Community discussions

MikroTik App

Search found 94 matches

by An5teifo
Sun Oct 27, 2024 6:11 pm
Forum: Containers
Topic: Edit mounted container file
Replies: 3
Views: 248

Re: Edit mounted container file

Okay so scp will work for me.
I have intially created regular folders via "Files" and added my content but then I was not able to start the container with the folders as volume mounts.
by An5teifo
Sun Oct 27, 2024 9:34 am
Forum: Containers
Topic: Edit mounted container file
Replies: 3
Views: 248

Edit mounted container file

Hello there, I wonder how someone could edit various config files for a container with a persistent volume? E.g. I would like to run Knot DNS but for this I would need to create a zone file with my settings. On my regular linux docker machine I could either edit the file directly at the shell (nano ...
by An5teifo
Tue Apr 02, 2024 9:42 am
Forum: General
Topic: xz Backdoor CVE-2024-3094 [SOLVED]
Replies: 23
Views: 51224

Re: xz Backdoor CVE-2024-3094 [SOLVED]

I also thought that RouterOS is not affected by this version but it makes sense if any CISO or other IT-related staff got the order to query if any product of MikroTik is vulnerable or not.

That's why it make sense from my point of view to highlight "we are not vulernable".
by An5teifo
Tue Apr 02, 2024 9:33 am
Forum: General
Topic: xz Backdoor CVE-2024-3094 [SOLVED]
Replies: 23
Views: 51224

Re: xz Backdoor CVE-2024-3094 [SOLVED]

Great to hear.
Maybe this topic can be pinned somewhere for the next couple of days/weeks if someone else is raising this question?
by An5teifo
Tue Apr 02, 2024 9:14 am
Forum: General
Topic: xz Backdoor CVE-2024-3094 [SOLVED]
Replies: 23
Views: 51224

xz Backdoor CVE-2024-3094 [SOLVED]

Can someone confirm if MikroTik devices are vulnerable to the current SSH backdoor?
See here https://openssf.org/blog/2024/03/30/xz- ... 2024-3094/.

Althought the malware scans for .rpm or .deb packages in general it would be a good to know if MikroTiks SSH server relys on liblzma or not.
by An5teifo
Wed Mar 06, 2024 2:48 pm
Forum: Forwarding Protocols
Topic: OPSF loop
Replies: 1
Views: 744

Re: OPSF loop

I think I fixed it by setting different costs for interface pointing to CCR2004 and CCR2116
by An5teifo
Wed Mar 06, 2024 2:21 pm
Forum: Forwarding Protocols
Topic: OPSF loop
Replies: 1
Views: 744

OPSF loop

Hello everyone, I stumbled accross a weird routing behaviour on my network. In general my network is: Mikrotik CCR2004 as internet & VPN router connected to 2x OPNsense which are connected to a Mikrotik CCR2116 as my network router. As a failover my CCR2004 is also direct to CCR2116 but with hig...
by An5teifo
Mon Jan 29, 2024 1:05 pm
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 296
Views: 85775

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

I think I found the issue: Your script requires a "total" value after the fetch command. Currently it is not being included at "as-value": downloaded=26;duration=00:00:00;status=finished Hiiiiii, could you share the whole script pls ? thx You can find it here -> https://forum.mi...
by An5teifo
Tue Jan 23, 2024 9:23 pm
Forum: Announcements
Topic: v7.14beta [testing] is released!
Replies: 510
Views: 169243

Re: v7.14beta [testing] is released!

It seems that
/tool fetch
does no longer include a "total" value - only "downloaded".
Is this expeded/hidden feature or a bug?
by An5teifo
Tue Jan 23, 2024 9:18 pm
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 296
Views: 85775

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

Which script are you have been using? I'm using a modified version of this one https://forum.mikrotik.com/viewtopic.php?p=935938&sid=9a9086e98c872089e19fd57de7aba7ed#p935938 I think I found the issue: Your script requires a "total" value after the fetch command. Currently it is not be...
by An5teifo
Tue Jan 23, 2024 8:26 pm
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 296
Views: 85775

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

I have tried the script you've mentioned with the today released 7.14beta8 version - it still does not work. Is there a possibility to debug a script to see where the error occurs? So far I just removed the "nolog" parameter but the only thing I get is Starting import of address-list: spam...
by An5teifo
Tue Jan 23, 2024 9:23 am
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 296
Views: 85775

