Community discussions

MikroTik App

Search found 5078 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 17
by Amm0
Tue Feb 11, 2025 11:22 pm
Forum: Announcements
Topic: Question to our users about controllers
Replies: 100
Views: 106665

Re: Question to our users about controllers

Given the likely enormous effort they put into new WinBox, and the largely unnoticed new redesigned WebFig in 7.17 that looks just like winbox4 ... I'd imagine the answer will be BOTH web and app... So the controller app will likely just have different choices on side ("Routers", "APs...
by Amm0
Tue Feb 11, 2025 1:19 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1909
Views: 594330

Re: 📣 WinBox 4 is here 📣

That is, currently in the file found at WinBox.app/Contents/Info.plist , you will find the lines: ... <key>CFBundleVersion</key> <string> 0.1 </string> ... Well, it matches the "my.example.com" as bundle id string, in same Info.plist ... although that's vendor is not visible in Finder. Bu...
by Amm0
Mon Feb 10, 2025 11:24 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1909
Views: 594330

Re: 📣 WinBox 4 is here 📣

We went from something that worked fine on windows and emulated well on others, most of the time, to something that doesn't work as well as the old one anywhere... Yeah, I feel the same way. I really hope MT won't retire v3 before everything’s up to par. Well, the "saving everything"/&quo...
by Amm0
Mon Feb 10, 2025 7:24 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

*) dhcpv4-client - allow selecting to which routing tables add default route (additional fixes); [...] That would be great for DUAL-ISP setups and regular changing IP [...] I'm still looking for a "Check Gateway" option in /ip/dhcp-client as that's ALSO needed for "DUAL-ISP" set...
by Amm0
Mon Feb 10, 2025 7:10 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1909
Views: 594330

Re: 📣 WinBox 4 is here 📣

While I like the feedback in "green bubble" (or red too) status that appear after a commit ("OK"/"Apply") ... they could use some attention in usability. I guess it's related to the "dirty fields" problem (i.e. two updates to same field, before winbox knows it...
by Amm0
Mon Feb 10, 2025 5:43 am
Forum: Virtualization
Topic: CHR using Apple Virtualization Framework (via UTM)
Replies: 55
Views: 10851

Re: CHR using Apple Virtualization Framework (via UTM)

Given the Super Bowl in US... Amm0's container&script superstore is now offering ... Easiest way to install a RouterOS * — via URL: utm://downloadVM?url=https://github.com/tikoci/chr-utm/releases/download/v7.17.2/RouterOS.utm.zip *assuming you have an Intel Mac with UTM installed — To install UT...
by Amm0
Sun Feb 09, 2025 8:27 pm
Forum: General
Topic: Startlink Business with Mikrotik issue
Replies: 4
Views: 2390

Re: Startlink Business with Mikrotik issue

What does "my Mikrotik" mean in terms of model number? Yup, not a lot details to help. In general, most RouterOS get full speed, even without bypass. It the spurious "use it for a hotspot service" - on same Mikrotik, or is that seperate? Perhaps try a speed-test to @TomjNorthIda...
by Amm0
Sun Feb 09, 2025 5:20 pm
Forum: General
Topic: Public-Mikrotik-Bandwidth-Test-Server(s)
Replies: 1061
Views: 1242326

Re: Public-Mikrotik-Bandwidth-Test-Server(s)

Not sure why UDP down did not work. In both bandwidth-test and speed-test, The UDP port maybe blocked by default firewall for UDP. For TCP, there is a connection tracked, so that works fine. But for UDP, the remote side starts, so nothing from LAN->WAN got that tracked. Also it can use a different ...
by Amm0
Sun Feb 09, 2025 2:43 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

In beta5 pull container from https://registry-1.docker.io doesn't work I'm using https://registry.hub.docker.com as you're supposed to according to some sources (including Podman). Works great. Mikrotik has changed their mind a few times, so registry-1.docker.io was in docs at some point. FWIW, I t...
by Amm0
Sun Feb 09, 2025 2:24 am
Forum: Scripting
Topic: uploading files from "bash" to 7.18's /ip/cloud/file-share feature using `curl`
Replies: 4
Views: 867

Re: uploading files from "bash" to 7.18's /ip/cloud/file-share feature using `curl`

Next step - creating MT cloud mountable FS with FUSE, something like https://github.com/fangfufu/httpdirfs :) We'll here is a write up of my notes on how the HTTP works inside file-share. Maybe ChatGPT can whip you up something ;) ?list - get the JSON you'd need To get a list of directories, use a ...
by Amm0
Sat Feb 08, 2025 10:19 pm
Forum: Scripting
Topic: uploading files from "bash" to 7.18's /ip/cloud/file-share feature using `curl`
Replies: 4
Views: 867

Re: uploading files from "bash" to 7.18's /ip/cloud/file-share feature using `curl`

FWIW, sometimes I show `bash` code since folk like to suggest "give me a real shell for RouterOS"... I think forget it's actually more tedious than RouterOS scripting. ;). Personally, I'd prefer WebDAV to newer custom protocols to mounting files, since WebDAV is an RFC & Apple supports...
by Amm0
Sat Feb 08, 2025 7:05 pm
Forum: General
Topic: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?
Replies: 51
Views: 4219

Re: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?

Yes DoH/Adlist works fine for me using Cloudflare. For those waiting for my response from Quad9, it hasn't happened. ticket No 39674 Well, still information... Just not good information. I'd imagine they have less folks than Mikrotik, and trying to run geo-redundant servers independently – not an e...
by Amm0
Sat Feb 08, 2025 6:49 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

On that device, IPSec is hardware offloaded, while WG requires CPU... Hardware offloading on hAP lite??? No, it's not :) True. My bad! I thought complaints were on hAPac2... My main point was changing two things at same time, makes it hard to judge which is the bigger performance issue. i.e. V6+IPS...
by Amm0
Sat Feb 08, 2025 6:42 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 469
Views: 436517

Re: NEW FEATURE: Back to Home VPN

I did but checked today and the new supout didnt show, I must not have completed the add process properly. Added it just now and its visible in the conversation trail. @anav, did they get back to you? Been following your saga here for a while on what should be a simple for someone as well-versed in...
by Amm0
Sat Feb 08, 2025 6:37 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

On that device, IPSec is hardware offloaded, while WG requires CPU... Question be how well does the IPSec config on v6 work when used as-is on v7 - that be more apples-to-apples test, given IPSec offloading. But no doubt RouterOS v7 uses more RAM than v6. And I'm sure more optimization is possible i...
by Amm0
Sat Feb 08, 2025 12:48 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

And some other supported modems are ... brand/model ? It is not MikroTik's job to direct you to their spec sheet Since this is the beta thread... questions and feedback should be encouraged — without insulting comments from others . I made the points I want to make about eSIM — it was feedback to M...
by Amm0
Fri Feb 07, 2025 11:23 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

I have hundreds of LTE devices I do not believe Well you don't know then do you? No need to believe - someone knows. Do they not sell things to customers who have questions? If they spend weeks developing a feature, is too much for Mikrotik to say something. There are physical SIM card that contain...
by Amm0
Fri Feb 07, 2025 7:11 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

Re "new eSIM support"... (and @pidro - my complaints were more toward MT - point being distilling forum posts that should be in docs is annoying) - Not sure if this update contains the fix and I can't test it at the moment. - I'm using with a 5ber eSIM [...] turned out 5ber did some change...
by Amm0
Fri Feb 07, 2025 6:14 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

I really like the eSIM support and works great, however it's not complete as only the following 3 parameter can be used Hello pidro, do you have an eSIM that requires the Confirmation code? Can you please contact us at support@mikrotik.com? Do I have to ask support to even know modems eSIM commands...
by Amm0
Fri Feb 07, 2025 6:00 pm
Forum: Scripting
Topic: uploading files from "bash" to 7.18's /ip/cloud/file-share feature using `curl`
Replies: 4
Views: 867

uploading files from "bash" to 7.18's /ip/cloud/file-share feature using `curl`

I've giving the new "file-share" a try in the 7.18 beta. It's working pretty, outside minor kinks, and /ip/cloud/file-share likely have a lot of useful applications. It should be noted file-share does supports uploading files too, which you can do from the web page at the "File Sharin...
by Amm0
Thu Feb 06, 2025 2:54 am
Forum: Forwarding Protocols
Topic: AMT - Automatic Multicast Tunneling support
Replies: 16
Views: 5178

Re: AMT - Automatic Multicast Tunneling support

Anyway, has anyone tested this over WG? Would that approach even work over WG or over VPNs?

I've never use AMT anywhere, so sorry for basic question - just the concept/config scheme look simpler than other approaches to tunnel multicast over a L3 VPNs.
by Amm0
Thu Feb 06, 2025 2:51 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

I really like the eSIM support and works great,
@Mikrotik, Is there a list of modems modules that the eSIM feature works on?
by Amm0
Thu Feb 06, 2025 2:47 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1909
Views: 594330

Re: 📣 WinBox 4 is here 📣

Oh, X11 scaling is scary... :-) Is this on i3wm by the way? Yes, i3wm. Winbox must be a disappointment to i3vm users... always organizing these overlapping winbox windows "manually" seems a PITA ;) MacOS Sequoia has nifty tiling options , so I feel the pain. +1 for some "Tile" o...
by Amm0
Tue Feb 04, 2025 2:46 pm
Forum: General
Topic: "Error in Gateway - non zero ip address expected!" when using Quick Set
Replies: 20
Views: 1275

Re: "Error in Gateway - non zero ip address expected!" when using Quick Set

I'm pretty sure that the example above doesn't cause any harm though. Basically it's helpful in most cases to prevent a totally wrong admin-mac= be "left over". And I'd imagine stuff like RTSP and LLDP might start having issues or oldies if it was wrong, or it kept changing (but that be d...
by Amm0
Tue Feb 04, 2025 2:24 am
Forum: General
Topic: "Error in Gateway - non zero ip address expected!" when using Quick Set
Replies: 20
Views: 1275

Re: "Error in Gateway - non zero ip address expected!" when using Quick Set

Do I understand correctly that we are addressing the potential problems of having auto-mac=yes, which is the default setting for devices with no configuration? And by 'no default configuration' we mean no config whatsoever (not even Quickset), right? And the potential problem (or one of the problem...
by Amm0
Mon Feb 03, 2025 8:57 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 2554

Re: Question on using the Internal Zerotier Controller [SOLVED]

Perhaps if we joined the EU..................... My question is how that work with frequency bands... Currently, Canada largely the FCC rules. For Wi-Fi, that likely better. For 5G/LTE with Mikrotik, you may be better off with EU rules... That lovely hAPaxLite-LTE6 is quite affordable but worthless...
by Amm0
Mon Feb 03, 2025 7:37 pm
Forum: General
Topic: "Error in Gateway - non zero ip address expected!" when using Quick Set
Replies: 20
Views: 1275

Re: "Error in Gateway - non zero ip address expected!" when using Quick Set

QuickSet works fine in latest versions. But since some routers come with older versions, some older versions on some devices did have bugs. Specifically one where if you changed the IP address and DHCP range, it only pick up the IP address, and set the /ip/dhcp-server/network to be 0.0.0.0/0. You co...
by Amm0
Mon Feb 03, 2025 7:16 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 566
Views: 114793

Re: v7.17.1 [stable] is released!

I'm having an issue after upgrading. I'm getting a message under bridge vlan: # duplicate vlan ids are not allowed due to interface list support, please merge vlan entries into one I have eyeballed the config and don't see any duplicates. Things seem to be working, but the message is concerning and...
by Amm0
Mon Feb 03, 2025 7:05 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 2554

Re: Question on using the Internal Zerotier Controller [SOLVED]

The most practical application I can think of is my intention to host an NAS for images/video, and have it accessible by globally located family members etc. Zerotier may be the best way to allow users to access, load, organize etc.............. my only concern is inadvertent deletion of files........
by Amm0
Mon Feb 03, 2025 6:40 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 2554

Re: Question on using the Internal Zerotier Controller [SOLVED]

Well, I'm actually surprised it's not in the UI. AFAIK, winbox/webfig UI is, mostly, automatic from the schema. And the current implementation of the controller only let you set only half dozen attributes & all are pretty "regular" from RouterOS schema. Perhaps other than our BNF frien...
by Amm0
Mon Feb 03, 2025 6:23 pm
Forum: General
Topic: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?
Replies: 51
Views: 4219

Re: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?

