Community discussions

MikroTik App
chris2506
刚刚加入了
Topic Author
Posts: 2
加入: Fri Jul 17, 2015 1:50 pm

Feature Request: zerotier vpn

Fri Jul 17, 2015 1:55 pm

Hi,

It would be great if RouterOS could use Zerotier One
https://www.zerotier.com/

Chris
Top
bleppard
刚刚加入了
Posts: 3
加入: Tue Oct 27, 2015 4:42 am

Re: Feature Request: zerotier vpn

Mon Nov 16, 2015 4:47 pm

Yes, I would really appreciate that also.
Top
DoctorZIP
刚刚加入了
Posts: 2
加入: Mon Feb 08, 2016 2:35 pm

Re: Feature Request: zerotier vpn

Mon Feb 08, 2016 2:53 pm

Join to guys. Would be great to have support of this service. Ready to be beta-tester:)
Top
jarda
Forum Guru
Forum Guru
Posts: 7752
加入: Mon Oct 22, 2012 4:46 pm

Mon Feb 08, 2016 5:25 pm

I don't understand why it is necessary or useful for routers.
Top
DoctorZIP
刚刚加入了
Posts: 2
加入: Mon Feb 08, 2016 2:35 pm

Re:

Fri Feb 12, 2016 9:27 am

I don't understand why it is necessary or useful for routers.
Because I can use many failover connections without static IPs.
Top
majestic
Frequent Visitor
Frequent Visitor
Posts: 90
加入: Mon Dec 05, 2016 11:19 am

Re:

Mon Jun 12, 2017 2:59 pm

I don't understand why it is necessary or useful for routers.
+1 I agree, it would be really useful as Mikrotik doesn't currently support dynamic multipoint VPN (DMVPN) or similar technology.

Zeroteir is a really a very easy/user friendly DMVPN clone (of sorts) which a lot of people deploy when they don't have native support for DMVPN.

It also doesn't require kernel drivers, its all done in usermode as well as uses typical linux tools/devices such as tun/tap, bridges and so forth which means it should't be rocket science to implement to ROS. Memory requirements is fairly minimal (about 4-5MB with about 50+ routes/networks connected).

The throughput is also very very decent and is only just a shy short of native IPSEC connections which is done in the kernel. I get high end 400Mbits (around 480Mits) on a gig connection with minimal CPU load running in usermode. If they did port it to kernel, it would beat IPSEC hands down.

p.s IMO its the best solution right now if you have OpenVZ machines you need to link up to your network/pool where you can't use IPSEC for whatever reason.

This is taken from a 4 CPU system (Intel(R) Xeon(R) CPU E3-1241 v3 @ 3.50GHz) and during the tests only two cores were maxed and this is all done in usermode, no kernel drivers and different DC/ISP.
Code:Select all
iperf3 -c 172.30.50.1 Connecting to host 172.30.50.1, port 5201 [ 4] local 172.30.0.165 port 55866 connected to 172.30.50.1 port 5201 [ ID] Interval Transfer Bandwidth Retr Cwnd [ 4] 0.00-1.00 sec 70.3 MBytes 590 Mbits/sec 157 233 KBytes [ 4] 1.00-2.00 sec 78.9 MBytes 662 Mbits/sec 0 411 KBytes [ 4] 2.00-3.00 sec 76.7 MBytes 643 Mbits/sec 173 247 KBytes [ 4] 3.00-4.00 sec 76.9 MBytes 645 Mbits/sec 38 188 KBytes [ 4] 4.00-5.00 sec 75.6 MBytes 634 Mbits/sec 7 263 KBytes [ 4] 5.00-6.00 sec 74.6 MBytes 626 Mbits/sec 33 215 KBytes [ 4] 6.00-7.00 sec 78.2 MBytes 656 Mbits/sec 12 317 KBytes [ 4] 7.00-8.00 sec 75.1 MBytes 630 Mbits/sec 44 148 KBytes [ 4] 8.00-9.00 sec 69.9 MBytes 586 Mbits/sec 39 172 KBytes [ 4] 9.00-10.00 sec 72.3 MBytes 607 Mbits/sec 19 231 KBytes - - - - - - - - - - - - - - - - - - - - - - - - - [ ID] Interval Transfer Bandwidth Retr [ 4] 0.00-10.00 sec 748 MBytes 628 Mbits/sec 522 sender [ 4] 0.00-10.00 sec 745 MBytes 625 Mbits/sec receiver
Top
warrendt
刚刚加入了
Posts: 1
加入: Wed Jul 05, 2017 1:11 pm

