Community discussions

Search found 92 matches

  • 1
  • 2
by expert
Mon May 13, 2019 11:37 pm
Forum: Beginner Basics
Topic: CCR1009-8G-1S-1S+, Smart card and Certificates
Replies: 10
Views: 3874

Re: CCR1009-8G-1S-1S+, Smart card and Certificates

I'd be interested to know more too if anyone has found a compatible product and some guidelines on how to set up. Thanks I got a reply from @support: Unfortunately, we cannot recommend any Smart Card for use in MikroTik devices. The Smart Card support in RouterOS requires significant rebuild and cu...
by expert
Fri Nov 23, 2018 5:20 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature requests
Replies: 1131
Views: 198089

Re: Feature requests

When do we ever see the option of select and copy text in the winbox log files? This has been asked for years. Plus the option to search for string of caracters? When studying your logs in winbox it's at times hard to get the eyes focused on what you want to see if there are many lines to read thro...
by expert
Sat Oct 06, 2018 6:40 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature requests
Replies: 1131
Views: 198089

Re: Feature requests

Remember that interface lists are handled by the CPU. An interface list is just a bit set in the interface definition which can be matched e.g. in the firewall ("is this bit set for the interface where this packet arrived") by the processor. This is entirely different from switch programming, where...
by expert
Sat Oct 06, 2018 12:27 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature requests
Replies: 1131
Views: 198089

Re: Feature requests

1. Please allow adding many to many entries into vlan table for CRS1xx,2xx. Currently, only many to one entries are allowed: Current: /interface ethernet switch vlan add ports=sfp1,sfp2 vlan-id=200 /interface ethernet switch vlan add ports=sfp1,sfp2 vlan-id=201 Proposed: /interface ethernet switch v...
by expert
Wed Oct 03, 2018 9:25 pm
Forum: General
Topic: hardware acceleration on only one bridge?
Replies: 13
Views: 1104

Re: hardware acceleration on only one bridge?

Well, with old configuration with master ports, it was possible to have two or more master ports on a single switch chip, while still maintaining hw offload.

The new bridge implementation IMHO still uses master port internally, so it's questionable why that's not possible anymore.
by expert
Fri Aug 31, 2018 1:04 pm
Forum: Scripting
Topic: How to ***really*** block invalid TCP and UDP packet
Replies: 43
Views: 35486

Re: How to ***really*** block invalid TCP and UDP packet

Well,

You are the expert. Why don't you explain it to us then?
Well, you're forum veteran, so why you're posting impressions instead of facts here?
by expert
Fri Aug 31, 2018 12:17 pm
Forum: Scripting
Topic: How to ***really*** block invalid TCP and UDP packet
Replies: 43
Views: 35486

Re: How to ***really*** block invalid TCP and UDP packet

As far as I know, when the payload of a message is too large to fit in a TCP/UDP packet (see MTU), then it gets split into multiple packets (ie: fragmented packets). The first packet contains the TCP/UDP headers with the source/dest ports but the next fragmented packets do not contain the real port...
by expert
Tue Aug 07, 2018 7:04 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 191
Views: 23367

Re: Blacklist Filter (Development Topic)

The script is readily available to download and inspect before hand because any self respecting person would do that rather than blindly running it. Dave has been here for years providing this service to users in the community and is extremely well trusted, just don't pi$$ him off and you'll be fin...
by expert
Tue Aug 07, 2018 6:17 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 191
Views: 23367

Re: Blacklist Filter (Development Topic)

I see everybody here is amazed how great service it is, but has anybody think about security risks of such service? Importing third-party script to your router without any validation? I wonder why this list is not provided as plain list of IPs and let everybody implement custom script parsing and va...
by expert
Mon Aug 06, 2018 7:05 pm
Forum: General
Topic: CCR1009-7G-1C-1S+ vs CCR1009-7G-1C-1S+PC
Replies: 18
Views: 1984

Re: CCR1009-7G-1C-1S+ vs CCR1009-7G-1C-1S+PC

I have replaced original fans in my home CCR1009-7G-1C-1S+ with Noctua NF-A4x20. Not PWM, 3-pin FLX version, as MikroTik does'n support PWM.
...and you lost the warranty. :lol:
by expert
Fri Aug 03, 2018 4:15 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: VLAN Trunk without knowing/cofiguring all VLANS
Replies: 5
Views: 996

Re: VLAN Trunk without knowing/cofiguring all VLANS

Can be the same be achieved on CRS1xx/2xx switches (VLANs configured on switch chip)?
by expert
Fri Aug 03, 2018 3:20 pm
Forum: Beginner Basics
Topic: CCR1009-8G-1S-1S+, Smart card and Certificates
Replies: 10
Views: 3874

