Community discussions

MikroTik App

Search found 20 matches

by Paradox
Mon Mar 20, 2023 5:39 pm
Forum: General
Topic: Feature Request: Ed25519 SSH keys
Replies: 57
Views: 22338

Re: Feature Request: Ed25519 SSH keys

I have a support/feature ticket on that topic (SUP-61929).
Also did a feature request...
by Paradox
Tue Mar 07, 2023 9:08 am
Forum: SwOS
Topic: feature request - https for webui
Replies: 31
Views: 16680

Re: feature request - https for webui

And who would be this intruder between the computer, and the router connected directly with a network cable?
Apparantly it's called network, because I always have direct connections between computer and switch :roll: :-P
by Paradox
Mon Mar 06, 2023 10:36 am
Forum: SwOS
Topic: No https support in SwOS web interface?
Replies: 7
Views: 4106

Re: No https support in SwOS web interface?

Sorry, I've found the discussion here: viewtopic.php?t=164109
by Paradox
Mon Mar 06, 2023 10:31 am
Forum: SwOS
Topic: feature request - https for webui
Replies: 31
Views: 16680

Re: feature request - https for webui

I don't need it - my switches (and the networks) are all under my physical control.
As long as there is no intruder in your network.
Yes, I'm also doing stuff like this, but it's not good security practice anymore: look for Zero Trust.
by Paradox
Mon Mar 06, 2023 10:09 am
Forum: SwOS
Topic: feature request - https for webui
Replies: 31
Views: 16680

Re: feature request - https for webui

The switch support already SSH, HTTPS on RouterOS, simply use already included RouterOS instead of SwOS...
Funny advice... IMHO SwOS is much simpler and setup is faster for some use cases.
by Paradox
Mon Mar 06, 2023 9:58 am
Forum: SwOS
Topic: No https support in SwOS web interface?
Replies: 7
Views: 4106

No https support in SwOS web interface?

Hi,

is there no https support in the SwOS management web interface?
by Paradox
Thu Oct 27, 2022 10:30 pm
Forum: General
Topic: Configuration deployment to a bunch of Mikrotik routers
Replies: 4
Views: 1016

Re: Configuration deployment to a bunch of Mikrotik routers

Actually I don't think that messing with 30+ VLANs makes it much easier to manage. I think I've got 6 or 7 VLANs at the moment and the firewall rules on the inter VLAN router are already much longer than what I call easy manageable. Also instead of 30+ routers (with bridge) I'd need 30+ switches the...
by Paradox
Thu Oct 27, 2022 12:25 pm
Forum: General
Topic: Configuration deployment to a bunch of Mikrotik routers
Replies: 4
Views: 1016

Configuration deployment to a bunch of Mikrotik routers

Hi, I want to deploy a configuration to a bunch of Mikrotik routers (> 30). The routers are used as follows: In a laboratory environment each router is used for a small, separated network. Inside of the separated networks there usually is a PC and some measurement equipment (connected via IP to the ...
by Paradox
Thu Oct 27, 2022 11:39 am
Forum: SwOS
Topic: Configuration of SwOS (CSS326-24G-2S+RM) for dynamic VLAN
Replies: 11
Views: 8721

Re: Configuration of SwOS (CSS326-24G-2S+RM) for dynamic VLAN

Hi,

I've ordered a CSS326-24G-2S+RM which is not delivered, yet. Is MAC based VLAN via RADIUS possible in the meantime? This is a must have feature for me for access switches.

Thanks!
by Paradox
Fri Dec 17, 2021 12:35 pm
Forum: Scripting
Topic: Remove all firewall settings before import
Replies: 5
Views: 9677

Re: Remove all firewall settings before import

Thanks, that one works!
by Paradox
Fri Dec 17, 2021 9:06 am
Forum: Scripting
Topic: Remove all firewall settings before import
Replies: 5
Views: 9677

Re: Remove all firewall settings before import

Thanks! But sorry, I've fogot to mention that I've already tried this one:
/ip firewall filter remove [find]
But it gives the error
failure: cannot remove builtin
and does not remove any rules.