Re: Feature Request: zerotier vpn

Wed Jul 05, 2017 1:13 pm

+1
Zerotier is an incredible VPN solution that allows default routes now. So you can force breakout of traffic wherever on the plant you wish
Top
MRACHINI
刚刚加入了
Posts: 10
加入: Fri Feb 26, 2016 12:53 am

Re: Feature Request: zerotier vpn

Thu Oct 26, 2017 8:50 pm

+1 using ZT since the start its amazing and would be a great addition to mikrotik.
Top
buraglio
Frequent Visitor
Frequent Visitor
Posts: 68
加入: Mon Aug 10, 2015 5:59 pm
Location:+1 (217)
Contact:

Re: Feature Request: zerotier vpn

Mon Nov 27, 2017 6:21 am

Agreed, ZT + MT would be freaking amazing. I'd be more than willing to help alpha this.
+1 using ZT since the start its amazing and would be a great addition to mikrotik.
Top
carlhjerpe
刚刚加入了
Posts: 13
加入: Fri May 15, 2015 12:49 pm

Re: Feature Request: zerotier vpn

Mon Jan 22, 2018 11:56 pm

Others are getting ZeroTier support.

https://docs.opnsense.org/manual/how-tos/zerotier.html
https://github.com/mwarning/zerotier-openwrt

This is a great replacement for OpenVPN, which isn't great in the MikroTik.

It'd be supercool to have ZeroTier as an interface type along with EoIP for tunneling both between MikroTiks and traveling clients.

Would enable people to do many cool things, and it's probably quite cheap to implement. Considering it's userspace code it's no problem keeping the source open and honoring the GPL.

Maybe with RouterOS 7?
Top
mindlesstux
刚刚加入了
Posts: 15
加入: Tue Mar 17, 2009 3:20 pm
Location:Charlotte, NC, USA
Contact:

Re: Feature Request: zerotier vpn

Sat Feb 03, 2018 6:48 am

Adding my voice to the pile.

它工作在允许me to create a little ospf network (overkill but other reasons driving that atm) to allow me to access my remote LANs with ease. Granted I have a VM at the far ends with quagga and zerotier installed to the routing at this time. Having a package for zerotier I could eliminate a VM that its sole job is to route out to zerotier.

I can think of other uses for it as well that would apply to one of my past jobs at a WISP where I started using mikrotik. One could make a whole management layer on zerotier and not have to do vlans or crazy vpn'ing, keeping it simple and clean. Need to work on location A? Join its network and after authing yourself into it, instant access to all devices then on that network. I have not tested yet to see if winbox would work doing a broadcast check for devices over zerotier when using it to access random networks, but in theory one could do that too.
Top
用户头像
cdiedrich
Forum Veteran
Forum Veteran
Posts: 997
加入: Thu Feb 13, 2014 2:03 pm
Location:Basel, Switzerland // Bremen, Germany
Contact:

Re: Feature Request: zerotier vpn

Sat Feb 03, 2018 6:06 pm

I personally don't see zeroTier in a router. It's a self-contained SD-WAN appliance like all the others that are around.
I manage a global network with MikroTik routers and SD-WAN appliances (not zeroTier) and am very happy it is separate.
And I just don't like stuffing each and every possible feature into a router just because it could be nice. If doing so, we will end up with sort of Homer Simpson's car design in a couple of years.
A router is a router and a SD-WAN appliance is a SD-WAN appliance. And IMO it should stay so.

Just my two cents,
-Chris
Top
marrold
Member
Member
Posts: 427
加入: Wed Sep 04, 2013 10:45 am

Re: Feature Request: zerotier vpn

Thu Feb 22, 2018 9:32 pm

+1, ZeroTier would be nice
Top
jantypas
newbie
Posts: 35
加入: Sun May 02, 2010 11:57 pm

Re: Feature Request: zerotier vpn

Sun Jan 13, 2019 12:31 am

I, too, am a ZeroTier user. For those who wonder why we should put it in Microtik, especially if it can appear as a layer-2 interface:
  • ZeroTier is great for doing OSPF across WANs -- yes, I know that's what BGP is for, but there are times we need a "broadcast" interface across a WAN
  • ZeroTier is great as a VPN when you have a client somewhere who knows to install a piece of software and that's it -- no config files, no edits, just install and give me a magic number
  • 我们使用ZeroTier佛r devices in the field that need a "trusted" interface but we can't count on it being routed via the default route. We can't change the routing tables on this test device, so ZeroTier lets us have a "side interface"
  • SDWAN in the cloud -- nice touch -- idenitty based firewall rules, who cares about your assigned IP
  • Works on V4 and V6
  • Mikrotik was never good with OpenVPN over UDP
As far why on the router -- many smaller shops have "a router", not an edge router, VPN unit etc. The shops that know what all of those parts are, are often Cisco shops. Mikrotik is often called CiscNO where I am -- "When your boss won't let you spend money on a Cisco, go with Mikrotik"
Top
rviteri
Frequent Visitor
Frequent Visitor
Posts: 85
加入: Fri Nov 18, 2011 5:53 pm

