Community discussions

MikroTik App

Search found 3048 matches: zerotier

Searched query: zerotier

  • 1
  • 2
  • 3
  • 4
  • 5
  • 11
by knx90
Wed Jun 11, 2025 7:16 pm
Forum: Beginner Basics
Topic: CHR Cloud Routing to peers
Replies: 11
Views: 990

Re: CHR Cloud Routing to peers

... new - maybe in the future i will need to know how to connect diffrent locations company into one network. So im looking best solutions, not only ZeroTier solutions or something like that.
by Larsa
Wed Jun 11, 2025 6:12 pm
Forum: Useful user articles
Topic: The ultimate Mikrotik iptables flowchart
Replies: 143
Views: 8656

Re: The ultimate Mikrotik iptables flowchart

- DNS
- DHCP
- NTP
- Winbox
- WebFig
- Rest API
- SSH
- IPSec
- L2TP/PPTP/SSTP
- Wireguard
- ZeroTier
- OpenVPN
- SNMP
- BGP/OSPF/RIP/MPLS
- FTP
- CAPsMAN
- RoMON
by knx90
Wed Jun 11, 2025 5:21 pm
Forum: Beginner Basics
Topic: CHR Cloud Routing to peers
Replies: 11
Views: 990

Re: CHR Cloud Routing to peers

... address-pool=dhcp_1 interface=LAN name=dhcp_1 /ip smb users set [ find default=yes ] disabled=yes /system logging action set 0 memory-lines=75 /zerotier set zt1 disabled=no disabled=no /zerotier interface add allow-default=no allow-global=no allow-managed=yes disabled=no instance=\ zt1 name= ...
by holvoetn
Wed Jun 11, 2025 10:04 am
Forum: General
Topic: hap ax3 zerotier invalid identity loaded from disk
Replies: 1
Views: 467

Re: hap ax3 zerotier invalid identity loaded from disk

I would first create a supout.rif file and file a support ticket so they can already look into it.

Next step would be to netinstall that device and see what happens then.
But I would not do that until you received feedback from support ...
by nullemotion
Wed Jun 11, 2025 9:50 am
Forum: General
Topic: hap ax3 zerotier invalid identity loaded from disk
Replies: 1
Views: 467

hap ax3 zerotier invalid identity loaded from disk

Hi. My setup: hAP ax^3, RouterOS 7.19.1, zerotier package 7.19.1. Install zerotier package, reboot, go to Zerotier/Instance, enable zt1 instance and get status "failed". Enable logs for Zerotier and get this one every time when i try ...
by sebastia
Sat Jun 07, 2025 5:14 pm
Forum: General
Topic: Outgoing unsolicited traffic to 5351/udp
Replies: 1
Views: 697

Re: Outgoing unsolicited traffic to 5351/udp

FYI: looks like related to zerotier node
by mndtrp
Sat Jun 07, 2025 11:04 am
Forum: Wireless Networking
Topic: "not responding" - f.k.a. SA Query timeout
Replies: 403
Views: 108629

Re: "not responding" - f.k.a. SA Query timeout

... DO NOT INSTALL THIS if you use it for something important. Can you also share the other packages related to the nightly builds? I use ZeroTier and would like to be able to completely test the nightly builds. FYI: Already running the 7.21_ab85 build including ZeroTier which was shared ...
by lurker888
Fri Jun 06, 2025 9:28 pm
Forum: Beginner Basics
Topic: Ready to start my custom firewall rules journey [SOLVED]
Replies: 43
Views: 3582

Re: Ready to start my custom firewall rules journey [SOLVED]

... package is ingested and injected through the (virtual) interface of the tunnel. L2 encapsulations, such as EoIP, L2TP, OpenVPN (ethernet mode), ZeroTier are handled similarly, but additionally bridging is involved. IPSec (policy based) is special and nasty. That's why it's usually not incorporated ...
by sirbryan
Thu Jun 05, 2025 5:47 pm
Forum: General
Topic: Back to Home VPN Relay Server
Replies: 7
Views: 1054

Re: Back to Home VPN Relay Server

We currently don't plan to support 3rd party relays, but it's an interesting idea worth considering. Yes, like self-hosted ZeroTier. A variation on this theme is to use BTH as a tool to enable ISPs/MSPs to remotely manage both routers (which I can usually get to) and internal devices, ...
by unlikely
Thu May 29, 2025 10:21 pm
Forum: General
Topic: Effective Backup Strategy for a MikroTik Router in Disaster Recovery Scenarios
Replies: 12
Views: 1976

Re: Effective Backup Strategy for a MikroTik Router in Disaster Recovery Scenarios

... included references to paths like /usb/ros-data/logs/diskFirewall, but the new CCR2004 no longer accepts /usb/... and instead requires usb/.... - ZeroTier instance names are not restored automatically and must be manually changed before import. - Handling users and groups is extremely challenging. ...
by unlikely
Sun May 25, 2025 7:23 pm
Forum: General
Topic: Effective Backup Strategy for a MikroTik Router in Disaster Recovery Scenarios
Replies: 12
Views: 1976

Effective Backup Strategy for a MikroTik Router in Disaster Recovery Scenarios

... start, and Ethernet interfaces have different names, just to mention a few of the issues I observed. Strangely, internet access to the router via ZeroTier still functions. - Restoring from an exported configuration also fails to fully recover the system. Users and groups are missing, containers ...
by keskol
Fri May 23, 2025 12:37 pm
Forum: General
Topic: Cannot disable beep on boot [SOLVED]
Replies: 3
Views: 1457

Cannot disable beep on boot [SOLVED]

... fetch: yes pptp: yes l2tp: yes bandwidth-test: yes traffic-gen: no sniffer: yes ipsec: yes romon: yes proxy: yes hotspot: yes smb: yes email: yes zerotier: yes container: no install-any-version: no partitions: no routerboard: no attempt-count: 0
by anav
Sun May 18, 2025 10:09 pm
Forum: Beginner Basics
Topic: Problems with Port Forwarding
Replies: 4
Views: 1418

Re: Problems with Port Forwarding

... IP or an upstream ISP router where you can forward ports, suggest using wireguard for your friends to get to your router to game securely or even zerotier networking. By the way it seems as you have VPN subnet, but your text said no need, so confusing to see it there. Set this to none, known to ...
by ironm
Fri May 16, 2025 12:11 pm
Forum: General
Topic: How to upgrade routerOS from command line (ssh) and local routeros-7.18.2-arm64.npk file?
Replies: 11
Views: 3331

Summary routerOS upgrade - How to upgrade routerOS from command line (ssh) and local routeros-7.18.2-arm64.npk file

... tr069-client-7.18.2-arm64.npk ups-7.18.2-arm64.npk user-manager-7.18.2-arm64.npk wifi-qcom-7.18.2-arm64.npk wireless-7.18.2-arm64.npk zerotier-7.18.2-arm64.npk
by anav
Mon May 12, 2025 10:50 pm
Forum: General
Topic: Firewall and NAT
Replies: 58
Views: 4577

Re: Firewall and NAT

... your friends are and then have them wireguard into your router and then give them access through firewall rules to the servers they need. OR Use zerotier to connect friends to your servers. No one these days hosts gaming servers or the like as its to hard protect properly and often your ISP shuts ...
by anav
Fri May 02, 2025 1:41 pm
Forum: General
Topic: NAT Hairpin Configuration Troubles
Replies: 22
Views: 5110

Re: NAT Hairpin Configuration Troubles

... list=authorized comment=userBob add address=myhobby.com list=authorized comment=userDavid Overall, much safer to get users to wireguard in, or zerotier in to reach your server............
by unlikely
Tue Apr 29, 2025 10:07 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

The only other approach is abuse BackToHome (BTH) - that does deal with CGNAT and is just WireGuard under the covers. i.e. if a site had a fixed public IP, and LTE back... BTH be same as WG when "primary WAN", but if failover BTH "proxy" WG via LTE CGNAT. The issue is @normis re...
by unlikely
Tue Apr 29, 2025 12:25 am
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

Well, since you're not listening to my advice or bothering to answer my questions, you're on your own. Good luck! I’m open to all advice and suggestions and truly appreciate everyone’s contributions. However, I still want to address or at least better understand my initial issue. You’ve stated that...
by Larsa
Tue Apr 29, 2025 12:09 am
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

Well, since you keep repeating yourself over and over again, don't listen to @Amm0's or my advice, and don't even bother to answer my questions, you're on your own. Good luck!
by unlikely
Tue Apr 29, 2025 12:05 am
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

Support gave you an adequate answer. You can run whatever L2 traffic you want over Zerotier, but you need to know how to manage it with flow rules. And yes, it works as expected. I don't think I can agree. To me it doens't seems a correct L2 behavior. It is not as ...
by Larsa
Mon Apr 28, 2025 11:53 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

Support gave you a proper answer. You can run any L2 traffic you want over Zerotier, but you need to know how to manage it using ZT flow rules together with correct ROS routing and firewall rules. And yes, it works as expected. Have you checked your firewall ...
by unlikely
Mon Apr 28, 2025 11:44 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

... correctly in my setup when bridging is enabled on two MikroTik nodes (CCR2004 running ROS 7.18.2 and RB5009 running ROS 7.18.2 or 7.19beta8) on ZeroTier Central. When bridging is disabled, OSPF adjacency is maintained for a short period. However, if I disable and re-enable the OSPF instance ...
by Larsa
Mon Apr 28, 2025 11:40 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

Just a tip, @unlikely: make a full network topology diagram, do a complete export, start packet sniffing, turn on OSPF logging, and if you still think there’s a bug somewhere, send everything over to support. But I still don't get why you're insisting on using L2 instead of just doing it the normal ...
by Larsa
Mon Apr 28, 2025 11:35 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

@xrlls, you should probably open your own thread since it gets complicated when mixing two different use cases in the same thread.
by unlikely
Mon Apr 28, 2025 11:34 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

I think OP isn't actually bridging zerotier on RouterOS bridge – although be to confirm... OP is just checking the "Allow Bridging" option on the ZT controller, AFAIK...
Correct.
ZeroTier interface is not part of any bridge.
So the answer from Mikrotik is more puzzling.
by Larsa
Mon Apr 28, 2025 11:32 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

@Amm0; Yeah, exactly. It might be something as simple as a firewall blocking the LSA packets. If they sniff the packets and turn on OSPF LSA logging, they should be able to figure out pretty quickly what's actually going on.
by unlikely
Mon Apr 28, 2025 11:28 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

... since OSPF broadcast should "just work" (without bridging IMO). Perhaps check /tool/sniffer to see if OSPF multicast is even hitting the zerotier interface (and ideally on far-end, to see if got there) – that confirm if ZT config issue, OR, bug in ZT+OSPF on RouterOS. Also, you don't ...
by Amm0
Mon Apr 28, 2025 11:26 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

Maybe @Amm0 can help you out here.
@Amm0 already explained to look at sniffers, or lab a smaller example. But ZeroTier "L2" should be transparent to "L3" [multicast] OSPF.
by Larsa
Mon Apr 28, 2025 11:24 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

@xrlls, like I told @unlikely, there’s no way to give you a real answer because you haven’t shared a full network topology or explained what you’re actually trying to do. From what I can tell, it sounds like you’re a bit unclear on basic L2/L3 networking. Maybe @Amm0 can help you out here.
by Amm0
Mon Apr 28, 2025 11:19 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

... L2 network, that is not what I am doing, and I agree that in such a configuration OSPF does not make sense. I think OP isn't actually bridging zerotier on RouterOS bridge – although be to confirm... OP is just checking the "Allow Bridging" option on the ZT controller, AFAIK...
by Larsa
Mon Apr 28, 2025 11:15 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

@unlikely: There is no way to give you a real answer because you have not shared a complete network topology or explained your actual goals.

