Community discussions

MikroTik App

Search found 4291 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 15
by Amm0
Wed Sep 18, 2024 9:50 pm
Forum: General
Topic: May you recomend me an SSTP VPN service?
Replies: 8
Views: 502

Re: May you recomend me an SSTP VPN service?

Amm0 I would ask you if I understand good, Oracle's gives a free of cost cloud forever, where is possible somehow to run a CHR image? Have you done it? Is it working ok? Where the server is located? I haven't tried their cloud. And your locale may add more complication, dunno. But some folks in for...
by Amm0
Wed Sep 18, 2024 9:44 pm
Forum: General
Topic: MQTT to Home Assistant
Replies: 17
Views: 3453

Re: MQTT to Home Assistant

I don't think I will spend time on the Lora [...] There seems to be an existing Things Network integration for Home Assistant, so there is probably not a lot of value to add. If your KNOT is a LoRa-enabled one... I'll note there are a lot of fun LoRaWAN sensors available, for a lot weird things, th...
by Amm0
Wed Sep 18, 2024 9:21 pm
Forum: Beginner Basics
Topic: Playing with VRFs - what am I doing wrong?
Replies: 20
Views: 1078

Re: Playing with VRFs - what am I doing wrong?

If the LAN side is also on 192.168.1.x/24? :? While you can generally pick your own LAN side subnet to NOT conflict (further), and avoid these esoteric RouterOS questions... But let's assume LAN absolutely has to be 192.168.1.1 and two WANs have to be 192.168.1.1... AFAIK that too should be fine wi...
by Amm0
Wed Sep 18, 2024 7:18 pm
Forum: Beginner Basics
Topic: Playing with VRFs - what am I doing wrong?
Replies: 20
Views: 1078

Re: Playing with VRFs - what am I doing wrong?

Sure, there are use cases for VRFs. More just saying that having multiple same subnets are allowed without VRF. Now it means the default route 0.0.0.0/0 needs to be % qualified, so gateway=192.168.1.1 %etherX-toWAN-Y . Failover happens by using check-gateway=ping (or more complex netwatch/recursive ...
by Amm0
Wed Sep 18, 2024 6:27 pm
Forum: Beginner Basics
Topic: Playing with VRFs - what am I doing wrong?
Replies: 20
Views: 1078

Re: Playing with VRFs - what am I doing wrong?

experiments with VRFs to implement an automatic failover between 2 ISPs Maybe I'm missing something here... But what is the point of using VRF for ISP failover? — VRFs have nothing to do with "automatic failover". Failover works without VRFs, and so layering VRF on top of failover mechani...
by Amm0
Tue Sep 17, 2024 9:16 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1063
Views: 187373

Re: 📣 WinBox 4 is here 📣

UI suggestion - Ability to disable labels, like "CPU" or "Memory (Free/Used/Total)", in the "Resource panel" aka status bar. i.e. have some "icons only" option in settings for status/"resource panel". Currently, it often wraps the labels, which looks...
by Amm0
Tue Sep 17, 2024 8:18 am
Forum: Beginner Basics
Topic: Missing SNMP Entries On hAP ac^3
Replies: 1
Views: 145

Re: Missing SNMP Entries On hAP ac^3

Nope. See viewtopic.php?t=190932 - there is workaround to use bridge hosts there, maybe that be a workaround.
by Amm0
Mon Sep 16, 2024 11:39 pm
Forum: Beginner Basics
Topic: Problem with VLANs and Bridge
Replies: 18
Views: 863

Re: Problem with VLANs and Bridge

The current full config be helpful to know what's going on at this point. It hard to follow all the changes/testing to know what is going on where. One tip is that /tool/torch can sometime help clarify what traffic is flowing where when dealing with the bridge. And how do you explain that ether8 whi...
by Amm0
Mon Sep 16, 2024 11:21 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1063
Views: 187373

Re: 📣 WinBox 4 is here 📣

It could be good also for branding, not only for whiners who don't fully appreciate your design choices. ;) Two birds with one stone. On the branding topic... - Some "white label" version of winbox4, without any logos, be nice at some point. The old winbox was pretty generic and did not h...
by Amm0
Mon Sep 16, 2024 10:52 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 654
Views: 249533

Re: v7.15.3 [stable] is released!

What else should I change? The topic, please. This one is not the right place for discussing this, create a new one. Very true. Just to close this out... since the permission have changed somewhat recently (but NOT in this release). Poster with fetch is using netwatch, which has restricted permissi...
by Amm0
Mon Sep 16, 2024 10:44 pm
Forum: Beginner Basics
Topic: Problem with VLANs and Bridge
Replies: 18
Views: 863

Re: Problem with VLANs and Bridge

Quick thoughts: - When 7.16 comes out, the bridge will be automatically marked as tagged, by virtue of use of a pvid= on /interface/bridge/port and/or having a /interface/vlan that listens on VLAN-enabled bridge (or using MVRP). So the need to muck with /interface/bridge/vlans should be limited to o...
by Amm0
Mon Sep 16, 2024 7:25 pm
Forum: General
Topic: Cannot ping from console VETH interface in containers bridge
Replies: 4
Views: 285

Re: Cannot ping from console VETH interface in containers bridge

Hence I've assumed it was a bug. But I admit it could be a "half baked" 7.16 change that has somehow leaked to 7.15.3. Entirely possible. I created/use a netinstall container . I know this worked at some point in past with a VETH on a vlan-enabled=yes bridge. But stopped worked in ~7.15, ...
by Amm0
Mon Sep 16, 2024 6:13 pm
Forum: Wireless Networking
Topic: LoRa point-to-point
Replies: 2
Views: 413

Re: LoRa point-to-point

True. While not PtP... one option is to run your own LNS/etc service to relay between devices You can run something like https://www.chirpstack.io as a container to do this (on ARM/X86 things, but not the KNOT) so it's still be self-contained without the cloud.
by Amm0
Mon Sep 16, 2024 5:38 pm
Forum: General
Topic: May you recomend me an SSTP VPN service?
Replies: 8
Views: 502

Re: May you recomend me an SSTP VPN service?

Or you can use CHR on a remote/cloud VPS. Never tried it, but there was a recent thread about CHR on Oracle's "free forever" cloud:
viewtopic.php?t=188848
I'm sure there are hosting service for CHR too.
by Amm0
Mon Sep 16, 2024 5:29 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1063
Views: 187373

Re: 📣 WinBox 4 is here 📣

I got a crash report (look like null pointer) from MacOS (14.6.1 / X86), soon after coming out of sleep: Crashed Thread: 0 Dispatch queue: com.apple.main-thread Exception Type: EXC_BAD_ACCESS (SIGSEGV) Exception Codes: KERN_INVALID_ADDRESS at 0x0000000000000000 Exception Codes: 0x0000000000000001, 0...
by Amm0
Mon Sep 16, 2024 3:49 am
Forum: Scripting
Topic: Rest API port reset [SOLVED]
Replies: 8
Views: 7595

Re: Rest API port reset [SOLVED]

di I get it right, that it's possible to turn on / off PoE with the API by sending a POST or PUT to the switch? Well, POST and PATCH .... PUT is for creating NEW records like "add" at CLI... but ethernet ports always exist so you need "PATCH" which same as CLI "set". P...
by Amm0
Mon Sep 16, 2024 3:16 am
Forum: Wireless Networking
Topic: Ax3 WiFi ignores access list [SOLVED]
Replies: 6
Views: 440

Re: Ax3 WiFi ignores access list [SOLVED]

... really wierd...
Yup. FWIW, the docs on how this works are lacking . My guess it operates a "matcher"/selector, not like the firewall "filter"/etc - or at least that how I rationalize the logic here.
by Amm0
Mon Sep 16, 2024 1:22 am
Forum: Wireless Networking
Topic: Ax3 WiFi ignores access list [SOLVED]
Replies: 6
Views: 440

Re: Ax3 WiFi ignores access list [SOLVED]

The interface or SSID to which connections should be denied is not specified. It worked well this way on HAP ac2. But i tried to specify interfaces in each entry- still ignored. The key is you need one that to be matched, just accept without ANYTHING will get skipped - or at least that's what I've ...
by Amm0
Sat Sep 14, 2024 9:52 pm
Forum: Scripting
Topic: Baffled by global variable behavior in scripting
Replies: 1
Views: 218

Re: Baffled by global variable behavior in scripting

It's just odd. But this is the documented behavior for recent versions: policy - policy that grants user management rights. Should be used together with the write policy. Allows also to see global variables created by other users (requires also 'test' policy). (from https://help.mikrotik.com/docs/di...
by Amm0
Fri Sep 13, 2024 10:23 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1063
Views: 187373

Re: 📣 WinBox 4 is here 📣

And all Cyrillic comments are unreadable in WinBox 4 It seems that winbox4 uses UTF-8 (finally), just like (probably) your web browser running webfig. True. But PSA there is still only one config that store things... And config just stores the bytes as provided from whatever UI/CLI. So can enter Cy...
by Amm0
Fri Sep 13, 2024 5:22 pm
Forum: Scripting
Topic: Syntax highlighting and completions for Sublime Text
Replies: 43
Views: 85369

Re: Syntax highlighting and completions for Sublime Text

I'm looking to significantly improve the syntax definition for ST4 to provide context-aware completions and wonder if someone from the MikroTik team could reach out to me and provide a full list of commands w/ parameters. As I understand some packages are only available on certain hardware and I on...
by Amm0
Fri Sep 13, 2024 5:13 pm
Forum: Scripting
Topic: check netwatch with api
Replies: 2
Views: 1030

Re: check netwatch with api

And the 2nd example would need to use a POST, not a GET (which is curl's default HTTP method). In RouterOS REST API, the POST method mimics the native API. For curl you need a "-X POST" to use the more CLI commands like print: curl -k -u admin:password - X POST https://192.168.88.1:443/res...
by Amm0
Fri Sep 13, 2024 5:06 pm
Forum: Scripting
Topic: cUrl->tool fetch
Replies: 1
Views: 175

Re: cUrl->tool fetch

Good afternoon. I ask for help in adapting the script. curl -X 'POST' \ 'https://wappi.pro/api/sync/message/send?profile_id=a53331f5-8845' \ -H 'accept: application/json' \ -H 'Authorization: 5232ab589f823063605b0274d3d3031d83ea841' \ -H 'Content-Type: text/plain' \ -d '{ "recipient": &qu...
by Amm0
Fri Sep 13, 2024 4:51 pm
Forum: General
Topic: RouterOS CHR limits bandwidth to ~400Mbit....
Replies: 25
Views: 1111

Re: RouterOS CHR limits bandwidth to ~400Mbit....

Which again points at CHR itself rather than at virtualization platform.
Yup. I'd look at the CPU usage on the Proxmox host, if CPU is low there, but CHR is high... you should increase the CPU cores assigned to CHR. Or perhaps memory too.
by Amm0
Fri Sep 13, 2024 4:37 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1063
Views: 187373

Re: 📣 WinBox 4 is here 📣

Great work, very creative solution to "dropdown vs tabs". Yes, and that one will stay for now. As seen in the thread, it is a much more divisive topic, than main window Tabs Are you sure? I'm just not sure there are that many fan of the "webfig-like dialogs". While the minority, ...
by Amm0
Fri Sep 13, 2024 3:51 pm
Forum: Announcements
Topic: Newsletter #114 | September 2023
Replies: 77
Views: 17723

Re: Newsletter #114 | September 2023

Mikrotik typically* does list CA bands in the "Brochure" of LTE products. And 2 x B3 is consistent with those specs for FG621 modem (e.g. new R11eL-FG621-EA) : Screenshot 2024-09-13 at 5.45.36 AM.png * except on the modem itself, see https://mikrotik.com/product/r11el_fg621_ea#fndtn-downlo...
by Amm0
Fri Sep 13, 2024 3:15 am
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 349
Views: 319336

Re: NEW FEATURE: Back to Home VPN

i was trying with facebook messenger. teams , whatsapp and messenger - all working Well, the share link returns HTML that requires JavaScript. So if FB tries to "unfurl" (e.g. click the link, to summarize content for a message stream), the BTH link is only a redirect to the App Store with...
by Amm0
Fri Sep 13, 2024 12:10 am
Forum: Containers
Topic: Containers won't start after power loss
Replies: 8
Views: 7014

Re: Containers won't start after power loss

Yeah... And the "Start at boot" is kinda of "one-and-done" situation. If the disk ain't mounted, for any reason, container won't start. It's not just limited USB, but stuff like ROSE+NFS for containers you'll also see this sometimes (or at least I have, occasionally). A schedule ...
by Amm0
Thu Sep 12, 2024 11:50 pm
Forum: General
Topic: Plain rsync using rose package
Replies: 3
Views: 255

Re: Plain rsync using rose package

And there is no USB on the RB750G either. And, with only 1G RAM... using a ram-disk (that could be persist to SD) for rsync isn't likely going to work either. Found out that an sdcard it is not the best storage for what I need. Perhaps, but SD card do have different speed rating/classes. And... also...
by Amm0
Thu Sep 12, 2024 9:33 pm
Forum: General
Topic: ECMP recursive routes
Replies: 34
Views: 3675

Re: ECMP recursive routes

Well, learn something new. In OP example they are not the same, what is intended is to try to install forwarding path over ether1 twice and through ether2 once, leading to forwarding where ether1 is chosen twice as much as ether2. This is not going to work in v7, because, like I said previously, equ...
by Amm0
Thu Sep 12, 2024 4:24 pm
Forum: General
Topic: Plain rsync using rose package
Replies: 3
Views: 255

Re: Plain rsync using rose package

Rsync and SMB/NFS should work If you add ROSE package from the "extra-packages". And ROSE can access file an SD card for either "sharing" or plain rsync. SCP should work without ROSE since a native feature. Although SCP would use RouterOS credentials, not ROSE things. But... ther...
by Amm0
Thu Sep 12, 2024 3:51 am
Forum: Scripting
Topic: Scripting using /system telnet
Replies: 4
Views: 375