Re: Feature Request: zerotier vpn

Wed May 29, 2019 4:34 pm

+1 +1 on this!
Top
rogierb
刚刚加入了
Posts: 10
加入: Wed May 14, 2014 4:44 pm

Re: Feature Request: zerotier vpn

Wed Jun 26, 2019 10:49 pm

3 time a +1 for ZT support
Top
emresumengen
刚刚加入了
Posts: 1
加入: Sat Jul 26, 2014 1:15 am

Re: Feature Request: zerotier vpn

Wed Jul 24, 2019 8:04 pm

I personally don't see zeroTier in a router. It's a self-contained SD-WAN appliance like all the others that are around.
I manage a global network with MikroTik routers and SD-WAN appliances (not zeroTier) and am very happy it is separate.
I can relate, and having that "option" to run it would not affect your use case at all. Yet, it would help a lot of people, with different agendas.
And I just don't like stuffing each and every possible feature into a router just because it could be nice. If doing so, we will end up with sort of Homer Simpson's car design in a couple of years.
A router is a router and a SD-WAN appliance is a SD-WAN appliance. And IMO it should stay so.

Just my two cents,
-Chris
Mikrotik is already a small box with lots of features, so I don't think it's fair to try steering it's direction to a "single use device" route... Plus, SD-WAN is not something independent of "routing". The concept of having a separate SD-WAN box does actually not make sense, and I believe it is in our lives just because many router companies could not find the perfect receipe on how to design SD-WAN but rather decided to buy a better startup (look at Cisco, we can clearly see IWAN "try" and then Viptela, and they are clearly keen on bundling it on the ISR). Still, I wouldn't ask (yet) to have this feature on a Cloud Router, but even then it's fair to think that eventually there won't be "routing" without "SD-WAN"...
Top
MikesellT
刚刚加入了
Posts: 5
加入: Fri Nov 15, 2019 9:43 am

Re: Feature Request: zerotier vpn

Fri Nov 15, 2019 9:51 am

I have been using Mikrotik for years, and I just recently started using ZeroTier. Combining them would be a no-brainer. I have tried to hodgepodge together a one-box solution by utilizing OpenWRT inside METARouter and connecting to ZeroTier via OpenWRT, but it's a real pain in the buggy butt. Adding ZeroTier would give Mikrotik a simple SD-WAN-like solution - for those who want it. I know there are some diehard Mikrotik users who don't see the point or haven't come around to SD-WAN yet, but, from my experience, you innovate or lose market share to competitors. I love Mikrotik. I will use them as long as I can, but adding a ZeroTier package would sure be a nice feature.
Top
jantypas
newbie
Posts: 35
加入: Sun May 02, 2010 11:57 pm

Re: Feature Request: zerotier vpn

Fri Nov 15, 2019 2:07 pm

Since Mikrotik appears not to be pursuing other concepts such as Wireguard and ZeroTier, and we're still waiting for OpenVPN with UDP, I finally gave up waiting and just bought a Protecteli box. The atom powered unit can easily run a small Linux distro (Ubutnu 19 in my case), and it handles all of the stuff Mikrotik can't -- Wireguard, ZeroTier, et al. I ended up picking up another (i5, 8GB ram, 120GSSD) for about $350. I'm giving pfSense and OpnSense a serious look since they cna do nearly everything Mikrotik does, and this as well.

Don't get me wrong, at scale, Mikrotik blows them away, but for the smaller sites, I'm having to reconsider Mikrotik.
Top
rogierb
刚刚加入了
Posts: 10
加入: Wed May 14, 2014 4:44 pm

Re: Feature Request: zerotier vpn

Mon Jan 20, 2020 10:52 pm

Adding ZeroTier would give Mikrotik a simple SD-WAN-like solution - for those who want it. I know there are some diehard Mikrotik users who don't see the point or haven't come around to SD-WAN yet, but, from my experience, you innovate or lose market share to competitors. I love Mikrotik. I will use them as long as I can, but adding a ZeroTier package would sure be a nice feature.
++1. I totally agree and would love to see the ZeroTier implementation.
Top
Schinigami
刚刚加入了
Posts: 1
加入: Tue Apr 14, 2020 6:53 pm