Without that, any suggestion would be pointless guessing.
by xrlls
Mon Apr 28, 2025 11:15 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

My point is that I think OSPF is less work. While I understand that routes can be pushed through Zerotier, relying on it, would require me to maintain both the Zerotier routing configuration and another route distribution method for the non-Zerotier connections. So I would ...
by Amm0
Mon Apr 28, 2025 11:13 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

... collect some sniffer or re-create small example of it not working in lab/CHRs/etc. If repo-able in small setup, that seem like a bug to MikroTik. ZeroTier should be transparent to OSPF – now OSPF then be connected everywhere, so that have be considered in your OSPF design. This simple example ...
by unlikely
Mon Apr 28, 2025 11:06 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

@unlikely, I get what you are saying about using ZeroTier as backup and your WireGuard links not needing static neighbor setup. BUT still, the same idea I mentioned to @xrlls applies here. If you already have ZeroTier in the mix, running OSPF on ...
by Amm0
Mon Apr 28, 2025 11:01 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

There are also few non-OSPF routers connected by Wireguard to the hub and few direct wireguard links between most important sites. ZeroTier is kind of a backup for wireguard. ZeroTier is slower with our slow connections. And I don't want to rely on routes manually defined in ZeroTier network. ...
by Larsa
Mon Apr 28, 2025 10:46 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

@unlikely, I get what you are saying about using ZeroTier as backup and your WireGuard links not needing static neighbor setup. BUT still, the same idea I mentioned to @xrlls applies here. If you already have ZeroTier in the mix, running OSPF on ...
by unlikely
Mon Apr 28, 2025 10:43 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

... the shared L2 domain, but that still leaves me wondering why you would want to do it this way. If all routers are already L2-connected through ZeroTier, it feels a bit like connecting a big switch to all your subnets instead of properly routing between them. I mean, wouldn't it be simpler and ...
by Larsa
Mon Apr 28, 2025 10:33 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

@xrlls, I think I get your reasoning, but I also think you are unnecessarily complicating things. If you're already using ZeroTier, then running OSPF on top of it is simply redundant. ZeroTier can fully handle dynamic route distribution and failover without needing a separate routing ...
by unlikely
Mon Apr 28, 2025 10:30 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

Easy configuration of OSPF. For Wireguard is is necessary to configure static neighbors. While for Zerotier (and L2 in general) it just works, as the neighbors are automatically discovered through multicast. For me ZeroTier is kind of a backup. I have some ptp wireguard ...
by Amm0
Mon Apr 28, 2025 8:38 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

I might ask the other way, what would your recommendation instead? You can use ZT to push any route. ZT does not care if the destination is within ZT's IP range — ZT is agnostic on gateway so you can often use ZT for just route distribution. And RouterOS will happy add whatever it gets from ZT dire...
by xrlls
Mon Apr 28, 2025 8:18 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

@unlikely I tried enabling bridging for the Zerotier endpoint (Rb5009, 7.18.2) not working and … heureka… it started working! I then disabled bridging again, and the multicast traffic stopped arriving on the RB5009. Enabling bridging on the non-working ...
by Larsa
Mon Apr 28, 2025 6:34 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

I mean some of the routers partecipating in OSPF are connected all to the same ZeroTier network / L2 domain, so brodcast mode should be possible. But every routers also belongs to other networks. Thanks for the clarification. I get that OSPF can work over the shared ...
by unlikely
Mon Apr 28, 2025 2:43 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

... problem, I previously stated that it works for me… and it does… on some of my routers. I currently have 3 MikroTik routers connected to the same ZeroTier network, and OSPF is working on two of them over Zerotier. On the third, a RB5009, running 7.18.2, I only see outgoing multicast traffic, no ...
by Michiganbroadband
Mon Apr 28, 2025 6:11 am
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 95
Views: 14291

Re: Netinstall on RM3011 Fails need help (technical questions)

... fetch: yes pptp: yes l2tp: yes bandwidth-test: yes traffic-gen: no sniffer: yes ipsec: yes romon: yes proxy: yes hotspot: yes smb: yes email: yes zerotier: yes container: no install-any-version: no partitions: no routerboard: no attempt-count: 0 after I set them today: (again) > /system device-mode ...
by anav
Sun Apr 27, 2025 11:46 pm
Forum: Useful user articles
Topic: Logging and Blocking IPs Based on Failed Authentication Attempts
Replies: 2
Views: 16979

Re: Logging and Blocking IPs Based on Failed Authentication Attempts

... if at all possible, if you must....... do you really have to???? a. use VPN for users to access subnet locations ( such as wireguard ) b. use zerotier for users to access subnet locations c. If you have to port forward, (i) ensure that the server is capable of a high level of encryption ( ...
by Michiganbroadband
Sun Apr 27, 2025 9:34 pm
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 95
Views: 14291

Re: Netinstall on RM3011 Fails need help (technical questions)

... fetch: yes pptp: yes l2tp: yes bandwidth-test: yes traffic-gen: no sniffer: yes ipsec: yes romon: yes proxy: yes hotspot: yes smb: yes email: yes zerotier: yes container: no install-any-version: no partitions:no routerboard:no This looks very restrictive. I changed all of the values as instructed ...
by xrlls
Sun Apr 27, 2025 11:35 am
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

... problem, I previously stated that it works for me… and it does… on some of my routers. I currently have 3 MikroTik routers connected to the same ZeroTier network, and OSPF is working on two of them over Zerotier. On the third, a RB5009, running 7.18.2, I only see outgoing multicast traffic, no ...
by rextended
Sat Apr 26, 2025 2:25 pm
Forum: General
Topic: Device-mode not in backup
Replies: 3
Views: 1266

Re: Device-mode not in backup

... install-any-version = no # flagging-enabled = yes # flagged = no # allowed = scheduler,fetch,bandwidth-test,sniffer,ipsec,romon,hotspot,smb,email,zerotier # forbidden = socks,pptp,l2tp,traffic-gen,proxy,container,partitions,routerboard
by AndreyUkraine
Fri Apr 25, 2025 5:21 pm
Forum: Forwarding Protocols
Topic: How is it possible to make a static DF router and the client is always in the UIB SG?
Replies: 0
Views: 1271

How is it possible to make a static DF router and the client is always in the UIB SG?

Good day everyone, Sorry for my English, I'm from Ukraine, and I have a problem. I have 5 routers connected via ZeroTier network, and PIM-SM is configured everywhere, but I need specific settings. I need my clients to be in the UIB SG on the RP router, even when they are turned ...
by unlikely
Fri Apr 25, 2025 9:08 am
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

The OP said " OSPF over a ZeroTier L2 domain (so mode broadcast), " which sounds a bit contradictory. I mean some of the routers partecipating in OSPF are connected all to the same ZeroTier network / L2 domain, so brodcast mode ...
by unlikely
Fri Apr 25, 2025 9:02 am
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

... had OSPF infra, perhaps with non-ZT things, and there OSPF over ZT would seem reasonable. But if you're using OSPF for route distribution ONLY for ZeroTier, that would seem silly. My idea was to use ZT as a secondary way for distributing routes and route packets among routers when better ways fails ...
by poisons
Fri Apr 25, 2025 1:01 am
Forum: General
Topic: Adding customized planet functionality to zerotier plugin
Replies: 1
Views: 1771

Re: Adding customized planet functionality to zerotier plugin

I want to see the same option in built in zerotier client, but as far as i see mikrotik team not provide any updates for build in zt client, so there is no pain to install zerotier client as container, where you may modify all necessary settings, like custom planets and so on.
by Larsa
Thu Apr 24, 2025 7:02 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

The OP said " OSPF over a ZeroTier L2 domain (so mode broadcast), " which sounds a bit contradictory. OSPF is basically a L3 routing helper, so I don't get how Layer 2 fits into the picture after reading the thread. I can understand ...
by Amm0
Thu Apr 24, 2025 6:40 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

Larsa makes good points. Personally I'd use ZT routes if possible, since it just so simple.

I've assumed OP already had OSPF infra, perhaps with non-ZT things, and there OSPF over ZT would seem reasonable. But if you're using OSPF for route distribution ONLY for ZeroTier, that would seem silly.
by Larsa
Thu Apr 24, 2025 6:21 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

There is absolutely no distinction in the type of devices used by ZeroTier. It can be ten smartphones or ten routers connecting the same number of subnets. What matters is the number of activated devices listed in the management console. Also, there's no ...
by StubArea51
Thu Apr 24, 2025 11:12 am
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

ZeroTier doesn’t have visible “routes”, just virtual networks and devices/routers associated to a virtual network. Since last year, new free accounts get 10 devices/routers total, while older accounts had 25 (still valid). ...
by rextended
Wed Apr 23, 2025 2:11 pm
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 95
Views: 14291

Re: Netinstall on RM3011 Fails need help (technical questions)

... email=yes fetch=yes \ hotspot=yes ipsec=yes l2tp=yes pptp=yes proxy=yes romon=yes scheduler=yes smb=yes sniffer=yes socks=yes traffic-gen=yes \ zerotier=yes install-any-version=yes partitions=yes routerboard=yes After reboot Install by downgrading on system/packages with 7.6: https://download.mikrotik.com/routeros/7.6/routeros-7.6-arm.npk ...
by Larsa
Wed Apr 23, 2025 11:58 am
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

ZeroTier doesn’t have visible “routes”, just virtual networks and devices/routers associated to a virtual network. Since last year, new free accounts get 10 devices/routers total, while older accounts had 25 (still valid). ...
by StubArea51
Wed Apr 23, 2025 10:33 am
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

... but why even bother using OSPF on a Layer 2 network? Even using OSPF with IP seems kind of weird since all internal routing is already built into ZeroTier, right? Maybe I’m missing something here... There are a few use cases for it. 1) ZeroTier's controller under the free version can only hold ...
by Larsa
Tue Apr 22, 2025 11:41 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

Just curious, but why even bother using OSPF on a Layer 2 network? Even using OSPF with IP seems kind of weird since all internal routing is already built into ZeroTier, right? Maybe I’m missing something here...
by unlikely
Tue Apr 22, 2025 9:25 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

What I have is this: Thanks. I can't see anything special or substantially different from my setup. When I turn off bridging in ZeroTier Central for my Mikrotik Node, I can't see anymore OSPF traffic logged by my very first Raw Prerouting firewall rule. OSPF log in Mikrotik only show ...
by xrlls
Tue Apr 22, 2025 6:40 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

What I have is this: /zerotier/interface> /zerotier/interface/print detail Flags: D - dynamic, X - disabled; R - running 0 R name="zerotier1" mac-address=3E:65:02:6A:A1:37 mtu=2800 arp-timeout=auto network="xxxxxxxxxxxxxx" ...
by unlikely
Tue Apr 22, 2025 6:05 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

... working... it might worth a ticket to Mikrotik at help.mikrotik.com. Include a supout.rif if you do file a ticket. I can confirm that OSPF over ZeroTier is generally working when bridging is enabled for Mikrotik routers nodes. But as soon I remove the bridging it stops working, and restart as ...
by unlikely
Tue Apr 22, 2025 6:02 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

... it should just work. The only issue I had was relating to firewall, where I needed to allow OSPF (or any other traffic for that matter) on the Zerotier interface. With broadcast/multicast? Without static neighbors? I think my firewall it's ok because with bridging enabled, OSPF is working. ...
by Amm0
Mon Apr 21, 2025 11:16 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

Seems a Mikrotik thing. Perhaps. Someone else had similar issues with OSPF broadcast mode and ZeroTier: https://forum.mikrotik.com/viewtopic.php?p=1118612#p1118520 There too, I thought it was flow rules, but OP was using Mikrotik controller which has NO flow rules. And ...
by xrlls
Mon Apr 21, 2025 10:45 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

... it should just work. The only issue I had was relating to firewall, where I needed to allow OSPF (or any other traffic for that matter) on the Zerotier interface.
by unlikely
Mon Apr 21, 2025 10:22 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

Thanks for reply.
Default flow rules allow for ip4, ip6 and arp, so ospf should be included.
By the way I also tried to put just accept and still doens't work on Mikrotik.
But it works on OPNsense with default or permissives flow rules and without bridging enabled.
Seems a Mikrotik thing.
by Amm0
Sun Apr 20, 2025 5:10 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Re: Multicast/OSPF over ZeroTier

You may need to change the "Flow Rules" for the ZT network on my.zerotier.com (see ZeroTier docs: https://docs.zerotier.com/rules/#rule-definition-language generally or examples here https://www.zerotier.com/blog/using-flow-rules-to-direct-users-to-services/ ...
by unlikely
Sun Apr 20, 2025 3:06 pm
Forum: General
Topic: Multicast/OSPF over ZeroTier
Replies: 45
Views: 5067

Multicast/OSPF over ZeroTier

I'm trying to setup OSPF over a ZeroTier L2 domain (so mode broadcast) among two Mikrotik routers and an OPNsense box. Apparently "Allow Ethernet bridging" should be enabled on ZeroTier central for the Mikrotik routers otherwise ...
by wynieDB
Thu Apr 17, 2025 10:05 am
Forum: General
Topic: Community made RouterOS packages
Replies: 2
Views: 1088