Re: Scripting using /system telnet

If the device support SSH, that could be an option (/system ssh-exec)... But there not same for telnet.
by Amm0
Wed Sep 11, 2024 10:43 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1063
Views: 187373

Re: 📣 WinBox 4 is here 📣

Not sure if anyone has mention, but with multiple winbox4 windows... they all appear as seperate icon in MacOS's launchbar. Normally multiple windows of an application, still only have one icon in the launchbar with the various window name showing in the context menu. The current "one icon per ...
by Amm0
Wed Sep 11, 2024 10:17 pm
Forum: General
Topic: Odd LTE issue
Replies: 13
Views: 753

Re: Odd LTE issue

In easy things to try... setting the mode to "IPv4" instead "auto" in the APN is worth a shot. Somehow there is an IPv6 DNS query that got responded in the sniff above... so I wonder what the mode setting is actually worth :D Yeah I saw the IPv6 in the torch ;) (that, and some L...
by Amm0
Wed Sep 11, 2024 9:35 pm
Forum: General
Topic: Odd LTE issue
Replies: 13
Views: 753

Re: Odd LTE issue

I guess tend to believe the modem is providing the funky IP address based on what's coming from the carrier... and RouterOS is just passing it along. Adding "lte" as log topic will shows how the LTE data session setup in the log, which I suspect might have some clues here. I'm not the expe...
by Amm0
Wed Sep 11, 2024 8:43 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1063
Views: 187373

Re: 📣 WinBox 4 is here 📣

The software engineer in me dreams of a more fully-featured script editing window with line numbers and maybe even syntax highlighting :) Or, perhaps just even mouse navigation support in the existing Terminal window... i.e. click/scroll in the terminal window when the CLI "edit" is shown...
by Amm0
Wed Sep 11, 2024 4:55 am
Forum: General
Topic: Suggestion to MikroTik - market verticals
Replies: 14
Views: 773

Re: Suggestion to MikroTik - market verticals

Tend to agree with @StubArea51 and others. But where I'd agree with OP is the area of "policy". It's often not granular/flexible enough to deal with some kinds of deployment (i.e. where you might have some "customer" account as well as the "admin" one). And while "...
by Amm0
Wed Sep 11, 2024 3:49 am
Forum: The Dude
Topic: Alert with the Dude
Replies: 1
Views: 425

Re: Alert with the Dude

There are notifications in Dude that function like alerts: https://wiki.mikrotik.com/wiki/Manual:The_Dude_v6/Notifications (it's a two-step process... once to setup the notification mechanism/parameters, and another to apply that notification type to probe/device). Three way to do this: - You can us...
by Amm0
Tue Sep 10, 2024 6:36 pm
Forum: General
Topic: Odd LTE issue
Replies: 13
Views: 753

Re: Odd LTE issue

Not to go back to basics here... but I notice "EE" as the carrier. Is the APN set correctly? AFAIK, EE uses some funky scheme to configure the APN. See https://forum.mikrotik.com/viewtopic.php?p=747903&hilit=eesecure#p747903 (and make sure "Use Network APN" is unchecked when ...
by Amm0
Tue Sep 10, 2024 8:11 am
Forum: Scripting
Topic: The start parameter of the :find function
Replies: 6
Views: 388

Re: The start parameter of the :find function

IMO it's really the docs could be clearer. The example shows a -1, so they give you the clue at least...clarity be better. In formal sense, the <start> is exclusive of itself, so it mean "search- after -this-index" or "start-after=-1:... and next number after -1 is 0, which is the sta...
by Amm0
Tue Sep 10, 2024 5:16 am
Forum: RouterBOARD hardware
Topic: LtAP mini external antenna ....querie !
Replies: 9
Views: 2709

Re: LtAP mini external antenna ....querie !

To come back to your discussion: The ltap mini needs 2 cable to the antenne for better performance ? Thamks J. Almost certainly* an external antenna would help. Mikrotik does sell the parts, see https://cdn.mikrotik.com/web-assets/product_files/guide_wapr_180135.pdf (while show wAP, LtAP mini have ...
by Amm0
Tue Sep 10, 2024 4:37 am
Forum: Scripting
Topic: /tool fetch vs. :tool fetch and /ping vs. :ping
Replies: 5
Views: 332

Re: /tool fetch vs. :tool fetch and /ping vs. :ping

It's style. Internally, they function the same (at the top level, that is). To test that, /console/inspect allow scripting access to the stuff like CLI completion... so you can see both : and / result in the same number of options (and using / instead of : work same too). :put [:len [/console/inspec...
by Amm0
Tue Sep 10, 2024 2:13 am
Forum: General
Topic: RouterOS CHR limits bandwidth to ~400Mbit....
Replies: 25
Views: 1111

Re: RouterOS CHR limits bandwidth to ~400Mbit....

Or just spin a CHR on the same prox host without any config just with BTest server, can't see a reason why it can take more than 2 minutes to do so True. But guess all path will still show half. I'll bet that CHR is using E1000 emulated network card, since AFAIK that's the default for a new VM. I h...
by Amm0
Tue Sep 10, 2024 1:49 am
Forum: General
Topic: RouterOS CHR limits bandwidth to ~400Mbit....
Replies: 25
Views: 1111

Re: RouterOS CHR limits bandwidth to ~400Mbit....

Unfortunately RouterOS does not allow me to run a speedtest and the proprietary "Bandwidth Test" is pretty annoying because I'd need another instance somewhere which for one I do not have and also does not give me same results as just the speedtest CLI test. Another forum member runs as p...
by Amm0
Tue Sep 10, 2024 1:28 am
Forum: General
Topic: CCR2004 as ZeroTier VPN concentrator
Replies: 5
Views: 344

Re: CCR2004 as ZeroTier VPN concentrator

I 100% agree with @larsa. Although have not specifically tried a CCR2004...but most of performance comes from the switch chip, not the CPU. And CPU is needed for ZT, or even WG AFAIK. As @larsa importantly notes RouterOS is both older version and lacks the full range of configuration options, that l...
by Amm0
Mon Sep 09, 2024 11:50 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1063
Views: 187373

Re: 📣 WinBox 4 is here 📣

A combo of windows that used to be tabs can now be seen at same time . Very powerful if used with workspaces. You need to get past the initial jarring effect of change first. Then all will become clearer. Going back to old ways is not the way forward. +1, agree. They just don't go far enough... sin...
by Amm0
Mon Sep 09, 2024 10:11 pm
Forum: Scripting
Topic: The start parameter of the :find function
Replies: 6
Views: 388

Re: The start parameter of the :find function

Is this designed to be like this? Yes. RouterOS uses 0-based indexes for variables/array/string, so -1 is before the first is logical. But... totally agree the docs are vague on find's parameters. Especially since params are different if "find" is an operator on a command (instead of a va...
by Amm0
Mon Sep 09, 2024 7:21 pm
Forum: General
Topic: www-ssl secure?
Replies: 5
Views: 399

Re: www-ssl secure?

@mkx my main point was the password storage is likely a better issue (assuming one is using "www-ssl" and not "www"). The example shows credentials stored inside the script, which I think is bad practice... For Linux .netrc is good suggestion. But I think OP is using Windows Powe...
by Amm0
Mon Sep 09, 2024 5:53 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1063
Views: 187373

Re: 📣 WinBox 4 is here 📣

Few more minor issues: - On first login screen, the "Neighbors" has checkboxes next to them but they do nothing. i.e. if one is checked, it does NOT become the "Connect to". And allows multiple ones to be selected, but again no actions other than a checkmark showing in UI. - In I...
by Amm0
Mon Sep 09, 2024 12:22 am
Forum: General
Topic: www-ssl secure?
Replies: 5
Views: 399

Re: www-ssl secure?

... it seems you're using www-ssl, so this shouldn't be an issue. Agree that best you can do. Password should be encrypted (at least to key size of certificate used for it) But I'd add it's important to consider the calling script has the username/password stored in it... so the script file should ...
by Amm0
Mon Sep 09, 2024 12:02 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1063
Views: 187373

Re: 📣 WinBox 4 is here 📣

I actually like the "single EXE" approach for winbox since in a lot of case that's often "less friction" than dealing with any package manager. So Mikrotik initial approach makes sense to me, especially for a management tool, in beta... That be said, I just also like some standar...
by Amm0
Sat Sep 07, 2024 9:10 pm
Forum: The Dude
Topic: Tracking and Visualizing Device Uptime and Downtime in MikroTik Dude
Replies: 2
Views: 988

Re: Tracking and Visualizing Device Uptime and Downtime in MikroTik Dude

Not sure if we can generate reports in any way using Dude or via ROS API . You struck one of the biggest limitation in Dude. While the Dude excels at being able to track things, esp RouterOS devices since it can use the binary winbox protocol (which likely more efficient than SNMP). Getting data ou...
by Amm0
Sat Sep 07, 2024 8:13 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1063
Views: 187373

Re: 📣 WinBox 4 is here 📣

Along those lines... I'd add a request for "branding kit support", to say apply a custom logo (or remove any logo) inside winbox4 once logged into a router?
by Amm0
Sat Sep 07, 2024 8:09 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1063
Views: 187373

Re: 📣 WinBox 4 is here 📣

Suggestions: - make the state files (settings, addresses, workspaces) human-readable e.g. by using JSON or XML format instead of binary - make the location of workspace files configurable, including having files sent to the managed router itself (as a file in the flash) +1, especially "as a fi...
by Amm0
Sat Sep 07, 2024 7:55 pm
Forum: Beginner Basics
Topic: Add alternate route
Replies: 6
Views: 620

Re: Add alternate route

I just noticed router1 and router2 are the same room... https://i.ibb.co/QvtD7FP/Network-2.jpg But the same approach would work to keep pure Layer3 static routing, just without GRE between Router1 and Router2 Router1 /interface/gre add name=gre2 local-address=<local-wanip> remote-address=<router2-wa...
by Amm0
Sat Sep 07, 2024 6:52 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1063
Views: 187373

Re: 📣 WinBox 4 is here 📣

> Linux distribution users wish for better distribution methods (unclear, many say current way is OK!) [...] Having it on Flathub would definitely simplify things - you could even link the Qt libraries dynamically, to reduce update size but that's not as important. There are a lot of Linux distro m...
by Amm0
Sat Sep 07, 2024 6:11 am
Forum: Beginner Basics
Topic: Add alternate route
Replies: 6
Views: 620

Re: Add intermediate route

I have done the above, What i am asking is, can i add alternate route, so that if one of the two GRE Tunnel is down due to internet down because of ISP then i can reach 2nd router through 1st router from 3rd Router I have edited the image so people can understand my question easily It actually the ...
by Amm0
Sat Sep 07, 2024 4:54 am
Forum: Useful user articles
Topic: WinBox for MacOS ??
Replies: 48
Views: 21062

Re: WinBox for MacOS ??

In case anyone on this thread did not see the WinBox4 beta announcement...
📣 WinBox 4 is here 📣"

So there is now a native MacOS WinBox. Still no native MacOS netinstall-cli or btest.exe however...
by Amm0
Fri Sep 06, 2024 10:50 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1063
Views: 187373

Re: 📣 WinBox 4 is here 📣

Very minor. . But in LTE firmware upgrade/check sections, the error message appears at bottom. And, the "Starting" part is not cleared upon an error. Screenshot 2024-09-06 at 11.30.13 AM.png It seems the new style error/status just below the status (which I like), but the LTE does not fol...
by Amm0
Fri Sep 06, 2024 10:18 pm
Forum: General
Topic: tool fetch xml [SOLVED]
Replies: 6
Views: 485

Re: tool fetch xml [SOLVED]

Since `curl` defaults to GET, and that works... my guess is some escaping issue in the URL - as OP show just "<some command string>" ...while the URL itself shouldn't require any escaping as shown... depending what in the ?query params part, that may need escaping. So I'd try putting quote...
by Amm0
Fri Sep 06, 2024 8:24 pm
Forum: General
Topic: Convert script to create in terminal
Replies: 4
Views: 355

Re: Convert script to create in terminal

The escaping does get tricky.

You can also use "/system/script export where name=XXXX" to get the "escaped form" of any script (and then cut-and-paste that as needed).
by Amm0
Fri Sep 06, 2024 5:46 pm
Forum: General
Topic: Odd LTE issue
Replies: 13
Views: 753

Re: Odd LTE issue

From where, remotely, or via the LAN/Wi-Fi? By default, ether1 accepts internet via DHCP, so it is NOT a LAN port. Only ether2 will give you LAN address. If it's remote, well, it depends on your LTE carrier/plan. A lot of cell carriers don't allow incoming ports (CGNAT)... so if your trying to get t...
by Amm0
Fri Sep 06, 2024 4:39 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1063
Views: 187373

Re: 📣 WinBox 4 is here 📣

Noticed when connecting to a wAPRac running 7.14.3, from a MacOS 14.6.1 (X86), the ZeroTier icon appears same as Wireguard icon. Other systems seems to correctly show blue-styled ZT logo. This has happened on beta3 and beta4. Screenshot 2024-09-06 at 6.11.21 AM.png Also, in Beta4 resizing the window...
by Amm0
Fri Sep 06, 2024 3:03 am
Forum: General
Topic: VRRP on Hyper-V instance ROS 7.15.3 not working (MAC Spoofing enabled)
Replies: 11
Views: 1185

Re: VRRP on Hyper-V instance ROS 7.15.3 not working (MAC Spoofing enabled)

Answering own question: 1. Set bridge port passed-though off vswitch frame types to admit tagged-only 2. Set bridge frame types to admit all, set PVID to the desired VLAN for VRRP packets 3. In bridge/vlans add desired VLAN to list, add bridge as untagged, port as tagged Perhaps post at least some ...
by Amm0
Fri Sep 06, 2024 2:42 am
Forum: Announcements
Topic: Updated btest.exe available for download
Replies: 21
Views: 63836

Re: Updated btest.exe available for download

UDP figures are pretty wrong in this application. You may need to lower the 2 Local/Remote UDP Tx packet size... If MTU is not 1500 along the whole, it will fragment packets which gets you a slower test result for UDP. Now the better question is when there will be an updated "btest.exe" f...
by Amm0
Fri Sep 06, 2024 2:35 am
Forum: Beginner Basics
Topic: LTE DYNAMIC PUBBLIC ADDRESS
Replies: 4
Views: 423

Re: LTE DYNAMIC PUBBLIC ADDRESS

You'd need to enable DDNS in /ip/cloud on the LTE device, then use that DNS name (snXXXX.mynetname.net) in the Dude device configuration. In Dude device, there is setting to say use DNS for IP, instead of IP that needs to be also be set in addition to the DNS name.
by Amm0
Thu Sep 05, 2024 10:41 pm
Forum: General
Topic: DHCP is offered but not bound to Brother printers only [SOLVED]
Replies: 36
Views: 1851

Re: DHCP is offered but not bound to Brother printers only [SOLVED]

It might be worth it (or at least simple) to try 7.16rc, as there were DHCP fixes in the release notes.

