Community discussions

MikroTik App

Search found 1591 matches

by mducharme
Tue Nov 30, 2021 9:14 am
Forum: RouterOS v7 BETA
Topic: v7.1rc7 [development] is released!
Replies: 134
Views: 12408

Re: v7.1rc7 [development] is released!

We really need at least working VPLS that does not crash the router. Currently setting up two hardware routers with static routing and MPLS, the VPLS tunnel will come up but crash both routers when traffic starts to pass or within a minute or two after the tunnel coming up even without traffic being...
by mducharme
Mon Nov 29, 2021 11:16 pm
Forum: General
Topic: IPv6 Stateless and Prefix Delegation
Replies: 1
Views: 87

Re: IPv6 Stateless and Prefix Delegation

This is fine: /ipv6 pool add name=office prefix-length=56 prefix=xxxx:b840:11::/48 /ipv6 dhcp-server add name=office interface=Office address-pool=office But as for this: /ipv6 nd prefix add prefix=::/0 interface=Office on-link=yes autonomous=no /ipv6 nd add interface=Office managed-address-configur...
by mducharme
Mon Nov 29, 2021 2:02 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc7 [development] is released!
Replies: 134
Views: 12408

Re: v7.1rc7 [development] is released!

Only fully removing QuickSet works in webfig, but it does not work in winbox.
I’m not sure what you mean here. I used a skin to remove Quickset from webfig and it disappears in winbox too so it is not possible to use quickset in winbox. You are experiencing different behaviour?
by mducharme
Mon Nov 29, 2021 12:59 pm
Forum: RouterBOARD hardware
Topic: The big CCR2004 reboot thread (was 2004 hardware issues?)
Replies: 335
Views: 46924

Re: The big CCR2004 reboot thread (was 2004 hardware issues?)

Do you think this device was build for V7 and that V6 is running in compatibility mode (32bit) on a 64bit CPU? It definitely is designed for v7 and runs in compatibility mode in v6, which is why it cannot use all of the RAM on v6. And, mikeeg02 is finding that the CCR2004 seems to not crash on v7 a...
by mducharme
Mon Nov 29, 2021 12:51 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc7 [development] is released!
Replies: 134
Views: 12408

Re: v7.1rc7 [development] is released!

What do you mean? You want to forbid the QuickSet feature for home users? That's a little counter intuitive, no? Yes, but skins can be used to do this. One example that we have is we purposely have both a DHCP client and PPPoE client on ether1. The DHCP client gets a private management IP for the r...
by mducharme
Mon Nov 29, 2021 7:14 am
Forum: RouterOS v7 BETA
Topic: LDP VPLS CHR OS 7rc6
Replies: 9
Views: 787

Re: LDP VPLS CHR OS 7rc6

I have it running from a CHR to a RB5009 and it is stable on both platforms. Are you running it with static routing only? Or OSPF? The instability that myself and others are experiencing is with static routing only, no OSPF. It just crashes the entire device, it doesn't pass anything. We are testin...
by mducharme
Mon Nov 29, 2021 3:24 am
Forum: RouterOS v7 BETA
Topic: v7.1rc7 [development] is released!
Replies: 134
Views: 12408

Re: v7.1rc7 [development] is released!

Mikrotik generally has a good "Why" on things, but boy it's not always easy to see (certainly reasonable people may differ, but getting their POV might help). I suspect the why is likely to do with performance. Probably the ability to have "or" and "else" conditions wi...
by mducharme
Mon Nov 29, 2021 2:47 am
Forum: RouterOS v7 BETA
Topic: v7.1rc7 [development] is released!
Replies: 134
Views: 12408

Re: v7.1rc7 [development] is released!

Is the v7 routing protocol status page going to be updated?
by mducharme
Sun Nov 28, 2021 8:26 am
Forum: RouterOS v7 BETA
Topic: v7.1rc7 [development] is released!
Replies: 134
Views: 12408

Re: v7.1rc7 [development] is released!

High CPU Usage on 7.1rc7 on CCR2004-16G and Rb5009 routing, management and unclassified. almost negligible load on network You may be cherry-picking a single unidentified interface in those screenshots. Please show the overall interfaces list instead, and the overall config for the device. You migh...
by mducharme
Sat Nov 27, 2021 10:43 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc7 [development] is released!
Replies: 134
Views: 12408

Re: v7.1rc7 [development] is released!

I view "device-mode" more like the replacement for "package". It is not a replacement for "package". While it is true that hotspot was a package, socks proxy was never a package by itself, tool fetch was not a package, etc. Now in v7, it's been relegated to a checkbox ...
by mducharme
Sat Nov 27, 2021 9:59 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc7 [development] is released!
Replies: 134
Views: 12408

Re: v7.1rc7 [development] is released!

Yes, somewhat solvable with a skin, but that's a per-user thing that could be forgotten. Forgotten admin tasks lead to Meris. There is a default skin, skins/default.json, that is used by default for all users. You can use the branding package creator in MikroTik "My Account" to make a bra...
by mducharme
Sat Nov 27, 2021 5:54 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc7 [development] is released!
Replies: 134
Views: 12408

Re: v7.1rc7 [development] is released!

This works in my limited testing. But noticed "quickset" isn't a choice, is that intentional or an oversight? The feature locking mechanism seems to be designed for features that could be used to hack into the device or aid in the spread of malware and the Meris botnet. All of the feature...
by mducharme
Fri Nov 26, 2021 8:11 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc7 [development] is released!
Replies: 134
Views: 12408

Re: v7.1rc7 [development] is released!

I see the changelog also...however only longterm shows longterm. Stable and testing shows 7rc7. I do not think this is a bug. This is the result of the change made in 6.49.1 where there was an "upgrade" channel added. You do not see v7 in the development channel anymore on v6 and can only...
by mducharme
Fri Nov 26, 2021 7:42 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc7 [development] is released!
Replies: 134
Views: 12408

Re: v7.1rc7 [development] is released!

Can confirm this as well.
Strange.. I am seeing the changelog no problem in Winbox on my RB4011.
by mducharme
Fri Nov 26, 2021 8:05 am
Forum: RouterOS v7 BETA
Topic: Wireguard client (minimally Android & iOS) - IPv6 traffic not passing through tunnel
Replies: 13
Views: 891

Re: Wireguard Android or iOS client - not working IPv6

With latest releases the Wireguard interfaces do not have link local addresses. This IPv6 is completely broken with Wireguard at the moment.
This isn't correct. IPv6 is working with wireguard for me with rc6 even without a link local. What doesn't work over wireguard is OSPFv3.
by mducharme
Fri Nov 26, 2021 6:37 am
Forum: RouterOS v7 BETA
Topic: CCR2004-16G-2S+ upgrade or not
Replies: 4
Views: 492

Re: CCR2004-16G-2S+ upgrade or not

I believe MikroTik is generally recommending 7.1rc6 for most devices now that shipped with 7.0.x stable.
by mducharme
Thu Nov 25, 2021 10:35 pm
Forum: RouterBOARD hardware
Topic: MikroTik CCR1072-1G-8S+ Port SFP Stuck Issue
Replies: 1
Views: 460

Re: MikroTik CCR1072-1G-8S+ Port SFP Stuck Issue

We have had this issue randomly with both CCR1072 and CCR1036 models where sometimes one or several SFP+ ports start only passing traffic one way, but both sides show running, and have to bounce them like this. In our case we use the MikroTik SFP+ DAC cables in those ports - I suspect the problem ma...
by mducharme
Thu Nov 25, 2021 6:59 am
Forum: RouterOS v7 BETA
Topic: LDP VPLS CHR OS 7rc6
Replies: 9
Views: 787

Re: LDP VPLS CHR OS 7rc6

VPLS is working very stable for me in 7.1rc6 on CHR. Running with PCIe pass-thru of Intel NIC's
I had someone else confirm it works on CHR but is broken on all of the hardware routers. It still should not be green on the v7 Routing Protocol Status page if it only works on CHR and nothing else.
by mducharme
Thu Nov 25, 2021 12:37 am
Forum: RouterOS v7 BETA
Topic: v7.1rc6 [development] is released!
Replies: 146
Views: 27004

Re: v7.1rc6 [development] is released!

I don't know the exact command, but you would need to do an UPDATE query with a LEFT JOIN for the same table twice (the radacct table both times) WHERE the delegatedipv6prefix field is NULL to SET delegatedipv6prefix to the prefix found in the matching accounting entry for DHCPv6 RADIUS accounting (...
by mducharme
Sun Nov 21, 2021 9:56 pm
Forum: RouterOS v7 BETA
Topic: Help needed to translate PCC routerOsV6 firewall mangle to routerOsV7
Replies: 2
Views: 362

Re: Help needed to translate PCC routerOsV6 firewall mangle to routerOsV7

I haven't tried PCC in v7 yet, but there shouldn't really be anything that needs translation - all you should have to do is add the routing table with the name of the routing mark. ex:
/routing table add disabled=no fib name=to_ether1
by mducharme
Sun Nov 21, 2021 9:41 am
Forum: RouterOS v7 BETA
Topic: v7.1rc6 [development] is released!
Replies: 146
Views: 27004

Re: v7.1rc6 [development] is released!

Delegated IPv6 Prefix Parameter is still not included in Radius Accounting Packet for PPP Service. As I said before, If I were you, I would try to create an SQL script that automatically updates the PPP accounting sessions with the IPv6 DHCP accounting information. It should be possible at least, n...
by mducharme
Sat Nov 20, 2021 2:05 pm
Forum: Forwarding Protocols
Topic: proxy-arp only for VPN connections?
Replies: 2
Views: 399

Re: proxy-arp only for VPN connections?

You don't *have* to use proxy-arp for VPN. Simply have your PPTP and L2TP configured to assign addresses in a range that is not in your LAN subnet and you will be able to reach the LAN devices just fine from the VPN without proxy-arp being enabled. Ex. if your LAN subnet is 192.168.88.0/24 then have...
by mducharme
Sat Nov 20, 2021 12:34 pm
Forum: RouterOS v7 BETA
Topic: LDP VPLS CHR OS 7rc6
Replies: 9
Views: 787

Re: LDP VPLS CHR OS 7rc6

VPLS is working very stable for me in 7.1rc6 on CHR. Running with PCIe pass-thru of Intel NIC's I haven't tried with CHR, but for both me and another user who are testing, VPLS has not worked successfully since it turned "green" on the v7 Routing Protocol Status page. It is a simple confi...
by mducharme
Fri Nov 19, 2021 5:49 am
Forum: RouterOS v7 BETA
Topic: LDP VPLS CHR OS 7rc6
Replies: 9
Views: 787

Re: LDP VPLS CHR OS 7rc6

Yes,

VPLS is broken in rc6 and the other rc's before. It doesn't transmit for a bit and then causes spontaneous reboots of the routers. I'm hoping to see improvements in rc7.
by mducharme
Fri Nov 19, 2021 4:50 am
Forum: Forwarding Protocols
Topic: Migrate BGP to another company address
Replies: 5
Views: 804

Re: Migrate BGP to another company address

If you are using full tables, OSPF can't handle those, so you will want to iBGP peer those two routers to make sure that they have the same view of the global routing table. If you are only getting a default route, that probably isn't necessary.
by mducharme
Fri Nov 19, 2021 4:18 am
Forum: General
Topic: IPv4 mode for Winbox
Replies: 8
Views: 649

Re: IPv4 mode for Winbox

It might be better if Winbox could support "happy eyeballs" in cases where the DNS successfully resolves to both IPv4 and IPv6 addresses. I'm not sure how difficult that would be, though.
by mducharme
Fri Nov 19, 2021 1:51 am
Forum: RouterOS v7 BETA
Topic: [bug?]Wireguard does work with same interface with many peers
Replies: 6
Views: 711

Re: [bug?]Wireguard does work with same interface with many peers

add allowed-address=0.0.0.0/0 interface=home-vpn public-key="leq6TcW70L/381zmBIiVIp5H18FhG1H0z3R6Iq7yzW8=" add allowed-address=0.0.0.0/0 interface=home-vpn public-key="rVR+SMf90M/EvjEeUwS1Dd+ji8B/nHTmZR4wqGQuxBI=" This is the problem. When having multiple peers on a single inter...
by mducharme
Thu Nov 18, 2021 4:34 am
Forum: RouterOS v7 BETA
Topic: Using WifiWave2 to bridge two Audience wirelessly, thoughts?
Replies: 5
Views: 767

Re: Using WifiWave2 to bridge two Audience wirelessly, thoughts?

They need to add "four address frame support" into wifiwave2 before it will support bridging.
by mducharme
Thu Nov 18, 2021 3:38 am
Forum: Announcements
Topic: v6.49.1 [stable] is released!
Replies: 129
Views: 19013

Re: v6.49.1 [stable] is released!

PLEASE ADD THE OPPORTUNITY TO DISABLE QUICKSET,
I believe you can do this now in v7 with webfig skins, as they work in winbox. I'm not sure if this works with the MikroTik app yet though.
by mducharme
Thu Nov 18, 2021 12:09 am
Forum: Announcements
Topic: v6.49.1 [stable] is released!
Replies: 129
Views: 19013

Re: v6.49.1 [stable] is released!

