[Discussion] MikroTik configuration abstraction complexity

In addition to Mozerd’s astute observations, look at the vision statement at the MT website…
Thats right, there isn’t one!! But you can find About Us… which says nothing about anything in particular.

About us

MikroTik is a Latvian company which was founded in 1996 to develop routers and wireless ISP systems. MikroTik now provides hardware and software for Internet connectivity in most of the countries around the world. Our experience in using industry standard PC hardware and complete routing systems allowed us in 1997 to create the RouterOS software system that provides extensive stability, controls, and flexibility for all kinds of data interfaces and routing. In 2002 we decided to make our own hardware, and the RouterBOARD brand was born. Our company is located in Riga, the capital city of Latvia and has more than 280 employees.


A wee bit more on the jobs page…
About MikroTik

SIA " Mikrotīkls " is a Latvian company founded in 1996 that develops and manufactures MikroTik RouterOS software and RouterBOARD routers. Our products are used by Internet service providers, companies and individual users who need to provide data flow routing, firewall, VPN and other management functions in various computer networks.

Our goal is to provide powerful and easy-to-use network management tools to the widest range of users. MikroTik products are distributed and used all over the world - we have seen MikroTik solutions on Everest and even in the mechanism of the SpaceX Falcon orbital rocket!

More about SIA “Mikrotīkls” company and products: https://mikrotik.com .

We respect our employees and the work environment. The company’s office is a modern class A building, which was rebuilt in 2017 especially for the needs of “Mikrotīkla” employees. Also, a new warehouse has been built, equipped according to all modern requirements. We have received several awards both as a TOP employer in Latvia and other prestigious awards as the best producers and exporters. The World Intellectual Property Organization presented “Mikrotīk” with an award for knowledge-based business focused on continuous development.

You would lose your bet. I didn’t say I continued exclusively in the Enterprise domain, did I?

If you’ve had SP/DC experience with other vendors, and assuming you worked with software engineers for network programmability or automation, you’d know MikroTik RouterOS is poor software code, horrible API etc.

No streaming telemetry, no gRPC, no OpenConfig, no YAML/JSON-like API input/output, CLI in/out, no root access like Juniper or Nokia SR-Linux.

A very interesting thread, thank you. It is also clearly obvious how different people have different needs and different ideas about our products. We sure can’t go in all directions this thread would want us to :slight_smile:

So, for all of us, it would be interesting to hear, which directions Mikrotik will go.

I agree with you. When performing strategic corporate procurements, I’ve always weighted software quality, reliability and end-to-end programmatic observability and manageability as higher than performance or cost per port. For these reasons it’s unlikely that Mikrotik would get very far in the procurement process. But then I don’t think that is their target market. Like you, I think they need a rethink about the management interface/API to be closer to best practice, but I can’t see them breaking into the telecoms/corporate core network market as a primary supplier.

Meanwhile, for SoHo requirements these fora are full of posts from people who have used Netgear (or similar products) in the past, then buy a Mikrotik and can’t get it to do simple things. The “plug and pray” market is something that I think Mikrotik ought to make a better job of supporting, even if it’s just a different overlay.

While I agree with a lot of what’s already been said above I think it’s something of a testament to Mikrotik and how good their hardware/software can be (within it’s limitations) that people are comparing them to the “big name vendors”.

But still I can’t see large enterprises changing from those big vendors without being able to get someone on a support call within an hour. Likewise I can’t those large enterprises who use the big consulting companies like NTT, Accenture, Atos etc recommending Mikrotik for solutions.

Personally I think Mikrotik hardware and software is outstanding for what I use it for but while the “enterprise” segment is tantalisingly close it still might just be as well a million miles away without a big expensive eco system to support those enterprise customers. Can’t see that happening anytime soon.

I think that a large part of the perplexities derive from the different directions that Mikrotik already took, though.

If the idea is to make powerful, high end devices for the high end professionals, it seems like (as reported by some of the posters that are into networking professionally) a number of needed/useful features/protocols/what_nots are missing.

If the idea is to make powerful, cheap devices intended for the mid-level professionals, this evidently worked for some time but now it looks like while the devices remain cheap, they start to look underpowered/unfit for this use.

If the idea is to make powerful, cheap devices for end users, they are currently unmanageable by the intended customers due to the (understandable) underlying complexities that are NOT mitigated in any way, not with a user-friendly UI, not with proper, clear, documentation, not with adequate sets of examples, not with a number of pre-defined quickset scripts covering the most common operations.

I can (obviously) only talk as an end user, my experience with Mikrotik is very small, and - personally - I am happy with the results I managed somehow to obtain, but it has costed me time, tears and blood to get the something I wished to get, and in my specific case (very simple requirements, only a little uncommon, but not as crazy as it seems) I got there using a couple of tricks found after tens of hours of reading and experimenting. Luckily I took the whole stuff as “fun” and “learning”, but I doubt that many other people with my same needs would have the same amount of patience and persistence, and I am anyway an empiricist at heart, and the whole matter is interesting.

Judging from the questions asked and issues reported on this forum[1], I could bet (and easily win the money) that more than 50 percent of devices managed by common people (and a not trifling percentage of those managed by professionals) are running in the wild mis-configured, with settings that are in the best cases unneeded or slowing down the devices and in the worst cases dangerously insecure.

If you prefer, would I recommend Mikrotik to a friend? No.

