Community discussions

MikroTik App

Search found 7038 matches

by mrz
Thu Dec 03, 2020 8:04 pm
Forum: RouterOS beta
Topic: v7.1beta3 [development] is released!
Replies: 261
Views: 79139

Re: v7.1beta3 [development] is released!

One thing i instantly noticed is that /export never terminates. Tried to reset to an empty configuration, same thing. When i run /export verbose the last thing that gets displayed is /radius incoming set accept=no port=3799 and then it hangs forever. Export problem is known, /routing menu export is...
by mrz
Thu Dec 03, 2020 8:01 pm
Forum: RouterOS beta
Topic: v7.1beta3 [development] is released!
Replies: 261
Views: 79139

Re: v7.1beta3 [development] is released!

How does the BGP related config migration work? Is this done automatically as part of the upgrade process? Yes it is part of the upgrade process, but keep in mind that routing filters are not converted yet and some of the config might still be missing. So it is recommended to make a backup of ROSv6...
by mrz
Thu Dec 03, 2020 12:34 pm
Forum: Forwarding Protocols
Topic: BGP Manual Refresh
Replies: 2
Views: 3299

Re: BGP Manual Refresh

What do you mean by hard refresh. Tear down the session and restart? If so then peer disable/enable.
by mrz
Thu Dec 03, 2020 9:45 am
Forum: Forwarding Protocols
Topic: Disable ECMP on OSPF?
Replies: 8
Views: 3227

Re: Disable ECMP on OSPF?

I am not saying ECMP is not asymmetric. Turning off ECMP might be useful but not in the case you are referring. You will not get consistency you are asking for.
by mrz
Wed Dec 02, 2020 1:14 pm
Forum: Scripting
Topic: To retain variable's values after reboot
Replies: 20
Views: 8609

Re: To retain variable's values after reboot

Why in the earth does not the RuterOS retains the global variable after reboot. Can you show any other scripting language or programming language where defined variables magically restores their values from previous script instance, without saving data to file, registry or database? If you want to ...
by mrz
Tue Dec 01, 2020 4:40 pm
Forum: Scripting
Topic: To retain variable's values after reboot
Replies: 20
Views: 8609

Re: To retain variable's values after reboot

Write variables in scheduler startup script is a better option than writing variables in l7 rules and other crazy stuff.
by mrz
Tue Dec 01, 2020 11:10 am
Forum: Forwarding Protocols
Topic: Disable ECMP on OSPF?
Replies: 8
Views: 3227

Re: Disable ECMP on OSPF?

You cannot turn it off.
And even if you could in your scenario it will introduce other mentioned problems, like asymmetric routing unpredictably. Only right way that fits your described scenario is to adjust interface costs.
by mrz
Mon Nov 30, 2020 1:37 pm
Forum: RouterOS beta
Topic: Routing RIP
Replies: 2
Views: 1139

Re: Routing RIP

Use CLI for now
by mrz
Fri Nov 27, 2020 5:10 pm
Forum: Forwarding Protocols
Topic: Blackhole
Replies: 4
Views: 4075

Re: Blackhole

/routing filter add chain=your_chain prefix=x.x.x.x/32 set-bgp-communities=65535: 666
by mrz
Fri Nov 27, 2020 12:15 pm
Forum: Forwarding Protocols
Topic: Blackhole
Replies: 4
Views: 4075

Re: Blackhole

add prefix in BGP networks
and set community in out filter.
by mrz
Thu Nov 26, 2020 4:38 pm
Forum: Forwarding Protocols
Topic: BGP Peer within VRF route advertisement
Replies: 5
Views: 1869

Re: BGP Peer within VRF route advertisement

There is no menu to show vpnv4 routes advertised to specific peer.
by mrz
Wed Nov 25, 2020 3:55 pm
Forum: RouterOS beta
Topic: /import safe-mode (feature request)
Replies: 2
Views: 1226

Re: /import safe-mode (feature request)

Enable safe mode and then run import.
by mrz
Sat Nov 21, 2020 9:19 am
Forum: Forwarding Protocols
Topic: BGP Peer within VRF route advertisement
Replies: 5
Views: 1869

Re: BGP Peer within VRF route advertisement

advertisements is only for ipvx routes. vpnv4 routres are in vpnv4 menu
by mrz
Tue Nov 17, 2020 9:30 am
Forum: RouterOS beta
Topic: V7 bgp peer in_filter and out filter config?
Replies: 3
Views: 1464

Re: V7 bgp peer in_filter and out filter config?

Then it is not clear what exactly you are unable to find, because there is an example that shows how to specify out filter:
/routing/bgp/template
add name=myAsTemplate as=65500 output.filter=myAsFilter
by mrz
Tue Nov 10, 2020 10:50 am
Forum: General
Topic: find from API
Replies: 2
Views: 581

Re: find from API

Because there is no find in api, use queries:
https://wiki.mikrotik.com/wiki/Manual:API#Queries
by mrz
Mon Nov 09, 2020 10:05 am
Forum: RouterOS beta
Topic: [REQUEST] IPv6 routing mark
Replies: 2
Views: 3042

Re: [REQUEST] IPv6 routing mark

Already supported in v7beta
by mrz
Fri Nov 06, 2020 6:23 pm
Forum: RouterOS beta
Topic: ROS 7.0beta5 mark based routing BOOTLOOP
Replies: 11
Views: 5902

Re: ROS 7.0beta5 mark based routing BOOTLOOP

@main is not mandatory, but is useful to know, because v7 allows to resolve gateways in other tables than main
by mrz
Fri Nov 06, 2020 3:53 pm
Forum: RouterOS beta
Topic: ROS 7.0beta5 mark based routing BOOTLOOP
Replies: 11
Views: 5902

Re: ROS 7.0beta5 mark based routing BOOTLOOP

You should look at the article again, it explains everything: The same example as in the manual with plugged in your table name and gateway /routing table add name=to_WAN1 fib /ip route add dst-address=0.0.0.0/0 gateway=192.168.1.1@main routing-table=to_WAN1 Hope you will figure out how to change va...
by mrz
Thu Nov 05, 2020 12:14 pm
Forum: RouterOS beta
Topic: ROS 7.0beta5 mark based routing BOOTLOOP
Replies: 11
Views: 5902

Re: ROS 7.0beta5 mark based routing BOOTLOOP

routing-marks can be used the same way as it was in v6, with one difference, you need to add table first in /routing table menu.
This is mentioned in the first sentence:
https://help.mikrotik.com/docs/display/ ... icyRouting
by mrz
Tue Nov 03, 2020 4:24 pm
Forum: Announcements
Topic: v6.46.8 [long-term] is released!
Replies: 36
Views: 29676

Re: v6.46.8 [long-term] is released!

Hey guys. I could be wrong, but it seems that DOH is unavailable on this release. Could you please check this? Thanks. Of course it is not available, in v6.46.x because it was implemented only in v6.47 MAJOR CHANGES IN v6.47: ---------------------- !) dns - added client side support for DNS over HT...
by mrz
Mon Nov 02, 2020 1:12 pm
Forum: RouterOS beta
Topic: DS-Lite (dual stack lite) internet connection as defined in RFCs 6333 and 6334
Replies: 11
Views: 9193

Re: DS-Lite (dual stack lite) internet connection as defined in RFCs 6333 and 6334

You can get received attributes and their values by accessing "options" variable on script event.
Example on how to use script on DHCP event and access variables can be seen here:
https://wiki.mikrotik.com/wiki/Manual:I ... pt_example
by mrz
Mon Nov 02, 2020 1:05 pm
Forum: General
Topic: OpenVPN 2.5.0 Upgrade
Replies: 4
Views: 2322

Re: OpenVPN 2.5.0 Upgrade

BF-CBC is not the only cipher that ROS supports, so I do not see any reason why you should not be able to connect to new server with disabled BF.
by mrz
Wed Oct 21, 2020 1:38 pm
Forum: General
Topic: Mikrotik CCR as Console server for cisco ?
Replies: 6
Views: 1198

Re: Mikrotik CCR as Console server for cisco ?

I have used to connect from MT router to connect to Cisco serial port. Works fine.
by mrz
Fri Oct 16, 2020 5:05 pm
Forum: RouterOS beta
Topic: v7.1beta2 [development] is released!
Replies: 385
Views: 153587

Re: v7.1beta2 [development] is released!

From v7 changelog:
-) Winbox does not show all features, use CLI for most functionality
by mrz
Fri Oct 16, 2020 2:54 pm
Forum: General
Topic: PHP APi Connection
Replies: 16
Views: 5487

Re: PHP APi Connection

there is no need to send /login again with md5 hash
by mrz
Fri Oct 16, 2020 2:31 pm
Forum: General
Topic: PHP APi Connection
Replies: 16
Views: 5487

Re: PHP APi Connection

as described in the link I provided.

send /login =name= =password= in first message
by mrz
Fri Oct 16, 2020 2:10 pm
Forum: RouterOS beta
Topic: v7.1beta2 [development] is released!
Replies: 385
Views: 153587

Re: v7.1beta2 [development] is released!

