Community discussions

MikroTik App

Search found 3623 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 13
by Amm0
Fri Mar 29, 2024 3:28 am
Forum: Wireless Networking
Topic: Can I safely uninstall wireless package - hEX
Replies: 16
Views: 532

Re: Can I safely uninstall wireless package - hEX

Ok, than why not 4) device families w/o wireless -> uninstall any wireless package [Legacy] CAPsMAN — which CONTROLS access points — was always an included feature & does not require an hardware, since it's a controller. Recently, CAPsMAN moved to the wireless package, but [Legacy] CAPsMAN stil...
by Amm0
Fri Mar 29, 2024 3:08 am
Forum: General
Topic: How can I switch wireless to wifiwave2?
Replies: 2
Views: 77

Re: How can I switch wireless to wifiwave2?

Check the logs and see if there is a message about disk space, or some other message? e.g. Do you have any other extra-package like zerotier or iot? Or other files on the router. The wAPac has only 16MB and with the new wifi-qcom-ac, RouterOS barely fit. A lot of folk need to use the netinstall, whi...
by Amm0
Thu Mar 28, 2024 4:20 pm
Forum: Virtualization
Topic: Plan to port BTH to CHR?
Replies: 7
Views: 867

Re: Plan to port BTH to CHR?

Still it a good request. Since beyond just the proxy feature of BTH... BTH also has the "friendly" apps to set it a VPN. That's another benefit to BTH over "plain" WG, which requires more manual cut-and-pasting of keys. That's exactly what is expected for beginners... Of course,...
by Amm0
Thu Mar 28, 2024 4:09 pm
Forum: General
Topic: Watchdog, or alternative?
Replies: 2
Views: 141

Re: Watchdog, or alternative?

I think watchdog with ping is a good idea if you have dynamic WANs like PPPoE or LTE. BUT you do NOT want to set it's timeout too aggressively (e.g. use 3-10 minutes) — otherwise if it take a while to reboot/connect/etc... it could reboot again before it finishes. And you have some time to access to...
by Amm0
Thu Mar 28, 2024 3:55 pm
Forum: RouterBOARD hardware
Topic: Outdoor 5G?
Replies: 6
Views: 337

Re: Outdoor 5G?

Yeah, 15M is a LONG way for a passive antennas. And a wAPac would fit nice on a mast. Since Mikrotik offers nothing beyond very old 4G modems for US market, we've long installed third-party modems instead into various Mikrotik board. Past few years used the Telit LM960s using 4 x external pigtails o...
by Amm0
Thu Mar 28, 2024 12:21 am
Forum: RouterBOARD hardware
Topic: Pure ROS boot...
Replies: 29
Views: 1482

Re: Pure ROS boot...

Well said @Cha0s. Tend to agree the lack of a real force password change (e.g. you can Ctrl-C or "Cancel", when prompted) was likely the actual compliance issue. The "sticker" scheme is a pretty tedious affair, see @kevinds post above. But if it's your only router and a newbie, l...
by Amm0
Wed Mar 27, 2024 8:11 pm
Forum: Announcements
Topic: v7.14.2 [stable] is released!
Replies: 461
Views: 93246

Re: v7.14.2 [stable] is released!

But would then it be speed of light in vacuum or in some thick air with large refractive index? Well, in the case of distance= it already a proxy for time. 10km equates to some timing intervals at the end of the day. Now the constant "indoor" means I don't trust Mikrotik math, or perhaps ...
by Amm0
Wed Mar 27, 2024 6:16 pm
Forum: RouterBOARD hardware
Topic: Outdoor 5G?
Replies: 6
Views: 337

Re: Outdoor 5G?

I might have been unclear - 5G as in cellular, not wifi. Not really. ATL is closest you get, but only in Europe. With an wAPacR or LtAP with pigtail/added modem modules, you can DIY to some degree. But even there most true 5G modems using M.2, so DIY for 5G/LTE get even more tricky (since you'd nee...
by Amm0
Wed Mar 27, 2024 4:58 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

Adlists do not load automatically after restart.[...] If this is intentional behavior, there should be information in the documentation [...] You can use the scheduler to update automatically,[...] What ever the reload strategy is it should be documented. Like what happens during the reload process...
by Amm0
Wed Mar 27, 2024 2:22 am
Forum: Beginner Basics
Topic: Unable to find new replacement for existing router...
Replies: 7
Views: 555

Re: Unable to find new replacement for existing router...

I dunno for sure with AX whether it's a good idea... but I've always used 20Mhz or 40Mhz if I cared about distance from Wi-Fi. You'll lose max speed near router, but I suspect speeds at a distance would improve/more stable. Playing with channel selection certainly be a good idea... although at 80Mhz...
by Amm0
Wed Mar 27, 2024 2:09 am
Forum: Wireless Networking
Topic: Mikrotik LHGG LTE18 frequently unresponsive
Replies: 8
Views: 638

Re: Mikrotik LHGG LTE18 frequently unresponsive

Hmm. The fact only winbox works is strange here. Since that shouldn't have anything to do with LTE not working right. Did you also upgrade the boot firmware in /system/routerboard/upgrade - so that matches the same version. Other thing to check is if your "Use Network APN" is checked the A...
by Amm0
Wed Mar 27, 2024 1:58 am
Forum: Beginner Basics
Topic: LTE6 and EE having issues? Anyone else, no LTE for 3 days now and no one can seem to solve it.
Replies: 7
Views: 653

Re: LTE6 and EE having issues? Anyone else, no LTE for 3 days now and no one can seem to solve it.

In general, you should be able to upgrade the firmware using LTE interface. There was some pre-release firmware for one of the modems, but I'd imagine it's been integrated into the stable build by now. While depending on modem... you'll likely better of making sure both RouterOS (/system/package) an...
by Amm0
Wed Mar 27, 2024 1:50 am
Forum: General
Topic: Precision Time Protocol (ieee 1588) CRS326-24G-2S+
Replies: 4
Views: 1674

Re: Precision Time Protocol (ieee 1588) CRS326-24G-2S+

Nice. FWIW, Mikrotik document Dante's QoS for the CRS326's HW QoS recently, suggesting there is full support coming in 7.15:
https://help.mikrotik.com/docs/pages/vi ... QoS)-Dante
by Amm0
Tue Mar 26, 2024 5:11 pm
Forum: RouterOS beta
Topic: Speedify Mulit WAN Bonding
Replies: 41
Views: 14112

Re: Speedify Mulit WAN Bonding

Between VoIP, Wifi calling, video conference, and the real driving force... Streaming Services. Oh there are use cases for bonding for sure. I didn't look too closely at the timestamps here. Been at this problem for a long while myself too, mainly on the LTE side of multiwan. I settled on Peplinks ...
by Amm0
Tue Mar 26, 2024 2:29 pm
Forum: General
Topic: Multiple APN profiles on LTE interface
Replies: 2
Views: 274

Re: Multiple APN profiles on LTE interface

Interesting idea. So you have two APNs assigned, but a working SIM for only one of them? I'm just not sure it's a good idea. In general, modems expects all APNs provided work. If one fails, the modem is going keep trying forever until it works... so it keep searching and that very well might interfe...
by Amm0
Tue Mar 26, 2024 5:43 am
Forum: RouterOS beta
Topic: Speedify Mulit WAN Bonding
Replies: 41
Views: 14112

Re: Speedify Mulit WAN Bonding

Not sure where MPTCP is coming in here. Although agree that MPTCP is more for applications needing control, than as network bonding protocol. Speedify uses UDP-based DLTS* to setup tunnels to some cloud server, so it's not TCP. I'd imagine their Linux version could be put in a /container similar to ...
by Amm0
Mon Mar 25, 2024 10:20 pm
Forum: Beginner Basics
Topic: Same IP on different Ether interfaces
Replies: 10
Views: 609

Re: Same IP on different Ether interfaces

That's why you're getting a command error. Now is routing "mark" in the firewall, it a "table" routes.
Sorry, I don't know what you mean
/ip route
add distance=1 dst-address=10.0.0.1/32 gateway=ether2 routing-table=port2
by Amm0
Mon Mar 25, 2024 8:08 pm
Forum: General
Topic: How does RouterOS prioritize domain name servers?
Replies: 3
Views: 416

Re: How does RouterOS prioritize domain name servers?

@mkx is correct. If you give a client two DNS servers via DHCP it can use either. Now... if you client use FQDN (e.g. hostname.example.com) for stuff, and you have a custom domain with it's own DNS. You can use the Mikrotik "FWD" record in /ip/dns/static to match on a domain name & tha...
by Amm0
Mon Mar 25, 2024 7:25 pm
Forum: Scripting
Topic: execute & parse
Replies: 15
Views: 774

Re: execute & parse

It just be nice if you could have some "stored functions" since they could just be saved in config like a script. e.g. "/system/scripts/function add addVLAN source={}" so NO :global be need. Without resorting the @Larsa's nifty but ugly approach. As a "config language",...
by Amm0
Mon Mar 25, 2024 7:07 pm
Forum: General
Topic: DNS and mDNS name conflict
Replies: 5
Views: 419

Re: DNS and mDNS name conflict

I guess I'm suggesting there may not be easy solution using Mikrotik DNS. Mikrotik has NO support for "discovery proxy" (https://www.rfc-editor.org/rfc/rfc8766.html) which resolve normal/unicast DNS queries into mDNS ones, which is kinda what you'd like in this case. No static DNS entries ...
by Amm0
Mon Mar 25, 2024 6:45 pm
Forum: General
Topic: DNS and mDNS name conflict
Replies: 5
Views: 419

Re: DNS and mDNS name conflict

Add'l detail, if you using a custom domain & want it resolved by mDNS. You'll need to add specific records to the DNS server used by clients to say that "regular" domain is enabled for mDNS lookups. This older document explains more how to add the Mikrotik to another DNS server (since ...
by Amm0
Mon Mar 25, 2024 6:25 pm
Forum: General
Topic: DNS and mDNS name conflict
Replies: 5
Views: 419

Re: DNS and mDNS name conflict

Just adding a .local to a static DNS is not enough to enable it for mDNS (or specifically DNS-SD). Bonjour uses multicast (or SRV and PTR DNS record) to actually resolve ".local" names. On Mac (or Linux distro/Windows with Bonjour/mDNS resolver enabled), it wouldn't check the DNS servers f...
by Amm0
Mon Mar 25, 2024 5:01 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

Well, Mikrotik has said they're working on a "solution". And at least it failed gracefully. Using Netinstall let you test 7.15beta. Whether it's fragmentation, "leftover" files from past, leases, graphing... The "math" using the UI is not always predictive of failure &a...
by Amm0
Mon Mar 25, 2024 4:15 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

Be curious, do you have any other things in Files?

e.g. since photo shows 46 million sector writes, there could be none.
by Amm0
Mon Mar 25, 2024 4:02 pm
Forum: Scripting
Topic: execute & parse
Replies: 15
Views: 774

Re: execute & parse

Like eval in another script languages ? Yes. And same generally approach: string interpolation to dynamically create a command. Here the use more complex. @rextended and @Sertik are trying to get around the restriction that a function must declare any global variables to be able to use them. So the...
by Amm0
Mon Mar 25, 2024 2:19 pm
Forum: Beginner Basics
Topic: Same IP on different Ether interfaces
Replies: 10
Views: 609

Re: Same IP on different Ether interfaces

While subnet is /32 based /ip/address, the issue isn't the /24. But more likely
routing-mark=port2
vs.
routing-table=port2

That's why you're getting a command error. Now is routing "mark" in the firewall, it a "table" routes.
by Amm0
Mon Mar 25, 2024 2:12 pm
Forum: Wireless Networking
Topic: Mikrotik LHGG LTE18 frequently unresponsive
Replies: 8
Views: 638

Re: Mikrotik LHGG LTE18 frequently unresponsive

The default IP is 192.168.88.1. You changed it to 192.168.188.1? Likely not. I believe 192.168. 188 .1 is the default IP on the LHGG (and some other LTE things I think). You may want to check the LTE firmware is update-to-date. It's an option on the LTE interface to check for upgrades. There should...
by Amm0
Mon Mar 25, 2024 5:53 am
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

As far as I know, this gives a result of -1. Depends. JS allows it and is -1. But in Python, it's an error. In C, it's left to an implementation detail. But of all things to complain about in RouterOS scripts... And even if "wrong", you never know what might break changing stuff, someone ...
by Amm0
Mon Mar 25, 2024 2:43 am
Forum: Beginner Basics
Topic: Dual WAN Setup - how to get both public IPs reachable
Replies: 6
Views: 1730

Re: Dual WAN Setup - how to get both public IPs reachable

I have exactly the same problem as Chaosphere64. [...] IPSec Lan2Lan connection [...] How can I solve this problem?
To @anav's point, your problem is not the same. IPSec isn't mentions at all here & that add more complexity.
Likely better to create a topic with your config/diagram/details.
by Amm0
Sun Mar 24, 2024 11:58 pm
Forum: Containers
Topic: Can't ping veth1, trying to add pihole to a container.
Replies: 1
Views: 338

Re: Can't ping veth1, trying to add pihole to a container.

It's blocked by firewall. Specifically the default !LAN input drop rule: /ip firewall filter add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN since bridge-pihole is not a member of the LAN /interface/list Several ways to allow. But this be ...
by Amm0
Sun Mar 24, 2024 11:41 pm
Forum: Beginner Basics
Topic: What happens to an interface that is not part of any bridge?
Replies: 7
Views: 587

Re: What happens to an interface that is not part of any bridge?