I guess this is because of rule 0, which is a builtin rule for fasttrack.
by Paradox
Thu Dec 16, 2021 5:08 pm
Forum: Scripting
Topic: Remove all firewall settings before import
Replies: 5
Views: 9677

Remove all firewall settings before import

Hi,
I want to sync my firewall settings from one VRRP router to another. Therefore I'm exporting the rules with
/ip firewall export file=firewallrules
. But before import on the second router I have to wipe out all firewall settings. How could I do this?
by Paradox
Wed Dec 15, 2021 10:46 pm
Forum: General
Topic: VRRP, VLAN and firewall rules
Replies: 3
Views: 1202

Re: VRRP, VLAN and firewall rules

I've indeed missed this... :oops: And it makes so much sense! Thanks!
by Paradox
Wed Dec 15, 2021 6:46 pm
Forum: General
Topic: VRRP, VLAN and firewall rules
Replies: 3
Views: 1202

Re: VRRP, VLAN and firewall rules

I guess this is caused because the route list has a dynamic route entry for each interface: vlan62 and vrrp62 which cannot be deactivated nor deleted. A possible workaround: Use the mangle rules to add a mark to all packets matching vlan62 and vrrp62. On the filter table use this mark instead of the...
by Paradox
Wed Dec 15, 2021 6:33 pm
Forum: General
Topic: VRRP, VLAN and firewall rules
Replies: 3
Views: 1202

VRRP, VLAN and firewall rules

Hello, I'm running 2 VRRP routers, that have some VLANS configured. See the interfaces: mikro-interfaces.png But now I've got a problem when setting up firewall rules. In the forward chain I'm trying to match against the output interface (which actually should be vrrp62), but I've noticed that some ...
by Paradox
Wed Dec 15, 2021 1:06 pm
Forum: General
Topic: Packets failing to match established firewall rule [SOLVED]
Replies: 11
Views: 8160

Re: Packets failing to match established firewall rule [SOLVED]

Hi, did you figure out what was going wrong? I've run into a similar situation: I've exported my firewall rules on router A and imported them on router B. While everything seems to be fine on router A, on router B no packages get the established/related state. Package counters stay at 0. If I add a ...
by Paradox
Tue Oct 19, 2021 6:18 pm
Forum: General
Topic: Allow WinBox broadcast on WAN interface
Replies: 6
Views: 4839

Re: Allow WinBox broadcast on WAN interface

BTW: MNDP was the right keyword 8)

For this to work you need:
* allow inbound traffic on UDP port 5678
* enable ip->neighbors->discovery on WAN or all interfaces (I was missing this)

Of course you also need to allow WinBox traffic to TCP 8291, too.
by Paradox
Tue Oct 19, 2021 6:03 pm
Forum: General
Topic: Allow WinBox broadcast on WAN interface
Replies: 6
Views: 4839

Re: Allow WinBox broadcast on WAN interface

I guess @OP is trying to get MNDP working on WAN interface. Which is IMO very stupid idea, but @OP might have a valid reason for doing it (e.g. in block of flats, every flat has its own MT router managed by landlord via WAN interface). Actually it's something like this. The WAN interfaces of severa...
by Paradox
Mon Oct 18, 2021 10:51 am
Forum: General
Topic: Allow WinBox broadcast on WAN interface
Replies: 6
Views: 4839

Allow WinBox broadcast on WAN interface

Hi,

I've setup a router with quick setup and I'd like to allow the WinBox broadcast messages on the WAN interface, so that the router automatically can be found.

I've tried to allow inbound UDP traffic to port 5678, but still the router cannot be found in WinBox. What else do I have to do?

Thanks!
by Paradox
Fri Oct 15, 2021 3:53 pm
Forum: General
Topic: Feature Request: Ed25519 SSH keys
Replies: 57
Views: 22338

Re: Feature Request: Ed25519 SSH keys

Hi,

I'd like to use Ed25519 SSH keys, too. I do not use any other key formats anymore.

Please add it!