OVPN over UDP works great for me on CHR I did notice when I try to add a routing mark I cant type any New Routeing Mark , It only have one option and that is to choose main, Probably this will help you to set up routing tables: https://help.mikrotik.com/docs/display/ROS/ROSv7+Basic+Routing+Examples...
by mrz
Fri Oct 16, 2020 2:00 pm
Forum: General
Topic: PHP APi Connection
Replies: 16
Views: 5487

Re: PHP APi Connection

https://wiki.mikrotik.com/wiki/Manual:API#Initial_login

see notes in login process post-v6.43
by mrz
Thu Oct 15, 2020 10:40 am
Forum: Forwarding Protocols
Topic: OSPF2 network-type
Replies: 5
Views: 1259

Re: OSPF2 network-type

In RouterOS v6 only network type that works without multicast is NBMA.
by mrz
Thu Oct 15, 2020 10:39 am
Forum: Forwarding Protocols
Topic: Default Route forwarding via eBGP
Replies: 4
Views: 1271

Re: Default Route forwarding via eBGP

Default route is special case, you will need to enable default-originate on all routers along the path to advertise default route.
by mrz
Tue Oct 13, 2020 3:53 pm
Forum: RouterOS beta
Topic: how to understand routing in v7
Replies: 7
Views: 4169

Re: how to understand routing in v7

I know my VPN tunnel,s are workjing as i can access the hosts behind then from the ROSv7 device itself fine.. I can ping the hosts from a laptop just no access.. it seems something in this wierd routin g method is causing me issues.. my /ip route i nthe gUI changes all the time.. If ping works and ...
by mrz
Tue Oct 13, 2020 8:13 am
Forum: Forwarding Protocols
Topic: Graceful restart
Replies: 9
Views: 8337

Re: Graceful restart

Yes, in ROSv7.
by mrz
Mon Oct 12, 2020 5:11 pm
Forum: General
Topic: BGP Filter by communities
Replies: 3
Views: 720

Re: BGP Filter by communities

/routing filter
 add  chain=<Your_out_chain> prefix=<your_prefix> set-bgp-communities=174:970
by mrz
Mon Oct 12, 2020 4:25 pm
Forum: General
Topic: BGP Filter by communities
Replies: 3
Views: 720

Re: BGP Filter by communities

According to docs you should be advertising with 174:970 community.
by mrz
Fri Oct 09, 2020 2:29 pm
Forum: General
Topic: ECMP balancing sometimes breaks TCP connection
Replies: 9
Views: 1868

Re: ECMP balancing sometimes breaks TCP connection

Don't trust anything written in the forum, wiki has correct answer :))
by mrz
Mon Oct 05, 2020 3:42 pm
Forum: RouterOS beta
Topic: VRF status with RouterOS v7
Replies: 16
Views: 7871

Re: VRF status with RouterOS v7

Since we now have IPv6 VRF support, I do not see the reason why not.
by mrz
Mon Oct 05, 2020 1:46 pm
Forum: Scripting
Topic: Torrent blocking working in y2020
Replies: 34
Views: 27444

Re: Torrent blocking working in y2020

The Torrent system on it's own is not illegal.
Downloading copyrighted content is illegal.
by mrz
Mon Oct 05, 2020 1:31 pm
Forum: RouterOS beta
Topic: VRF status with RouterOS v7
Replies: 16
Views: 7871

Re: VRF status with RouterOS v7

Yes of course, it will be implemented.
by mrz
Mon Oct 05, 2020 1:30 pm
Forum: Forwarding Protocols
Topic: OSPF / PTMP no subnets
Replies: 5
Views: 2214

Re: OSPF / PTMP no subnets

You use PtMP on non broadcast networks where hosts in the same L2 network cannot reach each other directly.
by mrz
Thu Oct 01, 2020 1:23 pm
Forum: RouterOS beta
Topic: fq_codel or cake in v7
Replies: 68
Views: 41282

Re: fq_codel or cake in v7

++1
by mrz
Thu Sep 24, 2020 3:00 pm
Forum: General
Topic: Re-sorting mangle rules order [SOLVED]
Replies: 1
Views: 857

Re: Re-sorting mangle rules order [SOLVED]

From terminal use "move" command
Or winbox drag and drop
by mrz
Wed Sep 23, 2020 3:31 pm
Forum: General
Topic: IPv6 Routing Mark in Firewall > Mangle Rules
Replies: 60
Views: 21819

Re: IPv6 Routing Mark in Firewall > Mangle Rules

Already supported in v7 beta
by mrz
Tue Sep 22, 2020 12:25 pm
Forum: General
Topic: Ripple20 - Treck stack vulnerabilities
Replies: 6
Views: 2000

Re: Ripple20 - Treck stack vulnerabilities

MT products are safe against Ripple20. And we do not use Treck IP stack anywhere.
by mrz
Mon Sep 21, 2020 6:26 pm
Forum: Scripting
Topic: Export over api differs from export over terminal [SOLVED]
Replies: 5
Views: 2455

Re: Export over api differs from export over terminal [SOLVED]

It is not the lib problem. Unfortunately at the moment API behaves like this.
by mrz
Thu Sep 17, 2020 2:38 pm
Forum: Forwarding Protocols
Topic: unable to delete/rename default bgp
Replies: 3
Views: 1241

Re: unable to delete/rename default bgp

Items are hard coded if other default configuration might depend on existence of such items.
by mrz
Thu Sep 17, 2020 10:49 am
Forum: Forwarding Protocols
Topic: unable to delete/rename default bgp
Replies: 3
Views: 1241

Re: unable to delete/rename default bgp

Default items cannot be renamed or deleted.
If you want your custom instances then add new ones and disable default.
by mrz
Tue Sep 15, 2020 10:00 am
Forum: RouterOS beta
Topic: v7.1beta2 [development] is released!
Replies: 385
Views: 153587

Re: v7.1beta2 [development] is released!

What kind of weirdness? Known issue is that ospf route can appear twice in routing table.
by mrz
Mon Sep 14, 2020 4:08 pm
Forum: General
Topic: IPv6, No routing to default gateway possible on my CHR
Replies: 2
Views: 1249

Re: IPv6, No routing to default gateway possible on my CHR

Adjust scopes, default route will not be able to recursively resolve the gateway if scopes and target scopes are exactly the same as values of route over which you want to resolve
https://wiki.mikrotik.com/wiki/Manual:I ... hop_lookup
by mrz
Mon Sep 14, 2020 12:00 pm
Forum: RouterOS beta
Topic: VRF status with RouterOS v7
Replies: 16
Views: 7871

Re: VRF status with RouterOS v7

You cannot find those parameters because VPNv4 is not implemented yet.
by mrz
Thu Sep 10, 2020 9:52 am
Forum: RouterOS beta
Topic: IGMP-Proxy missing in v7.1beta2?
Replies: 2
Views: 1554

Re: IGMP-Proxy missing in v7.1beta2?

There is no multicast package, it is now part of system package, however IGMP-Proxy is not available in ROSv7 at the moment.
by mrz
Wed Sep 09, 2020 3:24 pm
Forum: General
Topic: Migration of CA
Replies: 11
Views: 2256

Re: Migration of CA

ROS also supports automatic certificate enrolment protocol (check SCEP) so for large amount of clients it can be used.
by mrz
Wed Sep 09, 2020 2:29 pm
Forum: General
Topic: IPv6 routing
Replies: 2
Views: 790

Re: IPv6 routing

You can assign /128 address from /112 subnet on the server and route to to destination using link-local gateways
by mrz
Wed Sep 09, 2020 11:24 am
Forum: Scripting
Topic: dhcpv6-client receive dns name from options
Replies: 7
Views: 1568

Re: dhcpv6-client receive dns name from options

In dhcp clients script you can get options variable, which contains array of all received options. So you can extract option 40 with ($options->"40")
by mrz
Mon Sep 07, 2020 2:07 pm
Forum: General
Topic: Migration of CA
Replies: 11
Views: 2256

Re: Migration of CA

You cannot load backups between different type of devices, there may be unexpected results.
And even if backup loads, after loading config you will still need to decrypt private keys with passphrase. It is made that way for security reasons.
by mrz
Mon Sep 07, 2020 9:16 am
Forum: Forwarding Protocols
Topic: BGP Blackhole not working
Replies: 4
Views: 2573

Re: BGP Blackhole not working

Winbox already lists only unicast and unreachable for IPv6 routes the same as CLI.
by mrz
Mon Sep 07, 2020 9:14 am
Forum: RouterOS beta
Topic: Gateway State is "unreachable" in RouterOS 7
Replies: 1
Views: 2398

Re: Gateway State is "unreachable" in RouterOS 7

There is no ip/nexthop menu in ROS v7.
Instead you can check forwarding path: /routing/forwarding-path/print
by mrz
Fri Sep 04, 2020 4:34 pm
Forum: General
Topic: New router (CCR2004-1G-12S+2XS) - can't set up LAN
Replies: 12
Views: 2093

Re: New router (CCR2004-1G-12S+2XS) - can't set up LAN

It is possible that public IP subnet is actually routed to you over local addresses. But only ISP can give you definite answer.
by mrz
Fri Sep 04, 2020 1:44 pm
Forum: Forwarding Protocols
Topic: BFD Open port on default conf
Replies: 5
Views: 5242

Re: BFD Open port on default conf

You can set raw rules to accept packets from known destinations.
by mrz
Fri Sep 04, 2020 12:57 pm
Forum: RouterOS beta
Topic: Feature request : Ping check Gateway
Replies: 2
Views: 1057

Re: Feature request : Ping check Gateway

You can do this recursively.
viewtopic.php?t=157048
by mrz
Fri Sep 04, 2020 12:00 pm
Forum: General
Topic: Disable ICMP From Outside
Replies: 5
Views: 2884

Re: Disable ICMP From Outside

Of course it will drop incoming ICMP packets because you added rule to drop all incoming ICMP packets.
Read the article I provided earlier to at least understand the basics of how to set up firewall rules.
by mrz
Thu Sep 03, 2020 1:11 pm
Forum: General
Topic: Disable ICMP From Outside
Replies: 5
Views: 2884

Re: Disable ICMP From Outside

See basic firewall examples in the manual:
https://help.mikrotik.com/docs/display/ ... gtheRouter
by mrz
Tue Sep 01, 2020 11:51 am
Forum: General
Topic: BGP spamming updates
Replies: 6
Views: 1943

Re: BGP spamming updates

Since there is not a lot of info provided. I assume you are trying to advertise probably some connected or maybe other IGP routes which are flapping in routing table. My suggestion would be to add prefix that you want to advertise in BGP networks without synchronize, disable all redistribute-xx in b...
by mrz
Mon Aug 31, 2020 3:03 pm
Forum: Forwarding Protocols
Topic: using prefix lists in bgp filters [SOLVED]
Replies: 2
Views: 2876

Re: using prefix lists in bgp filters [SOLVED]

Your mentioned Prefix list is used only for RIP. There is no functionality in ROSv6 to specify list of prefixes in one filter rule.