"Seen" is where the theory meets practice. They're all interfaces to the router. RouterOS is also a [Layer 3] [IP] router & routers do routing. So with empty firewall... IP/IPv6 between traffic be allowed between all the interfaces, bridged or not. But an off-bridge ethernet interface ...
by Amm0
Sun Mar 24, 2024 9:36 pm
Forum: Beginner Basics
Topic: how to find version of runing Winbox
Replies: 2
Views: 266

Re: how to find version of runing Winbox

It's in the title bar of the first/login window that appears after launch. Once connect, I'm not sure where you could find out winbox version, since the titlebar will show the connected router's version AFTER login.
by Amm0
Sun Mar 24, 2024 9:18 pm
Forum: Scripting
Topic: fetch - how receive response code
Replies: 8
Views: 5157

Re: fetch - how receive response code

That's a shame. This seems to be a very old user need. I guess the best option is to resort to files as @rextended suggested. I hope MT improves the Fetch tool one day. 🤞 They added "output=user-with-headers" option recently, but that doesn't help on DNS failure. Also, if there is a some ...
by Amm0
Sun Mar 24, 2024 5:51 pm
Forum: General
Topic: TIP: Do not use rp-filter=Strict with Dual WAN policy-based routing [SOLVED]
Replies: 6
Views: 1180

Re: Policy-based routing with dual WAN [SOLVED]

Might want to change your title. Something like "TIP: Do not use rp-filter=strict with Dual WAN".

It's been years, but I have run into this one myself.
by Amm0
Sun Mar 24, 2024 5:48 pm
Forum: General
Topic: TIP: Do not use rp-filter=Strict with Dual WAN policy-based routing [SOLVED]
Replies: 6
Views: 1180

Re: Policy-based routing with dual WAN [SOLVED]

I read your case. I figured it was something like... ;)

e.g. "strict" does seem like a good option, and no routing tables at that time.... And the dual WAN enough config, might think it was some firewall rule, etc. etc....
by Amm0
Sun Mar 24, 2024 5:43 pm
Forum: General
Topic: TIP: Do not use rp-filter=Strict with Dual WAN policy-based routing [SOLVED]
Replies: 6
Views: 1180

Re: Policy-based routing with dual WAN [SOLVED]

Yup rp-filter=strict would do that. I can see how that how an esoteric /ip/setting like rp-filter might NOT be the first thought. FWIW, "strict" shouldn't be the default... so someone changed rp-filter at some point. And docs the option: Warning: strict mode does not work with routing tabl...
by Amm0
Sun Mar 24, 2024 5:18 pm
Forum: Virtualization
Topic: Plan to port BTH to CHR?
Replies: 7
Views: 867

Re: Plan to port BTH to CHR?

Also, CHR+BTH is bit trickier since there is default config/firewall on CHR for BTH to know what to modify. With the default conf on ARM/etc., there is notion of LAN (bridge) and WAN (ether1)... same isn't true on CHR. Still it a good request. Since beyond just the proxy feature of BTH... BTH also h...
by Amm0
Sun Mar 24, 2024 4:47 pm
Forum: Virtualization
Topic: Plan to port BTH to CHR?
Replies: 7
Views: 867

Re: Plan to port BTH to CHR?

True. Unless OP needed the proxy features for restricted NAT from BTH... That's the main benefit of BTH... and as it's already emplemented on other platform, I was wondering if it is planed on CHR. That's all... :wink: You can file a feature request at help.mikrotik.com. I suspect part of the probl...
by Amm0
Sun Mar 24, 2024 2:58 pm
Forum: Scripting
Topic: fetch - how receive response code
Replies: 8
Views: 5157

Re: fetch - how receive response code

If the problem is a "wrong URL"... It's either the DNS could not be resolve OR TCP cannot connect to the IP resolved. AFAIK, nothing will tell you that specifically, just "failed" as status (although you can check DNS using ":resolve" before). But if HTTP is not success...
by Amm0
Sun Mar 24, 2024 2:45 pm
Forum: RouterBOARD hardware
Topic: Request for Python Script to Change L2TP Password in MikroTik Router
Replies: 4
Views: 436

Re: Request for Python Script to Change L2TP Password in MikroTik Router

Personally I would use the REST-API if possible. Then just use Python with requests module. For background, Mikrotik has several "APIs". The low-level one is what typically called "API", and there is a python module wrappers: https://help.mikrotik.com/docs/display/ROS/API#API-Ex...
by Amm0
Sun Mar 24, 2024 3:28 am
Forum: SwOS
Topic: Feature suggestion - FW Upgrade availability through SNMP
Replies: 2
Views: 385

Re: Feature suggestion - FW Upgrade availability through SNMP

I don't think there is anything in the MIB, other than current version. Often you can use HTTP to fetch the current version from a Mikrotik web service, and then have an alert/rule/etc in NMS that compares the result from HTTP with the SNMP version from device. While Mikrotik has URL to fetch the cu...
by Amm0
Sun Mar 24, 2024 3:12 am
Forum: Scripting
Topic: Startup settings (factory defaults)
Replies: 2
Views: 249

Re: Startup settings (factory defaults)

Just to be clear: If no one do a /system/reset-configuration or push-and-hold reset button, the config does stick around. All changes are automatically saved and used immediately. You only need netinstall or branding if your want to replace what's in "/system/default-configuration print" -...
by Amm0
Sun Mar 24, 2024 3:09 am
Forum: Scripting
Topic: Startup settings (factory defaults)
Replies: 2
Views: 249

Re: Startup settings (factory defaults)

The netinstall will do it via "-s myscript.rsc": https://help.mikrotik.com/docs/display/ROS/Netinstall#Netinstall-InstructionsforLinux You can also create a branding package, that includes the default script (as well as logos etc.). Branding creates a package, so you copy it and reboot, th...
by Amm0
Sat Mar 23, 2024 8:53 pm
Forum: Beginner Basics
Topic: How to configure LAN IP Pool
Replies: 9
Views: 3798

Re: How to configure LAN IP Pool

So do you also have two /30 and /29 [public?] subnets from your ISP? Likely better if you wrote up your problem in a new post. This "LAN IP Pool" is confusing term. When a customer does not have BGP, I've seen /30 used as route point at a customer site for any additional /29+ subnets assig...
by Amm0
Sat Mar 23, 2024 8:29 pm
Forum: The Dude
Topic: Read-only Dude access - how?
Replies: 7
Views: 863

Re: Read-only Dude access - how?

Hi Amm0. To clarify, I meant that the Winbox tool specifically has been removed from Tools in the newer Dude client versions, not that the whole tool list has been removed. That makes more sense. To the original question is you'd have to make sure NOTHING uses "[Device.Password]". And a &...
by Amm0
Sat Mar 23, 2024 7:15 pm
Forum: Containers
Topic: Homeassistant as container and homekitbridge setup
Replies: 14
Views: 1175

Re: Homeassistant as container and homekitbridge setup

You can use multiple IP addresses, true.

But they are still in same VLAN/bridge as the VETH is using. So it's NOT a way to get into multiple Layer2 VLANs.
by Amm0
Sat Mar 23, 2024 6:59 pm
Forum: Virtualization
Topic: Plan to port BTH to CHR?
Replies: 7
Views: 867

Re: Plan to port BTH to CHR?

True. Unless OP needed the proxy features for restricted NAT from BTH...
by Amm0
Sat Mar 23, 2024 5:15 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

While I have confidence Mikrotik will figure out something for 16MB in 7.15 to improve the situation.... The open question, and worry, is 7.16, 7.17, etc. If all new features/fix go to the main package, we'll be in the same boat again soon. And there does not seem to be a plan to deal with that.
by Amm0
Sat Mar 23, 2024 4:37 pm
Forum: Scripting
Topic: Isolate a value from a console output [SOLVED]
Replies: 25
Views: 2181

Re: Isolate a value from a console output [SOLVED]

And I'm pretty sure that $ifadd is one address (with or without "/n") so no nil or str is returned, but one ip ... In your function, sure. My quick function example, no. My point was that on-error={} offers a false sense of security – since there are a lot of oddities in scripting. And a ...
by Amm0
Sat Mar 23, 2024 3:45 pm
Forum: Scripting
Topic: Isolate a value from a console output [SOLVED]
Replies: 25
Views: 2181

Re: Isolate a value from a console output [SOLVED]

It's that debugging later can be tricky. So you have to picky at the source. How anal you want to be is up to you. e.g. If your replacing the defconf, one error in a script, and the router won't work. For example on scripting pickyness, you'll note the need parse the prefix part using :find and :pic...
by Amm0
Sat Mar 23, 2024 3:17 pm
Forum: Scripting
Topic: Isolate a value from a console output [SOLVED]
Replies: 25
Views: 2181

Re: Isolate a value from a console output [SOLVED]

Good example @rextended. Why I'm always pitching functions since you can hide all the checks inside so you don't need repeat elsewhere. I'm not as adverse to on-error={} as @rextended BUT it is tricky... & in most cases your better off just letting things fail, or specifically checking every ste...
by Amm0
Sat Mar 23, 2024 2:54 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

It simply means that when these ARM devices were designed and released, such package did not exist yet. Fair enough. Y'all never marketed them as Wi-Fi 6. A lot of vendors would just tell folks to upgrade. But a lot of the great flexibility is lost when you cannot remove unneeded features & bro...
by Amm0
Sat Mar 23, 2024 2:38 am
Forum: Scripting
Topic: Isolate a value from a console output [SOLVED]
Replies: 25
Views: 2181

Re: Isolate a value from a console output [SOLVED]

Yup. :error will stop the script, and print message to the CLI/console. While the /log handles the case if same script run in background. So that combo covers both CLI and /system/script. But often it better to just add some more :if (error-condition) do={:error ...} checks along the way. And if som...
by Amm0
Sat Mar 23, 2024 1:19 am
Forum: The Dude
Topic: Read-only Dude access - how?
Replies: 7
Views: 863

Re: Read-only Dude access - how?

Did not mean to be confusing. While no user can view the password on from the Device dialog box. And you're likely right that the "writable" RouterOS stuff for a Device, use the logged in user. I think OP's point is Dude uses variables in various points, including Tools, but elsewhere too....
by Amm0
Fri Mar 22, 2024 10:38 pm
Forum: Scripting
Topic: Isolate a value from a console output [SOLVED]
Replies: 25
Views: 2181

Re: Isolate a value from a console output [SOLVED]

Sure, that kinda more what's the :do is used for. And, above code could fail, if an interface= had multiple IP address associated with it (e.g. "multihoming"). But.... it's often's better if a script fails immediately, than "catching" the on-error=. If something else further need...
by Amm0
Fri Mar 22, 2024 8:22 pm
Forum: The Dude
Topic: Read-only Dude access - how?
Replies: 7
Views: 863

Re: Read-only Dude access - how?

Well removing the Tool is one approach, but doesn't really solve the undesired privilege escallation. It's still a variable in the system... About only thing you can do is ALSO use a read-only account on the devices being monitored. So Dude itself does not have write access, thus when password is &q...
by Amm0
Fri Mar 22, 2024 6:52 pm
Forum: Scripting
Topic: Isolate a value from a console output [SOLVED]
Replies: 25
Views: 2181

Re: Isolate a value from a console output [SOLVED]

You can also make it a function, if you need to do for a multiple items: :global getInterfaceIP do={ :local currentIPv4 [/ip address get [find interface~$1] address] :return [:pick $currentIPv4 0 [:find $currentIPv4 "/" -1]] } :put [$getInterfaceIP ether1] Dorky side note: RouterOS has typ...
by Amm0
Fri Mar 22, 2024 6:40 pm
Forum: Scripting
Topic: Isolate a value from a console output [SOLVED]
Replies: 25
Views: 2181

Re: Isolate a value from a console output [SOLVED]

where you get the useless do {} and the other frills?????????? In a script, do you think I could drop the "do"? Yes. Harmless, but unnecessary. Since :do { ... } is do'ing nothing. e.g. this is identical in function: {:set currentIPv4 ([/ip address/get [find interface=$wanInt] address]); ...
by Amm0
Fri Mar 22, 2024 6:25 pm
Forum: RouterBOARD hardware
Topic: Pure ROS boot...
Replies: 29
Views: 1482

Re: Pure ROS boot...

True, lots of way to have a broken router with unauthorized physical access (e.g. a hammer also disable it).... But the requirement is it has a unique password, and after a reset, it still does. It's also inconvenient that Wi-Fi antennas use RP-SMA, but that's also the law. e.g. US FCC did not want ...
by Amm0
Fri Mar 22, 2024 4:59 pm
Forum: Scripting
Topic: Isolate a value from a console output [SOLVED]
Replies: 25
Views: 2181

Re: Isolate a value from a console output [SOLVED]

[:find $wfaddress "/" -1]
vs
([:len $currentIPv4] - 3)
by Amm0
Fri Mar 22, 2024 4:50 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

Different topic. I noticed you added Dante QoS support "in 7.15": https://help.mikrotik.com/docs/pages/viewpage.action?pageId=189497483#QualityofService(QoS)-Dante Starting from RouterOS v7.15, all MikroTik QoS-Capable devices comply with Dante. I'm just not sure what changed, since AFAIK ...
by Amm0
Fri Mar 22, 2024 4:42 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

Package size issue is being addressed! Please wait for the rc releases at least. There is no need for flooding this topic just regarding this issue. Both @strods and @normis have acknowledged the problem... Let's give them time to come up with something. Personally, getting older routers to 7.12.1 ...
by Amm0
Fri Mar 22, 2024 4:18 pm
Forum: RouterBOARD hardware
Topic: Pure ROS boot...
Replies: 29
Views: 1482

Re: Pure ROS boot...

No one is assuming anyone is an idiot. Various government are making judgement about what's best for "users". Get the default passwords threw a wrench in your current workflow. But I'd bet – even with sticker/password – someone can login and reset-configuration quicker than waiting 2 minut...
by Amm0
Fri Mar 22, 2024 7:38 am
Forum: General
Topic: UPnP won't work after literal hours of trying - help pls!
Replies: 12
Views: 661

Re: UPnP won't work after literal hours of trying - help pls!

