Community discussions

MikroTik App

Search found 3023 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 11
by chechito
Thu May 11, 2023 8:34 pm
Forum: General
Topic: Urgent: need help finding memory leak (RoS v6.48.6) [SOLVED]
Replies: 6
Views: 1769

Re: Urgent: need help finding memory leak (RoS v6.48.6) [SOLVED]

as rextended says i think is not a memory leak i have some Routers with months of uptime with that version


some missconfiguration
or
you are being ddos attacked

to start check this:
/ip firewall connection tracking print
check the total entries value
by chechito
Thu May 11, 2023 8:00 am
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55106

Re: v7.9 [stable] is released!

I found an issue on v7.9 (also in v7.8): There is an issue in the algorithm used for choosing the (random?) MAC address of a bridge (e.g. loopback). Two switches CRS317 in the same network got the same MAC address on the loopack interface. RoMON Address also is duplicated. Only one of both devices ...
by chechito
Thu May 11, 2023 7:57 am
Forum: General
Topic: QoS Hardware Offloading (QoS-HW)
Replies: 46
Views: 12184

Re: QoS Hardware Offloading (QoS-HW)

I tested in a CRS 317 Version 7.6 with L3 HW Offload, then Ingress ACL for rate limiting does not work, but in L2 Bridge Vlan Filtering Ingress ACL for rate limiting works OK

that's why i'm asking
by chechito
Thu May 11, 2023 5:16 am
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 42991

Re: Newsletter #113 | May 2023

i think marketing is backfiring on L009 ,some of us (me included) at first expected to see it as a worthy representative of 2011-3011-4011-5009 Latvian Muscle legendary Router Family when it is far from it We already have the rb4011 and rb5009 This Red Device first appeals to nostalgia then appeals ...
by chechito
Thu May 11, 2023 2:50 am
Forum: Forwarding Protocols
Topic: BGP is broken in 7.8
Replies: 19
Views: 3422

Re: BGP is broken in 7.8

just to close this loop with actual feedback and help I went online facebook MK group and posed the exact same question as I did here. Within 10min I got the answer --- Maybe this can help In v7 it is not possible to turn off synchronization with IGP routes (the network will be advertised only if t...
by chechito
Wed May 10, 2023 11:13 pm
Forum: General
Topic: QoS Hardware Offloading (QoS-HW)
Replies: 46
Views: 12184

Re: QoS Hardware Offloading (QoS-HW)

Greetings, fellow community members! We are glad to announce the beginning of a new project - Quality of Service Hardware Offloading (QoS-HW) , introduced in RouterOS v7.10 . The goal of the project is to perform QoS packet marking (VLAN PCP, IP DSCP, and in the future - MPLS EXP), traffic shaping,...
by chechito
Wed May 10, 2023 11:11 pm
Forum: General
Topic: QoS Hardware Offloading (QoS-HW)
Replies: 46
Views: 12184

Re: QoS Hardware Offloading (QoS-HW)

I noticed the CRS309 has 8 hardware TX queues (tx-queue0-packet) but I didn't see how to classify traffic to use each queue. i was tracking that for a while, now we know this is real keep in mind The current implementation is for QoS Phase 1 - QoS Marking (introduced in RouterOS v7.10). so maybe we...
by chechito
Wed May 10, 2023 8:27 pm
Forum: Beginner Basics
Topic: Packet Loss!!! BOND (802.3ad) on BRIDGE w/ HW Offload
Replies: 12
Views: 2757

Re: Packet Loss!!! BOND (802.3ad) on BRIDGE w/ HW Offload

until now CCR2004-16G-2S+ is the only product using 88E6191X switch chip

maybe you have found a bug
by chechito
Sun May 07, 2023 9:04 pm
Forum: Beginner Basics
Topic: DDOS attack need help
Replies: 38
Views: 3027

Re: DDOS attack need help

if 154.54.220.138 traffic is not relevant or important to you drop it
/ip firewall raw
add action=drop chain=prerouting src-address=154.54.220.138
lowering tcp timeout can help
/ip firewall connection tracking 
set tcp-established-timeout=16m
by chechito
Sun May 07, 2023 7:01 pm
Forum: Beginner Basics
Topic: DDOS attack need help
Replies: 38
Views: 3027

Re: DDOS attack need help

looks like was not so urgent after all
by chechito
Sun May 07, 2023 8:34 am
Forum: Beginner Basics
Topic: New to PPPoE
Replies: 3
Views: 648

Re: New to PPPoE

and static simple queues
by chechito
Sun May 07, 2023 8:31 am
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 119
Views: 130816

Re: DHCP Offering Lease Without Success

DHCP Offering Lease Without Success

most the time is a simptom of a problem in access network, some times not even related to the router

frequently is a simptom of wireless or wired network issues, not a router failure, most the time router is not culprit

dont shoot the messenger...
by chechito
Sun May 07, 2023 8:29 am
Forum: Forwarding Protocols
Topic: v7 BGP Full Tables Core Usage
Replies: 12
Views: 4916

Re: v7 BGP Full Tables Core Usage

sometimes when you open winbox and a window with many elements that consume alot of resources is a matter of clossing that windows and then exit winbox reopen winbox and wait (without opening a window with many elements) some minutes and that 100% core will be gone windows with many elements: simple...
by chechito
Fri May 05, 2023 4:38 am
Forum: RouterBOARD hardware
Topic: CCR2116 L3HW offloading and loopback interfaces?
Replies: 2
Views: 2317

Re: CCR2116 L3HW offloading and loopback interfaces?

I join the same question
by chechito
Wed May 03, 2023 5:19 pm
Forum: Forwarding Protocols
Topic: BGP implementation affected by CVE-2022-40302, CVE-2022-40302 or CVE-2022-43681?
Replies: 1
Views: 1951

Re: BGP implementation affected by CVE-2022-40302, CVE-2022-40302 or CVE-2022-43681?

i think is an interesting topic

and a reminder to secure control plane in our Routers
by chechito
Wed May 03, 2023 3:34 am
Forum: General
Topic: MUM plans for 2023?
Replies: 52
Views: 9074

Re: MUM plans for 2023?

:lol: :lol: :lol:
by chechito
Wed May 03, 2023 1:36 am
Forum: RouterBOARD hardware
Topic: New Hardware SPOILER!!! [RB L009UiGS-2HaxD] [SOLVED]
Replies: 48
Views: 13842

Re: New Hardware SPOILER!!! [RB L009UiGS-2HaxD] [SOLVED]

i think in an effort not to "self-compete" with the hap ax3 they have crippled this reference with that CPU come on guys !!! we are in 2023: high performance and single band wi-fi cant be in the same sentence !!! this is practically a hAP ax Lite with a bigger enclosure !!! sorry about my ...
by chechito
Tue May 02, 2023 6:56 pm
Forum: Beginner Basics
Topic: CCR1036 and high CPU temperature
Replies: 2
Views: 380

Re: CCR1036 and high CPU temperature

hi guys i have a mikrotik ccr1036-8g-2s +em with revision3. I see the temperature is 28 C while the CPU temperature is 52C.

Is it normal for CPU temperature to go up to 52C.
dont worry its normal temperature
by chechito
Tue May 02, 2023 6:53 pm
Forum: General
Topic: MUM plans for 2023?
Replies: 52
Views: 9074

Re: MUM plans for 2023?

maybe is time for Users to Make their own independent MUMs
by chechito
Tue May 02, 2023 3:38 am
Forum: RouterBOARD hardware
Topic: hAP AX2 vs hAP AX3 CPU power
Replies: 11
Views: 5578

Re: hAP AX2 vs hAP AX3 CPU power

Let's accompany this with some crude calculations % of advantage of ax3 over ax2 ax2-vs-ax3.png where you see single digit advantage is because is reaching CPU to SWITCH interface limit not cpu processing limit Could you please create the same conparison for AC3 vs AX3 and post it here? ???? ac3-vs...
by chechito
Mon May 01, 2023 4:40 pm
Forum: Wireless Networking
Topic: hAP ax3 preventing buyers remorse
Replies: 57
Views: 10079

Re: hAP ax3 preventing buyers remorse

I did some speedtest with new ax2 that I recieved, i tested only 5 GHz band TX/RX (default config out of the box, only thing changed SSID pw and admin pw and country set to my country) Server is on laptop, i have Intel AX200 WiFi card, i ran each test for about 5 minutes and distance between laptop...
by chechito
Sat Apr 29, 2023 7:13 pm
Forum: General
Topic: v7 to 6 any chance to downgrade?
Replies: 27
Views: 5287

Re: v7 to 6 any chance to downgrade?

looks like after a little more than a year the time to mandatorily go to V7.X has come, is not pretty but It is what we have
by chechito
Sat Apr 29, 2023 7:02 pm
Forum: General
Topic: The Mikrotik Android App should include a bandwidth-test client
Replies: 4
Views: 771

Re: The Mikrotik Android App should include a bandwidth-test client

can be a good idea, but many smartphones does not have enough CPU processing power to do bandwidth test with high speed, add this to the limitations of Wi-Fi connection, then you have the cocktail for many complaints about it
by chechito
Sat Apr 29, 2023 1:13 am
Forum: General
Topic: How to use the USB port on CCR2004-16G-2S+?
Replies: 2
Views: 637

Re: How to use the USB port on CCR2004-16G-2S+?

off topic

be aware newer shipments of this router come without USB port
by chechito
Fri Apr 28, 2023 4:19 am
Forum: Beginner Basics
Topic: Replacing a CRS106-1C-5S
Replies: 2
Views: 311

Re: Replacing a CRS106-1C-5S

You can buy another CSS106-1G-4P-1S and connect between them using back sfp ports with dac sfp cable S+DA0001 or equivalent, then you will have 8 poe ports plus 2 regular rj45 without poe total 10 gigabit ports
by chechito
Thu Apr 27, 2023 4:07 pm
Forum: General
Topic: CCR2216 - L3HW unusable at >10Gbit/s
Replies: 3
Views: 458

Re: CCR2216 - L3HW unusable at >10Gbit/s

what cpu usage you obtain in that conditions??
by chechito
Thu Apr 27, 2023 2:10 am
Forum: RouterBOARD hardware
Topic: Advice on changing the fans on CRS510-8XS-2XQ-IN
Replies: 2
Views: 2268

Re: Advice on changing the fans on CRS510-8XS-2XQ-IN

just in case

Keep an eye on qsfp module temperature
by chechito
Thu Apr 27, 2023 1:11 am
Forum: General
Topic: CCR2216-1G-12XS-2XQ and filter rules and performance
Replies: 1
Views: 277

Re: CCR2216-1G-12XS-2XQ and filter rules and performance

i think before doing that kind of investment a good idea is to know the product

Welcome

https://help.mikrotik.com/docs/display/ROS/RouterOS
by chechito
Wed Apr 26, 2023 7:47 pm
Forum: General
Topic: Skins for winbox too?!?
Replies: 68
Views: 7228

Re: Skins for winbox too?!?

i think You have hit the nail

i have a remote location where skin does not work on winbox and is with a limited user with only the following permisions in his respective user-group:

read, write, web, winbox
by chechito
Wed Apr 26, 2023 4:45 am
Forum: Wireless Networking
Topic: Please help me choose between hap ax2 and ax3 as access points [SOLVED]
Replies: 57
Views: 19785

Re: Please help me choose between hap ax2 and ax3 as access points [SOLVED]

some aproximate data about performance advantage of ax3 over ax2
ax2-vs-ax3.png
by chechito
Mon Apr 24, 2023 11:30 pm
Forum: General
Topic: Something NEEDS to be done about the default passwords
Replies: 169
Views: 14013

