Community discussions

Search found 199 matches

by JimmyNyholm
Tue Feb 20, 2018 1:42 pm
Forum: Forwarding Protocols
Topic: eoip sharing subnet
Replies: 6
Views: 237

Re: eoip sharing subnet

The EOIP tunnel is an interface to RouterOS. This is your inside of tunnel and can be part of bridge. the interface that holds the LocalIP that eoip binds to in the encapsulated iptraffic it generates should of course not be part of the same (or any bridge) this creates loops and defeats the purpose...
by JimmyNyholm
Sun Feb 18, 2018 3:21 pm
Forum: Forwarding Protocols
Topic: Choose right VPN tunnel when both peers are dual-homed
Replies: 2
Views: 89

Re: Choose right VPN tunnel when both peers are dual-homed

Hi. If both sides have static ip's this is easy. If you need L3 only then setup meshed gre tunnels with configured ipsec secret then the gre traffic is encrypted and all is well. You may then assign links ip's and loopback and enable ospf and set the weight. Using carefull settings and only routing ...
by JimmyNyholm
Sun Feb 18, 2018 2:58 pm
Forum: Forwarding Protocols
Topic: vrf connected route leaking
Replies: 20
Views: 3937

Re: vrf connected route leaking

Not yet, but v7beta is coming later this year
Are we there yet?
by JimmyNyholm
Sun Feb 18, 2018 12:31 pm
Forum: The User Manager
Topic: API set command
Replies: 1
Views: 84

Re: API set command

The manual is at: https://wiki.mikrotik.com/wiki/Manual:API
C# abstractions are found at nuget and discussed here in the scripting forum, and set command perhaps here: viewtopic.php?f=9&t=130899&p=642998&hil ... 23#p642998
by JimmyNyholm
Sat Feb 17, 2018 2:19 pm
Forum: Forwarding Protocols
Topic: eoip sharing subnet
Replies: 6
Views: 237

Re: eoip sharing subnet

EOIP is ethernet like interface encapsulated over ip packet. Ethernetlike makes it able to be part of bridge witch you seem to grasp but then you attach ip's to interfaces instead of the bridge? Please make a drawing on what you are trying to do, then we are much more able to help you. Subject suges...
by JimmyNyholm
Wed Feb 14, 2018 10:25 am
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 348
Views: 34038

Re: v6.42rc [release candidate] is released!

*) radius - increase allowed RADIUS server timeout to 60s; To add an important reason to the too short limit problem of timeout in radius: Successful authentications are answered immediately (in order of milliseconds if possible), but to protect the server from brute-force attacks and DOS-type atta...
by JimmyNyholm
Sat Feb 10, 2018 4:01 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: CVE-2018-5951: MikroTik RouterOS Denial of Service Vulnerability
Replies: 16
Views: 830

Re: CVE-2018-5951: MikroTik RouterOS Denial of Service Vulnerability

Did you read my post entirely? A simple firewall stops it. Why don't you have it?
Let me think......... FASTPATH!
by JimmyNyholm
Sat Feb 10, 2018 3:59 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: CVE-2018-5951: MikroTik RouterOS Denial of Service Vulnerability
Replies: 16
Views: 830

Re: CVE-2018-5951: MikroTik RouterOS Denial of Service Vulnerability

Interesting, if you call something that just uses your resources "a vulnerability", when you can clearly protect your device against this (like with firewall), would you also call Chrome a vulnerability? It uses tons of RAM on my machine. First the CVE is reserved but information is not official fr...
by JimmyNyholm
Fri Feb 09, 2018 5:31 pm
Forum: RouterOS v7
Topic: Feature request: Virtual Extensible LAN (VXLAN)
Replies: 15
Views: 4797

Re: Feature request: Virtual Extensible LAN (VXLAN)

+1000 Inspiration for code can be found in the openbsd projekt https://man.openbsd.org/vxlan.4
by JimmyNyholm
Fri Feb 09, 2018 5:08 pm
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 348
Views: 34038

Re: v6.42rc [release candidate] is released!

