Community discussions

Search found 87 matches

by jprietove
Sat Oct 12, 2019 10:47 am
Forum: Scripting
Topic: Script out entire router configuration or just a section of it?
Replies: 4
Views: 440

Re: Script out entire router configuration or just a section of it?

Maybe I'm not understanding well but, are you asking about "export" command?

Enviado desde mi Mi A2 mediante Tapatalk

by jprietove
Tue Oct 08, 2019 11:55 pm
Forum: General
Topic: Using PRTG to execute a script through Mikrotik API
Replies: 3
Views: 742

Re: Using PRTG to execute a script through Mikrotik API

I don't know exactly what are you trying to do. If you want to execute a script in a MikroTik router you can follow this link https://wiki.mikrotik.com/wiki/Manual:SNMP#Run_Script Using the OID and with write permissions in SNMP when PRTG gets the data though SNMP using this OID, the script is execu...
by jprietove
Wed Sep 18, 2019 8:29 pm
Forum: General
Topic: RouterOS v7.0beta1 (ARM)
Replies: 194
Views: 35915

Re: RouterOS v7.0beta1 (ARM)

Even if it's not perfect, we'd love to start testing BGP/MPLS on ARM/Tilera!
And CHR also, please!!
by jprietove
Fri Aug 30, 2019 9:01 pm
Forum: General
Topic: fiber pigtail connector
Replies: 5
Views: 766

Re: fiber pigtail connector

Just use Movistar ont as a Bridge. Ir is the usual way for ftth. Imho

Enviado desde mi Mi A2 mediante Tapatalk

by jprietove
Fri Aug 30, 2019 6:02 pm
Forum: General
Topic: fiber pigtail connector
Replies: 5
Views: 766

Re: fiber pigtail connector

I think he is talking about gpon. Have a look in this thread:

viewtopic.php?f=3&t=116364&hilit=Gpon

Enviado desde mi Mi A2 mediante Tapatalk

by jprietove
Wed Jul 17, 2019 11:05 am
Forum: Forwarding Protocols
Topic: OSPF Interface all passive
Replies: 9
Views: 1259

Re: OSPF Interface all passive

Well, not exactly because this is not OSPF-v3... it is (sorry for the mistake):
/routing ospf interface add interface=all passive=yes
by jprietove
Wed Jul 17, 2019 9:59 am
Forum: Forwarding Protocols
Topic: OSPF Interface all passive
Replies: 9
Views: 1259

Re: OSPF Interface all passive

Not as easy when you have a few hundred vlans. Not bad to script but would be nice to have a simple checkbox to automatically have all interfaces as passive and then add the ones you want.
/routing ospf interfaces add interface=all area=backbone passive=yes
by jprietove
Thu Jun 13, 2019 10:20 am
Forum: General
Topic: Reading NetFlow Data with Python
Replies: 2
Views: 259

Re: Reading NetFlow Data with Python

Take a look at https://code.google.com/archive/p/flowd/

You have a python example code and it works nice!
by jprietove
Mon May 27, 2019 11:42 pm
Forum: General
Topic: Mikrotik CCR 1072 Hang
Replies: 3
Views: 474

Re: Mikrotik CCR 1072 Hang

Any of you are using Ethernet port for something different of managing?

If it's used for routing, firewalling or anything it can hang the router

Enviado desde mi Mi A2 mediante Tapatalk

by jprietove
Mon May 13, 2019 12:34 pm
Forum: General
Topic: 70m cable with MikroTik
Replies: 8
Views: 726

Re: 70m cable with MikroTik

Cat 5 cable is not suitable for 1Gbps. Use cat 5e or, much better, cat 6

Enviado desde mi Mi A2 mediante Tapatalk

by jprietove
Tue Apr 23, 2019 10:34 pm
Forum: Forwarding Protocols
Topic: Your experience with larger/diverse Area0 OSPF networks?
Replies: 19
Views: 1430

Re: Your experience with larger/diverse Area0 OSPF networks?

In my opinion you should consider migrate to BGP with ospf. With good planning it's not painful and it's not necessary to get clients without service.


