Community discussions

MikroTik App

Search found 11929 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 40
by pe1chl
Wed Nov 01, 2023 10:02 pm
Forum: Wireless Networking
Topic: hap ax3/ax2 with jumbo frames
Replies: 6
Views: 1453

Re: hap ax3/ax2 with jumbo frames

Indeed. So when you want WiFi to work and also jumbo frames on ethernet you will have to set it up so the WiFi is not part of (the same) bridge. That will add an extra routing hop for your WiFi and the MTU can be different.
by pe1chl
Wed Nov 01, 2023 8:33 pm
Forum: Wireless Networking
Topic: hap ax3/ax2 with jumbo frames
Replies: 6
Views: 1453

Re: hap ax3/ax2 with jumbo frames

The wifiwave2 driver does not support MTU over 1500 bytes, that is why it keeps dropping back.
With only ethernet it would probably work fine.
(WiFi does not support jumbo frames)
by pe1chl
Wed Nov 01, 2023 6:39 pm
Forum: The Dude
Topic: Is too much to ask for Dude x64 windows client?
Replies: 33
Views: 8100

Re: Is too much to ask for Dude x64 windows client?

On Linux, you can install the i386 libs and 32-bit wine. Now...for Intel-based Mac, wine wouldn't work with 32-bit Dude. Must be CrossOver wine, it can run 32bit applications with emulation on 64bit CrossOver wine No idea, when installing wine64 on Debian Linux (64-bit) and using it to run winbox64...
by pe1chl
Wed Nov 01, 2023 6:24 pm
Forum: General
Topic: Manual DNS bypasses the Pihole - force redirect to pihole
Replies: 10
Views: 1831

Re: Manual DNS bypasses the Pihole - force redirect to pihole

except: if some client set the DNS server manually it bypass the pihole Once you have fixed that, some client will not use the DNS protocol on TCP/UDP port 53, but instead will use DoH or DoT. Or when you have a client that does not like your limitations, they will just setup a VPN and send everyth...
by pe1chl
Wed Nov 01, 2023 6:01 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93730

Re: v7.12rc is released!

Hold on, you're right, it is just webfig traffic. I thought it was total traffic, which be okay. But not sure what webfig traffic usage shows... It shows how much traffic it takes to display and update the page you are viewing in webfig. For some pages that is almost zero, because they are just sta...
by pe1chl
Wed Nov 01, 2023 2:06 pm
Forum: Beginner Basics
Topic: port forwarding not working on RB3011
Replies: 8
Views: 1826

Re: port forwarding not working on RB3011

The default firewall already blocks everything from WAN except port forwarded traffic . He chose to modify that, and now he has trouble. Lesson: when you do not understand how it works, and you modify it, it may break. This is the rule as it is by default: /ip firewall filter add chain=forward actio...
by pe1chl
Wed Nov 01, 2023 1:40 pm
Forum: General
Topic: Issue with ARP in a bridge
Replies: 4
Views: 2043

Re: Issue with ARP in a bridge

I recommend you to use netinstall to install the current version of RouterOS (6.49.10 when you want to remain on v6 or otherwise 7.11.2) and then reconfigure your router by pasting the export into a command prompt section by section. Or even better by manually configuring again what you really need ...
by pe1chl
Wed Nov 01, 2023 1:37 pm
Forum: General
Topic: IPsec IKEv2 and multiple traffic selectors per SA
Replies: 4
Views: 2429

Re: IPsec IKEv2 and multiple traffic selectors per SA

I used a similar scheme with multiple prefixes in the traffic selector quite widely. But, of course, StrongSwan acted as both server and client. (Linux servers). And there were no problems with this. More precisely, in IKEv2 mode Mikrotik only accepts the first prefix in the traffic selector. But i...
by pe1chl
Wed Nov 01, 2023 1:30 pm
Forum: Beginner Basics
Topic: port forwarding not working on RB3011
Replies: 8
Views: 1826

Re: port forwarding not working on RB3011

Study the packet flow to understand that. Or do not add rules to the default firewall before you understand what they do.

https://help.mikrotik.com/docs/display/ ... n+RouterOS
by pe1chl
Wed Nov 01, 2023 11:49 am
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93730

Re: v7.12rc is released!

These values are there for a purpose. Is there a problem with them? I presume these figures are the TX/RX rate of the connection with webfig. People probably assume these are the global TX/RX rate of the router (same as was on the LCD back in the old days)? Anyway, how important is that "purpo...
by pe1chl
Wed Nov 01, 2023 11:41 am
Forum: Forwarding Protocols
Topic: Multiple Peer sessions on the same IP address problem [SOLVED]
Replies: 10
Views: 5734

Re: Multiple Peer sessions on the same IP address problem [SOLVED]

You are replying to a very old topic, and things have changed a lot since then.
I would not know if that still works.
by pe1chl
Wed Nov 01, 2023 11:35 am
Forum: General
Topic: How to limit number of connection per local/public ip?
Replies: 4
Views: 1214

Re: How to limit number of connection per local/public ip?

You say you control 200 proxies.
Configure IN THOSE PROXIES what the maximum number of connections is.
by pe1chl
Wed Nov 01, 2023 11:33 am
Forum: Beginner Basics
Topic: ROS Documentation
Replies: 6
Views: 1477

Re: ROS Documentation

In case it was not clear yet: the bridge is not between internet and your local network. It is between the ports that you assign to your local network, usually all ports you do not use for internet or other purposes, and the WiFi interfaces (if any). In the current version of RouterOS it is like the...
by pe1chl
Tue Oct 31, 2023 4:34 pm
Forum: Beginner Basics
Topic: ROS Documentation
Replies: 6
Views: 1477

Re: Literally the first sentence in ROS Documentation

I am now setting up a new Mikrotik router and it is telling me to set up a bridge first thing, this just makes absolutely no sense to me as I thought the point of a bridge was to link different networking equipment together? Not just to create a dhcp network, the documentation doesn't say why it wa...
by pe1chl
Mon Oct 30, 2023 7:03 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93730

Re: v7.12rc is released!

Noted after installation (do no know how long it exists as I just changed IPv6 settings) that when you have IPv6 enabled but IPv6 routing disabled, the IPv6 forward chain gets hit with multicast packets from the local network, as if it wants to forward them. I've put that drop rule with log into 7....
by pe1chl
Mon Oct 30, 2023 1:58 pm
Forum: Forwarding Protocols
Topic: BGP: Whats the difference between these two commands?
Replies: 8
Views: 1845

Re: BGP: Whats the difference between these two commands?

I think it v6 it worked both ways which is of course a bit silly... "in" suggests that the network on the left is smaller (or same size) than the network on the right.
by pe1chl
Mon Oct 30, 2023 11:52 am
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93730

Re: v7.12rc is released!

Noted after installation (do no know how long it exists as I just changed IPv6 settings) that when you have IPv6 enabled but IPv6 routing disabled, the IPv6 forward chain gets hit with multicast packets from the local network, as if it wants to forward them. /ipv6 settings set forward=no /ipv6 firew...
by pe1chl
Mon Oct 30, 2023 11:48 am
Forum: Forwarding Protocols
Topic: BGP: Whats the difference between these two commands?
Replies: 8
Views: 1845

Re: BGP: Whats the difference between these two commands?

No.
The first one is "is the room in you" and the second one is "are you in the room".
by pe1chl
Mon Oct 30, 2023 11:29 am
Forum: General
Topic: How to limit number of connection per local/public ip?
Replies: 4
Views: 1214

Re: How to limit number of connection per local/public ip?

Why don't you solve the problem where it occurs: in the proxies ?
by pe1chl
Mon Oct 30, 2023 11:28 am
Forum: Forwarding Protocols
Topic: BGP: Whats the difference between these two commands?
Replies: 8
Views: 1845

Re: BGP: Whats the difference between these two commands?

The second version is the correct one. The first one does not make sense.
by pe1chl
Sun Oct 29, 2023 12:42 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93730

Re: v7.12rc is released!

However, different wireless drivers do interact with passing frames beyond basic MAC addressing and some drivers might burp on frames they don't recognize. I think the problem is that the drivers have to do some kind of workaround to replace ARP. The WiFi has the same MAC for all clients, but they ...
by pe1chl
Sun Oct 29, 2023 12:34 pm
Forum: General
Topic: ROUTEROS 7 BGP network announcement issue
Replies: 22
Views: 6272

Re: ROUTEROS 7 BGP network announcement issue

When my routing table is empty, the default route is announced immediately, which means that my configuration is good (maybe not optimal, but it works). When my routing table is full, I run into problems. I've been so irritated by the situation that I've made all the combinations you mentioned befo...
by pe1chl
Sat Oct 28, 2023 4:38 pm
Forum: RouterBOARD hardware
Topic: hAPax2 RAM size 1GB or 128MB ?
Replies: 18
Views: 3797

Re: hAPax2 RAM size 1GB or 128MB ?

It doesn't really matter. To continue to work in the wifiwave2 era, the hAP ac2 would need to have more flash as well.
by pe1chl
Sat Oct 28, 2023 12:33 pm
Forum: General
Topic: ROUTEROS 7 BGP network announcement issue
Replies: 22
Views: 6272

Re: ROUTEROS 7 BGP network announcement issue

When you want to keep your routing table fully populated from uplinks but want to send only default route to clients, it is probably best to run different instances (templates) for them.
by pe1chl
Sat Oct 28, 2023 11:35 am
Forum: Beginner Basics
Topic: DNS Server
Replies: 3
Views: 1291

Re: DNS Server

It thurns out that mikrotik doesnt like one word domains as static. # NAME REGEXP TYPE ADDRESS TTL 0 X ;;; defconf router.lan 192.168.1.1 1d 1 mobilesvr 192.168.1.150 1w3d 2 mobilesvr.lan 192.168.1.150 1w3d dig 'mobilesvr.lan' returns 192.168.1.150 dig 'mobilesvr' returns SERVFAIL I cannot confirm ...
by pe1chl
Sat Oct 28, 2023 11:02 am
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93730

Re: v7.12rc is released!

I don't really get all this tagged/untagged discussion. The 802.11 frame header has no place for a VLAN ID, so, technically, wifi interfaces are never tagged. Well 802.11 standard frame has no space for a VLAN tag, and only has space for 3 MAC addresses. But MT with WLAN driver "AP bridge"...
by pe1chl
Sat Oct 28, 2023 10:53 am
Forum: General
Topic: LHG 5 ac
Replies: 6
Views: 1484

Re: LHG 5 ac

Those are garbage, don't buy them!
No, I think we will see an AX model in the (near?) future...
by pe1chl
Fri Oct 27, 2023 3:16 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93730

Re: v7.12rc is released!

When you need fixes you can just as well install an RC version. At some point in time the version will change to 7.12 and it is still the same software.
by pe1chl
Fri Oct 27, 2023 10:59 am
Forum: General
Topic: Seamless Wi-Fi Roaming with Mikrotik Hotspot
Replies: 6
Views: 956

Re: Seamless Wi-Fi Roaming with Mikrotik Hotspot

The method you have will work, but you need to increase the "maximum number of connections" ("shared users") to something higher than 1. Even when you do not want that.
by pe1chl
Fri Oct 27, 2023 10:56 am
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11.2 [stable] is released!