Re: CCR1009-8G-1S-1S+, Smart card and Certificates

The card just arrived, however it does not work in CCR1009: [admin@ccr] > /certificate card-reinstall pin=1234 failure: Install failed! echo: certificate,critical it seems your card is not GlobalPlatform compatible! [admin@ccr] > /certificate card-verify pin=1234 failure: SIM not initialised! The ca...
by expert
Fri Aug 03, 2018 1:59 pm
Forum: General
Topic: [Feature request] export append=yes
Replies: 2
Views: 372

Re: [Feature request] export append=yes

So, nobody here found this feature useful?
by expert
Fri Aug 03, 2018 12:19 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 191
Views: 23367

Re: Blacklist Filter (Development Topic)

Hi, since I'm interested about the blacklist service and in order to evaluate whether it's useful to me, I'd like to know, what exactly is blacklisted?
Who/what created such list of IPs? Thanks in advance.
by expert
Wed Aug 01, 2018 10:18 pm
Forum: General
Topic: [Feature request] export append=yes
Replies: 2
Views: 372

[Feature request] export append=yes

Please implement append=yes option to the export command.

Use case: I'd like to perform router-to-router (partial) config transfer described in the following use case.
/ip dhcp server lease export file=config.rsc append=yes
/ip dns static export file=config.rsc append=yes
by expert
Tue Jul 31, 2018 9:18 pm
Forum: General
Topic: Dude traffic and firewall [SOLVED]
Replies: 1
Views: 509

Re: Dude traffic and firewall [SOLVED]

Solved, the following rule works:
/ip firewall filter add chain=input dst-address-type=local src-address-type=local action=accept comment="Allow local traffic"
by expert
Mon Jul 30, 2018 6:46 pm
Forum: General
Topic: Dude traffic and firewall [SOLVED]
Replies: 1
Views: 509

Dude traffic and firewall [SOLVED]

I have CCR1009 device running Dude and monitoring itself. The device has also configured firewall filters entirely based on interface lists. However, Dude traffic doesn't seem to have any in-interface and out-interface . Here's how the traffic appears in the log: 17:36:54 firewall,info DUDE input: i...
by expert
Fri Jul 20, 2018 2:46 pm
Forum: Beginner Basics
Topic: CCR1009-8G-1S-1S+, Smart card and Certificates
Replies: 10
Views: 3874

Re: CCR1009-8G-1S-1S+, Smart card and Certificates

I have ordered Gemalto (Safenet) TOP IM GX4 REV B SIM Pre-Cut - White from Amazon co uk.
I will soon post some results how (if) it works. Link to PDF specification

Image
by expert
Sun Jul 15, 2018 5:26 pm
Forum: Forwarding Protocols
Topic: Filter STP BDPUs egressing a bridge port on CRS a.k.a "BPDU-filter"
Replies: 3
Views: 2690

Re: Filter STP BDPUs egressing a bridge port on CRS a.k.a "BPDU-filter"

I recently observed similar issue, where BDPUs from the provider were entering my L2 network and interfering with my RSTP instance. The following filter fixed the problem: /interface bridge filter add action=drop chain=forward in-interface=wan dst-mac-address=01:80:C2:00:00:00/FF:FF:FF:FF:FF:FF comm...
by expert
Fri Jul 13, 2018 11:58 pm
Forum: General
Topic: Combo port problem
Replies: 3
Views: 797

Re: Combo port problem

That means in case of broken link, no automatic failover will occur, but manual intervention is needed. Either remove SFP module or reconfigure combo-mode to copper.
by expert
Fri Jul 13, 2018 4:02 pm
Forum: General
Topic: Combo port problem
Replies: 3
Views: 797

Combo port problem

I have a device with combo port (CRS106) and I have noticed strange behavior. Steps to reproduce: connect combo's copper port to other device using patch cable leave combo's SFP cage empty set combo-mode=auto -> link is up and running using copper port Now plug S-RJ01 module to the SFP cage. The dev...
by expert
Thu Jun 28, 2018 8:23 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 21972

Re: v6.42.5 [current]

I guess all of the following my devices are not upgradeable in the future due to low disk space :-( version: 6.42.5 (stable) free-hdd-space: 4648.0KiB board-name: CRS112-8P-4S version: 6.42.5 (stable) free-hdd-space: 4700.0KiB board-name: CRS106-1C-5S version: 6.42.5 (stable) free-hdd-space: 4692.0K...
by expert
Thu Jun 21, 2018 11:54 pm
Forum: Beginner Basics
Topic: wlan interfaces not running
Replies: 8
Views: 1429

Re: wlan interfaces not running

An interface is marked as "running" only if connected. Otherwise it stays exactly this way: neither running nor deactivated.
Connected to what?? We're talking about wireless interfaces, which are supposed to be always running, unless disabled=yes.
by expert
Thu Jun 21, 2018 11:32 pm
Forum: Beginner Basics
Topic: wlan interfaces not running
Replies: 8
Views: 1429

