Community discussions

MikroTik App

Search found 32 matches

by ucs75
Tue Apr 14, 2020 9:09 pm
Forum: General
Topic: LLDP
Replies: 136
Views: 73145

Re: LLDP

+100000 I would love to deploy MT switches all day long if they supported LLDP-MED. But without it, they're useless in offices with VoIP phones (all offices we support and upgrade). That's about 300 switches not sold in the last two years just with the deployments I managed. Can we get a bug-free LL...
by ucs75
Wed Feb 07, 2018 9:07 pm
Forum: General
Topic: DHCP options not working since 6.7 (MIPS)
Replies: 4
Views: 1752

Re: DHCP options not working since 6.7 (MIPS)

Thank you for adding with the s'xxx' option. I tried to amend my answer last night, but the page kept timing out whenever I attempted. Looking at the logging, it is sending the IP address as four hexadecimal numbers. Prefixing the opening single quote with an s forces it to send the ip address as a ...
by ucs75
Wed Feb 07, 2018 4:27 am
Forum: General
Topic: DHCP options not working since 6.7 (MIPS)
Replies: 4
Views: 1752

Re: DHCP options not working since 6.7 (MIPS)

Does AllWorx have a firmware upgrade to fix this? The problem is that it cannot understand an IP address sent in hex form. It must receive the dotted decimal notation (hex encoded).

--See below answers for workaround
by ucs75
Fri Dec 15, 2017 8:53 pm
Forum: General
Topic: Insecure VPN
Replies: 3
Views: 993

Insecure VPN

If I create, for example, a GRE tunnel and add a passphrase to each side of it, RouterOS will dynamically create an IPSec tunnel between my two endpoints. It will use the default proposal, which allows me to set the PFS DH Group, but not the Phase 1 DH Group. It always uses Group 2 -- which has been...
by ucs75
Sun Oct 02, 2016 11:50 pm
Forum: General
Topic: IPSec dual links
Replies: 6
Views: 2047

Re: IPSec dual links

Jaytscd, Think of IP-->IPSEC-->Policy-->General as a matching filter. Only packets that match the Source Address, Destination Address, and Protocol will be matched and acted upon. Everything else will be processed as normal. If you leave this too broad, you can shoot yourself in the foot by blocking...
by ucs75
Sun Oct 02, 2016 4:44 am
Forum: General
Topic: IPSec dual links
Replies: 6
Views: 2047

Re: IPSec dual links

One inconvenience exists. I cannot ping (access) WAN IP of branch Cisco892 and vice versa (From remote side I cannot ping WAN IP of Mikrotik). Is it fixable? In your IPSec Policy, General Tab -- look for the Protocol Field. Set this to 4. This will restrict the encryption policy to only match on th...
by ucs75
Sat Oct 01, 2016 8:05 pm
Forum: Beginner Basics
Topic: Mikrotik RB2011UiAS + UniFi AP configuration problem
Replies: 2
Views: 1183

Re: Mikrotik RB2011UiAS + UniFi AP configuration problem

Without having reviewed everything, I did notice that you have three ISPs and three Masquerade rules all on the same Routerboard. This has never worked for me. Masquerade often NATs using the wrong public IP in this setup. I've resolved this by adding a routerboard for each ISP/Required-Masquerade. ...
by ucs75
Sat Oct 01, 2016 7:47 pm
Forum: General
Topic: Route all traffic through ipsec
Replies: 1
Views: 1623

Re: Route all traffic through ipsec

Create a specific route for Center's External IP that utilizes the ISP. This is necessary to create the tunnel. Now create a default route (0.0.0.0/0) that utilizes the tunnel. Any route more specific than the default will take precedence. Otherwise, your traffic will all be routed over the tunnel.
by ucs75
Sat Oct 01, 2016 5:26 pm
Forum: General
Topic: IPSec dual links
Replies: 6
Views: 2047

Re: IPSec dual links

Is your IPSec setup at transport or tunnel mode? I would venture to guess that it's setup in tunnel mode. If so, try changing the config to use gre/ipsec with transport mode (restricted to protocol 47). This will change your policy to only match the packets with source of MT Router and Destination o...
by ucs75
Sat Oct 01, 2016 7:21 am
Forum: Forwarding Protocols
Topic: GRE Tunnel on Dynamic IP address
Replies: 9
Views: 23834

Re: GRE Tunnel on Dynamic IP address

I realize this is an old thread at the time of my reply, but thought it a good place to post a simple scripting solution to update the GRE tunnel remote-address when that remote-address is dynamic. This does assume the GRE tunnel is already functional and that the remote-address WAN ip is registere...
by ucs75
Thu Sep 29, 2016 1:55 am
Forum: General
Topic: MikroTik why not turn to new Cisco/Juniper?
Replies: 33
Views: 15169

Re: MikroTik why not turn to new Cisco/Juniper?