Likely you can still view the routing table in the Snmp tab, if that is an option.
Except when you have multiple routing tables, then SNMP retrieval of routes will fail in v7.
by pe1chl
Thu Oct 26, 2023 10:33 pm
Forum: General
Topic: VPN get disconnected when LTE interface is UP
Replies: 4
Views: 780

Re: VPN get disconnected when LTE interface is UP

Well of course in the typical setup where the normal WAN and the LTE both get their IP and default gateway using some dynamic mechanism (like PPPoE or DHCP) it can easily happen that adding another uplink kills the first one. You need to configure the routing in such a way that the different "d...
by pe1chl
Thu Oct 26, 2023 10:24 pm
Forum: General
Topic: port forwarding specific domain / hostname
Replies: 5
Views: 863

Re: port forwarding specific domain / hostname

... so you want to explain the visitors of https://test456.com/ "no, you must not enter that, you must enter https://test456.com:4443/ ??? And when they forget the :4443 then they get "warning! invalid certficate! someone may be eavesdropping on you!!" ?? Good luck with that. No, it i...
by pe1chl
Thu Oct 26, 2023 10:20 pm
Forum: General
Topic: External FTP server download error
Replies: 5
Views: 828

Re: External FTP server download error

Isn't it time by now (2023) that you abandon the use of FTP?
by pe1chl
Thu Oct 26, 2023 10:19 pm
Forum: General
Topic: Seamless Wi-Fi Roaming with Mikrotik Hotspot
Replies: 6
Views: 956

Re: Seamless Wi-Fi Roaming with Mikrotik Hotspot

You will need newer equipment for that. The new devices that support 802.11k/r/v can do roaming without re-authenticating, but the older devices cannot and it will not be added. However, even with this roaming you still can run into the situation where a user re-authenticates because their device be...
by pe1chl
Thu Oct 26, 2023 6:43 pm
Forum: General
Topic: l2tp tunnel that was working suddenly stops
Replies: 2
Views: 707

Re: l2tp tunnel that was working suddenly stops

Are these to another MikroTik router that you manage, or to some outside VPN service?
by pe1chl
Thu Oct 26, 2023 5:02 pm
Forum: General
Topic: How to upgrade to 2.5GbE + RB4011iGS+RM suitable?
Replies: 2
Views: 780

Re: How to upgrade to 2.5GbE + RB4011iGS+RM suitable?

In such cases it depends on what you actually expect. When a single client has to be able to setup a single connection and it has to be 2.5 Gbps the options are far more limited than when you expect 1 Gbps to each client but several clients together can add up to 2.5 Gbps. Also, you will almost alwa...
by pe1chl
Thu Oct 26, 2023 4:56 pm
Forum: General
Topic: Second gateway for specific computer
Replies: 2
Views: 624

Re: Second gateway for specific computer

Hi there, On a MikroTik CCR1016-12S-11S+ which runs RouterOS 7.6 I need to configure a second gateway only for a specific computer from my network. Currently I have tried several things I read in the Forums, but none of them worked. I tried Mangle prerouting as well, but without luck. Other posts w...
by pe1chl
Thu Oct 26, 2023 1:54 pm
Forum: RouterBOARD hardware
Topic: 4011
Replies: 2
Views: 2188

Re: 4011

It is not that clear cut. When you have a card from another manufacturer with a chipset that is also used in other MikroTik devices, it can just work.
In fact I have suggested that this may be a solution to have both 2 GHz and 5 GHz WiFi with wifiwave2 on the 4011.
by pe1chl
Thu Oct 26, 2023 11:21 am
Forum: General
Topic: Locked out of CCR1009-7G-1C-PC router, possibly hacked
Replies: 4
Views: 1029

Re: Locked out of CCR1009-7G-1C-PC router, possibly hacked

It is really very common that when first using netinstall (or when using it while in distress) one simply cannot get it to work. Besides the mistake that you made in this case, it generally is a picky program that will fail on many system configurations. It is always advisable to do a rehearsal of a...
by pe1chl
Thu Oct 26, 2023 11:18 am
Forum: Beginner Basics
Topic: Question about temperature, 62 C 0 63 C
Replies: 12
Views: 3509

Re: Question about temperature, 62 C 0 63 C

The "cpu temperature" is a temperature measured on the CPU chip itself, and it is always quite a lot higher than any temperature you would measure with a sensor on the board or on the outside of the package. 62c is not unreasonably high. That being said, it never hurts to have some additio...
by pe1chl
Thu Oct 26, 2023 11:13 am
Forum: General
Topic: Safe to Remove Antennas?
Replies: 3
Views: 1041

Re: Safe to Remove Antennas?

50 ohm terminators with the appropriate connector type should do the job.
Real ones are expensive, but suitable ones for this purpose can be obtained for cheap on Aliexpress.
by pe1chl
Thu Oct 26, 2023 11:11 am
Forum: General
Topic: 5009reboot fails
Replies: 4
Views: 918

Re: 5009reboot fails

What is the config on that router? I am observing the same thing on my RB4011, but by now I have found what causes it: I have added the package rose-storage and I have added a "disk" that is a mount of an external fileserver. This makes reboot getting stuck. So when you do something simila...
by pe1chl
Wed Oct 25, 2023 9:13 pm
Forum: General
Topic: Static route not showing in export
Replies: 9
Views: 1238

Re: Static route not showing in export

In my router running v7.12rc it certainly is present in the export. And it was before as well.
by pe1chl
Wed Oct 25, 2023 6:21 pm
Forum: General
Topic: Simple Web Server to Host Simple Files [SOLVED]
Replies: 15
Views: 4704

Re: Simple Web Server to Host Simple Files [SOLVED]

You can also add a simple web server on a computer (your preferred flavor of OS), or even a RaspBerry Pi on the LAN and port forward via NAT so it can be reached from the Internet. The question started with: I have an VPS that has MikroTik CHR installed on it. So to do it that way he would have to ...
by pe1chl
Wed Oct 25, 2023 5:45 pm
Forum: RouterBOARD hardware
Topic: hAPax2 RAM size 1GB or 128MB ?
Replies: 18
Views: 3797

Re: hAPax2 RAM size 1GB or 128MB ?

The rackmounted versions had the displays on the front. Sure, when you bought an RB2011 for desktop use it had the display on the top and that was inconvenient when you wanted to put it on a shelf in a rack, but the rackmounted RB2011 had no such issue. Same for the CCR devices from that time. Of co...
by pe1chl
Wed Oct 25, 2023 1:28 pm
Forum: General
Topic: Forum moderation volunteers
Replies: 238
Views: 37566

Re: Forum moderation volunteers

Read also the title: "My Youtube Video player has blocked"

There is no trace of anything related to MikroTik.
Ok exercise for you: see this recent new posting: viewtopic.php?t=200911
There is no trace of anything related to MikroTik.
Should it be deleted?
by pe1chl
Wed Oct 25, 2023 12:58 pm
Forum: General
Topic: Forum moderation volunteers
Replies: 238
Views: 37566

Re: Forum moderation volunteers

Is it so difficult to read, even for a moderator?? I am talking about the initial question. It does not mention an Adblocker. How is the first question inappropriate for this forum, as rextended wrote: "For me the mistake is not immediately deleting the post, instead of replying." I don't ...
by pe1chl
Wed Oct 25, 2023 12:39 pm
Forum: General
Topic: Forum moderation volunteers
Replies: 238
Views: 37566

Re: Forum moderation volunteers

Question and the first answer had no connection to Mikrotik even beeing asked for more details. I don't agree with that!! The first question was clearly from a person with limited knowledge of English, and was about a problem that could be related to his router. Maybe he (or the admin of the router...
by pe1chl
Wed Oct 25, 2023 12:34 pm
Forum: General
Topic: Static route not showing in export
Replies: 9
Views: 1238

Re: Static route not showing in export

Aha I see. In v6 it was S in cli as well, and in v7 it is s in cli but S in winbox.
Stupid, I would say...

Again, what RouterOS version do you have?
by pe1chl
Wed Oct 25, 2023 12:31 pm
Forum: Beginner Basics
Topic: bridge port received packet with own address - probably loop [SOLVED]
Replies: 7
Views: 2392

Re: bridge port received packet with own address - probably loop [SOLVED]

That will likely solve it, as long as you do not paste that export back again. Alternatively you can try changing (or just removing) the MAC address settings seen in the config. That will make them fall back to defaults which are the device-unique MAC addresses assigned during manufacturing. Then yo...
by pe1chl
Wed Oct 25, 2023 12:28 pm
Forum: General
Topic: Firewall kicked me out after 30mins - no clue why
Replies: 8
Views: 1101

Re: Firewall kicked me out after 30mins - no clue why

Hmm and what rule would you add for that?
I am legit curious, I'd like to understand where I went wrong and how I could fix it.
Thank you.
You have not shown us your full firewall configuration yet, so how should we know???
Show the result of a /ip firewall export
by pe1chl
Wed Oct 25, 2023 12:26 pm
Forum: General
Topic: Forum moderation volunteers
Replies: 238
Views: 37566

Re: Forum moderation volunteers

In these cases that is difficult to infer from the first question. Almost all questions on this forum initially are vague, do not include any context, and require additional posts to get that info. At that time it may become obvious that the question is not related to any MikroTik software or hardwa...
by pe1chl
Wed Oct 25, 2023 12:23 pm
Forum: General
Topic: Ipsec tunnel with only one public ip - it is possible?
Replies: 5
Views: 1109

Re: Ipsec tunnel with only one public ip - it is possible?

Thanks, sounds very promising .... is there any guide or manual how to achieve that ?
https://help.mikrotik.com/docs/display/ROS/L2TP
by pe1chl
Wed Oct 25, 2023 12:21 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93730

Re: v7.12rc is released!

So what seems to be the problem in ROS is that on shutdown/reboot sequence, NFS server doesn't get stopped. Hence exported disk partition still shows usage and unmounting it hangs. Yes, that is what I wrote is my guess as well. In this case it seems the NFS client won't stop because it gets no repl...
by pe1chl
Wed Oct 25, 2023 12:16 pm
Forum: RouterBOARD hardware
Topic: hAPax2 RAM size 1GB or 128MB ?
Replies: 18
Views: 3797

Re: hAPax2 RAM size 1GB or 128MB ?

I think the availability of interfaces on the different MikroTik models mainly depends on the chips they use in them. For each new model a chip (SoC) is selected and it offers some different types of interfaces. Adding a new interface type that is not directly supported by the SoC would mean extra s...
by pe1chl
Tue Oct 24, 2023 8:11 pm
Forum: General
Topic: Mikrotik Car Charger
Replies: 4
Views: 893

Re: Mikrotik Car Charger

Well, you are asking for a charger and "we" are not aware of any MikroTik product that has a rechargable battery.
So it is a bit unclear what you want to charge.
by pe1chl
Tue Oct 24, 2023 8:10 pm
Forum: General
Topic: Firewall kicked me out after 30mins - no clue why
Replies: 8
Views: 1101

Re: Firewall kicked me out after 30mins - no clue why

The reason that it breaks is that the rules you made do not accept input that is a reply to outgoing connects, like the update of DDNS.
But also other things would go wrong, like query of DNS or download of upgrades.
by pe1chl
Tue Oct 24, 2023 8:07 pm
Forum: Beginner Basics
Topic: bridge port received packet with own address - probably loop [SOLVED]
Replies: 7
Views: 2392

Re: bridge port received packet with own address - probably loop [SOLVED]

Looking at the MAC addresses, you probably restored a backup from another device?
by pe1chl
Tue Oct 24, 2023 8:06 pm
Forum: General
Topic: Static route not showing in export
Replies: 9
Views: 1238

Re: Static route not showing in export

Static routes have "AS" flag. I don't know what the s flag is for.
What RouterOS version do you have?
by pe1chl
Tue Oct 24, 2023 8:03 pm
Forum: Beginner Basics
Topic: Connected device uptime question.
Replies: 3
Views: 1130

Re: Connected device uptime question.