However there is a plan to implement use of address lists in ROSv7
by mrz
Mon Aug 31, 2020 2:42 pm
Forum: RouterOS beta
Topic: IPv6 Mangle routing-mark?
Replies: 3
Views: 5270

Re: IPv6 Mangle routing-mark?

Works as expected, note that routing table should be able to add routes in FIB: [admin@MikroTik] /routing/table> add name=test fib [admin@MikroTik] /routing/table> /ipv6/firewall/mangle [admin@MikroTik] /ipv6/firewall/mangle> add action=mark-routing new-routing-mark=test chain: input [admin@MikroTik...
by mrz
Mon Aug 31, 2020 2:34 pm
Forum: RouterOS beta
Topic: v7.1 recursive routes
Replies: 16
Views: 9200

Re: v7.1 recursive routes

Adjust scopes correctly.
/ip route
add dst-address=9.9.9.9/32 gateway=192.168.1.1 scope=11 target-scope=10
add gateway=9.9.9.9 target-scope=11
by mrz
Tue Aug 18, 2020 9:39 am
Forum: RouterOS beta
Topic: routing-mark and table and mangle in RouterOS v7 BETA 7
Replies: 16
Views: 47854

Re: routing-mark and table and mangle in RouterOS v7 BETA 7

Now again, look at this line from the manual (character by character)
/ip route add dst-address=8.8.8.8 gateway=172.16.1.1@main routing-table=myTable
And compare to what you are trying to set

Hint (again from the manual):
(as per user requests v7.0beta9 adds back 'routing-table' parameter)
by mrz
Mon Aug 17, 2020 10:58 am
Forum: RouterOS beta
Topic: routing-mark and table and mangle in RouterOS v7 BETA 7
Replies: 16
Views: 47854

Re: routing-mark and table and mangle in RouterOS v7 BETA 7

!!!!!!
/routing table add name=IRT-TEST fib
!!!!!
by mrz
Mon Aug 17, 2020 10:57 am
Forum: Forwarding Protocols
Topic: BGP - Convert origin ‘egp’ to ‘igp’ [SOLVED]
Replies: 3
Views: 2129

Re: BGP - Convert origin ‘egp’ to ‘igp’ [SOLVED]

In ROSv6 it is not possible, but v7 has some new filter features including origin change.
by mrz
Mon Aug 17, 2020 10:55 am
Forum: Forwarding Protocols
Topic: Only one route active with 3 BGP peers [SOLVED]
Replies: 1
Views: 1872

Re: Only one route active with 3 BGP peers [SOLVED]

Because BGP is designed to use only one best path by default.
by mrz
Thu Aug 13, 2020 9:48 am
Forum: Scripting
Topic: Problems when parsing routing table and prefixes change
Replies: 1
Views: 919

Re: Problems when parsing routing table and prefixes change

Find returns array of route ids that were matched by criteria (this can take some time if table is large) Foreach then goes through returned array which also takes time if array is very large. And if routing table changed after find returned the result you may get unexpected results. If route was re...
by mrz
Wed Aug 12, 2020 11:16 am
Forum: Scripting
Topic: Python API doesn't connect
Replies: 2
Views: 2021

Re: Python API doesn't connect

If port is open, check this working Python client:
https://wiki.mikrotik.com/wiki/Manual:API_Python3
by mrz
Thu Aug 06, 2020 10:28 am
Forum: Scripting
Topic: help getting id in python api
Replies: 3
Views: 1936

Re: help getting id in python api

NatRule.get(comment=RDP')[0]["id"]
by mrz
Mon Aug 03, 2020 10:01 am
Forum: Scripting
Topic: API Links
Replies: 155
Views: 218110

Re: API Links

API does not support such feature. You can only use queries to filter returned items by specific criteria, but no paging.
by mrz
Fri Jul 31, 2020 9:11 am
Forum: General
Topic: something wrong on the wiki
Replies: 6
Views: 2019

Re: something wrong on the wiki

Yes should be correct,
by mrz
Fri Jul 31, 2020 9:09 am
Forum: RouterOS beta
Topic: CCR and RouterOS V7.1. BGP very slowly.
Replies: 2
Views: 2415

Re: CCR and RouterOS V7.1. BGP very slowly.

Please contact support, we will investigate why it is so slow on your router.
by mrz
Thu Jul 30, 2020 5:17 pm
Forum: Forwarding Protocols
Topic: VRF Interface Limit
Replies: 14
Views: 5823

Re: VRF Interface Limit

Not really but almost. Total amount of tables is limited to 65k (this is including policy routing tables and vrfs in total).
by mrz
Thu Jul 30, 2020 4:39 pm
Forum: General
Topic: something wrong on the wiki
Replies: 6
Views: 2019

Re: something wrong on the wiki

192.168.0.0/16 was added by mistake.
Also fixed title form IPv4 to Ipv6.
by mrz
Thu Jul 30, 2020 8:59 am
Forum: Forwarding Protocols
Topic: VRF Interface Limit
Replies: 14
Views: 5823

Re: VRF Interface Limit

v7beta does not have this limit.
by mrz
Tue Jul 28, 2020 1:59 pm
Forum: General
Topic: winbox interface too small
Replies: 7
Views: 3192

Re: winbox interface too small

No, session is saved, next time you connect to the router zoom is restored from saved session.
by mrz
Tue Jul 28, 2020 1:57 pm
Forum: General
Topic: winbox interface too small
Replies: 7
Views: 3192

Re: winbox interface too small

Settings->Zoom-in
by mrz
Mon Jul 27, 2020 2:09 pm
Forum: RouterOS beta
Topic: /ip/route/check command disappeared?
Replies: 19
Views: 13933

Re: /ip/route/check command disappeared?

You can get route that resolves specified destination: /ip route print detail where x.x.x.x in dst-address and active DAd dst-address=0.0.0.0/0 routing-table=main pref-src="" gateway=10.155.101.1 immediate-gw=10.155.101.1%bridge type=unicast distance=1 scope=30 target-scope=10 From there y...
by mrz
Mon Jul 27, 2020 12:33 pm
Forum: RouterOS beta
Topic: [FEATURE REQUEST] IPv6 Route Rules [SOLVED]
Replies: 4
Views: 2726

Re: [FEATURE REQUEST] IPv6 Route Rules [SOLVED]

You are asking to add feature for v6 in v7beta forum? :D

An to answer the question, no v6 will not have ipv6 policy routing support.
by mrz
Mon Jul 27, 2020 11:08 am
Forum: RouterOS beta
Topic: BGP inside VRFs
Replies: 4
Views: 2636

Re: BGP inside VRFs

Yes, at the moment BGP in VRF does not work, we will try to make it work until next beta release.
by mrz
Mon Jul 27, 2020 10:34 am
Forum: RouterOS beta
Topic: ROSv7b8 and RPKI
Replies: 10
Views: 4594

Re: ROSv7b8 and RPKI

Hello, Which RFC you are referring to? If you mean something like this: https://rpki.readthedocs.io/en/latest/about/faq.html#what-if-the-rpki-system-becomes-unavailable-or-some-other-catastrophe-occurs-will-my-signed-prefixes-become-unreachable-to-others-will-other-prefixes-my-routers-learned-over-b...
by mrz
Mon Jul 27, 2020 10:06 am
Forum: Virtualization
Topic: MetaRouter removed ???
Replies: 1
Views: 4095

Re: MetaRouter removed ???

Metarouter is supported only on single core mips devices.
by mrz
Mon Jul 27, 2020 10:02 am
Forum: Scripting
Topic: Loop through submenus [SOLVED]
Replies: 3
Views: 1998

Re: Loop through submenus [SOLVED]

No, you cannot use variable values as menu names or parameter/variable names.

One workaround is to use :parse
by mrz
Mon Jul 27, 2020 9:59 am
Forum: RouterOS beta
Topic: [FEATURE REQUEST] IPv6 Route Rules [SOLVED]
Replies: 4
Views: 2726

Re: [FEATURE REQUEST] IPv6 Route Rules [SOLVED]

How to use routing rules in v7 is described here:
https://help.mikrotik.com/docs/display/ ... icyRouting

Rules work for both ipv4 and ipv6.
by mrz
Mon Jul 27, 2020 9:58 am
Forum: RouterOS beta
Topic: /ip/route/check command disappeared?
Replies: 19
Views: 13933

Re: /ip/route/check command disappeared?

Check is not implemented in ROS v7.
What does check give you that "/routing route print" does not?
by mrz
Thu Jul 23, 2020 5:15 pm
Forum: RouterOS beta
Topic: OSPF routes marked invalid
Replies: 15
Views: 9981

Re: OSPF routes marked invalid

FYI problem is only on P2P interfaces (not ospf interface type but actual P2P interfaces like l2tp etc. )
We will fix the problem as soon as possible.
by mrz
Wed Jul 22, 2020 4:51 pm
Forum: RouterOS beta
Topic: v7.1beta1 [development] is released!
Replies: 103
Views: 57504

Re: v7.1beta1 [development] is released!

Show output of
/routing/route/print detail
by mrz
Wed Jul 22, 2020 3:00 pm
Forum: RouterOS beta
Topic: OSPF routes marked invalid
Replies: 15
Views: 9981

Re: OSPF routes marked invalid

Does it start to work if you change interface type from point-to-point to broadcast?
by mrz
Wed Jul 22, 2020 12:40 pm
Forum: General
Topic: Slow ovpn cpu 100%
Replies: 5
Views: 1774

Re: Slow ovpn cpu 100%

Single core on ARMs (CCR2004 or RB4011) has a bit better single core performance, but do not expect magic. You will still not be able to do 600 / 600Mbs over OVPN.
by mrz
Wed Jul 22, 2020 10:58 am
Forum: RouterOS beta
Topic: v7.1beta1 [development] is released!
Replies: 103
Views: 57504

Re: v7.1beta1 [development] is released!