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

The other, more modern script does not work on me as I get the integer error. I'm skipping v7.13, going see what changes v7.14 and maybe v7.15 bring and then take a look at fixing the script after that, since fetch is mentioned in the beta changelog. v7.12 is fine for my networks, what I needed in ...
by An5teifo
Mon Jan 22, 2024 9:57 pm
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 296
Views: 85775

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

It just removes the entries with a specific comment
find where comment=$description dynamic]
The other, more modern script does not work for me as I get the integer error.
by An5teifo
Sun Jan 21, 2024 6:16 pm
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 296
Views: 85775

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

I found this script on the forum. It works OK on my hEX S running 7.13.2. The only change I've made was to concentrate all entries on a single "blacklist" and select the entries via the comment field. MH :global readfile do={ :local url $1 :local thefile "" :local filesize ([/to...
by An5teifo
Sun Jan 21, 2024 11:33 am
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 296
Views: 85775

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

Yes, I tried that as well.
I just received the same error messages as you @kevinds
by An5teifo
Sun Jan 21, 2024 10:13 am
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 296
Views: 85775

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

I just upgraded to 7.14beta7 to verify if fetch is working for this but it does not.
by An5teifo
Wed Jan 10, 2024 9:53 am
Forum: General
Topic: Looking for a router for 10 Gigabit
Replies: 1
Views: 643

Looking for a router for 10 Gigabit

Hello forum, after playing around with some virtual router/firewall I would like to step back to have a physical device in case my servers are down due to what ever reason. Some background: I am a prosumer running 10 Gigabit network at home and managing the IT of friends and family - so nothing miss...
by An5teifo
Mon Jan 08, 2024 9:36 am
Forum: General
Topic: Special routing
Replies: 9
Views: 2660

Re: Special routing

Thanks for the info. In general I am already using a CRS312-4C+8XG-RM as my core switch where my Proxmox servers are connected via a LACP bond. So far they work pretty well but as I would need also some firewall rules like DMZ-VLAN is not allowed to access some hosts from other VLANs this switch wou...
by An5teifo
Mon Jan 08, 2024 9:24 am
Forum: General
Topic: Special routing
Replies: 9
Views: 2660

Re: Special routing

So best would be to either leave as it is or get another router for VLAN routing?
by An5teifo
Mon Jan 08, 2024 8:59 am
Forum: General
Topic: Special routing
Replies: 9
Views: 2660

Re: Special routing

The only reason why I need to use OPNsense is IDS/IPS via Suricata and some Geoblocking to keep those Asian bots out of my network
by An5teifo
Sun Jan 07, 2024 10:14 pm
Forum: General
Topic: Special routing
Replies: 9
Views: 2660

Re: Special routing

CCR is responsible for my VPN tunnels, NAT/portforwarding, WAN traffic in general.

I am using it as my ISP only allows one MAC address on the interface. OPNsense in HA does not do that and I had troubles with that.
by An5teifo
Sun Jan 07, 2024 8:22 pm
Forum: General
Topic: Special routing
Replies: 9
Views: 2660

Re: Special routing

Anyone any idea?
I tried to play around with VRF but unfortunately when enabling any VRF I am no longer able to reach other devices (either devices via VPN or OPNsense itself)
by An5teifo
Sun Jan 07, 2024 12:18 am
Forum: General
Topic: CRS312 gets to 100 % CPU
Replies: 14
Views: 2805

Re: CRS312 gets to 100 % CPU

I think I finally found the trouble maker: As I use two OPNsense in HA configuration they syncronise each and every connection state so if a OPNsense goes down the other can take over immediately without any downtime. The setting is called "Synchronize Peer IP" and its default value is dir...
by An5teifo
Sat Jan 06, 2024 12:26 pm
Forum: General
Topic: CRS312 gets to 100 % CPU
Replies: 14
Views: 2805

Re: CRS312 gets to 100 % CPU

Another interessting fact: Even if I tell iperf3 to only use 1 thread the switch CPU goes up to 100 % PS E:\Users\mmuehlbacher\Downloads\iperf-3.1.3-win64> .\iperf3.exe -P 1 -c db1.hks.lan -t 60 Connecting to host db1.hks.lan, port 5201 [ 4] local 192.168.10.12 port 63031 connected to 192.168.20.97 ...
by An5teifo
Sat Dec 23, 2023 10:37 am
Forum: General
Topic: CRS312 gets to 100 % CPU
Replies: 14
Views: 2805

