Community discussions

MikroTik App

Search found 102 matches

by divB
Tue Jan 14, 2025 2:25 am
Forum: General
Topic: Any downside of using new-mss=clamp-to-ptmu globally (without qualifier)?
Replies: 3
Views: 2400

Any downside of using new-mss=clamp-to-ptmu globally (without qualifier)?

Hi, My RouterOS box is between some Ethernet and wireguard tunnels. For the longest time everything was perfectly fine (clients with MTU=1500 and wiewguard on the RouterOS router MTU=1420). Just recently one single SSL server seemed to hang. Turns out I can fix this by decreasing MTU on my clients o...
by divB
Thu Dec 05, 2024 2:47 am
Forum: Forwarding Protocols
Topic: iBGP default route based on OSPF metrics
Replies: 1
Views: 3313

iBGP default route based on OSPF metrics

Surprisingly I did not get a response to what I thought was a simple question . I'll ask again, based on what I want to achieve: I have 4 Point-to-Point links over which 2 iBGP sessions should be established to provide redundant default routes. The 4 PtP links are wireguard links and connect to two ...
by divB
Wed Dec 04, 2024 5:31 pm
Forum: General
Topic: Any advice for further debugging handshaking failed on wireguard roadwarrior setup?
Replies: 13
Views: 2510

Re: Any advice for further debugging handshaking failed on wireguard roadwarrior setup?

Yes I think quotes are only needed if comment has spaces or special characters. Just a simple word still works without.
by divB
Mon Dec 02, 2024 6:07 pm
Forum: Forwarding Protocols
Topic: Why does my OSPF metric not reflect in distance in the routing table?
Replies: 0
Views: 5611

Why does my OSPF metric not reflect in distance in the routing table?

Hi, I have two OSPF routes where one where one has OSPF metric 190 and the other has OSPF metric 100. Yet both of them have distance 110 when installed in the FIB (see attached screenshots). Why is this OSPF metric not reflected in the FIB and can it be changed? The reason is that I would like to ma...
by divB
Mon Dec 02, 2024 3:08 am
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 18650

Re: WireGuard Multi-WAN Policy Routing

Then please just ignore my answer.

I am sure sooner or later someone will find this post and has the same issue and will appreciate the pointer to a more universal solution.
I spent the last week working around RouterOS shortcomings and I’m happy to save someone else the same hassle.
by divB
Mon Dec 02, 2024 2:51 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8699

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

I think the issue with pre-src on 172.20.215.1/32 is that there is another direct connected route with higher priority. Alright, another crazy option: SNAT to an invalid address and then use a static route to force pref-src on that prefix. Disadvantage: All packages appear to come from the own addre...
by divB
Mon Dec 02, 2024 1:20 am
Forum: General
Topic: Wireguard tunnel extremely slow, barely working (Winbox not working), possible reasons?
Replies: 2
Views: 1078

Re: Wireguard tunnel extremely slow, barely working (Winbox not working), possible reasons?

@anav: It is the setup in https://forum.mikrotik.com/viewtopic.php?p=1112178, so public IP and multiple WANs. However, upon more and more debugging it turns out the issue is still the DNAT, or, more accurately the missing source address. It seems that for some packets, a different source address is ...
by divB
Mon Dec 02, 2024 12:43 am
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 18650

Re: WireGuard Multi-WAN Policy Routing

Yet still "not all can have specialized, niche vpn WAN only setups" as an argument that a broken design is "OK" is a fairly bad excuse. At least the issue should be acknowledged, rather than downplaying it. It should not matter if a WAN uplink is Ethernet, a VLAN device, a bridge...
by divB
Mon Dec 02, 2024 12:37 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8699

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

One day later and this stopped working. The crux really seems to be the initial source address that is assigned on the first routing decision. I'm sure I have the same config but different source address is chosen. Instead of 172.20.215.1, it's again the ISP IP or something else. @lurker888: Do you ...
by divB
Sun Dec 01, 2024 8:41 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 18650

Re: WireGuard Multi-WAN Policy Routing

This hack only works in the "trivial" case that your multiple WANs are in the main routing table. I have a setup where I establish my WAN uplinks via VPNs (also wireguard). Then you need policy routing (VRFs don't work because not implemented) and everything goes nuts. If you have that set...
by divB
Sun Dec 01, 2024 6:51 pm
Forum: General
Topic: Wireguard tunnel extremely slow, barely working (Winbox not working), possible reasons?
Replies: 2
Views: 1078

Wireguard tunnel extremely slow, barely working (Winbox not working), possible reasons?

I have a wireguard tunnel from a mobile device to a CHR, the setup described here: https://forum.mikrotik.com/viewtopic.php?p=1112178 Ping works flawlessly. Enthusiastically I tried connecting to Winbox over it but surprisingly I just get "Failed to establish secure connection". I tried si...
by divB
Sun Dec 01, 2024 2:46 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8699

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

It seems finally I could get it working with the combined ideas of @lurker888, @wiseroute, @Larsa and myself. Note that neither DNAT or SNAT by itself work for the reasons I mentioned a couple of times. It is important to indeed use a separate dummy device for DNAT. It is also necessary to create a ...
by divB
Sun Dec 01, 2024 1:45 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8699

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

@lurker, i will assume that you probably meant to write: iptables - t nat -a output -s 177 -o wan1 - j snat -to 210 no no.. it is literally -s 210 -o wan1 -j snat -to 210 ok. let us try to break down @divb first scenario: - vlan bridge/loopback/wireguard listen ip 210 - wan1 ip 177 no nat. full rou...
by divB
Sat Nov 30, 2024 4:13 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8699

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

Alright, good to know it works with 7.17rc1. Not sure when this changed, but it didn’t work before. If mangle works, that’s a third option along with NAT and routing rules. Would you mind summarizing again explicitly what the first 2 options are ("1. NAT" and "2. routing rules")...
by divB
Sat Nov 30, 2024 3:56 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8699

