Community discussions

MikroTik App

Search found 11903 matches

  • 1
  • 3
  • 4
  • 5
  • 6
  • 7
  • 40
by pe1chl
Tue Jun 13, 2023 10:18 am
Forum: Announcements
Topic: v7.10rc is released!
Replies: 183
Views: 53920

Re: v7.10rc is released!

Well, when you click it it does not show a checkmark but an exclamation mark. That indicates "not".
by pe1chl
Mon Jun 12, 2023 2:11 pm
Forum: RouterOS beta
Topic: OS upgrade Issue from version 6 to version 7
Replies: 43
Views: 8978

Re: OS upgrade Issue from version 6 to version 7

Known problems when upgrading systems that have BGP: - existing routing filters fail to work when they do not "accept" prefix. e.g. you made a filter to set local-pref, it will fail in v7. workaround: add an accept at the end before upgrading - existing peers which have update-source set t...
by pe1chl
Mon Jun 12, 2023 12:27 pm
Forum: RouterOS beta
Topic: [7.10 stable] DNS Crash
Replies: 54
Views: 11163

Re: [7.10rc3]DO NOT UPDATE!!!

In other words, you can trash the DNS service with just setting some unsupported value in some setting that doesn't have input validation? Interesting. I agree with you that such parameter values, unless they have some special meaning that is useful (like "infinity" or "not checked&q...
by pe1chl
Mon Jun 12, 2023 11:54 am
Forum: RouterOS beta
Topic: [7.10 stable] DNS Crash
Replies: 54
Views: 11163

Re: [7.10rc3]DO NOT UPDATE!!!

But DNS server crash is a very serious problem in my opinion. Most web pages cannot be accessed and are directly interrupted It is not a "DNS server crash", it is configuration of the DNS with unusable parameters. It would have to be found how that happened, but that likely cannot be trac...
by pe1chl
Mon Jun 12, 2023 11:52 am
Forum: Announcements
Topic: v7.9.2 [stable] is released!
Replies: 72
Views: 26332

Re: v7.9.2 [stable] is released!

Well, I "need" to run 7.10rc versions because they have BFD. But it seems that version is better than 7.9
When a 7.10 "stable" version is released (I know what stable means, not stability of the software but stability of the release version...) I will deploy it more widely.
by pe1chl
Sun Jun 11, 2023 7:34 pm
Forum: Announcements
Topic: v7.10rc is released!
Replies: 183
Views: 53920

Re: v7.10rc is released!

You will have to understand that v7 bgp is different from v6 bgp, many commands are different and some things are no longer there.
by pe1chl
Sun Jun 11, 2023 12:07 am
Forum: RouterOS beta
Topic: New User Manager in RouterOS v7
Replies: 211
Views: 81346

Re: New User Manager in RouterOS v7

The user manager in v7 is more towards a plain RADIUS server (with some more capabilities in that regard) and less of a fancy thing with web interface etc. That is apparently the direction they decided. You can put anything you like in the comment field for the record, but it is no longer accessible...
by pe1chl
Sun Jun 11, 2023 12:04 am
Forum: General
Topic: Partitioning or not
Replies: 11
Views: 1072

Re: Partitioning or not

Many thanks for your complete answer ! Just a last question/confirmation, when partitioning from 1 to 2 partitions, I will NOT loose any configuration ? Just create partition, copy config to the new, activate to test, reboot, reactivate the old, reboot. Thanks When you set 2 partitions and reboot y...
by pe1chl
Sat Jun 10, 2023 11:23 am
Forum: General
Topic: Partitioning or not
Replies: 11
Views: 1072

Re: Partitioning or not

Yes, you can partition the CCR2116, but not the CRS devices. In a 128MB device with typical usage you can make 2 partitions. Of course when you have usage of the space that could potentially expand, like user manager or dude, you should be careful. But in normal use for only firmware and configurati...
by pe1chl
Sat Jun 10, 2023 11:14 am
Forum: RouterOS beta
Topic: Performance regression + IPv6 not working - RB750Gr3
Replies: 7
Views: 4838

Re: Performance regression + IPv6 not working - RB750Gr3

We have argued with MikroTik that they should add new data to the performance figures on their older products, at least those that are still for sale, when used with RouterOS v7.x instead of v6.x. The published figures for products that were designed and released with v6 are all for running with v6 ...
by pe1chl
Fri Jun 09, 2023 4:14 pm
Forum: Announcements
Topic: v7.10rc is released!
Replies: 183
Views: 53920

Re: v7.10rc is released!

Ok thanks! I'm preparing to run a CCR1009 on v7.10 once it is released as "stable". Of course it is partitioned so I can switch back when required. I already prepared the 6.49 config (I know some snags in BGP config) and imported it in a CHR and upgraded that, and the result does not look ...
by pe1chl
Fri Jun 09, 2023 2:46 pm
Forum: Announcements
Topic: v7.10rc is released!
Replies: 183
Views: 53920

Re: v7.10rc is released!

Anyone with experience with these versions on the CCR1009 or other CCR10xx devices?
Before, I read about general instability on TILE so before taking the plunge (I have tested on CHR) it is good to know...
by pe1chl
Fri Jun 09, 2023 10:46 am
Forum: Announcements
Topic: v7.10rc is released!
Replies: 183
Views: 53920

Re: v7.10rc is released!

It can be tricky to debug. In this case apparently the WiFi interface becomes unresponsive. With newest firmware on the competitor's devices we see infrequent kernel crashes. As they make the "oops" output available to the user (including stack backtrace), we can see that it is happening i...
by pe1chl
Fri Jun 09, 2023 10:40 am
Forum: RouterBOARD hardware
Topic: USB -> RJ45 for PoE? Or will MT start putting USB-C ports?
Replies: 23
Views: 4029

Re: USB -> RJ45 for PoE? Or will MT start putting USB-C ports?

These devices run on 5V supply, which is easily supplied using any USB version.
The higher voltage 12-24V is only required when the device also has "passive" PoE-out, indeed to reduce current towards the next device.
"real" PoE usually uses 48V.
by pe1chl
Thu Jun 08, 2023 7:38 pm
Forum: General
Topic: DNS / UDP Priority ?
Replies: 1
Views: 339

Re: DNS / UDP Priority ?

Yes.
Read about QoS.
by pe1chl
Thu Jun 08, 2023 7:25 pm
Forum: General
Topic: Routeros, operating system services boot order [SOLVED]
Replies: 14
Views: 1138

Re: Routeros, operating system services boot order [SOLVED]

As I recall, when I set that up years ago, I tried a couple of delay times, and once I found what worked, I doubled that for the permanent script. Sure, but that holds only for your situation and possibly your test case. I can guarantee you that on a VDSL line, after a power loss, you will not have...
by pe1chl
Thu Jun 08, 2023 5:45 pm
Forum: General
Topic: router OS license differences
Replies: 5
Views: 827

Re: router OS license differences

It will not (or only barely) be financially attractive to use old computers as routers. Separate licenses cost money, and they are included with MikroTik devices. E.g. the new L009 for $129 comes with an L5 license included, CCR2004 for $465 comes with L6 license. Computers generally use a lot more ...
by pe1chl
Thu Jun 08, 2023 5:35 pm
Forum: Announcements
Topic: v7.10rc is released!
Replies: 183
Views: 53920

Re: v7.10rc is released!

The symptoms of the global variables now appear again in an hAP ax3, something is not being done right in the RouterOS code, they reintroduce bugs that were solved at least in the RB750Gr3.
Most RouterOS code is not dependent on the device it is running on.
by pe1chl
Thu Jun 08, 2023 5:33 pm
Forum: General
Topic: Routeros, operating system services boot order [SOLVED]
Replies: 14
Views: 1138

Re: Routeros, operating system services boot order [SOLVED]

Yes, that is unfortunately the only viable workaround. Ok, maybe you could make a clever script that does a DNS lookup in a loop (with a delay in the loop) until the resolve succeeds. When using a fixed wait time the actual delay required depends a lot on the configuration and many external factors....
by pe1chl
Thu Jun 08, 2023 4:07 pm
Forum: Announcements
Topic: v7.10rc is released!
Replies: 183
Views: 53920

Re: v7.10rc is released!

That in fact is also a "problem with the ISP"...
by pe1chl
Thu Jun 08, 2023 4:06 pm
Forum: Scripting
Topic: How to "resolve" an interface list? [SOLVED]
Replies: 19
Views: 3254

Re: How to "resolve" an interface list? [SOLVED]

Yes, it would certainly be preferable when there was a read-only property of each list that returns the actual members of that list.
by pe1chl
Thu Jun 08, 2023 3:31 pm
Forum: RouterBOARD hardware
Topic: USB -> RJ45 for PoE? Or will MT start putting USB-C ports?
Replies: 23
Views: 4029

Re: USB -> RJ45 for PoE? Or will MT start putting USB-C ports?

That is certainly true. That is why I included that in the reply with the special cable.
The fact that he has a device with some USB-C charging outputs does not mean they can deliver 12V.
by pe1chl
Thu Jun 08, 2023 3:30 pm
Forum: Scripting
Topic: How to "resolve" an interface list? [SOLVED]
Replies: 19
Views: 3254

Re: How to "resolve" an interface list? [SOLVED]

Yes, but without a concrete example, can't be clear what the user want do....
I think it is quite clear what he wants. And in general I do not like the "why would you want that??" approach to answering questions.
by pe1chl
Thu Jun 08, 2023 2:22 pm
Forum: Scripting
Topic: How to "resolve" an interface list? [SOLVED]
Replies: 19
Views: 3254

Re: How to "resolve" an interface list? [SOLVED]

My understanding is that when he has a list like the default "static" or "dynamic" lists, he wants to know which interfaces are member of that. He does not want to get the word "static", he wants a list of all interfaces that are considered static. /interface print whe...
by pe1chl
Thu Jun 08, 2023 12:12 pm
Forum: Scripting
Topic: How to "resolve" an interface list? [SOLVED]
Replies: 19
Views: 3254

Re: How to "resolve" an interface list? [SOLVED]

My understanding is that when he has a list like the default "static" or "dynamic" lists, he wants to know which interfaces are member of that.
He does not want to get the word "static", he wants a list of all interfaces that are considered static.
by pe1chl
Thu Jun 08, 2023 11:29 am
Forum: RouterBOARD hardware
Topic: USB -> RJ45 for PoE? Or will MT start putting USB-C ports?
Replies: 23
Views: 4029

Re: USB -> RJ45 for PoE? Or will MT start putting USB-C ports?

I see that on Aliexpress you can buy cables with a USB-C connector at one end and a barrel jack on the other, claiming that they output 12V DC. So likely there is such a chip built in to the USB-C connector that tells the supply to deliver 12V. Assuming that your powerbank REALLY is USB-C PD compati...
by pe1chl
Thu Jun 08, 2023 11:11 am
Forum: Scripting
Topic: How to "resolve" an interface list? [SOLVED]
Replies: 19
Views: 3254

Re: How to "resolve" an interface list? [SOLVED]

This is likely impossible. "interface lists" aren't really lists, they are bits set in a value related to every interface.
There does not seem to be a query function in RouterOS to ask which interfaces are (dynamic) member of a certain list.
by pe1chl
Thu Jun 08, 2023 11:08 am
Forum: General
Topic: Routeros, operating system services boot order [SOLVED]
Replies: 14
Views: 1138

Re: Routeros, operating system services boot order [SOLVED]

I can't find any information about the startup order of services when booting RouterOS into a router. I'd like to understand which services are activated first and which ones last, for example, assuming the services are enabled, does the client PPPoE service start before or after the SNTP service? ...
by pe1chl
Thu Jun 08, 2023 11:03 am
Forum: RouterBOARD hardware
Topic: USB -> RJ45 for PoE? Or will MT start putting USB-C ports?
Replies: 23
Views: 4029

Re: USB -> RJ45 for PoE? Or will MT start putting USB-C ports?