Cannot say your problem is what's fixed, but if it does then it's a bug in 7.15.3. If not, then running the sniffer might help figure out what/if anything the printer is sending.
by Amm0
Thu Sep 05, 2024 9:17 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1063
Views: 187373

Re: 📣 WinBox 4 is here 📣

Just don't be too harsh on us yet, first, let's celebrate that it's finally the day! I'm sure it was an enormous effort to get it this good for a beta. It did come out great for an early beta! While, I've not been a fan of this multiyear effort, because it is the Dude that needs a refresh... Now, I...
by Amm0
Wed Sep 04, 2024 7:27 pm
Forum: General
Topic: new-mss VS. clamp-to-pmtu with v7
Replies: 10
Views: 1189

Re: new-mss VS. clamp-to-pmtu with v7

Thanks @Amm0, your responses are always so clear and full of great information! This article has a lot of good info WG recommendations from ProCustodibus, specifically on MSS clamping: https://www.procustodibus.com/blog/2022/12/wireguard-performance-tuning/#mss-clamping They recommend the follow &q...
by Amm0
Wed Sep 04, 2024 6:23 am
Forum: General
Topic: new-mss VS. clamp-to-pmtu with v7
Replies: 10
Views: 1189

Re: new-mss VS. clamp-to-pmtu with v7

This all assumes the WAN used by WG on BOTH sides is 1500 MTU. It "most of the time" is 1500, so WG's 1420 MTU is right. But... for example, some PPPoE deployments might uses 1492 as MTU - which mean WG should be lower by 8 bytes.... This then effects the "manual" way of specify ...
by Amm0
Tue Aug 27, 2024 11:36 pm
Forum: Wireless Networking
Topic: wAP R - LTE interface fails at PIN "searching" state - v6 and v7
Replies: 1
Views: 291

Re: wAP R - LTE interface fails at PIN "searching" state - v6 and v7

I'd make sure the RouterBOOT matches the version you're using, that's in /system/routerboard. AFAIK, netinstall does not upgrade the bootloader.
by Amm0
Tue Aug 27, 2024 6:04 am
Forum: Forwarding Protocols
Topic: IP Directed Broadcast In CISCO Equivalent In Mikrotik
Replies: 12
Views: 1764

Re: IP Directed Broadcast In CISCO Equivalent In Mikrotik

I'm not sure there is an "equivalent". While the Linux kernel has "bc_forwarding" sysctl that is the linux version of cisco's "ip directed-broadcast". But... RouterOS does not directly expose the sysctl, and I'd imagine it's disabled by default per RFC2644 inside Router...
by Amm0
Thu Aug 22, 2024 8:22 pm
Forum: Beginner Basics
Topic: LTE Passthrough & UDR
Replies: 2
Views: 748

Re: LTE Passthrough & UDR

I think on most Ubiquity stuff it might be easier to do it reverse. e.g. use vlan10 as the passthrough interface & leaving the untagged ether1 + dhcp-client AFIAK, UBNT stuff uses hybrid ports by default with untagged being management. And, I think, it might be easier to configure the WAN from a...
by Amm0
Thu Aug 22, 2024 5:37 pm
Forum: General
Topic: Feature request : Multipath TCP (MPTCP) support
Replies: 14
Views: 9987

Re: Feature request : Multipath TCP (MPTCP) support

@Larsa what folks are talking about is using MPTCP for "multi-wan" support. So the way I view the request is that MPTCP can be used a tunnel interface between two RouterOS using multiple/different paths. e.g. you had Mikrotik with two LTE modems, that connected to CHR at some VPS, with MPT...
by Amm0
Thu Aug 22, 2024 4:15 pm
Forum: General
Topic: new-mss VS. clamp-to-pmtu with v7
Replies: 10
Views: 1189

Re: new-mss VS. clamp-to-pmtu with v7

@mrz can correct me... But "clamp-to-pmtu" on a local interface should get you the RourerOS interface's MTU less TCP's 40 bytes. So for WG with 1420 MTU, setting new-mss to "clamp-to-pmtu", should result in a 1380. So explicitly setting new-mss=1380 should be same as new-mss=clam...
by Amm0
Wed Aug 21, 2024 7:40 pm
Forum: Useful user articles
Topic: mDNS between VLANs with just bridge filters - Look Mum, no containers!
Replies: 69
Views: 22132

Re: mDNS between VLANs with just bridge filters - Look Mum, no containers!

mDNS and SSDP are working good but HDHomeRun isn't working, i also try mdns repeater from beta, but if i disable this method nothing works in mDNS Thanks I don't have a HDHomerun but it looks like it broadcasts as opposed to multicasts on UDP:65001. IP broadcasts are NOT same as multicast. And HDHo...
by Amm0
Tue Aug 20, 2024 8:22 am
Forum: General
Topic: Occasional FIN or RST packet showing up on WAN from my private subnets
Replies: 9
Views: 741

Re: Occasional FIN or RST packet showing up on WAN from my private subnets

Hard to know what the cause of the escape. One thing you can try is to drop invalid connections on OUTPUT. /ip/firewall/filter/add chain=output connection-state=invalid action=drop log=yes out-interface-list=WAN While the default firewall drops invalid on input if something goes awry during the TCP ...
by Amm0
Mon Aug 19, 2024 6:31 pm
Forum: Virtualization
Topic: BTH vpn
Replies: 3
Views: 515

Re: BTH vpn

If one side has a public IP, you can use normal WG. If you need to hole-punching proxy of BTH (i.e. both sides have some non-public/CGNAT-like WAN addresses), you use the BTH client config shown from /ip/cloud to create manually create a peer on remote router using the details from BTH client config...
by Amm0
Mon Aug 19, 2024 6:16 pm
Forum: General
Topic: Wireguard in 2nd WAN [SOLVED]
Replies: 34
Views: 2633

Re: Wireguard in 2nd WAN [SOLVED]

NAT trick is cleaver. But because there’s a bug in ROS, Peer B sends the "hello back" from a different address than the one it received the first "hello" from, which confuses Peer A. [...] To make it work, you have to use some workarounds to ensure that the "hello back"...
by Amm0
Fri Aug 16, 2024 7:07 pm
Forum: General
Topic: VRRP - NewBie
Replies: 9
Views: 965

Re: VRRP - NewBie

If you had some monitoring, you can see if there is some meaningful effect on memory from increasing the ARP cache - but I suspect not. In thinking about this... Perhaps the double ARPs are due to the /ip/dhcp-server. i.e. the DHCP servers for your VLANs are listening on the VLAN interfaces, so one ...
by Amm0
Thu Aug 15, 2024 10:55 pm
Forum: Wireless Networking
Topic: Missing wAP ax successor to wAP ac, what are outdoor AX WiFi alternatives?
Replies: 29
Views: 2894

Re: Missing wAP ax successor to wAP ac, what are outdoor AX WiFi alternatives?

wAP ax will be a very small device and is coming very very soon (question of days or weeks)
with an M.2 (or miniPCIe) slot (aka the ax version of wAPacR)?
by Amm0
Thu Aug 15, 2024 6:30 pm
Forum: RouterBOARD hardware
Topic: NetMetal ax / L23-UGSR — initial feedback from specs
Replies: 38
Views: 5447

Re: NetMetal ax / L23-UGSR — initial feedback from specs

FWIW the Sierra MC7455 allow you set the USB speed to USB 2.0 speeds, via AT command. Yep I was going to try this, the strange thing is that my netmetal goes into constant reboot loop when the MC7455 is installed, not being able to initialize the modem is ok, but reboot.... Well you have to send th...
by Amm0
Thu Aug 15, 2024 4:54 pm
Forum: General
Topic: SNMP Sending Wrong
Replies: 2
Views: 471

Re: SNMP Sending Wrong

The ifIndex should in an integer and description is a string – that part is right. What's confusing is that an interface SNMP ifIndex is the ".id" field in the config – NOT the "port number". You can see this if you use: /interface/print oid show-ids ... *B2 name=.1.3.6.1.2.1.2.2...
by Amm0
Thu Aug 15, 2024 1:08 am
Forum: RouterBOARD hardware
Topic: NetMetal ax / L23-UGSR — initial feedback from specs
Replies: 38
Views: 5447

Re: NetMetal ax / L23-UGSR — initial feedback from specs

I have MC7455 which doesn't work with NetMetal AX (i didn't try to "isolate" USB3.0 pins, but I'm sure it will work that way), but it's working without issue with RB33G/LtAP :) Standards, right? :-D FWIW the Sierra MC7455 allow you set the USB speed to USB 2.0 speeds, via AT command. See ...
by Amm0
Tue Aug 13, 2024 8:49 pm
Forum: General
Topic: ECMP recursive routes
Replies: 34
Views: 3675

Re: ECMP recursive routes

Going back to the OP's original config... I'm not sure what ECMP to the same gateway is trying to do. If the goal trying to use recursive route with ECMP to create a "OR" on the canary address (e.g. keep WAN active if EITHER of the canary address are up), the config is not going to do that...
by Amm0
Tue Aug 13, 2024 5:51 pm
Forum: Beginner Basics
Topic: Reach LAN from Zerotier with own controller
Replies: 9
Views: 619

Re: Reach LAN from Zerotier with own controller

Well, the /zerotier/controller is marked as "I" INVALID, so that a first level problem here. You have /zerotier/controller/print detail Flags: X - disabled, I - inactive 0 I disabled=no instance=zt1 name="ZTCP1" network="914..." private=yes broadcast=yes mtu=2800 multic...
by Amm0
Sun Aug 11, 2024 8:16 pm
Forum: General
Topic: ECMP recursive routes
Replies: 34
Views: 3675

Re: ECMP recursive routes

I do not dare to speculate as for CPU cycles spent per packet with and without ECMP using the same WAN. Agreed. JustIn the pantheon of worries, ECMP's CPU usage would not be the top of that list. To be honest, it's the using DNS servers as the canary address be my bigger worry. Unless the servers a...
by Amm0
Sun Aug 11, 2024 6:21 pm
Forum: General
Topic: ECMP recursive routes
Replies: 34
Views: 3675

Re: ECMP recursive routes

e.g. the first route lookup for a Internet address (0.0.0.0/0) get some canary address, and the 2nd route lookup of that canary is a "more specific route" (i.e. a /32) so that since since there is no conflict Given that route print detail shows things like gateway-status=10.100.8.8 recurs...
by Amm0
Sun Aug 11, 2024 6:03 pm
Forum: General
Topic: VRRP ipv6
Replies: 4
Views: 993

Re: VRRP ipv6

a pair of Switches with Router OS 7.1.5 and 7.8, it also only works well for one LAN, for the others it does not work, But VRRP has changed (i.e. added sync-connections, grouping, etc) between 7.1.5 and 7.8. So I'm not sure mixing versions is a good idea. when I configure DHCPv6, should it be the s...
by Amm0
Sun Aug 11, 2024 5:46 pm
Forum: General
Topic: ECMP recursive routes
Replies: 34
Views: 3675

Re: ECMP recursive routes

ECMP should not add significant CPU load over failover. And it's the scope/target-scope matter for recursive routes. The distance on the default route (i.e. dst-address=0.0.0.0/0) makes it failover (different distance) or ECMP (same distance for 0.0.0.0/0 routes) - but distance does not effect how r...
by Amm0
Sun Aug 11, 2024 5:06 pm
Forum: General
Topic: VRRP - NewBie
Replies: 9
Views: 965

Re: VRRP - NewBie

I should have checked myself, but you're right it creates multiple ARP cache entries. You can certainly increase the ARP cache size, which sounds like a good idea. But even if the ARP cache gets full... it's not like things just stop working. Rather, there just more ARP requests on the network (whic...
by Amm0
Fri Aug 09, 2024 2:41 am
Forum: General
Topic: VRRP - NewBie
Replies: 9
Views: 965

Re: VRRP - NewBie

You only add one ARP address per VRRP interface. VRRP responds to any arp for the default gateway (aka vrrp address), so it just needs one fake MAC address per VLAN in this case. The number of users will increase ARP counts, but there still only one MAC per client even with VRRP. Otherwise VRRP look...
by Amm0
Thu Aug 08, 2024 4:35 pm
Forum: Scripting
Topic: Disable the prompt from the terminal. [SOLVED]
Replies: 17
Views: 2014

Re: Disable the prompt from the terminal. [SOLVED]

It might be best to understand the WHY here... I feel like you're going down a wrong track in scripting if you're needing an "@echo off". But another approach be to just add an "as-value" to end of any command you don't want output from - normally that's used to store result into...
by Amm0
Thu Aug 08, 2024 7:46 am
Forum: Beginner Basics
Topic: Back to home Desktop
Replies: 18
Views: 3337

Re: Back to home Desktop

If you have ONLY a desktop, you can go to /ip/cloud and enabled BTH on the "BTH VPN" tab. The config for the FIRST user is on the "BTH VPN WireGuard" config tab in /ip/client. So if that's NOT used by a phone app, you can cut-and-paste to standard WireGuard desktop app. If you ne...
by Amm0
Thu Aug 08, 2024 4:13 am
Forum: Wireless Networking
Topic: "spotty" starlink optimizations?
Replies: 4
Views: 586

Re: "spotty" starlink optimizations?