The application/game controls how often it calls uPnP. And may not use uPnP if the random port assignment was acceptable on far-end, or have a low update interval. Possible there is bug/logic error in how uPnP works specifically on RouterOS with some application(s). Hard one to troubleshoot. About o...
by Amm0
Fri Mar 22, 2024 3:40 am
Forum: Containers
Topic: Homeassistant as container and homekitbridge setup
Replies: 14
Views: 1175

Re: Homeassistant as container and homekitbridge setup

Both @tangent and I, both wondered why Mikrotik always shows a separate bridge. @tangent write this up here: Put the VETH on the bridge . On this one... a) would this type of configuration be applicable even for rb450gx4 ? (Reason i ask is remember reading in manual not to use bridge vlan filtering ...
by Amm0
Fri Mar 22, 2024 3:04 am
Forum: Virtualization
Topic: interface names and numbering
Replies: 2
Views: 4482

Re: interface names and numbering

So are you using CHR on ESXi & trying to rename an interface, and that's not working?
by Amm0
Fri Mar 22, 2024 1:05 am
Forum: General
Topic: A faster way to import configuration? [SOLVED]
Replies: 2
Views: 1425

Re: A faster way to import configuration? [SOLVED]

I think it's important to note the ":export" is more a script to create a config, than the actual config. And, in scripting, you cannot "add" something if it already exists. So if you have some default config, then do an :import config-from-other-router.rsc, it will conflict with...
by Amm0
Thu Mar 21, 2024 11:50 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

... is necessary to have QCA9984 which is only for RB4011iGS+5HacQ2HnD-IN ... ... and for RBD25G-5HPacQD2HPnD (Audience). Admittedly Audience has flash larger than 16MB as well. with an footnote on RB4011i, that new wifi-qcom-ac only helps with 5Ghz, and the driver does not work for 2.4Ghz AFAIK......
by Amm0
Thu Mar 21, 2024 10:34 pm
Forum: General
Topic: Feature Suggestion: GARP/GVRP
Replies: 9
Views: 7752

Re: Feature Suggestion: GARP/GVRP

Well, for some it appears an ~18 years wait, but:
What's new in 7.15beta8 (2024-Mar-21 09:12):

*) bridge - added MVRP support;
by Amm0
Thu Mar 21, 2024 10:08 pm
Forum: General
Topic: MultiWAN + LAN through vlans [SOLVED]
Replies: 16
Views: 2332

Re: MultiWAN + LAN through vlans [SOLVED]

about two switch chip on 4011 - currently its very difficult question for me. And I will return to it (or not) after full setup and look at CPU utilization. Depending on how you're using the ports on the RB4011.... But if you can use two bridges, one with the ether1-5, other with ether6-10, and you...
by Amm0
Thu Mar 21, 2024 7:34 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

Update to 7.15beta8 fails on wAP AC with error: upgrade failed, free 133kB disk space for a(null)upgrade Even if MT has reduced size on latest version, your older version are to big to upgrade. Netinstall may be the only way out. Or, just use ethernet (or a VPN) to connect to router from desktop, a...
by Amm0
Thu Mar 21, 2024 6:12 pm
Forum: Containers
Topic: Homeassistant as container and homekitbridge setup
Replies: 14
Views: 1175

Re: Homeassistant as container and homekitbridge setup

have requested support to provide sample configuration for vlan aware veth ports in a single bridge configuration with multiple vlans (from homeautomation perspective even the matter server is expected to be on same network as ha/devices) I be curious what they say. Since the example in docs likely...
by Amm0
Thu Mar 21, 2024 5:54 pm
Forum: Containers
Topic: Homeassistant as container and homekitbridge setup
Replies: 14
Views: 1175

Re: Homeassistant as container and homekitbridge setup

1. Yes, if using the "/interface/ethernet/swtich" way of configuration VLANs, you cannot "bridge" the VETH. You need to use the "Bridge VLAN Filter" method for VLANs. And, also correct, on some devices using the bridge vlan filtering will lose hardware offloading. But o...
by Amm0
Thu Mar 21, 2024 7:41 am
Forum: Containers
Topic: Homeassistant as container and homekitbridge setup
Replies: 14
Views: 1175

Re: Homeassistant as container and homekitbridge setup

Indeed, we have a nearly-opposite statement in the first caution box in the MACVLAN section of the docs . LOL. @tangent, You're the one who pointed out RouterOS MACVLAN !== Docker MACVLAN a while back: https://forum.mikrotik.com/viewtopic.php?t=198122&hilit=VETH#p1021128 It's possible they clar...
by Amm0
Thu Mar 21, 2024 7:28 am
Forum: Containers
Topic: Homeassistant as container and homekitbridge setup
Replies: 14
Views: 1175

Re: Homeassistant as container and homekitbridge setup

You can treat VETH the same as a ether1 etc ports. So it can use in your "main" (or only) bridge, and using vlan-filtering=yes. Possible to make a trunk (e.g. /interface/bridge/vlans as a tagged=), or, an access or hybrid port by setting a PVID etc. The same as any other ethernet port livi...
by Amm0
Thu Mar 21, 2024 3:45 am
Forum: General
Topic: Wireguard from MT to client (win10) with several users to several VLAN's [SOLVED]
Replies: 38
Views: 3972

Re: Wireguard from MT to client (win10) with several users to several VLAN's [SOLVED]

Is it too much to help me out on that config for CRS112? It should be work documented, which is similar to CRS3xx, but slightly different. Now all CRSxxx VLAN config is way different than using bridge on the hAP/cAP/RB5009/etc for VLANs... But if you're testing this in EVE... it may be EVE support ...
by Amm0
Thu Mar 21, 2024 12:30 am
Forum: Forwarding Protocols
Topic: Documentation on ROS v7 Routing Select Rules?
Replies: 3
Views: 441

Re: Documentation on ROS v7 Routing Select Rules?

Well, you kinda need to be using some dynamic routing protocol like BGP/OSPF/RIP — but details like how any rule is invoked is missing as a starting point in the docs. Specifically both the rule and select-rule are invoked via the BGP/OSPF/RIP configuration. Standing alone /routing/filter do nothing...
by Amm0
Wed Mar 20, 2024 10:25 pm
Forum: General
Topic: Configuration for hidden ZeroTier features
Replies: 9
Views: 608

Re: Configuration for hidden ZeroTier features

Since the client is so small (less than 10 MB), it's possible it would fit even on smaller devices.
Or move the ZT client part into the main package, and leave the controller bit as zerotier.npk.

I do use zerotier.npk on these 16MB devices today...
by Amm0
Wed Mar 20, 2024 10:15 pm
Forum: General
Topic: Configuration for hidden ZeroTier features
Replies: 9
Views: 608

Re: Configuration for hidden ZeroTier features

I read the docs today since it's been a while. Seem even ZeroTier themselves gave up trying to map the JSON to the CLI: Currently most configuration is handled via manual editing of each node's local.conf. There are only a few available CLI commands. (https://docs.zerotier.com/multipath#using-the-cl...
by Amm0
Wed Mar 20, 2024 9:48 pm
Forum: General
Topic: Configuration for hidden ZeroTier features
Replies: 9
Views: 608

Re: Configuration for hidden ZeroTier features

The ZeroTier client library itself is very small and accessible using a single API. The idea to have some override to use a "real" ZT configuration file might be a reasonable solution. I wasn't a fan of this before — be "ugly" IMO as I'm more puritan there is ONE unified config ...
by Amm0
Wed Mar 20, 2024 9:36 pm
Forum: General
Topic: Configuration for hidden ZeroTier features
Replies: 9
Views: 608

Re: Configuration for hidden ZeroTier features

I'd pay to unlock them, unfortunately that not how it works here ;). Well, I would also call those options hidden since they all are a part of the current ZeroTier version included with RouterOS which simply lacks the ability to configure them. LOL. In fairness they do have to map all the options to...
by Amm0
Wed Mar 20, 2024 8:19 pm
Forum: General
Topic: Use Mikrotik's HotSpot solution to unblock Wireguard???
Replies: 24
Views: 1738

Re: Use Mikrotik's HotSpot solution to unblock Wireguard???

Very well stated. If we're covering risks... I'd add that nothing stops Mikrotik from changing how /ip/hotspot works internally – it very well may not relay on specific firewall extensions in future. But I get the problem here. There is some "missing middle-ground" between Tailscale & ...
by Amm0
Wed Mar 20, 2024 7:38 pm
Forum: General
Topic: REQUEST: Paid technical support plans
Replies: 16
Views: 866

Re: REQUEST: Paid technical support plans

Considering the same folks that do YouTube videos also answer tickets, we're not dealing with cisco here... And I like the Latvian sardonic charm :). I do get OP's problem. You can certainly hire a consultant to help setup a system. But issue is a consultant cannot guarantee future support of anythi...
by Amm0
Wed Mar 20, 2024 5:25 am
Forum: Scripting
Topic: Isolate a value from a console output [SOLVED]
Replies: 25
Views: 2181

Re: Isolate a value from a console output [SOLVED]

Is there a regex function? In the "find", "print where", or in an :if like statement you can use the tilde to match a variable or attribute against a regex: attribute~".*" Only boolean matches and no grouping or replacement however. So in the find shown above, you coul...
by Amm0
Wed Mar 20, 2024 5:21 am
Forum: Scripting
Topic: Isolate a value from a console output [SOLVED]
Replies: 25
Views: 2181

Re: Isolate a value from a console output [SOLVED]

If you want to store it a variable it looks like: :global wanIP [/ip/address get [find interface=ether1_WAN] address] You can then use that variable in future command. To output it, it's just: :put $wanIP Or, in a string like :put "my WAN IP is $wanIP" Alternatively, if you using DDNS in I...
by Amm0
Wed Mar 20, 2024 2:39 am
Forum: General
Topic: [Solved] Cannot use LTE without doing outbound traffic first on WAP R AC
Replies: 12
Views: 725

Re: Cannot use LTE without doing outbound traffic first on WAP R AC

The OP is using just "route failover". But to allow incoming traffic on the "backup" / inactive LTE route, you need to follow the "Failover with Firewall Marking" approach: https://help.mikrotik.com/docs/display/ROS/Firewall+Marking#FirewallMarking-FailoverWithFirewallM...
by Amm0
Wed Mar 20, 2024 2:15 am
Forum: Scripting
Topic: SMS forward
Replies: 2
Views: 511

Re: SMS forward

I dunno @eworm's internals, but $Message is going to be resolve when the global is declared, so it may not be valid for substitution. Or if allowed, the $Message have to be escaped, like \$Message so it can be [:parse ...] later. :global SmsForwardHooks { { match="ok"; allowed-number="...
by Amm0
Wed Mar 20, 2024 1:47 am
Forum: General
Topic: Network discovery over wireguard
Replies: 33
Views: 4439

Re: Network discovery over wireguard

There isn't some magic setting for that makes this easy ;). Config help to see where you got here, but it a lot of step to enable "discovery over WG"... The critical step is the bridge filter rules to restrict the bridged EoIP traffic to just multicast stuff like SSDP, mDNS, etc. What you ...
by Amm0
Wed Mar 20, 2024 12:40 am
Forum: General
Topic: Network discovery over wireguard
Replies: 33
Views: 4439

Re: Network discovery over wireguard

I still don't quite understand the difference between mDNS and SSDP I think I need both.. While not exact: Apple thing always use mDNS, Printers also use mDNS, but Google/Security Cams/VoIP more typically use SSDP. TVs generally do both. Reason why it's relevant is mDNS requires some specific trick...
by Amm0
Wed Mar 20, 2024 12:21 am
Forum: General
Topic: Use Mikrotik's HotSpot solution to unblock Wireguard???
Replies: 24
Views: 1738

Re: Use Mikrotik's HotSpot solution to unblock Wireguard???

@Larsa makes good points. And disclaimer: I use ZeroTier myself because all the WG key deployment stuff is so manual. But, I get the desire to avoid needing to use some SD-WAN SaaS/cloud thing. And I do like the concept here as a "DIY two factor auth" for WG peers. But...I still think Mikr...
by Amm0
Tue Mar 19, 2024 10:15 pm
Forum: Beginner Basics
Topic: AT&T FTTH, VLANs, CapsMAN Full Config
Replies: 20
Views: 4704

Re: AT&T FTTH, VLANs, CapsMAN Full Config

I recall from @pcunite's thread on AT&T FTTH that V7 worked with the 802.1x stuff. On the AT&T front with the RB5009... the mystery is there some GPON SFP that can replace the AT&T one. But... it's the CAPsMAN stuff where your decisions get tougher. You can keep APs at V6 and use RB5009 ...
by Amm0
Tue Mar 19, 2024 7:45 pm
Forum: General
Topic: Network discovery over wireguard
Replies: 33
Views: 4439

Re: Network discovery over wireguard

I was looking into WINS Microsoft recommends avoiding and decomissioning WINS servers for DNS now: Yes WINS is old, very old, just as I am, and as is NBT (Netbios over TCP). Well the even older NB F (NetBEUI) come up the other day (https://forum.mikrotik.com/viewtopic.php?t=205901). I was left wond...
by Amm0
Tue Mar 19, 2024 7:13 pm
Forum: General
Topic: UPnP won't work after literal hours of trying - help pls!
Replies: 12
Views: 661

Re: UPnP won't work after literal hours of trying - help pls!

