Community discussions

MikroTik App

Search found 8681 matches

  • 1
  • 3
  • 4
  • 5
  • 6
  • 7
  • 29
by Chupaka
Tue Oct 11, 2016 5:23 pm
Forum: Forwarding Protocols
Topic: multihomed BGP - filters not working?
Replies: 9
Views: 3045

Re: multihomed BGP - filters not working?

13 chain=atm-out protocol="" invert-match=no action=discard set-bgp-prepend-path="" isn't that the reason? seems like protocol="" won't match anything, that's why this rule won't discard anything. you need to unset 'protocol' field ('up' triangle at the right side of t...
by Chupaka
Tue Oct 11, 2016 1:01 am
Forum: Forwarding Protocols
Topic: multihomed BGP - filters not working?
Replies: 9
Views: 3045

Re: multihomed BGP - filters not working?

sounds like ISP1 has prefix-limit, and CCR starts to announce all ISP2 routes to ISP1

looks like you need to setup filters to allow only your networks to be announced
by Chupaka
Tue Oct 11, 2016 12:47 am
Forum: Announcements
Topic: Winbox 3.7 released!
Replies: 62
Views: 140332

Re: Winbox 3.7 released!

Old versions are able to connect to 6.38 unless Dude package is installed
by Chupaka
Thu Oct 06, 2016 10:05 pm
Forum: General
Topic: Public-Mikrotik-Bandwidth-Test-Server(s)
Replies: 1011
Views: 1130791

Re: 3.5 GIG - Public-Mikrotik-Bandwidth-Test-Server

Tom, I heard this server is quite popular among RouterOS admins :)

If you do not mind, I'd like to make this topic sticky on the forum so it stay on top
by Chupaka
Thu Oct 06, 2016 2:30 pm
Forum: Scripting
Topic: Another RouterOS API Delphi Client
Replies: 150
Views: 83598

Re: Another RouterOS API Delphi Client

/tool/torch
=interface=ether1
and then do 'Query & Listen'

if you need detailed info about some fields, add them with necessary ranges, like
/tool/torch
=interface=ether1
=src-address=0.0.0.0/0
by Chupaka
Thu Oct 06, 2016 2:28 am
Forum: General
Topic: Hide ip address
Replies: 3
Views: 3605

Re: Hide ip address

/ip firewall mangle add chain=prerouting action=change-ttl new-ttl=increment:1
by Chupaka
Thu Oct 06, 2016 2:22 am
Forum: General
Topic: new priority from dscp high 3 bits
Replies: 43
Views: 10542

Re: new priority from dscp high 3 bits

Huh... I thought, 'priority' has 0-7 range in RouterOS :o
[admin@TestPlace] > ip fi man add new-priority=

NewPriority ::= NewPriority | NewPriority
  NewPriority ::= 0..63    (integer number)
  NewPriority ::= from-dscp | from-dscp-high-3-bits | from-ingress

by Chupaka
Wed Oct 05, 2016 6:06 pm
Forum: Announcements
Topic: v6.38rc [release candidate] is released
Replies: 331
Views: 123383

Re: v6.38rc [release candidate] is released

*) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
I'd rather say, removed, not fixed:
17:51:27 interface,info ether3 link up 
17:51:27 interface,info ether6 link up 
17:51:27 interface,info ether7 link up 
No more speed info
by Chupaka
Tue Oct 04, 2016 5:15 pm
Forum: General
Topic: Feaure Request: Watchdog to watch multiple IP addresses
Replies: 7
Views: 3193

Re: Feaure Request: Watchdog to watch multiple IP addresses

Well, at least it should :)
by Chupaka
Fri Sep 30, 2016 2:45 pm
Forum: Announcements
Topic: v6.38rc [release candidate] is released
Replies: 331
Views: 123383

Re: v6.38rc [release candidate] is released

local proxy-arp normally means: router will reply to ARP for hosts it can directly reach, not for hosts it can route to.
in other words, it will search only interface/connected (by the way, which of two exactly? tech guys, we need your knowledge!) routes in routing table, not all routes? thanks
by Chupaka
Fri Sep 30, 2016 2:30 pm
Forum: Announcements
Topic: v6.38rc [release candidate] is released
Replies: 331
Views: 123383

Re: v6.38rc [release candidate] is released

*) arp - added local-proxy-arp feature;
when it will be in the manual? :) need at least a short description...
by Chupaka
Tue Sep 27, 2016 3:51 pm
Forum: General
Topic: How to fix IPv4 neighbor Table Overflow
Replies: 10
Views: 9507

Re: How to fix IPv4 neighbor Table Overflow

The problem only occur when i connect DVR on one of the interface on Mikrotik
and what happens with ARP table when you do that? we're not telepathists
by Chupaka
Tue Sep 27, 2016 3:33 pm
Forum: General
Topic: How to fix IPv4 neighbor Table Overflow
Replies: 10
Views: 9507

Re: How to fix IPv4 neighbor Table Overflow

check IP -> ARP when problem appears
by Chupaka
Tue Sep 27, 2016 2:43 pm
Forum: RouterBOARD hardware
Topic: CCR RAM SCAM!?
Replies: 31
Views: 7032

Re: CCR RAM SCAM!?

I'm 99,999% sure you will be fine with 500k
originally it was something like "I'm 99,999% sure you will be fine with 640k" :lol:
by Chupaka
Mon Sep 26, 2016 6:02 pm
Forum: General
Topic: How to fix IPv4 neighbor Table Overflow
Replies: 10
Views: 9507

Re: How to fix IPv4 neighbor Table Overflow

So, have you increased it? IP -> Settings -> Max Neighbor Entries

Also, check IP -> ARP when problem appears
by Chupaka
Mon Sep 26, 2016 5:47 pm
Forum: Announcements
Topic: SwOS version 1.17 released
Replies: 14
Views: 16333

Re: SwOS version 1.17 released

What do you do if this doesn't work?
what does it mean? try to plug 220V and repeat ;)
by Chupaka
Sat Sep 24, 2016 3:35 am
Forum: Announcements
Topic: v6.37rc [release candidate] is released, only one wireless package!
Replies: 320
Views: 103486

Re: v6.37rc [release candidate] is released, only one wireless package!

Does anyone have problems with recursive routing? I used this manual (Multiple host checking per Uplink), and everything works fine on first router. But exactly the same configuration (except gateways, of course) doesn't work on another two routers. When i add default route via virtual host 10.1.1....
by Chupaka
Tue Sep 20, 2016 3:32 pm
Forum: General
Topic: [BUG?] DHCP relay
Replies: 24
Views: 4721

Re: [BUG?] DHCP relay

So my idea is simple too:

1) Create DHCP Relays with unique local-addresses from any private subnet
2) On DHCP lease, add necessary IP address to the vlan via API

You just need to check whether step 1 will work :)
by Chupaka
Tue Sep 20, 2016 1:19 am
Forum: General
Topic: backup link, check-gateway
Replies: 15
Views: 7459

Re: backup link, check-gateway

and what happens instead?
by Chupaka
Mon Sep 19, 2016 6:04 pm
Forum: General
Topic: backup link, check-gateway
Replies: 15
Views: 7459

Re: backup link, check-gateway

its not work !
need more details. how do you mark necessary traffic, what do you expect and what goes wrong?
by Chupaka
Mon Sep 19, 2016 3:00 pm
Forum: Announcements
Topic: Winbox 3.5 released!
Replies: 19
Views: 18926

Re: Winbox 3.5 released!

WinBox still show us in many paces the "zombie" tabs like comment
Please remove it because all new users try use the comment even from terminal.
I don't have this column :) so new users won't see it too, I think
by Chupaka
Mon Sep 19, 2016 2:59 pm
Forum: Scripting
Topic: API - ACL Control
Replies: 37
Views: 21467

Re: API - ACL Control

something strange again, just like the last time. this command DOES exist :)
/system/script/run
=.id=script1
!done
=ret=Hello, I'm a script! And this is my output
by Chupaka
Mon Sep 19, 2016 2:54 pm
Forum: General
Topic: [BUG?] DHCP relay
Replies: 24
Views: 4721

Re: [BUG?] DHCP relay

The only problem is that users are bound to bridge, not the unnumbered vlan, so Cisco like idea isn't work. what's the idea? why don't you like the bridge? 4) ip route client's with gateway to vlan if your IPs are static, you do /ip address add address=89.223.20.254/32 network=89.223.20.46 interfac...
by Chupaka
Fri Sep 16, 2016 3:18 pm
Forum: General
Topic: [BUG?] DHCP relay
Replies: 24
Views: 4721

Re: [BUG?] DHCP relay

so you add /24 address to the bridge, and cannot ping a client in some vlan added to that bridge?..
by Chupaka
Fri Sep 16, 2016 2:59 pm
Forum: General
Topic: Feature request: VPN push route
Replies: 6
Views: 6160

Re: Feature request: VPN push route

you can but RouterOS won't push it to VPN clients. it's some Microsoft's extension to PPP (?) and it's not supported by RouterOS :(
by Chupaka
Thu Sep 15, 2016 8:09 pm
Forum: Scripting
Topic: API - ACL Control
Replies: 37
Views: 21467

Re: API - ACL Control

well, "/ip/hotspot/user/set" looks fine and works for me as a command :) maybe a typo in your actual code?..
by Chupaka
Thu Sep 15, 2016 7:00 pm
Forum: Scripting
Topic: API - ACL Control
Replies: 37
Views: 21467

Re: API - ACL Control

--- mikrotik.Read();
+++ List<string> test2 = mikrotik.Read();
and see what's in test2
by Chupaka
Thu Sep 15, 2016 3:42 pm
Forum: Scripting
Topic: API - ACL Control
Replies: 37
Views: 21467

Re: API - ACL Control

and what message do you receive in response to the last request?

mikrotik.Send("/ip/hotspot/user/set");
mikrotik.Send("=comment=killed");
should be
mikrotik.Send("/ip/hotspot/user/set", false);
mikrotik.Send("=comment=killed", false);
I think :)
by Chupaka
Thu Sep 08, 2016 4:20 pm
Forum: General
Topic: backup link, check-gateway
Replies: 15
Views: 7459

Re: backup link, check-gateway

what mean host1 and host2?
how can i make it ping to 8.8.8.8 for example?
8.8.8.8 is host1
by Chupaka
Tue Sep 06, 2016 12:20 am
Forum: General
Topic: Feature requests
Replies: 1744
Views: 639930

Re: Feature requests

1) having a secondary (or multiple) IP address in the event the first IP becomes unavailable or times out.
just add one more Radius Server entry with the same settings
by Chupaka
Mon Sep 05, 2016 5:24 pm
Forum: General
Topic: IPTV
Replies: 63
Views: 13955

Re: IPTV

kids are so kids...
by Chupaka
Mon Sep 05, 2016 4:03 pm
Forum: Announcements
Topic: v6.36.2 [current] is released!
Replies: 54
Views: 27480

Re: v6.36.2 [current] is released!