Enviado desde mi Mi A2 mediante Tapatalk

by jprietove
Tue Apr 23, 2019 1:09 am
Forum: General
Topic: LAG 802.3AD slowness
Replies: 16
Views: 1187

Re: LAG 802.3AD slowness

It depends on the ccr1009 model. Not all shares the same block diagram

Enviado desde mi Mi A2 mediante Tapatalk

by jprietove
Mon Apr 22, 2019 11:28 am
Forum: General
Topic: LAG 802.3AD slowness
Replies: 16
Views: 1187

Re: LAG 802.3AD slowness

Acording to https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_Hardware_Offloading only CRS3xxx series supports bonding with hardware offload. It means that other devices do bonding with CPU. CCR1009-7G-1C-1S+PC has 9 cores so it can take 1 Gbps from each G port and bond them in total of ...
by jprietove
Sat Apr 20, 2019 11:28 pm
Forum: General
Topic: LAG 802.3AD slowness
Replies: 16
Views: 1187

Re: LAG 802.3AD slowness

Try using ether 5 and 6, for example. ether 1 to 4 are connected to switch chip and this chip is connected to cpu by 1gbps line. This may be a problem in performance. Check block diagram here: https://i.mt.lv/cdn/rb_files/CCR1009-8G-1S-1Splus-160128140835.png Enviado desde mi Mi A2 mediante Tapatalk
by jprietove
Sat Apr 20, 2019 10:12 pm
Forum: General
Topic: LAG 802.3AD slowness
Replies: 16
Views: 1187

Re: LAG 802.3AD slowness

I'm afraid that bonding is hardware offload only in crs3xx series. In CCR series bonding is done on software. But I've reached 2gbps with bonding on ccr1009 in a transit router. I mean, different IP addresses for source and destination. So there should be a problem in your setup. Enviado desde mi Mi...
by jprietove
Sat Apr 20, 2019 5:30 pm
Forum: General
Topic: CRS326-24G-2S+ Q-in-Q without Service Tag
Replies: 2
Views: 552

Re: CRS326-24G-2S+ Q-in-Q without Service Tag

Follow the examples in https://wiki.mikrotik.com/wiki/Manual:C ... s_switches with ether type 0x8100 in bridge

Enviado desde mi Mi A2 mediante Tapatalk

by jprietove
Wed Apr 17, 2019 2:30 pm
Forum: Wireless Networking
Topic: BTest vs Internet Speed test
Replies: 4
Views: 792

Re: BTest vs Internet Speed test

I suggest this video from recent MUM Europe 2019 in VIenna:
Understanding throughput: https://youtu.be/zsrdgo0Npc8
by jprietove
Tue Apr 16, 2019 11:28 am
Forum: General
Topic: Feature requests
Replies: 1160
Views: 208035

Re: Feature requests - Re Winbox , close all

A feature I would like to see in Winbox is a new selection to close all winbox windows Example - many many windows open in winbox , click close-all and presto they all close and you still have your connected winbox session North Idaho Tom Jones Or I'm not understanding you... or for sure it is the ...
by jprietove
Mon Apr 15, 2019 10:43 pm
Forum: General
Topic: who can I hire to get a export to work as an import an a clone [SOLVED]
Replies: 7
Views: 552

Re: who can I hire to get a export to work as an import an a clone [SOLVED]

Sure a lot of people will be interested. You can also look here for someone near you:

https://mikrotik.com/consultants

Enviado desde mi Mi A2 mediante Tapatalk

by jprietove
Mon Apr 15, 2019 6:45 pm
Forum: General
Topic: Feature requests
Replies: 1160
Views: 208035

Re: Feature requests - Re Winbox , close all

A feature I would like to see in Winbox is a new selection to close all winbox windows
Example - many many windows open in winbox , click close-all and presto they all close and you still have your connected winbox session

North Idaho Tom Jones
Isn't it the existing Session -> Close Windows?
by jprietove
Wed Apr 10, 2019 11:17 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 40112

Re: UKNOF 43 CVE

In ipv6 usual prefix is /64. So a local attack will not be filtered by the rules proposed and the number of possible hosts is 2^64 because ipv6 addresses are 128 bit numbers.

Enviado desde mi Mi A2 mediante Tapatalk

by jprietove
Tue Apr 09, 2019 10:17 am
Forum: Beginner Basics
Topic: PPPoe pools - one for all?
Replies: 2
Views: 352

Re: PPPoe pools - one for all?

