maybe setups are more elegant/changed Everything seems to work fine now, but I need some quality assurance before going live, since I have never played around with mang...
by OlofL
Wed Feb 10, 2021 9:18 pm
Forum: RouterOS beta
Topic: RouterOS 7.1beta4 -- /routing ospf interface - cannot add interface
Replies: 1
Views: 1326

RouterOS 7.1beta4 -- /routing ospf interface - cannot add interface

From the routerosv7 help pages. https://help.mikrotik.com/docs/display/ROS/ROSv7+Basic+Routing+Examples /routing ospf interface add network=192.168.0.0/24 area=backbone_v2 There are no add commands under interface. Interface-template does work. [admin@MikroTik] /routing/ospf> interface/ find print [...
by OlofL
Wed Feb 10, 2021 8:45 pm
Forum: RouterOS beta
Topic: v7.1beta4 [development] is released!
Replies: 211
Views: 56990

Re: v7.1beta4 [development] is released!

BUG report: v7.1beta4, using GNS3 with CHR IMG file. Same setup as post above. These bugs are probably related. The export command does not exist under. /routing ospf or /routing bgp They where available in RouterOS v6. However, /routing export exists, but it hangs. [admin@MikroTik] /routing/ospf> e...
by OlofL
Wed Feb 10, 2021 8:40 pm
Forum: RouterOS beta
Topic: v7.1beta4 [development] is released!
Replies: 211
Views: 56990

Re: v7.1beta4 [development] is released!

BUG Report: When reporting an issue, please follow this template: Version number (if the issue is upgrade related, specify which version was installed before as well); Has the /system routerboard command changed name or been removed btw? [admin@MikroTik] > /system/package/update/print channel: stabl...
by OlofL
Mon Jul 13, 2020 10:50 am
Forum: Wireless Networking
Topic: LTE CAT6 modem disconnecting every 2-3 minutes
Replies: 44
Views: 24594

Re: LTE CAT6 modem disconnecting every 2-3 minutes

I have this issue on the new Mikrotik LTE Audience. I have upgraded to latest lte modem firmeware. I have tested all different routerboard software (testing/beta/stable) Upgraded routerboard firmware. I can reproduce this issue with LTE disconnecting by just starting a simple speedtest. Any news on ...
by OlofL
Wed Jul 08, 2020 4:44 pm
Forum: Beginner Basics
Topic: CRS317 management vlan IP address? [SOLVED]
Replies: 1
Views: 1673

CRS317 management vlan IP address? [SOLVED]

What am I missing to get the management IP working on my switch? I have followed the guide from the wiki, but I am not getting any IP connectivity. L2 forwarding works just fine for all vlans. All ports are supposed to be in trunk all vlan-mode. Followed the second example on this page: https://wiki...
by OlofL
Tue Jul 07, 2020 3:57 pm
Forum: RouterBOARD hardware
Topic: RB5011
Replies: 40
Views: 23078

Re: RB5011

this is tempting features, espeically with the new LTE6 mpic-e I am looking for a RB4011s sick performance, but with a built in 4G/5G modem. This would be awesome to do a selfbuilt SD-wan solution with dynamic ipsec tunnels.... +1 for LTE /mini pci-e slot with simcard support! Then I could build my...
by OlofL
Thu Jun 18, 2020 9:45 am
Forum: General
Topic: Traffic Flow Sample Rate
Replies: 5
Views: 3903

Re: Traffic Flow Sample Rate

Google took me here. Shameless bump? cant find a setting for sampling rate. NetFlow does not have sampling rate. Sampling rate is for sFlow, mainly used in Switches. At this time, RouterOS does not support sFlow However, many (all I tried) vendorrs support sampling in netflow/ipfix. Besides routeros.
by OlofL
Wed Jun 17, 2020 4:57 pm
Forum: General
Topic: Traffic Flow Sample Rate
Replies: 5
Views: 3903

Re: Traffic Flow Sample Rate

Google took me here.
Shameless bump?

cant find a setting for sampling rate.
by OlofL
Wed May 20, 2020 12:33 pm
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 148
Views: 45626

Re: Feature Request: IPSEC Improvements

Guys calm down, first we need to finish openvpn over udp.
You need to wait another two decades until alpha version of vti is available.
by OlofL
Wed Apr 08, 2020 4:11 pm
Forum: RouterBOARD hardware
Topic: RB4011 or similar performance - with built in 4G/5G?
Replies: 2
Views: 2473

RB4011 or similar performance - with built in 4G/5G?