If there are specific IPv6 related interfaces to be created, why are there no tabs on the interface window for these IPv6 tunnels? If you would go the EoIP tunnel tab on the interfaces window, you could only add 'normal' IPv4 tunnels, no IPv6. The only way to add such IPv6 tunnel is via the main in...
by Chupaka
Tue Aug 30, 2016 5:11 pm
Forum: General
Topic: Feature requests
Replies: 1744
Views: 639930

Re: Feature requests

Some time ago the possibility to change dynamic simple queues was removed, so my script which adds "packet-parks" parameter stopped working. what do you use them for? I want to exclude some traffic from the rate limitation (so called local traffic). I used to mark non-local traffic and ad...
by Chupaka
Mon Aug 29, 2016 4:09 pm
Forum: Announcements
Topic: v6.36.2 [current] is released!
Replies: 54
Views: 27480

Re: v6.36.2 [current] is released!

This interface is not a Master port and I have not configure it as a bridge interface (it is unused interface), I think maybe it is a bug for x86, so pl check it thoroughly. Please not I have not find this problem in router board with same ROS v6.36.2 have you read my answer? http://forum.mikrotik....
by Chupaka
Mon Aug 29, 2016 2:30 am
Forum: Announcements
Topic: v6.37rc [release candidate] is released, only one wireless package!
Replies: 320
Views: 103486

Re: v6.37rc [release candidate] is released, only one wireless package!

can there be some detail "unnecessary CPU usage in simple queues", eg not sources code of course but explanations a bit ? Simple Queue hashing algorithm had an issue which caused hash rebuilds. This caused additional CPU load. This fix affects all Simple Queue configurations but improveme...
by Chupaka
Sun Aug 28, 2016 6:27 pm
Forum: Announcements
Topic: v6.36.2 [current] is released!
Replies: 54
Views: 27480

Re: v6.36.2 [current] is released!

RouterOS X86: Show R before interface name of interface list but this interface not connected with any device, why?
/interface ethernet set etherX disable-running-check=no
by Chupaka
Fri Aug 26, 2016 1:56 pm
Forum: General
Topic: Feature requests
Replies: 1744
Views: 639930

Re: Feature requests

Some time ago the possibility to change dynamic simple queues was removed, so my script which adds "packet-parks" parameter stopped working.
what do you use them for?
by Chupaka
Thu Aug 25, 2016 3:20 pm
Forum: Announcements
Topic: v6.36.2 [current] is released!
Replies: 54
Views: 27480

Re: v6.36.2 [current] is released!

and what about the IPv6 EoIP?
as it was said, just add eoipv6 tunnel, not eoip:
[admin@TestPlace] /interface eoipv6> add remote-address=2a00:1028:8386:8c5e::1 tunnel-id=0
by Chupaka
Wed Aug 24, 2016 1:47 am
Forum: General
Topic: IPTV
Replies: 63
Views: 13955

Re: IPTV

we don't have access to your conversations with Support :)

it's community forum, we are just people like you. if you need an answer from support - write to support@mikrotik.com
by Chupaka
Thu Aug 18, 2016 5:21 pm
Forum: General
Topic: ping through vlan problem
Replies: 14
Views: 2585

Re: ping through vlan problem

that's strange. you have an address on BV30, but there's no even Local MAC address on it, only on BV10 and BV20. that's weird :) maybe try to reboot?..

p.s. that topic is 4 years old
by Chupaka
Thu Aug 18, 2016 4:46 pm
Forum: General
Topic: ping through vlan problem
Replies: 14
Views: 2585

Re: ping through vlan problem

so what do you see in Bridge Hosts?
by Chupaka
Thu Aug 18, 2016 4:25 pm
Forum: General
Topic: ping through vlan problem
Replies: 14
Views: 2585

Re: ping through vlan problem

/interface ethernet switch port
set 0 vlan-mode=disabled
set 1 vlan-mode=disabled
set 2 vlan-mode=disabled
set 3 vlan-mode=disabled
set 4 vlan-mode=disabled
maybe that's the reason? try to change this to default setting (vlan-mode=fallback), for example
by Chupaka
Thu Aug 18, 2016 2:53 pm
Forum: General
Topic: ping through vlan problem
Replies: 14
Views: 2585

Re: ping through vlan problem

I know that since the first post in this topic
did what?
do you see both MAC addresses under Bridge Hosts on 450?
try to ping both 192.168.1.1 and 192.168.1.5 from 450
by Chupaka
Thu Aug 18, 2016 2:45 pm
Forum: General
Topic: "Marry" a port to a AP
Replies: 12
Views: 2057

Re: "Marry" a port to a AP

Without crypto there is no way to protect against a transparent bridge sniffing everything.
what about first manual checking and then completely disabling port on link down (when some intruder tries to install transparent bridge)? :D
by Chupaka
Thu Aug 18, 2016 2:42 pm
Forum: General
Topic: ping through vlan problem
Replies: 14
Views: 2585

Re: ping through vlan problem

did what?

can't ping what?

what's with Hosts?

we're not telepathists
by Chupaka
Thu Aug 18, 2016 12:23 am
Forum: General
Topic: ping through vlan problem
Replies: 14
Views: 2585

Re: ping through vlan problem

everything

do you see both MAC addresses under Bridge Hosts on 450?

add some address (like 192.168.1.2/24) to bridge-vlan10 and try to ping both 192.168.1.1 and 192.168.1.5 from 450
by Chupaka
Thu Aug 18, 2016 12:18 am
Forum: General
Topic: "Marry" a port to a AP
Replies: 12
Views: 2057

Re: "Marry" a port to a AP

does your AP keep MAC addresses of bridged clients, or replaces it with its own MAC address?

if it keeps, then you want to force every wireless client, for example, to be authenticated via 802.1x?

or how should the router distinguish between AP and non-AP clients?
by Chupaka
Thu Aug 18, 2016 12:14 am
Forum: General
Topic: srcnat of mangled packets
Replies: 1
Views: 581

Re: srcnat of mangled packets

/ip route
add comment="iph route" distance=1 gateway=ether1 routing-mark=iph_route
are you sure that iph_nat_tbl addresses are directly accessible via ether1, without some gateway?..
by Chupaka
Wed Aug 17, 2016 5:52 pm
Forum: General
Topic: dst-nat to Azure WebApp hostname
Replies: 3
Views: 897

Re: dst-nat to Azure WebApp hostname

not sure, but... can't you use 'http-referrer' field for this? :)
by Chupaka
Wed Aug 17, 2016 5:22 pm
Forum: General
Topic: [solved] btest protocl hash
Replies: 9
Views: 1651

Re: btest protocl hash

Figure this out, and you'll have produced a way to capture Mikrotik credentials.... https://en.wikipedia.org/wiki/Security_through_obscurity :) I been able to find part of the auth protocol. To do this i created small server on perl. If server sends a challenge "0000000000000000000000000000000...
by Chupaka
Wed Aug 17, 2016 1:42 pm
Forum: General
Topic: dst-nat to Azure WebApp hostname
Replies: 3
Views: 897

Re: dst-nat to Azure WebApp hostname

redirect port 8001 to WebProxy, use redirection rule in WebProxy to redirect HTTP requests to your azure website
by Chupaka
Tue Aug 09, 2016 2:24 pm
Forum: Announcements
Topic: v6.37rc [release candidate] is released, only one wireless package!
Replies: 320
Views: 103486

Re: v6.37rc [release candidate] is released, only one wireless package!

Why then created it ?: http://forum.mikrotik.com/viewtopic.php?f=21&t=110425 http://forum.mikrotik.com/viewtopic.php?f=21&t=110419 because it's just an announcements and there's a note on the bottom? "If you experience version related issues, then please send supout file from your rout...
by Chupaka
Mon Aug 08, 2016 5:40 pm
Forum: Announcements
Topic: v6.37rc [release candidate] is released, only one wireless package!
Replies: 320
Views: 103486

Re: v6.37rc [release candidate] is released, only one wireless package!

by the way, in current RC you cannot add duplicate domain names too :)
by Chupaka
Thu Aug 04, 2016 4:16 pm
Forum: Scripting
Topic: If else commands scripting.
Replies: 50
Views: 50909

Re: If else commands scripting.

Ok I solved it without using a if statement. :foreach i in=[interface wireless find default-forwarding=yes] do={/interface wireless set $i default-forwarding=no} :foreach i in=[interface wireless find default-authentication=yes] do={/interface wireless set $i default-authentication=no} :foreach i i...
by Chupaka
Tue Aug 02, 2016 5:52 pm
Forum: Announcements
Topic: v6.36 [current] is released!
Replies: 183
Views: 73119

Re: v6.36 [current] is released!

what version of WinBox? have you checked another version?
by Chupaka
Sun Jul 31, 2016 10:30 pm
Forum: General
Topic: DNS utilization
Replies: 15
Views: 11275

Re: DNS utilization

And regarding how servers for queries are chosen that is correct - router will use 1 cache server and only if it starts to not respond will go to next entry and change only if current one is not responding. guys, please add this to the manual. was searching for it for about 10 minutes because it's ...
by Chupaka
Thu Jul 28, 2016 2:09 pm
Forum: General
Topic: Feature request: CLI hints in WinBox
Replies: 7
Views: 2673

Feature request: CLI hints in WinBox

Kinda idea for geeks, anyway: working in Firewall via WinBox I thought it would be nice to see Terminal command for current rule on bottom, like this:
winbox-cli-cmd.png
so you don't need to click all tabs to see some accidentally set values

devs, how real is this? :)
by Chupaka
Thu Jul 28, 2016 2:56 am
Forum: General
Topic: Public-Mikrotik-Bandwidth-Test-Server(s)
Replies: 1011
Views: 1130791

Re: 3.5 GIG - Public-Mikrotik-Bandwidth-Test-Server

That's why I say: set Watchdog Address to 127.0.0.1 :)
by Chupaka
Thu Jul 28, 2016 12:06 am
Forum: General
Topic: Public-Mikrotik-Bandwidth-Test-Server(s)
Replies: 1011
Views: 1130791

Re: 3.5 GIG - Public-Mikrotik-Bandwidth-Test-Server

One issue with the Mikrotik watchdog is --- when the simple queue kicks in and starts dropping packets in a RED (Random Early Detect) condition, the simple queue can and will also drop watchdog packets - which will result in un-needed reboots. but if 127.0.0.1 is not pingable after crash, you may u...
by Chupaka
Tue Jul 26, 2016 6:25 pm
Forum: General
Topic: Public-Mikrotik-Bandwidth-Test-Server(s)
Replies: 1011
Views: 1130791

Re: 3.5 GIG - Public-Mikrotik-Bandwidth-Test-Server

also, Watchdog should help in that case
by Chupaka
Thu Jun 30, 2016 3:18 pm
Forum: General
Topic: Router MAC
Replies: 11
Views: 2951

Re: Router MAC

why not use server's IP address ("server-address" variable) instead of MAC address? if you replace the router, IP address won't change, but MAC address will
by Chupaka
Thu Jun 30, 2016 2:37 pm
Forum: Beginner Basics
Topic: Two networks and DHCP server
Replies: 9
Views: 25374

Re: Two networks and DHCP server

How will I achieve such setup where some systems will have a static only on the range of 192.68.0.x while the hotspot on a different ip range, but all must pass thru the same interface. the only problem I see is you'll need to add static subnet to Walled Garden on Hotspot so they won't be asked for...
by Chupaka
Thu Jun 30, 2016 2:27 pm
Forum: General
Topic: One more off-topic from the big flooder =)
Replies: 8
Views: 2022

Re: One more off-topic from the big flooder =)

bwhaha, thanks, guys!

so many new buttons on users posts :D
by Chupaka
Wed Jun 29, 2016 5:53 pm
Forum: General
Topic: One more off-topic from the big flooder =)
Replies: 8
Views: 2022

One more off-topic from the big flooder =)

I just saw that today is 10 years and 10 days of my registration on MikroTik forum. 7424 posts - it's a bit more than 2 posts a day, and every 70th post is mine :lol: Many versions of RouterOS changed (from 2.9.7 to current 6.35) And link speeds from ADSL & 100mbps grew upto 10G :) And... to be ...
by Chupaka
Tue Jun 21, 2016 1:38 pm
Forum: General
Topic: Does the SYN protect chain really protect anything?
Replies: 5
Views: 2605

Re: Does the SYN protect chain really protect anything?

