Community discussions

MikroTik App

Search found 82 matches

by anthonws
Thu Jan 04, 2024 7:59 pm
Forum: General
Topic: Simple hairpin not working
Replies: 17
Views: 1757

Re: Simple hairpin not working

Here is what it worked for me: /ip firewall nat add action=masquerade chain=srcnat comment="Hairpin NAT" connection-mark="Hairpin NAT" log-prefix="Hairpin NAT Masquerade" add action=masquerade chain=srcnat comment="Default NAT Masquerade" out-interface=ether1....
by anthonws
Tue Jan 02, 2024 6:40 pm
Forum: General
Topic: hap ac3 ax - From 7.13 to 7.14 betas - No 2.4Ghz WiFi, Winbox, PING - 5Ghz WiFi and LAN works
Replies: 11
Views: 1671

Re: hap ac3 ax - From 7.13 to 7.14 betas - No 2.4Ghz WiFi, Winbox, PING - 5Ghz WiFi and LAN works

Sure, I'll explain a bit better. But I am now scared since you said "overwhelmed" :S 1. Device B (HAP AC3 AX), IP 192.168.25.3, is connected via RJ45 to Device A (RB4011 WiFi), IP 192.168.25.2. 2. Device B sits outside of the apartment (private storage room in the building) and is responsi...
by anthonws
Tue Jan 02, 2024 3:28 pm
Forum: General
Topic: hap ac3 ax - From 7.13 to 7.14 betas - No 2.4Ghz WiFi, Winbox, PING - 5Ghz WiFi and LAN works
Replies: 11
Views: 1671

Re: hap ac3 ax - From 7.13 to 7.14 betas - No 2.4Ghz WiFi, Winbox, PING - 5Ghz WiFi and LAN works

Thanks for the info. But, is my config incorrect then? Would this be a possible cause for the issues I described?
by anthonws
Tue Jan 02, 2024 2:52 pm
Forum: General
Topic: hap ac3 ax - From 7.13 to 7.14 betas - No 2.4Ghz WiFi, Winbox, PING - 5Ghz WiFi and LAN works
Replies: 11
Views: 1671

Re: hap ac3 ax - From 7.13 to 7.14 betas - No 2.4Ghz WiFi, Winbox, PING - 5Ghz WiFi and LAN works

Here's an "/export hide-sensitive" output. This is a simple config, since this is a "child" bridged AP device, that sits in my storage room. It has a VLAN for a specific port, for my Hyper-V server malware/trash lab VMs (it basically creates a direct isolated path towards my ISP)...
by anthonws
Tue Jan 02, 2024 2:00 pm
Forum: General
Topic: hap ac3 ax - From 7.13 to 7.14 betas - No 2.4Ghz WiFi, Winbox, PING - 5Ghz WiFi and LAN works
Replies: 11
Views: 1671

Re: hap ac3 ax - From 7.13 to 7.14 betas - No 2.4Ghz WiFi, Winbox, PING - 5Ghz WiFi and LAN works

@normis, I can access devices that are connected via LAN and WiFi (5Ghz), but cannot access the router itself (no PING, Winbox, SSH, HTTP).
2.4Ghz devices (Shelly mainly) are also not accessible.

@erlinden, will do.

Thanks
by anthonws
Tue Jan 02, 2024 1:31 am
Forum: General
Topic: hap ac3 ax - From 7.13 to 7.14 betas - No 2.4Ghz WiFi, Winbox, PING - 5Ghz WiFi and LAN works
Replies: 11
Views: 1671

hap ac3 ax - From 7.13 to 7.14 betas - No 2.4Ghz WiFi, Winbox, PING - 5Ghz WiFi and LAN works

IIRC, ever since I started using 7.13 beta (now with 7.14b4) I have started experiencing this weird behavior with my hap ac3 AX. After a couple of days (2 or 3) it stops responding to PING, I cannot access it via Winbox (discovery also doesn't pick it up) or HTTP, and 2.4Ghz WiFi stops being availab...
by anthonws
Fri Dec 15, 2023 5:21 pm
Forum: General
Topic: MACSEC - RB4011iGS+5HacQ2HnD + RBD53iG-5HacD2HnD
Replies: 1
Views: 2126

MACSEC - RB4011iGS+5HacQ2HnD + RBD53iG-5HacD2HnD

= Scenario = 1. RB4011iGS+5HacQ2HnD as main router (connect via ethernet to ISP ONT) 2. RBD53iG-5HacD2HnD as a bridge AP (located in my building basement), connected to RB4011 via ethernet 3. Ethernet cable goes partially through a public area (building garage) 4. Main subnet 192.168.25.0/24 5. 1 VL...
by anthonws
Sat Apr 08, 2023 10:37 pm
Forum: General
Topic: Zerotier performance on 4011
Replies: 4
Views: 732

Re: Zerotier performance on 4011

@Larsa, I don't think it is. I am using ZT in Mikrotik and haven't noticed a difference in performance, but that might be also the fact that it is single threaded... @Moba, agreed... It is unfortunate that we cannot squeeze a bit more of performance from RB4011 in this scenario. How I wished there w...
by anthonws
Fri Apr 07, 2023 12:28 pm
Forum: General
Topic: Zerotier performance on 4011
Replies: 4
Views: 732

Re: Zerotier performance on 4011

See answers here: https://discuss.zerotier.com/t/mikrotik ... -sec/11610.