*) crs3xx - added initial hw-offload support for 802.3ad and balance-xor bonding Jiiiha!.... Will test prompty. Offcourse 4 tuble ip hash srcip srcport dstip dstport will come later right!? Ok So I tested on a CRS326-24G-2S+ but neither winbox nor cli shows anything anywhere. Initial maybe initial ...
by JimmyNyholm
Fri Feb 09, 2018 4:27 pm
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 348
Views: 34038

Re: v6.42rc [release candidate] is released!

*) crs3xx - added initial hw-offload support for 802.3ad and balance-xor bonding
Jiiiha!.... Will test prompty. Offcourse 4 tuble ip hash srcip srcport dstip dstport will come later right!?
by JimmyNyholm
Wed Feb 07, 2018 2:04 pm
Forum: Announcements
Topic: MikroTik News February 2018 (Issue #80)
Replies: 49
Views: 6823

Re: MikroTik News February 2018 (Issue #80)

Excellent news on the PoE switch! Nice work, MikroTik. I have a 28 IP network camera installation coming up in May of this year. Could really use a rackmount 24 port PoE switch too!
And while youre at 24port powe why not 48port poe.
48 Gig ports with 1 qsfp+ port breakable to 4 sfp+ ports
by JimmyNyholm
Thu Feb 01, 2018 12:22 pm
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 348
Views: 34038

Re: v6.42rc [release candidate] is released!

that pvid could be seen in 41rc's aswell if you set something it goes away though
by JimmyNyholm
Thu Feb 01, 2018 12:00 pm
Forum: Announcements
Topic: MikroTik News February 2018 (Issue #80)
Replies: 49
Views: 6823

Re: MikroTik News February 2018 (Issue #80)

RouterOS v7, how cool is that!
The what and where now? Nothing that I see in that Issue mentions V7???
by JimmyNyholm
Tue Jan 30, 2018 8:31 pm
Forum: Forwarding Protocols
Topic: Strange readings in traffic monitor
Replies: 3
Views: 109

Re: Strange readings in traffic monitor

I'm running 1036 and 1072's with muliple full bgp feeds for both v4 and v6 its is not an issue.

What ROS version are you running? And what is your routerboard firmware version?

If you connect winbox to macserver you may se strange results connect using IP its unicast and stable.
by JimmyNyholm
Tue Jan 30, 2018 1:28 am
Forum: RouterOS v6 RC and v7 BETA
Topic: Routing traffic over 2 interfaces
Replies: 4
Views: 236

Re: Routing traffic over 2 interfaces

The question have ben answered. But as long as you take Layer2 in count you can with routing and proxy-arping overcome many subnetting wasting scenarios offcourse all depends on what problem you actually trying to solve.
by JimmyNyholm
Tue Jan 30, 2018 1:23 am
Forum: RouterOS v6 RC and v7 BETA
Topic: Slower ipsec with 6.41
Replies: 5
Views: 338

Re: Slower ipsec with 6.41

And support ticket number to Mikrotik is?
by JimmyNyholm
Tue Jan 30, 2018 1:02 am
Forum: RouterOS v6 RC and v7 BETA
Topic: ADD DYNAMIC VLAN ASSIGNMENT.
Replies: 37
Views: 13246

Re: ADD DYNAMIC VLAN ASSIGNMENT.

2018 Are we there yet?
by JimmyNyholm
Tue Jan 30, 2018 12:57 am
Forum: RouterOS v6 RC and v7 BETA
Topic: Bandwidth Test Tool and RADIUS
Replies: 6
Views: 1834

Re: Bandwidth Test Tool and RADIUS

I Did stumble over this today when I tried to uppgrade my sequrity a couple of notches.