I can't see any 'dst-limit' in your rules, so I don't know what you actually changed...
by Chupaka
Mon Jun 20, 2016 4:33 pm
Forum: General
Topic: Feature requests
Replies: 1744
Views: 639930

Re: Feature requests

I know that currently this can be achieved by using Netwatch and some scripting but it would be much easier if it were available directly on the route's properties.
it is available even without scripting: http://wiki.mikrotik.com/wiki/Advanced_ ... _Scripting
by Chupaka
Thu Jun 16, 2016 4:22 am
Forum: Announcements
Topic: v6.36rc [release candidate] is released, wireless-fp package is discontinued!
Replies: 295
Views: 107486

Re: v6.36rc [release candidate] is released, wireless-fp package is discontinued!

This will open the gates for amazing dynamic realtime blacklists distributed via BGP, and would totally obviate the problem with the adding-as-dynamic issue (as being discussed here anyway) I don't like the idea of establishing BGP peer to my billing system, sometime in a future. I prefer RouterOS ...
by Chupaka
Tue Jun 14, 2016 6:35 pm
Forum: Announcements
Topic: v6.36rc [release candidate] is released, wireless-fp package is discontinued!
Replies: 295
Views: 107486

Re: v6.36rc [release candidate] is released, wireless-fp package is discontinued!

Before you was able to manually add dynamic entry without timeout. Now there's no such possibility.
by Chupaka
Mon Jun 13, 2016 1:34 am
Forum: Announcements
Topic: v6.36rc [release candidate] is released, wireless-fp package is discontinued!
Replies: 295
Views: 107486

Re: v6.36rc [release candidate] is released, wireless-fp package is discontinued!

That doesn't make sense well, config versioning and NAND resource doesn't make sense for you? welcome to the world of telecom :) You want an item permanently in an address list, but you don't want it backed up and you don't want it saved? exactly. if your router reboots once a year just for OS upgr...
by Chupaka
Sun Jun 12, 2016 10:23 pm
Forum: Announcements
Topic: v6.36rc [release candidate] is released, wireless-fp package is discontinued!
Replies: 295
Views: 107486

Re: v6.36rc [release candidate] is released, wireless-fp package is discontinued!

the answer was posted earlier: how to add dynamic entry in this version? the goal is excluding such entries from export and NOT writing them to NAND I don't want to backup some data that is continuously synced to billing system. and I don't want to kill NAND by writing that data to persistent storage
by Chupaka
Sun Jun 12, 2016 2:37 pm
Forum: General
Topic: Load Balance"use upload from ISP and download from other ISP
Replies: 11
Views: 9110

Re: Load Balance"use upload from ISP and download from other

where can i find a freelancer to seutup this for me?
http://www.mikrotik.com/consultants
by Chupaka
Sun Jun 12, 2016 2:34 pm
Forum: Announcements
Topic: v6.36rc [release candidate] is released, wireless-fp package is discontinued!
Replies: 295
Views: 107486

Re: v6.36rc [release candidate] is released, wireless-fp package is discontinued!

Address lists can still be dynamic. Creating an item with a timeout makes it dynamic. it really should not be a big issue.
And what if I need infinite timeout? :)
by Chupaka
Fri Jun 10, 2016 1:11 am
Forum: General
Topic: Static DNS and CNAME?
Replies: 8
Views: 12718

Re: Static DNS and CNAME?

The only difference by which CloudFlare (and my provider) distinguishes sites is the name. So there MUST be a simple solution to provide an alias. Exactly. The name. So any DNS tricks won't work. You need to point original site to some proxy (for example, nginx) — it is done by A record, so RouterO...
by Chupaka
Thu Jun 09, 2016 1:54 pm
Forum: Announcements
Topic: v6.36rc [release candidate] is released, wireless-fp package is discontinued!
Replies: 295
Views: 107486

Re: v6.36rc [release candidate] is released, wireless-fp package is discontinued!

*) address-list - make "dynamic=yes" as read-only option; why-y-y?.. how to add dynamic entry in this version? the goal is excluding such entries from export and NOT writing them to NAND it's also not possible to add it with very big timeout: [admin@TestPlace] /ip firewall address-list> a...
by Chupaka
Tue Jun 07, 2016 11:26 am
Forum: General
Topic: Possible bug on 6.35.2
Replies: 10
Views: 2006

Re: Possible bug on 6.35.2

Isn't it much better and safer to use /interface set [find name="interfacename"] xxxx ?
also, why not just "/interface set interfacename xxxx"? :D
by Chupaka
Tue Jun 07, 2016 1:52 am
Forum: General
Topic: A place for poetry
Replies: 63
Views: 247503

Re: A place for poetry

installed and set up the router
no UDP support for OVPN
looking forward to version 7
by Chupaka
Tue Jun 07, 2016 1:46 am
Forum: General
Topic: A place for poetry
Replies: 63
Views: 247503

Re: A place for poetry

the Tao which you are following
is not the true Tao until you
install recent RouterOS version
by Chupaka
Tue Jun 07, 2016 1:43 am
Forum: General
Topic: A place for poetry
Replies: 63
Views: 247503

Re: A place for poetry

three things are certain:
death, taxes and packet loss
guess what is happening right now
by Chupaka
Tue Jun 07, 2016 1:29 am
Forum: General
Topic: A place for poetry
Replies: 63
Views: 247503

Re: A place for poetry

critical router just hung
don't rush to reboot it in haste
think about eternity
by Chupaka
Tue Jun 07, 2016 1:25 am
Forum: General
Topic: A place for poetry
Replies: 63
Views: 247503

Re: A place for poetry

calm down, engineer
your anger's not worth much
the network is down
by Chupaka
Tue Jun 07, 2016 1:16 am
Forum: General
Topic: A place for poetry
Replies: 63
Views: 247503

Re: A place for poetry

Following that t-shirt I saw on some EU MUM:

let your friends bridge their net
suddenly, looping occurs
you are no more their friend
by Chupaka
Wed Jun 01, 2016 4:52 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257653

Re: RouterOS v7.0 beta1 - when?

I don't see that behavior here! The dynamic entries show no timeout value, they are apparently directly managed by the parent entry and it uses the DNS TTL as timeout. Maybe you have explicity assigned a timeout? add entry with timeout and address=IP-address. it will count to 0s and disappear. now ...
by Chupaka
Wed Jun 01, 2016 2:32 pm
Forum: General
Topic: Uptime Challenge!
Replies: 25
Views: 17750

Re: Uptime Challenge!

1 year uptime, almost 10 pebibytes of data transferred, 2,6 Gbps average traffic :)
[admin@BR] > :put [ /sys reso get uptime ]                                   
52w1d18:09:13
[admin@BR] > :put ([ /int get ether3 tx-byte ] / 1024 / 1024 / 1024 / 1024)
9456
by Chupaka
Wed Jun 01, 2016 2:22 am
Forum: General
Topic: Public-Mikrotik-Bandwidth-Test-Server(s)
Replies: 1011
Views: 1130791

Re: 3.5 GIG - Public-Mikrotik-Bandwidth-Test-Server

With 186ms RTT, I'm getting 1912.4 Mbps/1933.6 Mbps Tx/Rx, not more. looks like there's somewhere 2G link in-between Belarus and USA :D
by Chupaka
Wed Jun 01, 2016 2:05 am
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257653

Re: RouterOS v7.0 beta1 - when?

domain lists for firewall
please check dynamic entries with domain name. they count down to 0s and stay here forever :)
by Chupaka
Mon May 30, 2016 11:39 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257653

Re: RouterOS v7.0 beta1 - when?

I must have missed the announcement of domain lists
the same thing here. Normis, could you add changes to the top or bottom of the changelist, not in the middle? :)
by Chupaka
Sat May 21, 2016 5:11 pm
Forum: General
Topic: API in Visual Basic 6 working fine!
Replies: 36
Views: 32212

Re: API in Visual Basic 6 working fine!

You cannot. RouterOS API still has 4kbytes limit on file size :)
Use ftp or scp for file transfer.
by Chupaka
Wed May 18, 2016 12:06 am
Forum: General
Topic: Squid Proxy
Replies: 26
Views: 9664

Re: Squid Proxy

What happens if you set squid's port 8080 in browser's proxy settings with and without that NAT rule?
by Chupaka
Tue May 17, 2016 4:13 pm
Forum: General
Topic: Squid Proxy
Replies: 26
Views: 9664

Re: Squid Proxy

why not just
/ip fi nat add chain=dstnat in-interface=lan protocol=tcp dst-port=80 action=dst-nat to-addresses=10.0.0.2 to-ports=SQUID_PORT
?
by Chupaka
Tue May 17, 2016 4:10 pm
Forum: General
Topic: API in Visual Basic 6 working fine!
Replies: 36
Views: 32212

Re: API in Visual Basic 6 working fine!

API works only over TCP, it's not possible to use API over MAC connection
by Chupaka
Mon Apr 18, 2016 4:44 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257653

Re: RouterOS v7.0 beta1 - when?

- Routing filter action "Update Address List" which adds/removes matching prefixes from an address list
oh my gosh! :shock: shut up and take my money!
by Chupaka
Tue Apr 12, 2016 2:07 pm
Forum: General
Topic: Feature Request: BGP Multicore
Replies: 6
Views: 4228

Re: Feature Request: BGP Multicore

in v7, bgp is light speed, just wait for it to become public :)
by Chupaka
Sun Mar 27, 2016 6:25 am
Forum: Announcements
Topic: Winbox3.4 released!
Replies: 53
Views: 34365

Re: Winbox3.4 released!

Winbox 3.4 disconnects from Mikrotik
When I try to connect to Mikrotik using MAC address
and what if you connect by IP?
by Chupaka
Thu Mar 24, 2016 1:22 pm
Forum: Announcements
Topic: Winbox3.4 released!
Replies: 53
Views: 34365

Re: Winbox3.4 released!

yep, finally working, thanks :)
by Chupaka
Thu Mar 24, 2016 11:12 am
Forum: Announcements
Topic: Winbox3.4 released!
Replies: 53
Views: 34365

Re: Winbox3.4 released!