So AMMO, reading the needle in the haystack are you saying, the OP should not use UPNP but should be using nat-pmp?? https://help.mikrotik.com/docs/display/ROS/NAT-PMP Likely not. See while NAT-PMP is an RFC, it's more an Apple thing. So it's mainly Bonjour (e.g. DNS-SD part of "mDNS") wi...
by Amm0
Tue Mar 19, 2024 7:04 pm
Forum: General
Topic: UPnP won't work after literal hours of trying - help pls!
Replies: 12
Views: 661

Re: UPnP won't work after literal hours of trying - help pls!

Are there still programs in 2024 requiring UPNP??? Well, ZeroTier will use uPnP to determine its paths too. And importantly most modern VoIP things follow the ICE RFC scheme, so not just games. While uPnP is not an RFC (NAT-PMP or PCP are the RFC-way), a lot of VoIP/video things will try uPnP to de...
by Amm0
Tue Mar 19, 2024 6:11 pm
Forum: General
Topic: Use Mikrotik's HotSpot solution to unblock Wireguard???
Replies: 24
Views: 1738

Re: Use Mikrotik's HotSpot solution to unblock Wireguard???

Re the netmap rule not working... I had CHR open, so added hotspot to look at the rules hotspot generates more. So yeah the netmap isn't triggering the various rule "hotspot=!auth,from-client action=jump jump-target=hs-unauth" need to steer traffic. So those WG peer IP getting netmap'ed d...
by Amm0
Tue Mar 19, 2024 5:51 pm
Forum: General
Topic: Use Mikrotik's HotSpot solution to unblock Wireguard???
Replies: 24
Views: 1738

Re: Use Mikrotik's HotSpot solution to unblock Wireguard???

[...] Unfortunately, I can still access the Mikrotik's WebIF when I type access.local in the browser. In other words, the hotspot “doesn’t show itself”. [...] So Mikrotik probably doesn't want to make it that easy for us 8) maybe there's something wrong with my netmap rules? No doubt. The netmap ma...
by Amm0
Tue Mar 19, 2024 5:12 pm
Forum: RouterBOARD hardware
Topic: Running out of space on 16MB RouterBOARDs
Replies: 38
Views: 7598

Re: Running out of space on 16MB RouterBOARDs

Our team of experts is working on this issue at this very moment.
Thanks for the update. I know it's not an easy problem to "just fix". But the 16MB problem has been on a slow simmer for "some time" ;).
by Amm0
Tue Mar 19, 2024 4:30 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

Similar screen is on UTM, but WinBox discovered the IP and I was able to login. Yes, I can access it through winbox too. But not through the screen. It always says the service is starting. True, but it will say "Service stopping" if STOP is request by QEMU host as an added detail here. Bu...
by Amm0
Mon Mar 18, 2024 10:44 pm
Forum: General
Topic: A strange day - VRRP/Wireguard
Replies: 5
Views: 429

Re: A strange day - VRRP/Wireguard

Since you might have traffic using VRRP IP over WG, you cannot just add a /routing/rule to drop it - which was my original thought. So.... a separate VPN router seems like a good call. That simply thinking about the WG interactions with VRRP if they are NOT on same router. e.g. You need to do a lot ...
by Amm0
Mon Mar 18, 2024 8:21 pm
Forum: General
Topic: GUIDE: Running Netinstall Server on a Tik
Replies: 53
Views: 4879

Re: GUIDE: Running Netinstall Server on a Tik

More I do know the QEMU emulation approach works on RB1100AHx4, I'm curious though.. When was it needed? Surely you are not doing this using your mobile phone to send the commands to the working router? I never used to run netinstall until recently. I recall only ONE issue MANY years ago where that...
by Amm0
Mon Mar 18, 2024 7:49 pm
Forum: General
Topic: v7.15beta broke backup file naming
Replies: 46
Views: 3094

Re: v7.15beta broke backup file naming

@Larsa I have not addressed any question towards you. Why does it matter what the OP's reason? Maybe his boss likes seeing friendly names in a folder, or he inherited the script.... If it's the backup system has rules using file names, that also have to change to any retention/etc rules as well – r...
by Amm0
Mon Mar 18, 2024 5:30 pm
Forum: General
Topic: GUIDE: Running Netinstall Server on a Tik
Replies: 53
Views: 4879

Re: GUIDE: Running Netinstall Server on a Tik

As for the official netinstall application, it has been my experience that not all versions work properly/correctly anyways. Oh that's true, but not common (but has happened once to me). Here that be solvable by changing the ARG for NET_VERSION and re-building to get a older/newer netinstall as nee...
by Amm0
Mon Mar 18, 2024 4:33 pm
Forum: General
Topic: GUIDE: Running Netinstall Server on a Tik
Replies: 53
Views: 4879

Re: GUIDE: Running Netinstall Server on a Tik

Leave it like it is please. Wouldn't something pynetinstall work a lot better? No need for x86 emulation I'm not sure about that. While X86 emulation has some cost, using the "real" netinstall from Mikrotik has some benefits. Since pynetinstall reverse-engineered netinstall's protocol, if...
by Amm0
Mon Mar 18, 2024 4:41 am
Forum: General
Topic: A strange day - VRRP/Wireguard
Replies: 5
Views: 429

Re: A strange day - VRRP/Wireguard

Quite the tale. So you have a WAN with some subnet of public IP, 10 WG tunnels, EoIP using WG peers. No BGP? e.g. just a subnet of public IPv4 on some bridge & using VRRP to potentially move one/more to another router on same "WAN bridge"? And all was working until you added a VRRP to ...
by Amm0
Mon Mar 18, 2024 1:12 am
Forum: Scripting
Topic: Writing to external MySql database
Replies: 2
Views: 262

Re: Writing to external MySql database

You're kinda reinventing the wheel. Lot of existing packages/software already does roughly this. Is this possible? Or do I have to keep sending emails? Or is there another indirect way or writing events to an external database like json, http or rest? Kinda. /tool/fetch url=... on RouterOS can work,...
by Amm0
Mon Mar 18, 2024 12:34 am
Forum: General
Topic: A call for a "lite" version of routeros 7 (image size reduction)
Replies: 22
Views: 1541

Re: A call for a "lite" version of routeros 7 (image size reduction)

Now..... I can only laugh at how some theorized "Lite Version" play out. e.g. @normis "Hey we solved the 16MB flash issue that we created for you!" How? : "Simple, re-write in Rust and cut half the features" When? : "Soon! But in Latvia...soon means years." Wh...
by Amm0
Mon Mar 18, 2024 12:31 am
Forum: General
Topic: A call for a "lite" version of routeros 7 (image size reduction)
Replies: 22
Views: 1541

Re: A call for a "lite" version of routeros 7 (image size reduction)

but there will be duplication of the common data between the packages. [...] The only feasible way left (short of inventing a new type of compressed file system images that can mount over each other - and that would be a waste of effort) to reduce size is to reduce features, there is just too much ...
by Amm0
Sun Mar 17, 2024 10:30 pm
Forum: Beginner Basics
Topic: NetBEUI over EOIP
Replies: 2
Views: 270

Re: NetBEUI over EOIP

Oh geez, NetBEUI (NetBIOS Extended User Interface). It was the MS(/IBM) LAN Manager protocol. If you used Windows for Workgroups 3.11, it was used for networking (before a TCP/IP stack was added later). But yes, EoIP should work. It's a layer-2 protocol. You may need to set MTU to 1500 on EoIP – the...
by Amm0
Sun Mar 17, 2024 6:13 pm
Forum: General
Topic: v7.15beta broke backup file naming
Replies: 46
Views: 3094

Re: v7.15beta broke backup file naming

Guys, we have rights to complain but I doubt they will revert the change and allow spaces in identity. I'd think there is some "space" for debate on file names. ;). In 7.15beta6, /system/identity allows spaces and most things — so not sure issue with identity. So, what are the characters ...
by Amm0
Sun Mar 17, 2024 4:44 pm
Forum: General
Topic: A call for a "lite" version of routeros 7 (image size reduction)
Replies: 22
Views: 1541

Re: A call for a "lite" version of routeros 7 (image size reduction)

Current (and likely future) devices already have more flash space... except for some pure switches, were it is not required so much. That's not really true. I mainly use MT's LTE routers & there are NO options >16MB flash. Labor cost more than the hardware in my case, so rather replace the rout...
by Amm0
Sat Mar 16, 2024 9:44 pm
Forum: Virtualization
Topic: CHR license warning
Replies: 25
Views: 4851

Re: CHR license warning

maybe I'm blind, can't see anything license related in the winbox title bar
He sees in the future. Hopefully.
I don't see anything in title bar either, at least in winbox v3.40.
by Amm0
Sat Mar 16, 2024 5:36 pm
Forum: Beginner Basics
Topic: QoS on hAP ax lite
Replies: 4
Views: 397

Re: QoS on hAP ax lite

Question is, if you really want QoS based on individual ports and connections, because it's possible to QoS all the traffic. I believe the idea here is the audio should get priority , not ONLY trying to prevent bufferbloat more generally I'll quote @pcunite : There seems to be some confusion here a...
by Amm0
Fri Mar 15, 2024 11:47 pm
Forum: Scripting
Topic: Delete all connection in Firewall-Connections
Replies: 15
Views: 20230

Re: Delete all connection in Firewall-Connections

The above will run even without making sure any 10 or 15 or 30 or 60...
If you remove the (timeout>60) matcher in @rextended version, it should still work against all records. The "where" still has something to do e.g. [:remove $".id"], even without matchers.
by Amm0
Fri Mar 15, 2024 11:33 pm
Forum: Scripting
Topic: Delete all connection in Firewall-Connections
Replies: 15
Views: 20230

Re: Delete all connection in Firewall-Connections

Geez.... This is like a compare-and-contrast in functional and procedural programming. But if we're voting... @rextended's very clear winner. @elico's version is fine if he likes that style. But it's just not efficient or clean if we're voting ;). Some nits however 1- Now on-error= to protect the [r...
by Amm0
Fri Mar 15, 2024 10:39 pm
Forum: Beginner Basics
Topic: LTE6 and EE having issues? Anyone else, no LTE for 3 days now and no one can seem to solve it.
Replies: 7
Views: 653

Re: LTE6 and EE having issues? Anyone else, no LTE for 3 days now and no one can seem to solve it.

Yeah there have been a few different things that have come up with EE from reading the forum. Curious if you need to do anything with APN, or was the default with "Use Network APN" checked enough for it to work (along with the modem firmware upgrade)? Might be helpful to others in future w...
by Amm0
Fri Mar 15, 2024 10:34 pm
Forum: Scripting
Topic: CURL command for disable a nat rule
Replies: 2
Views: 489

Re: CURL command for disable a nat rule

The issue is from `curl`, it needs to find the item. That requires using .query syntax in the REST API, see here for some examples: viewtopic.php?t=204028&hilit=query
by Amm0
Fri Mar 15, 2024 10:29 pm
Forum: RouterOS beta
Topic: ZeroTier added to RouterOS v7.1rc2
Replies: 335
Views: 309601

Re: ZeroTier added to RouterOS v7.1rc2

Netinstall may clear out internal space just enough but possibly next upgrade you will be stuck again. I think wireless.npk is a bit safer - but still may not fit in various beta and/or too much fragmentation/bad sectors. Using both wifi-qcom-ac and zerotier, at this point, is VERY risky for upgrad...
by Amm0
Fri Mar 15, 2024 8:48 pm
Forum: Beginner Basics
Topic: Load Balance for LAN
Replies: 13
Views: 737

Re: Load Balance for LAN

Zing over my head, what is the OP trying to do..... thats not available in queues, for example. I think you have a mental block any time "/container" get mentioned. ;). We kinda don't know what protocol's those VM servers are using – that the key detail to know here. But, generally speaki...
by Amm0
Fri Mar 15, 2024 8:28 pm
Forum: Scripting
Topic: simple double if / else error [SOLVED]
Replies: 11
Views: 2067

Re: simple double if / else error [SOLVED]

but it seems OK to me :local var [:put <etc>] is like correct???? LOL – I thought the same thing. While not a "scripting best practice" for sure, but :put should still return "true", as a string type . And OP has string "true" matchers already, not just a boolean =true...
by Amm0
Fri Mar 15, 2024 7:55 pm
Forum: Beginner Basics
Topic: Cross VLAN Multicast / PIM Config
Replies: 30
Views: 7373

Re: Cross VLAN Multicast / PIM Config

(2) replace the mDNS with a functioning PIM-SM configuration like DarkNate posted -- will this work with a native vlan and VLAN20/VLAN30 setup? What do I put in the source-address IP entries in that example? The receiver device IPs? I believe PIM-SM follows the RFCs, so the link-local 224.0.0.51/24...
by Amm0
Fri Mar 15, 2024 7:28 pm
Forum: Beginner Basics
Topic: Load Balance for LAN
Replies: 13
Views: 737

Re: Load Balance for LAN

It does seem like a case for a web proxy. HAProxy is great, I'd also suggest that either caddyserver or Traefik in a container might be better approach here since those are bit simplier than HAProxy. If you search for forum for either, you'll see how to do it on RouterOS. You also run any of these r...
by Amm0
Fri Mar 15, 2024 7:13 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

One tip to avoid speculation on the internal algo of adlist, is the [:time command={}] which can time things on RouterOS. Only did some quick tests using list from GH in docs, seems being found in adlist is quicker than the network time to resolve someone not on the list (over fiber to 1.1.1.1): :pu...
by Amm0
Fri Mar 15, 2024 5:41 pm
Forum: Scripting
Topic: $ROKU, the missing Roku TV remote for RouterOS
Replies: 4
Views: 1575

Re: $ROKU, the missing Roku TV remote for RouterOS

It works with anything that runs "Roku OS", a lot of TV have Roku built-in but the Roku sticks would also work. But it's not a universal remote ;) Since it uses IP directly to the TV, it does not actually involve the remote control. It uses a REST API on the TV to send the commands. So on ...
by Amm0
Fri Mar 15, 2024 2:30 pm
Forum: Beginner Basics
Topic: LTE6 and EE having issues? Anyone else, no LTE for 3 days now and no one can seem to solve it.
Replies: 7
Views: 653

Re: LTE6 and EE having issues? Anyone else, no LTE for 3 days now and no one can seem to solve it.

