Please check this video
i have delay action ( delete / disable / Enable ) in firewall CCR2116-12G-4s+ .
https://www.youtube.com/watch?v=ZbkLHiIsys0
Desktop_220315_0755.rar (838 KB)
Please check this video
i have delay action ( delete / disable / Enable ) in firewall CCR2116-12G-4s+ .
https://www.youtube.com/watch?v=ZbkLHiIsys0
Desktop_220315_0755.rar (838 KB)
any body there ?
Posting link to RAR allegedly containing video without a coherent explanation of what is bothering you usually attracts very little attention on this forum. Quite a few forum members have strong aversion towards videos even if they’re on youtube which makes tgem slightly more secure to open (myself included). Usually they last too long for the content provided (which often could be written in a few lines of text).
Posting a good truble explanation, accompanied with configuration export (run /export hide-sensitive file=anynameyouwish), will definitely attract more attention.
this video : https://www.youtube.com/watch?v=ZbkLHiIsys0
Yep, that’s not right. But I never saw it before.
I say this is a bug
Will this bug be solved?
I am worried …
![]()
![]()
![]()
![]()
No, this bug will be ignored forever.
On the serious note: open bug report with support … so that they officially have something to work on. They might ask you for further details (and/or supout.rif file) and it’s ben said that you’re explicitly informed about resolution (when it’s done).
Did you try to update to the latest 7.1.5 and see if anything changes ?
Or maybe to 7.2rc5 ?
Did you try connecting over IP instead of MAC?
It would be interesting if the behavior is different…
It had nothing to do with it
I update to 7.1.5
It is still a problem.
![]()
![]()
![]()
![]()
You can repeat the same behavior by enabling/disabling the connection tracking, for example:
/ip firewall connection tracking set enabled=yes
/ip firewall connection tracking set enabled=no
When you remove the last IP firewall filter, it takes some time to disable the connection tracking and few second delay is expected behavior. This happens in RouterOS v6 and v7.
If you add more IP firewall filter rules and remove some of them (without completely disabling connection tracking), your device should respond almost instantly.
Doing this for only 1 second was effective.
![]()
The problem still exists.
As EdPa explained, this is not a bug but the expected behavior. Cause: when the last firewall filter is removed, the connection tracking is automatically deactivated (since it’s not needed) which may take a few seconds.
Why is this a problem?
So why is this problem not in hAp and CHR 7.1.5? ( i tested )
But i test mikrotik os 7.1.5 iso and ccr2116 ..i have delay firewall action ( disable / delete /enable) .
The introduced delay looks like related to the connection tracking “max-entries”, see the “/ip firewall connection tracking print”. A higher number means a bigger delay to completely disable connection tracking.
But does the problem really affects your device in production? Are you planning to add/delete a single IP firewall rule occasionally?
This behaviour might appear differently depending on difference in hardware architecture ie SoC, switch chipset, device drivers and so on.
Does this behaviour cause any real problems for you? If so, please file it as a bug report to Mikrotik support.
I sent this bug to the mikrotik team 8 days ago. But no news yet.
![]()
![]()
![]()
![]()