+1000

Please add radius (PAP one time passwords) support to the bandwith testserver as well and only if radius server returns that user has a group that has the access offcourse
by JimmyNyholm
Tue Jan 30, 2018 12:44 am
Forum: Announcements
Topic: Tik App, MikroTik android utility ALPHA test
Replies: 310
Views: 91818

Re: Tik App, MikroTik android utility ALPHA test

I have to admit that it is a bit oxymoron to have "serious" concerns about 3rd party data exposure when you use android which is pretty much spyware on its own :P
Android is a virus :lol:
by JimmyNyholm
Mon Jan 29, 2018 2:57 pm
Forum: Announcements
Topic: New features in Dude RC
Replies: 22
Views: 7245

Re: New features in Dude RC

Upgraded to latest Ros42RC15 due to vmware tools support. (IE running on CHR) I think this RC version of dude has got the authentication faliure for bandwith test again or am I missing something in my dude role in my install. /user group add name=dude-group policy="telnet,ssh,reboot,read,test,sniff,...
by JimmyNyholm
Fri Jan 26, 2018 5:47 pm
Forum: Announcements
Topic: v6.39.3 [bugfix] is released!
Replies: 47
Views: 9410

Re: v6.39.3 [bugfix] is released!

In this release address list entry timeout option is broken! Entry is removed from address list randomly, but much more faster than specified amount of time many have raised this bug but no answer yet, perhaps it will be fixed in the next bugfix As of most comments on the forum have any one filed a...
by JimmyNyholm
Tue Jan 23, 2018 10:34 am
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 348
Views: 34038

Re: v6.42rc [release candidate] is released!

HW LACP is must. [Ticket#2018012222005306] RE: LACP HW CRS317-1G-16 [...] Hello, We are currently working on this feature. We hope to see it soon. Best regards, Arturs C. -- MikroTik.com Come to the MUM conferences, registration open in Cameroon, Kenya, Russia (Ekaterinburg), Russia (St. Petersburg...
by JimmyNyholm
Mon Jan 22, 2018 11:17 pm
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 348
Views: 34038

Re: v6.42rc [release candidate] is released!

I would love VLan Translation on CRS317-1G-16S+RM as well... when can vi se that?
by JimmyNyholm
Mon Jan 22, 2018 11:15 pm
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 348
Views: 34038

Re: v6.42rc [release candidate] is released!

HW LACP is must.
[Ticket#2018012222005306] RE: LACP HW CRS317-1G-16 [...]
by JimmyNyholm
Mon Jan 22, 2018 9:54 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature request: MPLS IPv6
Replies: 18
Views: 5889

Re: Feature request: MPLS IPv6

RouterOS firsts need ECMP for MPLS first. There is a lot people that have several links between routers for redundancy / more troughtput like us and with ldp enable, the Routers OS only sets a label for the first gateway. The other ECMP gateways dont get labels.. So no traffic is forwarded trought ...
by JimmyNyholm
Mon Jan 22, 2018 9:49 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: BGP multithreaded
Replies: 2
Views: 273

Re: BGP multithreaded

I have, no flapping all is working ok but convergence times is horrible. I have only 3 Full Feeds on each (ie: one full peer and two reflectors with all other peers) one tilera core is constantly at 100percent it will do as much as it can, as fast as it can. Forwarding and routing is good and fast a...
by JimmyNyholm
Mon Jan 22, 2018 8:56 pm
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 348
Views: 34038

Re: v6.42rc [release candidate] is released!

HW LACP is must.
by JimmyNyholm
Mon Jan 22, 2018 8:50 pm
Forum: Scripting
Topic: /tool fetch https check-certificate=yes undocumented, not working...
Replies: 7
Views: 174

Re: /tool fetch https check-certificate=yes undocumented, not working...

Can you please update wiki to reflect the new options. If I don't read the forum wrong it is possible to set HttpHeaders!? how? Examples please and in wiki to..... http-data cli tells me: http-data -- POST or PUT request body data So this tells me no headers can go into this field..... How do I chan...
by JimmyNyholm
Mon Jan 22, 2018 8:37 pm
Forum: General
Topic: RouterOS Radius Login SSH / Winbox
Replies: 1
Views: 79

Re: RouterOS Radius Login SSH / Winbox

Waiting for comment on this from Support: [Ticket#2018012222004996] RE: RADIUS LOGIN.
by JimmyNyholm
Mon Jan 22, 2018 12:06 pm
Forum: General
Topic: /31 bit mask doesn't work on GRE tunnel?
Replies: 3
Views: 161

Re: /31 bit mask doesn't work on GRE tunnel?

