Community discussions

MikroTik App

Search found 869 matches

bytangent
Sun Jun 18, 2023 3:11 am
Forum:Announcements
Topic:v7.10 [stable] is released!
Replies:180
Views:23291

Re: v7.10 [stable] is released!

terminals only understand characters,

We’ve had F1 onANSI X3.64 compatible terminalsat least since the VT220, released in 1983. If you’re using a terminal emulator that can’t send F1, get a better terminal emulator; they’re plentiful.
bytangent
Fri Jun 02, 2023 4:21 pm
Forum:RouterBOARD hardware
Topic:Question about RB5009 rack options
Replies:7
Views:611

Re: Question about RB5009 rack options

Therack mount kit for the RB5009allows you to rack as few as one of these.
bytangent
Sun May 28, 2023 5:04 am
Forum:General
Topic:Adding veth slows internet
Replies:10
Views:492

Re: Adding veth slows internet

完整的配置:https://pastebin.com/8Y8dAuAc许多曲estions: Where's that "/ip/route/print" output I asked for? Your config is too complicated for me to reconstruct the dynamic routing rules from the static commands. Until you post what result you got from all this, my only option is to dup...
bytangent
Sat May 27, 2023 9:42 am
Forum:General
Topic:Adding veth slows internet
Replies:10
Views:492

Re: Adding veth slows internet

@fragtion: Are you using the recommended NAT-based network configuration for your containers, or are you doing as the OP is doing and binding the veth straight to the bridge? I've done the latter for justifiable cause , and it can work, but I'm using these "routers" as glorified switches, ...
bytangent
Sat May 27, 2023 6:35 am
Forum:General
Topic:Adding veth slows internet
Replies:10
Views:492

Re: Adding veth slows internet

Giventhis prior post, I’ll guess that you’ve created a routing error, sending all traffic thru the container.

Post the output of “/ip/route/print”.
bytangent
Fri May 26, 2023 8:07 am
Forum:General
Topic:NetInstall Linux
Replies:4
Views:362

Re: NetInstall Linux

It stops because you may be assigning a different static IP to each subsequent box, and so you need to pass a different -a parameter each time. (The -i alternative is a recent addition.) If each box gets the exact same config instead, such as because each one gets the variable parts via DHCP, it’s t...
bytangent
Tue May 23, 2023 9:02 am
Forum:General
Topic:Mikrotik DHCP issues
Replies:12
Views:863

Re: Mikrotik DHCP issues

something is left from before.

It’scommon configuration flotsam.
bytangent
Tue May 09, 2023 12:29 pm
Forum:General
Topic:what framework is webfig written in?
Replies:20
Views:806

Re: what framework is webfig written in?

Spectacular things are great in year 1. In year 5, when upstream development has moved on to other projects, what once looked whizzy now looks outdated, and it's barely limping by in maintenance mode. In year 10, you're hand-patching the framework merely to get it to run on modern platforms, because...
bytangent
Tue May 09, 2023 10:40 am
Forum:General
Topic:what framework is webfig written in?
Replies:20
Views:806

Re: what framework is webfig written in?

Web frameworks have a half-life of about five years. Day 1, you select the current hotness and all is well, but by the time your app sees its first decade, people are going, “You wrote it inwhat? Are youloony?
bytangent
Mon May 08, 2023 2:02 pm
Forum:General
Topic:DoH DNS redirect not working properly on ROS7.9 and Cloudflare for Family
Replies:43
Views:1797

Re: DoH DNS redirect not working properly on ROS7.9 and Cloudflare for Family

why should Quick Set require default settings? MikroTik, not being idiots, have provided sensible starting defaults. If you're asking why these sensible starting defaults aren't the same as an empty configuration, it's because an empty configuration says "do nothing," and so it does nothi...
bytangent
Sun May 07, 2023 8:30 am
Forum:Announcements
Topic:v7.9 [stable] is released!
Replies:243
Views:43455

Re: v7.9 [stable] is released!

invalid mtu 9086 on sfp-sfpplus1 from fe80::ea5c:aff:fe83:f43c fe80::/10 is the prefix for IPv6 link-local addresses, so it means one of your LAN hosts (the one that’s assigned itself that IP) is trying to use jumbo packets and is getting slapped down by the router. It’s likely harmless, since the ...
bytangent
Sat May 06, 2023 7:17 pm
Forum:Beginner Basics
Topic:HEX S sfp get very hot and causing router to overheat
Replies:7
Views:439

Re: HEX S sfp get very hot and causing router to overheat

That’s why I gave you a CLI command. Cut and paste its text output into a “[code]”block.
bytangent
Sat May 06, 2023 12:30 pm
Forum:Beginner Basics
Topic:HEX S sfp get very hot and causing router to overheat
Replies:7
Views:439

Re: HEX S sfp get very hot and causing router to overheat

You can get small stick-on heat sinks that might help, but without knowing the SFP module in question, that's nearly pure speculation. With recent versions of RouterOS 7, the hEX line regains the ability to identify SFP module details. Care to share, jhony? I'd like to see the output of… /interface/...
bytangent
Sat May 06, 2023 6:17 am
Forum:General
Topic:非常缓慢的速度与vlan
Replies:7
Views:540

Re: Very slow speeds with VLANs

iperf3 reports packet loss at the end. Is it 0%?

What happens if you switch it into UDP mode? That lets you dial in a target bandwidth, -u -b. Without TCP’s retransmission help, it will fall apart and start losing packets at some point; where?
bytangent
Fri May 05, 2023 9:48 pm
Forum:Useful user articles
Topic:NetInstall from the command line via an EL9 VM on macOS Topic is solved
Replies:6
Views:928

Re: NetInstall from the command line via an EL9 VM on macOSTopic is solved

谢谢,anav。你应该提到distincti的关键on between the two approaches: mine uses a Linux VM from the command line, whereas the other article assumes you have a Windows VM and want to use the netinstall GUI. I'm half-tempted to ask you to remove the other link, though. It ticks every item o...
bytangent
Fri May 05, 2023 10:27 am
Forum:RouterBOARD hardware
Topic:Ideal ax travel router
Replies:3
Views:355

Re: Ideal ax travel router

SFP port, while nice, will add quite a bit to the price The hEX PoE and hEX S are around the same price, and they have an SFP port. What I really want is SFP+ so each copper port has a dedicated 1G back to the core, but for a travel router, I'll give that dream up. I wouldn't expect to get these fe...
bytangent
Fri May 05, 2023 7:29 am
Forum:Announcements
Topic:v7.9 [stable] is released!
Replies:243
Views:43455

Re: v7.9 [stable] is released!

I try to pull jc21/nginx-proxy-manager on CHR CHR implies a hypervisor, so why are you using containers? Put this on a VM out on the host. I see no reason to confine this to RouterOS's emaciated "container" feature. Don't tell me it's because of efficiency. This 600 meg container is an ab...
bytangent
Fri May 05, 2023 6:34 am
Forum:RouterBOARD hardware
Topic:Ideal ax travel router
Replies:3
Views:355

Ideal ax travel router

I've spent some time playing with the new hAP ax lite and ax², and I find I want a few small changes, which will turn either one into an ideal travel router. The simplest, cheapest option is to upgrade the USB-C port on the "lite" so that it will not only accept PD at a variety of voltage ...
bytangent
Fri May 05, 2023 4:14 am
Forum:Useful user articles
Topic:NetInstall from the command line via an EL9 VM on macOS Topic is solved
Replies:6
Views:928

Re: NetInstall from the command line via an EL9 VM on macOSTopic is solved

Thanks to your prompting, I did try a dumb switch, and it did work, but that led me to the question, "Why?" I quickly tracked it down to the Trusted setting on bridge ports in my CRS328, all disabled except for the one port toward my DHCP provider. NetInstall includes a BOOTP step, which i...
bytangent
Thu May 04, 2023 4:48 am
Forum:General
Topic:Something NEEDS to be done about the default passwords
Replies:145
Views:6277

Re: Something NEEDS to be done about the default passwords

I thought it was worth cross-posting my latest RouterOS article here because it includes a method for resetting the default password on one of the new routers using netinstall-cli. It's tested and working here. There are subtleties, but if you have a default configuration you want to apply anyway, y...
bytangent
Thu May 04, 2023 4:39 am
Forum:Useful user articles
Topic:NetInstall from the command line via an EL9 VM on macOS Topic is solved
Replies:6
Views:928

NetInstall from the command line via an EL9 VM on macOSTopic is solved

I've just worked through all the subtleties and published themhere.

Enjoy!
bytangent
Thu May 04, 2023 1:56 am
Forum:Beginner Basics
Topic:IGMP/PIM with Sonos [SOLVED]
Replies:3
Views:532

Re: IGMP/PIM with Sonos[SOLVED]

ROS 7 merged a bunch of packages into the main one , including “multicast.npk”. If it were not so, CLI menus like "/routing/pimsm" wouldn't exist until you installed the optional package. Note that routing-related features got a complete overhaul in ROS 7, so your referenced post from 201...
bytangent
Thu May 04, 2023 1:47 am
Forum:General
Topic:SFP Module Speeds 1.2Gb / 2.4Gb
Replies:5
Views:318

Re: SFP Module Speeds 1.2Gb / 2.4Gb

Relevant threadshereandhere.
bytangent
Sun Apr 30, 2023 1:01 am
Forum:RouterBOARD hardware
Topic:帮助网络设计和选择合适的公关oducts
Replies:11
Views:1293

Re: Help with Network design and choosing the right products

Fritzbox -> rb5009 -> switch ? I already argued against back-to-back routers above. To address your broader question, the cameras can go anywhere else on the LAN; that's one of the things VLANs give you. Presumably each camera is nearer one of the PoE switches than another, so that would set your b...
bytangent
Sat Apr 29, 2023 9:40 am
Forum:General
Topic:Something NEEDS to be done about the default passwords
Replies:145
Views:6277

Re: Something NEEDS to be done about the default passwords

Forget OCR and all the associated issues (highly inaccurate for one) Ever heard of the Dunning-Kruger effect ? OCR has been used in critical real-time industry-scale applications for decades. For computer-printed text, it's a solved problem, to the extent that researchers have been focusing on hand...
bytangent
Thu Apr 27, 2023 4:29 am
Forum:General
Topic:Something NEEDS to be done about the default passwords
Replies:145
Views:6277

Re: Something NEEDS to be done about the default passwords

never knew they added a reset button straight to netinstall function, that didn't exist when I started using netinstall

I traced it back as far asFebruary 2020, in RouterOS 6.
bytangent
Wed Apr 26, 2023 12:14 am
Forum:Containers
Topic:RB5009 Hello World
Replies:10
Views:956

Re: RB5009 Hello World

I'm pretty sure he means 7.10beta, whenever that appears.
bytangent
Mon Apr 24, 2023 5:48 am
Forum:General
Topic:Something NEEDS to be done about the default passwords
Replies:145
Views:6277

Re: Something NEEDS to be done about the default passwords

I assume your "attack senario" is something like the following: Partly, but I'm taking the OP's prior statements into account, where he's apparently in charge of a WISP that's taken over other smaller WISPs and now needs to take control of all the equipment they left behind and to do it w...
bytangent
Mon Apr 24, 2023 4:22 am
Forum:General
Topic:Something NEEDS to be done about the default passwords
Replies:145
Views:6277

Re: Something NEEDS to be done about the default passwords

the device is essentially inoperable as a network device until the user intervenes and is forced to not just leave it with default credentials. Hang on a sec. Your plan is to have a mode where someone remote can blank out the configuration and provide a new one, including a new non-empty password, ...
bytangent
Sat Apr 22, 2023 4:14 pm
Forum:RouterBOARD hardware
Topic:帮助网络设计和选择合适的公关oducts
Replies:11
Views:1293

Re: Help with Network design and choosing the right products

Mikrotik RB5009UPr+S+IN as my main router I don't see why you want that model given that you have an Internet router already — the FritzBox — and you want to add a PoE switch. If it were me designing it, I'd move the PoE role to a separate switch, then either choose the non-PoE model of the 5009 an...
bytangent
Thu Apr 20, 2023 5:37 pm
Forum:General
Topic:Something NEEDS to be done about the default passwords
Replies:145
Views:6277

Re: Something NEEDS to be done about the default passwords

the idea of netinstall is terrible because…it's no better than a randomized password as that gear is unserviceable to anyone other than you and your company Someone else's password is as good as random already. Or that's the idea, anyway, since the alternative is that you can guess the password, wh...
bytangent
Thu Apr 20, 2023 2:29 am
Forum:General
Topic:Something NEEDS to be done about the default passwords
Replies:145
Views:6277

