Community discussions

MikroTik App

Search found 97 matches

by expert
Tue Apr 07, 2020 12:18 am
Forum: General
Topic: crs3xx - bridge filter - hw offloading?
Replies: 5
Views: 2926

Re: crs3xx - bridge filter - hw offloading?

Well, there seems to be a problem with Switch > ACL on this device (6.46.4). There are no ports available. Any ideas?
by expert
Mon Apr 06, 2020 11:25 am
Forum: General
Topic: crs3xx - bridge filter - hw offloading?
Replies: 5
Views: 2926

Re: crs3xx - bridge filter - hw offloading?

Thanks, you may be right. But I'd be glad if @support will comment on this too...
by expert
Sun Apr 05, 2020 9:37 pm
Forum: General
Topic: CRS354-48G-4S+2Q+ (Heat issue?) [SOLVED]
Replies: 12
Views: 10319

Re: CRS354-48G-4S+2Q+ (Heat issue?) [SOLVED]

The following metrics were captured when the device is idle (no traffic, no attached devices): cpu-temperature: 56C board-temperature1: 36C psu1-voltage: 27.1V psu2-voltage: 53.7V psu1-current: 0A psu2-current: 0A psu1-state: ok fan1-speed: 4215RPM fan2-speed: 4230RPM fan3-speed: 4440RPM fan4-speed:...
by expert
Sat Apr 04, 2020 11:55 pm
Forum: General
Topic: CRS354-48G-4S+2Q+ (Heat issue?) [SOLVED]
Replies: 12
Views: 10319

Re: CRS354-48G-4S+2Q+ (Heat issue?) [SOLVED]

I did similar mod of my new CRS354-48P-4S+2Q+ with 4x Noctua NF-A4x20 FLX and one tiny fan for CPU, connected via Y-adaptor to fan1 header. So far, all good.
by expert
Sat Apr 04, 2020 11:41 pm
Forum: General
Topic: crs3xx - bridge filter - hw offloading?
Replies: 5
Views: 2926

crs3xx - bridge filter - hw offloading?

Hi,
do bridge filter rules ( /interface bridge filter ) maintain hw offloading?
Wiki does not explicitly answer that ( https://wiki.mikrotik.com/wiki/Manual:C ... s_switches )
My device: CRS354-48P-4S+2Q+

thanks.
by expert
Wed Mar 25, 2020 11:55 pm
Forum: General
Topic: Feature request: add interface list into bridge vlan table
Replies: 1
Views: 2655

Feature request: add interface list into bridge vlan table

It is possible to add interface-list as bridge port, then logically it makes sense to be able to add interface-list as bridge vlan tagged/untagged member. But the latter is not possible. Background : I have interface list uplink with members: sfpplus1, spfplus2 . I add the uplink list into bridge-ma...
by expert
Mon Dec 02, 2019 11:26 pm
Forum: Beginner Basics
Topic: CCR1009-8G-1S-1S+, Smart card and Certificates
Replies: 12
Views: 10297

Re: CCR1009-8G-1S-1S+, Smart card and Certificates

A year later: smart cards are still not working.

I volunteer myself to fix ROS source code to make smart cards working, if you, guys, in MK don't have time to do it.
by expert
Mon May 13, 2019 11:37 pm
Forum: Beginner Basics
Topic: CCR1009-8G-1S-1S+, Smart card and Certificates
Replies: 12
Views: 10297

Re: CCR1009-8G-1S-1S+, Smart card and Certificates

I'd be interested to know more too if anyone has found a compatible product and some guidelines on how to set up. Thanks I got a reply from @support: Unfortunately, we cannot recommend any Smart Card for use in MikroTik devices. The Smart Card support in RouterOS requires significant rebuild and cu...
by expert
Fri Nov 23, 2018 5:20 pm
Forum: General
Topic: Feature requests
Replies: 1742
Views: 637346

Re: Feature requests

When do we ever see the option of select and copy text in the winbox log files? This has been asked for years. Plus the option to search for string of caracters? When studying your logs in winbox it's at times hard to get the eyes focused on what you want to see if there are many lines to read thro...
by expert
Sat Oct 06, 2018 6:40 pm
Forum: General
Topic: Feature requests
Replies: 1742
Views: 637346

Re: Feature requests

Remember that interface lists are handled by the CPU. An interface list is just a bit set in the interface definition which can be matched e.g. in the firewall ("is this bit set for the interface where this packet arrived") by the processor. This is entirely different from switch programm...
by expert
Sat Oct 06, 2018 12:27 pm
Forum: General
Topic: Feature requests
Replies: 1742
Views: 637346

Re: Feature requests

1. Please allow adding many to many entries into vlan table for CRS1xx,2xx. Currently, only many to one entries are allowed: Current: /interface ethernet switch vlan add ports=sfp1,sfp2 vlan-id=200 /interface ethernet switch vlan add ports=sfp1,sfp2 vlan-id=201 Proposed: /interface ethernet switch v...
by expert
Wed Oct 03, 2018 9:25 pm
Forum: General
Topic: hardware acceleration on only one bridge?
Replies: 13
Views: 3734

Re: hardware acceleration on only one bridge?