CRS317 supports up to 4096 NAT entries. To clarify it is not about how many rules you have, but how many connections can be offloaded.
by mrz
Wed Jul 22, 2020 10:34 am
Forum: General
Topic: Slow ovpn cpu 100%
Replies: 5
Views: 1774

Re: Slow ovpn cpu 100%

One CCR core can encrypt/decrypt ~150Mbps, one tunnel is tied to one core, so it sounds about right.

If you want faster tunnel use ipsec which can use HW acceleration.
by mrz
Wed Jul 22, 2020 10:01 am
Forum: RouterOS beta
Topic: Enable BGP on ROSv7
Replies: 14
Views: 6643

Re: Enable BGP on ROSv7

Be more specific what exactly is not working.
by mrz
Wed Jul 22, 2020 9:41 am
Forum: RouterOS beta
Topic: IPv6 BGP routes unreachable [SOLVED]
Replies: 4
Views: 3944

Re: IPv6 BGP routes unreachable [SOLVED]

Please contact support. Add supout file and packet dump to see what exactly that edge router is sending.
by mrz
Tue Jul 21, 2020 9:48 am
Forum: Forwarding Protocols
Topic: Balanced ECMP on IPv6
Replies: 3
Views: 2136

Re: Balanced ECMP on IPv6

RouterOS v6 does not support IPv6 ECMP.

This feature is implemented in ROS v7 beta.
by mrz
Mon Jul 20, 2020 12:48 pm
Forum: RouterOS beta
Topic: CRS317 routing speed with pppoe and L3 offloading
Replies: 6
Views: 2782

Re: CRS317 routing speed with pppoe and L3 offloading

BTW CRS317 CPU has enough power to handle 1Gbps PPPOE traffic, probably on the edge but should handle it.
by mrz
Mon Jul 20, 2020 10:23 am
Forum: RouterOS beta
Topic: v7.0beta8 [development] is released!
Replies: 178
Views: 92245

Re: v7.0beta8 [development] is released!

in routing filter the is a bug! i created two chain: in-v4 and out-v4 Going in templates, the two chain are allowed to be chossen by input.filter but not by out put filter [admin@test-100G] /routing/bgp/template> set 0 input.filter= in-v4 out-v4 Output requires selection rules: /routing filter rule...
by mrz
Mon Jul 20, 2020 10:12 am
Forum: RouterOS beta
Topic: CRS317 routing speed with pppoe and L3 offloading
Replies: 6
Views: 2782

Re: CRS317 routing speed with pppoe and L3 offloading

L3 offload will not work with pppoe.
by mrz
Tue Jul 14, 2020 2:26 pm
Forum: General
Topic: CHR + AWS + IPv6
Replies: 16
Views: 4639

Re: CHR + AWS + IPv6

fe80::430:xxxxxxxxxx%ether1-WAN is link local address and it should be reachable unless blocked by service provider.
You can always disable "add-default-route" in dhcp settings and add static one.
by mrz
Mon Jul 13, 2020 9:51 am
Forum: RouterOS beta
Topic: OSPF problems
Replies: 4
Views: 3540

Re: OSPF problems

Please contact support with attached supout files. And at the moment do not use winbox for any tasks related to routing protocols.
by mrz
Wed Jul 08, 2020 1:52 pm
Forum: RouterOS beta
Topic: v7.0beta8 [development] is released!
Replies: 178
Views: 92245

Re: v7.0beta8 [development] is released!

Hi there, Just wondering if anyone is successfully using BFD as a gateway check on a static route? I am assuming this can be configured as a standalone option (as in, does not require BGP or other protocols as well) but packet captures show no BFD packets are sent (RB1100). Packet captures shows BF...
by mrz
Tue Jul 07, 2020 11:06 am
Forum: Forwarding Protocols
Topic: Mikrotik L2TPV3
Replies: 15
Views: 17101

Re: Mikrotik L2TPV3

Could you please tell me - are there any plans for implementing of any other multi-vendor EOIP capable technology? i.e. vxlan/gretap
VXLAN is already supported in ROSv7
by mrz
Tue Jun 30, 2020 3:47 pm
Forum: Forwarding Protocols
Topic: BGP Ram useage?
Replies: 3
Views: 1568

Re: BGP Ram useage?

1Million routes can easily fit in 256MB of RAM, so what you have told is not true. Not to mention that SD card cannot be used to extend RAM.
by mrz
Tue Jun 30, 2020 3:44 pm
Forum: Beginner Basics
Topic: fw does not drop winbox mac-telnet [SOLVED]
Replies: 8
Views: 3326

Re: fw does not drop winbox mac-telnet [SOLVED]

See packet flow diagram
https://wiki.mikrotik.com/wiki/Manual:Packet_Flow

mac telnet is not layer3 connection, so from in-interface it goes directly to local-in
by mrz
Tue Jun 30, 2020 10:00 am
Forum: Beginner Basics
Topic: DHCP relay
Replies: 5
Views: 1543

Re: DHCP relay

RFC already describes scenario when it should be used: "Relay Agent Information option is inserted by the DHCP relay agent when forwarding client-originated DHCP packets to a DHCP server. Servers recognizing the Relay Agent Information option may use the information to implement IP address or o...
by mrz
Mon Jun 29, 2020 4:24 pm
Forum: RouterOS beta
Topic: v7.0beta8 [development] is released!
Replies: 178
Views: 92245

Re: v7.0beta8 [development] is released!

It would be like asking MikroTik to make QUIC available. It is already available. Well, RouterOS can be client as well, so for example fetch command could benefit. It's not a big win there, though. It's probably not only the RouterOS traffic alone that would benefit from MPTCP. If one uses a WAN up...
by mrz
Mon Jun 29, 2020 2:50 pm
Forum: Beginner Basics
Topic: DHCP relay
Replies: 5
Views: 1543

Re: DHCP relay

by mrz
Fri Jun 26, 2020 12:14 pm
Forum: General
Topic: Multiple Road Warrior L2TP/IPsec clients behind NAT - solved
Replies: 98
Views: 83407

Re: Multiple Road Warrior L2TP/IPsec clients behind NAT - solved

Post ipsec policies and installed SAs from version where it works and from version where it does not. Multiple l2tp/ipsec connections behind one NAT router will work if at least one of the following conditions apply: *) each client gets NATed behind unique public IP address; *) each client uses uniq...
by mrz
Fri Jun 19, 2020 1:53 pm
Forum: RouterOS beta
Topic: ROSv7b8 and RPKI
Replies: 10
Views: 4594

Re: ROSv7b8 and RPKI

I can confirm the problem, we are looking into it.
by mrz
Thu Jun 18, 2020 10:08 am
Forum: RouterOS beta
Topic: ROSv7b8 and RPKI
Replies: 10
Views: 4594

Re: ROSv7b8 and RPKI

@schadom What was your setup? Which validator were you using? With all of the cries out on the forums for RPKI, I find it hard to believe that we are the only two people to have tested this? Post the rules that is not working. Did you run through verify rule with (rpki-verify=xxx) before trying to ...
by mrz
Tue Jun 16, 2020 12:52 pm
Forum: RouterOS beta
Topic: Mark Routing & IP Route in v7.0beta8
Replies: 4
Views: 4482

Re: Mark Routing & IP Route in v7.0beta8

@pe1chl In that example replace this: /routing rule add dst-address=8.8.8.8 action=lookup-only-in-table table=myTable with this (the same rule as you would use in ROSv6): /ip firewall mangle add chain=prerouting dst-address=8.8.8.8 action=mark-routing new-routing-mark=myTable As stated in the manual...
by mrz
Mon Jun 15, 2020 1:11 pm
Forum: Scripting
Topic: Script for If enivorment = then do
Replies: 14
Views: 3387

Re: Script for If enivorment = then do

Variable name contains arithmetic character. I would suggest to avoid creating such variable names, but if you still do then remember that such names must be always in double quotes, like in this example:
:global "not-good-var-name" "x"
:put $"not-good-var-name"
by mrz
Fri Jun 12, 2020 9:05 am
Forum: Forwarding Protocols
Topic: OSPF issue
Replies: 1
Views: 1083

Re: OSPF issue

You have to adjust interface costs on all links along available path.
by mrz
Fri Jun 12, 2020 9:03 am
Forum: Forwarding Protocols
Topic: MPLS forwarding table issue
Replies: 2
Views: 1378

Re: MPLS forwarding table issue

ECMP is not supported, MPLS will use only one path
by mrz
Wed Jun 10, 2020 8:31 am
Forum: Forwarding Protocols
Topic: [SOLVED] BGP Route Filters match-chain not working
Replies: 5
Views: 2815

Re: BGP Route Filters match-chain not working

chain returns true only if action=accept. If you set action discard in match chain it will never return true, Discard in this case means discard prefix from match chain. To translate your rules: * chain ASTEROID-IN-v4 gets prefix with AS 6939 * rule nr.2 sends pefix to be matched in DISCARD-UNWANTED...
by mrz
Tue Jun 09, 2020 2:02 pm
Forum: Forwarding Protocols
Topic: [SOLVED] BGP Route Filters match-chain not working
Replies: 5
Views: 2815

Re: BGP Route Filters match-chain not working

@alex
it does not work that way. match-chain is the name of the chain which is used to evaluate the route. If the chain accepts the route, 'match-chain' property produces a true match
by mrz
Tue Jun 09, 2020 8:42 am
Forum: RouterOS beta
Topic: ROSv7 documentation/ config guides
Replies: 14
Views: 6620

Re: ROSv7 documentation/ config guides

and if you added the network to advertise to the networks list as passive you would get a regular type 2 or 3 LSA V7 is the same, if you add network it is advertised as type2 or 3 LSA Passive and authentication parameters are there but not working at te moment, so it will not be a step back. BTW we...
by mrz
Mon Jun 08, 2020 4:36 pm
Forum: RouterOS beta
Topic: ROSv7 documentation/ config guides
Replies: 14
Views: 6620

Re: ROSv7 documentation/ config guides

Some basic stuff to start with ROSv7 routing config:
https://help.mikrotik.com/docs/display/ ... g+Examples
by mrz
Sat Jun 06, 2020 6:32 pm
Forum: RouterOS beta
Topic: v7.0beta8 [development] is released!
Replies: 178
Views: 92245

Re: v7.0beta8 [development] is released!