It is worrisome that it sounds like 6.49.1 has not fixed all of the upgrade issues where devices go into boot loops. Perhaps there were two causes of this and MikroTik has fixed only one.
by mducharme
Wed Nov 17, 2021 3:11 pm
Forum: Announcements
Topic: v6.49.1 [stable] is released!
Replies: 129
Views: 19013

Re: v6.49.1 [stable] is released!

What is this? !) device-mode - added feature locking mechanism;

I see you have "enterprise" and "home" as device modes, what is the difference?
by mducharme
Wed Nov 17, 2021 2:38 pm
Forum: Forwarding Protocols
Topic: IS-IS
Replies: 54
Views: 22108

Re: IS-IS

A lot of companies use RIP because they have older Cisco devices with licenses that only allow for RIP and do not allow for the use of more standard protocols like OSPF. Eventually as those devices are replaced, hopefully RIP will no longer be necessary.
by mducharme
Wed Nov 17, 2021 12:37 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 178
Views: 50672

Re: Advanced Routing Failover without Scripting

Unfortunately, no: routes with interface specified do not participate in recursive route lookup, at least in RouterOS v6 Hi Chupaka, As @anav points out above, you might want to update your tutorial to increase target-scope to be one more than scope, as that is necessary on RouterOS v7. This is not...
by mducharme
Wed Nov 17, 2021 7:54 am
Forum: Forwarding Protocols
Topic: IS-IS
Replies: 54
Views: 22108

Re: IS-IS

OSPF is more popular and supported in general, but IS-IS is much preferred in the service provider space. +1 for IS-IS
by mducharme
Tue Nov 16, 2021 4:24 am
Forum: General
Topic: Has MikroTik changed something with SSH output?
Replies: 5
Views: 471

Re: Has MikroTik changed something with SSH output?

What version did MikroTik change this? 7.1beta3 and later, and 6.49 and later. I haven't checked 6.48.5. RANCID needed an update as this change broke its ability to backup configs. They had to append "+cte200w" to the username instead of "+ct200w", as described on the RouterOS C...
by mducharme
Tue Nov 16, 2021 2:46 am
Forum: General
Topic: Has MikroTik changed something with SSH output?
Replies: 5
Views: 471

Re: Has MikroTik changed something with SSH output?

Yes, they have recently changed some things. What are you using to backup the config via SSH?
by mducharme
Mon Nov 15, 2021 11:59 pm
Forum: Wireless Networking
Topic: WPA3 in September?
Replies: 11
Views: 3312

Re: WPA3 in September?

Would be nice to have this feature in the testing branch, I don't see why I need to deal with ros7 to have something that's been out for months Because it is likely impossible. RouterOS 6 uses a kernel that is 10 years old. RouterOS 7 uses a kernel from last year. Probably the kernel from 10 years ...
by mducharme
Mon Nov 15, 2021 8:30 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 3.4 (Graphing everything) 💾 🛠 💻 📊
Replies: 31
Views: 2964

Re: 📌 Tool: Using Splunk to analyse MikroTik logs 3.4 (Graphing everything) 💾 🛠 💻 &#1282

I agree, there are many uses of this device tracking and control that extend beyond kids. I can also see potential for enhancing it even more with a few more features - just a few useful ones I have thought of: - The ability to be able to create a simple queue per host that includes the IPv4 address...
by mducharme
Mon Nov 15, 2021 1:25 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8485

Re: Mikrotik router Hacked!!!

Is not possible downgrade RouterBOOT or RouterOS prior to factory version. This isn't always the case - it is actually sometimes possible to downgrade RouterOS below the factory version (my coworker did it before), but it is not true for RouterBOOT - it is always impossible to downgrade RouterBOOT ...
by mducharme
Mon Nov 15, 2021 3:24 am
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8485

Re: Mikrotik router Hacked!!!

I disagree about having to make versions with and without protection and it is hard to ensure that that resolves the issue, and it certainly probably doesn't with older versions and the potential threat of a downgrade. I think it is a feature they can leave in there, but I wonder if they can potenti...
by mducharme
Mon Nov 15, 2021 2:36 am
Forum: Wireless Networking
Topic: How to bridge 3 buildings wirelessly
Replies: 16
Views: 1067

Re: How to bridge 3 buildings wirelessly

If you have line of sight, you can do 60ghz PTMP, with an AP at one site and subscriber radios at the other three sites.
by mducharme
Sun Nov 14, 2021 11:14 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8485

Re: Mikrotik router Hacked!!!

Perhaps MikroTik could add something in the future that could prevent downgrade to the older versions that allowed setting this without pushing the button?
by mducharme
Sun Nov 14, 2021 12:26 pm
Forum: General
Topic: To MT: Keep accounting (v7.x)
Replies: 32
Views: 2284

Re: To MT: Keep accounting (v7.x)

I have not looked at Kid Control. Can you there see traffic to/from all devices without adding one and one device to a list. Can those data be sent out using Syslog? Yes, to both. Kid Control tracks devices and packets sent/received by those devices and current rate for those devices, even if those...
by mducharme
Sun Nov 14, 2021 11:35 am
Forum: General
Topic: To MT: Keep accounting (v7.x)
Replies: 32
Views: 2284

Re: To MT: Keep accounting (v7.x)

I agree, a docker container would make the most sense for this functionality. If all you need to track is the bandwidth used by individual clients and graph those, /ip kid-control devices should be sufficient If you need more detail to see what destinations those clients went to and what they used, ...
by mducharme
Sun Nov 14, 2021 10:04 am
Forum: RouterBOARD hardware
Topic: RB5009 SFP+ 10G Optical & Copper DAC w/Intel X520-DA1
Replies: 4
Views: 1142

Re: RB5009 SFP+ 10G Optical DAC w/Intel X520-DA1

Have you tried changing the sfp-rate-select setting? Apparently with some transceivers that setting matters.
by mducharme
Sun Nov 14, 2021 2:31 am
Forum: General
Topic: To MT: Keep accounting (v7.x)
Replies: 32
Views: 2284

Re: To MT: Keep accounting (v7.x)

There has to be another solution for that. I do not care about /ip accounting and think it probably should be removed as to not clutter things up with useless old components. Maybe you can use one netflow collector and have something run through that to generate RRD graphs on 100 different pages, on...
by mducharme
Sat Nov 13, 2021 11:55 pm
Forum: RouterOS v7 BETA
Topic: RB5009 - RouterOS v7.1rc6: New user help please? [SOLVED]
Replies: 14
Views: 1546

Re: RB5009 - RouterOS v7.1rc6: New user help please? [SOLVED]

I always start with the default MikroTik firewall rules and make changes from there, if necessary. I see no need to reinvent the wheel and MikroTik does a very good job with the default rules. You can always see what the defaults were by running /system default-configuration print from the command l...
by mducharme
Sat Nov 13, 2021 6:38 am
Forum: RouterOS v7 BETA
Topic: 7.1rc6 MIPSBE? serious OSPF v3 IPv6 interface-template problems
Replies: 9
Views: 938

Re: 7.1rc6 MIPSBE? serious OSPF v3 interface-template problems

Does that last across a reboot? Its the initial detection of the interfaces BEFORE they are added to the OSPFv3 instance as interfaces that seems to be the issue.
Yes, it works fine after a reboot. OSPFv3 still comes up as before.
by mducharme
Sat Nov 13, 2021 12:40 am
Forum: RouterOS v7 BETA
Topic: some quick comments on configuring cake
Replies: 22
Views: 3969

Re: some quick comments on configuring cake

I have a question about priority QoS in cake. Our customers IP packets are encapsulated in PPPoE frames, which are then encapsulated in ethernet frames (VPLS tunnel), which then have two MPLS labels placed on them, which then have a VLAN header attached as the outermost layer. Is cake capable of rea...
by mducharme
Fri Nov 12, 2021 2:43 am
Forum: RouterOS v7 BETA
Topic: v7.1rc6 [development] is released!
Replies: 146
Views: 27004

Re: v7.1rc6 [development] is released!

What entries are to be expected in /routing/table ? I had the same issue with a dynamic and static "main" table after upgrading from ROS 6. I had to reset configuration to no-defaults and paste the .rsc back in to fix it. It did not seem to be possible to delete the extra static "mai...
by mducharme
Fri Nov 12, 2021 2:04 am
Forum: RouterOS v7 BETA
Topic: routeros7 socks packet to another gateway not working
Replies: 4
Views: 1068

Re: routeros7 socks packet to another gateway not working

ros 7 beta 6 , still have problem
You have to also manually define "vpn" as a routing table in v7 otherwise it will not work, it is a new feature:
/routing table
add disabled=no fib name=vpn
by mducharme
Thu Nov 11, 2021 10:04 pm
Forum: RouterOS v7 BETA
Topic: 7.1rc6 MIPSBE? serious OSPF v3 IPv6 interface-template problems
Replies: 9
Views: 938

Re: 7.1rc6 MIPSBE? serious OSPF v3 interface-template problems

Does that last across a reboot? Its the initial detection of the interfaces BEFORE they are added to the OSPFv3 instance as interfaces that seems to be the issue. I can't do a reboot at the moment but I will try that after. You might be having the issue with link local addresses sometimes missing o...
by mducharme
Thu Nov 11, 2021 5:13 pm
Forum: RouterOS v7 BETA
Topic: 7.1rc6 MIPSBE? serious OSPF v3 IPv6 interface-template problems
Replies: 9
Views: 938

Re: 7.1rc6 MIPSBE? serious OSPF v3 interface-template problems

Just try bringing up IPv6 address on an OSPFv3 interface on the MIPSBE device.... No soap according to my current tries... It comes up, the OSPF interface comes up, and an OSPF route to the new subnet appears on the ARM device that is a neighbor of the MIPSBE device. I can also create multiple VLAN...
by mducharme
Thu Nov 11, 2021 3:49 am
Forum: RouterOS v7 BETA
Topic: 7.1rc6 MIPSBE? serious OSPF v3 IPv6 interface-template problems
Replies: 9
Views: 938

Re: 7.1rc6 MIPSBE? serious OSPF v3 interface-template problems

NOTE: After seeing forum comments about 'networks=""' and 'prefixes=''"' redid templates from CLI via ssh instead of winbox or webfig. Having 'networks' set or any non local IPv6 address on the interface would prevent it from activating on my MipsBE routers. yes, there are a lot of t...
by mducharme
Wed Nov 10, 2021 9:26 pm
Forum: RouterOS v7 BETA
Topic: 7.1rc6 MIPSBE? serious OSPF v3 IPv6 interface-template problems
Replies: 9
Views: 938

Re: 7.1rc6 MIPSBE? serious OSPF v3 interface-template problems

OSPFv3 works fine for me. I see an issue in your config export:

add area=backbone-v3 cost=10 interfaces=dms0 prefix-list="" priority=1

You probably do not want prefix-list="".
by mducharme
Wed Nov 10, 2021 2:57 am
Forum: Forwarding Protocols
Topic: Migrate BGP to another company address
Replies: 5
Views: 804

Re: Migrate BGP to another company address

Is there a way we can advertise the same /24 on this router too, simultaneously? Or is it best to establish BGP session but not advertise the prefixes yet? You could only advertise the same /24 if the two locations are connected by some other means (ex. layer 2 circuit between them), or at least so...
by mducharme
Tue Nov 09, 2021 3:48 am
Forum: RouterOS v7 BETA
Topic: v7.1rc6 [development] is released!
Replies: 146
Views: 27004

Re: v7.1rc6 [development] is released!

using RouterOS 7.1RC6 with EVE-NG, when we configure OSPFv3 when starting the routers, everything works perfectly when turning off the lab and turning on OSPV3 again stops working, and does not form a neighbor Confirmed, OSPFv3 is also not working for me in rc6. It was working in rc5 I'm pretty sur...
by mducharme
Tue Nov 09, 2021 1:57 am
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 240
Views: 49991

Re: v6.49 [stable] is released!

Mikrotik going from proper RouterBOOT versioning to making it always the same as ROS version was the worst decision ever. There are rarely any RouterBOOT related changes in a changelog, so it's likely that only change is version number string. This stupid system also completely hides any importance...
by mducharme
Mon Nov 08, 2021 10:22 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc6 [development] is released!
Replies: 146
Views: 27004

Re: v7.1rc6 [development] is released!

Hopefully Winbox in a VRF will follow? Winbox in a VRF is already there it looks like, but is missing from the changelog. It is in the v7 Routing Protocol Status page. Edit: They appear to have just edited the page to remove the "winbox" mention after I posted that, but the setting is sti...
by mducharme
Mon Nov 08, 2021 10:19 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc6 [development] is released!
Replies: 146
Views: 27004

Re: v7.1rc6 [development] is released!

