L2 connections:
AC swch client
ehter4 ------ ether4
ehter5 ------ ether5
ether3------ether5
/interface bridge add name="br - pppoe" /interface ethernet set [ find default-name=ether4 ] name="ether4 - to swch" set [ find default-name=ether5 ] name="ether5 - to swch" /interface bonding add lacp-rate=1sec mode=802.3ad name="lacp1 - ether4, ether5" slaves="ether4 - to swch,ether5 - to swch" /ip pool add name=PPPoE ranges=10.4.0.0/24 /ppp profile add local-address=1.1.1.1 name=pppoe remote-address=PPPoE /interface bridge port add bridge="br - pppoe" horizon=1 interface=ether3 add bridge="br - pppoe" interface="lacp1 - ether4, ether5" /interface pppoe-server server add default-profile=pppoe disabled=no interface="br - pppoe" max-mru=1500 max-mtu=1500 /ppp secret add name=123 password=123 profile=pppoe /system identity set name=ACswch:
/interface bridge add name="br - switch" /interface ethernet set [ find default-name=ether3 ] name="ether3 - to client" set [ find default-name=ether4 ] name="ether4 - to AC" set [ find default-name=ether5 ] name="ether5 - to AC" /interface bonding add lacp-rate=1sec mode=802.3ad name="lacp1 - ether4, ether5" slaves="ether4 - to AC,ether5 - to AC" /interface bridge port add bridge="br - switch" interface="ether3 - to client" add bridge="br - switch" interface="lacp1 - ether4, ether5" /system identity set name=swchclient:
/interface pppoe-client add add-default-route=yes disabled=no interface=ether5 max-mru=1500 max-mtu=1500 name=pppoe-out1 password=123 user=123 /system identity set name=clientNow lets ping the AC inside of the pppoe session from the client:
/tool sms set keep-max-sms=20 port=usb1 receive-enabled=yes secret=passwordWait more then 30 minutes and send a SMS to the device.
15:23:16 gsm,error unable to load unread sms: timeoutTrying to re-enable sms receiving by receive-enabled=yes you get a timeout error"
/tool sms set receive-enabled=yes action timed out - try again, if error continues contact MikroTik support and send a supout file (13)Notes:
/system leds> exp # jan/02/1970 00:01:07 by RouterOS 6.6 # software id = 7IXG-ZI8H # /system leds set 0 interface=wlan1 set 1 interface=ether1
/system leds> exp ver # jan/02/1970 00:01:08 by RouterOS 6.6 # software id = 7IXG-ZI8H # /system leds set 0 disabled=no interface=wlan1 leds=led1,led2,led3,led4,led5 type=wireless-signal-strength set 1 disabled=no interface=ether1 leds=user-led type=interface-activityApply a little change:
/system leds :foreach i in=[find] do= { set $i led="" }Wrong export output:
/system leds> exp # jan/02/1970 00:03:11 by RouterOS 6.6 # software id = 7IXG-ZI8H # /system leds set 0 interface=wlan1 set 1 interface=ether1
/system leds> exp ver # jan/02/1970 00:03:24 by RouterOS 6.6 # software id = 7IXG-ZI8H # /system leds set 0 disabled=no interface=wlan1 leds="" type=wireless-signal-strength set 1 disabled=no interface=ether1 leds="" type=interface-activity
Thanks for this list. I hope that will not soon deletedHey guys,
Since there is currently no official known issues list / bug tracker, lets start one here on the forums.
I will be adding more.Thanks for this list. I hope that will not soon deleted
This is great idea but at the moment account cannot be created there. Captcha is not working.There's another bug list here: http://bugs.mikrotik-routeros.com/view_all_bug_page.php. I don't know how active it is though...
No offense to the maintaners of that list, but it seems to be kinda abandoned.This is great idea but at the moment account cannot be created there. Captcha is not working.There's another bug list here: http://bugs.mikrotik-routeros.com/view_all_bug_page.php. I don't know how active it is though...
MikroTik support is located at support@mikrotik.com, just like it says on top of this page. It would be much better and efficient, to submit bugs to mikrotik support, not post them on various (and multiple) online webpages.Mikrotik Support did you read these thread?
Please read disclaimer 3.Mikrotik Support did you read these thread?
All of the bugs/issues which I personally listed in this topic are reported to support.MikroTik support is located at support@mikrotik.com, just like it says on top of this page. It would be much better and efficient, to submit bugs to mikrotik support, not post them on various (and multiple) online webpages.
Even if they are reported, bugs still take a while to fix, MikroTik doesnt have 10 developers they can just throw right away at any issue that arises, we have to understand that. Im not saying there arent issues, or that there arent issues that should have been fixed a long time ago, there certainly are.As tomaskir wrote. All bugs on this site have their own Support TicketID
This means that bugs were reported ......
It works, but it is preferred that you include a supout.rif file and full description, because we only receive this one post, not whole thread.Normis, a question:
Does "Submit this post as a bug report to MikroTik Technical Support" here in the forums work? Is sending a ticket directly to support preferable?
Your e-mail-support is very good, but getting an answer takes way to long. I do not have the time to wait 1 week for each reply of the same case number. Sorry...In support emails, 90% of bugs are not bugs, but mistakes.
Tested on a few devices here on my end as well, confirmed. Added to the list, thanks!Issue:
Source IP of web proxy can't be configured in WinBox and WebFig. Configure it in terminal is Ok.
Please remember to use the format outlined in the 2nd post if you want a bug added. Also, please remember to use newest ROS, which is 6.6.New Bug
May specific to the RB2011UiAS-RM.
I haven't seen this previously on the RB2011UAS-RM with ROS 6.1.
Normis,This has been explained before. Why Bugzilla interface will not work.
... SKIP ...
In support emails, 90% of bugs are not bugs, but mistakes. Imagine what will happen, if they will all be listed publicly as "bugs".
Are you talking about actually editing the topics uder Manual? http://wiki.mikrotik.com/wiki/Manual:TOCWiki is open for registration by request. I will gladly offer you editing rights to our Wiki. Public registration was closed because of spam, and people promoting their services. If you only wish to correct the occasional mistake in our content, you are welcome to contact us for an account
You have true. If bugzila not suitable, suggest a way to inform the (forum) Mikrotik users.This has been explained before. Why Bugzilla interface will not work.
1. Somebody reports a "bug". Something is not working
2. Everyone thinks this is a bug, and starts to worry, to downgrade, to switch to other hardware
3. Support finds that "bug" was actually caused by typo mistake in firewall rule.
4. Bug is closed as "Invalid" but damage in #2 can't be undone
In support emails, 90% of bugs are not bugs, but mistakes. Imagine what will happen, if they will all be listed publicly as "bugs".
Verified and added to the list.Issue:
DNS cache does not update for static DNS name change
I checked this several times, and can't get it to repeat. Please submit to support with detailed steps how to repeat.Verified and added to the list.Issue:
DNS cache does not update for static DNS name change
PLEASE submit this to support@mikrotik.com and update your post with a support ticket ID.
Just copy your post from here to the email, it should be enough.
Here is a ticket with exact steps: Ticket#2013112266000451I checked this several times, and can't get it to repeat. Please submit to support with detailed steps how to repeat.
/interface pptp-server add name=pptp-in1 user=pptp /interface sstp-server add name=sstp-in1 user=pptp /interface bridge add name=br_ppp /ppp profile add bridge=br_ppp local-address=2.2.2.1 name=pptp remote-address=2.2.2.2 /interface bridge port add bridge=br_ppp interface=ether3 /interface pptp-server server set default-profile=pptp enabled=yes keepalive-timeout=5 /interface sstp-server server set default-profile=pptp enabled=yes keepalive-timeout=5 max-mru=1450 max-mtu=1450 /ip address add address=1.1.1.1/24 interface=ether5 network=1.1.1.0 /ppp secret add name=pptp password=pptp profile=pptp /system identity set name=SSTP_ACApply configs for client:
/interface bridge add name=br_ppp /ppp profile add bridge=br_ppp name=pptp /interface sstp-client add connect-to=1.1.1.1 keepalive-timeout=5 name=sstp-out1 password=pptp profile=pptp user=pptp verify-server-address-from-certificate=no /interface pptp-client add connect-to=1.1.1.1 keepalive-timeout=5 name=pptp-out1 password=pptp profile=pptp user=pptp /interface bridge port add bridge=br_ppp interface=ether3 /ip address add address=1.1.1.2/24 interface=ether5 network=1.1.1.0 /system identity set name=SSTP_ClientPPTP and SSTP can not connect. Errors in log regarding "could not add bridge port"
/interface l2tp-server server set enabled=yes /ip address add address=10.0.0.1/24 interface=ether5 network=10.0.0.0 add address=1.1.1.1/32 interface=ether5 network=1.1.1.1 /ip firewall mangle add action=log chain=input port=1701 protocol=udp add action=log chain=output port=1701 protocol=udp /ppp secret add name=123 password=123 /system identity set name=ACL2TP client:
/interface l2tp-client add connect-to=1.1.1.1 name=l2tp-out1 password=123 user=123 /ip address add address=10.0.0.2/24 interface=ether5 network=10.0.0.0 /ip route add distance=1 gateway=10.0.0.1 /system identity set name=ClientL2TP will not establish. Looking at the logs will show that the L2TP server replies with a wrong IP address:
/ip firewall nat add action=dst-nat chain=dstnat comment="Fix for an L2TP src-address bug" dst-address="Address you want your L2TP client to connect to" \ dst-port=1701 protocol=udp to-addresses="src-address that L2TP sends wrong packets with"Support TicketID:
It could be specific to only the 2 USB modems I tested, however even if the modems are rebooted with usb-power-reset, the issue continues. (however, after a routerboard reboot, they work)regarding this: http://forum.mikrotik.com/viewtopic.php ... 77#p395377
check if your 3g usb module is not hanging. In our testing we did not see any issues.
Sadly, this is not a bug, but rather a missing feature. Its hard to classify it as a bug, since its missing functionality, rather then something that should work, but doesnt.Issue:
Only a single IPsec VPN client (road warrior) can connect from behind the same NAT.
Anyhow, people should know that IPsec NAT-T support is incomplete (or even broken) on RouterOS. To my knowledge, it has not been documented/mentioned anywhere till now. And for me it also means there's currently not a single viable mobile VPN option available on RouterOS, despite all the new and exciting IPsec features introduced in RouterOS v6. Sad.Sadly, this is not a bug, but rather a missing feature.
I agree its a pain that its not working. As soon as we have a client that has multiple IPSec clients at the same location, we deploy a router and build a S2S tunnel, thats how we get over this particular problem.Anyhow, people should know that IPsec NAT-T support is incomplete (or even broken) on RouterOS. To my knowledge, it has not been documented/mentioned anywhere till now. And for me it also means there's currently not a single viable mobile VPN option available on RouterOS, despite all the new and exciting IPsec features introduced in RouterOS v6. Sad.Sadly, this is not a bug, but rather a missing feature.
I need this feature mostly for our employees who travel a lot and often need to access our office network during their business trips. If several travelers are staying in the same hotel at the same time, chances are they are behind the same NAT, and that's a huge problem. And, unfortunately, S2S is not a solution in this case at all.As soon as we have a client that has multiple IPSec clients at the same location, we deploy a router and build a S2S tunnel, thats how we get over this particular problem.
Maybe allow usage of SSTP as a second option?I need this feature mostly for our employees who travel a lot and often need to access our office network during their business trips. If several travelers are staying in the same hotel at the same time, chances are they are behind the same NAT, and that's a huge problem. And, unfortunately, S2S is not a solution in this case at all.As soon as we have a client that has multiple IPSec clients at the same location, we deploy a router and build a S2S tunnel, thats how we get over this particular problem.
Well, I have ASA5505 which handles similar scenarios just fine at the moment. Being able to use Mikrotik for similar tasks is very desirable, but does not seem to be possible, unfortunately.Maybe allow usage of SSTP as a second option?
Of course, that is only viable if you OSs support SSTP.
dynamic address-list or static address-list? it would be terrible for me to upgrade to v6.7 if the bug also meant for dynamic address-list, because i have port knock filter rules, which keeps re-adding dynamic address-list to keep alive an open connection.Known Issue in v6.7
Duplicate address-list entries (same list name and same address or address range) are causing a crash. Avoid making 2 identical entries, or write to support for v6.8rc1 pre-release version with the fix.
Thanks for your support, and keep sending emails to support if you find any problems.
firewall rules are not affected, as far as I sawdynamic address-list or static address-list? it would be terrible for me to upgrade to v6.7 if the bug also meant for dynamic address-list, because i have port knock filter rules, which keeps re-adding dynamic address-list to keep alive an open connection.
certificate set numbers=0 name=certname
EDIT: Verified, cant change the name in Winbox, only in Console.Issue:
As patrickmkt mentioned, certificate can't be renamed via Winbox.
If you can please post the issue in the format outlined in the 2nd post, with steps on how to reliably replicate, that would be great.How about the RB1100AH(x2) packet loss problem with queue/queuetree ?
http://forum.mikrotik.com/viewtopic.php ... ss#p398033
http://forum.mikrotik.com/viewtopic.php ... ss#p361783
http://forum.mikrotik.com/viewtopic.php ... ss#p349739
/interface pptp-server add name=pptp-in-test user=test /interface bridge add l2mtu=1598 name=bridge1 protocol-mode=rstp /ip pool add name=pool ranges=192.168.88.101-192.168.88.150 /ip dhcp-server add address-pool=pool disabled=no interface=bridge1 name=dhcp /ppp profile add bridge=bridge1 change-tcp-mss=yes name=ppp_bridging use-encryption=yes /interface bridge port add bridge=bridge1 interface=ether2 add bridge=bridge1 interface=ether3 add bridge=bridge1 interface=ether4 add bridge=bridge1 interface=ether5 /interface pptp-server server set default-profile=ppp_bridging enabled=yes max-mru=1460 max-mtu=1460 mrru=1600 /ip address add address=192.168.88.1/24 interface=bridge1 network=192.168.88.0 /ip dhcp-client add dhcp-options=hostname,clientid disabled=no interface=ether1 /ip dhcp-server network add address=192.168.88.0/24 dns-server=192.168.88.1 gateway=192.168.88.1 /ip dns set allow-remote-requests=yes /ip firewall nat add action=masquerade chain=srcnat out-interface=ether1 to-addresses=0.0.0.0 /ppp secret add name=test password=test service=pptpPPTP-client config
/interface bridge add l2mtu=1598 name=bridge1 protocol-mode=rstp /ppp profile add bridge=bridge1 change-tcp-mss=yes name=ppp_bridging use-encryption=yes /interface pptp-client add add-default-route=no allow=pap,chap,mschap1,mschap2 connect-to=\ 172.17.39.131 dial-on-demand=no disabled=no keepalive-timeout=60 max-mru=\ 1450 max-mtu=1450 mrru=1600 name=pptp-out-test password=test profile=\ ppp_bridging user=test /interface bridge port add bridge=bridge1 interface=ether2 add bridge=bridge1 interface=ether3 add bridge=bridge1 interface=ether4 add bridge=bridge1 interface=ether5 /ip address add address=192.168.88.2/24 interface=bridge1 network=192.168.88.0 /ip dhcp-client add dhcp-options=hostname,clientid disabled=no interface=ether1 /ip firewall nat add action=masquerade chain=srcnat out-interface=ether1 to-addresses=0.0.0.0Notes:
Support TicketID:Thanks, problem repeated.
Problem are specific to setups when DHCP-server is on the same bridge where pptp
is bridged.
we will fix that in one of the next versions.
Meanwhile you can ether place DHCP server on other device in the network, or use
EoIP over PPTP and bridge EOIP tunnel.
Excellent bug report, thank you!Issue:
DHCP over BCP
/ip proxy access add dst-port=80 dst-host=mail.mycompany.ru path="" action=deny redirect-to="https://mail.mycompany.ru/owa"Notes:
Author of this report is not responding to our emails, and we can't repeat it.2) SMS receiving stops working and cant be re-enabled
- http://forum.mikrotik.com/viewtopic.php ... 77#p395377
Should be fixed3) Source IP of web proxy can't be configured in WinBox and WebFig.
- http://forum.mikrotik.com/viewtopic.php ... 73#p396502
fixed4) PPTP/SSTP - could not add bridge port - BCP not working
- http://forum.mikrotik.com/viewtopic.php ... 95#p397295
new ppp package invalidates this5) L2TP Server bug - replies from wrong IP address
- http://forum.mikrotik.com/viewtopic.php ... 19#p398319
fixed6) Duplicate address-list entries (same list name and same address or address range) are causing a crash.
- http://forum.mikrotik.com/viewtopic.php ... 81#p398855
fixed7) Certificates can't be renamed via Winbox.
- http://forum.mikrotik.com/viewtopic.php ... 16#p400112
L2 connections:
server client device
ehter5 ------ ether5
ether4------ether4
/interface bridge add name=bridge1 protocol-mode=rstp /interface bridge port add bridge=bridge1 interface=ether4 /ip address add address=192.168.88.1/24 interface=bridge1 add address=10.0.0.1/24 interface=ether5 /ip pool add name=DHCP_pool ranges=192.168.88.101-192.168.88.150 /ip dhcp-server add address-pool=DHCP_pool disabled=no interface=bridge1 name=dhcp /ip dhcp-server network add address=192.168.88.0/24 gateway=192.168.88.1 /ppp profile add bridge=bridge1 name=ppp_bridging /interface pptp-server server set default-profile=ppp_bridging enabled=yes max-mru=1400 max-mtu=1400 /ppp secret add name=test password=test service=pptp /interface pptp-server add name=pptp-in-test user=testPPTP-client config:
/interface bridge add name=bridge1 protocol-mode=rstp /interface bridge port add bridge=bridge1 interface=ether4 /ip address add address=192.168.88.2/24 interface=bridge1 add address=10.0.0.2/24 interface=ether5 /ppp profile add bridge=bridge1 name=ppp_bridging /interface pptp-client add connect-to=10.0.0.1 disabled=no keepalive-timeout=10 max-mru=1400 max-mtu=1400 \ name=pptp-out-test password=test profile=ppp_bridging user=testDHCP client config:
/ip dhcp-client add default-route-distance=0 dhcp-options=hostname,clientid disabled=no interface=ether4Notes:
Support TicketID:Thanks, problem repeated.
Problem are specific to setups when DHCP-server is on the same bridge where pptp
is bridged.
we will fix that in one of the next versions.
Meanwhile you can ether place DHCP server on other device in the network, or use
EoIP over PPTP and bridge EOIP tunnel.
I tested this on 6.9 and it seems to work, can you please provide more detail how to reproduce on 6.9?Issue:
Web-proxy redirect-to
Added to the list, thanks!Issue:
Unable to initialite a system variable via SMS
The support response got lost in all my emails, sorry, my faultAuthor of this report is not responding to our emails, and we can't repeat it.2) SMS receiving stops working and cant be re-enabled
- http://forum.mikrotik.com/viewtopic.php ... 77#p395377
This issue is still present in 6.9 with the new ppp package, and can reliably be reproduced with the steps in the linked post.new ppp package invalidates this5) L2TP Server bug - replies from wrong IP address
- http://forum.mikrotik.com/viewtopic.php ... 19#p398319
This was fixed in v6.8 as well. if anyone can repeat it, email support with full access, description and supout.rif file4) DHCP over BCP does not work
- http://forum.mikrotik.com/viewtopic.php ... 46#p407146
I will email support asap, can reproduce it with the steps in this post:This was fixed in v6.8 as well. if anyone can repeat it, email support with full access, description and supout.rif file4) DHCP over BCP does not work
- http://forum.mikrotik.com/viewtopic.php ... 46#p407146
/routing bgp instance vrf exportThe resulting output will not include the instance or out-filter
Thanks for the report! Added to the list.Issue:
Export of BGP VRF configuration does not include the "instance" or "out-filter" entries.
Confirmed as well, and added to the list. This one could cause trouble even for me if I upgraded our IPSec AC.Issue:
During upgrade of RouterOS IPSEC peers become disabled
what is the output of these two commands?RB951Ui from MUM - RouterOS 6.5, connected to internet and then...
/system package update upgrade
router rebooted, all is ok but PoE firmware = 0.0
Checked in the day of MUM on two routers, same effect...
[admin@OmniTik-despa] /interface wireless> export hide-sensitive
# feb/25/2014 11:55:10 by RouterOS 6.6
# software id = 9SFF-0RWS
#
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
add authentication-types=wpa2-psk eap-methods="" management-protection=\
required mode=dynamic-keys name=MAIN supplicant-identity=""
/interface wireless
set [ find default-name=wlan1 ] allow-sharedkey=yes band=5ghz-onlyn \
basic-rates-a/g="" bridge-mode=disabled channel-width=20/40mhz-ht-below \
disabled=no frequency=5680 frequency-mode=superchannel \
ht-ampdu-priorities=0,1 ht-basic-mcs=mcs-0,mcs-1,mcs-2,mcs-3 ht-rxchains=\
0,1 ht-supported-mcs=mcs-0,mcs-1,mcs-2,mcs-3,mcs-10,mcs-11,mcs-12,mcs-13 \
ht-txchains=0,1 hw-retries=4 l2mtu=2290 max-station-count=2 mode=\
ap-bridge mtu=1540 nv2-cell-radius=10 nv2-security=enabled \
periodic-calibration=enabled preamble-mode=short rate-set=configured \
security-profile=MAIN ssid=TRUNK supported-rates-a/g="" tdma-period-size=\
3 tx-power=23 tx-power-mode=card-rates wireless-protocol=nv2 wmm-support=\
enabled
/interface wireless access-list
add interface=wlan1 mac-address=00:0C:42:X:Y:Z
[admin@OmniTik-despa] /interface wireless>
[admin@OmniTik-casa] /interface wireless> export hide-sensitive
# feb/25/2014 11:56:44 by RouterOS 6.10
# software id = PAXV-BRR1
#
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
add authentication-types=wpa2-psk management-protection=required mode=\
dynamic-keys name=MAIN supplicant-identity=""
/interface wireless
set [ find default-name=wlan1 ] band=5ghz-a/n bridge-mode=disabled \
channel-width=20/40mhz-ht-below disabled=no frequency-mode=superchannel \
ht-ampdu-priorities=0,1 ht-guard-interval=long hw-retries=1 l2mtu=2290 \
mtu=1540 noise-floor-threshold=-105 nv2-cell-radius=10 nv2-security=\
enabled periodic-calibration=enabled preamble-mode=short scan-list=\
5580,5680,5660,5700,5540,5180,5200,5220 security-profile=MAIN ssid=TRUNK \
tx-power=23 tx-power-mode=card-rates wireless-protocol=nv2 wmm-support=\
enabled
I will try to simulate this problem and create a proper reliable step-by-step process on how to reproduce it.Please fix this bug:
http://forum.mikrotik.com/viewtopic.php?f=14&t=79519
Decription:
IPv6 over PPPoE stops working after PPPoE connection disconnect.
