Is there anything better ?something better to do than troll a router manufactures forum?
I'm not sure it's the implementation. Some algorithms seem to perform poorly, though. Look at this: http://forum.mikrotik.com/viewtopic.php ... 78#p228478Replace racoon with openswan. With racoon ipsec on mikrotik are poooooooor.
http://forum.mikrotik.com/viewtopic.php?f=2&t=43809Just added this to the wiki...
I would like to see some more options when dealing with ordered lists. Particularly when new rules pop up at the bottom of a firewall config which is several hundred items, it is extremely time consuming to position them where they need to be.
Would be good if there could be additional options (and hotkeys) for items in ordered lists such as: send to top, send to bottom, up one, down one, up page & down page
I think it is time to start official mikrotik idea bank like http://brainstorm.ubuntu.com/ or http://ideabank.opendns.com/ . most of community driven projects have something to say your idea and vote .
The software is free , opensource , secure and simple to install and use at this address http://www.ideatorrent.org/ which used by Ubuntu.
And the old way to edit the wiki is not good way
I am just saying , look back at this thread couple months from now on, it will filled with many post from many different kind of feature request, example post 11-20 discussing about feature request A, post 21-35 discussing about Feature request D, in the post 36 a new user starting again discussing about feature request A, won't be a mess? hard to track which user talk which topic, sure won't be problem for 1-5 point of feature request, what if the feature request growing into 30+ , could be 1 giant huge thread with 1000 post on it, imagine you haven't visit mikrotik forum for couple months and spending time to thread 1000 post , search would be useful but it's not helpful for non-narrative jumping feature request discussion, imho it just not efficient.Heh, Next you'll want a bug tracker like almost every other vendor out there has where we can submit bugs and have other users confirm it and have MT update us on it!
We already have that in RC2Added another request: logging of interface status changes.
Rough example: 29 Oct 2010 16:02 +10:00 Interface ether1 changed from no link to connected 100/full (auto)
This is extremely useful in other managed switches so that you can see if a particular device is losing physical connection or changing speed/duplex for no good reason.
Good stuff!We already have that in RC2Added another request: logging of interface status changes.
Rough example: 29 Oct 2010 16:02 +10:00 Interface ether1 changed from no link to connected 100/full (auto)
This is extremely useful in other managed switches so that you can see if a particular device is losing physical connection or changing speed/duplex for no good reason.
If there is a way to get it to show the speed and duplex, I'm not sure how to do it at the moment./log print
...
10:12:18 interface,info ether3 link down
10:12:22 interface,info ether3 link up
2010-10-27 22:25:28 INFO(6) Port 3 link up, 1000Mbps FULL duplex
2010-10-27 22:25:01 INFO(6) Port 3 link down
Not often, but handy to know when customer is calling you asking about bad link performancein what cases does your link speed change without unplugging the cable? is it really so often that you need special log entry?
We have some sites that are very noisy RF environments, and they occasionally screw up ethernet links. We've tried various remedies, which I won't go into here, as this isn't the appropriate thread for it, but it would be handy to have logging of the speed/duplex for us as well.Not often, but handy to know when customer is calling you asking about bad link performancein what cases does your link speed change without unplugging the cable? is it really so often that you need special log entry?
It doesIt will be good if RouterOS will have integrated brute force protection and filter.
use firewall in that caseI would be nice that in /ip service I could set more ip address or one addres-list
thanks, much clearer now.I sorted the feature requests by number of votes: http://wiki.mikrotik.com/wiki/MikroTik_ ... e_Requests
No problem. I should mention that some new ideas and votes came in since I posted, and that I've re-sorted the list based on number of votes.thanks, much clearer now.
/file set [/file find name="xyz.txt"] name="sata1/xyz.txt"
/file add contents="test"
error - contact MikroTik support and send a supout file (3)
Linux kernel driver coretemp permits reading temperature sensor embedded inside Intel CPUTemperature sensing depends on there being a temperature sensor on the Board.
If the board has not got one, you can't magically make one in software.
They would have to make/get a driver that would work on all x86 CPUs.