Community made RouterOS packages

... title suggests, are there any plans of allowing packages for RouterOS to be created by community members? My reason: I am aware of a WireGuard and ZeroTier package which I assume was developed by MikroTik themsevles. On a project at work I decided to make use of Netbird which is a fantastic self-hosted ...
by Larsa
Wed Apr 16, 2025 11:10 pm
Forum: General
Topic: Layer 2 tunnel with Windows client
Replies: 2
Views: 896

Re: Layer 2 tunnel with Windows client

... is a nightmare without proper enterprise-grade network management tools. If your Mikrotik routers are ARM based, I strongly recommend checking out ZeroTier that is part of ROS v7. It supports Layer 2 bridging and can scale to manage hundreds or even thousands of networks and devices with ease. ...
by bradkuhl
Sun Apr 13, 2025 11:12 pm
Forum: General
Topic: Add vlan tag to ZT traffic going to certain subnet
Replies: 3
Views: 976

Re: Add vlan tag to ZT traffic going to certain subnet

The simplest approach is probably to go with regular routing: 1. In the Zerotier's management console -> Network Management -> Managed Routes , add 'destination' 10.252.0.0/24 'via' 10.10.10.3 2. On Router 3, add: ' /ip route add dst-address=10.252.0.0/24 gateway=vlan50 ...
by Larsa
Sun Apr 13, 2025 8:37 pm
Forum: General
Topic: Add vlan tag to ZT traffic going to certain subnet
Replies: 3
Views: 976

Re: Add vlan tag to ZT traffic going to certain subnet

The simplest approach is probably to go with regular routing: 1. In the Zerotier's management console -> Network Management -> Managed Routes , add 'destination' 10.252.0.0/24 'via' 10.10.10.3 2. On Router 3, add: ' /ip route add dst-address=10.252.0.0/24 gateway=vlan50 ...
by bradkuhl
Sun Apr 13, 2025 6:46 pm
Forum: General
Topic: Add vlan tag to ZT traffic going to certain subnet
Replies: 3
Views: 976

Add vlan tag to ZT traffic going to certain subnet

I have 3 locations linked with zerotier. All three have different subnets. This is working. I can access all three subnets from any location and from any ZT connected device (laptop) from a remote location. All the routers are mikrotik. ...
by liveup
Sat Apr 12, 2025 2:22 pm
Forum: General
Topic: bitcomet caused zerotier to disconnect
Replies: 0
Views: 930

bitcomet caused zerotier to disconnect

Routeros started zerotier, but when I started bitcomet, it caused zerotier to disconnect
by anav
Thu Apr 10, 2025 6:41 pm
Forum: Beginner Basics
Topic: interligando RBs
Replies: 2
Views: 859

Re: interligando RBs

For a secure connection suggest wireguard, assuming you have at least on public IP available at one of the routers, or the ISP router in front is capable of forwarding ports.
Alternatively use Zerotier.
by newhotelowner
Thu Apr 10, 2025 3:39 pm
Forum: General
Topic: Route VLAN traffic to office internet using zerotier
Replies: 2
Views: 834

Re: Route VLAN traffic to office internet using zerotier

... But I haven't figure out how to make Cuddy exit node, so that all internet traffic on VLAN goes through office wan (cuddy). - Or, alternatively, ZeroTier controller (generally, my.zerotier.com) lets you set routes too. So instead of above you can use ZeroTier to define a
by Amm0
Thu Apr 10, 2025 3:34 am
Forum: General
Topic: Route VLAN traffic to office internet using zerotier
Replies: 2
Views: 834

Re: Route VLAN traffic to office internet using zerotier

... Mikrotik, you can avoid the NAT translation since both sides will know how to route between 192.168.88.0 and 192.168.10.0/24 - Or, alternatively, ZeroTier controller (generally, my.zerotier.com) lets you set routes too. So instead of above you can use ZeroTier to define a routes as show above. ...
by newhotelowner
Thu Apr 10, 2025 3:04 am
Forum: General
Topic: Route VLAN traffic to office internet using zerotier
Replies: 2
Views: 834

Route VLAN traffic to office internet using zerotier

This is my current setup. Screenshot 2025-04-09 165808.jpg My work and home routers are connected over zerotier. I am able to directly access work devices though zerotier at my home. Example, My SIP phone at home is connected to my SIP gateway at work. I set up zero tier on ...
by lurker888
Wed Apr 09, 2025 2:49 am
Forum: MikroTik hardware questions
Topic: advise before the purchase of a hEX refresh [SOLVED]
Replies: 7
Views: 3864

Re: advise before the purchase of a hEX refresh [SOLVED]

... the SFP port of the micorSD slot, this is really not good value for money. Since you're interested in VPNs, only ARM (and ARM64) devices support ZeroTier in Mikrotik-land, so this does not. All the others I list below support it. It's also by far the weakest in terms of performance. I think your ...
by rextended
Sat Apr 05, 2025 4:35 pm
Forum: General
Topic: /tool/flood-ping - failure: not allowed by device-mode
Replies: 4
Views: 1751

Re: /tool/flood-ping - failure: not allowed by device-mode

... email=yes fetch=yes \ hotspot=yes ipsec=yes l2tp=yes pptp=yes proxy=yes romon=yes scheduler=yes smb=yes sniffer=yes socks=yes traffic-gen=yes \ zerotier=yes install-any-version=no partitions=yes routerboard=yes for previous versions some items like install-any-version=no partitions=yes routerboard=yes ...
by dricce
Thu Apr 03, 2025 7:43 pm
Forum: General
Topic: /tool/flood-ping - failure: not allowed by device-mode
Replies: 4
Views: 1751

/tool/flood-ping - failure: not allowed by device-mode

... fetch: yes pptp: yes l2tp: yes bandwidth-test: yes traffic-gen: no sniffer: yes ipsec: yes romon: yes proxy: yes hotspot: yes smb: yes email: yes zerotier: yes container: no install-any-version: no partitions: no routerboard: no attempt-count: 0 Error: /tool/flood-ping address=192.168.1.1 count=200 ...
by Larsa
Mon Mar 31, 2025 4:42 pm
Forum: Beginner Basics
Topic: Constant high outbound traffic from ether1
Replies: 14
Views: 2499

Re: Constant high outbound traffic from ether1

... a compromised PC on your LAN that’s part of a botnet. P.S. Never, ever open any ports from the router to the internet. Use a VPN like WireGuard or ZeroTier instead.
by t4thfavor
Mon Mar 31, 2025 5:44 am
Forum: General
Topic: Winbox getting stuck at downloading desciptors (Zerotier connection)
Replies: 1
Views: 5576

Re: Winbox getting stuck at downloading desciptors (Zerotier connection)

Same problem, it used to work, but I recently upgraded to 7.17 or 7.18 and now none of my zerotier stuff works. No changes.
by anav
Sat Mar 29, 2025 11:22 pm
Forum: Beginner Basics
Topic: Choice of VPN
Replies: 1
Views: 1314

Re: Choice of VPN

Look at zerotier to share gaming server............
by anav
Sat Mar 29, 2025 10:01 pm
Forum: Beginner Basics
Topic: VPN with relay on a VPS - working around the CGNAT
Replies: 15
Views: 3050

Re: VPN with relay on a VPS - working around the CGNAT

... Option2 You could do it right away with regular wireguard VPN if your router is an MT router. Preferred Option 1 Another alternative is to use zerotier which connects routers at layer2, but uses cloudflare secure servers. This is available right away as well. Preferred option 3
by jimmyz
Fri Mar 28, 2025 8:29 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 641
Views: 300503

Re: Problems: Re: v7.18.1 [stable] is released!

... 1 wifi-qcom 7.18.2 2025-03-11 11:59:04 10.2MiB 2 rose-storage 7.18.2 2025-03-11 11:59:04 3136.1KiB 3 routeros 7.18.2 2025-03-11 11:59:04 12.3MiB 4 zerotier 7.18.2 2025-03-11 11:59:04 836.1KiB 5 container 7.18.2 2025-03-11 11:59:04 100.1KiB 2,4GHz interface is disabled, only 5GHz is active. The ...
by Josephny
Sat Mar 22, 2025 11:21 am
Forum: General
Topic: How I Spent My Upgrade Time
Replies: 8
Views: 1994

How I Spent My Upgrade Time

... 2 rose-storage 7.17.2 2025-02-06 09:10:24 3128.1KiB 3 lora 7.17.2 2025-02-06 09:10:24 8.1KiB 4 extra-nic 7.17.2 2025-02-06 09:10:24 2208.1KiB 5 zerotier 7.17.2 2025-02-06 09:10:24 836.1KiB 6 user-manager 7.17.2 2025-02-06 09:10:24 332.1KiB 7 ups 7.17.2 2025-02-06 09:10:24 32.1KiB 8 tr069-client ...
by loloski
Fri Mar 21, 2025 4:07 am
Forum: Forwarding Protocols
Topic: SSH and Tunneling
Replies: 2
Views: 1793

Re: SSH and Tunneling

form a private network using zerotier together with the other participant and spawn your private server inside zerotier network and you are done
by gpetrom
Mon Mar 17, 2025 5:03 pm
Forum: Scripting
Topic: Api version response empty [SOLVED]
Replies: 7
Views: 11140

Re: Api version response empty [SOLVED]

... '', 'scheduled': '', 'size': '376977', 'available': 'True', 'disabled': 'True'}] Router RBwAPGR-5HacD2HnD [True, {'.id': '*10', 'name': 'zerotier', 'version': '', 'scheduled': '', 'size': '790673', 'available': 'True', 'disabled': 'True'}] After upgrading to 7.19beta5 same thing happens ...
by Jeroen3
Mon Mar 17, 2025 3:58 pm
Forum: General
Topic: ZeroTier loses connections after a while
Replies: 0
Views: 1881

ZeroTier loses connections after a while

Hello all, My RB5009UG+S+ on 7.18.2 with ZeroTier configured. There is an internet connection over ether1 vlan 6 via pppoe. It appears as though zerotier loses it's connection. There is ability for ping, but no real traffic is able to flow. Resetting ...
by dcavni
Mon Mar 17, 2025 2:54 pm
Forum: Wireless Networking
Topic: Capsman loosing connection when connected through switch
Replies: 34
Views: 11211

Re: Capsman loosing connection when connected through switch

... accept established,related,untracked" connection-state=established,related,untracked add action=accept chain=forward comment="Zerotier Forward" in-interface=zerotier1 add action=accept chain=input comment="Zerotier Input" in-interface=zerotier1 add action=accept ...
by luckylinux
Sat Mar 15, 2025 10:07 am
Forum: MikroTik hardware questions
Topic: Mikrotik CRS317-1G-16S+RM - These 16MB only Flash Devices are driving me Crazy
Replies: 2
Views: 2421

Mikrotik CRS317-1G-16S+RM - These 16MB only Flash Devices are driving me Crazy

I already faced the Issue in the Past where I had to remove Packages (e.g. Zerotier) from the CRS317-1G-16S+RM Device just to be able to install Updates. But what a PITA. At least expand flash *a bit* for some Packages that don't require SLC due to frequent writes ...
by anav
Fri Mar 14, 2025 9:00 pm
Forum: General
Topic: Port forwarding on a RB4011 with a GPON ONT
Replies: 3
Views: 1842

Re: Port forwarding on a RB4011 with a GPON ONT

... to forward ports, or ask the ISP provider and they forward ports upon your request. If not , then you cannot port forward. Alternatives, - use Zerotier and connect users to your servers that way ( at least for external users ). - use BTH wireguard and have users access your servers over wireguard, ...
by techmulti
Thu Mar 13, 2025 2:16 pm
Forum: General
Topic: VPN Routing question
Replies: 3
Views: 1336

VPN Routing question

Good afternoon, Having this issue if someone can enlighten me if this is possible to do. I have added a zerotier network between two mikrotik devices one situated at my home and one at my office. HQ Network subnet is 192.168.0.0/24 HQ Network has other subnets connecting to ...
by Anthemous
Tue Mar 11, 2025 11:25 am
Forum: Beginner Basics
Topic: Wireguard for Win PC dont work
Replies: 6
Views: 2591

Re: Wireguard for Win PC dont work

... and they all work perfectly, specifically this router is behind a LTE which gives Internet to the rest of the network, it is also connected to zerotier net without any problem so far and actually some test I did with OPVN also worked normally , without problem and this, only Wireguard (from ...
by Anthemous
Mon Mar 10, 2025 9:39 pm
Forum: Beginner Basics
Topic: Wireguard for Win PC dont work
Replies: 6
Views: 2591

Re: Wireguard for Win PC dont work

... mtu=1420 name=back-to-home-vpn /interface list add comment=defconf name=WAN add comment=defconf name=LAN /port set 0 name=serial0 /zerotier set zt1 disabled=no disabled=no /zerotier interface add allow-default=no allow-global=no allow-managed=yes disabled=no instance=\ zt1 name=zerotier1 ...
by holvoetn
Sun Mar 09, 2025 1:01 pm
Forum: General
Topic: Can't see some RoMon neighbours
Replies: 6
Views: 3240

Re: Can't see some RoMon neighbours

... frames (EtherType 0x88bf). But in cases where this is not working, you can circumvent it with workarounds. E.g. from home I can connect using Zerotier to a customer RB5009 105km away from me, that one has MPLS connections to 30 other locations all over the Northern part of Belgium. That MPLS ...
by Amm0
Sat Mar 08, 2025 4:30 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 227333

Re: v7.19beta [testing] is released!

