Documentation errors

The following documentation page https://wiki.mikrotik.com/wiki/Manual:CRS_Router#Management_port_2 says

You can find an example firewall that will block unwanted traffic to the CPU.

I would like to see and study that example.
Is it somewhere on the same page? Couldn’t find it.
Where is this example supposed to be? Is it on some other web page? A link would be fine.

The following page https://help.mikrotik.com/docs/pages/viewpage.action?pageId=3211299 under “Source NAT” says

Let`s assume you want to hide both office computer and server behind the public IP 172.16.16.1

But that address (172.16.x.x - 172.31.x.x) is a private address, much like 192.168.x.x and 10.x.x.x .
Cf. https://en.wikipedia.org/wiki/Private_network

I do agree that this is a wrong as well.
172.16.16.1 is not a public IP, so they should change what they write or another example IP.

The following wiki page is imprecise and incomplete in its description:
https://wiki.mikrotik.com/wiki/Manual:Special_Login

Questions / Remarks:

  1. Unbinding console from serial:
  • Unclear on which device to perform: on R1 or R2, or on both?
  • The command to do that is missing. It instead just shows the “print”.
  1. Adding new user named “serial” and binding it to the serial port:
  • Unclear on which device to perform: on R1 or R2, or on both?
  1. Unclear if after closing the session a reboot on the devices R1 and R2 is necessary, but it seems indeed necessary.
  • Has this to be done locally on the devices, or can it also be done from remote, ie. from PC?
  • Do both devices, R1 and R2, need to be rebooted?
  • What about reverting point #1, ie. re-binding console to the serial port ?
  • And also what about that user “serial” created in #2 above? Does its link to the serial port need to be terminated?
  1. And the Description says:

Special login can be used to access another device (like a switch, for example) that is connected through a serial cable by opening a telnet/ssh session that will get you directly on this device (without having to login to RouterOS first).

Without having to login to RouterOS? Really?
But he uses ssh to login to the device. Is he by that not doing a login to RouterOS?

The page should use the IPv4 Address Blocks Reserved for Documentation in RFC5737.

:slight_smile: But then people would rightfully complain that these addresses cannot be used in real networks… :slight_smile:
OTOH, a simple footnote saying that these IPs are just placeholder-examples in documentations should do the trick.

I actually asked them to introduce errors in the documents you are reading so as to keep you away from asking configuration questions. So far its working. :wink: