The official Mikrotik router thread

Hey so glad somebody else is trying this, as I was unsuccessful. Basically the same setup as you, but instead of my ISP limit of 200/100 on a speedtest its drops to 80/70. Switch back to default-small and speedtest goes normal 180/85. I have NAT ticked but remember taking that off and it did nothing. I didnt play with it much to be fair, and am also on ros7.2rc4. Take it a speedtest works fine for you?
What is your CPU usage like when you do the speedtest? I did notice that doing a speedtest, the speed starts slow and then creeps up to just under line speed. But I am not too concerned with speedtests as I just want a usable network when I have some heavier files downloading.

But obviously in your case, getting 80/70 means something might be off. What hardware are you running this on?
 
I am interested to try cake on my 5g once my mikrotik uk power plug arrives :P

Although I think once you enable queueing , you loose fasttrack and I wont be able to use the speeds that the 5g can do
 
I am interested to try cake on my 5g once my mikrotik uk power plug arrives :p

Although I think once you enable queueing , you loose fasttrack and I wont be able to use the speeds that the 5g can do
I have Fasttrack turned off, not sure why, but there was probably a reason for it (I think something to do with route marking on my old config)
 
Hey so glad somebody else is trying this, as I was unsuccessful. Basically the same setup as you, but instead of my ISP limit of 200/100 on a speedtest its drops to 80/70. Switch back to default-small and speedtest goes normal 180/85. I have NAT ticked but remember taking that off and it did nothing. I didnt play with it much to be fair, and am also on ros7.2rc4. Take it a speedtest works fine for you?
I also see my speedtest gets affected when I implement this
 
I also see my speedtest gets affected when I implement this
I asked about the HW as Cake is enough to peg my CPU usage at around 30% for a 30M/30M queue. This is on an RB760 with a quad core 880MHz CPU.

I'd imagine that the CPU would flatline at around 100M/100M, hence maybe why @yogidabear is seeing low speeds. In that case, something like fq-codel might be a better bet. I will test it out on my side and compare.
 
I asked about the HW as Cake is enough to peg my CPU usage at around 30% for a 30M/30M queue. This is on an RB760 with a quad core 880MHz CPU.

I'd imagine that the CPU would flatline at around 100M/100M, hence maybe why @yogidabear is seeing low speeds. In that case, something like fq-codel might be a better bet. I will test it out on my side and compare.
Exact same as you Hexs so we twinsys :) The CPU spikes to just over 50% but doesn't even hit 60% when doing the speedtest. Roughly 20% higher that usual doing a speedtest, but still doesn't explain why I get less than half what I should. My queues are a little different to yours in that I have some in a parent, but took all that away and had the same experience. Might be ros7.2, as we differ there but really not sure
 
Exact same as you Hexs so we twinsys :) The CPU spikes to just over 50% but doesn't even hit 60% when doing the speedtest. Roughly 20% higher that usual doing a speedtest, but still doesn't explain why I get less than half what I should. My queues are a little different to yours in that I have some in a parent, but took all that away and had the same experience. Might be ros7.2, as we differ there but really not sure
Are you seeing a lot of dropped traffic in your queues? It could be something to do with that, but it is odd that you are seeing a drop in packets even with the CPU having ample headroom.

Perhaps try an fq-codel config as I did above? I used the default config, and it seems to work well. I will fiddle with it this weekend and see if I can improve on it a bit
 
Are you seeing a lot of dropped traffic in your queues? It could be something to do with that, but it is odd that you are seeing a drop in packets even with the CPU having ample headroom.

Perhaps try an fq-codel config as I did above? I used the default config, and it seems to work well. I will fiddle with it this weekend and see if I can improve on it a bit
Thank you for all the help!! So we dont just do things because we can, and my reason for even commenting was before I did the speedtest I opened an RDP and was browsing the web and could have been mistaken but I think I saw a difference like things were better on cake. Have you noticed any difference since implementing as thats the only reason I was even bothered by reverting back?
 