Tricky problem. I guess it depends on how long the outages are... Now, moving the starlink so it's obstruction free is obviously better plan, but presume you're asking since that ain't possible. I suppose you can try tweak "persistent-keepalive" lower so you're not waiting for traffic to f...
by Amm0
Wed Aug 07, 2024 8:30 pm
Forum: Useful user articles
Topic: ZeroTier on Mikrotik – a rosetta stone [v7.1.1+]
Replies: 43
Views: 37866

Re: ZeroTier on Mikrotik – a rosetta stone [v7.1.1+]

But the following is also nice to know Tailscale vs. ZeroTier: Side-by-Side Comparison I think that's article is a pretty good summary. I'd agree with most of it, specifically Tailscale is different than WireGuard in many ways, but it’s a better comparison to ZeroTier than WireGuard due to the way ...
by Amm0
Wed Aug 07, 2024 7:48 pm
Forum: Useful user articles
Topic: ZeroTier on Mikrotik – a rosetta stone [v7.1.1+]
Replies: 43
Views: 37866

Re: ZeroTier on Mikrotik – a rosetta stone [v7.1.1+]

@amm0, would it be possible to ask you a question about my relatively simple setup? If so, I would love to reach out. Thanks!
Feel free to post your needs/question(s) and any relevant config.
by Amm0
Mon Aug 05, 2024 11:34 pm
Forum: Beginner Basics
Topic: Setup foe wAP ac for control my mixer
Replies: 6
Views: 529

Re: Setup foe wAP ac for control my mixer

Mikrotik's LAN default is 192.168.88.xx address. So likely you just need to set your mixer to use 192.168.88.2 (subnet mask 255.255.255.0), and then the Mikrotik's default Wi-Fi should find the mixer.
by Amm0
Mon Aug 05, 2024 3:06 pm
Forum: General
Topic: VRRP ipv6
Replies: 4
Views: 993

Re: VRRP ipv6

Someone else recently had troubles with IPv6 and VRRP, see viewtopic.php?t=209590. So possible it's a bug.

Was this working before, or is this first time setting up VRRP with IPv6?
by Amm0
Mon Jul 29, 2024 4:07 pm
Forum: Scripting
Topic: /tool fetch problem
Replies: 2
Views: 409

Re: /tool fetch problem

A Mikrotik array is not JSON. Either use the :serialise function in newer versions of RouterOS v7, or construct a data variable containg valid JSON. For example: :local jsondata "{\"mac\":\"aa:bb:cc:dd:ee:ff\",\"ip\":\"192.168.100.80\"}" True. But t...
by Amm0
Fri Jul 26, 2024 10:18 pm
Forum: General
Topic: IPv6 VRRP Oddness
Replies: 2
Views: 501

Re: IPv6 VRRP Oddness

Seems like a bug. Or perhaps need some configuration in the switch. They do keep adding things for L3HW offloading...so easy to imagine something like VRRP with IPv6 breaking.
by Amm0
Fri Jul 26, 2024 9:55 pm
Forum: Scripting
Topic: [BUG] REST endpoint producing invalid JSON
Replies: 3
Views: 645

Re: [BUG] REST endpoint producing invalid JSON

I too recommend file at help.mikrotik.com. The RFC for JSON requires UTF-8 formatting, so in that sense it's a bug. And it is kinda double-whammy since you can't use `jq` /etc. to fix the strings, since it's fails on parsing... before you could even call jq expressions. But the underlying issue, des...
by Amm0
Fri Jul 26, 2024 12:51 am
Forum: General
Topic: No RoMON Help Please
Replies: 7
Views: 1075

Re: No RoMON Help Please

https://help.mikrotik.com - create request, and one of the choices is "feature request".
by Amm0
Tue Jul 23, 2024 9:44 pm
Forum: RouterBOARD hardware
Topic: L009UiGS-2HaxD-IN vs. RBM33G Performance results [SOLVED]
Replies: 11
Views: 3368

Re: L009UiGS-2HaxD-IN vs. RBM33G Performance results [SOLVED]

Since you mention USB, the L0009 be the winner since it has USB 3.0. While RBM33G is USB 2.0. I'd go with the L009 just on the fact plus @normis's point the L009 has been more heavily tested with V7. Whether L009 or RMB33G is better/worse is likely pretty close and depend on the exact configuration....
by Amm0
Tue Jul 23, 2024 9:24 pm
Forum: RouterBOARD hardware
Topic: RBM33G + 5G
Replies: 65
Views: 19869

Re: RBM33G + 5G

In general, if you're trying a new modem on V7, if it supports MBIM you want to use that. Now sometimes mode=serial might be needed to access /system/serial-terminal to enter some AT command (which vary by modem for stuff like switching modes etc) - for example on Quectel the MBIM AT commands. But i...
by Amm0
Tue Jul 23, 2024 9:46 am
Forum: General
Topic: No RoMON Help Please
Replies: 7
Views: 1075

Re: No RoMON Help Please

Worth a feature request ticket. But... I'm not even sure RoMON is possible under Apple iOS. The iOS SDK deals with URL fetching or opening TCP/UDP sockets.. so Layer2 RoMON with it's non-IP ether-type likely poses a problem since iOS doesn't just allow raw Layer2 access to the network interface - ev...
by Amm0
Mon Jul 22, 2024 7:27 pm
Forum: Scripting
Topic: dos2unix script
Replies: 4
Views: 409

Re: dos2unix script

I have the latest RoS In the most recent V7 releases there are ":tocrlf" and ":tolf" commands available that do same as "dos2unix" (and reverse unix2dos). There is also now :convert, so we can see the effect those new commands do in hex (e.g. 0a == \n, 0d == \r): :put ...
by Amm0
Mon Jul 22, 2024 5:57 am
Forum: RouterBOARD hardware
Topic: Mikrotik hAP ax2 onboard USB 3.0 pads
Replies: 16
Views: 10493

Re: Mikrotik hAP ax2 onboard USB 3.0 pads

One thing to consider since this thread was started, is there is now the L23 routerboards: https://mikrotik.com/product/l23ugsr_5haxd2haxd#fndtn-downloads Now it is not USB 3.0 nor built in antennas, and you'd need a case... but does have same AX drivers without soldering or mucking with bootloader....
by Amm0
Fri Jul 19, 2024 7:06 pm
Forum: Beginner Basics
Topic: Simpler Failover for two Gateways I found working
Replies: 17
Views: 5175

Re: Simpler Failover for two Gateways I found working

I think @cyayon is right that that using the newer "src-address" in netwatch SHOULD work. But you'd need to know the src-address to set, which means having a static IP... so that kinda limits the approach while mangle it just setting routing table, which could have a interface route withou...
by Amm0
Fri Jul 19, 2024 6:51 pm
Forum: Beginner Basics
Topic: I'm just ready to tear my hair out...
Replies: 21
Views: 1308

Re: I'm just ready to tear my hair out...

It isn't meant to be intuitive. It's meant to be powerful. And I appreciate that power very much, and also the fact that these guys are affordable gigabit routers. But, they also offer the "quick" wizard - you'd think that a simple naked, absolutely minimal access point would be one of th...
by Amm0
Mon Jul 15, 2024 8:52 pm
Forum: Scripting
Topic: Feature Request: native JSON parsing function [SOLVED]
Replies: 4
Views: 2603

Re: Feature Request: native JSON parsing function [SOLVED]

I have an example of using :serialize/:deserialize with /tool/fetch for the pushover app's JSON API here:
viewtopic.php?t=136256#p1083224
The approach work for most JSON API with a change of the URL used inside the function and different array of data provided.
by Amm0
Mon Jul 15, 2024 8:33 pm
Forum: RouterBOARD hardware
Topic: RBM33G + 5G
Replies: 65
Views: 19869

Re: RBM33G + 5G

That Intel/Fibocom L860-GL16 modem seems like a PITA in a quick google. In theory, it should work since it is MBIM. It be an LTE interface since it's MBIM, not a ppp-client (although in theory that could work but even more complex If that's not working, one thing to try is to force RouterOS into MBI...
by Amm0
Sat Jul 13, 2024 9:42 pm
Forum: Scripting
Topic: PUSHOVER - ready MikroTik script to send messages
Replies: 23
Views: 12293

Re: PUSHOVER - ready MikroTik script to send messages

It's not the multi-line output per se. It the data type returned by "monitor" is a RouterOS array type. And one rule (which I forgot in my quick example of LTE monitor) is array cannot be interpolated, so a ":tostr" is needed. This will get rather ugly output, but should work: $n...
by Amm0
Fri Jul 12, 2024 11:59 pm
Forum: General
Topic: Traefik Reverse proxy
Replies: 6
Views: 630

Re: Traefik Reverse proxy

Good to hear. EDIT 2: It seems to benow working i added in interface list WAN and now its works, probably got looped somewhere? Thanks a lot. Yeah any proxy in a container get confusing in the firewall since you generally want all traffic inbound going to proxy, and outbound out of proxy going somep...
by Amm0
Fri Jul 12, 2024 11:47 pm
Forum: Scripting
Topic: Feature Request: native Base64 decoder function [SOLVED]
Replies: 2
Views: 2208

Re: Feature Request: native Base64 decoder function [SOLVED]

You should check out the new ":convert" operator in V7. For example, to get base64 string from the alphabet: :put [:convert from=raw to=base64 "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"] QUJDREVGR0hJSktMTU5PUFFSU1RVVldYWVphYmNkZWZnaGlqa2xtbm9wcXJzdHV2d3h5e...
by Amm0
Fri Jul 12, 2024 11:14 pm
Forum: RouterBOARD hardware
Topic: RBM33G + 5G
Replies: 65
Views: 19869

Re: RBM33G + 5G

I'm not the expert on the M.2 adapters since that add another dimension of complexity with third-party modem. i.e. The M.2 KeyB adapters are not all the same, so how the SIM/USB lines are wired (and/or DIP/etc switch on the adapter) may effect how SIM card is routed... so might want to look at any d...
by Amm0
Fri Jul 12, 2024 8:19 pm
Forum: Scripting
Topic: SLA based PBR
Replies: 3
Views: 932

Re: SLA based PBR

You mention several different topics. Some quick thoughts: 1. /tool/netwatch with icmp monitors can monitor latency/RTT, and a script can modify PBRs to steer new connection over different route. You can use interval/count to spread the test over a long period so the netwatch calculation isn't based...
by Amm0
Fri Jul 12, 2024 7:10 pm
Forum: General
Topic: Traefik Reverse proxy
Replies: 6
Views: 630

Re: Traefik Reverse proxy

Here are the rules I use (adapted for your proxy IP), which ignore the traefik container's IP from the dst-nat rules (otherwise the proxy with go back through the proxy because of NAT): /ip/firewall/nat add action=dst-nat chain=dstnat comment=traefik-proxy dst-port=8080 protocol=tcp src-address=!10....
by Amm0
Fri Jul 12, 2024 5:54 pm
Forum: General
Topic: Traefik Reverse proxy
Replies: 6
Views: 630

Re: Traefik Reverse proxy

You may have exclude the Traefik proxy IP itself from the rule. Otherwise you can end up with a loop with Traefik getting redirected to itself by the firewall rules.
by Amm0
Tue Jul 09, 2024 11:39 pm
Forum: General
Topic: vrrp configuration with fully redundant switches
Replies: 15
Views: 1076

Re: vrrp configuration with fully redundant switches

I'm confused at what you're trying to do. But a couple tips are: - Setting a "group-authority" can link VRRP interface into a "failure group", so if one falls over the rest do too. See docs, https://help.mikrotik.com/docs/display/ROS/VRRP#VRRP-Parameters - I'd use VRRP on a MLAG,...
by Amm0
Tue Jul 09, 2024 10:40 pm
Forum: Scripting
Topic: PUSHOVER - ready MikroTik script to send messages
Replies: 23
Views: 12293

Re: PUSHOVER - ready MikroTik script to send messages

Thank you for this. Either version of the code $[interface/lte/monitor lte1 once] doesn't add data/content at all to the message (not even the code is included). It this the correct way to pull MikroTik data into the message that is sent? The received message is as attached (sorry can't seem to att...
by Amm0
Tue Jul 09, 2024 4:02 am
Forum: Scripting
Topic: PUSHOVER - ready MikroTik script to send messages
Replies: 23
Views: 12293

Re: PUSHOVER - ready MikroTik script to send messages

:global npushover $npushover ({ user="private" token="private" message="Mikrotik SXT Rebooted <b>nPushover</b> $[interface/lte/monitor lte1 duration=2]" title="MikroTik SXTR" html=1 sound="magic" priority=0 url="https://192.168.x.1" "...
by Amm0
Thu Jul 04, 2024 12:04 pm
Forum: General
Topic: Adding veth slows internet
Replies: 30
Views: 2805

Re: Adding veth slows internet

Try /24 as the veth IP address. It’s currently just /32.
by Amm0
Thu Jul 04, 2024 12:35 am
Forum: Useful user articles
Topic: mDNS between VLANs with just bridge filters - Look Mum, no containers!
Replies: 69
Views: 22132

Re: mDNS between VLANs with just bridge filters - Look Mum, no containers!