Re: Something NEEDS to be done about the default passwords

Passwords are available in CSV format from the distributor accounts. You guys are good with scripts, come up with a script that takes these passwords from CSV as variables and uses them in your SSH mass config scripts :) Or ... just Flashfig routers en-masse with some big switch. [SOLVED] :lol: jus...
by chechito
Mon Apr 24, 2023 11:28 pm
Forum: General
Topic: Something NEEDS to be done about the default passwords
Replies: 169
Views: 14013

Re: Something NEEDS to be done about the default passwords

Passwords are available in CSV format from the distributor accounts. This seems like it would be a good solution for distributors, but what about a small ISP? And hopefully, the distributors only have the passwords for the routers they bought for resale, i.e. not all routers. distributor know passw...
by chechito
Mon Apr 24, 2023 10:38 pm
Forum: Wireless Networking
Topic: how much 60 Ghz devices are resistant to jamming?
Replies: 6
Views: 1390

Re: how much 60 Ghz devices are resistant to jamming?

i think you need a product way beyond consumer

maybe military equipment or something like that


if that is not your case, then off course any civil wireless equipment is vulnerable to jamming so this too
by chechito
Mon Apr 24, 2023 10:36 pm
Forum: General
Topic: Feature Request: SAFE MODE time based
Replies: 43
Views: 11700

Re: Feature Request: SAFE MODE time based

If MikroTik at least supported "show | compare" and "commit confirm xxx" like Juniper, it would be great.
yes that will be great in MikroTik
by chechito
Mon Apr 24, 2023 8:36 pm
Forum: Beginner Basics
Topic: Question about temperature, 62 C 0 63 C
Replies: 12
Views: 3447

Re: Question about temperature, 62 C 0 63 C

There is a reason why that device has so many ventilation openings... also for supported ambient temperature up to 50°C Max there is a tiny price to pay for such a versatile and powerfull device in a compact fashion, most electronics works ok up to 90°C or even more so i think 65°C is no problem
by chechito
Mon Apr 24, 2023 5:02 am
Forum: Beginner Basics
Topic: Mark/route traffic from socks/proxy?
Replies: 2
Views: 400

Re: Mark/route traffic from socks/proxy?

maybe output chain
by chechito
Sun Apr 23, 2023 10:18 pm
Forum: RouterBOARD hardware
Topic: hAP AX2 vs hAP AX3 CPU power
Replies: 11
Views: 5578

Re: hAP AX2 vs hAP AX3 CPU power

so here should AX3 shine.... Ans: Just the opposite this small CPU's have a narrow memory bus to be cheap and power efficient do you mean that the procesor is bad designed and can use only 4x874??? I dont think so :) Ans: bad designed no, goodfully market segmented i think hap AX3 can shine in speci...
by chechito
Sun Apr 23, 2023 10:15 pm
Forum: RouterBOARD hardware
Topic: hAP AX2 vs hAP AX3 CPU power
Replies: 11
Views: 5578

Re: hAP AX2 vs hAP AX3 CPU power

Well, official test results indicate 25% difference in real life (e.g. routing 25 filter rules, 512 byte packets: 1145Mbps ax3 VS 912Mbps ax2). Surely that's a lot less than the difference in CPU clock. But then routing (in v7 specially) can be memory-intensive and it's possible that RAM types (ena...
by chechito
Sun Apr 23, 2023 10:02 pm
Forum: RouterBOARD hardware
Topic: hAP AX2 vs hAP AX3 CPU power
Replies: 11
Views: 5578

Re: hAP AX2 vs hAP AX3 CPU power

i think ipsec tests reach the imposed limit of encryption engine before reaching cpu limit because of that the limits are the same
by chechito
Sun Apr 23, 2023 9:56 pm
Forum: RouterBOARD hardware
Topic: hAP AX2 vs hAP AX3 CPU power
Replies: 11
Views: 5578

Re: hAP AX2 vs hAP AX3 CPU power

published test cover some different scenarios: one of its is fast-path scenarios with big packets where you reach the limit of CPU to Switch interface the other scenarios are cpu taxing tasks where cpu becomes the limit this small CPU's have a narrow memory bus to be cheap and power efficient but th...
by chechito
Sun Apr 23, 2023 6:58 pm
Forum: General
Topic: how does L3HW actually works?
Replies: 128
Views: 33030

Re: how does L3HW actually works?

talking about bandwidth management... on a CRS-317 with ROS 7.6 runing a simple L3 HW offload with static routes all runing fine but ACL with Action= Rate (to do some bandwidth management) does not work ACL to drop traffic works ok with L3 HW offload similar ACL with Action= Rate (to do some bandwid...
by chechito
Fri Apr 21, 2023 7:17 pm
Forum: Beginner Basics
Topic: DHCP leasing to base address (offered, results without success)
Replies: 8
Views: 1641

Re: DHCP leasing to base address (offered, results without success)

in most cases, this symptom reflects that there are problems in the access network. Not the router
by chechito
Fri Apr 21, 2023 1:27 am
Forum: RouterBOARD hardware
Topic: RB4011iGS+5HacQ2HnD-IN with S+RJ10. Temperature problem
Replies: 9
Views: 2569

Re: RB4011iGS+5HacQ2HnD-IN with S+RJ10. Temperature problem

So, cannot install S-RJ10 in no one of MT with passive cooler. I search for heatsink but as i see it is apply in main surface (not this in outside): https://www.electronics-cooling.com/2016/07/pluggable-optics-modules-thermal-specifications-part-1/ The dimensions of these heatsink they don't fit in...
by chechito
Thu Apr 20, 2023 7:01 pm
Forum: General
Topic: Skins for winbox too?!?
Replies: 68
Views: 7228

Re: Skins for winbox too?!?

some days ago i tried Winbox Skin on a remote device and not worked, but reading this topic i tested on local device using 7.6 and worked OK, if i find why does not worked in my remote device i will post it
by chechito
Thu Apr 20, 2023 6:53 pm
Forum: General
Topic: Switch CRS518 100 Gbit interfaces function [SOLVED]
Replies: 3
Views: 488

Re: Switch CRS518 100 Gbit interfaces function [SOLVED]

is good to hear that MC-LAG/MLAG is working ok in your scenario
by chechito
Thu Apr 20, 2023 6:49 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+5HacQ2HnD-IN with S+RJ10. Temperature problem
Replies: 9
Views: 2569

Re: RB4011iGS+5HacQ2HnD-IN with S+RJ10. Temperature problem

is a very bad idea to match s+rj10 with a rb4011 or rb5009 compact passive cooled devices even worst on wifi version of 4011 s+rj10 gets very hot and it will transfer heat to the rb4011, maybe temperatures on rb4011 not rise so much but s+rj10 maybe gets hot beyond reliable operation, maybe internal...
by chechito
Wed Apr 19, 2023 8:08 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 425
Views: 140244

Re: v7.8 [stable] is released!

"Considerably slower" is relative to the hardware. My ARM, ARM64, and Tile boxes have seen significant improvements. Under 6.48.x my CCR1036 was showing 2-3% on 2Gbps of traffic. Now it shows 0% on the same traffic. take a look using tools profiling using ALL cores option to view individu...
by chechito
Wed Apr 19, 2023 7:50 pm
Forum: General
Topic: RouterOS on a CCR2004-1G-12S+2XS vs. VyOS on a SuperMicro SuperServer with 4 x 10 GBit Ethernet
Replies: 8
Views: 1624

Re: RouterOS on a CCR2004-1G-12S+2XS vs. VyOS on a SuperMicro SuperServer with 4 x 10 GBit Ethernet

i think CCR2004-1G-12S+2XS is a niche product designed to be a PoP simple router people often misconcept this product when see that ammount of SFP+ interfaces plus 2 SPF28 interfaces, look at it like a golden product to obtain a fiber switch plus a router for a cheap but it is neither of the two, mu...
by chechito
Wed Apr 19, 2023 7:16 pm
Forum: General
Topic: Switch CRS518 100 Gbit interfaces function [SOLVED]
Replies: 3
Views: 488

Re: Switch CRS518 100 Gbit interfaces function [SOLVED]

when you use the 100g interface only the first of four will be active

i dont know if you are the same user with another topic about CRS 518

in that scenario he is using a breakout DAC cable from 100g to 4 x 25g, maybe in that case the situation is different
by chechito
Wed Apr 19, 2023 7:01 pm
Forum: General
Topic: RouterOS on a CCR2004-1G-12S+2XS vs. VyOS on a SuperMicro SuperServer with 4 x 10 GBit Ethernet
Replies: 8
Views: 1624

Re: RouterOS on a CCR2004-1G-12S+2XS vs. VyOS on a SuperMicro SuperServer with 4 x 10 GBit Ethernet

Hey All, I need some advice for buying a new home router for my new house. I have the whole house CAT-7 cabling and 2 x 10 GBit Switches providing 1GBit/2.5GBit/5/10GBit for two isolated networks. Both Smart Managed, VLAN support and some SFP+ ports that are unused, as I don't have fiber lying in t...
by chechito
Tue Apr 18, 2023 10:42 pm
Forum: RouterBOARD hardware
Topic: hAP ax lite
Replies: 86
Views: 17689

Re: hAP ax lite

True but then you need to jump through additional hoops for setting up your own controller web interface, container, etc etc. I'll stick to wireguard, thankyouverymuch :lol: X2 !!! i agree with you there is too much hype with ZT, for those who want to use it fine, but for some people sometimes its ...
by chechito
Mon Apr 17, 2023 8:30 pm
Forum: RouterBOARD hardware
Topic: RouterOS v7.6 in CCR1072
Replies: 19
Views: 6211

Re: RouterOS v7.6 in CCR1072

if you have an issue with ccr1072, changing it for ccr2116/2216 will not resolve it
by chechito
Mon Apr 17, 2023 4:09 am
Forum: General
Topic: Block IP addresses based on their geographic location
Replies: 12
Views: 5809

Re: Block IP addresses based on their geographic location

1 - A script to block the IP addresses. https://forum.mikrotik.com/viewtopic.php?p=905420#p906705 2 - By adding the allowed address list that contains your location. https://mikrotikconfig.com/firewall/ https://www.iwik.org/ipcountry/ Wireguard https://forum.mikrotik.com/viewtopic.php?t=182340 Peer...
by chechito
Sat Apr 15, 2023 3:30 am
Forum: General
Topic: What model to use?
Replies: 34
Views: 2282

Re: What model to use?

YOu can limit speeds of several gigabits using CRS 3xx switches i have used CRS 317 with Routeros 7.6 to limit using Ingres ACL's rate parameter that way do not use CPU on switch and works ok With CRS 317 in L2 HW offload mode ingress ACL limit works OK, in L3 HW offload mode in 7.6 does NOT work, i...
by chechito
Sat Apr 15, 2023 12:56 am
Forum: Virtualization
Topic: CHR: number of CPUs limited to 64?
Replies: 5
Views: 7592

Re: CHR: number of CPUs limited to 64?

