true.7.15.x was the last version where BGP worked OK
how do you corelate encrypted traffic in this?Sorry sippan, what is BS is false hope and promises.
If you are unable to inspect encrypted traffic, then do pray tell what effing magic do you use........
BS. -.-Probably neither you need an expensive router add then pay for subscription services to handle DPI etc.........
/ip firewall nat add action=src-nat chain=srcnat dst-address={IP adr. of DNS upstream} dst-port=53 protocol=udp to-addresses={SRC IP which you want to use}
do you mean from RDS2216 <-> RDS2216 ?Would be interesting to see the same tests run on the RDS2216. Any chance you could try that?
What's new in 7.19beta6 (2025-Mar-19 09:56):
*) net - remove support for automatic multicast tunneling (AMT) interface (introduced in v7.18);
disables ARP? really? haven't seen that ever after
...fast-forward=no....
what exactly?None of that is true though, some really old info
very good point !
But if you try to write files to flash so that you fill the space, does it work?
on which column do you sort here?if nobody has reported it yet TLDR. the VLAN overview goes crazy with many VLAN interfaces (about 100 in a QinQ setup) (see gif)
WinBox 4.0beta18
Peek 2025-03-13 16-27.gif
...some "sortby=" on a print be helpful.
"enumerate" is a bit of over exaggerated... enumerate valid usernames in Mikrotik routers ...
do we have any update on [SUP-134566]: BGP-VRF V7?
when that feature will be implemented.
It works perfectly fine on v6
do we have any update on [SUP-134566]: BGP-VRF V7?
when that feature will be implemented.
It works perfectly fine on v6
same.Same issue, very badly waiting for WireGuard vrf support
try setting the PVID to 1 (or 4094 when not used otherwise) --> 187 coming in tagged and also PVID set to that VLAN ID does not go well in ROS ... stilladd bridge=BR1 interface=ether3 pvid=187 - if I add this admit-only-vlan-tagged i'm losing access to the other VLAN's
bummer ... thanks for the hint.As for the ticket system: there is a default filter to show only open issues in the list. you need to change the filter to "any status".
@inazmul...
if it is just for MACsec securing dark fibre and need to stay on a budget (sort of) consider a look towards the fs.com S5800-48F4SRNot really but Arista, Cisco, Juniper (and many others) all have decent macsec enabled switches.
...
+1I'd like to suggest a public status page for Mikrotik services. So people don't have to flood forum and support helpdesk with all the same "omg, it is down" reports.
exactly. thank you sir!Static DHCP leases have the MAC Address saved, so on that context menu (which seems to be the screenshot from) makes perfect sense.
...
I think, it will be usefull to have context option "Wake On Lan" in ip / dhcp-server / leases.
...
right click the space in "Saved" viewHow do i import saved session to new winbox4
tested it in EVE-NGYou can try the reverse thing: create a single VRRP, create VLANs on top of VRRP. This should work, if it's ok that a single VRRP handles all VLANs at once.
that's the nature of this community i learnt over the years now. sad.But putting myself in their shoes, if every time they release a change a horde of zombies appears shouting (even though it's in testing), it's only natural that they start hiding their actions more.an that is bad??
is there any docs how we are ablte to use this feature? or best-practice?bridge - added interface-list support for VLAN : the best features!!!!
This will simplify VLAN tables!thank you mikrotik.
tcp-close-wait-timeout + tcp-close-timeout
+2Need colors in log. Like Red for errors and other.
works in beta8@normis Winbox 4 beta 6
Can't add new interface lists. I can create them in the terminal and then add / remove members in Winbox but can't create a new list.
https://fccid.io/TV7WAPGR52AX/Test-Repo ... on-7634095 shows a little preview in the antenna radiation pattern exhibits...
It appears like a rather compact device, probably around 10x15x3 cm.
I haven't found actual photos, but I only had a quick peek.
is there a possible solution to resolve to upstream dns from e.g. a management VRF?Yes, it is like in any other configuration with vrf parameter.
/ip dns set servers=1.1.1.2@management
+1 for VXLAN!Is there any chance of Multicore Processing of Following in ROS v7.x:
1. MPLS + VPLS
2. PPPOE
3. VXLAN
yes the ENTER key functionality has not arrived yet ... same with applying changesI also noticed you can't just enter the IP and hit enter like in winbox3, now it's a bit more cumbersome to have to then first click start.
+1
hm https://fccid.io/TV7Is it nearly ready yet?? Don't we usually find stuff on the FCC websites in advance?wAP ax will be a very small device and is coming very very soon (question of days or weeks)
+1Need the group feature back badly. This is a show stopper for us as we sort clients that way.
now some more know thoughNot everybody knows the name for it ... and certainly not everybody knows how to use it properly ... hence post by @TheCat12 (which is, unlike yours, useful)this is considered PtP addressing and works fine
why is this even a ef'ing thing? i do not get itPeople are so gotten used to grey XP style interface, but are not used to the name? We call it winbox, because is easy to say and everyone knows what it is
thanks ... didn't know about that or at least never realized this was thereTIL: there is
which shows you really all cache entries.Code: Select all/ip/dns/cache/all/print
Unlike
Code: Select all/ip/dns/cache/print
maybe there will be more assets in the future?I like how an extra folder containing a single image file needed to be packed for distribution :P
It would be a useful feature to be able to make a backup that is portable to a different replacement Mikrotik device.
well that would then finally be the end for my hAP ac² devices and the migration to CAPsMAN!wAP ax will be a very small device and is coming very very soon (question of days or weeks)
On the Products page ....
is there a list of AMPERE devices which are ensured/trusted to work with ROS?RouterOS can be installed on AMPERE(TM) ARM systems (bare metal), and on ARM powered cloud services via CHR image.
is graylog a tool to graph and report netflow data? interessted in that TBHWe ended up using Graylog and the IPFIX endpoint. Only tracking NAT translations for CALEA requirements.
confirming this also.I confirm, usermanager works with Google Authenticator. tested and working perfectly.
https://foisfabio.it/index.php/2024/04/ ... ik-otp-vpn
but OP asked for help with port forwarding with hairpin NAT and dynamic IP comboThe best is use seriously IPv6: no needed any form of NAT.
for a simpler setup i'd prefer simple VLAN separationThanks @spippan, is there a preferred approach given that I might in future want to apply some QOS or speed threshold rules?
/export hide-sensitive
$"lease-address"