Community discussions

MikroTik App

Search found 45 matches

bymarkdutton
Sat Aug 05, 2023 1:35 pm
Forum:General
Topic:Bonds on a bridge acting like hub ports.
Replies:2
Views:607

Re: Bonds on a bridge acting like hub ports.

OK. It's a bit hard to show what is happening without "stupid screenshots" though. /interface ethernet set [ find default-name=ether2 ] name=ether2-bond-Aruba-Core set [ find default-name=ether9 ] l2mtu=9092 mtu=9000 name=ether9-To-SAN set [ find default-name=ether10 ] l2mtu=9092 mtu=9000 ...
bymarkdutton
Sat Aug 05, 2023 11:56 am
Forum:General
Topic:Bonds on a bridge acting like hub ports.
Replies:2
Views:607

Bonds on a bridge acting like hub ports.

I have two CRS326-24G-2S+ switches connected together to act as a core pair using MLAG. They are running 7.6 as it seems anything past this version is broken for MLAG. On the bridges of each switch I have 8 bonds and 4 normal ports. The 4 normal ports are not lagged. They go to storage devices which...
bymarkdutton
Wed May 10, 2023 4:24 pm
Forum:General
Topic:MLAG Bridge not work in ROS 7.7 - 7.8 - 7.9, OK in ROS 7.6
Replies:18
Views:3028

Re: MLAG Bridge not work in ROS 7.7 - 7.8 - 7.9, OK in ROS 7.6

I have the same issue. Very annoying on a mission critical network when they give you 30 minutes downtime. I noticed with 7.9, when I did a show lacp neighbour on a connected Cisco switch, it was showing the port address of one of the MTs for both neighbours, not the bond address. When I downgraded ...
bymarkdutton
Wed Nov 23, 2022 4:10 am
Forum:The Dude
Topic:How to Add dude users in V7
Replies:0
Views:929

How to Add dude users in V7

OK, I'm stumped.

How do I add users to MT to give different users access to Dude in V7. The Dude policy has gone from system/users.
bymarkdutton
Fri Nov 18, 2022 6:54 am
Forum:General
Topic:IPIP tunnel with custom keying
Replies:1
Views:197

IPIP tunnel with custom keying

I am sure this has been asked a million times, but is there any way to use custom keying for IPIP tunnels? I can change the default profiles and I don't mind this, but I can't set the tunnel to use IKEV2, which is what I need, as this is a peer setting.

Cheers
bymarkdutton
Wed Dec 22, 2021 2:37 am
Forum:General
Topic:Multi WAN both on DHCP [SOLVED]
Replies:22
Views:3235

Re: Multi WAN both on DHCP[SOLVED]

Thanks Sob. That was the key. I didn't know there was a variable to pick up. It works perfectly.

Cheers.
bymarkdutton
Tue Dec 21, 2021 3:45 am
Forum:General
Topic:Multi WAN both on DHCP [SOLVED]
Replies:22
Views:3235

Multi WAN both on DHCP[SOLVED]

Hi brains trust I have 2 WAN connections and both are DHCP. As the gateway addresses are not always the same, they are not P2P (interfaced based) and the routes themselves are dynamic, I have no solid reference to create any sort of policy based routing. Ideally, it would be great if you could nomin...
bymarkdutton
Wed Apr 28, 2021 2:37 pm
Forum:Forwarding Protocols
Topic:OSPF re-distributing other OSPF routes when set to no
Replies:2
Views:2098

OSPF re-distributing other OSPF routes when set to no

Hi all Sorry if this is already in the system. I may be wrong here, but if I set Redistribute Other OSPF Routes to no, I should not expect these routes to be propagated to other routers should I? I have a central router with 2 connected subnets (over IP tunnels) to 2 remote routers. Running all on A...
bymarkdutton
Tue Nov 12, 2019 4:17 am
Forum:General
Topic:IPIP over IPSEC using different profile and policy templates
Replies:2
Views:1502

Re: IPIP over IPSEC using different profile and policy templates

Thanks Sindy. That looks great.