Not sure what your setup is, but have you considered checking whether your billing system supports NetFlow?feature request : Umetered Content for PPPoE . 'Unmetered Content' services aren't counted against your monthly download inclusion . added to feature request page . just vote for it
No . it is radius .Not sure what your setup is, but have you considered checking whether your billing system supports NetFlow?feature request : Umetered Content for PPPoE . 'Unmetered Content' services aren't counted against your monthly download inclusion . added to feature request page . just vote for it
i think that this should be global. anywhere you specify a dns name it should be resolved.Hi,
Please add feature that will allow me to add DNS name instead of exact IP address. I need this to connect 2 or more MKT routers (PPTP connection) if they are connected to internet thru ADSL and theirs IP addresses are dynamic. I hope that you understand what I am saying and that we can expect this feature in new ROS.
bye,
I wouldnt go that far, but anything service based, like PPTP/SSTP/Ovpn/IPSEC connections (In particular the last 3, that is part of how a certificate is supposed to work.. DERR!!!). RADIUS, syslog, etc.i think that this should be global. anywhere you specify a dns name it should be resolved.
impossible. should be solved either on managed access switches, or using authentication like PPPoE[*] The most Important thing and this is will be the most great thing to MikroTik Server it can protect Server from NetCut Attacker and hide MAC in any scan in network because any one can scan and get MAC an ip and change his MAC and IP to login without any problem
i think that enabling feature in system auto-backup to senr rsc and/or backup files via tftp or ftp to a specyfied host. encrypted ftp sessions would be even better.many users write some scripts (many of them are not version compatibile) to backup and export configuration
maybe some feature like /tool backup to write backup and rsc file and send it via ftp, tftp, scp to a remote host. verry important feature would be to write files to memory and not internal storage. if you will do it verry often then your mikrotik will break.
this would resolve all problems with backups. no script incompatibility etc.
second feature request is to enable sending files via ftp, tftp. something like fetch but working in the other way.
isn't it exactly like that now?..1. backup_filename=Identity-date.
interface do not have neither download nor upload. it has received and sent packets. why do you need that madness?..2. Possibility to reverse interface speed graphics - I mean make Upload=Downlad, and Download=Upload for specific interface.
Nope . For now Identity=Mikrotik.1. backup_filename=Identity-date.
isn't it exactly like that now?..
My point of view is very simple ...2. Possibility to reverse interface speed graphics - I mean make Upload=Downlad, and Download=Upload for specific interface.
....
interface do not have neither download nor upload. it has received and sent packets. why do you need that madness?..
isn't it exactly like that now?..1. backup_filename=Identity-date.
interface do not have neither download nor upload. it has received and sent packets. why do you need that madness?..2. Possibility to reverse interface speed graphics - I mean make Upload=Downlad, and Download=Upload for specific interface.
so that somebody can take your password (keylog it, whatever) change rules, and then clear the log? not much of a log then, is it?Just a "/log clear" command. I'm surprised such a basic feature is still missing.
What stops him to do this now by using memory-lines? For God shake normis, it's just a shortcut command.so that somebody can take your password (keylog it, whatever) change rules, and then clear the log? not much of a log then, is it?Just a "/log clear" command. I'm surprised such a basic feature is still missing.
I know that normis, though it's not one command but two. What I suggested was a simple "/log clear" shortcut command implemented in exactly the right path where it belongs; that's all.well you said yourself, you can already do it with one command
I realize that, but I still want to see the time remaining (and possibly the original total time, if its easy to do) for the dynamic entries. The static entries can just have blank, or N/A or infinite or something like that; or it could be a read-only field that shows up in pr stat or winbox when its appropriate, but can't be set at all.dynamically added address-list entries have timeout set by firewall rule. static entries does not have that parameter.
I agree. For whatever reason, I seem to remember a time-left property of an address-list entry (I just can't remember where / what version I saw it in, or I could be mistaken). Simple: /ip firewall address-list get <id> time-left = (empty or time interval).I realize that, but I still want to see the time remaining (and possibly the original total time, if its easy to do) for the dynamic entries. The static entries can just have blank, or N/A or infinite or something like that; or it could be a read-only field that shows up in pr stat or winbox when its appropriate, but can't be set at all.dynamically added address-list entries have timeout set by firewall rule. static entries does not have that parameter.
It might be nice on occasion to be able to add a dynamic entry manually as well.