... upcoming 5G products, a new LMP 5G that show "16MB Flash". So while perhaps RouterOS without wifi fit okay, if you add something like zerotier, which is handy with LTE, you'd also be close to 16MB today. IMO 16MB flash is a risk since it's so close, that even stuff #bad blocks comes ...
by holvoetn
Fri Mar 07, 2025 4:36 pm
Forum: Beginner Basics
Topic: Wireguard on Router LTE not working
Replies: 16
Views: 4638

Re: Wireguard on Router LTE not working

... even have to be static (but it makes it easier if it is). Obviously, if there is no public reachable IP address, then you need something to get Zerotier or Back To Home or ... whatever, running. SXT will simply be a gateway to that device then.
by anav
Fri Mar 07, 2025 2:13 pm
Forum: Beginner Basics
Topic: Wireguard on Router LTE not working
Replies: 16
Views: 4638

Re: Wireguard on Router LTE not working

... another good option that would allow you to use BTH. So either way the hex refresh is a good option. Once you have the hex, another options is zerotier which is more complex but gets around not having a public IP. So do not despair, will get you to a useful setup!
by rralex89
Fri Mar 07, 2025 10:05 am
Forum: General
Topic: HEX refresh's switch chip, MT7621 dropping BPDU frames
Replies: 9
Views: 3844

Re: HEX refresh's switch chip, MT7621 dropping BPDU frames

... put them behind a VPN as my family is using my webserver quite heavily so cloudflare tunnel might be the best solution. I will investigate what zerotier is as i have absolutely no ideea. I used to have a server to RSYNC over ssh. That rule i need to delete indeed as i'm not using it I will also ...
by tryrtryrtryrt
Fri Mar 07, 2025 6:02 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 641
Views: 300503

Re: v7.18.1 [stable] is released!

... prefer default config and especially updates not to create bogus interfaces. P.S. Somewhere before 7.16.1 similar thing happened with addition of /zerotier set zt1 comment="ZeroTier Central controller - https://my.zerotier.com/" disabled=yes disabled=yes name=zt1 port=9993 After updating ...
by anav
Thu Mar 06, 2025 12:16 am
Forum: Beginner Basics
Topic: HTTPS ceritificates
Replies: 3
Views: 2121

Re: HTTPS ceritificates

... you dont have access to a public IP) and you and others can access the resources on your LAN behind a VPN, safely!! Another option would be to use Zerotier to do something similar.
by anav
Wed Mar 05, 2025 10:25 pm
Forum: General
Topic: HEX refresh's switch chip, MT7621 dropping BPDU frames
Replies: 9
Views: 3844

Re: HEX refresh's switch chip, MT7621 dropping BPDU frames

... set allowed-interface-list=none /tool mac-server mac-winbox set allowed-interface-list =TRUSTED Note: Consider other options for servers. Zerotier will allow you to link user to servers quite easily and securely. Wireguard another VPN would allow you to give access to servers securely ...
by cubitihon
Wed Mar 05, 2025 8:26 am
Forum: Beginner Basics
Topic: hAP ax2 upgrade to 7.18 don't have interface wifi
Replies: 5
Views: 3085

Re: hAP ax2 upgrade to 7.18 don't have interface wifi

... changes". This will reboot and your interfaces should magically appear. (If you're new to the device, I would also select the "zerotier" package just in case you will want to play around with it.) you are right, in the packages have two wifi packages and wifi-qcom is disable, ...
by lurker888
Wed Mar 05, 2025 7:03 am
Forum: Beginner Basics
Topic: hAP ax2 upgrade to 7.18 don't have interface wifi
Replies: 5
Views: 3085

Re: hAP ax2 upgrade to 7.18 don't have interface wifi

... changes". This will reboot and your interfaces should magically appear. (If you're new to the device, I would also select the "zerotier" package just in case you will want to play around with it.)
by mndtrp
Tue Mar 04, 2025 2:17 pm
Forum: General
Topic: hap ax3 random wireless disconnects
Replies: 325
Views: 80994

Re: hap ax3 random wireless disconnects

... not imported. Because Device Mode is reset during this process. 5. Reconfigured Device Mode. system/device-mode/update mode=home partitions=yes zerotier=yes scheduler=yes 6. The following configuration was not imported during Netinstall. /routing rule … /system scheduler … /system script … /tool/netwatch ...
by holvoetn
Tue Mar 04, 2025 2:06 pm
Forum: General
Topic: Feature Request: Tincvpn
Replies: 18
Views: 11410

Re: Feature Request: Tincvpn

Something which hasn't been updated since 2021 ?
Why would you do that ??

Consider Zerotier or Wireguard.
Both are available for ROS.

Thread closed.
by ilium007
Tue Mar 04, 2025 12:45 pm
Forum: General
Topic: hap ax3 random wireless disconnects
Replies: 325
Views: 80994

Re: hap ax3 random wireless disconnects

... fetch: yes pptp: yes l2tp: yes bandwidth-test: yes traffic-gen: no sniffer: yes ipsec: yes romon: yes proxy: yes hotspot: yes smb: yes email: yes zerotier: yes container: no install-any-version: no partitions: no routerboard: no attempt-count: 0 [admin@MikroTik] /system/device-mode> /system/routerboard/settings/set ...
by JohnTRIVOLTA
Mon Mar 03, 2025 2:39 pm
Forum: Wireless Networking
Topic: First time configuration Ax-Lite LTE with NordVPN
Replies: 67
Views: 9071

Re: VERY Frustrated with Mikrotik L41G-2axD&FG621-EA - AX Lite LTE

I use the same model for the backup connection over a year!
Currently i have set the device with the following VPNs :
Permanent - OpenVPN with server and client certificates. Additional - Wireguard/BTH/ and Zerotier!
The radio use for country Australia for best coverage!
by Larsa
Sun Mar 02, 2025 10:00 pm
Forum: General
Topic: DMVPN
Replies: 4
Views: 2046

Re: DMVPN

A modern alternative to DMVPN is an SD-WAN solution like ZeroTier, which is built into RouterOS. If you need both, you can integrate DMVPN with ZeroTier.
by holvoetn
Sat Mar 01, 2025 6:25 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 227333

Re: v7.19beta [testing] is released!

... this error message in log on wAP AX. Another wAP AX upgraded just fine, so did AX Lite and AX2. 0x17e0d0 manual upgrade request failed, no file (zerotier-7.19beta2-arm.npk) There was no zerotier present on that wAP to begin with, so why should it be there ? I've seen that same issue as well on ...
by utiker
Fri Feb 28, 2025 9:11 pm
Forum: General
Topic: Cannot disable preboot-etherboot after updating to ROS 7.18 [SOLVED]
Replies: 4
Views: 6753

Cannot disable preboot-etherboot after updating to ROS 7.18 [SOLVED]

... fetch: yes pptp: yes l2tp: yes bandwidth-test: yes traffic-gen: no sniffer: yes ipsec: yes romon: yes proxy: yes hotspot: yes smb: yes email: yes zerotier: yes container: no install-any-version: no partitions: no routerboard: no attempt-count: 0 [admin@MikroTik] /system/routerboard/settings> This ...
by sinisa
Thu Feb 27, 2025 8:34 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 641
Views: 300503

Re: v7.18 [stable] is released!

... more things that could be removed/made optional on a ROUTER without hurting it's function. And I also don't like to have on my router: BTH, Zerotier, nor any other "cloud" service that I don't control in full (but I understand that not everyone knows how to set up their own VPN). ...
by ff101
Thu Feb 27, 2025 1:01 pm
Forum: General
Topic: ZeroTier allow LAN to VPN
Replies: 0
Views: 3700

ZeroTier allow LAN to VPN

Hello together I have set up a ZeroTier VPN network. On one side I have a Teltonika cellular router with port forwarding from port 8080 to a web server behind it (port 80). I have tested the connection with a notebook connected to ZeroTier ...
by anav
Wed Feb 26, 2025 6:23 pm
Forum: General
Topic: Private IP can be accessed by public IP via WireGuard
Replies: 3
Views: 3512

Re: Private IP can be accessed by public IP via WireGuard

... for config purposes or its subnets when at a coffee shop or hotel. c. they cannot afford to host CHR on a cloud device. d. do not want to use zerotier between two MT routers. So the configuration you show, is a standard client peer for handshake connecting to a server peer for handshake scenario. ...
by fctech2490
Tue Feb 25, 2025 6:08 pm
Forum: Containers
Topic: Container and RouterOS v7.18 [stable]
Replies: 3
Views: 5507

Container and RouterOS v7.18 [stable]

... the issue in depth, I noticed that I am unable to pull images that have the format <repository>:<tag> For example, I can successfully pull: zerotier (zerotier/zerotier:latest | Docker Hub) cloudflared (cloudflare/cloudflared:latest | Docker Hub) However, I cannot pull: alpine (alpine:latest ...
by fctech2490
Tue Feb 25, 2025 4:01 pm
Forum: Containers
Topic: Container problems on CHR Topic is solved
Replies: 5
Views: 17402

Re: Container problems on CHR Topic is solved

... work unless you update to 7.18. Hi, I can confirm what you reported. After upgrading to version 7.18beta6, I was able to successfully pull the zerotier/zerotier:latest and cloudflare/cloudflared:latest containers from the registry at https://registry-1.docker.io. However, I am still experiencing ...
by jvincze84
Tue Feb 25, 2025 2:48 pm
Forum: Beginner Basics
Topic: Mikrotik AC3 And TP-Link Switch | VLAN
Replies: 2
Views: 3833

Re: Mikrotik AC3 And TP-Link Switch | VLAN

... name=vlan200-cams /ip smb users set [ find default=yes ] disabled=yes /snmp community set [ find default=yes ] addresses=0.0.0.0/0 /zerotier set zt1 comment="ZeroTier Central controller - https://my.zerotier.com/" name=zt1 port=9993 /zerotier interface add instance=zt1 ...
by NA9D
Sun Feb 23, 2025 6:40 am
Forum: General
Topic: Passing UDP Traffic over VPN with ZeroTier
Replies: 0
Views: 4376

Passing UDP Traffic over VPN with ZeroTier

Hi all, It's my understanding that ZeroTier can be configured to allow layer 2 traffic to pass across the VPN. I have a situation where I would like to send broadcast UDP traffic between a remote machine and one or more machines on my LAN. ...
by holvoetn
Sat Feb 22, 2025 9:25 am
Forum: Beginner Basics
Topic: Acceptable CPU load %
Replies: 3
Views: 4003

Re: Acceptable CPU load %

... daily hits 40-50% and that's when a morning 11gb copy job to NAS passes over wireguard. Other then that, usually less than 10%. Normal router, zerotier, wireguard, multiple vlan, dhcp, local dns, less then 25 FW rules, cake- queue applied to WAN, capsman, ...
by anav
Sat Feb 22, 2025 5:20 am
Forum: General
Topic: Feature Request- Add Zerotier Multipath Settings to RouterOS
Replies: 5
Views: 3657

Re: Feature Request- Add Zerotier Multipath Settings to RouterOS

sounds like a discord discussion to be had, but first I have to read up much more on zerotier.
by Amm0
Sat Feb 22, 2025 5:02 am
Forum: General
Topic: Feature Request- Add Zerotier Multipath Settings to RouterOS
Replies: 5
Views: 3657

Re: Feature Request- Add Zerotier Multipath Settings to RouterOS

... file allow a bunch of mode and control over how outbound tunnel are established. Bonding is just one, and that's the problem. See https://docs.zerotier.com/multipath/. But before @Larse chimes in, I'd add even the more simple "Low Bandwidth Mode" option - which is bool / "checkbox" ...
by anav
Sat Feb 22, 2025 4:22 am
Forum: General
Topic: Feature Request- Add Zerotier Multipath Settings to RouterOS
Replies: 5
Views: 3657

Re: Feature Request- Add Zerotier Multipath Settings to RouterOS

Hi ammo, use Elmers Glue !!

But what does that have to do with ops comment, so many fast fail over options???
by Amm0
Sat Feb 22, 2025 4:11 am
Forum: General
Topic: Feature Request- Add Zerotier Multipath Settings to RouterOS
Replies: 5
Views: 3657

Re: Feature Request- Add Zerotier Multipath Settings to RouterOS

for those of not in the know, can you describe what zerotier mulitipath would let you do............ in basic terms. Bonding WAN connections is one setting allowed by ZeroTier's "multipath" support. They have a "balance-aware" ...
by anav
Sat Feb 22, 2025 3:31 am
Forum: General
Topic: Feature Request- Add Zerotier Multipath Settings to RouterOS
Replies: 5
Views: 3657

Re: Feature Request- Add Zerotier Multipath Settings to RouterOS

for those of not in the know, can you describe what zerotier mulitipath would let you do............ in basic terms.
by skrux
Fri Feb 21, 2025 9:34 am
Forum: General
Topic: Feature Request- Add Zerotier Multipath Settings to RouterOS
Replies: 5
Views: 3657

Feature Request- Add Zerotier Multipath Settings to RouterOS

... said roadmap. It could be added in the ZT window, or only accessible via CLI, or just a window that pops up to let us edit the local.conf file for zerotier. This would allow so many fast fail over options for zerotier that I would like to be able to use on RouterOS like I am able to do on my servers ...
by danyrusdem
Thu Feb 20, 2025 3:26 pm
Forum: General
Topic: WireGuard no ping
Replies: 10
Views: 4013

Re: WireGuard no ping

... interface=MGMT lease-time=1w30m name=dhcp3 /routing table add disabled=no fib name=ISP1_1G add disabled=no fib name=ISP2_100MB /zerotier interface add allow-default=no allow-global=no allow-managed=yes disabled=yes instance=\ zt1 name=zerotier1 network=xxxx /interface bridge ...
by anav
Thu Feb 20, 2025 12:36 am
Forum: General
Topic: WireGuard no ping
Replies: 10
Views: 4013

Re: WireGuard no ping

... interface=MGMT lease-time=1w30m name=dhcp3 /routing table add disabled=no fib name=ISP1_1G add disabled=no fib name=ISP2_100MB /zerotier interface add allow-default=no allow-global=no allow-managed=yes disabled=yes instance=\ zt1 name=zerotier1 network=xxxx /interface bridge ...
by fseesink
Mon Feb 17, 2025 11:54 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2412
Views: 5308500

Re: 📣 WinBox 4 is here 📣

... Lens, LogSeq, NetBird, OBS, Obsidian, Rancher Desktop, Signal, Skype, Slack, Syncthing, Transmission, VSCode, VLC, VNC Viewer, VueScan, Wireshark, ZeroTier, and Zoom (and those are just some of the ones I skimmed in my list that I know are also cross-platform). They all properly show their version ...
by brwainer
Sun Feb 16, 2025 5:32 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 1907359

Re: v7.17.2 [stable] is released!

On this version I'm not getting any ARP responses from other routers within my Zerotier network. Downgrade to 7.16.2, same config works again. I also tried 7.18beta6, have the same problem. Full details of my issue, including the most minimal test config possible, ...
by brwainer
Sun Feb 16, 2025 5:21 am
Forum: General
Topic: Zerotier Struggles on v7.17
Replies: 3
Views: 3566

Re: Zerotier Struggles on v7.17

I have much simpler zerotier configuration that works on 7.16.2 but fails on 7.17.2, on both a RB1100AHx4 and a hAP-AX3. The Zerotier interface comes up, the router shows as connected on my.zerotier.com, but ping, ARP, etc. all fail ...
by poocman
Sat Feb 15, 2025 6:44 pm
Forum: General
Topic: VXLAN inside WireGuard tunnel
Replies: 4
Views: 2984

Re: VXLAN inside WireGuard tunnel

... takes 80 ... Thank you for the very detailed answer. I will look into this approach. To put two PCs in the same L2 space did you consider trying zerotier? This option is not off the table, but I thought I would try it without a third party.
by anav
Sat Feb 15, 2025 3:07 pm
Forum: General
Topic: VXLAN inside WireGuard tunnel
Replies: 4
Views: 2984

Re: VXLAN inside WireGuard tunnel

To put two PCs in the same L2 space did you consider trying zerotier?
by fctech2490
Sat Feb 15, 2025 12:17 am
Forum: Containers
Topic: Container problems on CHR Topic is solved
Replies: 5
Views: 17402

Re: Zerotier container problems Topic is solved

Anyone Does anyone have any updates regarding this issue? I’m adding another screenshot of the error from the logs to the post.
by shalak
Fri Feb 14, 2025 11:55 am
Forum: General
Topic: NAT Rule issue – out-interface-list fails for WireGuard traffic
Replies: 7
Views: 3254

Re: NAT Rule issue – out-interface-list fails for WireGuard traffic

... name=monitoring policy=read,test,api,!local,!telnet,!ssh,!ftp,!reboot,!write,!policy,!winbox,!password,!web,!sniff,!sensitive,!romon,!rest-api /zerotier set zt1 comment="ZeroTier Central controller - https://my.zerotier.com/" disabled=yes disabled=yes identity=XYZ name=zt1 port=9993 ...
by MikroTikMarc
Tue Feb 11, 2025 11:43 pm
Forum: 3rd party tools
Topic: MikroTik Professionals Conference (MTPC) Full Presentations!
Replies: 2
Views: 5613

MikroTik Professionals Conference (MTPC) Full Presentations!

... – Looking at the MikroTik RouterOS implementation of MSTP https://youtu.be/tU2OMDWJ2To Alessandro Campanella (1off) – the integration between ZeroTier and MikroTik https://youtu.be/0UzCAAf90LQ Jakub Rejzek – How we (co-)arranged the opening of the 60 GHz https://youtu.be/63ojN8PBRXA Leo De ...
by anav
Mon Feb 10, 2025 4:37 pm
Forum: General
Topic: Mikrotik Client and User security options (Web protection, DPI...)
Replies: 1
Views: 1982

Re: Mikrotik Client and User security options (Web protection, DPI...)

... ( port forwarding ) if at all possible. a. use wireguard to allow clients to connect to servers instead b. use CHR in cloud if need be c. use zerotier to connect users to servers IF stuck with port forwarding at least ensure you use source address list for each DSTNAT rule, ( users should ...
by wrathrbflyn
Sun Feb 09, 2025 4:10 am
Forum: General
Topic: Zerotier Struggles on v7.17
Replies: 3
Views: 3566

Re: Zerotier Struggles on v7.17

... and successful or failed connections, I discovered the source of my difficulties. I needed to configure NAT for connections going to the Zerotier network from the hAP LAN, which I had failed to do. There is a default NAT entry for LAN connections going to the WAN interface list, but since ...
by Larsa
Sat Feb 08, 2025 7:04 pm
Forum: General
Topic: Zerotier Struggles on v7.17
Replies: 3
Views: 3566

Re: Zerotier Struggles on v7.17

... in and maybe a bit tricky to get a clear picture of. Here are a few things that might help clarify things: What exactly isn’t working? - Are all Zerotier peers unreachable from the LAN, or just some? - Can LAN devices ping any Zerotier IPs, or is all Zerotier traffic failing from the LAN side? ...
by wrathrbflyn
Sat Feb 08, 2025 5:27 pm
Forum: General
Topic: Zerotier Struggles on v7.17
Replies: 3
Views: 3566

Zerotier Struggles on v7.17

I am attempting to troubleshoot a couple issues I am seeing in using Zerotier with rOS v7.17 where only some connections are passing as expected. A little background on my network configuration. I utilize multiple Zerotier networks for different purposes including ...
by holvoetn
Fri Feb 07, 2025 9:40 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 215192

Re: v7.18beta [testing] is released!

... automatically upgraded to 7.18.beta4 but other identical one complains about this: G01718@D4:01:C3:C1:8B:BE%*9 upgrade request failed, no file (zerotier-7.18beta4-arm64.npk) There is no zerotier on it or it was ever installed and both caps are 100% identical(reseted to cap mode via button) Confirmed ...
by rules
Fri Feb 07, 2025 5:15 pm
Forum: General
Topic: OSPF vs CCTV
Replies: 2
Views: 2022

Re: OSPF vs CCTV

Thanks Larsa, Zerotier looks quite interesting. I read through your Zerotier post just now and it does seem like it's more meant to be for WAN setups with a squishy internet centre though. My use case will be purely LAN. Would one ...
by Larsa
Fri Feb 07, 2025 11:23 am
Forum: General
Topic: OSPF vs CCTV
Replies: 2
Views: 2022

Re: OSPF vs CCTV

... a mesh network with more than five nodes (10 tunnels), I highly recommend looking into a mesh network solution (often called SD-WAN), like Zerotier, which is included in ROS and automatically manages internal routing—i.e., no need for OSPF or BGP. Zerotier is extremely easy to install and ...
by bpwl
Thu Feb 06, 2025 9:35 pm
Forum: Beginner Basics
Topic: Looking for VPN provider suggestion - with PortFWD
Replies: 10
Views: 6853

Re: Looking for VPN provider suggestion - with PortFWD

So via Zerotier I should be able to configure access from Internet to my Docker or Server via XXXX port? Eg. eventually become P2P Active user share? Total beginner with Zerotier , while looking for a P2P VPN service. Most public ...
by guipoletto
Thu Feb 06, 2025 8:28 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 215192

Re: v7.18beta [testing] is released!

[/quote] One might wonder about zerotier as well - it can be a handy way to exploit compromised devices [/quote] Why not drink the whole kool-aid and advocate for airgapped networks, the most secure form of network? or maybe only allow local ...
by pe1chl
Thu Feb 06, 2025 8:22 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 215192

Re: v7.18beta [testing] is released!

But zerotier has an associated device-mode flag!
by nmt1900
Thu Feb 06, 2025 7:53 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 215192

Re: v7.18beta [testing] is released!

... of some features, I don't understand why leave enabled socks feature which was previously exploited on vulnerable devices One might wonder about zerotier as well - it can be a handy way to exploit compromised devices
by fctech2490
Wed Feb 05, 2025 7:49 pm
Forum: Containers
Topic: Container problems on CHR Topic is solved
Replies: 5
Views: 17402

Container problems on CHR Topic is solved

Hello everyone, I’m having issues when trying to run the ZeroTier container in my environment. Currently, I’m running a CHR on **VMware ESXi 8.0 Update 2**, and I installed the CHR by downloading the OVA file from the official **MikroTik** website. When ...
by holvoetn
Tue Feb 04, 2025 4:13 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 215192

Re: v7.18beta [testing] is released!

There is no zerotier on it or it was ever installed and both caps are 100% identical(reseted to cap mode via button) I have never seen all these packages. AFAIK it shouldn't be there. Could it be that the CAP requires a reboot? ...
by erlinden
Tue Feb 04, 2025 3:46 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 215192

Re: v7.18beta [testing] is released!

There is no zerotier on it or it was ever installed and both caps are 100% identical(reseted to cap mode via button) I have never seen all these packages. AFAIK it shouldn't be there. Could it be that the CAP requires a reboot? ...
by ivicask
Tue Feb 04, 2025 3:04 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 215192

Re: v7.18beta [testing] is released!

... automatically upgraded to 7.18.beta4 but other identical one complains about this: G01718@D4:01:C3:C1:8B:BE%*9 upgrade request failed, no file (zerotier-7.18beta4-arm64.npk) There is no zerotier on it or it was ever installed and both caps are 100% identical(reseted to cap mode via button)
by anav
Tue Feb 04, 2025 12:32 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

Perhaps turning off electrical power to NY state just before superbowl starts would send the right message LOL. But I agree, there are some EU funny rules that are not so easy to overcome, but hey, anything is better than orange farts. By the way, who blinked first game seems to have started one mon...
by Amm0
Mon Feb 03, 2025 8:57 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

Perhaps if we joined the EU..................... My question is how that work with frequency bands... Currently, Canada largely the FCC rules. For Wi-Fi, that likely better. For 5G/LTE with Mikrotik, you may be better off with EU rules... That lovely hAPaxLite-LTE6 is quite affordable but worthless...
by Larsa
Mon Feb 03, 2025 8:18 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

Haha, Anav, I see you're out here securing your files and your finances at the same time! 😂 Maybe if we tweak that command a bit: # chmod +Money Boom! Instant economic growth! 💰💸 As for joining the EU... yeah, I think Canada prefers its maple syrup debts over Mediterranean siestas. But hey, if your ...
by anav
Mon Feb 03, 2025 8:11 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

Larsa, are you trying to talk sexy at me "# chmod +r *". ?? Sounds like, if was to guess, some linux NAS command to ensure read only LOL. Ammo, sounds like too much recent smoke inhalation has impaired your judgment of what I am able to accomplish ( or my budget ). I am starting a go fund ...
by Larsa
Mon Feb 03, 2025 7:07 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

@anav - If I were you, I'd ditch the self-hosted controller and just use the cloud-based one (my.zerotier.com). Regarding your files, just: "# chmod +r *". Fixed! ;)
by Amm0
Mon Feb 03, 2025 7:05 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

... application I can think of is my intention to host an NAS for images/video, and have it accessible by globally located family members etc. Zerotier may be the best way to allow users to access, load, organize etc.............. my only concern is inadvertent deletion of files.......... For ...
by anav
Mon Feb 03, 2025 6:51 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

... application I can think of is my intention to host an NAS for images/video, and have it accessible by globally located family members etc. Zerotier may be the best way to allow users to access, load, organize etc.............. my only concern is inadvertent deletion of files..........
by Amm0
Mon Feb 03, 2025 6:40 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

... with strings. I do suspect the CLI-only-ness of the controller substantially limits its usage on RouterOS. That, and the applications of /zerotier/controller are not well described in docs (i.e. using ZeroTier "roots" for hole-punching, but you can mange the users on RouterOS ...
by Larsa
Mon Feb 03, 2025 6:30 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

Thanks AMMO, so controller is limited to CLI, is there a sense it will migrate to Winbox eventually.

Way too complex, so I don’t think so. But you can add your own web-based manager: ZeroUI.
by Larsa
Mon Feb 03, 2025 6:27 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

Just highlight, once again, an grip of mine is the Mikrotik's ZT client does not support low-bandwidth, bonding, etc. as a "full" ZT client on PC/Mac does. And these restrictions still come in when using the controller, as traffic will go via the interface, not controller. Yeah, unfortuna...
by anav
Mon Feb 03, 2025 6:27 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

Thanks AMMO, so controller is limited to CLI, is there a sense it will migrate to Winbox eventually. Will stick to non-self-controller option especially since the benefit is tied to using a third party git program which also has to be loaded onto docker??
by Larsa
Mon Feb 03, 2025 6:23 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

... still a bit limited when it comes to running fully autonomous operations since ROS doesn't let you configure root servers. But with your own ZeroTier controller and ZeroUI , you not only get a slick web interface, but you also have full control over network rules, authentication, API access, ...
by Amm0
Mon Feb 03, 2025 6:05 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

... be "required". The big difference between WG config is that instead of the various keys and network needing to match like in WG... With ZeroTier (including your own controller) all the "client"/peers needs to know is the ONE /zerotier/controller's network= value. Unlike WG, ...
by NA9D
Mon Feb 03, 2025 4:41 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

The ZT servers are still in use. The docs mention this: A common misunderstanding is to conflate network controllers with root servers (planet and moons). Root servers are connection facilitators that operate at the VL1 level. Network controllers are configuration managers and certificate authoritie...
by anav
Mon Feb 03, 2025 4:32 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

Okay I had to read the docs to understand the use of the word controller. It would seem one can 'bypas' the zerotier site for setup and do it mostly on the mikrotik device. Does this mean one is still using zerotier servers? How is information protected/encrypted using the controller? ...
by anav
Mon Feb 03, 2025 3:41 pm
Forum: General
Topic: VLANs segregation
Replies: 13
Views: 4417

Re: VLANs segregation

... just your servers c. if you dont have a public IP rent a cloud server and get a CHR license and have people VPN through the CHR. d. consider using zerotier to provide access to your servers......
by Larsa
Mon Feb 03, 2025 12:47 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

I completely agree, especially regarding the steps to establish a good baseline. All major players like as Cisco, Juniper, and others, provide clear guidelines for the initial setup. I mean, how hard can it be? ;) Regarding the handbook (I assume you're referring to a user guide), it's a great idea....
by lurker888
Mon Feb 03, 2025 7:17 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

Personally, I think it's better to set ip-address, so the router gets a fixed address & docs should discuss and show using ip-address - your setting up a NEW network and RouterOS is likely to be the default route so example should set it to .1. But, as technical point, their instructions as-is ...
by Amm0
Mon Feb 03, 2025 6:44 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

/zerotier/controller # as array set [find] routes=("2.0/24@10.1.1.1","17.0/8@10.1.1.1") # or as string set [find] routes="2.0/8@10.1.1.1,17.0/8@10.1.1.1" # both forms work - so routes US military ...
by Amm0
Mon Feb 03, 2025 6:27 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

... comment to close together. So maybe why folks see some oddities there. :global ztcontroller do={ :if ($1 = "make") do={ :put "check zerotier instance 'zt1' is enabled" /zerotier :if ([:len [/zerotier/find]] != 1) do={:error "error - zerotier instance is not enabled"} ...
by lurker888
Mon Feb 03, 2025 6:19 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

First of all - thanks for the tip on opening the port on the router. Open on the WAN side - yes? Yeah. Well, actually I mean from everywhere, so in the input chain without additional filters. (The reason being that it's not uncommon to have a zt connection from inside your own network. In this case...
by NA9D
Mon Feb 03, 2025 6:07 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

First of all - thanks for the tip on opening the port on the router. Open on the WAN side - yes?

I just tried it again this time w/o entering the address and yeah, it worked - assigned an IP. OK. I have no idea where the cockpit error was. Oh well.
by lurker888
Mon Feb 03, 2025 5:58 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

Just an unrelated note: If you have a routable WAN address (even if dynamic), you should open port 9993/udp for the ZeroTier service. This enables other clients on the network (even if they are behind NAT) to make a direct connection and not have to use relays. You should especially ...
by NA9D
Mon Feb 03, 2025 5:53 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

OK. Strange. I'll try creating another network and seeing if I can duplicate my problem...
by lurker888
Mon Feb 03, 2025 5:52 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

... your explanation is off. (Using the same config.) If I delete the member, rejoin, and don't give it an explicit IP address assignment, I get: > /zerotier/controller/member/print Flags: A - AUTHORIZED Columns: NETWORK, ZT-ADDRESS, IP-ADDRESS # NETWORK ZT-ADDRESS IP-ADDRESS 0 A tst 23221c3302 172.30.30.100 ...
by NA9D
Mon Feb 03, 2025 5:37 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

HEY! That worked!!!! WOOT! Lurker888 thank you once again. And thanks to the others here as well. Looks like the key is that if you specify additional routes with a gateway address, you MUST assign that gateway address to whatever member is functioning as the gateway - it takes a static assignment. ...
by lurker888
Mon Feb 03, 2025 5:29 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

DHCP in never used in ZT. It is explicitly filtered in all ZT networks. (It's part of the "source" distribution for all zt clients. The desginers thought that it would be a security threat when joining networks run by people you don't really trust. Many people use ZT to for example run Min...
by NA9D
Mon Feb 03, 2025 5:25 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

Wait a minute... Looking at your entries: /zerotier/controller/set 0 private=yes ip-range=172.30.30.100-172.30.30.100 routes=172.30.30.0/24,0.0.0.0/0@172.30.30.1 /zerotier/controller/member/set 0 authorized=yes ip-address=172.30.30.1 You set the ...
by NA9D
Mon Feb 03, 2025 5:14 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

Hmm.

OK. Interesting...I'll try it again...

Could it be that since you are specifying a specific gateway IP address in the ZeroTier subnet that the router doesn't do a DHCP assignment but instead is expecting a fixed IP?
by lurker888
Mon Feb 03, 2025 5:12 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

For me everything works just fine. Commands: /zerotier/controller/set 0 private=yes ip-range=172.30.30.100-172.30.30.100 routes=172.30.30.0/24,0.0.0.0/0@172.30.30.1 /zerotier/controller/member/set 0 authorized=yes ip-address=172.30.30.1 Afterwards: ...
by NA9D
Mon Feb 03, 2025 4:57 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

/zerotier/controller # as array set [find] routes=("2.0/24@10.1.1.1","17.0/8@10.1.1.1") # or as string set [find] routes="2.0/8@10.1.1.1,17.0/8@10.1.1.1" # both forms work - so routes US military ...
by Amm0
Mon Feb 03, 2025 4:50 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

... do resolve a classFULL shortcut as prefix, just like everywhere else in CLI, but boy some typo in an classless IP most folks won't expect it: /zerotier/controller # as array set [find] routes=("2.0/24@10.1.1.1","17.0/8@10.1.1.1") # or as string set [find] routes="2.0/8@10.1.1.1,17.0/8@10.1.1.1" ...
by NA9D
Mon Feb 03, 2025 4:49 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

Well, that "client' is the router itself. My point is that when the extra routes are added, an IP address is never assigned. I'm happy to try it all over again for the tenth time. The IP address is assigned rapidly when using the example setup. So I don't think that it is taking a while.
by lurker888
Mon Feb 03, 2025 4:41 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

After authorization, you should see an ip address being assigned in the controller/member area. I don't know how frequently the client tries to reconnect; maybe you should try disabling/enabling the zt interface. EDIT: And in case you're adding this member as a gw of a route, you really would want t...
by NA9D
Mon Feb 03, 2025 4:24 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

... So yes. Here is it access denied. Now you go and list the members under the controller and then authorize the correct one.. [admin@MikroTik] /zerotier> controller/member/print Columns: NETWORK, ZT-ADDRESS # NETWORK ZT-ADDRESS 0 ZT-NA9D 5fb30d356d [admin@MikroTik] /zerotier> controller/member/set ...
by lurker888
Mon Feb 03, 2025 4:18 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

... some of the typos in the terminal session! In this case I demand that you smash one of our fingers with a claw hammer mob-style. [admin@MikroTik] /zerotier> interface/print interval=1 Columns: NAME, MAC-ADDRESS, NETWORK, STATUS # NAME MAC-ADDRESS NETWORK STATUS 0 NA9DNET 46:92:71:60:00:60 5fb30d356dc2cd47 ...
by NA9D
Mon Feb 03, 2025 4:08 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

... some of the typos in the terminal session! In this case, I tried to add a global 0.0.0.0/0 route to the 172.27.10.11 address. [admin@MikroTik] /zerotier> controller/add name=ZT-NA9D instance=zt1 ip-range=172.27.10.10-172.17.10.20 private=yes routes=172.27.10.0/24,0.0.0.0/0@172.27.10.11 [admin@MikroTik] ...
by NA9D
Mon Feb 03, 2025 4:01 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

I have followed the tutorial exactly. When I enter the steps exactly like they say and with the route example they use (and I've tried it with multiple different IP subnets) things work fine and the instance of the router is given an IP address. It's when I try to add the extra routes that I get zer...
by lurker888
Mon Feb 03, 2025 3:52 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

The guys at Mikrotik are various levels of user friendliness :-). The given example is one such. Actually it is exact and not in the least vague. The given syntax in given in the so-called Backus-Naur form. (https://en.wikipedia.org/wiki/Backus%E2%80%93Naur_form) I've used the controller and it work...
by NA9D
Mon Feb 03, 2025 1:32 am
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

When I set the config up like that, I don't get an IP Address assigned to the router's ZT client. Nothing gets assigned. I assumed I was doing something wrong. As far as forwarding between subnets - not sure. I've got multiple subnets on the router already. I don't have an issue with those or when u...
by Amm0
Mon Feb 03, 2025 1:02 am
Forum: Beginner Basics
Topic: Multicast UDP over Zerotier
Replies: 3
Views: 4652

Re: Multicast UDP over Zerotier

Check out multicast UDP in the rules engine: https://docs.zerotier.com/rules/ I think the default rule do allow multicast, so if it's not your rules.... If RouterOS is bridging ZT interface to LAN, then you need to set "Allow Bridging" on the ...
by Larsa
Sun Feb 02, 2025 11:28 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Re: Question on using the Internal Zerotier Controller [SOLVED]