Was anybody able to upgrade via 'Check for updates'?.. %)
by Chupaka
Wed Mar 23, 2016 4:02 pm
Forum: General
Topic: Feature requests
Replies: 1744
Views: 639930

Re: Feature requests

devs don't visit this forum
by Chupaka
Fri Mar 18, 2016 4:10 pm
Forum: Announcements
Topic: v6.34.3 [current] is released!
Replies: 58
Views: 44680

Re: v6.34.3 [current] is released!

is there any improvement in queue tree being assigned to a single core in a multi-core router?
is it with parent=global or parent=<interface>?
by Chupaka
Fri Mar 18, 2016 2:22 pm
Forum: General
Topic: New Packet flow diagram
Replies: 99
Views: 88344

Re: New Packet flow diagram

How can I generate his queue so that he does not bypass the limits?
1) authorization
2) just create a queue for 'everyone else' (10.0.0.0/16) with hard limits :)
by Chupaka
Fri Mar 18, 2016 11:21 am
Forum: Forwarding Protocols
Topic: IPv6 recursive nexthops via iBGP
Replies: 110
Views: 50241

Re: IPv6 recursive nexthops via iBGP

Just available? So, new style will stay here in release version? %)
by Chupaka
Wed Mar 16, 2016 12:40 am
Forum: Announcements
Topic: v6.34.3 [current] is released!
Replies: 58
Views: 44680

Re: v6.34.3 [current] is released!

Hi all, Justo to report that after upgrading RB951G-2HnD to 6.34.3 , IPsec/L2TP VPN stopped working . upgrading from what version? for example, What's new in 6.34 (2016-Jan-29 10:25): *) ipsec - fix phase2 hmac-sha-256-128 truncation len from 96 to 128 This will break compatibility with all previou...
by Chupaka
Tue Mar 15, 2016 3:00 pm
Forum: Announcements
Topic: v6.34.3 [current] is released!
Replies: 58
Views: 44680

Re: v6.34.3 [current] is released!

Avoid using magnet to attach your mAP Lite.
is it v6.34.3 problem? can you reproduce it on v6.35rc? :)
by Chupaka
Tue Mar 15, 2016 1:54 pm
Forum: Announcements
Topic: v6.34.3 [current] is released!
Replies: 58
Views: 44680

Re: v6.34.3 [current] is released!

Small bug in console:
MikroTik RouterOS 6.34.3 (c) 1999-2015       http://www.mikrotik.com/
It was released in 2016 ;)
What's new in 6.35rc29 (2016-Mar-14 15:30):
*) console - update copyright notice;
already fixed in RC :)
by Chupaka
Mon Mar 14, 2016 10:58 pm
Forum: Scripting
Topic: How to edit and delete added IP address
Replies: 12
Views: 47575

Re: How to edit and delete added IP address

you're funny, but this topic is about API, not about Terminal, SSH or whatever
by Chupaka
Mon Mar 14, 2016 5:16 pm
Forum: General
Topic: Firewall or Mangle DST-ADDRESS in ip>route based on gateway ip address
Replies: 10
Views: 3316

Re: Firewall or Mangle DST-ADDRESS in ip>route based on gateway ip address

to completely block packets via routes with gateway 172.16.30.12 you may try something like /interface bridge add name=blackhole protocol-mode=none /ip ad ad ad=192.0.2.1/30 int=blackhole /ip route add dst-address=172.16.30.12 gateway=192.0.2.2 scope=1 yep, kinda perversion... but I don't see any g...
by Chupaka
Fri Mar 11, 2016 10:02 pm
Forum: Forwarding Protocols
Topic: IPv6 recursive nexthops via iBGP
Replies: 110
Views: 50241

Re: IPv6 recursive nexthops via iBGP

I can't see any reason to use slashes instead of spaces, moreover slash has different positions on different keyboards — I don't believe they will change current command style...
by Chupaka
Fri Mar 11, 2016 1:36 pm
Forum: Announcements
Topic: Winbox3.2 released!
Replies: 59
Views: 25914

Re: Winbox3.2 released!

We can not make sure that everything can be done with single click. Why do not jut use "X" to close Winbox? in WinBox v2, pressing 'X' almost never saved current session, so it is MikroTik who taught us to press 'Exit' ;) so please return it back... You become responsible forever, for wha...
by Chupaka
Thu Mar 10, 2016 7:10 pm
Forum: General
Topic: Bye bye MIKROTIK...
Replies: 29
Views: 12439

Re: Bye bye MIKROTIK...

unfinsihed products
is it because this subforum is about RC and BETA versions? :D
by Chupaka
Thu Mar 10, 2016 7:02 pm
Forum: General
Topic: Firewall or Mangle DST-ADDRESS in ip>route based on gateway ip address
Replies: 10
Views: 3316

Re: Firewall or Mangle DST-ADDRESS in ip>route based on gateway ip address

to completely block packets via routes with gateway 172.16.30.12 you may try something like /interface bridge add name=blackhole protocol-mode=none /ip ad ad ad=192.0.2.1/30 int=blackhole /ip route add dst-address=172.16.30.12 gateway=192.0.2.2 scope=1 yep, kinda perversion... but I don't see any go...
by Chupaka
Thu Mar 10, 2016 3:57 pm
Forum: Forwarding Protocols
Topic: IPv6 recursive nexthops via iBGP
Replies: 110
Views: 50241

Re: IPv6 recursive nexthops via iBGP

C - connect, S - static, r - rip, b - bgp, o - ospf
and the very first v7 bug report :D a typo: should be 'connected', I think :)
by Chupaka
Wed Mar 09, 2016 3:36 pm
Forum: Announcements
Topic: v6.34.2 [current] is released!
Replies: 60
Views: 33986

Re: v6.34.2 [current] is released!

After upgrading to 6.34.2 Traffic Flow stopped recording Rx. Tx worked fine. I reverted back to 6.29. I didn't try any releases in-between. what NetFlow version do you use? ROS 6.29 (2015-May-27 11:19) introduced NAT info in TrafficFlow, and it was stabilized in 6.33 (2015-Nov-06 12:49), so now v1/...
by Chupaka
Fri Mar 04, 2016 12:27 am
Forum: Announcements
Topic: Winbox3.1 released!
Replies: 49
Views: 57061

Re: Winbox3.1 released!

Good day! Where to send a request to add functionality in Winbox?
support@mikrotik.com
by Chupaka
Mon Feb 29, 2016 11:06 pm
Forum: General
Topic: Mikrotik Certification test
Replies: 89
Views: 52312

Re: Mikrotik Certification test

if you have MTCRE, it is automatically assumed you have MTCNA. Even if you passed MTCNA 8 years ago, if your MTCRE is active, you automatically have MTCNA
by Chupaka
Fri Feb 19, 2016 2:31 pm
Forum: Announcements
Topic: v6.34.2 [current] is released!
Replies: 60
Views: 33986

Re: v6.34.2 [current] is released!

*) winbox - incomplete ARP entries are not refreshed;
I think, it should be "are now refreshed" or "were not refreshed" :)
by Chupaka
Mon Feb 15, 2016 4:01 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 579
Views: 276033

Re:

Bridge firewall has to be enabled explicitly. It is off by default.
did you mean 'use-ip-firewall' in bridge settings? it should not affect Bridge Filter
by Chupaka
Fri Feb 12, 2016 2:47 pm
Forum: Announcements
Topic: v6.34.1 [current] is released!
Replies: 59
Views: 27619

Re: v6.34.1 [current] is released!

problem in arp entry ip and mac on cero 00:00:00:00:00:00 i put the bug fix and is the same and teh version v6.35rc and is the same
What's new in 6.33.5 (2015-Dec-28 09:13):
*) arp - show incomplete ARP entries;
by Chupaka
Wed Feb 10, 2016 1:51 pm
Forum: Announcements
Topic: v6.34.1 [current] is released!
Replies: 59
Views: 27619

Re: v6.34.1 [current] is released!

e.g. :log warning "Hotspot login of User: $user with MAC: $mac-address" results in a log entry "Hotspot login of User: Test with MAC: -address" The new variables with the dash "-" seem not to work... Can someone confirm this? old variables show the same behaviour. you ...
by Chupaka
Tue Jan 26, 2016 2:37 pm
Forum: The Dude
Topic: The Dude is back! v6.34rc test build released
Replies: 269
Views: 104173

Re: The Dude is back! v6.34rc test build released

why those changes are not added to RouterOS changelog?
by Chupaka
Sat Jan 16, 2016 2:17 am
Forum: Announcements
Topic: v6.33.5 [current] is released!
Replies: 120
Views: 53542

Re: v6.33.5 [current] is released!

I downgraded to v6.32.x — it shows x86_64 too :)
It's old good virtual machine on ESXi host
by Chupaka
Fri Jan 15, 2016 4:06 pm
Forum: Announcements
Topic: v6.33.5 [current] is released!
Replies: 120
Views: 53542

Re: v6.33.5 [current] is released!

huh... so, there IS 64-bit version for PCs?..
ros_x86_64.gif
by Chupaka
Fri Jan 15, 2016 1:36 pm
Forum: Announcements
Topic: v6.33.5 [current] is released!
Replies: 120
Views: 53542

Re: v6.33.5 [current] is released!

looks like "Watchdog Timer" is hardware watchdog. setting "Watch Address" enables software watchdog which pings that address independently of hardware one. so you also need to unset the address to disable this behaviour
by Chupaka
Wed Jan 13, 2016 3:19 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257653

Re: RouterOS v7.0 beta1 - when?

Chupaka CU at the MUM ;)
seems like I won't be there :( I can't find affordable plane tickets from Minsk to Ljubljana. 500 euro is a bit expensive
by Chupaka
Wed Jan 13, 2016 2:00 pm
Forum: Announcements
Topic: v6.33.5 [current] is released!
Replies: 120
Views: 53542

Re: v6.33.5 [current] is released!

*) kernel - general improvement for core process scheduling;
what does that mean for performance? :)
by Chupaka
Sun Jan 10, 2016 8:57 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257653

Re: RouterOS v7.0 beta1 - when?

looking forward to EU MUM 2016 :D
by Chupaka
Thu Jan 07, 2016 1:38 pm
Forum: Scripting
Topic: Complete DELPHI API client: update 4
Replies: 69
Views: 50207

Re: Complete DELPHI API client: update 4

What is Byte() ?
a type cast?..
by Chupaka
Thu Jan 07, 2016 1:36 pm
Forum: Scripting
Topic: Another RouterOS API Delphi Client
Replies: 150
Views: 83598

Re: Another RouterOS API Delphi Client

as I see, the problem is with Synapse, not with RouterOS API unit

seems like Embarcadero removed TimeSeparator and ShortMonthNames vars in Delphi XE* - google for the "synapse delphi xe*"
by Chupaka
Mon Jan 04, 2016 11:34 pm
Forum: General
Topic: Mikrotik Router act as a switch and transparent firewall?
Replies: 41
Views: 83159

Re: Mikrotik Router act as a switch and transparent firewall?