I think using separated sockets (NUMA Nodes) on a single VM can penalize your obtainable performance in fact a 64 Cores VM can be close to diminishing returns point most 64 core CPU's have a Lower Base Clock to keep Power and Heat under control, in some scenarios a high base clock 32 core CPU can le...
by chechito
Fri Apr 14, 2023 7:18 am
Forum: General
Topic: CCR1016-12G as PPPoE server bottleneck
Replies: 13
Views: 752

Re: CCR1016-12G as PPPoE server bottleneck

you can try some sort of load outbound balancing without using mangle rules using Route Rules
by chechito
Thu Apr 13, 2023 9:31 pm
Forum: General
Topic: A very simple redirect (to an http page) after join WiFi
Replies: 38
Views: 6441

Re: A very simple redirect (to an http page) after join WiFi

dhcp-option.png
raw value appear automatically after you sucesfull ingress a value

https://wiki.mikrotik.com/wiki/Manual:I ... er#Example
by chechito
Thu Apr 13, 2023 9:05 pm
Forum: General
Topic: CCR1016-12G as PPPoE server bottleneck
Replies: 13
Views: 752

Re: CCR1016-12G as PPPoE server bottleneck

i think you can try disabling fast-track, that combined with mangle does not work well

if you already disabled it please reboot to remove fast-track dummy rules
by chechito
Thu Apr 13, 2023 6:55 pm
Forum: General
Topic: CCR1016-12G as PPPoE server bottleneck
Replies: 13
Views: 752

Re: CCR1016-12G as PPPoE server bottleneck

maybe your ccr1016 does not have a bottleneck although you have stated that

maybe a miss-configuration specially on load balancing, maybe some internal network problem, maybe a some provider or providers problem
by chechito
Thu Apr 13, 2023 5:46 pm
Forum: General
Topic: CCR1016-12G as PPPoE server bottleneck
Replies: 13
Views: 752

Re: CCR1016-12G as PPPoE server bottleneck

you have too much features on a single router If you want more performance you must separate the wan load balance duties from PPPoE Router to a separate Router When you had the PPPoE router only doing that task you can run it on fast-path mode without connection-tracking, in that way you can obtain ...
by chechito
Wed Apr 12, 2023 4:54 am
Forum: RouterBOARD hardware
Topic: Does RB5009 bonding hardware offloading work or not? [SOLVED]
Replies: 5
Views: 3218

Re: Does RB5009 bonding hardware offloading work or not? [SOLVED]

according to documentation its supports Bridge Hardware Offloading https://help.mikrotik.com/docs/display/ROS/Bridging+and+Switching#BridgingandSwitching-BridgeHardwareOffloading beware of this: Only 802.3ad and balance-xor modes can be HW offloaded. Other bonding modes do not support HW offloading....
by chechito
Tue Apr 04, 2023 6:21 am
Forum: Beginner Basics
Topic: One Web Site 2 ISP
Replies: 11
Views: 1017

Re: One Web Site 2 ISP

if you are using PCC Per connection classifier

set the ValuesToHash to src-address
by chechito
Mon Apr 03, 2023 10:08 pm
Forum: Beginner Basics
Topic: 10 GbE Routing possible?
Replies: 6
Views: 1401

Re: 10 GbE Routing possible?

Is the CCR2204 more powerful than the RB5009 even though it is older? yes CCR2004 is superior to RB5009, in some scenarios can be up to 4x better, in other scenarios only a 30% better ccr2004 has some higher level licensing and other useful things If you really want much more processing power i sug...
by chechito
Mon Apr 03, 2023 7:53 pm
Forum: RouterBOARD hardware
Topic: CCR2004-16G-2S+PC NO USB, WHYYY!??
Replies: 28
Views: 7329

Re: CCR2004-16G-2S+PC NO USB, WHYYY!??

Hi there. I just want to share my frustration with the CCR2004-16G-2S+PC. I was super excited about it when I first saw it on the YouTube channel and now I have one. Currently I have a RB5009 running some containers and working as main home router, but I would like to have a second SPF+ just to con...
by chechito
Mon Apr 03, 2023 1:39 am
Forum: General
Topic: CRS125-24G-1S & RouterOS 7.x poor routing performance
Replies: 14
Views: 1283

Re: CRS125-24G-1S & RouterOS 7.x poor routing performance

RB4011 is a v6 device
Uh? https://mikrotik.com/product/rb4011igs_rm "v7 only"?

indeed Latest shipment of rb4011 comes with v7 preinstalled

9b16fb82-ec41-472d-8496-5139c490937a.jpg
by chechito
Sun Apr 02, 2023 12:44 am
Forum: Wireless Networking
Topic: Lower power on 2.4Ghz for better overall performance?
Replies: 2
Views: 1622

Re: Lower power on 2.4Ghz for better overall performance?

unfortunately in that scenario if you lower your power problem can be worst for you, if environment is already dirty you want to use the highest power possible in a way that neighbor AP can hear your AP transmiting and share some airtime for your devices you will never obtain a good performance in s...
by chechito
Sun Apr 02, 2023 12:14 am
Forum: Beginner Basics
Topic: Which router model for Internet Cafe (150 PCs)?
Replies: 8
Views: 1104

Re: Which router model for Internet Cafe (150 PCs)?

i5 - 7400 , 16g ram?

if you already have it available go with it, it will perform better than a rb4011/rb5009
by chechito
Sat Apr 01, 2023 8:47 pm
Forum: General
Topic: Dynamic ARP Inspection (DAI) configuration on RouterOS
Replies: 5
Views: 2338

Re: Dynamic ARP Inspection (DAI) configuration on RouterOS

Yes, Dynamic ARP Inspection (DAI), is another standard wide feature not supported by MikroTik switches i am very sure MikroTik has this in the radar I hope in close future we will see it but I think today the priority is towards Layer 3 Hardware Acceleration features which are too much more relevant...
by chechito
Sat Apr 01, 2023 4:34 am
Forum: General
Topic: Fasttracking using filter vs mangle
Replies: 4
Views: 2468

Re: Fasttracking using filter vs mangle

i think maybe it's not so relevant once the connection is marked for fasttrack, most of the subsequent packets of that connection are fast-tracked avoiding processing overhead, placement of fast-track rule does not change anything for those packet (most of them) Fast track rule placement only impact...
by chechito
Fri Mar 31, 2023 6:38 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 506891

Re: Using RouterOS to QoS your network - 2020 Edition

AFAIK QUIC traffic is on 443 UDP
by chechito
Fri Mar 31, 2023 7:07 am
Forum: General
Topic: pppoe client isolation
Replies: 12
Views: 1521

Re: pppoe client isolation

i think the most optimal way is:

no connection-tracking
fast-path mode on

for isolation use Route Rules
by chechito
Thu Mar 30, 2023 8:41 pm
Forum: General
Topic: Trouble with the "Out. Bridge Port" filter
Replies: 3
Views: 436

Re: Trouble with the "Out. Bridge Port" filter

Out. Bridge Port Filter works only when use-ip-firewall in bridge settings is enabled

Bridging and Switching
Bridge Settings
https://help.mikrotik.com/docs/display/ ... geSettings
by chechito
Thu Mar 30, 2023 8:23 pm
Forum: Wireless Networking
Topic: SXTR how to open the case sim card lost inside
Replies: 8
Views: 1117

Re: SXTR how to open the case sim card lost inside

most the time this devices are used outdoors

if you open the case be careful when closing it again, if not, you can damage the SXT when water finds its way inside
by chechito
Thu Mar 30, 2023 5:31 am
Forum: General
Topic: CRS326-24S+2Q fault light
Replies: 16
Views: 3422

Re: CRS326-24S+2Q fault light

/system health detect-fans solved the problem!

Faulty unit shows four fans in system health.
After detect-fan, I can see just three fans.

useful info, thank you for sharing
by chechito
Thu Mar 30, 2023 5:27 am
Forum: General
Topic: high CPU load of ssl when using SSTP
Replies: 2
Views: 671

Re: high CPU load of ssl when using SSTP

check your system certificate settings, try disabling CRL download, and disabling use CRL
by chechito
Thu Mar 30, 2023 5:24 am
Forum: General
Topic: SSL problem with EOIP over L2TP VPN [SOLVED]
Replies: 3
Views: 542

Re: SSL problem with EOIP over L2TP VPN [SOLVED]

try enabling CLAMP TCP MSS option
by chechito
Thu Mar 30, 2023 4:59 am
Forum: General
Topic: Link Aggregation Only Speeds up in One Direction
Replies: 16
Views: 2162

Re: Link Aggregation Only Speeds up in One Direction

Here is the relevant info, as far as I can find. There are only a few things that can be configured in the Synology NAS. I've attached the MT config file.
@dazzaling69

you must pay attention at mkx explanations, he has fully explained why you cannot achieve more speed
by chechito
Thu Mar 30, 2023 4:57 am
Forum: General
Topic: Link Aggregation Only Speeds up in One Direction
Replies: 16
Views: 2162

Re: Link Aggregation Only Speeds up in One Direction

You still didn't show exact configuration of both devices in question. Until you do, we can keep talking about weather ...

your patience is admirable
by chechito
Tue Mar 28, 2023 10:30 pm
Forum: RouterOS beta
Topic: IPv6 hw-offload on DHCP-PD routes
Replies: 4
Views: 2396

Re: IPv6 hw-offload on DHCP-PD routes

DHCP-PD routes show the HW Flag?
by chechito
Tue Mar 28, 2023 10:29 pm
Forum: General
Topic: Advice please CRS125-24G-1S-2HnD-IN or CRS326-24G-2S+IN [SOLVED]
Replies: 3
Views: 499

Re: Advice please CRS125-24G-1S-2HnD-IN or CRS326-24G-2S+IN [SOLVED]

i think CRS-125 is almost EOL go for the CRS-326
by chechito
Mon Mar 27, 2023 11:52 pm
Forum: RouterBOARD hardware
Topic: Please make a 6x100g switch...
Replies: 20
Views: 4181

Re: Please make a 6x100g switch...

so now you may understand that maybe they dont want to make it beyond the fact that can be made or not surelly if you put on advance an order for 10.000 units of that hypoteticall product they will think twice about it, not only for your personal lab needs is not the first time that in this forum so...
by chechito
Mon Mar 27, 2023 11:30 pm
Forum: RouterBOARD hardware
Topic: Please make a 6x100g switch...
Replies: 20
Views: 4181

Re: Please make a 6x100g switch...

i hope MikroTik is working on a 8 x 100g switch but it will take months to come, i think maybe until the next year, and off course it will be far more expensive adittionally an 8 x 100g switch puts MikroTik on a predicament, almost in the obligation to release a possible CCR2316 with 4 x 100g + 12 x...
by chechito
Mon Mar 27, 2023 11:22 pm
Forum: General
Topic: Modern way to stop ISP customers with WEB redirect
Replies: 9
Views: 816

Re: Modern way to stop ISP customers with WEB redirect

some times redirection works when you actively reject connection of clients who forgot to pay

change drop action to reject action using
reject-with=icmp-host-prohibited
tcp reset
can help too

you can try different options available on drop rule
by chechito
Mon Mar 27, 2023 6:13 pm
Forum: RouterBOARD hardware
Topic: Please make a 6x100g switch...
Replies: 20
Views: 4181

Re: Please make a 6x100g switch...

is interesting to see that while 98DX8525 in theory can do 6 x 100g that was not implemented, maybe is a power/size requirements thing maybe product segmentation to differentiate it enough from maybe a future 8 x 100g port device 4 x 100g fit for many scenarios, you just need to add a secondary swit...
by chechito
Mon Mar 27, 2023 6:03 pm
Forum: General
Topic: VLAN-based rate limits with many VLANs
Replies: 5
Views: 729

Re: VLAN-based rate limits with many VLANs

how much total bandwidth you have available? growt planned? that will be your parameter to define which router to use i dont think in this case a switch can do a proper job for a small installation with around 500mbps i think a rb5009 can do the job, for any bigger go with ccr2116 i look this scenar...
by chechito
Fri Mar 24, 2023 6:21 pm
Forum: General
Topic: CCR2216 / L3HW offload = no on WAN port / Simple Queue issues [SOLVED]
Replies: 3
Views: 579

Re: CCR2216 / L3HW offload = no on WAN port / Simple Queue issues [SOLVED]

No fast-track but I have just found the solution.. It was 2 fold. 1) IPv6 was being used and thus bypassing the IPv6 target on the simple queue.. Some Ookla servers supported IPv6 and some did not.. obviously the ones that DID support IPv6 were bypassing my original simple queue BECAUSE I had only ...
by chechito
Fri Mar 24, 2023 6:18 pm
Forum: RouterBOARD hardware
Topic: CCR1072/1036 vs. CCR2116 with 2000x PPPoE
Replies: 31
Views: 15271

Re: CCR1072/1036 vs. CCR2116 with 2000x PPPoE

I would dump PPPoE, but my radius/billing software is limited on other ways to AAA dhe dhcp clients. Same problem here..stuck on radius because of that. and you are not alone, is a very real often situation, but will be useful to put some pressure over radius/billing software vendors to fix this i ...
by chechito
Fri Mar 24, 2023 6:06 pm
Forum: General
Topic: How do we request for an account deletion?
Replies: 24
Views: 2381

Re: How do we request for an account deletion?