Well, with old configuration with master ports, it was possible to have two or more master ports on a single switch chip, while still maintaining hw offload.

The new bridge implementation IMHO still uses master port internally, so it's questionable why that's not possible anymore.
by expert
Tue Aug 07, 2018 7:04 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 188
Views: 62557

Re: Blacklist Filter (Development Topic)

The script is readily available to download and inspect before hand because any self respecting person would do that rather than blindly running it. Dave has been here for years providing this service to users in the community and is extremely well trusted, just don't pi$$ him off and you'll be fin...
by expert
Tue Aug 07, 2018 6:17 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 188
Views: 62557

Re: Blacklist Filter (Development Topic)

I see everybody here is amazed how great service it is, but has anybody think about security risks of such service? Importing third-party script to your router without any validation? I wonder why this list is not provided as plain list of IPs and let everybody implement custom script parsing and va...
by expert
Mon Aug 06, 2018 7:05 pm
Forum: General
Topic: CCR1009-7G-1C-1S+ vs CCR1009-7G-1C-1S+PC
Replies: 18
Views: 6617

Re: CCR1009-7G-1C-1S+ vs CCR1009-7G-1C-1S+PC

I have replaced original fans in my home CCR1009-7G-1C-1S+ with Noctua NF-A4x20. Not PWM, 3-pin FLX version, as MikroTik does'n support PWM.
...and you lost the warranty. :lol:
by expert
Fri Aug 03, 2018 4:15 pm
Forum: General
Topic: VLAN Trunk without knowing/cofiguring all VLANS
Replies: 5
Views: 2386

Re: VLAN Trunk without knowing/cofiguring all VLANS

Can be the same be achieved on CRS1xx/2xx switches (VLANs configured on switch chip)?
by expert
Fri Aug 03, 2018 3:20 pm
Forum: Beginner Basics
Topic: CCR1009-8G-1S-1S+, Smart card and Certificates
Replies: 12
Views: 10297

Re: CCR1009-8G-1S-1S+, Smart card and Certificates

The card just arrived, however it does not work in CCR1009: [admin@ccr] > /certificate card-reinstall pin=1234 failure: Install failed! echo: certificate,critical it seems your card is not GlobalPlatform compatible! [admin@ccr] > /certificate card-verify pin=1234 failure: SIM not initialised! The ca...
by expert
Fri Aug 03, 2018 1:59 pm
Forum: General
Topic: [Feature request] export append=yes
Replies: 2
Views: 1050

Re: [Feature request] export append=yes

So, nobody here found this feature useful?
by expert
Fri Aug 03, 2018 12:19 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 188
Views: 62557

Re: Blacklist Filter (Development Topic)

Hi, since I'm interested about the blacklist service and in order to evaluate whether it's useful to me, I'd like to know, what exactly is blacklisted?
Who/what created such list of IPs? Thanks in advance.
by expert
Wed Aug 01, 2018 10:18 pm
Forum: General
Topic: [Feature request] export append=yes
Replies: 2
Views: 1050

[Feature request] export append=yes

Please implement append=yes option to the export command.

Use case: I'd like to perform router-to-router (partial) config transfer described in the following use case.
/ip dhcp server lease export file=config.rsc append=yes
/ip dns static export file=config.rsc append=yes
by expert
Tue Jul 31, 2018 9:18 pm
Forum: General
Topic: Dude traffic and firewall [SOLVED]
Replies: 1
Views: 1670

Re: Dude traffic and firewall [SOLVED]

Solved, the following rule works:
/ip firewall filter add chain=input dst-address-type=local src-address-type=local action=accept comment="Allow local traffic"
by expert
Mon Jul 30, 2018 6:46 pm
Forum: General
Topic: Dude traffic and firewall [SOLVED]
Replies: 1
Views: 1670

Dude traffic and firewall [SOLVED]

