There are no changes between v7.6 and v7.6rc3.Hello
wich are the differencies betweeen RC3 and final ? This night I applied the 7.6RC3 on a CRS317
I second that !*) x86 - improved ixgbe driver support;
Can you elaborate on the improved support? What included and added?
RouterOS version 7.6 is released in the "v7 stable" channel!
*) certificate - fixed SHA1 certificate name lookup;
*) certificate - improved certificate management, signing and storing processes;
*) certificate - restricted maximum retry attempt window for Let's Encrypt certificate to 60 minutes;
Thanks, I will stay on rc2 for a whileUpgrading HAP AC3 (RBD53iG-5HacD2HnD) from 7.6rc2 results in "kernel failure in previous boot". Multiple retries.
Same 7.6rc2 -> rc3Upgrading HAP AC3 (RBD53iG-5HacD2HnD) from 7.6rc2 results in "kernel failure in previous boot". Multiple retries.
We're so far unable to reproduce this locally. Please open a support ticket and provide a supout file.Same 7.6rc2 -> rc3Upgrading HAP AC3 (RBD53iG-5HacD2HnD) from 7.6rc2 results in "kernel failure in previous boot". Multiple retries.
Then how come there are problems using wifiwave2 now ?There are no changes between v7.6 and v7.6rc3.
I'm having the same issue between 7.6 and Cisco IOS-XE:ospf simple auth error "route,ospf,info Discarding packet: wrong chekcsum" between 6.49.7 and 7.6
7.5 and 6.x works well
%OSPF-4-ERRRCV: Received invalid packet: Bad Checksum
Disabling the wlan interfaces -> scheduling wifi2wave for uninstall -> reboot -> upgrade to 7.6 + add wifi2wave -> enabling wlan interfaces and adding conf back worked.Possibly because of wifi2wave,
Same 7.6rc2 -> rc3
wlan: [69:E:QDF] qdf_fs_read[55]: Fail to Open File /lib/firmware/.fileindex
wlan: [69:E:QDF] qdf_fs_write[137], Failed to open file /lib/firmware/.fileindex
wlan: [69:E:ANY] ramdump_work_handler: ** STARTING DUMP options:2
wlan: [69:E:ANY] ol_get_tgt_dump_location: ERROR: No wifi_dump dts node available in the dts entry file
wlan: [69:E:ANY] fw_get_core_dump: Assertion failed! 0:fw_get_core_dump /opt/atlassian/bamboo-agent/xml-data/build-dir/ROS-V73-JOB1/7/wireless-qca/drivers/arm/qca-wifi/os/linux/../../qca_ol/wifi2.0/../../offl>
CPU: 2 PID: 69 Comm: kworker/2:1 Tainted: G O L 5.6.3 #2
Hardware name: IPQ4019
Workqueue: events __qdf_defer_func [qdf@0x7f3fb000]
{8fbbddcc} _stext+0x97e8/0x465b68
{8fbbddd4} _stext+0x451920/0x465b68
{8fbbdde4} ol_diag_read_sram+0x750/0x810 [wifi_2_0@0x7f456000]
{8fbbde6c} ramdump_work_handler+0x78/0x17c [wifi_2_0@0x7f456000]
{8fbbdf0c} ahb_defer_reconnect+0x30/0x200 [qca_ol@0x7f8d1000]
{8fbbdf3c} _stext+0x2d3b4/0x465b68
{8fbbdf64} _stext+0x2d6b4/0x465b68
{8fbbdf8c} _stext+0x32274/0x465b68
{8fbbdfac} _stext+0x10e8/0x465b68
Exception stack(0x8fbbdfb0 to 0x8fbbdff8)
dfa0: 00000000 00000000 00000000 00000000
dfc0: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000
dfe0: 00000000 00000000 00000000 00000000 00000013 00000000
WLAN Panic @ fw_get_core_dump:3216: Take care of the TARGET ASSERT first
*) ethernet - added "5Gbps" option for speed setting;
*) l3hw - added "l3hw-settings" sub menu under the switch menu;
*) sfp - improved QSFP/SFP interface stability for 98DXxxxx and 98PX1012 switches;
*) winbox - added "address-list" parameter under "IP/DNS/Static" menu;
Do it on your bench or someplace where you can run Netinstall... In case the $#!+ Hits the Fan.MT any statement? Is it safe to upgrade from 7.5 to 7.6? Are you working on fix?
winbox 3.37 windowsPossible that the details are always asked and are not automatically written???
Winbox version and on what platform?
Those two changelog entries don't mention anything about WinBox, from which you provided the screenshots.NOPE:
NOPE again:
Normally, they write "CLI only" if so, and if not, its referred to Winbox and CLI?! So far is my understanding of their changelog-nomenclature.Those two changelog entries don't mention anything about WinBox, from which you provided the screenshots.
Look for them in CLI.
*) dns - added "match-subdomain" option for static entries (CLI only);
These work via winbox on all of the devices that I upgraded.Those two changelog entries don't mention anything about WinBox, from which you provided the screenshots.
Look for them in CLI.
@Guscht
is it visible via the CLI ?*) ethernet - added "5Gbps" option for speed setting;
"MT" might not support L3HW?!*) l3hw - added "l3hw-settings" sub menu under the switch menu;
I see you have already upgraded. But a simple answer on this is:MT any statement? Is it safe to upgrade from 7.5 to 7.6? Are you working on fix?
where can I find macsec settings in winbox?
viewtopic.php?p=961612&hilit=theosoft#p961612Upgrade went well on my RB5009 from 7.6rc3 to 7.6. But there is a problem with partitions, I can not copy part1 to part0 anymore.
Copying goes to 750% and than copying stops with an error
did you have an autosupout file created at reboot ?CCR2116 - Reboot every 2 hours without any reasons
I'm using 295 nats rules actually i plan to remove all of them and route directly but for the moment the router keep rebooting anyone with this problem ?
Aah, thank you for the answer !@malobertviewtopic.php?p=961612&hilit=theosoft#p961612Upgrade went well on my RB5009 from 7.6rc3 to 7.6. But there is a problem with partitions, I can not copy part1 to part0 anymore.
Copying goes to 750% and than copying stops with an error
It is reproduced and solution in progress..
VETH related bug...
No what happen is the router boot me out of the winbox and all the vlan stop working nothing work i have to reboot it manually to make it work again for about 2 hours and so ondid you have an autosupout file created at reboot ?CCR2116 - Reboot every 2 hours without any reasons
I'm using 295 nats rules actually i plan to remove all of them and route directly but for the moment the router keep rebooting anyone with this problem ?
I'm getting the same error on my device (arm64).not a valid dns name (6)
Not SFP or dac câble issue ? Or used brand not working correctly with this version...After the problem came back again it seem that the SFP+2 stop passing traffic until i disable and renable the port ...
I tried with different dac cable and transceiver all is working correctly it seem that over 1 gbps the bug occurNot SFP or dac câble issue ? Or used brand not working correctly with this version...After the problem came back again it seem that the SFP+2 stop passing traffic until i disable and renable the port ...
Is there any way in 7.6 to cancel the power reset command or override it?
https://m.xkcd.com/1172/moutazsalem, nice example of how every change breaks someone's workflow :)
If I run Winbox from local, it works, if I perform winbox from wireguard tunnel, it blocks and does not enter.winbox 3.37 windowsPossible that the details are always asked and are not automatically written???
Winbox version and on what platform?
Is this new behaviour? Can you share your config (/ip/firewall/filter/ export)? Make sure to remove any privacy related informationIf I run Winbox from local, it works, if I perform winbox from wireguard tunnel, it blocks and does not enter.
Is this new behaviour? Can you share your config (/ip/firewall/filter/ export)? Make sure to remove any privacy related informationIf I run Winbox from local, it works, if I perform winbox from wireguard tunnel, it blocks and does not enter.
