Community discussions

MikroTik App
 
User avatar
andrewe02000
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 74
Joined: Tue Aug 28, 2012 6:33 am
Location: Canton, OH
Contact:

What are your show stoppers for migrating to ROS7?

Tue Feb 14, 2023 8:07 pm

I am curious after looking at the results of how many devices that can be seen on Shodan that are on ROS7 as to why most in the community don't upgrade. https://www.shodan.io/search/facet?quer ... k&facet=os For me at least its mostly because of BGP route aggregation. I am just was curious what others in the community think are show stoppers for them. Thanks and route on. :)
 
User avatar
clambert
Member Candidate
Member Candidate
Posts: 161
Joined: Wed Jun 12, 2019 5:04 am

Re: What are your show stoppers for migrating to ROS7?

Tue Feb 14, 2023 9:55 pm

Mainly the non-availability of BGP attributes within a vrf. But the lack of a long-term version is another important reason.
 
User avatar
sirbryan
Member
Member
Posts: 400
Joined: Fri May 29, 2020 6:40 pm
Location: Utah
Contact:

Re: What are your show stoppers for migrating to ROS7?

Tue Feb 14, 2023 10:20 pm

I've yet to deploy it on the 802.11ad gear (wAP 60, Cubes, LHG60) because of stability issues others have mentioned on the forums, but the three Cubes I've upgraded to 7.7 have been just as stable as with 6.49.x. I think in that case, the Cube SA's are having the majority of the problems, not so much the 802.11ad models and Cube Pros.

Soon I hope to mass update my customer's hAP AC2/AC3 routers. The handful running 7 are doing just fine.
 
guipoletto
Member Candidate
Member Candidate
Posts: 201
Joined: Mon Sep 19, 2011 5:31 am

Re: What are your show stoppers for migrating to ROS7?

Tue Feb 14, 2023 10:38 pm

I have my whole network running V7

A couple RB433's protested (they didn't like having ether2 on one bridge, and ether3 on another, and the ancient IC+ switch chip mixed up the ARP tables)

other than that, a good 200 devices running V7 with some caveats

7.4 and 7.5 were stable

7.6+ introduces some problems. DNS is gone/unusable from 7.7 (but i had abolished "allow remote requests" long ago, so mostly unnafected)

My guess is that people are affraid to update because people are affraid to upgrade.
even within 6.x there are the 6.48.x faction, the 6.49.x faction, and the "i won't touch it till it dies" faction.

most of those are not proficient enough to fix their setup if something breaks (the won't touch crowd), and/or lack the time/patience to vet the migration to V7.

Plus (from what i've seen), the changes in the routing path significantly alter some failover setups (those that rely in recursive routing, for instance)
so most people are not exactly salivating on the idea of upgrading hundreds of remote locations with site-to-site+failover setups.
 
r00t
Long time Member
Long time Member
Posts: 674
Joined: Tue Nov 28, 2017 2:14 am

Re: What are your show stoppers for migrating to ROS7?

Wed Feb 15, 2023 4:26 am

My only valid reasons to upgrade are:
  • Security issue fix
  • Fix for bug in feature that's actively used
  • Significant improvement in performance of feature that's actively used
When device is doing what it should be doing, it's stable and there are no known security vulnerabilities on it, why upgrade it?
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12554
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: What are your show stoppers for migrating to ROS7?

Wed Feb 15, 2023 10:34 am

When device is doing what it should be doing, it's stable and there are no known security vulnerabilities on it, why upgrade it?
+1000
 
mducharme
Trainer
Trainer
Posts: 1777
Joined: Tue Jul 19, 2016 6:45 pm
Location: Vancouver, BC, Canada

Re: What are your show stoppers for migrating to ROS7?

Wed Feb 15, 2023 10:49 am

Our showstopper is MPLS experimental bits not yet working properly, as it has been for months. Moving to ROS 7 now would destroy our QoS completely.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: What are your show stoppers for migrating to ROS7?

Wed Feb 15, 2023 11:48 am

Mainly the problems with/around BGP:
- no BFD
- lack of a comprehensive "Peers" window that shows the current state of all BGP peers (connection active, uptime, number of prefixes, etc)
- "automatic config migration" issues (filters without explicit accept, peer update-source set to interface name)
- apparent lack of active development

(I do not use VRF, VPNv4 etc so not really affected by the problems apparently present in that area)
 
User avatar
k6ccc
Forum Guru
Forum Guru
Posts: 1579
Joined: Fri May 13, 2016 12:01 am
Location: Glendora, CA, USA (near Los Angeles)
Contact:

Re: What are your show stoppers for migrating to ROS7?