Re: Something NEEDS to be done about the default passwords

netinstall is not always an option…you aren't configuring them all in the same physical location You know what we need to fix that problem? A global network that will let us coordinate data across multiple sites, each with their own local network, like an inter-network kind of thing. Hey, I know, w...
bytangent
Wed Apr 19, 2023 4:29 pm
Forum:General
Topic:Something NEEDS to be done about the default passwords
Replies:145
Views:6277

Re: Something NEEDS to be done about the default passwords

The Llama MT Password Reading Magnifying Glass!! You joke, but while I do have solutions to that problem, they all suck: The benchtop illuminated magnifier with auxiliary lens I bought for micro-soldering works great for reading the new password labels, but only when I'm in my lab, it being clamped...
bytangent
Wed Apr 19, 2023 3:25 pm
Forum:General
Topic:Something NEEDS to be done about the default passwords
Replies:145
Views:6277

Re: Something NEEDS to be done about the default passwords

所以是什么problem with random 4 letters as a suffix to the part of serial number .. which is different as well each time ... as a default password? Extending the serial number might be okay, depending on how difficult it is to make the router give it up over a LAN link. The only measure I'm aw...
bytangent
Mon Apr 17, 2023 2:31 pm
Forum:RouterBOARD hardware
Topic:hAP ax lite
Replies:76
Views:6902

Re: hAP ax lite

DELETED
bytangent
Mon Apr 17, 2023 10:20 am
Forum:RouterBOARD hardware
Topic:hAP ax lite
Replies:76
Views:6902

Re: hAP ax lite

4 ports on AX Lite or 5 for AX2 / AX3, that's only 1 port difference ? That fifth port amounts to a big difference if you need PoE. The ax² has PoE in and out, while the "lite" has no PoE at all. Lack of PoE output falls out of the very different powering options between these two: the US...
bytangent
Thu Apr 13, 2023 4:28 pm
Forum:Containers
Topic:RB5009 Hello World
Replies:10
Views:956

Re: RB5009 Hello World

…"it silently fails to start"…Mikrotik said they would fix this You don't need to tell me. I'm the one who diagnosed the empty directory issue and reported it to MikroTik. :) And that is why I was able to build the "tangentsoft/echo:latest" container for you. ARM64 is powerful e...
bytangent
Thu Apr 13, 2023 3:28 pm
Forum:Containers
Topic:RB5009 Hello World
Replies:10
Views:956

Re: RB5009 Hello World

/container/add remote-image=hello-world:latest root-dir=hello interface=veth1 logging=yes … status remains stopped. Of course the status is "stopped." It runs, prints out its "hello, world" message, then stops. That's what that container does. And that's all it does. That isn't ...
bytangent
Thu Apr 13, 2023 1:47 pm
Forum:Announcements
Topic:v7.9rc is released!
Replies:253
Views:64032

Re: v7.9rc is released!

This is due to change in dockerhub. …and a good one, since it means we're moving toward a world of standards-based container tech, which will help break Docker, Inc's hold on this key technology. The day RouterOS goes fully OCI-compliant will be a great day. Multiple workarounds are already posted ...
bytangent
Wed Apr 12, 2023 5:21 pm
Forum:Containers
Topic:How can I bind a container straight to the bridge? Topic is solved
Replies:10
Views:788

Re: How can I bind a container straight to the bridge?Topic is solved

I filed the suggestion, and MikroTik says they'll think about changing the behavior. In other news, I have a more complete set of test results up now. I was surprised at the 29% best-case margin between the hAP ax lite and the ax². I thought it'd be more nearly night-and-day due to the 64-bit CPU an...
bytangent
Wed Apr 12, 2023 1:13 pm
Forum:General
Topic:Is it possible to set up a UDP broadcast relay on RouterOS?
Replies:9
Views:1798

Re: Is it possible to set up a UDP broadcast relay on RouterOS?

Since you're quoting me, I suppose you're hoping that I've developed this into a cookie-cutter solution in the meantime? Sorry, I have no interest in doing so. I don't own any UniFi gear. I was approaching it as a practical puzzle, not as a problem I had to solve for personal reasons. How about this...
bytangent
Tue Apr 11, 2023 10:17 am
Forum:Containers
Topic:How can I bind a container straight to the bridge? Topic is solved
Replies:10
Views:788

Re: How can I bind a container straight to the bridge?Topic is solved

Thanks again, Amm0. I'll stick with static IP on this switch. It is, after all, core infrastructure. I just thought I'd be cute and allow whole network re-IPing by using DHCP as much as possible. I've been made to change my subnet more than once over the years. What I really want is for RouterOS to ...
bytangent
Tue Apr 11, 2023 3:48 am
Forum:General
Topic:Aggregate SFP+ fiber [SOLVED]
Replies:2
Views:240

Re: Aggregate SFP+ fiber[SOLVED]

I'm somewhat confused by what you're expecting to get out of this. You have trouble reading words in manuals written by professional technical writers, but you expect you'll have better luck with words written by networking geeks who like as not don't even speak English as a first language on a web ...
bytangent
Tue Apr 11, 2023 3:40 am
Forum:Containers
Topic:How can I bind a container straight to the bridge? Topic is solved
Replies:10
Views:788

Re: How can I bind a container straight to the bridge?Topic is solved

For the archives, there's a potential problem with doing this: by putting the veth into the bridge, it participates in ROS's logic for deciding what MAC to give the bridge. I don't understand its rules, but I do know that in one test of this here, it ended up giving my bridge a different random MAC ...
bytangent
Tue Apr 04, 2023 12:52 am
Forum:Containers
Topic:Small iperf3 container
Replies:6
Views:510

Re: Small iperf3 container

Next step: try it on the CRS328, with its piddlin' 16 megs of flash.

Womp, womp: 356 Mbit/sec with 4 parallel streams.

I guess that's what I get for using an 800 MHz ARM CPU for traffic generation.

Well, at least it runs.
bytangent
Tue Apr 04, 2023 12:11 am
Forum:Containers
Topic:Small iperf3 container
Replies:6
Views:510

Re: Small iperf3 container

Yes, thank you, @Larsa. These are the principles I was expounding on in the mDNS repeater thread. Between what you see on trunk in my Fossil now andthe removed setcap stuff, I do think one could get that container under a meg.

Once again, not my itch, but the code's there for the taking now.
bytangent
Mon Apr 03, 2023 11:28 pm
Forum:Containers
Topic:Small iperf3 container
Replies:6
Views:510

Re: Small iperf3 container

In completely separate news , I figured out what the Alpine layer was adding that allowed the container to start on ROS: it won't create the /dev, /proc, /run, or /sys mount points for you. If any single one of those is missing, it will unpack successfully, but then silently fail to start. Between t...
bytangent
Mon Apr 03, 2023 11:24 pm
Forum:Containers
Topic:Small iperf3 container
Replies:6
Views:510

Re: Small iperf3 container

less than 5MB It's closer to seven megs unpacked: $ docker create --name foo --platform linux/arm64 taoyou/iperf3-alpine $ docker export foo | pv -b > /dev/null 6.97MiB (pv is the PipeViewer tool.) You might want to be aware that this line at the top of the taoyou container's Dockerfile switches th...
bytangent
Mon Apr 03, 2023 5:19 am
Forum:Containers
Topic:How can I bind a container straight to the bridge? Topic is solved
Replies:10
Views:788

Re: How can I bind a container straight to the bridge?Topic is solved

the bridge will use ARP to figure that out. That's what I thought, and I'm certain I tried something like that. Simply removing the IP from the bridge and restarting the container didn't help. I had to reboot the router to get it working. I guess there was stale routing information in there or some...
bytangent
Mon Apr 03, 2023 4:44 am
Forum:Containers
Topic:How can I bind a container straight to the bridge? Topic is solved
Replies:10
Views:788

How can I bind a container straight to the bridge?Topic is solved

In support of another project , I was trying to avoid the NAT layer in the standard container setup . I succeeded in adding veth1 straight to the single hardware bridge, avoiding the software "docker" bridge that MT recommends in their docs, but where I failed is in giving it an IP address...
bytangent
Mon Apr 03, 2023 4:30 am
Forum:Containers
Topic:Small iperf3 container
Replies:6
Views:510

Small iperf3 container

我一直在寻求使最小的iperf3 container for RouterOS. This constitutes weekend entertainment for me. What can I say; I nerd hard. What I have so far is here . If you've got 0.2 megs to spare on your router, give it a spin. I'm getting 3.3 Gbit/sec test results to my RB4011 runni...
bytangent
Fri Mar 31, 2023 5:34 pm
Forum:General
Topic:Feature Request: Ed25519 SSH keys
Replies:49
Views:14185

Re: Feature Request: Ed25519 SSH keys

That's only the host key part. It doesn't let you set up pre-shared ed25519 keys per user.

One hopes the latter piece is coming later in the 7.9 beta process.
bytangent
Wed Mar 29, 2023 6:42 pm
Forum:Beginner Basics
Topic:Winbox for M1 [SOLVED]
Replies:31
Views:16441

Re: Winbox for M1[SOLVED]

Official Wine64 from official repository Then you should be pointing people here , not at the personal GitHub repository of Dean M Greer, alias Gcenx, who merely happens to be the current macOS port maintainer for Wine. Or, you could point people here , the macOS page in the official Wine Wiki, whe...
bytangent
Wed Mar 29, 2023 5:45 am
Forum:Beginner Basics
Topic:Winbox for M1 [SOLVED]
Replies:31
Views:16441

Re: Winbox for M1[SOLVED]

@tangent, I think we're making the same point :) I don't, because "hashes" prove nothing unless you trust the source of the hashes. If the hashes come from the same source a the packages, why are you trusting the hashes to prove the trustworthiness of the packages? At best, all checking S...
bytangent
Wed Mar 29, 2023 4:33 am
Forum:Beginner Basics
Topic:Winbox for M1 [SOLVED]
Replies:31
Views:16441

Re: Winbox for M1[SOLVED]

It does check hashes automatically. Not quite my point. By " unimpeachable ," I mean that Homebrew has a track record of many years of providing trustworthy packages, and they've got a a reasonable governance model to protect that reputation. If anyone ever did push something harmful into...
bytangent
Wed Mar 29, 2023 4:02 am
Forum:Beginner Basics
Topic:Winbox for M1 [SOLVED]
Replies:31
Views:16441

Re: Winbox for M1[SOLVED]

So what's the difference with auditable public GitHub project that redistributed by brew? Not only is Homebrew all but unimpeachable as a source of trustworthy binaries, the same source of those tarballs Normis is recommending we use instead has a "How to Install Wine on Mac" guide that t...
bytangent
Tue Mar 28, 2023 4:43 pm
Forum:RouterOS beta and rc versions
Topic:mDNS repeater feature
Replies:299
Views:68948

Re: mDNS repeater feature

Lean and mean, I like! Yeah, especially since its closest competition is something like Gitlab CE , at 1.25 GB (gigabytes!) compressed, and something like 4 gigs when running. I get that it does more, but I dare say a whole lot of GitLab users could get by just fine with Fossil. This thread inspire...
bytangent
Tue Mar 28, 2023 4:13 pm
Forum:RouterOS beta and rc versions
Topic:mDNS repeater feature
Replies:299
Views:68948

Re: mDNS repeater feature

Perhaps I'm misunderstanding you I'm saying use both: Alpine in the first stage to install the necessary build tools and run "gcc -static mdns_repeater.c -o mdns_repeater", then "FROM scratch" to copy that binary into the actual container, resulting in something more on the orde...
bytangent
Tue Mar 28, 2023 3:57 pm
Forum:RouterOS beta and rc versions
Topic:mDNS repeater feature
Replies:299
Views:68948

Re: mDNS repeater feature

Alpine Linux is a very lean and productive platform For the first (builder) stage, sure, but I think it's possible to get the second stage down to "FROM busybox" or, better, "FROM scratch", leaving only a single statically linked binary inside the container. Whether it's 100k as...
bytangent
Tue Mar 28, 2023 3:54 pm
Forum:General
Topic:Run a script with external device (but without another platform)
Replies:15
Views:614

Re: Run a script with external device (but without another platform)

While you're right that the OP asked for remote DHCP renew, not reboot, rebooting the router would probably do what the OP actually wants. The nice thing about that method is that there's a dedicated user policy for that. It's always dangerous to assume that the client knows what they want and can p...
bytangent
Tue Mar 28, 2023 3:20 pm
Forum:General
Topic:Run a script with external device (but without another platform)
Replies:15
Views:614

Re: Run a script with external device (but without another platform)

create also separate user with read group Better, create a new group with only the "reboot" policy enabled. assign script owner to that user. There shouldn't be any need for custom RSC scripting on the RouterOS side. SSH lets you send the "/system/reboot" command string directly...
bytangent
Tue Mar 28, 2023 3:10 pm
Forum:RouterOS beta and rc versions
Topic:mDNS repeater feature
Replies:299
Views:68948

Re: mDNS repeater feature

i created an extended container image That's a very fine contribution. However, it looks like the upstream container could be trimmed down considerably: The run.sh script seems entirely superfluous. Look at the last line: all it does is pass its input parameters (given as CMD in the Dockerfile) to ...
bytangent
Tue Mar 28, 2023 2:44 pm
Forum:General
Topic:Run a script with external device (but without another platform)
Replies:15
Views:614

Re: Run a script with external device (but without another platform)

Generic Android SSH clients will expose you to the same risk of misconfiguration.