... get is: routes (IP@GW; Default: ) Push routes in the following format: Routes ::= Route[,Routes] Route ::= Dst[@Gw] Let's say 172.27.27.11 is the ZeroTier address of the node that acts as the gateway to your LAN 192.168.0.0/23 . Then you should write it exactly the way you did earlier ie ' routes ...
by tdabasinskas
Sun Feb 02, 2025 7:10 pm
Forum: General
Topic: Cannot change back the CPU frequency [SOLVED]
Replies: 26
Views: 19814

Cannot change back the CPU frequency [SOLVED]

... fetch: yes pptp: yes l2tp: yes bandwidth-test: yes traffic-gen: no sniffer: yes ipsec: yes romon: yes proxy: yes hotspot: yes smb: yes email: yes zerotier: yes container: yes install-any-version: no partitions: no routerboard: no attempt-count: 0 Any advice?
by NA9D
Sun Feb 02, 2025 5:30 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 16116

Question on using the Internal Zerotier Controller [SOLVED]

Hey all, I'm experimenting with Zerotier and have been following the steps listed in the documentation at: https://help.mikrotik.com/docs/spaces/ROS/pages/83755083/ZeroTier#ZeroTier-Controller I've successfully created a Zerotier connection ...
by NA9D
Sun Feb 02, 2025 5:21 pm
Forum: Beginner Basics
Topic: Multicast UDP over Zerotier
Replies: 3
Views: 4652

Re: Multicast UDP over Zerotier

Cool! Thanks! I'll check it out.
by Larsa
Sat Feb 01, 2025 11:40 pm
Forum: Beginner Basics
Topic: Multicast UDP over Zerotier
Replies: 3
Views: 4652

Re: Multicast UDP over Zerotier

Check out multicast UDP in the rules engine: https://docs.zerotier.com/rules/
by NA9D
Sat Feb 01, 2025 6:04 pm
Forum: Beginner Basics
Topic: Multicast UDP over Zerotier
Replies: 3
Views: 4652

Multicast UDP over Zerotier

Hey all, I am looking for a way to send multicast UDP traffic over a remote VPN connection. From what I have looked at Zerotier provides this functionality. I've have Zerotier installed on my router. I have it on my phone. I've successfully made a connection into my LAN, can ping ...
by joshhboss
Thu Jan 30, 2025 3:26 am
Forum: General
Topic: 7.17 Flash Fig Issues
Replies: 0
Views: 5675

7.17 Flash Fig Issues

... fetch: yes pptp: yes l2tp: yes bandwidth-test: yes traffic-gen: no sniffer: yes ipsec: yes romon: yes proxy: yes hotspot: yes smb: yes email: yes zerotier: yes container: no install-any-version: no partitions: no routerboard: yes attempt-count: 0 and config is like this for my ether1 port /interface ...
by joshhboss
Thu Jan 30, 2025 2:50 am
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 1907359

Re: v7.17 [stable] is released! Flash-Fig Issues

... fetch: yes pptp: yes l2tp: yes bandwidth-test: yes traffic-gen: no sniffer: yes ipsec: yes romon: yes proxy: yes hotspot: yes smb: yes email: yes zerotier: yes container: no install-any-version: no partitions: no routerboard: yes attempt-count: 0 and config is like this for my ether1 port /interface ...
by Amm0
Wed Jan 29, 2025 1:03 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 215192

Re: v7.18beta [testing] is released!

... fetch: yes pptp: yes l2tp: yes bandwidth-test: yes traffic-gen: no sniffer: yes ipsec: yes romon: yes proxy: yes hotspot: yes smb: yes email: yes zerotier: yes container: yes install-any-version: no partitions: no routerboard: no attempt-count: 0
by itimo01
Mon Jan 27, 2025 10:37 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 1907359

Re: v7.17 [stable] is released!

... kind of in shock. Am I reading this wrong? You can always enable features you need Like the docs state: system/device-mode/update mode=advanced zerotier=no https://help.mikrotik.com/docs/spaces/ROS/pages/93749258/Device-mode
by daveq
Mon Jan 27, 2025 5:02 pm
Forum: General
Topic: REQ: AirVPN / Wireguard fine tune assistance
Replies: 21
Views: 11228

Re: REQ: AirVPN / Wireguard fine tune assistance

... downloads" max-limit=1G name="03 Other" packet-mark=\ no-mark parent=TotalBand /routing table add disabled=no fib name=useWG /zerotier set zt1 disabled=no disabled=no /interface bridge port add bridge=bridge comment=defconf interface=ether2 internal-path-cost=10 \ path-cost=10 ...
by Larsa
Mon Jan 27, 2025 1:16 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 5190

Re: IPsec tunnels without known remote IP

... DDNS provider rather than the built-in IP Cloud. EDIT: If throughput isn’t critical and the hardware can handle it, I’d definitely consider ZeroTier with that many networks. It's about $105/month for 50 routers.
by llity
Sun Jan 26, 2025 4:05 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 215192

Re: v7.18beta [testing] is released!

Hope Zerotier supports custom PLANET.
by evilsabc
Fri Jan 24, 2025 5:24 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 1907359

Re: v7.17 [stable] is released!

... fetch: yes pptp: yes l2tp: yes bandwidth-test: yes traffic-gen: no sniffer: yes ipsec: yes romon: yes proxy: yes hotspot: yes smb: yes email: yes zerotier: yes container: no install-any-version: yes partitions: yes routerboard: yes attempt-count: 0 [admin@MikroTik] /system> routerboard print routerboard: ...
by nkourtzis
Fri Jan 24, 2025 1:19 pm
Forum: General
Topic: Support takes too long to respond to followed-up tickets
Replies: 8
Views: 3689

Re: Support takes too long to respond to followed-up tickets

@nkourtzis - Just curious, why are you using OSPF on top of ZeroTier? I have chosen ZeroTier as the easiest way to create a WAN with 70+ nodes that will be reasonably secure and work over different types of upstream connections, NATted/not-NATted, ISP ...
by Amm0
Thu Jan 23, 2025 10:30 pm
Forum: General
Topic: Support takes too long to respond to followed-up tickets
Replies: 8
Views: 3689

Re: Support takes too long to respond to followed-up tickets

... And @Larsa as usual has a good point... I got a bit distracted by RoMON in your other thread... But if everything is connected by ZeroTier, you can use its route distribution system, instead OSPF to edges. The routes do NOT have be ZT IPs - it really does "inject" any ...
by Larsa
Thu Jan 23, 2025 7:47 pm
Forum: General
Topic: Support takes too long to respond to followed-up tickets
Replies: 8
Views: 3689

Re: Support takes too long to respond to followed-up tickets

@nkourtzis - Just curious, why are you using OSPF on top of ZeroTier?
by Amm0
Thu Jan 23, 2025 7:37 pm
Forum: General
Topic: Support takes too long to respond to followed-up tickets
Replies: 8
Views: 3689

Re: Support takes too long to respond to followed-up tickets

... is in keeping with Mikrotik's minimalist communications. And by adding a comment, you go back to top of someone's queue I think. ;) On your OSPF+ZeroTier issue, it may not hurt to try 7.18beta2. Sometimes these problems get fixed by some unrelated bug fix. And/or that a good reason to update ...
by nkourtzis
Thu Jan 23, 2025 4:00 pm
Forum: General
Topic: Support takes too long to respond to followed-up tickets
Replies: 8
Views: 3689

Support takes too long to respond to followed-up tickets

Hello, I have the following two open tickets at help.mikrotik.com: SUP-176047 (problem with OSPF over ZeroTier) SUP-168963 (Routing process lockup that persists reboots) Both of them had been replied initially by support, then I replied back and now both are in the "waiting ...
by meetriks2
Wed Jan 22, 2025 3:27 pm
Forum: General
Topic: CCR2004-16G-2S+ shows wrong cpu mhz
Replies: 10
Views: 5844

Re: CCR2004-16G-2S+ shows wrong cpu mhz

... fetch: yes pptp: yes l2tp: yes bandwidth-test: yes traffic-gen: no sniffer: yes ipsec: yes romon: yes proxy: yes hotspot: yes smb: yes email: yes zerotier: yes container: no install-any-version: no partitions: no routerboard: yes attempt-count: 0 [admin@MR1] /system/device-mode> /system/res resource ...
by holvoetn
Wed Jan 22, 2025 2:27 pm
Forum: General
Topic: UDP hole punching
Replies: 4
Views: 3111

Re: UDP hole punching

... way to come in directly on that interface. But you CAN first go out (e.g. using wireguard if you have another server where it can be configured, zerotier or even Mikrotik's own Back To Home) and then use that tunnel to come back in. I am not concerned with security for now. Really, you should ...
by rextended
Wed Jan 22, 2025 1:07 pm
Forum: Scripting
Topic: :execute output to console? Or any other method?
Replies: 17
Views: 7779

Re: :execute output to console? Or any other method?

... 132.1KiB 11 XA ups 32.1KiB 12 XA user-manager 332.1KiB 13 wifi-qcom 7.18beta2 2025-01-21 09:27:58 10.2MiB 14 XA wireless 856.1KiB 15 XA zerotier 832.1KiB [admin@test] /system/package> :put [get 0] .id=*3;available=true;disabled=true;name=calea;scheduled=;size=20625;version= [admin@test] ...
by savix
Wed Jan 22, 2025 12:50 pm
Forum: General
Topic: RB5009UG+S+ ip problem
Replies: 16
Views: 4263

Re: RB5009UG+S+ ip problem

I am not a zerotier expert, but assuming stating the zerotier interface on the input chain rule was not enough or accurate, perhaps you need to add actual IP address??? ok. which rule should i copy inserting the exact zerotier ...
by anav
Tue Jan 21, 2025 11:11 pm
Forum: General
Topic: RB5009UG+S+ ip problem
Replies: 16
Views: 4263

Re: RB5009UG+S+ ip problem

I am not a zerotier expert, but assuming stating the zerotier interface on the input chain rule was not enough or accurate, perhaps you need to add actual IP address???
by savix
Tue Jan 21, 2025 7:28 pm
Forum: General
Topic: RB5009UG+S+ ip problem
Replies: 16
Views: 4263

Re: RB5009UG+S+ ip problem

... comment="admin to router" in-interface-list=LAN src-address-list=Authorized add action=accept chain=input comment="allow zerotier users to router" in-interface=zerotier1 add action=accept chain=input comment="users to services" in-interface-list=LAN dst-port=53 ...
by vovan700i
Tue Jan 21, 2025 4:19 pm
Forum: Virtualization
Topic: Why is Zerotier unavailable on X86 CHR?
Replies: 2
Views: 4323

Re: Why is Zerotier unavailable on X86 CHR?

... there is definitely very little feedback from developers, I can see they do listen and implement some features we ask for. One plus of running ZeroTier externally is that you get full access to all configuration settings, which are limited when running on ROS. While you are technically right, ...
by Larsa
Tue Jan 21, 2025 2:50 pm
Forum: Virtualization
Topic: Why is Zerotier unavailable on X86 CHR?
Replies: 2
Views: 4323

Re: Why is Zerotier unavailable on X86 CHR?

... Since this is just a user forum, we can only guess, and our opinions probably don’t affect their design decisions anyway. One plus of running ZeroTier externally is that you get full access to all configuration settings, which are limited when running on ROS.
by vovan700i
Tue Jan 21, 2025 2:12 pm
Forum: Virtualization
Topic: Why is Zerotier unavailable on X86 CHR?
Replies: 2
Views: 4323

Why is Zerotier unavailable on X86 CHR?