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

I've played around a bit more and this is the nicest version: /ip/firewall/mangle add chain=output action=mark-packet new-packet-mark=wg passthrough=yes protocol=udp src-port=13231 add chain=output action=mark-routing new-routing-mark=wg passthrough=yes packet-mark=wg /ip/firewall/nat add chain=dst...
by divB
Fri Nov 29, 2024 4:55 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8699

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

Thank you, you cleared up some important points for me! [...] It's not lazy coding, but a result of a philosophy regarding the protocol. One which obviously quite a few people don't agree with... but not exactly a bug. Ok, I get now what you are saying. But please hear me out until the end of my res...
by divB
Fri Nov 29, 2024 2:33 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8699

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

Actually this is not a bug, but simply an effect of how wireguard and linux routing works. By the way as far as I can tell, Mikrotik uses the stock linux implementation - and yes, the same thing happens on straight linux and yes, this is a frequently asked question on linux forums as well. To break...
by divB
Fri Nov 29, 2024 2:00 am
Forum: General
Topic: Any advice for further debugging handshaking failed on wireguard roadwarrior setup?
Replies: 13
Views: 2510

Re: Any advice for further debugging handshaking failed on wireguard roadwarrior setup?

@divb, I assume it's a bug (or at least very bad implementation) of wireguard that does not set source address properly when generating local packets. ok. let us find out... you have 3 interfaces in the router. 2 wan and 1 loopback (wg ip). now... from those 3 interfaces - 210, 253, 177 which ip di...
by divB
Fri Nov 29, 2024 1:45 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8699

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

well, if @op would listen to put wg to listen on interface address 177 (which is persistent in terms of path) - then he won't have this headache resolving pref-src or nat or spoofing issues. please read his other thread as well so you get the picture. i did tell him to use nat - but he insisted on ...
by divB
Fri Nov 29, 2024 1:38 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8699

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

I haven't tested with your particular config, but on my router, when I want to control the source address as well as the outgoing interface for WireGuard reply-packets, I use dstnat rules: * First create an address on the lo interface, let's say 10.20.30.40/32 * Add dstnat rule for destination 192....
by divB
Thu Nov 28, 2024 4:05 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8699

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

Wow crazy. Thanks. I looked everywhere but did not find this. At least I'm not alone. Ok, I really want to avoid NAT but I'm OK to use it as a workaround. However, I am still not able to get it running. I am using the packet sniffer tool and just filter for UDP and the IP of my road warrior setup an...
by divB
Thu Nov 28, 2024 2:43 am
Forum: General
Topic: Any advice for further debugging handshaking failed on wireguard roadwarrior setup?
Replies: 13
Views: 2510

Re: Any advice for further debugging handshaking failed on wireguard roadwarrior setup?

I continued to debug and the issue is, as I stated, that RouterOS uses the wrong source address which should be handled via pref-src. Since this is a new topic, I started a new thread: https://forum.mikrotik.com/viewtopic.php?t=212887 @wiseroute: it's obviously re written somewhere. either you have ...
by divB
Thu Nov 28, 2024 2:31 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8699

RouterOS blatantly ignores pref-src. Can this really be a bug?

This is a followup question from https://forum.mikrotik.com/viewtopic.php?t=212807 but posting new topic because original question is resolved. Per request, I am starting with a network diagram: Screenshot 2024-11-27 at 16.27.59.png RouterOS runs a wireguard "server" for a road warrior set...
by divB
Tue Nov 26, 2024 2:39 am
Forum: General
Topic: Wireguard - access from VRF [SOLVED]
Replies: 13
Views: 9364

Re: Wireguard - access from VRF [SOLVED]

Same issue, very badly waiting for WireGuard vrf support
by divB
Tue Nov 26, 2024 1:28 am
Forum: General
Topic: Any advice for further debugging handshaking failed on wireguard roadwarrior setup?
Replies: 13
Views: 2510

Re: Any advice for further debugging handshaking failed on wireguard roadwarrior setup?

Ok, major update: RouterOS did send the return packages out but I had the wrong filter in the packet sniffer (192.0.2.210/32 instead of 192.0.2.0/24). One definitely should take breaks in between. Now the situation is clear: Even though I request the connection to 192.0.2.210, the return packet does...
by divB
Tue Nov 26, 2024 12:11 am
Forum: General
Topic: Any advice for further debugging handshaking failed on wireguard roadwarrior setup?
Replies: 13
Views: 2510

Re: Any advice for further debugging handshaking failed on wireguard roadwarrior setup?

I am finding it difficult to understand what you are saying, but I will assume the mikrotik has 3 public ip addresses on it. And the incoming wg packets all come into the mikrotik via either the 2.249 or 2.253 interfaces but directed at the .210 address. Normally for this, I would use routing rules...
by divB
Tue Nov 26, 2024 12:04 am
Forum: General
Topic: Any advice for further debugging handshaking failed on wireguard roadwarrior setup?
Replies: 13
Views: 2510

Re: Any advice for further debugging handshaking failed on wireguard roadwarrior setup?

@anav: I replaced my public /24 with 192.0.2/24 and keys/other public IPs/secrets with asterisks. Not sure how easy to digest this full blown config is but as I said, the gist is: ISP (with dynamic IP) is vlan2/FTTH Two wireguard tunnels wg-bg1-ftth and wg-bg2-ftth which establish over this FTTH con...
by divB
Mon Nov 25, 2024 2:55 am
Forum: General
Topic: Any advice for further debugging handshaking failed on wireguard roadwarrior setup?
Replies: 13
Views: 2510

Any advice for further debugging handshaking failed on wireguard roadwarrior setup?