Hi Mates I am trying to create 2 trunks ports in Mikrotik 750. Can you please guide us achieve this task, Ether 1 – TRUNK 1 (Vlan 10, 20, 30) Etehr 2 – Vlan 10 Ether5 – TRUNK 2 (Vlan 20, 30) Thanks Abbas just create VLANs on ether1 and ether5, create three bridges, add necessary interfaces to them:...
by Chupaka
Tue Dec 29, 2015 1:19 pm
Forum: General
Topic: v6.33.3 [current] is released!
Replies: 59
Views: 25898

Re: v6.33.3 [current] is released!

on RB1100AHx2 or RB493G I not had this problem, immediately after reboot i receive private IP and DNS simultaneous. but on CCR1009 not receive DNS... can anyone explain me why this happens on CCR1009 ? well, then I'd first take a look on the Log to see the difference in, for example, event sequence...
by Chupaka
Tue Dec 29, 2015 12:41 pm
Forum: General
Topic: v6.33.3 [current] is released!
Replies: 59
Views: 25898

Re: v6.33.3 [current] is released!

this is a temporary solution until they fix the bug ?
or always use dns statically ?
Always. It's not a bug. Router reboots, gives out IPs via DHCP, and only after that he learns DNSs via PPPoE. DHCP Server cannot force clients to renew DHCP leases, AFAIR
by Chupaka
Tue Dec 29, 2015 1:23 am
Forum: General
Topic: v6.33.3 [current] is released!
Replies: 59
Views: 25898

Re: v6.33.3 [current] is released!

use router's DNS for customers or set DNS IPs in DHCP Network statically
by Chupaka
Thu Dec 24, 2015 2:34 pm
Forum: General
Topic: Suggestion: make "PCQ-Upload" compatible with "Masquerade" again
Replies: 15
Views: 5346

Re: Suggestion: make "PCQ-Upload" compatible with "Masquerade" again

well, it works for us in usual way (hundreds of active users per PCQ queue, RouterOS v6.10 to v6.33) on 'global' parent, and seems like that 'feature' was fixed in early v6: What's new in 6.0beta1 (2012-Apr-13 15:26): *) pcq queue is NAT aware (just like "/queue simple" and "/ip traff...
by Chupaka
Mon Dec 21, 2015 1:23 pm
Forum: Scripting
Topic: Another RouterOS API Delphi Client
Replies: 150
Views: 83598

Re: Another RouterOS API Delphi Client

It's working!!!)))) I'm sorry, there was no active users))
Thank you very-very much!))
bwahaha, glad to hear that =)
by Chupaka
Wed Dec 16, 2015 12:39 am
Forum: General
Topic: CacheMARA
Replies: 34
Views: 15410

Re: CacheMARA

isn't YouTube going through https now?
by Chupaka
Sun Dec 13, 2015 7:37 pm
Forum: General
Topic: 80 Gbps throughput reached in the CCR1072-1G-8S+ !!!
Replies: 9
Views: 3854

Re: 80 Gbps throughput reached in the CCR1072-1G-8S+ !!!

VMs on ESXi generate traffic
by Chupaka
Fri Dec 11, 2015 7:35 pm
Forum: General
Topic: NetInstall and NEWER Windows versions
Replies: 12
Views: 4764

Re: NetInstall and NEWER Windows versions

Even more interesting was the fact that my workstation had two NICs - the primary and the lab. Guess what - the primary NIC worked for netinstall / neighbor discovery. seems like it's because both those tools use first enumerated NIC and work only with it. if you disable one NIC - second one starts...
by Chupaka
Fri Dec 11, 2015 3:19 pm
Forum: Scripting
Topic: Another RouterOS API Delphi Client
Replies: 150
Views: 83598

Re: Another RouterOS API Delphi Client

There is no explanations about signs (* = ? .) http://wiki.mikrotik.com/wiki/Manual:API#Queries Could you please write a correct ROS.Query() for CLI command "/ip hotspot active print detail where user=username"? I need to get mac-address of username from the result, i tried different vari...
by Chupaka
Tue Dec 08, 2015 11:07 pm
Forum: General
Topic: Feature requests
Replies: 1744
Views: 639930

Re: Feature requests

Use ssh with key, then forward WinBox port to local router :)
by Chupaka
Tue Dec 08, 2015 11:02 pm
Forum: General
Topic: v6.33.3 [current] is released!
Replies: 59
Views: 25898

Re: v6.33.3 [current] is released!

Use Netinstall
by Chupaka
Tue Dec 08, 2015 1:36 am
Forum: The Dude
Topic: The Dude is back! v6.34rc test build released
Replies: 269
Views: 104173

Re: The Dude is back! v6.34rc test build released

Tried few times to re-download file and re-upload it to winbox. It just doesnt want to install.
Any suggestions?
what's the reason? it should be in Log after reboot
by Chupaka
Tue Dec 08, 2015 1:24 am
Forum: Announcements
Topic: 6.32.2 released
Replies: 57
Views: 31254

Re: 6.32.2 released

When I want to enter the IP Winbox shows me a message "ERROR: could not connect to" ip " can you ping that IP? is http://IP working? When I want to enter the MAC winbox shows me the message "Incorrect user or password" is strange because no one has changed the user or passw...
by Chupaka
Fri Dec 04, 2015 4:50 pm
Forum: The Dude
Topic: The Dude is back! v6.34rc test build released
Replies: 269
Views: 104173

Re: The Dude is back! v6.34rc test build released

Are language selection and web interface planned to brought back? Or maybe some Android client?
by Chupaka
Fri Dec 04, 2015 11:09 am
Forum: The Dude
Topic: The Dude is NOT Dead - New Dude Version...
Replies: 101
Views: 49211

Re: The Dude is NOT Dead - New Dude Version...

The same here. We're on v3.6 now, and if v4 is out of Beta now, I'd like to upgrade :)

Will new Dude be upgraded together with RouterOS, or it's independent package?

Will client upgrade itself automagically?
by Chupaka
Thu Dec 03, 2015 11:22 pm
Forum: General
Topic: Dude 3.6 Torch tool is not working with Ros after 5.0 rc5
Replies: 16
Views: 5510

Re: Dude 3.6 Torch tool is not working with Ros after 5.0 rc5

We will release it with one of the next RC builds
rc14 is here, but no dude*.npk around =(
by Chupaka
Wed Dec 02, 2015 10:23 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 579
Views: 276033

Re: Cloud Hosted Router

"switch" is about hardware functionality. This menu should be removed on CHR, I think
by Chupaka
Tue Dec 01, 2015 2:06 pm
Forum: Announcements
Topic: 6.33.2 version is released!
Replies: 41
Views: 19151

Re: 6.33.2 version is released!

Just a reminder that the export is still broken. what's in export file? [admin@Neighbours] > export file=test [admin@Neighbours] > export file=test-v verbose [admin@Neighbours] > file print where name~"test" # NAME TYPE SIZE CREATION-TIME 0 test.rsc script 15.4KiB dec/01/2015 15:04:18 1 t...
by Chupaka
Mon Nov 30, 2015 2:35 pm
Forum: General
Topic: NetFlow. No longer showing NAT'd destination address - Something chnaged
Replies: 35
Views: 10991

Re: NetFlow. No longer showing NAT'd destination address - Something chnaged

1) you cannot change template format in RouterOS (for example, you cannot remove unnecessary fields) 2) template format is sent in NetFlow packets every v9-template-refresh packets or every v9-template-timeout seconds, so netflow collector knows exact format even if it didn't know it ever before :) ...
by Chupaka
Fri Nov 27, 2015 2:22 am
Forum: General
Topic: NetFlow. No longer showing NAT'd destination address - Something chnaged
Replies: 35
Views: 10991

Re: NetFlow. No longer showing NAT'd destination address - Something chnaged

Template format? What do you mean? NetFlow packets contain information about the format of actual NetFlow data :)
by Chupaka
Mon Nov 23, 2015 1:25 am
Forum: General
Topic: enhance "check-gateway" feature - use arbitrary check IP
Replies: 34
Views: 46678

Re: enhance "check-gateway" feature - use arbitrary check IP

Bwhaha, 5 years xD

Have you read that article?
by Chupaka
Thu Nov 19, 2015 10:45 pm
Forum: General
Topic: Feature request:Vmware support - vmwaretools package
Replies: 17
Views: 14123

Re: Feature request:Vmware support - vmwaretools package

Unfortunately, all virtual features are being added to Cloud Hosted Router http://forum.mikrotik.com/viewtopic.php?f=21&t=98981
by Chupaka
Tue Nov 17, 2015 11:40 am
Forum: Scripting
Topic: Another RouterOS API Delphi Client
Replies: 150
Views: 83598

Re: Another RouterOS API Delphi Client

How do I run this command with api?:
/tool user-manager user  remove [find username=demo]
http://forum.mikrotik.com/viewtopic.php?t=26790
by Chupaka
Sat Nov 14, 2015 12:46 am
Forum: Announcements
Topic: 6.33 version released!
Replies: 139
Views: 56815

Re: 6.33 version released!

Probably, it's changing dynamic queues' parameters, and now dynamic queues are read-only. You should switch to newly-added CoA
by Chupaka
Fri Nov 13, 2015 2:02 pm
Forum: Scripting
Topic: Another RouterOS API Delphi Client
Replies: 150
Views: 83598

Re: Another RouterOS API Delphi Client

Hi all, I have this error : tr_mkrouter.msend /login tr_mkrouter.msend /login tr_mkrouter.msend =name=apiuser tr_mkrouter.msend =password=2010 <-----{My clear password} tr_mkrouter.msend =response=39582d42fb88ca42ae0958e46b24e318 tr_mkrouter.open opening router error = !trap=message=cannot log in D...
by Chupaka
Fri Nov 13, 2015 11:26 am
Forum: General
Topic: Traffic Flow changes in 6.29
Replies: 10
Views: 3061

Re: Traffic Flow changes in 6.29

Second one, I'm running this on a router running a hotspot service - will masquerading options affect how flows are captured & sent to the targets? Ahhh, I saw "something unusual" in your data, but haven't read thoroughly. Sure, you see two different flows: from the client to hotspot ...
by Chupaka
Thu Nov 12, 2015 5:42 pm
Forum: General
Topic: Traffic Flow changes in 6.29
Replies: 10
Views: 3061

Re: Traffic Flow changes in 6.29

hm-m-m... NFv5 works fine for me (we're using 'interfaces=all'), and in v6.33 topic someone said that the problem is now fixed
by Chupaka
Wed Nov 11, 2015 11:23 pm
Forum: Announcements
Topic: 6.33 version released!
Replies: 139
Views: 56815

Re: 6.33 version released!