I have CCR1009 device running Dude and monitoring itself. The device has also configured firewall filters entirely based on interface lists. However, Dude traffic doesn't seem to have any in-interface and out-interface . Here's how the traffic appears in the log: 17:36:54 firewall,info DUDE input: i...
by expert
Fri Jul 20, 2018 2:46 pm
Forum: Beginner Basics
Topic: CCR1009-8G-1S-1S+, Smart card and Certificates
Replies: 12
Views: 10297

Re: CCR1009-8G-1S-1S+, Smart card and Certificates

I have ordered Gemalto (Safenet) TOP IM GX4 REV B SIM Pre-Cut - White from Amazon co uk.
I will soon post some results how (if) it works. Link to PDF specification

Image
by expert
Sun Jul 15, 2018 5:26 pm
Forum: Forwarding Protocols
Topic: Filter STP BDPUs egressing a bridge port on CRS a.k.a "BPDU-filter"
Replies: 12
Views: 11037

Re: Filter STP BDPUs egressing a bridge port on CRS a.k.a "BPDU-filter"

I recently observed similar issue, where BDPUs from the provider were entering my L2 network and interfering with my RSTP instance. The following filter fixed the problem: /interface bridge filter add action=drop chain=forward in-interface=wan dst-mac-address=01:80:C2:00:00:00/FF:FF:FF:FF:FF:FF comm...
by expert
Fri Jul 13, 2018 11:58 pm
Forum: General
Topic: Combo port problem
Replies: 3
Views: 2637

Re: Combo port problem

That means in case of broken link, no automatic failover will occur, but manual intervention is needed. Either remove SFP module or reconfigure combo-mode to copper.
by expert
Fri Jul 13, 2018 4:02 pm
Forum: General
Topic: Combo port problem
Replies: 3
Views: 2637

Combo port problem

I have a device with combo port (CRS106) and I have noticed strange behavior. Steps to reproduce: connect combo's copper port to other device using patch cable leave combo's SFP cage empty set combo-mode=auto -> link is up and running using copper port Now plug S-RJ01 module to the SFP cage. The dev...
by expert
Thu Jun 28, 2018 8:23 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 54350

Re: v6.42.5 [current]

I guess all of the following my devices are not upgradeable in the future due to low disk space :-( version: 6.42.5 (stable) free-hdd-space: 4648.0KiB board-name: CRS112-8P-4S version: 6.42.5 (stable) free-hdd-space: 4700.0KiB board-name: CRS106-1C-5S version: 6.42.5 (stable) free-hdd-space: 4692.0K...
by expert
Thu Jun 21, 2018 11:54 pm
Forum: Beginner Basics
Topic: wlan interfaces not running
Replies: 8
Views: 16131

Re: wlan interfaces not running

An interface is marked as "running" only if connected. Otherwise it stays exactly this way: neither running nor deactivated.
Connected to what?? We're talking about wireless interfaces, which are supposed to be always running, unless disabled=yes.
by expert
Thu Jun 21, 2018 11:32 pm
Forum: Beginner Basics
Topic: wlan interfaces not running
Replies: 8
Views: 16131

Re: wlan interfaces not running

I don't think there's anything config-related, which could have impact on the running/not running state.
by expert
Thu Jun 21, 2018 11:24 pm
Forum: Beginner Basics
Topic: wlan interfaces not running
Replies: 8
Views: 16131

wlan interfaces not running

Hi, I have new wAP AC device. For unclear reason, I can't get wlan interfaces into running state, see: /interface wireless print Flags: X - disabled, R - running 0 name="wlan1" mtu=1500 l2mtu=1600 mac-address=CC:2D:E0:86:1B:E2 arp=enabled interface-type=Atheros AR9300 mode=ap-bridge ssid=&...
by expert
Tue Jun 12, 2018 10:44 am
Forum: General
Topic: any reviews/comments for CRS328-24P-4S+RM or CRS112-8P-4S-IN poe switches
Replies: 9
Views: 5314

Re: any reviews/comments for CRS328-24P-4S+RM or CRS112-8P-4S-IN poe switches

I have CRS112-8P-4S-IN it works more or less fine. To power some other devices (e.g. RB450G and thirdparty webcam) I had to set the port's POE status to force-on). I have it installed into 19'' rack using included "ears": https://img.routerboard.com/mimg/part441414762206m.jpg Hoverer I'd l...
by expert
Wed May 30, 2018 11:03 pm
Forum: Announcements
Topic: Winbox 3.14 released!
Replies: 77
Views: 58876

Re: Winbox 3.14 released!

Winbox 3.14, but also all older versions:

How to edit such dialog window, when screen is so small? Scroll does not work.
Image

Why aren't interfaces sorted by name?
Image
by expert
Mon Mar 26, 2018 8:54 pm
Forum: RouterBOARD hardware
Topic: CRS326, two groups Hw. Offloading
Replies: 4
Views: 1818

Re: CRS326, two groups Hw. Offloading

I guess you cannot have achieve that, unlike with old master-port configuration. You need to set up isolation profiles and/or vlans to create virtually two switches.
by expert
Mon Mar 26, 2018 8:51 pm
Forum: RouterBOARD hardware
Topic: hex POE 802.11af/at?
Replies: 7
Views: 3753

Re: hex POE 802.11af/at?

I was talking about CRS-8P-4S-IN which has two power jacks.
by expert
Mon Mar 26, 2018 2:24 pm
Forum: RouterBOARD hardware
Topic: hex POE 802.11af/at?
Replies: 7
Views: 3753

Re: hex POE 802.11af/at?

Q1: Can I plug both 24V and 48V PSUs at the same time and make use of PSU failover for the switch itself?

Q2: Can I then power up 24V passive POE devices and 48V active POE devices at the same time? Will 'auto' POE mode recognize them?
by expert
Sun Mar 04, 2018 8:38 pm
Forum: General
Topic: Bridge-based port mirroring
Replies: 5
Views: 6122

Re: Bridge-based port mirroring

But the question is what is your application case? You can sniff directly on Mikrotik or forward the sniffed data TZSP-encapsulated to some other machine. I'd like to implement permanent TAP device. Sniff tool in ROS with streaming feature may work, but it seems to be something you run temporarily....
by expert
Sun Mar 04, 2018 3:45 pm
Forum: General
Topic: Bridge-based port mirroring
Replies: 5
Views: 6122

Re: Bridge-based port mirroring

How can I achieve software-based port mirroring? Thanks.
by expert
Tue Feb 27, 2018 12:25 pm
Forum: General
Topic: Bridge-based port mirroring
Replies: 5
Views: 6122

Bridge-based port mirroring

Hi,
I'm looking for port mirroring based on bridge, which could be used on device without switch chip.
Is there such feature?
by expert
Sun Feb 18, 2018 9:10 pm
Forum: General
Topic: Feature request: partitioning
Replies: 4
Views: 1145

Feature request: partitioning

Feature request: please disable/hide partitioning menu in Winbox on devices, which don't support partitioning.

Q: What happens if I create partition on device, which doesn't support it? (I'm afraid to try, but I'd like to know...)
by expert
Wed Aug 16, 2017 12:55 am
Forum: RouterBOARD hardware
Topic: CRS326-24G-2S+RM fans
Replies: 20
Views: 16571

Re: CRS326-24G-2S+RM fans

I guess the PCB has fan pins somewhere. But you obviously loose the warranty.
by expert
Tue Jul 18, 2017 12:16 pm
Forum: Announcements
Topic: v6.40rc [release candidate] is released! (New bridge implementation delayed till 6.41rc)
Replies: 207
Views: 65826

Re: v6.40rc [release candidate] is released! (New bridge implementation)

I really think Mikrotik should discuss using partitions in addition to backups.
Can I make partition(s) on my mAP Lite? It has only 32MB disk space.
by expert
Thu May 04, 2017 1:54 pm
Forum: Announcements
Topic: v6.39.1 [current]
Replies: 158
Views: 58894

Re: v6.39.1 [current]

Some people here are complaining about serious issues with 3011 after upgrade.
However I haven't seen any reaction of MK confirming or rejecting that. So I'm asking whether is it safe to upgrade 3011 and wish to hear clear answer.
by expert
Sun Apr 02, 2017 8:48 pm
Forum: General
Topic: Hotspot Setup on wAP with RB3011
Replies: 2
Views: 1642

Re: Hotspot Setup on wAP with RB3011

You can hire a consultant
by expert
Sun Apr 02, 2017 3:29 pm
Forum: RouterBOARD hardware
Topic: RB3011 No metarouter?
Replies: 11
Views: 8483

Re: RB3011 No metarouter?

Now with RB1100AHx4 we need metarouter :-)
It is unlikely to happen. Metarouter has never worked on any of the multicore devices. And now it's a multicore ARM... Unlikely.
Has metarouter ever worked on anything? I mean for serious production use.
by expert
Fri Mar 24, 2017 6:40 pm
Forum: RouterBOARD hardware
Topic: Dead RB3011?
Replies: 10
Views: 3748

Re: Dead RB3011?