I've tried asking some related questions in this forum and never got any answer back... Folks at ZT forum are quite nice and understanding :)
by anthonws
Mon Dec 05, 2022 4:14 pm
Forum: RouterOS beta
Topic: ZeroTier added to RouterOS v7.1rc2
Replies: 335
Views: 310680

Re: ZeroTier added to RouterOS v7.1rc2

Hey all, Couple of questions: 1. What is the expected recurrence for package updates (if any)? I see that there is a big gap between ZT official version vs Mikrotik one. 2. Has anyone conducted perf tests between RB4011, for example? I have a RB4011 with ZT and a NUC (N4020) and I cannot get more th...
by anthonws
Fri Dec 02, 2022 2:38 am
Forum: General
Topic: Force specific LAN device via ZeroTier [SOLVED]
Replies: 5
Views: 801

Re: Force specific LAN device via ZeroTier [SOLVED]

Thank you :) All is good! Added a prerouting rule to mark route and then added a manual route for that mark, with the new gateway. Had to tweak the fasttrack rule to ignore the new mark and get "full speed" (around 70 MBits). Now on to ZeroTier and how to increase its speed (most probably ...
by anthonws
Thu Dec 01, 2022 4:33 pm
Forum: General
Topic: Force specific LAN device via ZeroTier [SOLVED]
Replies: 5
Views: 801

Re: Force specific LAN device via ZeroTier [SOLVED]

Mangle
Thanks for the feedback!

So, a prerouting rule, where source address A, with destination 0.0.0.0/0 and action route to ZT gateway?
by anthonws
Thu Dec 01, 2022 12:51 am
Forum: General
Topic: Force specific LAN device via ZeroTier [SOLVED]
Replies: 5
Views: 801

Force specific LAN device via ZeroTier [SOLVED]

Hello, I would like to have your insights on what would be the best way to route a specific client (LAN), that I have connected on a given port of the router, to use a different gateway from the rest of the subnet. Objective is to force only a specific device to exit via ZeroTier, instead of the dir...
by anthonws
Wed Aug 10, 2022 2:53 am
Forum: Wireless Networking
Topic: Looking for guidance on improving LTE signal (LHGGR LTE6) on a 6-7km distance connection
Replies: 3
Views: 862

Re: Looking for guidance on improving LTE signal (LHGGR LTE6) on a 6-7km distance connection

@bpwl Thanks for the reply, but unfortunately the problem is that there is no registration of that antenna in the area of cell coverage... I at least can't find any 5614 antenna in a wide range around that area. And this has been one of the aspects I have been struggling while looking into Intel off...
by anthonws
Tue Aug 09, 2022 2:54 pm
Forum: Wireless Networking
Topic: Looking for guidance on improving LTE signal (LHGGR LTE6) on a 6-7km distance connection
Replies: 3
Views: 862

Looking for guidance on improving LTE signal (LHGGR LTE6) on a 6-7km distance connection

Hi, Context: During summer vacations, and other times of the year, I visit a remote village where there is no cell phone reception. Nearest area with cellphone service in LOS, is around 6km to 7km from where the LHGGR LTE6 antenna is. I'm not a networking professional, and the only thing I have done...
by anthonws
Thu Aug 04, 2022 4:23 pm
Forum: RouterBOARD hardware
Topic: hAP ax² dual band Wi-Fi 6 (802.11ax)
Replies: 287
Views: 67530

Re: hAP ax² dual band Wi-Fi 6 (802.11ax)

I think it is. Offering clarity for people, to ensure they do a proper knowledgeable decision, instead of instantly regretting it after finding out things are still not as expected. Which, looking at a previous post, it clearly shows how it is not clear for the majority. This is a SOHO device, often...
by anthonws
Thu Aug 04, 2022 4:12 pm
Forum: RouterBOARD hardware
Topic: hAP ax² dual band Wi-Fi 6 (802.11ax)
Replies: 287
Views: 67530

Re: hAP ax² dual band Wi-Fi 6 (802.11ax)