Is there a a RB4011 or something in that range of perfomance that has 4G/5G built in? Im looking for a good CPE, like the RB4011. If main line goes down, I intend to use mobile broadband failover. The custom boards from mikrotik are so far too weak. I need RB4011 because of gigabit ipsec performance...
by OlofL
Fri Mar 13, 2020 4:56 pm
Forum: General
Topic: 31 subnet - Not finding an answer to default gateway.
Replies: 23
Views: 13455

Re: 31 subnet - Not finding an answer to default gateway.

As of 6.46.2, this still doesnt work.
by OlofL
Thu Feb 20, 2020 2:50 pm
Forum: General
Topic: GRE Tunnels and Dual Wan on one side
Replies: 4
Views: 4024

Re: GRE Tunnels and Dual Wan on one side

Hello, I dig up this topic because I have a similar issue. For load balancing purpose, I need to establish 2 gre tunnels between 2 routers. On one side I have 1 wan only, with a good bandwith, and on the otherside, I have 2 wan with low bandwith. Everything seems to go well, as both tunnels are run...
by OlofL
Thu Feb 20, 2020 2:47 pm
Forum: Announcements
Topic: v6.46.3 [stable] is released!
Replies: 28
Views: 52199

Re: v6.46.3 [stable] is released!

I am seeing some issues with routes over a /29 gre interface.
This has been observed since I went to v6.46.

viewtopic.php?f=2&t=157756&p=775916#p775705

Bug?
by OlofL
Thu Feb 20, 2020 2:45 pm
Forum: General
Topic: GRE over IPSEC stopped working
Replies: 5
Views: 4647

Re: GRE over IPSEC stopped working

I will set this to unsolved again, because I just had an equal case where the ip route for my ipsec gre link network is not routing properly...
And this time that trick is not working :/
by OlofL
Thu Feb 20, 2020 10:55 am
Forum: General
Topic: Request: add user with password hash
Replies: 10
Views: 4558

Re: Request: add user with password hash

Agree with this. Adding password with a hash is very critical, and a dealbreaker when automating big projects.
by OlofL
Wed Feb 19, 2020 2:34 pm
Forum: General
Topic: GRE over IPSEC stopped working
Replies: 5
Views: 4647

Re: GRE over IPSEC stopped working

Same problem here. It helped to restart VPN server on router side and delete clients and configure them again on client side. Hope that helps. I'm not sure but I think that Mikrotik might have some ipsec issues in versions 4.63.1-3. Do you also have a RB4011? Also, I downgraded to channel=long-term...
by OlofL
Wed Feb 19, 2020 2:21 pm
Forum: General
Topic: GRE over IPSEC stopped working
Replies: 5
Views: 4647

Re: GRE over IPSEC stopped working

Same problem here. It helped to restart VPN server on router side and delete clients and configure them again on client side. Hope that helps. I'm not sure but I think that Mikrotik might have some ipsec issues in versions 4.63.1-3. @Elliot I have restarted the vpn several times, on both ends. Howe...
by OlofL
Wed Feb 19, 2020 12:32 pm
Forum: General
Topic: GRE over IPSEC stopped working
Replies: 5
Views: 4647

GRE over IPSEC stopped working

Recently my gre tunnel over my ipsec tunnel stopped working. Remote site is using vyos. Ping works, so ipsec tunnel is obviously up, however, gre doesnt work. Here is a ping between both routers loopback interfaces. Which is in the ipsec policy. /ping src-address=172.24.32.54 172.18.255.26 count=3 S...
by OlofL
Tue Feb 18, 2020 11:36 am
Forum: Beginner Basics
Topic: How do I UNset a value under /system logging action ?
Replies: 1
Views: 2208

How do I UNset a value under /system logging action ?

How do I unset a value under /system logging action? I set the remote src-address to a value, but I see no way to unset it. There is no unset under this configuration stanza. Also, I cannot remove ` remote ` since its a default rule. So, how do I remove the `src-address` value in /system logging act...
by OlofL
Thu Jan 09, 2020 10:28 am
Forum: General
Topic: Generic grok mikrotik logs pattern
Replies: 2
Views: 3067

Re: Generic grok mikrotik logs pattern

Hello @orx did you find any patterns?
by OlofL
Thu Jul 18, 2019 11:53 am
Forum: General
Topic: encrypted password for mikrotik config
Replies: 24
Views: 10479

Re: encrypted password for mikrotik config

Any updates on this one?

In the world of automation, it would be nice to generate a list of users.
I need to not know the passwords of the other users.