And what's seen on serial console?
by expert
Tue Mar 21, 2017 10:21 pm
Forum: General
Topic: Vlans in switch chip for CCR
Replies: 3
Views: 1584

Re: Vlans in switch chip for CCR

Thank you. I was under the impression there was a switch chip from reading older posts.
Yes, there really was, but the device ( CCR1009-8G-1S-1S+ ) is no longer manufactured

Image
by expert
Sat Mar 18, 2017 4:45 pm
Forum: Virtualization
Topic: Metarouter in RB2011
Replies: 1
Views: 2637

Re: Metarouter in RB2011

Metarouter is a toy, it's not suitable for anything serious! Search for older posts...
by expert
Wed Mar 08, 2017 10:22 am
Forum: General
Topic: Default vlan ?
Replies: 2
Views: 1182

Re: Default vlan ?

What is the term default native VLAN? IEEE 802.1Q does not know such term.
There are ethernet frames without VLAN tag, those are mapped to VLAN ID 0.
There are frames with VLAN tag, those are mapped to VLAN ID >0.
Advice: do not use VLAN ID 1 unless you know what you're doing.
by expert
Sun Mar 05, 2017 3:35 pm
Forum: Announcements
Topic: v6.39rc [release candidate] is released
Replies: 390
Views: 139504

Re: v6.39rc [release candidate] is released

Is the RSTP problem fixed? viewtopic.php?t=118320&f=13#p585480
by expert
Sun Mar 05, 2017 12:37 pm
Forum: RouterBOARD hardware
Topic: RB2011 PoE
Replies: 5
Views: 3172

Re: RB2011 PoE

What does it mean has PoE ? Device 2011UIAs has:

a) PoE in on ether1
b) PoE out on ether10

What's wrong on having wan on e.g. eth7 ?
by expert
Tue Feb 28, 2017 1:56 pm
Forum: Virtualization
Topic: LEDE project, metarouter
Replies: 2
Views: 3955

LEDE project, metarouter

The LEDE Project (Linux Embedded Development Environment) has been released in stable version. Are there any plans to build Metarouter image?
by expert
Sat Feb 25, 2017 8:29 pm
Forum: Beginner Basics
Topic: RSTP Problems
Replies: 1
Views: 1006

Re: RSTP Problems

by expert
Thu Feb 23, 2017 1:17 pm
Forum: General
Topic: 8-Port managed POE/POE+ Switch for use with Mikrotik
Replies: 2
Views: 2534

Re: 8-Port managed POE/POE+ Switch for use with Mikrotik

Most (if not all) Mikrotik devices use non-standard passive PoE at 12-24V. I don't know any switch which is able to deliver passive PoE.

I would rather take passive PoE injektor which can be used with any switch Image
by expert
Thu Feb 23, 2017 12:57 am
Forum: Announcements
Topic: v6.38.3 [current]
Replies: 63
Views: 27514

Re: v6.38.3 [current]

LCD interfaces is broken, it does not switch between interfaces. In my case, LCD shows only pppoe-wan, other interfaces are not shown. What is the timeout then?
Image
by expert
Tue Feb 21, 2017 4:15 pm
Forum: Beginner Basics
Topic: SFP port on RB3011, where do you use it for?
Replies: 6
Views: 4574

Re: SFP port on RB3011, where do you use it for?

<dream>I'm using it for SFP VDSL modem</dream>

But no, I have it connected to Cloud Router Switch.
by expert
Mon Feb 20, 2017 9:20 pm
Forum: General
Topic: ssh/scp file autocompletition
Replies: 1
Views: 1144

ssh/scp file autocompletition

Hi, I've found problem when using autocompletition with ssh/scp from ROS. $ scp router: Now press <TAB> <TAB> to trigger autocompletition. Result: $ scp router:bad\\\ command\\\ name\\\ command\\\ \\\(line\\\ 1\\\ column\\\ 1\\\) Doing the same when remote host is linux, it works as expected: $ scp ...
by expert
Sat Feb 18, 2017 9:17 pm
Forum: Announcements
Topic: v6.39rc [release candidate] is released
Replies: 390
Views: 139504

Re: v6.39rc [release candidate] is released

Is the RSTP problem (which I reported here http://forum.mikrotik.com/viewtopic.php ... 50#p582781 ) fixed?
by expert
Wed Feb 15, 2017 1:08 pm
Forum: RouterBOARD hardware
Topic: Question about DAT cable maximum length.
Replies: 5
Views: 1931

Re: Question about DAT cable maximum length.

not DAT, but DAC :lol: (direct attach cable)
by expert
Wed Feb 15, 2017 9:47 am
Forum: Virtualization
Topic: Metarouter unreliable
Replies: 7
Views: 4464