It's only 5V No, that is wrong! USB-C supplies can deliver a number of different voltages. They start out at 5V but they talk to a chip on the receiving end that tells them what voltage to deliver. So indeed it would be possible to add such an input to a (new) MikroTik device and have it powered by...
by pe1chl
Thu Jun 08, 2023 12:28 am
Forum: Beginner Basics
Topic: WiFi - When to use "main interface", when to use "virtual interfaces"
Replies: 10
Views: 2410

Re: WiFi - When to use "main interface", when to use "virtual interfaces"

Every additional SSID decreases performance, so reducing the number SSID needed is what helps performance. e.g. If your goal is "cleanup the config" by using only virtual SSIDs... that's not a good idea. Indeed! I cleaned up my config and have only a single SSID now with mac-based assignm...
by pe1chl
Wed Jun 07, 2023 3:35 pm
Forum: Beginner Basics
Topic: Issues with the github website.
Replies: 13
Views: 1797

Re: Issues with the github website.

Out of interest, is there anyway to change the Actual MTU of the pppoe client? Not really. It is possible to set max-mtu (and max-mru ) on PPPoE-client, but that's only "negotiation input" from client's side In his case it apparently is (he asked on other forums) but in the general case a...
by pe1chl
Wed Jun 07, 2023 3:29 pm
Forum: Beginner Basics
Topic: Issues with the github website.
Replies: 13
Views: 1797

Re: Issues with the github website.

Yes that is OK, the value you should set in the IPv6->ND should be the same as the Actual MTU of your PPPoE interface while the connection is up. When that can be only 1454 due to the ISP network, that is the correct value to use. Also put it in the Max MTU and Max MRU fields of the PPPoE interface....
by pe1chl
Wed Jun 07, 2023 2:33 pm
Forum: Announcements
Topic: v7.9.2 [stable] is released!
Replies: 72
Views: 26332

Re: v7.9.2 [stable] is released!

Yes. You need to have a rule with that routing mark and what table it has to lookup. Actually I think that is a better solution as it gives you control over the sequence and the "lookup" or "lookup only". Hopefully it will be made like this for IPv4 as well (of course with warnin...
by pe1chl
Wed Jun 07, 2023 2:31 pm
Forum: RouterBOARD hardware
Topic: Long term effects of SSD HDD connected to 5009 router?
Replies: 26
Views: 4927

Re: Long term effects of SSD HDD connected to 5009 router?

I also have one RB4011 on my desk for testing purposes, but that one is not as much suited for docker containers because of the limited storage which can be easily expanded on RB5009. (One thing on 5009 that I dislike *very* much is the lack of serial port, but we have what we have.) Yeah, it is a ...
by pe1chl
Wed Jun 07, 2023 2:26 pm
Forum: Beginner Basics
Topic: system,critical,info cloud change time Jun/06/2023 07:37:42 => Jun/06/2023 12:15:30
Replies: 13
Views: 1950

Re: system,critical,info cloud change time Jun/06/2023 07:37:42 => Jun/06/2023 12:15:30

But really I posted the first line because I'm curious why the time change log after power cut. The reason for that is the router does not have a realtime clock chip. Its clock only runs when the device is powered on and running. At intervals of several hours it writes in a file, and the timestamp ...
by pe1chl
Wed Jun 07, 2023 2:22 pm
Forum: Beginner Basics
Topic: IPv6 nearly working . . . help needed
Replies: 20
Views: 2906

Re: IPv6 nearly working . . . help needed

Lots of babble babble but not even a reply to my question, let alone an attempt to try a solution.
I wish you good luck! (but will not help you further)
by pe1chl
Wed Jun 07, 2023 11:34 am
Forum: Beginner Basics
Topic: system,critical,info cloud change time Jun/06/2023 07:37:42 => Jun/06/2023 12:15:30
Replies: 13
Views: 1950

Re: system,critical,info cloud change time Jun/06/2023 07:37:42 => Jun/06/2023 12:15:30

Doesn't traffic get disrupted on your devices when power is cut ?
How odd ...
When the power gets cut, I notice it for other reasons. So I would first fix that before posting on a forum that my new device has a problem.
by pe1chl
Wed Jun 07, 2023 11:32 am
Forum: RouterBOARD hardware
Topic: Long term effects of SSD HDD connected to 5009 router?
Replies: 26
Views: 4927

Re: Long term effects of SSD HDD connected to 5009 router?

May I ask why? (I am too inclined to use it as is.)
Well, "powered hub" that is usually something in the "cheap crap Chinese computer add-on" category and it is probably less reliable than your router.
by pe1chl
Wed Jun 07, 2023 11:29 am
Forum: General
Topic: How to block Adguard LOCAL VPN
Replies: 18
Views: 2078

Re: How to block Adguard LOCAL VPN

Now you have identified one VPN that you do not like, and you may be able to block it in some way, but you will have to live with the fact that there are many different VPN providers, from "good" and "bad" guys, and that you will never be able to block them all. So your original ...
by pe1chl
Wed Jun 07, 2023 11:09 am
Forum: Beginner Basics
Topic: Issues with the github website.
Replies: 13
Views: 1797

Re: Issues with the github website.

That is not an advisable solution! IPv6 has a separate MTU setting under IPV6->ND that you can set to 1492. Set the ethernet MTU back to 1500. You can also experiment with setting the MTU of the PPPoE interface to 1500 and see if that remains after it re-connects. If so, your ISP supports larger MTU...
by pe1chl
Wed Jun 07, 2023 11:06 am
Forum: RouterBOARD hardware
Topic: Long term effects of SSD HDD connected to 5009 router?
Replies: 26
Views: 4927

Re: Long term effects of SSD HDD connected to 5009 router?

I would not add a powered hub only for this. Either use a powersupply connected to the device, or use it as it is.
by pe1chl
Wed Jun 07, 2023 11:05 am
Forum: Beginner Basics
Topic: system,critical,info cloud change time Jun/06/2023 07:37:42 => Jun/06/2023 12:15:30
Replies: 13
Views: 1950

Re: system,critical,info cloud change time Jun/06/2023 07:37:42 => Jun/06/2023 12:15:30

Well, maybe read more carefully before reply... he also says "I get cuts in traffic which is quite annoying while working remotely and in meetings". So it is likely not his power failing, but the ax2 crashing for some reason. What RouterOS version is it running? has that been updated after...
by pe1chl
Wed Jun 07, 2023 11:02 am
Forum: Beginner Basics
Topic: IPv6 nearly working . . . help needed
Replies: 20
Views: 2906

Re: IPv6 nearly working . . . help needed

Do you have a connection to the ISP with less than 1500 byte MTU? E.g. a PPPoE connection often has that problem. If so, first try to fix that. Try to set 1500 byte MTU and MRU on the PPPoE interface and see if that remains after re-negotiation. If so, your problem is probably fixed. If not remove t...
by pe1chl
Wed Jun 07, 2023 12:46 am
Forum: RouterOS beta
Topic: [7.10 stable] DNS Crash
Replies: 54
Views: 11163

Re: [7.10rc3]DO NOT UPDATE!!!

Way in the past, in some v6.xx version, one time I have seen the same thing on my router: timeout values suddenly zero, all DNS queries fail.
No idea what has caused it. Of course easy to fix.
by pe1chl
Tue Jun 06, 2023 11:45 am
Forum: Virtualization
Topic: Can not use GRE with CHR on Proxmox
Replies: 4
Views: 5303

Re: Can not use GRE with CHR on Proxmox

That is what I mean, there also is another setting to allow MAC spoofing. You NEED that to run a bridge in a VM.
by pe1chl
Mon Jun 05, 2023 4:16 pm
Forum: Forwarding Protocols
Topic: BGP and routing filter improvement suggestions
Replies: 61
Views: 25219

Re: BGP and routing filter improvement suggestions

Is BGP Route Flap Damping (RFC 2439) implemented?
As far as I know not supported. But it is a good feature request.
More than 10 years later, has it already been considered or even worked on?
by pe1chl
Mon Jun 05, 2023 4:09 pm
Forum: Virtualization
Topic: Can not use GRE with CHR on Proxmox
Replies: 4
Views: 5303

Re: Can not use GRE with CHR on Proxmox

I do not have experience with Proxmox, but in VMware ESXi there are settings for this, maybe on Proxmox as well.
by pe1chl
Mon Jun 05, 2023 4:07 pm
Forum: Beginner Basics
Topic: Masquarade src-address-type=!local?
Replies: 2
Views: 494

Re: Masquarade src-address-type=!local?

That is right. Using src-address-type=!local is likely too broad. But of course you could use src-address=!(the address of the external interface).
by pe1chl
Mon Jun 05, 2023 4:05 pm
Forum: General
Topic: v7 to 6 any chance to downgrade?
Replies: 27
Views: 5291

Re: v7 to 6 any chance to downgrade?

v7 is not production ready for my needs, so if you force v7 even on older hardware, then... this is the end of an era for me. May I ask why? Just curious what you are missing. What I don't understand is why, after all the times we have mentioned this, there still is not a published table of differe...
by pe1chl
Sun Jun 04, 2023 7:14 pm
Forum: General
Topic: Feature requests
Replies: 1742
Views: 637578

Re: Feature requests

The problem is that there is no BNF definition of the language that corresponds with the behavior of the parser. So you cannot make arbitrarily complex nested expressions that would be valid in almost any language. At some point it just issues an error. And of course, the indication and handling of ...
by pe1chl
Sun Jun 04, 2023 6:18 pm
Forum: General
Topic: Feature requests
Replies: 1742
Views: 637578

Re: Feature requests

For me, the most important is to add a BNF definition of the language and make the parser adhere to it. I have found many times that when combining various constructs that each are supported into a complicated expression, it does not work. You need to break up complicated expressions into various st...
by pe1chl
Sun Jun 04, 2023 11:21 am
Forum: General
Topic: Feature requests
Replies: 1742
Views: 637578

Re: Feature requests

Simplify a lot of work ? I would say it is just a niche case that is mainly a trick, and associative arrays (as in the example by rextended) are the proper way to do what you want. Sure there are some things that can be improved in the scripting language, and especially in its parser, but I don't co...
by pe1chl
Sat Jun 03, 2023 6:39 pm
Forum: General
Topic: Encountered an ARP table exhaustion attack
Replies: 15
Views: 1743

Re: Encountered an ARP table exhaustion attack

ok. the mac table is full. traffic dropped. let's clear up some old inactive entries. The problem is that the entries that make your table overflow are neither old nor inactive. They probably are waiting for the targeted machine to answer to the ARP query, and when that answer comes in to send the ...
by pe1chl
Sat Jun 03, 2023 11:58 am
Forum: Announcements
Topic: v7.10rc is released!
Replies: 183
Views: 53920

Re: v7.10rc is released!

Still issue on rb4011 with rc3 with vlan and l3hw
RB4011 and L3HW ??? What???
by pe1chl
Fri Jun 02, 2023 11:21 am
Forum: General
Topic: Address list import script - bug?
Replies: 11
Views: 1175

Re: Address list import script - bug?

Well, you could do an extra check before accepting an entry. When the entry has bits in the subnet part of the address, it is bad and should be discarded. E.g. when the entry is 80.81.82.83/24 it is bad. When it is 80.81.82.0/24 it is good. But when it is 80.81.82.0/2 it is bad. It would also be wor...
by pe1chl
Fri Jun 02, 2023 1:12 am
Forum: Announcements
Topic: v7.9.2 [stable] is released!
Replies: 72
Views: 26332

Re: v7.9.2 [stable] is released!

I think it has always been like that. This setting requires a reboot. Maybe it should indicate that.
by pe1chl
Thu Jun 01, 2023 9:01 pm
Forum: Forwarding Protocols
Topic: BGP and IPSec policy
Replies: 6
Views: 3042

Re: BGP and IPSec policy

The forum has a search function. When you search for VTI you can find the many other requests to have it implemented. Due to the limits of the search function it is not so easy to find the latest reply from a MikroTik employee, but I'm quite sure that the latest reply was "there currently are n...
by pe1chl
Thu Jun 01, 2023 4:16 pm
Forum: General
Topic: Encountered an ARP table exhaustion attack
Replies: 15
Views: 1743

Re: Encountered an ARP table exhaustion attack

A few days ago, I was attacked by a host in a local area network,This host scans the local area network segment 192.168.0.0/16, Probably not really an attack. Some applications think it is a good idea to locate other users of the application, or sometimes certain resources (like a printer) by scann...
by pe1chl
Thu Jun 01, 2023 4:08 pm
Forum: General
Topic: How to remove one or more NAT layers from my internal network?
Replies: 31
Views: 2007

Re: Accessing internet without NAT?