Ok, I have a simple Wireguard road warrier setup and it drives me NUTS!! I am always getting handshake failed messages from the client and after hours I figured out at least what it has to do with: Two uplinks. But from here, nothing makes sense. Setup: RouterOS router with 192.0.2.210/28 on vlan4 a...
by divB
Tue Oct 15, 2024 11:14 am
Forum: General
Topic: Can wireguard tunnel listen on an VRRP address? (Want redundant VPN)
Replies: 3
Views: 1393

Re: Can wireguard tunnel listen on an VRRP address? (Want redundant VPN)

Thank you. Now followup question: If a router which is VRRP slave receives a packet for the VRRP address, would it be forwarded to the VRRP master? Or, would a slave VRRP just not listen on this address? Then, what happens if a VRRP master listens on, say, 51820 and it transitions from master to sla...
by divB
Tue Oct 15, 2024 11:08 am
Forum: General
Topic: Why do I (apparently) need to use vrrp interfaces in firewall?
Replies: 6
Views: 1230

Re: Why do I (apparently) need to use vrrp interfaces in firewall?

Thank you!
Understood.

I believe the easiest option is to create an interface list for firewall rules and put both main interface and VRRP interface in.
I think it would be good to have a note on this in the documentation because this is not logical behavior if you're not aware of it.
by divB
Thu Oct 10, 2024 8:32 pm
Forum: General
Topic: Firewall Best Practice
Replies: 1
Views: 706

Firewall Best Practice

Hello, I started using the documentation to build my own firewall: https://help.mikrotik.com/docs/display/ROS/Building+Advanced+Firewall However, first, it does not include rules to allow traffic (probably for simplicity due to NAT) and second, I don't understand why the last rule is not a DROP all:...
by divB
Thu Oct 10, 2024 11:57 am
Forum: General
Topic: Why do I (apparently) need to use vrrp interfaces in firewall?
Replies: 6
Views: 1230

Why do I (apparently) need to use vrrp interfaces in firewall?

I just spent an hour debugging why my firewall rules were not working and not matching my specified interfaces. I have configured VRRP for many interfaces and it turns out, instead of, e.g. vlan3, I need to use vrrp3 in the firewall rules. I thought VRRP interface is just a virtual interface for the...
by divB
Wed Oct 02, 2024 11:24 am
Forum: Beginner Basics
Topic: I purchased a CHR license. Why is it still showing as expiring in /system/license/print ? [SOLVED]
Replies: 3
Views: 1438

Re: I purchased a CHR license. Why is it still showing as expiring in /system/license/print ? [SOLVED]

Thanks. Not sure, didn’t find it on the Documentation page for the CHR licenses.

This happens automatically, without having to run /system/license/renew etc?

Which firewall rule (host/port) is required for this check?
by divB
Wed Oct 02, 2024 9:49 am
Forum: Beginner Basics
Topic: I purchased a CHR license. Why is it still showing as expiring in /system/license/print ? [SOLVED]
Replies: 3
Views: 1438

I purchased a CHR license. Why is it still showing as expiring in /system/license/print ? [SOLVED]

See below. The first print was the demo license. I then purchased, issued renew command but there is still a next-renewal-at and deadline-at date: [admin@SunGate2] > /system/license/print system-id: xxxxxxxxxxx level: p10 limited-upgrades: no next-renewal-at: 2024-10-02 00:42:31 deadline-at: 2024-10...
by divB
Fri Sep 20, 2024 2:50 am
Forum: General
Topic: Can wireguard tunnel listen on an VRRP address? (Want redundant VPN)
Replies: 3
Views: 1393

Can wireguard tunnel listen on an VRRP address? (Want redundant VPN)

I have 2 Mikrotik routers. "Internal" network is a public /28, each router has an IP of this subnet and additionally a VRRP address. I want both routers to act as a redundant wireguard VPN server. Can wireguard on each router listen on an VRRP address to provide redundant VPN? If not, is t...
by divB
Sat Sep 14, 2024 3:09 am
Forum: MikroTik hardware questions
Topic: Can hEX Lite / RBM11G handle multiple wireguard tunnels, OSPF, BGP (NOT full table) etc?
Replies: 2
Views: 6463

Can hEX Lite / RBM11G handle multiple wireguard tunnels, OSPF, BGP (NOT full table) etc?

I am looking for an easy emergency "cold standby" backup device when my CHR is not functional. Hence speed is not important. The hEX Lite or RBM11G are the most cost effective solutions. Ideally I would like to rackmount them but if I get the RBM11G I need case, power supply etc all separa...
by divB
Sat Sep 14, 2024 12:05 am
Forum: General
Topic: RouterOS CHR limits bandwidth to ~400Mbit....
Replies: 25
Views: 3032

Re: RouterOS CHR limits bandwidth to ~400Mbit....

Thanks everyone, especially also for reporting back that you're running RouterOS successfully on Proxmox/KVM. Good to know that this is not a fundamental issue with CHR. I meanwhile did another test: mikrotik1: 10.227.79.111 runs bandwidth server mikrotik2: 10.227.79.100: client to test bandwidth Bo...
by divB
Fri Sep 13, 2024 11:13 am
Forum: General
Topic: RouterOS CHR limits bandwidth to ~400Mbit....
Replies: 25
Views: 3032

Re: RouterOS CHR limits bandwidth to ~400Mbit....

Also, let me ask, is anyone here actually running CHR on Proxmox and can confirm things are running fine? I just found https://blog.kroy.io/2019/08/23/battle-of-the-virtual-routers/#CHR .... also describing pretty poor performance. It would be hard for me to imagine that CHR on KVM would generally b...
by divB
Fri Sep 13, 2024 10:25 am
Forum: General
Topic: RouterOS CHR limits bandwidth to ~400Mbit....
Replies: 25
Views: 3032

Re: RouterOS CHR limits bandwidth to ~400Mbit....

No, in first post you stated that you run speedtest from container. Can you do the same but now watch perfmon
Same. CPU of "networking" goes to 40%
by divB
Thu Sep 12, 2024 9:50 pm
Forum: General
Topic: Feature Request: Wireguard over VRF
Replies: 12
Views: 7670

Re: Feature Request: Wireguard over VRF

Yes, please add VRF support for Wireguard! I am not sure is this is 100% the same issue but I am seeing something odd: I place one internet connection (interface + default route) into a VRF, say "wwan" I add mangle+snat rules to force a specific wireguard endpoint (for tunnel "wg-wwan...
by divB
Wed Sep 11, 2024 12:31 am
Forum: General
Topic: RouterOS CHR limits bandwidth to ~400Mbit....
Replies: 25
Views: 3032

Re: RouterOS CHR limits bandwidth to ~400Mbit....