/routing/rules still incorrectly handles min-prefix=0 No VPLS fix? VPLS is crashing the router in rc4 and rc5 whenever you try to put traffic through it, and I don't see any fixes in rc6. IMO, it really shouldn't be "green" in the v7 routing protocol status page like it is. A tunnel coming...
by mducharme
Mon Nov 08, 2021 6:28 am
Forum: Beginner Basics
Topic: RouterOS v7.0.5 Dual PPPoE Wan Setup.
Replies: 15
Views: 1435

Re: RouterOS v7.0.5 Dual PPPoE Wan Setup.

is there any1 that has a working setting for routeros 7 with dual wan pppoe setup with loadbalancing and failover that works? if there, can they share the setup here please? thanx. The issue might be the check-gateway=ping setting, it doesn't make sense for PPPoE since you can't really ping an inte...
by mducharme
Mon Nov 08, 2021 12:48 am
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 240
Views: 49991

Re: v6.49 [stable] is released!

and extra wear. it is nonsense to align ROS and bootloader version whrn changes are so infrequent. We don't upgrade RouterOS often. Our last standard version was 6.44.5 and early this year we adopted 6.47.9 as the new standard version after a lot of testing, so there are almost always guaranteed to...
by mducharme
Sun Nov 07, 2021 11:00 pm
Forum: RouterBOARD hardware
Topic: Make VLAN mgmt more easy, please
Replies: 3
Views: 885

Re: Make VLAN mgmt more easy, please

Taken an example from Zyxel attached, way easier. This isn't that much harder with RouterOS. Here is the equivalent: /interface bridge port add bridge=bridge interface=ether1 pvid=640 add bridge=bridge interface=ether2 pvid=2 add bridge=bridge interface=ether3 pvid=10 add bridge=bridge interface=et...
by mducharme
Sat Nov 06, 2021 3:37 pm
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 240
Views: 49991

Re: v6.49 [stable] is released!

You could (and should) have skipped that... Personally I disagree on this, I always do the RouterBOOT upgrades. MikroTik says the issue only appears here when the RouterBOOT upgrade is done from a very old version, 6.41.4 or older. We have upgraded quite a few devices successfully with no issues be...
by mducharme
Sat Nov 06, 2021 3:24 pm
Forum: RouterBOARD hardware
Topic: Firmware upgrade issues with 6.48.5 and 6.49
Replies: 4
Views: 1002

Re: Firmware upgrade issues with 6.48.5 and 6.49

I would generally advise upgrading the firmware at the same time, but just be careful about the release. Even if it is a new long term or new stable, do not assume it is working properly - wait at least a few weeks for the early reports from users before pulling the trigger, and do some tests in a l...
by mducharme
Sat Nov 06, 2021 2:57 pm
Forum: Announcements
Topic: v6.48.5 [long-term] is released!
Replies: 177
Views: 44756

Re: v6.48.5 [long-term] is released!

this version is a disaster.... If you see the thread for 6.49 (which has the same issues), MikroTik found that this issue only happens when you are upgrading from a device that has a very old RouterBOOT firmware (6.41.4 or older). If the RouterBOOT firmware is newer than 6.41.4 it *should* upgrade ...
by mducharme
Sat Nov 06, 2021 2:07 pm
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 240
Views: 49991

Re: v6.49 [stable] is released!

upgraded RB2011 from 6.48.3 to 6.48.5 and after second reboot (firmware upgrade) it has gone in netboot mode. Was it running firmware 6.48.3 before, or an older firmware? Above, MikroTik says that this happens if the device is running 6.41.4 or older before the upgrade, if it is running newer firmw...
by mducharme
Sat Nov 06, 2021 5:32 am
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26166

Re: v7.1rc5 [development] is released!

I just tried disabling my ether5 and ether2 HW offload turned active. So the HW offload is only meant to support one bridge due to RB4011 hardware limitations correct? With all MikroTik devices, you can only have one bridge that is hardware offloaded per switch chip. In your case bridge1 was being ...
by mducharme
Sat Nov 06, 2021 5:26 am
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26166

Re: v7.1rc5 [development] is released!

I actually have 2 bridges enabled. Is this the cause of the disabled HW offload? It is the case in both RouterOS v6 and v7 that if you have more than one bridge on a device, only one bridge can have hardware offload (per switch chip). Therefore it is better to use bridge VLAN filtering and multiple...
by mducharme
Sat Nov 06, 2021 5:10 am
Forum: General
Topic: Client isolation within VLAN and fast roaming [SOLVED]
Replies: 55
Views: 4103

Re: Client isolation within VLAN and fast roaming [SOLVED]

The point is to prevent wireless clients associated to different cAPs from talking to each other, plus it needs to be selective per VLAN. So your remark is important in terms that switch chip rules cannot prevent 2.4 GHz clients of a cAP from talking to 5 GHz clients of the same cAP, but due to the...
by mducharme
Sat Nov 06, 2021 4:59 am
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26166

Re: v7.1rc5 [development] is released!

There are 2 switch groups, SW1 (ether1-5), SW2 (ether6-10)
How many bridges do you have? I see your bridge is called BR1, do you have a BR2?
by mducharme
Sat Nov 06, 2021 4:53 am
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26166

Re: v7.1rc5 [development] is released!

Hello, I believe I have found a bug with treatment of /routing/rules with min-prefix set. The documentation states: min-prefix (integer [0..4294967295]) | Equivalent to Linux ip rule suppress_prefixlength . For example to suppress default route in routing decision set the value to 0. However, settin...
by mducharme
Sat Nov 06, 2021 3:01 am
Forum: RouterBOARD hardware
Topic: hAP ac³ - Port for Netinstall?
Replies: 4
Views: 957

Re: hAP ac³ - Port for Netinstall?

I need 100% certainty. I tried all ports and nothing happens !!!
Who used netinstall on port 1?
We have netinstalled over 600 hap ac3 units on port 1.
by mducharme
Fri Nov 05, 2021 2:18 pm
Forum: Announcements
Topic: v6.48.5 [long-term] is released!
Replies: 177
Views: 44756

Re: v6.48.5 [long-term] is released!

Unless you can instruct distributors to accept free returns/swaps of bricked hardware for swap for the duration?
Can’t you just netinstall the device to recover it? Others were reporting that that was working.
by mducharme
Thu Nov 04, 2021 9:44 pm
Forum: Wireless Networking
Topic: RADIUS Attribute (Mikrotik-Rate-Limit) for Wireless AP
Replies: 2
Views: 598

Re: RADIUS Attribute (Mikrotik-Rate-Limit) for Wireless AP

Client-Tx-Limit is only supported when a RouterBOARD is the client. It is up to the client to impose a limit on itself.
by mducharme
Wed Nov 03, 2021 7:41 am
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 240
Views: 49991

Re: v6.49 [stable] is released!

I have a bunch of routers that I am looking to upgrade to 6.49 but I'm very worried by these reports of issues, even though I haven't experienced any myself, so I am holding off just to be safe. I am hoping to see a 6.49.1 relatively soon that might fix this.
by mducharme
Mon Nov 01, 2021 11:45 pm
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 240
Views: 49991

Re: v6.49 [stable] is released!

Somebody else had reported that it wasn't actually the routerboot firmware that did it, but simply the second reboot after the successful upgrade causes the issue even if you don't upgrade routerboot. I have no idea what is actually the case.
by mducharme
Mon Nov 01, 2021 2:54 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26166

Re: v7.1rc5 [development] is released!

 /interface/bridge/set [find where name=bridge] protocol-mode=none 
I agree - changing something like the RSTP setting should not result in getting a new prefix from the pool.
by mducharme
Mon Nov 01, 2021 2:41 pm
Forum: RouterBOARD hardware
Topic: hAP ac³ - Port for Netinstall?
Replies: 4
Views: 957

Re: hAP ac³ - Port for Netinstall?

Use ether1, like most devices.
by mducharme
Fri Oct 29, 2021 7:53 pm
Forum: RouterOS v7 BETA
Topic: Recursive Routes
Replies: 5
Views: 1752

Re: Recursive Routes

The target scope must be larger than the scope of the route over which you want to resolve the gateway. Set at least to 11 Why was this changed from a less-than-or-equal-to (in RouterOS v6) to a less-than (in v7)? In v6 the target scope must be at least the size of the scope, so 10 would work. Was ...
by mducharme
Thu Oct 28, 2021 9:37 am
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26166

Re: v7.1rc5 [development] is released!

What exactly is Fixed... Is it the issue with Radius not Recording PD.????
I doubt it is the feature you (and me as well) are wanting. The RADIUS not recording prefix delegation is not a bug, it is the lack of a feature.
by mducharme
Thu Oct 28, 2021 12:20 am
Forum: General
Topic: Client isolation within VLAN and fast roaming [SOLVED]
Replies: 55
Views: 4103

Re: Client isolation within VLAN and fast roaming [SOLVED]

Perhaps I missed it, but why is there a need to deploy these bridge filter rules on all CAP devices? Isn't it just easier to set horizon=1 for the bridge ports for wlan1 and wlan2? I've never tried it, but I wonder if the "bridge horizon" setting under CAPsMAN datapath config will work whe...
by mducharme
Wed Oct 27, 2021 1:18 am
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26166

Re: v7.1rc5 [development] is released!

I've confirmed that VPLS still crashes the device like it did in rc4.
by mducharme
Tue Oct 26, 2021 10:35 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26166

Re: v7.1rc5 [development] is released!

I lost a whole bunch of random config and capsman was completely busted. I restored the .backup file I made in rc4 just before upgrade and everything is back again and fine now. I would recommend taking a backup just before upgrade just in case.
by mducharme
Tue Oct 26, 2021 9:31 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26166

Re: v7.1rc5 [development] is released!

Upgrade from 7.1rc4 resulted in losing all bridge ports on switch chip 2 only (ports 6-10), I had to re-add the ports.
by mducharme
Tue Oct 26, 2021 8:32 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26166

Re: v7.1rc5 [development] is released!

*) wireguard - do not consider WireGuard interface as ethernet; I dont understand?? I have RC4 wireguard and my wireguard interface DOES NOT SHOW UP under the Ethernet Tab (under Interface list). It does show up as an entry under the general tab of INTERFACE as does an SSTP connection etc.............
by mducharme
Mon Oct 25, 2021 2:15 pm
Forum: General
Topic: create .alter file for tr069 avsystem
Replies: 2
Views: 362

Re: create .alter file for tr069 avsystem

Using TR069 to run a .alter is the same as running /import file=whatever.alter

Test the .alter first with /import before using TR069 to push it
by mducharme
Sun Oct 24, 2021 12:09 am
Forum: General
Topic: CCR2004-1G-12S+2XS - Strange packet loss
Replies: 2
Views: 570

Re: CCR2004-1G-12S+2XS - Strange packet loss

Please see this: viewtopic.php?t=82883

Having some number of lost packets is normal for any UDP btest in the receive direction, so I wouldn't assume that that indicates a fault in the device.
by mducharme
Thu Oct 21, 2021 4:48 am
Forum: Forwarding Protocols
Topic: MPLS bugs, had enough
Replies: 16
Views: 1653

Re: MPLS bugs, had enough

Speed. MPLS doesn't even touch the routing table so traffic carried by MPLS labels tends to gain about 30% more bandwidth (if CPU is a limiting factor) and also reduces latency quite a bit Most carriers use MPLS internally Yes, I am aware. More bandwidth, but loss of some control since it bypasses ...
by mducharme
Thu Oct 21, 2021 3:38 am
Forum: Forwarding Protocols
Topic: MPLS bugs, had enough
Replies: 16
Views: 1653

Re: MPLS bugs, had enough

We havnt used VPLS in a while, still get problems with MPLS with regular routing of traffic. So advertising filters have nothing to do with it I don't think you understand - by using advertise filters, you can make it so that only your VPLS traffic has MPLS labels placed on it and nothing else, so ...
by mducharme
Wed Oct 20, 2021 7:32 pm
Forum: RouterOS v7 BETA
Topic: How to check if fasttrack is really working in V7
Replies: 3
Views: 872

Re: How to check if fasttrack is really working in V7

I recently migrate one of my router's to RouterOS v7rc4 version. I notice fasttrack counters (either packages/bytes) are the same for this firewall rule and for the subsequence one that accept new traffic in forward. If I'm not wrong, these counters should be different when fasttrack is active, due...
by mducharme
Tue Oct 19, 2021 2:28 am
Forum: Forwarding Protocols
Topic: MPLS bugs, had enough
Replies: 16
Views: 1653

Re: MPLS bugs, had enough

RouterOS v7 is basically completely different as far as how the routing engine is designed, and MPLS is much more integrated into the FIB so that you can see all of the MPLS label information inside the routing table as well. Unfortunately it is also one of the least stable parts of the RouterOS v7 ...
by mducharme
Sat Oct 16, 2021 2:03 pm
Forum: Beginner Basics
Topic: Stuck on first ROS baby steps: PPPOE-client not connecting
Replies: 7
Views: 1049

Re: Stuck on first ROS baby steps: PPPOE-client not connecting

When I set the Draytek without bridge mode, it connects without problems. So I'm thinking it cannot be a restriction to the Ubiquiti MAC? Sometimes there can be a small number of cached learned MACs on the ISP provided CPE device (usually set to around two or three) to prevent accidentally plugging...
by mducharme
Sat Oct 16, 2021 3:53 am
Forum: Beginner Basics
Topic: Stuck on first ROS baby steps: PPPOE-client not connecting
Replies: 7
Views: 1049

Re: Stuck on first ROS baby steps: PPPOE-client not connecting

It seems like "received PADO with unknown host-uniq, dropping" is an issue that kept coming up on different ROS versions since at least 2010, cannot find a solution anywhere. I don't think this message indicates an issue at all, but is instead a red herring. I would guess that else is try...
by mducharme
Wed Oct 13, 2021 9:45 pm
Forum: General
Topic: Wireguard proper server config
Replies: 35
Views: 2232