So how do you move firewall / other rules in webfig? There is no re-ordering capability as far as I can tell so I have to keep using winbox.
well, I drag it - and it moves :) just like in WinBox...
by Chupaka
Wed Nov 11, 2015 2:43 pm
Forum: Announcements
Topic: 6.33 version released!
Replies: 139
Views: 56815

Re: 6.33 version released!

indeed before posting here, i did that. in IE, Firefox and also google chrome. sure it's not cached.
checked my x86 installation - the link points to mikrotik.com...
We plan to make a new Dude release this year
yahooo!!!
by Chupaka
Mon Nov 02, 2015 10:54 am
Forum: General
Topic: Feature request: Remove fasttrack dummy rule
Replies: 33
Views: 60765

Re: Feature request: Remove fasttrack dummy rule

just replace "/ip firewall filter find" with "/ip firewall filter find dynamic=no", using item ids (like "*8") is router-dependent
by Chupaka
Fri Oct 30, 2015 3:29 pm
Forum: General
Topic: NetFlow. No longer showing NAT'd destination address - Something chnaged
Replies: 35
Views: 10991

Re: NetFlow. No longer showing NAT'd destination address - Something chnaged

Janis, that's what I wrote you on Sept, 14th: v5 should stay old way (because changing it breaks everything making v5 useless), v9 - receive additional NAT info :)

so, seems like 6.33 has ideal combination for NetFlow, thanks :)
by Chupaka
Wed Oct 28, 2015 12:21 am
Forum: General
Topic: Traffic Flow changes in 6.29
Replies: 10
Views: 3061

Re: Traffic Flow changes in 6.29

What's new in 6.33rc33 (2015-Oct-26 11:50):
*) trafflow - report flow addresses in v1 and v5 without NAT awerness
by Chupaka
Wed Oct 28, 2015 12:20 am
Forum: General
Topic: NetFlow. No longer showing NAT'd destination address - Something chnaged
Replies: 35
Views: 10991

Re: NetFlow. No longer showing NAT'd destination address - Something chnaged

this should fix that:
What's new in 6.33rc33 (2015-Oct-26 11:50):
*) trafflow - report flow addresses in v1 and v5 without NAT awerness
by Chupaka
Wed Oct 28, 2015 12:19 am
Forum: General
Topic: Netflow show private IP on WAN interface
Replies: 2
Views: 955

Re: Netflow show private IP on WAN interface

check with the latest version (6.33rc33) and NetFlow v9
by Chupaka
Wed Oct 28, 2015 12:17 am
Forum: General
Topic: troubles with traffic flow on version 6.29.1
Replies: 1
Views: 781

Re: troubles with traffic flow on version 6.29.1

huh, at last :) this should fix that:
What's new in 6.33rc33 (2015-Oct-26 11:50):
*) trafflow - report flow addresses in v1 and v5 without NAT awerness
by Chupaka
Mon Oct 19, 2015 6:37 pm
Forum: General
Topic: Bridge with Proxy
Replies: 14
Views: 2594

Re: Bridge with Proxy

sounds like MTU problem. you may try to decrease MSS for TCP packets by Mangle rule and check again
by Chupaka
Thu Oct 15, 2015 4:17 pm
Forum: General
Topic: l2tp unable to src-nat masquerade?
Replies: 3
Views: 2310

Re: l2tp unable to src-nat masquerade?

I have setup a rule such as this

chain=srcnat action=masquerade src-address=10.10.10.21

I am not seeing any traffic hitting this rule at all this src nat is not working.

Any idea?
the reason could be some other srcnat rule before this one, for example
by Chupaka
Thu Oct 15, 2015 4:14 pm
Forum: General
Topic: BUG: v6.32.2 - System reset-configuration no-defaults=yes / import
Replies: 2
Views: 2199

Re: BUG: v6.32.2 - System reset-configuration no-defaults=yes / import

you mean, "/export" and "/export compact" produce different results? that should be considered a bug
by Chupaka
Tue Sep 15, 2015 3:58 pm
Forum: General
Topic: PCQ and high (flooding) packet rate
Replies: 11
Views: 4832

Re: PCQ and high (flooding) packet rate

Is it possible to provide the server spec and approximate bandwidth/packets ? Actually i afraid from x86 network adapter bottleneck , IRQ Balancing , blabla.... Maybe i can use your experience to choose an x86 server for QOS . huh, cannot find any signs on the server :( it's some SuperMicro with 2x...
by Chupaka
Tue Sep 08, 2015 2:27 pm
Forum: General
Topic: PCQ and high (flooding) packet rate
Replies: 11
Views: 4832

Re: PCQ and high (flooding) packet rate

@Chupaka Did you find any solution or workaround ? Sometimes the routers cpu remains 100%
knock-knock on the wood, no complains for the last years. but we don't use CCRs for queueing. only x86, only hardcore :)
by Chupaka
Tue Sep 08, 2015 12:23 pm
Forum: Scripting
Topic: Remove host from hotspot using php api
Replies: 1
Views: 1748

Re: Remove host from hotspot using php api

in Terminal, you do 'find', then 'remove'. Why do you try 'remove' without 'find' in API? :)

http://forum.mikrotik.com/viewtopic.php?t=26790
by Chupaka
Tue Sep 01, 2015 2:36 pm
Forum: Announcements
Topic: v6.32 released [version temporarily removed]
Replies: 116
Views: 47997

Re: v6.32 released

*) firewall - fixed limit and dst-limit options.
requesting more details on this =)
by Chupaka
Thu Aug 20, 2015 8:42 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 579
Views: 276033

Re: Cloud Hosted Router

Chupaka. Once more. Ignore this bug.
thanks, reinstalled to solve :) I hoped there was easy way...
by Chupaka
Thu Aug 20, 2015 11:39 am
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 579
Views: 276033

Re: Cloud Hosted Router

At this time you could still change the flavor of kernel used.
how can I do that now, without network access to the router? I have only CLI
by Chupaka
Thu Aug 20, 2015 11:37 am
Forum: General
Topic: URL Redirection without Webproxy
Replies: 4
Views: 3229

Re: URL Redirection without Webproxy

marting , the hidden problem is that both facebook and youtube are in internal HSTS list of Chrome browser, so they will only open via HTTPS, not HTTP. if you redirect it to the server with non-FB/YT certificate, Chrome user will see strict error, not target website so, generally, it's not possible...
by Chupaka
Wed Aug 19, 2015 4:27 pm
Forum: General
Topic: URL Redirection without Webproxy
Replies: 4
Views: 3229

Re: URL Redirection without Webproxy

you can dst-nat only new TCP connections (without data transferred), and URL detection happens when data is being transferred - at that moment it's too late to do NAT

so it's only possible if you know destination IP address and don't care about actual data (URL, etc) inside the connection
by Chupaka
Wed Aug 19, 2015 12:01 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 579
Views: 276033

Re: Cloud Hosted Router

So, enjoy that switch while it is there as in the future it will be removed.
so, it's WinBox-only switch? I cannot change it via CLI?
by Chupaka
Tue Aug 18, 2015 8:25 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 579
Views: 276033

Re: Cloud Hosted Router

Huh... I disabled 'Allow x86-64' in System -> Resources -> Hardware, and now CHR on ESXi sees only 1 CPU core and no Ethernet (VMXNET3). How can I enable 'Allow x86-64' from console?
by Chupaka
Tue Aug 18, 2015 2:27 pm
Forum: Announcements
Topic: 6.31 released
Replies: 227
Views: 78651

Re: 6.31 released

64 version for bare metal x86 - not planned?
unclear, but most likely CHR will get priority with all 64Bit and multicore support for now
so, what is 'Allow x86-64' tick in x86 RouterOS?
by Chupaka
Tue Aug 18, 2015 12:54 pm
Forum: Announcements
Topic: 6.31 released
Replies: 227
Views: 78651

Re: 6.31 released

Вместо 32 ядер сервера - осталось только 1 ядро. I can confirm: 6.31on x86 detects only 1 CPU core: [admin@TestPlace] > sys hardware pr multi-cpu: yes [admin@TestPlace] > sys resource pr cpu-count: 1 if you check 'Allow x86-64' in WinBox under System -> Resources -> Hardware, then all CPUs are back...
by Chupaka
Tue Aug 11, 2015 10:32 pm
Forum: Announcements
Topic: MikroTik smartphone app (ex Tik-App)
Replies: 487
Views: 272291

Re: Tik App, MikroTik android utility ALPHA test

find by link or what?..
by Chupaka
Tue Aug 11, 2015 10:27 pm
Forum: General
Topic: Import large list of IP's to Firewall
Replies: 18
Views: 9513

Re: Import large list of IP's to Firewall

It was for big enough files or i misunderstood it? My list is surely MUCH bigger than 4kib. It has 257969 lines (4341454 bytes). yes, RouterOS Scripting cannot read so big files and stops on hitting something in other ban list(which is dynamic list of attackers). what?.. (O_o) what attackers? what ...
by Chupaka
Tue Aug 11, 2015 2:19 am
Forum: General
Topic: Import large list of IP's to Firewall
Replies: 18
Views: 9513

Re: Import large list of IP's to Firewall

so what exactly happens? how long is your list? it's not possible to work with files > 4KiB in RouterOS, for example
by Chupaka
Mon Aug 10, 2015 2:42 am
Forum: General
Topic: Import large list of IP's to Firewall
Replies: 18
Views: 9513

Re: Import large list of IP's to Firewall

Sadly it does not work for me.
I tried it
what 'it'?
by Chupaka
Fri Aug 07, 2015 7:19 pm
Forum: Announcements
Topic: v6.30.2 bugfix release
Replies: 147
Views: 59543

Re: v6.30.2 bugfix release

How can i disable 60+ firewall rules from terminal?
With "fasttrack dummy rule" I can't perform disable [find] because i can't disable dynamic rule.
disable [find dynamic=no]
by Chupaka
Mon Jul 27, 2015 11:49 pm
Forum: Announcements
Topic: v6.30.2 bugfix release
Replies: 147
Views: 59543

Re: v6.30.2 bugfix release

so please fix this.
fix what? "I have some error, I won't tell you anything about it, but please fix it - aren't you a telepathists?"
by Chupaka
Fri Jul 24, 2015 5:26 pm
Forum: Announcements
Topic: v6.30.2 bugfix release
Replies: 147
Views: 59543

Re: v6.30.2 bugfix release

*) winbox - restrict reversed ranges in dst-port under firewall
it's still allowed, at least on CCR:
reverse-port.gif
by Chupaka
Tue Jul 14, 2015 3:05 pm
Forum: Announcements
Topic: MikroTik smartphone app (ex Tik-App)
Replies: 487
Views: 272291

Re: Tik App, MikroTik android utility ALPHA test

SSL in WinBox protocol?.. what do you mean?
by Chupaka
Mon Jul 13, 2015 7:56 pm
Forum: Announcements
Topic: Manual Improvements
Replies: 94
Views: 31709

Re: Manual Improvements

is this incorrect command from the manual?.. a link?
by Chupaka
Mon Jul 13, 2015 7:01 pm
Forum: Announcements
Topic: Manual Improvements
Replies: 94
Views: 31709

Re: Manual Improvements

furthermore the variation: { :local address1 [/ip address get [/interface ethernet find name=ether1] address] :put $address1 } is likely as not to give an address from a completely different interface under that situation. that's completely incorrect command. first, you get ID of 'ether1' interface...
by Chupaka
Mon Jul 13, 2015 6:55 pm
Forum: Announcements
Topic: 6.30 released
Replies: 180
Views: 65845