Yes, you can use the same pool for all the profiles
by jprietove
Thu Apr 04, 2019 8:23 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 40112

Re: UKNOF 43 CVE

I have done several tests with GNS3 using CHR 6.44.2 (stable) and as long as the router has enough memory, it doesn't crash. In my tests, the attack 'steals' around 180 MiB. Using a CHR with 256 MB, system resources shows a total memory of 224 MiB and free-memory of 197 MiB before attack. During the...
by jprietove
Wed Apr 03, 2019 6:11 pm
Forum: General
Topic: Best (free?) network diagram tool
Replies: 3
Views: 438

Re: Best (free?) network diagram tool

I use GNS3 that is more than a diagram tool and you can also try https://draw.io
by jprietove
Tue Apr 02, 2019 8:28 pm
Forum: RouterBOARD hardware
Topic: Port Will Not Negotiate 1Gbps
Replies: 5
Views: 576

Re: Port Will Not Negotiate 1Gbps

I've used that configuration lots of time. No problem at all. Look your cables, connectors, etc. It should be almost 'plug and play'
by jprietove
Mon Apr 01, 2019 11:22 am
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 40112

Re: UKNOF 43 CVE

I have just tested this beta and I confirm that with 300 Mb RAM the router's memory doesn't fill. A CHR with 300 Mb of RAM with OSPF-v3 has 237 Mb of free-memory and during the attack it keeps on around 200 Mb.

Hopefully this fix will be in long-term and current branches soon.
by jprietove
Mon Apr 01, 2019 11:17 am
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 71353

Re: v6.45beta [testing] is released!

Version 6.45beta23 has been released. What's new in 6.45beta23 (2019-Apr-01 05:51): !) ipv6 - fixed soft lockup when forwarding IPv6 packets; !) ipv6 - fixed soft lockup when processing large IPv6 Neighbor table; ---------------------- Congratulations! I have tested this beta and I confirm that wit...
by jprietove
Sun Mar 31, 2019 12:01 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 40112

Re: UKNOF 43 CVE

This sounds almost exactly the same as what MikroTik will be fixing on Monday.

What would be characters 9, 10, 11, 12 of the md5sum?
Sorry @maznu but I don't get the same md5sum you expected. Maybe mine is a different but correlated attack
by jprietove
Sun Mar 31, 2019 11:03 am
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 40112

Re: UKNOF 43 CVE

I've done my own investigation and I think I can reproduce the problem. First it is important to note that the target of the attack needs not to be the Mikrotik itself: if it is forwarding traffic from an attack, its memory can exhaust and eventually it will reboot. So my lab is similar to this: an ...
by jprietove
Tue Mar 12, 2019 5:40 pm
Forum: Beginner Basics
Topic: CRS 3xxx VLAN configuration
Replies: 2
Views: 335

Re: CRS 3xxx VLAN configuration

Export your config and tell us exactly what you want to achieve
by jprietove
Tue Mar 05, 2019 8:46 pm
Forum: General
Topic: ipv6 strangeness
Replies: 2
Views: 238

Re: ipv6 strangeness

It is not strange, it is called hexadecimal: In the address 2001:db8::33/126 I will look into the last '33'. As it is HEX, in Binary it is 001100 11 The last two bits are not belonging to the prefix, so the prefix is 001100 00 If I write it in HEX again it is 30, os the prefix is 2001:db8::30/126 Th...
by jprietove
Tue Mar 05, 2019 3:19 pm
Forum: Beginner Basics
Topic: Can we create the PPPoE user pool for 500 or 1000?
Replies: 10
Views: 655

Re: Can we create the PPPoE user pool for 500 or 1000?

Pool 10 11 2 has not a next pool

Enviado desde mi Redmi 3 mediante Tapatalk

by jprietove
Sun Mar 03, 2019 5:44 pm
Forum: General
Topic: Taged and untaged to the same interface. [SOLVED]
Replies: 41
Views: 1677

Re: Taged and untaged to the same interface. [SOLVED]

I posted this on my previous answer. Clearly you didn't read it

Enviado desde mi Redmi 3 mediante Tapatalk

by jprietove
Sun Mar 03, 2019 5:16 pm
Forum: General
Topic: Taged and untaged to the same interface. [SOLVED]
Replies: 41
Views: 1677

Re: Taged and untaged to the same interface. [SOLVED]

[admin@R2] > interface bridge vlan add bridge=bridge1 vlan-ids=30 tagged=ether4,ether5 untagged=ether5
failure: interface cannot be in tagged and untagged at the same time

Enviado desde mi Redmi 3 mediante Tapatalk

by jprietove
Sun Mar 03, 2019 4:53 pm
Forum: General
Topic: Taged and untaged to the same interface. [SOLVED]
Replies: 41
Views: 1677

Re: Taged and untaged to the same interface. [SOLVED]

I think you should mark this as solved and forget about it. You asked a question, the answer is simply "no, you can't" and I really don't know why are we still feeding the yroll