Also, a "remove all dynamic" button might be handy (while I'm brainstorming). I haven't had to do that very often, but when I have, and its a huge address list, I just reboot the router currently.
any chance for this ?new policy in /user group.
special policy to log in via api called api, now it can be blocked via winbox policy only.
please separate those two.
Looks like it limited ... Because x86 with 2G RAM, and RB1100 with 512 Mb RAM has the same Value - 524288.max conntrack number depends on free resources on the router, more RAM more entries available.
feature request: implement certificate revocation lists (CRL) in OpenVPN server.
explanation: when client certificate used for OVPN connection is compromised/revoked by CA, mikrotik OVPN server has no option to block it (except to change username/password in /ppp secrets).
To expand, maybe array format (like [find] returns) would probably work good, of course this would mean re-writing current scripts that use the ping command's current output (only successful ping count).When troubleshooting latency problems I would like to be able to output traceroute to a variable. If capturing of traceroute output was possible, script could record path and source of congestion as it happens.
In addition return value of ping should be expanded as well to include more information, like latency. Sometimes, a test ping would return no packet loss but high latency renders the link unacceptable. Monitoring latency via script would also open the possibility of measuring approx. jitter.
thank you.
To expand, maybe array format (like [find] returns) would probably work good, of course this would mean re-writing current scripts that use the ping command's current output (only successful ping count).
I like your idea. Speaking of torch, please add a connection/packet mark filters.Please add src/dst address list support to torch. It can be useful to see what is going to oversea traffic for example.
you do have this option. in Bridge Filter. it's not possible in IP Firewall, because at that moment DST MAC is unknown (also, output interface can be PPP)Have dst-MAC added as an available option. Currently SRC-MAC is an option but not DST-MAC address
yep, it would be nice to have that info, for example, in NetFlow v9 output... just a dream...A way to tie the absolute SRC Address and Port, the NAPTed SRC Address and Port, and the DST Address and Port together for RIAA requests. Current the logging only shows the original SRC Address and Port from the users request and the DST Address and Port from the Users request. When we get complaints, they have the header information of the NAPTed packet and the time. We need something to tie this back to a user and to do that, we need the all six data items, Original SRCIP/Port, the new SRCIP/Port of the NATed packet, and the DSTIP/Port.
Hi guys,feature request: implement certificate revocation lists (CRL) in OpenVPN server.
explanation: when client certificate used for OVPN connection is compromised/revoked by CA, mikrotik OVPN server has no option to block it (except to change username/password in /ppp secrets).
THIS. Except for everything that uses certificates. SSTP, IPSEC, Ovpn.
basically you need a new permission option in groups, so that you can make RouterOS users who can access userman, and who can'tcan you add second password to usermen
so there is a password for pppoe,pptp,winbox etc connections
and a password for web interface login
what i was saying is that when users change that password the pppoe cassword also changes i want a password for users profile and anothe password to reset pppoe passwordbasically you need a new permission option in groups, so that you can make RouterOS users who can access userman, and who can'tcan you add second password to usermen
so there is a password for pppoe,pptp,winbox etc connections
and a password for web interface login
looks like you are not following this forum so much. request was discussed before, and will not happen anytime soon for many reasons.Provide Bug tracking system. Provide complete release notes with detailed information about linux kernels used and packages. Provide complete information about security vulns in RoS. Provide bug description for each confirmed bug (versions affected, fixed versions, workarounds)
Yeah. I know, but I think that it is not bad once again to remind about this issue. Maybe you will have pity on us and give us the solution, I know that it is hard, but it is absolutely needed.looks like you are not following this forum so much. request was discussed before, and will not happen anytime soon for many reasons.Provide Bug tracking system. Provide complete release notes with detailed information about linux kernels used and packages. Provide complete information about security vulns in RoS. Provide bug description for each confirmed bug (versions affected, fixed versions, workarounds)
You should at a minimum provide a list of known issues with a release to keep someone from installing an update and breaking things. Say like when upgrading to 5.0 from 4.16 could disable your wireless package. I know you don't always know when something is release what the bugs are but once you find out it should be listed some place.looks like you are not following this forum so much. request was discussed before, and will not happen anytime soon for many reasons.Provide Bug tracking system. Provide complete release notes with detailed information about linux kernels used and packages. Provide complete information about security vulns in RoS. Provide bug description for each confirmed bug (versions affected, fixed versions, workarounds)
Or for example when you upgrading from 4.17 to 5.2 - mac address settings on wireless interfaces changes to the BIA, although it was configured manually.You should at a minimum provide a list of known issues with a release to keep someone from installing an update and breaking things. Say like when upgrading to 5.0 from 4.16 could disable your wireless package. I know you don't always know when something is release what the bugs are but once you find out it should be listed some place.looks like you are not following this forum so much. request was discussed before, and will not happen anytime soon for many reasons.Provide Bug tracking system. Provide complete release notes with detailed information about linux kernels used and packages. Provide complete information about security vulns in RoS. Provide bug description for each confirmed bug (versions affected, fixed versions, workarounds)
Chadd
Hi"Load Previous Session" and "Exit" button on the left side (NOT 'Close (X)' the window, don't ask me why) should help...