I guess it comes back to the age old question? Would you rather do a bit of extra work and save a large amount of cash. Or do you spend big bucks and make it a no brainer? In the business were in we go for the first one and we love Mikrotik for giving us that chance. After all that's actually their...
by ucs75
Mon Sep 26, 2016 5:19 am
Forum: General
Topic: CCR EOIP over IPSEC performance
Replies: 6
Views: 4874

Re: CCR EOIP over IPSEC performance

Thanks again. I think I'll try loading a VM with RouterOS strictly for the eoip tunnels and run the rest of the connectivity and security on the main gateway.
by ucs75
Sat Sep 24, 2016 9:14 am
Forum: General
Topic: CCR EOIP over IPSEC performance
Replies: 6
Views: 4874

Re: CCR EOIP over IPSEC performance

I noticed that your config disables connection tracking. Did you happen to take note of the performance difference with and without conn-tracking enabled? If it's significant, I may need to look into adding a dedicated router for eoip tunnels -- because I'm not sure that disabling connection-trackin...
by ucs75
Fri Sep 23, 2016 8:37 am
Forum: General
Topic: CCR EOIP over IPSEC performance
Replies: 6
Views: 4874

Re: CCR EOIP over IPSEC performance

Thank you for your post, CKJ. Although I am disappointed to not see any further activity on this thread, I wanted to at least thank you. Your post caused me to do a little looking into the different flavors of AES-128. Previously I had just been clicking the first one (CBC). CBC's performance was ab...
by ucs75
Thu Sep 22, 2016 2:40 am
Forum: General
Topic: EoIP on CCR without fastpath = HORRIBLE performance
Replies: 1
Views: 1018

Re: EoIP on CCR without fastpath = HORRIBLE performance

Sorry, forgot to include RouterOS 6.34.6
by ucs75
Thu Sep 22, 2016 1:41 am
Forum: General
Topic: EoIP on CCR without fastpath = HORRIBLE performance
Replies: 1
Views: 1018

EoIP on CCR without fastpath = HORRIBLE performance

Am I missing something? The background / setup. ======================== Router A CCR1009-8G-1S-1S+ Bridge-LAN [ether-2, eoip-tunnel] ether-8 Static IP on /30 (directly connected to Router B) Router B CCR1009-8G-1S-1S+ Bridge-LAN [ether-2, eoip-tunnel] ether-8 Static IP on /30 (directly connected to...
by ucs75
Sun Sep 11, 2016 4:55 am
Forum: General
Topic: GRE over IPSEC, CCR, VERY SLOW
Replies: 39
Views: 24704

Re: GRE over IPSEC, CCR, VERY SLOW

Could you please post a sample config with GCM? There's clearly more to it than just changing the encryption algorithm in the proposal. I wasn't able to achieve a tunnel after updating the proposal. What else needs to be set?!
by ucs75
Thu Feb 12, 2015 3:11 am
Forum: General
Topic: SSTP certificate problem
Replies: 3
Views: 9226

Re: SSTP certificate problem

I'd just like my COMMERCIAL certificate to work. I ([+] Create)-ed a certificate from Winbox, and selected "crl sign", and "key cert. sign" as the only Key Usages. Filled in the various fields, including Days Valid: 1825 and Key Size 2048 I then [Create Cert. Request], using this...
by ucs75
Fri Nov 28, 2014 8:49 pm
Forum: Scripting
Topic: SSTP Client marking IP Addresses as DI (Dynamic Invalid)
Replies: 8
Views: 2980

Re: SSTP Client marking IP Addresses as DI (Dynamic Invalid)

Unfortunately that link didn't really help. I don't have the option of swapping around who is the hub and who is the spoke whenever the problem rears it's head. This has now happened to 6 or 8 of my production units. I've tried 6.18 through 6.22 hoping that a newer version has fixed the problem. But...
by ucs75
Mon Nov 03, 2014 9:34 pm
Forum: General
Topic: SSTP VPN with AES on Windows
Replies: 2
Views: 3046

Re: SSTP VPN with AES on Windows

Bump!!!!!
by ucs75
Wed Oct 29, 2014 7:01 pm
Forum: MikroTik hardware questions
Topic: Traffic generator killed ccr1009 ?
Replies: 16
Views: 4395

Re: Traffic generator killed ccr1009 ?

Two Dead CCR1009-8G-1S-1S+ units within 30 days here...

One was up for about 30 days, the other less than 24 hours.
by ucs75
Fri Oct 17, 2014 6:09 pm
Forum: Scripting
Topic: SSTP Client marking IP Addresses as DI (Dynamic Invalid)
Replies: 8
Views: 2980

Re: SSTP Client marking IP Addresses as DI (Dynamic Invalid)

Update:

I just had this happen on a CCR1009 --> CCR1009.

So the problem is not isolated by platform. Both RouterOS 6.18.

