Community discussions

MikroTik App

Search found 2078 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 7
by Larsa
Fri Apr 04, 2025 12:46 pm
Forum: Forwarding Protocols
Topic: Problem Azure and bgp/vpn
Replies: 7
Views: 711

Re: Problem Azure and bgp/vpn

And multihop and nexthop-choice are configured on the Mikrotik?
by Larsa
Fri Apr 04, 2025 12:19 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 92
Views: 16712

Re: WireGuard Multi-WAN Policy Routing

Unfortunately, MACVLAN still needs either routing rules or @Sindy's NAT trick to work properly.
by Larsa
Fri Apr 04, 2025 11:37 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 68
Views: 6512

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

@Mimiko, your only options are either routing rules or NAT, unless you’re on one of the newer ROS versions where they supposedly fixed the issue, i.e. that WireGuard’s initial handshake is going out via the default gateway instead of the inbound interface. Might’ve been mentioned in this or the othe...
by Larsa
Wed Apr 02, 2025 5:27 pm
Forum: General
Topic: DNS FWD ignores CNAME records
Replies: 6
Views: 3219

Re: DNS FWD ignores CNAME records

This is just a user forum. Please report bugs directly to MikroTik support: https://mikrotik.com/support
by Larsa
Wed Apr 02, 2025 5:15 pm
Forum: General
Topic: Public DNS to private IP
Replies: 41
Views: 1379

Re: Public DNS to private IP

@Josephny, please listen to BartoszP's advice — they're legit. My recommendation: don’t use an external DNS server for your local needs and private addresses (for a bunch of different reasons)
by Larsa
Wed Apr 02, 2025 2:48 pm
Forum: Forwarding Protocols
Topic: Problem Azure and bgp/vpn
Replies: 7
Views: 711

Re: Problem Azure and bgp/vpn

Did you read the blogs, and have you also checked how multihop and nexthop-choice are configured on your MikroTik?
by Larsa
Wed Apr 02, 2025 12:58 pm
Forum: General
Topic: Public DNS to private IP
Replies: 41
Views: 1379

Re: Public DNS to private IP

No need for public A records if you run your own internal DNS server with a split DNS setup. You can map a domain like mqtt-ha.mydomain.local (or whatever) to 10.100.0.1 and have all your IoT devices point to that DNS server. It’s best practice in setups like this and is simple, reliable and fully u...
by Larsa
Wed Apr 02, 2025 11:44 am
Forum: General
Topic: Large UDP packets not fragmented and sent over IPSEC
Replies: 4
Views: 539

Re: Large UDP packets not fragmented and sent over IPSEC

One thing you could try is adding a RAW rule to see if those fragments even hit the router’s CPU. RAW is processed before conntrack or filters, so it might be a good way to check if something’s silently dropping them early. Use something like this: " /ip firewall raw add chain=prerouting fragme...
by Larsa
Wed Apr 02, 2025 11:18 am
Forum: Forwarding Protocols
Topic: Problem Azure and bgp/vpn
Replies: 7
Views: 711

Re: Problem Azure and bgp/vpn

I might’ve missed or misunderstood something, but here are a few quick follow-up questions: 1. Is the Azure route (10.130.0.0/20) completely missing in the guest VRF, or is it there but inactive? If it’s inactive, it could be due to an unreachable next-hop or a higher route distance. 2. Are you usin...
by Larsa
Wed Apr 02, 2025 8:25 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 384
Views: 101743

Re: v7.19beta [testing] is released!

True word or gossip?

As Amm0 mentioned, check out the latest RFC as they’re working on now: RFC 9759 – Unified Time Scaling (synchronizing timers for MPLS). 😉
by Larsa
Tue Apr 01, 2025 10:33 pm
Forum: General
Topic: Leaking of IPv6 prefix that's not present on Router
Replies: 10
Views: 693

Re: Leaking of IPv6 prefix that's not present on Router

Ah, but of course, I totally missed that screenshot detail, good catch! 👍
That clears it up then. The connectivity issue clearly has nothing to do with that, so yep, looks like it was just a red herring. 😉
by Larsa
Tue Apr 01, 2025 9:50 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 384
Views: 101743

Re: v7.19beta [testing] is released!

please don't scare me, I got 8 BGP connections and a AS on a CCR running 7.15 since July I think and just considering to update and saw this :P

We’re still on 7.15 and won’t upgrade until there’s a long-term version with at least three patch releases.
by Larsa
Tue Apr 01, 2025 7:55 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 68
Views: 6512

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

It would also be valid to ask why input src-nat is omitted from the official packet flow diagrams by Mikrotik, while being fully and correctly supported.

Yeah, that question has come up a few times before. Personally, I think those packet flow diagrams have a lot of room for improvement! ;-)
by Larsa
Tue Apr 01, 2025 6:41 pm
Forum: Wireless Networking
Topic: Which router? [SOLVED]
Replies: 2
Views: 2353

Re: Which router? [SOLVED]

Hello @thomasz and welcome to the forum! Yes, both the RB5009 and L009 can handle this setup just fine. You can create two separate networks (either using VLANs or by assigning different ports) and connect each mesh system to its own network while still sharing the same internet connection. The RB50...
by Larsa
Tue Apr 01, 2025 6:35 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 68
Views: 6512

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

@lurker888: Great summary! Just wondering, why go with a bridge instead of assigning the addresses straight to the wg interface in this case? @Mimiko: You’ve probably already thought about it, but just a heads-up that each client still needs a unique public key in a separate peer entry, otherwise Wi...
by Larsa
Tue Apr 01, 2025 5:25 pm
Forum: General
Topic: Chromcast firewall rules
Replies: 4
Views: 384

Re: Chromcast firewall rules

Just a thought, and maybe I'm missing something, but can't you give full access just between the Chromecast and Streaming Host 1?
by Larsa
Tue Apr 01, 2025 5:09 pm
Forum: General
Topic: Leaking of IPv6 prefix that's not present on Router
Replies: 10
Views: 693

Re: Leaking of IPv6 prefix that's not present on Router

It seems you're running into a weird issue caused by multiple RA ULA prefixes being advertised on the same network. Your Mikrotik is advertising fd9d:..., but your Apple TV is also sending out RAs for fdf7:.... Devices like Home Assistant, the Apple Home app, and the HomeKit bridge might end up usin...
by Larsa
Tue Apr 01, 2025 4:13 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 68
Views: 6512

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

Okay, but first try to explain what you're trying to accomplish without using too many technical terms.
by Larsa
Tue Apr 01, 2025 3:58 pm
Forum: Beginner Basics
Topic: RB951G-2HnD - DUAL Wan Static IP
Replies: 4
Views: 365

Re: RB951G-2HnD - DUAL Wan Static IP

I want my router public ip address to be always that from nisp - regardless if aips is in use, my public ip should be that from nisp. That won’t work, unfortunately. You can’t use the public IP from nisp while sending traffic through aisp, since they’re on different networks and ISPs only route IPs...
by Larsa
Tue Apr 01, 2025 3:44 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 68
Views: 6512

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

It works. With routing rules, you force outbound traffic to use a specific egress interface, which automatically sets the source address to that WAN’s IP. But you can also use the Sindy NAT trick: "/ ip firewall nat chain=dstnat dst-address-type=local in-interface=WAN2 protocol=udp dst-port=wg-...
by Larsa
Tue Apr 01, 2025 2:56 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 68
Views: 6512

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

Have you tried policy routing using routing rules, with separate routing tables for each WireGuard instance?
by Larsa
Tue Apr 01, 2025 2:46 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 384
Views: 101743

Re: v7.19beta [testing] is released!

It might actually happen sooner than you'd expect. Word is Mikrotik has recently brought on about 15 people, supposedly working full-time on developing business-oriented features.
by Larsa
Tue Apr 01, 2025 2:02 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 540
Views: 157020

Re: v7.18.2 [stable] is released!

Mikrotik’s known VRRP’s been broken for a few releases now, but why it’s still not fixed is anyone’s guess. Still there in v7.19, apparently.

Pretty remarkable that a mission-critical HA (high availability) feature isn’t fixed right away, if you ask me.
by Larsa
Tue Apr 01, 2025 1:51 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 384
Views: 101743

Re: v7.19beta [testing] is released!

Anything about the VRRP bug yet?
by Larsa
Tue Apr 01, 2025 11:36 am
Forum: General
Topic: Chromcast firewall rules
Replies: 4
Views: 384

Re: Chromcast firewall rules

Hi @kanwhoa and welcome to the Mikrotik user forum! Thanks for the detailed post but a few things are a bit unclear though: You mention "full access between all bridge ports", but also describe firewall filtering between trusted and untrusted bridges. That sounds contradictory unless you m...
by Larsa
Tue Apr 01, 2025 8:43 am
Forum: General
Topic: VRRP Stuck in Master in both devices
Replies: 13
Views: 1812

Re: VRRP Stuck in Master in both devices

Great, that means Mikrotik has at least acknowledged the issue. The next step is to push the matter further and raise awareness in the two release channels that are currently active: v7.18.2 [stable] is released! v7.19beta [testing] is released! Post a short description of the problem, like in this ...
by Larsa
Mon Mar 31, 2025 10:05 pm
Forum: General
Topic: Leaking of IPv6 prefix that's not present on Router
Replies: 10
Views: 693

Re: Leaking of IPv6 prefix that's not present on Router

@kryptonian; this is most likely coming from an Apple device on your network. Apple HomeKit/Thread devices (especially early builds) can accidentally leak IPv6 prefixes via RA, like the 2103::/64 you're seeing. It’s not intentional, but it's a known quirk that’s been brought up in IPv6 and HomeKit d...
by Larsa
Mon Mar 31, 2025 6:09 pm
Forum: Beginner Basics
Topic: Phantom DAC created with L2TP/IPSEC
Replies: 6
Views: 524

Re: Phantom DAC created with L2TP/IPSEC

@jojorock If you really want help figuring this out, you need to be a lot clearer about what’s actually working and what’s not. Right now, some of what you're saying just doesn’t add up. You say the router isn’t even connected to the internet, has no local IP, no DNS, no DHCP… but then you show an a...
by Larsa
Mon Mar 31, 2025 5:13 pm
Forum: Beginner Basics
Topic: Phantom DAC created with L2TP/IPSEC
Replies: 6
Views: 524

Re: Phantom DAC created with L2TP/IPSEC

You have three L2TP clients enabled at the same time, all set to add-default-route=yes and dial-on-demand=yes. That creates multiple default routes which might cause unstable behavior, especially if another tunnel is added on top of this. The output from "ip route print" confirms it: 0 ADS...
by Larsa
Mon Mar 31, 2025 4:42 pm
Forum: Beginner Basics
Topic: Constant high outbound traffic from ether1
Replies: 14
Views: 1030

Re: Constant high outbound traffic from ether1

@eomcsqwipik: Once you’ve cleaned up your firewall, or preferably reset the entire router to factory default settings, and still see abnormally high outbound traffic, my guess is that you might have a compromised PC on your LAN that’s part of a botnet. P.S. Never, ever open any ports from the router...
by Larsa
Mon Mar 31, 2025 4:23 pm
Forum: General
Topic: ipv6 ND and vlan leaks
Replies: 13
Views: 832

Re: ipv6 ND and vlan leaks

I just glanced through your config very briefly and might be totally off or missing something here, so take this as a guess but it looks like both delegated IPv6 prefixes are being advertised on all VLANs. You're assigning one prefix to vlan10-lan and another to vlan20-iot, but the default /ipv6 nd ...
by Larsa
Mon Mar 31, 2025 4:03 pm
Forum: Beginner Basics
Topic: Phantom DAC created with L2TP/IPSEC
Replies: 6
Views: 524

Re: Phantom DAC created with L2TP/IPSEC

@jojorock; as @tdw pointed out, the DAC route is expected since it's created by the VPN tunnel. The remote and local IPs (i.e. 10.64.64.105 and 10.112.112.153) are assigned by the VPN server and the client might have limited control in this case. To figure out why the connection drops, here are a fe...
by Larsa
Mon Mar 31, 2025 2:37 pm
Forum: General
Topic: VRRP Stuck in Master in both devices
Replies: 13
Views: 1812

Re: VRRP Stuck in Master in both devices

If you haven't already, please report it to Mikrotik support (this is just a user forum).
by Larsa
Mon Mar 31, 2025 2:17 pm
Forum: Forwarding Protocols
Topic: Problem Azure and bgp/vpn
Replies: 7
Views: 711

Re: Problem Azure and bgp/vpn

Hi @FrancoisBellec and welcome to the forum! Azure usually requires EBGP multihop (typically TTL=255 for GTSM). Make sure multihop is enabled for the Azure peer. Routes might not be propagated across VRFs if the next-hop remains unreachable. It might also be worth checking if the Azure routes are ac...
by Larsa
Mon Mar 31, 2025 1:33 pm
Forum: General
Topic: Large UDP packets not fragmented and sent over IPSEC
Replies: 4
Views: 539

Re: Large UDP packets not fragmented and sent over IPSEC

Hi @Ishe and welcome to the forum! Are you running ROS v6? I'm not entirely sure, but I think ROS v6 had some issues with IP reassembly back in the day. Also (and this is just speculation) I vaguely remember reading somewhere that if fast-path was enabled, fragmented UDP packets might get dropped or...
by Larsa
Mon Mar 31, 2025 12:45 pm
Forum: Forwarding Protocols
Topic: MPLS has finally gotten stable ?
Replies: 18
Views: 7156

Re: MPLS has finally gotten stable ?