Configure and use IPv6, then you get many addresses that you can use without NAT.
by pe1chl
Thu Jun 01, 2023 11:29 am
Forum: General
Topic: Feature requests
Replies: 1742
Views: 637578

Re: Feature requests

Log is seen by admin to reveal some undesired activity. Copypasting is time consuming. Consider adding a button which will call New Firewall rule, with pre-filled IP from Log entry. This is supposed to improve usability. Of course you would not want to make a "new firewall rule" for that!...
by pe1chl
Thu Jun 01, 2023 11:24 am
Forum: Announcements
Topic: v7.10rc is released!
Replies: 183
Views: 53920

Re: v7.10rc is released!

That OID is a standard MIB-2 one.
by pe1chl
Thu Jun 01, 2023 11:22 am
Forum: Announcements
Topic: v7.9.2 [stable] is released!
Replies: 72
Views: 26332

Re: v7.9.2 [stable] is released!

WiFi AP being connected is from Ubuiqiti or Cisco, have seen it happen on both. We have several RB951G-2HnD and they have been upgraded from 7.7 to 7.9.1 when this first happened, before there was no such issue and there has been no config change. Normally such a situation will mean loss of connecti...
by pe1chl
Thu Jun 01, 2023 10:53 am
Forum: Announcements
Topic: v7.9.2 [stable] is released!
Replies: 72
Views: 26332

Re: v7.9.2 [stable] is released!

There appears to be a "new" issue (at least from 7.9.1 but it could be in any version after ~ 7.7) with WiFi in station mode (connecting to another AP), with a DHCP client on the wireless interface. When the WiFi gets established, the DHCP client does not always succeed in getting an addr...
by pe1chl
Wed May 31, 2023 9:25 pm
Forum: Announcements
Topic: v7.9.2 [stable] is released!
Replies: 72
Views: 26332

Re: v7.9.2 [stable] is released!

There appears to be a "new" issue (at least from 7.9.1 but it could be in any version after ~ 7.7) with WiFi in station mode (connecting to another AP), with a DHCP client on the wireless interface. When the WiFi gets established, the DHCP client does not always succeed in getting an addre...
by pe1chl
Wed May 31, 2023 3:42 pm
Forum: Forwarding Protocols
Topic: BGP and IPSec policy
Replies: 6
Views: 3042

Re: BGP and IPSec policy

It has been requested for many years, but the recent reply to it was that it is not planned to be implemented. That is indeed sometimes inconvenient, but it is what it is. Remember that there are tens of different VPN protocols each having multiple options, and it simply isn't possible to implement ...
by pe1chl
Wed May 31, 2023 1:47 pm
Forum: General
Topic: Custom Chains - Forward or Input?
Replies: 2
Views: 397

Re: Custom Chains - Forward or Input?

Think of them as a template, they're unused until you send something into them from a parent chain They are not a template. You can view them as a subroutine. It can be called from other chains (like input and forward) using action "jump" (which should have been named "call"). S...
by pe1chl
Wed May 31, 2023 1:43 pm
Forum: Forwarding Protocols
Topic: BGP and IPSec policy
Replies: 6
Views: 3042

Re: BGP and IPSec policy

What you want to do is not possible with MikroTik. RouterOS does not support VTI and apparently there are no plans to add it. What you can do instead: remove all your IPsec config and add a GRE tunnel with IPsec password. That will automatically create IPsec policies for transporting GRE over IPsec....
by pe1chl
Tue May 30, 2023 10:16 pm
Forum: Beginner Basics
Topic: Wireless access point recommendation?
Replies: 27
Views: 2044

Re: Wireless access point recommendation?

When I run a scan, I see about 100 APs on 2.4 GHz and 40 APs on 5 GHz. The entire 5GHz band is used, the high channels too. And I run my own PtP link on 5520 so don't want to be close to that either.
by pe1chl
Tue May 30, 2023 8:06 pm
Forum: Beginner Basics
Topic: Wireless access point recommendation?
Replies: 27
Views: 2044

Re: Wireless access point recommendation?

Main point (and I see this return on many threads where performance issues are being reported) is to make sure your chosen frequency is CLEAR from interference by other APs.
That is a good joke!
But I do not live in the desert...
by pe1chl
Tue May 30, 2023 7:59 pm
Forum: Containers
Topic: Launch container with CPU limit
Replies: 11
Views: 4692

Re: Launch container with CPU limit

I'm sure you can always find scenarios and cook up tests that show a problem.
My only remark is that in normal situations it will not be that much of a problem.
by pe1chl
Tue May 30, 2023 4:49 pm
Forum: Containers
Topic: Launch container with CPU limit
Replies: 11
Views: 4692

Re: Launch container with CPU limit

In Linux it is not like in some other OSes, that a process demanding CPU at the same (default) priority will automatically starve other processes. In fact, when a process is demanding a lot of CPU, its priority is automatically decreased a little, so that other processes will go first and it gets th...
by pe1chl
Tue May 30, 2023 4:45 pm
Forum: Beginner Basics
Topic: Wireless access point recommendation?
Replies: 27
Views: 2044

Re: Wireless access point recommendation?

While all of your remark is quite correct, my remark was about your indication towards 50% expected real life speed. 1201Mpbs date rate (yes, RADIO data rate. After all, we are talking about wifi), translates on AX device to 800Mbps-something speed. Over Wifi. That's a bit more then 50%. Ok, when I...
by pe1chl
Tue May 30, 2023 4:39 pm
Forum: General
Topic: Dual PSU priority
Replies: 4
Views: 491

Re: Dual PSU priority

Maybe you have other equipment and you can use an "automatic transfer switch" to switch between inverter and mains, and feed its output to the CCR2004 and maybe also to equipment that has only one powersupply. Usually you can set a priority in such devices (or it is fixed and you can wire ...
by pe1chl
Tue May 30, 2023 4:38 pm
Forum: General
Topic: Dual PSU priority
Replies: 4
Views: 491

Re: Dual PSU priority

Maybe you have other equipment and you can use an "automatic transfer switch" to switch between inverter and mains, and feed its output to the CCR2004 and maybe also to equipment that has only one powersupply. Usually you can set a priority in such devices (or it is fixed and you can wire ...
by pe1chl
Tue May 30, 2023 4:13 pm
Forum: Beginner Basics
Topic: Wireless access point recommendation?
Replies: 27
Views: 2044

Re: Wireless access point recommendation?

I also see 1201/1201 being reported as data rate. What is reported there is the RADIO datarate. The radio is halfduplex and it has additional overhead for the radio protocol. So unlike a 1Gbps ethernet link which gives you very near to 1Gbps actual throughput in both directions at the same time, a ...
by pe1chl
Tue May 30, 2023 4:08 pm
Forum: General
Topic: Address list import script - bug?
Replies: 11
Views: 1175

Re: Address list import script - bug?

Most likely scenario is that for an entry added by someone/something, the subnet mask was specified as /2 instead of e.g. /24 RouterOS will automatically match the aaa.bbb.ccc.ddd/2 address to leave only the first two bits, which can be 64, instead of throwing an error when an address is specified ...
by pe1chl
Tue May 30, 2023 3:38 pm
Forum: Beginner Basics
Topic: Wireless access point recommendation?
Replies: 27
Views: 2044

Re: Wireless access point recommendation?

But no gigaspeed over wireless. Current MT products do not have that capability. If other vendor, wrong place to ask. :lol: Cap AX says 'Wireless 5 GHz Max data rate 1200 Mbit/s' would that not be gigabit? Always remember that such speeds (not only for MikroTik but also for all other manufacturers)...
by pe1chl
Tue May 30, 2023 3:35 pm
Forum: General
Topic: Address list import script - bug?
Replies: 11
Views: 1175

Re: Address list import script - bug?

Most likely scenario is that for an entry added by someone/something, the subnet mask was specified as /2 instead of e.g. /24 RouterOS will automatically match the aaa.bbb.ccc.ddd/2 address to leave only the first two bits, which can be 64, instead of throwing an error when an address is specified w...
by pe1chl
Tue May 30, 2023 10:51 am
Forum: Announcements
Topic: v7.10rc is released!
Replies: 183
Views: 53920

Re: v7.10rc is released!

But in what real-world use-cases should I select this new option over the "normal" SNAT or Masquerading action?
Ask that in the topic about "Full-Cone NAT"... those people seem to have a use for it.
by pe1chl
Sun May 28, 2023 7:19 pm
Forum: Wireless Networking
Topic: Problem with dynamic VLAN
Replies: 12
Views: 2770

Re: Problem with dynamic VLAN

Well thinking about it more, converting multicast to unicast may indeed be the only way to get multicast working on a single WiFi SSID with dynamically assigned VLANs.... Maybe it would be better when the multicast-helper setting "default" recognized this and enabled multicast helper for t...
by pe1chl
Sun May 28, 2023 12:00 pm
Forum: Wireless Networking
Topic: Problem with dynamic VLAN
Replies: 12
Views: 2770

Re: Problem with dynamic VLAN

The multicast helper configuration (on or off) has no effect on this problem... Well, that was wrong... I had wrongly assumed that the setting "default" for multicast helper would be OK for typical multicasts like IPv6 RA or Chromecast, as with that setting it works OK when a single VLAN ...
by pe1chl
Sat May 27, 2023 8:31 pm
Forum: Wireless Networking
Topic: Problem with dynamic VLAN
Replies: 12
Views: 2770

Re: Problem with dynamic VLAN

I fully agree. I don't have any equipment capable of running wifiwave2 (I have a 4011 but cannot afford to lose 2.4GHz) so I cannot test that. Maybe you can do an experiment :-) When you have several APs running on VLANs (using the vlan tag option in the Wireless interface) you can just add a single...
by pe1chl
Sat May 27, 2023 5:00 pm
Forum: Wireless Networking
Topic: Problem with dynamic VLAN
Replies: 12
Views: 2770

Re: Problem with dynamic VLAN

The multicast helper configuration (on or off) has no effect on this problem... Of course the handling of VLAN tags (inside the wifi driver) requires additional processing. Not by looking at the access list every time, but by registering the VLAN determined from the access list at time of connection...
by pe1chl
Fri May 26, 2023 7:52 pm
Forum: Announcements
Topic: v7.10rc is released!
Replies: 183
Views: 53920

Re: v7.10rc is released!

(continuation of discussion in beta topic that has been locked) I found a temporary way to log something when BFD detects a link loss. I added a logging entry with topics=bgp,debug,!packet,!timer That logs a "Entering OpenConfirm state BgpStarter ..." message every time BGP is restarted. O...
by pe1chl
Fri May 26, 2023 7:43 pm
Forum: Beginner Basics
Topic: Palo Alto to Mikrotik Routing
Replies: 5
Views: 1044

Re: Palo Alto to Mikrotik Routing

Well, normally you would not add another address on the tunnel interface, but rather a static route like this:
/ip route add dst-address=192.168.100.0/23 gateway=192.168.81.2
by pe1chl
Fri May 26, 2023 6:16 pm
Forum: Beginner Basics
Topic: Palo Alto to Mikrotik Routing
Replies: 5
Views: 1044

Re: Palo Alto to Mikrotik Routing

When you have setup the GRE tunnel (that seems OK) of course then you need to add a route to the destination network via the remote IP on the GRE tunnel (10.10.6.2).
by pe1chl
Fri May 26, 2023 4:51 pm
Forum: Wireless Networking
Topic: Wireless repeater and AP
Replies: 15
Views: 2590

Re: Wireless repeater and AP

Remember that you cannot run a bridging wireless repeater across different brands! WiFi does not have a standardized transparent bridge mode.
The safest bet is to remove the bridge and make a routing setup, i.e. have a different network on the AP side (with its own DHCP server etc), and double-NAT.
by pe1chl
Fri May 26, 2023 4:19 pm
Forum: Wireless Networking
Topic: Problem with dynamic VLAN
Replies: 12
Views: 2770

Re: Problem with dynamic VLAN

Nobody else using dynamic VLAN assignment for wireless?
This problem is driving me nuts... I would at least want to hear if someone can confirm this problem or if I maybe have some subtle error in my config that causes this.
Even support has not replied to my ticket SUP-114289 after a month...
by pe1chl
Fri May 26, 2023 4:11 pm
Forum: Beginner Basics
Topic: Palo Alto to Mikrotik Routing
Replies: 5
Views: 1044

Re: Palo Alto to Mikrotik Routing

Your Palo Alto is probably doing "VTI". MikroTik does not support that.
Instead you can use a GRE tunnel over IPsec transport.
by pe1chl
Fri May 26, 2023 2:48 pm
Forum: Beginner Basics
Topic: How do I make IPv6 work?
Replies: 26
Views: 9835

Re: How do I make IPv6 work?