Enviado desde mi Redmi 3 mediante Tapatalk

by jprietove
Sun Mar 03, 2019 11:53 am
Forum: General
Topic: Taged and untaged to the same interface. [SOLVED]
Replies: 41
Views: 1677

Re: Taged and untaged to the same interface. [SOLVED]

I don't know exactly what are you asking in this post. One port can be 'tagged' and 'untagged' at the same time for different VLAN-id. Hybrid port is the name. BUT not for the SAME VLAN-ID A hybrid port can be useful in a construction where you have several nodes connected in a dumb switch (not vlan...
by jprietove
Sat Mar 02, 2019 7:12 pm
Forum: General
Topic: How to see what IP is generating traffic over specific port? [SOLVED]
Replies: 2
Views: 306

Re: How to see what IP is generating traffic over specific port? [SOLVED]

Use tool torch

Enviado desde mi Redmi 3 mediante Tapatalk

by jprietove
Thu Feb 21, 2019 5:39 pm
Forum: General
Topic: Security issue when Winbox exposed
Replies: 68
Views: 5954

Re: Security issue when Winbox exposed

No, I haven't missed it: look at the title I have choosen.
by jprietove
Thu Feb 21, 2019 5:25 pm
Forum: General
Topic: Security issue when Winbox exposed
Replies: 68
Views: 5954

Security issue when Winbox exposed

There seems to be an issue that allows bypass firewall and nat if winbox is exposed.
Please read this carefully

https://medium.com/tenable-techblog/mik ... d46398bf24

Enviado desde mi Redmi 3 mediante Tapatalk

by jprietove
Thu Feb 21, 2019 11:49 am
Forum: Beginner Basics
Topic: Mikrotik Packet Tracer
Replies: 3
Views: 717

Re: Mikrotik Packet Tracer

Not analogous but best is: reading, understanding, learning, practicing and a lot of Wireshark
by jprietove
Thu Feb 21, 2019 11:48 am
Forum: General
Topic: I Can't set 802.1p on VLAN for DHCP [probably BUG]
Replies: 9
Views: 652

Re: I Can't set 802.1p on VLAN

Chain should be output. Try this:
/ip firewall mangle
add action=set-priority chain=output new-priority=5 out-interface=vlan2
by jprietove
Wed Feb 06, 2019 2:52 pm
Forum: General
Topic: Severe port flapping on CRS328-24P-4S+ and CRS317-1G-16S+
Replies: 145
Views: 19439

Re: Severe port flapping on CRS328-24P-4S+ and CRS317-1G-16S+

Are any of you using port ether1 or just sfp-plus ports? If you are, remember that "The new Cloud Router Switch 317-1G-16S+RM is a rack-mountable manageable switch with Layer3 features, it has 16 SFP+ ports for high performance 10GbE connectivity and a 1GbE copper port for management. "
by jprietove
Tue Feb 05, 2019 2:31 pm
Forum: General
Topic: High CPU plus Latency plus Packet Drops when bonding with balance-rr
Replies: 11
Views: 1192

Re: High CPU plus Latency plus Packet Drops when bonding with balance-rr

I've been using CCR1016 with bonding in balance_rr with 1.7 Gbps traffic for more than one year, software based (not hardware) and CPU hardly goes more than 5-6%. It would be usefull to know if you are using RouterOS or SwitchOS, which RouterOS/SwitchOS version are you using, an export of your confi...
by jprietove
Thu Jan 31, 2019 2:53 pm
Forum: General
Topic: High CPU plus Latency plus Packet Drops when bonding with balance-rr
Replies: 11
Views: 1192

Re: High CPU plus Latency plus Packet Drops when bonding with balance-rr

What is happening Your router are doing bonding and bridging by software, thats the reason your CPU goes so high. As your traffic is going from only one point to other, the MAC-addresses of all traffic will be the same so if you use layer2 hash, only one path will be choosen. Improving a little Bet...
by jprietove
Thu Jan 31, 2019 10:57 am
Forum: Forwarding Protocols
Topic: Routing filter order
Replies: 11
Views: 2697

Re: Routing filter order

Maybe it's a typo? Look here: /routing bgp peer add address-families=ip,vpnv4 in-filter=casino-in name=up-gcp_casino out-filter=casinio-out remote-address=169.254.0.2 remote-as=65502 ttl=default ^^^^^^^ You wrote casinio-out instead of casino-out
by jprietove
Fri Jan 25, 2019 7:24 pm
Forum: General
Topic: Slow speeds on fibre with pppoe [SOLVED]
Replies: 4
Views: 773

Re: Slow speeds on fibre with pppoe [SOLVED]

Test mtu with ping and no fragment option. VLAN has additional bytes in header so instead of 1480 maybe it's 4 bytes less.