I use both, but to be honest never noticed any differences between them. "X" leaves as many settings in place as "exit" and vice versa."Load Previous Session" and "Exit" button on the left side (NOT 'Close (X)' the window, don't ask me why) should help...
An Android variant of Winbox would be great, but I wouldn't expect Mikrotik to dedicate the time and effort it would require, that's just not reasonable at this time. If Android tablets continue to proliferate it might become reasonable, but ATM I'm sure it's too much of a 'niche market' for them to devote efforts that could be better spent on RouterOS itself.BTW, any thoughts abt those tablets x android 2.1 or 2.2 X webfig? Or a future android winbox version?;
we already do have SSL webfig ...PS - can we get SSL webfig plz? The only way I'm comfortable with using it right now is through a VPN connection, which isn't always possible.
Because, for each service it is LOGICAL to have an option what interfaces (or even IP's) to run it on. It is not job for firewall to block it.you already answered it, you must use firewall. why make the same configuration in two places?
Well said!Because, for each service it is LOGICAL to have an option what interfaces (or even IP's) to run it on. It is not job for firewall to block it.
But as we all know, logic, user friendliness and usability ar enot strong sides of Mikrotik.
is Cisco logical?.. how can one allow management connections to some IP addresses of router and forbid ones to another addresses (users' default gateways, for example)?..for each service it is LOGICAL to have an option what interfaces (or even IP's) to run it on. It is not job for firewall to block it.
But as we all know, logic, user friendliness and usability ar enot strong sides of Mikrotik.
For RoS it is not logical to binding services to specific interface/address (although sometimes it use this method - pppoe server, hotspot etc.) , but for IOS it is because of the architecture and used practice for plain old packet filtering assignment behavior to interface.I mean, either cisco router allows binding services to specific interface/address and is far away, or it doesn't, and it's not logical, not user-friendly and not usable
Well, I said: logic, user friendliness and usability are not strong sides of Mikrotik.I don't think it's logical at all. Or user friendly!
For ease of use and functionality i would suggest to use TheDude for this - just remove probes, so no additional load anywhere, just network device map, where you can create device groups and operate with them (upgrade devices, for example). And if required, you can monitor your key routers in the network.Folders/groups in the startup window of winbox. With hundreds of diferent customers and many RBs in each customer, I need to group them to easy find the correct RBs.
It will be very good to let us make a tree with folders to keep our winbox saved entrys easy to find.
It's easyer directly in winbox : / It's not easy to do?For ease of use and functionality i would suggest to use TheDude for this - just remove probes, so no additional load anywhere, just network device map, where you can create device groups and operate with them (upgrade devices, for example). And if required, you can monitor your key routers in the network.Folders/groups in the startup window of winbox. With hundreds of diferent customers and many RBs in each customer, I need to group them to easy find the correct RBs.
It will be very good to let us make a tree with folders to keep our winbox saved entrys easy to find.
There is no plan for it and I do not see any strong reason to run SSD on MiniPCIe.It would be nice to have the drivers so the MiniPCIe drive could be used for a small SSD for extra storage or cache space.
Because the 411U board only has one USB port and I'm using it for a 3G modem.There is no plan for it and I do not see any strong reason to run SSD on MiniPCIe.
+1feature request: implement certificate revocation lists (CRL) in OpenVPN server.
explanation: when client certificate used for OVPN connection is compromised/revoked by CA, mikrotik OVPN server has no option to block it (except to change username/password in /ppp secrets).