What makes you think starting a v8 branch would change anything? IMO (and just speculating here) MT would really benefit from reorganizing and establishing an R&D department dedicated specifically to enterprise networking. Of course, priorities and development direction naturally depend on their...
by Larsa
Mon Mar 31, 2025 12:07 pm
Forum: Beginner Basics
Topic: CCR2004-1G-2XS-PCIe Help needed
Replies: 1
Views: 303

Re: CCR2004-1G-2XS-PCIe Help needed

Hi @Turmoil3489 and welcome to the forum! Firstly, not all SFP modules are automatically compatible with Mikrotik devices. Please check if your module is on Mikrotik’s official compatibility list or is known to work with RouterOS. Incompatible or high-power modules may either not show up at all or r...
by Larsa
Sun Mar 30, 2025 9:34 pm
Forum: Scripting
Topic: wrong ssh-exec output [SOLVED]
Replies: 2
Views: 2362

Re: wrong ssh-exec output [SOLVED]

It's likely caused by newline or whitespace characters in the output returned by ssh-exec. Even if the visible result is '1', the actual string might include hidden characters like '\r' or '\n', which would explain the length of 3. The built-in :tonum doesn’t handle end-of-line characters well. You ...
by Larsa
Sun Mar 30, 2025 8:21 pm
Forum: Beginner Basics
Topic: Simple question about port forwarding
Replies: 1
Views: 293

Re: Simple question about port forwarding

Yeah, your first rule is enough i.e. you don’t need to create each port mapping separately. When you omit the to-ports parameter, Mikrotik ROS automatically assumes that the destination port on the internal IP (in your case, 192.168.81.108) should be the same as the one on the external request. So: ...
by Larsa
Fri Mar 28, 2025 8:59 pm
Forum: General
Topic: Is there any way to trace current DNS requests received by the router? [SOLVED]
Replies: 7
Views: 5678

Re: Is there any way to trace current DNS requests received by the router? [SOLVED]

Yep, just predefine topic=dns and enable it when needed. It might still be a good idea to create your own action=DNSLOG. That way, you can easily filter out just the DNS requests once logging is enabled.
by Larsa
Fri Mar 28, 2025 8:45 pm
Forum: General
Topic: Problems with traffic flow through IPsec tunnel [SOLVED]
Replies: 2
Views: 4673

Re: Problems with traffic flow through IPsec tunnel [SOLVED]

Hi Alex and welcome to the forum! From your description, it sounds like you're running ROS v7 on a Mikrotik HeX (RB750Gr3) on the local side, but just to confirm, is the remote side a Bintec RS353? If so, that means there's only a Mikrotik device on one end of the IPsec tunnel, correct? That might b...
by Larsa
Fri Mar 28, 2025 7:31 pm
Forum: General
Topic: /file console-dump.txt
Replies: 5
Views: 544

Re: /file console-dump.txt

Your device might be hacked!
by Larsa
Fri Mar 28, 2025 7:29 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 384
Views: 101743

Re: v7.19beta [testing] is released!

I just don’t get why they still go with only 16MB. Not exactly future-proof, if you ask me. If you look at the cost for 32MB, the difference is basically pocket lint. The only explanation I can come up with is that they’re sitting on some massive warehouse full of 16MB chips they’re desperately tryi...
by Larsa
Fri Mar 28, 2025 7:07 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 384
Views: 101743

Re: v7.19beta [testing] is released!

@infabo: Not the new LMP 5G that was announced with just 16 MB of storage(!)
by Larsa
Fri Mar 28, 2025 6:33 pm
Forum: General
Topic: Is there any way to trace current DNS requests received by the router? [SOLVED]
Replies: 7
Views: 5678

Re: Is there any way to trace current DNS requests received by the router? [SOLVED]

I was hoping there would be a simpler way to see the DNS requests passing through my router. It's actually pretty easy! Just create your own logging action (output), for example called DNSLOG , and then add a logging rule for DNS requests using that action. After that, check all DNS requests by ope...
by Larsa
Fri Mar 28, 2025 4:47 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 384
Views: 101743

Re: v7.19beta [testing] is released!

I don’t mind paying a bit extra for enterprise-level functionality. This could serve as an additional revenue stream that helps fund continued development and support, especially with a focus on advanced functionality for businesses and service providers.
by Larsa
Fri Mar 28, 2025 12:12 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 384
Views: 101743

Re: v7.19beta [testing] is released!

.. I am able to venture that perhaps MikroTik will have to think about different Software and Firmware (Routerboard) for the same hardware for different applications. ... If the fight to split the main software package is already big, imagine thinking about multiple flavors of firmware? It's going ...
by Larsa
Thu Mar 27, 2025 9:20 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 384
Views: 101743

Re: v7.19beta [testing] is released!

Are you referring to MPLS L3 VPN RFC 4364, a generic IPv6 VPN RFC 4213, or tunneling methods like those in RFC 2473 or 2784/2890?

If you’re talking about MPLS, there are plenty of other mainstream capabilities I’d prefer to see implemented as well like EVPN, SR, TE and OAM.
by Larsa
Wed Mar 26, 2025 4:36 pm
Forum: General
Topic: Unable to send email via smtp.gmail.com
Replies: 16
Views: 1188

Re: Unable to send email via smtp.gmail.com

Hard to say exactly what’s going wrong, but an easy way to troubleshoot is to run "/system telnet" from a router that's having issues. This guide shows how to Testing SMTP using Telnet . It’ll let you see where the SMTP process is failing and should give you a proper error message in plain...
by Larsa
Wed Mar 26, 2025 4:14 pm
Forum: General
Topic: VRRP Best Practices
Replies: 3
Views: 559

Re: VRRP Best Practices

That's an even better alternative! Makes sense to balance the load and get the most out of both routers/providers while still keeping failover in place.
by Larsa
Wed Mar 26, 2025 3:47 pm
Forum: General
Topic: Unable to send email via smtp.gmail.com
Replies: 16
Views: 1188

Re: Unable to send email via smtp.gmail.com

If you're sending on behalf of "<user>@<myowndomain>.com" from a new IP address that isn’t part of Google Workspace’s infrastructure, you’ll need to manually add that IP address to your domain’s SPF record. Otherwise, Google (and other receivers) may reject or flag the message as unauthori...
by Larsa
Wed Mar 26, 2025 3:11 pm
Forum: General
Topic: Unable to send email via smtp.gmail.com
Replies: 16
Views: 1188

Re: Unable to send email via smtp.gmail.com

Just a quick follow-up to clarify: A Google app password usually works fine out of the box for regular Gmail addresses (like xxxxx@gmail.com). But if you're sending from a custom domain (like xxxx@yyyyy.com), it won’t work unless a proper SPF record is set up for that domain.
by Larsa
Wed Mar 26, 2025 1:36 pm
Forum: General
Topic: Unable to send email via smtp.gmail.com
Replies: 16
Views: 1188

Re: Unable to send email via smtp.gmail.com

Just to add to what's already been said: Google has become much stricter to prevent spam and abuse. An AUTH failure might not only mean wrong credentials. It can also happen if the sender is not authorised to send on behalf of the domain used in the "MAIL FROM:" during SMTP. Make sure the ...
by Larsa
Wed Mar 26, 2025 1:12 pm
Forum: General
Topic: VRRP Best Practices
Replies: 3
Views: 559

Re: VRRP Best Practices

I think option 2 might be cleaner and easier to maintain, especially with multiple VLANs. Fewer VRRP instances means less config overhead. Plus, tying VRRP directly to the main bonded interface ensures proper failover behavior. Unless you have a specific reason to isolate each VLAN with its own VRRP...
by Larsa
Tue Mar 25, 2025 9:51 pm
Forum: General
Topic: fasttrack x86
Replies: 22
Views: 4194

Re: fasttrack x86

To me, the key question still is: Does FastPath require a hard dependency on patched drivers, or can ROS use skb with standard hooks? Yes, of course. That's what we are discussing. Yeah, but you forgot to add my mighty conclusion: I’m still convinced it’s the latter — meaning this can be abstracted...
by Larsa
Tue Mar 25, 2025 5:28 pm
Forum: Forwarding Protocols
Topic: OSPF area id 0.0.0.0 does not consider interface cost
Replies: 10
Views: 1085

Re: OSPF area id 0.0.0.0 does not consider interface cost

It sounds like there might be some kind of misconfiguration. If you're absolutely sure everything is set up correctly, I’d recommend reaching out to support for further assistance. I don't have the time or resources to set up a test environment to check this for you, I hope you understand. A few add...
by Larsa
Tue Mar 25, 2025 4:12 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 175
Views: 20442

Re: New exciting features for storage

/disk test utility clears caches before running tests. Just a quick follow-up on the cache clearing part: even if /disk test flushes some caches before the run, that doesn't necessarily eliminate caching effects—especially in short burst tests where you're still likely to hit RAM-level buffers or c...
by Larsa
Tue Mar 25, 2025 2:13 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 175
Views: 20442

Re: New exciting features for storage

Just a quick note on the short bursts: those are most likely hitting cached data rather than reflecting sustained transfer speeds from storage to user space. The comparison to dd might be useful for Linux users, though both tools are fairly synthetic and don’t always reflect real-world I/O patterns....
by Larsa
Tue Mar 25, 2025 1:24 pm
Forum: General
Topic: fasttrack x86
Replies: 22
Views: 4194

Re: fasttrack x86

Hey, good points and nice digging! It’s fair to point out that Mikrotik has patched drivers, as you mentioned with L2MTU — but that was mostly with ROS 6.x. When ROS v6 was built on Linux 3.3.5, there were quite a few limitations around L2MTU handling, both in the networking stack and in many driver...
by Larsa
Mon Mar 24, 2025 10:38 pm
Forum: General
Topic: fasttrack x86
Replies: 22
Views: 4194

Re: fasttrack x86

My take: Honestly, I think “ interface driver extension ” most likely refers to using something like the skb->cb[] control buffer to tag packets internally. That buffer is explicitly designed for storing temporary, per-packet metadata and is commonly used by various subsystems (including Netfilter a...
by Larsa
Mon Mar 24, 2025 5:39 pm
Forum: General
Topic: fasttrack x86
Replies: 22
Views: 4194

Re: fasttrack x86

@NathanA: Fastpath and Fasttrack generally speaking do NOT work on x86....however, both of these features require specific support to be added to the network interface driver (ethernet chip, etc.). Do you know how it actually works under the hood? My guess is that Mikrotik uses their own skb attrib...
by Larsa
Mon Mar 24, 2025 2:52 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 175
Views: 20442