Re: Metarouter unreliable

Let me summarize metarouter ( mr ) status: * mr is unreliable(?) Can you tell how you use mr ? * mr not supported on CCRs and RB3011UIas * OpenWRT - no mr support in upstream project and builds provided by MK are obsolete * OpenWRT project is stagnant, but there's a young fork called LEDE project It...
by expert
Fri Feb 10, 2017 12:17 pm
Forum: General
Topic: Native vlan 1 + vlans connected to Cisco switch
Replies: 4
Views: 5888

Re: Native vlan 1 + vlans connected to Cisco switch

Native VLAN (Cisco VLAN1) is translated to Mikrotik VLAN ID 0
...and how is handled MK VLAN 1 on Cisco side? :shock:
by expert
Thu Feb 09, 2017 4:18 pm
Forum: Announcements
Topic: v6.38.1 [current]
Replies: 73
Views: 40070

Re: v6.38.1 [current]

Still having problems when on local bridge enabled rstp. After disabling rstp, everything works as it should. This was broken in release before this one. Two Mikrotik routers connected to each other. When rstp is enabled, I can't ping the other Mikrotik. I have the same problem, but I had short tim...
by expert
Mon Feb 06, 2017 12:54 pm
Forum: General
Topic: Feature requests
Replies: 1742
Views: 637346

Re: Feature requests

Would like every service MT runs (SMB, Socks, Proxy, DNS, etc.) to all have ACLs in /ip services AFAIK, and would be good to have it 'locked down' by default to say 1921.68.1.0/24 seeing that the default IP on hardware devices is 192.168.1.1/24. Afaik factory default is 192.168.88.1/24, but I agree...
by expert
Fri Feb 03, 2017 8:55 am
Forum: RouterBOARD hardware
Topic: Mikrotik VDSL / DSL Modem?
Replies: 381
Views: 200822

Re: Mikrotik VDSL / DSL Modem?

it will be available in february next year. hopefully. and then it will have to be tested.
It's February now, any news?
by expert
Wed Feb 01, 2017 4:37 pm
Forum: Beginner Basics
Topic: CCR1009-8G-1S-1S+, Smart card and Certificates
Replies: 12
Views: 10297

Re: CCR1009-8G-1S-1S+, Smart card and Certificates

Is there any step-by-step tutorial, how to use Smart Card? Which card to buy and how to use it?
by expert
Mon Jan 30, 2017 7:04 pm
Forum: Beginner Basics
Topic: Questions regarding port mirroring on cloud router switch
Replies: 5
Views: 2579

Re: Questions regarding port mirroring

I executed those commands but am not seeing mirrored traffic on my ether24 port as expected. I'm only seeing broadcast traffic from the switch group that it is a member of. if/when i make master port=none for ether24 I see no traffic.
What packet sniffer are you using? Wireshark?
by expert
Fri Jan 27, 2017 11:42 am
Forum: Beginner Basics
Topic: Safe Mode Powercycle - Useless
Replies: 13
Views: 4965

Re: Safe Mode Powercycle - Useless

- Wait 10 Minutes
--> Working config is back --> Great
I don't need to wait 10 minutes, all my devices are back in 1-2 seconds. How did you configured so long timeout?
by expert
Tue Jan 24, 2017 12:08 pm
Forum: Announcements
Topic: Newsletter 75, January 2017
Replies: 55
Views: 28910

Re: Newsletter 75, January 2017

I don't see any reference to a RJ45 console port in the description.
If it was there, it is corrected by now.
It was there, but now it's gone - it seems they corrected it.
by expert
Tue Jan 24, 2017 9:49 am
Forum: Announcements
Topic: Newsletter 75, January 2017
Replies: 55
Views: 28910

Re: Newsletter 75, January 2017

So why would it need a console port?
Why it's written in product specification?
Serial port RJ45 :shock: https://routerboard.com/CSS326-24G-2SplusRM
by expert
Thu Jan 19, 2017 11:39 am
Forum: Virtualization
Topic: Metarouter images
Replies: 378
Views: 387791

Re: Metarouter images

Is there some stable openwrt image for 6.38.1(951G-2HnD)? I tried different version from http://openwrt.wk.cz/ (AA, trunk) on some last few ROS versions and it's very unstable with: "system,error,critical router was rebooted without proper shutdown by watchdog timer" It seems that OpenWRT...
by expert
Wed Jan 18, 2017 10:39 pm
Forum: General
Topic: RS-232 hub for admin console
Replies: 1
Views: 945