I followed Quad9's documentation (https://docs.quad9.net/Setup_Guides/Open-Source_Routers/MikroTik_RouterOS_%28Encrypted%29/) [also listed above] and it was working but Netflix on my TV thought I was in a different country (Eastern European by my guess on the language). Are there any ways to fix th...
by Amm0
Mon Feb 03, 2025 6:05 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 2554

Re: Question on using the Internal Zerotier Controller [SOLVED]

1000% agree on overall need for "non-reference manual" presentation in docs, whether "user guide"/"by examples"/KBs, whatever... just there is a void between the "per command" view today and how to setup & use the router. On ZT controller docs... The ZT se...
by Amm0
Mon Feb 03, 2025 6:44 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 2554

Re: Question on using the Internal Zerotier Controller [SOLVED]

/zerotier/controller # as array set [find] routes=("2.0/24@10.1.1.1","17.0/8@10.1.1.1") # or as string set [find] routes="2.0/8@10.1.1.1,17.0/8@10.1.1.1" # both forms work - so routes US military and Apple IPs to a ZT member at 10.1.1.1 # & resolve the 2.0 into 2.0...
by Amm0
Mon Feb 03, 2025 6:27 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 2554

Re: Question on using the Internal Zerotier Controller [SOLVED]

FWIW, I do have a test script I've used before to enable the controller. I changed it to more closely match mikrotik instructions. You should be able to cut-and-paste to /system/script, then run the system script. That will output the current ZT configuration things. To setup a new fresh controller,...
by Amm0
Mon Feb 03, 2025 4:50 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 2554

Re: Question on using the Internal Zerotier Controller [SOLVED]

The guys at Mikrotik are various levels of user friendliness :-). The given example is one such. Actually it is exact and not in the least vague. LOL, so true. But an short example wouldn't hurt... And the do check the BNF in docs exactly – include the [@Gw] – but what happens without a route desti...
by Amm0
Mon Feb 03, 2025 1:02 am
Forum: Beginner Basics
Topic: Multicast UDP over Zerotier
Replies: 3
Views: 648

Re: Multicast UDP over Zerotier

Check out multicast UDP in the rules engine: https://docs.zerotier.com/rules/ I think the default rule do allow multicast, so if it's not your rules.... If RouterOS is bridging ZT interface to LAN, then you need to set "Allow Bridging" on the ZT controller side for the member. If you're r...
by Amm0
Sun Feb 02, 2025 8:30 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5182

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...

I would prefer terminal UI to be something like Midnight Commander where navigating through ROS sections can as navigating through directories in MC and in it rules listed like files list with configurable colums to show per row (like in Winbox). Entering the rule some dialog can be shown as form f...
by Amm0
Sun Feb 02, 2025 3:59 pm
Forum: RouterBOARD hardware
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 77
Views: 25708

Re: Running out of space on hAP ac2 [SOLVED]

Make backup, netinstall 7.17.1 and restore backup. That's not how I see it. Export config Netinstall Import config again. The whole "restore" process is complex... This decision would depend if user had an /certificates installed. An ":export show-sensitive" does not contain tho...
by Amm0
Sun Feb 02, 2025 2:42 pm
Forum: General
Topic: Is there a way to make the wifi signal stronger on LtAP LTE6?
Replies: 10
Views: 1011

Re: Is there a way to make the wifi signal stronger on LtAP LTE6?

The LtAP has a small 2GHz antenna inside, so it far from best for Wi-Fi performance in my limited experience with them. But @sindy is right, some data help. But my guess be "distance=" under Advanced, should be "indoor" - if not that can cause a lot flakiness. To check, go to &qu...
by Amm0
Sun Feb 02, 2025 12:12 am
Forum: Beginner Basics
Topic: Forum rules
Replies: 35
Views: 147670

Re: Forum rules

Che differenza fa? [What difference does it make?] ¿Che cosa? Easy to say when you're the "top poster in Italy"... But now I'm envisioning some SQL "SELECT count(post_id) FROM posts WHERE user = x..." * 1M posts * 100K users * X "bots" * N full scrapes Maybe phpBB does...
by Amm0
Sat Feb 01, 2025 11:35 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5182

⊹ visualizing VLAN bridging using $lsbridge and friends

So the scripts here are part of multi-year background project to build some interactive TUI (terminal user interface) over RouterOS, many covered by my other Scripting topics. But it takes a lot of parts - the "scripting VLAN bridging" part is covered here. We'll be on Mars before I'm &quo...
by Amm0
Sat Feb 01, 2025 6:46 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5182

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan

[...]Save the fiddly details for those who actually need to know them. [...] I have thought about a 7.16+ version @pcunite's VLAN/multiwan guide, using scripting functions. Mikrotik has done good work in scripting – and VLAN bridging – of late… [...] 3. In 7.16+, there is NO need to explicitly set ...
by Amm0
Sat Feb 01, 2025 12:59 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1909
Views: 594330

Re: 📣 WinBox 4 is here 📣

In System > Scripts, winbox4 will not save a script larger than ~64KB, which may be reasonable. But the problem is the edit box will ALLOWED to enter >64KB – without any indicator your beyond 64KB in the edit control. The really nasty effect comes when you try to Apply or OK a script source with >64...
by Amm0
Sat Feb 01, 2025 12:24 am
Forum: General
Topic: LTE interface disappears - No such item
Replies: 28
Views: 8285

Re: LTE interface disappears - No such item

This brings up a good question. Is the RB912R supposed to have the R11e-LTE card included? Nope. While it is a bit confusing with all the LTE talk (and I do believe GPS is still built in) but it does say: The LtAP mini ... with integrated LTE antennas (with two u.fl pigtails) and miniPCI-e slot, so...
by Amm0
Fri Jan 31, 2025 9:32 pm
Forum: Scripting
Topic: Append Bridge vlan values
Replies: 6
Views: 2485

Re: Append Bridge vlan values

Maybe this helps: [find dynamic=no vlan-ids=[:if ([:len [:find $"vlan-ids" "<VLAN_ID>"]]) do={:return $"vlan-ids"}]] LOL, I thought some [find (code)] trick might work – it was the embed :find in the find I didn't think about. Good work! Now whether a "configurati...
by Amm0
Fri Jan 31, 2025 7:48 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1909
Views: 594330

Re: 📣 WinBox 4 is here 📣

Can the quick zoom and magnify shortcuts in macOS be changed? I'm accustomed to using them with the trackpad on Command, and it's easy to accidentally touch them. I actually run into this one myself on Mac a few times*... It's actually pretty "sluggish at zooming" when you it too. It real...
by Amm0
Fri Jan 31, 2025 7:29 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

Maybe there just re-using topic id/hash for now, IDK. There are 104 topics FWIW.

@normis was hopeful earlier:
More CEF features are in development for the next betas
But some unique "log id" has long been missing... so hope that is part is included.
by Amm0
Fri Jan 31, 2025 7:15 pm
Forum: General
Topic: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?
Replies: 51
Views: 4219

Re: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?

If it's multiple people with Quad9 over DoH having issues, "someone" really should file a bug with Mikrotik and/or Quad9, if it's repo'able. Mikrotik does not always take some action from the forum. DNS is so critical to things & ideally DoH be 100% reliable... but errors in DNS often ...
by Amm0
Fri Jan 31, 2025 6:50 pm
Forum: Scripting
Topic: Append Bridge vlan values
Replies: 6
Views: 2485

Re: Append Bridge vlan values

LOL. I guess not may folks have tried scripting an existing bridge's trunk ports in 3 years... This problem is since /interface/bridge/vlan's vlan-ids attribute is an ARRAY type... so [find vlan-ids=10] does not work against the array type. I was hoping I was missing something google/search of forum...
by Amm0
Fri Jan 31, 2025 2:43 am
Forum: Scripting
Topic: Is there a Script equivalent of "GoTo"?
Replies: 16
Views: 1240

Re: Is there a Script equivalent of "GoTo"?

I have 32KB script and it is not possible to add/edit it over Winbox, crashes it on save, but over WebFig works. Interesting. Sounds like it's a Winbox issue, not a script limit. I'm on Winbox 3.41 in case that makes any difference. FWIW, limit is 64KB in V7. But even in 7.17, /system/script/edit w...
by Amm0
Thu Jan 30, 2025 8:40 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 566
Views: 114793

Re: v7.17 [stable] is released!

https://mikrotik.com/supportsec And it doesn't look promising when topics like this quickly gets deleted https://forum.mikrotik.com/viewtopic.php?t=214285 Still indexed by Google https://www.google.com/search?q=%22RouterOS+7.17+Firmware+Vulnerabilities%22 Well, in fairness, they do publish a "...
by Amm0
Thu Jan 30, 2025 6:34 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1909
Views: 594330

Re: 📣 WinBox 4 is here 📣

Please FIRE your designers! One more crazy design decision. All tabs have the same color and this small line on the top of a tab is absolutely inconspicuous and barely visible. Return back as it was before. That was definitely bad design decision. It was a problem before to know which tab you were ...
by Amm0
Thu Jan 30, 2025 6:24 pm
Forum: General
Topic: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?
Replies: 51
Views: 4219

Re: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?

My problem with mikrotik has been over the said period 9.9.9.9 DoH is giving me various timeout /drop issues vs cloudflare. why that is I don't know, it's just easyer for me to just use Cloudflare DoH. Am i happy with that situation, No, but it must be better than Google! You could file a ticket wi...
by Amm0
Thu Jan 30, 2025 5:51 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 566
Views: 114793

Re: v7.17 [stable] is released!

Well, "improving security of the users" by making changes and then not documenting them is effectively the same as denying 3rd parties. While, I don't doubt Mikrotik's efforts or good intent. It's the communications and attitude about security is downright lousy. Security topics deserve s...
by Amm0
Thu Jan 30, 2025 6:32 am
Forum: General
Topic: Log: a lot of logs
Replies: 12
Views: 1949

Re: Log: a lot of logs

Don't check the boxes in each of those logs in System>Logging for "dns", "wireguard", "ntp", "dhcp". You DO want the checkbox enabled for "!debug", "!packet", "!raw" things, under the "Topics". Like topics=wireguard, ! d...
by Amm0
Thu Jan 30, 2025 2:25 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1909
Views: 594330

Re: 📣 WinBox 4 is here 📣

use direct WinAPI calls to draw text (DrawText W ) without any libraries. [...] May be some day they'll realize it... Thanks for making me feel old, that worked in the 1990s in Win32s. But Winbox3 likely starts with DrawText A (), so may be a while... On that, I w ish M T take s tyling c ues from W...
by Amm0
Thu Jan 30, 2025 1:23 am
Forum: Announcements
Topic: Question to our users about controllers
Replies: 100
Views: 106665

Re: Question to our users about controllers

@normis, any update on the controller ? Last one from @normis was Sep 22 last year, but not what you were looking for... ========== NEW QUESTION ========== Thank you all for input. New question. What specific features would you like to provision in these controller type of setups. What is your #1 u...
by Amm0
Wed Jan 29, 2025 8:16 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

To be clear: I am NOT suggesting that defconf be applied when upgrading RouterOS. [...] Entirely by their own request. [...] Except it will reset only the firewall. I think it’s a pretty good idea for a lot of reasons. +1 - I love the idea. I feel like the default firewall keeps improving, so it be...
by Amm0
Wed Jan 29, 2025 6:33 pm
Forum: General
Topic: NORMUNDS FOR PRIME MINISTER
Replies: 15
Views: 3472

Re: NORMUNDS FOR PRIME MINISTER

Attempt5: " Damn, I forgot the keys in the car! "
Attempt6: " I wonder if these glasses make me look smarter? "
"We're going the taking shit about device-mode forever - don't blame me"
by Amm0
Wed Jan 29, 2025 6:06 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 566
Views: 114793

Re: v7.17 [stable] is released!

Does device-mode get reset during factory rest to defaults?? or once they are enabled on hardware, they persist? Documentation doesn't say. One probably needs to test to find out... See https://help.mikrotik.com/docs/spaces/ROS/pages/93749258/Device-mode I'm not a fan of device-mode" but the d...
by Amm0
Wed Jan 29, 2025 5:35 pm
Forum: Scripting
Topic: Persistent Environment Variables [SOLVED]
Replies: 60
Views: 45550

Re: Persistent Environment Variables [SOLVED]

Could it be related to the MikroTik Devices Controller ?
My guess is that webfig717+/winbox4 being "done" is the gating item there, I'd imagine they'll re-use those UI components, but those aren't done given the Winbox4 beta thread ;).
by Amm0
Wed Jan 29, 2025 5:30 pm
Forum: Scripting
Topic: Persistent Environment Variables [SOLVED]
Replies: 60
Views: 45550

Re: Persistent Environment Variables [SOLVED]

We've seen over the course of the V7 various changes to permissions and policy. Like, well, ":global" is truely global anymore, etc.... So exactly how to expose "persistent variables" in existing policy model is where some thorny issue may come up, since the underlying user/polic...
by Amm0
Wed Jan 29, 2025 2:03 am
Forum: Scripting
Topic: Is there a Script equivalent of "GoTo"?
Replies: 16
Views: 1240

Re: Is there a Script equivalent of "GoTo"?

FWIW, if you already have some procedural script with a lot of variables, which @k6ccc likely has... you cannot so easily just put everything in new local functions, since you cannot access other local variables/functions. (And, yes @optio, there are tricks like your [$mylocalfunction parentvar=$par...
by Amm0
Wed Jan 29, 2025 1:03 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

Because this time with device-mode s–t no one want lock his devices, so less persons than before do tests... I almost don't want to report this... But noticed "cloud" or "file-share" are not selectable in device-mode. If the whole of idea was minimizing the attack surface, we're...
by Amm0
Tue Jan 28, 2025 10:32 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

with the awesome UI and filtering of v6 [...] and especially filters with a UI and not by manually writing every filter. I'm still pissed I lost the "dynamic-in" rules – still no equivalent in V7... /routing filter add chain=dynamic-in distance=1 set-check-gateway=ping set-distance=1 whic...
by Amm0
Tue Jan 28, 2025 9:46 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

*) cloud - added file-share feature; I may be expecting too much, but to me it seems quite reasonable to put one thing together and imagine that they are creating an infrastructure for "desired state automation". I agree, lots of use cases. Like SMS/"Telegram"/etc notifications ...
by Amm0
Tue Jan 28, 2025 6:39 pm
Forum: General
Topic: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?
Replies: 51
Views: 4219

Re: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?