/interface bridge
add admin-mac=X:X:X:X:X:X auto-mac=no comment=defconf name=bridge \
protocol-mode=none
/interface ethernet
set [ find default-name=ether1 ] name=ether1-WAN
set [ find default-name=ether2 ] name=ether2-WAN-SKY
set [ find default-name=ether4 ] name=ether4-WIFI
/interface wireguard
add listen-port=51820 name=TUNNEL-NEGOZIO
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface lte apn
set [ find default=yes ] ip-type=ipv4 use-network-apn=no
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip firewall layer7-protocol
add comment="Always TCP: No fixed port" name=speedtest-servers regexp=\
"^.*(get|GET).+speedtest.*\$"
add name=Youtube regexp="^.+(youtube.com|youtube.net|.youtube.|.youtube).*\$"
add name=WhatsApp regexp=\
"^.+(whatsapp.com|whatsapp.net|.whatsapp.|.whatsapp).*\$"
add name=Facebook regexp=\
"^.+(facebook.com|facebook.net|.facebook.|.facebook).*\$"
/ip pool
add name=dhcp ranges=192.168.1.10-192.168.1.254
/ip dhcp-server
add address-pool=dhcp interface=bridge name=defconf
/port
set 0 name=serial0
/ppp profile
add local-address=10.0.8.1 name=OVPN use-encryption=yes
/routing bgp template
set default disabled=no output.network=bgp-networks
/routing ospf instance
add disabled=no name=default-v2
/routing ospf area
add disabled=yes instance=default-v2 name=backbone-v2
/routing table
add fib name=WAN1
/interface bridge port
add bridge=bridge comment=defconf ingress-filtering=no interface=ether3
add bridge=bridge comment=defconf ingress-filtering=no interface=ether5
add bridge=bridge ingress-filtering=no interface=ether4-WIFI
/interface bridge settings
set allow-fast-path=no
/ip neighbor discovery-settings
set discover-interface-list=none
/ip settings
set route-cache=no tcp-syncookies=yes
/ipv6 settings
set disable-ipv6=yes max-neighbor-entries=8192
/interface detect-internet
set internet-interface-list=WAN lan-interface-list=LAN wan-interface-list=WAN
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1-WAN list=WAN
add interface=TUNNEL-NEGOZIO list=LAN
add interface=ether2-WAN-SKY list=WAN
/interface ovpn-server server
set auth=sha1 certificate=SERVER cipher=aes256 default-profile=OVPN enabled=\
yes port=1180 protocol=udp require-client-certificate=yes
/interface wireguard peers
add allowed-address=10.0.8.1/32,192.168.0.0/24 endpoint-address=X.X.X.X \
endpoint-port=51820 interface=TUNNEL-NEGOZIO persistent-keepalive=10s \
public-key="XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"
/ip address
add address=192.168.1.1/24 comment=defconf interface=bridge network=\
192.168.1.0
add address=10.7.2.1/16 comment=INTERNET interface=ether1-WAN network=\
10.7.0.0
add address=10.0.8.2 interface=TUNNEL-NEGOZIO network=10.0.8.1
add address=192.168.11.100/24 interface=ether2-WAN-SKY network=192.168.11.0
/ip dhcp-server network
add address=192.168.1.0/24 comment=defconf gateway=192.168.1.1 netmask=24
/ip dns
set allow-remote-requests=yes servers=8.8.8.8,8.8.4.4
/ip dns static
add address=192.168.1.1 comment=defconf name=router.lan
/ip firewall address-list
add address=0.0.0.0/8 comment="defconf: RFC6890" list=no_forward_ipv4
add address=169.254.0.0/16 comment="defconf: RFC6890" list=no_forward_ipv4
add address=224.0.0.0/4 comment="defconf: multicast" list=no_forward_ipv4
add address=255.255.255.255 comment="defconf: RFC6890" list=no_forward_ipv4
add address=127.0.0.0/8 comment="defconf: RFC6890" list=bad_ipv4
add address=192.0.0.0/24 comment="defconf: RFC6890" list=bad_ipv4
add address=192.0.2.0/24 comment="defconf: RFC6890 documentation" list=\
bad_ipv4
add address=198.51.100.0/24 comment="defconf: RFC6890 documentation" list=\
bad_ipv4
add address=203.0.113.0/24 comment="defconf: RFC6890 documentation" list=\
bad_ipv4
add address=240.0.0.0/4 comment="defconf: RFC6890 reserved" list=bad_ipv4
add address=0.0.0.0/8 comment="defconf: RFC6890" list=not_global_ipv4
add address=10.0.0.0/8 comment="defconf: RFC6890" disabled=yes list=\
not_global_ipv4
add address=100.64.0.0/10 comment="defconf: RFC6890" list=not_global_ipv4
add address=169.254.0.0/16 comment="defconf: RFC6890" list=not_global_ipv4
add address=172.16.0.0/12 comment="defconf: RFC6890" list=not_global_ipv4
add address=192.0.0.0/29 comment="defconf: RFC6890" list=not_global_ipv4
add address=192.168.0.0/16 comment="defconf: RFC6890" disabled=yes list=\
not_global_ipv4
add address=198.18.0.0/15 comment="defconf: RFC6890 benchmark" list=\
not_global_ipv4
add address=255.255.255.255 comment="defconf: RFC6890" list=not_global_ipv4
add list=ddos-attackers
add list=ddos-target
add address=192.168.1.200 list=SMB
add address=192.168.0.200 list=SMB
add address=10.0.8.1 disabled=yes list=SMB
/ip firewall filter
add action=drop chain=forward comment="BLOCK WHATSAP" disabled=yes \
layer7-protocol=WhatsApp
add action=drop chain=forward comment="BLOCK FACEBOOK" disabled=yes \
layer7-protocol=Facebook
add action=drop chain=forward comment="BLOCK YOUTUBE" disabled=yes \
layer7-protocol=Youtube
add action=drop chain=input comment="BLOCK DNS Wan" connection-state=new \
dst-port=53 in-interface-list=WAN protocol=udp
add action=drop chain=input comment="BLOCK DNS Wan" connection-state=new \
dst-port=53 in-interface-list=WAN protocol=tcp
add action=add-src-to-address-list address-list=smb-flood \
address-list-timeout=none-dynamic chain=forward comment=\
"SMB Flood Gathering" connection-limit=100,32 dst-port=445 in-interface=\
bridge protocol=tcp
add action=add-src-to-address-list address-list=snpp-flood \
address-list-timeout=none-dynamic chain=forward comment=\
"SNPP/Backdoor Flood\r\
\nGathering" connection-limit=20,32 dst-port=444 in-interface=bridge \
protocol=tcp
add action=add-src-to-address-list address-list=msf-indication \
address-list-timeout=none-dynamic chain=forward comment=\
"Metasploit Indication" connection-limit=20,32 dst-port=4444 \
in-interface=bridge protocol=tcp
add action=add-src-to-address-list address-list=ssh-flood \
address-list-timeout=none-dynamic chain=forward comment=\
"SSH Flood Gathering" connection-limit=20,32 dst-port=22 in-interface=\
bridge protocol=tcp
add action=add-src-to-address-list address-list=telnet-flood \
address-list-timeout=none-dynamic chain=forward comment=\
"Telnet Flood\r\
\nGathering" connection-limit=20,32 dst-port=23 in-interface=bridge \
protocol=tcp
add action=log chain=forward comment="Abnormal Traffic" connection-bytes=\
80000000 disabled=yes limit=1,5:packet log-prefix=Abnormal-Traffic
add action=add-src-to-address-list address-list="port scanners" \
address-list-timeout=2w chain=forward comment="Port scanners to list " \
in-interface=!bridge log-prefix="port scanner" protocol=tcp psd=21,3s,3,1
add action=add-src-to-address-list address-list="port scanners" \
address-list-timeout=2w chain=input comment="Port scanners to list " \
protocol=tcp psd=21,3s,3,1
add action=add-src-to-address-list address-list="port scanners" \
address-list-timeout=2w chain=input comment="SYN/FIN scan" protocol=tcp \
tcp-flags=fin,syn
add action=add-src-to-address-list address-list="port scanners" \
address-list-timeout=2w chain=input comment="SYN/RST scan" protocol=tcp \
tcp-flags=syn,rst