Enviado desde mi Redmi 3 mediante Tapatalk

by jprietove
Thu Jan 24, 2019 10:34 pm
Forum: General
Topic: Bequant tcp traffic booster
Replies: 3
Views: 488

Re: Bequant tcp traffic booster

Anyone has experience in Bequant's tcp optimizer? http://www.bequant.com/bta.html Probably the same can be done by a Mikrotik CCR although they claim some patented technologies. And if someone can make same, send me a pm and give me a price for a 500Mbp backbone connection. Hello wireless Rudy, I h...
by jprietove
Tue Jan 22, 2019 12:39 pm
Forum: Virtualization
Topic: Proxomox Hosted CHR - IP Configuration
Replies: 2
Views: 551

Re: Proxomox Hosted CHR - IP Configuration

Try this:
/ip address add interface=ether1 address=99.88.9.17 network=99.88.7.180
/ip route add dst-address=0.0.0.0/0 gateway=99.88.7.180
by jprietove
Tue Jan 08, 2019 10:23 pm
Forum: General
Topic: load balancing speed problem
Replies: 2
Views: 414

Re: load balancing speed problem

I think you have been very well answered in the other forum viewtopic.php?p=706857#p706857

Enviado desde mi Redmi 3 mediante Tapatalk

by jprietove
Wed Dec 19, 2018 5:10 pm
Forum: General
Topic: server on cloud - what to install?
Replies: 7
Views: 703

Re: server on cloud - what to install?

In AWS you can select Mikrotik CHR at VM creation time. No need to install Linux or anything else... Just choose Mikrotik CHR instead of Windows, Ubuntu or any other thing

Enviado desde mi Redmi 3 mediante Tapatalk

by jprietove
Wed Dec 05, 2018 7:10 pm
Forum: Forwarding Protocols
Topic: OSPF loses routes after days
Replies: 23
Views: 2512

Re: OSPF loses routes after days

I just checked all my routers. All of the ip, network (same being /32), and router IDs are unique to each router. Try also to change interface network-type. Instead of broadcast, it seems your configuration could be PTMP because it (appears to) has a central Router. This way, the routers will not l...
by jprietove
Wed Dec 05, 2018 4:46 pm
Forum: Forwarding Protocols
Topic: OSPF loses routes after days
Replies: 23
Views: 2512

Re: OSPF loses routes after days

Check if there are several routers with same Id. Check also that router up address in loopback interface is correct, with /32 and network equal to address. Sometimes if configuration is copied from one router and pasted in another, and then the loopback IP is changed, the network remains. For exampl...
by jprietove
Mon Nov 26, 2018 9:55 am
Forum: Beginner Basics
Topic: 3011 update
Replies: 10
Views: 1016

Re: 3011 update

Why could you not use the automatic update that ArchilMindiashvili describe above? You can do > System>Packages>> Check For Updates >> Download and install >> Reboot system is updated I can't speak for OP, but there's a legitimate case: when a router doesn't have internet access (for any particular...
by jprietove
Sun Nov 25, 2018 2:21 pm
Forum: General
Topic: IP .2 can't ping out, but it can be pinged. IP .4 acts normal
Replies: 1
Views: 228

Re: IP .2 can't ping out, but it can be pinged. IP .4 acts normal

Try to see what is in ip, ARP. Maybe you have a static assignment for your Mac address and IP address

Enviado desde mi Redmi 3 mediante Tapatalk

by jprietove
Thu Oct 25, 2018 9:36 am
Forum: General
Topic: Extract PPP user list from RB backup
Replies: 1
Views: 258

Re: Extract PPP user list from RB backup

It is not recommended to restore a backup from a MikroTik into another one. But it can work, maybe it will not be fully functional, but I'm pretty sure that after restoring it into a same model router, you will be able to export the configuration you need. After that, reset configuration and build i...
by jprietove
Tue Sep 25, 2018 10:18 pm
Forum: General
Topic: question about transmit hash policy
Replies: 11
Views: 1354

Re: question about transmit hash policy

That's it: it should work ok, as it was an unique 5Gbps interface

Enviado desde mi Redmi 3 mediante Tapatalk

by jprietove
Tue Sep 25, 2018 7:42 pm
Forum: General
Topic: question about transmit hash policy
Replies: 11
Views: 1354