Thank you for all the help!! So we dont just do things because we can, and my reason for even commenting was before I did the speedtest I opened an RDP and was browsing the web and could have been mistaken but I think I saw a difference like things were better on cake. Have you noticed any difference since implementing as thats the only reason I was even bothered by reverting back?
I think it makes more of a difference on links that are slower/smaller, so someone running a 10/10 link would likely see a bigger difference than someone running a 100/100 link, for example.

It's all about managing packets so that there is enough bandwidth available for all devices, so that devices don't end up being starved for bytes when one client tries to hog it all. With cake/fq-codel turned on, for example, I notice a difference in browsing speed when my wife is watching a 4k Netflix movie, for instance. Prior to the queue, browsing was erratic due to all the available bandwidth going to the TV box, whereas now I can reserve a small bit for browsing (which is sporadic in nature) and the 'queued' bits for the 4k stream can play catch-up when my browsing traffic is quiet.

I'm going to try fq-codel out for a few days, and play around with other queue types until I find one that works. The only issue is that currently, we are having major issues in PE with Frogfoot, and seeing up to 10% packet loss on average every evening, so I don't really have an ideal time to sit and play with this stuff after hours.
 
It's all about managing packets so that there is enough bandwidth available for all devices, so that devices don't end up being starved for bytes when one client tries to hog it all.
I hear you!! 2 decades ago my ISP had a 2meg diginet pipe as its main feed, and P2P was the bane of our existence. Frogfoot was 2 linux propellor heads that were far brighter than me. Still not bright but luckily no longer an ISP :) Will try cake again, thank you.
 
Cross-posting from Hardware bargains:
MikroTik hAP ac2

Router with 5x GB Ethernet ports, AC Speeds, POE, USB and Router OS all for R360? Not sure if this is a bargain or if there's some kind of catch, I ordered two, since these sell for over 1k at other places.



I've seen Mikrotik mentioned a lot when it comes to networking stuff. Is it really that good?

What benefit would I have running a Mikrotik router over the standard Afrihost Huawei AX3?
 
Cross-posting from Hardware bargains:


I've seen Mikrotik mentioned a lot when it comes to networking stuff. Is it really that good?

What benefit would I have running a Mikrotik router over the standard Afrihost Huawei AX3?
They deserve the reputation that they have.

They have a steep learning curve, but their products are very flexible and provided you use the right product for the job, you can't go wrong.

There are many benefits, probably too many to list, but you will have access to enterprise-grade stuff that you likely won't find on the Huawei one that you currently have. Things like scripts, MPLS, proper QoS, web proxies, load balancing, site-to-site VPN, RADIUS, etc etc.

But be prepared to struggle at first if you aren't used to working with WinBox. It took me a good month of sitting and fiddling each day to get comfortable with the software, and I am still learning something each day. Their stuff is also really well documented, and community support is top notch.
 
The power to make or break just about anything,not odd to lock yourself out of it initially when you fiddle
Thank you reset button
I recommend everyone who is playing around click on the "safe mode" button in winbox

This will tell the router not to permanently apply changes, so a simple reboot can get you back in
if you lock yourself out, wish I knew about this from the beginning :)

Remember to turn it off to apply the changes when you are ready though
 
So was still unable to get cake working, and tried a couple different things so am going to blame ros7.2 opposed to my ignorance..... fq_codel on the other hand just works right off the bat, and am going to try that for a while

Code:
/queue type
add kind=fq-codel name=fq_codel
/queue simple
add max-limit=170M/85M name=Telkom queue=fq_codel/fq_codel target=TelkomPPPoE

Thank you again to @PhireSide for the help!!
 
I'm feeling lazy.....

Anyone feel like uploading some basic firewall 'hardening' scripts for a new install - RB3011 RoS 7.1.3
Mikrotik includes a pretty good default config, but it's always good to harden it further against common attacks. The most obvious changes are of course using a non-default username and a good password, and only allowing administrative access from restricted networks/subnetworks/VLANs.