Re: Wireguard proper server config

Yes, exactly, I never suggested that the actual client should not be configured with the server's port - it needs that. But there is no reason to specify the port that the client peer will use on the server side in the peer settings. For instance, it doesn't make sense to tell your Wireguard server ...
by mducharme
Wed Oct 13, 2021 4:02 am
Forum: RouterOS v7 BETA
Topic: Feature Request - NAT64/DNS64 CGN
Replies: 10
Views: 6395

Re: Feature Request - NAT64/DNS64 CGN

Couldn't you run Jool in Docker now?
by mducharme
Tue Oct 12, 2021 2:34 am
Forum: General
Topic: Wireguard proper server config
Replies: 35
Views: 2232

Re: Wireguard proper server config

The issue I have is that users will not realize that adding the IP creates the static route for you. They should realize this as it happens for all interfaces, not just wireguard. For instance, in the factory mikrotik configuration for most of the SOHO devices, the bridge has the IP address 192.168...
by mducharme
Tue Oct 12, 2021 12:37 am
Forum: General
Topic: Wireguard proper server config
Replies: 35
Views: 2232

Re: Wireguard proper server config

Ah okay I was not aware of that functionality of adding IP address, thanks for the clarification. Yes, whenever you have an IP on an interface, a dynamic connected (DC) route for the subnet is created with the interface as the gateway. This has the same settings as the static route that the origina...
by mducharme
Tue Oct 12, 2021 12:13 am
Forum: General
Topic: Wireguard proper server config
Replies: 35
Views: 2232

Re: Wireguard proper server config

YES you absolutely need this route.
He does not need that route since he has the IP address on the wireguard interface. If he removes the IP from the wireguard interface as you say then he would need that route.
by mducharme
Mon Oct 11, 2021 11:50 pm
Forum: General
Topic: Wireguard proper server config
Replies: 35
Views: 2232

Re: Wireguard proper server config

Removed port as suggested - no change. You also don't need the static ip route for the wireguard subnet as it will already be present as a connected route. After deleting this static route, reboot your device. If that doesn't help, my best guess is that there is some other firewall between your and...
by mducharme
Mon Oct 11, 2021 11:13 pm
Forum: General
Topic: Wireguard proper server config
Replies: 35
Views: 2232

Re: Wireguard proper server config

/interface wireguard peers
add allowed-address=10.20.50.2/32 endpoint-port=13231 interface=wgmt \
public-key="sensitive"
If the peer is an android phone that will move around in a Roadwarrior fashion, you should not be setting the endpoint-port for it.
by mducharme
Mon Oct 11, 2021 9:27 pm
Forum: RouterBOARD hardware
Topic: Mikrotik RB1100AHx4 magical reboot
Replies: 7
Views: 1460

Re: Mikrotik RB1100AHx4 magical reboot

I have found that when some Ubiquiti radios reboot, they seem to create a network loop for a very brief period of time. For instance, rebooting an SU connected to a ubiquiti AP causes the switch port on the AP side to go into spanning tree blocking mode for a brief time, because the Netonix switch t...
by mducharme
Sun Oct 10, 2021 5:05 am
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 240
Views: 49991

Re: v6.49 [stable] is released!

Does anyone know what has changed in 6.49 that would stop Rancid from connecting and taking a backup? Initially I thought it was to do with expired user account but have worked through all that and mtlogin can get in but rancid-run fails to pull the config. My coworker who uses RANCID is having the...
by mducharme
Sun Oct 10, 2021 5:04 am
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 240
Views: 49991

Re: v6.49 [stable] is released!

This might be a coincidence. But checking our SNMP log, we only see occasional -274° temp values on the two RB4011 updated to 6.49. Not on others still running 6.48.x. Yes, I spoke to soon. I occasionally see this -274 temperature value from other devices, but it is only for a brief time when the s...
by mducharme
Fri Oct 08, 2021 10:15 am
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 240
Views: 49991

Re: v6.49 [stable] is released!

Yes, this is unlikely a bug in the new version. We regularly see the RB temperature sensors return absolute zero when they cannot get a proper reading, in any version of RouterOS.
by mducharme
Fri Oct 08, 2021 8:48 am
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 240
Views: 49991

Re: v6.49 [stable] is released!

*) winbox - fixed support for "Delegated-IPv6-Prefix" for PPP services;
What exactly was fixed here?
by mducharme
Wed Oct 06, 2021 4:42 am
Forum: RouterOS v7 BETA
Topic: Feature Request: Static Link Local Address
Replies: 0
Views: 838

Feature Request: Static Link Local Address

Hello, Some providers with IPv6 require you to override the default link-local address of an interface with a static one like fe80::1 or fe80::2. This is possible with most routers, but currently, there is no ability on MikroTik routers to manually specify a link local address on an interface to ove...
by mducharme
Mon Oct 04, 2021 11:17 pm
Forum: RouterOS v7 BETA
Topic: (feature request ?) ARP mode : local-proxy-arp + reply-only
Replies: 3
Views: 953

Re: (feature request ?) ARP mode : local-proxy-arp + reply-only

+1, I would like to see this as well. I've found the MAC address based filtering doesn't always work properly in the bridge filter. Trying to do a bridge filter to match just BPDU packets ends up matching packets that have completely different MAC addresses that should not be matched by the bridge f...
by mducharme
Sat Oct 02, 2021 9:08 pm
Forum: Wireless Networking
Topic: Mini WISP-like Deployment
Replies: 8
Views: 1473

Re: Mini WISP-like Deployment

I would be comfortable setting up Mikrotiks for the P2P/P2MP backhaul links, it's the AP side I have done less with. You can consider MikroTik's 60GHz solutions. More bandwidth than you need for cheap, easy to set up, and they will stay out of the wifi range. You can to PTP up to ~1km safely, more ...
by mducharme
Sat Oct 02, 2021 8:41 am
Forum: Announcements
Topic: Newsletter 102
Replies: 30
Views: 29852

Re: Newsletter 102

I hope it will eventually get the wave2 driver package - that package is a huge improvement over the older wireless in terms of performance.

They might be able to find ways of limiting the memory and storage requirements for wave2 over time.
by mducharme
Thu Sep 30, 2021 8:36 pm
Forum: RouterBOARD hardware
Topic: S+31DLC10D Discontinued? Replacement? [SOLVED]
Replies: 2
Views: 1512

Re: S+31DLC10D Discontinued? Replacement? [SOLVED]

Are you releasing a new OEM optic for 10G SMF or? What is the suggested optic to use now?
It has been replaced by the XS+31LC10D.
by mducharme
Wed Sep 29, 2021 4:32 pm
Forum: RouterOS v7 BETA
Topic: CCR2004 High CPU Usage ROS7
Replies: 9
Views: 1934

Re: CCR2004 High CPU Usage ROS7

@raimondsp Thanks very much for the detailed explanation!
by mducharme
Wed Sep 29, 2021 12:43 am
Forum: RouterOS v7 BETA
Topic: CCR2004 High CPU Usage ROS7
Replies: 9
Views: 1934

Re: CCR2004 High CPU Usage ROS7

There is now further information in the latest newsletter about the performance of the CCR1009 model in RouterOS v7, which we can compare to RouterOS v6: RouterOS v6 - 25 ip filter rules, 512 bytes, Mbps: 3251.8 Mbps RouterOS v7 - 25 ip filter rules, 512 bytes, Mbps: 2618 Mbps This is about a 20% de...
by mducharme
Tue Sep 28, 2021 8:41 pm
Forum: Forwarding Protocols
Topic: RouterOS ignoring OSPF LSA with LA-bit set
Replies: 2
Views: 933

Re: RouterOS ignoring OSPF LSA with LA-bit set

This is old news, you can already find threads about it. It has been an issue for years. This has been fixed in RouterOS v7. They were unable to fix it in v6 for whatever reason. The workaround in v6 is to advertise that loopback route using redistribute connected on the origin router, then it is a ...
by mducharme
Tue Sep 28, 2021 4:26 am
Forum: Wireless Networking
Topic: [Discussion] Is MT treating non-PtP wireless seriously?
Replies: 8
Views: 1307

Re: [Discussion] Is MT treating non-PtP wireless seriously?

They can't (correct me if I'm wrong) modify the driver source as they don't have it. It's a similar problem as Raspberry Pi had - they had to go own silicone route as broadcomm refused to give them the sources for the GPU blob. I read online that Qualcomm does provide vendors like MikroTik with the...
by mducharme
Tue Sep 28, 2021 12:55 am
Forum: Useful user articles
Topic: MikroTik Wireguard server with Road Warrior clients
Replies: 48
Views: 17918

Re: MikroTik Wireguard server with Road Warrior clients

I strongly suspect the problem is in your firewall rules. Some of your rules don't make any sense. At one point you have a drop all rule on the input chain, then after that you have more input chain rules that will never be matched because everything will hit that drop all rule instead. Make a termi...
by mducharme
Mon Sep 27, 2021 11:53 pm
Forum: Wireless Networking
Topic: [Discussion] Is MT treating non-PtP wireless seriously?
Replies: 8
Views: 1307

Re: [Discussion] Is MT treating non-PtP wireless seriously?

Wifiwave2 changes nothing.... sorry. It's still a dumb driver living in the vacuum of its own ignorance. It does. I think you misunderstood me. I know that by itself, it doesn't handle anything regarding roaming and the 802.11 r/k/v standards. But with the current drivers, MikroTik is having to rei...
by mducharme
Mon Sep 27, 2021 11:23 pm
Forum: Useful user articles
Topic: MikroTik Wireguard server with Road Warrior clients
Replies: 48
Views: 17918

Re: MikroTik Wireguard server with Road Warrior clients

It looks like you have changed some rules from the defaults. Some of the default rules are configured to use the interface lists LAN and WAN instead of hardcoding a single interface. You have changed all of your firewall rules to use hardcoded "ether1" instead of interface list WAN and har...
by mducharme
Mon Sep 27, 2021 3:30 pm
Forum: RouterOS v7 BETA
Topic: CCR2004 High CPU Usage ROS7
Replies: 9
Views: 1934

Re: CCR2004 High CPU Usage ROS7

Just to clarify, you claim that the CCR2004, which was built FOR ROS7 which all 25, and 10gb SFP+ ports, can't to 2gb because of route caching, something that you didn't expect to exist on ROS7. I don't see how you think that this will prevent the CCR2004 from getting to 2Gbps because of route cach...
by mducharme
Mon Sep 27, 2021 3:14 pm
Forum: General
Topic: HW offload bridging
Replies: 24
Views: 1763

Re: HW offload bridging

Can you supply me with an example then?
I recommend the tutorials here:

viewtopic.php?f=23&t=143620
by mducharme
Mon Sep 27, 2021 2:46 pm
Forum: General
Topic: HW offload bridging
Replies: 24
Views: 1763

Re: HW offload bridging

So the CRS is useless for the intended setup described in the linked topic? Or can it be achived some other way? No, the CRS can handle this just fine without having to use the CPU for bridging. The issue is certainly with your config, so yes it can be achieved another way. You need to use bridge V...
by mducharme
Mon Sep 27, 2021 2:04 pm
Forum: Useful user articles
Topic: MikroTik Wireguard server with Road Warrior clients
Replies: 48
Views: 17918

Re: MikroTik Wireguard server with Road Warrior clients

I see another issue: /interface wireguard peers add allowed-address=10.0.0.1/32 interface=wireguard1 persistent-keepalive=25s \ public-key="[i](sensitive)[/i]" 10.0.0.1 is the IP of your router itself. You cannot assign the same IP to your client device (phone etc) that you have assigned t...
by mducharme
Mon Sep 27, 2021 1:55 pm
Forum: General
Topic: HW offload bridging
Replies: 24
Views: 1763

Re: HW offload bridging

How is it supposed to be configured? Only one bridge on a device can be hardware offloaded. As a result, you should avoid having multiple bridges on the same device. The default config for the CRS326 only has a single bridge, and you may want to revert to that to restore your original performance. ...
by mducharme
Mon Sep 27, 2021 1:03 pm
Forum: RouterOS v7 BETA
Topic: CCR2004 High CPU Usage ROS7
Replies: 9
Views: 1934

Re: CCR2004 High CPU Usage ROS7

Thanks @raimondsp for the clarification. I suspected that this could be related to the removal of the route cache in newer Linux kernel versions, which is something that is out of MikroTik's control. I wasn't sure if there were some other differences in the kernel as well that might account for some...
by mducharme
Mon Sep 27, 2021 4:26 am
Forum: General
Topic: RB4011 Slow Inter-VLAN Routing
Replies: 24
Views: 1524

Re: RB4011 Slow Inter-VLAN Routing

The initial connect is super slow. Once it’s done, performance is ok but sometimes unstable. Again, there are multiple reasons this could happen - from the scant info you have provided, this issue could be caused by anything. Please answer the other questions (and try the other suggestions) from my...
by mducharme
Mon Sep 27, 2021 3:45 am
Forum: Wireless Networking
Topic: [Discussion] Is MT treating non-PtP wireless seriously?
Replies: 8
Views: 1307

Re: [Discussion] Is MT treating non-PtP wireless seriously?