For most other network OS's we have, there is an option to paste the encrypted password.
by OlofL
Mon Jul 08, 2019 11:23 am
Forum: General
Topic: What VPN tech with dynamic routing behind NAT?
Replies: 3
Views: 2112

What VPN tech with dynamic routing behind NAT?

Hello, I have a scenario where I need a backup connection over LTE. The LTE connection has a private IPv4 from provider , and is subjected to change any time. I have the LtAP from mikrotik, and I need to setup a VPN with dynamic routing to play together with a VyOS router. Mikrotik behind NAT, dynam...
by OlofL
Wed Jul 03, 2019 8:00 pm
Forum: Beginner Basics
Topic: "Failed to start IGMP proxy, you probably some PIM interfaces configured"
Replies: 3
Views: 2623

Re: "Failed to start IGMP proxy, you probably some PIM interfaces configured"

/routing pim export

no config

reboot
enable igmp proxy - still invalid.. hmm?
@losty ?
by OlofL
Thu May 02, 2019 1:27 pm
Forum: General
Topic: Kernel Failure in previous boot
Replies: 18
Views: 26350

Re: Kernel Failure in previous boot

Same problem here... Router is rebooting almost 10 times every hour. /system routerboard print routerboard: yes model: RB4011iGS+ serial-number: xxxx firmware-type: al2 factory-firmware: 6.43.8 current-firmware: 6.44.3 upgrade-firmware: 6.44.3 /log print 09:37:22 system,error,critical router was reb...
by OlofL
Tue Jan 15, 2019 2:53 pm
Forum: General
Topic: After restart device the PPP connection is not established
Replies: 2
Views: 6686

Re: After restart device the PPP connection is not established

I was trying to connect a Huawei E3372 LTE modem. I used the mikrotik microusb to usb cable that came with the RB2011 router. I can confirm this was a power issue. I was using RB2011 with a 5v 0.8a power. Changed to 5v 1.2a power, still same issue. Changed to a RB3011 with the 5v, 1.2a power - and p...
by OlofL
Tue Nov 13, 2018 6:08 pm
Forum: General
Topic: Any success with ansible over SSH in 2018?
Replies: 3
Views: 5418

Any success with ansible over SSH in 2018?

Hello, Im trying to do some simple ansible scripts to push some config to routeros. Im on routeros 6.43 and ansible 2.7 and trying the ansible modules: raw , command and the new routeros_command https://docs.ansible.com/ansible/latest/modules/routeros_command_module.html. None succeeeds, and they ju...
by OlofL
Tue May 15, 2018 3:29 pm
Forum: General
Topic: How should I be using queueing when I am also using fast track?
Replies: 1
Views: 1027

How should I be using queueing when I am also using fast track?

I intend to limit WAN to LAN and LAN to WAN (up/download) bandwidth per host, with some burst traffic The wiki says on the fasttrack page: "Fasttracked packets bypass firewall, connection tracking, simple queues, queue tree ..." I am not getting a queue working, where I want to shape bandw...
by OlofL
Tue Feb 20, 2018 2:22 pm
Forum: General
Topic: L2TP IPSEC With Local Secret works. With windows NPS doesnt work.
Replies: 1
Views: 1469

L2TP IPSEC With Local Secret works. With windows NPS doesnt work.

My setup: Mikrotik RB2011 with public IP and L2TP server enabled, use IPSEC and PSK. # feb/20/2018 12:56:31 by RouterOS 6.41.2 My clients are connecting from behind NAT to the public IP. On another setup, I use local /ppp secret users and they connect just fine from behind NAT. (Server still public ...
by OlofL
Tue Oct 24, 2017 2:00 pm
Forum: General
Topic: LTE Huawei E3372? [SOLVED]
Replies: 7
Views: 4386

Re: LTE Huawei E3372? [SOLVED]

It's weird. I got it up running once. It showed up under /interface lte But then I had to unplug the device, and now its not showing up again. Have tried reboot router and unplug a couple of times without success. are you using original OTG? This was probably it. I was using a one dollar china cabl...
by OlofL
Mon Oct 23, 2017 2:26 pm
Forum: General
Topic: LTE Huawei E3372? [SOLVED]
Replies: 7
Views: 4386

Re: LTE Huawei E3372? [SOLVED]

It's weird. I got it up running once. It showed up under /interface lte

But then I had to unplug the device, and now its not showing up again.