Re: 6.30 released

When upgrade 6.30 tile,mips l2-tp default route problem. If select "Add default Route" then "Connect to address" added routing table. Why? have you read changelog? *) pptp & l2tp client: when adding default route, add special exception route for a tunnel itself (no need to a...
by Chupaka
Mon Jul 13, 2015 3:53 pm
Forum: Announcements
Topic: Manual Improvements
Replies: 94
Views: 31709

Re: Manual Improvements

This is not the issue.
so what is the issue?
looks like you have many addresses on ether1, not a single one. check with
:put [/ip address find interface="ether1"]
by Chupaka
Mon Jul 13, 2015 3:39 pm
Forum: Announcements
Topic: MikroTik smartphone app (ex Tik-App)
Replies: 487
Views: 272291

Re: Tik App, MikroTik android utility ALPHA test

For CCRs it shows negative memory size - problem with 32-bit signed integers :)
by Chupaka
Fri Jul 10, 2015 7:10 pm
Forum: Announcements
Topic: 6.30 released
Replies: 180
Views: 65845

Re: 6.30 released

Average CPU load 29% vs 31%?..
by Chupaka
Fri Jul 10, 2015 4:45 pm
Forum: Announcements
Topic: 6.30 released
Replies: 180
Views: 65845

Re: 6.30 released

I have access to several public IP addresses at each location. Can I use one IP for the IPsec EoIP tunnel and a different one for the L2TP server?
yep, that should work
by Chupaka
Mon Jul 06, 2015 1:29 pm
Forum: General
Topic: CCR & MetaRouter
Replies: 51
Views: 28316

Re: CCR & MetaRouter

let's wait for first ROS v7 betas
by Chupaka
Sun Jul 05, 2015 5:48 pm
Forum: Announcements
Topic: v6.29 released
Replies: 191
Views: 76890

Re: v6.29 released

I can't make any of arp static due to "Couldn't add new ARP, Already have such ARP!" error. It would be awesome if there was a command for that too. making static is only possible on gui (I know with some scripts it is possible. I mean something like "/ip arp set x static=yes") ...
by Chupaka
Fri Jul 03, 2015 1:59 am
Forum: General
Topic: Feature requests
Replies: 1744
Views: 639930

Re: Feature requests

Feature request: Ability to specify boot-file-name on a per static lease basis. This would add much needed flexibility for rather than using the global setting at the 'ip dhcp-server networ' level where all clients receive the same file. for now you should be able to create Network entry per IP wit...
by Chupaka
Mon Jun 29, 2015 12:59 pm
Forum: Scripting
Topic: Another RouterOS API Delphi Client
Replies: 150
Views: 83598

Re: Another RouterOS API Delphi Client

[dcc32 Fatal Error] RouterOSAPI.pas(67): F2613 Unit 'blcksock' not found. [dcc32 Fatal Error] RouterOSAPI.pas(67): F2613 Unit 'synautil' not found. [dcc32 Fatal Error] RouterOSAPI.pas(67): F2613 Unit 'synsock' not found. [dcc32 Fatal Error] RouterOSAPI.pas(67): F2613 Unit 'synacode' not found. thos...
by Chupaka
Fri Jun 26, 2015 3:34 pm
Forum: Scripting
Topic: Another RouterOS API Delphi Client
Replies: 150
Views: 83598

Re: Another RouterOS API Delphi Client

then... use correct path to RouterOSAPI.pas :)

p.s. that file is not in APITest, have you downloaded it separately?
by Chupaka
Thu Jun 25, 2015 9:35 pm
Forum: Announcements
Topic: FastTrack - New feature in 6.29
Replies: 237
Views: 204772

Re: FastTrack - New feature in 6.29

exactly. no slow processing (queues, firewall) at all. by design :)
by Chupaka
Thu Jun 25, 2015 2:39 pm
Forum: Announcements
Topic: v6.29 released
Replies: 191
Views: 76890

Re: v6.29 released

Sorry, I know this is not the 6.30rc topic, but there is no one official.
because it's not a release :)
There is a problem with the scheduler on v6.30rc22.
please write to support@mikrotik.com
by Chupaka
Mon Jun 22, 2015 4:31 pm
Forum: Announcements
Topic: v6.29 released
Replies: 191
Views: 76890

Re: v6.29 released

After upgrade from 6.24 to 6.29.1, ipsec packet mark in mangle-prerouting chain does not work, or it's not catched by filter-forward chain. seems like it won't be possible anymore, but another solution is coming: What's new in 6.30rc19 (2015-Jun-12 11:45): *) firewall - added ipsec-policy matcher t...
by Chupaka
Tue Jun 16, 2015 8:54 pm
Forum: Announcements
Topic: FastTrack - New feature in 6.29
Replies: 237
Views: 204772

Re: FastTrack - New feature in 6.29

seems like people are requesting an ability to do 'action=fasstrack passthrough=no'. MT? :)
by Chupaka
Tue Jun 16, 2015 4:18 pm
Forum: Announcements
Topic: Manual Improvements
Replies: 94
Views: 31709

Re: Manual Improvements

If this teaches us anything, is that we need to improve search and manual structure for easy navigation :) like, for example, merging the pages of Mangle, Filter and Nat in IP Firewall: does it have any sense to have three copies of firewall rules properties? I'm always getting lost in those sectio...
by Chupaka
Fri Jun 12, 2015 1:50 am
Forum: Announcements
Topic: v6.29 released
Replies: 191
Views: 76890

Re: v6.29 released

FREAK affects SSL/TLS, so SSTP and HTTPS are possibly affected, not OVPN or IPSec
by Chupaka
Fri Jun 12, 2015 1:44 am
Forum: Forwarding Protocols
Topic: What BGP setups need to be optimized
Replies: 57
Views: 32214

Re: What BGP setups need to be optimized

these are feature requests, not optimizations of current features ;)
by Chupaka
Wed Jun 10, 2015 11:34 am
Forum: Announcements
Topic: FastTrack - New feature in 6.29
Replies: 237
Views: 204772

Re: FastTrack - New feature in 6.29

now only thing missing is similar solution for simple queues - dynamic dummy simple queue for fasttracked traffic.
and also similar counter in TrafficFlow: how much traffic you have not billed :)
by Chupaka
Mon Jun 08, 2015 2:41 pm
Forum: Announcements
Topic: FastTrack - New feature in 6.29
Replies: 237
Views: 204772

Re: FastTrack - New feature in 6.29

what is faster: router with conntrack disabled, or fasttrack-enabled? :)
by Chupaka
Thu Jun 04, 2015 11:28 am
Forum: Announcements
Topic: FastTrack - New feature in 6.29
Replies: 237
Views: 204772

Re: FastTrack - New feature in 6.29

FastPath and FastTrack are a bit different things, AFAICS

I wonder, is it possible to use FastTrack on the router with ConnectionTracking disabled :) so it just skips processing of Filter, Mangle, etc.
by Chupaka
Tue Jun 02, 2015 4:21 pm
Forum: Announcements
Topic: v6.29 released
Replies: 191
Views: 76890

Re: v6.29 released

*) trafflow: add natted addrs/ports to ipv4 flow info; Please tell us more about that. Which fields are used? What netflow collector understands them? What format and for what collector are the NAT events anyway, do they correspond to any standard or a generally used format? (I guess that the forma...
by Chupaka
Mon Jun 01, 2015 4:41 pm
Forum: General
Topic: Check Gateway Ping doesnt work with ECMP !
Replies: 15
Views: 5472

Re: Check Gateway Ping doesnt work with ECMP !

let's wait for v7 betas and check :)
by Chupaka
Mon Jun 01, 2015 2:02 pm
Forum: Scripting
Topic: API Links
Replies: 155
Views: 219022

Re: API Links

Hi folks.
I need to print on a table id and the name of the hostpot users.
and remove the User by his id.
Can anyone help me.
/ip/hotspot/user/print
=.proplist=.id,name
then
/ip/hotspot/user/remove
=.id=ID_HERE
I use C Sharp
http://wiki.mikrotik.com/wiki/API_in_C_Sharp
by Chupaka
Sat May 30, 2015 2:22 pm
Forum: General
Topic: Check Gateway Ping doesnt work with ECMP !
Replies: 15
Views: 5472

Re: Check Gateway Ping doesnt work with ECMP !

Have you read my answers? :)
by Chupaka
Fri May 29, 2015 5:26 pm
Forum: General
Topic: eth. protocol 8864 (pppoe) hitting physical interface
Replies: 22
Views: 9582

Re: eth. protocol 8864 (pppoe) hitting physical interface

I've torch on pppoe interface, or interfaces eth1, but eth. 8864 protocol (pppoe) is still visible when I torch interface pppoe or ether1. whether it occurs because the broadcast pppoe? it's because you have traffic on pppoe interface. that traffic is encapsulated in 8864 protocol (pppoe) and is vi...
by Chupaka
Thu May 28, 2015 9:10 pm
Forum: General
Topic: How to Block torrent 100%? Only 2 lines. It is solved.
Replies: 59
Views: 112619

Re: How to Block torrent 100%? Only 2 lines. It is solved.

Those rules block peer discovery, afaics. They don't block p2p itself.
by Chupaka
Thu May 28, 2015 9:03 pm
Forum: General
Topic: eth. protocol 8864 (pppoe) hitting physical interface
Replies: 22
Views: 9582

Re: eth. protocol 8864 (pppoe) hitting physical interface

sorry I was wrong upload files, i should upload this file..
Anyway,
your pppoe client receives 5 Mbps of traffic - use Torch on it, not on ether1
by Chupaka
Wed May 20, 2015 2:23 pm
Forum: General
Topic: eth. protocol 8864 (pppoe) hitting physical interface
Replies: 22
Views: 9582

Re: eth. protocol 8864 (pppoe) hitting physical interface

i have the same problem, can somebody help me ?
your pppoe client receives 5 Mbps of traffic - use Torch on it, not on ether1
also, 5 Mbps on pppoe-out1 = 3 Mbps on ether2 + 2 Mbps on ether4. what's the problem?
by Chupaka
Fri May 15, 2015 5:48 pm
Forum: General
Topic: NPTv6 / RFC 6296 Support?
Replies: 53
Views: 16078

Re: NPTv6 / RFC 6296 Support?

Don't do it. Do it the right way. Not the hack way. I'm not sure what the real costs are but a few thousand euros per month sounds pretty steep for announcing a prefix. It'd be a couple hundred dollars a month in the states. Cost of doing business. Do it right or don't do it. it's not a business. i...
by Chupaka
Fri May 15, 2015 10:53 am
Forum: General
Topic: NPTv6 / RFC 6296 Support?
Replies: 53
Views: 16078

Re: NPTv6 / RFC 6296 Support?