Re: CRS312 gets to 100 % CPU

The switch just discovers some broadcast packages when running at 100 %: [mathias@Switch-CRS312] /tool/sniffer> packet/print Columns: TIME, INTERFACE, SRC-ADDRESS, DST-ADDRESS, IP-PROTOCOL, SIZE, CPU # TIME INTERFACE SRC-ADDRESS DST-ADDRESS IP-PROTOCOL SIZE CPU 0 14.692 Mathias-Desktop 192.168.10.12...
by An5teifo
Fri Dec 22, 2023 4:02 pm
Forum: General
Topic: CRS312 gets to 100 % CPU
Replies: 14
Views: 2805

Re: CRS312 gets to 100 % CPU

With regards to 1/2 bandwith: Initially I do get 6.5 Gbit sometimes.
by An5teifo
Fri Dec 22, 2023 2:52 pm
Forum: General
Topic: CRS312 gets to 100 % CPU
Replies: 14
Views: 2805

Re: CRS312 gets to 100 % CPU

Thanks for the marvelous packetflow drawing - this is exactly how I imagine it. I was able to check CRS312 hosts database on the bridge interface and both Mathias-Desktop as well as the VMs MAC address are known by the bridge. Unfortunately sniffing packages do not work as the bridge is hw-offloaded...
by An5teifo
Fri Dec 22, 2023 1:34 pm
Forum: General
Topic: CRS312 gets to 100 % CPU
Replies: 14
Views: 2805

Re: CRS312 gets to 100 % CPU

I have already removed VLAN10 from the port configuration. I had initally added it due to the message the VLAN10 is not a port member of the bridge which was resolved by your last information. In general all interfaces are hardware offloaded: [mathias@Switch-CRS312] > interface/bridge/port/print Fla...
by An5teifo
Fri Dec 22, 2023 1:14 pm
Forum: General
Topic: CRS312 gets to 100 % CPU
Replies: 14
Views: 2805

Re: CRS312 gets to 100 % CPU

Thanks for the info - I have done that but the CPU goes up to 100 % CPU immediately: [mathias@Switch-CRS312] > /tool/profile Columns: NAME, USAGE NAME USAGE ethernet 5% console 1% ssh 0.5% networking 49.5% winbox 0% management 1.5% routing 0% profiling 0% bridging 36.5% unclassified 6% total 100% So...
by An5teifo
Fri Dec 22, 2023 12:10 pm
Forum: General
Topic: CRS312 gets to 100 % CPU
Replies: 14
Views: 2805

Re: CRS312 gets to 100 % CPU

I disabled it as I only want to do L2 traffic but I already reenabled it - although result is the same nevertheless if L3 hw offloading is on or off.
by An5teifo
Wed Dec 20, 2023 1:33 pm
Forum: General
Topic: CRS312 gets to 100 % CPU
Replies: 14
Views: 2805

CRS312 gets to 100 % CPU

Hello everyone, I am using a CRS312-4C+8XG as my main switch. It is connected to two Proxmox servers via LACP. On my Proxmox servers I run an OPNsense appliance for firewalling and intervlan routing. I recently stumbled accross a strange behaviour regarding switching traffic: If I run iperf3 within ...
by An5teifo
Tue Dec 19, 2023 2:16 pm
Forum: General
Topic: CCR2004 bridge performance
Replies: 5
Views: 4714

Re: CCR2004 bridge performance

I already found the issue: QoS - I set an upload limit for 80M as this is my general WAN uplink.
As I added my other VLAN interfaces to the bridge I was not able to bypass the 80M limit.
by An5teifo
Tue Dec 19, 2023 11:40 am
Forum: General
Topic: CCR2004 bridge performance
Replies: 5
Views: 4714

Re: CCR2004 bridge performance

As a side note: Doing VLAN routing on CCR2004 does not generate 100 % on any CPU core.
One core is usually at around 25 %
by An5teifo
Tue Dec 19, 2023 11:30 am
Forum: General
Topic: CCR2004 bridge performance
Replies: 5
Views: 4714

Re: CCR2004 bridge performance

The current config would be below. Kindly note that at the moment I am using OPNsense as VLAN router (temporarily) until the low bridge performance on CCR2004 is fixed. # 2023-12-19 10:26:44 by RouterOS 7.13 # software id = 7092-YU0E # # model = CCR2004-16G-2S+ # serial number = ABC123 /interface br...
by An5teifo
Tue Dec 19, 2023 11:05 am
Forum: General
Topic: CCR2004 bridge performance
Replies: 5
Views: 4714

CCR2004 bridge performance

Hello, I currently testing a CCR2004-16G-S2+ for VLAN routing. The switch is connected via SFP+ ports (trunked) to a CRS326 & CSS326 switch (CRS326 is root bridge). Current CCR2004 config would be: [mathias@IBR] > /interface/bridge/print Flags: X - disabled, R - running 0 R name="bridge1&qu...
by An5teifo
Mon Dec 18, 2023 10:45 am
Forum: General
Topic: Special routing
Replies: 9
Views: 2660