I doubt it's IPv6 only, but suspect that's related. One thing to try is change the "IP Type" in the APN profile (under Interface > LTE APNs > default) from "auto" to "IPv4". Quick google suggest more may need in the APN for EE (https://community.ee.co.uk/t5/Mobile-Data/...
by Amm0
Fri Mar 15, 2024 7:11 am
Forum: General
Topic: GUIDE: Running Netinstall Server on a Tik
Replies: 53
Views: 4879

Re: GUIDE: Running Netinstall Server on a Tik

; I have no desire to take over this container's maintenance Now I do think you can use the container as-is if you do something like this: /container env set key=NETINSTALL_NPK name=netinstall value="routeros-7.15beta6-arm.npk /app/images/zerotier-arm-7.15beta6.npk /app/images/wifi-qcom-ac-7.1...
by Amm0
Fri Mar 15, 2024 7:00 am
Forum: General
Topic: GUIDE: Running Netinstall Server on a Tik
Replies: 53
Views: 4879

Re: GUIDE: Running Netinstall Server on a Tik

rebuilt this container along the glob pattern scheme I suggest, since ROS 7 does seem to be increasingly broken back up again. Yeah, the multiple package is a problem in publish image, esp after the "wireless split". I use this container, so approach with QEMU is great and works fine on A...
by Amm0
Fri Mar 15, 2024 5:36 am
Forum: General
Topic: GUIDE: Running Netinstall Server on a Tik
Replies: 53
Views: 4879

Re: GUIDE: Running Netinstall Server on a Tik

Simply adding both files with a space (there it is again :o ) in ENV doesn't work. Assuming the extra-package or wifi-qcom-* are in /app/images... You should be able to cheat with a space, but you'd need the full path. so NETINSTALL_NPK = routeros-arm-7.15beta6.npk /app/images/wifi-qcom....npk The ...
by Amm0
Fri Mar 15, 2024 4:32 am
Forum: Scripting
Topic: $ROKU, the missing Roku TV remote for RouterOS
Replies: 4
Views: 1575

Re: $ROKU, the missing Roku TV remote for RouterOS

I still use it, so it works. LMK if you run into trouble. You need to either add static DNS for "roku" or use the following to set the Roku's IP address to control: $ROKU set ip=192.168.88.249 If you run "$ROKU remote", it uses the VI-keys to navigate menus . When in the remote, ...
by Amm0
Fri Mar 15, 2024 4:23 am
Forum: General
Topic: v7.15beta broke backup file naming
Replies: 46
Views: 3094

Re: v7.15beta broke backup file naming

as this is likely going to go nowhere, i guess i'l just have to fix this on a per device basis as i update them. I can see being annoyed. But likely right call. I'm with @Larsa, these breaking changes should not be handled so cavalier. I still like to know the rational here... and/or some list of w...
by Amm0
Thu Mar 14, 2024 9:05 pm
Forum: General
Topic: CCR with a embedded LTE modem?
Replies: 6
Views: 373

Re: CCR with a embedded LTE modem?

My question is "there anything in the product line coming with a embedded LTE modem in the CCR" I doubt it. Although they should, most MT LTE devices are 16MB with limit CPUs. A CCR with multiple LTE modems be more interesting, since with 4x4 MIMO/5G there are lot of antenna ports. While ...
by Amm0
Thu Mar 14, 2024 5:45 pm
Forum: General
Topic: v7.15beta broke backup file naming
Replies: 46
Views: 3094

Re: v7.15beta broke backup file naming

To @mrz's point...certainly avoiding any even-close-to-special file names that have to go between system, or in scripts, should be a best practice. And, Mikrotik restricting at creation might prevent also sorts of corner-cases and avoids needing to consider encoding schemes in stuff like /tool/fetch...
by Amm0
Thu Mar 14, 2024 4:14 am
Forum: General
Topic: A call for a "lite" version of routeros 7 (image size reduction)
Replies: 22
Views: 1541

Re: A call for a "lite" version of routeros 7 (image size reduction)

I get the "16MB problem". And it is a problem. But not sure a "Lite" version help. I think just add more complexity & features don't so neatly correspond to the disk size is the other problem. And some of the code for features is in the kernel, or bundled into larger processe...
by Amm0
Thu Mar 14, 2024 3:08 am
Forum: Beginner Basics
Topic: Load Balance for LAN
Replies: 13
Views: 737

Re: Load Balance for LAN

Reason @anav asks is there MANY ways to do load balance, and types of WAN matter. You seem to want to use "packet marking", but in most cases "connection marking" is better. So details matter here. Mikrotik has a video on the "PCC method" of load balancing: https://www....
by Amm0
Thu Mar 14, 2024 2:56 am
Forum: General
Topic: Bridge and Web Interface - RESOLVED [SOLVED]
Replies: 15
Views: 1622

Re: Bridge and Web Interface [SOLVED]

My guess here is the default firewall has !LAN rule (under /ip/firewall/filter). So if the 2nd bridge interface is not added to the list=LAN under /interface/list, the firewall will block traffic. But if you do an "export file=myconfig" and post your config, it be clear. But "2nd brid...
by Amm0
Wed Mar 13, 2024 8:42 pm
Forum: Beginner Basics
Topic: Static DNS Priority [SOLVED]
Replies: 5
Views: 1260

Re: Static DNS Priority [SOLVED]

Yup, that right. The client gets all three returned at the DNS protocol level. But DNS is typically exposed to apps via gethostbyname() or modern variants, that's what's picking one of them to return. Some application (e.g. some browsers) directly speak DNS protocol so they can do their own "pi...
by Amm0
Wed Mar 13, 2024 4:08 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

Yes, having spaces in file names breaks parameter parsing in all CLI implementations I've seen and one has to use workarounds (such as enclosing such file name in a pair of double quotes). Other way around. It break existing script that were working with space. Perhaps good reason for the change, b...
by Amm0
Wed Mar 13, 2024 1:38 pm
Forum: Beginner Basics
Topic: Static DNS Priority [SOLVED]
Replies: 5
Views: 1260

Re: Static DNS Priority [SOLVED]

I think we're going to need more background on your question. Like what type of records are those (presumable "A", but there is also a non-standard "FWD" static entry too). Or.... is the case here you're using DoH with nextdns.io & then listing the DoH server's hostname as 3 ...
by Amm0
Wed Mar 13, 2024 4:53 am
Forum: Beginner Basics
Topic: Slow Throughput CHR virtual within Proxmox [SOLVED]
Replies: 8
Views: 1581

Re: Slow Throughput CHR virtual within Proxmox [SOLVED]

In fairness, most posters don't start with as much detail. Now CHR licensing is one area that is well documented. But OP came to forum for help & half the problems here are someone didn't read something ;). While not suggesting Mikrotik go this route... most other vendor highlight an unlicensed ...
by Amm0
Tue Mar 12, 2024 7:35 pm
Forum: Scripting
Topic: Adjusting netwatch ICMP check by % of current RTT values... `$scalenetwatch`
Replies: 5
Views: 382

Re: Adjusting netwatch ICMP check by % of current RTT values... `$scalenetwatch`

It actually assumes a set of netwatch parameters: "rtt-avg|rtt-jitter|rtt-max|rtt-stdev" . That list can be adjusted in the code below if desired: :foreach k,v in=$nwattrs do={ :if ($k~"rtt-avg|rtt-jitter|rtt-max|rtt-stdev") do={ :if ($ldenom = 0) do={ $setchg $1 $k $v } else={ $...
by Amm0
Tue Mar 12, 2024 6:57 pm
Forum: Scripting
Topic: Adjusting netwatch ICMP check by % of current RTT values... `$scalenetwatch`
Replies: 5
Views: 382

Re: Adjusting netwatch ICMP check by % of current RTT values... `$scalenetwatch`

If you have a netwatch, it has some status with the RTT and jitter collected from it. So the script pulls that data, say "rtt-avg" (used in status), and then the netwatch's sets "thr-avg" (use in the trigger) Overall, idea was script be used to set the stating point from which to...
by Amm0
Tue Mar 12, 2024 4:54 pm
Forum: General
Topic: Use Mikrotik's HotSpot solution to unblock Wireguard???
Replies: 24
Views: 1738

Re: Use Mikrotik's HotSpot solution to unblock Wireguard???

Or maybe actually, a 2nd idea is to use a "action=jump" in firewall, based on WG's subnet, to the hotspot chain. You'd have also configure hotspot somehow to know about the WG IP in its configuration (and again not hotspot expert either). But idea here be to get WG to go through those dyna...
by Amm0
Tue Mar 12, 2024 4:47 pm
Forum: General
Topic: Use Mikrotik's HotSpot solution to unblock Wireguard???
Replies: 24
Views: 1738

Re: Use Mikrotik's HotSpot solution to unblock Wireguard???

Whether possible, I dunno actually. With experimentation, maybe. We know this: /ip/hotspot has a "Setup" wizard, but in the lists to setup wireguard interface are not selectable. So it needs to on a physical or VLAN port to even have a chance of work – hotspot creates a bunch of dynamic fi...
by Amm0
Tue Mar 12, 2024 3:38 pm
Forum: General
Topic: MikroTik RouterOS boot speed is very slow- vmware
Replies: 15
Views: 3440

Re: MikroTik RouterOS boot speed is very slow- vmware

Thanks @Amm0! Mikrotik, can you please update your CHR image(s) so that EFI is supported out-of-the-box to fix the slow boot issue? Thanks! I put a GitHub Action around the bash script here: https://github.com/tikoci/fat-chr/releases Under "Assets", you find the vmdk for any 7.12.2 or new...
by Amm0
Tue Mar 12, 2024 5:35 am
Forum: Scripting
Topic: Adjusting netwatch ICMP check by % of current RTT values... `$scalenetwatch`
Replies: 5
Views: 382

Adjusting netwatch ICMP check by % of current RTT values... `$scalenetwatch`

This has come up a few times for me (and others) when using netwatch with a type=icmp check. Basically netwatch icmp is more "picky" than the type=simple check since it also check various RTT for max/min/stdev as well as jitter. This is useful, but when netwatch decides if a host= is "...
by Amm0
Mon Mar 11, 2024 10:52 pm
Forum: Scripting
Topic: Is it possible to respond to a specific ping
Replies: 6
Views: 396

Re: Is it possible to respond to a specific ping

I 100% agree with @tangent.

But one possibility is to have a firewall filter rule that matches the desired ping, and then does action=log. A schedule script could then search logs for that message, and run the desired script.
by Amm0
Mon Mar 11, 2024 10:09 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

Nostradamus: CUPS print server including most popular ink jet drivers is next You'd likely not need a CUPS printer server with DNS PTR records. Any modern printer uses mDNS for discovery, so if DNS-SD records were added to Mikrotik DNS, most printers work across VLANs/etc. (*where Mikrotik is the r...
by Amm0
Mon Mar 11, 2024 10:01 pm
Forum: General
Topic: Use Mikrotik's HotSpot solution to unblock Wireguard???
Replies: 24
Views: 1738

Re: Use Mikrotik's HotSpot solution to unblock Wireguard???

It be nice if there was an "enterprise" version of their Back-To-Home (BTH) features using to RADIUS/etc. BTH deal with turning user/passwd credentials into a WG peer on router, which kinda your underlying problem in trying to move from IPSec+RADIUS. Issue is Mikrotik's BTH apps all requir...
by Amm0
Mon Mar 11, 2024 6:04 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

Ah, I wasn't aware of that detail regarding mDNS. I suggest you open a feature request ticket then :)
SUP-100671, opened Dec 2022.
by Amm0
Mon Mar 11, 2024 5:51 pm
Forum: General
Topic: Netwatch wrong status
Replies: 13
Views: 700

Re: Netwatch wrong status

One note here on "tuning" – the "Status" tab will show all the RTT value (even if it's failing due to one of the defaults). So you can use the netwatch's "Status" tab as a guide on what to set. But if you adding a new one, you can add it, then look at what the actuals a...
by Amm0
Mon Mar 11, 2024 5:44 pm
Forum: General
Topic: Netwatch wrong status
Replies: 13
Views: 700

Re: Netwatch wrong status

We understand, the benefit in being able to see the "default" values within RouterOS, but they will not be exposed, at least not in near future, due to the way Netwatch is implemented, same goes for Wifi default values. Thanks Guntis for the clarity. If it's not easy, I get it. But would ...
by Amm0
Mon Mar 11, 2024 3:54 pm
Forum: Beginner Basics
Topic: How to configure and debug mikrotik CRS326 24 switch to act as a router to starlink?
Replies: 5
Views: 425

Re: How to configure and debug mikrotik CRS326 24 switch to act as a router to starlink?

I cannot recall if starlink assigns NTP via their DHCP. But if not, you might also want to enable /ip/cloud's update time option, or add an NTP client.
by Amm0
Mon Mar 11, 2024 3:50 pm
Forum: Beginner Basics
Topic: How to configure and debug mikrotik CRS326 24 switch to act as a router to starlink?
Replies: 5
Views: 425

Re: How to configure and debug mikrotik CRS326 24 switch to act as a router to starlink?