I will give it a try soon. In the meantime, I just used a policy VPN gateway in Azure and used the standard IPSEC policy based setup in Mikrotik (with my custom profile and policy settings), which worked perfectly.

Mark
bymarkdutton
Fri Nov 08, 2019 10:16 am
Forum:General
Topic:IPIP over IPSEC using different profile and policy templates
Replies:2
Views:1502

IPIP over IPSEC using different profile and policy templates

I need to create and IPIP tunnel to Azure with their VPN connector in routed mode. However, the default Profile and Proposal are used for my other IPIP tunnels. Is there a way to get an IPIP tunnel to use a different profile and proposal than default? If not is there a way to create an IP tunnel tha...
bymarkdutton
Thu Mar 14, 2019 2:10 pm
Forum:General
Topic:LLDP
Replies:136
Views:66699

Re: LLDP

LLDP-MED, yes please else the use of the PoE switches is limited.
Agree 100%. It is a fundamental requirement in any enterprise switch.
bymarkdutton
Thu Mar 14, 2019 2:09 pm
Forum:Beginner Basics
Topic:Voice vlan and mikrotik
Replies:3
Views:4430

Re: Voice vlan and mikrotik

You should enable DHCP VLAN on your phone: https://www.grandstream.com/sites/default/files/Resources/VLAN_Guide.pdf Or configure the VLAN manually. MikroTik does not currently support LLDP-MED which is necessary for communicating voice VLAN ID to phones. This normally isn't a huge problem since mos...
bymarkdutton
Tue Feb 12, 2019 8:08 am
Forum:Forwarding Protocols
Topic:OSPF advertising connected networks
Replies:2
Views:2898

Re: OSPF advertising connected networks

Thanks Murmaider! That did it. I was trying previously to do a discard on 192.168.220.0/30, but I don't think it ever matched properly. Either that, or it was another connected route that was causing the problem. Putting in the explicit allow for the route I wanted to advertise followed by a discard...
bymarkdutton
Mon Feb 11, 2019 12:38 pm
Forum:Forwarding Protocols
Topic:OSPF advertising connected networks
Replies:2
Views:2898

OSPF advertising connected networks

I know I am doing something really dumb here, but I am stuck and I need a hand. I create a backbone area between two routers using an IP tunnel (over IPSEC). For simplicity, the routers each have their local LAN interfaces, their Internet interfaces and their IP tunnel interface. I number the tunnel...
bymarkdutton
Wed Apr 25, 2018 10:43 am
Forum:Announcements
Topic:Advisory: Vulnerability exploiting the Winbox port [SOLVED]
Replies:203
Views:252230

Re: Advisory: Vulnerability exploiting the Winbox port


You can access graphs within winbox - no need to use web access to them.
Yes but the graphs in Winbox are rubbish compared to the web ones with their time and throughput scales.
bymarkdutton
Wed Apr 25, 2018 4:17 am
Forum:Announcements
Topic:Advisory: Vulnerability exploiting the Winbox port [SOLVED]
Replies:203
Views:252230

Re: Advisory: Vulnerability exploiting the Winbox port

This is the second advisory for this same port in as many weeks. Whilst we block it to the world we still feel compelled to update all our customers' routers. I hope this is not a sign of things to come. While I'm on my soapbox I'd like to suggest that graphs are moved off the web management port. T...
bymarkdutton
Thu Mar 09, 2017 4:34 am
Forum:Announcements
Topic:Statement on Vault 7 document release
Replies:92
Views:82177

Re: Statement on Vault 7 document release

You can limit the IP addresses for defined users. Just make sure that any user IDs that have anything more than read capability can log in only from the LAN side of the network. Yeah I know I can limit IP on the graphing, but what I would like to see is open to world graphing. From my understanding...
bymarkdutton
Thu Mar 09, 2017 3:04 am
Forum:Announcements
Topic:Statement on Vault 7 document release
Replies:92
Views:82177