Re: New exciting features for storage

I just realized I wasn’t clear enough. I meant running a disk speed test directly on the RDS2216 inside a container, if that’s possible.
by Larsa
Mon Mar 24, 2025 2:18 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 175
Views: 20442

Re: New exciting features for storage

Would be interesting to see the same tests run directly on the RDS2216. Any chance you could give that a try?
by Larsa
Sun Mar 23, 2025 8:28 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 175
Views: 20442

Re: New exciting features for storage

Thanks for great feedback and for sharing your hands-on experience! Looking forward to seeing what you come up with next.
by Larsa
Thu Mar 20, 2025 9:48 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 175
Views: 20442

Re: New exciting features for storage

Normis, if Mikrotik is still serious about developing a storage solution, it might be more practical to offer it as an add-on "install package" using one of the well-established open-source storage platforms rather than building a proprietary system from scratch. I strongly advise against ...
by Larsa
Thu Mar 20, 2025 6:20 pm
Forum: Forwarding Protocols
Topic: OSPF area id 0.0.0.0 does not consider interface cost
Replies: 10
Views: 1085

Re: OSPF area id 0.0.0.0 does not consider interface cost

Some troubleshooting tips: Enable BFD on all links to get a fast response when toggling links or making other changes. Set up OSPF logging on all routers to check if they are sending and receiving proper LSA messages. ( /system logging add topics=ospf,!packet action=memory ). If you can't spot inbou...
by Larsa
Thu Mar 20, 2025 2:28 pm
Forum: Forwarding Protocols
Topic: OSPF area id 0.0.0.0 does not consider interface cost
Replies: 10
Views: 1085

Re: OSPF area id 0.0.0.0 does not consider interface cost

The following recommendations are general since you haven’t described the overall topology of the solution. With over 500 subnets, I’d definitely consider using multiple OSPF areas, particularly Stub Areas or NSSA for your LTE links if they are not part of a transit path. Use area summarization at A...
by Larsa
Wed Mar 19, 2025 7:35 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 175
Views: 20442

Re: New exciting features for storage

Putting lipstick on a pig but since someone called it "Kermit the NAS," I guess it’s more like putting lipstick on Miss Piggy! 😉
by Larsa
Wed Mar 19, 2025 5:54 pm
Forum: Forwarding Protocols
Topic: OSPF area id 0.0.0.0 does not consider interface cost
Replies: 10
Views: 1085

Re: OSPF area id 0.0.0.0 does not consider interface cost

No need to use multiple areas, loopback interfaces, Stub, NSSA, or filters. In your scenario, just use a single area, and costs will work as expected. (Routing->OSPF->Interface Templates)
by Larsa
Wed Mar 19, 2025 5:27 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 175
Views: 20442

Re: New exciting features for storage

Normis, thanks for the reply and details on existing features. But let’s be real here—while these are basic storage functions , they’re nowhere near the administrative tools that actual enterprise (or even small office/home office) NAS solutions provide. Restructuring – More than just RAID Restructu...
by Larsa
Wed Mar 19, 2025 6:47 am
Forum: Announcements
Topic: New exciting features for storage
Replies: 175
Views: 20442

Re: New exciting features for storage

Managing storage requires administrative tools for restructuring, error handling, and backup/restore. All of these are missing in ROS. In other words, this solution is not suitable for mission-critical applications.
by Larsa
Tue Mar 18, 2025 6:53 pm
Forum: General
Topic: renew ssl certificate let's encrypt
Replies: 15
Views: 1425

Re: renew ssl certificate let's encrypt

Thanks for the feedback!

Anyone know if it's only web-wwl that works with automatic renewal of LE certificates using the DNS-01 challenge, or if it will also work for IPsec and cloud domains (ie, "type=cloud-dns")?
by Larsa
Tue Mar 18, 2025 4:45 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 384
Views: 101743

Re: v7.19beta [testing] is released!

Just for the record, in case this wasn’t reported to support: The Let's Encrypt DNS-01 challenge has stopped working. Ref: viewtopic.php?p=1133904
by Larsa
Tue Mar 18, 2025 4:44 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 540
Views: 157020

Re: v7.18.2 [stable] is released!

Just for the record, in case this wasn’t reported to support: The Let's Encrypt DNS-01 challenge has stopped working. Ref: viewtopic.php?p=1133904
by Larsa
Tue Mar 18, 2025 2:09 pm
Forum: General
Topic: renew ssl certificate let's encrypt
Replies: 15
Views: 1425

Re: renew ssl certificate let's encrypt

It is. And actually worked without port 80 open when I first issued the certificate with type=cloud-dns. This was introduced in 7.16. But maybe is broken now. I dont know.

Yeah, sounds like a bug to me. Maybe someone should open a ticket or mail "support@mikrotik.com" about it.
by Larsa
Tue Mar 18, 2025 1:13 pm
Forum: General
Topic: renew ssl certificate let's encrypt
Replies: 15
Views: 1425

Re: renew ssl certificate let's encrypt

I thought the whole idea of the Let's Encrypt DNS-01 challenge was that it doesn't require port 80 at all. Have I missed something?
by Larsa
Tue Mar 18, 2025 11:27 am
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 173
Views: 56003

Re: Feature Request: IPSEC Improvements

@wispmikrotik; This is just a user forum. You should get in touch directly with Mikrotik sales at "sales@mikrotik.com" or their support team at "support@mikrotik.com" for official information and assistance.
by Larsa
Tue Mar 18, 2025 9:29 am
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 173
Views: 56003

Re: Feature Request: IPSEC Improvements

@wmeibers: XFRM has been a standard part of IPsec since Linux 2.6, which was released in December 2003.
by Larsa
Mon Mar 17, 2025 11:37 pm
Forum: General
Topic: GNS3 with Mikrotik devices
Replies: 7
Views: 956

Re: GNS3 with Mikrotik devices

Unfortunately no wireless or anything else, just plain CHR.
by Larsa
Mon Mar 17, 2025 11:35 pm
Forum: General
Topic: forum guru status
Replies: 27
Views: 2136

Re: forum guru status

Well, congrats on guru status! Now, the real test: What’s the meaning of life? 😁
by Larsa
Mon Mar 17, 2025 11:26 pm
Forum: General
Topic: GNS3 with Mikrotik devices
Replies: 7
Views: 956

Re: GNS3 with Mikrotik devices

GNS3 is like ROS, pretty easy once you connect the dots! 😉 It runs just as well on Windows Hyper-V.
by Larsa
Mon Mar 17, 2025 3:11 pm
Forum: General
Topic: forum guru status
Replies: 27
Views: 2136

Re: Guru?!?!?

Yeah, I feel you. Times are rough, so enjoy all your slaps while you can! 😘
by Larsa
Mon Mar 17, 2025 2:03 pm
Forum: General
Topic: forum guru status
Replies: 27
Views: 2136

Re: Guru?!?!?

@anav, you gotta forgive me, but that was seriously hilarious!! ROFL 😂🤣😆

Ps..
@anav, you officially have 10 slaps reserved! 😉
by Larsa
Sat Mar 15, 2025 1:11 am
Forum: MikroTik hardware questions
Topic: Hardware for x86 (Replacing 2216)
Replies: 30
Views: 11532

Re: Hardware for x86 (Replacing 2216)

I just built an Ampere 80-core 3GHz machine and, now that I came across this thread, I'll be testing 40Gbps NICs, and eventually 100Gbps (if I can justify the expense; have zero need for it yet). You don’t need an 80-core 3GHz CPU to handle 100Gbps! Less than 16 cores are enough with proper NIC acc...
by Larsa
Sat Mar 15, 2025 1:00 am
Forum: MikroTik hardware questions
Topic: Hardware for x86 (Replacing 2216)
Replies: 30
Views: 11532

Re: Hardware for x86 (Replacing 2216)

PortalNET: The secret that no one will tell you.. either because they have not lost time testing.. is the NIC cards... in order to suceed with Multi-CPU x86_64 on RouterOS v7.15.xx stable version.. is the Network cards... because they are related to IRQ on the CPU.. Amm0: I'd listen to PortalNET co...
by Larsa
Fri Mar 14, 2025 1:30 am
Forum: General
Topic: PPPoE Compatibility Issues with vBRAS/NFV
Replies: 24
Views: 3303

Re: PPPoE Compatibility Issues with vBRAS/NFV

Totally off-topic, but I really don’t get why some ISPs still insist on using outdated tech like PPPoE with FTTx. I mean, all modern BNGs support IPoE with optional VLAN tagging, which is so much easier to set up and manage. Using PPPoE is just plain dumb and overcomplicated. ;-)
by Larsa
Fri Mar 14, 2025 1:07 am
Forum: General
Topic: Feature Request: LetsEncrypt certs via DNS Challenge
Replies: 10
Views: 1189

Re: Feature Request: LetsEncrypt certs via DNS Challenge

Nope, that’s about the www-ssl certificates I mentioned in my previous post. There’s no official Mikrotik documentation on sn.mynetname.net , just like this external blog also points out: " There is no documentation yet. How does this feature work? Let’s find out... " Maybe someone can ema...
by Larsa
Fri Mar 14, 2025 12:13 am
Forum: General
Topic: Feature Request: LetsEncrypt certs via DNS Challenge
Replies: 10
Views: 1189

Re: Feature Request: LetsEncrypt certs via DNS Challenge

I tried to find some comprehensive Mikrotik documentation on Let's Encrypt, but it looks like there's nothing except some brief info on certificate support for the 'www-ssl' service, IPsec and this external blog about cloud-dns.
by Larsa
Thu Mar 13, 2025 10:57 pm
Forum: General
Topic: Feature Request: LetsEncrypt certs via DNS Challenge
Replies: 10
Views: 1189

Re: Feature Request: LetsEncrypt certs via DNS Challenge

@Sindy claimed that updates for LetsEncrypt (LE) certs are now built into ROS and therefore don’t need to be scripted anymore. We don’t use LE, so I haven’t bothered to verify this. What’s the actual situation with this?
by Larsa
Thu Mar 13, 2025 9:31 am
Forum: Forwarding Protocols
Topic: v7.1.1 OspfNeighbor received wrong LS Ack
Replies: 48
Views: 42356

Re: v7.1.1 OspfNeighbor received wrong LS Ack

This is just a user forum. Please file a bug report with Mikrotik support or report it in the corresponding ROS version release thread.
by Larsa
Mon Mar 10, 2025 4:55 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2141
Views: 1292599

Re: 📣 WinBox 4 is here 📣

Yes.

Yes to what? 🤔

Anyway, my guess is that they’re till using v3. It would be interesting to see what would happen if everyone were forced to use v4. 😉
by Larsa
Mon Mar 10, 2025 2:20 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2141
Views: 1292599

Re: 📣 WinBox 4 is here 📣

Sign of times.
When mobile UI moves into desktop, it's a sign of idiotism.

Hear, hear!

Ps..
We don’t really know what’s going on behind the scenes, but one can’t help but wonder if they are deliberately ignoring the serious design flaws by burying their heads in the sand?!
by Larsa
Thu Mar 06, 2025 8:42 pm
Forum: MikroTik hardware questions
Topic: Mikrotik 5G hardware roadmap
Replies: 22
Views: 10162

Re: Mikrotik 5G hardware roadmap

I forgot to mention that most NMOs have a soft cap on max speed. With a standard consumer plan, inbound speeds usually top out around 800-900 Mbps. If you want higher, guaranteed speeds with better latency, you’ll need to pay extra.
by Larsa
Thu Mar 06, 2025 6:40 pm
Forum: MikroTik hardware questions
Topic: Mikrotik 5G hardware roadmap
Replies: 22
Views: 10162

Re: Mikrotik 5G hardware roadmap

5G/NR on normal/mid bands (FR1) will never ever get you 7 Gbps. For that, you’ll need a 5G radio that supports FR2, but the trade-off is a much smaller coverage area and you’ll have to be within 50 meters of the base station antenna to get that kind of speed.
by Larsa
Thu Mar 06, 2025 4:10 pm
Forum: Virtualization
Topic: CHR on GGCP slow download
Replies: 21
Views: 13617

Re: CHR on GGCP slow download

Thanks for testing! Since 7.16.2 and 7.15.3 give the same results as 7.18.1, it doesn’t seem to be a version-specific issue. But the fact that 6.49.18 performs so much better with the exact same settings is really weird. It might be worth checking if there have been any changes to the default TCP se...
by Larsa
Wed Mar 05, 2025 11:55 pm
Forum: MikroTik hardware questions
Topic: Mikrotik 5G hardware roadmap
Replies: 22
Views: 10162

Re: Mikrotik 5G hardware roadmap

LMP 5G with only 16 MB of storage, seriously?! The ATL 5G looks really promising, though. I guess all these new models are announced on MWC25's final day tomorrow (Thursday).