Detailed and easy to understand steps to solve this problem. Thank you for sharing your answer If that's detailed enough for you, maybe you can make it detailed enough for me? How do I make the router receive IPv6 address to redistribute it internally? Or no further steps are required? It just rece...
by pe1chl
Fri May 26, 2023 1:14 pm
Forum: General
Topic: hap lite, not enough disk space.
Replies: 64
Views: 56618

Re: hap lite, not enough disk space.

Indeed, unfortunately for a long time the units have been shipped with "bundle package".
6.49b22 is not off-factory, I think ?
Once you have bundle package, it will remain when you upgrade via the "check" button.
by pe1chl
Fri May 26, 2023 11:21 am
Forum: General
Topic: hap lite, not enough disk space.
Replies: 64
Views: 56618

Re: hap lite, not enough disk space.

Indeed, unfortunately for a long time the units have been shipped with "bundle package". That means all packages are always on the unit, except you can disable some of them. Then they will not appear in the menus and they won't be running (so they cannot cause security issues), but they st...
by pe1chl
Thu May 25, 2023 11:09 pm
Forum: General
Topic: hap lite, not enough disk space.
Replies: 64
Views: 56618

Re: hap lite, not enough disk space.

Netinstall. Or: don't upgrade.
by pe1chl
Thu May 25, 2023 8:08 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

!) route - added BFD (CLI only); In v6 the BFD logged messages using the facility "bfd". So I added that to the logging to get informative messages about bfd dead link detection. In the current version it does not seem to log anything, neither from bfd nor from bgp. I only see the lower u...
by pe1chl
Thu May 25, 2023 8:02 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

When using DHCPv6, the router can get its gateway via that. Nothing iffy about that. It does not need a RA receiver to receive a link-local address, that is assigned automatically derived from the MAC. The RA receiver is only required to set a global address on the link, which isn't required as you ...
by pe1chl
Thu May 25, 2023 5:06 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

Another possibility: use two devices. One running newest ROS version as border gateway (which is realistically the target for CVE-2023-32154 related attacks) and the other running whatever ROS version works for your wireless (and doesn't have to accept RAs because you use IPv4 for management) ... I...
by pe1chl
Thu May 25, 2023 4:09 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

CVE-2023-32154 will not affect most people.
by pe1chl
Thu May 25, 2023 3:13 pm
Forum: General
Topic: Cisco IPsec To Mikrotik
Replies: 8
Views: 1112

Re: Cisco IPsec To Mikrotik

... or do not bother about IPsec config on the MikroTik and just create the IPsec tunnel with an IPsec password. That will auto-generate the settings. However, getting IPsec to work between different manufacturers is not so simple. You need experience and persistence. "can nobody help me" ...
by pe1chl
Thu May 25, 2023 3:09 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

I guess i just need to buy new device, i dont have anything special installed and i did neinstall few months ago... Did you do backup before the netinstall and restore afterwards? Don't do that! Use export/import when you really need to transport some config. Better is to use default settings and d...
by pe1chl
Thu May 25, 2023 10:31 am
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

Indeed I also update a hAP ac2 without problems, but on that device the flash memory space is getting very tight. When you have put files of your own on the device, remove them. When you have installed extra stuff like user-manager, remove it (move to some other device). When you have done upgrade a...
by pe1chl
Wed May 24, 2023 9:28 pm
Forum: Announcements
Topic: EDITED Forum THEME / SKIN change
Replies: 92
Views: 11676

Re: EDITED Forum THEME / SKIN change

But all the white empty spaces in post are annoying as well.
Yeah it is idiotic that the number of posts, time of joining the forum (and location) is displayed with every post. People can look that up in the profile.
Due to this, extra blank space is added after every short post.
by pe1chl
Wed May 24, 2023 6:55 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

Well I guess that with any change in any system there will be people claiming it is a problem because their niche use is now no longer possible... I use a lot of comments, but as I have switched over to winbox quite some time ago (after initially using webfig because I use Linux and did not want to ...
by pe1chl
Wed May 24, 2023 1:46 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

One example is the DHCP lease tables. I have scripts that go through each of my edge routers (20ish at present) and makes current leases static for use by UISP and traffic shaping. Sometimes I have the customer's full name in the comment field, but more often than not I pull the hostname from the D...
by pe1chl
Wed May 24, 2023 12:00 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

As you can see from other commenters, who like it ... This is a matter of taste. How is "left aligned" in your big monitor not wasting space, but centering is wasting space? It is the same amount of wasted space, just in a different place. Do not use webfig in a maximised window on a ultr...
by pe1chl
Wed May 24, 2023 11:56 am
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

I like the inline comments in WebFig. It's saving me a lot of time scrolling. I ask that Mikrotik don't change this back. . Actually we have asked, earlier on this thread and on the 7.9 threads as well, to have the OPTION to choose inline or "newline" comments, just like the winbox has (a...
by pe1chl
Tue May 23, 2023 11:57 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

As expected (feared), the count is before route filtering, whereas in v6 it was after route filtering. But still better than nothing! If you refer to "filtered" by routing filters then there is no difference filtered or not filtered, total route count stays the same in both cases. In v7, ...
by pe1chl
Tue May 23, 2023 10:01 pm
Forum: Beginner Basics
Topic: Why not a definitive solution to block Youtube?
Replies: 55
Views: 20967

Re: Why not a definitive solution to block Youtube?

Please read all of the above before you post your useless addition!
by pe1chl
Tue May 23, 2023 8:40 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

It looks like the BFD actually works fine! Hooray! Next wish-list item: make the "BGP Sessions" tab in winbox auto-refreshing like the "BGP Peers" tab in version 6. Right now the information displayed w.r.t. active sessions, prefixes, rx/tx messages and uptime is stale unless you...
by pe1chl
Tue May 23, 2023 7:36 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

*) bgp - show approximate received prefix count by the session;
As expected (feared), the count is before route filtering, whereas in v6 it was after route filtering.
But still better than nothing!
by pe1chl
Tue May 23, 2023 4:16 pm
Forum: RouterOS beta
Topic: v7 and BFD, any ETA?
Replies: 149
Views: 27915

Re: v7 and BFD, any ETA?

It is not only about "router going down", it also (and mainly) is about "link going down". When you have a partial mesh of WiFi PtP links or Internet tunnels between many different locations, and there are alternative paths, you want your routing to adapt quickly when a link is d...
by pe1chl
Tue May 23, 2023 2:25 pm
Forum: Announcements
Topic: EDITED Forum THEME / SKIN change
Replies: 92
Views: 11676

Re: EDITED Forum THEME / SKIN change

What is the justification for removing the default style.
******** maintainers that blame all problems on styles...
by pe1chl
Tue May 23, 2023 12:49 am
Forum: General
Topic: "Routing Table" Parameter for IPv6 Routes Not in Effect (v7.5) [SOLVED]
Replies: 17
Views: 4398

Re: "Routing Table" Parameter for IPv6 Routes Not in Effect (v7.5) [SOLVED]

Well, routing rules are always a bit troublesome. One would want either a "destination is connected route" matcher in routing rules (so one can lookup in main table) or even better some feature to "automatically copy connected routes to this table" in routing tables. I understand...
by pe1chl
Mon May 22, 2023 2:23 pm
Forum: General
Topic: [BUG] Possible memory leak on hAP ac lite (64MB RAM) running ROS 7.x - known issue?
Replies: 4
Views: 613

Re: [BUG] Possible memory leak on hAP ac lite (64MB RAM) running ROS 7.x - known issue?

It is not advisable to upgrade "lite" devices to 7.x "just for the sake of upgrading".
I would say only do it when you require some functionality that is only in 7.x, if not remain on 6.x for the lifetime of the device.
by pe1chl
Mon May 22, 2023 12:51 pm
Forum: General
Topic: Any info about this ? ZDI-23-710 CVE-2023-32154
Replies: 48
Views: 8032

Re: Any info about this ? ZDI-23-710 CVE-2023-32154

The blog says "with enabled IPv6 advertisement functionality" but I think that should be read as "with enabled IPv6 advertisement receiver functionality", right?
I.e. merely having IPv6 router advertisement enabled is not a problem?
by pe1chl
Sat May 20, 2023 9:01 pm
Forum: General
Topic: Any info about this ? ZDI-23-710 CVE-2023-32154
Replies: 48
Views: 8032

Re: Any info about this ? ZDI-23-710 CVE-2023-32154

blog = new help docs?
No, blog = https://blog.mikrotik.com/
But nothing has been posted there for nearly two years...
by pe1chl
Sat May 20, 2023 5:28 pm
Forum: Announcements
Topic: FORUM MAINTENANCE: Password reset will be needed
Replies: 162
Views: 45199

Re: FORUM MAINTENANCE: Password reset will be needed

Come on! Not so impatient! It could take 2 years to fix that, BFD is still not working after 2 years.
by pe1chl
Sat May 20, 2023 5:24 pm
Forum: General
Topic: Webfig Enhancement
Replies: 24
Views: 6783

Re: Webfig Enhancement

In comparison with previous versions, inline comments are less usefull and readable for me. As example - in Interface list page or Firewall filter list page - there are many more important columns and I need to fit them to browser window.If I enlarge comment column to see full length of comments(wh...
by pe1chl
Fri May 19, 2023 5:58 pm
Forum: General
Topic: Any info about this ? ZDI-23-710 CVE-2023-32154
Replies: 48
Views: 8032

Re: Any info about this ? ZDI-23-710 CVE-2023-32154

Blog entry following soon
Blog? I did not know it still existed...
by pe1chl
Wed May 17, 2023 7:35 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

That must be a bug that involves more than setting a priority, as I use that to set 802.1p priority and it mostly works for me. I know about one peculiar bug: a GRE tunnel with "DSCP inherit" and IPsec transport, over PPPoE on a VLAN with 802.1p priority, will not work on the 4011 while th...
by pe1chl
Wed May 17, 2023 5:37 pm
Forum: Announcements
Topic: FORUM MAINTENANCE: Password reset will be needed
Replies: 162
Views: 45199

Re: FORUM MAINTENANCE: Password reset will be needed

Yes, that is a bit sad. But it only happened today, not during the forum maintenance.
by pe1chl
Wed May 17, 2023 1:44 pm
Forum: General
Topic: IKE2: can't agree on IKE proposal - RouterOS choosing wrong proposal!
Replies: 6
Views: 877

Re: IKE2: can't agree on IKE proposal - RouterOS choosing wrong proposal!

Yes, phase 1 at least has to be compatible for all. There is a chicken-egg problem because the server cannot know the identity of the client before starting phase 1 (especially when you cannot tie that to remote address). In general I would suggest that, however cute it may be to have all kinds of v...
by pe1chl
Wed May 17, 2023 12:59 pm
Forum: General
Topic: IKE2: can't agree on IKE proposal - RouterOS choosing wrong proposal!
Replies: 6
Views: 877

Re: IKE2: can't agree on IKE proposal - RouterOS choosing wrong proposal!