It would be good if we were more tolerant in this forum make it a nice site to share our findings and experiences with routeros countless times I have chosen not to post an answer, anticipating trolling or arrogant answers, is not worth it I include myself, we have fallen into following a trend towa...
by chechito
Wed Mar 22, 2023 6:52 pm
Forum: SwOS
Topic: SwitchOS not forwaring IPV6 packets from one CCR to another
Replies: 6
Views: 2490

Re: SwitchOS not forwaring IPV6 packets from one CCR to another

try enabling flood unknown multicast
by chechito
Wed Mar 22, 2023 3:11 am
Forum: General
Topic: Nasty issue with MAC address stuck on CRS504 with RoS >= 7.7
Replies: 5
Views: 778

Re: Nasty issue with MAC address stuck on CRS504 with RoS >= 7.7

MLAG issues have been seen sporadically at the forum, maybe not ready for production yet
by chechito
Mon Mar 20, 2023 4:40 pm
Forum: General
Topic: L3 Hardware Offloading with fast-track and NAT
Replies: 5
Views: 1744

Re: L3 Hardware Offloading with fast-track and NAT

i think need to try at least with 7.6 version
by chechito
Wed Mar 15, 2023 2:42 am
Forum: Beginner Basics
Topic: Bad performance (slow) of RB2011UAS-2HnD
Replies: 8
Views: 1420

Re: Bad performance (slow) of RB2011UAS-2HnD

keep in mind RB2011 is almost 10 years OLD

2023 hAP ax lite has better performance, and is cheaper with lower power consumption
by chechito
Tue Mar 14, 2023 4:04 am
Forum: General
Topic: PowerboxPro / QCA8337 - VLAN with HW offload possible?
Replies: 1
Views: 336

Re: PowerboxPro / QCA8337 - VLAN with HW offload possible?

in that devices is common to pass up to 500-600mbps of internet tráffic without problem by software bridging this is the most common scenario if you want to do it by hardware you can but only using eth1 to eth5, sfp interface is not inside the switching chip so any traffic to and/or from sfp interfa...
by chechito
Mon Mar 13, 2023 11:08 pm
Forum: Wireless Networking
Topic: Device cannot connect specifically to Mikrotik APs [SOLVED]
Replies: 5
Views: 1640

Re: Device cannot connect specifically to Mikrotik APs [SOLVED]

i think will be useful to enable more extensive logging on wireless topic
/system logging
add topics=wireless
in that way you can collect info at the moment your client device try to associate with the AP and the possible reason of failing to do so
by chechito
Sun Mar 12, 2023 11:24 pm
Forum: RouterBOARD hardware
Topic: 4x RB5009 in 1U how much heat does it create?
Replies: 2
Views: 1437

Re: 4x RB5009 in 1U how much heat does it create?

then you should also be concerned about the thermal contribution of the devices located above and below the 4 x rb5009 combo in each case there may be numerous variables that influence the final result off course you can't expect the same thermal behavior i think the most problematic situation is th...
by chechito
Sun Mar 12, 2023 6:06 pm
Forum: General
Topic: CCR2216 CPU UNBALANCED LOAD AFFECTING TRAFFIC
Replies: 21
Views: 3328

Re: CCR2216 CPU UNBALANCED LOAD AFFECTING TRAFFIC

i think you must return to ccr1072, usually newer platforms take months to optimize plus a new operating system version plus a new hardware architecture plus a new hardware offload using ASICs because of all this concurrent aggravating factors we can expect this process to be even more difficult tha...
by chechito
Sat Mar 11, 2023 5:43 pm
Forum: RouterBOARD hardware
Topic: CRS326-24G-2S+RM with 2.5GBit sfp+ possible?
Replies: 11
Views: 5782

Re: CRS326-24G-2S+RM with 2.5GBit sfp+ possible?

maybe Nbase-T support is not that far from 10GBase-T at the end 2.5g ang 5g are almost the same thing as 10gBaseT running at lower frequency Is true that many 10G baseT devices are incompatible with 2.5g or 5g BaseT, specially those on the early ages of 10G base T Compatibility guide gives us some l...
by chechito
Thu Mar 09, 2023 7:41 pm
Forum: Beginner Basics
Topic: CRS112-8G-4S: problem with Trunk to CCR1016-12G
Replies: 7
Views: 1036

Re: CRS112-8G-4S: problem with Trunk to CCR1016-12G

CRS1xx/CRS2xx series do not support hardware acceleration for typical bonding interface neither bridge vlan filtering Bonding configuration on CRS 1xx 2xx uses some kind of chip propietary mode which is not guarantee to be fully compatible with a different device, only guarantee work between 1xx/2xx...
by chechito
Thu Mar 09, 2023 7:30 pm
Forum: Wireless Networking
Topic: hAP ax3 CPU temp and performance [SOLVED]
Replies: 11
Views: 3670

Re: hAP ax3 CPU temp and performance [SOLVED]

state of art chips work well up to 90°C or even more without problem

please do not create duplicate topics
by chechito
Thu Mar 09, 2023 6:14 pm
Forum: Beginner Basics
Topic: QSFP Bonding
Replies: 17
Views: 2550

Re: QSFP Bonding

i think when you use a 40g or 100g link (not breakout cables) you only need to consider the first qsfp interface on configurations


do not expect a TCP test to be able to saturate such a "big" link, try udp test or traffic generator
by chechito
Thu Mar 09, 2023 6:12 pm
Forum: General
Topic: Spanning Tree Documentation - MSTP Example - Confusion
Replies: 2
Views: 649

Re: Spanning Tree Documentation - MSTP Example - Confusion

i think is better to start with a smaller topology (3 switches) to understand basic MSTP behavior

then

aditional switches to divide the lab in 2 regions and understand that specific aditional topic

i personally only have deployed small single region setups
by chechito
Thu Mar 09, 2023 6:06 pm
Forum: General
Topic: Terribly bad ingress shaping on CRS 317 and CRS326
Replies: 3
Views: 637

Re: Terribly bad ingress shaping on CRS 317 and CRS326

have you tried 7.6? which CRS 326 are you refering to?? CRS326-24G-2S+RM or CRS326-24S+2Q+RM When i was using Routeros 6.48.6 and 6.49.7 traffic shaping was erratic and a cause of service disruption when enabled so i avoided that feature Some weeks ago on a CRS 317 using only L2 VLan (no L3 HW offlo...
by chechito
Wed Mar 08, 2023 5:15 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 425
Views: 140244

Re: v7.8 [stable] is released!

What's the best way to monitor for issues with l3hw? Are there any counters I could watch or some other performance metrics? After a long break I've replaced an aging EdgeRouter 4 (behaving flawlessly save for lack of updates) with CCR2116 on 7.8 and started getting complaints of intermittent poor ...
by chechito
Tue Mar 07, 2023 4:42 pm
Forum: RouterBOARD hardware
Topic: RouterOS 7.8 bricked cAP XL ac
Replies: 14
Views: 5474

Re: RouterOS 7.8 bricked cAP XL ac

Aditional to previous good advice in the topic

For sucessful netinstall sometimes is useful to put a dumb switch between PC and Routerboard
by chechito
Mon Mar 06, 2023 6:10 pm
Forum: General
Topic: CCR2216 CPU Problem
Replies: 16
Views: 1941

Re: CCR2216 CPU Problem

by the way your configuration is build it will only works running by CPU, you must reconfigure using only bridge vlan filtering to be able to have the benefits of offloading if you already do that please post your "bridge vlan filtering" config and profile usage with it deployed additional...
by chechito
Sat Mar 04, 2023 6:16 pm
Forum: Beginner Basics
Topic: CRS326-24G-2S+ with two dhcp servers [SOLVED]
Replies: 13
Views: 1373

Re: CRS326-24G-2S+ with two dhcp servers [SOLVED]

Don't expect too much performance using CRS326-24G-2S+ as router doing Nat etc because it has a little cpu
by chechito
Sat Mar 04, 2023 5:58 pm
Forum: General
Topic: CCR2216 CPU Problem
Replies: 16
Views: 1941

Re: CCR2216 CPU Problem

Try using tools profile to obtain info About the CPU usage

Sometimes is better to use the setting "all" to see each core usage separately

Clicking on usage column header, allows You to sort by usage and see tasks with most usage at the top
by chechito
Fri Mar 03, 2023 3:35 pm
Forum: RouterBOARD hardware
Topic: hAP ax lite
Replies: 86
Views: 17689

Re: hAP ax lite

Hello,

does hAP AX Lite has IPSec/AES hw acceleration or not?

Thx.

not

not until now

but, even if that support is announced, dont expect it to be available inmediatly
by chechito
Fri Mar 03, 2023 12:22 am
Forum: RouterOS beta
Topic: L3HW Firewall Offloading - Doesn't Offload Inter-VLAN traffic [SOLVED]
Replies: 19
Views: 6764

Re: L3HW Firewall Offloading - Doesn't Offload Inter-VLAN traffic [SOLVED]

just today i deployed a CRS 317 doing inter VLAN routing with L3 HW offload 2 gbps of traffic with 1% of CPU usage, working ok with Ros 7.6

in my profile you can contact me to help you to solve the issue
by chechito
Thu Mar 02, 2023 9:29 pm
Forum: General
Topic: how does L3HW actually works?
Replies: 128
Views: 33030

Re: how does L3HW actually works?

I've read this thread multiples over the months. The real problem here is complexities and unclear visibility of this L3 offloading, what gets offloaded (routes), why, etc. We certainly don't have this much of a headache working with L3 offloading on other vendors. MikroTik needs to make some chang...
by chechito
Thu Mar 02, 2023 9:19 pm
Forum: General
Topic: CCR2216 CPU Problem
Replies: 16
Views: 1941

Re: CCR2216 CPU Problem

the point is that using vlan interfaces as ports inside the bridge since 6.41 are considered Layer2 misconfiguration Similar to this VLAN in a bridge with a physical interface https://help.mikrotik.com/docs/display/ROS/Layer2+misconfiguration#Layer2misconfiguration-VLANinabridgewithaphysicalinterfac...
by chechito
Thu Mar 02, 2023 5:38 pm
Forum: General
Topic: CCR2216 CPU Problem
Replies: 16
Views: 1941

Re: CCR2216 CPU Problem

L3HW Offload (FW - specific) doesn't work with VLANs. Submit a ticket, maybe we can get this pushed to high priority to get fixed. https://forum.mikrotik.com/viewtopic.php?t=193770 As you mentioned, there is hw operation with the bonding interface, but hw does not appear to be active for the vlan i...
by chechito
Thu Mar 02, 2023 5:36 pm
Forum: RouterBOARD hardware
Topic: 40G direct attach cable
Replies: 8
Views: 1737

Re: 40G direct attach cable

what you are requesting is some sort of passive or semmi passive splitter from 40g to 10g even though internally 40g works like a 4 x 10g connection is not a trivial task to split that i dont think you can do that without all the logic included on a switch is not that simple breakout cable relies on...
by chechito
Wed Mar 01, 2023 5:48 am
Forum: General
Topic: Hardware offloading for RB5009 or any RB series? [SOLVED]
Replies: 6
Views: 1211

Re: Hardware offloading for RB5009 or any RB series? [SOLVED]

Layer2 misconfiguration
VLAN in bridge with a physical interface
https://wiki.mikrotik.com/wiki/Manual:L ... _interface