Re: RS-232 hub for admin console

Finally, I bought this device and I'm very happy with it: https://s3.amazonaws.com/assets.mhint/product_images/151054/151054pro_3.jpg http://manhattan-products.com/usb-to-serial-converter8 It works perfectly in linux, here's how it identifies: [ 5.846246] mos7840 1-3.1:1.0: Moschip 7840/7820 USB Ser...
by expert
Wed Jan 18, 2017 12:56 pm
Forum: General
Topic: Firewall - Port are inactive in 6.38.1
Replies: 1
Views: 1461

Re: Firewall - Port are inactive in 6.38.1

It's a bug of Winbox 3.8. You can download fixed version. Next time you should first read forums & changelogs.
by expert
Mon Jan 16, 2017 2:52 pm
Forum: Announcements
Topic: Winbox 3.8 released!
Replies: 45
Views: 32320

Re: Winbox 3.8 released!

I like friday releases :)

Friday, 13th...
But today is Monday and broken Winbox 3.8 is still on download site...
by expert
Sun Jan 15, 2017 10:38 pm
Forum: Virtualization
Topic: Metarouter unreliable
Replies: 7
Views: 4464

Re: Metarouter unreliable

What version of RouterOS you are using? 3.24 is version of bootloader, not RouterOS.

There have been some metarouter issues fixed in 6.38: *) metarouter - fixed startup process (introduced in 6.37.2);
by expert
Sat Jan 14, 2017 1:20 pm
Forum: General
Topic: Switch Port VLAN-Type
Replies: 1
Views: 1609

Re: Switch Port VLAN-Type

I'm also interested in this topic. Has port's vlan-type any relation to R)STP ?
by expert
Fri Jan 13, 2017 10:46 pm
Forum: General
Topic: SSH communication in MIkrotik, how to generate RSA key
Replies: 4
Views: 3567

Re: SSH communication in MIkrotik, how to generate RSA key

can mikrotik run script via ssh to remote mikrotik?? i really need to know, i have tried ssh-key on Ubuntu-to-Mikrotik and its working fine, but Mikrotik-to-Mikrotik its asking password and not passing through.. need feedback from anyone please
/ip ssh set always-allow-password-login=yes
by expert
Fri Jan 13, 2017 10:30 am
Forum: RouterBOARD hardware
Topic: CCR1009-PC how it handles overheating?
Replies: 7
Views: 3464

Re: CCR1009-PC how it handles overheating?

Thanks, desktop version could be an option.
In RM version, can be fans set into low speed, e.g. 800rpm?
by expert
Fri Jan 13, 2017 10:11 am
Forum: RouterBOARD hardware
Topic: CCR1009-PC how it handles overheating?
Replies: 7
Views: 3464

Re: CCR1009-PC how it handles overheating?

How noisy are fans in CCR1009 RM version? Can be fans disabled?
( I plan to buy one into "open rack frame" and then the noise can be disturbing... ).
by expert
Fri Jan 13, 2017 9:36 am
Forum: RouterBOARD hardware
Topic: What is exactly direct attach cable?... Does it contain SFP+ interface?
Replies: 13
Views: 5257

Re: What is exactly direct attach cable?... Does it contain SFP+ interface?

To make it explicit: DAC cable is not optical cable, but copper cable.
by expert
Wed Jan 11, 2017 8:50 pm
Forum: General
Topic: Security vulnerability with mAP Lite
Replies: 5
Views: 1856

Re: Security vulnerability with mAP Lite

how often will that happen, and what is the resolution for this?
Rarely. But it doesn't matter - it's a vulnerability. Solution is to disable mgmt access over wireless, enable over wires.
by expert
Wed Jan 11, 2017 4:47 pm
Forum: General
Topic: Security vulnerability with mAP Lite
Replies: 5
Views: 1856

Security vulnerability with mAP Lite

New(or resetted) mAP Lite device is expecting winbox connections only on wlan interface (ether1 has DROP filters in default configuration ).

When device is first time started, attacker could connect as admin (with no password) over wlan just before trusted person has chance to set up anything.
by expert
Mon Jan 09, 2017 3:03 pm
Forum: General
Topic: RS-232 hub for admin console
Replies: 1
Views: 945

RS-232 hub for admin console

Hi, I need to connect multiple MikroTik devices into RS-232 hub to have persistent console access. Do you think will this device serve the purpose? The hub will be connected to the server running Debian GNU/Linux. https://www.aliexpress.com/item/USB-to-8-Ports-Serial-Converter-Adapter-Hub-FTDI-Chips...
by expert
Mon Jan 02, 2017 4:44 pm
Forum: General
Topic: RB2011 chip switch - Trunk and Hybrid ports
Replies: 7
Views: 4153