If you need an Android app that does nothing but reboot a remote router, offering zero other functionality, I fear you're going to have to write it yourself.
bytangent
Tue Mar 28, 2023 2:22 pm
Forum:General
Topic:Run a script with external device (but without another platform)
Replies:15
Views:614

Re: Run a script with external device (but without another platform)

Container…I'm using now a mipsbe RB750r2 RouterOS's container feature doesn't run on MIPS devices today and likely never will . SSH over Cgi request: cool, but it needs an external server (ok, it's available), an active internet connection, a public IP, expose port 22 to interent, Interesting but n...
bytangent
Sat Mar 25, 2023 4:54 pm
Forum:General
Topic:Run a script with external device (but without another platform)
Replies:15
Views:614

Re: Run a script with external device (but without another platform)

command by SSH: do you know if there is any app that can do it by a button? If it suffices to double-click the icon and wait for it to do its work, with no need any explicit feedback on the command's success or failure, your OS GUI of choice should have a way to launch any SSH command you like. Wit...
bytangent
2023年坐3月25日一14点
Forum:RouterOS beta and rc versions
Topic:mDNS repeater feature
Replies:299
Views:68948

Re: mDNS repeater feature

Wrong. 239.0.0.0/8 are defined to be per interface in RFC2365, so there no need to look at mDNS RFCs. Wrong argument. The same you could say about IGMP proxy - so no need to look for IGMP RFCs. Yes. All that RFC means is that the packets in that IP range don't automatically flow from one network to...
bytangent
Sat Mar 25, 2023 12:18 pm
Forum:SwOS
Topic:CSS610-8G-2S+IN
Replies:4
Views:774

Re: CSS610-8G-2S+IN

30$ more will get you 3x more ports and a better SWOS Or you can spend less and get less. Funny, that. The differences go beyond those two points , though. If I were in the CSS market — and I'm not; CRS for me, all the way — the option to have a modern platform in half the width with a wider PoE ra...
bytangent
Sun Mar 19, 2023 10:45 am
Forum:Containers
Topic:configuration of applications running in containers
Replies:1
Views:237

Re: configuration of applications running in containers

I suspect you've been caught by the disk renaming stuff in 7.7 and 7.8, so the old config no longer mounts the intended disk. The files are therefore ending up inside the container, not out in external storage. Rebuilding the container with proper ROS 7.8 disk names will solve it. If you absolutely ...
bytangent
Mon Mar 13, 2023 4:49 pm
Forum:RouterBOARD hardware
Topic:Mikrotik RouterBoard suitable for a ESXi Network?
Replies:3
Views:462

Re: Mikrotik RouterBoard suitable for a ESXi Network?

I have extensively researched… I wouldn't use the word "extensive" until I had the answer to the question you pose already in hand. Instead, you've got a question so vaguely posed it makes me doubt you've done more than a preliminary survey of the available options. You don't even name th...
bytangent
Thu Mar 02, 2023 5:07 am
Forum:Containers
Topic:I cannot add container because of error
Replies:2
Views:514

Re: I cannot add container because of error

The “lost+found” directory is wherefsckputs damaged file fragments when it detects data corruption. Files placed there aren’t meant to be used as-is.

Container images being what they are, there’s zero reason to try recovering a damaged file. Just go download the immutable image again.
bytangent
Sat Feb 25, 2023 1:24 am
Forum:Wireless Networking
Topic:Mesh and Multicast
Replies:3
Views:605

Re: Mesh and Multicast

OK.. not sure if you read my post tbh... As for myself, I believe you're depending on us to read your mind for all of the details you've left unstated, yet which are perfectly clear inside your own mind. :) I have no 'preconceptions' A single shared IP space across multiple networks absolutely does...
bytangent
Wed Feb 22, 2023 1:50 am
Forum:General
Topic:CRS326-24S+2Q+ : 100% CPU utilization bridging when a port goes up or down
Replies:9
Views:862

Re: CRS326-24S+2Q+ : 100% CPU utilization bridging when a port goes up or down

This feels like a bug in the layer that translates generic ROS configuration rules into specific switch chip programming commands. You’ve done a great job of diagnosing it as far as you can from the user level. It’s time to report it to MT support. Best distill the essential info into the actual rep...
bytangent
Fri Feb 10, 2023 11:47 pm
Forum:Wireless Networking
Topic:Mesh and Multicast
Replies:3
Views:605

Re: Mesh and Multicast

I'm trying to figure out the best way Your question reads as if you believe you've already come up with "the best way" and are now trying to arm-twist the universe into conforming. Let go of your preconceptions! multiple separate networks sharing multicast You don't come right out and say...
bytangent
Tue Feb 07, 2023 10:26 pm
Forum:Beginner Basics
Topic:Docker? Does anybody use it?
Replies:16
Views:1741

Re: Docker? Does anybody use it?

it is running a whole other operating system Containers share the kernel of the host, so it isn't a whole-other anything. Containers don't run without the host's kernel to handle the syscalls of the binaries inside. This is why Docker for macOS and Windows have to maintain a hidden Linux VM in the ...
bytangent
Sun Jan 22, 2023 11:50 pm
Forum:Announcements
Topic:v7.8beta [testing] is released!
Replies:306
Views:57120

Re: v7.8beta [testing] is released!

Any MIPS devices with more than 16MB of storage? With a little sorting on the product matrix , I count 32 products. Compressing it to product families , we get: BaseBox 2, 5, 6 CRS109-8G-1S-2HnD-IN CRS125-24G-1S-2HnD-IN KNOT LR8 & LR9 kits mANTBox 15s & 19s; mANTBox 2 12s NetBox 5 NetMetal ...
bytangent
Sun Jan 22, 2023 9:43 pm
Forum:Announcements
Topic:v7.8beta [testing] is released!
Replies:306
Views:57120

Re: v7.8beta [testing] is released!

new "rose-storage"…ARM, ARM64, Tile and x86 Several comments: The clients should be added to MIPS, since they need network storage the worst of all machine types. I don't care whether it's SMB, NFS, iSCSI, or nVME-over-TCP, all four, or some subset, but something would be welcome. I can l...
bytangent
Thu Jan 19, 2023 12:28 am
Forum:General
Topic:IPTV with IGMPProxy stopping after 4:30 minutes
Replies:4
Views:1299

Re: IPTV with IGMPProxy stopping after 4:30 minutes

It sounds like they’re using anIGMP querierto pinch off “unwanted” streams and you’re either blocking those requests or preventing the replies from getting back out.

Open IGMP to your WAN port.
bytangent
Mon Jan 16, 2023 6:47 am
Forum:Containers
Topic:Container crashes randomly
Replies:9
Views:1226

Re: Container crashes randomly

I don’t know what’s up with your container, but I do know enough to be confident that you’re thread-jacking. What you’ve got going on has nothing to do with the OP’s problems in this thread.
bytangent
Sun Jan 15, 2023 3:00 am
Forum:RouterBOARD hardware
Topic:Any Chance for a CRS610-8P-2S+IN
Replies:7
Views:801

Re: Any Chance for a CRS610-8P-2S+IN

The lack of TLS and SSH in SwOS is a deal-killer for me.

MikroTik, this proposed CRS610 is pretty much the product I was wanting back when I got into RouterOS. At the time, the closest thing available was a CRS328-24P, which is massively overkill for my purposes.
bytangent
Sat Jan 14, 2023 7:26 pm
Forum:General
Topic:802.1x (ethernet) Questions
Replies:9
Views:2019

Re: 802.1x (ethernet) Questions

RouterOS 7.2 was current when this thread was started, but while there have been several "dot1x" items in the changelog through 7.7, the current stable version, none advertise a feature you might call "allow only authenticated devices." Therefore, why would you expect that 802.1x...
bytangent
Sat Jan 14, 2023 5:21 am
Forum:Beginner Basics
Topic:Help in analyzing new setup [SOLVED]
Replies:3
Views:425

Re: Help in analyzing new setup[SOLVED]

I don’t see “/ip dhcp-server network gateway=…”
bytangent
Sat Jan 14, 2023 4:19 am
Forum:Beginner Basics
Topic:Which documentation is up-to-date: Wiki Vs. Help [SOLVED]
Replies:7
Views:643

Re: Which documentation is up-to-date: Wiki Vs. Help[SOLVED]

As a rule, the old wiki for RouterOS 6, and the new help site for 7.

Rarely, something hasn’t been moved over to the new site yet, so the wiki will end up more helpful with v7. The incidence of this can be expected to drop over time.
bytangent
Fri Jan 13, 2023 8:29 pm
Forum:General
Topic:Blacklisted Device by Mikrotik ?
Replies:5
Views:500

Re: Blacklisted Device by Mikrotik ?

is this a copy/counterfeint? The only way I think someone who isn't a MikroTik EE could know that is for you to post high-res pictures of both sides of the PCB, then hope someone else here with the same device — which you should identify explicitly, rather than make us guess — is interested enough ...
bytangent
Sun Jan 08, 2023 8:31 pm
Forum:General
Topic:UDP attack from LAN network [SOLVED]
Replies:28
Views:2121

Re: UDP attack from LAN network [SOLVED]

I'm not talking about taxable asset depreciation, and I didn't tell you you had to replace everything on the 3-5 year business amortization schedule. I'm saying that you should structure your business to have the capital equipment paid off in that time, so that if you do have to replace it, you aren...
bytangent
Sun Jan 08, 2023 6:25 pm
Forum:General
Topic:UDP attack from LAN network [SOLVED]
Replies:28
Views:2121

Re: UDP attack from LAN network [SOLVED]

I don't get any extra income from upgrading IPv6 onto that old network Do your customers agree that their ongoing subscription costs go to pay for badly-outdated technology? if they want to upgrade to IPv6 I will upgrade them at there cost. Why would one customer have to bear the entire cost of upg...
bytangent
Sun Jan 08, 2023 1:22 pm
Forum:General
Topic:UDP attack from LAN network [SOLVED]
Replies:28
Views:2121

Re: UDP attack from LAN network [Solved]

old legacy equipment which has it's own routing, bridges, spanning trees and management networks. Bridges pass Ethernet frames. They don't care about IPv4 vs IPv6. (Or IPX, or DECnet, or…) Some bridging implementations allow assigning an IP for management purposes, including RouterOS's, but having ...
bytangent
Sun Jan 08, 2023 1:01 am
Forum:General
Topic:UDP attack from LAN network [SOLVED]
Replies:28
Views:2121

Re: UDP attack from LAN network

Even if I could get IPV6 space There's no "if" about it. You can. You just haven't, yet. many of my RF and Fibre Links can't carry it because the equipment doesn't support it. Seriously? Name and shame, please. IPv6 is now literally decades old. What equipment are you using that is that f...
bytangent
Sat Jan 07, 2023 11:24 pm
Forum:General
Topic:UDP attack from LAN network [SOLVED]
Replies:28
Views:2121

Re: UDP attack from LAN network

>>>> I don't OWN any IP range in IPV6 It's currently free to get a /40 or smaller from ARIN if you already have a v4 block from them. If you're elsewhere in the world, governed by a different addressing authority, there's likely a similar policy. You might not even have to go through that bit of bu...
bytangent
Sat Jan 07, 2023 6:47 pm
Forum:General
Topic:UDP attack from LAN network [SOLVED]
Replies:28
Views:2121

Re: UDP attack from LAN network

The clients have IPV6 ethernet cards That's highly unlikely. In the vast majority of Internet-connected hosts, IPv6 is part of the OS kernel. The primary exception is if you have high-end network interfaces with TCP offloading . Otherwise, IPv6 is well above the level of the "Ethernet card,&qu...
bytangent
Fri Jan 06, 2023 12:38 am
Forum:Announcements
Topic:v7.7rc is released!
Replies:259
Views:76223

Re: v7.7rc is released!

What other info do you require to solve this? A trace of a run of the app with working DNS resolver? While the actual RouterOS developers would be in a better position to answer that than me, given that you cannot provide a reproducing test case, I'd expect a solid second-best to be: With 7.7rc3, c...
bytangent
Mon Jan 02, 2023 6:27 am
Forum:General
Topic:UDP attack from LAN network [SOLVED]
Replies:28
Views:2121

Re: UDP attack from LAN network

Use Torch to find the source MAC address. If it hasn’t been spoofed (as that 0.0.0.0 source IP has) it’ll guide you to the matching VM configuration.