Have tried reboot router and unplug a couple of times without success.
by OlofL
Mon Oct 23, 2017 11:13 am
Forum: General
Topic: LTE Huawei E3372? [SOLVED]
Replies: 7
Views: 4386

Re: LTE Huawei E3372? [SOLVED]

just Unplug Power wait few seconds then plug it back Nope. Model 2011UiAS Serial Number 4CA904EC4A14 Firmware Type ar9344 Factory Firmware 3.10 Current Firmware 3.41 Version 6.41rc47 (testing) And /port> print Flags: I - inactive # DEVICE NAME CHANNELS USED-BY BAUD-RATE 0 serial0 1 Serial Console a...
by OlofL
Mon Oct 23, 2017 9:59 am
Forum: General
Topic: LTE Huawei E3372? [SOLVED]
Replies: 7
Views: 4386

Re: LTE Huawei E3372? [SOLVED]

on which board you test that?
Check if the usb port is added under system ports.
RB2011.

And no, nothing under system ports. Just the serial interface.
by OlofL
Fri Oct 20, 2017 4:41 pm
Forum: General
Topic: Understanding Mikrotik's definition of "Throughput" [SOLVED]
Replies: 5
Views: 3126

Re: Understanding Mikrotik's definition of "Throughput" [SOLVED]

Im pretty sure it means the second one. The first one would be impossible :)
by OlofL
Fri Oct 20, 2017 4:37 pm
Forum: General
Topic: LTE Huawei E3372? [SOLVED]
Replies: 7
Views: 4386

LTE Huawei E3372? [SOLVED]

I cannot get this one started. Interface LTE shows nothing. Nothing in logs. RouterOS 6.41RC47. Ubuntu reports this as [23892.376108] usb 2-3.2: new high-speed USB device number 13 using xhci_hcd [23892.481169] usb 2-3.2: New USB device found, idVendor=12d1, idProduct=1f01 [23892.481172] usb 2-3.2: ...
by OlofL
Fri Oct 06, 2017 2:34 pm
Forum: Forwarding Protocols
Topic: Pushing routes to PPTP/L2TP client of my RB
Replies: 9
Views: 21173

Re: Pushing routes to PPTP/L2TP client of my RB

Or any solution in 2017?
This actually worked on a macos sierra client: under /ppp secrets just select user and add under routes=1.1.1.0/24

The user is connecting with L2TP IPSEC.
Now I have split tunneling and users doesnt hog cpu of my weak little rb2011 :-)

I haven't tried on windows though.
by OlofL
Mon Oct 02, 2017 1:30 pm
Forum: General
Topic: Bridge configuration on RB2011?
Replies: 0
Views: 823

Bridge configuration on RB2011?

I'm getting IPTV from my ISP on a tagged vlan (101) on interface sfp1. It should go out untagged on ether5 where my IPTV decoder is located. I'm not getting the IPTV to work. From what I know, the decoder should get a DHCP address from ISP IPTV network. I can see traffic going in and out on bridge p...
by OlofL
Tue May 09, 2017 4:20 pm
Forum: General
Topic: "Slow" download RB3011
Replies: 6
Views: 2456

Re: "Slow" download RB3011

So much info is missed out here. How is your "/ip firewall export" looking like?
What is using CPU when you access Internet?
Check out /tool profile
by OlofL
Tue May 09, 2017 1:04 pm
Forum: General
Topic: Flapping IPSEC VPN Between Mikrotik and VyOS
Replies: 3
Views: 3314

Re: Flapping IPSEC VPN Between Mikrotik and VyOS

Just to be safe since you've obfuscated the IPs. The SA src or dst is not included in either range to be tunneled correct? That would explain why it goes down as soon as it comes up. Alternatively you may have a layer 1 (physical) issue at one of the sites. Have you ruled that out? Possibly w/a sus...
by OlofL
Mon May 08, 2017 3:39 pm
Forum: General
Topic: traffik flow pre/post nat?
Replies: 4
Views: 2003

Re: traffik flow pre/post nat?

The thread is a bit old, but I'm having similar issues. I'm trying to collect using nProbe + ntopng, and I see that v9 and IPFIX flows contain post-NAT address information, but this seems to be ignored by nProbe/ntopng - did you ever find a solution? I'm having the same problem whereby clients appe...
by OlofL
Mon May 08, 2017 2:25 pm
Forum: General
Topic: Flapping IPSEC VPN Between Mikrotik and VyOS
Replies: 3
Views: 3314

Flapping IPSEC VPN Between Mikrotik and VyOS

Hello, I've had a flapping IPSE Ctunnel for a while now. I cannot find out what the problem is. I can't see in logs on either side that VPN has stopped/started. Other side seem to get unreachable for a good 5-10 minutes and then back up again on its own. I am not 100% sure it is a VPN problem though...
by OlofL
Fri Dec 16, 2016 12:06 am
Forum: General
Topic: traffik flow pre/post nat?
Replies: 4
Views: 2003

Re: traffik flow pre/post nat?