You may want to remove the following, likely harmless, but wrong: /ip dhcp-server network add address=0.0.0.0/24 dns-server=0.0.0.0 gateway=0.0.0.0 netmask=24 add address=100.64.0.0/10 gateway=100.85.202.158 A single Starlink with a CRS326 as a router should be fine IMO — starlink has variable speed...
by Amm0
Mon Mar 11, 2024 3:00 pm
Forum: General
Topic: Viasat Modem
Replies: 4
Views: 311

Re: Viasat Modem

I have one site with a Viasat backup, and recall the modem being kinda dumb about things. So switching between PC and Mikrotik may not be the best test, as it likely locks the PC's MAC address to the public IP. e.g. I think DHCP assignment from Viasat only runs once. If you connected modem to the Mi...
by Amm0
Mon Mar 11, 2024 2:40 pm
Forum: General
Topic: Netwatch wrong status
Replies: 13
Views: 700

Re: Netwatch wrong status

IDK about changing the defaults, that could break someone using it...and there is "simple" if you don't want the advanced controls of ICMP. But ICMP defaults are confusing. One option, for winbox at least, is showing the default values as "greyed out" (until set). Then someone kn...
by Amm0
Mon Mar 11, 2024 1:14 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

Though one cannot explicitely define PTR records, it will generate suiting PTRs from A- and AAAA-records. Good enough? Not really. While true DNS does return a PTR to a "in-addr.arpa" query automatically. You cannot add a PTR explicitly. These are needed to resolve mDNS/DNS-SD per RFC-675...
by Amm0
Mon Mar 11, 2024 1:48 am
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

@Amm0, default support for big files read from storage. RegEX is indeed all being used to recognize different types of entries and extract only what is needed. That it should be 0.0.0.0 "or NXD" is a parameter that could be separated from what is set in the file. Example of a domainPosix:...
by Amm0
Mon Mar 11, 2024 12:23 am
Forum: Scripting
Topic: snmpwalk/snmpget can't read global variable [SOLVED]
Replies: 12
Views: 1148

Re: snmpwalk/snmpget can't read global variable [SOLVED]

@Amm0 The SNMP run with a user called *sys, and this user can't read another vars from other users. Oh I'm sure you're right. Basically since the 7.12 script permission changes, it's bad idea to relay passing around :globals. It's always been a little wonky. Now there are quite few script helpers i...
by Amm0
Mon Mar 11, 2024 12:12 am
Forum: Scripting
Topic: snmpwalk/snmpget can't read global variable [SOLVED]
Replies: 12
Views: 1148

Re: snmpwalk/snmpget can't read global variable [SOLVED]

This is very weird:
[...]
Worked, need to write :put
:put [ping address=8.8.8.8 interval=200ms count=3 as-value]
SNMP is capturing stdout, as-value surpasses that. And /system/script don't "return" anything, like a function or [/cmd/get value] would – so :put is all ya got to SNMP.
by Amm0
Sun Mar 10, 2024 11:58 pm
Forum: Scripting
Topic: snmpwalk/snmpget can't read global variable [SOLVED]
Replies: 12
Views: 1148

Re: snmpwalk/snmpget can't read global variable [SOLVED]

In this case personally I will rather use file in root path which is using tmpfs (assuming ROS is running on device with flash drive) than writing value into some config if presistance is not needed since such file will act as global variable, preserved only in RAM, no flash writes upon setting val...
by Amm0
Sun Mar 10, 2024 11:36 pm
Forum: Scripting
Topic: snmpwalk/snmpget can't read global variable [SOLVED]
Replies: 12
Views: 1148

Re: snmpwalk/snmpget can't read global variable [SOLVED]

RouterOS ver 7.14 [...] /system script add dont-require-permissions=no name=test policy=read,write,policy,test source=":global test; :put \$test;" [/code] [...] SNMP Scripts can't read global var? It's permissions I think. Perhaps dont-require-permissions=yes would allow it to be read via...
by Amm0
Sun Mar 10, 2024 11:15 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

They need to implement this format, without it the feature is basically unusable. A lot of users would need to write converters from world's de facto standard into Mikrotik standard. It's better when they to implement the correct parser once and all of us can just use it. Same for bare domain names...
by Amm0
Sun Mar 10, 2024 10:22 pm
Forum: Announcements
Topic: MikroTik Devices Controller
Replies: 332
Views: 234417

Re: MikroTik Devices Controller

Dude is still working and usefull. BUT check competition...did you see cntroller from ubiquiti or even TP-Link? This is how to should look controller from 21 century... Agreed. More saying adding some modern HTML (instead a 32-bit app), on what was already working well (at least the "backend&q...
by Amm0
Sun Mar 10, 2024 6:59 pm
Forum: Scripting
Topic: Feature request: /tool fetch HTTP-POST can send a file
Replies: 23
Views: 12892

Re: Feature request: /tool fetch HTTP-POST can send a file

Ah, Telegram docs suggest this: In sendDocument, sending by URL will currently only work for GIF, PDF and ZIP files. And backup files are normally bigger than 64kB (and even bigger when base64-encoded for form-data). So not going to work for backups I think... But using /tool/e-mail is actually easi...
by Amm0
Sun Mar 10, 2024 6:36 pm
Forum: Announcements
Topic: MikroTik Devices Controller
Replies: 332
Views: 234417

Re: MikroTik Devices Controller

Shouldn't that be the Dude? And where is it now... Yes. He's happily living in a Ubuntu VM with i386 wine, running on Intel Mac. Folks understandably bag on the Dude's UI. But the backend server (dude.npk) is the real power. No cloud or containers & ahead-of-its-time using SQLite as the backend...
by Amm0
Sun Mar 10, 2024 5:22 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

Isn't the parameter name 'min-prefix' confusing? [...] The only mentioning in the documentation of this is on https://help.mikrotik.com/docs/display/ROS/Policy+Routing where it clearly states that "Equivalent to Linux IP rule suppress_prefixlength . For example to suppress the default route in...
by Amm0
Sun Mar 10, 2024 4:52 pm
Forum: Scripting
Topic: Feature request: /tool fetch HTTP-POST can send a file
Replies: 23
Views: 12892

Re: Feature request: /tool fetch HTTP-POST can send a file

They added other things to scripting that make this, slightly, easier "manually". No direct "multipart/form-data files" AFAIK in /tool/fetch however. For example, with some of the new scripting this, you MIGHT, depending on file size/type, using v7.13+ be able to do this in scrip...
by Amm0
Sun Mar 10, 2024 3:30 am
Forum: Forwarding Protocols
Topic: Multicast over GRE tunnel
Replies: 6
Views: 610

Re: Multicast over GRE tunnel

Hold on. You're doing all those things. I didn't scroll down in your original post. But you show this: admin@RouterA /routing/pimsm/static-rp> print 0 instance=pimsm-instance1 group= 239.10 .0.0/24 address=172.1.1.1 admin@RouterB /routing/pimsm/static-rp> print 0 instance=pimsm-instance1 group= 239....
by Amm0
Sun Mar 10, 2024 3:06 am
Forum: Forwarding Protocols
Topic: Multicast over GRE tunnel
Replies: 6
Views: 610

Re: Multicast over GRE tunnel

Perhaps adding the gre tunnel interface as well as the LAN one may be what's missing, dunno: /routing pimsm interface-template add instance=pimsm1 interfaces=gre1,bridge,vlan1,etc... And the new docs on PIM-SM make a mess of things with OSPF and loopback. But using an RP might help on the PIMSM rout...
by Amm0
Sun Mar 10, 2024 2:35 am
Forum: Forwarding Protocols
Topic: Multicast over GRE tunnel
Replies: 6
Views: 610

Re: Multicast over GRE tunnel

I guess I was hoping it was fixed... I've seen fixed in RNs... but not tested routed multicast myself. One thing to keep in mind with a tunnel involved is multicast need to end up somehow LAN, not the GRE tunnel endpoints. PIM can help with this too, but more configuration. One note: they do have /r...
by Amm0
Sat Mar 09, 2024 10:50 pm
Forum: Forwarding Protocols
Topic: Multicast over GRE tunnel
Replies: 6
Views: 610

Re: Multicast over GRE tunnel

by Amm0
Sat Mar 09, 2024 10:24 pm
Forum: Scripting
Topic: How do I protect source code from being pirated?
Replies: 29
Views: 1383

Re: How do I protect source code from being pirated?

V7.12 release notes say: *) console - restrict permissions to "read,write,reboot,ftp,romon,test" for scripts executed by DHCP, Hotspot, PPP and Traffic-Monitor services; But they don't doc the restriction at help.mikrotik.com for those. Only netwatch doc has note about — which doesn't ment...
by Amm0
Sat Mar 09, 2024 10:14 pm
Forum: RouterBOARD hardware
Topic: Chateau LTE18 ax external antenna conn. for LTE or WIFI?
Replies: 6
Views: 3829

Re: Chateau LTE18 ax external antenna conn. for LTE or WIFI?

The OP clarified what was going on Chateau LTE18 ax. The antenna selection is CLI only: UPDATE: external antenna conn. are for LTE Chateau LTE18 ax has only CLI menu to switch between internal and external antennas [aaa@mikrotik] > /interface/lte/settings set external-antenna= auto both div main non...
by Amm0
Sat Mar 09, 2024 9:16 pm
Forum: Scripting
Topic: How do I protect source code from being pirated?
Replies: 29
Views: 1383

Re: How do I protect source code from being pirated?

It was suggestion if this is really some "secret" algorithm in script, I'm not using PPPoE, so PPP profile scripts for PPPoE cannot execute fetch to some external service on LAN with some static IP (such service doesn't need to be on some server accessed over WAN) or there are some ROS bu...
by Amm0
Sat Mar 09, 2024 8:49 pm
Forum: Scripting
Topic: How do I protect source code from being pirated?
Replies: 29
Views: 1383

Re: How do I protect source code from being pirated?

@optio, perhaps... but don't forget there are restrictions what PPPoE scripts can do in recent V7... And, well, you may not have internet since it's bring up PPPoE... But making any of the PPPoE or dhcp-client etc scripts any MORE complex that strictly needed would NOT be my recommendation. One bug ...
by Amm0
Sat Mar 09, 2024 8:21 pm
Forum: Announcements
Topic: Newsletter #117 | March 2024
Replies: 22
Views: 18758

Re: Newsletter #117 | March 2024

To anyone in North America, neither the new wAP or '24 LtAP will work there. Now the new Fiber adapter – that is a good concept. In my opinion it's better to focus on real professional features (like advanced-switching, routing-protocols, encryption, API:s), unique hardware features (size, fanless, ...
by Amm0
Sat Mar 09, 2024 3:39 am
Forum: Scripting
Topic: How can i use rest api to run a script?
Replies: 4
Views: 387

Re: How can i use rest api to run a script?

Also if you can, can you provide the structure of running scripts? You use multiple `curl` commands is easiest. The REST does not directly let you run "a script" – each REST operation is one command. So in a bash, you can just set some environment variables (e.g. ROUTER= USER=. Theoretica...
by Amm0
Sat Mar 09, 2024 3:22 am
Forum: Scripting
Topic: How can i use rest api to run a script?
Replies: 4
Views: 387

Re: How can i use rest api to run a script?

Yeah you may need (or at least should) specify the interface for WOL. I don't know the internals of WOL, but certainly if you know the interface, it be better to specify interface=: it might flood all interface, or use ARP cache without the interface. For user group permissions, I believe just "...
by Amm0
Fri Mar 08, 2024 11:17 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

Okay just to be clear there is no such thing as $norules ??? Correct. It just a scripting variable that get REPLACED in a customized :import script – all config is scripting after all. If you did an :export after it just be "disabled=no". Please ignore it. But on this topic of $norules, o...
by Amm0
Fri Mar 08, 2024 9:42 pm
Forum: Scripting
Topic: How can i use rest api to run a script?
Replies: 4
Views: 387

Re: How can i use rest api to run a script?

You may need the Content-Type set. Something like this: USER=admin:pass ROUTER=192.168.20.1 curl -k -u $USER -X GET -H "Content-Type: application/json" https://$ROUTER/rest/system/resource You do need to have certificate on /ip/service for HTTPS. You can use Let's Encrypt to do this. Or, R...
by Amm0
Fri Mar 08, 2024 9:03 pm
Forum: Virtualization
Topic: CHR using Apple Virtualization Framework (via UTM)
Replies: 51
Views: 3589

Re: CHR using Apple Virtualization Framework (via UTM)

If you are coming from VMWare please checkout the Proxmox VE. It is brilliant. Build on top of Debian, QEMU and KVM. And Open Source. The company behind it offers paid support. LOL. Yeah I recently just installed Proxmox VE on an old server to test it... It better from a UI POV for sure. And the di...
by Amm0
Fri Mar 08, 2024 7:26 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

This is what I was asking before. Couldn't you use network address other than 0.0.0.0/0.
I think that's what they're working on... There are a few moving parts in re-mapping ;). The where/how take some testing I think.
by Amm0
Fri Mar 08, 2024 7:01 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

See #68 above (https://forum.mikrotik.com/viewtopic.php?t=205278#p1061800) If it was a export the "three rule way" is: /routing rule add action=lookup dst-address=10.0.0.0/8 table=main add action=lookup dst-address=172.16.0.0/12 table=main add action=lookup dst-address=192.168.0.0/16 table...
by Amm0
Fri Mar 08, 2024 6:50 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

However I like this seemingly elegant approach with apparently no downsides! /routing rule add action=lookup-only-in-table min-prefix=0 table=main Only place I'd worry a bit is with recursive routes — there is the canary 8.8.8.8/32 (or similar) in between. Should work since that's internal to routi...
by Amm0
Fri Mar 08, 2024 6:34 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

You didnt comment on $norules ?? Please describe what this does and it was not in the MT docs by the way, so its more interesting to me :-) That was just a typo. I just cut-and-paste from default configuration files, with a bunch of variables at top. My bad. e.g. If there is no multiwan, I don't wa...
by Amm0
Fri Mar 08, 2024 6:17 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