Here is what I am running:

Code:
/ip firewall filter add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
/ip firewall filter add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
/ip firewall filter add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
/ip firewall filter add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
/ip firewall filter add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec
/ip firewall filter add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec
/ip firewall filter add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related disabled=yes hw-offload=yes
/ip firewall filter add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
/ip firewall filter add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
/ip firewall filter add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
/ip firewall filter add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN
/ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface=pppoe0
##/ip firewall nat add action=dst-nat chain=dstnat comment=Wireguard dst-port=51820 protocol=udp to-addresses=10.0.0.5
##/ip firewall nat add action=dst-nat chain=dstnat comment=Transmission dst-port=51413 protocol=tcp to-addresses=10.0.0.5
/ip firewall raw add action=drop chain=prerouting comment="TCP invalid combination of flags attack (7 rules)" log=yes log-prefix=RAW protocol=tcp tcp-flags=!fin,!syn,!rst,!ack
/ip firewall raw add action=drop chain=prerouting log=yes log-prefix=RAW protocol=tcp tcp-flags=fin,syn
/ip firewall raw add action=drop chain=prerouting log=yes log-prefix=RAW protocol=tcp tcp-flags=fin,rst
/ip firewall raw add action=drop chain=prerouting log=yes log-prefix=RAW protocol=tcp tcp-flags=fin,!ack
/ip firewall raw add action=drop chain=prerouting log=yes log-prefix=RAW protocol=tcp tcp-flags=fin,urg
/ip firewall raw add action=drop chain=prerouting log=yes log-prefix=RAW protocol=tcp tcp-flags=syn,rst
/ip firewall raw add action=drop chain=prerouting log=yes log-prefix=RAW protocol=tcp tcp-flags=rst,urg
/ip firewall raw add action=drop chain=prerouting comment="TCP Port 0 attack (2 rules)" log=yes log-prefix=RAW protocol=tcp src-port=0
/ip firewall raw add action=drop chain=prerouting dst-port=0 log=yes log-prefix=RAW protocol=tcp
/ip firewall raw add action=drop chain=prerouting comment="UDP Port 0 attack (2 rules)" log=yes log-prefix=RAW protocol=udp src-port=0
/ip firewall raw add action=drop chain=prerouting dst-port=0 log=yes log-prefix=RAW protocol=udp
/ip firewall raw add action=drop chain=prerouting comment="SYN fragmented attack" fragment=yes log=yes log-prefix=RAW protocol=tcp tcp-flags=syn
/ip firewall raw add action=drop chain=prerouting comment="IP option loose-source-routing" ipv4-options=loose-source-routing log=yes log-prefix=RAW
/ip firewall raw add action=drop chain=prerouting comment="IP option strict-source-routing" ipv4-options=strict-source-routing log=yes log-prefix=RAW
/ip firewall raw add action=drop chain=prerouting comment="IP option record-route" ipv4-options=record-route log=yes log-prefix=RAW
/ip firewall raw add action=drop chain=prerouting comment="IP option router-alert" ipv4-options=router-alert log=yes log-prefix=RAW
/ip firewall raw add action=drop chain=prerouting comment="IP option timestamp" ipv4-options=timestamp log=yes log-prefix=RAW
/ip firewall raw add action=drop chain=prerouting comment="IP options left, except IP Stream used by the IGMP protocol" ipv4-options=any log=yes log-prefix=RAW protocol=!igmp

You will notice I use mostly standard rules, with a few added. It's controversial to allow ICMP pings in but I allow it for PMTU discovery to work properly. I've commented out some DSTNAT rules that you likely won't use as it's just port forwarding for my Wireguard server and Transmission. I also don't use Fasttrack, I think for another script that I used, but in my case, I can probably enable it again.

The raw rules are meant to stop most attacks that are commonly seen from botnets. I've only seen one or two actual attempts blocked, though.