I'm hoping that we might see these types of features once wifiwave2 is up and running. I agree they are necessary. I've been running into similar problems with roaming, and letting the device decide is not good enough. MikroTik's decision to make their own wireless drivers instead of using the manuf...
by mducharme
Mon Sep 27, 2021 3:30 am
Forum: General
Topic: RB4011 Slow Inter-VLAN Routing
Replies: 24
Views: 1524

Re: RB4011 Slow Inter-VLAN Routing

My switch is a CSS326-24G-2S+-RM, no routing in it. It has a single 10G trunk to the RB4011 with all the VLANs on it. I'm not sure that your router is actually being slow at inter-VLAN routing. Have you actually done throughput tests with iPerf? You say it is slow because accessing your server is s...
by mducharme
Mon Sep 27, 2021 3:20 am
Forum: Useful user articles
Topic: MikroTik Wireguard server with Road Warrior clients
Replies: 48
Views: 17918

Re: MikroTik Wireguard server with Road Warrior clients

The "no-internet-access" issue resolves if I configure the android client Allowed Addresses to my LAN subnet instead of 0.0.0.0/0, but I'm still getting the log barrage and I'm not certain that the traffic is properly routed through my pihole. Your wireguard interface is not in the Interf...
by mducharme
Mon Sep 27, 2021 2:51 am
Forum: Scripting
Topic: [PPPOE] How to disable the secret for 10 seconds when a user disconnects
Replies: 9
Views: 1388

Re: [PPPOE] How to disable the secret for 10 seconds when a user disconnects

The best way to fix this is for MikroTik to implement what is called "PADI Per-MAC Rate Limiting", similar in idea to ICMP rate limiting, which would ignore additional PPPoE PADI packets if they are received within too short of a timeframe from the same MAC Address. I have wanted such a fe...
by mducharme
Mon Sep 27, 2021 2:25 am
Forum: RouterOS v7 BETA
Topic: CCR2004 High CPU Usage ROS7
Replies: 9
Views: 1934

Re: CCR2004 High CPU Usage ROS7

I found similar CPU increases across the board with all devices that I have tested, and have been wondering the same thing. My RB4011 at home has similar results - a speedtest where the highest load CPU core is at ~15% on ROS 6, moving to ROS 7 with the same / equivalent config causes 28% usage on t...
by mducharme
Sat Sep 25, 2021 7:20 am
Forum: Announcements
Topic: v6.49rc [testing] is released!
Replies: 37
Views: 9162

Re: v6.49rc [testing] is released!

Wouldn't the correct solution be to add EXP --> PCP support to the MPLS and VLAN FastPath modules ? Yes, it would, but I didn't want to push for this in v6. Probably the person who wrote that code no longer works at MikroTik and so it might be asking too much to carry out a significant fix like tha...
by mducharme
Sat Sep 25, 2021 6:03 am
Forum: Announcements
Topic: v6.49rc [testing] is released!
Replies: 37
Views: 9162

Re: v6.49rc [testing] is released!

*) mpls - allow to disable FastPath (CLI only); Big thanks for this, MikroTik! Now with the ability to turn MPLS FastPath off, the feature to automatically copy MPLS EXP bits on ingress to VLAN Priority (PCP) on egress actually works again for the first time since MPLS FastPath was added - basicall...
by mducharme
Fri Sep 24, 2021 4:59 am
Forum: RouterOS v7 BETA
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 46361

Re: v7.1rc4 [development] is released!

In order for action=netmap to be useful for WAN failover scenarios in IPv6, it should probably be allowed in the srcnat chain as well, not just dstnat. Hopefully this is coming at some point?
by mducharme
Fri Sep 24, 2021 12:28 am
Forum: RouterOS v7 BETA
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 46361

Re: v7.1rc4 [development] is released!

MPLS deployment status for v7.1rc4 has not been updated at https://help.mikrotik.com/docs/display/ROS/v7+Routing+Protocol+Status. From what I can tell there are no routing changes from rc3 to rc4 that would affect the colour/status of any features on that page. VPLS still crashes the router with rc...
by mducharme
Wed Sep 22, 2021 5:40 am
Forum: RouterOS v7 BETA
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 46361

Re: v7.1rc4 [development] is released!

This problem isn't new, also had it in 7.1rc3
As a workaround, you can use queue trees with the parent set to the LAN and WAN interfaces, rather than simple queues. I've been running this since earlier betas with fq_codel with both IPv4 and IPv6 traffic and had no issues.
by mducharme
Wed Sep 22, 2021 1:12 am
Forum: RouterOS v7 BETA
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 46361

Re: v7.1rc4 [development] is released!

looks like the protected routerboot option is gone from hAP ac3 LTE6 and RB4011
Protected routerboot seems to be gone from Winbox but still present in the CLI.
by mducharme
Tue Sep 21, 2021 10:45 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 46361

Re: v7.1rc4 [development] is released!

SUP-61109 - Still cannot update RB2011 past 7.1 beta 6... This is probably not an issue with 7.1rc4, but rather with 7.1beta6. I was unable to upgrade my RB4011 above 7.1beta6 until I did a reset to no-defaults and uploaded the 7.1rc npk file to the device using MAC Winbox. A bug in 7.1beta6 caused...
by mducharme
Mon Sep 20, 2021 10:13 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 46361

Re: v7.1rc4 [development] is released!

IPv6 firewall nat has action=netmap available now, although not yet in winbox.
by mducharme
Mon Sep 20, 2021 7:35 am
Forum: RouterOS v7 BETA
Topic: v7.1rc3 [development] is released!
Replies: 172
Views: 24569

Re: v7.1rc3 [development] is released!

This statement is just incorrect. I'm afraid you are not quite familiar how virtualization and HW offload works...CHRs support HW offload for IPSec via Intel AES-NI, so as long as you're using the right ciphers and have proper instructions passed through to the VMs, it just works. Interesting - tha...
by mducharme
Mon Sep 20, 2021 5:20 am
Forum: RouterOS v7 BETA
Topic: v7.1rc3 [development] is released!
Replies: 172
Views: 24569

Re: v7.1rc3 [development] is released!

Does HW accelerated IPSec suppose to work on 7.1rc3 / Intel CHR combo? When I upgraded from 6.48 I lost HW acceleration flag for aes-256-gcm tunnels that were offloaded before... How did you have hardware offload on CHR? It is virtual - there is nothing to offload to. Probably the HW acceleration f...
by mducharme
Wed Sep 15, 2021 9:26 am
Forum: Announcements
Topic: Mēris botnet information
Replies: 57
Views: 47483

Re: Mēris botnet information

Is there a possible vulnerability for MNDP on UDP 5678? I've seen this mentioned before, that the Meris botnet devices all seem to have UDP 5678 open, but is this indicative of a vulnerability in MNDP, or instead just a means for the botnet to relocate nodes that have possibly changed IPs and that i...
by mducharme
Wed Sep 15, 2021 9:22 am
Forum: Forwarding Protocols
Topic: Load balancing with MPLS (breaks LACP)
Replies: 7
Views: 1765

Re: Load balancing with MPLS (breaks LACP)

Yes - I was going to mention that both sides would have to support balance-rr, which is mostly just MikroTik and Linux. I have heard that HPE supports balance-rr, but I've never tried it on HPE devices.
by mducharme
Wed Sep 15, 2021 7:13 am
Forum: RouterOS v7 BETA
Topic: 7.1rc3 - IPv6 Unable to Use [SOLVED]
Replies: 5
Views: 1211

Re: 7.1rc3 - IPv6 Unable to Use [SOLVED]

Hello,

Try going into IPv6->settings and check disable IPv6, then click Apply, and then uncheck it again and click Apply again, and see if there is any change.
by mducharme
Wed Sep 15, 2021 4:08 am
Forum: Forwarding Protocols
Topic: Load balancing with MPLS (breaks LACP)
Replies: 7
Views: 1765

Re: Load balancing with MPLS (breaks LACP)

MPLS traffic can be load balanced across the members of a bonding interface if you use balance-rr instead of 802.3ad.
by mducharme
Tue Sep 14, 2021 10:17 am
Forum: RouterOS v7 BETA
Topic: PLEASE MikroTik made NetInstall version for Docker....
Replies: 41
Views: 3634

Re: PLEASE MikroTik made NetInstall version for Docker....

I do not fully understand at what level the container-daemons live in ROS, but I'm sure your ROS must be booted up to a certain level for that. I am talking about this from an ISP perspective. At the local site, by where the user is, we have a head-end router there that is fully operational. Many c...
by mducharme
Tue Sep 14, 2021 9:56 am
Forum: RouterOS v7 BETA
Topic: PLEASE MikroTik made NetInstall version for Docker....
Replies: 41
Views: 3634

Re: PLEASE MikroTik made NetInstall version for Docker....

Are they all set by default to nand-if-fail-then-ethernet ? Yes, they all are, in our case. It seems to be set to this by default. Some of them we can successfully netinstall remotely, if there is enough bandwidth. Others time out because the connection is too slow. It doesn't happen very often tha...
by mducharme
Tue Sep 14, 2021 9:52 am
Forum: RouterOS v7 BETA
Topic: PLEASE MikroTik made NetInstall version for Docker....
Replies: 41
Views: 3634

Re: PLEASE MikroTik made NetInstall version for Docker....

Use case for us would be where a user 1000km away reboots their router while it is upgrading to a new RouterOS version, now it can no longer boot except to ethernet. We try to create a layer 2 tunnel to the user to netinstall their router when this happens but due to congestion long distance netinst...
by mducharme
Tue Sep 14, 2021 9:38 am
Forum: RouterOS v7 BETA
Topic: PLEASE MikroTik made NetInstall version for Docker....
Replies: 41
Views: 3634

Re: PLEASE MikroTik made NetInstall version for Docker....

Who said Windows netinstall binary? There has been a Linux netinstall version for months now. I think they wish to run the Linux netinstall binary in a docker container.
by mducharme
Tue Sep 14, 2021 9:02 am
Forum: RouterOS v7 BETA
Topic: How will firmware 7 be distributed , manual installed or automatic [SOLVED]
Replies: 11
Views: 2341

Re: How will firmware 7 be distributed , manual installed or automatic [SOLVED]

@Maggiore81, I would hope that with several thousands of deployed MikroTiks that you do not have them all set to upgrade automatically to the latest long-term. It is a much better option to use something like TR069 to handle updates in this case.
by mducharme
Fri Sep 10, 2021 7:06 pm
Forum: Announcements
Topic: WinBox v3.30 released!
Replies: 59
Views: 8104

Re: WinBox v3.30 released!

Just a caution - if you even just click OK in the show columns window without changing anything, it will still change what columns are displayed even though you haven't actually made any changes. You don't have to select or deselect anything to trigger this bug, apparently.
by mducharme
Thu Sep 09, 2021 9:22 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc3 [development] is released!
Replies: 172
Views: 24569

Re: v7.1rc3 [development] is released!

The reported crash when double clicking on a VPLS interface in Winbox has been fixed by the new Winbox v3.30
by mducharme
Thu Sep 09, 2021 8:28 pm
Forum: Useful user articles
Topic: MikroTik Wireguard server with Road Warrior clients
Replies: 48
Views: 17918

Re: MikroTik Wireguard server with Road Warrior clients

I do not have an Android device, but this should work in the same way as iOS. Wireguard is like a series of point to point tunnels, but the same IP can be used on the side of the wireguard system itself. So in this case there is a wireguard subnet 192.168.66.0/24 and you end up with the following po...
by mducharme
Thu Sep 09, 2021 3:17 am
Forum: RouterOS v7 BETA
Topic: v7.1rc3 [development] is released!
Replies: 172
Views: 24569

Re: v7.1rc3 [development] is released!

VPLS is not working - the tunnel comes up, but attempting to pass any traffic across causes a crash.
by mducharme
Thu Sep 09, 2021 12:45 am
Forum: RouterOS v7 BETA
Topic: v7.1rc3 [development] is released!
Replies: 172
Views: 24569

Re: v7.1rc3 [development] is released!

Omg, did they choose stateful IPv6 NAT? The only actions they have right now are masquerade, dst-nat, and redirect. Those are useful but what most people want to be able to Network Prefix Translation, which means using netmap, since the main NPT support in Linux does not support connection tracking...
by mducharme
Wed Sep 08, 2021 7:10 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc3 [development] is released!
Replies: 172
Views: 24569

Re: v7.1rc3 [development] is released!

Torch still does not see IPv6 traffic that is there.

IPv6 NAT is in winbox now, but action netmap is still missing.
by mducharme
Tue Sep 07, 2021 3:35 am
Forum: General
Topic: MikroTik Chateau 12 LTE - NSLookup OK, No Internet?
Replies: 27
Views: 1495

Re: MikroTik Chateau 12 LTE - NSLookup OK, No Internet?