A challenger appears: http://en.wikipedia.org/wiki/IEEE_802.1aqImplementation of TRILL (Transparent Interconnection of Lots of Links) as a future alternative to RSTP.
TRILL allows usage of multiple links simultaneously removing the biggest restriction in RSTP which is waste of bandwidth due to offline links.
http://tools.ietf.org/wg/trill/
http://en.wikipedia.org/wiki/TRILL_(computing)
Detailed explanation of advantages of TRILL over STP/RSTP - http://bradhedlund.com/2010/05/07/setti ... for-trill/
this is default behavior if you set "default"-auto detect max radio power
dhcp client txoptions add intf=ipKmInet option=dhcp-requested-address value=(addr)x.x.x.x
Out of interest and to gain some understanding: What is it you want?Feature request: DHCP-client option
I wondering, why there is no such trivial thing?
In %another_router_brand% I can put any custom options to DHCP client. For example, if I need to set dhcp-requested-address (option number 50), I can:But there is no way to do this with mikrotikCode: Select alldhcp client txoptions add intf=ipKmInet option=dhcp-requested-address value=(addr)x.x.x.x
I found similar question here: http://forum.mikrotik.com/viewtopic.php?f=2&t=46855
(option 60 (Vendor class identifier) in this case)
And the answer was: it is not possible.
So, if there is
/ip dhcp-server option
would be nice to have also
/ip dhcp-client option
I'm just trying to tell, that there may be many reasons to do that (for example, I have no idea why somebody need option #60, but I can tell why I need option #50).no, the question was, "why" do you need to do that? what is the result?
?..3) PPTP classless routing fix for Windows clients
even more: not only 'on connect' and 'on disconnect', but 'before connect' so that it would be possible to set, for example, server address from the list of servers (RR DNS, etc.)add option to ppp profile to call one script when client connects (post ip assignment) and another script when client disconnects
It would be really nice to have this feature integrated. Just a few words why it's really needed:integrate udpxy. Very useful for IPTV over WiFi for home users.
Oukey, so why are on different places made oportunity to allow access only from specified IPs ? /ip services /user and so on for example ?I don't think it's logical at all. Or user friendly!
RouterOS users expect that all access rules are managed by the firewall. Why run to 10 different places to turn on/off some service access when you can do it all in one place, with easy overview of all rules and their priorities.
+1, extremely actual I'd even upgrade my v3.28 pptp concentrator to v5 or even v6Unmetered content for ppp server specially in pppoe server . a featue which a router allows not to count some addresses in radius accounting .
for example we want pppoe users don't pay for opening http://www.mikrotik.com
It would be great, one "like" for udpxy.integrate udpxy. Very useful for IPTV over WiFi for home users.
If I understand correctly, multicast-helper works only for point-to-point radio links. Udpxy can help if there is a standard home WiFi network with multiple client devices.well, now (v6, AFAIR) ROS can send mutlicast paskets as unicast frames, so udpxy is not actual just for wifi
TEE
The TEE target will clone a packet and redirect this clone to another machine on the local network segment. In
other words, the nexthop must be the target, or you will have to configure the nexthop to forward it further if so
desired.
--gateway ipaddr
Send the cloned packet to the host reachable at the given IP address. Use of 0.0.0.0 (for IPv4 packets) or
:: (IPv6) is invalid.
To forward all incoming traffic on eth0 to an Network Layer logging box:
-t mangle -A PREROUTING -i eth0 -j TEE --gateway 2001:db8::1
+1+1feature request: implement certificate revocation lists (CRL) in OpenVPN server.
explanation: when client certificate used for OVPN connection is compromised/revoked by CA, mikrotik OVPN server has no option to block it (except to change username/password in /ppp secrets).
+1 and show CPU usage and Uptime by defaultin winbox show inline comments by default
This option is mentioned in the past before. I am afraid it got snowed under a bit since the development of the web based UI.Having a per device notepad would be awesome. I have alot of devices configured in a manner that would be difficult to understand without separate explanation. The general device notebook would help alot. It would also be helpful to write down initial signal strenghts to cpe's, etc..
BTW, I've heard new winbox is under developement. I really hope they listen to all our suggestions while developing it.