add action=add-src-to-address-list address-list="port scanners" \
address-list-timeout=2w chain=input comment="FIN/PSH/URG scan" protocol=\
tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack
add action=add-src-to-address-list address-list="port scanners" \
address-list-timeout=2w chain=input comment="ALL/ALL scan" protocol=tcp \
tcp-flags=fin,syn,rst,psh,ack,urg
add action=add-src-to-address-list address-list="port scanners" \
address-list-timeout=2w chain=input comment="NMAP NULL scan" protocol=tcp \
tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg
add action=add-src-to-address-list address-list=DoS_Attacked \
address-list-timeout=5m chain=input comment=DoS_Attacked \
connection-limit=32,32 protocol=tcp
add action=tarpit chain=input comment=DoS_Attacked connection-limit=10,32 \
protocol=tcp src-address-list=DoS_Attacked
add action=drop chain=forward comment="Bloccare IP addresses BOGON" \
src-address=0.0.0.0/8
add action=return chain=detect-ddos comment="SYN-ACK Flood" dst-limit=\
32,32,src-and-dst-addresses/10s protocol=tcp tcp-flags=syn,ack
add action=drop chain=forward comment="dropping port scanners" \
src-address-list="port scanners"
add action=drop chain=input comment="dropping port scanners" \
src-address-list="port scanners"
add action=drop chain=input comment="drop echo request" icmp-options=8:0 \
in-interface-list=WAN protocol=icmp
add action=accept chain=icmp comment="echo reply" icmp-options=0:0 protocol=\
icmp
add action=accept chain=icmp comment="net unreachable" icmp-options=3:0 \
protocol=icmp
add action=accept chain=icmp comment="host unreachable" icmp-options=3:1 \
protocol=icmp
add action=accept chain=icmp comment=\
"host unreachable fragmentation required" icmp-options=3:4 protocol=icmp
add action=accept chain=icmp comment="allow source quench" icmp-options=4:0 \
protocol=icmp
add action=accept chain=icmp comment="allow echo request" icmp-options=8:0 \
protocol=icmp
add action=accept chain=icmp comment="allow time exceed" icmp-options=11:0 \
protocol=icmp
add action=accept chain=icmp comment="allow parameter bad" icmp-options=12:0 \
protocol=icmp
add action=accept chain=input comment="Allow OpenVPN" dst-port=1180 protocol=\
tcp
add action=accept chain=input comment="Allow Wireguard" dst-port=51820 \
protocol=udp
add action=accept chain=input comment=winbox dst-port=1170 protocol=tcp
add action=accept chain=input comment="Allow Established connections" \
connection-state=established,related
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment=\
"defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
ipsec-policy=in,ipsec
add action=accept chain=forward comment="ACCETTA TRAFFICO DA WIREGUARD" \
in-interface=TUNNEL-NEGOZIO src-address=192.168.0.0/24
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
ipsec-policy=out,ipsec
add action=accept chain=forward comment="COMPUTER METEO" src-mac-address=\
X:X:X:X:X:X
add action=accept chain=forward comment=\
"defconf: accept established,related, untracked" connection-state=\
established,related,untracked
add action=accept chain=input comment=\
"defconf: accept established,related,untracked" connection-state=\
established,related,untracked
add action=add-src-to-address-list address-list=FW_Block_unkown_port \
address-list-timeout=1d chain=input comment=\
"Add IP of user to access list if they have tried port that is not open." \
disabled=yes in-interface-list=WAN log-prefix=FI_AS_port-test \
src-address=!10.7.0.1
add action=drop chain=icmp comment="deny all other types"
add action=drop chain=input comment="Drop Invalid connections" \
connection-state=invalid in-interface-list=!LAN
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
in-interface-list=!LAN
add action=drop chain=input comment="BLOCCO BLACKLIST" connection-state=new \
in-interface-list=!LAN src-address-list=blacklist
add action=drop chain=forward comment=\
"defconf: drop all from WAN not DSTNATed NO DROP TUNNEL TRAFFIC" \
connection-nat-state=!dstnat connection-state=new dst-address-list=!SMB \
in-interface-list=!LAN
add action=accept chain=forward comment=\
"defconf: accept all that matches IPSec policy" ipsec-policy=in,ipsec
add action=drop chain=forward comment=\
"defconf: drop all from WAN not DSTNATed NO DROP TUNNEL TRAFFIC" \
connection-nat-state=!dstnat connection-state=new dst-address-list=!SMB \
in-interface-list=WAN
add action=drop chain=forward comment="defconf: drop bad forward IPs" \
src-address-list=no_forward_ipv4
add action=drop chain=forward comment="defconf: drop bad forward IPs" \
dst-address-list=no_forward_ipv4
add action=drop chain=forward comment="Drop invalid connections" \
connection-state=invalid
/ip firewall mangle
add action=change-mss chain=forward comment=MTU in-interface=TUNNEL-NEGOZIO \
new-mss=clamp-to-pmtu passthrough=yes protocol=tcp tcp-flags=syn
add action=change-ttl chain=prerouting comment="NO TRaceroute" new-ttl=\
increment:1 passthrough=yes
add action=mark-connection chain=prerouting comment="MARK PER WAN1" \
connection-state=new in-interface=ether1-WAN new-connection-mark=\
WAN1_conn
add action=mark-routing chain=prerouting comment="MARK PER WAN1" \
connection-mark=WAN1_conn in-interface-list=LAN new-routing-mark=WAN1
/ip firewall nat
add action=dst-nat chain=dstnat comment="Force using DNS LAN" disabled=yes \
dst-port=53 in-interface=bridge protocol=udp to-ports=53
add action=dst-nat chain=dstnat comment="DNS GOOGLE VALERIO" disabled=yes \
dst-port=53 protocol=udp src-mac-address=X:X:X:X:X:X to-addresses=\
8.8.8.8 to-ports=53
add action=dst-nat chain=dstnat comment="WEBCAM CASA" dst-port=8181 \
in-interface=ether1-WAN protocol=tcp src-address=!192.168.0.0/24 \
to-addresses=192.168.1.51 to-ports=8080
add action=dst-nat chain=dstnat comment="Winbox WIFI" dst-port=1175 \
in-interface=TUNNEL-NEGOZIO protocol=tcp src-address=192.168.0.11 \
to-addresses=192.168.1.100 to-ports=1170
add action=dst-nat chain=dstnat comment="DAVIS WIFI" dst-port=8090 \
in-interface=TUNNEL-NEGOZIO protocol=tcp src-address=192.168.0.11 \
to-addresses=192.168.5.40 to-ports=80
add action=masquerade chain=srcnat comment="TUNNEL NEGOZIO" dst-address=\
192.168.0.0/24 ipsec-policy=out,none out-interface=TUNNEL-NEGOZIO
add action=masquerade chain=srcnat comment="defconf: masquerade" \
ipsec-policy=out,none out-interface-list=WAN
/ip firewall raw
add action=accept chain=icmp4 comment="defconf: echo reply" icmp-options=0:0 \
limit=5,10:packet protocol=icmp
add action=accept chain=icmp4 comment="defconf: net unreachable" \
icmp-options=3:0 protocol=icmp
add action=accept chain=icmp4 comment="defconf: host unreachable" \
icmp-options=3:1 protocol=icmp
add action=accept chain=icmp4 comment="defconf: protocol unreachable" \
icmp-options=3:2 protocol=icmp
add action=accept chain=icmp4 comment="defconf: port unreachable" \
icmp-options=3:3 protocol=icmp
add action=accept chain=icmp4 comment="defconf: fragmentation needed" \
icmp-options=3:4 protocol=icmp
add action=accept chain=icmp4 comment="defconf: echo" icmp-options=8:0 limit=\
5,10:packet protocol=icmp
add action=accept chain=icmp4 comment="defconf: time exceeded " icmp-options=\