Wed Feb 15, 2023 10:54 pm

Mine is mainly me having time to learn the differences. I don't do anything overly fancy other than multiple routing tables and I understand that there are some changes there. For me, October - January is really busy for me. So some time in the next couple months I will get to it.
 
Sob
Forum Guru
Forum Guru
Posts: 9188
Joined: Mon Apr 20, 2009 9:11 pm

Re: What are your show stoppers for migrating to ROS7?

Thu Feb 16, 2023 1:26 am

At home it's 6to4 instantly crashing system (SUP-97719). I need it to work, because it's still my source of IPv6 (ISP didn't yet manage to provide native IPv6 and I don't like third party tunnels). It might be useful indicator of v7 maturity. Given its low popularity, when they fix this, they probably fixed all other more important things (ok, I know it's not guaranteed). Elsewhere it's mainly that v6 is enough, and if it works... But soon I'll probably start to upgrade some devices for Wireguard, it's not absolute must, but I like it and I've been waiting for too long already.
 
Darrel41
just joined
Posts: 2
Joined: Thu Feb 16, 2023 1:23 am

Re: What are your show stoppers for migrating to ROS7?

Thu Feb 16, 2023 1:30 am

Write a reply to this: "What are your show stoppers for migrating to ROS7?"
Hi everyone!
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 21893
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: What are your show stoppers for migrating to ROS7?

Thu Feb 16, 2023 1:35 am

Main router still v6, as I can use an RB450Gx4 for Ver7 wireguard and testing of other functionality. Will probably wait for the first long term stable of Ver7 to move main router.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 21893
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: What are your show stoppers for migrating to ROS7?

Thu Feb 16, 2023 1:37 am

{rextended} When a structure is leaning over but hasn't fallen yet, where I come from we don't fix it !!
+1000
Fixed for ya buddy!
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12554
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: What are your show stoppers for migrating to ROS7?

Thu Feb 16, 2023 1:58 am

{rextended} When a structure is leaning over but hasn't fallen yet, where I come from we don't fix it !!
+1000
Fixed for ya buddy!

:shock: :lol:
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4324
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: What are your show stoppers for migrating to ROS7?

Thu Feb 16, 2023 2:15 am

Negating the question, I'm forced to use V7 because it has MBIM. Only non-LTE devices are still V6. Now V7 does get me zerotier and let's encrypt, but I'd still be using V6 if it had MBIM. SSTP worked well enough (and still a backup to ZT in V7).

So my "theoretical showstoppers" blocking some upgrade to V7 be:

1. the lack of "dynamic-in rules". e.g. "/routing filter rule ... chain=dynamic-in" isn't available in V7.
See viewtopic.php?t=180157
The dynamic-in stuff was the better way to set "check-gateway=ping" – I love their scripting language but really don't like it on some critical path (like the DHCP client for some remote site with only LTE connection)

2. I don't deal regularly BGP, so presumably someone like the new V7 BGP scheme. I'm not sure what the problem with the BGP configuration in V6 that required inventing an entire new language for it. But the ship long sailed on this one. Obviously the lack of BFD be blocking me first if I used BGP, in this theoretical world.
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1611
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: What are your show stoppers for migrating to ROS7?

Thu Feb 16, 2023 2:43 am

At home it's 6to4 instantly crashing system (SUP-97719). I need it to work, because it's still my source of IPv6 (ISP didn't yet manage to provide native IPv6 and I don't like third party tunnels)..

Nah, we need full-cone nat first! :lol:
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: What are your show stoppers for migrating to ROS7?

Thu Feb 16, 2023 10:40 am

I'm not sure what the problem with the BGP configuration in V6 that required inventing an entire new language for it. But the ship long sailed on this one.
One nice thing about the v7 BGP is that you do not necessarily need a BGP peer configuration entry for every connected peer, especially when you setting up a central router in an organisation where many "client" routers connect and want to exchange BGP information. You can make a single connection template that services many connections. In v6 I have such setups and e.g. one has 67 BGP peers defined, each with their IP address and AS number, which probably could be reduced to one or two connection templates with v7.
However, that would not be a critical new feature for me, as for such peers I need to setup tunnels and firewall rules anyway, and I just made a large number of preconfigured BGP peers in disabled state, which I can easily enable and enter the AS number. Not a big deal for me, but maybe others have insisted on having that.
The new "routing filter" also was apparently asked for by larger customers, but I think it is not an improvement, especially as the GUI does not support it. It now is a similar situation as with scripting: you have to enter filter rules in a plain window without any syntax help. Debugging is a tedious affair. That all was so simple with v6 and for my routing filters that worked just as well.
Also, it looks like the developer of the new BGP configuration was not really familiar with MikroTik configuration language in general.