It's a wish, and has been for many, many years. Maybe if I keep suggesting it, Mikrotik might eventually add it !What's new in 6.0beta5
*) ipsec - add support for Virtual Tunnel Interfaces;
We don't want to write scripts. We want usability without the need to write scripts in an ever changing script language. Everytime when I upgrade my ROS I am worried the few scripts I made did survive...You can scan for about 5-6seconds via terminal. Or you can use a script to scan for as long as you want and put the results into a text file.
As for notepad, count me in too.
I think this remote 'scan' and print to screen/file function is one of the highest valued reature requests. I know MT said once they are working on it but probably that is going to be ROSv.6.This reminded me of yet another feature worth mentioning. I'd like to have an ability to export scan results to a file (from winbox mostly). I'm collecting site surveys during client installs recently. This sometimes gives useful information about channel usage in that area. Screenshooting is very inconvenient.
Mikrotik, please go and write 'export wireless scan results to a file' on your added feature list for next release.. It's a must have and I'm sure very easy to implement.
This functionality already exists, it is CLI only though. You need to configure the "Routing Instance" against a "routing table", which is Mikrotik's pseudo-VRF system. Any peering sessions associated with this BGP instance will now occur within the "vrf"Please add the ability to peer with bgp neighbors within a VRF (Not MPBGP) basically in the ipv4 address-family vrf XXX.
It is on it's way, please see: http://www.mikrotik.com/download/share/du12.pdf- Metal for 2.4Ghz (HP)
just create a dedicated entry under Networks for the address of your lease- dhcp options per lease
huh... "[Ticket#2008092966000257] Receive Options for DHCP Server from RADIUS" - the last answer was almost three years ago:(also by radius)
Currently we are very busy in other projects, but this feature is on our todo list.
+1 like. Also /interface vlan show vlan-id by default at winbox.in winbox show inline comments by default
and in interfaces>eoip show tunnel-id by default
you'd better use scp, I think - it's more secure than fetchingRequest:
implement tar in order to e.g. copy a archive (via ssh) to a client connected to an ovpn server untar it on the client. Needed in case of full portalpage overhaul.
The implemente fetch function is just not flexible enough for tasks like the above mentioned.
Imagine a portal pages consisting of html pages and subfolders with html pages, no way anybody would want to replace every file in that structure one by one.
Thats a problem when dealing with MT devices connected to a vpn server. Anyways fetch is fine as long as the is a way to uncompress e.g. tar files.you'd better use scp, I think - it's more secure than fetchingRequest:
implement tar in order to e.g. copy a archive (via ssh) to a client connected to an ovpn server untar it on the client. Needed in case of full portalpage overhaul.
The implemente fetch function is just not flexible enough for tasks like the above mentioned.
Imagine a portal pages consisting of html pages and subfolders with html pages, no way anybody would want to replace every file in that structure one by one.
Note: maybe you can use this - you can run a winbox with a command line parameter (IP, name, password) so it is very easy to run winbox from browser (for example) and then it connect without asking for user credentials etc.I propose to discuss the possibility of implementing user authorization in Winbox, using SSL-certificate. Our company uses a lot of RouterBoard and we need a more flexible management of passwords on all RouterBoard.
use RADIUS?..Our company uses a lot of RouterBoard and we need a more flexible management of passwords on all RouterBoard.
Yes, we use Radius, but only for PPP authentication. You talk about this point → Radius Server settings: Service = Login?use RADIUS?..Our company uses a lot of RouterBoard and we need a more flexible management of passwords on all RouterBoard.
yes, plus "System -> Users -> AAA -> Use RADIUS"Yes, we use Radius, but only for PPP authentication. You talk about this point → Radius Server settings: Service = Login?
The walled garden options support regular expressions so there's nothing stopping you from doing this already.Many interesting suggestions here. I'm wishing for a walled garden configuration that allows an entire web site to be accessed. Seems to be too narrow, now. How about wild card support in the URL field?