At present it seems bi-directional between all /ip/dns mDNS interfaces. So you can essentially create one mDNS zone for all specified interfaces. See https://forum.mikrotik.com/viewtopic.php?t=208937&sid=84e0a0d1a322c029710d1d6cd1da7eef So if you want to get fine grained in what's allowed or not...
by Amm0
Wed Jul 03, 2024 10:21 pm
Forum: General
Topic: RoS 7.16 beta3 mDNS
Replies: 7
Views: 1498

Re: RoS 7.16 beta3 mDNS

Correct, in my test case. There RB1100AHx4 that hangs on my LAN that I use for mainly for testing beta/devices from work. I have one EoIP link on that RB1100 that is a /interface/bridge/port on BOTH sides - it bridges my folk's remote LAN bridge (from a cAPac that acts as both the AP and router, wit...
by Amm0
Wed Jul 03, 2024 8:01 pm
Forum: General
Topic: RoS 7.16 beta3 mDNS
Replies: 7
Views: 1498

Re: RoS 7.16 beta3 mDNS

In fairness, I did one test of this... between a remote EoIP to my folk house. If enable this 7.16 mDNS repeat in /ip/dns, I can see and control a Roku TV at least. So we'll have to wait for Mikrotik to say more on what it should do... All I can see is what a 15 minute tested showed ;). The remote E...
by Amm0
Wed Jul 03, 2024 7:19 pm
Forum: General
Topic: RoS 7.16 beta3 mDNS
Replies: 7
Views: 1498

Re: RoS 7.16 beta3 mDNS

AFAIK, it looks like RouterOS just copies the mDNS UDP packets between the selected interface. It's roughly same approach as https://forum.mikrotik.com/viewtopic.php?t=204025&hilit=mdns. Just implemented at a low-level. Basically RouterOS will look for mDNS if configured in /ip/dns, then re-broa...
by Amm0
Wed Jul 03, 2024 5:55 pm
Forum: Beginner Basics
Topic: VRRP bridge in MikroTik
Replies: 11
Views: 1086

Re: VRRP bridge in MikroTik

VRRP config be roughly the same across all versions, so it isn't the issue here. But I guess my first advice be to update to version 7.15.2 if the routers are newish (/system/package). Or even if older router, if only for testing, you'd be better off to start with V7. All the docs and bugs focus on ...
by Amm0
Wed Jul 03, 2024 10:35 am
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 117057

Re: v7.16beta [testing] is released!

Fair enough. Since I use ECMP, this a great. More that you might get more testers if they knew what to test. ;) Load balancing is always a topic. The practical effect of new "/ip/settings/set ipv4-multipath-hash-policy=l4" means there is no downside to using ECMP/routing approach over PCC/...
by Amm0
Wed Jul 03, 2024 8:52 am
Forum: Beginner Basics
Topic: VRRP bridge in MikroTik
Replies: 11
Views: 1086

Re: VRRP bridge in MikroTik

Was this working before you tried VRRP? One thing I noticed is each router needs BOTH VRRP interface and address. In the config, you should just one. But using Bridge VLAN filtering (or switch chip for vlans if older) is likely better plan here. The criss-crossing VLANs just add unneeded complexity....
by Amm0
Wed Jul 03, 2024 3:57 am
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 117057

Re: v7.16beta [testing] is released!

If you gave a little more detail on new things, people might try them. i.e. *) ip/ipv6 - added multipath hash policy settings; /ip/settings/set ipv4-multipath-hash-policy=<tab> l3 l3-inner l4 Does "l4" mean ports/protocols? Does it work with static ECMP routes, or only some/all routing pro...
by Amm0
Tue Jul 02, 2024 7:22 pm
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 117057

Re: v7.16beta [testing] is released!

*) dns - added support for DoH with static FWD entries; *) dns - added support for mDNS proxy (CLI only); So does the firewall rule need to allow 5353udp on the forward chain or the input chain? AFAIK, repeated mDNS via input (or output) chain (NOT forward) since it's a local process in Packet Flow...
by Amm0
Tue Jul 02, 2024 5:28 pm
Forum: Beginner Basics
Topic: VRRP bridge in MikroTik
Replies: 11
Views: 1086

Re: VRRP bridge in MikroTik

The VRRP interface should not listen on ether2, rather it should listen on vlan10-ether2.
by Amm0
Tue Jul 02, 2024 5:10 pm
Forum: General
Topic: RoS 7.16 beta3 mDNS
Replies: 7
Views: 1498

Re: RoS 7.16 beta3 mDNS

I've done a couple test and seems to work. But since mDNS just provides an IP address, one way it can go wrong is if the firewall blocks the resulting connection. On Mac (and some Linux and Windows with Bonjour installed), you can use: dns-sd -B _ipp._tcp to see any mDNS records for printers (IPP), ...
by Amm0
Tue Jul 02, 2024 2:37 am
Forum: Beginner Basics
Topic: VRRP bridge in MikroTik
Replies: 11
Views: 1086

Re: VRRP bridge in MikroTik

Perhaps post the config you're trying. The VRRP part is pretty simple: - Each VLAN needs a VRRP interface, with the VLAN interface being selected (note NOT the bridge). - Each VRRP interface should have /ip/address ending in .254 /32 (note NOT /24, the VLAN IP should be /24, not the VRRP interface)....
by Amm0
Mon Jul 01, 2024 11:47 pm
Forum: Scripting
Topic: PUSHOVER - ready MikroTik script to send messages
Replies: 23
Views: 12293

Re: PUSHOVER - ready MikroTik script to send messages

Pushover also support JSON as an input. And in 5 years since the OP, Mikrotik added JSON support RouterOS scripting (7.13+). While I'm sure the existing script is fine, I re-wrote to take an RouterOS array with ANY of the allowed by pushover's API. Since new [:serialize] will deal with types and esc...
by Amm0
Mon Jul 01, 2024 7:15 pm
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 117057

Re: v7.16beta [testing] is released!

yes, real mDNS repeater. Very simple config, just add interfaces and enable. I found /ip dns mdns-repeat-ifaces but overlooked "enable". Can you please give a hint? Thanks. You just need to specify the interface where mDNS should be "shared". /ip/dns set mdns-repeat-ifaces=vlan2...
by Amm0
Sun Jun 30, 2024 8:04 pm
Forum: General
Topic: LTE-gw
Replies: 3
Views: 479

Re: LTE-gw

OP has the use-default-gateway=yes set... otherwise the /ip/route wouldn't be there. It's an interface route, and modem knows the destination is the other end of the LTE "session". So there is no IPv4 gateway. The "actual" routing table is in /routing/route/print (/ip/route is mo...
by Amm0
Fri Jun 28, 2024 11:35 pm
Forum: General
Topic: IPTV cuts and pixelations with Movistar Spain and HAP ax3/ax2
Replies: 72
Views: 7607

Re: IPTV cuts and pixelations with Movistar Spain and HAP ax3

From a default configuration, the ax2 set a L2 MTU of 1568. Double checked applying defconf again. Believe you. But it is kinda bizarre that L2 MTU did anything here. The VLAN adds 4 bytes, so L2MTU needs to be large enough for that - so 1568 is plenty. Why 1592 L2MTU works... I just dunno why IP T...
by Amm0
Fri Jun 28, 2024 10:29 pm
Forum: General
Topic: IPTV cuts and pixelations with Movistar Spain and HAP ax3/ax2
Replies: 72
Views: 7607

Re: IPTV cuts and pixelations with Movistar Spain and HAP ax3

Any L2 frame size larger than the standard 1500 bytes (excluding the header) on your local network requires all other devices on the same network to have the same size. L3/WAN (PPPoE) is a different story. https://www.packetstreams.net/2018/07/the-secrets-of-mtu-l2-mtu-vs-l3-mtu.html Mikrotik "...
by Amm0
Fri Jun 28, 2024 6:19 am
Forum: RouterBOARD hardware
Topic: RBM33G + 5G
Replies: 65
Views: 19869

Re: RBM33G + 5G

I'm looking for a 5G "client" device to add 5G (at high speed) at a location where VDSL is not fast enough. I'm hoping for a 5G version of one of the known LTE devices (wAP, SXT etc), if not I likely go for a competitor like Teltonika. You have the Chateau if you're in Europe. Nothing out...
by Amm0
Fri Jun 28, 2024 2:00 am
Forum: General
Topic: Request for Comprehensive RouterOS v7 Manual with Examples to build code generation chatbot
Replies: 6
Views: 865

Re: Request for Comprehensive RouterOS v7 Manual with Examples to build code generation chatbot

Count me as doubtful that "accurate and effective configurations" be as simple as plugging in more specific training data, but IDK. Mikrotik does have PDF linked on the main docs page: https://help.mikrotik.com/docs/. And maybe there is a PDF for the "old wiki" someplace too, but...
by Amm0
Thu Jun 27, 2024 11:19 pm
Forum: General
Topic: grep configuration
Replies: 1
Views: 345

Re: grep configuration

I'm not sure of the use case for it actually, other than searching the /export. I'm still waiting for `awk` or `sed`. [:grep] kinda odd since in RouterOS does not follow the UNIX "everything-is-a-file", so search for plain strings in RouterOS does not make a lot of sense, IMO. For example ...
by Amm0
Thu Jun 27, 2024 9:03 pm
Forum: RouterBOARD hardware
Topic: RBM33G + 5G
Replies: 65
Views: 19869

Re: RBM33G + 5G

Anyone knows if there are existing and compatible 5G modem cards in miniPCIe form factor instead of M.2 that would work in a MikroTik device without other tinkering? None that I know. Best I've found in miniPCIe is CAT18. If you care more about the 5G bands, than the speed, Fibocom appears to make ...
by Amm0
Thu Jun 27, 2024 8:41 pm
Forum: General
Topic: Winbox for linux
Replies: 41
Views: 88811

Re: Winbox for linux

At least we know the long delay isn't a naming debate.

This would require a beta, but you can always rename it...
sudo mv /usr/bin/winbox-linux /usr/bin/`shuf -n 1 /usr/share/dict/words`box
by Amm0
Thu Jun 27, 2024 7:41 pm
Forum: General
Topic: How do you get RouterOS to ignore IPv6-supplied DNS
Replies: 9
Views: 878

Re: How do you get RouterOS to ignore IPv6-supplied DNS

Hmm. On the RB1100, using AT&T Fiber, I don't show any dynamic addresses in /ip/dns if IPv6 DHCP has it disabled (and if IPv6 DNS is "use peer DNS" checked, AT&T DNS gets added a dynamic, uncheck it get removed). At least in 7.16beta.
by Amm0
Thu Jun 27, 2024 3:19 am
Forum: General
Topic: Shipped Credentials Don't Work - What I Did
Replies: 3
Views: 407

Re: Shipped Credentials Don't Work - What I Did

You wouldn't be the first to complain. I suspect the credentials are "right", but some of the labels use a difficult to read font. And yeah there is no "reset to no password" in netinstall. You can access the original ones using a custom script, but adding you're own user with -s...
by Amm0
Wed Jun 26, 2024 9:24 pm
Forum: General
Topic: Private LTE/5G Networking Question(s)
Replies: 15
Views: 1382

Re: Private LTE/5G Networking Question(s)

Finding some ORAN radio HW is not the hard part. There are a lot of software parts need too. And even more software and a high-end CPU too if using an SDR. And MOST importantly some allowed frequency to actually broadcast, and some CPE that receives on that frequency... I got a CBRS/Band48 ORAN work...
by Amm0
Wed Jun 26, 2024 8:27 pm
Forum: Scripting
Topic: get IP
Replies: 6
Views: 735

Re: get IP

IDK how you're exactly doing to the FW and/or routing tables. But packet flow is different between "local process" (i.e. /tool/fetch on the RouterOS device with LTE backup) vs. a "forwarded" LAN user (i.e. the browser). Without knowing the specifics, I'd imagine you need an outpu...
by Amm0
Wed Jun 26, 2024 5:48 pm
Forum: General
Topic: Home Assistant container does not starts
Replies: 27
Views: 2172

Re: Home Assistant container does not starts

It is interesting, is anybody has positive experience installing HA on RB5009? :? In a quick test on RB5009 (arm64), I get a layer error (specifically, "error getting layer: resolving error" when downloading a layer). On RB1100Ahx4 (arm/v7), it imports and goes to start. There is a Traefi...
by Amm0
Wed Jun 26, 2024 7:44 am
Forum: General
Topic: IPTV cuts and pixelations with Movistar Spain and HAP ax3/ax2
Replies: 72
Views: 7607

Re: IPTV cuts and pixelations with Movistar Spain and HAP ax3

So are we down to the wi-fi where it cuts, or was wired ethernet also still a problem?

The various release posts are littered with general wi-fi problems, IDK if releated. But ax wi-fi and multicast, the chance of a bug goes up.
by Amm0
Wed Jun 26, 2024 6:20 am
Forum: General
Topic: Regex Format in Conditional DNS forwarding
Replies: 24
Views: 1366

Re: Regex Format in Conditional DNS forwarding

So, just use: .*[^lan|^wlan].ad.localdomain$|^ad.localdomain$ Well, that does make it easy and likely okay. But "." still means any character to the regex. While improbable, lan1ad.localdomain would match the domain parts. Not say it's critical, but \\. is there for a reason, since you wa...
by Amm0
Wed Jun 26, 2024 5:59 am
Forum: Scripting
Topic: Automate Scripting in n8n
Replies: 1
Views: 449

Re: Automate Scripting in n8n

Use a "POST" as the method, and add run to the URL part: "/rest/system/script/run".

PUT and PATCH are same as "add" and "set"... But to "run" a script, that an operation, so you need to use POST (and not an attribute to PATCH/set or PUT/add).
by Amm0
Tue Jun 25, 2024 9:41 pm
Forum: Scripting
Topic: get IP
Replies: 6
Views: 735

Re: get IP

Edit: @Amm0 was faster... :)
LOL. I couldn't even proofread my text.
by Amm0
Tue Jun 25, 2024 9:38 pm
Forum: Scripting
Topic: get IP
Replies: 6
Views: 735

Re: get IP

To get output of a command into a variable in RouterOS, you always need "as-value". /tool/fetch can output to a file or nothing, so output=user returns data to console (or variable via as-value) - so that's also needed too here. Since the output of /tool/fetch is an array with results and ...
by Amm0
Tue Jun 25, 2024 8:50 pm
Forum: General
Topic: Private LTE/5G Networking Question(s)
Replies: 15
Views: 1382

Re: Private LTE/5G Networking Question(s)

Perhaps if you're in Europe...

I do wish Mikrotik made one of the "Intercell" for Band 48 in US - there aren't a lot of good offerings. But LTE/5G is just complex, both in specs and regulations, and not sure any vendor can fix that.
by Amm0
Tue Jun 25, 2024 8:41 pm
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 117057

Re: v7.16beta [testing] is released!