Special routing

Hello there, I am using a CCR2004 router as my main internet router. Right behind it I am running two virtual OPNsense firewalls in HA mode which are also doing my inter VLAN routing. All devices share the network informations via OSPF in a single area (0.0.0.0). As the inter VLAN routing performanc...
by An5teifo
Mon Feb 27, 2023 2:02 pm
Forum: Useful user articles
Topic: IPS/IDS with SELK
Replies: 23
Views: 14071

Re: IPS/IDS with SELK

I also agree on that and it's important to only open ports to the internet which are needed and to keep any software up-to-date. Nevertheless it's also a good option to have another layer of security (if you have the ressources) to run it. I just thought that I mention it a the useful articles - I d...
by An5teifo
Mon Feb 27, 2023 1:54 pm
Forum: Useful user articles
Topic: IPS/IDS with SELK
Replies: 23
Views: 14071

Re: IPS/IDS with SELK

Yeah I know that but leaving an SQL port open vs SQL injection via HTTP are two different pairs of topic. If someone leaves something open without any usecase it is not good. But if you have a regular webserver you would need port 80 & 443 open to the web - and there are also the bad guys how tr...
by An5teifo
Mon Feb 27, 2023 1:47 pm
Forum: Useful user articles
Topic: IPS/IDS with SELK
Replies: 23
Views: 14071

Re: IPS/IDS with SELK

Do you guys understand the usecase of an IDS/IPS or are you just bashing on this topic because you have some free time?
by An5teifo
Mon Feb 27, 2023 1:38 pm
Forum: Useful user articles
Topic: IPS/IDS with SELK
Replies: 23
Views: 14071

Re: IPS/IDS with SELK

It not blocks traffic based on invalid TCP, UDP, whatever - it blocks traffic from e.g. known bad hosts automatically. Also it does deep inspection and stops any malicous traffic which you in general would allow on a firewall level - e.g. TCP/443 for you webserver. If a bad bot would like to try som...
by An5teifo
Mon Feb 27, 2023 10:35 am
Forum: Useful user articles
Topic: IPS/IDS with SELK
Replies: 23
Views: 14071

Re: IPS/IDS with SELK

SELKS is an IDS/IPS while T-Pot is a Honeypot
by An5teifo
Wed Feb 22, 2023 2:35 pm
Forum: Announcements
Topic: v7.8rc is released!
Replies: 125
Views: 48273

Re: v7.8rc is released!

Unfortunately RC3 still did not solve SUP-107271.
by An5teifo
Mon Feb 20, 2023 10:54 am
Forum: Useful user articles
Topic: IPS/IDS with SELK
Replies: 23
Views: 14071

Re: IPS/IDS with SELK

Please note it's not my GitHub repository - I just mentioned it as I used it as a guidline for installing.
From my point of view it looks like that you are using wrong paths and therefore the application cannot find them.
by An5teifo
Sun Feb 19, 2023 10:58 pm
Forum: Useful user articles
Topic: IPS/IDS with SELK
Replies: 23
Views: 14071

Re: IPS/IDS with SELK

I run mine on Debian 11 - how did you install it?
Just run the easyinstall.sh script?
by An5teifo
Sun Feb 19, 2023 10:29 pm
Forum: Useful user articles
Topic: IPS/IDS with SELK
Replies: 23
Views: 14071

Re: IPS/IDS with SELK

Which OS are you using?
by An5teifo
Sun Feb 19, 2023 11:22 am
Forum: Useful user articles
Topic: IPS/IDS with SELK
Replies: 23
Views: 14071

Re: IPS/IDS with SELK

Have you verified that all containers are up and running? It seems that Suricata is not running. If you enter sudo docker ps it should display something like: CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES d40a1db11567 jasonish/suricata:master-amd64 "/etc/suricata/new_e…" 10 days ag...
by An5teifo
Fri Feb 17, 2023 7:47 am
Forum: Announcements
Topic: v7.8rc is released!
Replies: 125
Views: 48273

Re: v7.8rc is released!