Solution
To avoid compatibility issues you should use bridge VLAN filtering.
by chechito
Wed Mar 01, 2023 5:40 am
Forum: General
Topic: FQ_Codel and Mikrotik CCR CPU Utilization
Replies: 39
Views: 6721

Re: FQ_Codel and Mikrotik CCR CPU Utilization

i agree about limited single core performance on Tile Architecture, but in the test realized by sirbryan he replicated the situation in a rb4011 which has much better single core performance (it has OoO A15 CPU) at a rate normal for that router doing shapping 200-300mbps
by chechito
Mon Feb 27, 2023 6:48 pm
Forum: RouterBOARD hardware
Topic: CCR2116-12G-4S hotspot
Replies: 3
Views: 1435

Re: CCR2116-12G-4S hotspot

i think 2116 can be a good upgrade, just keep in mind that CCR2116 only works on RouterOS Version 7.x if you already have your RB1100 setup working on V 7.x is a good idea but if you are on RouterOS 6.xx you must test your setup on V7.xx before on lab environment to be sure you can migrate to CCR211...
by chechito
Mon Feb 27, 2023 12:30 am
Forum: General
Topic: clear mkt router memory
Replies: 1
Views: 286

Re: clear mkt router memory

check tools-graphing
by chechito
Mon Feb 20, 2023 6:23 pm
Forum: RouterOS beta
Topic: L3HW Firewall Offloading - Doesn't Offload Inter-VLAN traffic [SOLVED]
Replies: 19
Views: 6764

Re: L3HW Firewall Offloading - Doesn't Offload Inter-VLAN traffic [SOLVED]

@IPANetEngineer

thank you for your answer
by chechito
Mon Feb 20, 2023 6:08 pm
Forum: RouterOS beta
Topic: L3HW Firewall Offloading - Doesn't Offload Inter-VLAN traffic [SOLVED]
Replies: 19
Views: 6764

Re: L3HW Offloading - Doesn't Offload Inter-VLAN traffic [SOLVED]

One thing that would help to disambiguate: l3 hw offload - stateless offload of IPv4/IPv6 routes into hardware l3 fw offload - stateful offload of IPv4 connections and NAT (IPv6 fastpath/fasttrack yet to be implemented) Brief list of what we discovered with fw offload in our lab and in prod for an ...
by chechito
Mon Feb 20, 2023 3:21 pm
Forum: General
Topic: storm-rate and ingress/egress rate limits Traffic-Storm-Control
Replies: 9
Views: 2778

Re: storm-rate and ingress/egress rate limits Traffic-Storm-Control

Try ingress ACL to apply the limits, i made some test with 7.6 on CRS 317 and looks like it worked
by chechito
Mon Feb 20, 2023 9:45 am
Forum: RouterOS beta
Topic: L3HW Firewall Offloading - Doesn't Offload Inter-VLAN traffic [SOLVED]
Replies: 19
Views: 6764

Re: L3HW Offloading - Doesn't Offload Inter-VLAN traffic [SOLVED]

Try rebooting

Try disabling ando enabling Global L3 hw offload on switch

Maybe reboot again
by chechito
Mon Feb 20, 2023 8:55 am
Forum: RouterOS beta
Topic: L3HW Firewall Offloading - Doesn't Offload Inter-VLAN traffic [SOLVED]
Replies: 19
Views: 6764

Re: L3HW Offloading - Doesn't Offload Inter-VLAN traffic [SOLVED]

try removing this
/interface bridge settings
set use-ip-firewall=yes use-ip-firewall-for-pppoe=yes use-ip-firewall-for-vlan=yes
EDIT
and maybe try adding this
/interface ethernet switch
set 19 l3-hw-offloading=yes
by chechito
Mon Feb 20, 2023 7:53 am
Forum: Virtualization
Topic: CHR Hardware for PPPoE server for 2 Lakh Subscribers
Replies: 8
Views: 3241

Re: CHR Hardware for PPPoE server for 2 Lakh Subscribers

i dont think that more than 25.000 concurrent users per BNG PPPoE server can be a good idea

You can Virtualize several of this BNG on a server capable of doing that massive task, maybe a server of 32 cores (Only real Performance cores not eficiency intel cores)
by chechito
Mon Feb 20, 2023 7:46 am
Forum: General
Topic: CRS326-24S+2Q+ : 100% CPU utilization bridging when a port goes up or down
Replies: 10
Views: 1921

Re: CRS326-24S+2Q+ : 100% CPU utilization bridging when a port goes up or down

you are adding 4.000 VLAN tagged to an interface?, can you explain that?
by chechito
Sat Feb 18, 2023 6:01 am
Forum: General
Topic: CCR2216 CPU UNBALANCED LOAD AFFECTING TRAFFIC
Replies: 21
Views: 3328

Re: CCR2216 CPU UNBALANCED LOAD AFFECTING TRAFFIC

your stable CCR1072 setup is running RouterOS 6 or 7 ?
by chechito
Fri Feb 17, 2023 4:59 am
Forum: General
Topic: storm-rate and ingress/egress rate limits Traffic-Storm-Control
Replies: 9
Views: 2778

Re: storm-rate and ingress/egress rate limits Traffic-Storm-Control

pleaso confirm what version of routeros are you running on your CRS 317
by chechito
Wed Feb 15, 2023 9:22 pm
Forum: Scripting
Topic: Detect device that take down network
Replies: 4
Views: 1282

Re: Detect device that take down network

that kind of problem must be mitigated in access layer (manged switches and/or wireless access-points), the scope of actions you can do from main router is very limited
by chechito
Wed Feb 15, 2023 5:54 pm
Forum: RouterBOARD hardware
Topic: CCR2004-16G-2S+PC NO USB, WHYYY!??
Replies: 28
Views: 7329

Re: CCR2004-16G-2S+PC NO USB, WHYYY!??

also retiring UBS deducts some watts from device power budget, another reason to opt on removing it, specially on a passive cooled device
by chechito
Wed Feb 15, 2023 5:50 pm
Forum: RouterBOARD hardware
Topic: Stability of higher max clock speed with newer OmniTIK boards
Replies: 1
Views: 1047

Re: Stability of higher max clock speed with newer OmniTIK boards

i think that kind of devices do not benefit too much from increased CPU clock speed because already starved on memory bus bandwidth
by chechito
Tue Feb 14, 2023 5:26 pm
Forum: RouterBOARD hardware
Topic: hAP ax lite
Replies: 86
Views: 17689

Re: hAP ax lite

specs says
Operating System	RouterOS v7
obviously a new product will not be ported to old software
by chechito
Tue Feb 14, 2023 5:03 pm
Forum: General
Topic: Is hAP ax² enough for 2WANs + 2LANs 1Gbps each?
Replies: 22
Views: 1631

Re: Is hAP ax² enough for 2WANs + 2LANs 1Gbps each?

for that situation i think you better consider RB5009
by chechito
Fri Feb 10, 2023 7:19 pm
Forum: General
Topic: Switch rule except mac syntax?
Replies: 12
Views: 976

Re: Switch rule except mac syntax?

i think another approach can be:
first rule to allow only that mac
second rule to drop any other mac
by chechito
Tue Feb 07, 2023 6:27 pm
Forum: General
Topic: Hardware offloading FastTrack on CRS354 not happening
Replies: 6
Views: 1402

Re: Hardware offloading FastTrack on CRS354 not happening

check this Offloading Fasttrack Connections https://help.mikrotik.com/docs/display/ROS/L3+Hardware+Offloading#L3HardwareOffloading-OffloadingFasttrackConnections info you found on wiki.mikrotik.com is legacy documentation L3 Hardware offloading is a new feature, so is better to stick with help.mikro...
by chechito
Sat Feb 04, 2023 3:22 pm
Forum: General
Topic: Radius Queue Problem
Replies: 6
Views: 885

Re: Radius Queue Problem

you can write a script to periodically disable queues, you can use certain conditions to choose which queues to disable
by chechito
Sat Feb 04, 2023 2:21 am
Forum: General
Topic: Wireguard Config File
Replies: 10
Views: 7939

Re: Wireguard Config File

first google search result of : wireguard qr code generator

https://www.wireguardconfig.com/qrcode
by chechito
Wed Feb 01, 2023 10:22 pm
Forum: RouterBOARD hardware
Topic: hAP ax lite
Replies: 86
Views: 17689

Re: hAP ax lite

will be nice to test this hAP ax lite wifi 6 with a client device like ESP32-C6 Wi-Fi 6
by chechito
Tue Jan 31, 2023 4:08 pm
Forum: General
Topic: High Density Scenario - 30k client
Replies: 11
Views: 2012

Re: High Density Scenario - 30k client

Divide-and-conquer

do not concentrate a labor on a single device, when you can is better to have multiple devices to distribute the load specially at the access layer
by chechito
Tue Jan 31, 2023 1:08 am
Forum: Wireless Networking
Topic: My experience and issues in hi-density networks at school [SOLVED]
Replies: 75
Views: 14148

Re: My experience and issues in hi-density networks at school [SOLVED]

I haven't used capsman for some time

but with all the recent changes i bet you will be better with a 6.xx version you validated and tested stable and stay with it as long as your devices supports it, until we see how capsman evolve in 7.x and wave2 era
by chechito
Sat Jan 28, 2023 12:25 am
Forum: Wireless Networking
Topic: WIFI 6 Roadmap
Replies: 199
Views: 144531

Re: WIFI 6 Roadmap

Not sure I understand the post above me... I have a Cambium XE3-4. And I can confirm that my Google Pixel 6 Pro connects to the 6E from my wireless access point. Mikrotik RB5009 + Mikrotik CRS326-24G+2S-RM + Mikrotik S+RJ10 + Cambium L142A + Cambium XE3-4 My phone also connected to a Netgear WAX630...
by chechito
Fri Jan 27, 2023 7:54 pm
Forum: Beginner Basics
Topic: VLAN by MAC on CCR2004?
Replies: 9
Views: 1990

Re: VLAN by MAC on CCR2004?

by chechito
Fri Jan 27, 2023 7:46 pm
Forum: Beginner Basics
Topic: Mikrotik hotel guest device [SOLVED]
Replies: 8
Views: 1468

Re: Mikrotik hotel guest device [SOLVED]

Power via USB ... check the Mikrotik MQS. Works fine with power bank+ hAP ac Lite. I can even add mAP Lite at the PoE out port of the hAP ac Lite, all powered at the same time. Or just powerbank+mAP Lite for the lightweight travel set. (Config of the mAP Lite is a bit complex, if no ethernet or MQS...
by chechito
Fri Jan 27, 2023 6:07 am
Forum: General
Topic: Newbie-- Recursive Routes-- Mangle -- Fasttrack?
Replies: 5
Views: 702

Re: Newbie-- Recursive Routes-- Mangle -- Fasttrack?