If the malware is smart enough and deeply enough dug into your systems that it can spoof the MAC, too, then it sucks to be you today.Sorry.
bytangent
Sun Jan 01, 2023 11:09 pm
Forum:RouterOS beta and rc versions
Topic:mDNS repeater feature
Replies:299
Views:68948

Re: mDNS repeater feature

a simple tutorial

Already done.
bytangent
Sun Jan 01, 2023 1:00 am
Forum:RouterOS beta and rc versions
Topic:mDNS repeater feature
Replies:299
Views:68948

Re: mDNS repeater feature

Here's another: screen-sharing to conference room displays. The plan to put a bad-ass LED wall in the boardroom might give the CEO a fuzzy, but if you tell him he can't have it because there's a Chinese ODM board at the heart of it that's as full of holes as a block of Jarlsberg, he's gonna buy the ...
bytangent
Sun Jan 01, 2023 12:43 am
Forum:RouterOS beta and rc versions
Topic:mDNS repeater feature
Replies:299
Views:68948

Re: mDNS repeater feature

it's a lot of work, for what they think are "questionable" use cases. There are far better use cases. Here's one: AirPrint in a corporate environment. It's convenient in BYOD shops to let people print from their iPhones or whatever, but if you think printers that haven't received firmware...
bytangent
Sun Jan 01, 2023 12:21 am
Forum:RouterOS beta and rc versions
Topic:mDNS repeater feature
Replies:299
Views:68948

Re: mDNS repeater feature

Did you buy something that you can run a container on? If not then yes you’re going to regret this purchase. I'm not certain about that. I still think this approach is worth trying. If you're wondering why I don't try it and report back, it's because on the networks I manage that have mDNS devices,...
bytangent
Sun Jan 01, 2023 12:16 am
Forum:RouterOS beta and rc versions
Topic:mDNS repeater feature
Replies:299
Views:68948

Re: mDNS repeater feature

using the security card isn't a valid excuse I think I might be one of the most likely of this forum's members to go around waving the "security" flag, and even I will tell you that a flat refusal to support mDNS forwarding on security grounds is bogus. mDNS forwarding is a routing decisi...
bytangent
Sat Dec 31, 2022 3:46 am
Forum:General
Topic:Getting up on my soapbox...
Replies:7
Views:736

Re: Getting up on my soapbox...

spending thousands and thousands of dollars…with zero monitoring. Simple answer: you aren't paying for monitoring. The money's going into other things, which some of us find more valuable. The interface absolutely sucks. Oh, I've seen a lot worse, but sure, I'll grant that there are prettier things...
bytangent
Fri Dec 30, 2022 5:19 pm
Forum:RouterOS beta and rc versions
Topic:WG tunnel UDP is 5x faster than TCP
Replies:19
Views:2153

Re: WG tunnel UDP is 5x faster than TCP

You’re mixing two separate issues. CPU usage involved with on-device bandwidth test, and TCP vs UDP. They’re entirely orthogonal. TCP isn’t slow because of the CPU. It’s slow because TCP-in-TCP is always bad, on all CPUs, everywhere.
bytangent
Wed Dec 28, 2022 10:57 am
Forum:Beginner Basics
Topic:Subnet conflict using DHCP Client
Replies:1
Views:215

Re: Subnet conflict using DHCP Client

Yes, you have to change it. Routing rules that try to say "from 192.168.1.0/24 to 192.168.1.0/24" will result either in loops or dead-ends. The only way this is difficult is if you haven't got DNS set up locally and have a bunch of references to raw IPs. If everyone's referring to hosts by...
bytangent
Wed Dec 28, 2022 7:53 am
Forum:General
Topic:Severe port flapping on CRS328-24P-4S+ and CRS317-1G-16S+
Replies:213
Views:63911

Re: Severe port flapping on CRS328-24P-4S+ and CRS317-1G-16S+

CRS328-24P <-> CRS312 with 1m Mikrotik DAC, port flapping every 2 hours. both switch running Stable 7.6 Please don't hijack unrelated threads. We are clearly not talking about cases like yours here. That should be obvious even to a newbie: nowhere in the world does "every 2 hours" qualify...
bytangent
Tue Dec 20, 2022 6:14 pm
Forum:SwOS
Topic:CRS309-1G-8S+ No link till reboot.
Replies:10
Views:1063

Re: CRS309-1G-8S+ No link till reboot.

Nothing jumps out at me, and if I may judge from the silence of others, at anyone else, either. If you were running RouterOS, I’d next suggest posting the sanitized configuration and the logs you get on connection. Since you aren’t, my advice is to switch to RouterOS. If that doesn’t clear things up...
bytangent
Tue Dec 20, 2022 4:57 am
Forum:SwOS
Topic:CRS309-1G-8S+ No link till reboot.
Replies:10
Views:1063

Re: CRS309-1G-8S+ No link till reboot.

If you knew what mattered here, you’d have the problem solved already. How about you take a step back and accept that you’re here for another perspective. If I ask you for something you didn’t think to provide, that’s your alternative perspective, right there.
bytangent
Tue Dec 20, 2022 4:35 am
Forum:SwOS
Topic:CRS309-1G-8S+ No link till reboot.
Replies:10
Views:1063

Re: CRS309-1G-8S+ No link till reboot.

I ask for the unusual pieces of your environment, and you give me the boring elements most proximate to your switch? Are youtryingto be difficult?

Unusual = not the things everyone else here is using.

Environment = complete surroundings.

Try drawing a network map.
bytangent
Tue Dec 20, 2022 3:12 am
Forum:SwOS
Topic:CRS309-1G-8S+ No link till reboot.
Replies:10
Views:1063

Re: CRS309-1G-8S+ No link till reboot.

The implication is that this isn’t happening to anyone else.

So, what’s unusual about your environment? If the problem isn’t internal to the device…
bytangent
Sun Dec 18, 2022 12:05 am
Forum:Containers
Topic:Looking for Docker container ideas for RouterOS
Replies:121
Views:18117

Re: Looking for Docker container ideas for RouterOS

The "buildx build" vs "build" distinction doesn't matter. If the old image builder works, so will the new one. If you need the new one (buildx) to get some feature not available in the old one, then use the new one. The platform name differences aren't important. The container bu...
bytangent
Sat Dec 17, 2022 10:55 pm
Forum:Containers
Topic:Looking for Docker container ideas for RouterOS
Replies:121
Views:18117

Re: Looking for Docker container ideas for RouterOS

I wasn't successful at building that container on my Mac and uploading it, so instead... It builds and exports just fine here: $ git clone https://github.com/fschuindt/docker-smb $ cd docker-smb $ docker build -t smb --platform=linux/arm/v7 . # for 32-bit ARM $ docker build -t smb --platform=linux/...
bytangent
Sat Dec 17, 2022 2:49 am
Forum:Virtualization
Topic:L2TPV3 Port Forwarding in Docker
Replies:6
Views:1481

Re: L2TPV3 Port Forwarding in Docker

That's a neat trick. How? You can find a lot of images for that in https://hub.docker.com/search?q=routeros I wasn't so much interested in "how can I download that myself" as in "how can I make that myself?" However, your link led me to this Dockerfile , which shows one way: wra...
bytangent
Fri Dec 16, 2022 10:53 pm
Forum:Virtualization
Topic:L2TPV3 Port Forwarding in Docker
Replies:6
Views:1481

Re: L2TPV3 Port Forwarding in Docker

i have installed mikrotik RouterOS in docker That's a neat trick. How? Usually it's the other way around . it using port 115 No, it's using IP protocol 115. ( Source .) Ports are a TCP or UDP abstraction, but you're speaking of L2TPv3 over IP. anyone can help me for forwarding that port in docker? ...
bytangent
Fri Dec 16, 2022 10:34 pm
Forum:Useful user articles
Topic:How to install Winbox on macOS
Replies:14
Views:4941

Re: How to install Winbox on macOS

Everything broken again under Ventura. I found and fixed two such problems: 1. The new System Settings app changes the UI layout, but the setting referred to above is still there, under Privacy & Security → Security. (Scroll down.) 2. The OS installer nuked my ~/.wine directory, causing it to f...
bytangent
Wed Dec 14, 2022 5:12 pm
Forum:Containers
Topic:How upgrade container?
Replies:15
Views:2621

Re: How upgrade container?

Incidentally, this thread inspired me to come up witha better analogy.
bytangent
Wed Dec 14, 2022 4:24 pm
Forum:Containers
Topic:How upgrade container?
Replies:15
Views:2621

Re: How upgrade container?

Mikrotiks are generally "pets" It isn't necessarily so. Larger organizations will have an automated deployment process that takes a stock RouterOS box, upgrades it to some tested firmware release, maybe sets a skin, applies a configuration, tests it all, and shuts it down, ready for deplo...
bytangent
Wed Dec 14, 2022 4:11 pm
Forum:Containers
Topic:How upgrade container?
Replies:15
Views:2621

Re: How upgrade container?

I'll probably stick with RPi and SSH.

Containers are not VMs. Get your head around that, and you'll start to see why containerization is taking over the world.
bytangent
Wed Dec 14, 2022 4:01 pm
Forum:RouterBOARD hardware
Topic:what can be used to power the 2-pin terminal of the rb5009?
Replies:23
Views:3096

Re: what can be used to power the 2-pin terminal of the rb5009?

长时间供电电线voltag更高e. All else being equal, yes. it's current times wire resistance equals power loss. Sorry, but you've jumbled several concepts. Current (I) times wire resistance (R) equals voltage loss (V) , not power loss (P) . V=IR. Rearranged to solve for I — I=...
bytangent
Tue Dec 13, 2022 8:20 pm
Forum:RouterBOARD hardware
Topic:what can be used to power the 2-pin terminal of the rb5009?
Replies:23
Views:3096

Re: what can be used to power the 2-pin terminal of the rb5009?

it would let so much ports unused if I used the 24 ports POE?

There are 8-port PoE-out switches in the MikroTik line. The newest is theCSS610-8P, though you'll lose RouterOS support by going that way. TheCRS112-8Psolves that, but it's much older tech.
bytangent
Tue Dec 13, 2022 3:52 am
Forum:Containers
Topic:Manually Specify Container MAC or IPv6 Address
Replies:3
Views:644

Re: Manually Specify Container MAC or IPv6 Address

容器最终用一个新的MAC地址你hould never count on a container to have a fixed internal address. It meant to be dynamic, since a container runtime cannot generically predict what order the containers will come up in, nor how many there will be. In the specific case of RouterOS, ...
bytangent
Tue Dec 13, 2022 3:35 am
Forum:Containers
Topic:How upgrade container?
Replies:15
Views:2621

Re: How upgrade container?

Or is my logic flawed ?

Nope; it's precisely correct, often phrased as the "cattle vs pets" analogy. If you can't "slaughter" your cattle and bring new ones into their place without major disruption, you're doing something wrong.
bytangent
Tue Dec 13, 2022 3:31 am
Forum:General
Topic:Mikrotik iOS App 1.2.11
Replies:8
Views:1090

Re: Mikrotik iOS App 1.2.11

There must be a conditional element to the symptom, then, because I also have a single "full" user that isn't named "admin", and I was able to use the iOS app to update three different routers to 7.7rc1 today, never once needing to give it my password again.
bytangent
Mon Dec 12, 2022 6:35 pm
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

It would be great to have option to nest docker in a docker, or at least have an option to mount /var/run/docker.sock

I don’t believe RouterOS is running full-fat Docker Engine. By all the signs, it’s a barebonesOCIruntime, closer to crun or systemd-nspawn.

There is no API socket to be had.
bytangent
Sun Dec 11, 2022 8:02 am
Forum:RouterBOARD hardware
Topic:what can be used to power the 2-pin terminal of the rb5009?
Replies:23
Views:3096

Re: what can be used to power the 2-pin terminal of the rb5009?

A multi-dc outlet would allow me to plug it to the UPS easily. Taking the PoE path means only the power delivery device needs UPS power. A nice bonus falls out of this if you were using the fiber port on the 5009 as the LAN core uplink. While you might be tempted to reject this idea since you can't...
bytangent
Sat Dec 10, 2022 4:20 pm
Forum:General
Topic:Does Paramount+ require IPv6 ? [SOLVED]
Replies:11
Views:1084

Re: Does Paramount+ require IPv6 ?[SOLVED]

Such service would be inaccesible to 2/3 users (global average). IPv6 deployment rates are fairly well correlated with GDP; the low-ranked countries on one measure tend to be the low-ranked countries on the other. Paramount’s accountants might’ve chosen to leave some small fraction of dollars on th...
bytangent
Sat Dec 10, 2022 4:04 pm
Forum:General
Topic:Is there a router/switch to beat the 4011?
Replies:25
Views:4529

Re: Is there a router/switch to beat the 4011?