To fix you have to disable/enable ipv6 address and then release/renew dhcpv6 client.
Here is video of problem (not made by me)
http://www.youtube.com/watch?v=6Mo1HN4y ... e=youtu.be
Issue is same as in video, but with 6.10 it changed so that additional step is required (releasing/renewing dhcpv6)
Versions affected: 6.x
I tested on a RB750 and a RB951-2n, but it does not happen for me, I dont have a 433ah I can test on.Issue:
bad blocks problem
He did say he had to downgrade to 6.4.You can actually see in your picture, that you have v6.4, so why do you write that this only happens in v6.10?
upgraded to 6.10, bad blocks started increasing.You can actually see in your picture, that you have v6.4, so why do you write that this only happens in v6.10?
Could you please check on another 433ah as I mentioned in here http://forum.mikrotik.com/viewtopic.php ... 50#p411879?trying to reinstall with net install with no luck still 2.3%
Unfortunately I do not have any other 433ah rbCould you please check on another 433ah as I mentioned in here http://forum.mikrotik.com/viewtopic.php ... 50#p411879?
Thanks!
/snmp set trap-interfaces=ether1But it does no effect when sending trap to a subnet, that belongs to another interface. The packet is generated with source address of that "another" interface.
10.0.0.1 10.0.0.2
Router1 --------(vpn)------------Router2
(ether1) (ether1)
| |
| |
| |
192.168.0.1 192.168.1.1
/ip address add interface=vpn address=10.0.0.1/30 /ip address add interface=ether1 address=192.168.0.1/24 /ip route add gateway=10.0.0.2 /snmp set enabled=yes trap-community=public trap-generators=interfaces,start-trap \ trap-interfaces=ether1 trap-target=192.168.1.2Configuration on Router2
/ip address add interface=vpn address=10.0.0.2/30 /ip address add interface=ether1 address=192.168.1.1/24 /ip route add gateway=10.0.0.1 /ip firewall filter add chain=forward comment="Block traffic generated in VPN subnet for security reason" \ in-interface=vpn out-interface=ether1 src-address=10.0.0.0/30 action=dropSo when trap will be generated, server will not recieve it. It will be blocked by firewall because it has source ip address 10.0.0.1, but we need 192.168.0.1.
/system logging action set 3 bsd-syslog=no name=remote remote=192.168.1.2 remote-port=514 src-address=\ 192.168.0.1 syslog-facility=daemon syslog-severity=auto target=remoteSupport TicketID:
I have tested it with both versions 6.9 and 6.10 but the problem is still there!!!I will email support asap, can reproduce it with the steps in this post:This was fixed in v6.8 as well. if anyone can repeat it, email support with full access, description and supout.rif file4) DHCP over BCP does not work
- http://forum.mikrotik.com/viewtopic.php ... 46#p407146
http://forum.mikrotik.com/viewtopic.php ... 50#p407146
Edit: sent with [Ticket#2014020466000625]
/ip address add address=10.0.0.1/30 interface=ether2 network=10.0.0.0 add address=10.2.0.1/30 interface=ether4 network=10.2.0.0 /ip route vrf add interfaces=ether2,ether4 routing-mark=vrf1When a PC with IP address 10.0.0.2 run a traceroute towards 10.2.0.2, the router (first hop) just won't show up.
Tested and confirmed, added to the list.Issue:
Router always looks in the main table when it has to send ICMP TTL exceeded in transit (type 11)
I took me a bit to understand and simulate your issue, I have a few quesions:Issue:
Wrong behaivor of SNMP TRAP generator
Description:
In SNMP configuration options there is parameter which means "List of interfaces that traps are going to be sent out"ros code
/snmp set trap-interfaces=ether1But it does no effect when sending trap to a subnet, that belongs to another interface. The packet is generated with source address of that "another" interface.
/routing igmp-proxy
set quick-leave=yes
/routing igmp-proxy interface
add alternative-subnets=10.0.0.0/8 interface=ether2 upstream=yes
add interface=ether7
L2 connections:
Client1 VRF_Router Client2
ehter4 ------ ether4
ether5------ether5
/ip address add address=10.0.0.1/30 interface=ether4 network=10.0.0.0 add address=10.2.0.1/30 interface=ether5 network=10.2.0.0 /ip route vrf add interfaces=ether4,ether5 routing-mark=vrf1 /system identity set name=VRF_RouterConfig on Client1:
/ip address add address=10.0.0.2/30 interface=ether4 network=10.0.0.0 /ip route add distance=1 gateway=10.0.0.1 /system identity set name=Client1Config on Client2:
/ip address add address=10.2.0.2/30 interface=ether5 network=10.2.0.0 /ip route add distance=1 gateway=10.2.0.1 /system identity set name=Client2Run a trace from Client2 to Client1:
[admin@Client2] > tool traceroute 10.0.0.2
# ADDRESS LOSS SENT LAST AVG BEST WORST STD-DEV STATUS
1 100% 5 timeout
2 10.0.0.2 0% 4 2.4ms 2.1 1.9 2.4 0.2
Well summarized tomaskir.This is a repost of an issue submitted by Poki: http://forum.mikrotik.com/viewtopic.php ... 00#p413242
Reposted here with an easier to recreate configuration, to make re-testing with newer versions easier.
Issue:
Router looks in the main routing table and not in a VRF for ICMP TTL exceeded (type 11)
Support TicketID:
2014030666000236
Your bug is still open, and is being investigated. Sorry if that wasn't clear. We answer ALL emails. If you didn't get an answer, either it's in your junk folder, or we are still looking into it.Well summarized tomaskir.This is a repost of an issue submitted by Poki: http://forum.mikrotik.com/viewtopic.php ... 00#p413242
Reposted here with an easier to recreate configuration, to make re-testing with newer versions easier.
Issue:
Router looks in the main routing table and not in a VRF for ICMP TTL exceeded (type 11)
Support TicketID:
2014030666000236
I just wanted to mention that I still don't have a reply from Mikrotik about this issue.
It's a shame. Instead of being grateful about helping them improve their OS, they don't even bother to consider our bug reports.
Hi normis,Your bug is still open, and is being investigated. Sorry if that wasn't clear. We answer ALL emails. If you didn't get an answer, either it's in your junk folder, or we are still looking into it.
Normis. How sure are you about this. I have send an email the 6th about DHCP over BCP... We answer ALL emails. If you didn't get an answer, either it's in your junk folder, or we are still looking into it.......
In this case you have responded with an update to a 101 days old ticket, which means it gets buried in the priority list. I suggest making a new ticket when you have a new problem.Ticket#2013120266000175
I have not received any response yet.
But it is not a new problem. You stated it should be solved in version 6.8 but I can still reproduce it in 6.9 and 6.10In this case you have responded with an update to a 101 days old ticket, which means it gets buried in the priority list. I suggest making a new ticket when you have a new problem.Ticket#2013120266000175
I have not received any response yet.
/interface ethernet switch port set [find] learn-restricted-unknown-sa=yes
/interface ethernet switch set bridge-type=customer-vlan-bridge
/interface ethernet
set [ find default-name=sfp1 ] auto-negotiation=no
set [ find default-name=ether1 ] master-port=sfp1
set [ find default-name=ether2 ] master-port=sfp1
set [ find default-name=ether3 ] master-port=sfp1
/interface vlan
add interface=sfp1 l2mtu=1584 name=vlan199 vlan-id=199
/interface ethernet switch
set bridge-type=customer-vlan-bridge
/interface ethernet switch egress-vlan-translation
add customer-vid=199 new-customer-vid=0 port=ether1
add customer-vid=199 new-customer-vid=0 port=ether2
add customer-vid=199 new-customer-vid=0 port=ether3
/interface ethernet switch ingress-vlan-translation
add customer-vid=0 new-customer-vid=199 port=ether1 sa-learning=yes
add customer-vid=0 new-customer-vid=199 port=ether2 sa-learning=yes
add customer-vid=0 new-customer-vid=199 port=ether3 sa-learning=yes
Issue:
CRS125-24G-1S-RM: Configuration elements missing from the Web interface: Switch and LCD
I dont have a CRS to test with, could anyone please confirm these?Issue:
CRS125-24G-1S-RM: Switch setting bridge-type=customer-vlan-bridge is not retained after reboot.
Fixed in v6.116) Export of BGP VRF configuration does not include the "instance" entries
- viewtopic.php?f=2&t=78816&start=50#p409634
Marked invalid, since we can't repeat this in any type of setup. Could be a problem with something else in this system/network7) During upgrade of RouterOS IPSEC peers become disabled
- viewtopic.php?f=2&t=78816&start=50#p410240
I have tried to replicate this issue for 2 hours without success as well.Marked invalid, since we can't repeat this in any type of setup. Could be a problem with something else in this system/network7) During upgrade of RouterOS IPSEC peers become disabled
- viewtopic.php?f=2&t=78816&start=50#p410240
fixed in 6.114) DHCP over BCP does not work
- viewtopic.php?f=2&t=78816&p=407146#p407146
If you assume that there are bugs only by reading the forum release topic, I can disappoint you, 90% of those reports are caused by user error, or appear only in very specific situations that most likely will never affect you. Do you actually have any problems yourself, and if yes, tell us the Support ticket number, so I can check if we have fixed it for v6.11tomaskir
I am not an engineer - i am a project manager feeding of your trail - just spend another 10k on MT products which seems not to work due to already published sw bugs with crs and ccr systems - NO doubt about hardware engineering - first class - software too unpredictable to manage, maybe a bug, maybe engineer issue -
spend another 2k of engineer work to get basic vlan configuration running on CRS - well 4 days into production - user complain re speed issues etc = see posts. ros 6.10
I hope you see my current frustrations re Mikrotik products getting released without proper product certification - CRS as my main concern. CCR does not bond with Cisco as many times posted before.