Of course it depends on what the connected device is. When it is a MikroTik device you can also see the uptime in IP->Neighbors.
And it depends on your requirements. When you want to know if it had recently connected you can use the "Last Seen" field in the leases.
by pe1chl
Tue Oct 24, 2023 8:01 pm
Forum: General
Topic: Ipsec tunnel with only one public ip - it is possible?
Replies: 5
Views: 1109

Re: Ipsec tunnel with only one public ip - it is possible?

At least when using L2TP/IPsec you do not need any special tricks.
Put the L2TP server on the site with the public IP and connect it from the other site. That one can even have a dynamic IP.
by pe1chl
Tue Oct 24, 2023 4:57 pm
Forum: General
Topic: LHG 5 ac
Replies: 6
Views: 1484

Re: LHG 5 ac

Maybe they have a warehouse full of old LHG 5 and no more LHG 5 ac in stock, then they would have to produce it again? The architecture of the LHG 5 ac is similar to the hAP ac2 and its limited 16 MB flash is becoming a problem with RouterOS v7. So maybe at some time we will see a LHG 5 ax to replac...
by pe1chl
Tue Oct 24, 2023 4:52 pm
Forum: General
Topic: RB 2011 100% CPU Usage
Replies: 4
Views: 1499

Re: RB 2011 100% CPU Usage

Also first check that when the load is 100% there is not a lot of wireguard traffic.
by pe1chl
Tue Oct 24, 2023 4:50 pm
Forum: RouterBOARD hardware
Topic: hAPax2 RAM size 1GB or 128MB ?
Replies: 18
Views: 3797

Re: hAPax2 RAM size 1GB or 128MB ?

If I recall, AC2 or cap AC had such an occurrence (128 vs 256 Mb RAM), no ? Yes, I think this really happened :-( My ac2 has only 128 MB RAM. I think in that case the website always said 128 MB RAM but some users found that they bought a device that in reality had 256 MB RAM, then they bought more ...
by pe1chl
Tue Oct 24, 2023 4:45 pm
Forum: Beginner Basics
Topic: My Youtube Video player has blocked
Replies: 6
Views: 1890

Re: My Youtube Video player has blocked

When I use Adblocker my YouTube video player has stopped.
You got the wrong forum. It is a forum about MikroTik routers. You should write to forum about your Adblocker software.
Or Youtube. Youtube has started banning users that use an Adblocker.
by pe1chl
Tue Oct 24, 2023 1:51 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93730

Re: v7.12rc is released!

This time I manually rebooted the router before trying to install the update, and the reboot was hanging. Just like the update is hanging when I try it after some uptime. Could it be caused by rose-storage? I have an NFS mount (the router mounts a share from an NFS server). I could imagine that thi...
by pe1chl
Tue Oct 24, 2023 12:13 pm
Forum: General
Topic: DHCP alert - valid server required if DHCP server on same device?
Replies: 3
Views: 1170

Re: DHCP alert - valid server required if DHCP server on same device?

Hello, does the DHCP server of RouterOS on the same device have to be specified as a valid server for the DHCP alert (/ip dhcp-server alert valid-server=), or is it automatically treated as a "valid server"? No, it is not required. Just enabling that function will find other DHCP servers ...
by pe1chl
Tue Oct 24, 2023 12:12 pm
Forum: General
Topic: LHG 5 ac
Replies: 6
Views: 1484

Re: LHG 5 ac

Maybe most buyers preferred the extra link margin for AC use that an XL provides... I do have an LHG 5 ac but it sits unused in storage because I did not notice that it does not support 10 MHz bandwidth, which we use. So now I use a LHG XL HP5 instead (of course on normal power). When you want bette...
by pe1chl
Tue Oct 24, 2023 11:47 am
Forum: Beginner Basics
Topic: Mikrotik AWS to Mikrotik Home Tunnel bad performance
Replies: 13
Views: 2179

Re: Mikrotik AWS to Mikrotik Home Tunnel bad performance

Buy a new router. E.g. an RB5009.
by pe1chl
Mon Oct 23, 2023 3:49 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93730

Re: v7.12rc is released!

Well, in general I agree with that, but not in the case of netinstall. That is just a badly designed/implemented program.
by pe1chl
Mon Oct 23, 2023 2:23 pm
Forum: Beginner Basics
Topic: Mikrotik AWS to Mikrotik Home Tunnel bad performance
Replies: 13
Views: 2179

Re: Mikrotik AWS to Mikrotik Home Tunnel bad performance

But the 20Mb for SSTP over 1G uplink does seem like it's MTU related
Actually 20Mb is about the upper bound for all encrypting tunnels on the 2011. Only plain tunnels (GRE, IPIP) without encryption exceed that.
by pe1chl
Sun Oct 22, 2023 12:10 pm
Forum: General
Topic: Detect internet stopped working
Replies: 31
Views: 2896

Re: Detect internet stopped working

Yes, best solution every time is to disable "detect internet", it provides no useful function. It is easy enough to maintain the WAN and LAN interface lists manually. Yeah, I am only using it because for some reason I can't make the router use a route with a distance higher than the main ...
by pe1chl
Sun Oct 22, 2023 12:07 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11.2 [stable] is released!

Hi,
one of my CRS328-24P-4S+ don't know about PoE on interfaces 9-24, however PoE on theese ports still works...

Same model, with same RoS version, but different device this problem haven't.
Did you restore a "backup" file from another device on that one?
by pe1chl
Sun Oct 22, 2023 12:04 pm
Forum: General
Topic: Default drop rule
Replies: 5
Views: 1328

Re: Default drop rule

Cofiguration is relatively complex to post and contains too many private details to remove... talking about ~150 rules or so. Allow-all is great as soho firewall default, but generally shouldn't be a croproate practice... Of course. I do not like the default config either, although it is already mu...
by pe1chl
Sat Oct 21, 2023 11:21 am
Forum: Beginner Basics
Topic: Mikrotik AWS to Mikrotik Home Tunnel bad performance
Replies: 13
Views: 2179

Re: Mikrotik AWS to Mikrotik Home Tunnel bad performance

SSTP client on my home Mikrotik router
What is the model of your home MikroTik router?
Did you disable "fasttrack"?
by pe1chl
Sat Oct 21, 2023 11:18 am
Forum: General
Topic: Default drop rule
Replies: 5
Views: 1328

Re: Default drop rule

You need to understand that the default firewall installed by RouterOS (on models that have a default configuration) operates on the principle that undesired traffic is blocked and at the end of the list there is an implicit "default accept". The structure of the rules is dependent on that...
by pe1chl
Sat Oct 21, 2023 11:15 am
Forum: General
Topic: Detect internet stopped working
Replies: 31
Views: 2896

Re: Detect internet stopped working

Yes, best solution every time is to disable "detect internet", it provides no useful function.
It is easy enough to maintain the WAN and LAN interface lists manually.
by pe1chl
Sat Oct 21, 2023 11:12 am
Forum: Beginner Basics
Topic: Seperate lan subnets
Replies: 10
Views: 1890

Re: Seperate lan subnets

Forward chain From subnet or interface To subnet or interface Action drop Repeat for all combinations. That is actually a bad solution. It does not scale, when you have 5 interfaces there are already 20 combinations. Better: add each interface to an interface list. There already exists the interfac...
by pe1chl
Fri Oct 20, 2023 7:09 pm
Forum: Beginner Basics
Topic: Debug Basics
Replies: 12
Views: 1873

Re: Debug Basics

I explained what is available in RouterOS. What he knows from other platforms is not available. No need to discuss that any further. I should say once you understand the packet flow (at least in general) in RouterOS it is not required to trace the entire flow, you immediately know which rules the pa...
by pe1chl
Fri Oct 20, 2023 6:41 pm
Forum: Beginner Basics
Topic: Debug Basics
Replies: 12
Views: 1873

Re: Debug Basics

The packet flow can be found here: https://wiki.mikrotik.com/wiki/Manual:Packet_Flow
At any point in the flow where there is a [| |] box you can insert a log rule.
by pe1chl
Fri Oct 20, 2023 5:00 pm
Forum: Beginner Basics
Topic: Debug Basics
Replies: 12
Views: 1873

Re: Debug Basics

You can add a log option to a rule in the firewall to log when it matches, or you can add an extra "log" rule with the appropriate matching criteria (in this case an address, but it can be anything) and when it matches it will log the appropriate message. The default logging configuration ...
by pe1chl
Fri Oct 20, 2023 10:46 am
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93730

Re: v7.12rc is released!

Upgrading from v6.9x to 7.12rc2 all bgp, mpls, ospf settimg all missing. Thx What did you expect...just upgrade and continue? You just moved to a new major version! Well, in normal situations it would convert them during the upgrade. If that happened and if it works correctly depends on details of ...
by pe1chl
Thu Oct 19, 2023 11:25 pm
Forum: Beginner Basics
Topic: RTP Counter In Queue Trees
Replies: 7
Views: 1455

Re: RTP Counter In Queue Trees

Why waste time on protocol recognition when you can just use the DSCP values that any reasonable SIP application already sets?
by pe1chl
Thu Oct 19, 2023 3:49 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93730

Re: v7.12rc is released!

Yes, that is a common issue with IPsec. People configure "more secure" IPsec settings (PFS, 256 bits, DH with long keys) and then it only works between routers but not with commonly used client devices... Worst is that it requires ongoing research to know what settings are supported in eac...
by pe1chl
Thu Oct 19, 2023 3:47 pm
Forum: General
Topic: DNSSEC
Replies: 43
Views: 23692

Re: DNSSEC

When going to the trouble of setting up a container with a good DNS resolver, I would not rely on the behavior of the existing DNS resolver in RouterOS. Let the container make its own queries and if necessary use RouterOS only to NAT them to the outside world, not to resolve them. You can then confi...
by pe1chl
Wed Oct 18, 2023 2:46 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93730

Re: v7.12rc is released!

I confirm that (on 7.12rc1) the Bridge VLAN "Current tagged" column incorrectly lists the wlan interfaces. I have added them both to Tagged for several VLANs, but wlan2 does not appear correctly in "Current tagged" even when a client is connected that uses the VLAN (RADIUS assign...
by pe1chl
Tue Oct 17, 2023 11:51 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93730

Re: v7.12rc is released!

Is the router ever going to do downloads (for upgrade) over IPv6?? The download server has an IPv6 record but RouterOS does not request it...
by pe1chl
Tue Oct 17, 2023 12:22 pm
Forum: General
Topic: open port vs forward port
Replies: 3
Views: 1035

Re: open port vs forward port

Yes, many devices list "open port requirements" for access they want TO the internet. But in most default configurations of routers with connection-tracking firewall (like MikroTik), ALL ports are already open outbound. So there is nothing you need to change on the router. It is unfortunat...
by pe1chl
Tue Oct 17, 2023 12:19 pm
Forum: General
Topic: IP and IK rating
Replies: 2
Views: 661

Re: IP and IK rating

You need to ask such questions to sales or on the support site, not here on the community forum.
by pe1chl
Tue Oct 17, 2023 12:17 pm
Forum: General
Topic: Is this an attack?
Replies: 5
Views: 962

Re: Is this an attack?