IP Acccounting is deprecated and removed from ROS v7. What do I use then to get traffic data from each client that I do use in Splunk for MikroTik? SNMP is not an option. Script will then fail 100% if some do an upgrade to 7.x, since on-error seem to not handle this situation. . On-error catches on...
by mrz
Fri Jun 05, 2020 10:59 pm
Forum: RouterOS beta
Topic: v7.0beta8 [development] is released!
Replies: 178
Views: 92245

Re: v7.0beta8 [development] is released!

IP Acccounting is deprecated and removed from ROS v7.
by mrz
Fri Jun 05, 2020 9:11 pm
Forum: RouterOS beta
Topic: v7.0beta8 [development] is released!
Replies: 178
Views: 92245

Re: v7.0beta8 [development] is released!

Where is CAKE?!?!?!?

Literally everyone expects it, yet there's nothing about it from mikrotik..

Kind of pathetic on their part tbh.
You can find cakes here:
https://majaskukas.lv/
Even trendy gluten free ones, which probably you like the most.
by mrz
Fri Jun 05, 2020 9:03 pm
Forum: RouterOS beta
Topic: ROSv7 documentation/ config guides
Replies: 14
Views: 6620

Re: ROSv7 documentation/ config guides

There is no equivalent. If you did not specify output filter chain in the templae, then all routes from the routing table is being advertised.
If you specify output chain then by default chain blocks everything. You need to configure filters to accept prefixes you want to advertise from routing table.
by mrz
Fri Jun 05, 2020 1:43 pm
Forum: RouterOS beta
Topic: v7.0beta8 [development] is released!
Replies: 178
Views: 92245

Re: v7.0beta8 [development] is released!

Those parameters are subject to change, so no manual for now.
by mrz
Fri Jun 05, 2020 12:28 am
Forum: RouterOS beta
Topic: ROSv7 documentation/ config guides
Replies: 14
Views: 6620

Re: ROSv7 documentation/ config guides

At the moment there is none because configuration can and probably will change.

What exactly you were not able to set up?
by mrz
Thu Jun 04, 2020 5:28 pm
Forum: RouterOS beta
Topic: v7.0beta8 [development] is released!
Replies: 178
Views: 92245

Re: v7.0beta8 [development] is released!

@pe1chl this message typically will appear when there is no local address set or not piicked automatically.
by mrz
Thu Jun 04, 2020 5:22 pm
Forum: RouterBOARD hardware
Topic: ARP TABLE ENTY FROM AN INTERFACE DISABLED
Replies: 1
Views: 913

Re: ARP TABLE ENTY FROM AN INTERFACE DISABLED

That is static entry that you have added. If you dont like it remove it.
by mrz
Thu Jun 04, 2020 5:05 pm
Forum: RouterOS beta
Topic: v7.0beta8 [development] is released!
Replies: 178
Views: 92245

Re: v7.0beta8 [development] is released!

IPv6 works a lot better in v7, ipv6 policy routing and ECMP coming soon
by mrz
Thu Jun 04, 2020 5:00 pm
Forum: General
Topic: RPKI
Replies: 49
Views: 19876

Re: RPKI

Yes,
RouterOS implements RTR client. You connect to the server which will send route validity information.
This informaton can be used to validate routes in route filters against group with "rpki-validate".
ANd then further in filters "match-rpki" can be used to match exact state.
by mrz
Thu Jun 04, 2020 4:49 pm
Forum: RouterOS beta
Topic: routing-mark and table and mangle in RouterOS v7 BETA 7
Replies: 16
Views: 47854

Re: routing-mark and table and mangle in RouterOS v7 BETA 7

/routing table add name=IRT-TEST fib /ip route add dst-address=0.0.0.0/0@IRT-TEST gateway=10.10.54.161@main check-gateway=ping distance=10 add check-gateway=ping distance=10 dst-address=1.1.1.1/32 gateway=10.10.54.145 /routing rule add dst-address=8.8.8.8 action=lookup table=IRT-TEST firewall the s...
by mrz
Thu Jun 04, 2020 3:47 pm
Forum: RouterOS beta
Topic: routing-mark and table and mangle in RouterOS v7 BETA 7
Replies: 16
Views: 47854

Re: routing-mark and table and mangle in RouterOS v7 BETA 7

First add table in /routing table menu

THen you can add routing rules in /routing rule menu

and routes in specific table
/ip route add dst-address=x.x.x.x@table gateway=y.y.y.y@main
by mrz
Fri May 29, 2020 9:28 am
Forum: General
Topic: API for C#
Replies: 3
Views: 2368

Re: API for C#

In the same topic look at "Class with SSL support", it has new authentication method.
by mrz
Mon May 18, 2020 10:04 am
Forum: RouterOS beta
Topic: beta5: Is this an error in the script parser? [SOLVED]
Replies: 2
Views: 5967

Re: beta5: Is this an error in the script parser? [SOLVED]

First you are trying to use undeclared variable gArr Then you are declaring global variable with the same name in 'if' scope. I assume that you want to access already existing global variable and if it does not exist or is empty then add first entry, in that case script should look something like th...
by mrz
Wed May 13, 2020 8:04 pm
Forum: RouterOS beta
Topic: beta5: script parser error [SOLVED]
Replies: 2
Views: 4979

Re: beta5: script parser error [SOLVED]

It is not related to beta version and as far as I know never supposed to work. What you are doing in script is run first loop which returns internal id (for example *1 for ether1) In next loop you are trying to find IP address with interface equal to "*1", obviously it will fail because th...
by mrz
Mon Apr 27, 2020 10:14 am
Forum: Forwarding Protocols
Topic: OSPF disabling all ports on 'state change from Full to Down'
Replies: 12
Views: 7299

Re: OSPF disabling all ports on 'state change from Full to Down'

CCR does not work correctly with half duplex links, it is hardware limitation. For interface not to hang completely it is occasionally flapped. Regarding RB3011, if switch group is overloaded it will reset the switch group One workaround is: /interface ethernet switch set switch1,switch2 cpu-flow-co...
by mrz
Tue Apr 21, 2020 1:33 pm
Forum: RouterOS beta
Topic: FEATURE REQUEST: Add Basic Firewall Rule Wizard
Replies: 71
Views: 23382

Re: FEATURE REQUEST: Add Basic Firewall Rule Wizard

Very similar to default config is described in first time configuration
https://help.mikrotik.com/docs/display/ ... gtheRouter
"ProtectingtheRouter" and "ProtectingtheClient" sections
by mrz
Wed Apr 15, 2020 1:12 pm
Forum: Forwarding Protocols
Topic: Problems with MPLS IPv4 VPN
Replies: 72
Views: 32256

Re: Problems with MPLS IPv4 VPN

Regarding Issue1:
RDs should be unique, so this is not a RouterOS bug, but misconfiguration.

Regarding Issue2:
Yes we are aware of route selection problems in VRFs, unfortunately you will have to wait for ROS v7 updates.
by mrz
Wed Apr 15, 2020 8:44 am
Forum: RouterOS beta
Topic: Question: Multi-thread BGP
Replies: 10
Views: 7765

Re: Question: Multi-thread BGP

Load distribution between cores can be done without multithreading.
https://www.youtube.com/watch?v=NbfKplzda7I
by mrz
Tue Apr 14, 2020 6:07 pm
Forum: RouterOS beta
Topic: Question: Multi-thread BGP
Replies: 10
Views: 7765

Re: Question: Multi-thread BGP

All I can say is tht it will not be multithreaded. AFAIK none of currently existing implementations are fully multithreaded.
by mrz
Tue Apr 14, 2020 6:03 pm
Forum: RouterOS beta
Topic: Feature Request: BGPQ3 Automated Routing Policies
Replies: 2
Views: 2353

Re: Feature Request: BGPQ3 Automated Routing Policies

You should ask BGPQ3 devs not MT.
by mrz
Tue Apr 14, 2020 11:29 am
Forum: RouterOS beta
Topic: Cannot set routing-mark or table for routing rule
Replies: 18
Views: 32237

Re: Cannot set routing-mark or table for routing rule

Yes, routing marks do not work at the moment.
by mrz
Tue Apr 14, 2020 9:34 am
Forum: RouterOS beta
Topic: mangle and routing-mark can not work for RouterOS v7
Replies: 9
Views: 7771

Re: mangle and routing-mark can not work for RouterOS v7

THere are several problems with routing marks in beta5. Wait until beta6 is released.
by mrz
Thu Apr 09, 2020 3:03 pm
Forum: General
Topic: RB133 Slow internet speed test
Replies: 3
Views: 1908

Re: RB133 Slow internet speed test

mipsle support is dropped (last fully supported version 6.32.3 and 6.32.4)
by mrz
Thu Apr 09, 2020 12:07 pm
Forum: RouterOS beta
Topic: V7 Routing Protocols Option [SOLVED]
Replies: 3
Views: 10382

Re: V7 Routing Protocols Option [SOLVED]

no, it is in-house development.
by mrz
Thu Apr 09, 2020 11:28 am
Forum: RouterOS beta
Topic: Feature Request - BGP RPKI
Replies: 21
Views: 10887

Re: Feature Request - BGP RPKI

Currently work in progress
by mrz
Thu Apr 09, 2020 11:28 am
Forum: RouterOS beta
Topic: V7 Routing Protocols Option [SOLVED]
Replies: 3
Views: 10382

Re: V7 Routing Protocols Option [SOLVED]

RouterOS is not using quagga and will not use FRR
by mrz
Thu Apr 09, 2020 11:25 am
Forum: Forwarding Protocols
Topic: How to redistribute OSPF Metric to BGP Local Pref.
Replies: 1
Views: 2180

Re: How to redistribute OSPF Metric to BGP Local Pref.