I understand your concerns as a project manager. What I would advise is telling your engineers to actually contact official Mikrotik support.tomaskir
I am not an engineer - i am a project manager feeding of your trail - just spend another 10k on MT products which seems not to work due to already published sw bugs with crs and ccr systems - NO doubt about hardware engineering - first class - software too unpredictable to manage, maybe a bug, maybe engineer issue -
spend another 2k of engineer work to get basic vlan configuration running on CRS - well 4 days into production - user complain re speed issues etc = see posts. ros 6.10
I hope you see my current frustrations re Mikrotik products getting released without proper product certification - CRS as my main concern. CCR does not bond with Cisco as many times posted before.
Yay! I should have read the forums first...I just submitted a ticket (#2014031566000139) about this very issue yesterday!fixed in 6.114) DHCP over BCP does not work
- viewtopic.php?f=2&t=78816&p=407146#p407146
That is fixed in 6.11 as well:Please don't ignore the ticket, though, even though this issue is fixed...I reported a second issue in the same ticket, where you can hard-crash an x86 RouterOS box running PPTP or L2TP server if the incoming request negotiates both MPPE encryption and MLPPP MRRU, if you are using the SMP/multicore kernel.
-- Nathan
How come I can not find ROS 6.11 on the official download page?That is fixed in 6.11 as well:Please don't ignore the ticket, though, even though this issue is fixed...I reported a second issue in the same ticket, where you can hard-crash an x86 RouterOS box running PPTP or L2TP server if the incoming request negotiates both MPPE encryption and MLPPP MRRU, if you are using the SMP/multicore kernel.
-- Nathan
From 6.11 RC devel log:
What's new in 6.11 (2014-Mar-14 10:13):
*) ppp - mppe encryption together with mrru locked the router;
The excerpt was from the 6.11 release candidate development page.How come I can not find ROS 6.11 on the official download page?
Sorry tomaskir had work overload the last few weeks.nz_monkey is not responding either, nz_monkey, if you are reading this, please contact me
I can confirm that the bug is solved. Just tested it!fixed in 6.114) DHCP over BCP does not work
- viewtopic.php?f=2&t=78816&p=407146#p407146
/queue type print where name=default-small # Notice the default pfifo-limit=10 /queue type set [/queue type find name=default-small] pfifo-limit=50 # Now we change that to 50 /queue type export compact # Our changes are not in export compact /queue type print where name=default-small # Notice the pfifo-limit=50Notes:
/tool mac-server
remove 0
failure: can not remove the default entry
add interface=ether2
failure: interface unsupported
for me (v6.11, x86) it's exported, but in strange manner: "set 16 pfifo-limit=20". I don't think that default-small has index 16 on every systemDescription:
When doing a "export compact" changes to queue type default-small are not exported
have you tried v6.10 on CCR? adding works for me both in 6.10 CCR and 6.11 x86Unable to change or add any telnet interfaces into mac-server
Model: CCR1036-12G-4S
ROS Version 6.11
I have 6.10 on another device that is not a CCR and am able to use these commands with no issue.Code: Select all/tool mac-server remove 0 failure: can not remove the default entry add interface=ether2 failure: interface unsupported
for me (v6.11, x86) it's exported, but in strange manner: "set 16 pfifo-limit=20". I don't think that default-small has index 16 on every systemDescription:
When doing a "export compact" changes to queue type default-small are not exported
have you tried v6.10 on CCR? adding works for me both in 6.10 CCR and 6.11 x86Unable to change or add any telnet interfaces into mac-server
Model: CCR1036-12G-4S
ROS Version 6.11
I have 6.10 on another device that is not a CCR and am able to use these commands with no issue.Code: Select all/tool mac-server remove 0 failure: can not remove the default entry add interface=ether2 failure: interface unsupported
also, removing should not work on any device, just because it's default entry. you should be able only disable it, not remove
/tool mac-server> print
Flags: X - disabled, * - default
# INTERFACE
0 * ether2
1 ether3
2 ether4
3 ether5
as you can see, you DO have default entry (marked by "*")Here is the print off the 750gl with 6.10 showing the all default entry removed via command line.
Code: Select all/tool mac-server> print Flags: X - disabled, * - default # INTERFACE 0 * ether2 1 ether3 2 ether4 3 ether5
Can you test on a RouterBoard?for me (v6.11, x86) it's exported, but in strange manner: "set 16 pfifo-limit=20". I don't think that default-small has index 16 on every systemDescription:
When doing a "export compact" changes to queue type default-small are not exported
As said before, you can set the default to a different value then "all", or you can disable it, but it can not be removed.Here is the print off the 750gl with 6.10 showing the all default entry removed via command line.
Code: Select all/tool mac-server> print Flags: X - disabled, * - default # INTERFACE 0 * ether2 1 ether3 2 ether4 3 ether5
Here's the result from my RB951-2n (mipsbe):Can you test on a RouterBoard?
I tested on powerpc and mipsbe, on those its not exported.
[admin@MikroTik] /queue type> ex
# jan/05/1970 00:18:03 by RouterOS 6.11
#
[admin@MikroTik] /queue type> set default-small pfifo-limit=20
[admin@MikroTik] /queue type> ex
# jan/05/1970 00:18:07 by RouterOS 6.11
#
/queue type
set 9 pfifo-limit=20
[admin@MikroTik] /queue type>
Here is how it looks for me on a 750GL:Here's the result from my RB951-2n (mipsbe):
so seems like the only thing to be fixed is using type names instead of indices, which are different from system to systemCode: Select all[admin@MikroTik] /queue type> ex # jan/05/1970 00:18:03 by RouterOS 6.11 # [admin@MikroTik] /queue type> set default-small pfifo-limit=20 [admin@MikroTik] /queue type> ex # jan/05/1970 00:18:07 by RouterOS 6.11 # /queue type set 9 pfifo-limit=20 [admin@MikroTik] /queue type>
[admin@C1] > /queue type print where name=default-small
Flags: * - default
0 * name="default-small" kind=pfifo pfifo-limit=10
[admin@C1] > # Notice the default pfifo-limit=10
[admin@C1] > /queue type set [/queue type find name=default-small] pfifo-limit=50
[admin@C1] > # Now we change that to 50
[admin@C1] > /queue type export compact
# jan/03/1970 21:33:02 by RouterOS 6.11
# software id = 3VYV-V1LD
#
[admin@C1] > # Our changes are not in export compact
[admin@C1] > /queue type print where name=default-small
Flags: * - default
0 * name="default-small" kind=pfifo pfifo-limit=50
[admin@C1] > # Notice the pfifo-limit=50
what does "export verbose" show?..
[admin@C1] /queue type> exp ver
# jan/02/1970 00:08:00 by RouterOS 6.11
# software id = 3VYV-V1LD
#
/queue type
set 0 kind=pfifo name=default pfifo-limit=50
set 1 kind=pfifo name=ethernet-default pfifo-limit=50
set 2 kind=sfq name=wireless-default sfq-allot=1514 sfq-perturb=5
set 3 kind=red name=synchronous-default red-avg-packet=1000 red-burst=20 red-limit=60 red-max-threshold=50 red-min-threshold=10
set 4 kind=sfq name=hotspot-default sfq-allot=1514 sfq-perturb=5
set 5 kind=pcq name=pcq-upload-default pcq-burst-rate=0 pcq-burst-threshold=0 pcq-burst-time=10s pcq-classifier=src-address pcq-dst-address-mask=32 pcq-dst-address6-mask=128 pcq-limit=50 pcq-rate=0 pcq-src-address-mask=32 pcq-src-address6-mask=128 pcq-total-limit=2000
set 6 kind=pcq name=pcq-download-default pcq-burst-rate=0 pcq-burst-threshold=0 pcq-burst-time=10s pcq-classifier=dst-address pcq-dst-address-mask=32 pcq-dst-address6-mask=128 pcq-limit=50 pcq-rate=0 pcq-src-address-mask=32 pcq-src-address6-mask=128 pcq-total-limit=2000
set 7 kind=none name=only-hardware-queue
set 8 kind=mq-pfifo mq-pfifo-limit=50 name=multi-queue-ethernet-default
set 9 kind=pfifo name=default-small pfifo-limit=50
[admin@C1] /queue type> exp com
# jan/02/1970 00:08:38 by RouterOS 6.11
# software id = 3VYV-V1LD
#
[admin@C1] /queue type>
Actually, on that particular 750GL w/ ros 6.10 I can remove the interface completely and not just change it. When adding a new interface back into the mac-server the first one added becomes to default. I can not remove it via winbox however I can remove it via cli.As said before, you can set the default to a different value then "all", or you can disable it, but it can not be removed.
Regarding 6.11 and adding a mac-server interface, I dont have a CCR to test on, can someone test please?
Issue:
Super slow index page for the administration interface once you log on
Description:
Once you log on the administration interface, the loading time of the page is like almost 30 seconds
Chances are this is a browser cache issue. Have you tried cleaning your browser cache?Was perfect before I moved to the new 6.11.
I have many devices on 6.11, webfix is fine everywhere.Issue:
Super slow index page for the administration interface once you log on
Description:
Once you log on the administration interface, the loading time of the page is like almost 30 secondsChances are this is a browser cache issue. Have you tried cleaning your browser cache?Was perfect before I moved to the new 6.11.
what is the output of these two commands?RB951Ui from MUM - RouterOS 6.5, connected to internet and then...
/system package update upgrade
router rebooted, all is ok but PoE firmware = 0.0
Checked in the day of MUM on two routers, same effect...
/interface ethernet poe settings print
/interface ethernet poe settings upgrade
v6.11 on router in this time shows:what is the output of these two commands?RB951Ui from MUM - RouterOS 6.5, connected to internet and then...
/system package update upgrade
router rebooted, all is ok but PoE firmware = 0.0
Checked in the day of MUM on two routers, same effect...
/interface ethernet poe settings print
/interface ethernet poe settings upgrade
It looks that this bug is still there? I tested this now with 6.11 and 6.12rc1 (Apr/04/2014 13:30:46).new ppp package invalidates this5) L2TP Server bug - replies from wrong IP address
- http://forum.mikrotik.com/viewtopic.php ... 19#p398319
The bug is still there, its on the first post's list, which is up to date with 6.11It looks that this bug is still there? I tested this now with 6.11 and 6.12rc1 (Apr/04/2014 13:30:46).
By the way, is there any progress with a similar problem where multihop BFD (with BGP) uses too bad source IP of the outgoing interface and not loopback address ( [Ticket#2013110666000642] )?
/interface ethernet switch ingress-vlan-translation
add ports=ether2 customer-vid=0 new-customer-vid=8 sa-learning=yes
/interface ethernet switch egress-vlan-translation
add customer-vid=8 new-customer-vid=0 ports=ether2
/system reset-configuration
/system/reset-configuration
=no-defaults=yes
Yes I have two of my CRS125-24G-1S-RM have missing switch and LCD menu from the Web interface.Issue:
CRS125-24G-1S-RM: Configuration elements missing from the Web interface: Switch and LCDI dont have a CRS to test with, could anyone please confirm these?Issue:
CRS125-24G-1S-RM: Switch setting bridge-type=customer-vlan-bridge is not retained after reboot.