11:0-255 protocol=icmp
add action=drop chain=icmp4 comment="defconf: drop other icmp" protocol=icmp
add action=drop chain=prerouting comment=DDOS dst-address-list=ddos-target \
src-address-list=ddos-attackers
add action=drop chain=prerouting comment="DNS Amplification" dst-port=53 \
in-interface-list=WAN protocol=udp
add action=drop chain=prerouting comment="Well-Known Port+ winbox da wan" \
dst-port=2000,22,23,80,53,1170 in-interface=!TUNNEL-NEGOZIO \
in-interface-list=WAN protocol=tcp
add action=drop chain=prerouting comment=\
"Well-Known Virus/Flooding Port- esscludo ip nas" dst-address-list=!SMB \
dst-port=445,2000,4444,444 in-interface-list=LAN protocol=tcp
add action=drop chain=prerouting comment="Memcached Flood" in-interface-list=\
LAN protocol=udp src-port=11211
add action=drop chain=prerouting comment="drop port scanner" in-interface=\
!TUNNEL-NEGOZIO src-address-list="port scanners"
add action=drop chain=prerouting comment="defconf: drop bogon IP's" \
src-address-list=bad_ipv4
add action=drop chain=prerouting comment="defconf: drop bogon IP's" \
dst-address-list=bad_ipv4
add action=drop chain=prerouting comment="defconf: drop bogon IP's" \
src-address-list=bad_src_ipv4
add action=drop chain=prerouting comment="defconf: drop bogon IP's" \
dst-address-list=bad_dst_ipv4
add action=drop chain=prerouting comment="defconf: drop non global from WAN" \
in-interface-list=WAN log=yes src-address-list=not_global_ipv4
add action=drop chain=bad_tcp comment="defconf: TCP flag filter" protocol=tcp \
tcp-flags=!fin,!syn,!rst,!ack
add action=drop chain=bad_tcp comment=defconf protocol=tcp tcp-flags=fin,syn
add action=drop chain=bad_tcp comment=defconf protocol=tcp tcp-flags=fin,rst
add action=drop chain=bad_tcp comment=defconf protocol=tcp tcp-flags=fin,!ack
add action=drop chain=bad_tcp comment=defconf protocol=tcp tcp-flags=fin,urg
add action=drop chain=bad_tcp comment=defconf protocol=tcp tcp-flags=syn,rst
add action=drop chain=bad_tcp comment=defconf protocol=tcp tcp-flags=rst,urg
add action=drop chain=bad_tcp comment="defconf: TCP port 0 drop" port=0 \
protocol=tcp
add action=accept chain=prerouting in-interface=TUNNEL-NEGOZIO src-address=\
192.168.0.0/24
add action=accept chain=icmp4 comment="defconf: echo reply" icmp-options=0:0 \
limit=5,10:packet protocol=icmp
add action=accept chain=icmp4 comment="defconf: net unreachable" \
icmp-options=3:0 protocol=icmp
add action=accept chain=icmp4 comment="defconf: host unreachable" \
icmp-options=3:1 protocol=icmp
add action=accept chain=icmp4 comment="defconf: protocol unreachable" \
icmp-options=3:2 protocol=icmp
add action=accept chain=icmp4 comment="defconf: port unreachable" \
icmp-options=3:3 protocol=icmp
add action=accept chain=icmp4 comment="defconf: fragmentation needed" \
icmp-options=3:4 protocol=icmp
add action=accept chain=icmp4 comment="defconf: echo" icmp-options=8:0 limit=\
5,10:packet protocol=icmp
add action=accept chain=icmp4 comment="defconf: time exceeded " icmp-options=\
11:0-255 protocol=icmp
add action=drop chain=icmp4 comment="defconf: drop other icmp" protocol=icmp
add action=drop chain=prerouting in-interface-list=WAN protocol=!tcp \
src-address=!X.X.X.X src-address-list=FW_Block_unkown_port
/ip firewall service-port
set ftp disabled=yes
set tftp disabled=yes
set h323 disabled=yes
set sip disabled=yes
set pptp disabled=yes
set udplite disabled=yes
set dccp disabled=yes
set sctp disabled=yes
/ip route
add check-gateway=ping disabled=no distance=2 dst-address=0.0.0.0/0 gateway=\
10.7.0.1 pref-src=0.0.0.0 routing-table=WAN1 scope=30 \
suppress-hw-offload=no target-scope=10
add disabled=no distance=2 dst-address=192.168.5.0/24 gateway=192.168.1.100 \
pref-src=0.0.0.0 routing-table=main scope=30 suppress-hw-offload=no \
target-scope=10
add check-gateway=ping disabled=no distance=3 dst-address=192.168.0.0/24 \
gateway=10.0.8.1 pref-src="" routing-table=main scope=30 \
suppress-hw-offload=no target-scope=10
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=\
192.168.11.1 pref-src=0.0.0.0 routing-table=main scope=30 \
suppress-hw-offload=no target-scope=10
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set ssh disabled=yes
set api disabled=yes
set winbox address=192.168.1.0/24,10.0.8.0/30,192.168.0.11/32 port=1170
set api-ssl disabled=yes
/ppp secret
add name=vrcomputer profile=OVPN remote-address=10.0.8.5 service=ovpn
/system clock
set time-zone-name=Europe/Rome
/system identity
set name=ROUTER-CASA
/system ntp client
set mode=broadcast
/tool bandwidth-server
set enabled=no
/tool e-mail
set address=X.X.X.X from=noreply@XXXXXXX.com user=smtp@XXXXXXXX.it
/tool graphing interface
add interface=ether1-WAN
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
/tool mac-server ping
set enabled=no
Are your cAPs running ROS 7.6?CapsMan stopped working when I upgraded from 7.5. None of the controlled access points (CAPs) would connect to CapsMan. I downgraded and everything went back to normal. (small setup with 20 access points)
/routing/bgp/advertisements/print now shows a detailed list, where on rc1 it showed only a summary. There was a "show" command that showed the full list.
So now I tried /routing/bgp/advertisements/print count-only to see if it maybe shows a summary only.
It showed:
704
no such item (4)
From now on, /routing/bgp/advertisements/print only shows a single item and then it prints that no such item (4) error.
[admin@dr_05] /routing/bgp/advertisements> print count-only
848915
[admin@dr_05] /routing/bgp/advertisements> print
0 peer=bgp_feed-1 dst=23.161.0.0/24
bgp.nexthop=10.155.101.183 .origin=0 .as-path=sequence 444
0 peer=to_231-1 dst=60.48.0.0/14
bgp.nexthop=10.155.101.1 .origin=0 .as-path=sequence 444 65530 100 6667 1273 4788 4788
.communities=35859:2842,41743:2842,47883:2842,49940:2842,51200:46098,53760:46098,55855:63748
.atomic-aggregate=yes
....
Update of CAPsMAN from 7.5 to 7.6 went smooth, even on CAPsMAN itself and on all AP´s (5x) also. (ROS and FW).Are your cAPs running ROS 7.6?CapsMan stopped working when I upgraded from 7.5. None of the controlled access points (CAPs) would connect to CapsMan. I downgraded and everything went back to normal. (small setup with 20 access points)
What a most creative implementation of firewall rules. You have to do some work on that./interface bridge
add admin-mac=X:X:X:X:X:X auto-mac=no comment=defconf name=bridge \
protocol-mode=none
I did not do much, at first I entered the /routing/bgp/advertisements/print command, which in rc1 (I never installed rc2 or rc3) printed a short listing of my BGP peers and the number of advertisements to each of them..../routing/bgp/advertisements/print now shows a detailed list, where on rc1 it showed only a summary. There was a "show" command that showed the full list.
So now I tried /routing/bgp/advertisements/print count-only to see if it maybe shows a summary only.
It showed:
704
no such item (4)
From now on, /routing/bgp/advertisements/print only shows a single item and then it prints that no such item (4) error.
Works, maybe anything else you did to trigger the problem? Or list is changing when you are doing the print?