Make the firewall setup so that everything that is not required is blocked.
In fact that is what the default firewall setup does.
No need to add such rules for specific ports, only add rules for things you want open.
by pe1chl
Mon Oct 16, 2023 9:26 pm
Forum: General
Topic: MikroTik RouterOS and CDP support
Replies: 5
Views: 1152

Re: MikroTik RouterOS and CDP support

Did you already check if RouterOS performs the functions you need?
by pe1chl
Mon Oct 16, 2023 3:44 pm
Forum: Forwarding Protocols
Topic: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow
Replies: 16
Views: 3132

Re: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow

I don't think you can/should do RPKI validation on a single-peer endpoint. Leave that to your upstream ISP. They can do all the route selection for you and send you only a default route.
by pe1chl
Mon Oct 16, 2023 11:06 am
Forum: RouterBOARD hardware
Topic: Search for new mikrotik router
Replies: 11
Views: 3319

Re: Search for new mikrotik router

It depends on the internal structure of your small home. I have a similar small appartment but straight through the middle there is a concrete wall (part of the structure of the building), while all other walls are plasterboard. I do require two WiFi devices for reasonable coverage. Otherwise the si...
by pe1chl
Sat Oct 14, 2023 10:31 pm
Forum: General
Topic: DHCP Client lease expired
Replies: 7
Views: 1170

Re: DHCP Client lease expired

When you have more than one DHCP client of course you should set the default route distance differently in each of them, and probably setup two route tables and a script to insert a default route in the second table, and routing rules or mangling. I would not think it would cause the issue that you ...
by pe1chl
Sat Oct 14, 2023 10:27 pm
Forum: Forwarding Protocols
Topic: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow
Replies: 16
Views: 3132

Re: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow

I don't see how any of that would be an advantage when having only one peer.
by pe1chl
Sat Oct 14, 2023 3:31 pm
Forum: Forwarding Protocols
Topic: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow
Replies: 16
Views: 3132

Re: ROS 7.11.2 CHR BGP not Multithreaded and V. Slow

BGP can run multithreaded (see posting above), but when you have only 1 peer there is nothing to gain that way.
Is this only a test? Or else, why would you run full-table BGP with only 1 peer?
Ask the ISP to send you only a default route...
by pe1chl
Sat Oct 14, 2023 3:23 pm
Forum: General
Topic: Invalid value in Connection Bytes in webfig
Replies: 3
Views: 642

Re: Invalid value in Connection Bytes in webfig

I don't think that will be fixed... v6 is no longer maintained except for security issues, and this seems to be a niche problem.
by pe1chl
Sat Oct 14, 2023 3:22 pm
Forum: General
Topic: DHCP Client lease expired
Replies: 7
Views: 1170

Re: DHCP Client lease expired

Maybe you have put those ports in a bridge? make sure each of them is not member of any bridge.
by pe1chl
Fri Oct 13, 2023 10:25 pm
Forum: General
Topic: RouterOS 6.49.1 vs 7.11.2 IPSEC NAT problem
Replies: 5
Views: 967

Re: RouterOS 6.49.1 vs 7.11.2 IPSEC NAT problem

Forgot to mention it was a binary backup, not an exported config
You copied a binary backup to another router? that cannot be done. It is accepted, but it causes weird issues.
by pe1chl
Fri Oct 13, 2023 10:23 pm
Forum: General
Topic: RB 2011 100% CPU Usage
Replies: 4
Views: 1499

Re: RB 2011 100% CPU Usage

20 Mbit/s is enough to fully load a 2011 when it has to encrypt/decrypt the traffic.
Unless you show the config export, nobody can help you with a solution.
by pe1chl
Fri Oct 13, 2023 10:20 pm
Forum: General
Topic: L2 vs L3
Replies: 4
Views: 1115

Re: L2 vs L3

As mkx indicates, the difference comes when routing, which is why MikroTik can justify the moniker "Cloud Router Switch." Yes, it's a router, and it's a switch. This line of products are better at switching than routing, but the fact that your CRS series switch can also route packets betw...
by pe1chl
Fri Oct 13, 2023 7:47 pm
Forum: RouterBOARD hardware
Topic: Search for new mikrotik router
Replies: 11
Views: 3319

Re: Search for new mikrotik router

RB4011 series - amazingly powerful routers
The 4011 is a bit of a dead end. Cannot support BOTH 2.4/5 GHz WiFi AND new WiFi driver. Not recommended for new purchase.
by pe1chl
Fri Oct 13, 2023 5:20 pm
Forum: Scripting
Topic: Remove disk from /files
Replies: 10
Views: 2065

Re: Remove disk from /files

Fine!
by pe1chl
Fri Oct 13, 2023 12:05 pm
Forum: Beginner Basics
Topic: Problem Upgrading from 6.49 lt to 7.11
Replies: 3
Views: 1596

Re: Problem Upgrading from 6.49 lt to 7.11

He is already on upgrade channel (see the question) so that is not it. I think a more likely reason for it failing is that the flash is probably almost full. The hAP ac2 has a chronic lack of space. I have one running 7.12rc1 and it has only 1000kB free out of the total 16M (16000kB). It may be bett...
by pe1chl
Fri Oct 13, 2023 11:01 am
Forum: Scripting
Topic: Remove disk from /files
Replies: 10
Views: 2065

Re: Remove disk from /files

To have it solved you will first have to reproduce it on v7, as v6 is no longer maintained except for security issues.
I think it has been improved in v7. You can now assign a name to a disk yourself and it will stick to that disk.
by pe1chl
Thu Oct 12, 2023 9:23 pm
Forum: General
Topic: Command to save config on the terminal
Replies: 2
Views: 1923

Re: Command to save config on the terminal

Everything you configure in the terminal is immediately saved.
It is not like in some other routers that you configure things only in memory and then have to "write" that to flash.
by pe1chl
Thu Oct 12, 2023 9:21 pm
Forum: Scripting
Topic: Remove disk from /files
Replies: 10
Views: 2065

Re: Remove disk from /files

One would expect, just like in Linux, to have a checkmark to select automatic mounting on boot yes/no.
Other than that, I don't see an issue. Maybe you can schedule a job at boot to eject the disk when you do not want it to be mounted by default.
by pe1chl
Thu Oct 12, 2023 11:04 am
Forum: General
Topic: MikroTik RouterOS and CDP support
Replies: 5
Views: 1152

Re: MikroTik RouterOS and CDP support

You need to find that out yourself, because I do not know what "full CDP support" means.
by pe1chl
Wed Oct 11, 2023 6:17 pm
Forum: Forwarding Protocols
Topic: BGP prepend filters - Can I prepend input with own AS?
Replies: 6
Views: 2813

Re: BGP prepend filters - Can I prepend input with own AS?

Because BGP adds its own ASN only when sending routes to remote peers (so prepending own as is possible only in output). By adding local as in input you are deliberately "saying" that those routes are looped, you might as well just reject the routes. No, the purpose of prepending own AS o...
by pe1chl
Wed Oct 11, 2023 12:31 pm
Forum: General
Topic: MikroTik RouterOS and CDP support
Replies: 5
Views: 1152

Re: MikroTik RouterOS and CDP support

Look in "/ip neighbor" and its settings, there is some rudimentary support there.
by pe1chl
Wed Oct 11, 2023 11:12 am
Forum: RouterOS beta
Topic: BGP - Prefix Count
Replies: 9
Views: 3489

Re: BGP - Prefix Count

Maybe you can use this script to show you prefix counts on commandline: /system script add comment="print BGP prefix count" dont-require-permissions=no name=\ bgp-prefixes owner=admin policy=read source="/routing/bgp/session {\r\ \n :global prefixes ({});\r\ \n :global active ({});\r\...
by pe1chl
Tue Oct 10, 2023 2:17 pm
Forum: RouterOS beta
Topic: BGP - Prefix Count
Replies: 9
Views: 3489

Re: BGP - Prefix Count

Hello Mat I have exactly the same problem with version 7.11.2 I'm a bit disappointed that Mikrotik hasn't replied to you since June 2023, It's inconceivable to me... Well, this forum is mainly for inter-user communication. When you want a reply from support and/or some chance your topic gets put on...
by pe1chl
Tue Oct 10, 2023 2:14 pm
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM: Which port is sfp-sfpplus2?
Replies: 2
Views: 2071

Re: CRS328-24P-4S+RM: Which port is sfp-sfpplus2?

I would think the bottom is 1 and the top is 2.
That is also the way our new CCR2004 is numbered (I did not expect it because for other manufacturers the top is the lower numbered port)
by pe1chl
Sun Oct 08, 2023 11:51 am
Forum: Wireless Networking
Topic: "lost connection, no beacons received"
Replies: 53
Views: 7033

Re: "lost connection, no beacons received"

Please don't pollute the topic with unrelated things!
by pe1chl
Sat Oct 07, 2023 3:44 pm
Forum: Beginner Basics
Topic: Configure VLAN access to specific devices [SOLVED]
Replies: 6
Views: 3350

Re: Configure VLAN access to specific devices [SOLVED]

Yes. But only in the old WiFi drivers and not in the new wifiwave2. So let's first check which one you use.
Edit: seems to be possible now as well, but I do not know how as I do not use that myself.
by pe1chl
Sat Oct 07, 2023 11:06 am
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93730

Re: v7.12rc is released!

And can you assign the VLAN to each client separately using RADIUS (via user-manager)? That was possible in the old WiFi.
by pe1chl
Sat Oct 07, 2023 11:01 am
Forum: General
Topic: Tool to migrate/convert *.cfg.rsc between different devices
Replies: 10
Views: 1753

Re: Tool to migrate/convert *.cfg.rsc between different devices

Hint: use the "/export show-sensitive terse" command (especially the "terse" parameter) when you want easier handling in a text editor or script. I don't use it because my Perl script first performs the equivalent action on "non-terse" exports, but it can save some work...
by pe1chl
Fri Oct 06, 2023 4:52 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93730

Re: v7.12rc is released!

This time I manually rebooted the router before trying to install the update, and the reboot was hanging. Just like the update is hanging when I try it after some uptime. Could it be caused by rose-storage? I have an NFS mount (the router mounts a share from an NFS server). I could imagine that this...
by pe1chl
Fri Oct 06, 2023 4:46 pm
Forum: General
Topic: Tool to migrate/convert *.cfg.rsc between different devices
Replies: 10
Views: 1753

Re: Tool to migrate/convert *.cfg.rsc between different devices

Except that it isn't true... the features of routers differ, and adaptations are required in the export file to be able to import it on another one.
by pe1chl
Fri Oct 06, 2023 11:55 am
Forum: General
Topic: Tool to migrate/convert *.cfg.rsc between different devices
Replies: 10
Views: 1753

Re: Tool to migrate/convert *.cfg.rsc between different devices

I have never seen it... You are right, migration of config in MikroTik routers is a bit of a problem. It is not possible to do it using .backup files, but the backup restore procedure does not check that and happily messes up the device. And the load of .rsc files also is problematic. The import com...
by pe1chl
Thu Oct 05, 2023 4:42 pm
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

For example: Cloudflare tunnel cannot be started because the returned (argotunnel.com) domain record does not contain an SOA record. Interesting that you found an actual problem resulting from that behavior. But did you really confirm it to be the reason? As you mentioned I encountered a problem wi...
by pe1chl
Thu Oct 05, 2023 3:13 pm
Forum: General
Topic: The predicted demise of "tls-host=" firewall filters is near!
Replies: 21
Views: 2467

Re: The predicted demise of "tls-host=" firewall filters is near!