+1, I can confirm this happens to my CRS @ 6.12 as well in exactly the same situation. Only solution is to reset the config using the reset switch, as the router never proceeds past 'Starting services'. I'm down to 6.11 now.On my CRS running 6.12, if I enter this code:The ether2 port will correctly work as it did in 6.11 and before, until I restart the router. Then it freezes at boot up at the "Starting services" readout.Code: Select all/interface ethernet switch ingress-vlan-translation add ports=ether2 customer-vid=0 new-customer-vid=8 sa-learning=yes /interface ethernet switch egress-vlan-translation add customer-vid=8 new-customer-vid=0 ports=ether2
I've tried removing the egress-vlan-translation as well, and just having the first 2 lines. It still freezes at startup.
As I said, this works correctly in 6.11 and before, and I isolated the freezing to just this area of my working config.
Please be more specific. Ideally, follow the template in post2.also there is a bug with encrypted VPN connections since OS version 6.8 and not fixed until this moment.
When I do /system resource print there's a massive loss of hdd disk space:http://domain.name/API/report?software_id=ABCD-1234&report=registered%20connections&content=%5b%20%20{%20%20%22.id%22:%20%22*17%22, [... and so on ...]
[admin@MikroTik] /> /sys resource pr
uptime: 8w6d15h19m2s
version: 6.10
build-time: Feb/12/2014 13:46:18
free-memory: 6.7MiB
total-memory: 32.0MiB
cpu: MIPS 74Kc V4.12
cpu-count: 1
cpu-frequency: 600MHz
cpu-load: 5%
free-hdd-space: 552.0KiB
total-hdd-space: 128.0MiB
write-sect-since-reboot: 1170438
write-sect-total: 1187250
bad-blocks: 0%
architecture-name: mipsbe
board-name: RB911G-5HPnD
platform: MikroTik
[admin@MikroTik] /system scheduler> /file pr
# NAME TYPE SIZE CREATION-TIME
0 post-6.10.rsc script 2695 mar/02/2014 18:34:14
1 ABCD-1234.key .key file 204 jan/01/2002 01:19:04
2 um-before-migration.tar .tar file 17.5KiB jan/02/1970 00:00:35
3 5MB.zip .zip file 5.0MiB mar/06/2014 08:56:33
4 pub directory mar/02/2014 18:31:28
5 post-mesh.rsc script 2267 mar/05/2014 14:06:04
6 20MB.zip .zip file 20.0MiB mar/18/2014 18:23:18
7 pre-6.10.rsc script 2694 mar/02/2014 18:31:31
8 skins directory jan/01/1970 00:00:40
9 script-functions.rsc script 1574 apr/28/2014 09:58:53
no such item (4)
[admin@MikroTik2] /system resource> /tool fetch mode=http host="www.mikrotik.com" address=159.148.147.196 port=80 src-path="\?query&%*{:981293819381938192381983198312319283918239183987321498172498712349871234981274981273498213479218437921843721983472193847219348712349872134912873491283471293487219348712349872134981274391283472193487129348712349871234981273491283471293487123948712349871234981273491283472193487213948712391874192387421934871239487123987"
status: finished
[admin@MikroTik2] /system resource> /file pr
# NAME TYPE SIZE CREATION-TIME
0 Working-latest.rsc script 6.7KiB jan/02/2014 13:31:21
1 log.0.txt .txt file 50.2KiB may/06/2014 10:52:26
2 pre-6.10.rsc script 7.7KiB jan/01/2002 03:04:16
3 skins directory jan/01/1970 01:00:17
4 webproxy directory sep/19/2013 13:56:24
5 webproxy/error.html .html file 163.7KiB dec/29/2013 21:24:00
6 pub directory jan/01/2002 02:08:25
7 log.1.txt .txt file 68.3KiB apr/12/2014 10:53:24
8 with-uSD file 293.7KiB jan/01/2002 02:00:10
9 micro-sd disk apr/15/2014 09:21:54
10 WORKING.rsc script 5.6KiB jan/01/2002 03:55:00
11 micro-sd/lost+found directory jan/02/1970 01:03:02
12 micro-sd/web-proxy1 web-proxy store mar/12/2014 15:23:42
13 micro-sd/web-proxy2 web-proxy store jan/01/2002 02:01:17
[admin@MikroTik2] /system resource>
[admin@server ~]$ ftp mikrotik2
Connected to mikrotik2.
220 MikroTik2 FTP server (MikroTik 6.10) ready
Name (mikrotik2:admin):
331 Password required for admin
Password:
230 User admin logged in
Remote system type is UNIX.
ftp> dir
229 Entering Extended Passive Mode (|||42036|)
150 Opening data connection
drwxrwx--- 1 root root 2048 Jan 1 01:00 ?query&%*{:9812938193819381923819831983123192839182391839873214981724987123498712349812749812734982134792184379218437219834721938472193487123498721349128734912834712934872193487123498721349812743912834721934871293487123498712349812734912834712934871239487
drwxrwx--- 5 root root 4096 Jan 1 02:00 micro-sd
-rw-rw---- 1 root root 51541 May 6 10:56 log.0.txt
-rw-rw---- 1 root root 69899 Apr 12 10:53 log.1.txt
drwxrwx--- 1 root root 2048 Jan 1 02:08 pub
drwxrwx--- 1 root root 2048 Sep 19 13:56 webproxy
-rw-rw---- 1 root root 300776 Jan 1 02:00 with-uSD
drwxrwx--- 1 root root 2048 Jan 1 01:00 skins
-rw-rw---- 1 root root 6853 Jan 2 13:31 Working-latest.rsc
-rw-rw---- 1 root root 5688 Jan 1 03:55 WORKING.rsc
-rw-rw---- 1 root root 7838 Jan 1 03:04 pre-6.10.rsc
226 Transfer complete
ftp> mdelete *query*
mdelete ?query&%*{:9812938193819381923819831983123192839182391839873214981724987123498712349812749812734982134792184379218437219834721938472193487123498721349128734912834712934872193487123498721349812743912834721934871293487123498712349812734912834712934871239487 [anpqy?]? y
550 ?query&%*{:9812938193819381923819831983123192839182391839873214981724987123498712349812749812734982134792184379218437219834721938472193487123498721349128734912834712934872193487123498721349812743912834721934871293487123498712349812734912834712934871239487: No such file or directory
ftp> cd "?query&%*{:9812938193819381923819831983123192839182391839873214981724987123498712349812749812734982134792184379218437219834721938472193487123498721349128734912834712934872193487123498721349812743912834721934871293487123498712349812734912834712934871239487"
550 ?query&%*{:9812938193819381923819831983123192839182391839873214981724987123498712349812749812734982134792184379218437219834721938472193487123498721349128734912834712934872193487123498721349812743912834721934871293487123498712349812734912834712934871239487: No such file or directory
ftp>
Thanks for the report, added!Issue:
Queue graphs always available for viewing
Very nice report, thank you!Issue:
Can't list or delete files with overly long filenames
This sounds like the same problem described here: http://forum.mikrotik.com/viewtopic.php?f=13&t=84744Issue:
SMB shares disappear at random times
fixed in v6.133) L2TP Server bug - replies from wrong IP address
- viewtopic.php?f=2&t=78816&p=398319#p398319
compact only exports changed values. default-small is the default value, so it will not be exported. not a bug6) Queue type default-small not exported with export compact
- viewtopic.php?f=2&t=78816&p=417649#p417649
The default value is changed, and the change to the default value is not exported.compact only exports changed values. default-small is the default value, so it will not be exported. not a bug6) Queue type default-small not exported with export compact
- viewtopic.php?f=2&t=78816&p=417649#p417649
[tomas@router] /queue type> exp
# may/13/2014 10:09:06 by RouterOS 6.12
# software id = FR5N-MA9W
#
[tomas@router] /queue type> set [find name=default-small] pfifo-limit=50
[tomas@router] /queue type> exp
# may/13/2014 10:09:13 by RouterOS 6.12
# software id = FR5N-MA9W
#
[tomas@router] /queue type> set [find name=pcq-download-default] pcq-rate=1024
[tomas@router] /queue type> exp
# may/13/2014 10:09:59 by RouterOS 6.12
# software id = FR5N-MA9W
#
/queue type
set 6 pcq-rate=1024
[tomas@router] /queue type>
I can confirm that. It causes connection drops. For example you are able to connect with WinBox over VPN, but after a few seconds it disconnects. Also opening Webfig or loading the graphing-images fairs after loading some data.also there is a bug with encrypted VPN connections since OS version 6.8 and not fixed until this moment.
It's really work fine now for mipsbe architecture (checked on RB951G-2HnD, ROS v6.13 and v6.15), but at the same time bug still appear for tile architecture (checked on CCR1036-8G-2S+, ROS v6.13 and v6.15).fixed in v6.133) L2TP Server bug - replies from wrong IP address
- viewtopic.php?f=2&t=78816&p=398319#p398319
Normis: Just an update, this is still NOT fixed for me in 6.16/6.17 on a RB 750GL.Now I get it. We checked in v6.13 and it worked for us, but it looks like v6.12 has this issue. Seems it's fixed.
This is more a Winbox issue, but confirmed, and added to the list.Issue:
Winbox doesn't unlock upload files after upload whole folder via Winbox > Files menu
I could not replicate this in 6.17.I could not restore configuration with no-password backup file. Tried several files, not only 1.
If I put password when backup the file, I can restore the config.
v6.15
RB951Ui-2HnD
Sorry, I could not let the router reboot for this moment (if successful), I will update later.I could not replicate this in 6.17.
Since this seems to be working in 6.17, can you please verify and let us know if you still have this issue.
Hi guys, i'm having trouble collecting data from simple queues on 6.17, i'm using cacti as nms.
Apparently the OID's of simple queues have changed, i'm trying to reproduce manually the situation making a snmpwalk on a device from OID ".1.3.6.1.4.1.14988.1.1.2" and the first OID taht came is ".1.3.6.1.4.1.14988.1.1.3.9.0". Is anyone having issues with collecting data trough snmp on 6.17?
Thanks and sorry for the bad english.
How about this bug.Issue:
Queue graphs always available for viewing
Description:
Regardless of the settings in /tool graphing queue, a queue graph is always available
Eg.
Internal devices use default subnet 192.168.88.0/24
In /tools graphing all three options (interfaces, resources and queue) are set to be allowed from 10.10.10.0/24.
Then neither resource and interface graphs are available, as I suspect because of the allowed subnet.
But the queue graph is available for viewing.
Versions affected:
RouterOS 6.5 and 6.12
Did not test versions in between
How to reproduce:
Create a /tool graphing queue for a non-used subnet/IP address and see http://ip-address/graphs
See example in description.
Support TicketID:
Ticket#2014050666000189
I tested it on 6.17 and could not replicate... so I removed it from the list.How about this bug.