I'm personally against anything to do with nat and IPv6. We don't need another bandaid like nat originally was. Use IPv6 the way it was intended to be used.
any comments on how to balance a few IPv6 uplinks? or just failover for the home Internet?
by Chupaka
Wed May 06, 2015 12:54 am
Forum: Announcements
Topic: RouterOS v6.28 released
Replies: 229
Views: 93220

Re: RouterOS v6.28 released

Now are 15 days after I have installed the 6.28 on my border BGP routers, my gateways, firewalls and user-managers.

No one single problem
on 17th day one of my CCRs became loosing packets on _some_ neighbour routers until reboot... I hope it was just a Moon in wrong phase :)
by Chupaka
Tue May 05, 2015 5:59 pm
Forum: General
Topic: Feature Request - LAC/LNS functionality
Replies: 128
Views: 55335

Re: Feature Request - LAC/LNS functionality

what was that?..
by Chupaka
Mon May 04, 2015 3:11 pm
Forum: Announcements
Topic: RouterOS v6.28 released
Replies: 229
Views: 93220

Re: RouterOS v6.28 released

Hello,

Upload rate in queues is shown in bits instead of kb alson on this version.
The queues are set in radius.
1228800 bps is 1228,8 kbps, and WinBox does not round limits in output. for example, 1228000 should be shown as 1228k
by Chupaka
Thu Apr 30, 2015 7:12 pm
Forum: Forwarding Protocols
Topic: What BGP setups need to be optimized
Replies: 57
Views: 32214

Re: What BGP setups need to be optimized

full table towards the CCR and 3-5 minute load times
huh... what is full view load time on cisco routers?..
by Chupaka
Thu Apr 30, 2015 12:48 pm
Forum: Forwarding Protocols
Topic: What BGP setups need to be optimized
Replies: 57
Views: 32214

Re: What BGP setups need to be optimized

Please add support for
this topic is about optimization, new features will be in version 7
by Chupaka
Thu Apr 30, 2015 1:07 am
Forum: Announcements
Topic: FastTrack - New feature in 6.29
Replies: 237
Views: 204772

Re: FastTrack - New feature in 6.29

Note, that all packets that goes fasttrack, will not be visible in firewall and you will not be able to limit them in queue global.
I wonder whether those packets will be accounted by Traffic Flow...
by Chupaka
Tue Apr 28, 2015 4:08 pm
Forum: Announcements
Topic: RouterOS v6.27 released
Replies: 273
Views: 134994

Re: RouterOS v6.27 released

it depends on your setup, I think :)
by Chupaka
Mon Apr 27, 2015 4:20 pm
Forum: General
Topic: mikrotik NAT
Replies: 1
Views: 572

Re: mikrotik NAT

I have 10.200.x.x/18 for clients,
/ip firewall address-list
add address=10.220.0.0/18 list=p-108
also, it's better to NAT all traffic on uplink interface, so remove 'src-address-list=' from your nat rule
by Chupaka
Mon Apr 27, 2015 4:14 pm
Forum: General
Topic: Mangle, per Src-IP/PCC and nth ?
Replies: 2
Views: 959

Re: Mangle, per Src-IP/PCC and nth ?

probably you could use 'dst-limit' firewall matcher, but why do you need this at all?
by Chupaka
Thu Apr 16, 2015 5:34 pm
Forum: General
Topic: DDoS story, or WARNING: use 'conection-limit' with caution!
Replies: 168
Views: 112296

Re: DDoS story, or WARNING: use 'conection-limit' with caution!

what you think about this http://wiki.mikrotik.com/wiki/DDoS_Dete ... d_Blocking, they redirect to this post but are different
as you can see in page history, that was me who created and edited that article :)
by Chupaka
Mon Apr 13, 2015 12:56 pm
Forum: Scripting
Topic: Reset pppoe connection
Replies: 7
Views: 3804

Re: Reset pppoe connection

if you have the same problem - then use the same solution!
http://forum.mikrotik.com/viewtopic.php ... 53#p214453
by Chupaka
Mon Apr 13, 2015 12:53 pm
Forum: Scripting
Topic: API address-list add or remove
Replies: 21
Views: 32569

Re: API address-list add or remove

if you get .id from /ppp/active, then you must use it under /ppp/active, not /interface/ or something

the correct command is:
/ppp/active/remove
=.id=*80000010
by Chupaka
Wed Apr 08, 2015 12:20 pm
Forum: Announcements
Topic: RouterOS v6.27 released
Replies: 273
Views: 134994

Re: RouterOS v6.27 released

I had cases where i copy .npk files and then after reboot, device simply wont upgrade
And the reason is in Log, isn't it? :)
by Chupaka
Mon Apr 06, 2015 8:19 pm
Forum: General
Topic: Feature requests
Replies: 1744
Views: 639930

Re: Feature requests

Functionality such as DNETMAP +1 isn't it already here?.. just use 'action=netmap" in 'dstnat' chain... Please add ability to set comment for dynamically added entries in address list. This feature let for e.g. make script which resolves blocked IP addresses to their FQDN and puts it into comm...
by Chupaka
Thu Apr 02, 2015 5:51 pm
Forum: General
Topic: DDoS story, or WARNING: use 'conection-limit' with caution!
Replies: 168
Views: 112296

Re: DDoS story, or WARNING: use 'conection-limit' with caution!

okay, that again confirms that one should not blindly copy any configs found in the Internet, as many things depend on the topology :)
by Chupaka
Thu Apr 02, 2015 2:41 pm
Forum: General
Topic: DDoS story, or WARNING: use 'conection-limit' with caution!
Replies: 168
Views: 112296

Re: DDoS story, or WARNING: use 'conection-limit' with cauti

Hi Chupaka. This limit seems really low to me. Surely if you had asymmetric routing on your network it would only take 2 VoIP calls from a single customer site to exceed this limit? I put those rules on access routers, so there's no asymmetric routing and yes, in case of asymmetric routing, if rout...
by Chupaka
Mon Mar 30, 2015 4:56 pm
Forum: General
Topic: Feature Request: gretap tunneling
Replies: 10
Views: 6795

Re: Feature Request: gretap tunneling

Could this be added as a feature request?
Did you email support to ask for this feature? <...> Forum is not always monitored by staff.
by Chupaka
Tue Mar 10, 2015 2:14 pm
Forum: Virtualization
Topic: What can i install on xen?related to server(proxy..cache...)
Replies: 4
Views: 4236

Re: What can i install on xen?related to server(proxy..cache...)

Don't expect any more 3.x versions unless there is a serious bug fix.???
don't expect new 3.x versions at all, even if there's serious bug :)
by Chupaka
Mon Mar 02, 2015 7:57 pm
Forum: General
Topic: Check Gateway Ping doesnt work with ECMP !
Replies: 15
Views: 5472

Re: Check Gateway Ping doesnt work with ECMP !

Routing engine is rewritten for RouterOS v7, they won't do major changes in v6, so wait for first betas :)
by Chupaka
Mon Feb 23, 2015 4:14 pm
Forum: General
Topic: CCR1036 PPPoE 1000+ clients 400+ Mbit/s degraded perfomance
Replies: 10
Views: 6234

Re: CCR1036 PPPoE 1000+ clients 400+ Mbit/s degraded perfoma

I observed the same behaviour with IPoE and PCQ queues - on 400-500 Mpbs clients begin to complain =( switched back to x86 seems like CCR is still not for shaping, while we're successfully using them as simple firewall/policy routers at upto 2.5 Gbps and more (5 min average) What is your opinion no...
by Chupaka
Wed Feb 18, 2015 12:32 am
Forum: General
Topic: Webfig skins (tutorial)
Replies: 100
Views: 123445

Re: Webfig skins (tutorial)

he said logos, not logs :)
by Chupaka
Wed Feb 18, 2015 12:28 am
Forum: Announcements
Topic: RouterOS v6.27 released
Replies: 273
Views: 134994

Re: RouterOS v6.27 released

[offtop]
A week after 6.27 release, and no new RC builds... Seems like v7 is coming :) Or some Latvian holidays?..

P.S. To make this post completely off the topic: Normis, please hide that floating header on the forum, it just disturbs and nothing else...
[/offtop]
by Chupaka
Sat Feb 14, 2015 6:49 pm
Forum: Forwarding Protocols
Topic: OSPF with ECMP via different interfaces of the same router
Replies: 3
Views: 2111

Re: OSPF with ECMP via different interfaces of the same router

hm, nice idea =) I thought about doing traffic segmentation on the switch (so that packets won't go between ports where R2 is connected), but this fits even in case of unmanaged switch but... is it working after that? p.s. instead of making address-list, probably it's better use src-address-type=loc...
by Chupaka
Tue Feb 10, 2015 8:17 pm
Forum: General
Topic: [BUG] SSH client does not works from background script
Replies: 11
Views: 3952

Re: [BUG] SSH client does not works from background script

Have you reportet that problem to MT support at support@mikrotik.com?
by Chupaka
Fri Feb 06, 2015 3:17 pm
Forum: General
Topic: CCR & MetaRouter
Replies: 51
Views: 28316

Re: CCR & MetaRouter

I think, news will be on March, 27th, at EU MUM :)
by Chupaka
Wed Feb 04, 2015 12:04 pm
Forum: General
Topic: DDoS story, or WARNING: use 'conection-limit' with caution!
Replies: 168
Views: 112296

Re: DDoS story, or WARNING: use 'conection-limit' with cauti

sorry for the long delay I think, routing to blackhole is better just because it drops packets earlier (on routing decision step), without checking filter rules. anyway, you still need filter rules for the first packet, which is detected after 'prerouting', and for dst-natted packets if any on produ...
by Chupaka
Wed Jan 28, 2015 4:30 pm
Forum: General
Topic: IPv6 Ping does not work with domain names
Replies: 59
Views: 47131

Re: IPv6 Ping does not work with domain names

hm-m-m... I think, 8.8.8.8 is not very IPv6...
by Chupaka
Wed Jan 14, 2015 4:36 am
Forum: General
Topic: Known issues and bugs - a list
Replies: 284
Views: 171408

Re: Known issues and bugs - a list

Is this a known issue, or amI wrong with some configuration? you are wrong. when you set gateway=interface, packet is sent from the interface directly to the connected network. if it's p2p tunnel, packet has only one way - the remote peer. but in case of broadcast interfaces (like Ethernet), router...
by Chupaka
Tue Jan 13, 2015 1:38 pm
Forum: General
Topic: Known issues and bugs - a list
Replies: 284
Views: 171408

Re: Known issues and bugs - a list

Every time I set e-mail configuration via WinBox in Tools / Email Settings and tick “Start TLS” checkbox, then exit from WinBox and open it again checkbox next to “Start TLS” is not ticked. seems like it's because 'start-tls' has three values: "no", "tls-only", "yes" -...
by Chupaka
Mon Jan 12, 2015 9:27 pm
Forum: Beginner Basics
Topic: vlan + dhcp server
Replies: 8
Views: 6367

Re: vlan + dhcp server

well, I just thought you were going to compare packets from v5 and v6 :(

we don't use screening, just plain DHCP Relay on switches. also, those switches work with many linux and bsd servers, so I think it's v6 who have broken DHCP server, not v5
  • 1
  • 3
  • 4
  • 5
  • 6
  • 7
  • 29