As you can see in picture, the netflow 5 flows are captured after dst-nat is done.

The behavior seem to differ in ipfix. Is this a bug or working as intended?
ipfix vs netflow5.PNG
by OlofL
Wed Dec 14, 2016 1:10 am
Forum: General
Topic: traffik flow pre/post nat?
Replies: 4
Views: 2003

traffik flow pre/post nat?

It seems like traffik flow is captured pre dst nat. This means when I'm analyzing it looks like all traffic is headed for my WAN IP. Is it possible to get the traffik flow to capture flows post dst nat? The ipv4 next hop address field is populated with the right destination nat address. I am capturi...
by OlofL
Fri Sep 30, 2016 3:14 pm
Forum: RouterBOARD hardware
Topic: HAP AC
Replies: 538
Views: 197627

Re: HAP AC

Hm, tried to test network performance between windows PC connected by gigabit cable (cat.5e) to hAP AC and MacBook Pro connected by wifi 5ghz (1000-1300Mbit connection). Why transfer speed is so low? iperf -c 192.168.1.253 -t 30 -i 5 ------------------------------------------------------------ Clie...
by OlofL
Tue Dec 01, 2015 10:12 am
Forum: Beginner Basics
Topic: IPSEC problems with hAP and Bintec RS123
Replies: 17
Views: 3685

Re:

Read the fasttrack thread instead asking what is it. Unfortunately it has some problems as it is quite newly introduced feature.
The thread is huge, why would you just not answer here instead?
by OlofL
Fri Nov 20, 2015 9:26 am
Forum: General
Topic: Routing different subnets through different providers, possible???
Replies: 5
Views: 1177

Re: Routing different subnets through different providers, possible???

It's not metrics... I want all 10.x.x.x traffic from every location to route through Location A / Provider A. I want all 192.x.x.x. traffic from every location to route through Location B / Provider B. I think it has to do with masquerade and srcnat, but what I've tried hasn't worked. Currently I h...
by OlofL
Thu Nov 12, 2015 2:43 pm
Forum: General
Topic: Firewall filter rule with est+rel breaks when edited with gui? bug?
Replies: 1
Views: 917

Re: Firewall filter rule with est+rel breaks when edited with gui? bug?

Seems like this might have been a bug connected to the browser. The routers where earlier upgraded from 6.4 to 6.32, but deleting browser cache helped.
by OlofL
Thu Nov 12, 2015 2:41 pm
Forum: Beginner Basics
Topic: DNS over VPN (PPTP)
Replies: 1
Views: 2014

Re: DNS over VPN (PPTP)

I don't think it is possible to set on Mikrotik. You have to do it on the clients.
Powershell:
Set-VPNConnection -Name "Your-Connection" -DNSSuffix "something.local"
by OlofL
Thu Nov 05, 2015 10:37 am
Forum: General
Topic: LTE Interface Hijacking my Default Route
Replies: 3
Views: 1635

Re: LTE Interface Hijacking my Default Route

So... I got a 4g/LTE USB Dongle with a SIM card in it. The problem is whenever I reboot my router or disable/re-enable the LTE interface, it adds a default route with it's address as the gateway. This overrides my default routes and screws up everything for me. Anyone familiar with this issue? I do...
by OlofL
Tue Nov 03, 2015 1:25 pm
Forum: Beginner Basics
Topic: [SOLVED]Default route to Internet
Replies: 10
Views: 11738

Re: Default route to Internet

/ip firewall nat src-address=192.168.88.0/24 action=masquerade out-interface=ether3 chain=src-nat

meaning
address incoming to router with address 192.168.88.0/24 will be source-nated
with technique masquerade (meaning it will use the outgoing address of interface) ether3.
by OlofL
Tue Nov 03, 2015 12:35 pm
Forum: General
Topic: Firewall filter rule with est+rel breaks when edited with gui? bug?
Replies: 1
Views: 917

Firewall filter rule with est+rel breaks when edited with gui? bug?

Hello, if I create a rule from command line with two connection-states in one rule: /ip firewall filter add connection-state=established,related dst-address=192.168.213.0/24 chain=forward comment="est/rel to guests" If I then open this rule from the webgui the connection-state is removed, ...