I am having troubles with OSPF IPv6. If I just announce regular routes via a passive interface only a few are being seen by the other routers. Currently I need to stick with redistribute connected. Also packet sniffer slows down my IPv6 speed dramatically (off ~150 Mbit, on ~ some kbits) but only on...
by An5teifo
Tue Feb 14, 2023 1:54 pm
Forum: Beginner Basics
Topic: VLAN doesn´t access to WAN
Replies: 2
Views: 581

Re: VLAN doesn´t access to WAN

From a quick view I think you messed up with src-nat /ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade" disabled=yes \ ipsec-policy=out,none out-interface-list=WAN add action=masquerade chain=srcnat disabled=yes src-address=192.168.1.0/24 add action=masquerad...
by An5teifo
Fri Feb 10, 2023 10:46 pm
Forum: General
Topic: IPv6 firewall rules [SOLVED]
Replies: 11
Views: 3368

Re: IPv6 firewall rules [SOLVED]

Thank you both.
I completly reworked firewall rules on all of my Mikrotik routers with dedicated chains (which makes more sense if you know this nice feature).

So far everything works well and I haven't seen any issues.
by An5teifo
Fri Feb 10, 2023 3:51 pm
Forum: General
Topic: IPv6 firewall rules [SOLVED]
Replies: 11
Views: 3368

Re: IPv6 firewall rules [SOLVED]

Thanks for clarification!
As I used an OPNsense firewall before I am still learning what is best practice on Mikrotik
by An5teifo
Fri Feb 10, 2023 3:39 pm
Forum: Beginner Basics
Topic: routing all networks to specific server ip
Replies: 2
Views: 422

Re: routing all networks to specific server ip

Can you also share your current firewall settings?
by An5teifo
Fri Feb 10, 2023 3:33 pm
Forum: Beginner Basics
Topic: Firewall ether1 - pppoe - vlan7
Replies: 4
Views: 885

Re: Firewall ether1 - pppoe - vlan7

I would add all untrusted interfaces into a dedicated list e.g. WAN.
by An5teifo
Fri Feb 10, 2023 3:27 pm
Forum: Virtualization
Topic: CHR on Hyper-V and ZeroTier Networks
Replies: 11
Views: 5853

Re: CHR on Hyper-V and ZeroTier Networks

Hello there,

as a side note: I am running a virtualized x86 ROS on Proxmox (=KVM/QEMU).
Zerotier addon would be available.
by An5teifo
Fri Feb 10, 2023 2:58 pm
Forum: General
Topic: IPv6 firewall rules [SOLVED]
Replies: 11
Views: 3368

Re: IPv6 firewall rules [SOLVED]

Thanks for clarification.
I think I managed it for IPv6 now thanks to you!

May I additional just ask: Does it make sense to also create a dedicated jump-rule for IPv4 addresses?
by An5teifo
Fri Feb 10, 2023 1:18 pm
Forum: General
Topic: IPv6 firewall rules [SOLVED]
Replies: 11
Views: 3368

Re: IPv6 firewall rules [SOLVED]

Just a further question: Wouldn't it be better to drop any non allowed traffic instead of rejecting it?
by An5teifo
Fri Feb 10, 2023 12:58 pm
Forum: General
Topic: IPv6 firewall rules [SOLVED]
Replies: 11
Views: 3368

Re: IPv6 firewall rules [SOLVED]

Thanks @ConradPino I will start my journey with your suggestions!
by An5teifo
Fri Feb 10, 2023 8:04 am
Forum: Announcements
Topic: v7.8beta [testing] is released!
Replies: 307
Views: 82435

Re: v7.8beta [testing] is released!

Not sure if this is relevant on 7.8 beta but one of my Wireguard peers is not working after a router reboot. I need to disable and reenable the peer manually to get it running.
by An5teifo
Thu Feb 09, 2023 10:08 pm
Forum: General
Topic: IPv6 firewall rules [SOLVED]
Replies: 11
Views: 3368

Re: IPv6 firewall rules [SOLVED]

Because I have several VLANs where I would like to only allow specific hosts/ports.

Mikrotiks default firewall rules are more into WAN/LAN but not for LAN#1 LAN#2 and so on
by An5teifo
Thu Feb 09, 2023 7:21 pm
Forum: General
Topic: IPv6 firewall rules [SOLVED]
Replies: 11
Views: 3368

IPv6 firewall rules [SOLVED]

Hello everyone, I recently tried to implement some proper firewall rules for IPv6 by copying my currently existing and working IPv4 firewall rules. But somehow it's not working really working. My network consists of several VLANs to separate traffic from management LAN, DMZ, IoT and so on and I do o...
by An5teifo
Thu Feb 09, 2023 5:29 pm
Forum: Announcements
Topic: MikroTik Devices Controller
Replies: 374
Views: 258305