If it was me, I'd also move the entire "client config" section (that's only used for generating the client qr/config) to another tab on the selected peers menu). +1 - it is nice feature but really confusing if you don't know. If on another tab... it both be easy to have some add'l WG attr...
by Amm0
Tue Jun 25, 2024 6:16 pm
Forum: General
Topic: Regex Format in Conditional DNS forwarding
Replies: 24
Views: 1366

Re: Regex Format in Conditional DNS forwarding

Good to hear. You do kinda have to test them, since RouterOS has its own flavor. I kinda knew the ?! was likely not going work here. But \\D \\w etc stuff I'm not sure about... and seemingly the 3rd problem here (1st being the lack of escaped "\$", 2nd the "?!" does not work) sin...
by Amm0
Mon Jun 24, 2024 9:56 pm
Forum: General
Topic: Regex Format in Conditional DNS forwarding
Replies: 24
Views: 1366

Re: Regex Format in Conditional DNS forwarding

If using :put with your regex does not work to match true/false correct, it ain't going to work as a /system/script. As I said the $ is WRONG and needs escaping. A :put at the CLI would catch that. You've never said what it should match, so hard to know what's right/wrong (and the ?! may not be allo...
by Amm0
Mon Jun 24, 2024 5:28 pm
Forum: The Dude
Topic: help: (7.15+) ros_command function and Logs entries [SOLVED]
Replies: 7
Views: 3053

Re: help: (7.15+) ros_command function and Logs entries [SOLVED]

You need to make sure the SNMP profile in Dude aligns with the settings (v2, community, etc) in RouterOS SNMP, and the right Dude SNMP profile is assigned to a Device... but that about only tricky part. Once enable it, go to the router Device's properties, and under Service tab, hit "Discover&q...
by Amm0
Mon Jun 24, 2024 5:15 pm
Forum: Scripting
Topic: remove [find] gets stuck while executing [SOLVED]
Replies: 21
Views: 3575

Re: remove [find] gets stuck while executing [SOLVED]

This is a bug IMO. The CPU is slow, but finding 48 entries should not be measured in minutes. Perhaps seconds... since "resolving" the interface list into interface likely a more complex affair than it appears. While making the bridge port "invalid" (by deleting parent bridge) ma...
by Amm0
Mon Jun 24, 2024 4:47 pm
Forum: The Dude
Topic: help: (7.15+) ros_command function and Logs entries [SOLVED]
Replies: 7
Views: 3053

Re: help: (7.15+) ros_command function and Logs entries [SOLVED]

If you just need temp, the ros_command() is way to go. I was just thinking if you're repeating this for voltage, CPU, etc. etc., the built-in SNMP probes will track all that. Enabling SNMP would use some resources, I don't know if it significant in most cases. Certainly on low-memory/CPU devices, ru...
by Amm0
Mon Jun 24, 2024 4:05 pm
Forum: The Dude
Topic: help: (7.15+) ros_command function and Logs entries [SOLVED]
Replies: 7
Views: 3053

Re: help: (7.15+) ros_command function and Logs entries [SOLVED]

Another approach is enabling SNMP on the router. Then you can use oid() to read the read the temperature (or voltage) since those are the Mikrotik SNMP MIB. The MIB changes way less than scripting commands. The Dude will also show more stats on each device if SNMP is enabled on router.
by Amm0
Mon Jun 24, 2024 8:04 am
Forum: General
Topic: Regex Format in Conditional DNS forwarding
Replies: 24
Views: 1366

Re: Regex Format in Conditional DNS forwarding

@tanget's right, RouterOS is closer to the C-runtime's more limited subset. But I'm not sure your doing anything tricky in the regex... You can run a simple test on RouterOS CLI to check a regex too: :put ("aaa"~"[a]{3}") # true :put ("aaa"~"[a]{4}") # false B...
by Amm0
Mon Jun 24, 2024 7:40 am
Forum: Scripting
Topic: Rest API port reset [SOLVED]
Replies: 8
Views: 7595

Re: Rest API port reset [SOLVED]

Is it possible for it to work in a browser by typing it in a web browser bar? Like... http://user:password@192.168.1.2/rest/interface/disable--data{".id":"*5"} I'm trying a thousand and one ways and nothing at all. It's possible? ha ha ha No, the URL in a browser always makes a ...
by Amm0
Sun Jun 23, 2024 10:50 pm
Forum: The Dude
Topic: help: (7.15+) ros_command function and Logs entries [SOLVED]
Replies: 7
Views: 3053

Re: help: (7.15+) ros_command function and Logs entries [SOLVED]

/system/health is kinda weird in how it works, since the values like temp are just plain list items... So the simple "get temperature" isn't going to work.... You can just use a :do {} on-error={} to prevent errors (like temperature not being found): :do { :put [/system/health/get [find na...
by Amm0
Sun Jun 23, 2024 8:10 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 654
Views: 249533

Re: v7.15.1 [stable] is released!

Yes. But open a topic in The Dude or Scripting section.
hello everybody! sorry if this isnt the right place for this, but...
Please keep this forum topic strictly related to this particular RouterOS release.
by Amm0
Sun Jun 23, 2024 8:00 pm
Forum: Scripting
Topic: remove [find] gets stuck while executing [SOLVED]
Replies: 21
Views: 3575

Re: remove [find] gets stuck while executing [SOLVED]

*] Create custom interface list and add all 48 Ethernet ports to that list as list members (this can be automated in a script). Do not include ether49 to this list unless you want to suffer from your WinBox connection being reset in the next step. Well, learn something new. I didn't know .../bridge...
by Amm0
Sun Jun 23, 2024 4:23 am
Forum: Scripting
Topic: remove [find] gets stuck while executing [SOLVED]
Replies: 21
Views: 3575

Re: remove [find] gets stuck while executing [SOLVED]

Is this happening in /system/script or via the CLI. I also tried to run the same script by first creating a script entry in /system/script (both from terminal and GUI) and it gets stuck equally well. The hang is just weird. If same script works on ARM, does sound like a bug. Using a :local in a :im...
by Amm0
Sat Jun 22, 2024 10:50 pm
Forum: The Dude
Topic: Parse failed
Replies: 1
Views: 701

Re: Parse failed

You might need a / in front of interface in your ros_command().

Using SNMP from dude to read them may be better. I wrote up how to do this here:
viewtopic.php?t=192103&hilit=lte+dude
by Amm0
Sat Jun 22, 2024 10:24 pm
Forum: Scripting
Topic: remove [find] gets stuck while executing [SOLVED]
Replies: 21
Views: 3575

Re: remove [find] gets stuck while executing [SOLVED]

Is this happening in /system/script or via the CLI. If it's the CLI, a local is gone upon the next prompt - so it's nil [:nothing]. You'd need some curly braces at CLI: /interface/bridge/vlans { :local x [find]; remove $x } You may also want to qualify the "find" as things can be weird in ...
by Amm0
Sat Jun 22, 2024 10:17 pm
Forum: General
Topic: Export session .csv
Replies: 2
Views: 303

Re: Export session .csv

JSON could work using :serialize: :put [:serialize to=json [/user-manager/session/print as-value ]] Or for a CSV, it's often easier to use :foreach with a :put or :set $list ($list,"$user,$started,....") inside. Or alternatively abusing "print as-value where" to make it one line...
by Amm0
Sat Jun 22, 2024 6:20 pm
Forum: General
Topic: r/MikroTik, unofficial subreddit, my own personalized approach to discuss this topic given my experiences
Replies: 8
Views: 931

Re: r/MikroTik, unofficial subreddit, my own personalized approach to discuss this topic given my experiences

Going back beyond USENET people are rude on the internet. Get over it. And online communities have rules. Your experiences on Reddit have nothing to do with Mikrotik software/hardware.... so you're starting by violating the rules here... IDK how many words you wrote... but in a quick scan there noth...
by Amm0
Sat Jun 22, 2024 5:59 pm
Forum: Virtualization
Topic: Increase CHR Free license limit to 10 Mbit/s
Replies: 33
Views: 3004

Re: Increase CHR Free license limit to 10 Mbit/s

I got no dog in this fight.

But there is a point that the hAPlite/etc retails for $24.95. So $20 CHR be more profitable than that and at 100Mb/s max close in performance.
by Amm0
Sat Jun 22, 2024 4:16 am
Forum: Virtualization
Topic: Increase CHR Free license limit to 10 Mbit/s
Replies: 33
Views: 3004

Re: Increase CHR Free license limit to 10 Mbit/s

That is a good point. Some of the hardware has lower specs than 1G and less than $45... Yet you cannot get "software-only" below 1G.
I never thought about... but "P0.xx" paid license isn't a bad idea.

i.e.
P0.1 with 100Mb/s for $20?
P0.01 with 10Mb/s for $10?
by Amm0
Fri Jun 21, 2024 4:49 am
Forum: General
Topic: Best Place to Store API Credentials
Replies: 2
Views: 294

Re: Best Place to Store API Credentials

I use /ppp/secrets - the password for a "secret" is marked as "sensitive" in the policy, so it doesn't get shown or exported without show-sensitive. In theory, someone be able to login to serial console (if one is enabled) using the API key. But if goal is obfuscate some API key,...
by Amm0
Fri Jun 21, 2024 3:29 am
Forum: Virtualization
Topic: Increase CHR Free license limit to 10 Mbit/s
Replies: 33
Views: 3004

Re: Increase CHR Free license limit to 10 Mbit/s

I believe there is some "trick" (which @normis pointed out in some forum post). Basically the trial license just don't allow upgrade but remains full speed - if I recall correctly... But kinda with @holvoetn, if there is a hint of some production use, the $50-100 for license is pretty fair...
by Amm0
Thu Jun 20, 2024 3:49 am
Forum: General
Topic: Asking for help with LTE connection
Replies: 5
Views: 751

Re: Asking for help with LTE connection

You may need to make sure "Use Network APN" is UNCHECK in Interface > LTE > LTEs APN. If use-network-apn=yes / "checked" in the APN profile. the APN is IGNORED. You also may want to make sure the routerboard firmware is update-to-date too. Check in System > RouterBoard > Update. ...
by Amm0
Wed Jun 19, 2024 11:02 pm
Forum: General
Topic: URL to get latest versions of ROS branches [SOLVED]
Replies: 7
Views: 7687

Re: URL to get latest versions of ROS branches [SOLVED]

https://download.mikrotik.com/routeros/NEWESTa7.<channel> curl https://download.mikrotik.com/routeros/NEWESTa7.stable # 7.15.1 1717764551 curl https://download.mikrotik.com/routeros/NEWESTa7.testing # 7.16beta2 1718183008 Or to get just the version, awk works: curl -s https://download.mikrotik.com/r...
by Amm0
Wed Jun 19, 2024 10:21 pm
Forum: Scripting
Topic: $INQUIRE - prompt user for input using arrays +$CHOICES +$QKEYS
Replies: 28
Views: 5283

Re: $INQUIRE - prompt user for input using array of questions + $CHOICES

I did create another function, $qkeys in a different thread. [...] See https://forum.mikrotik.com/viewtopic.php?t=192475#p1080993 To keep things together and consistent, I updated the "qkeys" function in another thread, to a more sophisticated version $QKEYS function below that takes an a...
by Amm0
Wed Jun 19, 2024 5:18 am
Forum: Scripting
Topic: $INQUIRE - prompt user for input using arrays +$CHOICES +$QKEYS
Replies: 28
Views: 5283

Re: $INQUIRE - prompt user for input using array of questions + $CHOICES

Tutti, mi piace quando c'è collaborazione!!! LOL, so Mikrotik @druvis did a good video to explain "Scripting Arrays": https://www.youtube.com/watch?v=eWCJw0uZ-lE Essentially, the $INQUIRE script at top is just a "for" loop shown in the video, just with more stuff going on inside...
by Amm0
Tue Jun 18, 2024 6:16 pm
Forum: General
Topic: Mikrotik and Dante/NDI AV in general
Replies: 9
Views: 3371

Re: Mikrotik and Dante/NDI AV in general

Dante makes "Domain Manager" that, essentially, acts as an authenticated mDNS proxy to deal with Dante across VLANs, but it ain't cheap and likely overly complicated for nearly all cases. Not sure I'd recommend this... But Dante is good multicast and mDNS/DNS-SD citizen, so some DIY Router...
by Amm0
Tue Jun 18, 2024 12:56 am
Forum: Useful user articles
Topic: Marine Modem suitable for mast mounting
Replies: 10
Views: 6622

Re: Marine Modem suitable for mast mounting

Ain't Telit LM960A18 an LTE module? Do you know of any 5G/NR (SA/NSA) modules out there? None in miniPCIe. Even Cat18 modem in miniPCIe is hard to find, and think the Telit is only one with US-bands. Why it's annoying that the L23/NetMetal use miniPCIe... Seems Mikrotik considered it in the design,...
by Amm0
Tue Jun 18, 2024 12:37 am
Forum: Useful user articles
Topic: Marine Modem suitable for mast mounting
Replies: 10
Views: 6622

Re: Marine Modem suitable for mast mounting

Yeah, they should fit well. Btw, do you know of any 5G miniPCIe modules compatible with ROS v7? I use the Telit LM960A18. For US, they support all Verizon and AT&T bands and CA modes, and imporantly come in miniPCIe. But I think that's the highest end modem you can get without going to M.2. Tel...
by Amm0
Tue Jun 18, 2024 12:08 am
Forum: Useful user articles
Topic: Marine Modem suitable for mast mounting
Replies: 10
Views: 6622

Re: Marine Modem suitable for mast mounting

There is also the NetMetal AX. You'd have to add modem, pigtails, and antentas still.

Or, there are a few boutique marine LTE antennas that have space for a router inside, so imagine the L23 board (same CPU/specs as NetMetal AX) might work too.
.
by Amm0
Mon Jun 17, 2024 11:27 pm
Forum: General
Topic: Mikrotik and Dante/NDI AV in general
Replies: 9
Views: 3371

Re: Mikrotik and Dante/NDI AV in general

Never heard of Dante until this post - really interesting too. LOL, I thought of you since I'd imagine the Dante could be forwarded using bridge filters too. But its starts getting complex since while mDNS is used for discovery of audio channels, the audio flows can use unicast or multicast dependi...
by Amm0
Mon Jun 17, 2024 6:45 pm
Forum: Scripting
Topic: A few undocumented operators that are kind of neat.
Replies: 14
Views: 2792

Re: A few undocumented operators that are kind of neat.