[1] look also at the answers/solutions provided by even the most experienced members, it is rarely a "Ha, you are in this known case, just do this and that to solve your issue, read here and much more often "Hmmm, you could try this (or that or this other thing), it may work if you are on version x.xx, but not y.yy compare with this <link to a cryptic seemingly unrelated post on the forum, that actually contains part of the solution>.

I will agree that since there is no real effort to improve the ‘question quality’, its no surprize the ‘answer quality’ is not optimal.
Overuse of the word powerful in the explanation, flexible would be more apropos.
Recommend to a friend: Not unless they were tinkerers, otherwise the ISP provided router is usually adequate, or a consumer off-the shelf router.
Recommend to family: Yes, but realizing I’m on the hook for all support.

Well, I did mean powerful.

Flexible is the exact opposite of what Mikrotik is, it is rigid in itself, the fact that a few knowledgeable/initiated users (like you) can manage to make it bend to their will (through secret, arcane magic spells) doesn’t make it flexible.

https://www.pirelli.com/global/en-ww/life/innovation/industry/-power-is-nothing-without-control-celebrates-25-years-52060/

For the longest time I thought the same as you, but over time, it was clear that it was my lack of networking knowledge and Ros Principals that was keeping me from unlocking the flexibility.
There are many ways to skin a cat [ as mkx & rextended would say :wink: ] with RoS, and that leads to many ways to solve issues.

One direction is the easiest:
Enable official ONIE support on MikroTik hardware, at least all models that are new and has Marvell ASIC/PIPE.

Problem solved, we can install our own NOS and not have problems with VXLAN/EVPN offloading to ASIC or even MPLS/SR-MPLS if the ASIC supports it.

This costs you nothing for developing, give us flashing software to flash official ONIE bootloader for MikroTik, that’s it, about 3 months worth of coding + testing? Not much time to make this happen, since you have access to RouterBOOT source code and the hardware in your offices. Should be a fairly doable software project for some C/Rust programmers in your company. ONIE version 2023.11 looks like something that could work.

@jaclaz

  1. Nobody is asking for a Juniper MX2020 from MikroTik.

  2. MikroTik HARDWARE isn’t the problem. In last 10 years of MikroTik, 1/10 are hardware issues.

  3. MikroTik SOFTWARE is the problem. In last 10 years of MikroTik, 10/10 are software issues.

They can opt for fastest/cheapest solution i.e. enable official ONIE flashing support. OR, they hire more software engineers who can build ROSv8 or whatever to be on-par with Nokia SR-Linux:

  1. Open source components and data model
  2. Contribute back to upstream Linux kernel
  3. Remove Linux dataplane
  4. Move to DPDK/VPP or XDP for software dataplane

Computer Networking, as an engineering domain, operates under distinct constraints that often limit the number of “systemically optimal” solutions:

  1. Protocols and Standards — You cannot act on your own, packet flow is pre-determined by specs.
  2. Physics and transport medium — Self explanatory.
  3. Complexity and performance trade-offs — Complexity not only in system design, but also config complexity (circa this post), that leads to human layer issues for scale and manageability.
  4. Security — There are limited number of ways to ensure maximum security/and or reasonable compromise

Due to these constraints, there are typically only a few ways to design and implement something in networking while achieving optimal performance, security, and reliability within the defined protocol and physical limitations. Networking has many potential solutions, but the constraints guide engineers towards a narrow range of “systemically optimal” choices based on the specific context and requirements.

My rule of thumb personally based on my experience in SP and DC market is, at best I have two systematically optimal options in a given scenario and if I’m lucky I get three.

What’s strange about MikroTik as a network vendor is we don’t see them in IETF meetings, we don’t see them in NANOG, SANOG, UKNOG, NLNOG etc.

Other vendors, small or big, attend these events, especially IETF, since all are interested to mingle, improve, and make business deals, but MikroTik employees are nowhere to be seen. If you search for Normis or MikroTik employees on LinkedIn, good luck finding them. Now search for VyOS, Nvidia Cumulus, Arista etc, and see the difference.

Cisco, Juniper, Arista, Huawei etc have all contributed tons of RFCs to the community, which RFC draft/spec has MikroTik ever contributed to?

:laughing: normis is my name just as DarkNate is yours

@Darknate
Yes, it is clear that the issue is mainly software, but I would venture a little further, saying that the software is not as bad as it seems, a relevant part of the perceived (and also objectively found) issues seem to me not due to the core of the software but rather at the poor way features are documented causing mis-configurations.

I have a fantastic theory about this. :open_mouth:

Some years ago an alien ship landed in Latvia and a semi-god creature gave to a bunch of engineers the capability of making good hardware and almost decent software but, in the tradition of these stories, he wanted something in exchange for this gift, and he took away their capability to write documentation and to communicate with their customers. :laughing:

As someone said this, Mikrotik is not plug and play it’s more like plug n pray :laughing:

No praying is necessary, but if you are administrating a network, you better at least understand networking.

Tasks/decisions/issues like you describe here aren’t solved by just throwing lots of software engineering manpower at it. But I think you already knew that (because you already mentioned the term “product managers” and I assume you were talking about the role in a software development cycle). From what we can see from the outside how ROS evolves I can just make a wild guess. But I dont believe that there is someone with a clear “product-vision” nor someone who defines a roadmap of upcoming ROS features. It seems to be mainly driven by customer feedback (bug reports) and maybe some engineers personal goals (e.g. BTH feature that nobody asked for, sure it is nice, but does it address the real painpoints? nope)