Do you
What do you mean by this? Start "BTest Server" on localhost and then make a speedtest to 127.0.0.1?

Then I just get 10% networking, 10% BTest, 10% firewall (roughly).

And speeds 3.1Gbps / 6.7Gbps (Rx/Tx)
by divB
Tue Sep 10, 2024 9:04 pm
Forum: General
Topic: RouterOS CHR limits bandwidth to ~400Mbit....
Replies: 25
Views: 3032

Re: RouterOS CHR limits bandwidth to ~400Mbit....

Thank you @kleshki! See here:
Screenshot 2024-09-10 at 11.03.36.png
Indeed, the CPU is under heavy load. It fluctuates but above is roughly the situation during the bandwidth test. Have of the CPU goes into "networking" (which is not very specific to me).
by divB
Tue Sep 10, 2024 9:54 am
Forum: General
Topic: RouterOS CHR limits bandwidth to ~400Mbit....
Replies: 25
Views: 3032

Re: RouterOS CHR limits bandwidth to ~400Mbit....

Or just spin a CHR on the same prox host without any config just with BTest server, can't see a reason why it can take more than 2 minutes to do so Ok I tried it out now with 1xP-10 and 1xP-unlimited. Again, the result is truly incredible. The first screenshot shows the demo license. RX is just 1Mb...
by divB
Tue Sep 10, 2024 9:33 am
Forum: General
Topic: RouterOS CHR limits bandwidth to ~400Mbit....
Replies: 25
Views: 3032

Re: RouterOS CHR limits bandwidth to ~400Mbit....

Thank you all for helping to debug, I really appreciate it! Some feedback on the suggestions: Another forum member runs as public "Bandwidth Test" server, see: viewtopic.php?t=104266 Great! I tried this out and the result is truly surprising! TX (i.e. upload) is around 700Mbps but RX (i.e....
by divB
Mon Sep 09, 2024 11:02 pm
Forum: General
Topic: RouterOS CHR limits bandwidth to ~400Mbit....
Replies: 25
Views: 3032

Re: RouterOS CHR limits bandwidth to ~400Mbit....

What is your configuration? I.e. firewall rules and so on. As for the config, it's really big and I am not sure how relevant. Just basic firewall rules but no traffic shaping etc. I tried to strip away everything completely unnecessary and attach config at the bottom. Have you run perftests from CH...
by divB
Mon Sep 09, 2024 8:44 pm
Forum: General
Topic: RouterOS CHR limits bandwidth to ~400Mbit....
Replies: 25
Views: 3032

RouterOS CHR limits bandwidth to ~400Mbit....

I have the following setup (see https://snipboard.io/mdF74v.jpg for a picture): A FTTH connection with 1Gbps symmetric on vlan2 A managed Gigabit ethernet switch A proxmox host connected to the GB switch the vlan2 and an internal LAN vlan3 (both tagged) A CHR VM (P10) on proxmox that has a VLAN awar...
by divB
Mon Sep 09, 2024 9:59 am
Forum: General
Topic: Tagged packets simply do not match any longer in srcnat chain for packets tagged in output chain!
Replies: 2
Views: 699

Tagged packets simply do not match any longer in srcnat chain for packets tagged in output chain!

Hi all, Sorry for posting another question on this topic but I can literally not believe this. Either I am staring too long at it or it's another weird bug. I am tagging OUTPUT packets with a route mark to 8.8.8.8: /ip firewall mangle add action=mark-routing chain=output dst-address=8.8.8.8 log=\ ye...
by divB
Mon Sep 09, 2024 9:16 am
Forum: General
Topic: Routing mark uses wrong source address (RouterOS bug?)
Replies: 3
Views: 1078

Re: Routing mark uses wrong source address (RouterOS bug?)

Just got back to this after 3 weeks. All of a sudden this does not work any longer :-( The following rule 3 chain=output action=mark-routing new-routing-mark=default_wwan passthrough=no dst-address=192.0.2.1 protocol=udp dst-port=51522 log=no log-prefix="" does not match any longer (packet...
by divB
Tue Aug 27, 2024 9:45 am
Forum: General
Topic: How to predefine hostnames for DHCP leases?
Replies: 11
Views: 2843

Re: How to predefine hostnames for DHCP leases?

Thank you! Options are a global setting ... how would I make the connection to the lease and and where would/could the hostname be stored? The link mentions $(HOSTNAME) but to me it's unclear where the value of this variable actually comes from (and how it connects to a specific lease entry). Or ......
by divB
Mon Aug 26, 2024 9:04 am
Forum: General
Topic: How to revert srcnat pre-routing instead of post-routing?
Replies: 3
Views: 639

Re: How to revert srcnat pre-routing instead of post-routing?

Thank you, this seems to work, indeed! For future reference (and poking holes, if not correct): /ip firewall nat add action=dst-nat chain=dstnat dst-address=192.0.2.209 dst-port=443 protocol=tcp to-addresses=10.227.4.10 to-ports=443 /ip firewall mangle add action=mark-connection chain=prerouting dst...
by divB
Mon Aug 26, 2024 8:17 am
Forum: General
Topic: How to revert srcnat pre-routing instead of post-routing?
Replies: 3
Views: 639

How to revert srcnat pre-routing instead of post-routing?