Re: RB2011 chip switch - Trunk and Hybrid ports

Perhaps you can explain a little more detailed. I did not manage to get this running on RB2011UiAS-RM. It is no problem to assign VLANs to ports, but I failed in untaggig one VLAN while leaving the other VLANs tagged for output packets and tagging untagged traffic while leaving all tagged traffic a...
by expert
Sun Dec 18, 2016 12:34 pm
Forum: General
Topic: Serial port over RJ-45
Replies: 1
Views: 974

Serial port over RJ-45

Hi,
what the reason to have serial port over RJ-45 on Cloud switches? AFAIK no standard defines that.
I'm going to buy combination Cloud Core Router (D-Sub serial connector) and Cloud Core Switch (RJ-45 serial connector) and will need two different console cables.
by expert
Fri Dec 16, 2016 4:59 pm
Forum: General
Topic: winbox for ubuntu
Replies: 37
Views: 51457

Re: winbox for ubuntu

In what language and framework is Winbox developed? C or C++ ? Gtk or Qt?
by expert
Fri Dec 16, 2016 2:14 pm
Forum: Beginner Basics
Topic: Enabling DHCP in Mitrotik on bridge mode
Replies: 6
Views: 3369

Re: Enabling DHCP in Mitrotik on bridge mode

First i would put your modem into bridge mode and then use the mikrotik to do the routing dhcp server etc. This way you avoid double natting. Personally i use a rb951g wifi init Setup some firewall rules, nat on your wan interface, create a bridge and add your wifi interface and all your ether port...
by expert
Thu Dec 15, 2016 4:40 pm
Forum: RouterBOARD hardware
Topic: Which switch to buy
Replies: 2
Views: 1104

Which switch to buy

Hi,
I'm planning new home setup where main router will be RB3011UiAS-RM (yeah, I have rack).
However, with switch I'm not decided, which would you buy if you have option?
  • CRS125-24G-1S-RM (cheaper, more memory & better cpu)
  • CRS226-24G-2S+RM (two SFPs for future upgrades)
by expert
Wed Dec 14, 2016 3:06 pm
Forum: Announcements
Topic: v6.38rc [release candidate] is released
Replies: 331
Views: 123050

Re: v6.38rc [release candidate] is released

Does it solve the following Metarouter issue? http://forum.mikrotik.com/viewtopic.php?f=15&t=115422
by expert
Sat Dec 10, 2016 3:06 pm
Forum: Virtualization
Topic: [ROS 6.37.3] MetaRouter: Unable to create virtual routers, OpenWRT slows down host network connectivity
Replies: 3
Views: 3063

Re: [ROS 6.37.3] MetaRouter: Unable to create virtual routers, OpenWRT slows down host network connectivity

did you find a ROS version that works?
I have upgraded my old RB450G from 5.26 (worked) to 6.37.3 (not working). I'm not going to downgrade 6.37->6.36->... until I find version that works.

It seems to be bug of Router OS, but who cares?
by expert
Tue Dec 06, 2016 1:22 pm
Forum: Virtualization
Topic: Metarouter not working on RB450G (6.37.3)
Replies: 5
Views: 3811

Metarouter not working on RB450G (6.37.3)

Hello, I'm trying to run metarouter on my RB450G, software version 6.37.3. Am I doing something wrongly? [expert@rb] /metarouter> add name="test" memory-size=32 [expert@rb] /metarouter> console test [Ctrl-A is the prefix key] Starting... Generating SSH 2048bit RSA host key... Generating SS...
by expert
Mon Dec 05, 2016 7:43 pm
Forum: Virtualization
Topic: Metarouter images
Replies: 378
Views: 387791

Re: Metarouter images

For running RouterOS in MetaRouter you don't need an image! That is the default image. Are you sure? It does not work for me. It's RB450G, ROS 6.37.2. [expert@rb] /metarouter> add name="test" memory-size=32 [expert@rb] /metarouter> console test [Ctrl-A is the prefix key] Starting... Gener...
by expert
Mon Dec 05, 2016 10:44 am
Forum: Virtualization
Topic: Metarouter images
Replies: 378
Views: 387791

Re: Metarouter images

Do exists some more images other than OpenWRT?
Found short note on Debian/DebWRT http://dev.debwrt.net/ticket/274 but there seems not be any progress.
It it possible to run RouterOS in metarouter?
by expert
Sun Dec 04, 2016 1:35 pm
Forum: Virtualization
Topic: Metarouter images
Replies: 378
Views: 387791

Re: Metarouter images

Latest images found there: http://openwrt.wk.cz/