################################################
# 7.3.1 is the last one working
11:27:55 sstp,ppp,debug uw: LCP open
11:27:55 sstp,ppp,debug,packet uw: sent LCP ConfReq id=0x1
11:27:55 sstp,ppp,debug,packet <magic 0x20b5cf3b>
11:27:55 sstp,ppp,debug,packet uw: rcvd LCP ConfReq id=0x0
11:27:55 sstp,ppp,debug,packet <mru 4091>
11:27:55 sstp,ppp,debug,packet <magic 0x9f299f49>
11:27:55 sstp,ppp,debug,packet <pcomp>
11:27:55 sstp,ppp,debug,packet <accomp>
11:27:55 sstp,ppp,debug,packet <auth 0xc227>
11:27:55 sstp,ppp,debug,packet <callback 0x06>
11:27:55 sstp,ppp,debug,packet <mrru 1614>
11:27:55 sstp,ppp,debug,packet <ed 0x01 4c 31 e9 33 4b af 41 e6 96 bd 10 1a 2e 91 cc e5 00 00 00 00>
11:27:55 sstp,ppp,debug,packet uw: sent LCP ConfRej id=0x0
11:27:55 sstp,ppp,debug,packet <pcomp>
11:27:55 sstp,ppp,debug,packet <accomp>
11:27:55 sstp,ppp,debug,packet <callback 0x06>
11:27:55 sstp,ppp,debug,packet <mrru 1614>
11:27:55 sstp,ppp,debug,packet <ed 0x01 4c 31 e9 33 4b af 41 e6 96 bd 10 1a 2e 91 cc e5 00 00 00 00>
11:27:55 sstp,ppp,debug,packet uw: rcvd LCP ConfAck id=0x1
11:27:55 sstp,ppp,debug,packet <magic 0x20b5cf3b>
11:27:55 sstp,ppp,debug,packet uw: rcvd LCP ConfReq id=0x1
11:27:55 sstp,ppp,debug,packet <mru 4091>
11:27:55 sstp,ppp,debug,packet <magic 0x9f299f49>
11:27:55 sstp,ppp,debug,packet <auth 0xc227>
11:27:55 sstp,ppp,debug,packet uw: sent LCP ConfNak id=0x1
11:27:55 sstp,ppp,debug,packet <auth mschap2>
11:27:55 sstp,ppp,debug,packet uw: rcvd LCP ConfReq id=0x2
11:27:55 sstp,ppp,debug,packet <mru 4091>
11:27:55 sstp,ppp,debug,packet <magic 0x9f299f49>
11:27:55 sstp,ppp,debug,packet <auth mschap2>
11:27:55 sstp,ppp,debug,packet uw: sent LCP ConfAck id=0x2
11:27:55 sstp,ppp,debug,packet <mru 4091>
11:27:55 sstp,ppp,debug,packet <magic 0x9f299f49>
11:27:55 sstp,ppp,debug,packet <auth mschap2>
11:27:55 sstp,ppp,debug uw: LCP opened
################################################
# 7.4 is the first not working version.
16:25:31 sstp,ppp,debug uw: LCP lowerup
16:25:31 sstp,ppp,debug,packet uw: sent LCP ConfReq id=0x3
16:25:31 sstp,ppp,debug,packet <magic 0x3c390d4d>
16:25:31 sstp,ppp,debug uw: LCP open
16:25:31 sstp,ppp,debug,packet uw: rcvd LCP ConfReq id=0x0
16:25:31 sstp,ppp,debug,packet <mru 4091>
16:25:31 sstp,ppp,debug,packet <magic 0xd275f908>
16:25:31 sstp,ppp,debug,packet <pcomp>
16:25:31 sstp,ppp,debug,packet <accomp>
16:25:31 sstp,ppp,debug,packet <auth 0xc227>
16:25:31 sstp,ppp,debug,packet <callback 0x06>
16:25:31 sstp,ppp,debug,packet <mrru 1614>
16:25:31 sstp,ppp,debug,packet <ed 0x01 4c 31 e9 33 4b af 41 e6 96 bd 10 1a 2e 91 cc e5 00 00 00 00>
16:25:31 sstp,ppp,debug,packet uw: sent LCP ConfRej id=0x0
16:25:31 sstp,ppp,debug,packet <pcomp>
16:25:31 sstp,ppp,debug,packet <accomp>
16:25:31 sstp,ppp,debug,packet <auth 0xf0e9>
16:25:31 sstp,ppp,debug,packet <callback 0x06>
16:25:31 sstp,ppp,debug,packet <mrru 1614>
16:25:31 sstp,ppp,debug,packet <ed 0x01 4c 31 e9 33 4b af 41 e6 96 bd 10 1a 2e 91 cc e5 00 00 00 00>
16:25:31 sstp,ppp,debug,packet uw: rcvd LCP ConfAck id=0x3
16:25:31 sstp,ppp,debug,packet <magic 0x3c390d4d>
16:25:31 sstp,ppp,debug,packet uw: rcvd LCP TermReq id=0x1
16:25:31 sstp,ppp,debug,packet 08F9uD200<CDt00000397
16:25:31 sstp,ppp,debug,packet uw: sent LCP TermAck id=0x1
16:25:31 sstp,ppp,debug uw: LCP lowerdown
################################################
# 7.6 is not working either but debug logs for sstp/ppp have gone sparse too
16:43:04 sstp,ppp,info uw: initializing...
16:43:04 sstp,ppp,info uw: initializing...
16:43:04 sstp,ppp,info uw: connecting...
16:43:04 sstp,ppp,info uw: connecting...
16:43:05 sstp,packet uw sending
16:43:05 sstp,packet SSTP_DUPLEX_POST /sra_{BA195980-CD49-458b-9E23-C84EE0ADCD75}/ HTTP/1.1r
16:43:05 sstp,packet Content-Length: 18446744073709551615r
16:43:05 sstp,packet Host: ::r
16:43:05 sstp,packet r
16:43:05 sstp,packet
16:43:05 sstp,ppp,debug uw: CCP close
16:43:05 sstp,ppp,debug uw: BCP close
16:43:05 sstp,ppp,debug uw: IPCP close
16:43:05 sstp,ppp,debug uw: IPV6CP close
16:43:05 sstp,ppp,debug uw: MPLSCP close
16:43:05 sstp,ppp,info uw: terminating... - closed by remote peer
16:43:05 sstp,ppp,info uw: terminating... - closed by remote peer
16:43:05 sstp,ppp,debug uw: LCP lowerdown
/interface sstp-client
add authentication=mschap2 connect-to=some.host.net http-proxy=0.0.0.0 name=uw pfs=yes profile=uw tls-version=only-1.2 user="domain\\some.user" \
verify-server-address-from-certificate=no verify-server-certificate=yes
/ppp profile
add change-tcp-mss=yes name=uw use-encryption=yes use-ipv6=no use-mpls=no use-upnp=no
Disabling Fasttrack made it worse for my testing. definitely something changed in wireguard as its dropping packets etc. What port are you using for your wireguard?Have problems on a CCR2004-16g-2s and sfponu module.
Issue shows after firmware update add next boot, no pon link at sfp.
SFP is visible and hardware info is ok, but no pon link.
So after every firmware update i need get out sfponu and insert it again, only after that pon link is ok. Simple rebooting doesnt solve problem
That same problem was on a rb4011, rb5009. I think some power reset solution for sfp+ port needed.
And onemore, when fasttrack is enabled (action=fasttrack-connection chain=forward connection-state=established,related hw-offload=yes ) all wireguard connections works very slow and dropping packets. Tried play with mtu but only disabling fasttrack helps.