I have set up a simple policy routing that sends all packets with source address 192.0.2.0/24 through interface wan2 (all other traffic goes through wan1). Now the router has public IP 192.0.2.209/28 and I want to run port forwarding (dstnat) over it: All packets to 192.0.2.209:443 shall be forwarde...
by divB
Sun Aug 25, 2024 11:45 pm
Forum: General
Topic: Mikrotik DDNS just doesn't work
Replies: 3
Views: 1349

Re: Mikrotik DDNS just doesn't work

Yeah, it would be really great to have clarification on this. I am still testing my setup, if I know for sure that it will work once I buy the license I am fine.
by divB
Sun Aug 25, 2024 8:54 pm
Forum: General
Topic: Mikrotik DDNS just doesn't work
Replies: 3
Views: 1349

Mikrotik DDNS just doesn't work

Hi, I have P10 license (trial right now) for CHR and DDNS just doesn't work. It's always stuck in "Updating": [admin@SunGate1] > ip cloud print ddns-enabled: yes ddns-update-interval: 5m update-time: no status: updating... [admin@SunGate1] > Cloud is reachable (and no specific firewall rul...
by divB
Sat Aug 24, 2024 11:51 am
Forum: RouterOS beta
Topic: IP > Cloud on v7 CHR stuck at "updating..." [SOLVED]
Replies: 5
Views: 24252

Re: IP > Cloud on v7 CHR stuck at "updating..." [SOLVED]

I have the same issue with v7.15.3.

Can it be that this is still not fixed?
by divB
Sat Aug 24, 2024 11:45 am
Forum: General
Topic: Wireguard tunnel doesn't work after WAN interface is in VRF
Replies: 1
Views: 991

Re: Wireguard tunnel doesn't work after WAN interface is in VRF

For everyone having the same issue: I figured it out:

It works when you ping with vrf=isp.

It seems now that vlan2 is in VRF isp, every connection from the router itself that uses this VRF is automatically in. In my case, the Wireguard tunnel. Now the tunnel interface is ALSO in VRF isp...
by divB
Sat Aug 24, 2024 11:43 am
Forum: Wireless Networking
Topic: Looking for affordable, no-frills 4G/5G or LTE stick for ROS7/CHR
Replies: 2
Views: 2836

Re: Looking for affordable, no-frills 4G/5G or LTE stick for ROS7/CHR

I'm not sure that's necessarily true. KVM supports USB passhrough. So nothing on host required and for CHR instance it looks just like a regular USB device directly plugged in
by divB
Sat Aug 24, 2024 11:38 am
Forum: Beginner Basics
Topic: Is cloud available on test license?
Replies: 3
Views: 1438

Re: Is cloud available on test license?

Thanks. Wow that's weird then: [admin@SunGate1] > /ip/cloud/force-update [admin@SunGate1] > /ip/cloud/print ddns-enabled: yes ddns-update-interval: 5m update-time: no [admin@SunGate1] > Seems updates are just not happening. I have internet access. How can I debug this? EDIT: [admin@SunGate1] > /ping...
by divB
Sat Aug 24, 2024 11:34 am
Forum: General
Topic: How to define untagged (or default/native VLAN) of an Ethernet interface?
Replies: 4
Views: 816

Re: How to define untagged (or default/native VLAN) of an Ethernet interface?

I switched everything over to a big bridge now. Bridge has one port (ether1) which has all tagged VLANs. And the VLAN interfaces are now children of the bridge, not ether1.
by divB
Fri Aug 23, 2024 2:38 pm
Forum: General
Topic: How to predefine hostnames for DHCP leases?
Replies: 11
Views: 2843

Re: How to predefine hostnames for DHCP leases?

:shock: :shock: :( :( :(

Crazy.
Every other DHCP server supports this.
Sad that RouterOS has to stand out
by divB
Fri Aug 23, 2024 12:49 pm
Forum: General
Topic: How to define untagged (or default/native VLAN) of an Ethernet interface?
Replies: 4
Views: 816

How to define untagged (or default/native VLAN) of an Ethernet interface?

I run CHR and get an ether1 interface with multiple VLANs. I’ve created VLAN devices such as vlan1, vlan2, vlan3. Now, some traffic is untagged and shall correspond to vlan1. But I see nowhere an option to either specify the default PVID of the Ethernet interface nor do I see the option to specify a...
by divB
Fri Aug 23, 2024 11:50 am
Forum: General
Topic: How to predefine hostnames for DHCP leases?
Replies: 11
Views: 2843

How to predefine hostnames for DHCP leases?

Normally one can define hostnames that are proposed/sent to the client. I thought this is "Client ID" but now my static leases got ignored: This seems to be a MATCHING field, along with the MAC address. So I have to leave that one empty. In my opinion, static leases should only match MAC a...
by divB
Fri Aug 23, 2024 12:04 am
Forum: General
Topic: Routing mark uses wrong source address (RouterOS bug?)
Replies: 3
Views: 1078

Re: Routing mark uses wrong source address (RouterOS bug?)

I see, thanks!! I tried it and it works: [admin@SunGate1] > /ip/route/print where routing-table=default_wwan Flags: A - ACTIVE; s - STATIC Columns: DST-ADDRESS, GATEWAY, DISTANCE # DST-ADDRESS GATEWAY DISTANCE 2 As 0.0.0.0/0 lte1 1 [admin@SunGate1] > [admin@SunGate1] > /ip/firewall/nat/print Flags: ...
by divB
Thu Aug 22, 2024 7:41 am
Forum: General
Topic: Routing mark uses wrong source address (RouterOS bug?)
Replies: 3
Views: 1078

Routing mark uses wrong source address (RouterOS bug?)

Hello, I would like to send all packets for 192.0.2.1, udp, por 51522 over my lte interface. I have put the default route for the lte interface in routing table "default_wwan": [admin@SunGate1] > /ip/route/print where routing-table="default_wwan" Flags: A - ACTIVE; s - STATIC Col...
by divB
Thu Aug 22, 2024 6:19 am
Forum: Wireless Networking
Topic: Huawei E3372 unreliable in RouterOS 7.15.3. Any advice??
Replies: 0
Views: 2926

Huawei E3372 unreliable in RouterOS 7.15.3. Any advice??

