Community discussions

MikroTik App

Search found 24 matches

by darklord
Sun Apr 09, 2023 12:17 am
Forum: General
Topic: Kid control + SNMP
Replies: 1
Views: 631

Kid control + SNMP

Hello, is it feasible for mikrotik team to implement snmp interface for kid control function? I want to gather per-user stats from mikrotik into monitoring system, but /ip/kid-control/device/print oid gives me error only. Or at least, give opportunity to display all values in bytes without "mul...
by darklord
Sun Mar 05, 2023 8:19 pm
Forum: General
Topic: Can someone please explain the PSD attributes?
Replies: 7
Views: 14768

Re: Can someone please explain the PSD attributes?

Can somebody explain to me, why my PSD rule is not kicking in with this case? One single IP is trying to connect on closed port tcp/23, I have full logserver of dropped packets, but this rule is not hitting. One significant thing is, that source port for every connection attempt is the same. add act...
by darklord
Mon Feb 27, 2023 2:23 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 425
Views: 149165

Re: v7.8 [stable] is released!

Scripts run count on my CCR2004 is always 0. When I run script from winbox, this counter increases, but once I close and reopen winbox, I have 0 again. ROS 7.7, after update to 7.8 still the same. This is not happening on rb4011, so maybe only related to arm64?
by darklord
Mon Feb 27, 2023 1:55 pm
Forum: General
Topic: CCR2004 - script run count
Replies: 2
Views: 411

Re: CCR2004 - script run count

After upgrade to 7.8 situation is the same, still script run count disapperas after a while. Could somebody with CCR2004-16-1S+ check this - maybe I have HW issue?
by darklord
Thu Feb 23, 2023 10:04 pm
Forum: General
Topic: CCR2004 - script run count
Replies: 2
Views: 411

CCR2004 - script run count

I just realized that scripts run count on my CCR2004 is always 0. When I run script from winbox, this counter increases, but once I close and reopen winbox, I have 0 again. ROS 7.7 stable. This does not happen on RB2011 with same OS version. Am I only one with this error?
by darklord
Wed Feb 22, 2023 12:21 pm
Forum: General
Topic: OpenVPN log spam
Replies: 7
Views: 886

Re: OpenVPN log spam

I have opened support ticket for this, we will see if this is a bug or configuration issue
by darklord
Tue Feb 21, 2023 11:46 am
Forum: General
Topic: OpenVPN log spam
Replies: 7
Views: 886

Re: OpenVPN log spam

I will try to make capture direct on line without TZSP streaming to be completely sure I have not missed anything, and if this is confirmed, I will contact support.
by darklord
Tue Feb 21, 2023 11:37 am
Forum: General
Topic: OpenVPN log spam
Replies: 7
Views: 886

Re: OpenVPN log spam

I have captured this situation now, but it is really suspicious. Looks like RouterOS OpenVPN implementation BUG , because ONLY ONE packet has been received to udp/1194, and 31 packets has been sent back to "attacker" AND 80k LINES were written into log # cat mktk-hostname.log | uniq -c 1 F...
by darklord
Mon Feb 20, 2023 3:28 pm
Forum: General
Topic: OpenVPN log spam
Replies: 7
Views: 886

Re: OpenVPN log spam

It is ~10k lines from same IP in same second. This will not get caught by "connection ratio" as from firewalls point of view its one connection (or udp stream to be precise)
by darklord
Mon Feb 20, 2023 2:53 pm
Forum: General
Topic: OpenVPN log spam
Replies: 7
Views: 886

OpenVPN log spam

Hello, is there any way to block "port scanners" or like, causing floods in my logs? I have openvpn server on 1194/udp, and few times a day I am facing logs like this: Feb 20 13:19:22 mktk-hostname ovpn,info <50.116.31.18>: disconnected <TLS failed> And by flood I mean ~10k same lines in s...
by darklord
Fri Jan 27, 2023 11:40 am
Forum: Beginner Basics
Topic: DHCP vs VLANS
Replies: 23
Views: 2978

Re: DHCP vs VLANS

Great, so its no-problem here. Thanks!
by darklord
Fri Jan 27, 2023 10:59 am
Forum: Beginner Basics
Topic: DHCP vs VLANS
Replies: 23
Views: 2978

Re: DHCP vs VLANS

Is this configuration with bridge port inside VLAN somehow related to security of device, eg exposing some router interface into network? How (and where) should this situation be filtered?
by darklord
Wed Jan 25, 2023 10:34 pm
Forum: Beginner Basics
Topic: DHCP vs VLANS
Replies: 23
Views: 2978