I think with the wifiwave2 package installed, it is now to be considered "the normal and accepted behavior".... or else it would have been fixed by now.Hap ac3 log: error while running customized default configuration script: no such item
Tried to rename wifi back to wlan1 and wlan2 (also to wifi1 and wifi2) and reboot, nothing changed
When the "get-custom-defconf" is interrupted for some reason, the "flag" get-custom-defconf runned successfully is not set, and everytime at reboot it try to run the script,Code: Select allsep/02/2022 16:13:17 system,error,critical error while running customized default configuration script: bad command name wireless (line 985 column 25) sep/02/2022 16:13:17 system,error,critical
# wait wlan3 it takes 7sec slower to load than wlan1/2 on Audience
$addCL (" :local count 0;")
$addCL (" :while ([/interface wireless find default-name=\"wlan3\"] = \"\") do={ ")
$addCL (" :if (\$count = 15) do={")
$addCL (" :log warning \"DefConf: Unable to find wlan3 interface\";")
$addCL (" /quit")
$addCL (" }")
$addCL (" :delay 1s; :set count (\$count +1);")
$addCL (" };")
# TODO: set band and ext, probably use setWlan function
$addCL (" /interface wireless {")
$addCL (" :local wl3 [find default-name=\"wlan3\"]")
$addCL (" :local wlanMac [get \$wl3 mac-address];")
$addCL (" :set ssid \"SYNC-\$[:pick \$wlanMac 9 11]\$[:pick \$wlanMac 12 14]\$[:pick \$wlanMac 15 17]\"")
$addCL (" set \$wl3 disabled=no mode=ap-bridge band=5ghz-a/n/ac ssid=\$ssid security-profile=wpsSync wps-mode=push-button")
# set channnel width 20/40/80mhz-XXXX (russia 20/40mhz-XX)
<<< LINE 983 >>> # wait wlan3 it takes 7sec slower to load than wlan1/2 on Audience
:local count 0;
<<< @mkx LINE 985 >>> :while ([/interface wireless find default-name="wlan3"] = "") do={
:if ($count = 30) do={
:log warning "DefConf: Unable to find wlan3 interface";
/quit
}
:delay 1s; :set count ($count +1);
};
<<< LINE 993 >>> :local hwInfo [/interface wireless info hw-info [.. find where default-name="wlan3"] as-value];
$addDL ("#| channel-width: 20/40mhz-XX;")
<<< LINE 995 >>> $addCL (" set \$wl3 channel-width=20/40mhz-XX")
$addCL (" };")
}
+1*) ospf - fixed checksum calculation;
All routers upgraded to this version now complain with "wrong checksum from <blah>" and OSPF isn't propogating routes.
> /routing/bgp/advertisements/print detail where peer=bgp-22-2-1
0 peer=bgp-22-2-1 dst=2001:c76:a00:300::/56 local-pref=100 nexthop=10c:760a::2200 origin=0
> ipv6/route/print where dst-address=2001:c76:a00:300::/56
Flags: D - DYNAMIC; A - ACTIVE; b, y - COPY
Columns: DST-ADDRESS, GATEWAY, DISTANCE
DST-ADDRESS GATEWAY DISTANCE
DAb 2001:c76:a00:300::/56 2001:c76:a00::22 200
My issue in the end was an in-path CR354-48G-4S+2Q+ causing issues with Bonding of interfaces to another switch as well as packets dropping around 20% inside the switch. Rebooting it didnt help, but backing this switch down to 7.5 solved the issue.Disabling Fasttrack made it worse for my testing. definitely something changed in wireguard as its dropping packets etc. What port are you using for your wireguard?Have problems on a CCR2004-16g-2s and sfponu module.
Issue shows after firmware update add next boot, no pon link at sfp.
SFP is visible and hardware info is ok, but no pon link.
So after every firmware update i need get out sfponu and insert it again, only after that pon link is ok. Simple rebooting doesnt solve problem
That same problem was on a rb4011, rb5009. I think some power reset solution for sfp+ port needed.
And onemore, when fasttrack is enabled (action=fasttrack-connection chain=forward connection-state=established,related hw-offload=yes ) all wireguard connections works very slow and dropping packets. Tried play with mtu but only disabling fasttrack helps.
It gave the same error here (all were previously in version 7.5), when updating to 7.6, OSPF stopped working with the checksum error, I tried to remove and reconfigure and it still didn't solve it, the way was to go back to version 7.5 , done everything went back to normal!ospf simple auth error "route,ospf,info Discarding packet: wrong chekcsum" between 6.49.7 and 7.6
7.5 and 6.x works well
No more issues by uploading file through sftp, instead of ftp.The ugly premission denied issue seems still exist in 7.6
I'm able to run adguardhome without errors, until I edit AdguardHome.yaml to set upstream_dns_file: disk1/adguardhome/conf/greatfire.txt
Then log report permission denied error.
Oct/20/2022 12:42:07 ipsec, error unable to get certificate CRL(3) at depth:0 cert:CN=...
Oct/20/2022 12:42:07 ipsec, error unable to get certificate CRL(3) at depth:1 cert:C=...
+1 - in my case the characters of the IPv6 address are shifted and ::<less than 4 characters> is resolved wrong for example ::15 is resolved to :1500 instead of :0015I think I've got a bug with /routing/bgp/advertisements/print with IPv6 sessions:
The next-hop value ist just bullshit. Fortunately it's just a display bug, because the routes are advertised with the correct next-hop:Code: Select all> /routing/bgp/advertisements/print detail where peer=bgp-22-2-1 0 peer=bgp-22-2-1 dst=2001:c76:a00:300::/56 local-pref=100 nexthop=10c:760a::2200 origin=0
BR,Code: Select all> ipv6/route/print where dst-address=2001:c76:a00:300::/56 Flags: D - DYNAMIC; A - ACTIVE; b, y - COPY Columns: DST-ADDRESS, GATEWAY, DISTANCE DST-ADDRESS GATEWAY DISTANCE DAb 2001:c76:a00:300::/56 2001:c76:a00::22 200
Johannes
Not yet. To be able to update them to 7.6 from capsman, you need to upgrade the capsman server first. But it's a catch 22, since the access points lose connectivity as soon as I upgrade the capsman server.Are your cAPs running ROS 7.6?CapsMan stopped working when I upgraded from 7.5. None of the controlled access points (CAPs) would connect to CapsMan. I downgraded and everything went back to normal. (small setup with 20 access points)
The access points are on 7.5.Update of CAPsMAN from 7.5 to 7.6 went smooth, even on CAPsMAN itself and on all AP´s (5x) also. (ROS and FW).
Are your cAPs running ROS 7.6?
From what version did you came from? (AP´s)
*) firewall - fixed usage of "netmap" action for IPv6 source NAT;
I just did a new install.Not yet. To be able to update them to 7.6 from capsman, you need to upgrade the capsman server first. But it's a catch 22, since the access points lose connectivity as soon as I upgrade the capsman server.
Are your cAPs running ROS 7.6?
Yesterday I've updated from 7.5 to 7.6 ccr1016 with capsman, crs328, some capAC2 and wAPac. All fine! cAPs get update before capsman router.The access points are on 7.5.
Update of CAPsMAN from 7.5 to 7.6 went smooth, even on CAPsMAN itself and on all AP´s (5x) also. (ROS and FW).
From what version did you came from? (AP´s)
I haved the same problem some weeks ago, but is not RouterOS the problem: after reboot do not start.I just updated from 7.5 to 7.6 on CRS326-24G-2S+RM and now it's a brick.
Doesn't make sense, IMHO, as it works perfectly well under Ubuntu as virtual machine (Hyper-V) in Windows 10/11.Same here.
I keep on old Dell laptop especially for that purpose (2008 and no battery).
Still true after 2 days...CCR2116-12G-4S+ now on production
[…]
BGP v4: WORK (AS->not-MikroTik AS multi-peer ebgp)
BGP v6: WORK (AS->not-MikroTik AS single-peer ebgp)
[…]
news this problem?If I run Winbox from local, it works, if I perform winbox from wireguard tunnel, it blocks and does not enter.
winbox 3.37 windows
Most likely this is your problemnews this problem?
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
in-interface-list=!LAN
The Wireguard interface is on the LAN listmoderator nite: no need to quote whole preceding post. Just use "Post Reply" button.
How about some documentation on how the /ip/dns/static address-list field is supposed to be used?
Offtopic: Good to see your powers clipped. Simping for mikrotik and telling that all bugs or missing features are user's fault doesn't help in the long run. One of the worst moderator on a technical forum.Till now, I never have a single problem with netinstall on old / new computers, if the OS is correctly configured, and netinstall correctly configured and used.
That's simply not true... MT is using some uncommon functions which makes it almost impossible to use it right form the start in Windows. Don't you think if it was a good product there would be no complains? There are many different for example TFTP implementations which simply work without any extra work required, the same should apply to this product. We are here with some extra IT knowledge then average user and almost everybody here knows how to handle Windows. The problem is the app itself which should be redesigned according to nowadays systems specification and probably written from scratch.moderator nite: no need to quote whole preceding post. Just use "Post Reply" button.