添加一个CRS310, CRS328-4C-20S、CRS317或CRS326 -24S+ to keep LAN traffic off the router. Per the diagram sindy posted, you will still end up loading the CPU with WAN traffic due to the SFP+ port on the RB4011 not being handled by the switch chip, but routing is a CPU function on the RB4011 anyway....
bytangent
Sat Dec 03, 2022 1:01 pm
Forum:Announcements
Topic:v7.7beta [testing] is released!
Replies:322
Views:106379

Re: v7.7beta [testing] is released!

…unlikely (although not impossible) that there will be any new MIPSBE Mikrotik devices… The CRS518 was released just this last July on MIPSBE. Perhaps you meant "no MIPSBE wireless routers"? However, to the point of this subthread, maybe the goal is to push such devices into the role of C...
bytangent
Tue Nov 15, 2022 2:05 pm
Forum:Containers
Topic:/dev/stdout and /dev/stderr permission denied on many containers
Replies:2
Views:739

Re: /dev/stdout and /dev/stderr permission denied on many containers

mounting files instead of folders are not yet implemented. Until that lack is filled, you can copy all the files out of the directory in the image containing the one you want to modify, make your changes, and then mount the changed directory over the top of the original. Containers implement a unio...
bytangent
Mon Nov 14, 2022 2:37 pm
Forum:Containers
Topic:Container status on error
Replies:11
Views:2883

Re: Container status on error

的following code is the dockerfile...#!/bin/bash A Dockerfile isn't a Bash shell script. It contains shell script sections, but it won't run if you say "bash Dockerfile". Drop the shebang line; it makes a counterfactual declaration. RUN apk add python3 && apk add py3-pip You sho...
bytangent
Mon Nov 14, 2022 2:25 pm
Forum:Wireless Networking
Topic:wifi bridge between bbox and iptv
Replies:12
Views:2336

Re: wifi bridge between bbox and iptv

Wifi Multicast , to be received by all connections, is sent out at the basic rate (6Mbps mostly if not tuned) I understand that. I am simply predicting that if you increase the basic rate to cover your IPTV stream's needs, you'll still run into problems. is not ACKed nor retransmitted For IPTV, the...
bytangent
Fri Nov 11, 2022 2:30 pm
Forum:Containers
Topic:Container status on error
Replies:11
Views:2883

Re: Container status on error

i need a python package That's one way. Another is linked indirectly above, PyInstaller . That packages the Python interpreter, your program, and any modules it requires into a self-contained package you can COPY over from the first-stage build. This way, you might not even need Alpine as a base. I...
bytangent
Thu Nov 10, 2022 3:44 pm
Forum:Containers
Topic:Container status on error
Replies:11
Views:2883

Re: Container status on error

i looked in the "opt"-file but nothing is in there. Yes, because you didn't read the multi-stage guide I linked you to above. As formulated, you've thrown the first stage away entirely, replacing it with the second stage. You need at least one "COPY" or "ADD" command i...
bytangent
Thu Nov 10, 2022 12:07 pm
Forum:Containers
Topic:Container status on error
Replies:11
Views:2883

Re: Container status on error

FROM python:3.6 There's your space problem, right there: you've indirectly based your container on the flabby buildpack-deps image, which accounts for essentially all of the space your container takes. Your actual application adds approximately zilch to the size of the base. It's fine to use such b...
bytangent
Thu Nov 10, 2022 9:54 am
Forum:Containers
Topic:Mikrotik Container Topic is solved
Replies:4
Views:1358

Re: Mikrotik ContainerTopic is solved

This containergets the effect you want using VLANs.

Still, if the “interface” parameter doesn’t take a list, it’s worthfiling a feature requestfor it.
bytangent
Wed Nov 09, 2022 1:48 pm
Forum:Containers
Topic:Container status on error
Replies:11
Views:2883

Re: Container status on error

You've got a device with 16 MiB of flash and you're trying to load a 290 MiB container . I'm guessing it's trying to download the image to the internal flash and failing. You might have to "export" the image using Docker Desktop, upload that to the USB drive thru scp or WinBox, then use th...
bytangent
Wed Nov 09, 2022 10:46 am
Forum:Wireless Networking
Topic:wifi bridge between bbox and iptv
Replies:12
Views:2336

Re: wifi bridge between bbox and iptv

I see that I still have 2 or 3 things to learn about networking ;-) It's a fascinating and deep field. "Plug the cables in and turn it on" is step 1, not the final step. I'll try to follow the tunnel idea. ♂️ Maybe N-way MIMO and the latest 802.1abgnxyzqrtstuv standard will keep your ...
bytangent
Tue Nov 08, 2022 6:24 pm
Forum:Wireless Networking
Topic:wifi bridge between bbox and iptv
Replies:12
Views:2336

Re: wifi bridge between bbox and iptv

Multicast wifi is only at basic rates, single channel, with no ACK or retransmits. The issue with multicast being throttled over most WiFi implementations is a side issue. Yes, it's bad, and yes, it contributes to the problem, but I've seen the same problems I reference in the other posts with unic...
bytangent
Tue Nov 08, 2022 1:07 pm
Forum:Wireless Networking
Topic:wifi bridge between bbox and iptv
Replies:12
Views:2336

Re: wifi bridge between bbox and iptv

It’s not expected to work. Existing threads:1,2.
bytangent
Sun Nov 06, 2022 4:42 pm
Forum:Beginner Basics
Topic:Internet speed
Replies:15
Views:1021

Re: Internet speed

Usingthe very same test data sourceanav gave above, you’re likely to top out around 270 Mbit/sec.

CRS devices are switches first and foremost, not routers.
bytangent
Sun Nov 06, 2022 3:02 pm
Forum:RouterBOARD hardware
Topic:Error trying to setup MLAG on CRS317-1G-16S+RM
Replies:7
Views:918

Re: Error trying to setup MLAG on CRS317-1G-16S+RM

The embedded “>” is a prompt character, indicating you should have pressed enter after the first line, then copied the second one in.

You could also remove the angle bracket entirely. It’ll work as a single-line command.
bytangent
Sun Nov 06, 2022 12:38 pm
Forum:Beginner Basics
Topic:Internet speed
Replies:15
Views:1021

Re: Internet speed

I am looking for something that can be rack mounted.

Both the 4011 and 5009 have rack mount kits available.

If cost is the issue, a 1U rack mount shelf is $20.

If presence of WiFi is the issue, it can be turned off.
bytangent
Sat Nov 05, 2022 11:19 am
Forum:General
Topic:PSA: Don't run OM3 under a rug…
Replies:3
Views:392

Re: PSA: Don't run OM3 under a rug…

In case it's unclear, the resulting damage wasn't from tripping: it was merely from being trodden on occasionally. This cable was sold as bend-resistant plenum type, so I figured it'd put up with this abuse well enough. Nope. The stuff positively fell apart over the course of a year, resulting in th...
bytangent
Fri Nov 04, 2022 10:33 am
Forum:General
Topic:PSA: Don't run OM3 under a rug…
Replies:3
Views:392

PSA: Don't run OM3 under a rug…

…across the walking path!

IMG_0057.jpg
bytangent
Fri Nov 04, 2022 2:01 am
Forum:RouterBOARD hardware
Topic:Bridge Interface and CPU Relationship for RB4011iGS+ [SOLVED]
Replies:5
Views:945

再保险:接口和桥梁CPU Relationship for RB4011iGS+[SOLVED]

I think you'll find this article enlightening even though it doesn't have anything specifically to do with your problem. Simply seeing the options for how to solve a problem with bridges vs VLANs vs both under RouterOS should help you to put that other "talk" into context, then begin to ev...
bytangent
Fri Oct 28, 2022 1:02 pm
Forum:Containers
Topic:Setup Ubuntu on Docker Container Topic is solved
Replies:4
Views:1970

Re: Setup Ubuntu on Docker ContainerTopic is solved

I want to setup ubuntu docker container on RouterOS…

Containers are not VMs.
bytangent
Fri Oct 28, 2022 8:32 am
Forum:General
Topic:I need to upgrade from 6 to 7, what I should know?
Replies:12
Views:880

Re: I need to upgrade from 6 to 7, what I should know?

should expect the exact "same" general behavior?

No.
bytangent
Wed Oct 26, 2022 10:02 pm
Forum:Containers
Topic:Container crashes randomly
Replies:9
Views:1226

Re: Container crashes randomly

I've already told you at least twice that you need to pass those same options to the container on the RouterOS side in the "cmd" parameter.

Code:Select all
/container/add cmd="172.19.50.238:8082 172.19.48.1:8083" ...
bytangent
Tue Oct 25, 2022 5:32 am
Forum:General
Topic:Severe port flapping on CRS328-24P-4S+ and CRS317-1G-16S+
Replies:213
Views:63911

Re: Severe port flapping on CRS328-24P-4S+ and CRS317-1G-16S+

latest long-term version RouterOS

It was fixed in 7.4, which is “stable,” not LTS.
bytangent
Mon Oct 24, 2022 8:40 pm
Forum:Containers
Topic:Container crashes randomly
Replies:9
Views:1226

Re: Container crashes randomly

But this still does not explain the "randomness" of the Container quiting. I expect you're simply seeing the normal variation in starting and stopping delays. Keep in mind, this isn't a full-power desktop computer, there's a virtualization and containerization layer to deal with atop that...
bytangent
Mon Oct 24, 2022 4:27 am
Forum:Containers
Topic:/container: Permission denied (13) Topic is solved
Replies:7
Views:2213

Re: /container: Permission denied (13)Topic is solved

apache2: could not open error log file /var/log/apache2/error.log.
12:41:51 container,info,debug AH00015: Unable to open logs

So map /var/log/apache2 to a volume the container can write to.
bytangent
Sat Oct 22, 2022 9:40 pm
Forum:Containers
Topic:Container crashes randomly
Replies:9
Views:1226

Re: Container crashes randomly

I currently have a problem with crashing Containers. Why do you characterize a result of "done" as "crashing?" I'd take it literally: it's done with what you asked it to do. Indeed, I can't see that you've told these containers to do anything, so it comes back and says, "I'...
bytangent
Wed Oct 19, 2022 3:50 pm
Forum:Forwarding Protocols
Topic:Multicast noob questions
Replies:3
Views:640

Re: Multicast noob questions

I have VLANs for normal PCs, Guests, SIP-Phones, Cameras, House-stuff and untrusted appliances. I also separated the KNX stuff, as i want to carefully configure rules for this. One of the characteristics of VLANs vs router-separated switches or vs multiple isolated bridges on a single switch is tha...
bytangent
Wed Oct 19, 2022 11:05 am
Forum:SwOS
Topic:SwitchOS CLI
Replies:27
Views:14022

Re: SwitchOS CLI

…thefalse beliefthatjust put the httpson that deviceand it becomes safe...

It’s a good start, though.
bytangent
Wed Oct 19, 2022 11:03 am
Forum:SwOS
Topic:SwitchOS CLI
Replies:27
Views:14022

Re: SwitchOS CLI

Really impressive that there is really someone who makes all this effort to "annoy" a "home" network ... You haven’t been paying attention to security at all, then. LAN equipment attacks are HUGE . Also, there’s no reason to restrict this to “home” networks. Just for one example...
bytangent
Wed Oct 19, 2022 10:45 am
Forum:SwOS
Topic:SwitchOS CLI
Replies:27
Views:14022

Re: SwitchOS CLI

…apart from disfiguring it, with the SwOS you can do nothing… Such lack of imagination. Given admin access on a SwOS box, I can: create a transparent network tap permit DHCP poisoning fry unsuspecting nodes by applying forced passive PoE pierce VLAN barriers mangle traffic …and doubtless more if ...
bytangent
Tue Oct 18, 2022 4:12 pm
Forum:Forwarding Protocols
Topic:Multicast noob questions
Replies:3
Views:640

Re: Multicast noob questions

how is it possible to connect different vlans to a multicast address? With a multicast router. And what protocol, your next question will be, does one route multicast with? Answer: PIM-SM . RouterOS also has a proprietary IGMP proxy service that may be of use here. There have been reports of bugs w...
bytangent
Sun Oct 16, 2022 9:47 am
Forum:General
Topic:Containers (permissions - chown)
Replies:5
Views:570

Re: Containers (permissions - chown)

Presumably one of the things you want to monitor is the behavior of the router itself. Since it matters less that it’s working correctly internally than that it provides external service to the LAN, external monitoring is more useful anyway, telling you more of what you want to know.
bytangent
Sun Oct 16, 2022 9:22 am
Forum:General
Topic:Containers (permissions - chown)
Replies:5
Views:570

Re: Containers (permissions - chown)

If you have a hypervisor, you don’t need RouterOS containers. Install a host OS of your choice alongside the CHR, then install the container there, atop Docker Engine. Not only do you get the ability to run rootful containers, it’ll likely run better and faster that way besides.
bytangent
Sun Oct 16, 2022 8:18 am
Forum:General
Topic:Containers (permissions - chown)
Replies:5
Views:570

Re: Containers (permissions - chown)

It seems to me that you’re waiting on upstream changes here. Separately, this is a terribly inefficient container: Node.js, minimum 256 MB storage to load and run, and who knows how much RAM to run atop that. I wouldn’t run this on anything less than an RB5009, and I’d prefer to run it on a proper s...
bytangent
Mon Oct 10, 2022 11:10 am
Forum:General
Topic:Port 4000 Opened [SOLVED]
Replies:22
Views:1660

Re: Port 4000 Opened[SOLVED]

There else should I check please?

You said you posted the client's router rules, we checked them, and Znevna now blames your router. Is the next step not obvious? Post your router's sanitized configuration so we can check it, too.

If you aren't willing to do that, then check it yourself.
bytangent
Sun Oct 09, 2022 2:34 am
Forum:General
Topic:Comparing config files
Replies:39
Views:2425

Re: Comparing config files

Of course in v7 use/export show-sensitive terse

I've modifiedmy backup toolto add both of these things. Thanks.
bytangent
Sat Oct 08, 2022 7:44 am
Forum:General
Topic:Port 4000 Opened [SOLVED]
Replies:22
Views:1660

Re: Port 4000 Opened[SOLVED]

If these are “MikroTik routers”, why do their MAC OUI prefixes belong to Intel anda subsidiary of Foxconn?
bytangent
Sat Oct 08, 2022 5:35 am
Forum:General
Topic:Port 4000 Opened [SOLVED]
Replies:22
Views:1660

Re: Port 4000 Opened[SOLVED]

IsUPnPenabled?
bytangent
Fri Oct 07, 2022 10:24 pm
Forum:Beginner Basics
Topic:Bridge (bandwidth)
Replies:2
Views:349

Re: Bridge (bandwidth)

How much bandwidth we can use in bridge mode? Potentially, all of it. If you want a more specific answer, pose a more specific question. Why we can't use all bandwidth in bridge mode? Most likely because you haven't got a pure bridge and are forcing traffic down through the router's CPU. Except o...
bytangent
Fri Oct 07, 2022 3:05 pm
Forum:General
Topic:Comparing config files
Replies:39
Views:2425

Re: Comparing config files

My backup toolproduces diffs as part of its regular behavior. The docs explain why you’re better off not using git for this, but if you must, it wouldn’t be difficult to convert it.
bytangent
Tue Oct 04, 2022 12:17 am
Forum:Announcements
Topic:Newsletter 108
Replies:84
Views:42231

Re: Newsletter 108

just one single 2.5Gb port... For 1G WAN and 2.5G uplink to the LAN core, leaving 1.5G aggregate for the other three ports before you get any congestion. Me, I wanted an SFP+ port for the same reason. Overkill, but then you could have fiber back to the core, 2.5G to the WAN, and no congestion for t...
bytangent
Sat Oct 01, 2022 1:12 am
Forum:General
Topic:Switch CRS112-8P-4S as a media converter [SOLVED]
Replies:42
Views:3228

Re: Switch CRS112-8P-4S as a media converter[SOLVED]

The dynamic route overrides the default route entirely for your LAN traffic, sending everything to ether8. Surely you want a /32 pointing to your management host here? If you must have a /24 to allow multiple hosts behind ether8, realize that you've got a router here now, not a switch. CPU load is e...
bytangent
Fri Sep 30, 2022 9:13 pm
Forum:General
Topic:Switch CRS112-8P-4S as a media converter [SOLVED]
Replies:42
Views:3228

Re: Switch CRS112-8P-4S as a media converter[SOLVED]

What does "/ip route print" say?

Will you post the new combined RSC as I asked you to above, so we don't have to piece it together in our heads?
bytangent
Thu Sep 29, 2022 9:01 am
Forum:General
Topic:GUIDE: Running Netinstall Server on a Tik
Replies:23
Views:2153

Re: GUIDE: Running Netinstall Server on a Tik

Nobody sane runs containers on internal flash.

This one is functionally read-only. It shouldn’t materially shorten the lifetime of the host router.
bytangent
Thu Sep 29, 2022 8:26 am
Forum:General
Topic:GUIDE: Running Netinstall Server on a Tik
Replies:23
Views:2153

Re: GUIDE: Running Netinstall Server on a Tik

there is actually no need for a native ARM build

…says the guy with a gig of flash.

Those wanting containers for several CPU types on smaller routers will appreciate not having to pay the cost of a CPU emulator.
bytangent
Thu Sep 29, 2022 2:37 am
Forum:General
Topic:GUIDE: Running Netinstall Server on a Tik
Replies:23
Views:2153

Re: GUIDE: Running Netinstall Server on a Tik

Nice; now we just need a native ARM build of netinstall from MikroTik. (Request already put in as SUP-89685, but reposting to add more votes might help.) Instead of passing the name of a file in as an environment variable and mapping the storage for same in from a volume, I think it would be simpler...
bytangent
Tue Sep 27, 2022 7:33 pm
Forum:General
Topic:v7.5 container mount files
Replies:5
Views:649

Re: v7.5 container mount files

There's a big fat warning They're merely saying that if you map a file or directory on the host into the container, the safety guarantees of the container go out the window for that file or directory . If you want an example, they're saying if you bind-mount the host's /etc into the container, you'...
bytangent
Tue Sep 27, 2022 6:48 pm
Forum:General
Topic:v7.5 container mount files
Replies:5
Views:649

Re: v7.5 container mount files

Linux requires loopback filesystem driver for that I don't interpret the OP's question as asking about filesystems-on-files, which is what you need the loop driver for. Instead, I believe he's asking about bind-mounting single files into place inside the container. This is useful when the container...
bytangent
Tue Sep 27, 2022 12:30 am
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

Routeros is a picky community. ;-) Computers are picky things. Those of us who've learned to become facile with them learn not to use the wrong terminology and to jump on instances of it where we see it elsewhere as a sign of either sloppy or outright incorrect thinking. When you're asking for help...
bytangent
Mon Sep 26, 2022 5:42 pm
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

When you say USB and mount together, you imply block devices and file systems. HID devices are neither. You can’t “mount” a keyboard in Linux. As to your actual question, you might be able to do an mknod(8) call and map the dev node in that way. It depends in part on whether the SYS_MKNOD capability...
bytangent
Mon Sep 26, 2022 4:45 pm
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

Is it possible to "mount" usb devices in a container ?

Did you eventryto read the docs? Thin as they currently are,they do cover this.
bytangent
Sat Sep 24, 2022 8:28 pm
Forum:General
Topic:Switch CRS112-8P-4S as a media converter [SOLVED]
Replies:42
Views:3228

Re: Switch CRS112-8P-4S as a media converter[SOLVED]

How can it affect the CPU load so drastically?

Why do you believe an old CRS1xx era switch chip has the brains to understand L3 down to the level that it can make decisions about TCP connections?

It might, but I wouldn't bet on it.

Thus the experiment.
bytangent
Sat Sep 24, 2022 4:57 pm
Forum:General
Topic:Switch CRS112-8P-4S as a media converter [SOLVED]
Replies:42
Views:3228

Re: Switch CRS112-8P-4S as a media converter[SOLVED]

As I tried to point out up-thread, anything involving "/ip firewall" is going to make packets hit the CPU. …on ROS 6, the presence of complete IP firewall doesn't prevent L2 forwarding among switch chip ports in hardware. There are a number of points I think we're getting separated on her...
bytangent
Fri Sep 23, 2022 11:18 pm
Forum:General
Topic:Switch CRS112-8P-4S as a media converter [SOLVED]
Replies:42
Views:3228

Re: Switch CRS112-8P-4S as a media converter[SOLVED]

/ip firewall connection tracking Is that still in your config, BrateloSlava? As I tried to point out ip-thread, anything involving "/ip firewall" is going to make packets hit the CPU. That, or it'll be ineffective because another part of the config (e.g. fast-path) causes the packets to b...
bytangent
Fri Sep 23, 2022 2:54 am
Forum:General
Topic:General Licensing Question [SOLVED]
Replies:3
Views:723

Re: General Licensing Question[SOLVED]

MikroTik hardware comes with an embedded license. You cannot move this license to a new system in any way…

(First search result in the docs for “license,” by the way.)
bytangent
Thu Sep 22, 2022 1:15 am
Forum:General
Topic:Feature Request: Ed25519 SSH keys
Replies:49
Views:14185

Re: Feature Request: Ed25519 SSH keys

Six years stretches the word “patience” all out of shape. This in a world where RouterOS has dropped DSA (as it should) leaving only the semi-obsolescent RSA, a tech older than most of the board’s participants, I’d warrant. It’s past time for this lack to be filled. The option to DIY a fix for ourse...
bytangent
Thu Sep 22, 2022 1:10 am
Forum:General
Topic:Switch CRS112-8P-4S as a media converter [SOLVED]
Replies:42
Views:3228

Re: Switch CRS112-8P-4S as a media converter[SOLVED]

Bingo. If you want line-rate switching, you cannot do anything to the packets that forces them to cross the CPU. That includes firewalling, but it isn’t limited to it. The packets have to stay on the switch chip. This series has ACL rules that work purely at the switch chip level, but they’re less p...
bytangent
Thu Sep 15, 2022 6:04 pm
Forum:Containers
Topic:Looking for Docker container ideas for RouterOS
Replies:121
Views:18117

Re: Looking for Docker container ideas for RouterOS

My AdGuardHome runs fine with an IP from the subnet sitting on the main bridge

Good to know; thanks.

This brings us back to the skimpy state of the docs, of course.☹️
bytangent
Wed Sep 14, 2022 7:22 pm
Forum:Beginner Basics
Topic:problem with multi bridge interface
Replies:11
Views:891

再保险:问题multi bridge interface

Sounds like VLANs to me.
bytangent
Wed Sep 14, 2022 4:59 pm
Forum:Beginner Basics
Topic:problem with multi bridge interface
Replies:11
Views:891

再保险:问题multi bridge interface

how does this intercsect with my problem..? Your device — one of the CRS326 models based on the header of your RSC file — isn't a CRS1xx or 2xx, so you can't have multiple bridges per switch chip. I'm going to guess it's one of the 24G models based on details of your bridge setup. From that, we can...
bytangent
Wed Sep 14, 2022 4:16 pm
Forum:Beginner Basics
Topic:problem with multi bridge interface
Replies:11
Views:891

再保险:问题multi bridge interface

雷竞技官网网站下载硬件卸载只作用于一个桥interface. It's more nuanced than that. The CRS1xx/2xx series allow up to 7 hardware-accelerated bridges. Everything else allows one per switch chip . That qualifier is important, because several of the products in MikroTik's lineup have more than o...
bytangent
Wed Sep 14, 2022 4:14 pm
Forum:General
Topic:CAs certificates on my Mikrotik.
Replies:1
Views:206

Re: CAs certificates on my Mikrotik.

You can create any number of certificates of any type, including those marked as "key-usage=key-cert-sign." You can then use those "CA" certs to sign any other certificates arbitrarily.