RouterOS v6 does not have such functionality.
by mrz
Wed Apr 01, 2020 12:10 pm
Forum: Forwarding Protocols
Topic: OSPF disabling all ports on 'state change from Full to Down'
Replies: 12
Views: 7299

Re: OSPF disabling all ports on 'state change from Full to Down'

OSPF goes down because physical links are flapping, it can be seen in your logs. Logs are written asynchronously, so when difference between events are in milliseconds interface flap may appear after OSPF message.
by mrz
Wed Apr 01, 2020 9:34 am
Forum: General
Topic: Correction request : Authority flag for Import CA Certificate Autority in RouterOS
Replies: 14
Views: 6814

Re: Correction request : Authority flag for Import CA Certificate Autority in RouterOS

This certificate have "Authority" flag and was show in WebFig under Certificate > Sign menu as CA and you can use to TRY to sign certificate, but you CANNOT sign another certificate because there is NOT the private key. There is specific flag that indicates whether private key is imported...
by mrz
Fri Mar 27, 2020 9:35 am
Forum: Forwarding Protocols
Topic: Loopback as MPLS Interface [SOLVED]
Replies: 2
Views: 9192

Re: Loopback as MPLS Interface [SOLVED]

MPLS interface entries are required to correctly determine MPLS MTU on interfaces participating in MPLS packet forwarding. Without these entries MPLS will not work properly, I would suggest to leave default "all" enabled.
by mrz
Thu Mar 26, 2020 9:08 am
Forum: RouterOS beta
Topic: FEATURE REQUEST: Add Basic Firewall Rule Wizard
Replies: 71
Views: 23382

Re: FEATURE REQUEST: Add Basic Firewall Rule Wizard

That is why we have quickset where you can disableenable default firewall ruleset or default NAT rules.
by mrz
Wed Mar 25, 2020 7:52 am
Forum: Forwarding Protocols
Topic: OSPF loses default-route with virtual-link
Replies: 2
Views: 2148

Re: OSPF loses default-route with virtual-link

default route over virtual link does not work in v6. This problem is fixed in ROSv7.
by mrz
Fri Mar 20, 2020 10:37 am
Forum: Scripting
Topic: PHP API Login Method Example [Help Please] [SOLVED]
Replies: 13
Views: 21126

Re: PHP API Login Method Example [SOLVED]

I do not know anything about php api, but shouldn't it be like this?
$this->write('/login', false);
$this->write('=name=' . $login, false); 
$this->write('=password=' . $password);
by mrz
Fri Mar 20, 2020 10:17 am
Forum: Scripting
Topic: PHP API Login Method Example [Help Please] [SOLVED]
Replies: 13
Views: 21126

Re: PHP API Login Method Example [SOLVED]

send in initial login message
/login
=name=user
=password=xxx
by mrz
Mon Mar 16, 2020 4:19 pm
Forum: General
Topic: Feature requests
Replies: 1740
Views: 631999

Re: Feature requests

Thanks, If you find anything else strange with history report to support.
by mrz
Wed Mar 11, 2020 12:38 pm
Forum: General
Topic: How to raise "upgradeable to"?
Replies: 26
Views: 7651

Re: How to raise "upgradeable to"?

See the date of original post. A lot has changed since then. mipsle devices are deprecated.
by mrz
Tue Mar 10, 2020 10:43 am
Forum: Forwarding Protocols
Topic: Where is igmp-proxy?
Replies: 1
Views: 3179

Re: Where is igmp-proxy?

install multicast package.
by mrz
Thu Mar 05, 2020 2:20 pm
Forum: General
Topic: ip-sec between MikroTik and Cisco ASA not passing traffic
Replies: 23
Views: 7351

Re: ip-sec between MikroTik and Cisco ASA not passing traffic

By looking at installed SA counters my guess is that RouterOS matches packets against policy properly, encapsulates and sends them to remote peer.
Either remote peer is dropping incoming packets or does not send a reply.
by mrz
Thu Mar 05, 2020 12:18 pm
Forum: General
Topic: ip-sec between MikroTik and Cisco ASA not passing traffic
Replies: 23
Views: 7351

Re: ip-sec between MikroTik and Cisco ASA not passing traffic

Do you have any fasttrack rules or other routing tables than main?
by mrz
Tue Mar 03, 2020 6:05 pm
Forum: Beginner Basics
Topic: Default firewall rules and connecting using PPPoE
Replies: 4
Views: 3121

Re: Default firewall rules and connecting using PPPoE

No, default firewall rules won't protect if a new pppoe WAN interface is added afterwards.
This is false information. Default configuration for quite some blocks access on interfaces that are not in either LAN or WAN interface lists.
by mrz
Tue Mar 03, 2020 6:03 pm
Forum: Forwarding Protocols
Topic: OSPF Drops when adding a comment?
Replies: 13
Views: 5283

Re: OSPF Drops when adding a comment?

Changing comments on interface and address does not trigger any reconnects.
You know how it goes, if you have encountered a problem on specific interfaces then contact support with request to fix it.
by mrz
Tue Mar 03, 2020 3:34 pm
Forum: General
Topic: DHCPv6 DUID change - bug?
Replies: 18
Views: 10872

Re: DHCPv6 DUID change - bug?

RFC states: The DUID is designed to be unique across all DHCP clients and servers, and stable for any specific client or server - that is, the DUID used by a client or server SHOULD NOT change over time if at all possible; for example, a device's DUID should not change as a result of a change in the...
by mrz
Tue Mar 03, 2020 3:15 pm
Forum: Forwarding Protocols
Topic: OSPF Drops when adding a comment?
Replies: 13
Views: 5283

Re: OSPF Drops when adding a comment?

No it is specific to protocols. For example BGP in v7 will have parameters that will not reset connection.
OSPF should also have parameters that will not reset adjacencies.
by mrz
Tue Mar 03, 2020 12:00 pm
Forum: Forwarding Protocols
Topic: OSPF Drops when adding a comment?
Replies: 13
Views: 5283

Re: OSPF Drops when adding a comment?

BTW OSPF in v7beta is already implemented, so if you have any complains or suggestions about v7 OSPF feel free to send them to support while it is in beta state.
by mrz
Tue Mar 03, 2020 11:42 am
Forum: General
Topic: TTL expires in transit.
Replies: 2
Views: 1950

Re: TTL expires in transit.

You have a routing loop somewhere. Run traceroute to see where.
by mrz
Mon Mar 02, 2020 2:12 pm
Forum: General
Topic: ProtonVPN on Mikrotik
Replies: 56
Views: 26603

Re: ProtonVPN on Mikrotik

SHA512 is not supported and UDP is supported only in ROS v7
by mrz
Mon Mar 02, 2020 1:23 pm
Forum: General
Topic: ProtonVPN on Mikrotik
Replies: 56
Views: 26603

Re: ProtonVPN on Mikrotik

Unfortunately, Mikrotik routers do not support OpenVPN client connection, therefore, it is not possible to set up a ProtonVPN connection on it. We're sorry for the inconveniences.
BTW OVPN is also supported, maybe they require some specific OVPN feature?
by mrz
Mon Mar 02, 2020 12:26 pm
Forum: General
Topic: ProtonVPN on Mikrotik
Replies: 56
Views: 26603

Re: ProtonVPN on Mikrotik

By looking at this example:
https://protonvpn.com/support/linux-ikev2-protonvpn/

it is very similar to nordvpn config, so you can use NordVPN RouterOS setup example as a reference:
https://wiki.mikrotik.com/wiki/IKEv2_EA ... d_RouterOS
by mrz
Mon Mar 02, 2020 11:57 am
Forum: Forwarding Protocols
Topic: BGP VPN4 Issues
Replies: 1
Views: 2565

Re: BGP VPN4 Issues

You need either fullmesh (all peers connected to each other) or set for example R2 as route reflector.
by mrz
Fri Feb 28, 2020 11:57 am
Forum: RouterOS beta
Topic: 7beta5 Bricked my HAPAC2
Replies: 2
Views: 3491

Re: 7beta5 Bricked my HAPAC2

How old was bootloader? Very old bootloader will not work with v7. Try to load backup booter and then reinstall with netinstall.
by mrz
Fri Feb 21, 2020 11:39 am
Forum: RouterOS beta
Topic: Feature request: RPKI integration/validation
Replies: 1
Views: 2551

Re: Feature request: RPKI integration/validation

Use search, there are already several topics about RPKI.
In short, we are working on it.
by mrz
Thu Feb 20, 2020 2:36 pm
Forum: Forwarding Protocols
Topic: BGP merging two ASN to one i.e. operating two ASN simultanously in one part of the network
Replies: 4
Views: 3643

Re: BGP merging two ASN to one i.e. operating two ASN simultanously in one part of the network

Yes, confederations are used to migrate to new AS while still keeping the old AS during migration process. In terms of setup you just need to specify "confederation-as" and "confederation-peers" in BGP instance configuration.
by mrz
Thu Feb 20, 2020 1:59 pm
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 148
Views: 45266

Re: Feature Request: IPSEC Improvements

That would require to store large CA database on the router.
by mrz
Thu Feb 20, 2020 10:21 am
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 148
Views: 45266

Re: Feature Request: IPSEC Improvements

It works if you do not use IP unnumbered (at least on Cisco)
by mrz
Wed Feb 19, 2020 4:40 pm
Forum: General
Topic: IKEv2 IPsec VPN and IPv6
Replies: 8
Views: 6602

Re: IKEv2 IPsec VPN and IPv6

But in my case it would be connections made FROM various IPv4 devices (PCs and phones) TO a router that sits behind a NATTED IPv4 and only has public IPv6 visible to the internet... Don't know how that would work (I remember reading that the new IP CLOUD already has IPv6 support, so maybe it could ...
by mrz
Mon Feb 10, 2020 11:22 am
Forum: Scripting
Topic: logs mikrotik CGNAT NETMAP
Replies: 1
Views: 3004

Re: logs mikrotik CGNAT NETMAP

Set log=yes for that NAT rule and set up logging in /system logging menu to send all firewall logs to remote syslog server.
by mrz
Mon Feb 10, 2020 11:06 am
Forum: Forwarding Protocols
Topic: Selective filtering of BGP routes distributed into OSPF not working?
Replies: 2
Views: 2391

Re: Selective filtering of BGP routes distributed into OSPF not working?