Another thing that struck me is that Mikrotik has been improving its design language.
by Larsa
Wed Mar 05, 2025 10:21 pm
Forum: Virtualization
Topic: CHR on GGCP slow download
Replies: 21
Views: 13617

Re: CHR on GGCP slow download

Okay, with the same config as v6? Then it might be 7.18.1. Have you tried 7.15.3 or 7.16.2? Btw, just wondering, are you using some kind of default ROS firewall config while testing? What endpoints are you using while testing? Exactly the same default CHR config. No ROS firewall at all (I've posted...
by Larsa
Wed Mar 05, 2025 9:04 pm
Forum: Virtualization
Topic: CHR on GGCP slow download
Replies: 21
Views: 13617

Re: CHR on GGCP slow download

Okay, with the same config as v6? Then it might be 7.18.1. Have you tried 7.15.3 or 7.16.2? Btw, just wondering, are you using some kind of default ROS firewall config while testing? What endpoints are you using while testing? EDIT: Just tried iPerf in a lab instance with v7.15 to a local Win11 and ...
by Larsa
Wed Mar 05, 2025 8:09 pm
Forum: General
Topic: Route two different ISP parallel communication is it posible [SOLVED]
Replies: 16
Views: 8032

Re: Route two different ISP parallel communication is it posible [SOLVED]

No need to speculate. This is a standard setup to get split outbound traffic working, just like he asked. If there’s anything else, I’m pretty sure @nonpe can speak for himself.
by Larsa
Wed Mar 05, 2025 7:25 pm
Forum: General
Topic: CORE ROUTER CCR 1036 12G 4S
Replies: 3
Views: 1046

Re: CORE ROUTER CCR 1036 12G 4S

@omoluwabi; The CCR1036-12G-4S is a powerhouse router with a 36-core CPU, delivering around 15 Gbps routing capacity and 10 Gbps with 256 IPsec tunnels. It has no problem handling a full BGP table with more than 1 million IPv4 prefixes and approx 220,000 IPv6 prefixes. It’s equipped with only GbE po...
by Larsa
Wed Mar 05, 2025 6:34 pm
Forum: General
Topic: Route two different ISP parallel communication is it posible [SOLVED]
Replies: 16
Views: 8032

Re: Route two different ISP parallel communication is it posible [SOLVED]

@nonpe; you can try this setup to route subnet 192.168.88.1/24 through ISP2 while keeping ISP1 as the default gateway for everything else. This assumes you’ve already created the routing table ISP2. 1. Mark traffic from the subnet to use ISP2 /routing rule add src-address=192.168.88.1/24 action=look...
by Larsa
Wed Mar 05, 2025 3:32 pm
Forum: Virtualization
Topic: CHR on GGCP slow download
Replies: 21
Views: 13617

Re: CHR on GGCP slow download

To start with, e2-micro is an entry-level VPS type with a shared vCPU, which means it only gets a fraction of a physical CPU core. When the vCPU is shared with other workloads, it can easily get maxed out and cause CHR’s throughput to drop to almost zero. Second, the VPC firewall should be turned of...
by Larsa
Wed Mar 05, 2025 1:49 pm
Forum: General
Topic: VRRP multicast traffic isolation
Replies: 2
Views: 4484

Re: VRRP multicast traffic isolation

Read about authentication in the Mikrotik docs: RouterOS > High Availability Solutions > VRRP
by Larsa
Wed Mar 05, 2025 11:14 am
Forum: General
Topic: My Mikrotik is sometimes incredible slow, need help.
Replies: 19
Views: 1893

Re: My Mikrotik is sometimes incredible slow, need help.

I have an issue with my old Mikrotik CRS125-24G-1S switch. My internet (or LAN connection) is sometimes incredible slow! Using my ethernet connected pc is sometimes only 1-2Mbit/sec, same if I test with another computer, or through a Wireless AP...Looking at Resources, it says cpu load is somewhere...
by Larsa
Tue Mar 04, 2025 10:10 pm
Forum: General
Topic: Feature Request: Official BNF for RouterOS Scripting
Replies: 4
Views: 1535

Re: Feature Request: Official BNF for RouterOS Scripting

Looks like your looking for a syntax checker while I am looking for a syntax teacher. :-) No reason why we both cant be happy.

Haha, yeah! Some of those add-ons actually do both if you hook them up to Copilot. Win-win!
by Larsa
Tue Mar 04, 2025 8:38 pm
Forum: General
Topic: Request for Comprehensive RouterOS v7 Manual with Examples to build code generation chatbot
Replies: 81
Views: 13708

Re: Request for Comprehensive RouterOS v7 Manual with Examples to build code generation chatbot

I have an opinion nonetheless (they're free, after all): Why not check out claude.ai's current level of understanding before concluding how to make AI more accurate and useful for ROS config help? My analysis on how well claude.ai does with ROS is not worth the electrons used to express them here, ...
by Larsa
Tue Mar 04, 2025 8:06 pm
Forum: General
Topic: Feature Request: Official BNF for RouterOS Scripting
Replies: 4
Views: 1535

Re: Feature Request: Official BNF for RouterOS Scripting

Nowadays, almost all tools, like editors and IDEs like Notepad++, Emacs, and VS Code, can read BNF and highlight syntax errors. Smart IDEs like Visual Studio, Eclipse, and JetBrains can also warn about logical errors, such as unassigned or misspelled variables, flawed conditions (if/then/else), infi...
by Larsa
Tue Mar 04, 2025 7:42 pm
Forum: General
Topic: Feature Request: Official BNF for RouterOS Scripting
Replies: 4
Views: 1535

Feature Request: Official BNF for RouterOS Scripting

Background Many developers and tools, including modern AI/LLM models, can now understand and process formal syntax definitions. Having an official BNF (Backus-Naur Form) for ROS scripting would make it much easier to analyze, validate, and generate scripts accurately. Why this would be useful Bette...
by Larsa
Tue Mar 04, 2025 7:42 pm
Forum: General
Topic: Request for Comprehensive RouterOS v7 Manual with Examples to build code generation chatbot
Replies: 81
Views: 13708

Re: Request for Comprehensive RouterOS v7 Manual with Examples to build code generation chatbot

So if you ask me... better AI with RouterOS config start with an LSP. And LSP be useful since a real person can use it check their own code and get "hints" etc. Win, win. Since today's LLMs also understand syntax definitions and can be trained accordingly, it would be great if Mikrotik co...
by Larsa
Tue Mar 04, 2025 4:04 pm
Forum: General
Topic: Request for Comprehensive RouterOS v7 Manual with Examples to build code generation chatbot
Replies: 81
Views: 13708

Re: Request for Comprehensive RouterOS v7 Manual with Examples to build code generation chatbot

But it's RouterOS scripting where these LLM falter. Stuff like JavaScript is 10000x more common & on top there is plenty of linter to pre-check output of LLM for JavaScript validity. I'd have to imagine more LLM take advantage of "LSP" (see https://langserver.org), while open standard...
by Larsa
Tue Mar 04, 2025 3:55 pm
Forum: General
Topic: Request for Comprehensive RouterOS v7 Manual with Examples to build code generation chatbot
Replies: 81
Views: 13708

Re: Request for Comprehensive RouterOS v7 Manual with Examples to build code generation chatbot

Yeah, AI is great for boilerplate work, but you need to know the basics to fix the flaws. Plus, you need access to multiple LLM engines (ie different models) since answers still vary a lot depending on the situation.
by Larsa
Tue Mar 04, 2025 3:46 pm
Forum: Beginner Basics
Topic: Re: Setting Up Policy-Based Routing with Mikrotik Hex Refresh for Selective VPN Traffic [SOLVED]
Replies: 51
Views: 10740

Re: Setting Up Policy-Based Routing with Mikrotik Hex Refresh for Selective VPN Traffic [SOLVED]

Didn’t mean you specifically, but if you relate… well, I’m not gonna argue! 65+ maybe? :D
by Larsa
Tue Mar 04, 2025 3:28 pm
Forum: Beginner Basics
Topic: Re: Setting Up Policy-Based Routing with Mikrotik Hex Refresh for Selective VPN Traffic [SOLVED]
Replies: 51
Views: 10740

Re: Setting Up Policy-Based Routing with Mikrotik Hex Refresh for Selective VPN Traffic [SOLVED]

@3zzy, don’t mind all the grumpy old men in this forum. Everyone has different backgrounds and opinions on what’s right or wrong ;) I totally get your point. Not everyone has the same learning style, and modern tools exist to make complex tasks more accessible. While mastering the basics is valuable...
by Larsa
Tue Mar 04, 2025 2:38 pm
Forum: Forwarding Protocols
Topic: BFD without dynmaic routing protocol
Replies: 7
Views: 1189

Re: BFD without dynmaic routing protocol

Firstly, have you considered VRRP? I think this would be an easy-to-implement and elegant solution using the MikroTik devices. VRRP would also be completely independent of other devices in the network for their default gateway. You can also add ROS Netwatch to monitor the ISP connection status and t...
by Larsa
Tue Mar 04, 2025 1:29 pm
Forum: Forwarding Protocols
Topic: BFD without dynmaic routing protocol
Replies: 7
Views: 1189

Re: BFD without dynmaic routing protocol

This is just a thought but have you considered VRRP as described in Mikrotik RouterOS > High Availability Solutions VRRP.