9.9.9.9 DOH still doesn't work properly for me, I have serveral drops per day. 1.1.1.1 works a treat! I watched a video from the Quad9 CEO [... —] I'd trust the Swiss to run DNS, more than these Californians billionaires ;) FWIW Quad9 guy did another interview recently - I guess the all the trackin...
by Amm0
Tue Jan 28, 2025 5:15 pm
Forum: Scripting
Topic: Persistent Environment Variables [SOLVED]
Replies: 60
Views: 45550

Re: Persistent Environment Variables [SOLVED]

I also thought about using json, but... [...] So, in conclusion, layer7 is certainly not going away anytime soon, but hopefully by the time it is removed, it will be possible to use serialize and deserialize using the text field of a script... A possible solution is to convert everything into a bas...
by Amm0
Tue Jan 28, 2025 6:07 am
Forum: Beginner Basics
Topic: Containers - Mounts vs Root Dir vs Work Dir
Replies: 1
Views: 708

Re: Containers - Mounts vs Root Dir vs Work Dir

It is confusing initially. The /container/mount "src" is the RouterOS directory, so that can be anything, with any levels of nesting desired. I don't use PiHole but given the above, but I do something like this: SRC -> DST /disk1/pihole/etc/pihole -> /etc/pihole /disk1/pihole/etc/dnsmasq -...
by Amm0
Mon Jan 27, 2025 11:50 pm
Forum: Useful user articles
Topic: MikroTik LTE Sierra Wireless MC7455
Replies: 25
Views: 15699

Re: MikroTik LTE Sierra Wireless MC7455

I have not tried a MC7455 since they add the "/interface/lte/show-capabilities" - now it could be the capability is wrong and blocking what otherwise would work... I have scripts that use at-chat with MC7455, so that worked at some point I know for sure. And I filed a bug long ago about th...
by Amm0
Mon Jan 27, 2025 11:35 pm
Forum: General
Topic: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?
Replies: 51
Views: 4219

Re: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?

Nice AMMO. A touch of skepticism is always healthy. So just plain 9.9.9.9 no DOH etc.? Yeah. For me, no DoH... Now I get the logic of DoH to "hide" your request - totally valid. It's just not my concern - someone, somewhere is collecting the DNS queries is my thought. So I'm not a big fan...
by Amm0
Mon Jan 27, 2025 11:20 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 566
Views: 114793

Re: v7.17 [stable] is released!

Maybe I'm missing something here... but this "device-mode" thing seems REALLY problematic... [...] This seems like the death of MirkoTik in our network at this point... or, never upgrading past 7.16.2 ... I'm kind of in shock. Am I reading this wrong? That was the theme from the 7.17beta ...
by Amm0
Mon Jan 27, 2025 10:57 pm
Forum: General
Topic: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?
Replies: 51
Views: 4219

Re: Quick take: Cloudfare, Quad9, Google, NextDNS, Adguard or Pihole?

It's not it's SENDING data to Mr. Black – worse case is some random website doesn't work if something got on his list which be easily remedied. Since it's a static file, no info is leaking out from "adlist" either beyond what normal would (i.e. something NOT on the list). I don't use any l...
by Amm0
Mon Jan 27, 2025 10:15 pm
Forum: Announcements
Topic: MikroTik Devices Controller
Replies: 380
Views: 266481

Re: MikroTik Devices Controller

Maybe, an overhaul of Dude is the new controller.
We could only hope. Or, just add Dude features into winbox4.
by Amm0
Mon Jan 27, 2025 10:14 pm
Forum: Useful user articles
Topic: MikroTik LTE Sierra Wireless MC7455
Replies: 25
Views: 15699

Re: MikroTik LTE Sierra Wireless MC7455

You got no channels, not even for GPS – so something is not right. You should see 2+ channels with a 100D USBCOMP. I'd try adding more logging on LTE, and pay attention to the startup — maybe there is a clue on the "unsupported" for at-chat... I've never need at-chat not work or get that m...
by Amm0
Mon Jan 27, 2025 7:55 pm
Forum: Useful user articles
Topic: MikroTik LTE Sierra Wireless MC7455
Replies: 25
Views: 15699

Re: MikroTik LTE Sierra Wireless MC7455

Does at-chat work with MC7455 when using mbim mode? I know it worked at some point on miniPCIe in wAPacGR, and with 100D since GPS worked too. I don't have MC7455 online to check RN, but I can see it "did work", at least with MC7455 (and MC7354) specifically. I'm using EM7455 (with mpcie ...
by Amm0
Mon Jan 27, 2025 7:31 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5182

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan

@rextended, Then as a scheme for /24, this is easier without breaking balls, easy readable... 2 = 10.0.2.x 3 = 10.0.3.x ... 99 = 10.0.99.x 100 = 10.10.0.x 101 = 10.10.1.x ... 109 = 10.10.9.x 110 = 10.11.0.x 111 = 10.11.1.x ... 999 = 10.99.9.x 1000 = 10.100.0.x 1001 = 10.100.1.x 1002 = 10.100.2.x Tha...
by Amm0
Mon Jan 27, 2025 7:28 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5182

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan

Yea! That looks like it works. You could confirm it's removed by running the "$catvlan" again and it should everything with a [] empty array.
by Amm0
Mon Jan 27, 2025 7:06 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5182

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan

@eddieb - thanks again for testing! - I put an updated 1.3 version with, hopefully, a fix for the bad-behaving :convert on MIPSBE. I put the relevant fix for scripting-denizens in post #20 above. [eddie@ccr1009] > :foreach testnum in=(1,60,128,256,257,512,513,4094,4095,1024*1024,1024*1024*1024,1024*...
by Amm0
Mon Jan 27, 2025 5:58 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5182

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan

Internal Scripting Notes... so I still think it's a bug. More convinced now that look in more detail. i.e. Even if I give Mikrotik that :convert follow CPU endianness, the array size should be consistently 8: 128 got byte-array: 128;0;0;0;0;0;0;0 (8 array) 256 got byte-array: 1;0;0;0;0;0;0 ( 7 arra...
by Amm0
Mon Jan 27, 2025 5:48 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5182

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan

Interesting, good find. It's the CPU, your hAPac is a MIPSBE, while I'm using ARM things on my two test devices for this. The geeky explanation is that "BE" in MIPSBE stand for big-endian, and this affects how numbers are stored in low-level memory blocks, which somehow effecting [:convert...
by Amm0
Mon Jan 27, 2025 5:31 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5182

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan

Thanks! It seems some bug in [:convert to=byte-array]: == use :convert to make a byte-array so we can get at the IP parts ... got 60;0;0;0;0;0;0;0 I'm using an ARM-based RB1100 mainly, and another ARM system to test. == use :convert to make a byte-array so we can get at the IP parts ... got 60 == ve...
by Amm0
Mon Jan 27, 2025 4:58 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5182

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan

almost ... [eddie@hap] > $prettyprint [$pvid2array 60] "ipprefix": "172.75.0" Hmm. Somehow the "highbits" in vlan-id are NOT nothing, which is how you ended up with that. But I don't know how yet.... I do know the "75" comes from that it thinks highbits are t...
by Amm0
Mon Jan 27, 2025 3:22 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5182

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan

tnx for the arry fix, that one seems solved after I replaced the code in /system/scripts/autovlan and ran it ... but it creates a strange network ... My bad. And thanks for testing!!! I updated the script, v1.2 with a fix. There was a new global, "autovlanstyle" also add in the update. Bu...
by Amm0
Sun Jan 26, 2025 11:57 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1909
Views: 594330

Re: 📣 WinBox 4 is here 📣

It's in the "known issues" in post #1 . ********** STATUS UPDATE Dec 13 *************** Known issues to be addressed : [...] Can't ping DNS name But in general winbox4 really should resolve DNS (or have some content menu/shortcut) on the client side... I mentioned this in #1197 : Feature r...
by Amm0
Sun Jan 26, 2025 9:18 pm
Forum: Beginner Basics
Topic: Starlink Packet Loss Troubleshooting
Replies: 17
Views: 2357

Re: Starlink Packet Loss Troubleshooting

/queue type add kind=cake name=qcake /queue tree add bucket-size=0.01 max-limit=20M name=queue1 packet-mark=no-mark parent=ether1 queue=qcake @tangent has a good article on configuring CAKE: https://tangentsoft.com/mikrotik/wiki?name=CAKE+Configuration&p There are a lot of subtle tweaks that mi...
by Amm0
Sun Jan 26, 2025 4:28 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5182

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan

As a VLAN outsider, this all looks excellent to the point that I can see myself directing newbies at it and saying, “Just do it this way.” Save the fiddly details for those who actually need to know them. Yeah I'm working towards that… As you see above, there might be bugs ;) And likely more cleanu...
by Amm0
Sun Jan 26, 2025 4:20 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5182

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan

[eddie@hap] > /system/script/run autovlan [eddie@hap] > $mkvlan 60 not an array [eddie@hap] > $catvlan 99 not an array [eddie@hap] > vlan 99 already exits on that router. it does not create or shows a vlan suggestions ? It turns out some code in catvlan might not work when run from /system/script (...
by Amm0
Sun Jan 26, 2025 4:08 pm
Forum: Scripting
Topic: Detecting Internet connection
Replies: 11
Views: 7328

Re: Detecting Internet connection

I agree that not reaching cloud.mikrotik.com might not represent a full internet access problem and the service could just be limited or degraded. Yeah that was my only point that "wan" generally means there is internet. For example, in past /ip/cloud things have gone down for short perio...
by Amm0
Sun Jan 26, 2025 1:19 am
Forum: Scripting
Topic: Detecting Internet connection
Replies: 11
Views: 7328

Re: Detecting Internet connection

DONE!! I guess you could also add one more email when detect-internet goes to "WAN state". This would happen if you can ping google DNS 8.8.8.8, but not reach Mikrotik's servers (via UDP). The app says something like "Internet (Limited)" if in WAN state, while if "Internet ...
by Amm0
Sun Jan 26, 2025 12:50 am
Forum: Scripting
Topic: Detecting Internet connection
Replies: 11
Views: 7328

Re: Detecting Internet connection

No I think it's a totally reasonable approach. I use /interface/detect-internet in default config on detect-interface-list=WAN since Mikrotik's mobile app show the internet status on the app main screen... And correct, it's "safe" as long as as you do NOT set the "three bottom attribu...
by Amm0
Sat Jan 25, 2025 7:29 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5182

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan

alternative "numbering plans"... I realized it should have some choice of "style" for how the PVID/vlan-id is converted to an IP address. And, just note, you can always use that part of the $pvid2array and $prettyprint code without the rest of the automatic config stuff, like yo...
by Amm0
Sat Jan 25, 2025 6:55 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5182

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan

Bookmarked for future use! 🙏 It could still use cleanup, and alternative "numbering plans"... Despite my commentary on the forum on esoteric scripting topics... my business use for scripting is automating doing config, or output setting without running a dozen CLI commands. Yet there actu...
by Amm0
Sat Jan 25, 2025 6:34 pm
Forum: Scripting
Topic: Detecting Internet connection
Replies: 11
Views: 7328

Re: Detecting Internet connection

/interface detect-internet set detect-interface-list=WAN internet-interface-list=WAN lan-interface-list=LAN wan-interface-list=WAN I'm not sure I'd the use automatically adding interface to WAN or LAN interface list. You already have to interfaces defined as WAN to even use detect-internet. And sin...
by Amm0
Sat Jan 25, 2025 4:46 pm
Forum: The User Manager
Topic: The User Manager I can't install.
Replies: 6
Views: 3176

Re: The User Manager I can't install.

I'm just glad in 7.18, MT finally allowing you just select/install packages like UM from /system/packages, without download/unzip/"copy to router" steps. This whole drag-drop or smb/scp/ftp/etc files was more work than needed, given it's a set of well-known list of packages...
by Amm0
Sat Jan 25, 2025 4:36 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1909
Views: 594330

Re: 📣 WinBox 4 is here 📣

I was hoping in the /ip/firewall/connections section of the new Winbox you could also filter by Ports.. I posted this same thing several months ago (https://forum.mikrotik.com/viewtopic.php?p=1106664#p1106664) and got no responses. Agree it's annoying you cannot filter by ports. But it's also a pro...
by Amm0
Sat Jan 25, 2025 4:29 pm
Forum: General
Topic: Default values [SOLVED]
Replies: 15
Views: 1768

Re: Default values [SOLVED]

@nichky - I only commented since initial suggestion of plain/unqualified [find] was a BAD idea. But I didn't test the mtu= part myself.
@anav
Where is???
Easy to confuse, we're all one country over here now.
by Amm0
Sat Jan 25, 2025 3:14 pm
Forum: General
Topic: [feature suggesstion] Allow copying selected lines from Winbox log view
Replies: 7
Views: 1002

Re: [feature suggesstion] Allow copying selected lines from Winbox log view

workaround open terminal /log/print and copy what you want This is a joke, right? The other way to look at is someone being helpful. Now if I'm looking at the log view in winbox...I'm probably not already in a terminal...so that quite a few steps. But Winbox's log view in general could use many imp...
by Amm0
Sat Jan 25, 2025 2:43 am
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...
Replies: 30
Views: 5182

🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan...