So, getting LTE on my CHR running is a nightmare. I've been trying muliple sticks. The first one was E3372-607 with stick firmware and ppp. Port showed up, ppp device showed up but connection was just never established. I have up. Got another E3372h-607, this was has firmware 21.315.01.00.910 and on...
by divB
Wed Aug 21, 2024 10:02 pm
Forum: General
Topic: Problem with Huawei E3372 and RouterBOARD 951Ui 2HnD
Replies: 4
Views: 6568

Re: Problem with Huawei E3372 and RouterBOARD 951Ui 2HnD

Have you ever figured out anything more? I have the same issue and it I am really stuck. My stick is definitely in modem mode. I use usb_modeswitch on host PC (12d1:1506, which provides the serial ports) and then pass through to CHR via proxmox. One additional interesting thing: Im not sure where th...
by divB
Tue Aug 20, 2024 11:32 am
Forum: General
Topic: PPP (LTE\3G) Client doesn't work on any router with os 7.X on huawei e3372 stick [SOLVED]
Replies: 3
Views: 3640

Re: PPP (LTE\3G) Client doesn't work on any router with os 7.X on huawei e3372 stick [SOLVED]

Hi, and thank you for the hint.

But how do find the right channel for Data and Info? I assume it's just coincidence that they are the same for you?

For me, channel=1 answers to all the AT commands but I assume that's the Info channel, not the data channel right? How do I find out the data channel?
by divB
Mon Aug 12, 2024 1:54 am
Forum: Beginner Basics
Topic: Is cloud available on test license?
Replies: 3
Views: 1438

Is cloud available on test license?

I am trying out the CHR test license and for some reason my dynamic DNS does not update: [admin@SunGate1] > /ip/cloud/print ddns-enabled: yes ddns-update-interval: 5m update-time: no status: updating... [admin@SunGate1] > According to the docs, the demo/test license should still include all function...
by divB
Mon Aug 12, 2024 12:37 am
Forum: Wireless Networking
Topic: Looking for affordable, no-frills 4G/5G or LTE stick for ROS7/CHR
Replies: 2
Views: 2836

Looking for affordable, no-frills 4G/5G or LTE stick for ROS7/CHR

Can anyone confirm a working (ROS7) LTE/5G (4G ok too) USB stick <$80 that's actually available?

I can only find the Huawei E3372h-325 and it seems it's not supported (or at least, not easily).
by divB
Mon Aug 05, 2024 8:40 am
Forum: General
Topic: Wireguard tunnel doesn't work after WAN interface is in VRF
Replies: 1
Views: 991

Wireguard tunnel doesn't work after WAN interface is in VRF

My WAN interface is vlan2 and have put it in a separate VRF: /ip vrf add interfaces=vlan2 name=isp Reason is that I am getting the default route via DHCP and I do not want the default route to land in the main table. Of course, since main table doesn't have the default gateway anymore, nothing can c...
by divB
Wed Nov 10, 2021 8:49 am
Forum: General
Topic: Why does RouterOS send my ICMP Time Exceeded to the wrong interface and how can I avoid it?
Replies: 2
Views: 2532

Re: Why does RouterOS send my ICMP Time Exceeded to the wrong interface and how can I avoid it?

Thanks for responding. Ok, let me try: Interfaces: br-wan (=main uplink), gre-vultr (=second uplink, via GRE tunnel), br-lan (local RF1912 network). br-wan's address is 233.252.102.170 and has it's default gateway 233.252.102.169 (via NAT). /ip address add address=192.168.200.254/24 interface=br-lan...
by divB
Wed Nov 10, 2021 4:22 am
Forum: General
Topic: Why does RouterOS send my ICMP Time Exceeded to the wrong interface and how can I avoid it?
Replies: 2
Views: 2532

Why does RouterOS send my ICMP Time Exceeded to the wrong interface and how can I avoid it?

Hi, I have multiple uplinks on my router, say br-wan1 and br-wan2. br-wan1 is default gateway but I use source routing ("ip rule") to ensure a separate routing table is consulted for traffic with source for br-wan2. This works exactly as expected. However, RouterOS messes up my traceroute:...
by divB
Wed Oct 27, 2021 8:07 am
Forum: Forwarding Protocols
Topic: Debugging BGP session [SOLVED]
Replies: 1
Views: 5852

Re: Debugging BGP session [SOLVED]

I know this is not a solution but after days of debugging (and recording raw BGP packets and decoding OPEN message) I confirmed that the issue is the other endpoint. I was able to select a different endpoint and it hopped immediately to ESTABLISHED.
by divB
Mon Oct 25, 2021 7:54 am
Forum: Forwarding Protocols
Topic: What is the reason IPv4 prefixes over IPv6 BGP peer could not work?
Replies: 6
Views: 6921

What is the reason IPv4 prefixes over IPv6 BGP peer could not work?

Hi, Just to start, I have one BGP peer to which I can only talk via IPv6 but I need to announce both IPv6 and IPv4 prefixes over it. Sureley enough, only the IPv6 prefix is announced, although I ticked both "ip" and "ipv6" in the address families. The only thing I could find abou...
by divB
Mon Oct 25, 2021 7:41 am
Forum: Forwarding Protocols
Topic: How to do OSPF with pt(m)p over a /31 tunnel? [SOLVED]
Replies: 2
Views: 5457

Re: How to do OSPF with pt(m)p over a /31 tunnel? [SOLVED]

Thanks. I finally got it working with ptp. In the end, even with the /31. EDIT: Just for future reference: Check the other tunnel endpoint! Linux (and derived systems) have the inconvenient property of setting the tunnel ttl to "inherit". OSPF sets TTL=1 (since they should just go one hop)...
by divB
Sun Oct 24, 2021 7:54 am
Forum: Forwarding Protocols
Topic: Debugging BGP session [SOLVED]
Replies: 1
Views: 5852

Debugging BGP session [SOLVED]

Hello, I am setting up a BGP session via a GRE tunnel. In my opinion I have done everything correctly but the peer does not show up as "E - established". I think this should be the first step that should work, right? Then I started the packet sniffer on that GRE interface and I see that no...
by divB
Thu Oct 21, 2021 2:14 am
Forum: Forwarding Protocols
Topic: How can I simply announce a prefix on one interface?
Replies: 0
Views: 2780

How can I simply announce a prefix on one interface?