I insist... https://forum.mikrotik.com/viewtopic.php?p=1077894#p1077894 I'm fine leaving RouterOS (& what lex/yacc-like things it has to do for CLI/API) to Mikrotik. Now they should open the boot process with ONIE/GRUB/whatever - getting something like cilium/NokiaSR/OpenWRT/etc. to run on Mikr...
by Amm0
Mon Jun 17, 2024 6:03 pm
Forum: Scripting
Topic: $INQUIRE - prompt user for input using arrays +$CHOICES +$QKEYS
Replies: 28
Views: 5283

Re: $INQUIRE - prompt user for input using array of questions + $CHOICES

I did create another function, $qkeys in a different thread. This is simplified version of $INQUIRE, that just takes keypresses to either run a command, or present a menu if array contained another array. See https://forum.mikrotik.com/viewtopic.php?t=192475#p1080993 So for @Sertik's case, the $qkey...
by Amm0
Mon Jun 17, 2024 5:44 pm
Forum: Scripting
Topic: $INQUIRE - prompt user for input using arrays +$CHOICES +$QKEYS
Replies: 28
Views: 5283

Re: $INQUIRE - prompt user for input using array of questions + $CHOICES

I don't want to tinker with your function. It is better and easier for the author to make changes to it. :) $CHOICES was designed to be simple, and, eventually a "plugin" to $INQUIRE as a "type" in menu. Some future $SELECT is the missing function that stay in same menu to make ...
by Amm0
Mon Jun 17, 2024 4:18 pm
Forum: Scripting
Topic: A few undocumented operators that are kind of neat.
Replies: 14
Views: 2792

Re: A few undocumented operators that are kind of neat.

I wrote a more practical example of the $(>[]) syntax "quote" / "op yesterday, $qkeys. This lets you assign a keypress to a command, in a menu like tree. You can check the array, $qkeymap, to be whatever commands you regular use. Then, just run "$qkeys" at CLI and have one-k...
by Amm0
Sun Jun 16, 2024 9:34 pm
Forum: General
Topic: Need an API to have the specificities of each Mikrotik router in order to integrate it into my store
Replies: 3
Views: 451

Re: Need an API to have the specificities of each Mikrotik router in order to integrate it into my store

In 7.16beta, you can even process the "CSV Product Matrix" (that's actually a TSV) using RouterOS scripts.

See viewtopic.php?t=208218&hilit=matrix#p1079318
by Amm0
Sun Jun 16, 2024 4:36 pm
Forum: General
Topic: SQM - using FQ-CODEL in interface queues and fasttrack
Replies: 12
Views: 2935

Re: SQM - using FQ-CODEL in interface queues and fasttrack

I asked what that does. @strods said it applies to the ethernet https://forum.mikrotik.com/viewtopic.php?t=202612&hilit=fq_codel#p1043420 With another poster suggesting it adds: /queue type add name=fq-codel-ethernet-default kind=fq-codel fq-codel-ecn=no /queue interface set [find default-queue=...
by Amm0
Sun Jun 16, 2024 3:57 pm
Forum: General
Topic: Let's Encrypt UPPER case issue [SOLVED]
Replies: 6
Views: 1318

Re: Let's Encrypt UPPER case issue [SOLVED]

I just happen to never use uppercase names, so I guess I never noticed. And LE IMO shouldn't force this - DNS names should be case-insensitive per RFCs. Perhaps RouterOS should do that internally... since it might not someone first thought as to the issue. I'd imagine there are at least some folks w...
by Amm0
Sun Jun 16, 2024 4:27 am
Forum: Beginner Basics
Topic: Nat rule not works out:(unknown 0)
Replies: 2
Views: 1118

Re: Nat rule not works out:(unknown 0)

So it works if you use an IP address in whatever app/media-center/etc in 192.168.0.x that's using it. Just it does not show up as "discovered". Is that the issue? AFAIK HDHomeruns just use UDP broadcast message to kick start discovery. So while NAT/filter may be need to connect using unica...
by Amm0
Sat Jun 15, 2024 8:52 pm
Forum: General
Topic: Mikrotik and Dante/NDI AV in general
Replies: 9
Views: 3371

Re: Mikrotik and Dante/NDI AV in general

The "IF" is because specifics often matter ;). Dante has come up a few times in the forum, let me add some details here since I'm pretty familiar with Dante audio networks . n.b. I wrote more than intended, but easy to explain in one post, once - since there are a lot of "IF" wit...
by Amm0
Sat Jun 15, 2024 1:22 am
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 117057

Re: v7.16beta [testing] is released!

LMK, I can file bug report if needed, but given @mozerd's comments, I'm guess something more generically is wrong in /disk in 7.16beta1/2. Not too sure about that issue being generic. No disk nor container problems on my RB5009 :? Perhaps. It may be specific to ROSE + RAID in my case. I narrowed do...
by Amm0
Fri Jun 14, 2024 8:00 pm
Forum: Scripting
Topic: A few undocumented operators that are kind of neat.
Replies: 14
Views: 2792

Re: A few undocumented operators that are kind of neat.

/console/inspect always tells some story about scripting. So on the (>) syntax... Mikrotik does use the LISP "quote" term... /console/inspect request=completion input="(" TYPE COMPLETION STYLE OFFSET PREFERENCE SHOW TEXT completion ( syntax-meta 1 75 no start of subexpression com...
by Amm0
Thu Jun 13, 2024 11:14 pm
Forum: Beginner Basics
Topic: Zerotier and routing tables
Replies: 9
Views: 1161

Re: Zerotier and routing tables

Looks like a typo... 192 is pretty close to 191 ;)
by Amm0
Thu Jun 13, 2024 10:33 pm
Forum: Scripting
Topic: $INQUIRE - prompt user for input using arrays +$CHOICES +$QKEYS
Replies: 28
Views: 5283

Re: $INQUIRE - prompt user for input using array of questions + $CHOICES

Could you correct the $CHOISES function so that it would be possible to use the "enter" key to select a menu item WITHOUT COMPLETING THE WORK? That is, the function would transfer the selected item to some global variable, while remaining in the selection loop to select another item (the ...
by Amm0
Thu Jun 13, 2024 9:24 pm
Forum: Scripting
Topic: A few undocumented operators that are kind of neat.
Replies: 14
Views: 2792

Re: A few undocumented operators that are kind of neat.

I cannot believe I didn't see this one. Despite being in the target demographic. This post will only be of interest to a few select individuals. If you are unfamiliar with mikrotik scripting, or have never used functions, this post is probably not for you, but you're welcome to read it anyway. Great...
by Amm0
Thu Jun 13, 2024 6:03 pm
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 117057

Re: v7.16beta [testing] is released!

Yeah something is wrong with disk mounting or something. On RB1100AHx4, it's had ROSE installed since it was in beta and is my main test box, so it's seen many beta/rc/etc's. Disk/ROSE has never messed up BEFORE... But in 7.16beta1, all containers stopped worked and could not add new ones — figured ...
by Amm0
Wed Jun 12, 2024 7:53 pm
Forum: Scripting
Topic: Script Execution Error - Dynu.com 7.13 was fine 7.15 no bueno
Replies: 14
Views: 1854

Re: Script Execution Error - Dynu.com 7.13 was fine 7.15 no bueno

Few notes about the "new" Dynu script above: 1. My script above is for NEWER RouterOS versions. Specifically, it uses an ":onerror" built-in command which was added recently. Since one way to deal with potential script error is more output on what a script is going... the newer &...
by Amm0
Mon Jun 10, 2024 12:49 am
Forum: Scripting
Topic: Script Execution Error - Dynu.com 7.13 was fine 7.15 no bueno
Replies: 14
Views: 1854

Re: Script Execution Error - Dynu.com 7.13 was fine 7.15 no bueno

I wrote a more modern version using a function. This works in 7.16beta1 and 7.13. Since it's a function, the parameters like username, password, WAN interface, and DDNS are at bottom: $updateDynu MYHOST.ddnsgeek.com user=MYUSER password=MYPASSWORD interface=ether1 You should be able to use it the co...
by Amm0
Sun Jun 09, 2024 7:28 pm
Forum: Scripting
Topic: Script Execution Error - Dynu.com 7.13 was fine 7.15 no bueno
Replies: 14
Views: 1854

Re: Script Execution Error - Dynu.com 7.13 was fine 7.15 no bueno

Fair enough. I didn't get past the first line.

As I look beyond the 3rd line ;). The policy is right.

My guess is the "src-path=" in the /tool/fetch line. While that has historically work with HTTP, in V7 using url= is better plan.
by Amm0
Sat Jun 08, 2024 7:55 pm
Forum: Scripting
Topic: Script Execution Error - Dynu.com 7.13 was fine 7.15 no bueno
Replies: 14
Views: 1854

Re: Script Execution Error - Dynu.com 7.13 was fine 7.15 no bueno

This issue is now resolved, it was identified there was a new-line in one of the lines, resulting in an error. Scripting functionality is very hard to debug, does anyone have any tips they could share? You can save it as .rsc file to Files, then in CLI use ":import dnsscript.rsc verbose=yes&qu...
by Amm0
Fri Jun 07, 2024 7:03 pm
Forum: General
Topic: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]
Replies: 31
Views: 3141

Re: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]

I'm glad it worked. The PBR rules are likely better - it is kinda better to see some config and could adjust routing more specifically later if needed. But I still maintain your originally setup should have "just worked". It's time to break out some wireshark/tcpdump and figure out what go...
by Amm0
Fri Jun 07, 2024 6:13 pm
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 117057

Re: v7.16beta [testing] is released!

It even put comments on in /interface/bridge/vlan on what triggered the "D" dynamic vlan entry there, i.e. "added by pvid", "added by vlan on bridge", ... Ammo, is that a feature that goes with MVLAN.... or whatever the acronym is for automatically adding vlans on trun...
by Amm0
Fri Jun 07, 2024 4:50 pm
Forum: Scripting
Topic: REST API - Convert Lease to Static
Replies: 3
Views: 676

Re: REST API - Convert Lease to Static

I think patch should work. What may be the issue is the sh/bash/zsh/etc wildcard expansion. Try some single quotes around the URL part. i.e. curl -k -u 'api':'password' -X PATCH 'http://10.0.1.1/rest/ip/dhcp-server/lease/*85' --data '{"comment": "test"}' -H "content-type: ap...
by Amm0
Thu Jun 06, 2024 11:59 pm
Forum: RouterBOARD hardware
Topic: Better choice for homelab router
Replies: 2
Views: 1067

Re: Better choice for homelab router

Depends on what you're doing. I like the RB1100AHx4. And if you're talking about a home Mikrotik lab, it be a great choice. You can add disks for lightweight RAID/NAS or Dude and have plenty of ports. It also has some unquie features too, like the off-line "bypass"/passthrough between port...
by Amm0
Thu Jun 06, 2024 11:23 pm
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 117057

Re: v7.16beta [testing] is released!

This was good too: *) bridge - added dynamic tagged entry when VLAN interface is created on vlan-filtering bridge; It even put comments on in /interface/bridge/vlan on what triggered the "D" dynamic vlan entry there, i.e. "added by pvid", "added by vlan on bridge", ...
by Amm0
Thu Jun 06, 2024 10:25 pm
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 117057

Re: v7.16beta [testing] is released!

*) console - improved :serialize and :deserialize commands and added support for DSV (delimiter separated values) format; That's going to be useful. Thought I'd provide an example, since I tested it (and works with a couple files at least). As example script to use them... this takes the product ma...
by Amm0
Thu Jun 06, 2024 7:09 pm
Forum: General
Topic: cycle outgoing IP addresses
Replies: 17
Views: 1116

Re: cycle outgoing IP addresses

Credit to @rextended for "code2=title". Grreat, thanks! Are there any other hidden gems for phpBB that can be used in this forum? In tips, there is CPAN module "md2phpbb" - that takes Markdown and gets almost-Mikrotik-forum phpBB. I used that to take a GitHub README.md to make a ...
by Amm0
Thu Jun 06, 2024 6:52 pm
Forum: General
Topic: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]
Replies: 31
Views: 3141

Re: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]

Thanks @Larsa for opening a ticket. Some PBR rule would get this working. But it is not a new feature that a VPN has an option to "routes all traffic" — which is what ZT's "allow-default=yes" should do. And not everything should have to involve complex config to setup. Now in fai...
by Amm0
Thu Jun 06, 2024 6:08 pm
Forum: Announcements
Topic: WinBox v3.40 released!
Replies: 165
Views: 166430

Re: WinBox v3.40 released!