It is always difficult to follow other people's fragmented config and claimed problems, but on my router it works OK using "ip ipsec policy group", different settings per group, and linking of the identity to the group. It looks like you already have that, however. The order of the rules m...
by pe1chl
Wed May 17, 2023 12:53 pm
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43026

Re: Newsletter #113 | May 2023

I have no such requirement, my prefix is static. And most users don't have the requirement to open ports to a local server.
by pe1chl
Tue May 16, 2023 2:07 pm
Forum: Wireless Networking
Topic: Mikrotik x86 compatible wireless
Replies: 7
Views: 5272

Re: Mikrotik x86 compatible wireless

I guess x86 in combination with Wireless is not the main focus of MikroTik...
by pe1chl
Tue May 16, 2023 12:11 pm
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43026

Re: Newsletter #113 | May 2023

it takes extensive configuration with scripts to achieve basic functionality like a selective firewall There really isn't much difference between IPv4 and IPv6 firewall configuration. A problem in RouterOS v6 is that IPv6 is an optional module that is disabled by default, and when you first poweron...
by pe1chl
Tue May 16, 2023 11:30 am
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43026

Re: Newsletter #113 | May 2023

I am talking about performance. Your complaint is that it is slow. Still no exact test or comparison with those other routers Well, I agree with him that "Test results" for products on the product page (certainly for those that are still being sold) should include a specification of what ...
by pe1chl
Tue May 16, 2023 10:48 am
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43026

Re: Newsletter #113 | May 2023

Give specific numbers, how much IPv6 are you routing
These days, on my home router the traffic volume ratio is about 40/60 for IPv6/IPv4.
At work, it is about 50/50.
by pe1chl
Tue May 16, 2023 10:44 am
Forum: General
Topic: QoS Hardware Offloading (QoS-HW)
Replies: 46
Views: 12199

Re: QoS Hardware Offloading (QoS-HW)

The most often used priority sequence for the 3 bit field is: 1,2,0,3,4,5,6,7
So indeed 1 is lowest, 2 is above that, and then 0 (default) is higher and 3-7 are above that (7 is highest).
by pe1chl
Tue May 16, 2023 10:41 am
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

WPA3 is a change in security, not in rf waves, if your client has it implemented as expected and your AP too it just works. Got a few Aruba APs running and if there's something that has been working no matter what it's WPA3. Unless you have a crap Android phone that doesn't even get those patches a...
by pe1chl
Tue May 16, 2023 10:37 am
Forum: Beginner Basics
Topic: NTP server problems [SOLVED]
Replies: 22
Views: 3601

Re: NTP server problems [SOLVED]

Yes it looks OK. But "is synced" is not sufficient, you really need that detail that /system/ntp/client/print provides, e.g. the synced stratum and system offset, and even the synced server. E.g. when synced stratum is 10 or more, it can still be synchronized but some other clients may ref...
by pe1chl
Mon May 15, 2023 9:30 pm
Forum: Beginner Basics
Topic: NTP server problems [SOLVED]
Replies: 22
Views: 3601

Re: NTP server problems [SOLVED]

What does /system/ntp/client/print show?
by pe1chl
Mon May 15, 2023 9:15 pm
Forum: General
Topic: IKE2: can't agree on IKE proposal - RouterOS choosing wrong proposal!
Replies: 6
Views: 877

Re: IKE2: can't agree on IKE proposal - RouterOS choosing wrong proposal!

So RouterOS is choosing the proposal of site1, instead of roadwarrior, although site1 has a remote id matcher configured.
I don't see it in your config. You need to have an /ip/ipsec/identity configuration.
by pe1chl
Mon May 15, 2023 5:06 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

I am still wondering why the comment is now a column? And I actually wonder and question the decision-process behind this change. I think it is great! It has always been possible in winbox, and the setting "inline comments" is always the first thing I do when using winbox on a new device....
by pe1chl
Mon May 15, 2023 3:33 pm
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43026

Re: Newsletter #113 | May 2023

People used to buy RB2011UiAS-2HnD-IN because they are used to it and used to have same configs on all devices for years, and never because they needed RACK mount option (which 2011 doesn't have at all, not that 4 slow wifi routers in a RACK makes much sense to me anyways) RB2011 without WiFi does ...
by pe1chl
Mon May 15, 2023 11:14 am
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55128

Re: v7.9 [stable] is released!

It has been a bit of a mess for quite some time... duplicated field names in Winbox (e.g. "Full duplex") and different names for what could be the same thing ("Speed" vs "Rate"). Usually one of them is the configured setting and the other one is the negiotiated setting....
by pe1chl
Sun May 14, 2023 12:21 pm
Forum: Beginner Basics
Topic: Limit access to the Management interface
Replies: 6
Views: 1303

Re: Limit access to the Management interface

Is ether13 a member of a bridge of which all other ports are a member too? In that case you cannot limit access this way. The rule would need the name of the bridge as the in-interface, and it would match all bridge member ports. Of course it is possible to implement a bridge filter, but I'm not sur...
by pe1chl
Sat May 13, 2023 5:52 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

We have over 700 devices and not all of them connected. As mentioned, impossible to know which ones.
by pe1chl
Sat May 13, 2023 4:27 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

For now, I would not recommend the use of WPA3. (independent from the use of MikroTik WiFi) I don't have problems with WPA3 on Ubiquiti AP, i have combo WPA2/3 but then, i only have them for like 2-3 months now. I have tested with WPA2/WPA3 on Ubiquiti and I find that some devices won't connect to ...
by pe1chl
Sat May 13, 2023 1:27 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

It is actually quite common to see issues like this whenever new WiFi standards are introduced and also when they are implemented by AP manufacturers... I have seen it all on our Unifi system. It will take some time before the perfect balance between new features and compatibilty is found. For now, ...
by pe1chl
Sat May 13, 2023 12:49 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

My uploads were aweful, like I said above, i need to test more! but whatever type i used over time it got worse be-it cake/FQ_Codel or simple queues. now i've downgraded all is well. Ok I use only DSCP-based marking of traffic and translation to 802.11p priority tagging which is processed by my DSL...
by pe1chl
Sat May 13, 2023 12:46 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

Disabling WPA3 should eliminate PMKSA error, as it is WPA3 related.
I am not so sure about that.
For sure it is. But it depends on the connected clients. It may well be that your modern clients on 5GHz have no problem, and the old crap or IoT devices (ESP based) have problems.
by pe1chl
Sat May 13, 2023 12:06 pm
Forum: Announcements
Topic: v7.10beta [testing] is released!
Replies: 249
Views: 52945

Re: v7.10beta [testing] is released!

Sadly I've had to downgrade to 7.9 due to problems with QOS.
What did you configure w.r.t QoS and what problems do you have? I presume it isn't related to qos-hw.
by pe1chl
Fri May 12, 2023 11:12 pm
Forum: RouterBOARD hardware
Topic: Fan installation in RB1100AHx4
Replies: 13
Views: 4848

Re: Fan installation in RB1100AHx4

Thanks for the pictures... did you check the 2 locations for transistors (or double diodes) near the 5V FAN connection? Do they have 5V on some of the pins? They could be related to the FAN pins, and the fact that they are not populated could explain why there is no output voltage on that connector....
by pe1chl
Fri May 12, 2023 11:09 pm
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43026

Re: Newsletter #113 | May 2023

Well, when you use 40 MHz channel width you effectively have only one channel anyway, so it does not matter if it always uses channel 1...
IMHO the max width on 2 GHz is 20 MHz, which gives you 3 channels.
by pe1chl
Fri May 12, 2023 12:39 pm
Forum: General
Topic: QoS Hardware Offloading (QoS-HW)
Replies: 46
Views: 12199

Re: QoS Hardware Offloading (QoS-HW)

P.S. Please stay on the topic!
If only MikroTik would do that themselves. I.e. finish the unfinished features in v7 before starting a new one.
by pe1chl
Fri May 12, 2023 11:47 am
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43026

Re: Newsletter #113 | May 2023

Fiber is a commercial operation here. The places where it was deployed early were subsidized or at least guaranteed by some authority like a municipality or a housing agency. In most places, there is a cold calculation of "what will it cost to deploy it, how many customers will we get, and what...
by pe1chl
Fri May 12, 2023 11:08 am
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43026

Re: Newsletter #113 | May 2023

The issue is not only "internet speed". When I do a scan on an indoor router here, I see about 100 APs on 2 GHz (and I only have 1-6-11 in my scanlist so there probably are more), and only 15 on 5 GHz. Almost any ISP provides a dual-band router these days, but of course the shielding is a ...
by pe1chl
Fri May 12, 2023 10:54 am
Forum: General
Topic: ⚠️WARNING: RouterOS v7.10+ will break all scripts based on [/system clock get date] or other date(s)
Replies: 64
Views: 13814

Re: ⚠️WARNING: RouterOS v7.10+ will break all scripts based on [/system clock get date] or other date(s)

Come on, it took me a moment to modify all my scripts on the forum and in production to be ready I think the issue is not how much work it is for a capable programmer to modify the code, but more the vast number of copy/paste programmers that have tinkered a script that works and suddenly it breaks...
by pe1chl
Thu May 11, 2023 11:34 pm
Forum: Beginner Basics
Topic: What is the best for pcc
Replies: 2
Views: 321

Re: What is the best for pcc

It depends on what you want: best distribution of load, or least chance of subtle problems with certain sites or services.
I use "src address only". That gives least chance of trouble, but it only distributes load well when you have lots of users.
by pe1chl
Thu May 11, 2023 11:28 pm
Forum: General
Topic: QoS Hardware Offloading (QoS-HW)
Replies: 46
Views: 12199

Re: QoS Hardware Offloading (QoS-HW)

aditionally i am not sure PPPoE Server can benefit of L3 Hardware Offload at all
Maybe not this hardware, but actually some of the SoC do implement PPPoE hardware offloading, as it is a common use case for consumer routers.
However, it does not look like RouterOS uses it.
by pe1chl
Thu May 11, 2023 10:52 pm
Forum: General
Topic: ⚠️WARNING: RouterOS v7.10+ will break all scripts based on [/system clock get date] or other date(s)
Replies: 64
Views: 13814

Re: ⚠️WARNING: RouterOS v7.10+ will break all scripts based on [/system clock get date] or other date(s)

Back in 2018 it "was considered" to add a function library for scripting, and input was requested for what functions would be useful to have: https://forum.mikrotik.com/viewtopic.php?p=951855 One of the first proposed category was manipulation of date/time values. Unfortunately we never go...
by pe1chl
Thu May 11, 2023 10:46 pm
Forum: General
Topic: ⚠️WARNING: RouterOS v7.10+ will break all scripts based on [/system clock get date] or other date(s)
Replies: 64
Views: 13814

Re: ⚠️WARNING: RouterOS v7.10+ will break all scripts based on [/system clock get date] or other date(s)

Yes, it is just the name of the version, which happens to include a date/time (only for v7, in v6 this wasn't done).
Of course it can be changed when they change their build scripts. Still, that will show the new format date only for new versions, not for neighbors that run older versions.
by pe1chl
Thu May 11, 2023 7:06 pm
Forum: General
Topic: QoS Hardware Offloading (QoS-HW)
Replies: 46
Views: 12199

Re: QoS Hardware Offloading (QoS-HW)

When you are working on this anyway, please consider the following: 1. allow to set software queue priority directly from DSCP. now, there is a detour required: set "priority" from DSCP, then set "packet mark" from priority, then assign queue priority based on packet mark. Howeve...
by pe1chl
Thu May 11, 2023 5:35 pm
Forum: General
Topic: ⚠️WARNING: RouterOS v7.10+ will break all scripts based on [/system clock get date] or other date(s)
Replies: 64
Views: 13814

Re: ⚠️WARNING: RouterOS v7.10+ will break all scripts based on [/system clock get date] or other date(s)

BTW, another place to adopt:
[admin@MikroTik] > :put [ /system/resource/get build-time ]
May/09/2023 10:38:53
That is probably just as string as distributed in the package, not the result of a function that is running on the device itself...
by pe1chl
Wed May 10, 2023 11:09 pm
Forum: General
Topic: Translate ROS6 to ROS7 IP ROUTE
Replies: 12
Views: 924

Re: Translate ROS6 to ROS7 IP ROUTE

Yes, it should be enough to define a policy and peer. As long as there is "some" route to the remote network, ipsec will pickup the traffic and send it according to policy. (not that I would do that... I would define a GRE/IPsec tunnel and assign an IP to each endpoint and route the traffi...
by pe1chl
Wed May 10, 2023 8:57 pm
Forum: General
Topic: Translate ROS6 to ROS7 IP ROUTE
Replies: 12
Views: 924

Re: Translate ROS6 to ROS7 IP ROUTE

What should i choose on gateway in route list on external tunnel ipsec site to site connections? For that you normally do not have to add any route. Your default route will be sufficient. There only has to exist "a" route to the destination for ipsec site to site to work, it does not even...
by pe1chl
Wed May 10, 2023 8:52 pm
Forum: General
Topic: ⚠️WARNING: RouterOS v7.10+ will break all scripts based on [/system clock get date] or other date(s)
Replies: 64
Views: 13814

Re: ⚠️WARNING: RouterOS v7.10+ will break all scripts based on [/system clock get date] or other date(s)

At this point, we're taking about the output of "clock get" to avoid the need to parse English month names... Nothing more is included AFAIK (yet?). The change notes said: *) console - changed time format according to ISO standard; So I expected any date/time output visible on the console...
by pe1chl
Wed May 10, 2023 8:46 pm
Forum: Scripting
Topic: Is it possible to transfer data from the script to Graphing
Replies: 5
Views: 1618

Re: Is it possible to transfer data from the script to Graphing

of course you can write a script that displays the interesting data in a loop (e.g. every few seconds), and when you start that from the terminal you can look at it. you can even maintain some derived values in the script and display them as well, like average, average over last minute, lowest, high...
by pe1chl
Wed May 10, 2023 5:36 pm
Forum: General
Topic: ⚠️WARNING: RouterOS v7.10+ will break all scripts based on [/system clock get date] or other date(s)
Replies: 64
Views: 13814

Re: ⚠️WARNING: RouterOS v7.10+ will break all scripts based on [/system clock get date] or other date(s)

What I don't understand is why the new date format is implemented only for console, and only in very limited cases. The first log message I see already breaks the new system: 14:27:56 system,info ntp change time May/10/2023 14:27:56 => May/10/2023 14:27:56 I mean, was it really that difficult to mak...
by pe1chl
Wed May 10, 2023 11:17 am
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55128

Re: v7.9 [stable] is released!