OSPF-in chain is used only when routes are received from other OSPF neighbors.
To control what external routes will be sent to other OSPF neighbors you need to use OSPF out.
by mrz
Tue Jan 28, 2020 12:03 pm
Forum: RouterOS beta
Topic: Feature Request - BGP RPKI
Replies: 21
Views: 10887

Re: Feature Request - BGP RPKI

ROS didn't use Quagga and no there will not be FRR.
by mrz
Mon Jan 27, 2020 2:34 pm
Forum: Announcements
Topic: v6.46.2 [stable] is released!
Replies: 120
Views: 62865

Re: v6.46.2 [stable] is released!

Auto upgrader will not try to install if at least one package is missing or not finished downloading.
by mrz
Tue Jan 21, 2020 2:08 pm
Forum: General
Topic: Simple Queues script to change type [SOLVED]
Replies: 9
Views: 6471

Re: Simple Queues script to change type [SOLVED]

If you have more than one item with total-queue="default-small" then you need to iterate through find results.
For example using foreach
:foreach i in=[find where total-queue="default-small"] do={set $i total-queue=wireless-default }
by mrz
Tue Jan 21, 2020 11:30 am
Forum: General
Topic: Simple Queues script to change type [SOLVED]
Replies: 9
Views: 6471

Re: Simple Queues script to change type [SOLVED]

set [find total-queue="default-small" ] total-queue=wireless-default
by mrz
Tue Jan 21, 2020 9:52 am
Forum: Announcements
Topic: v6.46.2 [stable] is released!
Replies: 120
Views: 62865

Re: v6.46.2 [stable] is released!

Sometimes I just get the files from the mikrotik.com download section, collecting the main package and some optional packages, then I FTP the whole thing to the router and reboot. This is in fact the only way to add one or more optional packages. Of course after doing the FTP I first list the Files...
by mrz
Mon Jan 20, 2020 4:48 pm
Forum: RouterOS beta
Topic: IP route table display
Replies: 4
Views: 16396

Re: IP route table display

You can do print on the same menu and you will see parameters related only to static IP routes. Routing route should be used to monitor all routes (including filtered ones) and their protocol specific parameters. eally breaking an old Mikrotik tradition of changing stuff on a menu level (in this cas...
by mrz
Mon Jan 20, 2020 12:13 pm
Forum: Forwarding Protocols
Topic: Further BGP improvements?
Replies: 4
Views: 2974

Re: Further BGP improvements?

Yes, we are working on BGP at the moment. First beta with enabled BGP is coming soon.
by mrz
Thu Jan 16, 2020 7:15 pm
Forum: Scripting
Topic: API enable\disable ip sec peer
Replies: 2
Views: 3068

Re: API enable\disable ip sec peer

Please read documentation on how to use API
https://wiki.mikrotik.com/wiki/Manual:A ... escription
by mrz
Thu Jan 16, 2020 2:22 pm
Forum: RouterOS beta
Topic: IP route table display
Replies: 4
Views: 16396

Re: IP route table display

v7 have completely reworked routing table with completely different flags. v7 Has 3 Flag columns: * shows if route is dynamically added by any protocol * route status flag (active, inactive, disabled) * protocol flag (bgp, osf,static,connected etc.) I would suggest to use /routing/route menu to moni...
by mrz
Mon Jan 13, 2020 12:28 pm
Forum: Forwarding Protocols
Topic: OSPF Networks
Replies: 2
Views: 2328

Re: OSPF Networks

@marcocamza If you mean add /12 in OSPF network configuration so that OSPF runs on all matching networks, then yes you can do it.
If you mean to advertise /12 instead /24 then no, unless you run those networks in area, then you can do summarization on ABR.
by mrz
Thu Jan 09, 2020 1:01 pm
Forum: Forwarding Protocols
Topic: does Mikrotik support RFC5549
Replies: 11
Views: 6568

Re: does Mikrotik support RFC5549

At the moment, no, it is not supported.
by mrz
Thu Jan 09, 2020 12:58 pm
Forum: Forwarding Protocols
Topic: Default Route from BGP to OSPF
Replies: 22
Views: 15557

Re: Default Route from BGP to OSPF

Yes, that particular problem from 2017 is fixed. If you have the same symptoms contact support.
by mrz
Wed Nov 27, 2019 11:48 am
Forum: RouterOS beta
Topic: how add multiple route tables, route rules in v7 beta [SOLVED]
Replies: 12
Views: 15190

Re: how add multiple route tables, route rules in v7 beta [SOLVED]

We are open to suggestions while v7 is in beta state.
by mrz
Tue Nov 26, 2019 5:28 pm
Forum: RouterOS beta
Topic: DS-Lite (dual stack lite) internet connection as defined in RFCs 6333 and 6334
Replies: 11
Views: 9193

Re: DS-Lite (dual stack lite) internet connection as defined in RFCs 6333 and 6334

We will try to add some functionality to read options in the script.
by mrz
Tue Nov 26, 2019 4:28 pm
Forum: Scripting
Topic: Can't specify log buffer as variable
Replies: 2
Views: 1939

Re: Can't specify log buffer as variable

Do not use the system parameter names as variable names and everything will work as expected:
https://wiki.mikrotik.com/wiki/Manual:S ... able_names
by mrz
Tue Nov 26, 2019 4:13 pm
Forum: RouterOS beta
Topic: how add multiple route tables, route rules in v7 beta [SOLVED]
Replies: 12
Views: 15190

Re: how add multiple route tables, route rules in v7 beta [SOLVED]

/routing table
add name=G-2 vrf=main
add name=G0SQ vrf=main
add name=CIR vrf=main

/ip/route
add gateway="EXTRA PPPOE@main" dst-address=0.0.0.0/0^G-2
add gateway=192.168.100.1@main dst-address=0.0.0.0/0^G-SQ
add gateway=103.225.xx.xx@main dst-address=0.0.0.0/0^CIR
...
by mrz
Mon Nov 25, 2019 12:55 pm
Forum: RouterOS beta
Topic: how add multiple route tables, route rules in v7 beta [SOLVED]
Replies: 12
Views: 15190

Re: how add multiple route tables, route rules in v7 beta [SOLVED]

Show what IP routes and route rules you had on v6 and I will show you how they should look like in v7.
by mrz
Mon Nov 25, 2019 11:56 am
Forum: RouterOS beta
Topic: how add multiple route tables, route rules in v7 beta [SOLVED]
Replies: 12
Views: 15190

Re: how add multiple route tables, route rules in v7 beta [SOLVED]

It is just an example to show the syntax. Use addresses you want to route.
by mrz
Fri Nov 22, 2019 12:13 pm
Forum: Forwarding Protocols
Topic: BGP: Remove extra prepends from upstream
Replies: 2
Views: 2362

Re: BGP: Remove extra prepends from upstream

Just prioritize by setting local pref or weights in your end.
by mrz
Wed Nov 13, 2019 12:19 pm
Forum: General
Topic: Microsoft CA - SCEP
Replies: 1
Views: 1066

Re: Microsoft CA - SCEP

Enable certificate debug logs to see what exactly fails.
by mrz
Wed Nov 13, 2019 10:45 am
Forum: RouterOS beta
Topic: [ROS 7.0b3] Kernel module 'igb' [SOLVED]
Replies: 12
Views: 15949

Re: [ROS 7.0b3] Kernel module 'igb' [SOLVED]

If you know that driver is in vanilla kernel, then write to support with attached supout file from the device, we will see if it can be enabled.
by mrz
Mon Nov 11, 2019 9:24 am
Forum: RouterOS beta
Topic: Can't SSH from CHR Version 7.0 Beta 3
Replies: 3
Views: 3653

Re: Can't SSH from CHR Version 7.0 Beta 3

Problem will be solved in next beta.
by mrz
Fri Nov 08, 2019 5:06 pm
Forum: RouterOS beta
Topic: OpenVPN Bad decompression
Replies: 5
Views: 4489

Re: OpenVPN Bad decompression

Name at least one good reason to support LZO? Even on standard OpenVPN it is being deprecated
by mrz
Tue Nov 05, 2019 10:13 am
Forum: Scripting
Topic: adding item with place-before on cleared list fails
Replies: 1
Views: 2140

Re: adding item with place-before on cleared list fails

Because console does not know where "0" is located unless you do print before.
by mrz
Mon Nov 04, 2019 4:20 pm
Forum: RouterOS beta
Topic: VRF IPv6 support with RouterOS v7
Replies: 4
Views: 5020

Re: VRF IPv6 support with RouterOS v7

Yes, it will. At the moment VRFs are still not enabled.
by mrz
Mon Nov 04, 2019 4:18 pm
Forum: RouterOS beta
Topic: 7.0 Beta2 script bug
Replies: 2
Views: 3320

Re: 7.0 Beta2 script bug

x86 and CHR won't have routerboard menu. Solution:
:do { :put [/system routerboard print] } on-error={:put "not supported"}
by mrz
Mon Nov 04, 2019 4:03 pm
Forum: RouterOS beta
Topic: Can't SSH from CHR Version 7.0 Beta 3
Replies: 3
Views: 3653

Re: Can't SSH from CHR Version 7.0 Beta 3

What is the remote device? If it is RouterOS does it have strong-crypto enabled too? If it is not ROS devices, does it have enabled all needed algorithms that is used by the ssh client when strong crypto is enabled?
by mrz
Tue Oct 15, 2019 11:09 am
Forum: Scripting
Topic: dynamic=no doesn't work in /ip route
Replies: 4
Views: 2605

Re: dynamic=no doesn't work in /ip route

Works with find too:
[admin@p3_450] /ip route> :put [find  where !dynamic]      
*2;*1
[admin@p3_450] /ip route> :put [find  where !static]        
*401691fd
by mrz
Mon Oct 14, 2019 6:36 pm
Forum: Scripting
Topic: dynamic=no doesn't work in /ip route
Replies: 4
Views: 2605