Sorry, why should it? The purpose of the use-application-dns.net domain was to tell Firefox in a network that the network admin does not want the users to use DoH. The domain is registered on internet and one is supposed to override that in a local static entry with an NXDOMAIN response. I even ask...
by pe1chl
Thu Oct 05, 2023 11:14 am
Forum: General
Topic: The predicted demise of "tls-host=" firewall filters is near!
Replies: 21
Views: 2467

Re: The predicted demise of "tls-host=" firewall filters is near!

Or just block based on IP or IP address ranges. Just like always because for years we knew this was coming. The problem is that you cannot block services that run on large CDN or other server farms like Google's in that way. When you even can find all addresses used by Youtube, you may find that th...
by pe1chl
Thu Oct 05, 2023 11:12 am
Forum: General
Topic: The predicted demise of "tls-host=" firewall filters is near!
Replies: 21
Views: 2467

Re: The predicted demise of "tls-host=" firewall filters is near!

Funny topic. You guys want firefox to be more secure and less secure at the same time :) Well, the issue is that "secure" can have different definitions depending on the viewpoint. The people at Firefox (and some vocal organizations) consider it "secure" when only the end-user c...
by pe1chl
Wed Oct 04, 2023 12:45 pm
Forum: General
Topic: The predicted demise of "tls-host=" firewall filters is near!
Replies: 21
Views: 2467

The predicted demise of "tls-host=" firewall filters is near!

Firefox has now started rolling out the implementation of Encrypted Client Hello (ECH) to their users: https://blog.mozilla.org/en/products/firefox/encrypted-hello/ This will mean that using firewall filters that use tls-host= (or L7 filters that try to do the same thing) to "block certain webs...
by pe1chl
Wed Oct 04, 2023 11:19 am
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

Frankly I would prefer when features like SMB or PROXY were just removed from RouterOS... get a NAS!
by pe1chl
Mon Oct 02, 2023 2:34 pm
Forum: General
Topic: Can't access Bitbucket.org through Mikrotik
Replies: 1
Views: 550

Re: Can't access Bitbucket.org through Mikrotik

Such problems are normally a combination of MTU issues and badly configured firewall (not necessarily your firewall, can just as well be at bitbucket.org).
by pe1chl
Sun Oct 01, 2023 11:31 pm
Forum: Beginner Basics
Topic: Cannot connect to the internet with PPOE with vlan
Replies: 3
Views: 763

Re: Cannot connect to the internet with PPOE with vlan

/interface vlan
add interface=ether1 mtu=1492 name=EboxVlan vlan-id=40
That is wrong. mtu should not be set to 1492 there. Remove that.
by pe1chl
Sun Oct 01, 2023 10:01 pm
Forum: Forwarding Protocols
Topic: GRE over IPsec
Replies: 13
Views: 3338

Re: GRE over IPsec

I don't understand you either. Maybe you are difficult to understand.
by pe1chl
Sun Oct 01, 2023 2:37 pm
Forum: Forwarding Protocols
Topic: GRE over IPsec
Replies: 13
Views: 3338

Re: GRE over IPsec

What protocols best fit to securely connect same networks over public network?
GRE/IPsec is a good choice. That is completely unrelated to your first question.
by pe1chl
Sun Oct 01, 2023 2:37 pm
Forum: Forwarding Protocols
Topic: GRE over IPsec
Replies: 13
Views: 3338

Re: GRE over IPsec

Transport Mode
It will be transport mode when both endpoints directly have a public IP address.
When there is NAT in front of the MikroTik router at one end, it will be tunnel mode (because IPsec transport mode does not support NAT).
by pe1chl
Sun Oct 01, 2023 2:18 pm
Forum: General
Topic: Recomandation router with good wifi
Replies: 16
Views: 2021

Re: Recomandation router with good wifi

A friend asked for a recommendation, he is interested only in wifi strength and quality, so the number of ports is not important, but to recommend something similar is an overkill. Of course you also need to consider if you want to recommend MikroTik to your friend, or if that is just overkill. Whe...
by pe1chl
Sat Sep 30, 2023 4:02 pm
Forum: General
Topic: Feature requests
Replies: 1744
Views: 640139

Re: Feature requests

Make a ticket on the customer support portal at https://help.mikrotik.com/servicedesk
by pe1chl
Fri Sep 29, 2023 7:44 pm
Forum: Scripting
Topic: Frustrated trying to create a script
Replies: 14
Views: 2384

Re: Frustrated trying to create a script

Also, I would warn against trying to do too much in a single expression. At some point it just won't work and there are no ways to debug it. It is safest to move some calculated value into a variable first before using it inside another expression, and also best to use the . string concat operator i...
by pe1chl
Fri Sep 29, 2023 12:03 pm
Forum: RouterOS beta
Topic: BGP Filter bgp-as-path reject
Replies: 7
Views: 4845

Re: BGP Filter bgp-as-path reject

As I wrote above (at a time when all of this simply did not work due to bugs, that have been fixed now) there is a "bgp-input-remote-as" you can use for that.
by pe1chl
Thu Sep 28, 2023 7:52 pm
Forum: General
Topic: Export, Print, Get...everything?
Replies: 9
Views: 1146

Re: Export, Print, Get...everything?

When you want to generate a mail with the data YOU find interesting, you can do it.
But probably your requirements are quite unique, so it would not be reasonable to have a standard facility for that.
Print what you want and mail it.
by pe1chl
Wed Sep 27, 2023 11:04 am
Forum: SwOS
Topic: SwOS Lite v2.17 packet loss issue
Replies: 15
Views: 3751

Re: SwOS Lite v2.17 packet loss issue

What happened with fixed speed and duplex?
by pe1chl
Tue Sep 26, 2023 11:39 pm
Forum: The User Manager
Topic: Radius - Unknown User (dhcp)
Replies: 5
Views: 4668

Re: Radius - Unknown User (dhcp)

I don't think it can be solved with scripting. What we need is a default user entry (that matches any username that is not explicitly in the table). Or even better: the possibility to specify username as a regexp, so you can add entries that match e.g MAC addresses with some OUI or (with some effort...
by pe1chl
Tue Sep 26, 2023 8:47 pm
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

"/log [/user/get XXX password]"
For how many years now has this not been working? It was years before the end of v6 that passwords were no longer retrievable (only stored encrypted)...
by pe1chl
Tue Sep 26, 2023 8:31 pm
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

@MT: please check all of YOUR SFP(+) models on compatibility with a new ROS version! It seems that SFP support is the "rocket science" of today. Unlike in their early days, rockets today often work on the first try and failures are quite rare. SFP changes usually fail every time (somethin...
by pe1chl
Tue Sep 26, 2023 8:29 pm
Forum: The User Manager
Topic: First time configuring User manager
Replies: 22
Views: 4847

Re: First time configuring User manager

The firewall rule needs an extra parameter in-interface-list=LAN or in-interface-list=!WAN or similar, so that it won't accept RADIUS traffic from internet. As I mentioned before, it is extremely sad that there is no possibility in user-manager to have a "default user" that determines what...
by pe1chl
Tue Sep 26, 2023 5:10 pm
Forum: The User Manager
Topic: First time configuring User manager
Replies: 22
Views: 4847

Re: First time configuring User manager

Yes, you get the VLAN you assign to the user as a tagged VLAN on the bridge, so when you want to do anything with it you need to create a VLAN subinterface on the bridge and configure DHCP on it. And firewall rules. As I mentioned, I use it with a PSK on the wireless. The only reason I use the user-...
by pe1chl
Mon Sep 25, 2023 8:12 pm
Forum: SwOS
Topic: SwOS Lite v2.17 packet loss issue
Replies: 15
Views: 3751

Re: SwOS Lite v2.17 packet loss issue

Check if the trunk is configured for autonegotiation and if so, try to set fixed speed and Full Duplex at each end.
by pe1chl
Mon Sep 25, 2023 7:37 pm
Forum: The User Manager
Topic: First time configuring User manager
Replies: 22
Views: 4847

Re: First time configuring User manager

Of course you need to configure it so that the VLANs actually work. I did not check that in the config, but you would need a DHCP server on each VLAN etc. I still do have a (common) WPA2-PSK password on the SSID, that makes it "secure". Without password it will indicate insecure. And of co...
by pe1chl
Mon Sep 25, 2023 4:22 pm
Forum: Beginner Basics
Topic: IPv6 routing basics
Replies: 10
Views: 1217

Re: IPv6 routing basics

For such a config, router A must have static routes for the subnets connected to router B, or autorouting must be setup to distribute these.
by pe1chl
Mon Sep 25, 2023 4:01 pm
Forum: Beginner Basics
Topic: IPv6 routing basics
Replies: 10
Views: 1217

Re: IPv6 routing basics

Yes, of course. Unless you use multiple routing tables.
by pe1chl
Mon Sep 25, 2023 3:18 pm
Forum: General
Topic: discover mac address
Replies: 1
Views: 536

Re: discover mac address

It depends. When that device somehow tries to obtain info via the network, e.g. DHCP client, IP Cloud client using default route, etc it may be possible to find it by doing packet trace on the port on mikrotik1 where mikrotik2 is connected.
by pe1chl
Mon Sep 25, 2023 3:14 pm
Forum: General
Topic: Sending syslog to a remote over TLS?
Replies: 3
Views: 1051

Re: Sending syslog to a remote over TLS?

In the meantime you may work around your problem by setting up a VPN to your syslog host and sending the traffic over that.
by pe1chl
Mon Sep 25, 2023 3:11 pm
Forum: Beginner Basics
Topic: IPv6 routing basics
Replies: 10
Views: 1217

Re: IPv6 routing basics

A problem still stands which is I can't ping interfaces of a same router together even though the ipv6/setting/set forward is set to yes. (e.g ether4 and ether3 of the router can't ping each other) What is the problem?? should I add some routes? but I thought by default they're connected Yes you ma...
by pe1chl
Mon Sep 25, 2023 12:29 pm
Forum: Beginner Basics
Topic: IPv6 routing basics
Replies: 10
Views: 1217

Re: IPv6 routing basics

When you want to connect two routers using 2 cables, e.g. for redundancy or load sharing, you need to configure a "bonding" interface with those ethernet ports as member, and configure the address on the bonding interface.
by pe1chl
Mon Sep 25, 2023 11:10 am
Forum: The User Manager
Topic: First time configuring User manager
Replies: 22
Views: 4847

Re: First time configuring User manager

The problem is not the MAC address, the problem is that the RADIUS server does not answer your query.
So you need to fix that first. Try to use the router LAN address instead of 127.0.0.1
Make sure the input rules of the firewall don't block RADIUS (UDP port 1812-1813,3799)
by pe1chl
Sun Sep 24, 2023 10:49 pm
Forum: The User Manager
Topic: First time configuring User manager
Replies: 22
Views: 4847

Re: First time configuring User manager

When you get no reply from the RADIUS server, usually the secret is wrong between them. You have no secret configured in the radius server and user-manager, maybe that is mandatory (I do not know, I do have it). Also I do not use 127.0.0.1 but the IP of the router on the LAN, but that should not be ...
by pe1chl
Sun Sep 24, 2023 12:51 pm
Forum: The User Manager
Topic: First time configuring User manager
Replies: 22
Views: 4847

Re: First time configuring User manager

Under /system logging enable debug for wireless and radius (all topics) and you can see exactly what is happening. (open the log window) I keep logging for wireless enabled so I can see the devices joining the network performing the authentication. Logging for radius I have disabled during normal us...
by pe1chl
Sat Sep 23, 2023 10:50 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11.2 [stable] is released!