Exactly but that only works on MT <-> MT ppp's not other brands...

Please Fix
by JimmyNyholm
Sun Jan 21, 2018 9:44 pm
Forum: General
Topic: RouterOS Radius Login SSH / Winbox
Replies: 1
Views: 79

RouterOS Radius Login SSH / Winbox

Hi All. Why do SSH radius login do pap by default and not settable? (Don't Read me Wrong I need pap because I use one time passwords there are nothing to challenge on so chap is not an option) And Why do Winbox radius login only do chap by default and not settable? (This hits me because I need PAP, ...
by JimmyNyholm
Sat Jan 20, 2018 3:14 pm
Forum: Announcements
Topic: v6.41 [current]
Replies: 304
Views: 36678

Re: v6.41 [current]

If it's critical for you - just stay with 6.40 or earlier :)
:wink: Am doing just that, was just stating the obvious. :D
by JimmyNyholm
Sat Jan 20, 2018 3:04 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Any plans for SD WAN?
Replies: 12
Views: 595

Re: Any plans for SD WAN?

SD-WAN can balance, prioritice (duplicate packets for guaranteed delivery with lowest possible latency) on multiple encrypted paths and such on applications/steams level. Yes I would love MT to do this but it is currently not possible with the design in current hardware or CPU power and software. Bu...
by JimmyNyholm
Sat Jan 20, 2018 2:47 pm
Forum: RouterOS v7
Topic: Future Request: Enable telnet & winbox services on vrf interfaces/ips
Replies: 1
Views: 156

Re: Future Request: Enable telnet & winbox services on vrf interfaces/ips

I'm told Full VRF mode will be there in V7.

uprf is not vrf enabled either witch is bigger issue for me. renders current vrf pretty much useless.
by JimmyNyholm
Sat Jan 20, 2018 2:43 pm
Forum: RouterOS v7
Topic: Feature request: Virtual Extensible LAN (VXLAN)
Replies: 15
Views: 4797

Re: Feature request: Virtual Extensible LAN (VXLAN)

Hell Yes... The newer chips in switch hardware all ready have hardware tagging enable new software/hardware tagging interface type PLEASE!
by JimmyNyholm
Sat Jan 20, 2018 2:30 pm
Forum: Announcements
Topic: v6.41 [current]
Replies: 304
Views: 36678

Re: v6.41 [current]

Which will disable fastpath on your router, yes!? It won't. TCP MSS has to be adjusted only in the first two packets of each session, and the fasttracking rule only applies on the following ones anyway (TCP state established is reached after the SYN,ACK has been processed). I wasn't talking about f...
by JimmyNyholm
Sat Jan 20, 2018 2:04 pm
Forum: Announcements
Topic: v6.41 [current]
Replies: 304
Views: 36678

Re: v6.41 [current]

The problem is already fixed in 6.42rc.

The workaround is to add TCP MSS rule to your firewall rules
Witch will disable fastpath on your router yes!?
by JimmyNyholm
Fri Jan 12, 2018 11:45 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Please resolve the problem setup
Replies: 2
Views: 173

Re: Please resolve the problem setup

How many neighbours is that?
by JimmyNyholm
Fri Jan 12, 2018 7:31 pm
Forum: General
Topic: ethernet tx/rx too long
Replies: 6
Views: 1149

Re: ethernet tx/rx too long

Someone know what this is? I have it on in 6.41 HapACs connected with Max L2Mtu on sfp to CCRS...
by JimmyNyholm
Fri Jan 12, 2018 6:24 pm
Forum: Announcements
Topic: v6.41 [current]
Replies: 304
Views: 36678

Re: v6.41 [current]

Can someone explain why eoip interface has a l2mtu setting of 65535 in this version and not changeble.