Newbie-- Recursive Routes-- Mangle -- Fasttrack? = Problems
by chechito
Fri Jan 27, 2023 4:33 am
Forum: General
Topic: Speed Test over 40Gbps QSFP28 link slow
Replies: 3
Views: 751

Re: Speed Test over 40Gbps QSFP28 link slow

https://help.mikrotik.com/docs/display/ROS/Bandwidth+Test Bandwidth Test uses a lot of resources. If you want to test real throughput of a router, you should run bandwidth test through the tested router not from or to it. To do this you need at least 3 routers connected in chain: the Bandwidth Serve...
by chechito
Fri Jan 27, 2023 1:39 am
Forum: General
Topic: How to make sure that a Mikrotik machine is not compromised
Replies: 4
Views: 903

Re: How to make sure that a Mikrotik machine is not compromised

if you are so security concerned the first thing you need to do is to buy equipment directly from official distributors you are self exposing you to supply chain problems and after that looking for a fix for it, so fix the problem at their origin the fact of trying to change factory version informat...
by chechito
Fri Jan 27, 2023 1:35 am
Forum: General
Topic: Speed Test over 40Gbps QSFP28 link slow
Replies: 3
Views: 751

Re: Speed Test over 40Gbps QSFP28 link slow

bandwidth test run using CPU

switches have an small CPU only for management

for testing 40g you will need several servers on each end of the link to generate traffic
by chechito
Thu Jan 26, 2023 7:48 pm
Forum: Forwarding Protocols
Topic: Unicast Reverse Path Forwarding
Replies: 10
Views: 12346

Re: Unicast Reverse Path Forwarding

rp-filter in Loose mode does not help?
by chechito
Thu Jan 26, 2023 5:10 am
Forum: General
Topic: Best Bandwidth Solution [SOLVED]
Replies: 6
Views: 1119

Re: Best Bandwidth Solution [SOLVED]

if you configure the burst-threshold value significantly below max-limit value that do not happen

if you use a burst-threshold value between burst-limit and max-limit is when you end up in the situation you refer to @TomjNorthIdaho
by chechito
Thu Jan 26, 2023 4:21 am
Forum: General
Topic: Best Bandwidth Solution [SOLVED]
Replies: 6
Views: 1119

Re: Best Bandwidth Solution [SOLVED]

When an ISP has bandwidth bursting configured to their customers , many ( if not all ) customers maxing out their accounts for the bandwidth they have purchased will see their video quality get better, then get worse, then get better, then get worse and sometimes see temporarily frozen video ( or s...
by chechito
Thu Jan 26, 2023 3:10 am
Forum: Wireless Networking
Topic: WIFI 6 Roadmap
Replies: 199
Views: 144531

Re: WIFI 6 Roadmap

I have a Unifi Enterprise AP with an SSID set to 6Ghz and a unique SSID tied only to it along with a Google Pixel 6. I can confirm it does not detect the WIFI 6E SSID.
try setting the same ssid available on 5ghz and 2ghz radio
by chechito
Tue Jan 24, 2023 11:20 pm
Forum: The Dude
Topic: The Dude: Large scale setup. Improved performance. No timeouts.
Replies: 8
Views: 5154

Re: The Dude: Large scale setup. Improved performance. No timeouts.

very useful info, thank you for sharing 8)
by chechito
Tue Jan 24, 2023 5:01 pm
Forum: Announcements
Topic: v7.7 [stable] is released!
Replies: 357
Views: 114085

Re: v7.7 [stable] is released!

Almost 5 days from my initial report for "very weird" memory usage (which I strongly believe to be a memory leak) starting on v7.7, confirmed by other users here, some reports of it really looking to be DNS resolver related, support ticket alteady opened, at least one user already posted ...
by chechito
Mon Jan 23, 2023 10:30 pm
Forum: The Dude
Topic: The Dude: Large scale setup. Improved performance. No timeouts.
Replies: 8
Views: 5154

Re: The Dude: Large scale setup. Improved performance. No timeouts.

how much chart Keep time you use for:

Raw value:
10 min value:
2 hour value:
1 day value:

Using the windows client to visualize a history graph of a service or a device , have you had trouble when visualizing several days graph?
by chechito
Mon Jan 23, 2023 10:14 pm
Forum: The Dude
Topic: The Dude: Large scale setup. Improved performance. No timeouts.
Replies: 8
Views: 5154

Re: The Dude: Large scale setup. Improved performance. No timeouts.

useful info

thank you for sharing !!! :wink:
by chechito
Mon Jan 23, 2023 9:03 pm
Forum: General
Topic: best pratice after lot of upgrades
Replies: 5
Views: 565

Re: best pratice after lot of upgrades

i normally do not try or install every release on production equipment unless a feature or a fix obliges me to do it, for example in RouterOS 6.x i was on 6.40.8 or 6.40.9 until new bridge vlan filter implementation was mature, then i jumped to 6.42.12, then 6.43.1, then 6.44.6, then 6.46.8, then 6....
by chechito
Mon Jan 23, 2023 5:35 pm
Forum: Announcements
Topic: v7.8beta [testing] is released!
Replies: 307
Views: 76559

Re: v7.8beta [testing] is released!

which comes from acquisition of Meru Networks
by chechito
Mon Jan 23, 2023 5:17 pm
Forum: RouterOS beta
Topic: 7.8beta2 adds new package ROSE-storage
Replies: 67
Views: 27348

Re: 7.8beta2 adds new package ROSE-storage

OMG great features !!!
by chechito
Sun Jan 22, 2023 5:26 pm
Forum: General
Topic: Pros/Cons using RAW vs Filter [SOLVED]
Replies: 36
Views: 5591

Re: Pros/Cons using RAW vs Filter [SOLVED]

About this matter I have a doubt: Doing Traffic filtering on a switch by using Hardware ACLs before traffic reach the router can be a feasible way to firewall a router without loosing the high performance fast-path mode? Read the official explanation: https://help.mikrotik.com/docs/display/ROS/Brid...
by chechito
Sun Jan 22, 2023 5:19 pm
Forum: General
Topic: Pros/Cons using RAW vs Filter [SOLVED]
Replies: 36
Views: 5591

Re: Pros/Cons using RAW vs Filter [SOLVED]

@chechito: it is an excellent way to filter the router, but you need an extra device to do that, and you should have a switch that supports an high number of rules. They are stateless rules and works at wire-speed. Thinking about that another approach can be using the newer 2116/2216 which have an ...
by chechito
Sun Jan 22, 2023 5:18 am
Forum: General
Topic: Pros/Cons using RAW vs Filter [SOLVED]
Replies: 36
Views: 5591

Re: Pros/Cons using RAW vs Filter [SOLVED]

About this matter

I have a doubt:

Doing Traffic filtering on a switch by using Hardware ACLs before traffic reach the router can be a feasible way to firewall a router without loosing the high performance fast-path mode?
by chechito
Sun Jan 22, 2023 1:10 am
Forum: General
Topic: Locked out!
Replies: 16
Views: 1924

Re: Locked out!

if you see the device in ip neighbors maybe you can try mac telnet
by chechito
Sun Jan 22, 2023 1:09 am
Forum: Announcements
Topic: v7.7 [stable] is released!
Replies: 357
Views: 114085

Re: v7.7 [stable] is released!

I disabled DNS, reboot MT and problem was solved. /ip dns set allow-remote-requests=no cache-max-ttl=1w cache-size=2048KiB max-concurrent-queries=100 \ max-concurrent-tcp-sessions=20 max-udp-packet-size=4096 query-server-timeout=2s query-total-timeout=10s \ servers="" use-doh-server="...
by chechito
Sun Jan 22, 2023 1:01 am
Forum: RouterOS beta
Topic: Feature request: changing default bucket size
Replies: 10
Views: 2570

Re: Feature request: changing default bucket size

you can use a script to mass change all your queues bucket size to the value of your preference
@chechito, do not lost your time again
viewtopic.php?p=944759#p943984
He's just a troll.

Roger That 8)
dont_feed_the_troll.png
by chechito
Sat Jan 21, 2023 4:14 pm
Forum: General
Topic: On X86 IPv4 Fast Path Issue
Replies: 1
Views: 321

Re: On X86 IPv4 Fast Path Issue

i think fast-path is hardware dependent due to variety of x86 hardware possible combinations i dont think will be feasible so for fast-path deployments a fast routerboard can blow an x86 machine x86 can be more useful for heavy processing scenarios in "slow" path, for example heavy queuing
by chechito
Sat Jan 21, 2023 4:10 pm
Forum: RouterOS beta
Topic: Feature request: changing default bucket size
Replies: 10
Views: 2570

Re: Feature request: changing default bucket size

you can use a script to mass change all your queues bucket size to the value of your preference
by chechito
Sat Jan 21, 2023 4:06 pm
Forum: General
Topic: Pros/Cons using RAW vs Filter [SOLVED]
Replies: 36
Views: 5591

Re: Pros/Cons using RAW vs Filter [SOLVED]

If you do not drop, for example DDoS attack on RAW side, it consume also: connection-tracking resources (when is enabled) mangle on prerouting resources (when are present) dst-nat resources (when are present) bridge resources (if involved) cpu resources to subtract -1 to TTL (or drop packet) again ...
by chechito
Sat Jan 21, 2023 3:59 pm
Forum: Announcements
Topic: v7.7 [stable] is released!
Replies: 357
Views: 114085

Re: v7.7 [stable] is released!

I disabled "Allow Remote Requests" and configured provider's DNS server for clients. But the problem remained. In one hour, 1 MB of memory has leaked and continues to leak. . If you didn't try it, try rebooting the MK box after disabling "allow remote requests" just to "cle...
by chechito
Fri Jan 20, 2023 4:20 pm
Forum: Announcements
Topic: v7.7 [stable] is released!
Replies: 357
Views: 114085

Re: v7.7 [stable] is released!

i have 6 simple queues, traditional queue types: pcq, pfifo, maybe if you are using some new type of queue
by chechito
Fri Jan 20, 2023 4:09 pm
Forum: Announcements
Topic: v7.7 [stable] is released!
Replies: 357
Views: 114085

Re: v7.7 [stable] is released!

ROS 7.7 hAP ac2 Constantly linear increase in memory usage daily.gif Earlier in the logs, I saw messages that there was not enough memory and a reboot with a kernel error. Logs are not saved. Now I'm monitoring the situation. i have a pair of hap ac2 with 7.7 with a basic configuration and dont exi...
by chechito
Wed Jan 18, 2023 7:13 am
Forum: Beginner Basics
Topic: When unlocking port 80 on NAT some sites do not work
Replies: 7
Views: 675

Re: When unlocking port 80 on NAT some sites do not work

the nowadays very common practice of doing nat without specifying interface

thank you for sharing the solution
by chechito
Wed Jan 18, 2023 1:25 am
Forum: General
Topic: What's wrong with PPTP-CLIENT on Routeros 7 ?
Replies: 3
Views: 1137

Re: What's wrong with PPTP-CLIENT on Routeros 7 ?

thank you for sharing
by chechito
Tue Jan 17, 2023 9:58 pm
Forum: General
Topic: Multiple l2tp login with same user
Replies: 1
Views: 462

Re: Multiple l2tp login with same user

try changing static ip adressing to dynamic ip adressing
by chechito
Tue Jan 17, 2023 9:36 pm
Forum: General
Topic: Vsol Interface Error CRS317 RoSv7
Replies: 3
Views: 387

Re: Vsol Interface Error CRS317 RoSv7

have you tryed V7.6 and V7.7 ?
by chechito
Tue Jan 17, 2023 4:51 pm
Forum: RouterBOARD hardware
Topic: CCR1036 -12G-4S not starting after reboot. [SOLVED]
Replies: 4
Views: 1575

Re: CCR1036 -12G-4S not starting after reboot. [SOLVED]

beautiful machines, a truly workhorse for years, going to some repair and still going
by chechito
Tue Jan 17, 2023 4:49 pm
Forum: General
Topic: Vsol Interface Error CRS317 RoSv7
Replies: 3
Views: 387

Re: Vsol Interface Error CRS317 RoSv7

when you Upgrade to routeros 7.x you upgraded routerboot too?