Re: Statement on Vault 7 document release

Whilst we block most of our client routers from the Internet to all but our own IP address for management, there are some clients who want to have the graphs publicly available. I would like to see a separate port for graphing if possible so that this functionality can be available to anyone without...
bymarkdutton
Tue Jul 21, 2015 6:28 am
Forum:Wireless Networking
Topic:CapsMan wishlist
Replies:0
Views:821

CapsMan wishlist

Hi All I have just started trialing Capsman in a development environment. I have only scratched the surface, but these are on my wishlist now. - Auto tuning of an internal wireless network. Power levels and frequencies to ensure smooth transition between nodes. - A graphical heat map in Capsman (or ...
bymarkdutton
Tue Jul 21, 2015 4:57 am
Forum:Wireless Networking
Topic:CAPsMAN and AP frequencies
Replies:12
Views:9671

Re: CAPsMAN and AP frequencies

I would like to add to this. I have found the following (using Capsman 2). If you set your frequency to auto on the CAP, BEFORE you enable capsman control, it will be auto frequency if Capsman does not specify a channel. However, the auto channel system does not honour the implicit 3 usable channels...
bymarkdutton
Tue Aug 19, 2014 9:45 am
Forum:General
Topic:VLANS and switch ports
Replies:2
Views:1280

Re: VLANS and switch ports

OK. Thanks for that. So in relation to multiple VLANS. I only need to define a vlan to ports and CPU if I want to manipulate the VLAN as in my example? The other vlans can be left unassigned at the switch level? It all works fine this way and I have done a million tests, but I don't want to have it ...
bymarkdutton
Tue Aug 19, 2014 4:00 am
Forum:General
Topic:VLANS and switch ports
Replies:2
Views:1280

VLANS and switch ports

Hello. I am trying to wrap my head around where I need to actively configure vlan settings on the switch ports. Most commonly, if I want to create a VLAN trunk to an external switch, I simply create multiple VLAN interfaces and assign them all to the same physical port on the Mikrotik. I end up with...
bymarkdutton
Tue Jul 29, 2014 2:37 pm
Forum:General
Topic:Backup failing on CCR v6.15
Replies:3
Views:2508

Re: Backup failing on CCR v6.15

OK. Update.

冷启动后(关机),come up working again. We can run until the new firmware is out GA. It seems that this is a start up issue.
bymarkdutton
Tue Jul 29, 2014 12:44 pm
Forum:General
Topic:Backup failing on CCR v6.15
Replies:3
Views:2508

Re: Backup failing on CCR v6.15

OK Thanks Normis

Next problem though will be that I can't upgrade the router without netflash.

If I factory default, will I get access to the flash again? I have rebooted, but this did not help.

Is thre any way to get the flash writing without defaulting unit?

Mark
bymarkdutton
Tue Jul 29, 2014 12:30 pm
Forum:General
Topic:Backup failing on CCR v6.15
Replies:3
Views:2508

Backup failing on CCR v6.15

Hi All I have a CCR 9 core on 6.15. It is in operation and working, but I can no longer create a backup. The password for the admin has reverted to blank also and won't save. I can't create a capture file with packet sniffer. It is as if the file system has become read only. The exact error when I t...
bymarkdutton
Fri May 18, 2012 12:37 pm
Forum:General
Topic:My RB493 crashes when I run rsync across my VPN
Replies:3
Views:1871

Re: My RB493 crashes when I run rsync across my VPN

我已经重新配置运行之外的工作VPN tunnel and it seems to have sorted it. Not sure why the load is so high with Rsync, but it killed the router over IPSEC.
bymarkdutton
Thu May 17, 2012 5:30 pm
Forum:General
Topic:My RB493 crashes when I run rsync across my VPN
Replies:3
Views:1871

Re: My RB493 crashes when I run rsync across my VPN

Correct it is an IPSEC tunnel.