Re: dynamic=no doesn't work in /ip route

When route is not dynamic then "dynamic" parameter is not set wich is not equal to "no" Correct way is [admin@p3_450] /ip route> print where dynamic Flags: X - disabled, A - active, D - dynamic, C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme, B - blackhole, U - unre...
by mrz
Mon Oct 14, 2019 6:32 pm
Forum: Forwarding Protocols
Topic: Static MPLS configuration
Replies: 4
Views: 4186

Re: Static MPLS configuration

For static LDP bindings to work, you also need static routes in routing table: [admin@p3_450] /mpls local-bindings> print Flags: X - disabled, A - advertised, D - dynamic, L - local-route, G - gateway-route, e - egress # DST-ADDRESS LABEL PEERS 0 G 10.255.0.0/24 1000 1 G 10.255.1.0/24 1113 [admin@p3...
by mrz
Fri Oct 11, 2019 12:24 pm
Forum: Forwarding Protocols
Topic: BGP bug report
Replies: 1
Views: 2465

Re: BGP bug report

On the right upper corner is a search
viewtopic.php?f=14&t=146206&p=719583
by mrz
Wed Oct 09, 2019 12:22 pm
Forum: Scripting
Topic: Login API pear2/Net_RouterOS 6.45.x
Replies: 4
Views: 4775

Re: Login API pear2/Net_RouterOS 6.45.x

I do not see a problem you just try new login method and fall back if you receive ret, as shown in the python example:
https://wiki.mikrotik.com/wiki/Manual:A ... ple_client

See "login" function
by mrz
Fri Oct 04, 2019 5:17 pm
Forum: General
Topic: Winbox - 64bits
Replies: 1
Views: 1158

Re: Winbox - 64bits

by mrz
Fri Oct 04, 2019 1:46 pm
Forum: Forwarding Protocols
Topic: Filters for +500 prefixes
Replies: 9
Views: 5038

Re: Filters for +500 prefixes

Similar feature is currently in development.
by mrz
Fri Oct 04, 2019 11:51 am
Forum: RouterOS beta
Topic: adding fib to vrf failed with timeout
Replies: 3
Views: 4653

Re: adding fib to vrf failed with timeout

Thank you for the report, at this moment VRFs are not implemented. Adding table to the vrf will simply crash the route.
by mrz
Thu Oct 03, 2019 2:22 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 387
Views: 191775

Re: RB4011

If you see unclassified process, generate supout file and send it to support.
by mrz
Mon Sep 30, 2019 10:31 am
Forum: Forwarding Protocols
Topic: PPP & VRF bug? [SOLVED]
Replies: 3
Views: 11798

Re: VRF bug? [SOLVED]

PPP is not fully VRF aware. Workaround is to change table with route filters or use scripts to add routes manually to correct VRF.
by mrz
Fri Sep 27, 2019 7:30 pm
Forum: RouterOS beta
Topic: Cannot set routing-mark or table for routing rule
Replies: 18
Views: 32237

Re: Cannot set routing-mark or table for routing rule

Config is changed in v7
/routing table
add fib name=xx vrf=main
/ip route
add dst-address=8.8.8.8^xx gateway=10.155.101.1@main
/ip route rule 
add dst-address=1.1.1.1 action=lookup table=xx
by mrz
Fri Sep 27, 2019 6:17 pm
Forum: RouterOS beta
Topic: RouterOS v7.0beta2 bug fund
Replies: 9
Views: 6622

Re: RouterOS v7.0beta2 bug fund

- IPv4 route marking/rules appears to be dead Routing mark is configured differently, first you add the table and only then you can add routes to the table or use it in routing rules. /routing table add fib name=xx vrf=main /ip route add dst-address=8.8.8.8^xx gateway=10.155.101.1@main /ip route ru...
by mrz
Fri Sep 27, 2019 4:36 pm
Forum: RouterOS beta
Topic: RouterOS v7.0beta2 bug fund
Replies: 9
Views: 6622

Re: RouterOS v7.0beta2 bug fund

There is not much new because most of the new features were backported already to v6.
If you see trivial small bugs, list them here anyway
by mrz
Tue Sep 17, 2019 10:21 am
Forum: Scripting
Topic: Is QuickSet available via the API?
Replies: 1
Views: 2510

Re: Is QuickSet available via the API?

No.
by mrz
Mon Sep 16, 2019 11:11 am
Forum: Beginner Basics
Topic: RB4011iGS+5HacQ2HnD-IN remove default config
Replies: 2
Views: 1574

Re: RB4011iGS+5HacQ2HnD-IN remove default config

not related to v7beta, moved to basics.
by mrz
Thu Sep 12, 2019 11:09 am
Forum: RouterOS beta
Topic: Should OSPF work?
Replies: 3
Views: 4901

Re: Should OSPF work?

To run ospfv3 use following settings:

/routing ospf
instance add name=instance_v3 version=3
area add name=backbone_v3 instance=instance_v3
interface add network=%ether1 area=backbone_v3

But OSPFv3 might not work, thee are problems with LS Updates
by mrz
Tue Sep 10, 2019 6:59 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 256084

Re: RouterOS v7.0 beta1 - when?

Recursive nexthops in v7 works without any scripts.
by mrz
Fri Sep 06, 2019 4:22 pm
Forum: General
Topic: RouterOS v7.0beta1 (ARM)
Replies: 203
Views: 101104

Re: RouterOS v7.0beta1 (ARM)

BGP currently disabled, stay tuned.
by mrz
Mon Sep 02, 2019 10:55 am
Forum: Scripting
Topic: Decimals ?
Replies: 10
Views: 10889

Re: Decimals ?

Yes only integers. Anywhere where you see decimal representation is actually a string.
by mrz
Thu Aug 29, 2019 10:52 am
Forum: Scripting
Topic: Running script via API does not set global variable
Replies: 3
Views: 2549

Re: Running script via API does not set global variable

does it work with dont-require-permissions=yes?
by mrz
Wed Aug 28, 2019 12:54 pm
Forum: General
Topic: Error Terminal command symbol - $
Replies: 4
Views: 2051

Re: Error Terminal command symbol - $

$ is a special char and must be escaped:
https://wiki.mikrotik.com/wiki/Manual:S ... _Sequences
by mrz
Thu Aug 22, 2019 11:54 am
Forum: Forwarding Protocols
Topic: BGP and more specific routes.
Replies: 10
Views: 5184

Re: BGP and more specific routes.

I might be mistaken, but by looking at your config, looks like you set /22 on sfp interface, and then divide clients in two subnets, by assigning on client side /23 subnets? This will also cause packet drops.
by mrz
Thu Aug 22, 2019 9:56 am
Forum: Forwarding Protocols
Topic: BGP and more specific routes.
Replies: 10
Views: 5184

Re: BGP and more specific routes.

Using interface name as gateway is invalid setup on broadcast networks. You can use it only on point to point interfaces, otherwise you will get those "mysterious" packet drops.
by mrz
Thu Aug 22, 2019 9:53 am
Forum: Forwarding Protocols
Topic: route ospf error -> Discarding packet: locally originated
Replies: 26
Views: 51705

Re: route ospf error -> Discarding packet: locally originated

Do you have connection tracking enabled?
by mrz
Tue Aug 20, 2019 11:36 am
Forum: Forwarding Protocols
Topic: Multicast Routing
Replies: 1
Views: 2614

Re: Multicast Routing

by mrz
Tue Aug 13, 2019 4:49 pm
Forum: Scripting
Topic: api login issues 6.46beta16
Replies: 2
Views: 4860

Re: api login issues 6.46beta16

by mrz
Fri Aug 09, 2019 5:20 pm
Forum: General
Topic: Mac telnet problem after upgrade... wrong password
Replies: 7
Views: 7987

Re: Mac telnet problem after upgrade... wrong password

see my post above.
You will not be able to connect from old ROS versions to 6.45.3
by mrz
Tue Aug 06, 2019 11:27 am
Forum: Announcements
Topic: v6.45.3 [stable] is released!
Replies: 90
Views: 60846

Re: v6.45.3 [stable] is released!

It will not include peer, if you upgraded from version where policy was set without peer.
If you set peer after upgrade or added policy already in v6.45.3 then it will be exported.
by mrz
Thu Aug 01, 2019 12:46 pm
Forum: Forwarding Protocols
Topic: default route via TE Tunnel and OSPF
Replies: 4
Views: 3096

Re: default route via TE Tunnel and OSPF

Well yes, you could use other routing protocol that does not listen on interface. For example BGP and set lower distance than OSPF routes.

Or try to change nexthop in routing filter for OSPF routes, but this would reliably work only on external routes.
by mrz
Thu Aug 01, 2019 11:06 am
Forum: Forwarding Protocols
Topic: default route via TE Tunnel and OSPF
Replies: 4
Views: 3096

Re: default route via TE Tunnel and OSPF

Probably easiest way is to simply run OSPF on TE interface.
by mrz
Mon Jul 29, 2019 10:38 am
Forum: Scripting
Topic: mass-enable all of my vlan using script
Replies: 7
Views: 4211

Re: mass-enable all of my vlan using script

/interface vlan enable [find]
by mrz
Fri Jul 26, 2019 3:01 pm
Forum: Forwarding Protocols
Topic: Route selection - What am I missing? [SOLVED]
Replies: 3
Views: 11493

Re: Route selection - What am I missing? [SOLVED]

Will not be changed in current implementation, but there are plans to redo this part in new implementation on which we are working right now.
by mrz
Fri Jul 26, 2019 11:24 am
Forum: Scripting
Topic: 6.43 change in login process and API libraries?
Replies: 18
Views: 17524

Re: 6.43 change in login process and API libraries?

The reason is new password storage. To keep md5 we would need to store password in plain text on the router, which is not what we want. Do you use tenet over unsecure networks? I think not, most likely you will chose ssh instead. With api is the same, consider unsecure api as telnet, and api over ss...