Anyhow, if you need further help, you'll need to provide much more detail about the entire setup in the drawing.
by Larsa
Tue Mar 04, 2025 1:14 pm
Forum: Forwarding Protocols
Topic: BFD without dynmaic routing protocol
Replies: 7
Views: 1189

Re: BFD without dynmaic routing protocol

BFD is just a signaling protocol, and ROS can use it with OSPF or BGP. How is the device in the drawing, labeled "Device with Single HOP BFD Activated," configured in terms of type/model, protocol (L2/L3?), etc.? Is it under your control? Since you haven't provided any details about the se...
by Larsa
Mon Mar 03, 2025 10:44 pm
Forum: Beginner Basics
Topic: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492
Replies: 104
Views: 12553

Re: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492

Yeah, for a router like CHR, there aren't really any obvious advantages to running it x86 "bare metal." On the contrary, it's way easier to manage a virtual instance with CHR, which is also easy to move "live" between different environments if you need to perform maintenance on a...
by Larsa
Mon Mar 03, 2025 9:03 pm
Forum: Beginner Basics
Topic: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492
Replies: 104
Views: 12553

Re: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492

Reply from Mikrotik support: "Seems like some HW limitation, try using hypervisor and install CHR, this will allow to deal with hw incompatibilities if such arise. We do not create drivers for hw, they are based on Linux kernel. " @himurae; that reply from Mikrotik support is not entirely...
by Larsa
Mon Mar 03, 2025 6:46 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 175
Views: 20442

Re: 📣 WinBox 4 is here 📣

n/a
by Larsa
Mon Mar 03, 2025 6:38 pm
Forum: Beginner Basics
Topic: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492
Replies: 104
Views: 12553

Re: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492

@anav; afaik, all VPS providers allow you to configure lower NIC MTUs. But why would you need a lower NIC MTU in a cloud environment?
by Larsa
Mon Mar 03, 2025 5:37 pm
Forum: Beginner Basics
Topic: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492
Replies: 104
Views: 12553

Re: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492

This is how you change the MTU in a virtual environment running CHR (or any other virtual guest). Windows Hyper-V - With SR-IOV: MTU can be changed directly by CHR. - Without SR-IOV (using the Hyper-V virtual switch): MTU must be set on the host first and then on the virtual switch for changes to ta...
by Larsa
Mon Mar 03, 2025 9:58 am
Forum: Forwarding Protocols
Topic: OSPF - Null auth failure when setting non-default instance
Replies: 2
Views: 2233

Re: OSPF - Null auth failure when setting non-default instance

Keep instance-id=0 (default and standard for OSPFv2) to maintain compatibility with BIRD and other OSPF implementations. Changing it is unnecessary unless using OSPFv3 multi-instance setups, which I suspect doesn't apply here. If running an older RouterOS version, consider upgrading, since MikroTik ...
by Larsa
Sun Mar 02, 2025 10:00 pm
Forum: General
Topic: DMVPN
Replies: 4
Views: 1321

Re: DMVPN

A modern alternative to DMVPN is an SD-WAN solution like ZeroTier, which is built into RouterOS. If you need both, you can integrate DMVPN with ZeroTier.
by Larsa
Sat Mar 01, 2025 6:28 pm
Forum: Virtualization
Topic: CHR on GGCP slow download
Replies: 21
Views: 13617

Re: CHR on GGCP slow download

20250301, The problem is still happening, Neither Mikrotik nor Google Cloud solved the problem, Can anyone submit a new ticket to Mikrotik? @bugtik, if you need help in this user forum, you’ll have to provide more details about your GCE setup, including networking (GCP/VPC), mode, IP settings, fire...
by Larsa
Fri Feb 28, 2025 8:21 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2141
Views: 1292599

Re: 📣 WinBox 4 is here 📣

@Teslasystems: Wow, that was truly an impressive amount of quality work you put into this. Hope you get some feedback from Mikrotik.
by Larsa
Fri Feb 28, 2025 6:26 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 175
Views: 20442

Re: New exciting features for storage

Larsa, you are confusing this with a home NAS. It's not Normis, does indeed not! 😉 Just to be clear, I'm comparing the RouterOS v7 special ROSE edition, running on the ROSE Enterprise Data Server RDS2216 (" designed for enterprise environments. Secure, scalable, and under your control "),...
by Larsa
Fri Feb 28, 2025 3:06 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 384
Views: 101743

Re: v7.19beta [testing] is released!

In general, "improved stability" usually means that they've fixed a bug that used to cause a crash.
by Larsa
Fri Feb 28, 2025 1:46 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 540
Views: 157020

Re: v7.18 [stable] is released!

I just realized I forgot to give a heads-up in this thread too, like I did in "v7.18rc [testing]":

Heads-up - breaking changes for management and monitoring:
*) console - put !empty sentence when API query returns nothing;
by Larsa
Fri Feb 28, 2025 1:27 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 175
Views: 20442

Re: New exciting features for storage

Yeah, but why waste valuable resources on this experiment? I mean, it’s not even close to offering basic functionality for the SMB market like DSM or QTS do, so IMO the whole concept is dead on arrival and just a total waste of money. Why not just call it what it is: a router with some extra storage...
by Larsa
Fri Feb 28, 2025 10:51 am
Forum: Announcements
Topic: New exciting features for storage
Replies: 175
Views: 20442

Re: New exciting features for storage

Hmm, I’d say the RDS2216 sits somewhere between the CCR2216 and CCR2116 in terms of both specs and price. But yeah, the RDS2216 has a pretty attractive price for that configuration, plus, like you said, you get some storage as well (though personally I wouldn’t use it as a business-critical storage ...
by Larsa
Fri Feb 28, 2025 8:32 am
Forum: Announcements
Topic: New exciting features for storage
Replies: 175
Views: 20442

Re: New exciting features for storage

Well, this new ”cool toy” RDS2216 isn’t even playing the same sport as WAFL, let alone competing in 24x7x365 business-critical operations.

I’d say MikroTik is in way over its head on this one and in a different galaxy than NetApp. 😉
by Larsa
Thu Feb 27, 2025 10:38 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 175
Views: 20442

Re: New exciting features for storage

Even vanilla Btrfs RAID 1 can be a real headache, for example, if a disk intermittently disconnects or fails for some reason and then gets marked as unreliable. Restoring a Btrfs RAID 1 is a pretty complicated process and requires expert knowledge, as @Petch1 pointed out in another thread. In other ...
by Larsa
Thu Feb 27, 2025 8:14 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 540
Views: 157020

Re: v7.18 [stable] is released!

@oreggin; the Wiki describes a planned disk replacement, but @pe1chl ran into an unexpected failure. Since Btrfs RAID1 doesn’t have automatic resync, it might be unreliable when disks go offline (kernel RAID handles resyncing differently) Beyond what @pe1chl mentioned, there are plenty of other risk...
by Larsa
Thu Feb 27, 2025 7:55 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 540
Views: 157020

Re: v7.18 [stable] is released!

n/a
by Larsa
Thu Feb 27, 2025 3:36 pm
Forum: Announcements
Topic: Newsletter #123 | February 2025
Replies: 36
Views: 8461

Re: Newsletter #123 | February 2025

bcachefs is the answer. It is the ultimate filesystem for Linux. Cache tiering, Erasure Coding (RAID5/6), No Write-Hole, Snapshots. its currently marked experimental in the kernel, but the roadmap is to have this removed within 6 months. I doubt that CacheFS will be non-experimental within six mont...
by Larsa
Thu Feb 27, 2025 2:30 pm
Forum: Announcements
Topic: Question to our users about controllers
Replies: 117
Views: 173163

Re: Question to our users about controllers

Secure Zero Touch Provisioning (SZTP) for mass deployment in enterprise networking would be a welcome addition. Most major vendors already support it. The client is relatively small (similar to TR-369/069), and there are some open-source reference implementations available for the config servers as ...
by Larsa
Thu Feb 27, 2025 11:38 am
Forum: Announcements
Topic: Newsletter #123 | February 2025
Replies: 36
Views: 8461

Re: Newsletter #123 | February 2025

Regarding BTRFS, I strongly advise against using advanced RAID setups or filling up the storage. These factors, combined with other known issues and the lack of clear documentation on storage configuration, pose a significant risk. If a filesystem or storage failure occurs without proper repair tool...
by Larsa
Wed Feb 26, 2025 7:42 pm
Forum: MikroTik hardware questions
Topic: RDS2216 bootloader, linux
Replies: 6
Views: 2958

Re: RDS2216 bootloader, linux

If you're thinking about drivers, pretty much all Prestera drivers developed by Marvell are already available in Linux, and since RouterOS is based on Linux, I'm pretty sure MT is using the same ones.
by Larsa
Wed Feb 26, 2025 7:04 pm
Forum: MikroTik hardware questions
Topic: RDS2216 bootloader, linux
Replies: 6
Views: 2958

Re: RDS2216 bootloader, linux

If that’s the case, using the 98DX4310 only as a standalone switch with just the control plane connected to the PCI bus would be pretty useless.
by Larsa
Wed Feb 26, 2025 3:51 pm
Forum: MikroTik hardware questions
Topic: RDS2216 bootloader, linux
Replies: 6
Views: 2958

Re: RDS2216 bootloader, linux

I have the exact same thoughts. The hardware is really interesting for that price, with built-in NIC features like 2×100G, 4×25G, etc and an SFF-8644. The problem with this setup, as I see it, is that you simply can't rely on a locked-down and limited network operating system environment like Mikrot...
by Larsa
Wed Feb 26, 2025 9:33 am
Forum: General
Topic: radsec issues after 7.15 upgrade
Replies: 17
Views: 10924

Re: radsec issues after 7.15 upgrade

If you haven’t already, file a bug report with Mikrotik support (this is just a user forum).
by Larsa
Tue Feb 25, 2025 11:41 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 8516

Re: Got stuck building IKEv2 w/ MFA for remote client

Totally missed it was about the IPsec identity. Since we're not using ISRG, I wasn't aware that LE certificate creation and renewal is now fully automated by ROS. Can this also manage IPsec certificates using LE?

P.S.
Fixed my previous reply so it won't confuse future readers.
by Larsa
Tue Feb 25, 2025 10:40 pm
Forum: General
Topic: Recursive routing not working while using wireguard interface as gateway [SOLVED]
Replies: 12
Views: 8607

Re: Recursive routing not working while using wireguard interface as gateway [SOLVED]

You need to add a routing rule to make sure traffic goes through the "TEST1" table instead of the "main" table. Just an example to illustrate: " /ip route rule add src-address=x.x.x.x/y action=lookup table=TEST1 ". This ensures that routing follows the specified table f...
by Larsa
Tue Feb 25, 2025 8:34 pm
Forum: General
Topic: Recursive routing not working while using wireguard interface as gateway [SOLVED]
Replies: 12
Views: 8607

Re: Recursive routing not working while using wireguard interface as gateway [SOLVED]

WireGuard's "Cryptokey" routing differs from traditional IP routing. That said, you can treat the WG interface just like a regular Ethernet interface. Just give it an IP address like you would with any other network interface, and recursive routing will work the same way.
by Larsa
Tue Feb 25, 2025 3:37 pm
Forum: General
Topic: Why are threads for previous major releases being locked? [SOLVED]
Replies: 17
Views: 7968

Re: Why are threads for previous major releases being locked? [SOLVED]

@Sergejs, appreciate the feedback and the clarification. Thanks!
by Larsa
Mon Feb 24, 2025 11:03 pm
Forum: General
Topic: Why are threads for previous major releases being locked? [SOLVED]
Replies: 17
Views: 7968

Re: Why are threads for previous major releases being locked? [SOLVED]

I don’t think anyone’s missing your point, but it still doesn’t actually explain why, which was my original question.

The same applies to whether “closed thread = closed branch” also means never releasing any new patches for that branch again.
by Larsa
Mon Feb 24, 2025 9:05 pm
Forum: General
Topic: CVE-2024-54772 Information About
Replies: 20
Views: 6722

Re: The twelve Rules of Mikrotik Club

There is an extremely simple and easy-to-implement solution to mitigating brute-force attacks: just gradually increasing the response delay after each failed login attempt, up to a set limit, to prevent account lockout.
by Larsa
Mon Feb 24, 2025 8:32 pm
Forum: General
Topic: Why are threads for previous major releases being locked? [SOLVED]
Replies: 17
Views: 7968

Re: Why are threads for previous major releases being locked? [SOLVED]

New version is out = MT no longer wants to hear about bugs in previous one because they will not be hotfixing that one anymore = topic closed. Yeah, that’s my guess too: topic closed = branch closed . But I’m still not convinced about the actual when and why . Maybe it’s just as simple as there bei...
by Larsa
Mon Feb 24, 2025 8:24 pm
Forum: General
Topic: Why are threads for previous major releases being locked? [SOLVED]
Replies: 17
Views: 7968

Re: Why are threads for previous major releases being locked? [SOLVED]

To rephrase it again: The known enemy is the best enemy. There are a lot of topics on downgrading to the older versions just to have network in the known equilibrium point even if not all functions work as expected for that versions. Totally agree with "The known enemy is the best enemy,"...
by Larsa
Mon Feb 24, 2025 7:54 pm
Forum: General
Topic: Why are threads for previous major releases being locked? [SOLVED]
Replies: 17
Views: 7968

Re: Why are threads for previous major releases being locked? [SOLVED]

@wrkq I appreciate your take on this, but I’m not sure how it ties into my original question. I was specifically asking why forum threads for previous patch releases (like v7.16.x and v7.17.x) get locked as soon as a new major release comes out. What you explained about backporting and long-term sup...
by Larsa
Mon Feb 24, 2025 5:51 pm
Forum: General
Topic: Why are threads for previous major releases being locked? [SOLVED]
Replies: 17
Views: 7968

Re: Why are threads for previous major releases being locked? [SOLVED]

Fixes, updates and new features are added to the newest MikroTik RouterOS version. It is not possible to release "fixed/improved 7.13" (example), that contains specific issue fix. That's why the latest release version topic is open and we are looking into it closely for proper reports, th...
by Larsa
Mon Feb 24, 2025 5:11 pm
Forum: General
Topic: Why are threads for previous major releases being locked? [SOLVED]
Replies: 17
Views: 7968

Why are threads for previous major releases being locked? [SOLVED]

Sorry if I missed where this is explained, but I honestly don’t get why threads for previous major releases, like "v7.16.2 [stable]" and "v7.17.2 [stable]", are locked the moment a new major release drops. I’m pretty sure most users are probably still on older versions, so why sh...
by Larsa
Mon Feb 24, 2025 8:14 am
Forum: General
Topic: Software ID - License - What the hell!
Replies: 8
Views: 7534

Re: Software ID - License - What the hell!