RAM shortage (where firmware is stored during the upgrade) is common problem on those smaller smips devices, you must make sure you have at least 7.7MB free RAM available (winbox/system/resources) before upgrade, unfortunately this doesn't help you now I guess... No, those small smips devices do NO...
by pe1chl
Sat Sep 23, 2023 10:46 pm
Forum: The User Manager
Topic: First time configuring User manager
Replies: 22
Views: 4847

Re: First time configuring User manager

I don't have any wifiwave2 devices so I can't comment...
by pe1chl
Fri Sep 22, 2023 7:06 pm
Forum: General
Topic: MAC change on VLAN subinterface [SOLVED]
Replies: 5
Views: 1292

Re: MAC change on VLAN subinterface [SOLVED]

When you need to change the VLAN MAC, of course it will change when you change the parent ethernet interface MAC.
Of course the MAC on the untagged VLAN and all other VLANs will change as well, but that likely does not matter.
by pe1chl
Fri Sep 22, 2023 6:59 pm
Forum: General
Topic: Should moderators redact sensitive info, and how much?
Replies: 49
Views: 3977

Re: Should moderators redact sensitive info, and how much?

Why should a newcomer on a forum know less than a person with hundreds of posts ? I learned what a public IP is and about sensitivity at school then university, years before setting up my first home network, I worked with sensitive data for years before writing a single post here and touching a Mik...
by pe1chl
Fri Sep 22, 2023 6:10 pm
Forum: The User Manager
Topic: First time configuring User manager
Replies: 22
Views: 4847

Re: First time configuring User manager

You need to enable "MAC authentication" in your wireless security profile, select a MAC format, MAC "as username", and add "usernames" that are the MAC addresses of the devices you want to accept (in that same format). The users have no password. To assign a VLAN to the...
by pe1chl
Fri Sep 22, 2023 4:53 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11.2 [stable] is released!

First inform you about what "stable" means before you base your expectations on it. That prevents disappointment. To be fair, regardless of what "stable" means I'd expect firmware updates _not_ to brick my devices. Yes, but so do we expect for "testing" or "develo...
by pe1chl
Fri Sep 22, 2023 2:25 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11.2 [stable] is released!

not what I expected on "stable" tree.
First inform you about what "stable" means before you base your expectations on it. That prevents disappointment.
by pe1chl
Wed Sep 20, 2023 5:20 pm
Forum: General
Topic: Webfig Enhancement
Replies: 24
Views: 6851

Re: Webfig Enhancement

I only used CLI to export/import large sections of configuration
Welcome brother, sorry you hear your escape attempt failed.
What does this message mean? Please delete it.
by pe1chl
Wed Sep 20, 2023 11:39 am
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

Yeah, value-name should have been named "prompt", and pre-input should have been named "default". What is now "prompt" is redundant because a parameter without name is also considered a prompt (probably for backward compatibility?) and because a linefeed is issued after...
by pe1chl
Wed Sep 20, 2023 11:33 am
Forum: Wireless Networking
Topic: A bit better WiFi security with per-user PSK? [SOLVED]
Replies: 62
Views: 10114

Re: A bit better WiFi security with per-user PSK? [SOLVED]

But be honest now, how practical is for me, small home user to tackle in with RADIUS, user manager ? (i will, i have test equipment ready for that even if i said that i don't want to do that.) Actually, user-manager is easy to get going. I am using it now instead of access lists on WiFi (i.e. a sec...
by pe1chl
Wed Sep 20, 2023 11:22 am
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

It looks like the issue is more that the "preinput" name is unclear, it should have been something like "default". In the example you suggest that the preinput is a "prompt" on the same line, but in fact it is the initial content of the input buffer, that you can backsp...
by pe1chl
Tue Sep 19, 2023 7:32 pm
Forum: Wireless Networking
Topic: A bit better WiFi security with per-user PSK? [SOLVED]
Replies: 62
Views: 10114

Re: A bit better WiFi security with per-user PSK? [SOLVED]

I don't wanna mess with RADIUS, User Managers etc and for what, for something that more and more vendors implement... For eg. TP-Link... Not expensive as Ruckus... And Mikrotik targets home users also... So this looks important for me... You have bought the wrong equipment. MikroTik provides you wi...
by pe1chl
Tue Sep 19, 2023 5:22 pm
Forum: Wireless Networking
Topic: A bit better WiFi security with per-user PSK? [SOLVED]
Replies: 62
Views: 10114

Re: A bit better WiFi security with per-user PSK? [SOLVED]

As for IoT - I put those into a separate VLAN / SSID and don't care much about them. You can also lock them up later on with access lists if needed. I use separate VLANs for IoT and similar, but creating a separate SSID for each network is very inefficient. So now I use a single SSID and have MAC a...
by pe1chl
Tue Sep 19, 2023 5:17 pm
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 148
Views: 45747

Re: Feature Request: IPSEC Improvements

unsubscribing, since I do not even care anymore. moved back to fortigates because of this crap.
Useless to report that here. Report the number of units you planned to buy and have canceled to sales@mikrotik.com, then it may have an effect.
by pe1chl
Tue Sep 19, 2023 5:16 pm
Forum: General
Topic: Webfig Enhancement
Replies: 24
Views: 6851

Re: Webfig Enhancement

I'm still hoping that webfig will be enhanced at some time so it has the same features as winbox.
That really is possible using today's web features.
by pe1chl
Tue Sep 19, 2023 11:49 am
Forum: Wireless Networking
Topic: A bit better WiFi security with per-user PSK? [SOLVED]
Replies: 62
Views: 10114

Re: A bit better WiFi security with per-user PSK? [SOLVED]

The problem is that EAP isn't supported by minimal systems (like printers and IoT devices), and that many devices do not work properly when both PSK and EAP are configured on the same SSID (although the standard and the configuration of RouterOS does allow that). Another problem is that configuring ...
by pe1chl
Tue Sep 19, 2023 11:45 am
Forum: General
Topic: Webfig Enhancement
Replies: 24
Views: 6851

Re: Webfig Enhancement

Why would CLI be inescapable? This is not Cisco!
I only used CLI to export/import large sections of configuration, for the usual management of routers I never use CLI.
by pe1chl
Tue Sep 19, 2023 11:43 am
Forum: Forwarding Protocols
Topic: Suggestion for Enhancement to MikroTik's IP Traffic Flow (Source/Destination AS)
Replies: 16
Views: 4335

Re: Suggestion for Enhancement to MikroTik's IP Traffic Flow (Source/Destination AS)

They released version 7, claiming they would revolutionize it. I agree that v7 in general has been a disappointment. It has been delayed far too long, and the revolutionary new routing engine is unfinished and shows little progress. It seems that MikroTik has moved away from the small ISP market an...
by pe1chl
Sat Sep 16, 2023 12:27 pm
Forum: General
Topic: Winbox under wine - new install, new problem
Replies: 5
Views: 1077

Re: Winbox under wine - new install, new problem

Aha that is an interesting observation! I will try to configure fixed resolutions to see if that solves it. Maybe it keeps the desktops active when the screen is off. (I will have to plan some time for that to reboot the system into textmode and fiddle with xorg.conf, always a tedious and frustratin...
by pe1chl
Sat Sep 16, 2023 12:24 pm
Forum: Wireless Networking
Topic: A bit better WiFi security with per-user PSK? [SOLVED]
Replies: 62
Views: 10114

Re: A bit better WiFi security with per-user PSK? [SOLVED]

Did you read this comment: Ruckus actually managed to get a patent for this “feature” 10+ years ago
by pe1chl
Fri Sep 15, 2023 7:54 pm
Forum: Announcements
Topic: CVE-2023-30799
Replies: 14
Views: 31100

Re: CVE-2023-30799

There is System->Packages->Check installation but it is completely unclear what it does and what it doesn't do.
by pe1chl
Fri Sep 15, 2023 7:31 pm
Forum: General
Topic: Winbox under wine - new install, new problem
Replies: 5
Views: 1077

Re: Winbox under wine - new install, new problem

Ok, but in my case it seems related to the display going to sleep, the X server somehow locking the applications (or informing them) and then wine incorrectly handling that. I remember from the past when I enabled a screen saver in a system where programs were continuously displaying output, there w...
by pe1chl
Fri Sep 15, 2023 5:55 pm
Forum: General
Topic: Winbox under wine - new install, new problem
Replies: 5
Views: 1077

Winbox under wine - new install, new problem

I have been running winbox under wine for ages. Now I have installed a new Linux system, and I have an interesting new problem... (it isn't a winbox problem, the same thing happens when I run e.g. wordpad.exe so it is something related to wine or another system component) My issue is this: when the ...
by pe1chl
Fri Sep 15, 2023 4:33 pm
Forum: Announcements
Topic: CVE-2023-30799
Replies: 14
Views: 31100

Re: CVE-2023-30799

You could also just give in and grant users the capability to get a Linux shell, of course protected by a flag in device-mode and a warning that routers with this enabled cannot be supported via the usual channels. That would likely end the constant search of "vulnerabilities" to get that ...
by pe1chl
Fri Sep 15, 2023 4:21 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11.2 [stable] is released!

You can always downgrade.
Well, that probably requires a netinstall by now... even within v6, upgrading such devices often was problematic.
by pe1chl
Fri Sep 15, 2023 3:24 pm
Forum: General
Topic: Feature requests
Replies: 1744
Views: 640139

Re: Feature requests

Sure the System->Packages menu could have some very simple improvements! Not only selection of a version, but also selection of packages to install. The packages are available from the update server, so why do we have to download them on a computer, finding the correct architecture, unzip the file, ...
by pe1chl
Fri Sep 15, 2023 2:34 pm
Forum: General
Topic: Feature requests
Replies: 1744
Views: 640139

Re: Feature requests

#3 Ability to hide/remove certain columns from some of the screens would be wonderful. This will allow support staff to reduce the clutter by having fewer but relevant columns displayed on some mobile devices such as small laptops. #4 If the above custom configuration can be saved as part of a user...
by pe1chl
Fri Sep 15, 2023 10:59 am
Forum: General
Topic: Mikrotik as CLIENT OPENVPN with tls-auth static key
Replies: 26
Views: 30887

Re: Mikrotik as CLIENT OPENVPN with tls-auth static key

I obviously needed to remove some parameters before the import: dev-type tap dev tap0 writepid /var/run/openvpn_client1.pid auth RSA-SHA256 local 192.168.x.y tls-client client lport 0 ca /etc/openvpn/client/client1.ca cert /etc/openvpn/client/client1.cert key /etc/openvpn/client/client1.key tls-aut...
by pe1chl
Fri Sep 15, 2023 10:28 am
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11.2 [stable] is released!