First, these function will only work on 7.17+ , and must have a /interface/bridge with vlan-filtering=yes enabled. The "functions" below wrap operations around VLANs – including DHCP server, interface list, address-list, etc. They employ a few "scripting tricks" internally (inclu...
by Amm0
Sat Jan 25, 2025 1:22 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

Outside of /ip/cloud/file-share... Also, I notice /ip/smb causes a crash on RB1100AHx4 with RAID1+bfrs when accessing from MacOS. Now, I do have 30K+ files (if you include ones inside /container), but also has 60GB disk and not caused a crash in previous version. But it seems very repo-able since an...
by Amm0
Fri Jan 24, 2025 8:58 pm
Forum: Scripting
Topic: Functions and function parameters
Replies: 69
Views: 126761

Re: Functions and function parameters

Well I'm more for X.509 authentication, but the world is against me with these API key schemes. You can argue these thing both ways. I trust the https://mikrotik.com/client/supout viewer enough that shows just a file listing... And file or using some "sensitive" is certainly better than th...
by Amm0
Fri Jan 24, 2025 8:45 pm
Forum: Beginner Basics
Topic: Starlink Packet Loss Troubleshooting
Replies: 17
Views: 2357

Re: Starlink Packet Loss Troubleshooting

That's curious finding. Maybe router mode is employing some queue and/or tunnel....
by Amm0
Fri Jan 24, 2025 8:36 pm
Forum: Scripting
Topic: Functions and function parameters
Replies: 69
Views: 126761

Re: Functions and function parameters

if username, password, etc. are defined in the script, put them right inside the function.............. For that, there is the $SECRET function that stashes them at least persists a password sensitive attribute. It far from ideal, but better than putting them directly in a script IMO: https://forum...
by Amm0
Fri Jan 24, 2025 8:30 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

*) cloud - added file-share feature; It's the first public beta, there might be (for sure there are) bugs. Thank for the report, will investigate all the issues described. Did some testing of "file-share", so have a few more nits ;). This actually might be useful for SMS/text/etc notifica...
by Amm0
Fri Jan 24, 2025 6:43 pm
Forum: Scripting
Topic: Functions and function parameters
Replies: 69
Views: 126761

Re: Functions and function parameters

I don't see any obvious obstacles for changing this behavior and making local variables available inside of local functions. Local functions are located in a single script and can't be used anywhere outside of this script, so I think they should see all local variables defined prior to the function...
by Amm0
Fri Jan 24, 2025 5:37 pm
Forum: General
Topic: Default values [SOLVED]
Replies: 15
Views: 1768

Re: Default values [SOLVED]

So the correct sytax to reset all ether1 parameters to default values, except comments, is:
/interface/ethernet reset [find where default-name=ether1]
The "where" is redundant AFAIK, so not sure why you show that. I am missing something?
by Amm0
Fri Jan 24, 2025 5:34 pm
Forum: General
Topic: Default values [SOLVED]
Replies: 15
Views: 1768

Re: Default values [SOLVED]

Stop suggest using "0" and use interface name. If you're working at the Terminal, using the numbers is fine – you need to do a recent print of course, which was shown.... It's only in "background" scripts where using "0" or other numbers from a print is BAD idea & ...
by Amm0
Fri Jan 24, 2025 5:23 pm
Forum: Scripting
Topic: Functions and function parameters
Replies: 69
Views: 126761

Re: Functions and function parameters

In RouterOS local functions... local variables within a local function are local only the function & local function cannot access other local variables. Local variables are always "scoped" to (e.g. available in) the code blocks they are contained (i.e. within the { }), and local functi...
by Amm0
Fri Jan 24, 2025 3:33 pm
Forum: General
Topic: Default values [SOLVED]
Replies: 15
Views: 1768

Re: Default values [SOLVED]

Yup, "reset" is the command to, well, reset something to default. Most RouterOS config items support the "reset" subcommand. FWIW, at the Terminal prompt, you can do a: /interface/ethernet print /interface/ethernet reset 0 mtu= In @ConradPino's example the [find] will find all et...
by Amm0
Fri Jan 24, 2025 12:26 am
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 469
Views: 436517

Re: NEW FEATURE: Back to Home VPN

Interesting, thanks!! I believe, in the app, if you want JUST the LAN (which let other network traffic go out wi-fi/lte)... you can use the ⋮ next to the connect, and "Edit", the allowed addresses to remove 0.0.0.0/0 and replace it with your LAN subnet(s). By default, all traffic goes thr...
by Amm0
Thu Jan 23, 2025 11:42 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 469
Views: 436517

Re: NEW FEATURE: Back to Home VPN

It‘s not about being able to reach the media (even DNS works fine). The question is about performance of routing between the different ip ranges for large amounts of data like 4k streams I cannot say I've run performance benchmarks*. But I'd imagine you should be able get 50Mb/s or more through the...
by Amm0
Thu Jan 23, 2025 10:30 pm
Forum: General
Topic: Support takes too long to respond to followed-up tickets
Replies: 8
Views: 996

Re: Support takes too long to respond to followed-up tickets

Just to link the threads, this is kinda a continuation of this one: https://forum.mikrotik.com/viewtopic.php?t=213760 And @Larsa as usual has a good point... I got a bit distracted by RoMON in your other thread... But if everything is connected by ZeroTier, you can use its route distribution system,...
by Amm0
Thu Jan 23, 2025 7:37 pm
Forum: General
Topic: Support takes too long to respond to followed-up tickets
Replies: 8
Views: 996

Re: Support takes too long to respond to followed-up tickets

LOL. They are bad about "progress"... it's either fixed, your problem, or in limbo. I'm just offering hope - it being "open" rather than closed is in keeping with Mikrotik's minimalist communications. And by adding a comment, you go back to top of someone's queue I think. ;) On y...
by Amm0
Thu Jan 23, 2025 6:59 pm
Forum: Scripting
Topic: KNOT modbus 64-bit
Replies: 1
Views: 584

Re: KNOT modbus 64-bit

If you post the data you're getting or spec, that help... In 7.16 and above, the :convert can do some of the arithmetic. And all version support bit shifts/OR/XOR/ANDs when dealing a number type. Exactly the right incantation, some recieved output help... At a high-level, you can do: :put [:convert ...
by Amm0
Thu Jan 23, 2025 5:15 pm
Forum: General
Topic: Support takes too long to respond to followed-up tickets
Replies: 8
Views: 996

Re: Support takes too long to respond to followed-up tickets

If you login to Jira at help.mikrotik.com, you should be able to find your ticket. You can add a comment to ask for an update and/or add another supout.rif with the problem. Although, sometimes they don't say anything, if they think it's a problem and don't have an answer (and they escalated). ;) No...
by Amm0
Thu Jan 23, 2025 3:18 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

Anyway, this release is shaping up much better. 7.17 was a mess, I lost the RAID in the first 7.17 beta myself and containers didn't start etc. With 7.18beta2, I had no issues. I'm guessing Mikrotik would rather see case to support@mikrotik – with a supout.rif – on the 7.16.2 upgrade with kernel dis...
by Amm0
Thu Jan 23, 2025 2:42 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 469
Views: 436517

Re: NEW FEATURE: Back to Home VPN

You really should be able to use your media servers IP address while connected to BTH, without doing anything. Now if your media server app does discovery to find the media server, that won't work... you need to use the media server LAN IP address (or a DNS name defined in /ip/dns/static) in the med...
by Amm0
Thu Jan 23, 2025 1:52 am
Forum: The User Manager
Topic: The User Manager I can't install.
Replies: 6
Views: 3176

Re: The User Manager I can't install.

Perhaps use the "Upload" button in Files, instead of drag-and-drop... End of the day, the package MUST be in the root folder, otherwise it will not be found after a reboot to install – at boot ONLY the root directory / is searched for *.npk files. (If this is a test system... you can use 7...
by Amm0
Wed Jan 22, 2025 8:14 pm
Forum: The Dude
Topic: How to delete Dude servers old data?
Replies: 1
Views: 636

Re: How to delete Dude servers old data?

IDK for sure it will remove old data... but in the "Settings" (on top tool bar), under "Charts", there are settings to control retention. By default, it's 10 years. Something to try at least.... Dude Retention Settings.png But it does prune the data, so year back data should be p...
by Amm0
Wed Jan 22, 2025 5:47 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

Okay, I got the /ip/cloud/file-share feature almost working. However @normis's comments do not quite match my experience: it only opens up the file share and has a valid HTTPS certificate. Webfig is not opened to the world, when you enable file share. It is a different service. I had HTTPS enabled i...
by Amm0
Wed Jan 22, 2025 3:15 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

How this works? Has someone tried already? *) cloud - added file-share feature; I enabled it, or at least I thought, but doesn't work. It says running, and looked based on BTH's relay service to share files over internet. /ip/cloud/file-share/settings/print enabled: yes dns-name: <sn>.routingtheclo...
by Amm0
Tue Jan 21, 2025 8:50 pm
Forum: RouterOS beta
Topic: /ip/route/check command disappeared?
Replies: 24
Views: 18952

Re: /ip/route/check command disappeared?

And it returns in 7.18 reincarnated!
/ip/route/check dst-ip=8.8.8.8                                 
     status: ok            
  interface: wan2  
    nexthop: 1.2.3.4
by Amm0
Tue Jan 21, 2025 8:40 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

This one could use a bit more explanation... *) cloud - added file-share feature; Now it did work to create a /ip/cloud/file-share ... but the URL with "routingthecloud.net" does not seem to work in browser (it gets a 404). Is this for BTH use only? i.e. I noticed the /ip/cloud/back-to-hom...
by Amm0
Tue Jan 21, 2025 8:00 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 500
Views: 87826

Re: v7.18beta [testing] is released!

NICE WORK. I'm undecided on what to report the most beautiful, besides the FastTrak, I should copy half the list... Indeed. Upgraded a RB1100AHx4, KNOT, and CHR(s). The RB1100 has some auto-start containers with ROSE RAID/bfrs & all just came up – which includes MQTT and LoRa server, and 7.18be...
by Amm0
Tue Jan 21, 2025 5:34 pm
Forum: Containers
Topic: Home Assistant container on RouterOS - fails to extract and start
Replies: 12
Views: 2447

Re: Home Assistant container on RouterOS - fails to extract and start

Based on at tip in from Amm0 I changed HA from branch “stable” to “latest”, installed HA container and it worked! 😊 from https://forum.mikrotik.com/viewtopic.php?t=214037#p1120343 # ... add veth and networking config ... # SSD is at "raid1/" and layer-dir= and tmpdir= explicitly use the &...
by Amm0
Tue Jan 21, 2025 1:59 am
Forum: Virtualization
Topic: Router OS 7 on UEFI
Replies: 77
Views: 18566

Re: Router OS 7 on UEFI

CHR will have drivers for the virtualized network drivers... Otherwise, AFAIK ARM64 native build does not have a lot of drivers.
by Amm0
Mon Jan 20, 2025 9:40 pm
Forum: General
Topic: Which HW for Verizon Cellular in NY
Replies: 8
Views: 742

Re: Which HW for Verizon Cellular in NY

Understandable. I regularly complain about this. But it has not improved for North American LTE/5G users — and newer LTE devices are even worse the older ones. The original CAT6 modems at least worked with AT&T and T-Mobile... but newer "refreshed" LTE devices, generally with "(20...
by Amm0
Mon Jan 20, 2025 9:13 pm
Forum: General
Topic: Which HW for Verizon Cellular in NY
Replies: 8
Views: 742

Re: Which HW for Verizon Cellular in NY

None work "great" and no 5G options for US. The LTE6 will work okay with AT&T, albeit 5G and limited to CAT6 speeds - but it does at least couple CA modes for AT&T. And LTE6 may work for Verizon, in some areas, but it's without Verizon's Band 13 – which VZW widely deployed/uses – t...
by Amm0
Mon Jan 20, 2025 7:37 pm
Forum: Containers
Topic: Home Assistant container - success stories?
Replies: 5
Views: 1037

Re: Home Assistant container - success stories?