This is just a user forum, not a time machine !!!!!!!!!!!!!!!!!!!!!!!!!! 😉

You replied to a post from 2013 so it might be better to email MikroTik support directly.
by Larsa
Thu Feb 20, 2025 9:57 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 29042

Re: v7.18rc [testing] is released!

This was really leaked OR maybe it's an April Fools video ready with quite some time in advance :)

Yeah, @sirbryan totally wrecked Mikrotik's April Fool’s prank they’d been planning for over a year! 🤣
by Larsa
Thu Feb 20, 2025 5:47 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 29042

Re: v7.18rc [testing] is released!

For all you storage haters: https://youtu.be/g1wpIIfYpZA?feature=shared Fun, but was this intended for April 1st? 😉 Anyway, I’d never ever trust MT ROS for business-critical data storage — for pretty obvious reasons! Now please go back and fix those routing issues. But maybe the development team th...
by Larsa
Thu Feb 20, 2025 5:36 pm
Forum: General
Topic: IPsec parameter negotiation (and ancient defaults)
Replies: 14
Views: 4549

Re: IPsec parameter negotiation (and ancient defaults)

Well, Amm0, in that case, I'm also here for moral support! 😉 But considering pe1chl's specific need and the limited documentation on this, I think it'll be pretty tough to figure out how it works behind the scenes. So, MT is probably the only one who can say if it's doable or not (if they even bothe...
by Larsa
Wed Feb 19, 2025 5:00 pm
Forum: General
Topic: Reverse wireguard tunnel dstnat
Replies: 11
Views: 2939

Re: Reverse wireguard tunnel dstnat

If the data center already uses the entire 10.122.0.0/16 subnet for other purposes, it’s better to pick a different subnet for the WireGuard tunnel. That way, you avoid routing conflicts and make return traffic easier to manage if needed. A good option would be 172.16.10.0/24, with for example 172.1...
by Larsa
Wed Feb 19, 2025 2:53 pm
Forum: General
Topic: Reverse wireguard tunnel dstnat
Replies: 11
Views: 2939

Re: Reverse wireguard tunnel dstnat

I think you might have accidentally written the wrong address for one of the WireGuard interfaces since both have the same one.
by Larsa
Wed Feb 19, 2025 1:40 pm
Forum: General
Topic: Reverse wireguard tunnel dstnat
Replies: 11
Views: 2939

Re: Reverse wireguard tunnel dstnat

I'm not sure what you mean by "proxy server," but if your DNS-NAT is set up correctly, you shouldn't need a return route. To access your LAN, you'll still need to add a route from the datacenter and allow access in the forward chain on the LtAP. If you want to allow access to the LtAP itse...
by Larsa
Wed Feb 19, 2025 12:54 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 29042

Re: v7.18rc [testing] is released!

It is clear that in 7.16 some breakage was introduced in the routing... and now we cannot assume that it will ever be fixed?I presume the window for BGP fixes in 7.18 has again been closed now that we are in rc? Is "routing" still a priority for MikroTik or do we now only get fixes and ad...
by Larsa
Wed Feb 19, 2025 10:30 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2141
Views: 1292599

Re: 📣 WinBox 4 is here 📣

Most software I'm aware of these days doesn't support EOS any more, and why would they if M$ doesn't support them.

Windows 7 is still used by approx 34 million users! 😉
by Larsa
Wed Feb 19, 2025 10:11 am
Forum: General
Topic: Reverse wireguard tunnel dstnat
Replies: 11
Views: 2939

Re: Reverse wireguard tunnel dstnat

It's much easier to understand if you just explain the end goal. For example, do you want to access the LAN behind the LtAP from the data center, or the other way around (or both ways?)

To make it easier to suggest a practical solution, please provide the subnet on each side.
by Larsa
Tue Feb 18, 2025 3:31 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2141
Views: 1292599

Re: 📣 WinBox 4 is here 📣

Yeah, that also means Winbox 4 won't run on anything older than Windows 10 (ie, no XP, Vista or Win 7/8).
by Larsa
Tue Feb 18, 2025 12:31 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 29042

Re: v7.18rc [testing] is released!

Heads-up - breaking changes for management and monitoring:
*) console - put !empty sentence when API query returns nothing;
by Larsa
Tue Feb 18, 2025 12:25 pm
Forum: General
Topic: CVE-2024-54772 Information About
Replies: 20
Views: 6722

Re: CVE-2024-54772 Information About

Yeah, brute force dictionary attack is the correct term here. 'Username Enume' is totally off in this context—probably named that way just to create some hype.
by Larsa
Tue Feb 18, 2025 12:19 pm
Forum: Announcements
Topic: v6.49.18 [long-term] is released!
Replies: 42
Views: 58366

Re: v6.49.18 [stable] is released!

Brute force dictionary attack is the correct term, not "Username Enume" which is totally wrong in this context. Also, access to port 8291 is required and additional dictionary attacks for the password, which will be very tricky if there's a delay between attempts.
by Larsa
Mon Feb 17, 2025 7:08 pm
Forum: General
Topic: Firewall rules analysis
Replies: 110
Views: 15758

Re: Firewall rules analysis

@Josephny: I'm sure we would all agree that communicating technical concepts is a very challenging endeavor. Yeah, especially since there still isn’t a good user guide that clearly explains the packet flow in a simple, easy-to-understand way. Another thing that can be confusing is that WinBox mixes...
by Larsa
Mon Feb 17, 2025 11:50 am
Forum: General
Topic: VISIO stencils
Replies: 23
Views: 48117

Re: VISIO stencils

The .vsdx format is for complete diagrams, while .vssx, .vss, and .vsx are for collections of shapes (stencils). Also reread my previous comment.
by Larsa
Mon Feb 17, 2025 11:39 am
Forum: General
Topic: VISIO stencils
Replies: 23
Views: 48117

Re: VISIO stencils

@Jotne: Perhaps I misunderstood what you’re looking for, but .vsdx is the standard format for Visio nowadays. You can easily convert it to .vssx, .vss, or .vsx for stencil use (just drag the shapes into a new stencil and save it in your preferred format). @Normis: "Are there major differences b...
by Larsa
Sat Feb 15, 2025 10:28 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 167967

Re: v7.18beta [testing] is released!

Thanks so much, I completely missed this! Breaking changes like these should come with bold warning signs. It’s also a typical sign that Mikrotik’s developers and managers still don’t get their business customers. Mikrotik could at least try by adding a section called 'Breaking changes' in the relea...
by Larsa
Sat Feb 15, 2025 10:14 am
Forum: MikroTik hardware questions
Topic: Danteswitch
Replies: 12
Views: 3435

Re: Danteswitch

When I reread your first post, I realized I totally missed two key details: that you’ll be using the switch standalone and with PoE. With that in mind and since you will only run pure Dante traffic, pretty much any switch with PoE will do.

Ps..
Looks like you’re double-quoting your replies.
by Larsa
Fri Feb 14, 2025 6:27 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 167967

Re: v7.18beta [testing] is released!

It doesn’t necessarily have to be ROS; it could be storage constraints, hardware or network failure, power shutdown, or other environmental issues. So there’s no point in continuing to speculate until you can access the server.
by Larsa
Fri Feb 14, 2025 5:21 pm
Forum: MikroTik hardware questions
Topic: Danteswitch
Replies: 12
Views: 3435

Re: Danteswitch

It might work, but if this is for a recording setup and Dante is sharing the network with other bulk traffic, I’d say QoS is essential to maintain audio quality. Dante is pretty sensitive to latency and jitter, so QoS makes sure that Dante streams are prioritized over other types of network traffic....
by Larsa
Fri Feb 14, 2025 5:18 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 167967

Re: v7.18beta [testing] is released!

only have the model, but i canot reach the server x86 Supermicro SYS-530MT-H8TNR Okay, when you have access, please provide the full config, including NICs, storage boards, etc. Btw, it might be worth checking if the setup complies with Mikrotik’s requirements. Just a tip: if the Supermicro is co-l...
by Larsa
Fri Feb 14, 2025 3:38 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 167967

Re: v7.18beta [testing] is released!

@SMARTNETTT – Hopefully just on a lab server then, right? If this is regarding a bare metal x86, provide the manufacturer, model, and full configuration — without that, your warning is pretty useless! If it happens multiple times and your configuration is supported, open a support ticket with Mikrot...
by Larsa
Fri Feb 14, 2025 3:08 pm
Forum: MikroTik hardware questions
Topic: Danteswitch
Replies: 12
Views: 3435

Re: Danteswitch

@orfeous, Starting from ROS v7.15, all Mikrotik QoS-capable switches can use Dante. For more info on switches supporting Dante, check out these links: Mikrotik help - Bridging and Switching - MikroTik QoS-Capable devices ("QoS Device Support") Mikrotik help - Bridging and Switching - Appli...
by Larsa
Fri Feb 14, 2025 11:39 am
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 173
Views: 56003

Re: Feature Request: IPSEC Improvements

XFRM has been a part of IPsec since Linux 2.6, released in December 2003.
by Larsa
Thu Feb 13, 2025 6:04 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 8516

Re: Got stuck building IKEv2 w/ MFA for remote client

Here are some other troubleshooting suggestions. Sorry if I misunderstand or missed anything both of you already tried! - Check that Windows trusts the Mikrotik CA Open certmgr.msc. Go to "Trusted Root Certification Authorities". Check that the signing CA of the Mikrotik certificate is the...
by Larsa
Thu Feb 13, 2025 4:30 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 8516

Re: Got stuck building IKEv2 w/ MFA for remote client

Just a long shot, but have you tried checking with extended logging on Windows? 1. "C:\> netsh trace start VpnClient per=yes maxsize=0 filemode=single" 2. Test the VPN connection 3. "C:\> netsh trace stop" 4. Open the .etl file using Event Viewer (eventvwr.msc). The .etl files ar...
by Larsa
Thu Feb 13, 2025 2:26 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 8516

Re: Got stuck building IKEv2 w/ MFA for remote client

@Guscht: Can't help, but a notice: It's 2025, IPsec is an old, outdated overcomplicated, error-prone dinosaur. If possible, use a modern technology like Wireguard. Sure, IPsec is a "dinosaur" — just one that happens to be the standard for countless enterprises, governments, and critical i...
by Larsa
Thu Feb 13, 2025 1:37 pm
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 88
Views: 86478

Re: Newsletter #122 | December 2024

...a fiber socket in each guest room... Even though it sounds a bit unusual to me, it’s possible it exists. But I can’t remember ever seeing it in a hotel, and I’ve traveled quite a bit. I mean, bringing your own fiber optic patch cables plus an SFP/RJ45 Ethernet media converter doesn’t exactly fee...
by Larsa
Wed Feb 12, 2025 12:25 am
Forum: General
Topic: Connecting Mikrotik via openconnect protocol
Replies: 5
Views: 5050

Re: Connecting Mikrotik via openconnect protocol

OpenConnect is already supported as an add-on container app service.
by Larsa
Tue Feb 11, 2025 5:14 pm
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 88
Views: 86478

Re: Newsletter #122 | December 2024

Have you ever seen a hotel or student housing with an SFP port in the wall, or did you mean something else? Usually, when fiber (passive or not) is installed in a property for the end user, it's typically terminated with Ethernet or WiFi.
by Larsa
Tue Feb 11, 2025 12:10 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2141
Views: 1292599

Re: 📣 WinBox 4 is here 📣

v3 is already abandoned. They've said many times that there won't be any changes. Only security fixes. I afraid that some day, after updating to new RouterOS, it will show "Protocol is not supported"... And I also feel bad with this stupid design in v4. For me it's like a toy currently, I...
by Larsa
Mon Feb 10, 2025 8:46 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2141
Views: 1292599

Re: 📣 WinBox 4 is here 📣

We went from something that worked fine on windows and emulated well on others, most of the time, to something that doesn't work as well as the old one anywhere...