Hi, I currently have the following straight forward config in bird to announce a net 192.168.1.0/24 on a particular interface (via source address) from my AS65536 to the peering AS64496: router id 10.1.1.1; protocol device { scan time 5; } protocol kernel { scan time 60; import none; } protocol stat...
by divB
Tue Oct 19, 2021 10:39 am
Forum: General
Topic: GRE tunnel does not receive 224.0.0.5
Replies: 3
Views: 780

Re: GRE tunnel does not receive 224.0.0.5

Thanks, I have checked this already. GRE tunnel MTU is 1476 on both sides (Linux and Mikrotik). I have tried setting to a smaller value, like MTU=1200. No changes. Is there a configuration/mtu with which I can exclude all MTU related issues? Any more suggestions? EDIT: I also tried ping to the multi...
by divB
Tue Oct 19, 2021 10:09 am
Forum: Forwarding Protocols
Topic: Why is Mikrotik sending multicast with ptmp? Bug? [SOLVED]
Replies: 1
Views: 5009

Why is Mikrotik sending multicast with ptmp? Bug? [SOLVED]

I need to connect Mikrotik OSPF with bird over a non-multicast connection. I have tried nbma but the neighbors are just not recognized, despite identical configuration. When I try ptmp, Mikrotik is still sending multicast. Here is what arrives at the Linux box: 07:04:47.192109 IP (tos 0xc0, ttl 1, i...
by divB
Tue Oct 19, 2021 9:03 am
Forum: Forwarding Protocols
Topic: How to do OSPF with pt(m)p over a /31 tunnel? [SOLVED]
Replies: 2
Views: 5457

How to do OSPF with pt(m)p over a /31 tunnel? [SOLVED]

How can I properly add neighbors for ptp and ptmp? There is only an "NBMA Neighbors" tab and "Neighbors" is readonly. Also, what is the proper way to configure OSPF over a point-to-point link (IPIP or GRE) with a /31 network? Say the tunnel endpoint has 192.168.1.254/31 and the M...
by divB
Tue Oct 19, 2021 7:47 am
Forum: General
Topic: GRE tunnel does not receive 224.0.0.5
Replies: 3
Views: 780

GRE tunnel does not receive 224.0.0.5

Hi, So I know IPIP does not support multicast but GRE does. I created a GRE tunnel between a Linux machine and my Mikrotik router. From the linux end I send packets addressed to 244.0.0.5 (a multicast address). With tcpdump I can clearly see these packets being transmitted. However, on the Mikrotik ...
by divB
Sun Oct 17, 2021 9:56 am
Forum: General
Topic: How can I change the default route for a packet (or put routes into multiple tables)?
Replies: 8
Views: 3416

Re: How can I change the default route for a packet (or put routes into multiple tables)?

Ok for the rest of the world, after banging my head on this for the last two days I finally got it working. There can be multiple rules and multiple rules can jump to different tables. Key observation is (and unfortunately Mikrotiks documentation is totally lacking here) that if a rule is applied an...
by divB
Sat Oct 16, 2021 9:15 am
Forum: Forwarding Protocols
Topic: How can I leak my routes from main table into another (VRF?) table?
Replies: 1
Views: 3656

How can I leak my routes from main table into another (VRF?) table?

What am I doing wrong? I have a normal main routing table: https://snipboard.io/IpZxKO.jpg This table contains (a) dynamic routes from all kinds of connected interfaces, (b) static routes, (c) will soon include OSPF or BGP routes. It also includes a default gateway. What I want to achieve is to crea...
by divB
Fri Oct 15, 2021 8:59 pm
Forum: General
Topic: How can I change the default route for a packet (or put routes into multiple tables)?
Replies: 8
Views: 3416

Re: How can I change the default route for a packet (or put routes into multiple tables)?

On future keep one eye on VRF... I have briefly looked into this but I have trouble understanding. I also played around briefly but lost connection to the router. Gave up because I am not on-site (Safe Mode to the rescue!!) Would you be willing to give a brief example using the numbers above? Inter...
by divB
Fri Oct 15, 2021 12:56 pm
Forum: General
Topic: How can I change the default route for a packet (or put routes into multiple tables)?
Replies: 8
Views: 3416

Re: How can I change the default route for a packet (or put routes into multiple tables)?

Yes, the routes on main table are set manually or by BGP? Right now manually as well as automatically (the automatic ones are for the various interfaces. Turns out without these not even simple forwarding from one interface to the other works). There are a few tens of entries right now. However, I ...
by divB
Fri Oct 15, 2021 12:39 pm
Forum: General
Topic: How can I change the default route for a packet (or put routes into multiple tables)?
Replies: 8
Views: 3416

Re: How can I change the default route for a packet (or put routes into multiple tables)?

Hi, I think this was pretty much what I was saying (" either via "ip route rule "). My problem is a different one: I want to replace the default route only . Currently my main routing table is big...and it has a default route, say via 193.0.0.169. If the source address is from net 233...
by divB
Fri Oct 15, 2021 9:11 am
Forum: General
Topic: How can I change the default route for a packet (or put routes into multiple tables)?
Replies: 8
Views: 3416

How can I change the default route for a packet (or put routes into multiple tables)?

Hello, How can I make routes to appear in multiple tables? Or, alternatively, how can I make sure that a newly created table contains all the routes from the main table? What I actually want is to override the existing default route if and only if a package has source address from 233.252.0.0/24. If...
by divB
Wed Feb 24, 2021 3:27 am
Forum: MikroTik hardware questions
Topic: Redundancy for RB750G ... best approach?
Replies: 0
Views: 1023

Redundancy for RB750G ... best approach?

I have a RouterBoard 750G which I housed in a 19" rack using the dual 19" rackmount case (the right slot is empty). I installed it 4 years ago and so far it works nicely. However, it is in a remote spot. There is someone who can do basic things but it is very hard for myself to get there. ...
by divB
Thu Feb 18, 2021 4:16 pm
Forum: General
Topic: Why does 6.38 to 6.48.1 upgrade destroy my router and how can I avoid it?
Replies: 4
Views: 1475

Re: Why does 6.38 to 6.48.1 upgrade destroy my router and how can I avoid it?