If I do bridging it is this value that is the max l2 recieved right? and it sould after adding headers fragment if outgoing interface after routelookup has a smaller ip mtu?
by JimmyNyholm
Fri Jan 12, 2018 5:33 pm
Forum: Announcements
Topic: Securing your device is important
Replies: 24
Views: 1614

Re: Securing your device is important

Set networks for ALL services even if they are disabled. Set networks for ALL users, with strong passwords. Disable Mac Servers for interfaces that do not need it. Disable IP Neighbour for interfaces that do not need it. IF Deploying Romon consider segment key usage and have different hops for diffe...
by JimmyNyholm
Fri Jan 12, 2018 5:17 pm
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 348
Views: 34038

Re: v6.42rc [release candidate] is released!

Version 6.42rc5 has been released.
*) bridge - properly update "actual-mtu" after MTU value changes (introduced v6.41);
Please explain.
by JimmyNyholm
Thu Jan 11, 2018 9:27 am
Forum: Forwarding Protocols
Topic: BGP Route Reflectors, how to properly configure??
Replies: 19
Views: 7539

Re: BGP Route Reflectors, how to properly configure??

Others has all ready provided insights to your question. I just had one more. When using MT as a route reflector and if you follow guides that the reflector actually not participating in the data path. MT will only reflect installed routes it can't currently (it has been asked for) be pure reflector...
by JimmyNyholm
Wed Jan 10, 2018 5:37 pm
Forum: SwOS
Topic: VLANS on CRS317-1G-16S+
Replies: 3
Views: 253

Re: VLANS on CRS317-1G-16S+

There is no problem with RouterOs in current version 6.41 as far as I know. I have 20 of them in production and 3 more in a labb doing P switching mpls in hardware on L3 only interfaces. Never se any cpu hit on it as long as you only do stuff that is currenty supported att the hardware offload (swit...
by JimmyNyholm
Mon Jan 08, 2018 10:26 am
Forum: Forwarding Protocols
Topic: Filter For Prefixes Origin My OWn AS Allow
Replies: 1
Views: 84

Re: Filter For Prefixes Origin My OWn AS Allow

Your own as prefixes originated from somewhere in your as comming over ibgp (reflected or meshed) is essential empty of aspath so:

^$
by JimmyNyholm
Sun Jan 07, 2018 3:27 pm
Forum: Forwarding Protocols
Topic: Bonding 2 WAN Connections for faster streaming
Replies: 3
Views: 199

Re: Bonding 2 WAN Connections for faster streaming

For the second question. Yes to do what ever fashion you have to control both ends of the communication. Off course this doable by overlay over other transports but the above knowledge will take you there. And by saying it is Doable is NOT saying I would recommend it!. Again take the above mentions...
by JimmyNyholm
Sun Jan 07, 2018 3:19 pm
Forum: Forwarding Protocols
Topic: Bonding 2 WAN Connections for faster streaming
Replies: 3
Views: 199

Re: Bonding 2 WAN Connections for faster streaming

Some one correct me but: I am afraid it it not possible as long as you only have one stream: Bear with me on this one. Not speaking MT just saying: L2 Bond with or without bonding protocol: One Stream has to take the same path as long it is available, this is due to not have packet out of order prob...
by JimmyNyholm
Sun Jan 07, 2018 3:00 pm
Forum: Forwarding Protocols
Topic: OSPF DEFAULT ROUTES
Replies: 3
Views: 208

Re: OSPF DEFAULT ROUTES

This is doable and by reading up on the wiki and underlying linux chains stuff you will be able to. Mangle mark all connections coming in from the other interface, then you can pre or post route change the marked connections going out again. I am only doing pure routing in the isp space. For me this...
by JimmyNyholm
Sun Jan 07, 2018 2:53 pm
Forum: Forwarding Protocols
Topic: OSPF & PPPoE - strange issue
Replies: 2
Views: 174

Re: OSPF & PPPoE - strange issue

pppoe client not getting IP is one problem.

I would say that in this case ospf has nothing to do with it looking at all interfaces in ospf process it is surly down as no IP i assigned.
Your question is not for the Forwarding protocols section i'm afraid.