Re: DHCP vs VLANS

I also did netinstall and replicated same situation on fresh router. Should I fill some bug report?
by darklord
Wed Jan 25, 2023 10:26 pm
Forum: Beginner Basics
Topic: DHCP vs VLANS
Replies: 23
Views: 2978

Re: DHCP vs VLANS

Yes, when I turn off HW offloading for ether8 vlan55 works with SFP without having bridge in bridge vlan interface as it should. Looks like bug for me...
by darklord
Wed Jan 25, 2023 9:51 pm
Forum: Beginner Basics
Topic: DHCP vs VLANS
Replies: 23
Views: 2978

Re: DHCP vs VLANS

When I completely change sfp-sfpplus1 for ether1 and make trunk port there, reconnect cable and it is working as you are suggesting (eg without bridge itself configured as vlan port). So it has definitely something to do with SFP connected to CPU and not to switch chip.
by darklord
Wed Jan 25, 2023 9:47 pm
Forum: Beginner Basics
Topic: DHCP vs VLANS
Replies: 23
Views: 2978

Re: DHCP vs VLANS

Yes, I have twice exported config, reset configuration and imported config with no change. So this is not the issue here. Maybe its related to SFP, as this is not connected to switch chip?
by darklord
Wed Jan 25, 2023 9:12 pm
Forum: Beginner Basics
Topic: DHCP vs VLANS
Replies: 23
Views: 2978

Re: DHCP vs VLANS

mkx: so my config in first post should work, but is not working for vlan55. Or I do not understand where is problem, if I should not add bridge interface itself to bridge vlan.
by darklord
Wed Jan 25, 2023 8:43 pm
Forum: Beginner Basics
Topic: DHCP vs VLANS
Replies: 23
Views: 2978

Re: DHCP vs VLANS

Which device should serve as DHCP server for "other" VLANs, e.g. VLAN 55?
RB4011, but this is not issue, as I already found error in my config.

anav: this is my full config to date, I was only playing with VLANs on clean device.
by darklord
Wed Jan 25, 2023 7:08 pm
Forum: Announcements
Topic: v7.7 [stable] is released!
Replies: 357
Views: 120976

Re: v7.7 [stable] is released!

Is there any chance that this certificate chain issue https://forum.mikrotik.com/viewtopic.php?t=188947#p957046 will be fixed in 7.8 ? I am using certificates in IPSec with no problems (Custom CA, intermediate and end-user cert) but I wan to upgrade CA (and intermediate + enduser ofc) but I am not a...
by darklord
Wed Jan 25, 2023 6:49 pm
Forum: Beginner Basics
Topic: DHCP vs VLANS
Replies: 23
Views: 2978

Re: DHCP vs VLANS

My CCR is now configured as a switch, because I am trying to learn right VLAN approach (instead filtering vlan at interface and having multiple per-vlan bridges), clean overall config and then it will replace 4011. I have already found my error (but I do not fully understand the matter) - I have to ...
by darklord
Wed Jan 25, 2023 4:21 pm
Forum: General
Topic: IKEv2 EAP to NordVPN - certificate issue
Replies: 10
Views: 5850

Re: IKEv2 EAP to NordVPN - certificate issue

Is there any roadmap when this certificate problem will be fixed? I need to change certificates on more routers due to new internal CA, but have same problem with "unable to get local issuer certificate" when I test new CA with new certs. And to downgrade OS is really not an option for me...
by darklord
Wed Jan 25, 2023 3:27 pm
Forum: Beginner Basics
Topic: DHCP vs VLANS
Replies: 23
Views: 2978

DHCP vs VLANS

Hello, I am trying to understand why I have to enable DHCP snooping to enable DHCP clients on different VLANS be able to get IP address. My config: # jan/02/1970 03:35:44 by RouterOS 7.7 # software id = XMRC-DMUB # # model = CCR2004-16G-2S+ # serial number = censored /interface bridge add frame-type...
by darklord
Tue Jan 10, 2023 3:40 pm
Forum: General
Topic: Stock availability in general
Replies: 2
Views: 510

Stock availability in general

Hello, is there any problem with Mikrotik production? I am trying to find CCR2004-16G-2S+ for sale in eshops in central europe, and there are exact ZERO pcs available, some eshops stating that production has ended. Is it some kind of temporary shortage? I am planning home reconstruction - to move al...
by darklord
Wed Mar 09, 2022 11:47 am
Forum: SwOS
Topic: swOS 802.1x Authentication
Replies: 2
Views: 6209

Re: swOS 802.1x Authentication

Hello, is any chance that dot1x will be included also in SwOS in mid-term future? As lack of this feature disqualifies mikrotik switches from many implementations.