Yeah, I feel the same way. I really hope MT won't retire v3 before everything’s up to par.
by Larsa
Mon Feb 10, 2025 11:33 am
Forum: General
Topic: Externally monitoring OSPF neighbor states?
Replies: 3
Views: 3169

Re: Externally monitoring OSPF neighbor states?

We're running a script-based approach since MT hasn't implemented SNMP for OSPF LSA yet (only for BGP). Check out "OSPF SNMP monitoring" in the "Routing Protocol Overview".
by Larsa
Sun Feb 09, 2025 1:45 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 167967

Re: v7.18beta [testing] is released!

WireGuard works well for monitoring and management, but it’s not the best choice for large-scale operations that require many connections and high throughput. In these cases, IPSec is the only real option. If someone finds IPSec tricky to set up, it’s likely more a matter of experience and expertise...
by Larsa
Sat Feb 08, 2025 11:10 pm
Forum: Wireless Networking
Topic: Very slow LTE [SOLVED]
Replies: 46
Views: 11021

Re: Very slow LTE [SOLVED]

My take on this is pretty simple: 1. Carrier aggregation is a must to get decent speeds with CAT6. 2. I'm pretty sure the China box won't do much better than the MT if properly configured. 3. Most built-in external antennas on 4G CPEs are used for Wi-Fi nowadays, not the LTE radio. For example, with...
by Larsa
Sat Feb 08, 2025 9:40 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 175
Views: 20442

Re: New exciting features for storage

@sirbryan, that’s not gonna happen. ROS is designed as an embedded NOS with its own limitations. When it comes to running ROS as CHR, there are way better options. Plus, MT lacks the skill set and experience, and ROS is too unreliable for storage solutions like hyper-convergence.
by Larsa
Sat Feb 08, 2025 8:30 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 167967

Re: v7.18beta [testing] is released!

For RAM I'd say WG definitely ... because IPsec is part of ROS since ages and I'm sure they did whatever possible to reduce its memory footprint. I don't think they put the same amount of energy into WG so far. I'm not saying anything about CPU utilization, but probably WG fares better (everybody's...
by Larsa
Sat Feb 08, 2025 7:04 pm
Forum: General
Topic: Zerotier Struggles on v7.17
Replies: 3
Views: 2904

Re: Zerotier Struggles on v7.17

That was a lot to take in and maybe a bit tricky to get a clear picture of. Here are a few things that might help clarify things: What exactly isn’t working? - Are all Zerotier peers unreachable from the LAN, or just some? - Can LAN devices ping any Zerotier IPs, or is all Zerotier traffic failing f...
by Larsa
Sat Feb 08, 2025 1:16 pm
Forum: Forwarding Protocols
Topic: OSPF Fast Reroute on ROS v7
Replies: 3
Views: 4842

Re: OSPF Fast Reroute on ROS v7

OSPF with BFD = fast reroute within a few ms.
by Larsa
Fri Feb 07, 2025 11:35 pm
Forum: Beginner Basics
Topic: Can't figure out recursive routing
Replies: 5
Views: 2931

Re: Can't figure out recursive routing

It pretty easy to understand using recursive routing in this simple terms: A → B (A needs to reach B) B → C (B is reachable via C) So, A → C (indirectly via B) Example using recursive routing with ROS: 1. Set A to go via B: /ip route add dst-address=A gateway=B 2. Resolve B via C: /ip route add dst-...
by Larsa
Fri Feb 07, 2025 1:23 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 167967

Re: v7.18beta [testing] is released!

@oreggin, if you're looking for advanced MPLS/BGP solutions, you’ll probably need to consider other brands—but that also comes with additional costs. Since this is just a user forum, if you have a serious business case, you might want to contact MikroTik directly at sales@mikrotik.com or support@mik...
by Larsa
Fri Feb 07, 2025 12:49 pm
Forum: General
Topic: Still fighting with Ecobee (and losing)
Replies: 14
Views: 4260

Re: Still fighting with Ecobee (and losing)

I've also been thinking about getting some Ecobees. Do you use them standalone, or together with something like Home Assistant or another system?
by Larsa
Fri Feb 07, 2025 11:23 am
Forum: General
Topic: OSPF vs CCTV
Replies: 2
Views: 1765

Re: OSPF vs CCTV

OSPF only handles routing between nodes in a network and doesn’t impact performance per se. Building your own mesh network works fine with a few nodes, but as the number of nodes increases, the number of tunnels grows exponentially (see below). OSPF is pretty easy to configure, but you have to do it...
by Larsa
Thu Feb 06, 2025 10:15 pm
Forum: General
Topic: ✈️ MTPC 2024 info and my experience
Replies: 3
Views: 2207

Re: ✈️ MTPC 2024 info and my experience

@MikroTikMarc, looks like you guys had a great time!

Gotta say, your presentation on YouTube how to build a complex OSPF lab for under $100 using Proxmox and CHR was awesome too! 🚀 Btw, here’s the link to the blog page that was mentioned in the presentation: https://admiralplatform.com/blog-page/
by Larsa
Wed Feb 05, 2025 10:39 pm
Forum: Beginner Basics
Topic: How to run IPv6 from starlink on a mikrotik?
Replies: 37
Views: 17994

Re: How to run IPv6 from starlink on a mikrotik?

With IPv6, you get a public IP; with IPv4, only CGNAT
by Larsa
Wed Feb 05, 2025 6:53 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2141
Views: 1292599

Re: 📣 WinBox 4 is here 📣

Yeah, and if MT is using their own Layout Manager, scaling might not work as well if DPI awareness isn't handled properly. The built-in Layout Manager scales just fine on high-resolution screens. Try the example app "Thermostat".
by Larsa
Wed Feb 05, 2025 2:45 pm
Forum: Forwarding Protocols
Topic: [OSPF][iBGP] route filtering syntax help [SOLVED]
Replies: 16
Views: 10684

Re: [OSPF][iBGP] route filtering syntax help [SOLVED]

I’m not sure what you mean by “concentrator” in this case so you'll need to be more specific than that. Btw, did you manage to spot the root cause by checking how OSPF adds default routes to the routing table in one of the black nodes? That said, MED is primarily designed to influence inbound traffi...
by Larsa
Wed Feb 05, 2025 10:38 am
Forum: General
Topic: ip cloud ddns-enabled
Replies: 21
Views: 4651

Re: ip cloud ddns-enabled

@JavierCastilla: Which is the support service and how can I register my devices for that?

I was referring to the business impacted by a failing service, not the one that made the equipment.
by Larsa
Tue Feb 04, 2025 11:07 pm
Forum: General
Topic: ip cloud ddns-enabled
Replies: 21
Views: 4651

Re: ip cloud ddns-enabled

@Dida: What difference does it make if 1 or 200 services are down?

Are you being sarcastic? If we’re talking business, there’s a massive difference. One service down is a problem, but 200? That’s a full-blown disaster—support is in for an absolute nightmare of a day!
by Larsa
Tue Feb 04, 2025 10:16 pm
Forum: General
Topic: ip cloud ddns-enabled
Replies: 21
Views: 4651

Re: ip cloud ddns-enabled

@kevag: seems the service is down since yesterday ..200+ routers dont resolve. can this be verified by mikrotik officials ? any news when this will come back in service? MikroTik IP Cloud DDNS is free, which means there’s no SLA. With 200+ routers, I’d definitely start looking into global services ...
by Larsa
Tue Feb 04, 2025 4:16 pm
Forum: General
Topic: ip cloud ddns-enabled
Replies: 21
Views: 4651

Re: ip cloud ddns-enabled

The service might be down at the moment. It happens occasionally...
by Larsa
Tue Feb 04, 2025 3:35 pm
Forum: Forwarding Protocols
Topic: [OSPF][iBGP] route filtering syntax help [SOLVED]
Replies: 16
Views: 10684

Re: [OSPF][iBGP] adding cost on backbone neighbor [SOLVED]

ok now I want to create a iBGP filter rule to execute this...

I thought you were having trouble with OSPF. What are you trying to solve with BGP? Some more background would help.
by Larsa
Tue Feb 04, 2025 3:27 pm
Forum: General
Topic: "Error in Gateway - non zero ip address expected!" when using Quick Set
Replies: 20
Views: 5184

Re: "Error in Gateway - non zero ip address expected!" when using Quick Set

I prefer "auto-mac=smart" because it adapts to new conditions automatically. ;)
by Larsa
Tue Feb 04, 2025 11:53 am
Forum: General
Topic: ATL suddenly says "sim not present"
Replies: 22
Views: 6063

Re: ATL suddenly says "sim not present"

@SiB: I remember that problems on LHGR and some connector spray help or office tape :) And this was a popular problem with fist and second revision of LHGR. Second problems was how exit(take out) a sim card - this was not easy job. Yeah, I remember a few years ago when we switched MNO and had to sw...
by Larsa
Mon Feb 03, 2025 9:45 pm
Forum: 3rd party tools
Topic: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management
Replies: 80
Views: 29500

Re: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management

You can use Docker on Windows with the built-in WSL2, which is a Hyper-V virtual machine where you can run any distro you like, such as Ubuntu. To set up Docker, install either Docker Desktop following this this guide or without Docker Desktop using this tutorial.
by Larsa
Mon Feb 03, 2025 8:18 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 11988

Re: Question on using the Internal Zerotier Controller [SOLVED]

Haha, Anav, I see you're out here securing your files and your finances at the same time! 😂 Maybe if we tweak that command a bit: # chmod +Money Boom! Instant economic growth! 💰💸 As for joining the EU... yeah, I think Canada prefers its maple syrup debts over Mediterranean siestas. But hey, if your ...
by Larsa
Mon Feb 03, 2025 8:10 pm
Forum: General
Topic: "Error in Gateway - non zero ip address expected!" when using Quick Set
Replies: 20
Views: 5184

Re: "Error in Gateway - non zero ip address expected!" when using Quick Set

I know why, but I still think making users set the bridge MAC manually is an ugly kludge.
by Larsa
Mon Feb 03, 2025 7:25 pm
Forum: General
Topic: "Error in Gateway - non zero ip address expected!" when using Quick Set
Replies: 20
Views: 5184

Re: "Error in Gateway - non zero ip address expected!" when using Quick Set

Seriously, I don't know what the admin-mac is or what it is used for. I read some of the threads, faithfully staying in my 20-40% comprehension level, and I see that it is, by default, set to the same mac-address as the lowest numbered eth port, and that there might be a problem is/when restoring f...
by Larsa
Mon Feb 03, 2025 7:07 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 11988

Re: Question on using the Internal Zerotier Controller [SOLVED]

@anav - If I were you, I'd ditch the self-hosted controller and just use the cloud-based one (my.zerotier.com). Regarding your files, just: "# chmod +r *". Fixed! ;)
by Larsa
Mon Feb 03, 2025 6:30 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 11988

Re: Question on using the Internal Zerotier Controller [SOLVED]

Thanks AMMO, so controller is limited to CLI, is there a sense it will migrate to Winbox eventually.