If you're asking about some narrower purpose, please be explicit about it.
bytangent
Fri Sep 09, 2022 4:05 pm
Forum:General
Topic:Remote SSH tunneling (ssh -R )
Replies:5
Views:19301

Re: Remote SSH tunneling (ssh -R )

I tried using the "command" argument That establishes a listener on the remote host via a different SSH tunnel than the one you used to get to the remote server, so it won't tunnel back through your firewall. RouterOS does support tunneling, both directions, though it's disabled by defaul...
bytangent
Wed Sep 07, 2022 12:07 am
Forum:Containers
Topic:Looking for Docker container ideas for RouterOS
Replies:121
Views:18117

Re: Looking for Docker container ideas for RouterOS

where should one install the Docker Engine? doesn't it require another Linux/Win VM…? You've got two basic options: You're running a type-1 hypervisor (e.g. ESXi) so you have no choice but to spin up a VM running the container runtime environment alongside CHR and whatever else you're running. Ther...
bytangent
Tue Sep 06, 2022 9:57 pm
Forum:Containers
Topic:Looking for Docker container ideas for RouterOS
Replies:121
Views:18117

Re: Looking for Docker container ideas for RouterOS

It's far better to either run another VM on the same host. For a small user like me, paying for an extra VM is an overhead I don't need. Docker Engine is far lighter than a single VM, and it's far more capable than RouterOS's Containers feature is ever likely to be. If you want even lighter-weight ...
bytangent
Tue Sep 06, 2022 9:28 pm
Forum:Containers
Topic:Looking for Docker container ideas for RouterOS
Replies:121
Views:18117

Re: Looking for Docker container ideas for RouterOS

我也测试拉特OS 7和1级表示“允许”e That sounds like CHR, in which case containers are kind of silly. It's far better to either run another VM on the same host, or if this is running on a Type 2 Hypervisor (e.g. VirtualBox, Hyper-V) then start Docker Engine out on the host, alongsid...
bytangent
Tue Sep 06, 2022 8:50 pm
Forum:Containers
Topic:Looking for Docker container ideas for RouterOS
Replies:121
Views:18117

Re: Looking for Docker container ideas for RouterOS

No, you're right: the current RouterOS docs on containers positively suck compared to what you get for other container platforms. Your next-best option is SSHing into a box running the containers.npk package, typing "/container", and then pressing the F1 and Tab keys a lot. Between that, t...
bytangent
Tue Sep 06, 2022 7:37 pm
Forum:Containers
Topic:Looking for Docker container ideas for RouterOS
Replies:121
Views:18117

Re: Looking for Docker container ideas for RouterOS

if you consider that as a customer you should "help yourself" that's inded fine. There's tremendous value in choosing solutions that give you the freedom to build your own solutions atop the platform. If the method avoids lock-in, so much the better. Later today, I'll be working with a di...
bytangent
Tue Sep 06, 2022 12:08 pm
Forum:Containers
Topic:Looking for Docker container ideas for RouterOS
Replies:121
Views:18117

Re: Looking for Docker container ideas for RouterOS

Most arguments that I read are "something is missing/not good enough on the mikrotik device and I want to add/replace it". What's wrong with that argument? It's a perfectly valid use case. The cost argument is not valid either as cheap and power efficient devices can be found on the marke...
bytangent
Tue Sep 06, 2022 7:12 am
Forum:Containers
Topic:Looking for Docker container ideas for RouterOS
Replies:121
Views:18117

Re: Looking for Docker container ideas for RouterOS

I was looking into documentation and I didn't see how one would do port mapping with Containers in ROS 7.

How did you missthis? It's precisely the same thing as "docker create --publish 80:80".
bytangent
Wed Aug 31, 2022 8:06 pm
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

Why not NFS Sure, fine. While we're dreaming, let's ask for iSCSI, too. That would be more likely to get accepted I dunno. Both facilities are equally available in the kernel. Most NASes speak SMB by default. Obviously Windows does, too, but what might surprise you is that Apple went over to SMB fr...
bytangent
Wed Aug 31, 2022 6:31 pm
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

Would it be possible to add permissions for mounting As far as I can tell, that requires CAP_SYS_ADMIN, the shameful secret capability that grants a user a whole raft of abilities . I wouldn't be surprised if MikroTik said, "Nah, are you nuts? We're not giving you that one! It'd let you root t...
bytangent
Wed Aug 31, 2022 5:51 pm
Forum:General
Topic:CRS328 does not suck
Replies:2
Views:371

Re: CRS328 does not suck

In case anyone's wondering why there wasn't a prior post from me titled "CRS328 sucks ," it's because I had a whole list of candidates for why I wasn't getting the advertised speed, and I use this 10G link rarely enough that I had yet to eliminate any of the possibilities: Host OS weirdne...
bytangent
Tue Aug 30, 2022 11:40 pm
Forum:Beginner Basics
Topic:Firewall not blocking Hikvision
Replies:8
Views:798

再保险:防火墙不阻塞Hikvision

If you're unwilling to implement VLAN boundaries, my next suggestion is to run Torch on the camera's network interface to see what it's saying. It might not be using the IP you're blocking, thus giving the behavior you observe, for example.
bytangent
Tue Aug 30, 2022 11:33 pm
Forum:General
Topic:CRS328 does not suck
Replies:2
Views:371

CRS328 does not suck

There's too much griping on this board, so in an effort to counter some of that, I offer this: % iperf3 -c … Connecting to host …, port 5201 [ ID] Interval Transfer Bitrate [ 5] 0.00-1.00 sec 1.09 GBytes 9.37 Gbits/sec [ 5] 1.00-2.00 sec 1.09 GBytes 9.41 Gbits/sec [ 5] 2.00-3.00 sec 1.09 GBytes 9.40...
bytangent
Tue Aug 30, 2022 1:23 am
Forum:Beginner Basics
Topic:Firewall not blocking Hikvision
Replies:8
Views:798

再保险:防火墙不阻塞Hikvision

Is this hAP ac³ your Internet router, with the modem in bridge mode, connected to ether1? If not, my best guess is that your RouterOS bridge configuration bypasses the firewall by offloading everything it can to the built-in switch chip. A related possibility is all that VPN stuff you've got going i...
bytangent
Fri Aug 26, 2022 7:01 pm
Forum:Beginner Basics
Topic:Endless winbox login attempts on own interfaces
Replies:3
Views:376

Re: Endless winbox login attempts on own interfaces

the source of the login attempts are the interfaces of the router itself You're saying this .253 address is assigned to the router itself? If so, I'd use Torch to grab some frames and analyze them in Wireshark, to see if I could get some more detail down in the packets. 38K attempts in a day or two...
bytangent
Tue Aug 23, 2022 5:07 pm
Forum:Beginner Basics
Topic:Unable to get simple subnet routing to work.
Replies:11
Views:646

Re: Unable to get simple subnet routing to work.

I would next look at routing on the clients, presumably learned via DHCP. The ping packet may get to the client from the router, that doesn't tell you that the client then knows how to get the reply back to the router. The command varies: "ip route" on modern Linux, "netstat -r" ...
bytangent
Tue Aug 23, 2022 3:31 pm
Forum:Beginner Basics
Topic:Unable to get simple subnet routing to work.
Replies:11
Views:646

Re: Unable to get simple subnet routing to work.

That output shows that "simple subnet routing" does work as you expect. All those dynamic routes ("D") are what you were expecting RouterOS to add for you. (Incidentally, you can drop the "network=192.168.88.0" type stuff from your "/ip/address/add" commands. ...
bytangent
Tue Aug 23, 2022 2:04 pm
Forum:Beginner Basics
Topic:Unable to get simple subnet routing to work.
Replies:11
Views:646

Re: Unable to get simple subnet routing to work.

What does "/ip/route/print" say?
bytangent
Tue Aug 23, 2022 10:55 am
Forum:Beginner Basics
Topic:Unable to get simple subnet routing to work.
Replies:11
Views:646

Re: Unable to get simple subnet routing to work.

Your pared-back configuration requires me to ask something you could’ve shown straightforwardly: are these three ports still bridged together, as they presumably are in the default configuration for whatever device you’re using?

The full (but sanitized) configuration would’ve answered both questions.
bytangent
Sun Aug 21, 2022 6:35 pm
Forum:Beginner Basics
Topic:Need assistance with SSTP
Replies:13
Views:679

Re: Need assistance with SSTP

Sorry, but what is a wireguard ?

This.
bytangent
Sat Aug 20, 2022 2:45 pm
Forum:Forwarding Protocols
Topic:IP Multicast on v7
Replies:4
Views:962

Re: IP Multicast on v7

With a reproducible test case that takes only a minute to complete, why are you messing around on the forum? Send it to MikroTik support. It’ll be Christmas in Latvia.
bytangent
Fri Aug 19, 2022 11:53 pm
Forum:SwOS
Topic:CRS368 getting wrong IP address [SOLVED]
Replies:8
Views:1200

Re: CRS368 getting wrong IP address[SOLVED]

If the switch was running RouterOS, you could bind its DHCP client to a specific port, bridge, or VLAN and get the behavior you want.

Although SwOS doesn't appear to have the same ability, isn't it as simple as settingthe "Allow From VLAN" fieldto something only the RB5009 can serve?
bytangent
Fri Aug 19, 2022 10:13 pm
Forum:SwOS
Topic:CRS368 getting wrong IP address [SOLVED]
Replies:8
Views:1200

Re: CRS368 getting wrong IP address[SOLVED]

my CRS368 I see no such product on MikroTik's site, even if I search the "Archived" products. I thought that by putting both devices on a VLAN that only they use, all communication would be isolated. I think I need a network diagram to make sense of what you're putting down in prose. Labe...
bytangent
Fri Aug 19, 2022 5:51 pm
Forum:Forwarding Protocols
Topic:IP Multicast on v7
Replies:4
Views:962

Re: IP Multicast on v7

any effort with Bootstrap protocol ends up sooner or later in full CPU usage and reboot is needed. How long does it take to get into that state? Why do you need automatic RP discovery? If there's only one path to the RP, and its IP rarely changes, if ever, static RP is not only perfectly fine, it's...
bytangent
Fri Aug 19, 2022 2:01 am
Forum:Beginner Basics
Topic:basic ICMP rule [SOLVED]
Replies:5
Views:1090

Re: basic ICMP rule[SOLVED]

I don't see how you can blame the ISP when "lan ping still does not work," but success, I guess?
bytangent
Fri Aug 19, 2022 12:24 am
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

While I agree that this "-2" offset is odd, what I'm saying is, the AGH container expects 65534, the UID/GID of the Alpine user "nobody." Since you're using external mounts, these values should persist across container rebuilds. If not, then that's a bug. The exact values don't m...
bytangent
Thu Aug 18, 2022 11:55 pm
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

@MikroTik can we fix the mounts? File ownership between the inside and outside of the container is always tricky with containers, because they don't share user and group databases. I'm guessing it's not that hard to find out why mounts are created with 3276 6 :3276 6 instead of 3276 8 :3276 8 Those...
bytangent
Thu Aug 18, 2022 10:42 pm
Forum:Announcements
Topic:Newsletter 107
Replies:50
Views:23177

Re: Newsletter 107

¡Paquete自由!✊
bytangent
Thu Aug 18, 2022 9:05 pm
Forum:Announcements
Topic:v6.48.6 [long-term] is released!
Replies:126
Views:262684

Re: v6.48.6 [long-term] is released!

(traffic passing between ports on different switch chips hits CPU ... pretty hard if CPU is not very fast).

Agreed. Forthe project in question, there were already firewall/router stages between the switch chips, so the traffic was already going to cross the CPU.
bytangent
Thu Aug 18, 2022 8:52 pm
Forum:Announcements
Topic:v6.48.6 [long-term] is released!
Replies:126
Views:262684

Re: v6.48.6 [long-term] is released!

AFAIK the limitation about HW offload only being available for one bridge (per switch chip) still applies. Yes, good catch. I just had MikroTik confirm that, for an unrelated project. For the CRS328, there's one switch chip, so you get one hardware-accelerated bridge, only. Contrast RB1100, where y...
bytangent
Thu Aug 18, 2022 7:59 pm
Forum:Announcements
Topic:v6.48.6 [long-term] is released!
Replies:126
Views:262684

Re: v6.48.6 [long-term] is released!

几个Mikrot雷竞技网站ik设备v7.2、固件crashed and randomly rebooted once a week due to memory leaks. While annoying, a minute of downtime a week doesn't sound too bad to me. That's 99.99% SLA . Plus, the nature of this sort of problem is that you can schedule the reboot for a non-peak t...
bytangent
Thu Aug 18, 2022 7:10 pm
Forum:Announcements
Topic:v7.5beta [testing] is released!
Replies:138
Views:38038

Re: v7.5beta [testing] is released!

after the fresh deploy or redeploy the file permission are broken One of the things you have to understand about Docker is that user and group databases are different inside the container relative to outside it. If you ever used NFS without something like idmapd or NIS+ alongside it, it's the same ...
bytangent
Thu Aug 18, 2022 12:33 am
Forum:Announcements
Topic:v6.48.6 [long-term] is released!
Replies:126
Views:262684

Re: v6.48.6 [long-term] is released!

@tangent is mixing L2hw offloading (e.g. ethernet link bonding) and L3hw offloading (IP routing). So does MikroTik. :) Quotes from the ChangeLog: l3hw - fixed bonding source MAC address; l3hw - improved system stability when using 7 or more VLAN interfaces; Those are L2 interactions. It may be that...
bytangent
Wed Aug 17, 2022 11:00 pm
Forum:Announcements
Topic:v6.48.6 [long-term] is released!
Replies:126
Views:262684

Re: v6.48.6 [long-term] is released!