Worst of all, it looks like that developer has left. All development in this area has come to a standstill, and only some bugs are being fixed, no new features have been seen for a long time. BFD has been "a work in progress" for a year and a half. That is a bit worrying for me.
 
User avatar
StubArea51
Trainer
Trainer
Posts: 1742
Joined: Fri Aug 10, 2012 6:46 am
Location: stubarea51.net
Contact:

Re: What are your show stoppers for migrating to ROS7?

Thu Feb 16, 2023 11:03 am

We've migrated a lot of client networks to ROSv7 or to mixed ROSv6 and ROSv7 environments

A lot of it hinges on the complexity of routing in the existing network - simpler OSPF/BGP/MPLS networks seem to be running well on 7.7. Those with more complicated feature sets seem to uncover bugs faster due to "feature stacking"

Biggest show-stoppers we've encountered are:

No Long-term version
Lack of BFD
Limitations in VRF and Route Reflection
IPv6 fastpath
CCR2k gear reboots/crash (usually related to firewall rules or connection tracking)
MPLS Throughput issues (still trying to nail down the origin of this problem)
 
dot02
Member Candidate
Member Candidate
Posts: 132
Joined: Tue Jun 15, 2021 1:23 am

Re: What are your show stoppers for migrating to ROS7?

Thu Feb 16, 2023 4:30 pm

We are running on 7.5 only to have a standardised deployment across all devices, but waiting desperately for a 7.x long-term version to be released. I'd really like to know that is holding back...

I agree with r00t, as long as:
  • There are no security issues
  • the release is still officially supported
  • We don't need any for the new features (which might introduce new bugs and side-effects)
  • An upgrade would not increase performances significantly
...then I don't upgrade.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: What are your show stoppers for migrating to ROS7?

Thu Feb 16, 2023 4:47 pm

Those that want a long-term version: what is the requirement for that? It is not like the long-term version at MikroTik has some sacred status. New versions are sometimes promoted to long-term at the moment of release, without any prior field-testing. I could understand the desire to have a long-term version when it is especially well tested before being promoted, but that is not what is happening. Making enough requests for a long-term release could make them promote 7.7 to long-term. How does that help you more than deciding for yourself whether it is a good release to use?
 
User avatar
StubArea51
Trainer
Trainer
Posts: 1742
Joined: Fri Aug 10, 2012 6:46 am
Location: stubarea51.net
Contact:

Re: What are your show stoppers for migrating to ROS7?

Thu Feb 16, 2023 5:25 pm

Those that want a long-term version: what is the requirement for that?

It's definitely not a new concept in network engineering. Going back over 20 years, Cisco produced safe harbor code that turned into their "star" code for the most stable release within a major version.

Just like any other vendor, all core features (routing/switching/bridging/firewall/queuing) are proven to be stable and only bugs get patched when found until the next version of Long Term is released. This worked incredibly well for ROS v6 and we built a lot of stable networks on 6.48.6 with the confidence that it would work.

So we need feature parity with ROSv6 - when I talked with Janis on the MTU podcast, he said that was a high priority for the development team.

My take is - let's say we get feature parity by summer of 2023 - it will prob be another 2 or 3 months before a version is moved to long term imo. So long term target is prob not sooner than Q3 2023.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: What are your show stoppers for migrating to ROS7?

Thu Feb 16, 2023 6:55 pm

Those that want a long-term version: what is the requirement for that?
It's definitely not a new concept in network engineering. Going back over 20 years, Cisco produced safe harbor code that turned into their "star" code for the most stable release within a major version.
Sure, but that is not at all what a MikroTik long-term version is... that is just the previous "stable" version.
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1611
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: What are your show stoppers for migrating to ROS7?

Thu Feb 16, 2023 6:58 pm

My take is - let's say we get feature parity by summer of 2023 - it will prob be another 2 or 3 months before a version is moved to long term imo. So long term target is prob not sooner than Q3 2023.

I wouldn't be too sure about that and just like pe1chl pointed out, I suspect MT will probably follow their usual practice and drop a long-term version pretty soon after the first stable is available.

With this in mind, you really need to follow your own strict release management guidelines (and best practices) and for example wait for any numner of bug fixes during a specific time before even try to throw something from long term into production testing.

Who is online

Users browsing this forum: CGGXANNX and 23 guests