Additionally, Rsync is running directly across the connection. It is not tunnelled inside SSH.
bymarkdutton
Thu May 17, 2012 10:19 am
Forum:General
Topic:My RB493 crashes when I run rsync across my VPN
Replies:3
Views:1871

My RB493 crashes when I run rsync across my VPN

Hi All I have a weird problem on my home RB493. I will say from the outset, I have set up dozens of Mikrotiks and I have been using them internally for a couple of years and this is a one off to me. I have a RB2011L in the office, which I am evaluating. It is normally an RB450G. I have an IPSEC tunn...
bymarkdutton
Sat Sep 10, 2011 9:13 am
Forum:General
Topic:Bug in queue tree decision logic
Replies:6
Views:2195

Re: Bug in queue tree decision logic

BTW Fewi I like your idea of using RFC1918 as the source address list so only outbound packets would fire the routing mark. I just put a new rule in my adhoc-bdsl routing table that duplicated the main table rule so the rule would fire in both directions and the inbound route was catered for. It wou...
bymarkdutton
Sat Sep 10, 2011 9:04 am
Forum:General
Topic:Bug in queue tree decision logic
Replies:6
Views:2195

Re: Bug in queue tree decision logic

谢谢Fewi我你说我一样的策略n your post. I have been able to get the outbound interface working fine using routing marks and a custom routing table. The issue now for me is I already have a huge mangle table for my packet marking rules. To keep things tidy and to get maximum pe...
bymarkdutton
Sat Sep 10, 2011 6:14 am
Forum:General
Topic:Bug in queue tree decision logic
Replies:6
Views:2195

Re: Bug in queue tree decision logic

OK. Sorry guys. I have led you astray. The router is very busy, so sometimes it can lead me to make a false assumption. I just did a packet trace on the interfaces. It turns out that the router is NOT using the wrong queues. It is using the wrong interface. However, it is outbounding traffic on the ...
bymarkdutton
Sat Sep 10, 2011 5:33 am
Forum:General
Topic:Bug in queue tree decision logic
Replies:6
Views:2195

Re: Bug in queue tree decision logic

Following are all logs except firewall export, which is huge and I would rather not disclose it anyway. The issue is the queues should be attached to the egress interface and they are not. I know this because when I connect externally to my 4-Amcom-BDSL interface via https (443), and drag a file dow...
bymarkdutton
Sat Sep 10, 2011 4:20 am
Forum:General
Topic:Eth. port flapping, when is this going to be solved?
Replies:78
Views:15623

Re: Eth. port flapping, when is this going to be solved?

Seems it is caused by various things. It is not really a flapping port as such. Flapping ports don't usually just disable then re-enable with a corresponding log entry. Flapping ports are usually the result of a problem with the Ethernet connection to the remote device. I know I can make the problem...
bymarkdutton
Sat Sep 10, 2011 4:12 am
Forum:General
Topic:Bug in queue tree decision logic
Replies:6
Views:2195

Bug in queue tree decision logic

Hi All I have found a bug in the queue tree decision logic which is making it impossible for me to use the router as I need to. The scenario is I have 2 WAN interfaces and I have 2 queue trees attached to these interfaces. I have various mangle rules to create connection and packet marks to fee the ...
bymarkdutton
Wed Aug 10, 2011 6:19 pm
Forum:General
Topic:Eth. port flapping, when is this going to be solved?
Replies:78
Views:15623

Re: Eth. port flapping, when is this going to be solved?

I think I have almost homed in on this problem for my situation. I swapped out my RB750G for my RB450G today. No problems initially, but then I set about making the changes I had made on the RB750G just before it started to play up (coincidentally the same day I upgraded the firmware). My config is ...
bymarkdutton
Wed Aug 10, 2011 7:04 am
Forum:General
Topic:Eth. port flapping, when is this going to be solved?
Replies:78
Views:15623

Re: Eth. port flapping, when is this going to be solved?