/ip hotspot walled-garden add dst-host=":^www\\.paypal\\.com\$" dst-port=443 action=allow /ip hotspot walled-garden add dst-host=":^content\\.paypalobjects\\.com\$" dst-port=443 action=allow /ip hotspot walled-garden add dst-host=*.akamaiedge.net action=allow /ip hotspot walled-garden add dst-host=paypal.112.2O7.net
More specific domains take precendence over less specific domains, so: --server=/google.com/1.2.3.4 --server=/www.google.com/2.3.4.5 will send queries for *.google.com to 1.2.3.4, except *www.google.com, which will go to 2.3.4.5
you need to set static IP address for that lease and add /32 network for that address with necessary gatewayAdd a feature to the dhcp server that makes it possible to change the default gateway for static leases.
Okay, I saw that it is indeed possible to add another gateway in RouterOS version 6. Too bad that I can't upgrade right now until a few other issues has been resolved in the latest release.you need to set static IP address for that lease and add /32 network for that address with necessary gatewayAdd a feature to the dhcp server that makes it possible to change the default gateway for static leases.
[admin@Mikrotik] > ping 127.0.0.1 count=2
HOST SIZE TTL TIME STATUS
127.0.0.1 56 64 6ms
127.0.0.1 56 64 5ms
sent=2 received=2 packet-loss=0% min-rtt=5ms avg-rtt=5ms max-rtt=6ms
HOST SIZE TTL TIME STATUS
there's some undocumented featurewhen an entry appears in /ip dhcp-server lease you could then launch a script passing internal *id as parameter and do some actions based on it.
add custom firewall rule etc.
i know this is a "BIG" feature request, but imagine the possibilities.
/ip dhcp-server set 0 lease-script=
1 why is it undocumented ?there's some undocumented featurewhen an entry appears in /ip dhcp-server lease you could then launch a script passing internal *id as parameter and do some actions based on it.
add custom firewall rule etc.
i know this is a "BIG" feature request, but imagine the possibilities.Code: Select all/ip dhcp-server set 0 lease-script=
Wiki includes info about that. I wrote on the board about variables for lease-script, before it was published on wiki.there's some undocumented featurewhen an entry appears in /ip dhcp-server lease you could then launch a script passing internal *id as parameter and do some actions based on it.
add custom firewall rule etc.
i know this is a "BIG" feature request, but imagine the possibilities.Code: Select all/ip dhcp-server set 0 lease-script=
+1Xtables-Addons with GeoIP for Firewall
We use TheDude to manage MT Devices. Makes things much easier than using winbox alone.Hi, an other basic request:
I work for an ISP, we have to manage a very high number of mikrotik devices.
We have been using winbox.exe but in our situation looking for the correct device is becoming really frustrating...
Add a "search button" on winbox applicaton could help us..
Thank you!
use 'Filter' button, 'Enabled' -> 'is' -> 'yes'From time to time i wish i can hide "disabled" interfaces in winbox "Interface list" menu. I think this can be useful when working with new CCR switches and even 2011 RB's.
if you close the window, not saved\если закрыть окно -не сохраняетсяuse 'Filter' button, 'Enabled' -> 'is' -> 'yes'
Or at least an on lease script call out for the dhcp clientDoes MT support Multiple DHCP Scopes and Multiple IP's on the LAN interface?
:global ifslink 5180,5750,5770,5790,5810,5830,5850,5870,5890 :global ifs5ghz 5390,5410,5430,5450,5470,5490,5510,5530,5550,5570,5590,5610,5630,5650,5670,5690,5180,5750,5770,5790,5810,5830,5850,5870,5890 :global ifs2ghz 2409,2429,2414,2434,2419,2439,2424,2444,2449,2469,2454,2474,2459,2479,2464,2484(example have even more channels) But how do i configure this device in winbox?
You mean SOHO routers? RouterOS is in no way a SOHO software, even despite the fact that quite a few of Mikrotik routers are targeting SOHO market.I can't understand why all decent routers I have met in my life
I uphold this. I also need in ppp profile an option to specify default packet-marks for simple queue.MT please please. We need more queue options in PPP profile. For example we need different values in max-limit and limit-at. When using Radius for AAA, now dynamic simple queues create with same value at limit-at. It restricts us to do some QoS and it fights off RouterOS`s powerful, intelligent queue features.
+1UPS package should be refreshed with more options ... event reporting (mail) would be nice and also possibility to share ups status with other routerboards (and linux boxes running for example apcupsd) over the network so all units could be safely shutdown in case of ups battery exhaustion. After power restoration WOL commands could be issued and so on ...
JF