I see this in AX3 upon inspection of logs (same on AX2 but not for RB5009) What script ? While no line numbers, the message does vary depending on where a failure happens. Some bad code in /system/script get you: "executing script script14 from winbox failed, please check it manually" You...
by Amm0
Fri Mar 08, 2024 5:58 pm
Forum: Virtualization
Topic: CHR using Apple Virtualization Framework (via UTM)
Replies: 51
Views: 3589

Re: CHR using Apple Virtualization Framework (via UTM)

Thanks @ayufanpl. Used VMWare for decades and for a time built iOS apps. Most server/apps/OS supported VMWare, while KVM was hit/miss. Seems the reverse is happening, which is good since VMWare is now pretty expensive. While I know UNIX/Linux well enough, all the KVM/QEMU stuff I'm trying to learn. ...
by Amm0
Fri Mar 08, 2024 5:19 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

Just to finish from @anav POV. You can also do any inter-VLAN/etc blocking in /routing/rule's BEFORE the "min-prefix=0 table=main" rule to based on those IP. e.g. action=drop or action=unreachable. As alternative to doing it in firewall... e.g. In order: 1. Any drops rules... 2. Send local...
by Amm0
Fri Mar 08, 2024 4:40 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

Hi Ammo, you know I am a little slow, what are the practical effect of using $norules or "min-prefix=0. What is it that they do in simple terms........ Nothing to do with WG. It's about how to keep the routing rules "readable" for multiwan. Say the main route table has some typical m...
by Amm0
Fri Mar 08, 2024 3:50 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

@Amm0: You read my mind! I was thinking of testing that along with some variations of nat/masq if I get some spare time this weekend. @rplant: yeah, that's about what I had in mind. We'll see what I manage to do over the weekend. Yeah I'm not sure exactly HOW... but somehow "lying" to WG ...
by Amm0
Fri Mar 08, 2024 3:37 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

For example, unrelated to WG, @rplant's point: I have also recently found (as used above) the following rule is very handy before other routing rules. /routing rule add action=lookup comment="min-prefix=0, all except 0.0.0.0/0" disabled=no min-prefix=0 table=main Any route that we have in ...
by Amm0
Fri Mar 08, 2024 3:26 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

I'm blushing!!
I didn't mean to attack-the-attacker either. @anav you do good work here. Just solving some of these "non-problems" is what sometimes eventually yields to simpler "pathways to success". But always a lot of complaining and arguing before that.
by Amm0
Fri Mar 08, 2024 4:02 am
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

@wfburton/Amm0, I have a similar idea that doesn't involve separate routing tables. The main route table can deal with interface as gateway... Perhaps add'l IPs in-between WG and WAN that use recursive routes and masquerade rules... e.g re-route WG through the main routing table (which interface-ba...
by Amm0
Fri Mar 08, 2024 1:58 am
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

Can we implement working configs now, yes! .... Geez, a little harsh... @Larsa has something working — his problem is clear: "we want to minimize script use in production environments whenever possible". It's not a "lack of understanding". May not agree with problem, or think it...
by Amm0
Thu Mar 07, 2024 10:45 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

I get folks think @Larsa is overly pedantic about using scripts for adjusting routing rules.... but the release thread highlight the non-theoritical side-effects of using script for stuff like WAN routing: https://forum.mikrotik.com/viewtopic.php?p=1061545#p1061520 All my router use dhcp-client scri...
by Amm0
Thu Mar 07, 2024 10:31 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

Starting with this Beta release, scripts fail that used to run OK. In particular, scripts run from Scheduler, Netwatch, DHCP-Client-Advanced, DHCP-Server-Advanced Mikrotik changed the permissions available to these scripts recently, maybe the policy further restricted here? But these kinda scripts ...
by Amm0
Thu Mar 07, 2024 10:22 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

I don't known what version your running but keep an eye out for check gateway options. It has one for ping. Of course. BUT again you need use a static route to set. e.g. the check-gateway=ping cannot be added to dynamic default route from DHCP client, without using a script . And, since this a comm...
by Amm0
Thu Mar 07, 2024 10:07 pm
Forum: Virtualization
Topic: CHR using Apple Virtualization Framework (via UTM)
Replies: 51
Views: 3589

Re: CHR using Apple Virtualization Framework (via UTM)

This be good news for Mac ARM users. I suspect if it work under Apple Virtualization on ARM Mac... it work any other KVM hypervisor using AArch64. e.g. Apple is kinda "worse case" since only supports VirtIO. KVM long offered VirtIO, but most Linux hypervisors do have other supporting func...
by Amm0
Thu Mar 07, 2024 9:17 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

Well I think you've distilledthe core issue here: ROS route control is purely based on static IP addresses rather than the logical interface names that are available in the kernel (e.g. "ip rule add from DEVICE table table-name"). The route rules are easier than firewall things in general ...
by Amm0
Thu Mar 07, 2024 7:53 pm
Forum: General
Topic: hAP ac lite LTE6 and wan LTE
Replies: 5
Views: 1179

Re: hAP ac lite LTE6 and wan LTE

By default, Mikrotik will use "internet" as APN (if Use Network APN is uncheck). Since some carrier just ignore APN, while others will provide via network, but some do require it be set to something specific. You should google your carrier name and "APN". Set that in the winbox u...
by Amm0
Thu Mar 07, 2024 7:37 pm
Forum: Virtualization
Topic: CHR using Apple Virtualization Framework (via UTM)
Replies: 51
Views: 3589

Re: CHR using Apple Virtualization Framework (via UTM)

All reasons why I'm pro-virtualization. Good news is seems the world is coalescing around VirtIO since Microsoft and even Apple support.... since dealing with device drivers has been a PITA my entire life. FWIW, I did see @normis report WRT to "AArch64" on the 7.15beta thread: CHR images a...
by Amm0
Thu Mar 07, 2024 7:16 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

Correct. Maybe MikroTik should, now that they are working on this, provide an ONIE install file as well. An iPXE script would work for both ONIE and KVM. An iPXE script could fetch RouterOS via HTTP & be invoked via ONIE or PXE support in KVM/etc. If documented... iPXE install be the fewest ste...
by Amm0
Thu Mar 07, 2024 7:08 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

If using public ip's wouldn't this work? And that's the rub here... They're public IP, but may change since via DHCP. So some static Linux route rules need to get updated when that public changes (where in VyOS or RSC). The solution (on RouterOS) is to use a script from within DHCP client to update...
by Amm0
Thu Mar 07, 2024 6:48 pm
Forum: Scripting
Topic: How do I protect source code from being pirated?
Replies: 29
Views: 1383

Re: How do I protect source code from being pirated?

No one remember MetaROUTER?
Ahead of the times. VRF and Docker, before either were invented. Left with /container that can't run RouterOS inside it (like MetaROUTER could), but some RouterOS-on-RouterOS certainly be one way to ofuscate things on V6.
by Amm0
Thu Mar 07, 2024 5:37 pm
Forum: Scripting
Topic: How do I protect source code from being pirated?
Replies: 29
Views: 1383

Re: How do I protect source code from being pirated?

If one reads the tea leaves here: I'm thinking OP's company sells fully-configured mikrotik for say 3X cost of hardware. They hire more junior folk to install it, who realize it's just a config file & get the idea to sell it for 2X hardware themselves... Now if your business's only added value i...
by Amm0
Thu Mar 07, 2024 5:10 pm
Forum: Scripting
Topic: How do I protect source code from being pirated?
Replies: 29
Views: 1383

Re: How do I protect source code from being pirated?

FWIW, I was not actually suggesting using my ROT13 code above. My attempt at humor here. e.g. Isn't RSC already obfuscated enough? If someone has access to the router, they can get the config via export, and nothing you do be too hidden. e.g. since first step to post on this forum is including the c...
by Amm0
Thu Mar 07, 2024 8:47 am
Forum: Scripting
Topic: How do I protect source code from being pirated?
Replies: 29
Views: 1383

Re: How do I protect source code from being pirated?

Long live Caesar! Oh for fun. In recent V7, the simplest be to use ":convert transform=rot13" somehow. One way, make function, to both encode and decode something & ofuscate that code using ROT13 "encryption": :glob enc do={:retu [:conv transform=ro $1]} Then use that functi...
by Amm0
Thu Mar 07, 2024 7:13 am
Forum: Virtualization
Topic: CHR using Apple Virtualization Framework (via UTM)
Replies: 51
Views: 3589

Re: CHR using Apple Virtualization Framework (via UTM)

But it doesn't see any of the NICs or USB interfaces. Isn't there some extra-nic.npk you can install – maybe already did – just a thought. That would probably explain why the install kernel doesn't see the USB drive after it takes over from UEFI. It does replicate QEMU where the CD-ROM had to be tr...
by Amm0
Thu Mar 07, 2024 4:16 am
Forum: Beginner Basics
Topic: Multiple WAN IP addresses on the same interface, forwarding to internal devices
Replies: 2
Views: 277

Re: Multiple WAN IP addresses on the same interface, forwarding to internal devices

Just for testing, I'd use action=netmap which maps all ports. If that works, you can get more restrictive on ports and protocols. But it has to be symmetrical for both side to communicate & keep IPs hidden but "mapped" 1 to 1. /ip firewall nat add chain=dstnat dst-address=10.0.0.1 acti...
by Amm0
Thu Mar 07, 2024 1:33 am
Forum: Beginner Basics
Topic: api not giving any response
Replies: 6
Views: 417

Re: api not giving any response

And remove the port 8728 from the url...
LOL. I have the edit window open but didn't hit save.

Better url to output to screen. output=user will cause it print to console to see results.
/tool fetch url=http://172.16.0.1/rest/ip/address output=user
by Amm0
Thu Mar 07, 2024 12:58 am
Forum: Beginner Basics
Topic: api not giving any response
Replies: 6
Views: 417

Re: api not giving any response

Opps. By "API", you mean the REST API. That's a different problem. When you use the CLI, the src-address is loopback 172.0.0.1. So that needs to be in the allowed-address for www in your case. And, as REST is an HTTP-based API, the port for it is "80" NOT 8728. /tool fetch url=ht...
by Amm0
Thu Mar 07, 2024 12:53 am
Forum: Beginner Basics
Topic: api not giving any response
Replies: 6
Views: 417

Re: api not giving any response

5 api 8728 0.0.0.0/0 main failure: Idle timeout - waiting data Remove the "allowed access". It should be grey in winbox, so may need to hit the up arrow there to remove it. Otherwise, it matching if the caller's IP is 0.0.0.0 I suspect. Although I get 0.0.0.0/0 should be everything... I k...
by Amm0
Thu Mar 07, 2024 12:46 am
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

@ AMMO , I did not know you were a fiction writer. ;-P I just believe in Santa Claus. To @anav's point, WG is trying to create it's own peer-to-peer tree, so you are "fighting" WG when trying to get Mikrotik involved in it's routing. It was designed to use route rules. My conclusion, is t...
by Amm0
Wed Mar 06, 2024 10:17 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

I don't know why it's good anyway . . . in ROS That why I asked about ARM64 CHRs. On AWS I believe ARM64 is cheaper but AMPERE is not going work. And, there a lot of smaller ARM64 boards that can run KVM, but need RouterOS as ARM64 disk image. Some hyped "AI" (GPU-enabled) enterprise serv...
by Amm0
Wed Mar 06, 2024 10:04 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

What is AMPERE??
Due to the stupid name it is impossible to Google...
Maybe some Kleenex™ would help to clear it up.

AArch64 be way clear. Get Ampere adds GPUs etc... but for RouterOS it's ARM64 on enterprise servers.
by Amm0
Wed Mar 06, 2024 9:32 pm
Forum: Virtualization
Topic: Portainer or Yacht on MT /Container
Replies: 5
Views: 391

Re: Portainer or Yacht on MT /Container

The Yacht looks interesting. It does all things that RouterOS doesn't with /container without all larger scale pod stuff... I'd imagine it be possible to "port" yacht for docking on RouterOS. It is open source. Most of the interaction with docker daemon only happens in a few places in the ...
by Amm0
Wed Mar 06, 2024 7:47 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

!) system - added support for AMPERE (R) hardware (new ARM64 ISO file, new ARM64 extra-nics.npk package); Is there some cloud provider that has AMPERE that is known to work and/or "supported"? I tried on large AMPERE box on Equinix Metal cloud, since they support AMPERE. But Equinix requi...
by Amm0
Wed Mar 06, 2024 6:55 pm
Forum: Wireless Networking
Topic: Due Dilligence Question - Cube 60ACPro [SOLVED]
Replies: 15
Views: 1026

Re: Due Dilligence Question - Cube 60ACPro [SOLVED]

LOL. Fair enough... And I believe out-of-box they do work ;). Now I'd like to think QuickSet updates both password, not sure, never tried that... But simplicity and easy-of-use are not Mikrotik strong point (flexible, yes), so these new user wizards often cause more problems. 61q0NePuZBL._AC_UF1000,...
by Amm0
Wed Mar 06, 2024 6:22 pm
Forum: Virtualization
Topic: CHR using Apple Virtualization Framework (via UTM)
Replies: 51
Views: 3589

Re: CHR using Apple Virtualization Framework (via UTM)

I personally think it better to always use a hypervisor. In years of using Mikrotik, never once tried metal X86 before here. Mikrotik need to just build a ARM64 CHR version of "AMPERE", since it's not just Apple where this comes up. And the "security warning" in this thread on UE...
by Amm0
Wed Mar 06, 2024 5:55 pm
Forum: Wireless Networking
Topic: Due Dilligence Question - Cube 60ACPro [SOLVED]
Replies: 15
Views: 1026

Re: Due Dilligence Question - Cube 60ACPro [SOLVED]