Capacitor or fuse as 1A requirement for capacitors makes no sense.Check the capacitor on power adapter, try to replace it with another new...(any between 12V/24V is good, but must be 1A at least)
"Simple" TCP might not be so simple ... I guess the tricky part of netinstall binary is that it includes BOOTP/DHCP server and TFTP server, additionally device opens sort of control connection (could be it's actually a service which gets started after device boots from image received from netinstall server via TFTP) which allows netinstall binary to push actual npk files and default configuration ... none of which is possible using simple TFTP. Surely netinstall could relly on other (standard) servers to provide these services, but that would mean multiple servers (by multiple vendors) with appropriate config. I guess that would proove a nightmare for every Mikrotik user but hard-core network admins. I guess the tricky part is to bind BOOTP/DHCP and TFTP services to correct interface, at least BOOTP/DHCP service has to listen to "raw" IP/UDP network interface to catch those broadcasts from client. Even standard ISC DHCP server on linux used to bind to raw network device to deal with requests reliably (I'm not sure about recent versions though).As the protocol isn't documented anyway, it may also be best to just overhaul it completely and change to a simple TCP connection that does everything. That should solve the firewall issues too.
That is what I mean: do not use BOOTP, TFTP etc but just run a TCP service ...
I don't understand what you wanted to explain. If L2 would be enough for Netinstall to work defining IP addresses would be unnecessary.@Panbambaryla:
L2 protocol... [...]
You can see after you have posted if a new message in the mean time has entered between your latest post and replied post(not a problem on this small forum). Then you can edit your post and quote whats needed. Another stuff happens when you quote a post, an email are sent to the user.To moderator: during my message composition time another post can appear, so quoting the one I am responding to, is the best, direct approach to keep things tight. The forum should eventually cut the quotations to a few first sentences if not implemented yet.
Same here but with a /48 on both sides. It looks like IPv6 NETMAP is still broken, no matter which direction you go in (prerouting/dstnat or postrouting/srcnat).*) firewall - fixed usage of "netmap" action for IPv6 source NAT;
Not sure what this means. From what I see source nat using netmap doesn't seem to work correctly.
I have a srcnat rule to netmap from fdyy:yyyy:yyyy:yyyy::/64 to 2a01:xxxx:xxxx:xxxx::/64.
But every single outgoing connection has an ipv6 source address set to 2a01:xxxx:xxxx:xxxx::
Search in this thread for partition for the solution, you are not the only one. I had this after the upgrade. Delete your veth interface and everything works well after that.ros76_partition.jpg
So this isn't right? Rb5009UPr
Part1 now broken after i canceled this process.. Anything known?
That's what i did beforehand.. Funny enough "partitioN" does not return results.. searching for "veth" however did!Search in this thread for partition for the solution, you are not the only one. I had this after the upgrade. Delete your veth interface and everything works well after that.ros76_partition.jpg
So this isn't right? Rb5009UPr
Part1 now broken after i canceled this process.. Anything known?
Sounds positive,CCR2116-12G-4S+ now on production
from netinstalled 7.6beta7 on "test",
previously updated via drag&drop npk from 7.6beta7 to 7.6beta8 on "test",
previously updated via drag&drop npk from 7.6beta8 to 7.6rc1 on "pre-production",
updated again via drag&drop npk from 7.6rc1 to 7.6 (stable) on "production"
BGP v4: WORK (AS->not-MikroTik AS multi-peer ebgp)
BGP v6: WORK (AS->not-MikroTik AS single-peer ebgp)
BUG:
1) Dual boot still required for upgrade the RouterBOOT.
2) RouterOS package still called "routeros" instead of "routeros-arm64" (on this model) and this prevent "The Dude" to be able to upgrade the device.
3) The Original User-Manager not exist on RouterOS v7. The surrogate can not even be compared with the Original v6.
It's the same for me./routing/bgp/advertisements/print now shows a detailed list, where on rc1 it showed only a summary. There was a "show" command that showed the full list.
So now I tried /routing/bgp/advertisements/print count-only to see if it maybe shows a summary only.
It showed:
704
no such item (4)
From now on, /routing/bgp/advertisements/print only shows a single item and then it prints that no such item (4) error.
> /routing/bgp/advertisements/print count-only
4366
no such item (4)
I'm using it with 2 BGP full tables, around 1.900.000 prefixes in table...Thx @rextended.Only the default routes from all 3 peers, they are the same provider, the second IPv4 is for failover.
As long as you have no special routing needs or have multiple providers, etc., it is useless to have any full route table.
I would be interested to know if anyone is running 7.6 in production with full internet routing table or at least receiving more than 500k routes from peers.
It is stable, I have 2 CCR2216 with 2 BGP full table each, it works as edge routers, I can reboot each without impact of the backbone. iBgp is instant running, eBgp is about 3 mins to be 100%...all is IPV4 and IPV6...Thanks for the reply. Can you comment on the stability?
- How long does it take to build the routing table if the router reboots or if the eBGP peer is disconnected?
- Do you have any concerns or is running stable?
- Would you recommend for ISP production environment?
Many thx.
I have the same problemLike 7.6rc2 and 7.6.rc3 this 7.6 release has the same issue for us.
CCR2216, 2 bgp links full table, around 1.900.000 prefixes in routing table.
issue with cli command : /routing/bgp/advertisements/
when using /routing/bgp/advertisements/print with where command to filter a peer, that working with no issue.
but
when using just /routing/bgp/advertisements/print, causing 100% cpu at routing & management process and memory is falling down rapidly. after lost 9Gb RAM we device to force reboot...
nobody has this issue ?
regards
Hi,updated hex from 7.2 to 7.6 but version remains the same
Hi,Hi,
You've updated RouterOS but not Routerboard, please follow https://www.youtube.com/watch?v=WPW3mHlEzn4
:global new
:global old
:global status
:set status [/interface get [/interface find name=("pppoe-out1")] running]
:if ($status=true) do={
:set new [/ip address get [/ip address find dynamic=yes interface=("pppoe-out1")] address]
:set new [:pick $new 0 ([:len $new] -3)]
:set old [/ip firewall nat get [find comment=("src-nat")] to-addresses]
:if (!($new=$old)) do={
/ip firewall nat set [/ip firewall nat find comment=("src-nat")] to-addresses=$new
}}
/ip firewall nat
add action=src-nat chain=srcnat comment=src-nat ipsec-policy=out,none out-interface=pppoe-out1 to-addresses=xx.xx.xx.xx
:if ([/interface get pppoe-out1 running]) do={
:local new [/ip address get ([find where interface=pppoe-out1]->0) address]
:set new [:pick $new 0 [:find $new "/"]]
:local old [/ip firewall nat get [find where comment="src-nat"] to-addresses]
:if ($new != $old) do={
/ip firewall nat set [find where comment="src-nat"] to-addresses=$new
}
}
/ip firewall nat set [find where comment="src-nat"] to-addresses=$"local-address"
If "local-address" would never be broken, this should be the best way.or better, removing all useless parts, if you put this on ppp profile / scripts / on up:Code: Select all/ip firewall nat set [find where comment="src-nat"] to-addresses=$"local-address"
If "local-address" would never be broken, this should be the best way.or better, removing all useless parts, if you put this on ppp profile / scripts / on up:Code: Select all/ip firewall nat set [find where comment="src-nat"] to-addresses=$"local-address"
I was, until my internal OSPF links started flapping.Thx @rextended.
I would be interested to know if anyone is running 7.6 in production with full internet routing table or at least receiving more than 500k routes from peers.
Glad to see it wasn't just me. Did you try disabling L3HW offload? That fixed it for me on 7.6, but kind of defeated the purpose of using those routers in the first place. :-)BPG/OSPF with large (300'000+) tables and L3HW enabled is unstable and peer connections flap with OSPF resets in the log.
For us, this issues started with 7.5 and did not improve with 7.6.
The OSPF CRC "fix" causes packet drops with ("%OSPF-4-ERRRCV: Received invalid packet: Bad Checksum")
Had to go back to 7.4.1 to get things stable.