Re: MikroTik Devices Controller

1) Centralized firewall management
2) Grouped device management (e.g. multiple devices can be at one group and I only need to create firewall rules for this group)
3) Updates
4) Scripting - either on specific devices or a central API endpoint for REST request.
by An5teifo
Thu Feb 09, 2023 2:52 pm
Forum: General
Topic: Speed IPv6 with Packet Sniffer
Replies: 0
Views: 410

Speed IPv6 with Packet Sniffer

Dear forum, I am running a CCR2004-16G-2S+ as my main internet router. As my local ISP only provide IPv4 addresses I have some tunnels to other ISPs with different technologies (GRE, SIT, EoIP, VXLAN). So far everything works properly and I get my usual expected up- & download speed (300/40 for ...
by An5teifo
Thu Feb 09, 2023 2:41 pm
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1235237

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

Hello there,

yesterday I installed SELKS and connected it with my Mikrotik --> viewtopic.php?t=193417
by An5teifo
Thu Feb 09, 2023 2:26 pm
Forum: Beginner Basics
Topic: VRRP and VLANs on bridge - possible?
Replies: 5
Views: 1908

Re: VRRP and VLANs on bridge - possible?

Its quiet simple: Bridge <-- VLAN <-- VRRP To be more detailed. You create a bridge and VLANs (via interface). On IP/Address you can assign a specific IP address AND network to a VLAN. Additional you need to add the VLAN on the bridge interface as tagged (+ the bridge itself). For a VRRP you need to...
by An5teifo
Thu Feb 09, 2023 2:21 pm
Forum: Beginner Basics
Topic: Need help with CCR2004 and wifi
Replies: 1
Views: 337

Re: Need help with CCR2004 and wifi

You can do this via RADIUS.
RouterOS has a specific version of it called "User Manager" --> https://help.mikrotik.com/docs/display/ROS/User+Manager
by An5teifo
Wed Feb 08, 2023 4:07 pm
Forum: Useful user articles
Topic: IPS/IDS with SELK
Replies: 23
Views: 14071

IPS/IDS with SELK

Dear forum, as I recently migrated from OPNsense fully to Mikrotik I had some concerns as there is no IDS/IPS native available on Mikrotik - but luckily the internet has some solutions which I implemented and where I would like to share some tips and tricks with you: I found a GitHub project called ...
by An5teifo
Tue Feb 07, 2023 1:30 pm
Forum: General
Topic: VRRP issues [SOLVED]
Replies: 4
Views: 931

Re: VRRP issues [SOLVED]

It seems I had some misconfiguration/understood the settings wrong. I only set all other VRRP interfaces to the master but I did not configure the master to be itself group master. With this setting it works far better. And I also unticked the "Preemption Mode" setting. So now from a netwo...
by An5teifo
Tue Feb 07, 2023 12:50 pm
Forum: General
Topic: VRRP issues [SOLVED]
Replies: 4
Views: 931

Re: VRRP issues [SOLVED]

Thanks for the information.
In general I am using the group master feature, sync connection state and preemption mode on master.
Additional I am also using a script which adds OSPF costs to 65000 on the backup node so all traffic would be routed via the master router to my main internet router.
by An5teifo
Tue Feb 07, 2023 10:23 am
Forum: General
Topic: VRRP issues [SOLVED]
Replies: 4
Views: 931

VRRP issues [SOLVED]

Hello everyone, I already raised a ticket at support but would also like to see if anyone has also a clue what could be wrong: I am currently migrating from virtualized OPNsense to virtualized x86 ROS. So far the setup works pretty well but I am struggeling a lot with VRRP. In general I have several...
by An5teifo
Mon Jan 30, 2023 7:26 pm
Forum: Forwarding Protocols
Topic: BGP filtering [SOLVED]
Replies: 20
Views: 8724

Re: BGP filtering [SOLVED]

No in general I only have one ISP but it is only providing my an IPv4 address.
I am connected to several tunnelbroker, vIXP etc. which all uses different types of tunneling (GRE, EoIP, VXLAN, SIT).

So far I did not see any issues on that.
by An5teifo
Mon Jan 30, 2023 5:20 pm
Forum: Forwarding Protocols
Topic: BGP filtering [SOLVED]
Replies: 20
Views: 8724

Re: BGP filtering [SOLVED]

I am just someone who is new to BGP and peering with others.
by An5teifo
Mon Jan 30, 2023 5:16 pm
Forum: Forwarding Protocols
Topic: BGP filtering [SOLVED]
Replies: 20
Views: 8724

Re: BGP filtering [SOLVED]

Behind my Mikrotik I am running a dedicated firewall.
Access to Mikrotik is only granted from a specific IP range.