Likely got this part: but there are two password for the Wi-Fi – one for the 5Ghz and 60Ghz. So need to change both. But other than that should be good to go. Also they use "auto" frequency for 5Ghz by default. Default config creates an active-backup bond, with 60G and 5Ghz interface in it...
by Amm0
Wed Mar 06, 2024 5:12 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

Assume that connection tracking wouldn't work for any of ROS's built-in services like WinBox, OSPF, BGP, etc. In a multi-WAN environment, you would then need to set up policy routes for each WAN interface and individual service that doesn't arrive through the default gateway. These built-ins do sta...
by Amm0
Wed Mar 06, 2024 5:09 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

A purely philosophical question then arises: is this a bug or just a very flexible router?
Both?
by Amm0
Wed Mar 06, 2024 5:05 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

Similar things happen on ZeroTier, where it's tunnels (e.g. "zt1" instance/process) do appear in the firewall... but without an interface e.g. (unknown) — since there the outer VL1, not the zerotier1 inner traffic (where zerotier1 does appear as interface in firewall). Peers are dynamic, b...
by Amm0
Wed Mar 06, 2024 4:47 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

Well... If you're looking for affirmation there is a potential bug... @anav should be right on the logic, but I believe your results. The whole idea is RouterOS abstracts away Linux kernel details into the unified config scheme and packet flow diagram. Here, I suspect it's the kernel doing the keepa...
by Amm0
Wed Mar 06, 2024 4:06 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

Well, on Linux, WireGuard also makes heavy use of scripts and routing rules. If you look at the bash script for wg-quick, maybe the DHCP rule doesn't look so bad. Perhaps there is bug here... in RouterOS, @anav's logic should hold true for a tunnel/interface. But WG needing /routing/rule on RouterOS...
by Amm0
Wed Mar 06, 2024 3:46 pm
Forum: Wireless Networking
Topic: Due Dilligence Question - Cube 60ACPro [SOLVED]
Replies: 15
Views: 1026

Re: Due Dilligence Question - Cube 60ACPro [SOLVED]

I was going to say it used wap2, or at least what older cubes use. Also, then information printed on the sticker is stored by Mikrotik and available to distributors AFAIK. So that includes the SSID password. While likely low risk, if the manufacturing database of the stickers was ever compromised, t...
by Amm0
Wed Mar 06, 2024 3:32 pm
Forum: Virtualization
Topic: CHR using Apple Virtualization Framework (via UTM)
Replies: 51
Views: 3589

Re: CHR using Apple Virtualization Framework (via UTM)

qemu-img convert -O qcow2 mikrotik-7.15beta4-arm64.iso mikrotik-7.15beta4-arm64.qcow2 The step 10. does this conversion (or rather attachment of RAW). Yeah that may be a bug in UTM (or gremlins)... it seem to try to convert it, and then reports in dialog it cannot find mikrotik-7.15beta4-arm64 .qco...
by Amm0
Wed Mar 06, 2024 3:12 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

I think the issue is other side also knows about the 3 WANs – it's not a smartphone/desktop wanting VPN access. It's the far-end wants to steer some traffic down a particular WAN(s), that may not be the "primary"*. I don't think DDNS/etc solve this issue — somehow the dynamic public IP add...
by Amm0
Wed Mar 06, 2024 2:39 pm
Forum: Announcements
Topic: v7.14.2 [stable] is released!
Replies: 461
Views: 93246

Re: v7.14 [stable] is released!

Also, when you do an export you get a reference starting with "*". Object with inconsistencies can be deleted but not everyone is able or interested in sanity checking for these inconsistencies - which might have a potential to introduce post-upgrade breakages. We have inherent weakness h...
by Amm0
Wed Mar 06, 2024 6:21 am
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 81
Views: 4312

Re: WireGuard Multi-WAN Policy Routing

In order to facilitate the handshake to complete in a multi-WAN environment (when the inbound interface is not the default gateway) you MUST use policy routing; otherwise the response packet is handed out through the default gateway which makes the handshake fail it the. Okay? And on top of that, y...
by Amm0
Wed Mar 06, 2024 5:31 am
Forum: Virtualization
Topic: CHR using Apple Virtualization Framework (via UTM)
Replies: 51
Views: 3589

Re: CHR using Apple Virtualization Framework (via UTM)

Now for Apple Virtualization on ARM MacOS ... My best guess is the new RouterOS "ARM64 ISO" is missing a needed "virtio_blk.ko" (at least doesn't appear in ISO or any .NPK) And since VirtIO is only* disk option on Apple Virtualization, kinda problematic (*if there isn't virtio_bl...
by Amm0
Wed Mar 06, 2024 2:09 am
Forum: Virtualization
Topic: CHR using Apple Virtualization Framework (via UTM)
Replies: 51
Views: 3589

Re: CHR using Apple Virtualization Framework (via UTM)

OK. You can boot/install via UTM: Just for fun, I tried the ARM64 ISO, emulated in UTM on Intel Mac — WORKED. Instructions almost just work on Intel UTM with QEMU emulation.... Clearly the NVMe disk seem required (tried IDE or VirtIO – neither worked). But for Intel UTM, the ISO image seems to need...
by Amm0
Tue Mar 05, 2024 8:22 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

It must be using the same DNS resolver (e.g. effected by cache size). I'd just prefer it was a generic way to dynamically load a "normal" /etc/host with real hosts – that be useful as "poor man's zone file" to load same hosts on multiple routers. e.g. I don't want 0.0.0.0 as host...
by Amm0
Tue Mar 05, 2024 7:59 pm
Forum: Virtualization
Topic: CHR using Apple Virtualization Framework (via UTM)
Replies: 51
Views: 3589

Re: CHR using Apple Virtualization Framework (via UTM)

I have a Studio and MacBook Pro. You've given me a couple ideas to try. There is an efiboot.img on the ISO. It also has all the packages on the ISO. Kernel boots on Apple and on QEMU but doesn't know where init is. I'm not expect here, but re-packaging I can do. I added ZIP file output to my GitHub...
by Amm0
Tue Mar 05, 2024 6:06 pm
Forum: General
Topic: Routers Coming with Default Passwords
Replies: 69
Views: 6679

Re: Routers Coming with Default Passwords

The only reference I could find is about the hex: https://forum.mikrotik.com/viewtopic.php?t=182498#p939154 According to it both FTDI and Prolific (common) USB-serial converters work. But seemingly you need to configure the console on the USB port, the kind of thing that typically you won't do unti...
by Amm0
Tue Mar 05, 2024 6:00 pm
Forum: Virtualization
Topic: CHR using Apple Virtualization Framework (via UTM)
Replies: 51
Views: 3589

Re: CHR using Apple Virtualization Framework (via UTM)

I was able to boot Ampere/ARM64 ISO on Qemu with KVM acceleration: https://github.com/ayufan-research/mikrotik-qemu-arm64. Works just fine. Tested on Raspberry PI 5 and Rock 5B. Thanks for sharing your scripts. Some working examples always help. FWIW... this is a likely a good call: ... qemu-system...
by Amm0
Tue Mar 05, 2024 5:44 pm
Forum: Virtualization
Topic: CHR using Apple Virtualization Framework (via UTM)
Replies: 51
Views: 3589

Re: CHR using Apple Virtualization Framework (via UTM)

I'm excited to see what people come up with now that the Ampere ISO is out. I tried messing around with it but I can't get things to boot. I tried on Equinox Metal, but couldn't get it work. I do not think it's Mikrotik fault... Metal uses iPXE with netboot.xyz for custom OSes. I use VMWare on X86....
by Amm0
Tue Mar 05, 2024 5:27 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

*) branding - added option to hide default configuration prompt; How? It's not an option to Branding Kit Maker on mt.lv... Nothing about how to build a "defconf" works is documented. Sorta get $action=="revert" is based on prompt in winbox (thus RN to "hide")... & ...
by Amm0
Tue Mar 05, 2024 4:31 pm
Forum: General
Topic: Routers Coming with Default Passwords
Replies: 69
Views: 6679

Re: Routers Coming with Default Passwords

You are not to be taken seriously when you claim that a router should be accessible for admins from the internet side by default. Or, not understanding a long press is how you get PXE boot mode (for netinstall). And that Mikrotik is not going to reverse course on the passwords. To me it seems @jo2j...
by Amm0
Mon Mar 04, 2024 9:01 pm
Forum: Scripting
Topic: Retrieveing a global variable readonly to a local variable
Replies: 9
Views: 466

Re: Retrieveing a global variable readonly to a local variable

I guess if you want a "readonly global to local", you can use :return in /system/script to get some static data. e.g. /system/script/add name=staticUrl source={ :return "http://example.com" } dont-require-permissions=yes :put [/system/script/run staticUrl] # http://example.com #o...
by Amm0
Mon Mar 04, 2024 8:56 pm
Forum: Scripting
Topic: Retrieveing a global variable readonly to a local variable
Replies: 9
Views: 466

Re: Retrieveing a global variable readonly to a local variable

@Amm0 Not that I need or want to use this kind of trickery, but one could use *any* setting that can be easily found and use the comment field (disabling the setting), i.e. one could use (as an example) a (bogus, disabled) static route or a firewall nat or filter rule? All true. Same concept: use s...
by Amm0
Mon Mar 04, 2024 7:39 pm
Forum: Scripting
Topic: Retrieveing a global variable readonly to a local variable
Replies: 9
Views: 466

Re: Retrieveing a global variable readonly to a local variable

:global's are just Linux env variable under-the-covers, and there is NOT some /etc/profile that loads :global's – /system/script run in some user context & various other restrictions/rule depending in other place scripts are used (netwatch, dhcp, etc.). But in the end using one :global in anothe...
by Amm0
Mon Mar 04, 2024 2:37 pm
Forum: General
Topic: MikroTik RouterOS boot speed is very slow- vmware
Replies: 15
Views: 3440

Re: MikroTik RouterOS boot speed is very slow- vmware

I could have been clearer... Mikrotik's official CHR image requires "Legacy BIOS". And those are slow to boot (minutes) on Fusion. Using "UEFI" booting with Mikrotik's official image does not work — although Mikrotik includes the EFI booting code in image. The links to my "r...
by Amm0
Mon Mar 04, 2024 1:54 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 409
Views: 75262

Re: v7.15beta [testing] is released!

Any chance we will have :exit really, really soon to fix this? Otherwise I will have a lot of work to do, implementing other (and probably a lot more complicated) workarounds to my scripts.
Or repurpose :quit for early termination when used in /system/script
by Amm0
Sun Mar 03, 2024 7:30 pm
Forum: Announcements
Topic: v7.14.2 [stable] is released!
Replies: 461
Views: 93246

Re: v7.14 [stable] is released!

Interesting... *) lte - added "at-chat" support for Sierra Wireless EM9293 5G modem; But it's not listed on: https://help.mikrotik.com/docs/display/ROS/Peripherals Does the Sierra EM9293 support reading RSRQ, RSRP, etc.? Previous generations Sierra modems only support reading "RSSI&qu...
by Amm0
Sun Mar 03, 2024 6:14 pm
Forum: General
Topic: User poll about using Winbox
Replies: 100
Views: 62718

Re: User poll about using Winbox

4) Does the name Sessions actually convey what this feature is meant to do? Just realized The Dude uses the term " panels ", which is not a bad term – better than session at least. While a Dude "panel" is not quite same as winbox "session".... There is one thing you ca...
by Amm0
Sun Mar 03, 2024 4:36 pm
Forum: Announcements
Topic: v7.14.2 [stable] is released!
Replies: 461
Views: 93246

Re: v7.14 [stable] is released!

update Did I understand correctly that they forgot to update the documentation? The code is now like this — /disk set usb1 nfs-sharing=yes Apparently, my configs with NFS got migrated to nfs-sharing=yes at some point – seem to work as I didn't notice till just now. But doc do show nfs-export=yes......
by Amm0
Sat Mar 02, 2024 8:59 pm
Forum: General
Topic: MikroTik RouterOS boot speed is very slow- vmware
Replies: 15
Views: 3440

Re: MikroTik RouterOS boot speed is very slow- vmware

Just tested this on VMWare Fusion. Tried an upgrade from v7.14betaX to 7.14 stable... After a reboot, it got the "Load system" message... after 2+ minutes ... the login shows up. Tried OVA and VMDK with Fusion in new machine too. Both take minutes to start. Reboot from RouterOS, same few m...
by Amm0
Sat Mar 02, 2024 5:30 am
Forum: Scripting
Topic: SNMP OID for LTE
Replies: 3
Views: 321

Re: SNMP OID for LTE

True. But carrier is not available from SNMP AFAIK. While carrier can likely be inferred from mtxrLTEModemIMSI since MCC/MNC are in first part, but not quite same as saying the carrier name. Overall, there are few others items "missing" in SNMP for LTE, like info about carrier aggregation,...
by Amm0
Sat Mar 02, 2024 4:47 am
Forum: Beginner Basics
Topic: 2 MIKROTIKs and 2 isolated LANs
Replies: 5
Views: 536

Re: 2 MIKROTIKs and 2 isolated LANs

While the rule shown, if on Mikrotik B, is mostly right. Likely not the whole story however, why config would help. The related questions are: - should "Mikrotik A" LAN (192.168.88.0/24) be able connect to "Mikrotik B" LAN (192.168.77.0/24)? - should LAN clients on 192.168.77.0/2...
by Amm0
Fri Mar 01, 2024 3:39 pm
Forum: Scripting
Topic: fetch seems to behave different when called in function [SOLVED]
Replies: 12
Views: 1167

Re: fetch seems to behave different when called in function [SOLVED]

Whole system has to fit in 16MB, so there are some limits on how many features scripting can have... so no linter to find the "use of undefined global in function". There is ":import verbose=yes <scriptfile.rsc>" that helps find what line something is failing. On this one: For ex...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 13