Have not read anything about it, also not heard anything from Mikrotik itself.
I have just tested it and the but is still present on version 6.17!!!
It is quite easy.I tested it on 6.17 and could not replicate... so I removed it from the list.How about this bug.
Have not read anything about it, also not heard anything from Mikrotik itself.
I have just tested it and the but is still present on version 6.17!!!
Can you give exact step-by-step to replicate pls?
/queue simple add name=queue1 target=""and allow any unused IP address to view the graphs of the queue
/tool graphing queue add allow-address=1.1.1.1/32If you now browse to the IP address of the router and look at the graphs, the queue graph is still available for viewing!
/tool graphing queue add allow-address=1.1.1.1/32 allow-target=no
Sounds like that can make a difference, but in the end it doesn'tby default, 'allow-target' is enabled, so if your rule catches anything ('target=""'), then anyone should be able to see that queue on graphs page, I think
so recheck withros code
/tool graphing queue add allow-address=1.1.1.1/32 allow-target=no
Very nice job pinning it down!I checked that, and there are actually two bugs:
1. in Terminal, you can create simple queue with target="" - after that WinBox shows "Target" in red; if you create such entry in WinBox, it says "Error in Target - at least one entry expected!"
2. if 'target' contains at least one entry that is not an IP address (like interface or empty target created via bug #1), Graphing always shows that queue via web, in spite of 'allow-*' settings
And here it is my logs:I have this bug:
http://forum.mikrotik.com/viewtopic.php?f=2&t=87082
Description:
I have IPv6 enable over PPPoE.
When ether1 stop then PPPoE drop and can't connect for some minutes.
It take many, many, many conection/disconnection every second for about 4-5 minutes and sometimes 10minutes.
I must wait this time or stop and start PPPoE.
The problem appears if yet i have only enable IPv6 support in my PPPoE without any other IPv6 configuration like DHCPv6 client etc.
Every time my ISP make changes in Brass, the PPPoE client connection drop and ether1 drop normally, and i have this problem.
I tested in 6.15, 6.16 and 6.17 with same result.
I tested in many RB.
I did send a bug report to support couple of months ago, number is mentioned in the post I wrote earlier.Very nice job pinning it down!I checked that, and there are actually two bugs:
1. in Terminal, you can create simple queue with target="" - after that WinBox shows "Target" in red; if you create such entry in WinBox, it says "Error in Target - at least one entry expected!"
2. if 'target' contains at least one entry that is not an IP address (like interface or empty target created via bug #1), Graphing always shows that queue via web, in spite of 'allow-*' settings
Want to put it into a proper bug-report format and submit to MikroTik and this thread, or should I?
yep, it would be nice =) I'm a bit overloaded with current work...or should I?
# jul/25/2014 15:32:08 by RouterOS 6.17
# software id = 4RFY-E9RX
#
/interface bridge
add admin-mac=02:BB:BB:BB:BB:BB auto-mac=no name=bridge-tunnel
/ppp profile
add bridge=bridge-tunnel name=profile-tunnel
/interface pptp-client
add add-default-route=no allow=pap,chap,mschap1,mschap2 connect-to=\
192.168.1.133 dial-on-demand=no disabled=no keepalive-timeout=60 max-mru=\
1450 max-mtu=1450 mrru=1600 name=pptp-tunnel password=tunneltest profile=\
profile-tunnel user=tt
/ip address
add address=192.168.40.5/24 interface=bridge-tunnel network=192.168.40.0
/ip dhcp-client
add default-route-distance=0 dhcp-options=hostname,clientid disabled=no \
interface=ether1
add default-route-distance=0 dhcp-options=hostname,clientid disabled=no \
interface=bridge-tunnel use-peer-dns=no use-peer-ntp=no
# jan/02/1970 00:21:04 by RouterOS 6.17
# software id = 8J2K-5ZUR
#
/interface bridge
add admin-mac=02:AA:AA:AA:AA:AA auto-mac=no name=bridge-tunnel priority=0x4000
/ip pool
add name=pool1 ranges=192.168.40.100-192.168.40.200
/ip dhcp-server
add address-pool=pool1 authoritative=yes disabled=no interface=bridge-tunnel \
name=server1
/ppp profile
add bridge=bridge-tunnel name=profile-tunnel
/interface pptp-server server
set default-profile=profile-tunnel enabled=yes mrru=1600
/ip address
add address=192.168.40.1/24 interface=bridge-tunnel network=192.168.40.0
/ip dhcp-client
add dhcp-options=hostname,clientid disabled=no interface=ether1
/ip dhcp-server network
add address=192.168.40.0/24 gateway=192.168.40.1
/ppp secret
add local-address=192.168.80.1 name=tt password=tunneltest profile=\
profile-tunnel remote-address=192.168.80.2
pedro@pedro-Aspire-E1-572:~/agenda_reboot$ snmpwalk -v2c -cxxxx x.x.x.x
iso.3.6.1.2.1.1.1.0 = STRING: "RouterOS RB750"
iso.3.6.1.2.1.1.2.0 = OID: iso.3.6.1.4.1.14988.1
iso.3.6.1.2.1.1.3.0 = Timeticks: (16616100) 1 day, 22:09:21.00
iso.3.6.1.2.1.1.4.0 = STRING: "NOC"
iso.3.6.1.2.1.1.5.0 = STRING: "Frank Peluffo"
iso.3.6.1.2.1.1.6.0 = STRING: "RIOGRANDE"
iso.3.6.1.2.1.1.7.0 = INTEGER: 78
iso.3.6.1.2.1.2.1.0 = INTEGER: 0
iso.3.6.1.2.1.4.1.0 = INTEGER: 1
iso.3.6.1.2.1.4.2.0 = INTEGER: 255
iso.3.6.1.2.1.4.24.3.0 = Gauge32: 4
iso.3.6.1.2.1.17.2.1.0 = INTEGER: 3
iso.3.6.1.2.1.25.1.1.0 = Timeticks: (16616100) 1 day, 22:09:21.00
iso.3.6.1.2.1.25.1.2.0 = Hex-STRING: 07 DE 07 1E 0A 00 30 00 2D 03 00
iso.3.6.1.2.1.25.2.2.0 = INTEGER: 32768
iso.3.6.1.2.1.25.2.3.1.1.65536 = INTEGER: 65536
iso.3.6.1.2.1.25.2.3.1.1.131073 = INTEGER: 131073
iso.3.6.1.2.1.25.2.3.1.2.65536 = OID: iso.3.6.1.2.1.25.2.1.1
iso.3.6.1.2.1.25.2.3.1.2.131073 = OID: iso.3.6.1.2.1.25.2.1.4
iso.3.6.1.2.1.25.2.3.1.3.65536 = STRING: "main memory"
iso.3.6.1.2.1.25.2.3.1.3.131073 = STRING: "disk: system"
iso.3.6.1.2.1.25.2.3.1.4.65536 = INTEGER: 1024
iso.3.6.1.2.1.25.2.3.1.4.131073 = INTEGER: 1024
iso.3.6.1.2.1.25.2.3.1.5.65536 = INTEGER: 32768
iso.3.6.1.2.1.25.2.3.1.5.131073 = INTEGER: 61440
iso.3.6.1.2.1.25.2.3.1.6.65536 = INTEGER: 22176
iso.3.6.1.2.1.25.2.3.1.6.131073 = INTEGER: 10764
iso.3.6.1.2.1.25.2.3.1.7.65536 = Counter32: 0
iso.3.6.1.2.1.25.2.3.1.7.131073 = Counter32: 0
iso.3.6.1.2.1.25.3.2.1.1.1 = INTEGER: 1
iso.3.6.1.2.1.25.3.2.1.2.1 = OID: iso.3.6.1.2.1.25.3.1.3
iso.3.6.1.2.1.25.3.3.1.1.1 = OID: ccitt.0
iso.3.6.1.2.1.25.3.3.1.2.1 = INTEGER: 100
iso.3.6.1.2.1.47.1.1.1.1.1.65536 = INTEGER: 65536
iso.3.6.1.2.1.47.1.1.1.1.1.262145 = INTEGER: 262145
iso.3.6.1.2.1.47.1.1.1.1.2.65536 = STRING: "RouterOS 6.17 on RB750"
iso.3.6.1.2.1.47.1.1.1.1.2.262145 = STRING: "Linux 3.3.5 ehci_hcd RB400 EHCI"
iso.3.6.1.2.1.47.1.1.1.1.3.65536 = OID: ccitt.0
iso.3.6.1.2.1.47.1.1.1.1.3.262145 = OID: ccitt.0
iso.3.6.1.2.1.47.1.1.1.1.4.65536 = INTEGER: 0
iso.3.6.1.2.1.47.1.1.1.1.4.262145 = INTEGER: 65536
iso.3.6.1.2.1.47.1.1.1.1.5.65536 = INTEGER: 3
iso.3.6.1.2.1.47.1.1.1.1.5.262145 = INTEGER: 2
iso.3.6.1.2.1.47.1.1.1.1.6.65536 = INTEGER: -1
iso.3.6.1.2.1.47.1.1.1.1.6.262145 = INTEGER: -1
iso.3.6.1.2.1.47.1.1.1.1.7.65536 = STRING: "MIPS 24Kc V7.4"
iso.3.6.1.2.1.47.1.1.1.1.7.262145 = STRING: "1:1"
iso.3.6.1.2.1.47.1.1.1.1.8.65536 = ""
iso.3.6.1.2.1.47.1.1.1.1.8.262145 = ""
iso.3.6.1.2.1.47.1.1.1.1.9.65536 = ""
iso.3.6.1.2.1.47.1.1.1.1.9.262145 = ""
iso.3.6.1.2.1.47.1.1.1.1.10.65536 = ""
iso.3.6.1.2.1.47.1.1.1.1.10.262145 = ""
iso.3.6.1.2.1.47.1.1.1.1.11.65536 = ""
iso.3.6.1.2.1.47.1.1.1.1.11.262145 = STRING: "rb400_usb"
iso.3.6.1.2.1.47.1.1.1.1.12.65536 = ""
iso.3.6.1.2.1.47.1.1.1.1.12.262145 = STRING: "0x1d6b"
iso.3.6.1.2.1.47.1.1.1.1.13.65536 = ""
iso.3.6.1.2.1.47.1.1.1.1.13.262145 = STRING: "0x0002"
iso.3.6.1.2.1.47.1.1.1.1.14.65536 = ""
iso.3.6.1.2.1.47.1.1.1.1.14.262145 = ""
iso.3.6.1.2.1.47.1.1.1.1.15.65536 = ""
iso.3.6.1.2.1.47.1.1.1.1.15.262145 = ""
iso.3.6.1.2.1.47.1.1.1.1.16.65536 = INTEGER: 2
iso.3.6.1.2.1.47.1.1.1.1.16.262145 = INTEGER: 2
iso.3.6.1.2.1.9999.1.1.1.1.0 = STRING: "MikroTik DHCP server"
iso.3.6.1.2.1.9999.1.1.1.2.0 = OID: iso.3.6.1.4.1.14988.1
iso.3.6.1.2.1.9999.1.1.6.4.1.4.192.168.1.100 = INTEGER: 2
iso.3.6.1.2.1.9999.1.1.6.4.1.4.192.168.1.101 = INTEGER: 2
iso.3.6.1.2.1.9999.1.1.6.4.1.4.192.168.1.102 = INTEGER: 2
iso.3.6.1.2.1.9999.1.1.6.4.1.4.192.168.1.103 = INTEGER: 2
iso.3.6.1.2.1.9999.1.1.6.4.1.4.192.168.1.105 = INTEGER: 2
iso.3.6.1.2.1.9999.1.1.6.4.1.4.192.168.1.106 = INTEGER: 2
iso.3.6.1.2.1.9999.1.1.6.4.1.4.192.168.1.108 = INTEGER: 2
iso.3.6.1.2.1.9999.1.1.6.4.1.5.192.168.1.100 = Gauge32: 186706