This just shows the state of confusion of what is supported vs not and what works vs it doesn't :) Fast roaming between APs is still not supported. Only within the same AP, between interfaces. And beta firmware's should not be used to state that something is supported. Until something gets GA, it is...
by anthonws
Thu Aug 04, 2022 2:33 pm
Forum: RouterBOARD hardware
Topic: hAP ax² dual band Wi-Fi 6 (802.11ax)
Replies: 287
Views: 67530

Re: hAP ax² dual band Wi-Fi 6 (802.11ax)

Now the questions are: 1. Will it support beam forming? 2. Will it support fast roaming between different APs? 3. We can all say "Yes" to #1 and #2, but the follow-up question would be: When? 4. And what about CAPsMAN support? I am happy for MT to finally showing signs of catching up the t...
by anthonws
Tue Jul 19, 2022 9:34 pm
Forum: Wireless Networking
Topic: WIFI 6 Roadmap
Replies: 199
Views: 144509

Re: WIFI 6 Roadmap

Personally, my biggest gripe is subpar roaming capabilities... Mobility is an important use case for me, as is bandwidth. Lack of fast roaming support is getting into my skin. Spending 1000 euros in 3 to 4 WiFi 6E AP's doesn't feel like too farfetched for me. Technology is an enabler for me. It allo...
by anthonws
Tue Jul 12, 2022 1:34 pm
Forum: Wireless Networking
Topic: cAP ac wireless performance: RouterOS v7.4rc versus OpenWrt v22.03rc? [SOLVED]
Replies: 7
Views: 3415

Re: cAP ac wireless performance: RouterOS v7.4rc versus OpenWrt v22.03rc? [SOLVED]

You can find a bit of perf info here: https://www.reddit.com/r/mikrotik/comments/uy3nhg/poor_wifi_performance_on_cap_ac/ And from the looks of it, folks won't need to use custom builds anymore. Specific pull requests have been reviewed and will be merged into master branch. https://github.com/openwr...
by anthonws
Tue Jun 28, 2022 1:27 pm
Forum: RouterOS beta
Topic: posts not strictly related to: v7.4beta [testing]
Replies: 165
Views: 12702

Re: v7.4beta [testing] is released!

Mikrotik is the new Nintendo :D Masters in "Even More Stability" changelog!!!

Thanks Znevna for the detailed container fixes/changes list! Awesome work!
by anthonws
Thu Apr 14, 2022 3:02 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 104030

Re: v7.3beta [testing] is released!

The same question again, do you think that we should stop working on BFD or fixing crashes to make pretty BGP logs? Fixing bad code vs implementing needed (basic) features is not a sane tradeoff to ask customers. And to be honest, your tone was not the most polite with that "ridiculous" c...
by anthonws
Wed Feb 23, 2022 11:26 am
Forum: Announcements
Topic: v7.2rc2 and v7.2rc3 is released!
Replies: 222
Views: 86348

Re: v7.2rc2 and v7.2rc3 is released!

I'm a regular home SOHO user, but looking at the quality of builds they are pushing out, even under 7.1 stable (yeah, call it "upgrade" branch...), with bootloops, BGP, VLAN, etc., issues, I am just mind boggled how it can happen. Clearly like you state, it must be very poor management dec...
by anthonws
Mon Dec 27, 2021 6:32 am
Forum: Announcements
Topic: v7.2rc1 is released!
Replies: 240
Views: 161232

Re: v7.2rc1 is released!

After adding 33th address, cpu load and memory leak starts, when memory runs out, the router crashes

https://youtu.be/Yi5_QShkT0Y
Good catch!! I reverted to 7.1.1 because of the CPU impact (RB4011), and Profiler did not exactly helped understanding where the impact was...
by anthonws
Mon Nov 15, 2021 12:15 pm
Forum: RouterOS beta
Topic: v7.1rc6 [development] is released!
Replies: 145
Views: 56687

Re: v7.1rc6 [development] is released!

Does the ether1 connect to a LAN device (not WAN) ? If you switch to another ethernet port , do you still have this port flapping ? If yes, it could be the issue of the device. for example: the apple TV 4K has this issue (if it is wire connection). It is a well known issue of Apple TV. Ether1 conne...
by anthonws
Sun Nov 14, 2021 1:05 pm
Forum: RouterOS beta
Topic: v7.1rc6 [development] is released!
Replies: 145
Views: 56687

Re: v7.1rc6 [development] is released!

@erlinden
Thanks for the feedback.
@pe1chl
No issues when was using RC5... I've restarted both the router and the ONT. Let us see, but I suspect this is going to continue to happen after a while.

I'll share more info today/tomorrow.
by anthonws
Sun Nov 14, 2021 12:42 pm
Forum: RouterOS beta
Topic: v7.1rc6 [development] is released!
Replies: 145
Views: 56687

Re: v7.1rc6 [development] is released!