Why shouldn't there be any additional service running on the router?
by An5teifo
Mon Jan 30, 2023 5:01 pm
Forum: Forwarding Protocols
Topic: BGP filtering [SOLVED]
Replies: 20
Views: 8724

Re: BGP filtering [SOLVED]

Thanks for that. From a firewall perspective I am already pretty solid.
I just recently received my own ASN and try to figure out any best practice rules for peering with others via BGP.
by An5teifo
Mon Jan 30, 2023 2:48 pm
Forum: Forwarding Protocols
Topic: BGP filtering [SOLVED]
Replies: 20
Views: 8724

Re: BGP filtering [SOLVED]

But e.g. on input I do currently have also
if ( dst-len > 48 ) { accept }
rule for IPv6.
With such a rule I would also filter some routable IPv4 ranges - wouldn't I?

If so it would make sense to create to different chains - 1x v4 & 1x v6
by An5teifo
Mon Jan 30, 2023 2:15 pm
Forum: Forwarding Protocols
Topic: BGP filtering [SOLVED]
Replies: 20
Views: 8724

Re: BGP filtering [SOLVED]

So should I create two generell in/output filters?
One for IPv4 and one for IPv6?
by An5teifo
Mon Jan 30, 2023 1:55 pm
Forum: Forwarding Protocols
Topic: BGP filtering [SOLVED]
Replies: 20
Views: 8724

Re: BGP filtering [SOLVED]

Okay from this perspective I agree.

Are there any general recommondation regarding BGP in-filtering as I came accross some input that accepting anything is not always the best solution?
by An5teifo
Mon Jan 30, 2023 12:28 pm
Forum: Forwarding Protocols
Topic: BGP filtering [SOLVED]
Replies: 20
Views: 8724

Re: BGP filtering [SOLVED]

Isn't a bit weird?
If I set a filter the default is being reject anything - if I do not set a filter (leaving it blank) everything would be accepted?!
by An5teifo
Mon Jan 30, 2023 11:42 am
Forum: Forwarding Protocols
Topic: BGP filtering [SOLVED]
Replies: 20
Views: 8724

Re: BGP filtering [SOLVED]

Hello felixhappy,

I thought that on ROS 7 the default filter mechanism is to deny any?
by An5teifo
Thu Jan 26, 2023 3:36 pm
Forum: Forwarding Protocols
Topic: BGP filtering [SOLVED]
Replies: 20
Views: 8724

BGP filtering [SOLVED]

Hello there, as I am very new to BGP and it's filtering mechanism I would like out to get some help: What would be the right filter for an - input "Any route that you send me I will accept" - output "I only send you my biggest /40 subnet but not the /48 & /64 subnets which I split...
by An5teifo
Mon Jan 23, 2023 2:23 pm
Forum: Forwarding Protocols
Topic: BGP announce /48 subnet
Replies: 2
Views: 2251

Re: BGP announce /48 subnet

Okay got it

Outbound filter like
if (dst==own address/48) {accept}
by An5teifo
Mon Jan 23, 2023 1:55 pm
Forum: Forwarding Protocols
Topic: BGP announce /48 subnet
Replies: 2
Views: 2251

BGP announce /48 subnet

Hello everyone, I just took my 1st steps to BGP and want to announce my /48 IPv6 subnet to my BGP peer. So far I only found the ability to announce "connected" which includeds this subnets but also my splitted /64 subnets. Is there any possiblity to announce only the "big" /48 su...
by An5teifo
Fri Jan 20, 2023 12:36 pm
Forum: General
Topic: IPv6 routing
Replies: 3
Views: 1089

IPv6 routing

Hello everyone, crossposting my Reddit question also here: as my ISP does not provide any IPv6 connectivity but still wanted to have it I rented a cloud server and deployed a CHR image from Mikrotik. The cloud server provides a /64 public routable address but set the default gateway to fe80::/1 via ...
by An5teifo
Mon Apr 25, 2022 9:15 pm
Forum: General
Topic: Wireguard failover (?)
Replies: 14
Views: 2480

Re: Wireguard failover (?)

Seems that this was the issue: I don't know why or how but it seems my HQ acted as a client (and not as the server) for wireguard connection.
Now, after I have removed the preconfigured port from Wireguard peer on MT remote it works as expected.
by An5teifo
Mon Apr 25, 2022 7:35 pm
Forum: General
Topic: Wireguard failover (?)
Replies: 14
Views: 2480

Re: Wireguard failover (?)