(routerboot is located under system routerboard menu, you must have the actual version in current and upgrade)
routerboot.png
by chechito
Mon Jan 16, 2023 8:23 pm
Forum: RouterBOARD hardware
Topic: CCR1036 -12G-4S not starting after reboot. [SOLVED]
Replies: 4
Views: 1575

Re: CCR1036 -12G-4S not starting after reboot. [SOLVED]

thank you for sharing
by chechito
Mon Jan 16, 2023 4:42 pm
Forum: Beginner Basics
Topic: Hardware offload in 7.3.1 on Hex S
Replies: 11
Views: 3864

Re: Hardware offload in 7.3.1 on Hex S

is not the same game

CCR 2116 and 2216 hardware offload is using Marvell Switching ASIC's
CRS 3xx and 5xx Switch hardware offload is using Marvell Switching ASIC's too

Hex-S uses a MediaTek SoC (different vendor) so enabling hardware offload on that chip need a separate development
by chechito
Mon Jan 16, 2023 4:36 pm
Forum: RouterBOARD hardware
Topic: What m2 to add to a CCR2216 switch
Replies: 5
Views: 1753

Re: What m2 to add to a CCR2216 switch

If high disk bandwidth is a MUST! - CCR2116-12G-4S+ is equipped with 1x M.2 slot with 4xPCIe3.0 lanes.
CCR2116-12G-4S+ supports Current PCIe NVMe drives ? classic PCIe AHCI drives ? or both ?
by chechito
Thu Jan 12, 2023 2:16 am
Forum: RouterBOARD hardware
Topic: RB750gr3 bricked after failed upgrade
Replies: 6
Views: 2146

Re: RB750gr3 bricked after failed upgrade

put a dumb switch between your PC and MikroTik ROuter, that can help to make Netinstall see the router to recover

dont forget to disconnect PC from any other network connection including virtual interfaces
by chechito
Thu Jan 12, 2023 12:40 am
Forum: Beginner Basics
Topic: Breakout cable settings for CRS504-4XQ-IN
Replies: 3
Views: 1990

Re: Breakout cable settings for CRS504-4XQ-IN

take a look at this info


MikroTik SFP module compatibility table
https://wiki.mikrotik.com/wiki/MikroTik ... lity_table

QSFP+/QSFP28 interface supported link rates
https://wiki.mikrotik.com/wiki/MikroTik ... link_rates
by chechito
Wed Jan 11, 2023 10:50 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+RM power consumption
Replies: 7
Views: 1846

Re: RB4011iGS+RM power consumption

DC 12V 2A worked not stable and with errors. i think you are at the lower edge of supported voltages, i think is better to stick with 24volts for PoE and at least 18-19volts on jack for reliable operation if you are trying a 12volt adapter, normal voltage drop because rb4011 can ramp up to 1.5 amp ...
by chechito
Wed Jan 11, 2023 7:48 pm
Forum: Wireless Networking
Topic: Capsman performance degradation due to many clients?
Replies: 10
Views: 1390

Re: Capsman performance degradation due to many clients?

you can influence cliente behavior on AP selection whit:

AP physical location
AP TX power
Taking advantage of environment to limit AP coverage

Last resort will be Access-lists, be ware of testing them properly to avoid degrading user experience
by chechito
Wed Jan 11, 2023 7:18 pm
Forum: General
Topic: Configuration for QSFP+ Breakout to 4xSFP+
Replies: 4
Views: 1278

Re: Configuration for QSFP+ Breakout to 4xSFP+

be aware a bonding interface on 2004 will run on software, not hardware accelerated
by chechito
Sat Jan 07, 2023 7:54 pm
Forum: General
Topic: Percentage IN PCC Load Balancd [SOLVED]
Replies: 8
Views: 1434

Re: Percentage IN PCC Load Balancd [SOLVED]

Wan1 5/0
Wan1 5/1
Wan1 5/2
Wan1 5/3
Wan2 5/4

Using PCC
by chechito
Sat Jan 07, 2023 7:50 pm
Forum: RouterBOARD hardware
Topic: CCR2004-1G-12S-2XS - are there any "before you buy" caveats?
Replies: 8
Views: 3228

Re: CCR2004-1G-12S-2XS - are there any "before you buy" caveats?

If You have the budget make yourself a favor Get ccr2116, You Will not regret it, 995usd of the Best MikroTik can deliver I'm not saying 2004 is a Bad product, but from a ccr1009 i don't think is a relevant upgrade If You still on buying a ccr 2004 get 16g versión no PC CCR2004-1G-12S+2XS is a niche...
by chechito
Fri Jan 06, 2023 12:20 am
Forum: General
Topic: Add /32 routes on DHCP leases
Replies: 8
Views: 1236

Re: Add /32 routes on DHCP leases

i guess /32 route creation is to propagate it on IGP
by chechito
Thu Jan 05, 2023 6:19 pm
Forum: General
Topic: IPv6 - Multiple bridges with only /64 from ISP [SOLVED]
Replies: 38
Views: 4095

Re: IPv6 - Multiple bridges with only /64 from ISP [SOLVED]

It's a shame that LACNIC's prices are not so pleasant.
by chechito
Thu Jan 05, 2023 6:15 pm
Forum: RouterBOARD hardware
Topic: hAP ax lite / L41G-2axD
Replies: 3
Views: 1818

Re: hAP ax lite / L41G-2axD

We'll see how much the price goes up.
by chechito
Thu Jan 05, 2023 6:03 pm
Forum: General
Topic: IPv6 - Multiple bridges with only /64 from ISP [SOLVED]
Replies: 38
Views: 4095

Re: IPv6 - Multiple bridges with only /64 from ISP [SOLVED]

i think the "single bridge" thing is very relevant mostly on new equipment which includes an integrated Switch like ccr2116/2216 i have the same habit of using a bridge for wan interface even when using only a single port as a useful tool to do some L2 trouble-shooting, if you dont enable ...
by chechito
Thu Jan 05, 2023 4:50 am
Forum: Wireless Networking
Topic: WIFI 6 Roadmap
Replies: 199
Views: 144531

Re: WIFI 6 Roadmap

one example of wifi6 for iot only on 2.4ghz

https://www.espressif.com/en/news/ESP32_C6
by chechito
Wed Jan 04, 2023 1:56 am
Forum: RouterBOARD hardware
Topic: CCR2216-1G-12XS-2XQ NAT stats
Replies: 3
Views: 1564

Re: CCR2216-1G-12XS-2XQ NAT stats

I guess my question is could this be used as a ISP core router running CGNAT? i think its a bad idea, why?: because CG-NAT will be done by Software using CPU on Fast_track mode with many connections tracked beyond what 2 2 16 can do with hardware offload i think 2 2 16 is suited for a specific role...
by chechito
Mon Jan 02, 2023 9:58 pm
Forum: General
Topic: HEX (RB750Gr3) VPN choice
Replies: 8
Views: 2557

Re: HEX (RB750Gr3) VPN choice

keep in mind small routers like 750gr3 are designed to be a small Branch VPN client router, not a VPN concentrator for multiple branches if your VPN traffic scale UP you will quickly end up limited by CPU and/or by HW offload engine, when that happen you will need to upgrade to upper tier device lik...
by chechito
Mon Jan 02, 2023 8:12 pm
Forum: General
Topic: Could add new queue tree: too many packet marks in system
Replies: 10
Views: 1573

Re: Could add new queue tree: too many packet marks in system

i suggest you consider another scheme

i have tested up to 30k simple queues OK so you have a possible alternative
by chechito
Mon Jan 02, 2023 8:11 pm
Forum: General
Topic: Could add new queue tree: too many packet marks in system
Replies: 10
Views: 1573

Re: Could add new queue tree: too many packet marks in system

i can only say two things
OMG
WTF
by chechito
Sun Jan 01, 2023 10:39 pm
Forum: Beginner Basics
Topic: Out of box line speed or fastrak\fastpath?
Replies: 2
Views: 471

Re: Out of box line speed or fastrak\fastpath?

be aware of this block diagrams

Image

Image
by chechito
Sun Jan 01, 2023 1:53 am
Forum: General
Topic: Happy New Year ☃ ✨
Replies: 5
Views: 705

Re: Happy New Year ☃ ✨

Happy new year to all Forum Members !!! 8) :mrgreen: :twisted:
by chechito
Sat Dec 31, 2022 3:08 am
Forum: RouterBOARD hardware
Topic: CCR2004-1G-2XS-PCIe in a box :)
Replies: 6
Views: 2112

Re: CCR2004-1G-2XS-PCIe in a box :)

thank you for sharing :idea:
by chechito
Fri Dec 30, 2022 9:40 pm
Forum: General
Topic: Ratelimit gig levels on 1072
Replies: 1
Views: 282

Re: Ratelimit gig levels on 1072

doing that with only CPU muscle do not scale

you must use an ASIC so the most feasible alternative is to use an aditional Switch
by chechito
Fri Dec 30, 2022 2:42 pm
Forum: Wireless Networking
Topic: About MESH with Mikrotik devices [SOLVED]
Replies: 6
Views: 2667

Re: About MESH with Mikrotik devices [SOLVED]

Try the wireless repeater setting to connect the hap mini to hap ac lite
by chechito
Thu Dec 29, 2022 10:46 pm
Forum: General
Topic: NAT Issues every 10-14 days
Replies: 42
Views: 4469

Re: NAT Issues every 10-14 days

@sirbryan

check your connection tracking table size using
/ip firewall connection tracking print 
check total-entries: value at peak hour

i have seen Routers Working OK with around 700k-800k
by chechito
Thu Dec 29, 2022 9:44 pm
Forum: General
Topic: NAT Issues every 10-14 days
Replies: 42
Views: 4469

Re: NAT Issues every 10-14 days

2h4min

i think that's a good start point from 1 day default setting
by chechito
Thu Dec 29, 2022 8:15 pm
Forum: General
Topic: CCR2004-1G-12S+2XS design approach [SOLVED]
Replies: 10
Views: 1797

Re: CCR2004-1G-12S+2XS design approach [SOLVED]

i think CCR2004-1G-12S+2XS is a niche product aimed to replace another niche product, the CCR1016-12S-1S+ what niche? In a role that can be described like a Simple Distribution Router with all the interfaces in fiber in this context the CCR2004-1G-12S+2XS meet its main goal, which is to serve as an ...
by chechito
Thu Dec 29, 2022 1:38 am
Forum: Forwarding Protocols
Topic: Routing rule use cases
Replies: 16
Views: 15986

Re: Routing rule use cases

most the time i use route rules to do High speed Load Balancing (PBR) when, mangle method is not feasible because of high CPU usage, route rule allow to achieve PBR at the highest speeds
by chechito
Wed Dec 28, 2022 2:31 am
Forum: General
Topic: 7.6 Address List Isn't Processing Accept Rule
Replies: 6
Views: 807

Re: 7.6 Address List Isn't Processing Accept Rule

Lately I see more and more frequently the use of the src-nat rule without specifying interfaces, i dont know why this is so popular
by chechito
Tue Dec 27, 2022 7:54 pm
Forum: General
Topic: Best way to "split" CRS 317-1G-16S+ into two switches
Replies: 4
Views: 755

Re: Bet way to "split" CRS 317-1G-16S+ into two switches

i think Bridge VLan Filtering
by chechito
Tue Dec 27, 2022 3:59 pm
Forum: General
Topic: how does L3HW actually works?
Replies: 128
Views: 33030

Re: how does L3HW actually works?

I have a dream of a Mikrotik router with hardware forwarding tables large enough to hold multiple full BGP tables.