iso.3.6.1.2.1.9999.1.1.6.4.1.5.192.168.1.101 = Gauge32: 231869
iso.3.6.1.2.1.9999.1.1.6.4.1.5.192.168.1.102 = Gauge32: 258959
iso.3.6.1.2.1.9999.1.1.6.4.1.5.192.168.1.103 = Gauge32: 256089
iso.3.6.1.2.1.9999.1.1.6.4.1.5.192.168.1.105 = Gauge32: 254832
iso.3.6.1.2.1.9999.1.1.6.4.1.5.192.168.1.106 = Gauge32: 204265
iso.3.6.1.2.1.9999.1.1.6.4.1.5.192.168.1.108 = Gauge32: 254738
iso.3.6.1.2.1.9999.1.1.6.4.1.7.192.168.1.100 = INTEGER: 3
iso.3.6.1.2.1.9999.1.1.6.4.1.7.192.168.1.101 = INTEGER: 3
iso.3.6.1.2.1.9999.1.1.6.4.1.7.192.168.1.102 = INTEGER: 3
iso.3.6.1.2.1.9999.1.1.6.4.1.7.192.168.1.103 = INTEGER: 3
iso.3.6.1.2.1.9999.1.1.6.4.1.7.192.168.1.105 = INTEGER: 3
iso.3.6.1.2.1.9999.1.1.6.4.1.7.192.168.1.106 = INTEGER: 3
iso.3.6.1.2.1.9999.1.1.6.4.1.7.192.168.1.108 = INTEGER: 3
iso.3.6.1.2.1.9999.1.1.6.4.1.8.192.168.1.100 = Hex-STRING: 00 25 AB 01 B3 5F
iso.3.6.1.2.1.9999.1.1.6.4.1.8.192.168.1.101 = Hex-STRING: 9C 20 7B D9 6D A1
iso.3.6.1.2.1.9999.1.1.6.4.1.8.192.168.1.102 = Hex-STRING: 18 34 51 21 2D 92
iso.3.6.1.2.1.9999.1.1.6.4.1.8.192.168.1.103 = Hex-STRING: 48 5D 60 4B 86 7B
iso.3.6.1.2.1.9999.1.1.6.4.1.8.192.168.1.105 = Hex-STRING: E0 B9 A5 F3 38 BC
iso.3.6.1.2.1.9999.1.1.6.4.1.8.192.168.1.106 = Hex-STRING: 14 99 E2 7A 2F 12
iso.3.6.1.2.1.9999.1.1.6.4.1.8.192.168.1.108 = Hex-STRING: F0 C1 F1 97 D2 D9
Mikrotik responded to my ticket by saying it's a feature. A PPTP tunnel can be used either for routing traffic or for bridging, but not both.Issue:
DHCP over BCP via PPTP fails.
Description:
DHCP over BCP via PPTP fails.
This was reported as a bug previously in this thread, then reported as fixed. I am reporting that it is still broken.
Bridges on each of two routers are connected together via a PPTP tunnel. DHCP server on one bridge, DHCP client on the other bridge. The DHCP client will never get an IP address.
Per the Wiki entry, one should configure IP addresses for the PPTP tunnel endpoints, usually entered in
PPP->Secrets. However, if you do this, DHCP will fail.
If I delete the IP addresses for the PPTP tunnel endpoints, DHCP will work.
If BCP between bridges is all that is required, not including PPTP tunnel endpoint addresses is a work-around.
If you need to also route packets over the PPTP tunnel, then this work-around cannot be used.
It used to work both ways in 5.26. If the new configuration, post 6.x, requires one to delete the IP addresses on the tunnel endpoints, this should be carefully documented and the Wiki updated to reflect this fact.
I think it's just a bug, but maybe Mikrotik wants to call it an undocumented new feature.
If the Mikrotik response is that it's working correctly now (i.e. tunnel endpoint IP addresses MUST be omitted for BCP), then I will update the Wiki page. The Wiki page currently says local/remote addresses must be included, although the example given does not include them.
There is workaround for this problem. You can define the bond with manual mtu size 1508 bytes and then maybe this will works with PPPoE.Issue:
MTU error in a PPPoE session on a bonding interface
Description:
It is impossible to run full 1500 byte frames inside of a PPPoE session if the PPPoE session built on top of a bonding interface.
If you send a 1500 MTU frame over the PPPoE session, it is dropped, and this therefore creates MTU issues in this scenario.
/system identity set name=R1
/interface bridge
add admin-mac=02:00:00:00:00:01 auto-mac=no mtu=1500 name=bridge-loopback protocol-mode=none
/ip address
add address=192.168.1.1/24 interface=ether1 network=192.168.1.0
add address=192.168.0.1/32 interface=bridge-loopback network=192.168.0.1
/routing bfd interface
set [ find default=yes ] interval=2s min-rx=2s
add interface=ether1
/routing ospf instance
set [ find default=yes ] router-id=192.168.0.1
/routing ospf interface
add cost=1 interface=bridge-loopback network-type=point-to-point passive=yes
add interface=ether1 network-type=point-to-point use-bfd=yes
/routing ospf network
add area=backbone network=192.168.0.0/16
/routing bgp instance
set default client-to-client-reflection=no router-id=192.168.0.1
/routing bgp network
add network=192.168.2.0/24 synchronize=no
/routing bgp peer
add multihop=yes name=R1-R2 remote-address=192.168.0.2 remote-as=65530 ttl=\
default update-source=192.168.0.1 use-bfd=yes
/system identity set name=R2
/interface bridge
add admin-mac=02:00:00:00:00:01 auto-mac=no mtu=1500 name=bridge-loopback protocol-mode=none
/ip address
add address=192.168.1.2/24 interface=ether1 network=192.168.1.0
add address=192.168.0.2/32 interface=bridge-loopback network=192.168.0.2
/routing bfd interface
set [ find default=yes ] interval=2s min-rx=2s
add interface=ether1
/routing ospf instance
set [ find default=yes ] router-id=192.168.0.2
/routing ospf interface
add cost=1 interface=bridge-loopback network-type=point-to-point passive=yes
add interface=ether1 network-type=point-to-point use-bfd=yes
/routing ospf network
add area=backbone network=192.168.0.0/16
/routing bgp instance
set default client-to-client-reflection=no router-id=192.168.0.2
/routing bgp network
add network=192.168.3.0/24 synchronize=no
/routing bgp peer
add multihop=yes name=R1-R2 remote-address=192.168.0.1 remote-as=65530 ttl=\
default update-source=192.168.0.2 use-bfd=yes
/ip firewall nat
add action=src-nat chain=srcnat dst-address=192.168.0.2 dst-port=4784 \
protocol=udp to-addresses=192.168.0.1
/ip firewall nat
add action=src-nat chain=srcnat dst-address=192.168.0.1 dst-port=4784 \
protocol=udp to-addresses=192.168.0.2
[admin@R1] > /routing bfd neighbor print
Flags: U - up
# INTERFACE ADDRESS PROTOCOLS MULTIHOP STATE
[admin@R1] >
[admin@R2] > /routing bfd neighbor print
Flags: U - up
# INTERFACE ADDRESS PROTOCOLS MULTIHOP STATE
0 ether1 192.168.1.1 ospf no down
1 unspecified 192.168.0.1 bgp yes down
[admin@R2] >
[admin@R1] > /routing bfd neighbor print
Flags: U - up
# INTERFACE ADDRESS PROTOCOLS MULTIHOP STATE
0 U ether1 192.168.1.2 ospf no up
1 U unspecified 192.168.0.2 bgp yes up
[admin@R1] >
[admin@R2] > /routing bfd neighbor print
Flags: U - up
# INTERFACE ADDRESS PROTOCOLS MULTIHOP STATE
0 U ether1 192.168.1.1 ospf no up
1 U unspecified 192.168.0.1 bgp yes up
[admin@R2] >
[admin@xxxx] > system resource print uptime: 5d20h41m50s version: 6.20 build-time: Oct/01/2014 10:06:12 free-memory: 70.0MiB total-memory: 122.9MiB cpu: Intel(R) cpu-count: 1 cpu-frequency: 2128MHz cpu-load: 1% free-hdd-space: 9.7GiB total-hdd-space: 9.8GiB write-sect-since-reboot: 23676 write-sect-total: 23676 architecture-name: x86 board-name: x86 platform: MikroTik [admin@xxxx] > ip dhcp-server option add name=OPTION1 value=192.168.1.1 code=161 failure: Unknown data type! [admin@xxxx] > ip dhcp-server option add name=OPTION1 value=username code=184 failure: Unknown data type!Notes:
[admin@xxxx] > /system resource print uptime: 35w6d10h16m48s version: 5.26 free-memory: 6872KiB total-memory: 28284KiB cpu: Intel(R) cpu-count: 1 cpu-frequency: 3059MHz cpu-load: 1% free-hdd-space: 10122156KiB total-hdd-space: 10310772KiB write-sect-since-reboot: 2562062 write-sect-total: 2562062 architecture-name: x86 board-name: x86 platform: MikroTik [admin@xxx] > ip dhcp-server option add name=OPTION1 value=192.168.1.1 code=161 [admin@xxx] > ip dhcp-server option add name=OPTION2 value=username code=184
The issue is mostly your configuration -- as of v6, the DHCP server is more picky about types matching what the DHCP Option is "supposed" to have.Issue:
Can't add any DHCP options with v6.x
ip dhcp-server option add name=OPTION1 value="'192.168.1.1'" code=161
/system ntp client set enabled=yes server-dns-names=si.pool.ntp.org
seems like it's because 'start-tls' has three values: "no", "tls-only", "yes" - and Winbox supports only checkbox currentlyEvery time I set e-mail configuration via WinBox in Tools / Email Settings and tick “Start TLS” checkbox, then exit from WinBox and open it again checkbox next to “Start TLS” is not ticked.
Are you talking about new RouterOS 6.25 RC or new WinBox 3 RC?tls winbox issue already fixed in new RC
you are wrong. when you set gateway=interface, packet is sent from the interface directly to the connected network. if it's p2p tunnel, packet has only one way - the remote peer. but in case of broadcast interfaces (like Ethernet), router needs to know the MAC address of target (gateway MAC address).Is this a known issue, or amI wrong with some configuration?