The problem is that from version v6.41.0 onward there was the introduction of new bridge concept that removed the master/slave on ethernet ports. This was documented in the release notes https://mikrotik.com/download/changelogs for v6.41.0. At that point a script was made available to migrate old c...
by divB
Thu Feb 18, 2021 4:06 am
Forum: General
Topic: Why does 6.38 to 6.48.1 upgrade destroy my router and how can I avoid it?
Replies: 4
Views: 1475

Why does 6.38 to 6.48.1 upgrade destroy my router and how can I avoid it?

Hi, It just took me about 4 hours to recover from my upgrade to 6.48 on my RouterBoard 450G. I have a configuration in which my WAN is connected via ether1, an adm net via ether2, the lan via ether3 and ether4 and ether5 is a VLAN tagged port for all of them. So I have VLANs, bridges and stuff. This...
by divB
Tue Feb 14, 2017 11:53 pm
Forum: Virtualization
Topic: Metarouter unreliable
Replies: 7
Views: 4713

Re: Metarouter unreliable

Thanks sricci. That's a sad reply.

I think at the very least, a force-reboot and force-stop of the meta routers should be implemented so that they can't hang. A metarouter should not be able to crash the whole host system :-(
by divB
Sun Jan 15, 2017 10:56 pm
Forum: Virtualization
Topic: Metarouter unreliable
Replies: 7
Views: 4713

Re: Metarouter unreliable

According to "/system resource print" it is version: 6.38 (stable).

It's really frustrating. Sometimes the meta router just crashes and the only way to get it back is to reboot the entire system.
by divB
Sun Jan 15, 2017 7:36 pm
Forum: Virtualization
Topic: Metarouter unreliable
Replies: 7
Views: 4713

Metarouter unreliable

Hi, I am using metarouter (with OpenWRT) on RB450G with 3.24 and metarouter (not OpenWRT!) seems to be pretty unreliable: Very often, when rebooting/shutting down, the router just hangs with Status "rebooting" or "shutting-down". There is no way no force a clean restart of a meta...
by divB
Sun Jan 15, 2017 2:55 am
Forum: General
Topic: DNS forwarding
Replies: 2
Views: 3841

Re: DNS forwarding

Thank you, this is a nice hack.
I'll implement it but this should really be a functionality of RouterOS :-/
by divB
Sun Jan 15, 2017 2:54 am
Forum: General
Topic: Feature request: per-domain forwarding in DNS
Replies: 25
Views: 27068

Re: Feature request: per-domain forwarding in DNS

I have two questions: 1.) Is there any chance to make it work for TCP? I guess the reason is that the actual content is in the packets after SYN, SYN-ACK, ACK so that the first three packages of the connection cannot be marked? 2.) I now have this setting: [admin@ugate] /ip firewall layer7-protocol>...
by divB
Sun Jan 15, 2017 2:12 am
Forum: General
Topic: Making forwarded ports available from internal
Replies: 2
Views: 1441

Making forwarded ports available from internal

I have set a public IP with masquerding and some IP forwardings: [admin@ugate] /ip firewall nat> print Flags: X - disabled, I - invalid, D - dynamic 0 ;;; default configuration chain=srcnat action=masquerade out-interface=br-wan log=no log-prefix="" 1 ;;; SSH chain=dstnat action=dst-nat to...
by divB
Thu Jan 12, 2017 11:57 pm
Forum: General
Topic: DNS forwarding
Replies: 2
Views: 3841

DNS forwarding

Hi, Is it possible to have RouterOS act as a DNS server, pointing to DNS servers for the queries but forward certain zones to a separate DNS server? With dnsmasq this can be done with: server=/localhost/127.in-addr.arpa/0.in-addr.arpa/255.in-addr.arpa/intra.mydomain.net/1.168.192.in-addr.arpa/1.7.10...
by divB
Tue Jan 10, 2017 2:34 pm
Forum: Virtualization
Topic: OpenWRT on MetaRouter and opkg
Replies: 1
Views: 3683

OpenWRT on MetaRouter and opkg

Hi, I got OpenWRT for my METAROUTER (RB450) according to the Wiki from: http://www.mikrotik.com/download/metarouter/openwrt-mr-mips-rootfs.tgz However, does anyone know where I can find an opkg repository? I would like to install packages such as openvpn, ... Currently it is set to http://openwrt.pa...
by divB
Thu Aug 27, 2015 6:03 pm
Forum: Virtualization
Topic: OpenVPN with OpenWRT
Replies: 1
Views: 4309

OpenVPN with OpenWRT

Hi, I just configured a meta router with the provided OpenWRT package. This is really great! However, there are not many packages and using opkg does not work because the referenced repository in opkg.conf results in a 404. How can I install OpenVPN within this OpenWRT instance as easily as possible...
by divB
Wed Aug 26, 2015 12:03 am
Forum: Beginner Basics
Topic: Confusion about interface, switch, bridge, VLAN
Replies: 3
Views: 2454

Re: Confusion about interface, switch, bridge, VLAN

This is a great explanation - thank you! Do I understand correctly that 1.) For a physical port 5 that has vlan1,vlan2,vlan3 tagged I would need to create three interfaces and bridge them together? 2.) For example, vlan1_eth2 in your example - is this really needed? Because eth2 is an untagged port ...
by divB
Mon Jul 06, 2015 8:31 pm
Forum: Beginner Basics
Topic: Confusion about interface, switch, bridge, VLAN
Replies: 3
Views: 2454

Confusion about interface, switch, bridge, VLAN

I am new to RouterOS and just trying to replace my router based on WRT54GL/OpenWRT with RouterBoard 750. I am confused with the architectural way Mikrotik handles VLANs (and interfaces, switches etc). What I want: - Interface 1: WAN (static IP), VLAN3, untagged - Interface 2: VLAN1, untagged - Inter...