Severe port flapping with RB4011iGS+5HacQ2HnD + rc6.

Submitted supout: https://help.mikrotik.com/servicedesk/s ... /SUP-65942

Disabling auto negotiation does not fix this. Disabling port and re-enabling it fixes it (temporarily).
by anthonws
Wed Sep 22, 2021 10:10 am
Forum: RouterOS beta
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 83131

Re: v7.1rc4 [development] is released!

SUP-61109 - Still cannot update RB2011 past 7.1 beta 6... This is probably not an issue with 7.1rc4, but rather with 7.1beta6. I was unable to upgrade my RB4011 above 7.1beta6 until I did a reset to no-defaults and uploaded the 7.1rc npk file to the device using MAC Winbox. A bug in 7.1beta6 caused...
by anthonws
Tue Sep 21, 2021 2:55 pm
Forum: RouterOS beta
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 83131

Re: v7.1rc4 [development] is released!

SUP-61109 - Still cannot update RB2011 past 7.1 beta 6...

Thanks,
anthonws.
by anthonws
Tue Sep 21, 2021 10:21 am
Forum: RouterOS beta
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 83131

Re: v7.1rc4 [development] is released!

Date and timestamp issue with netflow has been fixed! Finally! I stopped bothering and did not check. I will do it now :) Update: I can confirm it is indeed fixed! I've spent so many hours tshooting this, thinking the issue was with my Kibana or logstash that I can no longer count them... Eventuall...
by anthonws
Wed Sep 08, 2021 5:08 pm
Forum: Containers
Topic: v7.1rc3 adds container support
Replies: 493
Views: 162696

Re: v7.1rc3 adds Docker (TM) compatible container support

An example of how to use container package to run PiHole in RouterOS can be found here Wow! Very interesting! One less device eating power and occupying rack space (RPi4). Any thoughts about adding info on preferred HW for a given container? What kind of guardrails exist to ensure RouterOS works as...
by anthonws
Fri Sep 03, 2021 11:10 pm
Forum: RouterOS beta
Topic: v7.1rc2 [development] is released!
Replies: 194
Views: 44472

Re: v7.1rc2 [development] is released!

RB2011 still locked in 7.1beta6 (no upgrade path) :( In such situations you should do a /export of the full configuration and maybe also a backup, install the newer version, and restore the configuration from a local winbox connected to the MAC address. (so you can wipe it entirely before importing...
by anthonws
Fri Sep 03, 2021 3:50 am
Forum: RouterOS beta
Topic: v7.1rc2 [development] is released!
Replies: 194
Views: 44472

Re: v7.1rc2 [development] is released!

RB2011 still locked in 7.1beta6 (no upgrade path) :(
by anthonws
Wed Aug 25, 2021 6:52 pm
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78076

Re: v7.1rc1 [development] is released!

Will there be a way to have CAKE without a bandwidth limit? I'd like to see a version where it detects packet loss and automatically enables queueing. Isn't this what autorate-ingress is all about? I'm waiting to have CAKE stable to test this on my LHGGR LTE6, mainly for bufferbloat management and ...
by anthonws
Tue Aug 24, 2021 10:56 pm
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78076

Re: v7.1rc1 [development] is released!

Where are you targeting the CAKE queue? At the LTE connection? Has it been stable? I wanted to try our CAKE + Autorate Ingress (given my LTE connection bandwidth is quite random). No, it's on my pppoe Internet connection. I didn't think there was a point in using CAKE on LTE since I don't know the ...
by anthonws
Tue Aug 24, 2021 1:24 pm
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78076

Re: v7.1rc1 [development] is released!

So far all is working fine on my CRS317, RB4011 and LtAP-Mini (+R11e-LTE6). Noteworthy features in use are IPv6 to Internet, IPv6 over Wireguard (multiple tunnels), CAKE using queue tree. Lets see how stable it is ... Where are you targeting the CAKE queue? At the LTE connection? Has it been stable...
by anthonws
Tue Aug 24, 2021 12:08 am
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78076

Re: v7.1rc1 [development] is released!

Updated LHGGR from 6.49 latest beta to 7.1RC1. Update went smooth. I'm still testing, but it seems that the radio is now finding much less antennas than it did and also it looks like throughput has decreased a bit (TBD with more tests). And Winbox is always saying a modem firmware update is availabl...
by anthonws
Mon Aug 23, 2021 8:42 pm
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78076

Re: v7.1rc1 [development] is released!

Upgraded my test RB750GR3 Netflow now reports an incorrect date of 1970-01-01 Netflow v9 with NFSEN target I reported this also for beta 6 (SUP-51582). Support told me they could not repro... I provided all of the needed info (several traces and debug logs from netflow from a Linux box...). I gave ...
by anthonws
Mon Aug 23, 2021 12:47 pm
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78076

Re: v7.1rc1 [development] is released!

