Community discussions

MikroTik App

Search found 13 matches

by FattyAcid
Thu Jan 26, 2023 9:59 pm
Forum: Announcements
Topic: v7.8beta [testing] is released!
Replies: 307
Views: 86326

Re: v7.8beta [testing] is released!

Believe me, while this is possible to achieve manually, you just want the box to "know" what o365 traffic is. That is not something a generic router can do. You need to buy a special box that has a maintenance contract to provide you with the dynamic information required for that. What is...
by FattyAcid
Thu Jan 26, 2023 6:13 am
Forum: General
Topic: FIPS 140-2 Compliant
Replies: 2
Views: 2232

Re: FIPS 140-2 Compliant

Anyone from MikroTik going to chime in on this ? This has been asked before and as far as I recall Mikrotik has always been radio silent on this. I'd stay away from Mikrotik if this is a requirement. You're much safer if you use a vendor that has gone through this certification and has a FIPS mode.
by FattyAcid
Thu Jan 26, 2023 6:00 am
Forum: Announcements
Topic: v7.8beta [testing] is released!
Replies: 307
Views: 86326

Re: v7.8beta [testing] is released!

It is already fixed in v7.7 and v7.8betas
Can you please elaborate? What is fixed in v7.7 and v7.8 betas.
by FattyAcid
Thu Jan 26, 2023 5:57 am
Forum: Announcements
Topic: v7.8beta [testing] is released!
Replies: 307
Views: 86326

Re: v7.8beta [testing] is released!

"DMVPN" is such a killer feature in the enterprise world. VyOS has support for it since years. in general called SD-WAN. This is implemented in v7 using ZeroTier. This will be my last post on this as it's getting off-topic, but ZeroTier is a pretty basic SD-WAN and is in no way equivalent...
by FattyAcid
Sat Jan 21, 2023 10:24 am
Forum: Announcements
Topic: v7.8beta [testing] is released!
Replies: 307
Views: 86326

Re: v7.8beta [testing] is released!

This is a disappointing release as 7.8, should have been 7.7.1. When are we going to see Mikrotik address those critical route/switch features that most enterprises use. Specifically: 1. BFD fixed 2. BGP-VPNv4-VRF RR fixed 3. Something equivalent to Cisco DMVPN, HP DVPN, Meraki AutoVPN, or Fortinet ...
by FattyAcid
Tue Nov 08, 2022 4:07 am
Forum: RouterBOARD hardware
Topic: End-of-Sale and End-of-Life of TILE-based CCR [SOLVED]
Replies: 14
Views: 7580

Re: End-of-Sale and End-of-Life of TILE-based CCR [SOLVED]

This tweet from IP Architects suggests sooner than expected. https://twitter.com/stubarea51/status/1584164274213044230?cxt=HHwWjICq5fPAivwrAAAA FYI, IP Architects' tweet is just referencing my post on Reddit r/mikrotik. And I'm the person who started this post here. Apparently I'm the first person ...
by FattyAcid
Thu Oct 20, 2022 7:59 pm
Forum: RouterBOARD hardware
Topic: End-of-Sale and End-of-Life of TILE-based CCR [SOLVED]
Replies: 14
Views: 7580

End-of-Sale and End-of-Life of TILE-based CCR [SOLVED]

Does Mikrotik publish End-of-Sale/End-of-Support dates? The TILE processor was discontinued this year by Nvidia: https://network.nvidia.com/files/pdf/eol/LCR-000851.pdf https://network.nvidia.com/files/pdf/eol/LCR-000901.pdf Has Mikrotik stopped manufacturing TILE-based CCR models or are they contin...
by FattyAcid
Thu Oct 20, 2022 7:22 pm
Forum: RouterBOARD hardware
Topic: CRS518-16XS-2XQ running OSPF + VRRP + interVLAN routing
Replies: 0
Views: 658

CRS518-16XS-2XQ running OSPF + VRRP + interVLAN routing

Can a pair of CRS518-16XS-2XQ do this? - Configured as MLAG peers with a 2 x 25G bond for the peer-ports - The remaining 25G links (14) on the CRS518s configured as MLAG trunks carrying 4-10 VLANs up to access switches - The subnet gateway for each VLAN residing on the CRS518s with VRRP between the ...
by FattyAcid
Wed Oct 19, 2022 8:56 am
Forum: Forwarding Protocols
Topic: IS-IS
Replies: 172
Views: 65942

Re: IS-IS

1) IS-IS, 2) VTI, 3) something equivalent to Cisco DMVPN or GETVPN or HP DVPN or Meraki AutoVPN, 4) BGP Multipath, 5) Lack of commit/rollback

Those are the five features that prevent me from recommending Mikrotik to large enterprise customers.
by FattyAcid
Fri Oct 14, 2022 12:13 am
Forum: General
Topic: What does HW-Offload mean when two switch chips on CCR2004?
Replies: 2
Views: 1836

What does HW-Offload mean when two switch chips on CCR2004?

I have this config on my CCR2004-16G-2S+: # jan/02/1970 12:51:37 by RouterOS 7.5 # software id = XXXXXXXXXX # # model = CCR2004-16G-2S+ # serial number = XXXXXXXXXX /interface bridge add name=bridge1 vlan-filtering=yes /interface bridge port add bridge=bridge1 frame-types=admit-only-vlan-tagged inte...
by FattyAcid
Thu Oct 13, 2022 2:44 am
Forum: General
Topic: CCR2004-16G-2S+ no default firewall?
Replies: 5
Views: 1582

Re: CCR2004-16G-2S+ no default firewall?

Thanks guys makes perfect sense. I've done lots of firewalls on RouterOS v6, just haven't done any under v7 yet.
by FattyAcid
Wed Oct 12, 2022 11:50 pm
Forum: General
Topic: CCR2004-16G-2S+ no default firewall?
Replies: 5
Views: 1582

CCR2004-16G-2S+ no default firewall?

I received a new CCR2004-16G-2S+ with 7.5 and it appears to have no default firewall configured and it doesn't have one under
/system default-configuration print.

What is the thinking behind that?
by FattyAcid
Fri Aug 12, 2022 12:26 am
Forum: RouterBOARD hardware
Topic: RouterBOARD with highest IPSec throughput for single SA
Replies: 3
Views: 4412

RouterBOARD with highest IPSec throughput for single SA

I'm getting about 425-450 Mbps max throughput over single IPSec SA using IKEv2, AES256, SHA256 between a RB4011 and Palo Alto 7000, regardless of throughput test tool. I see one core hit 100% CPU on this test with the RB4011, so I assume it's maxed out? The RB4011 has 1 Gb symmetric Internet and the...