7.1beta3 is not the newest, it came out in December. beta 4-6 came out since, and then rc1 and rc2.
by mducharme
Mon Sep 06, 2021 1:39 am
Forum: RouterOS v7 BETA
Topic: ZeroTier interface not running
Replies: 3
Views: 980

Re: ZeroTier interface not running

This happened to me too, but it started working suddenly after I disabled both the zerotier interface and the zerotier instance and then re-enabled both.
by mducharme
Fri Sep 03, 2021 8:47 am
Forum: RouterOS v7 BETA
Topic: ZeroTier added to RouterOS v7.1rc2
Replies: 207
Views: 59509

Re: ZeroTier added to RouterOS v7.1rc2

I found the official MikroTik docs really helpful for getting ZeroTier going: https://help.mikrotik.com/docs/display/ROS/ZeroTier
by mducharme
Fri Sep 03, 2021 3:40 am
Forum: RouterOS v7 BETA
Topic: ZeroTier added to RouterOS v7.1rc2
Replies: 207
Views: 59509

Re: ZeroTier added to RouterOS v7rc2

That's just the tip of the iceberg - like I said, It's a phenomenal protocol and we use it in the Service Provider world for OOB Mgmt and also building MPLS transport over the Internet. I'm very interested in this MPLS transport option. Currently we use EoIP for this - we have many locations added ...
by mducharme
Thu Sep 02, 2021 3:56 am
Forum: General
Topic: hAP - TR069 with STUN support
Replies: 7
Views: 1451

Re: hAP - TR069 with STUN support

STUN support does not currently exist on MikroTik. IPv6 can be an option for these devices.
by mducharme
Thu Sep 02, 2021 3:46 am
Forum: Announcements
Topic: v6.48.4 [stable] is released!
Replies: 76
Views: 41112

Re: v6.48.4 [stable] is released!

I submitted a ticket about this, but skins are no longer getting installed in this version from the branding packages that were working fine before. Using hap ac3 devices.
by mducharme
Thu Sep 02, 2021 1:12 am
Forum: RouterOS v7 BETA
Topic: v7.1rc2 [development] is released!
Replies: 194
Views: 20466

Re: v7.1rc2 [development] is released!

What is this then:
7RC2 thread
viewtopic.php?f=1&t=178063
That is a typo/omission - it should say v7.1rc2, not 7RC2. There is no such thing as v7.0rc2.
by mducharme
Thu Sep 02, 2021 12:43 am
Forum: RouterBOARD hardware
Topic: The big CCR2004 reboot thread (was 2004 hardware issues?)
Replies: 335
Views: 46924

Re: The big CCR2004 reboot thread (was 2004 hardware issues?)

Do you know if it works in v7? If so i wan't to look if we can upgrade 2 of the 3 CCR2004 who are acting as a PPPoE server with OSPF.
Yes, this workaround should still work fine in v7.
by mducharme
Tue Aug 31, 2021 12:14 am
Forum: RouterBOARD hardware
Topic: The big CCR2004 reboot thread (was 2004 hardware issues?)
Replies: 335
Views: 46924

Re: The big CCR2004 reboot thread (was 2004 hardware issues?)

I wan't to but on the routing status page it stills says /31 adress not supported, that we really need unfortunately.
6.x does not support /31 addresses either. If they release it, it will be a brand new feature in 7.x.
by mducharme
Mon Aug 30, 2021 11:07 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc1 [development] is released!
Replies: 345
Views: 38251

Re: v7.1rc1 [development] is released!

Is that one sufficient to restore everything on the same device (also independent from the software version)? Take both a .backup file and also do an export file=mybackup.rsc (or whatever name you want to give it) from the command line, and copy both the .backup and the mybackup.rsc off the device....
by mducharme
Mon Aug 30, 2021 9:59 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc1 [development] is released!
Replies: 345
Views: 38251

Re: v7.1rc1 [development] is released!

It seems I'm stuck with 7.1beta6 now on that device!
I had a similar issue on my RB4011 upgrading to 7.1rc1, what I wound up doing to upgrade was to reset to no-default-configuration so that it was completely blank and use mac winbox to upload 7.1rc1. You could give that a try on your 2011.
by mducharme
Sun Aug 29, 2021 5:52 am
Forum: RouterOS v7 BETA
Topic: 7.1rc1 upgrade - config lost and restore fails
Replies: 3
Views: 777

Re: 7.1rc1 upgrade - config lost and restore fails

Try to reset to no-defaults and then manually upload 7.1beta6 and hit the downgrade button in system->packages. Otherwise you can try to netinstall 7.1beta6 and this should be successful. Since this is beta software, it would be advisable to not only do a .backup file but also export an .rsc backup....
by mducharme
Thu Aug 26, 2021 7:15 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc1 [development] is released!
Replies: 345
Views: 38251

Re: v7.1rc1 [development] is released!

In v7.1rc1, Torch is not showing any IPv6 traffic, only IPv4. This behaviour was also in previous betas.
by mducharme
Thu Aug 26, 2021 4:19 am
Forum: RouterOS v7 BETA
Topic: v7.1rc1 [development] is released!
Replies: 345
Views: 38251

Re: v7.1rc1 [development] is released!

Does wifiwave2 have four address mode support yet?
by mducharme
Wed Aug 25, 2021 7:16 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc1 [development] is released!
Replies: 345
Views: 38251

Re: v7.1rc1 [development] is released!

Hello, I have these two static ipv6 routes that show up in a config export but do not appear in the routes list, or the output of the print command, so I cannot delete them (at first I just had one, and I tried creating a new one to replace it but it got changed in the same way somehow): /ipv6 route...
by mducharme
Mon Aug 23, 2021 7:56 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc1 [development] is released!
Replies: 345
Views: 38251

Re: v7.1rc1 [development] is released!

- hide-sensitive in exports is now default and has to be explicitly disabled with show-sensitive. A good idea in my opinion, but should be mentioned somwhere in bold letters! This broke my WireGuard, RoMON and CAPsMAN setup on export -> reset -> import without any error message. IMO this is not goo...
by mducharme
Tue Aug 03, 2021 5:37 am
Forum: RouterOS v7 BETA
Topic: Can't mark routes in IPv6->Firewall->Mangle
Replies: 1
Views: 704

Re: Can't mark routes in IPv6->Firewall->Mangle

There is a "mark routing" in the IPv6 mangle actions, but it is only available through the command line and hidden in Winbox.

That being said, in most cases it makes more sense to use routing rules for policy routing, as it is easier to avoid creating routing loops.
by mducharme
Sun Aug 01, 2021 3:47 am
Forum: RouterOS v7 BETA
Topic: Bridge to Wireguard interface [SOLVED]
Replies: 14
Views: 2479

Re: Bridge to Wireguard interface [SOLVED]

ukvpn is a bridge, just so that I can organise a dhcpd for connected devices on ether{4,5} I presume what you are trying to do is get the devices on ether4 and ether5 to go online through the wireguard VPN whereas everything else should go online the normal way. Is this correct? If so, you need to ...
by mducharme
Sat Jul 31, 2021 8:54 pm
Forum: RouterOS v7 BETA
Topic: Bridge to Wireguard interface [SOLVED]
Replies: 14
Views: 2479

Re: Bridge to Wireguard interface [SOLVED]

I'm still confused about how to set up the routing for the ukvpn bridge. When I attach a client, it doesn't seem to know to go via wireguardUK! Currently you are doing ECMP it looks like, which is doing load balancing where some traffic is going over your regular connection and some is going over w...
by mducharme
Thu Jul 29, 2021 11:14 pm
Forum: RouterOS v7 BETA
Topic: Bridge to Wireguard interface [SOLVED]
Replies: 14
Views: 2479

Re: Bridge to Wireguard interface [SOLVED]

Wireguard is a layer 3 tunnel and cannot be bridged. I would call it a bug that it even allows you to add it as a bridge port, since other tunnel types that cannot be bridged (like GRE) are hidden from the list of potential bridge ports.
by mducharme
Thu Jul 29, 2021 6:43 am
Forum: Forwarding Protocols
Topic: Can someone explain the point of VRF to me?
Replies: 5
Views: 1939

Re: Can someone explain the point of VRF to me?

There are a few reasons here. First of all, VRF's are very often used for providing customers with MPLS L3 VPN's. This allows an ISP to give a customer a managed service whereby they handle the routing between the customer's individual locations and their internal networks. Most such customers have ...
by mducharme
Thu Jul 29, 2021 4:51 am
Forum: General
Topic: Bridge port egress stop STP/BPDU
Replies: 4
Views: 1530

Re: Bridge port egress stop STP/BPDU

I've found an issue when using dst-address mac matching in the bridge filter: dst-mac-address=01:80:C2:00:00:00/FF:FF:FF:FF:FF:FF That setting actually matches a lost of destination mac addresses that do not match that. If I log the rule I end up seeing a lot of packets matching other destination ma...
by mducharme
Wed Jul 28, 2021 1:48 am
Forum: RouterBOARD hardware
Topic: MikroTik RB5009UG+S+IN
Replies: 170
Views: 28312

Re: MikroTik RB5009UG+S+IN

No, in my case it is a RouterOS 7.1 beta6 bug. I do not have this issue with any version other than RouterOS 7.1 beta6, and MikroTik has said they have found the problem and reproduced it and it will be fixed in beta 7.
by mducharme
Tue Jul 27, 2021 9:10 pm
Forum: RouterBOARD hardware
Topic: MikroTik RB5009UG+S+IN
Replies: 170
Views: 28312

Re: MikroTik RB5009UG+S+IN

I am running 7.1beta6 on my 4011. The only issues that I have are that I cannot reboot (it kernel panics on reboot and I have to pull the power), I have to disable and re-enable IPv6 every boot-up, and there is a slow memory leak that causes it to crash every 5 weeks or so. Other than those three th...
by mducharme
Mon Jul 26, 2021 7:01 am
Forum: RouterBOARD hardware
Topic: MikroTik RB5009UG+S+IN
Replies: 170
Views: 28312

Re: MikroTik RB5009UG+S+IN

But probably it's old 4011 numbers that were always untrue, not the new 5009 ones. I suspect that the 5009 results could actually be underestimated. Assuming those switch chips are capable of not only bridge VLAN filtering, but layer 3 hardware offloading like CRS3xx model switches, it could be pos...
by mducharme
Mon Jul 26, 2021 6:54 am
Forum: RouterBOARD hardware
Topic: Hardware recommendation for Internet gateway
Replies: 7
Views: 1546

Re: Hardware recommendation for Internet gateway

Hi, In general you should look at the "Test results" tab on a MikroTik product page, specifically looking for the Routing, 25 IP filter rules, 512 byte Mbps result. This will provide a good ballpark as to the routing throughput for the device in an average scenario - I say average scenario...
by mducharme
Fri Jul 23, 2021 4:57 am
Forum: Beginner Basics
Topic: VLANS & Management VLAN
Replies: 27
Views: 2573

Re: VLANS & Management VLAN

I think anav did not clearly communicate what he (probably) meant: The CRS112 does not have hardware support for bridge VLAN filtering, and the CPU in that device is quite weak, so using bridge VLAN filtering on it is not really practical, and you are best off setting up VLANs using the CRS1xx/2xx s...
by mducharme
Fri Jul 23, 2021 3:50 am
Forum: RouterBOARD hardware
Topic: MikroTik RB5009UG+S+IN
Replies: 170
Views: 28312

Re: MikroTik RB5009UG+S+IN

Probably having a second 10G SFP+ interface would make the unit too wide in order to be able to put two side by side in a rack, like it is designed. They would have to remove one of the copper ports, which means you would be using only 7 ports on an 8 port switch chip. It is understandable in this s...
by mducharme
Thu Jul 22, 2021 11:12 pm
Forum: RouterOS v7 BETA
Topic: Configuration resets after reboot due to routing-mark settings (v7.1 beta5 & beta6
Replies: 5
Views: 1383

Re: Configuration resets after reboot due to routing-mark settings (v7.1 beta5 & beta6

Did you create the new routing table named "TEST" before using that to mark-routing?
by mducharme
Wed Jul 21, 2021 10:11 am
Forum: RouterOS v7 BETA
Topic: Wireguard on wAP AC
Replies: 6
Views: 1225

Re: Wireguard on wAP AC

Wireguard doesn't traditionally have hardware acceleration anyway, but is still known for being very efficient and fast regardless.
by mducharme
Fri Jul 16, 2021 12:18 pm
Forum: RouterOS v7 BETA
Topic: v7 launch date
Replies: 156
Views: 29202

Re: v7 launch date

They had changed the syntax of the route filters already once because a lot of people were complaining about the new syntax and it became a big point of contention, but people did not like the new syntax either. As a result, they are re-conceptualizing the routing filters syntax yet again with this ...
by mducharme
Thu Jul 15, 2021 7:31 am
Forum: Wireless Networking
Topic: Virtual interfaces for 60GHz
Replies: 8
Views: 1206

Re: Virtual interfaces for 60GHz

They could, that's why I would use a firewall on the devices. As far as I am aware the type of attack you bring up is entirely possible, if the device is not secured properly.
by mducharme
Thu Jul 15, 2021 5:56 am
Forum: Wireless Networking
Topic: Virtual interfaces for 60GHz
Replies: 8
Views: 1206

Re: Virtual interfaces for 60GHz

Yes, that's probably possible. But why would you keep changing the MAC on the station side to begin with? Presumably you control both sides?
by mducharme
Thu Jul 15, 2021 5:37 am
Forum: Wireless Networking
Topic: Virtual interfaces for 60GHz
Replies: 8
Views: 1206

Re: Virtual interfaces for 60GHz

Is this really true? If so, then what stops someone from making a script that changes the identity of some station and cramming the AP with a long list of dummy interfaces?
I'm afraid I don't understand your question. Can you clarify?
by mducharme
Thu Jul 15, 2021 5:25 am
Forum: Wireless Networking
Topic: Virtual interfaces for 60GHz
Replies: 8
Views: 1206

Re: Virtual interfaces for 60GHz

The station interfaces are only created after connect, but they are not dynamic, so they will stay there even if the far end goes down.
by mducharme
Wed Jul 14, 2021 2:55 am
Forum: RouterOS v7 BETA
Topic: Routing speeds on v7 RB4011
Replies: 11
Views: 2376