Did you try using the fully qualified remote-image, i.e. including :latest. This worked to create HA on a RB1100AHx4, which 32-bit too. # SSD is at "raid1/" and layer-dir= and tmpdir= explicitly use the "real" disk /container/config set layer-dir=raid1/layers registry-url=https:/...
by Amm0
Mon Jan 20, 2025 7:24 am
Forum: General
Topic: Log: a lot of logs
Replies: 12
Views: 1949

Re: Log: a lot of garbage

The "!dns !package" log rule will mean "debug" (or anything NOT dns and NOT package - which is a log. In general, the "double negative" rules really make it difficult to predict what will happen since it's essentially "everything else"... So may be more OTHER ...
by Amm0
Mon Jan 20, 2025 2:21 am
Forum: Forwarding Protocols
Topic: AMT - Automatic Multicast Tunneling support
Replies: 16
Views: 5178

Re: AMT - Automatic Multicast Tunneling support

If they followed them, by hypothesis, all of them, they would do yours in 20 years.
I guess someone wins the lottery... ;)

And, their AMT implementation does look simplier than PIM-SM or IGMP proxy (x2). Hopefully AMT works with WG tunnels to add multicast.
by Amm0
Sat Jan 18, 2025 8:49 pm
Forum: General
Topic: PXE Boot From Mikrotik
Replies: 17
Views: 25926

Re: PXE Boot From Mikrotik

Did you try from the CLI to set the DHCP Option? I suppose it's possible winbox/webfig used ߵsmartquoteߴ or some unknown Windows locale/code-page/keyboard thing in winbox... This will explicitly update any existing entry, if any unicode was present the CLI will strip it. /ip dhcp-server option set [...
by Amm0
Sat Jan 18, 2025 7:57 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1909
Views: 594330

Re: 📣 WinBox 4 is here 📣

"Only critical bugs will be fixed in Winbox 3" . Sounds crazy, right? Not really. WinBox3 has not had new features for a long time... so I think it's been in the "only critical bugs" even before winbox4 came out . I think when you start seeing some "new winbox protocol"...
by Amm0
Sat Jan 18, 2025 7:40 pm
Forum: General
Topic: Feature Request: WINS Server
Replies: 8
Views: 4763

Re: Feature Request: WINS Server

Unfortunately yes. For example if you merge different office locations within OSPF over p2p wire guard links. In that case you have different networks in most cases, and to get for SMB share, printers etc to live across offices you still have to rely on WINS. Or use Active Directory (either MS or S...
by Amm0
Sat Jan 18, 2025 7:32 pm
Forum: Containers
Topic: Looking for Docker container ideas for RouterOS
Replies: 125
Views: 44477

Re: Looking for Docker container ideas for RouterOS

WINS is a 31-year-old, obsolete Microsoft legacy service Agree. But still really curious on what drives any use case for WINS... But just to answer the question... you can install samba in an Alpine container, and enable WINS in it's config (and add LMHOSTS, have RouterOS DHCP set container as WINS...
by Amm0
Sat Jan 18, 2025 4:11 am
Forum: The User Manager
Topic: The User Manager I can't install.
Replies: 6
Views: 3176

Re: The User Manager I can't install.

You need to open up the File window in winbox, and drag the file to the blank spot in the window - not the menu itself – so that .npk package appears at the root directory inside Files dialog box. Then do a System > Reboot. You check Logs to see if has any messages after reboot after copy'ing the UM...
by Amm0
Sat Jan 18, 2025 2:35 am
Forum: Virtualization
Topic: Router OS 7 on UEFI
Replies: 77
Views: 18566

Re: Router OS 7 on UEFI

I maintain the fat-chr project, so it's possible to add a variant for a 1MB aligned VHD image in future – but I'm not sure that's whole problem here with Azure Gen2 +ARM64... Basically the ARM64 build is different animal...Mikrotik has suggested it's really for AMPERE-based systems... so it may not ...
by Amm0
Sat Jan 18, 2025 1:51 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1909
Views: 594330

Re: 📣 WinBox 4 is here 📣

[...]measurement unit jumps left/right depending on the order of magnitude of the numbers. eg. comparing "1.0 Mbps" and "1000.0 Mbps" the position of the Mbps are different - it moves sideways depending on the value and I find this distracting to read Agreed on alignment & M...
by Amm0
Fri Jan 17, 2025 10:44 pm
Forum: Virtualization
Topic: Router OS 7 on UEFI
Replies: 77
Views: 18566

Re: Router OS 7 on UEFI

ARM64 CHR may need NVMe disk, I think, although not 100%. I recall some issue with QEMU where the fix is to use NVMe emulation.
by Amm0
Fri Jan 17, 2025 9:19 pm
Forum: General
Topic: time-zone-autodetect ?
Replies: 2
Views: 1419

Re: time-zone-autodetect ?

Are you running the latest stable version (7.17, or 7.16.2)? e.g. Some devices come with older versions, and I want to say there was some bug someplace in TZ auto-detect and/or NTP in older versions. FWIW, Mikrotik has a build in time sync in /ip/cloud, so there is not a specific need to use your ow...
by Amm0
Fri Jan 17, 2025 9:05 pm
Forum: Scripting
Topic: Feature request: adding "remove after next run" feature in schedulers
Replies: 2
Views: 1895

Re: Feature request: adding "remove after next run" feature in schedulers

Good idea. It let you "queue" some action simply... Now you can always have the last action of schedule script to remove itself. But this is a bit trickier...as there is NO "this" variable to know what script you're in (/system/scheduler/remove [find name="$name"] will ...
by Amm0
Fri Jan 17, 2025 8:57 pm
Forum: General
Topic: Question about back-to-home-vpn
Replies: 3
Views: 790

Re: Question about back-to-home-vpn

Yeah I really don't know for sure on this one. Only guesses... Presumably the generated config should be the generic peer configuration, and it's totally unclear what the 0.0.0.0/32 is for from docs... It would be nice hear from someone at MikroTik about this! Agreed. Mikrotik really should write up...
by Amm0
Fri Jan 17, 2025 8:35 pm
Forum: General
Topic: Question about back-to-home-vpn
Replies: 3
Views: 790

Re: Question about back-to-home-vpn

Good question. IDK exactly. But agree I think it's superfluous when using the generated config in a normal WG client. It is NOT a /0 default route, rather a /32 — so not sure it's be useful if normal WG app, unless some client app used "0.0.0.0". But dunno My only WAG is it's used by their...
by Amm0
Thu Jan 16, 2025 11:32 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 16396

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

The "Who's Online?" from the main forum page has been removed too. I suspect they blocked the "public profiles", to reduce the URLs that could be scraped/DDoS/whatever...
by Amm0
Thu Jan 16, 2025 7:36 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1909
Views: 594330

Re: 📣 WinBox 4 is here 📣

Since 7.17 is forcing me to use new Winbox instead old one, that i'm used to it, How does it forcing you to use new WinBox? WinBox 3.41 works fine on 7.17. Yeah...you might want to explain what you mean... i would like to ask if there is a way to fix comment section under connections, that i would ...
by Amm0
Thu Jan 16, 2025 5:45 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 469
Views: 436517

Re: NEW FEATURE: Back to Home VPN

Why and what traffic is coming in from the dynamic BTH interface that is added? [...] the counter increments steadily without a BTH client out there. So what traffic is this, mddns? Seeing as you have persistent keep alive set to the relay server, the router keeps in contact with the relay server??...
by Amm0
Wed Jan 15, 2025 7:39 pm
Forum: Containers
Topic: Home Assistant container on RouterOS - fails to extract and start
Replies: 12
Views: 2447

Re: Home Assistant container on RouterOS - fails to extract and start

I can see that an autosupout was created at the time the process halted..should I send it to MT for investigation? Perhaps a case at support@mikrotik.com. The path and layer-dir= is about the only knobs I know to try here... Make sure to generate a new supout.rif with the current state and include ...
by Amm0
Wed Jan 15, 2025 7:18 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1909
Views: 594330

Re: 📣 WinBox 4 is here 📣

in macOS, on Winbox Terminals, it is no more possible to input ^ or ~ characters without having to make copy-paste. That's odd. I can use both the caret and tilde fine in Terminal, on MacOS, using latest beta. Are you using an external keyboard, or perhaps foreign keyboards might cause a difference...
by Amm0
Wed Jan 15, 2025 5:09 pm
Forum: Containers
Topic: Home Assistant container on RouterOS - fails to extract and start
Replies: 12
Views: 2447

Re: Home Assistant container on RouterOS - fails to extract and start

Hmm. Can you also change tmpdir=usb1/pull in /container/config (settings), to remove that slash too?

If that does not work, you could try to the the "layer-dir" in container settings this specifies where the layers are stored:
/container config set layer-dir=usb1/layers
by Amm0
Wed Jan 15, 2025 11:08 am
Forum: Containers
Topic: Home Assistant container on RouterOS - fails to extract and start
Replies: 12
Views: 2447

Re: Home Assistant container on RouterOS - fails to extract and start

Try using root-dir=usb1/ha (without the leading /).

RouterOS file paths do not start with a /, and while some item (like /container/mount) will ignore a leading slash /... root-dir= is very picky.
by Amm0
Wed Jan 15, 2025 12:21 am
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 16396

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

migrate to other forum software that supports load balancing, high availibility etc
Im 100% sure one can do this with PHPBB and HAProxy
https://www.haproxy.org/
+1 to haproxy

It has been flaky today too...
by Amm0
Tue Jan 14, 2025 4:11 am
Forum: Scripting
Topic: [SOLVED] Using Dynamic Variable Names
Replies: 40
Views: 37298

Re: [SOLVED] Using Dynamic Variable Names

While it's nifty trick to use [:parse] to create new globals or use one without a declaration... In most cases, your better off using an array-of-maps or array-of-lists & using TWO :foreach loops. And bad examples of using [:parse] to have "dynamic variable names" are even less helpful.
by Amm0
Tue Jan 14, 2025 3:37 am
Forum: General
Topic: Any downside of using new-mss=clamp-to-ptmu globally (without qualifier)?
Replies: 3
Views: 1213

Re: Any downside of using new-mss=clamp-to-ptmu globally (without qualifier)?

"Most" clients will be automatically set the TCP MSS correctly (assuming ICMP/"ping" is not blocked in the path), but it's not 100%. And why "it worked for a while, then some device broke it..." So using an adjust-mss action makes sense for WG - keep in mind it only app...
by Amm0
Tue Jan 14, 2025 12:00 am
Forum: Scripting
Topic: [API bug/suggestion] Regex in queries
Replies: 16
Views: 8284

Re: [API bug/suggestion] Regex in queries

Please be patient, we will have some new features in ROSv7. :) Well folks have been patient... But even the new REST API, which borrows the API query syntax, does not support regex either. So it's useful beyond just the older API, since I'd imagine REST just proxies the native API. If API supported...
by Amm0
Mon Jan 13, 2025 9:53 pm
Forum: General
Topic: Traffic generator strange problem
Replies: 5
Views: 1150

Re: Traffic generator strange problem

If you create a pcap with your ping from the router using sniffer, and they use that same pcap in traffic generator does it work? IDK why the Juniper might not see it. But again if something generated is malformed, perhaps it drops it. Or, if IP/arp was wrong, then generated traffic might not be goi...
by Amm0
Mon Jan 13, 2025 9:46 pm
Forum: Beginner Basics
Topic: Automation Gateway With Mikrotik [SOLVED]
Replies: 9
Views: 1821

Re: Automation Gateway With Mikrotik [SOLVED]

The CHR solution looks cool, but CHR + server looks a bit to much for me right now. [...] Maybe flashing the RB951 with openWRT + Zerotier (I hope this is not a sin to be told here) Most commercial VPN services (Nord, SurfShark, etc.) don't allow port forwarding, so that not a viable options. I'll ...
by Amm0
Mon Jan 13, 2025 8:24 pm
Forum: Beginner Basics
Topic: Automation Gateway With Mikrotik [SOLVED]
Replies: 9
Views: 1821

Re: Automation Gateway With Mikrotik [SOLVED]

Yeah ZeroTier works pretty well for these cases. While WireGuard and EoIP+IPSec be alternatives if you have a public IP someplace where you can do port forwarding... But without a public IP, you need another router someplace with a public IP that the MIPS RB951 will initiate a connection, and the re...
by Amm0
Mon Jan 13, 2025 7:59 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 469
Views: 436517

Re: NEW FEATURE: Back to Home VPN

Yeah maybe @normis has a clue here. I am trying to follow the MT documents. While I get it... that would include doing a /system/reset-configuration no-defaults=no keep-users=yes IMO. And I bet everything would work. I doubt the docs assume anyone has custom firewall rules or VLANs in their docs... ...
by Amm0
Mon Jan 13, 2025 7:43 pm
Forum: General
Topic: Traffic generator strange problem
Replies: 5
Views: 1150

Re: Traffic generator strange problem

If you're running 7.17rc, you need to enable the traffic generator in /system/device-mode (see 7.17 thread here, or docs).