You want too much from a teaser. Teaser makes you think. Try it. I was thinking about this today (i.e. had to fix a font problem with wine after an update). So ~6 months ago we saw an icon. Since y'all like multi-year teasers, perhaps the clue be the language/framework behind the icon? That's my my...
by Amm0
Thu Jun 06, 2024 4:36 pm
Forum: General
Topic: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]
Replies: 31
Views: 3141

Re: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]

I actually meant “ allow default ”. It works initially but any changes or deletions afterward don’t show up in ROS. LOL, I actually did mean "allow-default=yes" myself — I get confused with naming. I tested it long ago, but believe you there might be problem if 0.0.0.0/0 change is push to...
by Amm0
Thu Jun 06, 2024 3:22 pm
Forum: General
Topic: cycle outgoing IP addresses
Replies: 17
Views: 1116

Re: cycle outgoing IP addresses

It's all pseudo-random anyway. There is a "Julian-Gregorian twister" here since the cycle will change between 30|31|29|28 to 1 in above script as it use the day of the month which can break the cycle ;). If you want a more random one, change the index to be a random number. V7 has a built-...
by Amm0
Thu Jun 06, 2024 4:05 am
Forum: General
Topic: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]
Replies: 31
Views: 3141

Re: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]

EDIT: Btw, forgot to mention there's a bug in the interface that ROS uses to manage the "Allow Default" setting for Zerotier. Changes to or removing the default route with Zerotier Central don't get properly propagated to the ZT client in ROS; you have to fix the changes manually. Do you ...
by Amm0
Wed Jun 05, 2024 9:11 pm
Forum: General
Topic: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]
Replies: 31
Views: 3141

Re: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]

Now on what you want 0.0.0.0/0 to be... the local internet for everything? Or just the 192.168.250.0/23's subnets. Or should all internet traffic go the Azure thing mention earlier. I'm still thinking the using ZT default route should have work. But you need a src-nat on "zerotier1" in /ip...
by Amm0
Wed Jun 05, 2024 9:02 pm
Forum: General
Topic: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]
Replies: 31
Views: 3141

Re: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]

Here is the diagram without the link (there is 1MB limit on images):
Screenshot 2024-06-05 at 10.58.10 AM.jpg
by Amm0
Wed Jun 05, 2024 8:45 pm
Forum: General
Topic: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]
Replies: 31
Views: 3141

Re: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]

Also keep in mind any routes added by ZT with have distance=1 by default. This may not be want you want, since there may be local routes at same distance. I'd also increase the distance= on the ZT instance ("zt1" typically). The default distance=1 of ZT injected /ip/route's can easily lead...
by Amm0
Wed Jun 05, 2024 8:39 pm
Forum: General
Topic: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]
Replies: 31
Views: 3141

Re: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]

That what confused me too. I think... there is a ZT member at Azure to act as an internet gateway & idea is the "robot router" send everything but ZT tunnel themselves via that. I get using ZT address to act as a "global LAN" IP address for the device doing port forwarding pa...
by Amm0
Wed Jun 05, 2024 8:27 pm
Forum: General
Topic: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]
Replies: 31
Views: 3141

Re: ZeroTier Gateway Tunneling On MikroTik Device [SOLVED]

I get the general problem, but kinda lost in what's where. Some simple diagram would help here. But when things don't just work, you can look to /ip/firewall/connection (and filter) to see what going on with NAT/routing - as NAT is my generalized guess here. WRT to ZT providing 0.0.0.0/0 routes... D...
by Amm0
Wed Jun 05, 2024 8:22 pm
Forum: Beginner Basics
Topic: MACVLAN direct to LACP
Replies: 2
Views: 594

Re: MACVLAN direct to LACP

Good day to all, newbie here (please be indulgent). I can assign MACVLAN to interfaces, assign to VLANs to interfaces, to VLANs to LACPs, but I can not assign MACVLAN to LACP directly. I'm missing something or "it should be possible" but it need a fix by Mikrotik devs ? LOL. I had the sam...
by Amm0
Wed Jun 05, 2024 5:23 pm
Forum: General
Topic: cycle outgoing IP addresses
Replies: 17
Views: 1116

Re: cycle outgoing IP addresses

I'm with @BertozP if need is just daily... use /system/schedule that's set interval of 1d. The following should work. You'd have to change the list of IP addresses to rotate, and the /ip/address that will be rotated must of the comment "cycle" (no spaces, but you change in the script). The...
by Amm0
Tue Jun 04, 2024 7:01 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 654
Views: 249533

Re: v7.15 [stable] is released!

I think MVRP forced some changes here. _i.e._ now it not just bridge on the local router that modifies /interface/bridge/vlan, but potentially MVRP too. Hopefully at some point the PVID per port will disappear and the "untagged ports" in the VLAN configuration will provide this config... I...
by Amm0
Tue Jun 04, 2024 6:16 pm
Forum: Forwarding Protocols
Topic: VRRP + DST-NAT
Replies: 4
Views: 652

Re: VRRP + DST-NAT

Connection tracking is confusing. So I'm not sure, especially how NAT is handled.

But my first thought would be to disable fast-track rule (if enabled) to see if that changes this "d" vs "s".
by Amm0
Tue Jun 04, 2024 5:56 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 654
Views: 249533

Re: v7.15 [stable] is released!

*) bridge - reworked dynamic VLAN creation; Before I could join a Port untagged to a VLAN by giving it the PVID that I wanted and it would show up in my static created VLAN in /interface/bridge/vlan. Since 7.15 I need to manually add the untagged port to the VLAN settings, otherwise I have the stat...
by Amm0
Tue Jun 04, 2024 5:03 pm
Forum: General
Topic: cycle outgoing IP addresses
Replies: 17
Views: 1116

Re: cycle outgoing IP addresses

Cycle or randomize are different things. You cannot do this with a NAT rule alone. And while "netmap" is very useful, not sure it can help here. One way a "random" (per connection) change happen using ECMP route on gateway. @jvanhambelgium's /29 ISP to customer is pretty common, ...
by Amm0
Tue Jun 04, 2024 3:50 am
Forum: Scripting
Topic: The issue of a function containing variables unsuccessfully.
Replies: 15
Views: 1356

Re: The issue of a function containing variables unsuccessfully.

Geez, "yes" and "no"
NOT "on" and "off" — which I fixed from original example

Or... "where" — I'm not sure that's needed since there is only one attribute to be searched;.
by Amm0
Tue Jun 04, 2024 3:34 am
Forum: Scripting
Topic: The issue of a function containing variables unsuccessfully.
Replies: 15
Views: 1356

Re: The issue of a function containing variables unsuccessfully.

Or do NOT use the "enable" and "disable" commands , use the disable=yes|no attribute with a "set". Why? Commands cannot be variables, but attributes can. This avoids the ugly [:execute] & the related issues with that like escaping, creating new subshell/etc., lack o...
by Amm0
Tue Jun 04, 2024 2:53 am
Forum: Scripting
Topic: external editor syntax highlighting
Replies: 51
Views: 109002

Re: external editor syntax highlighting

Just use VS Code, someone has made an extension with highlighting. Ain't got time to reinvent the wheel Yup. That one works really well. Thanks to whomever does these plugins/extensions – I couldn't write a script if there were not colors on things. I also know regular `vi` (vim) has .rsc built it,...
by Amm0
Sun Jun 02, 2024 6:17 pm
Forum: Scripting
Topic: Script not running
Replies: 5
Views: 824

Re: Script not running

Why the :put just doesn't work for me? The only way to see in console what is happening is using /log info for debug. Is that normal? Where put prints on? That's expected in /system/script and /system/scheduler, or any of the "background" scripts. Basically there is no terminal where the ...
by Amm0
Sun Jun 02, 2024 3:51 am
Forum: General
Topic: Best way to forward web traffic to portal page?
Replies: 4
Views: 863

Re: Best way to forward web traffic to portal page?

Really depends on the need. If really simple like you have one web server, you can use dst-nat rule to redirect Mikrotik's port 80 and 443 to your web server. Any DNS point the Mikrotik. Now in the case, that web server likely need SSL certs etc. setup. SSL is one area where stuff like traefik and c...
by Amm0
Sun Jun 02, 2024 3:43 am
Forum: General
Topic: Deserialize .json SKIN vs. API [SOLVED]
Replies: 5
Views: 864

Re: Deserialize .json SKIN vs. API [SOLVED]

Yeah I like your SMB approach. FWIW, you just need write permission to create a script, no policy. The script itself needs no policy since it's just storing the JSON. But yeah the "write user" have to create the JSON as the script themself. And... I am presuming there is another background...
by Amm0
Sat Jun 01, 2024 10:03 pm
Forum: Containers
Topic: CLIGAMES - container with UNIX CLI games & playable with /system/telnet
Replies: 6
Views: 8055

Re: CLIGAMES - container with UNIX CLI games & playable with /system/telnet

Someone has too much time available ... :lol: On that front, I cleaned up the README, and put the "ammo74/cligames" container on DockerHub recent: https://hub.docker.com/r/ammo74/cligames (the Dockerfile, and GitHub builder code remain at: https://github.com/tikoci/cligames - which is wha...
by Amm0
Sat Jun 01, 2024 7:49 pm
Forum: Containers
Topic: Horrible container performance from 7.14 up to 7.15rc2
Replies: 29
Views: 6498

Re: Horrible container performance from 7.14 up to 7.15rc2

Maybe there is an issue, IDK. But to clarify on the "duckdns" sub-case... 1. Does it show "starting" for 10 minutes, or it goes to "running" and just does respond? 2. Assuming logging is enabled, does anything appear during the 10 minutes? 3. Does "/container/shell...
by Amm0
Sat Jun 01, 2024 6:17 pm
Forum: Beginner Basics
Topic: Basic Zerotier Question.
Replies: 3
Views: 571

Re: Basic Zerotier Question.

Okay so it sounds very doable. Its a bit better than trying it over wireguard as wireguard then trips over the routing issue, where zerotier does not. To be honest, you shouldn't have to do anything. ZT will tunnel use the Wi-Fi - since that have lower latency than LTE. It be over ZL1 tunnel, but s...
by Amm0
Sat Jun 01, 2024 5:38 pm
Forum: Beginner Basics
Topic: Basic Zerotier Question.
Replies: 3
Views: 571

Re: Basic Zerotier Question.

I could ask for a diagram ;) So let's assume you ZT – correct if wrong: - You using my.zerotier.com as ZT controller (i.e. not running a local controller under /zerotier/controller on the Mikrotik) - Nothing in ZT is bridged, specifically: - no "member" (aka peer) has "bridging" ...
by Amm0
Sat Jun 01, 2024 4:56 pm
Forum: General
Topic: Deserialize .json SKIN vs. API [SOLVED]
Replies: 5
Views: 864

Re: Deserialize .json SKIN vs. API [SOLVED]

I tried adding custom menus to the skin.json but they don't display in webfig. the menu system notes I already use it for other purposes. I also thought about using layer 7 but it's a pain to mess up from a user-friendly user. Could I do something with bees? I thought your SMB approach was not a ba...
by Amm0
Sat Jun 01, 2024 2:09 am
Forum: General
Topic: v. 7.14.3 - 7.15RC3 - 7.15RC4 router was rebooted without proper shutdown, probably kernel failure
Replies: 29
Views: 3110

Re: v. 7.14.3 - 7.15RC3 - 7.15RC4 router was rebooted without proper shutdown, probably kernel failure

Most likely hardware.....
Maybe. Some hardware malfunction causing issues in the kernel is exactly kinda thing watchdog was designed to catch.

All I know is I'm pretty sure the band-aid of disabling watchdog ain't going to fix anything. I always use watchdog and never seen some false positive.
by Amm0
Sat Jun 01, 2024 1:57 am
Forum: General
Topic: Routing VLAN to specific WAN using Policy Routing
Replies: 19
Views: 1943

Re: Routing VLAN to specific WAN using Policy Routing

So I am running in circles, if I enable add default routes of WAN, cannot control where traffic flows towards WAN, if I disable the default routes, traffic flows correctly, but the IoT devices have issues. The route always needs to exist in main, if it exists in a routing table. The PBR docs have s...
by Amm0
Sat Jun 01, 2024 1:10 am
Forum: Scripting
Topic: Script not running
Replies: 5
Views: 824

Re: System Script not running

It a bit unclear whether you want to make one array with {1,2,3,4} or two-dim array like {{1;2};{3;4}}. i.e. :local notificationTeam {{"mateo";"mateo@example.com"} ; {"carlo";"carlo@example.com"}} vs. :local notificationTeam {{"sofia@example.com";&qu...
by Amm0
Fri May 31, 2024 8:31 pm
Forum: Scripting
Topic: New command in RouterOs 7
Replies: 35
Views: 10052

Re: New command in RouterOs 7

FWIW, I already had a GitHub project that compiled the REST schema, and as part of that there is an "inspect.json" that get generates with output of /console/inspect. I recently automated it all at GitHub, and put a tiny web page that has downloadable form of the "command schema"...
by Amm0
Fri May 31, 2024 7:59 pm
Forum: General
Topic: How to covert int to hex type value and save it in a string? [SOLVED]
Replies: 13
Views: 6166

Re: How to covert int to hex type value and save it in a string? [SOLVED]

I hope you like those functions @rextended, FWIW your num2hex function still comes in handy... While num2hex is super helpful, half the code is doing that one conversion ;): https://forum.mikrotik.com/viewtopic.php?t=204990#p1078202 Since despite the new built-in " :convert ", still canno...
by Amm0
Fri May 31, 2024 7:07 pm
Forum: General
Topic: v. 7.14.3 - 7.15RC3 - 7.15RC4 router was rebooted without proper shutdown, probably kernel failure
Replies: 29
Views: 3110

Re: v. 7.14.3 - 7.15RC3 - 7.15RC4 router was rebooted without proper shutdown, probably kernel failure

I'd ping Mikrotik again. You shouldn't have to disable watchdog. If it really is a watchdog bug, that's kinda serious IMO - the last thing you'd want is the monitoring for crashes, to cause crashes....
by Amm0
Fri May 31, 2024 6:28 pm
Forum: General
Topic: HOWTO: Import ZeroTier Members into Mikrotik DNS using $ZT2DNS
Replies: 3
Views: 1207

Re: HOWTO: Import ZeroTier Members into Mikrotik DNS using $ZT2DNS

[...] noticed you only take into account IPv4 addresses, while 6PLANE and RFC4193 IPv6, if any, are ignored. [...] I don't understand where to find 32 bits to compose the former. UPD : Found info about 6PLANE here : The 8-bit fc prefix indicates a private IPv6 network with an "experimental&quo...
by Amm0
Fri May 31, 2024 4:29 pm
Forum: General
Topic: v. 7.14.3 - 7.15RC3 - 7.15RC4 router was rebooted without proper shutdown, probably kernel failure
Replies: 29
Views: 3110

Re: v. 7.14.3 - 7.15RC3 - 7.15RC4 router was rebooted without proper shutdown, probably kernel failure

That was a lousy answer from support. Blame watchdog itself? If watchdog is causing a reboot when it should not, that is a bigger bug! If you don't know, you can look at the autosupout.rif via an account on www.mikrotik.com there is an online viewer for the `.rif` files. That will have the log from ...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 15