Is this working on LHGGR now? Hoping LTE is now fixed :)
by anthonws
Wed Aug 11, 2021 5:01 pm
Forum: Wireless Networking
Topic: LHGG Lte 6
Replies: 4
Views: 1357

Re: LHGG Lte 6

I've posted about a somewhat related issue https://forum.mikrotik.com/viewtopic.php?f=2&t=177480&p=872068#p872068. I get carrier aggregation (Primary: B1, CA: B20, optimally) just fine. But every once in a while it swaps them around for 5 minutes or so which absolutely tanks performance. If...
by anthonws
Wed Aug 11, 2021 1:54 am
Forum: Wireless Networking
Topic: LHGG Lte 6
Replies: 4
Views: 1357

Re: LHGG Lte 6

+1 Also not working for me. And when locking B3 I expected that CA would be B1, but nothing... Also cell locking breaks a couple of hours later... I know there is a v28 modem firmware, but it's beta and I don't want to cross that path. Personally I am not happy with the stability and the capabilitie...
by anthonws
Tue Jul 27, 2021 6:49 pm
Forum: RouterOS beta
Topic: v7.1beta6 [development] is released!
Replies: 377
Views: 243464

Re: v7.1beta6 [development] is released!

Had to return to OpenWrt, can't withstand unreliable WiFi from ROS and is too much time consuming to fine tune it. OpenWrt WiFi just works fast and reliable out of the box without having to tinker with it. offtopic: I had Linksys WRT1200 and WRT3200 running for several years with OpenWrt. Wifi suck...
by anthonws
Sun Jun 06, 2021 11:52 pm
Forum: RouterOS beta
Topic: v7.1beta6 [development] is released!
Replies: 377
Views: 243464

Re: v7.1beta6 [development] is released!

I also had my date "reset" after the upgrade. But because the LTE interface wouldn't work (no other WAN for me) I don't know if this was interim issue or general one with NTP or whatever...anyhow I downgraded due to the LTE problem. Thanks for sharing! Reported bug (SUP-51582). Cheers, an...
by anthonws
Fri Jun 04, 2021 12:43 am
Forum: RouterOS beta
Topic: v7.1beta6 [development] is released!
Replies: 377
Views: 243464

Re: v7.1beta6 [development] is released!

Is there any known issue with Traffic Flow in beta6? It looks like I can't get any netflow info into logstash (and I have checked everything in terms of config, FW, etc.) If no one has an idea, I will open a support case to check if it really is an issue in MT or not. Cheers, anthonws. Replying to ...
by anthonws
Wed Jun 02, 2021 1:26 pm
Forum: RouterOS beta
Topic: v7.1beta6 [development] is released!
Replies: 377
Views: 243464

Re: v7.1beta6 [development] is released!

Is there any known issue with Traffic Flow in beta6? It looks like I can't get any netflow info into logstash (and I have checked everything in terms of config, FW, etc.)

If no one has an idea, I will open a support case to check if it really is an issue in MT or not.

Cheers,
anthonws.
by anthonws
Wed May 05, 2021 11:22 pm
Forum: Announcements
Topic: v6.49beta [testing] is released!
Replies: 171
Views: 90761

Re: v6.49beta [testing] is released!

Reverted to beta 27 as both 36 and 38 were completely broken (router simply hanged randomly [most definitely kernel panic]). I would classify them more as Alpha than Beta.
by anthonws
Fri Apr 30, 2021 12:18 pm
Forum: Announcements
Topic: v6.49beta [testing] is released!
Replies: 171
Views: 90761

Re: v6.49beta [testing] is released!

Anyone care to send autosupout.rif file from the crashes experienced with these versions?
RB4011iGS+5HacQ2HnD + 6.49 beta 38.

I had 2 locks (no wifi or ethernet). Have to unplug from power. Is there a way that I can collect any data to send to support?

Thanks,
anthonws.
by anthonws
Tue Sep 29, 2020 11:59 am
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 184
Views: 115383

Re: v6.48beta [testing] is released!

RB4011iGS+5HacQ2HnD + 6.48beta40

When enabling IPFIX router enters reboot loop.

Shall I open a support case to share suppout?

Thanks,
anthonws.
by anthonws
Mon Sep 21, 2020 8:10 am
Forum: RouterOS beta
Topic: v7.1beta2 [development] is released!
Replies: 385
Views: 154386

Re: v7.1beta2 [development] is released!

I just setup Wireguard on my hAP AC² (...) I can also confirm that 2,4 GHZ Wifi is broken and client's don't get dhcp on that one, 5 GHZ seems to work fine. For me it works... until it stops working. Then I do /interface/wireless { disable wlan1; enable wlan1} ant it works again... until it stops w...
by anthonws
Mon Aug 24, 2020 10:23 am
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 184
Views: 115383

Re: v6.48beta [testing] is released!