Otherwise, it's possible you're not generating a valid packet that be dropped before your router sees it. Do you see it on the Mikrotik touch or sniffer locally?
by Amm0
Mon Jan 13, 2025 7:38 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 469
Views: 436517

Re: NEW FEATURE: Back to Home VPN

IDK what's going. I've always seen the rules, but only have a couple test devices, both are running 7.17rc. Although this was all working in 7.16 too. I'd try again, and NOT use the smartphone app - IMO that makes this MORE configuring unless you really do have "factory defaults". So disab...
by Amm0
Mon Jan 13, 2025 7:25 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 469
Views: 436517

Re: NEW FEATURE: Back to Home VPN

To cut to chase, you're right that if you have customization in /ip/firewall/filter things get more complex. I think the underlying assuming is that you do NOT have any modifications to the default firewall.... Now why some are missing, it's possible that unless you have an BTH peers that have "...
by Amm0
Mon Jan 13, 2025 6:31 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 469
Views: 436517

Re: NEW FEATURE: Back to Home VPN

1. Do I need to keep the IPV6 addresses, even though I am strictly using IPV4, in other words does MT relay server require that for all devices?? IPv6 address are not required on the peers or router, although it will be generated in the sample/exported/shared config. But on IPv6... keep in mind if ...
by Amm0
Mon Jan 13, 2025 3:31 am
Forum: Virtualization
Topic: Dell R610 and x86 RouterOS
Replies: 6
Views: 1721

Re: Dell R610 and x86 RouterOS

You might want to post your config. I believe the default configuration is empty, so routing might not work out of the box.
by Amm0
Mon Jan 13, 2025 3:04 am
Forum: Beginner Basics
Topic: Disable Webfig Username autofill
Replies: 9
Views: 3449

Re: Disable Webfig Username autofill

Is there a way to just simply remove the login username by default? Nope, or at least no documented way I could find. And, agree, it's annoying. Considering Mikrotik encourages everyone to NOT use "admin" as username (i.e. to add another element to a password attack), it a poor default th...
by Amm0
Sun Jan 12, 2025 8:18 pm
Forum: Scripting
Topic: $ROKU, the missing Roku TV remote for RouterOS
Replies: 4
Views: 8877

Re: $ROKU, the missing Roku TV remote for RouterOS

I don't know if there any other users of my $ROKU script, but in the latest RokuOS update some permissions have changed that will break the script . Specifically "ECP" which is the web service used to control the TV via HTTP over the LAN. So to keep using the script, you must enable on the...
by Amm0
Sun Jan 12, 2025 7:02 pm
Forum: Beginner Basics
Topic: Is there a simple way to hang a virtual "Out of order" sign?
Replies: 13
Views: 1736

Re: Is there a simple way to hang a virtual "Out of order" sign?

Not "simple" at all.
And here I thought you like making things more complex. ;)
by Amm0
Sun Jan 12, 2025 6:40 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 469
Views: 436517

Re: NEW FEATURE: Back to Home VPN

One only needs the APP to create the first user ( the smartphone itself ). It automatically turns on BTH VPN, and creates the first two entries! I had thought one needed to manually turn on BTH VPN in ip cloud first. It's likely best to do it phone BTH app - so you can test it first. But doing it v...
by Amm0
Sun Jan 12, 2025 5:44 pm
Forum: Beginner Basics
Topic: Is there a simple way to hang a virtual "Out of order" sign?
Replies: 13
Views: 1736

Re: Is there a simple way to hang a virtual "Out of order" sign?

FWIW, both modern Windows and MacOS desktop OSes support using DHCP options to detect the captive portal, which /ip/hotspot support (returning the JSON needed by Option 114). Now hotspot also does all the older DNS/redirects schemes too - which @mkx is correct, they don't as well these days since ne...
by Amm0
Sat Jan 11, 2025 9:45 pm
Forum: Beginner Basics
Topic: Is there a simple way to hang a virtual "Out of order" sign?
Replies: 13
Views: 1736

Re: Is there a simple way to hang a virtual "Out of order" sign?

A certain Amm0 :wink: explained how hotspot can only take care of the wifi part in a post in one of the two threads I mentioned: https://forum.mikrotik.com/viewtopic.php?t=208023#p1077781 Your memory is better than mine. But despite my poor summary there... I'm pretty /ip/hotspot applies to any LAN...
by Amm0
Sat Jan 11, 2025 8:28 pm
Forum: General
Topic: ATL LTE 18 slowing down to a crawl
Replies: 11
Views: 1651

Re: ATL LTE 18 slowing down to a crawl

We have many similarly configure LTE routers, so it's easier for me to test that a version works before dealing with anything remote... But if you got just one and it's remote, that makes it harder... Especially if it's stable for hours and then dies, that's sounds really annoying... Their support i...
by Amm0
Sat Jan 11, 2025 8:13 pm
Forum: General
Topic: ATL LTE 18 slowing down to a crawl
Replies: 11
Views: 1651

Re: ATL LTE 18 slowing down to a crawl

If you can't disable the interface without a crash, that seems like bug somewhere. I'd file a ticket at support@mikrotik.com, and make sure to include a supout.rif when you have the problem. If it keeps happening, you can also try running 7.17rc (+upgrading the boot and LTE firmware too for 7.17), w...
by Amm0
Sat Jan 11, 2025 8:02 pm
Forum: Beginner Basics
Topic: Is there a simple way to hang a virtual "Out of order" sign?
Replies: 13
Views: 1736

Re: Is there a simple way to hang a virtual "Out of order" sign?

This thread has a few approach to a similar problem: https://forum.mikrotik.com/viewtopic.php?t=195386&hilit=captive+portal Basically the options from that are: 1. Create a [largely unused] captive portal on new VLAN, with update HTML with your "Out of order" sign. For maintenance, you...
by Amm0
Sat Jan 11, 2025 7:46 pm
Forum: RouterOS beta
Topic: /ip/route/check command disappeared?
Replies: 24
Views: 18952

Re: /ip/route/check command disappeared?

I wasn't sure if it internally used in matcher if the = was "ip-prefix" type. Apparently not, according to MT's @mrz in this thread ( https://forum.mikrotik.com/viewtopic.php?t=103590 ) from ~8 years ago: I recently became aware that you can use a "in" operator in a command line ...
by Amm0
Sat Jan 11, 2025 5:11 pm
Forum: General
Topic: ATL LTE 18 slowing down to a crawl
Replies: 11
Views: 1651

Re: ATL LTE 18 slowing down to a crawl

The part of the story missing is the LTE metrics. If you're doing monitoring, adding RSRP, RSRQ, and SINR likely be useful since it could be on the LTE carrier side (i.e. time-of-day, changing bands, etc.) which some data either confirm or rule-out. Now the dramatic drop in traffic might indicate so...
by Amm0
Sat Jan 11, 2025 4:24 pm
Forum: General
Topic: Adding veth slows internet
Replies: 35
Views: 4902

Re: Adding veth slows internet

Never bridge VETH interfaces with physical ports, it will disable hardware forwarding. "Never" is overly strong, but because it's a consideration worth taking into account, I've added it to the list of consequences The loss of HW forwarding is a good point, and a valid consideration. With...
by Amm0
Sat Jan 11, 2025 7:35 am
Forum: General
Topic: Mangle and Fasttrack [SOLVED]
Replies: 12
Views: 5517

Re: Mangle and Fasttrack [SOLVED]

but FASTTRACK works with a "change MSS" in the ppp profile?
MSS adjustment happens on first/"new" TCP SYN packet & "new" connections not covered by fasttrack established/related rule...
by Amm0
Sat Jan 11, 2025 2:43 am
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 145793

Re: v7.17rc [testing] is released!

With my ISP you normally have to pay a subscription for IPTV and get a TV-Box. But if you don't subscribe and pay nothing, the IPTV multicast streams with all the channels are still available on the ethernet connection that PPPoE uses, not in a separate VLAN, free of charge, you just don't get the ...
by Amm0
Sat Jan 11, 2025 2:32 am
Forum: General
Topic: Adding veth slows internet
Replies: 35
Views: 4902

Re: Adding veth slows internet

Couple questions... 1. Is the LAN bridge using auto-mac=no? – if it's =yes, then it's possible VETH become the "first interface" in the bridge, in which case it changes the bridge MAC address to be VETH, which may have some side-effects & using a admin-mac= is generally a best practice...
by Amm0
Fri Jan 10, 2025 10:11 pm
Forum: RouterOS beta
Topic: /ip/route/check command disappeared?
Replies: 24
Views: 18952

Re: /ip/route/check command disappeared?

Did you try using query (.query in REST POST)?
/ip/route/print
?active
?dst-address=10.10.10.1
?#&
Now if you got multiple responses, your code have to deal with getting the first from the array, since there is no "pick" in API.
by Amm0
Fri Jan 10, 2025 8:52 pm
Forum: Beginner Basics
Topic: Printer on different VLAN
Replies: 18
Views: 2356

Re: Printer on different VLAN

Well, at least we have a test of AI's AGI abilities - if an LLM can figure out RouterOS config, we're got AGI and domed. But seems were long way from that... Change the "/interface mdns" to: /ip/dns/set mdns-repeat-ifaces=LAN-34,IOT-200 And, the firewall rules are likely not optional, but ...
by Amm0
Fri Jan 10, 2025 7:40 pm
Forum: General
Topic: My LHG - LTE18 is having a Stroke. :D
Replies: 13
Views: 2179

Re: My LHG - LTE18 is having a Stroke. :D

Yeah point being there are three possible places to update: 1. /system/package 2. /system/routerboard/update 3. /interface/lte/firmware-upgrade & with LTE likely best ALL align (and/or at latest stable), since over many releases I have see weird things with LTE (no showing up, not running, disap...
by Amm0
Fri Jan 10, 2025 6:55 pm
Forum: Beginner Basics
Topic: Printer on different VLAN
Replies: 18
Views: 2356

Re: Printer on different VLAN

The automatic search feature in the Brother Full driver did not found the printer (I expected that cause they were not in the same broadcast domain). After putting the IP statically - printer was found immediately but installation failed. Even adding a FORWARD rule of allowing ALL from VLAN34->Prin...
by Amm0
Fri Jan 10, 2025 6:33 pm
Forum: General
Topic: 4G/LTE router with Dual SIM [SOLVED]
Replies: 20
Views: 2872

Re: 4G/LTE router with Dual SIM [SOLVED]

Yeah that one says TWO modems, and TWO SIM. But none going to run RouterOS™.
by Amm0
Fri Jan 10, 2025 6:24 pm
Forum: General
Topic: Bridging two MikroTik router LANs via back-to-home-vpn [SOLVED]
Replies: 10
Views: 2932

Re: Bridging two MikroTik router LANs via back-to-home-vpn [SOLVED]

On routerA it's needed because routerB is trying to connect to the routerA thought the internet and without that rule firewall would drop the traffic. Perhaps there is some outbound traffic from that port that opens up a hole in routerB allowing response traffic? Anyway, I think it does not hurt to...
by Amm0
Fri Jan 10, 2025 3:54 pm
Forum: General
Topic: Question on massive site-to-site VPN implementation
Replies: 13
Views: 1877

Re: Question on massive site-to-site VPN implementation

This is using /zerotier/controller. By the way, in this case are there any flow rules I can edit? I am asking because now RoMON goes through the ZeroTier interface, but OSPF does not discover peers in any broadcast mode, it only works if they are defined statically. But for 80 peers, I obviously pr...
by Amm0
Fri Jan 10, 2025 6:58 am
Forum: General
Topic: Bridging two MikroTik router LANs via back-to-home-vpn [SOLVED]
Replies: 10
Views: 2932

Re: Bridging two MikroTik router LANs via back-to-home-vpn [SOLVED]

Good write up! Few points: - BTH does add all the firewall stuff automatically - that's why it "easy"... while doing it "by hand" on RouterB you do have to allow the WG port otherwise it be blocked by the default firewall's drop WAN in rule. - AFAIK, the BTH "server" ru...
by Amm0
Fri Jan 10, 2025 4:48 am
Forum: General
Topic: 4G/LTE router with Dual SIM [SOLVED]
Replies: 20
Views: 2872

Re: 4G/LTE router with Dual SIM [SOLVED]

To be fair on the posted image, also Huawei claims the same. It seems more likely that it is something lost in translation (or whatever) connected with amazon than originating from the manufacturers. RouterOS do sounds generic, it is a router and has an OS ;). I believe you can report them to Amazo...
by Amm0
Fri Jan 10, 2025 4:38 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1909
Views: 594330

Re: 📣 WinBox 4 is here 📣

I found this about WinBox encryption https://margin.re/2022/02/mikrotik-authentication-revealed/. No idea if the author was correct or whether it's still relevant to the current version. It's actually documented as ECSRP for key exchange and authentication [...] AES128-CBC-SHA as an encryption algo...
by Amm0
Thu Jan 09, 2025 11:07 pm
Forum: General
Topic: My LHG - LTE18 is having a Stroke. :D
Replies: 13
Views: 2179

Re: My LHG - LTE18 is having a Stroke. :D

Sorry, /system/routerboard is where you upgrade the firmware (but the "firmware"/BIOS is called RouterBOOT).
by Amm0
Thu Jan 09, 2025 10:29 pm
Forum: General
Topic: 4G/LTE router with Dual SIM [SOLVED]
Replies: 20
Views: 2872

Re: 4G/LTE router with Dual SIM [SOLVED]

Yes, I too am going that very path :-) I just have ordered 2 LTE sticks, and will first test a solution on the PC (Linux), and later move it to a dedicated small router device... On Linux, if mbimcli works (assuming ModemManager is installed) then it should work on "real" RouterOS.
by Amm0
Thu Jan 09, 2025 10:20 pm
Forum: General
Topic: NORMUNDS FOR PRIME MINISTER
Replies: 15
Views: 3472

Re: NORMUNDS FOR PRIME MINISTER

I heard they were discussing Latvia buying Cloudflare...
Or is it the other way around? :lol:
LOL. Perhaps,

Latvia's GDP = $43.63 billion
Cloudflare, Inc. (NET) market cap = $39.71 billion
by Amm0
Thu Jan 09, 2025 9:18 pm
Forum: General
Topic: 4G/LTE router with Dual SIM [SOLVED]
Replies: 20
Views: 2872