Re: question about transmit hash policy

and i think you have mistake i have up to 5gbps :D you told i am able use up to 5Mbps :D anyway thank you. You are right. 5 Gbps... :D :D and alst question my friend is what will happen if one my slave port bandwidth will be full ? are the other packets drop ? or they will transmit from other slave...
by jprietove
Tue Sep 25, 2018 6:25 pm
Forum: General
Topic: question about transmit hash policy
Replies: 11
Views: 1354

Re: question about transmit hash policy

Hello, in balance rr i think i will get retransmitting segments for tcp/ip If you use same cables (good quality Cat6), same length, it should be OK : no retransmission errors, no jitter and no problems. so its better use layer2-layer3 transmit hash, so when layer2-layer3 transmit hash in enabled i ...
by jprietove
Tue Sep 25, 2018 5:23 pm
Forum: General
Topic: question about transmit hash policy
Replies: 11
Views: 1354

Re: question about transmit hash policy

in addition to my last posts please http://prntscr.com/kyh2a1 1. when i have set layter2-layer3 transmit hash i see outgoing traffic balanced over active LAG ports, but sometimes i see one of the ports outgoing traffic is around 180mb and its not balance, when i check flow i see its from one src ip...
by jprietove
Tue Sep 25, 2018 5:21 pm
Forum: General
Topic: question about transmit hash policy
Replies: 11
Views: 1354

Re: question about transmit hash policy

1. as i understand your explaination because i have a switch behind my routers and my computers are connected to switches i should choose layer2-layer3 transmit poliocy so in this case outgoing traffic will go towards all ports right? so i can have 5gbps throughput for outgoing traffic ? but if i c...
by jprietove
Tue Sep 25, 2018 1:20 pm
Forum: General
Topic: question about transmit hash policy
Replies: 11
Views: 1354

Re: question about transmit hash policy

so my questions are : 1. right now can i have 5gb throughput from my brocade switch to mikrotik ccr 1016 ? You have configured your bonding mode=802.3ad. This means that "LACP balances outgoing traffic across the active ports based on hashed protocol header information and accepts incoming traffic ...
by jprietove
Mon Sep 17, 2018 6:25 pm
Forum: General
Topic: IPSec and OSPFv3
Replies: 2
Views: 757

Re: IPSec and OSPFv3

Well, it was a very long time ago when this question was post in this forum. Maybe this is useful for somebody: IPSec can't transfer multicast traffic, so it is not possible to configure IPSec policy for it. Instead, you can use GRE6 tunnel between your routers and add this GRE interfaces to OSPF-v3...
by jprietove
Tue Jul 03, 2018 10:35 am
Forum: General
Topic: Reference Manual
Replies: 5
Views: 481

Re: Reference Manual

by jprietove
Mon Jul 02, 2018 10:29 pm
Forum: General
Topic: IP address on backup VRRP is invalid [SOLVED]
Replies: 5
Views: 608

Re: IP address on backup VRRP is invalid [SOLVED]

I think, you got your subnet masks wrong. VRRP-Interfaces always should be configured with /32 No, it is not necessary. The objective of VRRP is to have two or more devices for failover. If the main fails, the backup actives the IP that is shared in both routers (that is, configured the SAME IP add...
by jprietove
Mon Jul 02, 2018 6:27 pm
Forum: General
Topic: IP address on backup VRRP is invalid [SOLVED]
Replies: 5
Views: 608

Re: IP address on backup VRRP is invalid [SOLVED]

It is OK: as soon as Master is not reachable, Backup VRRP will put their IPs on valid state.
by jprietove
Sat Jun 09, 2018 10:39 am
Forum: Forwarding Protocols
Topic: OSPF - How large can a flat network grow?
Replies: 8
Views: 1067

Re: OSPF - How large can a flat network grow?

In a WISP covering a very extensive area with 30 PPPoE servers, more than 300 PtMP and more than 2000 CPE we had problem with MPLS: sometimes MPLS forwarding table doesn't follow OSPF. We decided to split the very big OSPF domain into several little ones using iBGP. Routing tables have diminished fr...
by jprietove
Wed Jun 06, 2018 2:04 pm
Forum: Forwarding Protocols
Topic: Temporarily disable BGP full route feed
Replies: 7
Views: 797

Re: Temporarily disable BGP full route feed

You can do it using a static route before disabling BGP Peer:
/ip route add gateway=[ip_default_gateway]
by jprietove
Mon May 21, 2018 3:01 pm
Forum: General
Topic: Certificates - SCEP-SERVER - Get errors, possible bugs?
Replies: 0
Views: 637

Certificates - SCEP-SERVER - Get errors, possible bugs?