Re: Routing speeds on v7 RB4011

Yes. If you are able to use Fasttrack for a large portion of traffic, or have fewer rules by accepting certain traffic between VLANs early, you can squeeze a bit more out of it theoretically (maybe another 1 or 2 Gbps), but I think 2.5Gbps is probably a good estimate for that device.
by mducharme
Wed Jul 14, 2021 1:35 am
Forum: RouterOS v7 BETA
Topic: Routing speeds on v7 RB4011
Replies: 11
Views: 2376

Re: Routing speeds on v7 RB4011

I know this is probably how long is a piece of string question, but just wanted to get a rough idea. Usually for a rule of thumb I go to the "Test results" tab for the device's MikroTik product page and check the result for 512 byte packets Mbps with 25 ip filter rules. This generally sho...
by mducharme
Tue Jul 13, 2021 6:42 am
Forum: RouterOS v7 BETA
Topic: IPv6 forwarding not working in 7.1beta6
Replies: 18
Views: 2900

Re: IPv6 forwarding not working in 7.1beta6

The issues that I have with the RB4011 and IPv6 are to do with missing link-local addresses. When the router first boots, I get link-local IPv6 addresses for some interfaces, but not the bridge. Without this, the hosts on the bridge cannot get connectivity to the Internet. Disabling IPv6 through IPv...
by mducharme
Mon Jul 12, 2021 8:17 pm
Forum: General
Topic: CCR2004-1G-12S+2XS SFP+ Upload issues
Replies: 16
Views: 1709

Re: CCR2004-1G-12S+2XS SFP+ Upload issues

But it also doesn't explain the issue where with the switch, it works perfectly fine? The link to the modem is the same in that case but somehow it isn't affected by the issue?
The SFP+ module could be autonegotiating correctly to 1Gbps in the switch but not the router.
by mducharme
Mon Jul 12, 2021 10:30 am
Forum: RouterOS v7 BETA
Topic: v7.1beta6 [development] is released!
Replies: 377
Views: 70527

Re: v7.1beta6 [development] is released!

It's July and we're due for beta7. I have no "insider information", but I personally suspect beta7 might take a bit longer rather than the usual two month window between releases, if only due to the fact that they have been redesigning and re-implementing the route filter system from the ...
by mducharme
Mon Jul 12, 2021 6:05 am
Forum: General
Topic: CCR2004-1G-12S+2XS SFP+ Upload issues
Replies: 16
Views: 1709

Re: CCR2004-1G-12S+2XS SFP+ Upload issues

Though it doesn't seem like anything weird is going on there? Nothing weird going on there? Your module is SFP+ but it should be negotiating to 1Gbps if that is all that your modem supports. I haven't had experience with this module to understand how it shows the auto negotiation for lower speeds p...
by mducharme
Sun Jul 11, 2021 5:30 am
Forum: General
Topic: CCR2004-1G-12S+2XS SFP+ Upload issues
Replies: 16
Views: 1709

Re: CCR2004-1G-12S+2XS SFP+ Upload issues

The link to the modem is 1gbit.
Can you show the "Status" tab for the sfp-sfpplus port that goes to the modem/ONT?
by mducharme
Sat Jul 10, 2021 7:08 am
Forum: Wireless Networking
Topic: Deploy MikroTik 5Ghz Wireless PTMTP instead of Fiber Optic FTTH Solution
Replies: 2
Views: 790

Re: Deploy MikroTik 5Ghz Wireless PTMTP instead of Fiber Optic FTTH Solution

FTTH is much more expensive, but not much can go wrong with it other than somebody digging in the wrong place or equipment failures. 5GHz wireless is much slower, and has so much interference from home routers that it may not be feasible to deliver 5GHz service unless you control all of the customer...
by mducharme
Thu Jul 08, 2021 11:45 pm
Forum: General
Topic: VLAN Translation
Replies: 3
Views: 549

Re: VLAN Translation

I need to set up VLAN translation, VLAN 1 included from Cisco switch. SwOS has fewer features than RouterOS so probably SwOS won't help you. You can try doing some things in the "Rule" tab of the "Switch" menu. I know that can be used to change a VLAN tag so it might be possible...
by mducharme
Wed Jul 07, 2021 7:38 pm
Forum: RouterOS v7 BETA
Topic: Wireguard - Unable to access computers on different LAN
Replies: 5
Views: 2690

Re: Wireguard - Unable to access computers on different LAN

but when a second Peers is created, the first Peers no longer works. This is because Wireguard uses the allowed-addresses to determine which peer the packet should be sent to. If the address you are pinging is in the allowed-addresses range for peer 1, it sends it to peer 1. If it is in the allowed...
by mducharme
Tue Jul 06, 2021 12:03 am
Forum: General
Topic: SFP+ Cable between RB4011 and Edgeswitch?
Replies: 2
Views: 485

Re: SFP+ Cable between RB4011 and Edgeswitch?

RB4011 will not work with a DAC, according to specs...use an AOC instead.
The RB4011 was listed as incompatible with the old MikroTik DACs that have been discontinued. It is however listed as compatible with the new XS+DA0001.
by mducharme
Mon Jul 05, 2021 3:33 am
Forum: RouterOS v7 BETA
Topic: NTP Client is borked
Replies: 6
Views: 1233

Re: NTP Client is borked

I found that the NTP client can only be configured properly from the CLI. Certain things like using DNS names for NTP server addresses do not work in the GUI. Configure it through the CLI instead and see if there is still a problem. These are the settings I use (a verbose export): /system ntp client...
by mducharme
Mon Jul 05, 2021 3:30 am
Forum: RouterOS v7 BETA
Topic: [Feature Request] Limit the possibility of upgrading a device with the image for the wrong architecture
Replies: 3
Views: 1102

Re: [Feature Request] Limit the possibility of upgrading a device with the image for the wrong architecture

I haven't tried this on ROS 7, but at least on ROS 6 if you upload the wrong architecture and reboot it will fail to upgrade and indicate that the package is the wrong architecture. So I think this check is already supposed to be in place. If it got by somehow, perhaps there is a bug.
by mducharme
Mon Jul 05, 2021 2:27 am
Forum: RouterOS v7 BETA
Topic: SDWAN using Zerotier [SOLVED]
Replies: 49
Views: 18993

Re: SDWAN using Zerotier

Thanks for the clarification/correction. I set up Zerotier once, and read about the multipath support but must have misunderstood.
by mducharme
Mon Jul 05, 2021 12:33 am
Forum: RouterOS v7 BETA
Topic: SDWAN using Zerotier [SOLVED]
Replies: 49
Views: 18993

Re: SDWAN using Zerotier

Also, maybe I'm not up to the speed but what problem ZT solves which WG+OSPF doesn't? Zerotier builds a full mesh and uses the lowest latency path between any two nodes. If there is any loss (indicating congestion) it shifts that traffic to a backup path automatically. You can build a full mesh wit...
by mducharme
Sun Jul 04, 2021 10:35 pm
Forum: Wireless Networking
Topic: WPA3 in September?
Replies: 11
Views: 3312

Re: WPA3 in September?

Good to know, thanks. As far as I can see, RouterOS v7 is in beta, though. So maybe then the question should rather be, will RouterOS v7 be stable in September? Probably not. My own guess at the rate they have been going would be around mid-2022. However, they are supposedly stabilizing individual ...
by mducharme
Sun Jul 04, 2021 10:16 pm
Forum: Wireless Networking
Topic: WPA3 in September?
Replies: 11
Views: 3312

Re: WPA3 in September?

Hi, will RouterOS support WPA3 in September? That's probably when Apple will release iOS 15 with WPA3 support. So I'm gonna need it by then I assume.
It already does, in RouterOS v7.
by mducharme
Sun Jul 04, 2021 8:50 am
Forum: Announcements
Topic: Newsletter June 2021 (#100)
Replies: 55
Views: 21724

Re: Newsletter June 2021 (#100)

All of this 6GHz talk probably fits better as RouterOS v7-specific topics. RouterOS v7 already has the wifiwave2 package, which uses the manufacturer drivers (instead of MikroTik's own) and already seemingly supports WiFi 6 - the mode setting is there and the drivers are there. It is very possible t...
by mducharme
Sun Jul 04, 2021 12:37 am
Forum: Wireless Networking
Topic: CAPsMAN VLAN Issue [SOLVED]
Replies: 8
Views: 2055

Re: CAPsMAN VLAN Issue [SOLVED]

Is this guide wrong or did something change since it was written?
On CAP devices there is generally no need for bridge vlan filtering. Disable bridge vlan filtering and delete the VLANs from bridge->VLANs tab, then all of the VLANs you have created will just work without needing configuration.
by mducharme
Fri Jul 02, 2021 8:46 am
Forum: Announcements
Topic: SwOS Lite version 2.13 released!
Replies: 38
Views: 19462

Re: SwOS Lite version 2.13 released!

I think this topic probably should have been closed since 2.14 is out now?
by mducharme
Fri Jul 02, 2021 4:43 am
Forum: Beginner Basics
Topic: Tunneling VLAN traffic over Wireguard
Replies: 18
Views: 2585

Re: Tunneling VLAN traffic over Wireguard

You are missing allowed-addresses it looks like, and possibly other things are wrong.

Have a look at this thread, it may be helpful: viewtopic.php?f=23&p=865133
by mducharme
Fri Jul 02, 2021 4:36 am
Forum: RouterOS v7 BETA
Topic: v7 launch date
Replies: 156
Views: 29202

Re: v7 launch date

Anyone care to comment if that means the 7.1 beta might well be "stable" enough for me with my RB4001, CRS328 and 4x cAP AC? I wouldn't recommend it yet for most people, unless you are an enthusiast. I am running it at home on my RB4011 and audience and hap AC with no major issues. There ...
by mducharme
Thu Jul 01, 2021 12:15 am
Forum: RouterOS v7 BETA
Topic: v7.1beta6 [development] is released!
Replies: 377
Views: 70527

Re: v7.1beta6 [development] is released!

/ip/firewall/mangle/export doesn't work correctly for mark-routing action.
Did you add the routing table named "via-gw" first? It doesn't let you mark-routing for a routing mark unless that mark matches the name of a routing table defined on the router in v7.
by mducharme
Mon Jun 28, 2021 5:28 am
Forum: RouterOS v7 BETA
Topic: v7.1beta6 [development] is released!
Replies: 377
Views: 70527

Re: v7.1beta6 [development] is released!

@nannou9 called attention to this problem:

Wireguard tunnels are selectable in the bridge->ports list. They should probably not appear there as they are layer-3-only tunnels like GRE, and I see that GRE interfaces do not appear in the bridge->ports list.
by mducharme
Mon Jun 28, 2021 3:19 am
Forum: Useful user articles
Topic: MikroTik Wireguard server with Road Warrior clients
Replies: 48
Views: 17918

Re: MikroTik Wireguard server with Road Warrior clients

but instead added WG interface to my bridge and client is using IP from my main home network subnet. Wireguard is a layer 3 tunnel, not layer 2, so it will not work adding it as a bridge port like that. MikroTik should not even allow adding layer-3-only interface types to a bridge, and they do not ...
by mducharme
Wed Jun 23, 2021 3:07 am
Forum: RouterOS v7 BETA
Topic: WireGuard: Response packets not routed
Replies: 5
Views: 1430

Re: WireGuard: Response packets not routed

/ip address
add address=10.0.0.0/24 interface=localnet network=10.0.0.0
I'm not sure if this is the cause of your problem, but 10.0.0.0/24 is not a valid address given that subnet mask. You should use something that doesn't end in .255 or .0 for a /24.
by mducharme
Tue Jun 22, 2021 12:03 am
Forum: Forwarding Protocols
Topic: Debugging EoIP tunnel
Replies: 12
Views: 2810

Re: Debugging EoIP tunnel

I tried to leave local IP field empty and set IPsec password at the same time, but this way tunnel doesn't get ready.
You can probably write a script to handle the changes for the tunnel automatically in event of an IP change.
by mducharme
Mon Jun 21, 2021 5:49 am
Forum: General
Topic: VLAN can't access internet, router, or local LAN
Replies: 13
Views: 927

Re: VLAN can't access internet, router, or local LAN

:( when you waste too many hours because you fat fingered something. Thanks for spotting that. That, naturally, fixed it. No problem. It is actually quite a common issue, even for people who are used to MikroTik. The issue is that so many other routers have a separate netmask setting that in the IP...
by mducharme
Mon Jun 21, 2021 4:53 am
Forum: General
Topic: VLAN can't access internet, router, or local LAN
Replies: 13
Views: 927

Re: VLAN can't access internet, router, or local LAN

add address=192.168.90.1 interface=alexa network=192.168.90.1 This is incorrect - by not specifying /24, it uses the default of /32 which is a subnet of one IP (i.e. netmask 255.255.255.255). So you have given the router an IP on this VLAN, with a subnet mask that is only large enough to accommodat...
by mducharme
Mon Jun 21, 2021 4:03 am
Forum: General
Topic: VLAN can't access internet, router, or local LAN
Replies: 13
Views: 927