Could this be related to 'ARP entries building up' here: https://forum.mikrotik.com/viewtopic.php?t=195759 and hence causing issues not handing out IP's anymore? No. ARP entries are not DHCP entries. When DHCP assigns an existing address to a new device (while the old address is no longer assigned)...
by pe1chl
Fri Sep 15, 2023 10:25 am
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

I have some TCP performance issue on a CCR2004 (Router B) running 7.12beta3 and beta7, but just on forwarding plane. You say forwarding but then you are testing from router to router? To test forwarding performance, put an end-system (e.g. a PC) at each end behind the routers, and test between the ...
by pe1chl
Thu Sep 14, 2023 6:01 pm
Forum: General
Topic: Firewall in front of a router: where should I run opnvpn service ?
Replies: 4
Views: 952

Re: Firewall in front of a router: where should I run opnvpn service ?

Furthermore, when you run OpenVPN on the OPNsense firewall it would presumably be the openvpn.net implementation.
That is massively better than the "OVPN" in RouterOS.
by pe1chl
Thu Sep 14, 2023 11:49 am
Forum: General
Topic: Packet sniffer - where it sniffs?
Replies: 6
Views: 2755

Re: Packet sniffer - where it sniffs?

Yes but with IPsec tunnel interfaces it is always unclear where to sniff. On a plain Linux system the issue is exactly the same. Because the plaintext traffic and the encrypted traffic is assigned to the same interface. Indeed, with VTI it would be better, but MikroTik has no VTI. Instead you can us...
by pe1chl
Thu Sep 14, 2023 9:35 am
Forum: General
Topic: Packet sniffer - where it sniffs?
Replies: 6
Views: 2755

Re: Packet sniffer - where it sniffs?

When you configure plain IPsec tunnel policies, you are asking for this kind of trouble...
by pe1chl
Wed Sep 13, 2023 9:44 pm
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

Again I had the problem that my RB4011 hangs during update. It appears to happen "after some uptime" only. It was running 7.12beta3 for 20 days, I did the update, and it shuts down but does not perform the update. Of the 10 ethernet ports, only the LED on port 10 remains on. That one is do...
by pe1chl
Wed Sep 13, 2023 9:11 pm
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

Please, any chance to make the station-bridge mode compatible over the air between different generations of devices? bridge mode is already incompatible between manufacturers. basically you have to see wifiwave2 devices as a different manufacturer. when you require transparent bridging over differe...
by pe1chl
Wed Sep 13, 2023 4:11 pm
Forum: Forwarding Protocols
Topic: Suggestion for Enhancement to MikroTik's IP Traffic Flow (Source/Destination AS)
Replies: 16
Views: 4335

Re: Suggestion for Enhancement to MikroTik's IP Traffic Flow (Source/Destination AS)

What do you mean, support for template formatting? When you select IPFIX you can mostly select the members of the template (Ok, some check marks enable multiple fields) but when your collector cannot parse a template that has fields it does not want, I'd say the blame is on the collector. I wrote a ...
by pe1chl
Tue Sep 12, 2023 11:24 pm
Forum: Forwarding Protocols
Topic: Suggestion for Enhancement to MikroTik's IP Traffic Flow (Source/Destination AS)
Replies: 16
Views: 4335

Re: Suggestion for Enhancement to MikroTik's IP Traffic Flow (Source/Destination AS)

In my opinion even more important is to extend the byte counters to 64 bits. (now they are 32 bits which really does not cut it with today's network speeds)
by pe1chl
Tue Sep 12, 2023 5:45 pm
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

The "new devices" listing on the hardware page has a MIPSBE device, with 16MB flash even.
by pe1chl
Tue Sep 12, 2023 5:41 pm
Forum: General
Topic: ARP entries building up
Replies: 23
Views: 5713

Re: ARP entries building up

As I wrote before, it is something that the new Linux kernel does. Probably there is a reason for that change, is more efficient or whatever.
by pe1chl
Tue Sep 12, 2023 5:03 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11, 7.11.1 and more [stable] are released!

I would say what "stable" means is a matter of opinion
When you want it like that, fine. But some people have the opinion that "stable" means (or suggests) that it works fine and does not crash. But that is not aligned with reality.
by pe1chl
Tue Sep 12, 2023 4:58 pm
Forum: General
Topic: ARP entries building up
Replies: 23
Views: 5713

Re: ARP entries building up

So, create the scheduled script. That works, and causes no further issues.
by pe1chl
Tue Sep 12, 2023 11:05 am
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11.2 [stable] is released!

I hope the improved routing filters they promised should be _IN_ before they make an LTS v7 So basically we have one group who wishes that a long term version is released as soon as possible so that they can deploy v7 in their organization that has the policy of only running long term versions, and...
by pe1chl
Mon Sep 11, 2023 5:04 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11, 7.11.1 and more [stable] are released!

... and then there are (probably) thousands of us using RouterOS on dozens of devices from home applications to medium size enterprises and did not encounter any serious issue for years, so we are perfectly fine with calling it "stable" :) Again (100th time): "stable" in the cha...
by pe1chl
Mon Sep 11, 2023 12:13 pm
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

One way of reproducing this is to have multiple route tables. The SNMP OID does not really provide for that, and it seems RouterOS just merges the output for the different tables which disturbs the sorting and thus the increasing of the OID in walk.
by pe1chl
Mon Sep 11, 2023 11:16 am
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

Well, maybe you noticed it only now because you were debugging things, but that "OID not increasing" is a bug that has been present for a long time.
Maybe there are other problems now as well...?
by pe1chl
Sat Sep 09, 2023 10:51 am
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11.2 [stable] is released!

You can call ANY version a long term release.
by pe1chl
Fri Sep 08, 2023 8:10 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11.2 [stable] is released!

Yes, I think there should also be a "security" channel that only gets updated when security-related fixes are made, and that can be trusted to set as an auto-update channel. I.e. updates are placed there only a couple of weeks after being released in the "stable" channel, and no ...
by pe1chl
Fri Sep 08, 2023 6:55 pm
Forum: General
Topic: [SOLVED] Source based routing disables access to mikrotik
Replies: 7
Views: 1361

Re: [SOLVED] Source based routing disables access to mikrotik

Yeah I have already made a feature request to have an option to automatically add local routes to additional route tables (they only are automatically added to table main), but we'll have to wait and see if that ever gets honored. In my environment this is also a regularly occurring problem. https:/...
by pe1chl
Fri Sep 08, 2023 3:40 pm
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43234

Re: Newsletter #113 | May 2023

And indeed, newsletter 114 was released!
by pe1chl
Thu Sep 07, 2023 8:52 pm
Forum: General
Topic: [SOLVED] Source based routing disables access to mikrotik
Replies: 7
Views: 1361

Re: Source based routing disables access to mikrotik

It is very important that you apply new-route-mark mangling that indicates a second routing table only to traffic that is actually going to internet. When you apply it to packets that go to the internal network (incoming traffic) that traffic will not arrive. So you must make sure that you configure...
by pe1chl
Thu Sep 07, 2023 11:26 am
Forum: Beginner Basics
Topic: hap mini lite as repeater
Replies: 2
Views: 1216

Re: hap mini lite as repeater

On MikroTik you can add a virtual interface to the primary wifi and then route between them. So first you configure it as a CPE and then you manually add a virtual wireless in ap mode, add a network address and DHCP server, and you can use it to extend the network. Is not a repeater, but works much ...
by pe1chl
Thu Sep 07, 2023 11:14 am
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

If no one make a support case out of it, it will possible stay like this.
It happens here too, so it will probably be easy to reproduce (my config has a pool from DHCPv6 client but in addition it lists static-only twice).
by pe1chl
Wed Sep 06, 2023 2:40 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11, 7.11.1 and more [stable] are released!

When you do not require IoT or Lora, do not upload them to the router. It is not a good idea to have them in "disabled" state, there are bugs that cause problems with the upgrading. Just "uninstall" them instead of "disabling" (or enable them).
by pe1chl
Wed Sep 06, 2023 2:38 pm
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

eoip and other tunneling protocols would only work if transporting routers along the path fragment packets on the way instead of rejecting and dropping it. This was mainly about transparent bridging across Wi-Fi point-to-point links. Issues with 3rd parties refusing to transport or fragment them do...
by pe1chl
Wed Sep 06, 2023 2:27 pm
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43234

Re: Newsletter #113 | May 2023

Youtube channel has announced new products CRS310-8G+2S+IN, 915 Omni antenna, hAP ax lite LTE6.
by pe1chl
Wed Sep 06, 2023 2:07 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11, 7.11.1 and more [stable] are released!

Downloads of updates are done to a folder named .download which you cannot see in winbox but you can see it when you FTP to the device. There (using an FTP client) you can also delete whatever is in there and try again. When in doubt about the downloading, do only "Download" (not "Dow...
by pe1chl
Wed Sep 06, 2023 2:01 pm
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 43234

Re: Newsletter #113 | May 2023

It also appears that short "news" items are now published on the Youtube channel. The newsletter already became more like a pointer to that in a past edition, maybe they really planned to abandon it but continued due to popular demand. Anyway, publishing individual news items instead of ag...
by pe1chl
Wed Sep 06, 2023 1:58 pm
Forum: Beginner Basics
Topic: when to upgrade ROS (7.xx)
Replies: 24
Views: 3751

Re: when to upgrade ROS (7.xx)

The foul-up of the vlan-filtered bridge across multiple switch chips.
That broke my network because I make extensive use of VLANs and have both tagged and untagged ports on my RB4011.
The breakage was such that it was quite difficult to diagnose.
by pe1chl
Wed Sep 06, 2023 11:57 am
Forum: Beginner Basics
Topic: when to upgrade ROS (7.xx)
Replies: 24
Views: 3751

Re: when to upgrade ROS (7.xx)

@en1gm4 I'm kind of in the same boat. My main router here at home is a RB4011iGS+ that is running 6.49.8. I have been watching ROS 7 for about a year, but currently have no real NEED to upgrade to it. I also have a RB4011 and have upgraded it some time ago, but it has been an interesting ride. Some...
by pe1chl
Tue Sep 05, 2023 11:19 am
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11, 7.11.1 and more [stable] are released!

I can only pray for those user 100 km away from the LoRa station, who will need to go by foot, air or any means and fix this on site. Poor users. I would say "stupid users" for not configuring some VPN to allow remote access to the device... When you cannot reach the device at all, how di...
by pe1chl
Tue Sep 05, 2023 11:17 am
Forum: Wireless Networking
Topic: Auto channel selection - how does it decide?
Replies: 28
Views: 29779

Re: Auto channel selection - how does it decide?