I do, for way smaller tables on WAN routers (CCR2004-1G-12S+2XS). Rapid memory leak and reboot in few minutes after issuing the
when using /routing/bgp/advertisements/print with where command to filter a peer, that working with no issue.
but
when using just /routing/bgp/advertisements/print, causing 100% cpu at routing & management process and memory is falling down rapidly. after lost 9Gb RAM we device to force reboot...
nobody has this issue ?
print
/routing/bgp/advertisements/print count-only
Please send or post supout.rif file. Maybe we can see a little more from the file
I have excluded all the rules of the Mangle and Raw firewall, but the connection does not work, there must be some other problems.The Wireguard interface is on the LAN listmoderator nite: no need to quote whole preceding post. Just use "Post Reply" button.
niente da fare, non funzionaNon usare le sessioni di altri dispositivi... che magari sono di versioni differenti. Seleziona su Session <none>
does not enter on winbox, blocks on that screenI do not understand where is the problem :(
We upgrade the CCR2116 to 7.6 this morning but our second BGP peer is still not coming up. When enabling the peer it starts to load some routes and then suddenly stops with the same error message as version 7.5 in the log: Write to bgp failed (32) { #buf=1 max=64 sk=Socket{ 5 a } }@miasharmse84
I had the same issue with 7.5, corrected since 7.6 beta8....
ok, I understand that, ma non ho capito perché ti ci fa ¯\_( ͡° ͜ʖ ͡°)_/¯does not enter on winbox, blocks on that screen
No.Hello, do you have any issues with RB1100AHx2 after upgrading to 7.6 from 7.5?
Hi, thank you for the confirmation.No.Hello, do you have any issues with RB1100AHx2 after upgrading to 7.6 from 7.5?
We have on duty 3x 1100AHx2 that were upgraded successfully with no issues.
Has anyone encountered a similar situation?ROS 7.6:
rb750gr3, ipv6 dhcpclient on pppoe-client can't get prefix.Tried multiple times, still doesn't work.
hap ac2 work fine.
Is there any improvement for now in v7 over v6? I mean v7 has a lot of bug fixies, but any new function? Is still v6 better, than v7?6.9? Really ... you should go up to 6.40 , good copy , jump to 6.41 which changed "a lot", then up to 6.49.x and then to 7.x
RouterOS version 7.6 is released in the "v7 stable" channel!
*) macsec - added configuration support with VLAN, ARP, DHCP and bridge tagging/untagging;
Which HW?Can someone please clarify that if i move from 6.48.6 to 7.6 for example then my download speed will be affected? Meaning that if i download a single file from the internet with a 300Mbit/s connection using lets say hap ac for that i will be downloading it around 300 Mbit/s with 6.48.6 but with 7.6 the download speed will be reduced to around ~250 ?
There are a few topics that say the speedtest results are lower due to some software architectural changes. What i want to know is that, are single file download speeds affected as well?
hap acWhich HW?Can someone please clarify that if i move from 6.48.6 to 7.6 for example then my download speed will be affected? Meaning that if i download a single file from the internet with a 300Mbit/s connection using lets say hap ac for that i will be downloading it around 300 Mbit/s with 6.48.6 but with 7.6 the download speed will be reduced to around ~250 ?
There are a few topics that say the speedtest results are lower due to some software architectural changes. What i want to know is that, are single file download speeds affected as well?
So is this a yes?Why change if the previous one is better, and you do not need any "new" feature?
It is a known bug. See also the 7.7beta topic where this is mentioned (it is not yet solved in 7.7beta either!).anybody else having issues with BGP peer "stopped"?
WinBox gui "connection" stopped, but Sessions show "Established".
commandline reports different statuses.
changing policy on the fly, refreshes, sometimes end up in "stopped".
/ip firewall filter add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related hw-offload=yes src-address-list=!GuestsNetwork
/queue simple
add max-limit=5M/5M name=WiFiGuests queue=pcq-upload-default/pcq-download-default target=10.5.50.0/24 total-queue=wireless-default
[jcrowder@csw-sundown01] > ipv6 route print
Flags: D - DYNAMIC; I, A - ACTIVE; c, o, y - COPY; H - HW-OFFLOADED
Columns: DST-ADDRESS, GATEWAY, DISTANCE
DST-ADDRESS GATEWAY DISTANCE
DAoH ::/0 fe80::1afd:74ff:fe05:6b49%bond1 110
DIoH 2001:470:4327::/64 bond1 110
DAcH 2001:470:4327::/64 bond1 0
DAoH 2001:470:4327::a/128 fe80::1afd:74ff:fe05:6b49%bond1 110
DAoH 2001:470:4327:1::/64 fe80::1afd:74ff:fe05:6b49%bond1 110
DAcH 2001:470:4327:32::/64 vlan10 0
DAcH 2001:470:4327:34::/64 vlan15 0
DAcH 2001:470:4327:62::/64 vlan255 0
DAcH fe80::%bridge/64 bridge 0
DAcH fe80::%bond1/64 bond1 0
DAcH fe80::%vlan15/64 vlan15 0
DAcH fe80::%vlan255/64 vlan255 0
DAc fe80::%vlan30/64 vlan30 0
DAcH fe80::%vlan10/64 vlan10 0
[jcrowder@csw-sundown01] >
[SUM] 0.00-10.00 sec 49.8 MBytes 41.8 Mbits/sec 4992 sender
[SUM] 0.00-10.00 sec 49.0 MBytes 41.1 Mbits/sec receiver
/system logging add topics=e-mail
/log print follow-only
# on a separate terminal, please execute the following command to send a test email
# please use an actual email address.
/tool e-mail send to=noreply@example.com subject="test" body="test"
/system logging remove [find topics="e-mail"]
Jan/02/1970 00:05:55 wireless,info XX:XX:XX:XX:XX:XX@wlan2 established connection on 5700000, SSID eduroam
Jan/02/1970 00:06:55 wireless,info XX:XX:XX:XX:XX:XX@wlan2: lost connection, 802.1x authentication timeout
Thanks for answer.
I have 7.6 on 750gr3 many days without problem.
That is not true. I have not had 3DES in the proposal for years. Maybe you need to show the relevant export of your config, but do it in aGRE tunnel between two mikrotik routers works only if default proposals contains 3DES.
If 3DES remove, then traffic does not passed.
I thought I had some error in the configuration, and decided to run a traceroute through WinBox graphics window, using a canonical name - it works. Ping (graphical) - too. But ping and traceroute to anything from the local domain from a terminal doesn't work.
When making such broad statements, please include some detail.routerOS V7.6 not shows reachable OR unreachable network details (exemple : route table)
Did you find a solution to this? I am also having an issue with the hotspot not redirecting to a custom pagein my setup hotspot not redirect to login page, if using routing mark.. goes fine in 7.2.1
I have "router was rebooted without proper shutdown by watchdog timer" at my RB3011 after upgrading from 6.49.6 to 7.6 too. It happened randomly 3 times already within 3 weeks after upgrading.I'm getting "router was rebooted without proper shutdown by watchdog timer" and "kernel failure in previous boot" on AC3 (7.6) almost every night in the middle of the night usualy between 1 and 3 PM. What could be causing this? I'm also using adguard container on this device, so free RAM is arround 67 MB. Realy strange, that reboot usualy happens when nobody is using internet.
Unless you can derive a scenario yourself (some thing you do or something externally that triggers it) the only way to hopefully get it resolved is to make a supout file as short as possible after the crash and make a support ticket where you include it.I have "router was rebooted without proper shutdown by watchdog timer" at my RB3011 after upgrading from 6.49.6 to 7.6 too. It happened randomly 3 times already within 3 weeks after upgrading.
And I wonder what could be causing this too
One thing we found out is that the best way to upgrade from 6.x to 7.x is upgrading through netinstall (do an export first, to guide You and do a backup too - in case You want to rollback), then starting over. This is only needed going from 6.x to 7.x. Upgrades from 7.x to 7.y can be done the usual way.I have "router was rebooted without proper shutdown by watchdog timer" at my RB3011 after upgrading from 6.49.6 to 7.6 too. It happened randomly 3 times already within 3 weeks after upgrading.
And I wonder what could be causing this too
Is there any documentation about it?*) macsec -
{ :local test1 do={:put "test1"} :local test2 do={:put "test2"} :local test3 do={:put "test3"} :local test4 do={:put "test4"} :local test5 do={:put "test5"} [] [] }