Re: Feature Request: zerotier vpn

Tue Apr 14, 2020 6:55 pm

+++ ZeroTier
Top
N8jar
刚刚加入了
Posts: 2
加入: Wed May 08, 2019 7:54 pm

Re: Feature Request: zerotier vpn

Thu Apr 23, 2020 2:17 pm

+1 ZeroTier Integration
Top
jdevora
刚刚加入了
Posts: 9
加入: Tue Mar 27, 2012 4:18 pm

Re: Feature Request: zerotier vpn

Thu May 21, 2020 1:21 am

I would love to have zerotier integration as well...
Top
用户头像
anav
Forum Guru
Forum Guru
Posts: 17370
加入: Sun Feb 18, 2018 11:28 pm
Location:Nova Scotia, Canada
Contact:

Re: Feature Request: zerotier vpn

Thu May 21, 2020 2:41 am

+1 in RoS 8.0;-)
Top
用户头像
bpwl
Forum Guru
Forum Guru
Posts: 2733
加入: Mon Apr 08, 2019 1:16 am

Re: Feature Request: zerotier vpn

Thu May 21, 2020 11:00 am

+1 in RoS 8.0;-)
Zerotier would be very nice. Suggested zerotier for access to a Mikrotik sitting behind double NAT and load balancers. No way to have access from the internet. Zerotier would allow LAN sharing because it does ICE, STUN (NAT hole punching) and has even imbedded free TURN services.viewtopic.php?f=13&t=159879#p787881

If not zerotier, than there are alternatives like Neorouter, SoftEther. (but no free TURN server here).

Something to be linked to VXLAN (ROS 7) ?

@anav: cannot answer your Private Message in this forum (message stays in the outbox).
Top
用户头像
anav
Forum Guru
Forum Guru
Posts: 17370
加入: Sun Feb 18, 2018 11:28 pm
Location:Nova Scotia, Canada
Contact:

Re: Feature Request: zerotier vpn

Thu May 21, 2020 1:53 pm

@anav: cannot answer your Private Message in this forum (message stays in the outbox).
拉脱维亚在北美人残酷的玩笑。的消息leaves the senders outbox only when the intended reader opens it at his/her inbox.
We dont use polish notation calculators either (backwards);-)
Top
用户头像
gnro
newbie
Posts: 36
加入: Sun Aug 05, 2018 9:52 am

Re: Feature Request: zerotier vpn

Sun Dec 20, 2020 12:01 pm

+1, ZeroTier would be nice and very useful on small sites.
Top
3675
刚刚加入了
Posts: 1
加入: Fri Feb 05, 2021 1:36 pm

Re: Feature Request: zerotier vpn

Fri Feb 05, 2021 1:41 pm

+100500
Is there any chance to get this feature? Or I will change Microtik brand to other equipment.
Top
caspat
newbie
Posts: 47
加入: Wed Apr 28, 2010 3:55 pm

Re: Feature Request: zerotier vpn

Fri Aug 06, 2021 1:14 pm

+1000 It would be so great!!
Top
用户头像
rextended
Forum Guru
Forum Guru
Posts: 11474
加入: Tue Feb 25, 2014 12:49 pm
Location:Italy
Contact:

Re: Feature Request: zerotier vpn

Fri Aug 06, 2021 7:40 pm

For you MikroTik has to stop creating routers and only create VPN boxes.

Whenever someone invents another VPN, the "one-post-user-and-go" group and also some of regular users ask to integrate it...

They don't even have a stable v7.2 and have to waste time with VPNs ...

Sounds like great bullshit to me...
Top
wispmikrotik
Member Candidate
Member Candidate
Posts: 120
加入: Tue Apr 25, 2017 10:43 am

Re: Feature Request: zerotier vpn

Tue Aug 31, 2021 7:52 pm

Top
chris2506
刚刚加入了
Topic Author
Posts: 2
加入: Fri Jul 17, 2015 1:50 pm

Re: Feature Request: zerotier vpn

Tue Aug 31, 2021 9:20 pm

Finally, that's awesome!
Top
用户头像
anav
Forum Guru
Forum Guru
Posts: 17370
加入: Sun Feb 18, 2018 11:28 pm
Location:Nova Scotia, Canada
Contact:

Re: Feature Request: zerotier vpn

Tue Aug 31, 2021 9:34 pm

I will compare zerotier to using wireguard to config routers. that is probably the basic utility for a home owner that I can think of.
Top

Who is online

Users browsing this forum:Bing [Bot],Google [Bot],jazzipup,joshhboss,Semrush [Bot]and 33 guests