Re: wlan interfaces not running

I don't think there's anything config-related, which could have impact on the running/not running state.
by expert
Thu Jun 21, 2018 11:24 pm
Forum: Beginner Basics
Topic: wlan interfaces not running
Replies: 8
Views: 1429

wlan interfaces not running

Hi, I have new wAP AC device. For unclear reason, I can't get wlan interfaces into running state, see: /interface wireless print Flags: X - disabled, R - running 0 name="wlan1" mtu=1500 l2mtu=1600 mac-address=CC:2D:E0:86:1B:E2 arp=enabled interface-type=Atheros AR9300 mode=ap-bridge ssid="wifi2" fre...
by expert
Tue Jun 12, 2018 10:44 am
Forum: General
Topic: any reviews/comments for CRS328-24P-4S+RM or CRS112-8P-4S-IN poe switches
Replies: 9
Views: 2191

Re: any reviews/comments for CRS328-24P-4S+RM or CRS112-8P-4S-IN poe switches

I have CRS112-8P-4S-IN it works more or less fine. To power some other devices (e.g. RB450G and thirdparty webcam) I had to set the port's POE status to force-on). I have it installed into 19'' rack using included "ears": https://img.routerboard.com/mimg/part441414762206m.jpg Hoverer I'd like to put...
by expert
Wed May 30, 2018 11:03 pm
Forum: Announcements
Topic: Winbox 3.14 released!
Replies: 77
Views: 23638

Re: Winbox 3.14 released!

Winbox 3.14, but also all older versions:

How to edit such dialog window, when screen is so small? Scroll does not work.
Image

Why aren't interfaces sorted by name?
Image
by expert
Mon Mar 26, 2018 8:54 pm
Forum: RouterBOARD hardware
Topic: CRS326, two groups Hw. Offloading
Replies: 4
Views: 615

Re: CRS326, two groups Hw. Offloading

I guess you cannot have achieve that, unlike with old master-port configuration. You need to set up isolation profiles and/or vlans to create virtually two switches.
by expert
Mon Mar 26, 2018 8:51 pm
Forum: RouterBOARD hardware
Topic: hex POE 802.11af/at?
Replies: 7
Views: 1519

Re: hex POE 802.11af/at?

I was talking about CRS-8P-4S-IN which has two power jacks.
by expert
Mon Mar 26, 2018 2:24 pm
Forum: RouterBOARD hardware
Topic: hex POE 802.11af/at?
Replies: 7
Views: 1519

Re: hex POE 802.11af/at?

Q1: Can I plug both 24V and 48V PSUs at the same time and make use of PSU failover for the switch itself?

Q2: Can I then power up 24V passive POE devices and 48V active POE devices at the same time? Will 'auto' POE mode recognize them?
by expert
Sun Mar 04, 2018 8:38 pm
Forum: General
Topic: Bridge-based port mirroring
Replies: 5
Views: 1470

Re: Bridge-based port mirroring

But the question is what is your application case? You can sniff directly on Mikrotik or forward the sniffed data TZSP-encapsulated to some other machine. I'd like to implement permanent TAP device. Sniff tool in ROS with streaming feature may work, but it seems to be something you run temporarily....
by expert
Sun Mar 04, 2018 3:45 pm
Forum: General
Topic: Bridge-based port mirroring
Replies: 5
Views: 1470

Re: Bridge-based port mirroring

How can I achieve software-based port mirroring? Thanks.
by expert
Tue Feb 27, 2018 12:25 pm
Forum: General
Topic: Bridge-based port mirroring
Replies: 5
Views: 1470

Bridge-based port mirroring

Hi,
I'm looking for port mirroring based on bridge, which could be used on device without switch chip.
Is there such feature?
by expert
Sun Feb 18, 2018 9:10 pm
Forum: General
Topic: Feature request: partitioning
Replies: 4
Views: 368

Feature request: partitioning

Feature request: please disable/hide partitioning menu in Winbox on devices, which don't support partitioning.