What about this?Is there a way to install a Mikrotik to a brand new server which include ssd?
We bought a brand new ASUS RS100-X7/PI2 server, but impossible mission to install a Mikrotik to this server. This is our second server, which unusable with Mikrotik.
This server contains a 30 GB SSD, but the install hangs on hard drive search option.
We try lot of option: AHCI mode, IDE mode, RAID mode, Netinstall to server, Netinstall to a SSD drive through windows7 docking station, usb boot. Nothing can work.
Is the a way to use modern 3rd party hardware to use mikrotik, or we need to buy an unstable CCR?
We want a quick reply, because we spent a lot of money to modern hardwares, but RouterOS can't support new systems.
Thanks ill give it a shot.Probably you need to set up some basic firewall http://wiki.mikrotik.com/wiki/Securing_your_router
If you have no filters at all and you have configured the DNS server of Mikrotik to 'Allow remote requests' then it's probably being used by bots and stuff filling up your gateway bandwidth and/or causing high cpu usage.
Everytime you reboot your router I assume you get a new IP so it's ok for a while until the bots find the new IP (they scan all the time all the internet) and start all over again.
I am noticing the same thing on a RB750 for the last few months. Currently using v6.29.1, I tried downgrading to v6.27 and still had the same issue. The Mikrotik has all the proper firewall rules to protect it from the internet and torch even shows that there is almost no traffic going through it at the time.Hi.
I recently got myself a RB941-2nD (rOS 6.29.1) and i noticed the following.
I run a PPPoE interface dialing my aDsL connection from my ISP router.
After 2-3 days of uptime router starts perfomance degradation in internet.
While link is 15down/1up it turns into an unstable 2mbit max down and 0.2up(ISP is fine)
Plus this speed is stuttering like packets flow every second.
no filter rules nor anything. rb is acting as an internet gateway only.
On resources tab when the incident occurs its shows a min of 21% to 45% cpu usage while nothing is going on.
After a clean reboot everything comes back normal plus cpu usage drops to a reasonable value of 1%-5%.
Problem was confirmed after 3 times.
Hi mate.I am noticing the same thing on a RB750 for the last few months. Currently using v6.29.1, I tried downgrading to v6.27 and still had the same issue. The Mikrotik has all the proper firewall rules to protect it from the internet and torch even shows that there is almost no traffic going through it at the time.Hi.
I recently got myself a RB941-2nD (rOS 6.29.1) and i noticed the following.
I run a PPPoE interface dialing my aDsL connection from my ISP router.
After 2-3 days of uptime router starts perfomance degradation in internet.
While link is 15down/1up it turns into an unstable 2mbit max down and 0.2up(ISP is fine)
Plus this speed is stuttering like packets flow every second.
no filter rules nor anything. rb is acting as an internet gateway only.
On resources tab when the incident occurs its shows a min of 21% to 45% cpu usage while nothing is going on.
After a clean reboot everything comes back normal plus cpu usage drops to a reasonable value of 1%-5%.
Problem was confirmed after 3 times.
eth1 is to the internet (isp modem), eth2 goes out to my sector (RB912), eth3 is an IP camera watching the room with the RB750 (not currently streaming, requires you to manually connect).
What I notice when this happens, even though eth5 is disabled (to stop someone from plugging in, its in a remote building) it will show traffic (RX/TX) on eth5 that mirrors traffic on eth2. eth2-5 belong to the same bridge. I believe I have tried it before while using master/slave ports also (originally moved to a bridge to see if it cured this issue).
Nothing in the log when it happens, and rebooting causes it to go back to normal for a few days. Traffic on eth5 goes back down to 0. Rebooting the RB750 has no affect on my external IP since that is all handled by the modem. I will work on sanitizing my /export, then I can upload it.
EDIT: Just updated to v6.30.1, will see if anything in there fixes the issue.
Issue:
LTE interface - when anything is entered in modem-init, it cannot be set to empty/unset
Description:
tested on: RB912UAG-2HPnD + Huawei ME909s-120
Versions affected:
6.30 (tested on this)
How to reproduce:
on factory resetted system, with lte1 in interfaces:
- enter anything to modem-init (even space), apply and save it
- then, it is not possible to delete it, or to unset with the black triangle; after clicking
apply or ok, the previously entered value is back there; It is possible to change
modem-init value to any other value except empty
- this happens even if the lte interface is disabled
- and the same result via terminal ( interface lte set modem-init="" )
I copied your export verbatim. And I created my own configuration from scratch with a completely config-reset router JUST in case.Maybe you're missing something when creating the bridge..
Why use a bridge then? With what you have described so far you do not need a bridge.ETH-1 WAN
ETH8-LAN goes to a GS728TP Switch. I have 10 APS here, no VLANS.
Did you move the IP to ether8 after disabling the bridge?I have already disabled the guest bridge and point re-create my dhcp and pointed directly into ETH8 and still have issues.
It turns out that the issue with the bridge and DHCP affects the x64 mode of CHR (on which I tried the configuration above).At first glance there seems to be an issue with DHCP when running on a bridge.
When an interface is slave to a bridge it seems that it doesn't respond to DHCP client requests.
What's really weird is that I have numerous installations with bridges and DHCP server running on them without a problem whatsoever!
But trying your configuration (or even a new one from scratch) I cannot get an IP from DHCP when on bridge.
When I put the dhcp server on the interface directly and disable the bridge then it works right away!
It may be an issue with the latest versions of Mikrotik when creating new DHCP servers and/or bridges (but not if those were created on older versions?)
The working installations that I have have been set up many versions ago and I was just upgrading them.
I haven't set up a bridge/dhcp in the last stable version of mikrotik (6.30.2).
So, at first glance it seems that there's an issue with DHCP when running on a bridge.
Can anyone else confirm that?
It turns out that the issue with the bridge and DHCP affects the x64 mode of CHR (on which I tried the configuration above).At first glance there seems to be an issue with DHCP when running on a bridge.
When an interface is slave to a bridge it seems that it doesn't respond to DHCP client requests.
What's really weird is that I have numerous installations with bridges and DHCP server running on them without a problem whatsoever!
But trying your configuration (or even a new one from scratch) I cannot get an IP from DHCP when on bridge.
When I put the dhcp server on the interface directly and disable the bridge then it works right away!
It may be an issue with the latest versions of Mikrotik when creating new DHCP servers and/or bridges (but not if those were created on older versions?)
The working installations that I have have been set up many versions ago and I was just upgrading them.
I haven't set up a bridge/dhcp in the last stable version of mikrotik (6.30.2).
So, at first glance it seems that there's an issue with DHCP when running on a bridge.
Can anyone else confirm that?
Disabling x64 restores the dhcp-server functionality on a bridge.
http://forum.mikrotik.com/viewtopic.php ... 15#p494315
/ip service set www address=ХХХ.ХХХ.ХХХ.0/24 port=6665
and
/ip service set www address=ХХХ.ХХХ.ХХХ.0/24 port=6000
:execute name_script
:excute script="name_script"
:execute "script_name"
1) Updating from 6.27 to 6.33.1 (on CCR), script stop working.ì, so any backward compatibilty...Old syntax also works for backward compatibility
Code: Select all:execute "script_name"
My scritp work fine in 6,27 whitout quotesScript names, strings etc should always be used in quotes.
6.33.1 x86 platform provide only one option, Tile platform two options. why?Works on both platforms the same.
03:16:54 radius,debug new request 0d:01 code=Access-Request service=login
03:16:54 radius,debug sending 0d:01 to x.x.x.x:1812
03:16:54 radius,debug,packet sending Access-Request with id 5 to x.x.x.x:1812
03:16:54 radius,debug,packet Signature = 0x3fca657862be8355a291bf32522c7be6
03:16:54 radius,debug,packet Service-Type = 1
03:16:54 radius,debug,packet User-Name = "xxxx"
03:16:54 radius,debug,packet MS-CHAP-Challenge = 0xb9a374da514667be08e1b20d8cfa64ca
03:16:54 radius,debug,packet MS-CHAP2-Response = 0x000021402324255e262a28295f2b3a33
03:16:54 radius,debug,packet 7c7e000000000000000053f2a38fb731
03:16:54 radius,debug,packet 4b9054306d76e615c45c02f6b04bf03a
03:16:54 radius,debug,packet 44a6
03:16:54 radius,debug,packet Calling-Station-Id = "10.20.0.100"
03:16:54 radius,debug,packet NAS-Identifier = "AC0001"
03:16:54 radius,debug,packet NAS-IP-Address = 10.20.0.2
03:16:54 radius,debug,packet received Access-Accept with id 5 from x.x.x.x:1812
03:16:54 radius,debug,packet Signature = 0xcc112ac0c094bc2a0ad010f0a0559bdf
03:16:54 radius,debug,packet MS-CHAP2-Success = 0x00533d36343936424233454546343336
03:16:54 radius,debug,packet 35354638443631453330434544373544
03:16:54 radius,debug,packet 3541394231413943303433
03:16:54 radius,debug,packet MT-Group = "full"
03:16:54 radius,debug received reply for 0d:01
03:16:54 system,info,account user xxxx logged in from 10.20.0.100 via web
03:16:54 system,info,account user xxxx logged out from 10.20.0.100 via web
Hello, I'm not sure if this is the correct thread, so if not, can a mod please move it.
I recently upgraded to RouterOS 6.33.3 (Hardware - 2011UIAS-2HnD) from an older 6.xx version (I can't remember what version it was ) but have noticed that I now get very slow response when accessing via Winbox (version 3)
When I connect via Winbox and click on Terminal, it takes about 3 minutes for the Terminal Window to reach the command prompt. In addition, I notice that the Date and Time clock takes ages to reflect the correct time. Basically, any function (eg list files, DHCP lists, etc) that I launch takes an absolute age to launch.
I would appreciate it if anyone has experienced similar and which version you recommend I roll back to.
PS: I did an 'auto-upgrade' in order to preserve all my existing rules and configurations - would it help to reset and then reload from a backup?
Hi, Upgrading Winbox to 3.4 appears to have helped.I'm having similar issues - did you find a fix or work-around?Hello, I'm not sure if this is the correct thread, so if not, can a mod please move it.
I recently upgraded to RouterOS 6.33.3 (Hardware - 2011UIAS-2HnD) from an older 6.xx version (I can't remember what version it was ) but have noticed that I now get very slow response when accessing via Winbox (version 3)
When I connect via Winbox and click on Terminal, it takes about 3 minutes for the Terminal Window to reach the command prompt. In addition, I notice that the Date and Time clock takes ages to reflect the correct time. Basically, any function (eg list files, DHCP lists, etc) that I launch takes an absolute age to launch.
I would appreciate it if anyone has experienced similar and which version you recommend I roll back to.
PS: I did an 'auto-upgrade' in order to preserve all my existing rules and configurations - would it help to reset and then reload from a backup?