It seemed that my OPNsense fw has established a connection with my remote side via a NAT.
I removed the prefilled Wireguard listen-port and let it choose a new random one and after that the connection looks like an incoming VPN client-> server connection which I expect.
by An5teifo
Mon Apr 25, 2022 7:13 pm
Forum: General
Topic: Wireguard failover (?)
Replies: 14
Views: 2480

Re: Wireguard failover (?)

What is also strange:

On my internet border router (= HQ) I cannot see any connections going to the dst port?!
Althought wireguard VPN is up and running and hosts can ping each other.

It's a bit weird?
by An5teifo
Mon Apr 25, 2022 6:42 pm
Forum: General
Topic: Wireguard failover (?)
Replies: 14
Views: 2480

Re: Wireguard failover (?)

Sounds like an HA setup issue. Is there some mac address change somewhere?? If there is no change to destination port or IP address, and if the HQ MT WANIP stays up, not sure what can be done at the client side ??? I am also not sure - from a WAN perspective even the MAC address stays the same as a...
by An5teifo
Mon Apr 25, 2022 6:21 pm
Forum: General
Topic: Wireguard failover (?)
Replies: 14
Views: 2480

Re: Wireguard failover (?)

Try more details. Is it client to server (= remote is behind NAT and HQ needs to wait until it connects) or peer to peer (any side can initialize connection to the other)? What exactly happens on failover? Does the second machine come up with same IP address and WG listening on same port? If so, it...
by An5teifo
Mon Apr 25, 2022 5:08 pm
Forum: General
Topic: Wireguard failover (?)
Replies: 14
Views: 2480

Re: Wireguard failover (?)

@anav: May I ask, where to place/use such a script as you have mentioned at para 6?
by An5teifo
Mon Apr 25, 2022 2:52 pm
Forum: General
Topic: Wireguard failover (?)
Replies: 14
Views: 2480

Re: Wireguard failover (?)

Hmm maybe something like
"ping 5x" if no ping then restart Wireguard service.

I did not know how to do this via SSH so I just disabled the Wireguard interface and enabled it again but that did not solve my issue.
by An5teifo
Mon Apr 25, 2022 2:35 pm
Forum: General
Topic: Wireguard failover (?)
Replies: 14
Views: 2480

Re: Wireguard failover (?)

I am not sure if this might be my reason as I am using a static IP address which is being terminated on my HQ Mikrotik router.
No hostname or dynamic hostnames are being used.
by An5teifo
Mon Apr 25, 2022 11:51 am
Forum: General
Topic: Wireguard failover (?)
Replies: 14
Views: 2480

Wireguard failover (?)

Hello everyone, I recently rebuild my local network and my remote network: HQ: ISP -> Mikrotik (internet border router) -> 2x OPNsense as HA configuration with CARP -> LAN Remote: ISP -> Mikrotik -> LAN On both places I am using Wireguard as VPN connection and so far it works pretty out of the box. ...
by An5teifo
Fri Dec 31, 2021 6:45 pm
Forum: Beginner Basics
Topic: Different WLAN with CAPsMAN
Replies: 2
Views: 2787

Re: Different WLAN with CAPsMAN

Thanks for the advice - I already found help on Reddit.
The thing in general is that I do not need a very high bandwith as only my mobile phone + sometimes a laptop is connected to it.
I just wanted to have a 2.4 & 5 GHz within one device and the regular disk APs were already sold-out on Amazon.
by An5teifo
Fri Dec 17, 2021 10:15 pm
Forum: Wireless Networking
Topic: CAPsMAN 2.4 & 5 GHz same SSID [SOLVED]
Replies: 1
Views: 4034

CAPsMAN 2.4 & 5 GHz same SSID [SOLVED]

Hello there, I recently moved from Unifi to Mikrotiks Audience and run the Wifi via CAPsMAN. What is a bit weird to me is, if setup just SSIDs with authentication (like for a home AP) I receive any SSID at 2.4 & 5 GHz. As soon as I create a dedicated channel setting and use it for my SSIDs, I on...
by An5teifo
Mon Dec 13, 2021 11:13 am
Forum: Beginner Basics
Topic: Different WLAN with CAPsMAN
Replies: 2
Views: 2787

Different WLAN with CAPsMAN

Hello everyone, I recently decided to replace my last bit of network (Unifi) with Mikrotik Audience for WLAN coverage. Currently I am setting up my 10 Gbase-T switch (CRS312-4C+8XG-RM) to act as my CAPsMAN controller for this an probably another WLAN device. So far I created my three different WLAN ...