One day soon I hope this will be reality !
even with other vendors that is difficult to achieve and quite expensive
by chechito
Tue Dec 27, 2022 1:25 am
Forum: General
Topic: Session limit reached (current license allows only 200 session)
Replies: 11
Views: 3787

Re: Session limit reached (current license allows only 200 session)

i think a RB4011iGS+RM or RB5009UG+S+IN will fit properly for that work-load this include Level 5 License
by chechito
Mon Dec 26, 2022 9:46 pm
Forum: RouterBOARD hardware
Topic: CCR2216-1G-12XS-2XQ (New Flagship)
Replies: 69
Views: 16354

Re: CCR2216-1G-12XS-2XQ (New Flagship)

i think direct comparison clock by clock between tilera cpu of ccr1xxx and arm cpu of ccr 2xxx is not accurate this is because there is a big differential in arquitecture, tilera is in-order execution core, Vs Arm A72 out-of-order execution on CCR 2xxx, the ammount of instructions executed per clock...
by chechito
Mon Dec 26, 2022 5:43 pm
Forum: RouterBOARD hardware
Topic: CCR2216-1G-12XS-2XQ (New Flagship)
Replies: 69
Views: 16354

Re: CCR2216-1G-12XS-2XQ (New Flagship)

dont look only your average cpu usage in ccr1072 this metric tells little about real cpu load, because of the high ammount of cores average value is inherently low, only when all cores saturate you will see a high average value sometimes 20-30% of average cpu usage on ccr1072 is a sign of an almost ...
by chechito
Sat Dec 24, 2022 5:40 am
Forum: RouterBOARD hardware
Topic: CCR2004-1G-2XS-PCIe in a box :)
Replies: 6
Views: 2112

Re: CCR2004-1G-2XS-PCIe in a box :)

thanks for sharing

i have a doubt

in system -> routerboard -> settings , you see some info about cpu clock?
by chechito
Fri Dec 23, 2022 4:08 am
Forum: RouterBOARD hardware
Topic: RouterOS v7.6 in CCR1072
Replies: 19
Views: 6211

Re: RouterOS v7.6 in CCR1072

i think for the time tile TILE-Gx72 Processor was announced (almost 10 years ago) 72 core count was pushing the limits, even today looks like for a General Purpose CPU scaling towards such high ammount of cores into a monolytic chip falls in to diminishing returns and technical difficulties, in fact...
by chechito
Fri Dec 23, 2022 2:03 am
Forum: RouterBOARD hardware
Topic: RouterOS v7.6 in CCR1072
Replies: 19
Views: 6211

Re: RouterOS v7.6 in CCR1072

that issue of different memory ram size looks like a faulty ram channel or channels i have only one case a ccr1072 with showing only 8gb of ram, the interesting thing is that the damn router works ok, but has a light load (6gbps of traffic), no performance problems either i think is interesting to s...
by chechito
Thu Dec 22, 2022 11:05 pm
Forum: General
Topic: Graphing 100% cpu usage
Replies: 9
Views: 2297

Re: Graphing 100% cpu usage

newer Routerboards have limited storage space, so if you have enabled Graphing for a great ammount of objects you will end up with problems We must abandon the habit of enabling graphing for all interfaces if we have many interfaces for example in a pppoe bras router with many users Same situation w...
by chechito
Thu Dec 22, 2022 10:55 pm
Forum: RouterBOARD hardware
Topic: RouterOS v7.6 in CCR1072
Replies: 19
Views: 6211

Re: RouterOS v7.6 in CCR1072

i think MikroTik Lack of validated network design guidelines is the main reason of ccr1072 deployment miscarriages i have "rescued" several docens of ccr1072 which were at doorstops i think in most cases misconceptions about product scaling drove customers toward flawed network designs hav...
by chechito
Thu Dec 22, 2022 10:47 pm
Forum: General
Topic: Recursive routing working in 7.6?
Replies: 14
Views: 2334

Re: Recursive routing working in 7.6?

recommended reading about changes in Routeros 7 https://help.mikrotik.com/docs/display/ROS/IP+Routing#IPRouting-NexthopLookup There are changes in RouterOS v7 nexthop lookup. Routes are processed in scope order, and updates to routes with a larger scope cannot affect the state of nexthop lookup for ...
by chechito
Thu Dec 22, 2022 10:43 pm
Forum: General
Topic: CRS305 Poor VLAN Performance
Replies: 20
Views: 1598

Re: CRS305 Poor VLAN Performance

are you still on routeros 6.48.6 ??

if you want L3 offloading you need to go to Routeros 7
by chechito
Tue Dec 20, 2022 4:02 pm
Forum: General
Topic: src-nat or netmap
Replies: 1
Views: 432

Re: src-nat or netmap

i think netmap is best suited for /24 to /24 scheme
by chechito
Tue Dec 20, 2022 3:47 pm
Forum: RouterOS beta
Topic: Help needed with routing filters v7
Replies: 37
Views: 14522

Re: Help needed with routing filters v7

i think this is very important

https://help.mikrotik.com/docs/display/ ... s-Networks
networks.png
by chechito
Tue Dec 20, 2022 5:58 am
Forum: RouterBOARD hardware
Topic: RouterOS v7.6 in CCR1072
Replies: 19
Views: 6211

Re: RouterOS v7.6 in CCR1072

most the time ccr1072 random reboots come from a flawed implementation, so dont expect miracles from a version change

plenty of 1072 working flawlessly with 6.48.6, have not tryed v7.x on ccr1072 until today
by chechito
Tue Dec 20, 2022 5:56 am
Forum: General
Topic: l3 hardware offload and rp-filter
Replies: 1
Views: 332

Re: l3 hardware offload and rp-filter

interesting question
by chechito
Thu Dec 15, 2022 8:33 am
Forum: General
Topic: RB2011UiAS only running at 100mb?
Replies: 28
Views: 2348

Re: RB2011UiAS only running at 100mb?

RB2011 legendary WorkHorse
Good Router
10 years OLD

consider something newer for serious current demands
by chechito
Wed Dec 14, 2022 6:45 pm
Forum: General
Topic: IPv6 no routing for clients [SOLVED]
Replies: 12
Views: 2913

Re: IPv6 no routing for clients [SOLVED]

i think you must request your provider to route a network for your internal network use behind your router
by chechito
Tue Dec 13, 2022 5:58 pm
Forum: General
Topic: L2TP /IPSec issue on Windows
Replies: 3
Views: 3501

Re: L2TP /IPSec issue on Windows

which version of windows??

for windows 10 works ok using default ipsec proposal, check that
/ip ipsec proposal
set [ find default=yes ] auth-algorithms=sha1 disabled=no enc-algorithms=aes-256-cbc,aes-192-cbc,aes-128-cbc lifetime=30m name=default pfs-group=modp1024
by chechito
Mon Dec 12, 2022 6:35 pm
Forum: Scripting
Topic: Users list automatically removed and admin only works
Replies: 5
Views: 657

Re: Users list automatically removed and admin only works

just a basic checking, verify you had updated routeboot on
system ->routerboard
all looks normal in the basics
by chechito
Mon Dec 12, 2022 1:24 am
Forum: General
Topic: how does L3HW actually works?
Replies: 128
Views: 33030

Re: how does L3HW actually works?

In the vast majority of use cases, you'd want to offload as much to the hardware as possible, and only CPU-route packets going directly to the router, or traffic that particular chipsets can't handle properly. i dont think so L3HW Device Support dictates a maximum Fasttrack Connections around 4.5k ...
by chechito
Sun Dec 11, 2022 6:44 pm
Forum: The Dude
Topic: Feature Request: Dude Tools based on User Privilege
Replies: 2
Views: 5859

Re: Feature Request: Dude Tools based on User Privilege

at the moment looks like dude development is stopped so don't expect new features soon
by chechito
Sun Dec 11, 2022 6:39 pm
Forum: Scripting
Topic: Users list automatically removed and admin only works
Replies: 5
Views: 657

Re: Users list automatically removed and admin only works

check your hdd/storage free Space on system -> resources if you have plenty free space and still having issues maybe you have burned internal storage because of inproper use of graphing or other write intensive features maybe for example you are graphing all 1.000 pppoe interfaces and/or queues, tha...
by chechito
Sun Dec 11, 2022 4:21 am
Forum: General
Topic: Show your best uptime :)
Replies: 11
Views: 1233

Re: Show your best uptime :)

"Show your old, unmaintained RouterOS here".
i agree with you, only exception is 6.48.6 for those who still do not want to go to v7 until long term v7 arrives and is proven/tested
by chechito
Sat Dec 10, 2022 3:54 am
Forum: RouterBOARD hardware
Topic: NAND change and license migration ..Help
Replies: 35
Views: 4005

Re: NAND change and license migration ..Help

if you dont use PPPoE or Hotspot you can go with a Cheap Level 4 license to revive this Router I hope you find a replacement power supply for that router, is a frecuent fail point avoid to do graphing or any other write intensive feature to avoid burning the flash storage again this revision of rout...
by chechito
Fri Dec 09, 2022 7:50 pm
Forum: Beginner Basics
Topic: MANtbox 2 12s PtMP Max Distance
Replies: 5
Views: 940

Re: MANtbox 2 12s PtMP Max Distance

keep in mind because of the Sectorial Antennas you will pick up a lot of neighboring noise and 2ghz has a lot of noise nowadays
by chechito
Thu Dec 08, 2022 7:53 pm
Forum: Wireless Networking
Topic: Safe to use LHG 5 indoors?
Replies: 6
Views: 1997

Re: Safe to use LHG 5 indoors?

sure you can, but you must lower tx power, try lower vaules like 5db
by chechito
Thu Dec 08, 2022 7:26 pm
Forum: General
Topic: Mikrotik Hardware suggestion
Replies: 6
Views: 553

Re: Mikrotik Hardware suggestion

average CPU usage does not tell the whole story watch every core usage be aware that on x86 modern CPUS this metric can be mascarade because of Simultaneous multithreading (SMT) if you upgrade to 3700x i suggest you to disable Simultaneous multithreading (SMT) on bios so you can see the real full us...
by chechito
Wed Dec 07, 2022 10:35 pm
Forum: Announcements
Topic: v6.48.6 [long-term] is released!
Replies: 126
Views: 275360

Re: v6.48.6 [long-term] is released!

good version
uptime.png
by chechito
Tue Dec 06, 2022 6:20 pm
Forum: General
Topic: CCR2004-1G-12S+2XS Performance Update Dec 2022 - 7.4.1 = 19Gbps
Replies: 5
Views: 2523

Re: CCR2004-1G-12S+2XS Performance Update Dec 2022 - 7.4.1 = 19Gbps

in routing test ccr2004 was working on fast-path mode ?

have you tryed bridge without vlan to allow fast-path in bridge mode?
by chechito
Tue Dec 06, 2022 5:26 pm
Forum: General
Topic: QoS - prioritise at the user/IP address level? [SOLVED]
Replies: 1
Views: 456

Re: QoS - prioritise at the user/IP address level? [SOLVED]

/queue simple
add max-limit=15M/15M name=queue1-total target=192.168.88.0/24
add limit-at=5M/5M max-limit=15M/15M name=queue2-VIP-PC parent=queue1-total target=192.168.88.251/32
add max-limit=15M/15M name=queue3-the_rest parent=queue1-total target=192.168.88.0/24
one example
by chechito
Tue Dec 06, 2022 1:26 am
Forum: General
Topic: Practical limit of simultaneous openvpn connections hap ac2 [SOLVED]
Replies: 3
Views: 861

Re: Practical limit of simultaneous openvpn connections hap ac2 [SOLVED]

i think is better to try a bigger device like rb4011 or rb5009
by chechito
Tue Dec 06, 2022 1:22 am
Forum: RouterBOARD hardware
Topic: CCR1036-8G-2S+ not showing PSU qty [SOLVED]
Replies: 5
Views: 1114

Re: CCR1036-8G-2S+ not showing PSU qty [SOLVED]

older revisions of ccr1036 does not have dual power supply

your health information looks like an old version with only one power supply

newer models with dual power supply does not show current (amperes) value in health
by chechito
Mon Dec 05, 2022 12:28 am
Forum: General
Topic: RouterOS bridge mysteries explained
Replies: 86
Views: 27227

Re: RouterOS bridge mysteries explained

topic´s name is beautiful :lol:
by chechito
Fri Dec 02, 2022 5:26 pm
Forum: General
Topic: Support not answering tickets?
Replies: 4
Views: 618

Re: Support not answering tickets?

do not expect avanced features like IGMP to be functional on new devices like ax models, they will make it work but, will take time (we are talking about months)
  • 1
  • 2
  • 3
  • 4
  • 5
  • 11