Way too complex, so I don’t think so. But you can add your own web-based manager: ZeroUI.
by Larsa
Mon Feb 03, 2025 6:27 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 11988

Re: Question on using the Internal Zerotier Controller [SOLVED]

Just highlight, once again, an grip of mine is the Mikrotik's ZT client does not support low-bandwidth, bonding, etc. as a "full" ZT client on PC/Mac does. And these restrictions still come in when using the controller, as traffic will go via the interface, not controller. Yeah, unfortuna...
by Larsa
Mon Feb 03, 2025 6:23 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 11988

Re: Question on using the Internal Zerotier Controller [SOLVED]

@NA9D - Unfortunately, you're still a bit limited when it comes to running fully autonomous operations since ROS doesn't let you configure root servers. But with your own ZeroTier controller and ZeroUI , you not only get a slick web interface, but you also have full control over network rules, authe...
by Larsa
Mon Feb 03, 2025 4:51 pm
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 6693

Re: 1.3km Possible?

Here’s a simulation for 2.4 GHz signal loss in a somewhat dense forest using 36 dBm EIRP , with a minimum received power sensitivity of -90 dBm which BTW is extremely weak . You typical need at least -80 dBm for a somewhat stable connection and -67 dBm or better for normal performance. Typical fores...
by Larsa
Mon Feb 03, 2025 1:14 pm
Forum: Forwarding Protocols
Topic: How can I do load balancing in ospf?
Replies: 4
Views: 3429

Re: How can I do load balancing in ospf?

Please don't double-post. I've already answered your question here: viewtopic.php?p=1123269#p1123298
by Larsa
Mon Feb 03, 2025 1:10 pm
Forum: Wireless Networking
Topic: "not responding" - f.k.a. SA Query timeout
Replies: 370
Views: 87894

Re: "not responding" - f.k.a. SA Query timeout

@blondasek, @maigonis - This is just a user forum. If you haven't already, please email a support.rif to support@mikrotik.com.
by Larsa
Mon Feb 03, 2025 12:47 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 11988

Re: Question on using the Internal Zerotier Controller [SOLVED]

I completely agree, especially regarding the steps to establish a good baseline. All major players like as Cisco, Juniper, and others, provide clear guidelines for the initial setup. I mean, how hard can it be? ;) Regarding the handbook (I assume you're referring to a user guide), it's a great idea....
by Larsa
Mon Feb 03, 2025 8:51 am
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 6693

Re: 1.3km Possible?

Unfortunately, you do need line of sight for WiFi to work on 2.4/5 GHz. No amount of dark magic will get through 1.3 km of trees. Check Sindy’s previous answer on this.
by Larsa
Sun Feb 02, 2025 11:28 pm
Forum: Beginner Basics
Topic: Question on using the Internal Zerotier Controller [SOLVED]
Replies: 40
Views: 11988

Re: Question on using the Internal Zerotier Controller [SOLVED]

Well, to begin with, the documentation for the controller is a masterpiece of vagueness, to say the least. 😉 Unfortunately, the people who wrote it forgot to include an example of how to add a route to a gateway. The only cryptic and inconsistent explanation you get is: routes (IP@GW; Default: ) Pus...
by Larsa
Sun Feb 02, 2025 7:34 pm
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 6693

Re: 1.3km Possible?

..but I do have some small houses all connected via twisted pair… This is overhead (exposed to UV, cold, rain, etc.)..

Shouldn’t be a problem if you're using a protective conduit or an outdoor-rated cable that’s UV-resistant and built to handle cold, moisture, and all kinds of weather.
by Larsa
Sun Feb 02, 2025 6:28 pm
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 6693

Re: 1.3km Possible?

With the short distance, you can go for a super flexible multimode ... @OP mentioned 1.3km distance ... and that's direct distance. Which is way longer than 550m limit for multimode fiber. So if @OP decides for digging, it should be single-mode ... which is most often laid inside protective tube. D...
by Larsa
Sun Feb 02, 2025 5:17 pm
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 6693

Re: 1.3km Possible?

Talk to Verizon? I can think of any number of forms of torture I'd prefer....

Same here, I’d rather have a dentist appointment without anesthesia! 🤣🤣🤣
by Larsa
Sun Feb 02, 2025 3:44 pm
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 6693

Re: 1.3km Possible?

@Josephny; If you're planning to install fiber yourself and have your own machinery, just go ahead and use a narrow trenching blade. A depth of about 15-16 inches should be enough. There are plenty of reinforced microducts with pre-installed fiber designed for direct burial in the ground for about 2...
by Larsa
Sun Feb 02, 2025 11:31 am
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 6693

Re: 1.3km Possible?

Regarding fiber, if you're the landowner and somewhat handy, you can rent a small walk-behind trencher to lay the fiber in a ditch. To terminate it, you can rent a Fusion Splicer and use splice-on connectors, or go with mechanical connectors if you want to skip the splicing. There are also plenty of...
by Larsa
Sun Feb 02, 2025 9:33 am
Forum: Forwarding Protocols
Topic: ospf not doing load balancing
Replies: 3
Views: 4678

Re: ospf not doing load balancing

Unfortunately, OSPF does not perform load balancing by itself; it only sets up routes in the routing table. Instead, you can use bonding, which is explained here: https://help.mikrotik.com/docs/spaces/ROS/pages/8323193/Bonding. If you plan to use the routers at two different locations, set up two Eo...
by Larsa
Sat Feb 01, 2025 11:40 pm
Forum: Beginner Basics
Topic: Multicast UDP over Zerotier
Replies: 3
Views: 3613

Re: Multicast UDP over Zerotier

Check out multicast UDP in the rules engine: https://docs.zerotier.com/rules/
by Larsa
Fri Jan 31, 2025 8:54 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2141
Views: 1292599

Re: 📣 WinBox 4 is here 📣

Same here, "Cmd +/-" for zooming on Macs is pure muscle memory these days.
by Larsa
Fri Jan 31, 2025 12:27 pm
Forum: RouterOS beta
Topic: L4S support in routerOS7
Replies: 10
Views: 12290

Re: L4S support in routerOS7

@dtaht - Good summary. Any guess on the current status of L4S among the key stakeholders? Can you picture a real-life scenario where BBRv3 coexists with fq_codel or L4S? And yeah, it would probably be a good idea to switch from in-house queue managers to BQL.
by Larsa
Thu Jan 30, 2025 3:16 pm
Forum: General
Topic: IPSEC multiple policy with p2p
Replies: 15
Views: 5432

Re: IPSEC multiple policy with p2p

@Larsa I am looking what is the best solution for this kind scenario: Secure connection to site to site - IPSEC prefered. Site A: has subnet A1 which has to have access to Site B subnet B1 and B2. Site B: has two subnets B1 and B2 to access from/to Site A subnet A1. Since your setup is a single sit...
by Larsa
Thu Jan 30, 2025 1:08 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2141
Views: 1292599

Re: 📣 WinBox 4 is here 📣

Just curious, what is a "normal resolution" nowadays according to MT?
by Larsa
Thu Jan 30, 2025 1:04 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2141
Views: 1292599

Re: 📣 WinBox 4 is here 📣

It is impossible to fix all scaling issues in Windows. Windows is very bad at DPI scaling compared to other OS and Winbox is definitely not the only program that has small pixel level issues at these settings. Since Winbox is now made in QT, we will not be able to fix all issues, at this point, mos...
by Larsa
Wed Jan 29, 2025 7:43 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 167967

Re: v7.18beta [testing] is released!

I think it’s a pretty good idea for a lot of reasons.
by Larsa
Wed Jan 29, 2025 12:44 pm
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 167967

Re: v7.18beta [testing] is released!

@fischerdouglas: yeah, plus L3VPN/MPLS-TE, MPLS-MGMT and BGP/MPLS L3 VPN (128)...
by Larsa
Wed Jan 29, 2025 9:21 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 167967

Re: v7.18beta [testing] is released!

…a valid BGP table from them in every single AFI/SAFI…

All SAFIs? Well, then you’re in for a long wait! 😉
by Larsa
Wed Jan 29, 2025 12:04 am
Forum: Announcements
Topic: v7.18beta [testing] is released!
Replies: 573
Views: 167967

Re: v7.18beta [testing] is released!

I agree, but I also want to stress that loading 4 full tables on an internet border gateway is not the only use-case for BGP. Somewhat OT: I’m not trying to diminish the problems you’re dealing with (and I really hope MT puts some effort into fixing it), but BGP was basically designed for routing b...
by Larsa
Tue Jan 28, 2025 7:45 pm
Forum: General
Topic: Error connecting to L2TP/IPSec server
Replies: 3
Views: 2864

Re: Error connecting to L2TP/IPSec server

Okay, if the VPS is running some kind of Windows, did you restart it after changing the AssumeUDPEncapsulationContextOnSendRule settings? Here are a few more ideas: - Even if the ISAKMP session is established, a firewall or NAT might be blocking the ESP packets between the client and server. Double-...
by Larsa
Tue Jan 28, 2025 4:44 pm
Forum: General
Topic: Winbox 4 does not display system note correctly
Replies: 5
Views: 2983

Re: Winbox 4 does not display system note correctly

Same here, v4 still needs some more work before it’s usable.
by Larsa
Tue Jan 28, 2025 4:37 pm
Forum: General
Topic: Error connecting to L2TP/IPSec server
Replies: 3
Views: 2864

Re: Error connecting to L2TP/IPSec server

Just a guess, but check this out: viewtopic.php?t=175528
by Larsa
Tue Jan 28, 2025 4:19 pm
Forum: General
Topic: Winbox 4 does not display system note correctly
Replies: 5
Views: 2983

Re: Winbox 4 does not display system note correctly

@encrypted - Welcome to the forum! You might get more attention if you post your issue in the dedicated thread: "WinBox 4 is here".
by Larsa
Tue Jan 28, 2025 2:49 pm
Forum: General
Topic: IPSEC multiple policy with p2p
Replies: 15
Views: 5432

Re: IPSEC multiple policy with p2p

I’m not exactly sure what you’re looking for. Are you trying to add more sites or just filter certain types of traffic? It might be helpful if you could clarify your needs with a brief description of what you’re trying to achieve without IPsec-specific terms.
by Larsa
Mon Jan 27, 2025 10:17 pm
Forum: 3rd party tools
Topic: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management
Replies: 80
Views: 29500

Re: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management

No problem, here you are: ;)
C:\> a:install

Jokes aside, you should be able to install Docker on a PC running Windows.
by Larsa
Mon Jan 27, 2025 7:02 pm
Forum: Scripting
Topic: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan & friends...
Replies: 44
Views: 16016

Re: 🧐 example of automating VLAN creation/removal/inspecting using $mkvlan/$rmvlan/$catvlan

VLANs should only be chosen between 2 and 1002 (or 1005 depending on the manual or manufacturer)

Well, not really. But only if you use switches in the early Brontosaurus period ie VTPv1/2 ;)
by Larsa
Mon Jan 27, 2025 3:32 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 4392

Re: IPsec tunnels without known remote IP

Well, it might be, but IMO I doubt it, since the core dataplane library, libstrongswan, itself is about 10-15 MB, and that’s without any cryptographic backends at all. Then you need the control plane with all the management tools and user interfaces. On the other hand, MT might have a special stripp...
by Larsa
Mon Jan 27, 2025 2:47 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 4392

Re: IPsec tunnels without known remote IP

If you find a solution using ROS, please share how you fixed it. Otherwise, there's always StrongSwan, which lets you to dynamically configure policies and assign specific IP ranges or subnets based on the peer's identity (like as FQDN or other attributes) similar to how it was done with racoon
by Larsa
Mon Jan 27, 2025 1:16 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 4392

Re: IPsec tunnels without known remote IP

@pe1chl, does it matter which side is the responder or initiator? If not, both ends could act as initiators using DDNS. Regarding dynamic IPs, the same basic issues apply as with WG. Most ISPs don’t change IPs mid-session as long as the traffic is frequent enough, so some kind of keep-alive mechanis...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 7