TL/TR: Hello, I'm trying to configure an scenario with certificates and I've found a bug and a possible one. [*]Trying to sign a certificate via SCEP only works on CLI. Winbox gets an error "Error in SCEP URL - double field expected" [*]Trying to add Registration Authorities I get an error 'failure...
by jprietove
Thu May 17, 2018 9:19 am
Forum: Wireless Networking
Topic: Wireless P2P with no line of sight
Replies: 1
Views: 307

Re: Wireless P2P with no line of sight

Hello, try yourself different antenna combinatios with MikroTik Wireless Calculator: https://mikrotik.com/calculator
by jprietove
Wed May 09, 2018 8:34 pm
Forum: General
Topic: Netinstall + ubuntu 16.04 [SOLVED]
Replies: 6
Views: 3401

Re: Netinstall + ubuntu 16.04 [SOLVED]

What version of wine are you using ? I'm using Wine 1.6.2 with Ubuntu 16.04.4 LTS, Netinstall for RouterOS v.6.40.1. I've just downloaded Netinstall v.6.42.1 and works OK. Tried with your IP addresses, everything works fine. Please, check: All your computer interfaces are disabled, except your wire...
by jprietove
Wed May 09, 2018 6:26 pm
Forum: General
Topic: Netinstall + ubuntu 16.04 [SOLVED]
Replies: 6
Views: 3401

Re: Netinstall + ubuntu 16.04 [SOLVED]

Hello, I can confirm than NetInstall runs properly on Ubuntu 16.04 using Wine. Instructions for using NetInstall can be found at https://wiki.mikrotik.com/wiki/Manual:Netinstall Be sure to run it as sudo. In my computer I launch it using: gksu wine /media/Compartida/Red/netinstall.exe Press reset bu...
by jprietove
Tue May 01, 2018 7:31 pm
Forum: General
Topic: Bug: ISO8601 timestamp in syslog - always using UTC time
Replies: 4
Views: 1215

Re: Bug: ISO8601 timestamp in syslog - always using UTC time

Hello, after digging I've found a mistake in my rsyslog configuration that led to this problem. Mikrotik remote log is reporting logs with its current time, so I think it is fine.
by jprietove
Tue May 01, 2018 12:53 pm
Forum: General
Topic: Bug: ISO8601 timestamp in syslog - always using UTC time
Replies: 4
Views: 1215

Re: Bug: ISO8601 timestamp in syslog - always using UTC time

Hello. I am having this problem too. CHR version 6.42.1. I'm reporting this as a bug
by jprietove
Thu Apr 19, 2018 10:02 am
Forum: Virtualization
Topic: mikrotik in gns3 and qemu
Replies: 2
Views: 2432

Re: mikrotik in gns3 and qemu

When using GNS3 I prefer to build my own qcow2 image starting from .ISO file. I use this commands: qemu-img create -f qcow2 routeros-6.40.7.qcow2 256M qemu-system-i386 -net none -cdrom mikrotik-6.40.7.iso -m 256M routeros-6.40.7.qcow2 Look the option -net none : this tells QEMU to create the image w...
by jprietove
Mon Apr 16, 2018 1:14 pm
Forum: General
Topic: BGP Peer to only advertise default gateway
Replies: 1
Views: 232

Re: BGP Peer to only advertise default gateway

Be sure that your instance has: redistribute-connected: no redistribute-ospf: no redistribute-other-bgp: no redistribute-rip: no redistribute-static: no client-to-client-reflection: no And you will have no need to use any filter. If this doesn' work, please export here your BGP configuration for bot...
by jprietove
Sun Apr 01, 2018 6:43 pm
Forum: SwOS
Topic: CSS106-1G-4P-1S AutoNegotiation Drops to 100M
Replies: 2
Views: 815

Re: CSS106-1G-4P-1S AutoNegotiation Drops to 100M

First of all, I would check all the cables and verify they are Cat6 or at least Cat5e and they are firmly and well crimped
by jprietove
Fri Mar 30, 2018 9:05 pm
Forum: Forwarding Protocols
Topic: WISP with PPPoE and VLANs
Replies: 5
Views: 1324