I hate to have to downgrade to 6.7 because of the performance losses, but so far, that's all I know to do!
by ucs75
Fri Oct 17, 2014 6:08 pm
Forum: Scripting
Topic: SSTP Client marking IP Addresses as DI (Dynamic Invalid)
Replies: 8
Views: 2980

Re: SSTP Client marking IP Addresses as DI (Dynamic Invalid)

I've searched repeatedly for weeks, and not found anything. Hence my asking.

Perhaps a link to the thread you referenced? Just saying "yep" really doesn't help much!
by ucs75
Mon Oct 13, 2014 3:16 am
Forum: Scripting
Topic: SSTP Client marking IP Addresses as DI (Dynamic Invalid)
Replies: 8
Views: 2980

SSTP Client marking IP Addresses as DI (Dynamic Invalid)

I have been running into this problem repeatedly lately. Client -- RB951G-2HnD RouterOS 6.18 Firmware 3.18 Server -- CCR1009-8G-1S-1S+ RouterOS 6.18 Firmware 3.10 and 3.18 Client establishes SSTP connection, and server assigns IP address as defined in the username/password (Secret Section). Sometime...
by ucs75
Sat May 03, 2014 5:03 am
Forum: Forwarding Protocols
Topic: Mikrotik -> Linux xl2tp fails to negotiate mppe
Replies: 3
Views: 6657

Re: Mikrotik -> Linux xl2tp fails to negotiate mppe

Well, I'm glad I could have this conversation with myself! Hope this helps someone in the future.... RouterOS Version was the problem. The trouble occurred on v5.24 So RouterOS v5.24 has a serious bug in the l2tp client, which prevents it from negotiating mppe encryption is a perfect match is not ha...
by ucs75
Sat May 03, 2014 4:24 am
Forum: Forwarding Protocols
Topic: Mikrotik -> Linux xl2tp fails to negotiate mppe
Replies: 3
Views: 6657

Re: Mikrotik -> Linux xl2tp fails to negotiate mppe

Update: I found one problem in my config. I had noccp set in the pppd config, blocking mppe from being supported. So now it's coming up but telling me that the Mikrotik is failing to negotiate. May 2 20:18:06 ubuntu pppd[1791]: rcvd [CCP ConfReq id=0x84 <mppe +H -M +S +L -D -C>] May 2 20:18:06 ubunt...
by ucs75
Sat May 03, 2014 3:51 am
Forum: General
Topic: Error connecting Mikrotik PPTP VPN Client to a Linux VPN Svr
Replies: 4
Views: 6834

Re: Error connecting Mikrotik PPTP VPN Client to a Linux VPN

What's up with the:
Warning: can't open options file /root/.ppprc: Permission denied

It looks like the process has no permissions to read it's own config file.
by ucs75
Sat May 03, 2014 1:40 am
Forum: Forwarding Protocols
Topic: Mikrotik -> Linux xl2tp fails to negotiate mppe
Replies: 3
Views: 6657

Mikrotik -> Linux xl2tp fails to negotiate mppe

I've spent hours on this now and made very little headway. If I 'require' Encryption on the MT Client, the resulting pppd log shows: ... May 2 17:29:01 ubuntu pppd[1367]: rcvd [LCP TermReq id=0x18 "Encryption negotiation rejected\000"] May 2 17:29:01 ubuntu pppd[1367]: LCP terminated by pe...
by ucs75
Wed Nov 06, 2013 4:36 pm
Forum: General
Topic: l2tp 20% Packet Loss
Replies: 4
Views: 4722

Re: l2tp 20% Packet Loss

Taking time to encapsulate would result in higher latency, not packet loss. I have previously been able to run six concurrent tests at 5ms with 0% packet loss. Good thought though...and thanks for responding! That being said, the problem is not resolved - although I don't have a full root-cause anal...
by ucs75
Tue Nov 05, 2013 8:58 pm
Forum: General
Topic: l2tp 20% Packet Loss
Replies: 4
Views: 4722

l2tp 20% Packet Loss

Local Office: RB751 v5.24 Remote Office: CCR1016-12G 6.4 With, or without Encryption, I am consistently getting 20% packet loss through an l2tp tunnel between these devices. To test, I am using a linux box, and sending 10000 packets at 5ms intervals. Pinging the external interface of the CCR (no tun...
by ucs75
Sun Sep 29, 2013 6:35 am
Forum: Beginner Basics
Topic: Winbox use and readout
Replies: 6
Views: 3047

Re: Winbox use and readout

BUMP!!
by ucs75
Mon Sep 23, 2013 9:46 pm
Forum: MikroTik hardware questions
Topic: RB751 CPU usage get too high
Replies: 15
Views: 12779

Re: RB751 CPU usage get too high

I didn't see anyone ask what his logging settings were. If 'flash' means writing to disk, is it possible that he has some logging rules set to write to disk that are active during usage -- and therefore crippling the unit?