Upgrading 2011UiAS-2HnD from beta 12 to beta 27 puts router in bootloop (stuck). Last message is "Starting services" and then router reboots.

Downgraded to beta 12 and restored configuration.
by anthonws
Mon May 18, 2020 8:41 pm
Forum: RouterBOARD hardware
Topic: Severe port flapping/reset/unstable in brand new RB4011iGS+5HacQ2HnD-IN
Replies: 2
Views: 1357

Re: Severe port flapping/reset/unstable in brand new RB4011iGS+5HacQ2HnD-IN

Does the flapping occur if you disable the wireless? I once had a routerboard that had frequent flaps, but it was the antenna that was placed to close to the board. Interesting. No I did not tested this. I'll do a quick test later on. What I notice is that it gets quite sensitive when removing/plac...
by anthonws
Mon May 18, 2020 7:10 pm
Forum: RouterBOARD hardware
Topic: Severe port flapping/reset/unstable in brand new RB4011iGS+5HacQ2HnD-IN
Replies: 2
Views: 1357

Severe port flapping/reset/unstable in brand new RB4011iGS+5HacQ2HnD-IN

Hey, Just acquired a RB4011iGS+5HacQ2HnD-IN from Amazon and since the very first instance that I've noticed several instabilities in the router. I've migrated from a RB2011UiAS-2HnD-IN which was/is rock solid working for the past years. Tested both importing config from previous router and also star...
by anthonws
Mon Apr 27, 2020 12:18 am
Forum: General
Topic: Netflow forwardingStatus (id 89)
Replies: 0
Views: 1264

Netflow forwardingStatus (id 89)

Hi! I've just setup elastiflow and started forwarding traffic flow (all interfaces) to that service. I have a GeoIP block rule (FW Input) that rejects incoming packets outside of my country CIDR (working just fine). I can successfully see the rule working when looking at logs. Looking at the elastif...
by anthonws
Sat Apr 25, 2020 7:34 pm
Forum: Beginner Basics
Topic: [SOLVED] Whitelist CIDR vs Blacklist
Replies: 2
Views: 1971

Re: Whitelist CIDR vs Blacklist

Solved. Added an Input FW rule to block everything !MYCOUNTRY, with a reject icmp network unreachable. Then used the following script to populate "MYCOUNTRY" list. /log info "Loading MYCOUNTRY ipv4 address list" /ip firewall address-list remove [/ip firewall address-list find lis...
by anthonws
Thu Apr 23, 2020 5:12 pm
Forum: Beginner Basics
Topic: [SOLVED] Whitelist CIDR vs Blacklist
Replies: 2
Views: 1971

[SOLVED] Whitelist CIDR vs Blacklist

What would be the best approach to only allow incoming traffic from a specific CIDR (my country), vs blocking everyone else?

I assume it would be more effective in terms of filtering.

Any hints? Or anyone willing to share something similar that they have achieved?

Thanks,
anthonws.
by anthonws
Sat Mar 21, 2020 6:14 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 180432

Re: v6.47beta [testing] is released!

I'm now constantly getting "DoH connection error: Idle timeout - connecting"...

It was working just a while ago...
by anthonws
Fri Mar 20, 2020 12:36 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 180432

Re: v6.47beta [testing] is released!

DoH?!?!?! AMAZING! Thank you so much for listening to your community!
by anthonws
Mon Feb 24, 2020 6:18 pm
Forum: RouterOS beta
Topic: Feature Request - Wireguard Protocol
Replies: 167
Views: 84452

Re: Feature Request - Wireguard Protocol

I'm actually more interested in understanding the actually benefits from a server perspective (Mikrotik Router), like the benefits on a ar9344 CPU (which doesn't look like it has AES-NI alike instructions). That is, *if* we ever get WireGuard in ROS.... LOLO I'm honestly more geared towards changing...
by anthonws
Sun Feb 16, 2020 5:54 pm
Forum: General
Topic: Netflow to external server (HTTPS/TLS)
Replies: 1
Views: 1291

Netflow to external server (HTTPS/TLS)

Is there any guide/manual/info that anyone can point me on how to implement Netflow to an external service, with proper traffic encryption?

Thanks,
anthonws.

Edit: Maybe the best option would be a site-to-site VPN (IPsec)...
by anthonws
Sun Dec 22, 2019 1:07 pm
Forum: General
Topic: Cloudfare for MIPSBE
Replies: 0
Views: 974

Cloudfare for MIPSBE

Anyway of getting the Cloudfare client for MIPSBE? According to this post, someone else has done it. https://forum.mikrotik.com/viewtopic.php?t=132678&sid=a141ddac1d5e61856e505f0920de1c9d#p693725 Really hoping to find a proper solution to run DoH without having to have another equipment (piHole)...
by anthonws
Thu Oct 24, 2019 9:09 pm
Forum: RouterOS beta
Topic: 7.0beta3 available in testing?
Replies: 40
Views: 16914

Re: 7.0beta3 available in testing?