Hi, I would like to discuss why Zerotier is unavailable on X86 CHR. According to the forum, there are many people asking for it (e.g. https://forum.mikrotik.com/viewtopic.php?p=1109645&hilit=zerotier#p1109645) I know Zerotier could be ...
by krissg
Sun Jan 19, 2025 5:09 pm
Forum: General
Topic: RB5009 vlan mgmt to sxt passthrough
Replies: 2
Views: 6078

Re: RB5009 vlan mgmt to sxt passthrough

... address-pool=pool-VLAN_200_MGMT_LTE interface=bridge-LAN \ name=DHCP_MGMT_LTE_VLAN /snmp community set [ find default=yes ] name=Zabbix /zerotier set zt1 disabled=no disabled=no /zerotier interface add allow-default=no allow-global=no allow-managed=yes disabled=no instance=\ zt1 name=zt_giolbas ...
by krissg
Sun Jan 19, 2025 2:17 pm
Forum: General
Topic: RB5009 vlan mgmt to sxt passthrough
Replies: 2
Views: 6078

RB5009 vlan mgmt to sxt passthrough

... add add-arp=yes address-pool=pool-VLAN_40_TV interface=VLAN_40_TV name=\ DHCP_TV_VLAN /snmp community set [ find default=yes ] name=Zabbix /zerotier set zt1 comment="ZeroTier Central controller - https://my.zerotier.com/" \ name=zt1 port=9993 /zerotier interface add allow-default=no ...
by anav
Sat Jan 18, 2025 10:41 pm
Forum: General
Topic: RB5009UG+S+ ip problem
Replies: 16
Views: 4263

Re: RB5009UG+S+ ip problem

... comment="admin to router" in-interface-list=LAN src-address-list=Authorized add action=accept chain=input comment="allow zerotier users to router" in-interface=zerotier1 add action=accept chain=input comment="users to services" in-interface-list=LAN dst-port=53 ...
by daveq
Fri Jan 17, 2025 4:10 pm
Forum: Beginner Basics
Topic: Looking for VPN provider suggestion - with PortFWD
Replies: 10
Views: 6853

Re: Looking for VPN provider suggestion - with PortFWD

Here is my result: Zerotier seems not to have PortForwarding (or havent found how) to access my local hosted services from internet via IP,DDNS or similar... Mikrotik's Back to Home VPN - when I enable / installed on Android afterwards ...
by daveq
Fri Jan 17, 2025 4:08 pm
Forum: General
Topic: REQ: AirVPN / Wireguard fine tune assistance
Replies: 21
Views: 11228

REQ: AirVPN / Wireguard fine tune assistance

... downloads" max-limit=1G name="03 Other" packet-mark=\ no-mark parent=TotalBand /routing table add disabled=no fib name=useWG /zerotier set zt1 disabled=no disabled=no /interface bridge port add bridge=bridge comment=defconf interface=ether2 internal-path-cost=10 \ path-cost=10 ...
by savix
Fri Jan 17, 2025 11:37 am
Forum: General
Topic: RB5009UG+S+ ip problem
Replies: 16
Views: 4263

RB5009UG+S+ ip problem

... lease-time=12h name=dhcp1 /ip kid-control add name=Andrew add name=Vivi /ip pool add name=dhcp_pool ranges=192.168.1.2-192.168.1.254 /zerotier set zt1 comment="ZeroTier Central controller - https://my.zerotier.com/" name=zt1 port=9993 /zerotier interface add allow-default=no ...
by EdPa
Thu Jan 16, 2025 3:58 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 1907359

v7.17.2 [stable] is released!

... - preserve configured country while using setup-repeater, added "country" argument (CLI only); *) x86 - Realtek r8169 updated driver; *) zerotier - added debug logging; *) zerotier - do not show default settings in export; *) zerotier - upgraded to version 1.14.0; To upgrade, click "Check ...
by Amm0
Mon Jan 13, 2025 9:46 pm
Forum: Beginner Basics
Topic: Automation Gateway With Mikrotik [SOLVED]
Replies: 9
Views: 10710

Re: Automation Gateway With Mikrotik [SOLVED]

The CHR solution looks cool, but CHR + server looks a bit to much for me right now. [...] Maybe flashing the RB951 with openWRT + Zerotier (I hope this is not a sin to be told here) Most commercial VPN services (Nord, SurfShark, etc.) don't allow port forwarding, so that not a viable options. ...
by warpedhead
Mon Jan 13, 2025 8:49 pm
Forum: Beginner Basics
Topic: Automation Gateway With Mikrotik [SOLVED]
Replies: 9
Views: 10710

Re: Automation Gateway With Mikrotik [SOLVED]

... of wireguard for mips? The CHR solution looks cool, but CHR + server looks a bit to much for me right now. Maybe flashing the RB951 with openWRT + Zerotier (I hope this is not a sin to be told here)
by anav
Mon Jan 13, 2025 8:31 pm
Forum: Beginner Basics
Topic: Automation Gateway With Mikrotik [SOLVED]
Replies: 9
Views: 10710

Re: Automation Gateway With Mikrotik [SOLVED]

The reason I recommend the CHR approach, or BTH VPN for that matter is for privacy. Zerotier is still traffic going through their servers and some companies may be leery of someone tapping into their networks without complete assurances of privacy Disagree with AMMO, ...
by Amm0
Mon Jan 13, 2025 8:24 pm
Forum: Beginner Basics
Topic: Automation Gateway With Mikrotik [SOLVED]
Replies: 9
Views: 10710

Re: Automation Gateway With Mikrotik [SOLVED]

Yeah ZeroTier works pretty well for these cases. While WireGuard and EoIP+IPSec be alternatives if you have a public IP someplace where you can do port forwarding... But without a public IP, you need another router someplace ...
by warpedhead
Mon Jan 13, 2025 8:05 pm
Forum: Beginner Basics
Topic: Automation Gateway With Mikrotik [SOLVED]
Replies: 9
Views: 10710

Automation Gateway With Mikrotik [SOLVED]

... can remotely connect and diagnose, nice, but HOW? AFAIK the LTE won't give me a public IP, so I cant make a simple VPN. My RB is MIPS based, so no zerotier for me. What other routes could I go?
by anav
Mon Jan 13, 2025 5:30 pm
Forum: Beginner Basics
Topic: Looking for VPN provider suggestion - with PortFWD
Replies: 10
Views: 6853

Re: Looking for VPN provider suggestion - with PortFWD

Someone else will have to answer your zerotier questions as I have little experience.

Looking at your diagram from the other thread, it would appear you are stuck with switches that dont provide guaranteed vlan performance.
Suggest a pair of hex refreshes are decent cheap managed switches............
by daveq
Mon Jan 13, 2025 5:15 pm
Forum: Beginner Basics
Topic: Looking for VPN provider suggestion - with PortFWD
Replies: 10
Views: 6853

Re: Looking for VPN provider suggestion - with PortFWD

... (for photos) will be available also remotely, yeayyy :shock: :) This should cover most of the Services from NAS which I wanted to connect to 2. Zerotier - will take some time to read and understand all , seems pretty new feature https://help.mikrotik.com/docs/spaces/ROS/pages/83755083/ZeroTier ...
by anav
Mon Jan 13, 2025 4:07 pm
Forum: Beginner Basics
Topic: Looking for VPN provider suggestion - with PortFWD
Replies: 10
Views: 6853

Re: Looking for VPN provider suggestion - with PortFWD

I would look at a. zerotier as its available in RoS for any networking things you want to do........... ( basically puts all joined entities into a layer2 construct together ) b. BTH VPN this would be used for you to remotely configure ...
by CGGXANNX
Mon Jan 13, 2025 10:41 am
Forum: Announcements
Topic: v7.17rc [testing] is released!
Replies: 408
Views: 176239

Re: v7.17rc [testing] is released!

... switch chips; *) switch - fixed storm-rate accuracy on 98DX224S, 98DX226S, and 98DX3236 switch chips; *) x86 - Realtek r8169 updated driver; *) zerotier - added debug logging; *) zerotier - do not show default settings in export; *) zerotier - upgraded to version 1.14.0; Some probably small ...
by anav
Mon Jan 13, 2025 4:30 am
Forum: Beginner Basics
Topic: Looking for VPN provider suggestion - with PortFWD
Replies: 10
Views: 6853

Re: Looking for VPN provider suggestion - with PortFWD

... users to reach your router by using public IP address of a router in a different location, not aware of any............ ( did you consider zerotier ??) (you could rent your own cloud server for this for about $7 plus buy CHR MT license.
by RabbRubb
Sat Jan 11, 2025 9:55 pm
Forum: Beginner Basics
Topic: SSH out via dst-nat [SOLVED]
Replies: 3
Views: 10556

Re: SSH out via dst-nat [SOLVED]

... /ip dhcp-server add address-pool=dhcp interface=bridge lease-time=10m name=dhcp1 /ip smb users set [ find default=yes ] disabled=yes /zerotier set zt1 comment="ZeroTier Central controller - https://my.zerotier.com/" \ name=zt1 port=9993 /zerotier interface add allow-default=no ...
by Hagelsturm
Sat Jan 11, 2025 2:44 pm
Forum: General
Topic: ZeroTier version mismatch (1.10.3 vs. 1.14)
Replies: 1
Views: 1986

Re: ZeroTier version mismatch (1.10.3 vs. 1.14)

the new version is in 7.17rc my misstake
by Hagelsturm
Sat Jan 11, 2025 2:29 pm
Forum: General
Topic: ZeroTier version mismatch (1.10.3 vs. 1.14)
Replies: 1
Views: 1986

ZeroTier version mismatch (1.10.3 vs. 1.14)

Hi everyone, I recently updated to RouterOS 7.16 and noticed in the changelog that ZeroTier is supposedly upgraded to version 1.14. However, in the ZeroTier web interface, it still shows version 1.10.3. I'm a bit confused about which version is actually running on ...
by dcavni
Sat Jan 11, 2025 1:30 am
Forum: General
Topic: Winbox getting stuck at downloading desciptors (Zerotier connection)
Replies: 1
Views: 5576

Winbox getting stuck at downloading desciptors (Zerotier connection)

What could be causing that Winbox won't connect over Zerotier. In Winbox 3 it gets stuck at "downloading descriptors" and in Winbox 4 it gets stuck at "reading the index file". Interesting thing is, that i could connect to this ...
by nkourtzis
Fri Jan 10, 2025 4:33 pm
Forum: General
Topic: Question on massive site-to-site VPN implementation
Replies: 13
Views: 4048

Re: Question on massive site-to-site VPN implementation

This is using /zerotier/controller. By the way, in this case are there any flow rules I can edit? I am asking because now RoMON goes through the ZeroTier interface, but OSPF does not discover peers in any broadcast mode, it only ...
by Amm0
Fri Jan 10, 2025 3:54 pm
Forum: General
Topic: Question on massive site-to-site VPN implementation
Replies: 13
Views: 4048

Re: Question on massive site-to-site VPN implementation

This is using /zerotier/controller. By the way, in this case are there any flow rules I can edit? I am asking because now RoMON goes through the ZeroTier interface, but OSPF does not discover peers in any broadcast mode, it only ...
by nkourtzis
Fri Jan 10, 2025 12:45 pm
Forum: General
Topic: Question on massive site-to-site VPN implementation
Replies: 13
Views: 4048

Re: Question on massive site-to-site VPN implementation

the way, I solved the RoMON issue with ZeroTier: I had to enable bridging mode for each peer. This is when using /zerotier/controller for your peers? ...or using my.zerotier.com service? I ask since the default flow rules for ZeroTier's cloud ...
by mutluit
Thu Jan 09, 2025 10:13 pm
Forum: General
Topic: 4G/LTE router with Dual SIM [SOLVED]
Replies: 20
Views: 7489

Re: 4G/LTE router with Dual SIM [SOLVED]

... decent web UI, but all the features are pretty fixed in how they work and there aren't a lot of customizations. Small example, Cudy's do support ZeroTier but they don't let you customize anything about it which then makes it hard to more granular route selection. Now, RouterOS offers way more ...
by Amm0
Thu Jan 09, 2025 7:01 pm
Forum: General
Topic: 4G/LTE router with Dual SIM [SOLVED]
Replies: 20
Views: 7489

Re: 4G/LTE router with Dual SIM [SOLVED]

... decent web UI, but all the features are pretty fixed in how they work and there aren't a lot of customizations. Small example, Cudy's do support ZeroTier but they don't let you customize anything about it which then makes it hard to more granular route selection. Now, RouterOS offers way more ...
by Amm0
Thu Jan 09, 2025 6:43 pm
Forum: General
Topic: Question on massive site-to-site VPN implementation
Replies: 13
Views: 4048

Re: Question on massive site-to-site VPN implementation

the way, I solved the RoMON issue with ZeroTier: I had to enable bridging mode for each peer. This is when using /zerotier/controller for your peers? ...or using my.zerotier.com service? I ask since the default flow rules for ZeroTier's cloud ...
by nkourtzis
Thu Jan 09, 2025 5:03 pm
Forum: General
Topic: Question on massive site-to-site VPN implementation
Replies: 13
Views: 4048

Re: Question on massive site-to-site VPN implementation

... person should "touch something red" so that they don't get into an argument. Go figure... :-) By the way, I solved the RoMON issue with ZeroTier: I had to enable bridging mode for each peer.
  • 1
  • 2
  • 3
  • 4
  • 5
  • 11