I too am having port flapping on my RB750G since upgrading from 5.0beta to 5.5. I am using 4 ports. Three of the ports are dropping then resuming. It is not false logging as I went to the log to work out why I was getting VOIP silence periods of around 10 - 20 seconds. Looking at the log it appears ...
bymarkdutton
Wed Jul 20, 2011 1:46 pm
Forum:Beginner Basics
Topic:How do I stop interfaces from changing names after restore??
Replies:4
Views:1768

Re: How do I stop interfaces from changing names after resto

人这是好如果没有错误the export. I have just done an export from a 750G on v5.5. When I go to import I get "expected end of line at line x, column y" The problem is the exported line is creating the script with the wrong syntax. E.G. /queue interface set 1-Loca...
bymarkdutton
Wed Jul 20, 2011 1:13 pm
Forum:Beginner Basics
Topic:How do I stop interfaces from changing names after restore??
Replies:4
Views:1768

Re: How do I stop interfaces from changing names after resto

I too was trying to figure this out. However, in defence of Mikrotik, when you do a copy run tftp, then copy tftp run you ARE working with text files.
bymarkdutton
Fri Mar 18, 2011 7:46 am
Forum:General
Topic:Efficient connection marking and packet marking for QoS
Replies:2
Views:1490

Efficient connection marking and packet marking for QoS

Hi All Just want to do a sanity check. I have setup a queue tree and use mangle rules to create the appropriate packet marks. I read an interesting wiki article showing a rule that would filter TCP traffic, by port, etc and give it a connection mark, with passthrough enabled. Immediately following i...
bymarkdutton
Tue Oct 19, 2010 2:01 pm
Forum:General
Topic:Accessing remote IPSEC site from within Router
Replies:9
Views:2348

Re: Accessing remote IPSEC site from within Router

OK. I believe it is definately preserving the markings on encryption. here is what I do. in prerouting mangle table, I mark the packets based on DSCP, address:port, whatever as VOIP. I then create a queue tree with a queue dedicated to VOIP. The queue tree is attached to my external interface. My SI...
bymarkdutton
Tue Oct 05, 2010 9:38 am
Forum:General
Topic:Accessing remote IPSEC site from within Router
Replies:9
Views:2348

Re: Accessing remote IPSEC site from within Router

That's right. On a standard Linux router using the Freeswan IPSEC stack we would set a flag in the ipsec.conf file being hidetos=no. This would cause the encrypter to put the DSCP flag into the outer packet. We would then create a mangle rule as follows. iptables -t mangle -I TS -p 50 -j RETURN ipta...
bymarkdutton
Tue Oct 05, 2010 6:42 am
Forum:General
Topic:Accessing remote IPSEC site from within Router
Replies:9
Views:2348

Re: Accessing remote IPSEC site from within Router

Excellent diagrams! I actually saw these previously, but I did not scroll down to the end, which shows clearly the double handling of packets through the output routing phase if encrypted. This leads me to two more questions. 1. Will packet marks survive the encryption process? 2. Related to above, ...
bymarkdutton
Fri Oct 01, 2010 9:15 am
Forum:General
Topic:Accessing remote IPSEC site from within Router
Replies:9
Views:2348

Re: Accessing remote IPSEC site from within Router

OK, that makes sense. Could you please in basic ascii art, show the path the packets take including encryption. I am used to Linux IP using freeswan, which encrypts data before it enters the routing stack. I can see the advantages of encypting after routing, particularly when doing QoS, but I am a b...
bymarkdutton
Fri Sep 24, 2010 5:06 am
Forum:General
Topic:Accessing remote IPSEC site from within Router
Replies:9
Views:2348

Accessing remote IPSEC site from within Router

Hi All I have a set up where I have two sites linked via RB750G routers over IPSEC tunnel. I want site B to get its DHCP from a DHCP server in site A. I have set up the relay, etc, but there is an issue getting the routers to traverse the tunnel correctly. Devices behind the router are fine as they ...