Re: VLAN can't access internet, router, or local LAN

You got it, This looks like almost everything except your bridge definition. i.e. the line that actually creates your bridge "bridge" is missing. Maybe you deleted it because it has the admin mac, if the admin mac didn't get hidden, but I would need to see that too, with the exception of ...
by mducharme
Mon Jun 21, 2021 1:50 am
Forum: General
Topic: VLAN can't access internet, router, or local LAN
Replies: 13
Views: 927

Re: VLAN can't access internet, router, or local LAN

Simplification is good. I reverted to the default list you recommended. Unfortunately, there was no change with the issue. VLAN clients can access (ping) each other, but not the router itself, nor the internet, nor the other network. the router cannot access the clients either. So, perhaps there is...
by mducharme
Mon Jun 21, 2021 12:57 am
Forum: General
Topic: VLAN can't access internet, router, or local LAN
Replies: 13
Views: 927

Re: VLAN can't access internet, router, or local LAN

This makes it looks like they are added. Yes, that is fine then. I see that you added an extra rule that doesn't need to be there: chain=input action=drop log=yes log-prefix="" You are already dropping everything not coming in from LAN, so that drop rule can result in dropping things that...
by mducharme
Mon Jun 21, 2021 12:27 am
Forum: General
Topic: VLAN can't access internet, router, or local LAN
Replies: 13
Views: 927

Re: VLAN can't access internet, router, or local LAN

I've been goofing around for the firewall for sometime, and even with logging enabled I'm not getting any hints as to what the issue is. Since the VLAN was added to the bridge, both interface are on the address list "LAN" Adding "bridge" to an interface list does not also add an...
by mducharme
Sun Jun 20, 2021 10:47 pm
Forum: General
Topic: Trying to add a wireless VLAN (CAPsMAN)
Replies: 2
Views: 348

Re: Trying to add a wireless VLAN (CAPsMAN)

The SSID shows up, and I can connect to it. However, no IP address is assigned from DHCP. So, I must be missing a configuration, or an option somewhere. You don't only need an ip pool - you also need a DHCP server and DHCP network for DHCP to work. Under IP->DHCP server, there is a DHCP Setup butto...
by mducharme
Sun Jun 20, 2021 9:45 pm
Forum: RouterOS v7 BETA
Topic: OSPF distribute-default option is missing [SOLVED]
Replies: 8
Views: 2199

Re: OSPF distribute-default option is missing [SOLVED]

There's no option for redistribute=static or even redistribution at all on v7beta6. Do you have a screenshot of the setting? It is at the CLI only, not though the GUI: [admin@Michael-RB4011] /routing/ospf/instance> print Flags: X - disabled, I - inactive 0 name="OSPFv2" version=2 vrf=main...
by mducharme
Sun Jun 20, 2021 6:42 am
Forum: RouterOS v7 BETA
Topic: OSPF distribute-default option is missing [SOLVED]
Replies: 8
Views: 2199

Re: OSPF distribute-default option is missing [SOLVED]

They did away with the default route as part of the instance configuration. From the help docs: All route distribution control is now done purely with routing filter select, no more redistribution knobs in the instance. This gives greater flexibility on what routes from which protocols you want to ...
by mducharme
Sun Jun 20, 2021 6:07 am
Forum: General
Topic: My ISP ( WiLogic ) uses MikroTik Routers and without a doubt..
Replies: 25
Views: 1872

Re: My ISP ( WiLogic ) uses MikroTik Routers and without a doubt..

Yes, the "configure script" with Netinstall is the way to accomplish this. Also, if you wish, you can remotely upgrade this configure script using TR069, in case you want to make changes to your defaults and avoid having to Netinstall the device over again. You can probably even use TR069 ...
by mducharme
Sat Jun 19, 2021 9:02 pm
Forum: RouterOS v7 BETA
Topic: OSPF distribute-default option is missing [SOLVED]
Replies: 8
Views: 2199

Re: OSPF distribute-default option is missing [SOLVED]

Yet another problem with v7 OSPF! I can't find a distribute-default setting anywhere for creating a default OSPF route. I need this for a network I want to build, but since it's not available in v7 yet, I'm out of luck. Will it ever be added again? No, but it is currently possible to redistribute t...
by mducharme
Sat Jun 19, 2021 4:02 am
Forum: Forwarding Protocols
Topic: Use OSPF with /32 subnets
Replies: 5
Views: 2019

Re: Use OSPF with /32 subnets

I'm going to try this, but why does it work this way? Also, is the R1's network supposed to be 10.20.0.2? Sorry, it was a typo, I have fixed it above. The only reason the network setting is provided in the first place is because, in the case of /32's, you use the network setting to specify the IP o...
by mducharme
Sat Jun 19, 2021 3:24 am
Forum: Forwarding Protocols
Topic: Use OSPF with /32 subnets
Replies: 5
Views: 2019

Re: Use OSPF with /32 subnets

I already selected the PtP network type, but it didn't work. I also set up loopback interfaces and added them to the interface templates. For some reason, I can't ping the other routers with /32 addresses even though all that connects them is a simple ethernet cable, and there's no firewall rules a...
by mducharme
Sat Jun 19, 2021 2:37 am
Forum: Forwarding Protocols
Topic: Use OSPF with /32 subnets
Replies: 5
Views: 2019

Re: Use OSPF with /32 subnets

Is there a way to get OSPF working with Mikrotik routers that have /32 addresses? Yes, it should be working. At least, these /32's work fine with OSPF over PPP tunnels. First, I would ask if you can ping the other router on its /32 address? You need for that to be working before OSPF will work. OSP...
by mducharme
Fri Jun 18, 2021 9:44 pm
Forum: General
Topic: My ISP ( WiLogic ) uses MikroTik Routers and without a doubt..
Replies: 25
Views: 1872

Re: My ISP ( WiLogic ) uses MikroTik Routers and without a doubt..

And then we want to give a service that works, 99% of the time that someone who is not in the trade (or works at other WISPs) gets their hands on it, messes up, disconnects from the network, you have to go and fix it, and then complains that the service is not working. We have a different way of so...
by mducharme
Wed Jun 16, 2021 10:09 pm
Forum: Forwarding Protocols
Topic: Debugging EoIP tunnel
Replies: 12
Views: 2810

Re: Debugging EoIP tunnel

I tried to remove IPsec secret from the EoIP interface (both side, of course) but the EoIP tunnel got disconnected and remained disconnected after 1-2 minutes too. I think I should not change my firewall rules just because of this change because GRE is also needed for IPsec. You don't have to chang...
by mducharme
Tue Jun 15, 2021 1:09 am
Forum: Forwarding Protocols
Topic: Debugging EoIP tunnel
Replies: 12
Views: 2810

Re: Debugging EoIP tunnel

Both after removing sensitive data.
Have you tried EoIP without encryption, and/or IPsec by itself without EoIP, for comparison purposes?
by mducharme
Sat Jun 12, 2021 8:56 am
Forum: RouterOS v7 BETA
Topic: v7.1beta6 [development] is released!
Replies: 377
Views: 70527

Re: v7.1beta6 [development] is released!

Is MLAG planned to work with MSTP in the future? Or will it only work with STP/RSTP?
by mducharme
Thu Jun 10, 2021 5:02 pm
Forum: Wireless Networking
Topic: HAP AC2 WIFI connection jittery/lagging Oculus Quest 2 Airlink
Replies: 6
Views: 2312

Re: HAP AC2 WIFI connection jittery/lagging Oculus Quest 2 Airlink

Issue appears to be your wireless configuration...
change distance=indoors
to
distance=any
I think here you meant to say change installation=indoor to installation=any, not distance=any. distance=indoors is ok for that setting and is the default.
by mducharme
Tue Jun 08, 2021 6:43 am
Forum: Useful user articles
Topic: MikroTik Wireguard server with Road Warrior clients
Replies: 48
Views: 17918

Re: MikroTik Wireguard server with Road Warrior clients

Guaranteed the problem is routing LOL, Its not that difficult to put in the wireguard settings, although the tricky part is putting in 0.0.0.0/0 at the client site, peer entry for allowed IPs and to put in the endpoint with listening port appended at the client side, peer entry if there is not a se...
by mducharme
Tue Jun 08, 2021 4:00 am
Forum: RouterOS v7 BETA
Topic: RouterOSv7 first look – MLAG on CRS 3xx switches
Replies: 10
Views: 2916

Re: RouterOSv7 first look – MLAG on CRS 3xx switches

I just tried using MSTP on the Bridge the MLAG ports are on, it definitely does not support that version of STP.
That seems an odd limitation.. I would hope that this is just a temporary state of affairs and that MLAG will support MSTP later.
by mducharme
Mon Jun 07, 2021 6:44 am
Forum: General
Topic: TCP Established and Call of Duty disconnects
Replies: 6
Views: 765

Re: TCP Established and Call of Duty disconnects

A few days ago I took out my Edge Router 12P and installed mikrotik ccr-1036 thinking that the performance of the network was going to improve and in fact it was but I have several problems with gamers that previously did not have especially those who play Call Of Duty and that is that sporadically...
by mducharme
Mon Jun 07, 2021 6:40 am
Forum: RouterOS v7 BETA
Topic: RouterOSv7 first look – MLAG on CRS 3xx switches
Replies: 10
Views: 2916

Re: RouterOSv7 first look – MLAG on CRS 3xx switches

One thing I noticed is that the documentation says "The MLAG requires enabled STP or RSTP protocol" - does MLAG not work with MSTP?
by mducharme
Mon Jun 07, 2021 6:16 am
Forum: RouterOS v7 BETA
Topic: CHR - Broken upgrade from RouterOS 7.1 b4
Replies: 5
Views: 1320

Re: CHR - Broken upgrade from RouterOS 7.1 b4

Sorry, typed the wrong version number: 7.1 beta 4.
Try setting up a new server with beta 6. There was an issue with beta 4 and earlier, if I recall it was something to do with the partition table format being incorrect. It may be the cause of the issues you are having.
by mducharme
Sun Jun 06, 2021 10:17 pm
Forum: Announcements
Topic: v6.47.10 [long-term] is released!
Replies: 150
Views: 35916

Re: v6.47.10 [long-term] is released!

I do have personal experience with hAP mini units in the field as we have about 50 of them deployed to customers, with the bundle package and tr069 package (currently running 6.48). I have upgraded them a few times now, but try to make the upgrades infrequent to try to avoid issues with insufficient...
by mducharme
Sun Jun 06, 2021 6:11 am
Forum: Announcements
Topic: v6.47.10 [long-term] is released!
Replies: 150
Views: 35916

Re: v6.47.10 [long-term] is released!

dear BartoszP, yes, on MTCNA class, which topics that the router have to have routing package ? remember that static routing does NOT need routing package as the function already inside of system. routing package contain dynamic routing functions such as ospf, rip, and bgp. it only needed on advanc...
by mducharme
Fri Jun 04, 2021 9:32 am
Forum: Announcements
Topic: SwOS Lite version 2.14 released!
Replies: 28
Views: 42842

Re: SwOS Lite version 2.14 released!

Can anybody confirm if this fixes the link issues with Intel SFP NIC's? Currently on 2.13 release candidate for that to work as 2.13 final could not link.
by mducharme
Fri Jun 04, 2021 3:13 am
Forum: Useful user articles
Topic: MikroTik Wireguard server with Road Warrior clients
Replies: 48
Views: 17918

Re: MikroTik Wireguard server with Road Warrior clients

I do the same ping troubleshooting without IP address :-) I know you do, but I am thinking more about what is easiest to understand for people who are not as technically proficient. If Wireguard does not seem to be working, it could be harder for them to trace down the issue if you do not have an a...
by mducharme
Thu Jun 03, 2021 11:13 am
Forum: Announcements
Topic: v6.47.10 [long-term] is released!
Replies: 150
Views: 35916

Re: v6.47.10 [long-term] is released!

Also it is best to not enable the "store on disk" checkmark because keeping Graphing data on disk (flash) causes a very high number of flash writes. "Store on disk" itself is not a problem, depending on how things are configured. In Tools->Graphing, there is a "Graphing Set...
by mducharme
Thu Jun 03, 2021 10:36 am
Forum: Useful user articles
Topic: MikroTik Wireguard server with Road Warrior clients
Replies: 48
Views: 17918

Re: MikroTik Wireguard server with Road Warrior clients

There is another reason I can see for having IP addresses on the Wireguard interfaces themselves - easy troubleshooting. If Wireguard is not working and you don't know why, having the IPs on both sides on that interface, and using those to do ping tests, allows you eliminate certain kinds of routing...
by mducharme
Thu Jun 03, 2021 8:24 am
Forum: Announcements
Topic: v6.47.10 [long-term] is released!
Replies: 150
Views: 35916

Re: v6.47.10 [long-term] is released!

Features like Graphing take up space on the disk without actually displaying as files. In previous cases I have had to disable Graphing so that the graph data is deleted in order to successfully upgrade 16MB flash devices.
by mducharme
Tue Jun 01, 2021 4:36 am
Forum: Forwarding Protocols
Topic: OSPFv3 + DHCPV6 Relay Not Routing Correctly
Replies: 3
Views: 2395

Re: OSPFv3 + DHCPV6 Relay Not Routing Correctly

Hello I'm having difficulties setting up a dhcpv6 relay through ospfv3 and i'm not sure if its a configuration issue or just broken/incompatible as I know ipv6 implementation is far from complete thus far. I believe the DHCPv6 relay feature was not designed for prefix delegation, so it doesn't add ...