Hi guys, We are using BGP on RouterOS 5/6 and have a 32 AS number, but a new peer only supports 16 bit AS numbers. I am aware that we should be able to deal with this using the AS_TRANS number as a 16 bit placeholder, but I don't know if RouterOS supports that. Does anyone know? Is there any configu...
Hi, I am using the API with the perl interface that is linked to from the API page of the wiki and connecting to a postgresql database all with encoding utf8. I have a script that checks through access list entries and we have a customer (maybe more than one) who's name contains an ñ (Spanish eñe). ...
Hi all. One utility that proves very handy on Linux boxes is tcptraceroute, which allows you to troubleshoot not being able to connect to a specific service when you can ping the host. Often this is due to nat, mangles and filters on routers between you and the host in question and tcpraceroute make...
Hi. I've just tried RC8 for this very reason, but the memory and hard disk entries still don't seem to be there. Did this bugfix get dropped from rc8 in the end? I'm using rc8 on a 411 board, and am getting this response from a snmpwalk on .1.3.6.1.2.1.25.2.3.1.6: iso.3.6.1.2.1.25.2.3.1.6.65536 = IN...
Hi. I can happily set wireless-protocol=nv2-nstreme-802.11 using terminal or telnet, and I can change wireless-protocol to "any" using the API. When I try to set wireless-protocol=nv2-nstreme-802.11 using the API however, it just ignores the setting completely. Any ideas? I wonder if it's ...
Hi. With version 3.28 I had our router setup with all local interfaces set to reply-only arp, and the dhcp server set to add arp leases - thus helping to prevent arp spoofing. This still works in the most part with 4.11, but when a dhcp lease is renewed and if the arp lease isn't there, the arp leas...
For us, keeping the pool on the radius server is preferable - it works (or used to :? ) very nicely. Are you currently on 4.10? Did you definitely try Framed-IP-Address on 4.10? Yes, the host to-address record shows as the incorrect IP assigned form the local hotspot pool. I'll probably sent a reque...
Hi. We've just upgraded our office router from 3.28 to 4.10, and find that the router now ignores Framed-IP-Address in the radreply packet sent by freeradius. We're using the hotspot method of controlling staff logins using their MAC address, which was working seemlessly with 3.28. Freeradius report...
Hi. Ocasionaly it has been known for one of our nodes to be shutdown by mistake, instead of rebooting - which tends to need a visit to fix. Obviously this is the fault of rushing things, not looking carefuly etc, but it could be easily avoided by disallowing shutdown in all groups whilst still allow...
Hi all. I'm experimenting with authenticating all of our users using the hotspot service and radius. Our distribution points are all Mikrotik based and I would like to add hotspot functionality to all of them. At the moment we are using the 3.30 firmware. All of our customers use CPEs which are rout...
Hi all. I'm trying to get cookie authentication working, on a very basic hotspot setup. Everything else is working fine, including the trial system and cookies are working fine in Firefox, but in Internet Explorer it seems the cookie isn't even stored in the first place. I have all security and priv...
Hi. I do have quite a few requests, so I'm not sure if it's best to detail them in different posts or not. Anyway, here is the list: 1. To be able to keep settings such as "inline comments", "show categories" and displayed columns saved somehow. 2. To be able to do continuous tra...
Hi. We have a few CPEs out there that we changed the MAC on, but would now like to put them back to the hardware MAC set on the cards. It seems ethernet ports can have the MAC reset by /interface ethernet reset-mac <interface name> , but I can see no way to do this with wireless cards. Any ideas? Ch...
Hi all. I'm not sure this is the best place to ask about this, but I couldn't find an API forum. On version 3.18 of routeros, when we did an /interface/wireless/access-list/print, it included a comment field, which is handy for us as we use this field for customer names. I'm not sure when this chang...
The duplication on the Mikrotik side has stopped . I don't know why. On the syslog side, I've dsicovered myself to be a buffoon - during my many attempts to get rsyslog working I had ended up with three different commands, all of which did added the same log entry... Doh! Cheers for your help though...
Hi all. We wish to log all connections through our router to a syslog server (rsyslog on debian). We have a filter setup which logs all new tcp connections which is working, but for some reason on the mikrotik log (i.e. /log/print) each connection is logged twice (i.e we have twice the number of rec...
Hi all. I am trying to use a Mikrotik mini-router to connect using PPPoE through a Zyxel Prestige 660R-61C router to Telefonica ADSL here in Spain, and I wondered if anyone can help me get it working. The settings to connect directly through the Zyxel are currently as follows: Mode: Routing Encapsul...
When we have people using P2P we tend to find ping times go all over the place, even if we create queue rules. The only reason I can think this is the case is due to the large number of connections that P2P tarffic tends to make. If this is the case (and even if it isn't) it would be very useful to ...
We have a routerboard 532A with a 564 daughterboard supplying two backhaul links and one distribution link (about 15 direct connections). All of these connections get to the internet via one of the LAN ports. The only configuration is 4 static IPs on different subnets and 5 routes including 1 defaul...
In winbox, it is extremely useful to be able to see all current connections, but when the number of connections gets to be more that 1000 it would be even more so if we could filter connections by source, destination, port range, etc etc.
Also, is there any standard way to request features?
Hi. Using a general P2P blocking filter was working very nicely until this week, when we have noticed emule getting through - perhaps using the "protocol obfuscation" setting. Also another client called "ares", which I believe uses gnutella, seems to be getting through, and I am ...