Re: 4G/LTE router with Dual SIM [SOLVED]

Help!
How can I post an image here at all? :oops:
Is only an external link possible?
When you do a reply, below the text box/button there a tab that says "Attachments", you can add a graphic as a file, then use "Place inline".
by Amm0
Thu Jan 09, 2025 9:11 pm
Forum: General
Topic: Quick Set Bug v7.16.2
Replies: 3
Views: 1277

Re: Quick Set Bug v7.16.2

@anav is right, but it is unfortunately ironic that the "easy-to-use" QuickSet method is fraught with bugs and caveats. On the specific issue, QuickSet messing up /ip/dhcp-server/network with 0.0.0.0 is known issue in some combo of older versions AND older default configuration built-in (/...
by Amm0
Thu Jan 09, 2025 7:27 pm
Forum: Scripting
Topic: Securely storing apikey/tokens for /tool/fetch... Approaches? == $SECRET
Replies: 10
Views: 5400

Re: Securely storing apikey/tokens for /tool/fetch... Approaches? == $SECRET

Yeah the whole idea of $SECRET is that it uses /ppp/profile password= variable, which in RouterOS policy is "sensitive" - you indeed you do need policy permission for it. Now the main benefit of using a "sensitive" attribute to store the "secret" is that stuff like API ...
by Amm0
Thu Jan 09, 2025 7:13 pm
Forum: General
Topic: My LHG - LTE18 is having a Stroke. :D
Replies: 13
Views: 2179

Re: My LHG - LTE18 is having a Stroke. :D

I'd make sure you also upgraded the firmware in /system/routerboot to match. If that matches, then... it may be worth it do a backup, and upgrade to the "testing" channel with 7.17rc. I recall others some issues with LHG specifically in 7.16 or 715, so doing another search through forum ma...
by Amm0
Thu Jan 09, 2025 7:01 pm
Forum: General
Topic: 4G/LTE router with Dual SIM [SOLVED]
Replies: 20
Views: 2872

Re: 4G/LTE router with Dual SIM [SOLVED]

While I mainly use Mikrotik router as LTE devices, I do have one site with an inherited Cudy LT something. Amazon is wrong, it's not RouterOS. It has decent web UI, but all the features are pretty fixed in how they work and there aren't a lot of customizations. Small example, Cudy's do support ZeroT...
by Amm0
Thu Jan 09, 2025 6:43 pm
Forum: General
Topic: Question on massive site-to-site VPN implementation
Replies: 13
Views: 1877

Re: Question on massive site-to-site VPN implementation

the way, I solved the RoMON issue with ZeroTier: I had to enable bridging mode for each peer. This is when using /zerotier/controller for your peers? ...or using my.zerotier.com service? I ask since the default flow rules for ZeroTier's cloud service will block RoMON. In which case, you need to add...
by Amm0
Wed Jan 08, 2025 10:23 pm
Forum: General
Topic: 4G/LTE router with Dual SIM [SOLVED]
Replies: 20
Views: 2872

Re: 4G/LTE router with Dual SIM [SOLVED]

In general, a USB stick with LTE should work via USB, and multiple via a hub should too. But not all modems are compatible, and some may require issuing AT commands to switch modes. Mikrotik has a list of modem here: https://help.mikrotik.com/docs/spaces/ROS/pages/13500447/Peripherals#Peripherals-Ce...
by Amm0
Wed Jan 08, 2025 7:33 pm
Forum: General
Topic: NORMUNDS FOR PRIME MINISTER
Replies: 15
Views: 3472

Re: NORMUNDS FOR PRIME MINISTER

Attempt4: Why did I volunteer to attend this event for Viktors......
I think the PM's drug-sniff dogs excluded him from the event.
by Amm0
Wed Jan 08, 2025 6:10 pm
Forum: General
Topic: NORMUNDS FOR PRIME MINISTER
Replies: 15
Views: 3472

Re: NORMUNDS FOR PRIME MINISTER

Maybe @normis is taking you seriously...
Gc_FYR5XkAAenOb-2.jpeg
I heard they were discussing Latvia buying Cloudflare...
by Amm0
Wed Jan 08, 2025 5:29 pm
Forum: General
Topic: Question on massive site-to-site VPN implementation
Replies: 13
Views: 1877

Re: Question on massive site-to-site VPN implementation

Jinx! But with way better details than I was able to provide. :-D I like the OP's presentation, since these choices are kinda of matrix. I'd already wrote my post when I got a conflict, otherwise I'd agree with your assessment ;). Perhaps I'm more agnostic on IPSec IKE2 vs WireGuard — neither have ...
by Amm0
Wed Jan 08, 2025 5:18 pm
Forum: General
Topic: Interface / MVRP Checkbox?
Replies: 3
Views: 2188

Re: Interface / MVRP Checkbox?

Well the text is confusing. But so is the RouterOS bridge interface... see @sindy's "RouerOS bridging mysteries explained", which pre-dates MVRP and dynamic /interface/bridge/vlan assignments: https://forum.mikrotik.com/viewtopic.php?t=173692 In 7.16 and above, /interface/vlan (i.e. dynami...
by Amm0
Wed Jan 08, 2025 4:46 pm
Forum: General
Topic: Question on massive site-to-site VPN implementation
Replies: 13
Views: 1877

Re: Question on massive site-to-site VPN implementation

For completeness, RouterOS also support OpenVPN in layer-2 - although whether multicast/OSPF//RoMON work on it IDK since I've not used it. On ZeroTier, you can run RouterOS as a controller without a license AFAIK. But your list does not capture that ZeroTier only works on ARM devices. Since that mea...
by Amm0
Wed Jan 08, 2025 3:59 pm
Forum: Scripting
Topic: :execute output to console? Or any other method?
Replies: 17
Views: 2652

Re: :execute output to console? Or any other method?

I just need the config spat out in the terminal to be seamlessly integrated with our config change software It's this I'm confused by: sending to terminal is different from automation. If your config software can use SSH to issue the "export" command, that will spit out to "terminal&...
by Amm0
Wed Jan 08, 2025 3:41 pm
Forum: General
Topic: LTE issue on reboot
Replies: 21
Views: 2172

Re: LTE issue on reboot

On word of caution... while a missing interface may be the problem-du-jour, it hard to predict the future. And this is what makes scripting around LTE failure tricky. For example, your+AI script looks for "lte1" as the name of the interface...but over the course of many, many RouterOS vers...
by Amm0
Wed Jan 08, 2025 2:36 am
Forum: Scripting
Topic: Base64 and SHA256 function for Scripting
Replies: 12
Views: 7006

Re: Base64 and SHA256 function for Scripting

Yeah :convert transform= only does SHA512 only, even in 7.17rc6. I filed a ticked (SUP-126958) a year ago about SHA256 (and HMAC's) - in my case, it limits being about to sign AWS HTTP requests, which need SHA256. I got the "Thank you for the feature request. We will see what we can do." f...
by Amm0
Tue Jan 07, 2025 11:03 pm
Forum: General
Topic: LTE issue on reboot
Replies: 21
Views: 2172

Re: LTE issue on reboot

Be careful, it might be easy to get trapped in a boot-loop this way ... Not really a concern.. if it goes into a loop it will be because the LTE card isn't working and if that's the case the unit is no good to us and its a swap out anyway That where the ping watchdog isn't a bad option... as that w...
by Amm0
Tue Jan 07, 2025 9:39 pm
Forum: General
Topic: Tools for graphs and reports
Replies: 10
Views: 2484

Re: Tools for graphs and reports

FWIW, you can run Splunk locally, so no cloud required. @Jonte uses syslog data to capture monitoring data - instead of SNMP (or REST/API) which is why it's pretty complete set of monitored things. Unfortunately, the log parsing is done via Splunk in @Jonte's approach... so not so easy to use Graphi...
by Amm0
Tue Jan 07, 2025 9:27 pm
Forum: General
Topic: LTE issue on reboot
Replies: 21
Views: 2172

Re: LTE issue on reboot

I'd add that if it's only some units... I'd make sure the RouterBOOT and LTE firmware matches, if you haven't already. RouterOS used to support a "/system routerboard settings set init-delay=5s" to delay LTE. I know the option is not on ARM, and docs support only RB9xx but might be worth c...
by Amm0
Tue Jan 07, 2025 7:59 pm
Forum: Wireless Networking
Topic: Are any Chateau 5G versions USA compaitble?
Replies: 2
Views: 1304

Re: Are any Chateau 5G versions USA compaitble?

Those do not support LTE or 5G in US.

And there are NO 5G products in the line-up that have support for US bands. Closest you can do is the US variant of the LTE6 Chateau, and that one does not do AX Wi-Fi.
by Amm0
Mon Jan 06, 2025 5:53 pm
Forum: Wireless Networking
Topic: Use SXT6 LTE units as point to points
Replies: 5
Views: 1944

Re: Use SXT6 LTE units as point to points

AFAIK, it's an LTE antenna, and there is no Wi-Fi*. So if you want to make a PtP link OVER an LTE network, you can do that. But you cannot just use two SXT-LTE6 without some LTE network. In the US, you can use LTE Band 48 to create your on LTE network, but you need a eNB/etc hardware for that & ...
by Amm0
Mon Jan 06, 2025 4:56 pm
Forum: General
Topic: How can Mikrotik/RouterOS send emails using Gmail?
Replies: 15
Views: 9835

Re: How can Mikrotik/RouterOS send emails using Gmail?

Okay AMMO how does your router send you an email when your WAN goes down ;-PP
Well, if you have multiple WANs. ;)
by Amm0
Mon Jan 06, 2025 4:53 pm
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 145793

Re: v7.17rc [testing] is released!

But as I understand it, this mode is not compatible with wpa3-psk? Is there any example of how it is used? To use PPSK... you set "multi-passphrase-group" on a security profile, which will then use any password+vlan-id combo add'ed under /interface/wifi/security/multi-passphrase with the ...
by Amm0
Mon Jan 06, 2025 4:35 pm
Forum: General
Topic: downgrade ROS to pre-7.13 version [SOLVED]
Replies: 14
Views: 2672

Re: downgrade ROS to pre-7.13 version [SOLVED]

I too wish there was a long-term channel, since I too like more time after "stable" before upgrading production things... since sometime "stable" isn't quite stable. But I suspect your #3 problem isn't going away, since they have changed some of the permissions scheme (i.e. some ...
by Amm0
Mon Jan 06, 2025 4:54 am
Forum: Wireless Networking
Topic: Quectel Redcap RG255C-GL PCI-e 5G Modem Support
Replies: 11
Views: 4830

Re: Quectel Redcap RG255C-GL PCI-e 5G Modem Support

For the uninformed, does this mean it's possible to get the modem to function? I did have it working and then I shelved my wAP-R however when booting it back up it stopped working, the interface showing up as "inactive". Not sure if I've broken something or if something has changed on ROS...
by Amm0
Mon Jan 06, 2025 4:37 am
Forum: General
Topic: Tools for graphs and reports
Replies: 10
Views: 2484

Re: Tools for graphs and reports

My apologies for the late reply. I don't know why I don't get notifications. Some times the turtle wins the race. I believe 7.17rc (which is likely going to stable soon) has some new SNMP attributes – although I have NOT tested it. I maintain a webpage, https://tikoci.github.io/restraml/ , where yo...
by Amm0
Mon Jan 06, 2025 4:22 am
Forum: General
Topic: Doesn't RB5009 have a serial port?? [SOLVED]
Replies: 43
Views: 8911

Re: Doesn't RB5009 have a serial port?? [SOLVED]

What I don't get is that they added the serial port to the L009.... but not the 5009. Odd decision. (Just saw this today on a L009 I was installing in a rack.) The RB5009 came out before the L009, so I'd like to think MT learned a serial port is still useful ;). Also the L009 is a replacement for t...
by Amm0
Sun Jan 05, 2025 7:46 pm
Forum: General
Topic: Can i change Zerotier port number?
Replies: 5
Views: 1485

Re: Can i change Zerotier port number?

You can if you want... it's on the "zt1" instances, so it applies to all connect ZT networks that use the instance. Theoretically, changing the default likely make ZT hole punching scheme go through an extra step internally, but cannot imagine it be significant.
by Amm0
Sun Jan 05, 2025 5:48 am
Forum: Beginner Basics
Topic: old configs don't work [SOLVED]
Replies: 16
Views: 3972

Re: old configs don't work [SOLVED]

So your have a Mikrotik router, it has one port going to some switch with 2+ devices with same IP and subnet? If each device with the same IP was connected to a different port on Mikrotik router, the duplicate IP/subnet is solved by adding an interface to route, in which case only a src-nat be neede...
by Amm0
Sun Jan 05, 2025 12:30 am
Forum: General
Topic: Bridging two MikroTik router LANs via back-to-home-vpn [SOLVED]
Replies: 10
Views: 2932

Re: Bridging two MikroTik router LANs via back-to-home-vpn [SOLVED]

I believe you might be able to but not an easily. First, using wg-export is wrong - that's going to replicate the entire wireguard config... While what I think you want to do is make the router2 as peer to router1's BTH. So you need to create an additional BTH user ("shared user") via app ...
by Amm0
Sat Jan 04, 2025 7:23 pm
Forum: Beginner Basics
Topic: Router on Stick for lab purposes
Replies: 4
Views: 1536

Re: Router on Stick for lab purposes

Cheapest is a CHR in a virtual machine. They have a free trial. And you can also use bigger tools like GNS3 to emulate multiple routers. If you want hardware, all the routes have same features including BGP/OSPF and certainly VLANs, so even a hAPaxLite or new "refresh" hEX both let you tes...
by Amm0
Sat Jan 04, 2025 6:25 pm
Forum: Forwarding Protocols
Topic: AMT - Automatic Multicast Tunneling support
Replies: 16
Views: 5178

Re: AMT - Automatic Multicast Tunneling support

If you open a feature request ticket, sometimes MT will say something to effect that it will be in the next release...
by Amm0
Sat Jan 04, 2025 5:12 pm
Forum: General
Topic: Feature request : Multipath TCP (MPTCP) support
Replies: 16
Views: 12458

Re: Feature request : Multipath TCP (MPTCP) support

Peplink does not use MPTCP to do WAN bonding. While possible to do same WAN bonding using subflows and proxy, the standards around MPTCP aggregation are all about client-server communication, not networking bonding. And, I'm not sure there is too much value in /tool/fetch being MPTCP aware which is ...
by Amm0
Fri Jan 03, 2025 5:22 am
Forum: General
Topic: veth MTU
Replies: 3
Views: 2033

Re: veth MTU

Up.

Also, is there a more official forum for feature requests? I don't want to submit a service ticket just for a wishlist item.
If you go to help.mikrotik.com, there is a category for feature requests. Stuff like adding a setting like MTU on VETH seems like a fair request.
by Amm0
Tue Dec 31, 2024 11:00 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 126
Views: 16396

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

And seems unstable today, with a lot of HTTP 500 errors & 1200+ active users shown now....
by Amm0
Tue Dec 31, 2024 6:28 pm
Forum: Scripting
Topic: Netwatch is not working properly
Replies: 5
Views: 1552

Re: Netwatch is not working properly

Perhaps the issue is the ICMP check uses more data to decide up and down, like latency and %loss. If you're not using those... use "simple" as the netwatch, which also uses ICMP but only fails if a ping fails above timeout. The ICMP check will fail on a lot of things, which can create unex...
by Amm0
Sun Dec 29, 2024 3:21 am
Forum: General
Topic: Failover between Routerboard Hex(Starlink) and a SXT LTE6 [SOLVED]
Replies: 47
Views: 5384

Re: Failover between Routerboard Hex(Starlink) and a SXT LTE6 [SOLVED]

change the 9.9.9.9 route's distance to 1, the dhcp one is not used since 0.0.0.0 routes to 9.9.9.9, which then routes to 192.168.168.1 - why it's called recursive routing: it goes through the route table twice. the one with distance 10 is in fact correctly not used/unavailable since a route with a h...
by Amm0
Sat Dec 28, 2024 5:44 am
Forum: General
Topic: Failover between Routerboard Hex(Starlink) and a SXT LTE6 [SOLVED]
Replies: 47
Views: 5384

Re: Failover between Routerboard Hex(Starlink) and a SXT LTE6 [SOLVED]

For detection of failure of starlink... Three+ choices: 1. "check-gateway=ping", see https://help.mikrotik.com/docs/spaces/ROS/pages/4390920/Load+Balancing#LoadBalancing-SimpleFailoverExample & post my above To do this, you can add a script to the /ip/dhcp-client for starlink on hEX :i...
by Amm0
Fri Dec 27, 2024 6:54 pm
Forum: General
Topic: Failover between Routerboard Hex(Starlink) and a SXT LTE6 [SOLVED]
Replies: 47
Views: 5384

Re: Failover between Routerboard Hex(Starlink) and a SXT LTE6 [SOLVED]

Not @Amm0 but if I may, these are the issues I've mentioned a few posts ago. @BartKindtNZ - sorry just reading this. But @sindy offers better advice here. I put him in the "meticulous" category too :). I was trying to get you up-and-running in few steps to be able to test/tweak... but I f...
by Amm0
Fri Dec 27, 2024 6:36 pm
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 84
Views: 54464

Re: Newsletter #122 | December 2024

Are we getting yet another offtopic monologue in the Newsletter topic? Yes. But highlights the need for better communication about their roadmap. i.e. If they giving up on the US market, that be good to know – none of new LTE products have US variants. The new cAPax+LTE is actually a nice offering ...
by Amm0
Tue Dec 24, 2024 6:40 pm
Forum: Scripting
Topic: Scripting error
Replies: 3
Views: 1572

Re: Scripting error

I used Chatgtp for the following code however I cannot see anything wrong myself. VS Code with RouterOS (routeros) plugin cannot seem to find any faults during debugging too. Well, ":urlEncode" is not a thing, among other problems - like all the :execute may not be needed. But there a lot...
by Amm0
Mon Dec 23, 2024 3:21 pm
Forum: General
Topic: hAP ax Lite LTE - problems with connection [SOLVED]
Replies: 15
Views: 2958

Re: hAP ax Lite LTE - problems with connection [SOLVED]

Your APN settings from config don't look right. 0. Although it look like APN is wrong. Wth LTE, you should make sure the /system/routerboard firmware is updated too. In winbox, you can check this in System > RouterBoard and hit "Update". Also, that the LTE modem firmware is updated, which ...
by Amm0
Sun Dec 22, 2024 7:48 pm
Forum: Beginner Basics
Topic: V7.12Beta Back To Home VPN WireGuard not working on Dual ISP WAN. Support Required
Replies: 5
Views: 3384

Re: V7.12Beta Back To Home VPN WireGuard not working on Dual ISP WAN. Support Required

Agreed. But I'd point out that it will use any failover routes in main, but it take at least the DDNS update interval time for it to failover to 2nd WAN. BTH and WG both get complex when you want to use a routing table or PCC, instead of main. So using a more frequent update in /ip/cloud will quickl...
by Amm0
Sat Dec 21, 2024 9:30 pm
Forum: General
Topic: Zerotier help
Replies: 5
Views: 1842

Re: Zerotier help

Also, if same config works in 7.16, but does not work in 7.17... that be worth a ticket to support@mikrotik.com - ideally with a supout.rif for BOTH 7.16 and 7.17 since the supout.rif will have logs etc and your config for them.
by Amm0
Sat Dec 21, 2024 9:29 pm
Forum: General
Topic: Zerotier help
Replies: 5
Views: 1842

Re: Zerotier help

It's the "failed" on the ZT instance that is pretty odd. It could be a bug since I believe they updated the ZeroTier version in 7.17... But I have 7.17rc3 running on several wAPacR and RB1100AHx4 and ZT seems fine, so dunno exactly. You can also try to limit ZeroTier to just the upstream i...
by Amm0
Sat Dec 21, 2024 6:56 pm
Forum: General
Topic: Zerotier help
Replies: 5
Views: 1842

Re: Zerotier help

You'd have to post your configuration as the defaults should work to allow ZL1 tunnels. But you might try downgrading to 7.16.2 to see if is in fact an issue in the 7.17rc.... When you wipe the router... are you upgrading the firewire in /system/routerboard? Did you use something like "/system/...
by Amm0
Sat Dec 21, 2024 6:50 pm
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 84
Views: 54464

Re: Newsletter #122 | December 2024

Another newsletter... still nothing for LTE/5G that works outside EU, no Audience AX, no mixed voltage PoE switches, no devices with LCD & nothing more in the RB5009/L009 form factor. Disappointing year in hardware offerings IMO.
by Amm0
Sat Dec 21, 2024 6:30 pm
Forum: Scripting
Topic: executing script from net failed
Replies: 35
Views: 3891

Re: executing script from net failed

There are a lot of places script can live (PPP, netwatch, dhcp-client, dhcp-server, mqtt, etc. etc.). The message does mean some script is broken. So million dollar question is there any script that's enabled, someplace – that why everyone want to look at config. But at some level, I think opening a...
by Amm0
Sat Dec 21, 2024 6:11 pm
Forum: General
Topic: Failover between Routerboard Hex(Starlink) and a SXT LTE6 [SOLVED]
Replies: 47
Views: 5384

Re: Failover between Routerboard Hex(Starlink) and a SXT LTE6 [SOLVED]

All true @sindy. I do normally use VRRP on the LANs, so forgot the ICMP would further delay "fail-back". My generalized worry is always over-engineering failover so that itself produces outages, like here starlink should be pretty reliable, so failover should be pretty rare... So if perhap...
by Amm0
Sat Dec 21, 2024 5:57 pm
Forum: Containers
Topic: I set the hostname to homeassistant.local but cannot access it.
Replies: 3
Views: 2045

Re: I set the hostname to homeassistant.local but cannot access it.

It might help if you got the port number correct - it's 8123 not 8321. That's probably why you "can't access it" (whatever that really means). LOL, yeah I didn't check that part... But Mikrotik's instructions for setting up HomeAssistant put it on a seperate bridge, so .local like also ma...
by Amm0
Fri Dec 20, 2024 11:53 pm
Forum: General
Topic: Failover between Routerboard Hex(Starlink) and a SXT LTE6 [SOLVED]
Replies: 47
Views: 5384

Re: Failover between Routerboard Hex(Starlink) and a SXT LTE6 [SOLVED]

There are few ways to design this.... But, if you want something basic without VLANs or "passthrough".... I don't see harm in leaving the hEX as is, and then put the SXT on the hEX LAN. i.e. assuming all have default configuration, the most basic failover be to: - set the ip address of SXT...
by Amm0
Fri Dec 20, 2024 11:04 pm
Forum: General
Topic: Questions related to "Using RouterOS to VLAN your network"
Replies: 2
Views: 1295

Re: Questions related to "Using RouterOS to VLAN your network"

4- Your base problem here might be that you are not aware a bridge has multiple personalities as explained in this thread. IMHO: heavy stuff, may take several readings before you really get it and I will admit I still don't get it completely myself. RouterOS bridge mysteries explained While that's ...
by Amm0
Fri Dec 20, 2024 5:45 am
Forum: Containers
Topic: I set the hostname to homeassistant.local but cannot access it.
Replies: 3
Views: 2045

Re: I set the hostname to homeassistant.local but cannot access it.

HomeAssistant has to be on the same LAN network as the browser for the .local name to resolve. This is because it use mDNS to "discover" the IP address, but mDNS require being on the same IP subnet to work. Mikrotik has a feature in 7.16, to enable broadcasting mDNS lookups, like homeassis...
by Amm0
Fri Dec 20, 2024 2:34 am
Forum: Containers
Topic: Container Memory/CPU usage visibility
Replies: 4
Views: 10244

Re: Container Memory/CPU usage visibility

Anyone knows/heard of container roadmap ? Being able to display memory/cpu consumed would be great.
+1, to both a roadmap & per-container mem/CPU. I'd also add showing the disk usage of a container be nice too.

Ideally via /container item, than having to start the profile tool to see it.
by Amm0
Thu Dec 19, 2024 6:07 pm
Forum: Beginner Basics
Topic: Incorporating a backup gateway into my setup
Replies: 14
Views: 2228

Re: Incorporating a backup gateway into my setup

@slimprize - You can mark your top post as "solved". I don't think anyone cares too much about who solves... there are new puzzles in forum everyday. @anav - luck played a role too... since easiest case of failover is static IP as primary and DHCP as secondary, with the primary WAN gateway...
by Amm0
Wed Dec 18, 2024 8:42 pm
Forum: Beginner Basics
Topic: WireGuard or OpenVPN [SOLVED]
Replies: 51
Views: 13899

Re: WireGuard or OpenVPN [SOLVED]

Also, I think it is enough of hijacking this topic, better open new one for Xray in ROS container in "3rd party tools" section, since this conversation is gone OT. Or Mikrotik just add AmneziaWG and/or XRay containers to docs as examples and to test/fix /container support for them better....
by Amm0
Wed Dec 18, 2024 6:03 pm
Forum: Beginner Basics
Topic: Incorporating a backup gateway into my setup
Replies: 14
Views: 2228

Re: Incorporating a backup gateway into my setup

Usually when this ISP has been done, I have been unable to ping even the modem because it is in bridge mode and does not have an IP address. Yup, and then it should failover from the check-gateway=ping. All more advanced approaches do get real complex, so if your ISP is bridge (and most are), the c...
by Amm0
Wed Dec 18, 2024 5:52 pm
Forum: RouterBOARD hardware
Topic: 5009 version with wifi ?
Replies: 63
Views: 6910

Re: 5009 version with wifi ?

I think, it's better to have separated roles.... RB must only be wired router. Personally, I'm not concerned by the nomenclature. So get RB5009 specifically having Wi-Fi may not be right in their name scheme, but some "hAPax4" in the RB5009/L009 frame be nice. As noted, IMO it's a common ...
by Amm0
Wed Dec 18, 2024 5:33 pm
Forum: Scripting
Topic: Using :return from :onerror in= command block
Replies: 13
Views: 2001

Re: Using :return from :onerror in= command block

P.S. Propose them in ticket with optional :return for both blocks :) Yeah I already put that in the ticket: While I get idea of :onerror could be used in an :if statement (which docs highlight)…. But in reality it likely be better if :onerror always returned :nothing unless an explicit :return was ...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 17