There is no declared hardware offload. There is, but it wasn't added until v7.1. Quoting the ChangeLog : "support for Layer 3 hardware acceleration on all CRS3xx devices." The implication is that it isn't in v6 at all. ( Confirmed in the docs .) There's significant improvement to this in ...
bytangent
Wed Aug 17, 2022 6:57 am
Forum:Announcements
Topic:Newsletter 107
Replies:50
Views:23177

Re: Newsletter 107

Guess I'll just skip the AX2 for now until the performance regression is fixed. The ax² is that more powerful hardware mkx was referring to. Compared to the ac² , it’s got a 20.6% faster clock rate, and it’s running on the more efficient 64-bit ARM instruction set besides. That should be more than ...
bytangent
Wed Aug 17, 2022 6:48 am
Forum:Beginner Basics
Topic:basic ICMP rule [SOLVED]
Replies:5
Views:1090

Re: basic ICMP rule[SOLVED]

It pings out of the box, so you’ve configured the capability away somehow. Post your sanitized configuration here and we can help you debug it.
bytangent
Wed Aug 17, 2022 12:25 am
Forum:Scripting
Topic:Upload router backups via SFTP
Replies:2
Views:1056

Re: Upload router backups via SFTP

Alternately, flip the problem andpull via scpinstead.
bytangent
Mon Aug 15, 2022 10:35 pm
Forum:RouterBOARD hardware
Topic:How hot is too hot for CRS326-24G-2S+ ?
Replies:3
Views:940

Re: How hot is too hot for CRS326-24G-2S+ ?

CPU temperature of about 84C in a room that is not especially warm Temperature is relative, so saying "60°C over ambient" is more concise and more useful. If the room temp rises 1°C, so will the CPU, assuming the before and after conditions are both at equilibrium. I don't have the same m...
bytangent
Mon Aug 15, 2022 12:57 am
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

what if mikrotik needs 10 times, spread across all over a-z :P You'd better hope not, because drawing 10 items from a pool of 305 creates 1.6×10¹⁸ possible combinations. ( Math ) Maybe I'll just write a script to automate it :P build, save, curl upload, ssh container add, start. rinse and repeat in...
bytangent
Sun Aug 14, 2022 11:57 pm
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

I can't make it work creating a "veth2" By putting veth2 at 172.17.0.3/16, it's inside the subnet of veth1. That means you need to attach it to the "dockers" bridge so it's visible to all the other 172.17.0.0/16 hosts, it participates in the established NAT rule, etc. Alternatel...
bytangent
Sun Aug 14, 2022 10:59 pm
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

It seems like mikrotik needs more than just /bin/sh. I can't see why, other than to support "/container shell". Next time looking for time to waste I'll turn them off one by one Cut your wasted time to log₂(n) by bisecting it. First "rm /bin/[a-m]*" after installation, which tel...
bytangent
Sun Aug 14, 2022 8:28 pm
Forum:General
Topic:Wireguard on GPRS connection
Replies:16
Views:1043

Re: Wireguard on GPRS connection

where should I search in the firewall rules? I obliquely told you already , but okay, I'll spell it out. You're missing this on "router A": /ip firewall filter add action=accept chain=input dst-port=13231 protocol=udp Without this, the default "drop all not coming from LAN" rule...
bytangent
Sun Aug 14, 2022 6:57 pm
Forum:General
Topic:DDoS protection
Replies:2
Views:522

Re: DDoS protection

Is there a way to protect my server and clients from DDoS Sure, lots of ways . maybe by using 2 public IP addresses and switching between them, Why would that work? You have to publish both IPs somehow. Unless you can come up with a way to do that without letting your attacker learn it, too, they'l...
bytangent
Sun Aug 14, 2022 4:19 pm
Forum:General
Topic:Wireguard on GPRS connection
Replies:16
Views:1043

Re: Wireguard on GPRS connection

He’s saying that the WG conn needs to be bounced when the IP changes.

至于我的防火墙的建议,这不是optional. If the remote router can’t connect to the “server” router on port 13231, you get the very symptom you complain of.
bytangent
Sun Aug 14, 2022 12:29 pm
Forum:RouterOS beta and rc versions
Topic:RB4011 is missing CPU frequency adjustment
Replies:32
Views:5622

Re: RB4011 is missing CPU frequency adjustment

Not to mention that there is no “unlocked” RB4011 in the lineup at a premium price.

Do I understand the conspiracy theory’s premise correctly, that we could all just drive our home routers at 2, 3GHz and avoid the CCR line or something?

Lunacy.
bytangent
Sun Aug 14, 2022 8:13 am
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

RUN [ "/bin/busybox", "--install", "/bin" ] That tells BusyBox to install all its sub-command links. ( Details ) I can only speculate about whether doing this in your container will help. The only solid case I could think of is that it might be calling system(3), thus ...
bytangent
Sun Aug 14, 2022 3:31 am
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

Anyone able to run any "FROM scratch" images in mikrotik? Yes. I got this one running a few days ago. This is the package I was trying How did you build it? It should be a command like: $ docker buildx build -t stubby --platform linux/arm/v7 --load . …from the directory containing the Doc...
bytangent
Sun Aug 14, 2022 12:50 am
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

Completely erased the container and re-deployed without mounts etc in the first place. Now the container seems to start! Some settings you make on a container when deploying it the first time from an image get baked into the container permanently. Mounts are one. Port mappings are another. You can'...
bytangent
Sat Aug 13, 2022 10:18 pm
Forum:General
Topic:Wireguard on GPRS connection
Replies:16
Views:1043

Re: Wireguard on GPRS connection

/ip firewall filter add action=accept chain=input disabled=yes dst-port=8291 protocol=tcp Change that rule to open port 13231 (your WireGuard listen port) instead. (You will then be running WinBox over WG for remote management, a far safer method than exposing WinBox to the open Internet.) Having d...
bytangent
Fri Aug 12, 2022 7:55 pm
Forum:General
Topic:Wireguard on GPRS connection
Replies:16
Views:1043

Re: Wireguard on GPRS connection

This remote server is connected through a 4G GPRS internet connection. I know little about this sort of thing, but my web-fu says GPRS is a pre-4G thing. So, is it 4G, or is it GPRS? It has no public accessible IP addres. At some level, a connection's route has to include a public IP, else you aren...
bytangent
Thu Aug 11, 2022 2:54 pm
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

for example a shell command to interact the docker image after it strarts Yes, the subcommands of "/container" are underdocumented on the help site. Until their doc people get around to filling that out, use the CLI to discover the commands by poking around with F1 and TAB keystrokes. Fro...
bytangent
Thu Aug 11, 2022 10:41 am
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

Is it possible to have more help on how to use CMD in container By "CMD" do you mean the Linux command shells? That information is widely available, and it goes deep. There is zero reason for MikroTik to bother trying to add to that vast ocean of training. how to interact with other conta...
bytangent
Sun Aug 07, 2022 1:41 am
Forum:RouterBOARD hardware
Topic:Number of CPU cores on CRS3xx
Replies:13
Views:4834

Re: Number of CPU cores on CRS3xx

Interesting, same CPU (98DX3236) https://wifimag.ro/pdf/Prestera_98DX3336_pb.pdf same ROS, different cores... Running the CPU in 2-core mode caused SFP instability. (I saw it here.) They fixed it in 7.4: "disabled second CPU core for CRS328-24P-4S+ device in order to improve SFP+ link stabilit...
bytangent
Sat Aug 06, 2022 7:31 am
Forum:Beginner Basics
Topic:after import 9 port switch backup - router Ports 10, 11, 12 don't function
Replies:8
Views:663

Re: after import 9 port switch backup - router Ports 10, 11, 12 don't function

While that is a better backup/restore strategy in some ways , it's still literal-minded. If the old config added 9 ports to a single bridge, you'll get 9 ports on a single bridge if you apply it to a new switch with more ports. Same advice: either manually add the remaining ports to the bridge, or p...
bytangent
Fri Aug 05, 2022 4:20 pm
Forum:Announcements
Topic:not strictly related to v7.5beta
Replies:30
Views:2292

Re: not strictly related to v7.5beta

Perhaps you were assuming automated patch application. We can try that, too: $ cd ~/src/linux/kernel $ git reset --hard v5.6.19 $ zstdcat ../routeros-7-source/linux-5.6.3.patch.zst | patch -p1 --batch | grep -c FAILED 28 That's 28 cases where a human will have to go in and find out why the automated...
bytangent
Fri Aug 05, 2022 3:17 pm
Forum:Announcements
Topic:not strictly related to v7.5beta
Replies:30
Views:2292

Re: not strictly related to v7.5beta

The difficulty does not dpeend (much) on number of inserted lines Programmer here: yes, it does. Source: my RSI. :) But okay, we can add diffstat's -m option to get that answer. It tells us there are 4095 hunks in the 5.6.3 patch file and 4953 hunks between Linux kernel 5.6.3 and 5.6.19. It's a hel...
bytangent
Fri Aug 05, 2022 1:57 pm
Forum:Announcements
Topic:not strictly related to v7.5beta
Replies:30
Views:2292

Re: v7.5beta [testing] is released!

取决于他们如何改变…我们没有to guess about that. MikroTik's policy for complying with the GPL is to give the sources to anyone who asks. Some recipients then use their freedoms under the GPL to repost the archive publicly, such as this one here . (Beware: they're using Git LF...
bytangent
Fri Aug 05, 2022 11:50 am
Forum:Announcements
Topic:not strictly related to v7.5beta
Replies:30
Views:2292

Re: v7.5beta [testing] is released!

5.6.19 may not be that big of a jump from 5.6.3 The Linux kernel is one of the busiest software projects of all time. Even between two point releases made a few months apart, it's a huge jump: $ cd ~/src/linux/kernel $ git diff v5.6.3..v5.6.19 | diffstat ... 1687 files changed, 17478 insertions(+),...
bytangent
Fri Aug 05, 2022 11:33 am
Forum:General
Topic:Strange behavior of CRS354-48G-4S+2Q+ [SOLVED]
Replies:7
Views:845

Re: Strange behavior of CRS354-48G-4S+2Q+[SOLVED]

I can see quite different mac address How different? If it's the same except for the last octet, that's normal. Each port on the switch has a different MAC, and you may be connecting to a different port in each case due to bridging. The addresses assigned to a given switch will be in order, so they...
bytangent
Tue Aug 02, 2022 10:05 pm
Forum:Beginner Basics
Topic:after import 9 port switch backup - router Ports 10, 11, 12 don't function
Replies:8
Views:663

Re: after import 9 port switch backup - router Ports 10, 11, 12 don't function

You're lucky the backup for a different type of device restored to the new one in the first place. I'm going to guess that the old config listed 9 ports on the bridge, and your new config now has 9 ports on the bridge, just like the backup told it to do. Computers are literal-minded that way. You ca...
bytangent
Tue Aug 02, 2022 6:34 pm
Forum:General
Topic:Setting System Clock
Replies:6
Views:637

再保险:设置系统时钟

Multicast was intended to work everywhere, and with intentional effort by all network owners between the endpoints it can be made to do so, but as a rule, multicast doesn’t work over the Internet because you can’t ever get that many ducks in a row.
bytangent
Mon Aug 01, 2022 4:33 pm
Forum:General
Topic:邻居公共IP是行不通的
Replies:38
Views:4361

Re: Neighbour public IP doesn't work

use, for example, at start 77.99.55.xxx/yy Virtually every IPv4 address belongs to someone now. That one is part of Virgin Media UK's 77.99.0.0/16 range. Recommend instead use of these special RFC5735 address ranges: TEST-NET-1: 192.0.2.0/24 TEST-NET-2: 198.51.100.0/24 TEST-NET-3: 203.0.113.0/24 Th...
bytangent
Mon Aug 01, 2022 4:30 pm
Forum:General
Topic:邻居公共IP是行不通的
Replies:38
Views:4361

Re: Neighbour public IP doesn't work

everyone can reach it except we cannot reach each other The problem sounds analogous to the hairpin NAT problem , the difference being that it's pushed one layer out, into your ISP's border routers. The logic might be something like "If the source IP belongs to one of our customers, the destin...
bytangent
Wed Jul 27, 2022 5:57 pm
Forum:General
Topic:Low throughput via CRS112-8P-4S
Replies:6
Views:662

Re: Low throughput via CRS112-8P-4S

Theoretically this cpu has 94.7Mb/s in routing mode wih 25 ip filter rules …with full-size Ethernet frames, which occurs only during ideal traffic flow. Real flows include partial frames, so you move a column over in the test results and find 32.8 Mbit/sec, matching more with your results. Obviousl...
bytangent
Tue Jul 26, 2022 11:03 am
Forum:Containers
Topic:v7.1rc3 adds container support
Replies:493
Views:135129

Re: v7.1rc3 adds Docker (TM) compatible container support

Yes a working guide for an MDNS repeater container If you have one of MikroTik's higher-end switches , this might work: /interface/ethernet/switch/rule add switch=switch1 mirror=yes ports=ether4,ether5 \ mac-protocol=ip dst-address=224.0.0.251/32 \ protocol=udp dst-port=5353 add switch=switch1 mirr...