Whenever you are using "auto channel selection", you must always make sure you have a "channel list" of valid non-overlapping channels for that band. E.g. on 2.4 GHz you should have a channel list of 2412,2437,2462 (channel 1,6,11). When not doing that, the selected channel will ...
by pe1chl
Mon Sep 04, 2023 3:18 pm
Forum: General
Topic: Restart OpenVPN process from CLI w/o restarting device
Replies: 1
Views: 1117

Re: Restart OpenVPN process from CLI w/o restarting device

Most likely the answer is: "it cannot be done". RouterOS does not provide that level of access to the user/admin. You would need a shell login and that can only be obtained by "rooting" the device, there are several methods in older versions but MikroTik usually releases updates ...
by pe1chl
Mon Sep 04, 2023 2:50 pm
Forum: RouterOS beta
Topic: New User Manager in RouterOS v7
Replies: 211
Views: 81687

Re: New User Manager in RouterOS v7

Of course I am only talking about RouterOS v7 because that is the subject of this thread.
The problem you will get is that the first connect works OK but when you roam from one AP to another it will fail.
by pe1chl
Mon Sep 04, 2023 2:09 pm
Forum: RouterOS beta
Topic: New User Manager in RouterOS v7
Replies: 211
Views: 81687

Re: New User Manager in RouterOS v7

In my experience, it is not possible to limit the number of logins for WiFi. It will be OK for other connection types, like PPPoE.
When you limit the number of logins, users are incorrectly rejected.
by pe1chl
Mon Sep 04, 2023 11:43 am
Forum: RouterOS beta
Topic: New User Manager in RouterOS v7
Replies: 211
Views: 81687

Re: New User Manager in RouterOS v7

When you do not want to limit the number of logins, instead of setting it to 2 just remove the value (click triange alongside it).
by pe1chl
Mon Sep 04, 2023 11:41 am
Forum: General
Topic: /export hangs
Replies: 11
Views: 5483

Re: /export hangs

It can be helpful to look in another router or in an older export what would be the next item after the last one that is still shown. That is the item that causes the problem. I also noticed in recent versions that some items may take quite some time to export even in fast devices. E.g. I have a CCR...
by pe1chl
Mon Sep 04, 2023 12:19 am
Forum: Wireless Networking
Topic: A bit better WiFi security with per-user PSK? [SOLVED]
Replies: 62
Views: 10114

Re: A bit better WiFi security with per-user PSK? [SOLVED]

It is important to remove the "shared users" property from newly created users, where it unfortunately defaults to "1".
With that setting, the user will be unable to roam between APs.
by pe1chl
Sun Sep 03, 2023 12:06 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11, 7.11.1 and more [stable] are released!

It's likely RouterOS 6 Linux kernel doesn't have new hardware support. Back port v6 or new kernel v7 or both? There will be no more development in v6, only patches for security problems. Unfortunately the work force is split between (largely) developing new gimmicks for v7 and (much less) bringing ...
by pe1chl
Sat Sep 02, 2023 10:18 am
Forum: Wireless Networking
Topic: A bit better WiFi security with per-user PSK? [SOLVED]
Replies: 62
Views: 10114

Re: A bit better WiFi security with per-user PSK? [SOLVED]

There is no need to install certificates on devices. That depends on the software on the devices. In new Android devices, for example, you need to install the CA certificate or else it won't connect. In other software you sometimes do not get the opportunity to specify a certificate (e.g. Windows) ...
by pe1chl
Thu Aug 31, 2023 3:46 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11 and 7.11.1 [stable] are released!

People... bugs and features that are not mentioned in the release notes are most likely not fixed. No need to refer to that after a new stable release.
When you want to mention it at all (probably useless), do so in the 7.12beta topic.
by pe1chl
Thu Aug 31, 2023 2:35 pm
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

Yes, jumbo frames over 802.11 is a no-go. You will need to either fragment/reassemble them or find another wireless solution.
by pe1chl
Thu Aug 31, 2023 12:12 pm
Forum: General
Topic: Bridge traffic stats not existant
Replies: 4
Views: 1118

Re: Bridge traffic stats not existant

Yes that is true, but that does not cover his case. What he has is a bridge with traffic between ports, that passes through the firewall (that can be enabled via a setting). Now, of course that traffic is counted in firewall counters, but he wants to count it in bridge counters as well. That is just...
by pe1chl
Thu Aug 31, 2023 12:08 pm
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

I think the main use for >1500 byte MTU is not to bridge jumbo frames but to allow tunneling protocols to have some headroom to transport a 1500 byte MTU frame without fragmentation.
(e.g. EoIP, VXLAN etc can be used to work around the problem of missing 4-address mode)
by pe1chl
Tue Aug 29, 2023 7:11 pm
Forum: General
Topic: VLAN's Showing but not running or even down.
Replies: 3
Views: 1043

Re: VLAN's Showing but not running or even down.

Downgrade or upgrade (testing version). 7.11 has serious VLAN issues.
by pe1chl
Tue Aug 29, 2023 7:08 pm
Forum: General
Topic: Bridge traffic stats not existant
Replies: 4
Views: 1118

Re: Bridge traffic stats not existant

Yes. "traffic of the bridge" is only traffic that enters the bridge from the router side, not traffic between ports of the bridge.
In "normal" usage of a bridge, e.g. on a LAN, it shows the routed traffic towards the bridge, not the traffic between devices on the LAN.
by pe1chl
Tue Aug 29, 2023 3:56 pm
Forum: General
Topic: IPSec VTI
Replies: 55
Views: 23139

Re: IPSec VTI

Agreed.. IPsec without VTI is terrible. I really don't understand why it is not available yet. _ALL_ VPN's I use and manage are route based. Yeah mine too, but they are GRE/IPsec which provides the same functionality. With MikroTik routers that works well. It is only the cross-manufacturer support ...
by pe1chl
Tue Aug 29, 2023 11:59 am
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 165864

Re: v7.11 [stable] is released!

Doesn't seem at all stable to me. For the 1000th time: "stable" in the version name does not mean it works without bugs, it never crashes, it does what you want. "stable" means it is not being tinkered with all the time. Sure the 7.11 version has more than the average number of ...
by pe1chl
Tue Aug 29, 2023 11:53 am
Forum: General
Topic: IPSec VTI
Replies: 55
Views: 23139

Re: IPSec VTI

IS-IS is probably a feature requested by a large (potential) customer. I see no reason why MikroTik developers would suddenly decide to add another routing protocol (while the coding of the existing routing protocols is not finished) just by themselves. So sales has come by and said "we can sel...
by pe1chl
Mon Aug 28, 2023 2:19 pm
Forum: General
Topic: Forum moderation volunteers
Replies: 238
Views: 37566

Re: Forum moderation volunteers

OpenWRT is software. MikroTik sells hardware, and includes software with it (RouterOS). I do not see that as competiting product. It is good to point to OpenWRT when comparing features and developments, but nobody would select OpenWRT where they would otherwise select RouterOS. They are completely d...
by pe1chl
Mon Aug 28, 2023 10:14 am
Forum: General
Topic: Forum moderation volunteers
Replies: 238
Views: 37566

Re: Forum moderation volunteers

"openwrt" can hardly be called a "competing product", right?
by pe1chl
Sat Aug 26, 2023 11:03 am
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

Watch out with 7.12beta3 if you have 100G ports on a CCR2216 and you use QSFP28 which are attached to a cable (DAC or AOC or so). This apparently is rocket science! MikroTik simply cannot get it working right. Every new release there are changes in SFP, which fix some problem and it breaks somewher...
by pe1chl
Sat Aug 26, 2023 1:05 am
Forum: Announcements
Topic: FORUM MAINTENANCE: Password reset will be needed
Replies: 162
Views: 45436

Re: FORUM MAINTENANCE: Password reset will be needed

Most likely the result page for that search query includes a user that has some error in their profile entry?
by pe1chl
Sat Aug 26, 2023 12:59 am
Forum: Scripting
Topic: FastTrack-Friendly QoS Script
Replies: 61
Views: 39399

Re: FastTrack-Friendly QoS Script

Well, I think it is better to set priority based on DSCP than to use port numbers. Any reasonable SIP and RTP device already sets DSCP properly (EF). "Set priority from dscp high 3 bits" works fine for most cases, and it seems that support of a fully configurable DSCP->Priority mapping tab...
by pe1chl
Fri Aug 25, 2023 5:06 pm
Forum: Announcements
Topic: MikroTik Devices Controller
Replies: 332
Views: 239988

Re: MikroTik Devices Controller

There already are the protocols used by winbox, the API (which is about the same, I think), and the REST API introduced in v7.
Maybe the latter is what they intend to use in the controller...?
by pe1chl
Fri Aug 25, 2023 1:50 pm
Forum: The Dude
Topic: DUDE v7 server "needed packages are not available"
Replies: 35
Views: 14158

Re: DUDE v7 server "needed packages are not available"

The Dude is no longer being developed. I don't expect the situation to change. When you want to keep using it, deploy your own scripting solution for upgrades.
by pe1chl
Fri Aug 25, 2023 1:49 pm
Forum: General
Topic: traffic usage counters
Replies: 14
Views: 3087

Re: traffic usage counters

Of course, but that is not something I as a normal user am going to hit and for which I would need to do bookkeeping.
When I have exceeded that limit I will get a letter.
(this is for fixed connections, for mobile it is different and there are defined limits above which you will get a very low speed)
by pe1chl
Thu Aug 24, 2023 11:34 pm
Forum: General
Topic: traffic usage counters
Replies: 14
Views: 3087

Re: traffic usage counters

Well that will probably vary by region. Here we have flat-rate internet, no charge for traffic.
by pe1chl
Thu Aug 24, 2023 9:08 pm
Forum: General
Topic: Mikrotik as CLIENT OPENVPN with tls-auth static key
Replies: 26
Views: 30887

Re: Mikrotik as CLIENT OPENVPN with tls-auth static key

It has been added to 7.12beta. When you need it, test it with that version before it becomes "stable release".
by pe1chl
Thu Aug 24, 2023 7:46 pm
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

Ok, works for me... (RB4011, hAP ac2, CCR1009, CHR)
by pe1chl
Thu Aug 24, 2023 6:01 pm
Forum: Announcements
Topic: v7.12beta [testing] is released!
Replies: 263
Views: 126078

Re: v7.12beta [testing] is released!

console died so far i can reproduce this on a spare CCR1036 and CRS317 so this is not architecture specific
Is that on a physical console? (serial port and terminal program)
As I cannot reproduce that on a terminal window...
by pe1chl
Thu Aug 24, 2023 5:07 pm
Forum: General
Topic: IPSec VTI
Replies: 55
Views: 23139

Re: IPSec VTI

regarding the other protocols you mentioned, like NHRP, I can't tell, I just want interfaces :P When you think that VTI just means "standard IPsec tunnel but with virtual interfaces instead of policies on existing interfaces": that is not really true, read back above to e.g. explanation b...
by pe1chl
Thu Aug 24, 2023 4:24 pm
Forum: General
Topic: IPSec VTI
Replies: 55
Views: 23139

Re: IPSec VTI

so, if IPSEC is that exotic, please tell me why there is so many threads about it and why is mikrotik working hard on supporting hw-acceleration for IPSEC wherever possible and why is mikrotik improving their ipsec implementation all the time? how do you know, what types of vpn are being requested ...
by pe1chl
Thu Aug 24, 2023 2:17 pm
Forum: General
Topic: IPSec VTI
Replies: 55
Views: 23139

Re: IPSec VTI

true, but dude, please don't refer to VTI as "every type of VPN" like it is some exotic thing.
It is exotic in the market for MikroTik devices. Ok, maybe not so much now as it was a couple of years ago, but still most MikroTik users demand OpenVPN or Wireguard, not IPsec.
  • 1
  • 2
  • 3
  • 4
  • 5
  • 40