Re: WISP with PPPoE and VLANs

IMO, your problem may be caused because 1 public IP address is not enough. I have at home 60 TCP connections with not very much usage of Internet. It goes to near 200 when several devices are used. If you have only 1 IP address for 2000 customers, considering that TCP port is a 16-bit number so ther...
by jprietove
Fri Mar 30, 2018 5:29 pm
Forum: Forwarding Protocols
Topic: Simulating blackhole in lab enviroment
Replies: 2
Views: 521

Re: Simulating blackhole in lab enviroment

Let's say the providers R2 and R3 has AS numbers 65002 and 65003, respectively. If R2 provides a Blackhole community, usually 65002:666, the peer with R1 has an IN-FILTER like this: [admin@MikroTik] > routing filter print Flags: X - disabled 0 chain=bgp-in bgp-communities=65002:666 invert-match=no a...
by jprietove
Mon Feb 12, 2018 8:35 pm
Forum: Scripting
Topic: Find specific firewall nat
Replies: 1
Views: 376

Re: Find specific firewall nat

Similar as you write: /ip firewall nat print where chain=srcnat && action=masquerade && out-interface="bridge-local" If you need it on a script, syntax changes but essentially it is the same: :if ([:len [/ip firewall nat find chain=srcnat && action=masquerade && out-interface="bridge-local"] ] > 0) ...
by jprietove
Wed Jan 31, 2018 1:26 pm
Forum: Forwarding Protocols
Topic: strange vpls up down in mpls chain
Replies: 3
Views: 460

Re: strange vpls up down in mpls chain

It seems that you don't have VPLS interface passive in OSPF.
In OSPF interfaces add all as passive and then, add only the interfaces that has to be active to OSPF, i.e., ether1, ether2...
by jprietove
Fri Dec 01, 2017 3:10 pm
Forum: Beginner Basics
Topic: DHCP-Relay three routers
Replies: 2
Views: 364

Re: DHCP-Relay three routers

Hello: you need R1 to know how to get to 10.10.11.0/24. And R2 needs to know how to get there too. Try the following

Code: Select all

R1
/ip route add dst-address=10.10.11.0/24 gateway=192.168.60.2

R2
/ip route add dst-address=10.10.11.0/24 gateway=192.168.60.6
by jprietove
Thu Nov 30, 2017 8:09 pm
Forum: Beginner Basics
Topic: Failover Script
Replies: 3
Views: 434

Re: Failover Script

Have you considered using 'check-gateway=ping'? From the wiki (https://wiki.mikrotik.com/wiki/Manual:IP/Route) "Periodically (every 10 seconds) check gateway by sending either ICMP echo request (ping) or ARP request (arp). If no response from gateway is received for 10 seconds, request times out. Af...
by jprietove
Thu Nov 30, 2017 8:02 pm
Forum: Beginner Basics
Topic: OSFP need hint.
Replies: 2
Views: 353

Re: OSFP need hint.

Hello. I don't really understand what do you mean when you say "R2, R3 and R4 did not know about each other's existence, but only about R1". You can use different totally-stub areas for R2, R3 and R4. This way, R2, R3 and R4 will have a default gateway that will be R1. BUT they can send packets to a...
by jprietove
Wed Jun 14, 2017 10:10 am
Forum: General
Topic: Bug in ipv6 link-local address is now generated from tunnel local-address
Replies: 8
Views: 1719

Re: Bug in ipv6 link-local address is now generated from tunnel local-address

This issue has been fixed in version 6.39.2. I've tested it and seems it is working fine.

Thank you very much!
by jprietove
Tue Feb 21, 2017 9:09 am
Forum: General
Topic: Bug in ipv6 link-local address is now generated from tunnel local-address
Replies: 8
Views: 1719

Re: Bug in ipv6 link-local address is now generated from tunnel local-address

Thank you very much for your opinions. Anybody knows how to report this bug? Or maybe Mikrotik read this forum and will solve it?

Thank you again!
by jprietove
Wed Feb 15, 2017 10:37 am
Forum: General
Topic: Bug in ipv6 link-local address is now generated from tunnel local-address
Replies: 8
Views: 1719

Bug in ipv6 link-local address is now generated from tunnel local-address

In Release 6.37 there was this improvement: *) tunnel - ipv6 link-local address is now generated from tunnel local-address; Now, using Release 6.38 I've found what I think is a bug: Let's create a 6to4 tunnel with local address 10.0.0.1 and show the associated ipv6 link-local address: [admin@MikroTi...