In case if anybody has misbehaving rb4011 using vlans, please make sure you have MSTP enabled on bridge. Didn’t work in long run. I tried also disabling hw offloading on bridge ports or enable ign snooping as someone suggested and none of it helped. Gave up and reverted to 7.7 again. My 4011 is doi...
by pe1chl
Wed May 10, 2023 11:03 am
Forum: Wireless Networking
Topic: Problem with dynamic VLAN
Replies: 12
Views: 2770

Re: Problem with dynamic VLAN

As I mentioned, I tried it both with access-list and with radius authentication, but the result is the same. So the issue is in the handling of the assigned VLAN, not in the mechanism that assigns it. I think no special treatment of multicast should be required. E.g. I have a separate VLAN where my ...
by pe1chl
Tue May 09, 2023 10:41 pm
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43026

Re: Newsletter #113 | May 2023

I optimized my WiFi by using only a single SSID and using VLAN assignment via RADIUS (user-manager) to get each client on the correct VLAN. This is on classic Wireless, not wifiwave2. It turns out it does not work correctly: the client receives directed traffic and broadcasts, but not multicasts fro...
by pe1chl
Tue May 09, 2023 10:04 pm
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43026

Re: Newsletter #113 | May 2023

Well, at the moment I am more bothered by the bug in VLAN assignment via RADIUS even for a single client...
by pe1chl
Tue May 09, 2023 9:30 pm
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43026

Re: Newsletter #113 | May 2023

That is not so bad, right? It is sufficient for typical home-router use where internet is on ether1 and home devices are on the other ports. Ok, it is not optimal for use of SFP1. It would preferably be reconfigurable so that SFP1 is on the direct connection to the SoC and ether1-ether8 on the secon...
by pe1chl
Tue May 09, 2023 7:25 pm
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43026

Re: Newsletter #113 | May 2023

It says "2011... container support: no". But well, 2011 supported MetaROUTER.
by pe1chl
Tue May 09, 2023 5:49 pm
Forum: Scripting
Topic: Script - get item numbers
Replies: 3
Views: 1742

Re: Script - get item numbers

Item numbers are only valid in the user interface, not in scripts. The numbers are generated when a "print" command is used and are only valid for that login session.
To refer to items in scripts you always need to use [find ...], not item numbers.
by pe1chl
Tue May 09, 2023 4:10 pm
Forum: General
Topic: Packet loss on RB5009 when using multiple WAN links
Replies: 6
Views: 583

Re: Packet loss on RB5009 when using multiple WAN links

Well you could start by disabling fasttrack and see if it works better...
by pe1chl
Tue May 09, 2023 12:05 pm
Forum: General
Topic: ROS 7.9 IPSec defect
Replies: 24
Views: 4870

Re: ROS 7.9 IPSec defect

In recent versions you can have a user-defined RAMdisk. But I do not know if you can upgrade from packages stored there. And of course it would not work with the built-in upgrade commands, as I don't think you can set the download location, it is always .download in the root. (well, maybe you could ...
by pe1chl
Tue May 09, 2023 11:52 am
Forum: General
Topic: what framework is webfig written in?
Replies: 20
Views: 1451

Re: what framework is webfig written in?

Of course it is a disadvantage that you need to study a lot and do a lot of work when others (that use a framework) suddenly are able to do "spectacular" things like having a canvas with multiple overlapping child windows, like winbox has, and you want to introduce that in webfig. Or you w...
by pe1chl
Tue May 09, 2023 11:47 am
Forum: General
Topic: ROS 7.9 IPSec defect
Replies: 24
Views: 4870

Re: ROS 7.9 IPSec defect

Also, when you have a router that allows it (sufficient storage), always make 2 partitions and copy your running partition to the other one before the upgrade. Then, whenever an upgrade is not what you like it to be, you can just activate the other partition and reboot, and you are back to exactly w...
by pe1chl
Tue May 09, 2023 11:22 am
Forum: General
Topic: How to setup WiFi calling (aka VoWIFI) on mikrotik
Replies: 20
Views: 10658

Re: How to setup WiFi calling (aka VoWIFI) on mikrotik

You are probably talking about installation of a SIP app and configuring that to make calls via some SIP server. That is not what is commonly known as VoWIFI. VoWIFI is a service provided by telecom companies in addition to their VoLTE service (voice over 4G/5G), that does not use SIP directly on th...
by pe1chl
Mon May 08, 2023 10:56 am
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55128

Re: v7.9 [stable] is released!

Just look at Ubi Unifi interface - that's how modern interface should look like. When the look of the user interface is important to you, select the product that has the look you like! I think most users of MikroTik equipment do not care a bit how the webfig looks. Furthermore, I don't think "...
by pe1chl
Fri May 05, 2023 5:17 pm
Forum: Beginner Basics
Topic: Not TCP protocol prerouting: in:lte1 out
Replies: 52
Views: 3113

Re: Not TCP protocol prerouting: in:lte1 out

ok, I'll do an export (text-only ) of the configuration, scripts and modem settings. Then I'll do a total reset so at least I have the firewall with the default rules; then I'll add what's missing by hand. I don't see any other solution. You can also use this command in commandline mode: /system/de...
by pe1chl
Fri May 05, 2023 5:10 pm
Forum: General
Topic: Feature Request : DSCP on DHCP packets
Replies: 19
Views: 9043

Re: Feature Request : DSCP on DHCP packets

It may still be an option to go back to Orange, as nowadays it is EU-mandatory for providers to allow other manufacturer's equipment on their network. In the past, many ISPs implemented things like this to silently lockout other routers than what they provide themselves, and other manufacturers were...
by pe1chl
Fri May 05, 2023 12:07 pm
Forum: Beginner Basics
Topic: Not TCP protocol prerouting: in:lte1 out
Replies: 52
Views: 3113

Re: Not TCP protocol prerouting: in:lte1 out

Delete the "add action=drop chain=input comment="Winbox on WAN" dst-port=8291 in-interface=lte1 protocol=tcp" as well. You don't want that! The remainder seems to be about the default firewall, but I did not check that to every bit. I think MikroTik should add a "reset firew...
by pe1chl
Fri May 05, 2023 10:57 am
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55128

Re: v7.9 [stable] is released!

@pe1chl Because the user @jimint some users probably don't understand the difference between data transport and the services transported by transport.... Sorry but I lost track of that discussion due to excessive quote stripping (probably mandated by a dictator moderator). It looks like it is time ...
by pe1chl
Fri May 05, 2023 10:49 am
Forum: Beginner Basics
Topic: Not TCP protocol prerouting: in:lte1 out
Replies: 52
Views: 3113

Re: Not TCP protocol prerouting: in:lte1 out

There is no reason to block SCTP. Just use the default firewall rules. You contradict yourself, in the default firewall the SCTP directed to an IP that does not exist is deleted anyway... (or at most his machine is used to perhaps amplify an attack, if the response goes out again on the WAN because...
by pe1chl
Fri May 05, 2023 1:18 am
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55128

Re: v7.9 [stable] is released!

Also showing dropped packets making it unusable on RB4011iGS+
You are also thinking that "rx drop" indicates a problem?
by pe1chl
Fri May 05, 2023 1:16 am
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55128

Re: v7.9 [stable] is released!

I got IPv6 working but I am not sure why things worked in 7.8 and earlier releases, but I had to make a change to get it working in 7.9.
Most likely the config is wrong and it happened to work.
Please start a new topic with you export included. Not useful to discuss within this release topic.
by pe1chl
Fri May 05, 2023 1:14 am
Forum: Beginner Basics
Topic: Not TCP protocol prerouting: in:lte1 out
Replies: 52
Views: 3113

Re: Not TCP protocol prerouting: in:lte1 out

There is no reason to block SCTP.
Just use the default firewall rules.
by pe1chl
Thu May 04, 2023 10:53 pm
Forum: Beginner Basics
Topic: Not TCP protocol prerouting: in:lte1 out
Replies: 52
Views: 3113

Re: Not TCP protocol prerouting: in:lte1 out

@pe1chl So I would do well to delete them ? I have been using them for a few years and they have always worked well , only lately they give me that problem. Those rules bring you absolutely nothing. They never "worked well", they were just no-ops. Until, apparently, some of your devices s...
by pe1chl
Thu May 04, 2023 9:58 pm
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55128

Re: v7.9 [stable] is released!

IPv6 works fine for me on version 7.9 Are you using stateful or slaac? I am using slaac. The dhcpv6 client asks for and gets a prefix for ND. I add an address from the pool for the router which creates a route. This works fine with 7.8 but not 7.9. I will dig into it later but was curious what is w...
by pe1chl
Thu May 04, 2023 6:50 pm
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55128

Re: v7.9 [stable] is released!

IPv6 works fine for me on version 7.9
by pe1chl
Thu May 04, 2023 6:49 pm
Forum: Beginner Basics
Topic: Not TCP protocol prerouting: in:lte1 out
Replies: 52
Views: 3113

Re: Not TCP protocol prerouting: in:lte1 out

I'm just curious where the SCTP is coming from here. It's also connection oriented like TCP, so this could be a replay from a client initiating it. The above is why I stated that people should not mess with the "raw" table when they do not know exactly what they are doing. When there was ...
by pe1chl
Thu May 04, 2023 4:30 pm
Forum: Beginner Basics
Topic: Not TCP protocol prerouting: in:lte1 out
Replies: 52
Views: 3113

Re: Not TCP protocol prerouting: in:lte1 out

In general it can be said that people who do not have a detailed understanding of firewalls should NOT mess with the "raw" table! Especially they should not copy other people's "advice for firewall rules". Rules in the "raw" table can have unintended consequences and us...
by pe1chl
Thu May 04, 2023 4:25 pm
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55128

Re: v7.9 [stable] is released!

"rx drop" is not packet loss. And where is the packet loss in winbox? I make a ping www.google.com packet-loss=0% So what is your problem? I see the same thing. Packet loss is 0% on ping from either router or host behind it. So my conclusion is: no problem. But apparently some people beli...
by pe1chl
Thu May 04, 2023 2:03 pm
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55128

Re: v7.9 [stable] is released!

"rx drop" is not packet loss.
by pe1chl
Thu May 04, 2023 1:56 pm
Forum: General
Topic: hap lite, not enough disk space.
Replies: 64
Views: 56618

Re: hap lite, not enough disk space.

All settings are saved in a database on disk. When the disk is full, that cannot happen anymore.
Basically you need to make sure the disk never is full. For a hEX S this should be no problem unless you put user files on the flash. Don't! Use a USB stick.
by pe1chl
Wed May 03, 2023 7:50 pm
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55128

Re: v7.9 [stable] is released!

Being a person that uses the webfig much more than winbox, this change: . *) webfig - added inline comments; . is plain terrible. I'd love being able to at least choose the old behavior and having the comments on a different line instead of inline. Please consider having this as an option and not f...
by pe1chl
Wed May 03, 2023 6:28 pm
Forum: Beginner Basics
Topic: Local DNS not working on RB5009
Replies: 8
Views: 1684

Re: Local DNS not working on RB5009

And make sure it does not use 192.168.132.1 as the external resolver...
by pe1chl
Wed May 03, 2023 6:24 pm
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55128

Re: v7.9 [stable] is released!

Packet loss is 0% on my RB4011. You will need to provide more details.
by pe1chl
Wed May 03, 2023 12:24 pm
Forum: Announcements
Topic: WinBox v3.38 released!
Replies: 50
Views: 47551

Re: WinBox v3.38 released!

Of course there are reasons why one cannot upgrate to v7, but I can't imagine that this particular issue would get any priority. It looks like the sequence is always the same and may be the sequence these address lists were added during configuration. It is a matter of "getting used to". Y...
by pe1chl
Wed May 03, 2023 11:44 am
Forum: Announcements
Topic: WinBox v3.38 released!
Replies: 50
Views: 47551

Re: WinBox v3.38 released!

You are right, I tested it only with v7 but now that I look on a v6.49 router indeed it is not sorted. Apparently the sorting is done by the router, not winbox.
by pe1chl
Wed May 03, 2023 11:27 am
Forum: General
Topic: Upgrade RouterOS with additionalpackages
Replies: 3
Views: 357

Re: Upgrade RouterOS with additionalpackages

Yes, either you use "check for updates" and let the router download the packages, or when that isn't possible (e.g. because the router has no internet connectivity) you check which packages you have and upload the same new version of everything (routeros-xxx and otherpackage-xxx) to the ro...
by pe1chl
Wed May 03, 2023 11:24 am
Forum: Scripting
Topic: SNR and CCQ in WiFiWave2
Replies: 5
Views: 2080

Re: SNR and CCQ in WiFiWave2

wifiwave2 is an implementation of drivers from the manufacturer of the chipset, rather than an in-house written driver (which wireless is). So there are many small details that are missing or incomplete... this is only one of them. We can only hope that over time, some things are coming back. But li...
by pe1chl
Wed May 03, 2023 11:15 am
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55128

Re: v7.9 [stable] is released!

When looking at the "/ip dns cache" it appears that in the Name column, every instance of .com is replaced with .cOm
This is not happening in the Data column (e.g. for a CNAME to a .com domain)
Why is that?

Edit: nevermind, apparently Cloudflare DNS is doing that...
by pe1chl
Tue May 02, 2023 8:04 pm
Forum: Announcements
Topic: WinBox v3.38 released!
Replies: 50
Views: 47551

Re: WinBox v3.38 released!

Any chance to fix this viewtopic.php?p=938420#p938367 simple issue of not sorted Address List in DHCP static lease drop down option? Reported already many times with each new release :-(, How much time takes this fix...on or two minutes? It works OK here. Did you try to reproduce it without your se...
by pe1chl
Tue May 02, 2023 3:38 pm
Forum: Announcements
Topic: WinBox v3.38 released!
Replies: 50
Views: 47551

Re: WinBox v3.38 released!

This means that if I use winbox 3.37 and earlier, with bad skins from 7.8 onwards (barring future bugfixes), I can have full access , instead using 3.38 the menus are hidden correctly, giving false security , but just use 3.37 and you still have full access ?.... I think skins are not really about ...
by pe1chl
Tue May 02, 2023 12:37 pm
Forum: Announcements
Topic: WinBox v3.38 released!
Replies: 50
Views: 47551

Re: WinBox v3.38 released!

Firewall rules lists are still 'cut in the middle' when first displayed. As soon as you move to another tab and go back to the previous one, the list is complete. My experience is that: - "filter" list is cut at line 96 - "nat" at line 46 - "mangle" at line 73 Works OK...
by pe1chl
Tue May 02, 2023 12:01 pm
Forum: Wireless Networking
Topic: Problem with dynamic VLAN
Replies: 12
Views: 2770

Problem with dynamic VLAN

From help.mikrotik.com: Access List Sub-menu: /interface wireless access-list Access list is used by access point to restrict allowed connections from other devices, and to control connection parameters. Access list rules are processed one by one until matching rule is found. Then the action in the ...
by pe1chl
Mon May 01, 2023 4:50 pm
Forum: Scripting
Topic: FastTrack-Friendly QoS Script
Replies: 61
Views: 39279

Re: FastTrack-Friendly QoS Script

How exactly does the dscp tagging know to fall into precidence 1-8? No mark is obvious. But like the netflix rule you did, there is no packet mark to put into the queue for it to recognize. I'm guessing dscp and the priority for ip precedence 1-8 is linked. How exactly does that work? Priority 1 is...
by pe1chl
Mon May 01, 2023 4:17 pm
Forum: RouterOS beta
Topic: 7.8beta2 adds new package ROSE-storage
Replies: 67
Views: 27374

Re: 7.8beta2 adds new package ROSE-storage

Try with NFS v3, that works for me...
by pe1chl
Mon May 01, 2023 3:33 pm
Forum: Announcements
Topic: v7.9rc is released!
Replies: 253
Views: 76461

Re: v7.9rc is released!

When VLAN of a wireless interface (old style) is dynamically assigned (via access list or user-manager RADIUS attributes) the affected client gets only broadcast and directed traffic, not multicast traffic. Don't know when this problem was introduced exactly. I think it worked in v6. I recently merg...
by pe1chl
Fri Apr 21, 2023 5:12 pm
Forum: RouterOS beta
Topic: v7 and BFD, any ETA?
Replies: 149
Views: 27915

Re: v7 and BFD, any ETA?

You are joining mrz in the "stupid remark" contest?
by pe1chl
Fri Apr 21, 2023 4:31 pm
Forum: RouterOS beta
Topic: v7 and BFD, any ETA?
Replies: 149
Views: 27915

Re: v7 and BFD, any ETA?

We expect MikroTIk to have a checklist of all items in v7 that have no feature parity relative to v6, and work on that with highest priority. Only after those items have all been implemented or documented as "will not come back" (e.g. /ip/accounting), we expect major "new features&quo...
by pe1chl
Fri Apr 21, 2023 2:01 pm
Forum: RouterOS beta
Topic: v7 and BFD, any ETA?
Replies: 149
Views: 27915

Re: v7 and BFD, any ETA?

You don't understand how stupid that remark is, don't you?
It has been "a work in progress" for well over 1.5 years...
At some point in time people can no longer wait for your pathetically slow progress...
by pe1chl
Fri Apr 21, 2023 11:08 am
Forum: General
Topic: Unstable IPSEC connection between MikroTiks and Forcepoint NGFW [SOLVED]
Replies: 9
Views: 1733

Re: Unstable IPSEC connection between MikroTiks and Forcepoint NGFW [SOLVED]

I have been using IPsec on e.g. Cisco routers for more than 20 years, and I can assure you it was just as bad on Cisco back then. It is just a flaw in the protocol, for which each manufacturer invents workarounds. And even admins do. (like setting up regular pings and recovery action scripts, that i...
by pe1chl
Fri Apr 21, 2023 10:47 am
Forum: General
Topic: Unstable IPSEC connection between MikroTiks and Forcepoint NGFW [SOLVED]
Replies: 9
Views: 1733

Re: Unstable IPSEC connection between MikroTiks and Forcepoint NGFW [SOLVED]

Ipsec is notorious for these problems, and some manufacturers have worked around them better than others. Usually when you have "DPD" (Dead Peer Detection) active it will be more stable, but some manufacturers get it goofed up even with that. E.g. we have an IPsec tunnel with Microsoft Azu...
by pe1chl
Thu Apr 20, 2023 12:53 pm
Forum: General
Topic: "Routing Table" Parameter for IPv6 Routes Not in Effect (v7.5) [SOLVED]
Replies: 17
Views: 4398

Re: "Routing Table" Parameter for IPv6 Routes Not in Effect (v7.5) [SOLVED]

It would be better when this was the same in IPv4 as it is now in IPv6. You can then put the rule at a desired place in a list of rules, so you can define the priority of routing marks.
by pe1chl
Wed Apr 19, 2023 7:46 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 425
Views: 140295

Re: v7.8 [stable] is released!

The route caching from 6 is gone in 7, so any traffic that would benefit from that (speed tests) will suffer as a result.
Yes, it is more interesting to see the CPU load figures under typical load than the "speed test maximum speed"...
by pe1chl
Wed Apr 19, 2023 12:26 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 425
Views: 140295

Re: v7.8 [stable] is released!

Probably you have a typo that we cannot see because you removed your address...
by pe1chl
Wed Apr 19, 2023 12:22 pm
Forum: RouterOS beta
Topic: New User Manager in RouterOS v7
Replies: 211
Views: 81346

Re: New User Manager in RouterOS v7

In theory it is possible with 1 SSID and running 2 authentication algorithms on that SSID, in practice it does not work because there are far too many clients that do not understand that.
by pe1chl
Tue Apr 18, 2023 12:39 pm
Forum: Wireless Networking
Topic: 802.11r for hAP ac2?
Replies: 75
Views: 14211

Re: 802.11r for hAP ac2?

Yeah, but that is probably not going to happen... The situation is that early on, MikroTik (like some similar companies) did a lot of in-house work to make better drivers for WiFi than the chip manufacturers provided as reference code. They added extra features, even including completely reworked ch...
by pe1chl
Tue Apr 18, 2023 11:45 am
Forum: Forwarding Protocols
Topic: IRR Filtering on eBGP Sessions
Replies: 11
Views: 3140

Re: IRR Filtering on eBGP Sessions

IRR filtering and RPKI are not the same thing. They are related, yes.
by pe1chl
Mon Apr 17, 2023 8:32 pm
Forum: General
Topic: Lots of unsuccessful DHCP offers and probably loop warnings
Replies: 3
Views: 290

Re: Lots of unsuccessful DHCP offers and probably loop warnings

When using Unifi, make sure you have the management network (untagged on the APs) separate from your user networks (VLAN tagged).
Don't allow users on the management network. I know it is the default to have that.
by pe1chl
Sun Apr 16, 2023 8:26 pm
Forum: General
Topic: DHCP static and dynamic, two pools (hAP ax3) [SOLVED]
Replies: 3
Views: 617

Re: DHCP static and dynamic, two pools (hAP ax3) [SOLVED]

What you need to do is: have a DHCP server, two DHCP networks, and one pool.
by pe1chl
Sat Apr 15, 2023 10:21 pm
Forum: RouterBOARD hardware
Topic: Fan installation in RB1100AHx4
Replies: 13
Views: 4848

Re: Fan installation in RB1100AHx4

when you have it open anyway, make a hi-res photo of that area of the board and put it here...
by pe1chl
Sat Apr 15, 2023 9:41 pm
Forum: RouterBOARD hardware
Topic: Fan installation in RB1100AHx4
Replies: 13
Views: 4848

Re: Fan installation in RB1100AHx4

Probably the situation is that "there is no FAN controller" means "it is foreseen on the PCB but not populated for this model to save some cost". Of course you can get voltage for the fan but you need to look for the PCB position where the FAN controller could be, and bridge some...
by pe1chl
Sat Apr 15, 2023 9:38 pm
Forum: General
Topic: Random ips created with conflict.
Replies: 1
Views: 318

Re: Random ips created with conflict.

After a client has requested a new IP, the DHCP server can perform a "conflict check" (to find if other devices use this IP). Maybe you have some tricky network setup or device that is detected by that check. You can turn off Conflict Detection in the DHCP server config and see what happens.
by pe1chl
Sat Apr 15, 2023 11:17 am
Forum: RouterOS beta
Topic: Static DNS FWD entries using DoH not working [SOLVED]
Replies: 18
Views: 9858

Re: Static DNS FWD entries using DoH not working [SOLVED]

I fully agree that DoH should have been implemented as "just another external resolver" that you can combine with normal resolvers, static records, FWD etc. The RouterOS DNS resolver would get the query, and first look it up in local cache, local records, forward when indicated, and only w...
by pe1chl
Sat Apr 15, 2023 10:09 am
Forum: General
Topic: PVID Uses [SOLVED]
Replies: 23
Views: 1911

Re: PVID Uses [SOLVED]

In fact, long ago I made a support call to 3com (that was a manufacturer of switches at the time) about an issue with their "port mirror" function. I had noticed that when using that function to monitor traffic, it would incorrectly output a VLAN tag in some circumstances. I think that it ...
by pe1chl
Fri Apr 14, 2023 6:18 pm
Forum: General
Topic: A very simple redirect (to an http page) after join WiFi
Replies: 38
Views: 6451

Re: A very simple redirect (to an http page) after join WiFi

I'm waiting if somebody knows a simple way to activate it, just with the purpose to redirect. Don't assume that every crazy idea you think of is always possible to implement, either with unlimited resources or within the limits of RouterOS! In fact, the kind of thing you are trying to do here (pres...
by pe1chl
Fri Apr 14, 2023 6:13 pm
Forum: General
Topic: A very simple redirect (to an http page) after join WiFi
Replies: 38
Views: 6451

Re: A very simple redirect (to an http page) after join WiFi

I think the URL needs in option 114 needs to respond with a MIME type of application/captive+json with some JSON Bummer... why do they make those things so complicated? I had not studied it in detail and assumed that the URL in the DHCP option would simply point to the portal page. And in fact ther...
by pe1chl
Fri Apr 14, 2023 6:04 pm
Forum: Wireless Networking
Topic: 802.11r for hAP ac2?
Replies: 75
Views: 14211

Re: 802.11r for hAP ac2?

