Packed rejected !!!!

I sent all to mt support and now waiting…

We were having the exact same problems until I turned connection tracking off. Once connection tracking is off all of our problems disappear. If you turn off connection tracking while packets are being rejected the problem goes away, just as if you rebooted the router.

Hope this helps,
Ken

Don’t disable connection tracking :wink: !!!


Email from mikrotik support :

Hello,

you have a lot of people that use P2P sharing programs.

You can decrease tcp-established-timeout in “/ip fireall connection tracking”,
or limit connections per customer (100 for example)

in firewall there is a parameter connection-limit. you can set this parameter
and with the action drop, each new connection will be dropped if the
connection count reaches the set number.

or wait for v2.9.8 (there will be larger connection table and more improvements)

Regards,
Normunds

Waiting… :slight_smile:

When connection tracking is switched off, there is no problem. We have two identical bridges installed, one for over 1 month and the new one for one week. We had the same problem with the new one - packet rejecting. We compared configuration many times but we forgot to check connection tracking. Now when it is OFF, it works fine and I hope it will be functional for many weeks like the old bridge.

Please update us, do you have problem with new bridge, and also for other users, with connection tracking off, is the problem completely overcomed.

I ave over 30 routers mt in my network. when connection tracking is off after 1-2 hours routers don’t see network only his neighbours (sometimes more) - routing doesn’t work, all users have problem with connection to internet and crazy ping’s. Network is not working propely.

With connection tracking OFF, you can`t use mangle… it is a handicap to loose this feature!

Best solution - change rtc estabilihed timout (30 m or ???). I have 30m :wink: and all work’s ok without packed rejected.

By default it is 10 days, or something like that. You shortened this to 30min and everything goes OK? If the answer is YES; it`s worth trying…

After 2 days when connection tracking is OFF it works fine, no packet rejected. We use the connection only for bridge purposes so no mangling and routing is performed.

Now I’have 30 min and all works OK.Somtimes i’have packed rejected but amll amount and really somtimes.

how to set rtc estabilihed setting?

Hello friends,

I have a similar problem with CCR1036-8g2s+.

I work in an ISP and we have 2 CCRs1036-8g2s+ (let’s call them R1 and R2), 2 CCRs 1036-12g4s and 1 CCR1016-12g.

R1:
SFP+1 Link-IP 2Gb BGP.
SFP+2 (Vlan1) Link-IP 500Mb Point-to-Point - (Vlan2) IX 2Gb.

R2:
SFP+1 Link-IP 500Mb BGP.
SFP+2 (Vlan1) IX 3Gb BGP.

The other routers are authenticating our clients.
I was using LONG-TERM version in all routers, when this problems started, I’ve updated all versions to STABLE 6.46.6.
Everything are working fine when it suddenly stop.
The router still working, the CPU is always working with about 20-35%, nothing wrong on LOG and everything still connected but not working.
When pinging, I receive PACKET REJECTED and after a while it receives timeout.
If we reboot our router, everything back to normal and it starts working fine again.
I had reviewed all the configurations, route filters, firewall rules, and asked our providers to check their sides.
Until now, I couldn’t find nothing that could cause this issue.

I appreciate any help.
Thank you!

@Jellison, can you exclude heat issues?
What do the following commands say if you issue them at the local serial console of the devices when remote connection is not possible due to the said error situation? :

/system health print

/system resource print

And: do you have some scripts running in the background, ie. in the scheduler?

@Mutluit, thanks for answering :slight_smile:

Yeah, the CPU are working in about 55 to 58Cº, fan OK and we have temperature control at room.
CPU work in about 20 to 40% only, it looks normal when it happens.

2 scheduled scripts
1 create backup
1 send backup
create backup are running at 00:00.
Send backup are running at 00:08.

Today it happened again, it was about 19:15, it was rebooted by watchdog timer and again, everything BACK TO NORMAL!
But when it happens, our clients lose connection for a while, something about 5 minutes to reload everything again.
I don’t know if it’s a bug or not, but it’s really hard to figure out what’s wrong with it.

:frowning:

Hello Guys,

We replaced the router with a RB1072 and until now, no problems.
I don’t know if it’s a capacity problem or something related to this, but after replaced, the problem is gone!

NOTE: The problem started when we reached 3,5Gb.

The supout file was sent to Mikrotik, but no answers yet.
Hope that could help you guys.

Hi,

I have also started experiencing this problem after years of everything running smoothly.

We have CCR1072s, every 22 hours we will experience intermittent connectivity and packet rejected until we reboot the router.

We were running LONG-TERM but updated to the latest stable to try and rectify the problem, however it still happens.

We have a redundant setup and the 2nd router is just fine running the same version and hardware.