BGP doesn't exist in v7. Don't install beta without knowing the limitations, please. Hi Normis! Where can I see the current limitations? Are these the limitations? "What is not available: - BGP / MPLS disabled - Extra packages - Winbox does not show all features, use CLI for most functionality...
by anthonws
Sat Aug 03, 2019 2:26 pm
Forum: General
Topic: Feature request - DNSCrypt support...
Replies: 173
Views: 81151

Re: Feature request - DNSCrypt support...

Mikrotik is a business, so we have to treat this feature request as such. Not on ideological (privacy of user) or technical (DoT vs DoH) grounds. That said, the question Mikrotik is asking themselves is obvious. Is this feature "worth it"? Our approach should be to not only say "yes&...
by anthonws
Fri Jul 12, 2019 8:11 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257379

Re: RouterOS v7.0 beta1 - when?

When? please an update - we are in so much pain with the existing 1072's and really don't want to replace them all if we don't need to! Or at least open up a version of CHR for ISO install with Intel drivers... when it's 1072 with ROS 7 becomes useless. why do we need beta for some devices in the e...
by anthonws
Mon May 20, 2019 5:00 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257379

Re: RouterOS v7.0 beta1 - when?

p.s. Now, before everyone get's super hyped and expects a release next month...Personally, and by experience in the software engineering industry, I don't expect any betas before EOCY 2019 or Q1 2020. I was at a MUM recently and they said we could expect "stable" RouterOS 7 release before...
by anthonws
Mon May 20, 2019 2:20 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257379

Re: RouterOS v7.0 beta1 - when?

I just want to let everyone know, that v7 is progressing pretty good this year, and most core functionality is usable. Some more difficult parts need to be done and we can release a public beta. Thanks for the feedback @normis! It sure adds a bit more of clarity, although there's no rough timelines...
by anthonws
Mon May 20, 2019 12:20 am
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257379

Re: RouterOS v7.0 beta1 - when?

Windows Phone was not vaporware, it was real ... shit. And that's why it disappeared real soon ... Well, it really showed that Microsoft thrives only on existing installed base. In a "new market", it really stands no chance against the competition. However, what I meant is that the platfo...
by anthonws
Sun May 19, 2019 12:04 am
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257379

Re: RouterOS v7.0 beta1 - when?

It's getting closer every day! ;)
What an awesome slogan for Mikrotik!

"Trust in Mikrotik! What you're waiting for is getting closer every day!" TM

Microsoft tried patenting that for Windows Phone/Mobile, but Mikrotik got there first ;)
by anthonws
Mon May 13, 2019 1:28 pm
Forum: General
Topic: Feature Request: OpenVPN [ovpn] udp tunnels
Replies: 249
Views: 139473

Re: Feature Request: OpenVPN [ovpn] udp tunnels

I'm going to stick around for more 9 years at least. 11 years is not enough time to age properly a piece of software.

To me, software has to be distilled for a minimum of 20 years!

No one better than Mikrotik knows how to do this properly!!

/S
by anthonws
Mon May 13, 2019 1:19 pm
Forum: General
Topic: [Feature request] Wireguard
Replies: 148
Views: 65820

Re: [Feature request] Wireguard

Wireguard was tested by INRIA Source: https://www.security.nl/posting/608796/Onderzoekers+testen+cryptografische+werking+WireGuard-vpn Abstract : WireGuard is a free and open source Virtual Private Network (VPN) that aims to replace IPsec and OpenVPN. It is based on a new cryptographic protocol der...
by anthonws
Sat May 11, 2019 6:46 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 304
Views: 157826

Re: v6.45beta [testing] is released!

I'm waiting for 8 months when the bug 2018101022007579 will be fixed. I started refusing from CCR wherever such an opportunity arises And the funny thing is that in half a year, the support responded only once “Sorry, we will reconsider the priorities” Your top router dies completely from two packa...
by anthonws
Wed May 08, 2019 5:15 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257379

Re: RouterOS v7.0 beta1 - when?