I don't think that would be unsolvable. In the past we also had times when a "new" wireless driver was available as an optional package, and you could install it in addition to a full install. Ok, that has sometimes caused headaches when in a new RouterOS version that "new" drive...
by pe1chl
Fri Apr 14, 2023 1:33 pm
Forum: Wireless Networking
Topic: 802.11r for hAP ac2?
Replies: 75
Views: 14211

Re: 802.11r for hAP ac2?

Probably it works better when you are a distributor and call them saying "hey we have sold 50000 of those cAP ac and now this customer wants to order 50000 more cAP ax but only when you make the old units operate to the same standards and management" :-)
by pe1chl
Fri Apr 14, 2023 1:30 pm
Forum: General
Topic: A very simple redirect (to an http page) after join WiFi
Replies: 38
Views: 6451

Re: A very simple redirect (to an http page) after join WiFi

That is a nice one! Now, we have to find which devices actually use that :-) (I mean the special URI) I see that a Samsung phone with Android 11 actually does ask for option 114, but when I set it to some valid URL it does not show that page in Chrome by default. Probably when using that config it s...
by pe1chl
Fri Apr 14, 2023 1:16 pm
Forum: General
Topic: PVID Uses [SOLVED]
Replies: 23
Views: 1911

Re: PVID Uses [SOLVED]

aaa.. ok. i have forgotten about that voip thing. 😂 are you using soft phone so you needed that vlan enable card? In a way, yes. As I wrote, it is for the attendant stations. Most users have a phone with 2 ethernet ports, one to the switch and the other to the PC, and the phone itself (helped by th...
by pe1chl
Fri Apr 14, 2023 1:12 pm
Forum: Wireless Networking
Topic: 802.11r for hAP ac2?
Replies: 75
Views: 14211

Re: 802.11r for hAP ac2?

In some other thread Normis explicitly mentioned wireless is NEEDED as base for wifiwave2. Ok, maybe there are some "invisible" parts that are required. But in general the wifiwave2 package replaces commands (others go away) and apparently also disables drivers from wireless. I would love...
by pe1chl
Fri Apr 14, 2023 12:56 pm
Forum: Wireless Networking
Topic: 802.11r for hAP ac2?
Replies: 75
Views: 14211

Re: 802.11r for hAP ac2?

I still think conceptually it should be possible to run wifiwave2 on AC2, cAP AC, cAP XL AC, wAP AC, ... but then the wifiwave2 package needs to be stripped from all excess fat for it to fit. And then there is still the question if it will run properly on those devices. I guess it would only be pos...
by pe1chl
Fri Apr 14, 2023 12:51 pm
Forum: Wireless Networking
Topic: 802.11r for hAP ac2?
Replies: 75
Views: 14211

Re: 802.11r for hAP ac2?

Those are still based on ARCH, not CHIP. Container package is present in all ZIP files, arm arm64 and x86. There is no hAP ac3 version of container. It is all the same in all arm routers. What you are asking is one package for hAP ac3 and another package for hAP ac3 I presume you mean to mention tw...
by pe1chl
Fri Apr 14, 2023 11:50 am
Forum: Wireless Networking
Topic: 802.11r for hAP ac2?
Replies: 75
Views: 14211

Re: 802.11r for hAP ac2?

We can't have PER-CHIPSET packages, since NAND/RAM is different per model, not per chipset But you CAN have all kinds of other optional packages, like container, rose-storage, user-manager etc, that are voluntarily added and are nicely updated when the router is updated. So I don't understand why y...
by pe1chl
Fri Apr 14, 2023 11:43 am
Forum: General
Topic: PVID Uses [SOLVED]
Replies: 23
Views: 1911

Re: PVID Uses [SOLVED]

but.. all in all, i pretty much don't see any significant benefits for end devices ie. servers and desktop to have vlan implanted in their card. since server farm usually uses any other method for out of band management. The reason I found this stupid problem is that in our company the VoIP traffic...
by pe1chl
Fri Apr 14, 2023 11:34 am
Forum: General
Topic: PVID Uses [SOLVED]
Replies: 23
Views: 1911

Re: PVID Uses [SOLVED]

If I plug into eth1 with pvid 107, I get an address from switch0.107's dhcp server, if I plug into eth2 with pvid 101, I get an ip address from switch0.101's dhcp server. Same as if I use a raspberry pi. Or using an old Dell Optiplex 380 with Broadcom built in Gb ethernet adapter With DHCP there is...
by pe1chl
Thu Apr 13, 2023 10:12 pm
Forum: Beginner Basics
Topic: Unable to update Router OS
Replies: 10
Views: 695

Re: Unable to update Router OS

When there is a server 10.0.0.1 that does DNS but not for the internet, the above setup will fail.
There is no "when server 1 says NO let's ask server 2" function in DNS.
by pe1chl
Thu Apr 13, 2023 10:10 pm
Forum: General
Topic: A very simple redirect (to an http page) after join WiFi
Replies: 38
Views: 6451

Re: A very simple redirect (to an http page) after join WiFi

This is not for wpad.dat!
And the option number is 114 not 144.
The only useful thing in that post is that it shows the single quotes that I already mentioned but that Giovanni had omitted.
by pe1chl
Thu Apr 13, 2023 10:07 pm
Forum: General
Topic: PVID Uses [SOLVED]
Replies: 23
Views: 1911

Re: PVID Uses [SOLVED]

While I have seen this (Windows strips vlan tags) stated multiple times, I have never seen the behavior myself. It must be specific to some "smart" adapter/driver combination, or perhaps some non-default setting in windows. In Windows, the handling of VLAN tags is done in each manufacture...
by pe1chl
Thu Apr 13, 2023 8:51 pm
Forum: General
Topic: A very simple redirect (to an http page) after join WiFi
Replies: 38
Views: 6451

Re: A very simple redirect (to an http page) after join WiFi

You can add an option in DHCP server: number 114 with string value of your URL (single quotes). Then put that in an option set, and attach that option set to your DHCP server. That would work according to RFC 8910, but in practice it will not work because nobody ever requests that option. But it wou...
by pe1chl
Thu Apr 13, 2023 7:33 pm
Forum: General
Topic: A very simple redirect (to an http page) after join WiFi
Replies: 38
Views: 6451

Re: A very simply redirect (to an http page) after join WiFi

Yes, that should work. But it is important to know: it only works when the client device does that "captive portal detection" and you can catch and redirect it. There are "standards" like sending a URL via DHCP for the login page (which you could set to the wanted dashboard) but ...
by pe1chl
Thu Apr 13, 2023 7:12 pm
Forum: Beginner Basics
Topic: Unable to update Router OS
Replies: 10
Views: 695

Re: Unable to update Router OS

You have this:

/ip dns
set allow-remote-requests=yes servers=8.8.8.8,10.0.0.1

Is that 10.0.0.1 a valid DNS resolver that can lookup internet DNS names? If not, remove it. Make it 1.0.0.1 or 1.1.1.1 or 9.9.9.9 or whatever.
by pe1chl
Thu Apr 13, 2023 7:11 pm
Forum: General
Topic: A very simple redirect (to an http page) after join WiFi
Replies: 38
Views: 6451

Re: A very simply redirect (to an http page) after join WiFi

It is something the connecting device needs to do. Often modern devices can do that, as a workaround for WiFi networks that require acceptance of ToS etc.
Search for "captive portal" and "captive portal detection" etc.
by pe1chl
Thu Apr 13, 2023 2:45 pm
Forum: General
Topic: PVID Uses [SOLVED]
Replies: 23
Views: 1911

Re: PVID Uses [SOLVED]

I think in general it is inconvenient that in VLAN configuration (e.g. in VLAN filtered bridge) there are TWO places to configure untagged ports. In my opinion it is most convenient when under VLAN configuration, for each VLAN it is defined on which ports that VLAN is to be present, either untagged ...
by pe1chl
Thu Apr 13, 2023 10:38 am
Forum: Wireless Networking
Topic: 802.11r for hAP ac2?
Replies: 75
Views: 14211

Re: 802.11r for hAP ac2?

And also no new drivers for old units. So no wifiwave2 for hAP ac2 and no usable wifiwave2 for RB4011 (because 2GHz does not work). Essentially there is a cut in the MikroTik product line. Before that point you can have features like 4-address mode (transparent bridge) and modes optimized for Pt(m)P...
by pe1chl
Thu Apr 13, 2023 10:27 am
Forum: Wireless Networking
Topic: 802.11r for hAP ac2?
Replies: 75
Views: 14211

Re: 802.11r for hAP ac2?

But not on hAP ac2, cAP ac, wAP ac 1. gen as the previous poster writes!
You have announced yourself that MikroTik will abandon development for such units and will only go forward with wifiwave2.
by pe1chl
Wed Apr 12, 2023 5:37 pm
Forum: Beginner Basics
Topic: max-MTU Question [SOLVED]
Replies: 113
Views: 11353

Re: max-MTU Question [SOLVED]

so long story short - don't fuck with larger MTU sizes within a network that at some point might access the internet. Something like a network between |Server| and |Shared Storage/MAS|, could easily have jumbo frames on, providing |Server| and |Shared Storage| use separate dedicated NICS with MTU15...
by pe1chl
Wed Apr 12, 2023 3:03 pm
Forum: Beginner Basics
Topic: max-MTU Question [SOLVED]
Replies: 113
Views: 11353

Re: max-MTU Question [SOLVED]

Ok, the initial SYN packet for sure will have "new" state, but I'm not so sure that the ACK SYN has that as well, it could be "established" state already (which formally begins only after another outgoing ACK). But as mentioned, I never bother with "fasttrack" because I...
by pe1chl
Wed Apr 12, 2023 2:36 pm
Forum: Beginner Basics
Topic: connection between two ipsec tunels
Replies: 6
Views: 371

Re: connection between two ipsec tunels

The crucial difference between a "plain IPsec tunnel" as you have now, and a GRE or IPIP tunnel with IPsec transport, is that the plain IPsec tunnel at all systems needs to know all other IP subnets. A GRE or IPIP tunnel can just route any traffic, also traffic from A that you send to B bu...
by pe1chl
Wed Apr 12, 2023 2:30 pm
Forum: General
Topic: Bridgeable single DHCP
Replies: 3
Views: 296

Re: Bridgeable single DHCP

That is what I said, I think that is impossible to do except when you buy another router (can be cheap model like hEX) and put that only on the single port that you want this extremely unusual config for. (although I remember that exactly the same question was posted before on the forum so maybe you...
by pe1chl
Wed Apr 12, 2023 11:55 am
Forum: Beginner Basics
Topic: connection between two ipsec tunels
Replies: 6
Views: 371

Re: connection between two ipsec tunels

... and then he'll need to add a peer D :-)
slowly this will become an intangible mess.
also, it assumes all traffic from A to C has to pass via B. maybe it is possible to make a direct tunnel from A to C?
by pe1chl
Wed Apr 12, 2023 11:49 am
Forum: General
Topic: Bridgeable single DHCP
Replies: 3
Views: 296

Re: Bridgeable single DHCP

There is nothing you can do w.r.t. routing or NAT for the DHCP service, it operates at a lower level much like ARP. It does not respect firewall rules. You may be able to accomplish something with a bridge filter, but it will be very expensive (CPU-wise). Maybe you can use a second router, connect i...
  • 1
  • 3
  • 4
  • 5
  • 6
  • 7
  • 40