Q: What happens if I create partition on device, which doesn't support it? (I'm afraid to try, but I'd like to know...)
by expert
Wed Aug 16, 2017 12:55 am
Forum: RouterBOARD hardware
Topic: CRS326-24G-2S+RM fans
Replies: 17
Views: 3913

Re: CRS326-24G-2S+RM fans

I guess the PCB has fan pins somewhere. But you obviously loose the warranty.
by expert
Tue Jul 18, 2017 12:16 pm
Forum: Announcements
Topic: v6.40rc [release candidate] is released! (New bridge implementation delayed till 6.41rc)
Replies: 207
Views: 35306

Re: v6.40rc [release candidate] is released! (New bridge implementation)

I really think Mikrotik should discuss using partitions in addition to backups.
Can I make partition(s) on my mAP Lite? It has only 32MB disk space.
by expert
Thu May 04, 2017 1:54 pm
Forum: Announcements
Topic: v6.39.1 [current]
Replies: 158
Views: 36044

Re: v6.39.1 [current]

Some people here are complaining about serious issues with 3011 after upgrade.
However I haven't seen any reaction of MK confirming or rejecting that. So I'm asking whether is it safe to upgrade 3011 and wish to hear clear answer.
by expert
Sun Apr 02, 2017 8:48 pm
Forum: General
Topic: Hotspot Setup on wAP with RB3011
Replies: 3
Views: 711

Re: Hotspot Setup on wAP with RB3011

You can hire a consultant
by expert
Sun Apr 02, 2017 3:29 pm
Forum: RouterBOARD hardware
Topic: RB3011 No metarouter?
Replies: 11
Views: 5287

Re: RB3011 No metarouter?

Now with RB1100AHx4 we need metarouter :-)
It is unlikely to happen. Metarouter has never worked on any of the multicore devices. And now it's a multicore ARM... Unlikely.
Has metarouter ever worked on anything? I mean for serious production use.
by expert
Fri Mar 24, 2017 6:40 pm
Forum: RouterBOARD hardware
Topic: Dead RB3011?
Replies: 10
Views: 1606

Re: Dead RB3011?

And what's seen on serial console?
by expert
Tue Mar 21, 2017 10:21 pm
Forum: General
Topic: Vlans in switch chip for CCR
Replies: 3
Views: 664

Re: Vlans in switch chip for CCR

Thank you. I was under the impression there was a switch chip from reading older posts.
Yes, there really was, but the device ( CCR1009-8G-1S-1S+ ) is no longer manufactured

Image
by expert
Sat Mar 18, 2017 4:45 pm
Forum: Virtualization
Topic: Metarouter in RB2011
Replies: 1
Views: 589

Re: Metarouter in RB2011

Metarouter is a toy, it's not suitable for anything serious! Search for older posts...
by expert
Wed Mar 08, 2017 10:22 am
Forum: General
Topic: Default vlan ?
Replies: 2
Views: 485

Re: Default vlan ?

What is the term default native VLAN? IEEE 802.1Q does not know such term.
There are ethernet frames without VLAN tag, those are mapped to VLAN ID 0.
There are frames with VLAN tag, those are mapped to VLAN ID >0.
Advice: do not use VLAN ID 1 unless you know what you're doing.
by expert
Sun Mar 05, 2017 3:35 pm
Forum: Announcements
Topic: v6.39rc [release candidate] is released
Replies: 391
Views: 80781

Re: v6.39rc [release candidate] is released

Is the RSTP problem fixed? viewtopic.php?t=118320&f=13#p585480
by expert
Sun Mar 05, 2017 12:37 pm
Forum: RouterBOARD hardware
Topic: RB2011 PoE
Replies: 5
Views: 1850

Re: RB2011 PoE

What does it mean has PoE ? Device 2011UIAs has:

a) PoE in on ether1
b) PoE out on ether10

What's wrong on having wan on e.g. eth7 ?
by expert
Tue Feb 28, 2017 1:56 pm
Forum: Virtualization
Topic: LEDE project, metarouter
Replies: 2
Views: 1676

LEDE project, metarouter

The LEDE Project (Linux Embedded Development Environment) has been released in stable version. Are there any plans to build Metarouter image?
by expert
Thu Feb 23, 2017 1:17 pm
Forum: General
Topic: 8-Port managed POE/POE+ Switch for use with Mikrotik
Replies: 2
Views: 1627

Re: 8-Port managed POE/POE+ Switch for use with Mikrotik

Most (if not all) Mikrotik devices use non-standard passive PoE at 12-24V. I don't know any switch which is able to deliver passive PoE.

I would rather take passive PoE injektor which can be used with any switch Image
by expert
Thu Feb 23, 2017 12:57 am
Forum: Announcements
Topic: v6.38.3 [current]
Replies: 63
Views: 14241

Re: v6.38.3 [current]

LCD interfaces is broken, it does not switch between interfaces. In my case, LCD shows only pppoe-wan, other interfaces are not shown. What is the timeout then?
Image
by expert
Tue Feb 21, 2017 4:15 pm
Forum: Beginner Basics
Topic: SFP port on RB3011, where do you use it for?
Replies: 6
Views: 2252

Re: SFP port on RB3011, where do you use it for?

<dream>I'm using it for SFP VDSL modem</dream>

But no, I have it connected to Cloud Router Switch.
  • 1
  • 2