A lot of days without New firmware... Is It a Ros 7 signal?
No. It's just a signal of no signal. Typical around these corners...
by anthonws
Wed May 08, 2019 2:33 am
Forum: General
Topic: Feature Request: OpenVPN [ovpn] udp tunnels
Replies: 249
Views: 139473

Re: Feature Request: OpenVPN [ovpn] udp tunnels

This is getting to a point of being just plain pathetic... Just forget about UDP and/or LZO... Just make a decision, and if possible, fast! #1 Adopt OVPN from source (not this crippled implementation) #2 Adopt WireGuard (it's more than a "standard" now) Oh, and provide timelines for this p...
by anthonws
Wed Apr 10, 2019 1:03 pm
Forum: General
Topic: v6 RC and v7 BETA
Replies: 126
Views: 46665

Re: v6 RC and v7 BETA

They probably have other methods, feedback from distributors, people contacting support, MUM participants, ... so they probably know well what customers want. Being more open about their plans, and generally making customers feel closer to developement and heard, that's surely something they could ...
by anthonws
Wed Apr 10, 2019 12:46 am
Forum: General
Topic: Feature request - DNSCrypt support...
Replies: 173
Views: 81151

Re: Feature request - DNSCrypt support...

DoH is no longer a "waste of time" and it's now massively used by the industry (there's even Android Apps to turn on that nowadays with CloudFare for example). So, questions: 1. Is there an intention from Mikrotik to implement this? 2. Is there a sharable roadmap for the feature to be impl...
by anthonws
Wed Apr 10, 2019 12:40 am
Forum: General
Topic: v6 RC and v7 BETA
Replies: 126
Views: 46665

Re: v6 RC and v7 BETA

@anthonws: MikroTik already has that... kind of. Description of this forum is "BETA Testing and Feature Suggestions for the next RouterOS release (ROS v7)", so you're welcome to post your ideas and people do so. Others comment on it to show their interest. Only the actual voting is missin...
by anthonws
Tue Apr 09, 2019 5:01 pm
Forum: General
Topic: v6 RC and v7 BETA
Replies: 126
Views: 46665

Re: v6 RC and v7 BETA

Community driven features and minimal public roadmap is not something Mikrotik knows how to handle properly. Since I recognize that roadmap/feature plans are difficult for the majority to "read" properly (i.e. understand that they might be (de)prioritized), at least the community driven fe...
by anthonws
Fri Apr 05, 2019 11:57 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257379

Re: RouterOS v7.0 beta1 - when?

https://forum.mikrotik.com/viewtopic.php?p=725088#p725088 — isn't that about authenticity? :) dude, honestly i'm not here for the lulz. we work with business customers and we expect clear statements from MT so that we can plan our next hardware purchases. I think the plan is very clear if you're de...
by anthonws
Thu Apr 04, 2019 3:50 pm
Forum: General
Topic: v6 RC and v7 BETA
Replies: 126
Views: 46665

Re: v6 RC and v7 BETA

@normis Any timeline you can announce for v7 I know there was meant to be an announcement at the recent MUM but unfortunately there was not. I'm in the same boat as many others with bgp performance issues and really need a timeline that I can give to the CEO before I have to start looking at other ...
by anthonws
Sun Mar 10, 2019 12:19 am
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257379

Re: RouterOS v7.0 beta1 - when?

Context: Long time (home) user, lurking in the forums, enjoying reading change logs and all the advancement that Mikrotik is doing. Perspective on the topic: I can see that Mikrotik could definitely improve their marketing and messaging around the roadmap of their products and the future investments...
by anthonws
Mon Jan 21, 2019 10:15 pm
Forum: General
Topic: Feature request - DNSCrypt support...
Replies: 173
Views: 81151

Re: Feature request - DNSCrypt support...

Instead of wordless pluses, how about a discussion on TLS vs HTTPS. TLS gives you a specific port and capability to filter and NAT etc. HTTPS gives you more security, but also the inability to catch this traffic as an administrator. More aspects? Both would be the ideal scenario :) Naturally that I...
by anthonws
Wed Mar 29, 2017 12:28 am
Forum: Beginner Basics
Topic: Mikrotik L2TP IPSec Client to Strongswan Server
Replies: 0
Views: 1495

Mikrotik L2TP IPSec Client to Strongswan Server

Hi! I've configured a Strongswan server in my VPS, using this guide: https://raymii.org/s/tutorials/IPSEC_vpn_with_Ubuntu_16.04.html. Could anyone help me with configuring my Mikrotik router to connect as a client? I've already imported the user, CA Pub and VPN Pub certs into the router. Really appr...
by anthonws
Sat Jan 09, 2016 7:02 pm
Forum: Beginner Basics
Topic: SSTP VPN CA certificate import problem
Replies: 2
Views: 1922

Re: SSTP VPN CA certificate import problem

Is it possible to setup a SSTP VPN (not site to site) using a wildcard certificate (i.e. *.domain.com)? And has anyone used certificates from DigiCert to establish a SSTP VPN in RouterOS? If yes, can anyone please provide some pointers for a n00b? :P Much appreciated and sorry for the thread hijack!...