These rules only allow access to router services from my local LAN:

Code:
/ip service set telnet address=10.0.0.0/24
/ip service set ftp address=10.0.0.0/24
/ip service set www address=10.0.0.0/24
/ip service set ssh address=10.0.0.0/24
/ip service set api address=10.0.0.0/24
/ip service set winbox address=10.0.0.0/24
/ip service set api-ssl address=10.0.0.0/24

IPv6 firewall rules:

Code:
/ipv6 firewall address-list add address=::/128 comment="defconf: unspecified address" list=bad_ipv6
/ipv6 firewall address-list add address=::1/128 comment="defconf: lo" list=bad_ipv6
/ipv6 firewall address-list add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6
/ipv6 firewall address-list add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6
/ipv6 firewall address-list add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6
/ipv6 firewall address-list add address=100::/64 comment="defconf: discard only " list=bad_ipv6
/ipv6 firewall address-list add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6
/ipv6 firewall address-list add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6
/ipv6 firewall address-list add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6
/ipv6 firewall filter add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked log=yes log-prefix=IPv6
/ipv6 firewall filter add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
/ipv6 firewall filter add action=accept chain=input comment="defconf: accept ICMPv6" protocol=icmpv6
/ipv6 firewall filter add action=accept chain=input comment="defconf: accept UDP traceroute" port=33434-33534 protocol=udp
/ipv6 firewall filter add action=accept chain=input comment="defconf: accept DHCPv6-Client prefix delegation." dst-port=546 protocol=udp src-address=fe80::/10
/ipv6 firewall filter add action=accept chain=input comment="defconf: accept IKE" dst-port=500,4500 protocol=udp
/ipv6 firewall filter add action=accept chain=input comment="defconf: accept ipsec AH" protocol=ipsec-ah
/ipv6 firewall filter add action=accept chain=input comment="defconf: accept ipsec ESP" protocol=ipsec-esp
/ipv6 firewall filter add action=accept chain=input comment="defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
/ipv6 firewall filter add action=drop chain=input comment="defconf: drop everything else not coming from LAN" in-interface-list=!LAN
/ipv6 firewall filter add action=accept chain=forward comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
/ipv6 firewall filter add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
/ipv6 firewall filter add action=drop chain=forward comment="defconf: drop packets with bad src ipv6" src-address-list=bad_ipv6
/ipv6 firewall filter add action=drop chain=forward comment="defconf: drop packets with bad dst ipv6" dst-address-list=bad_ipv6
/ipv6 firewall filter add action=drop chain=forward comment="defconf: rfc4890 drop hop-limit=1" hop-limit=equal:1 protocol=icmpv6
/ipv6 firewall filter add action=accept chain=forward comment="defconf: accept ICMPv6" protocol=icmpv6
/ipv6 firewall filter add action=accept chain=forward comment="defconf: accept HIP" protocol=139
/ipv6 firewall filter add action=accept chain=forward comment="defconf: accept IKE" dst-port=500,4500 protocol=udp
/ipv6 firewall filter add action=accept chain=forward comment="defconf: accept ipsec AH" protocol=ipsec-ah
/ipv6 firewall filter add action=accept chain=forward comment="defconf: accept ipsec ESP" protocol=ipsec-esp
/ipv6 firewall filter add action=accept chain=forward comment="defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
/ipv6 firewall filter add action=drop chain=forward comment="defconf: drop everything else not coming from LAN" in-interface-list=!LAN

This should be a good starting point for you :)
 
So was still unable to get cake working, and tried a couple different things so am going to blame ros7.2 opposed to my ignorance..... fq_codel on the other hand just works right off the bat, and am going to try that for a while

Code:
/queue type
add kind=fq-codel name=fq_codel
/queue simple
add max-limit=170M/85M name=Telkom queue=fq_codel/fq_codel target=TelkomPPPoE

Thank you again to @PhireSide for the help!!
No problem!

I am also using fq_codel again as cake is also not working 100% for me. I find that it 'ramps up' download speeds too slowly, so it will sometimes sit and download at a fraction of line speed and then if I start browsing the web it will suddenly speed up. I think it needs more tuning but fq_codel seems to work a little better 'out of the box', so to speak.

One small change I can recommend relating to your setup-

I'd change this:

add max-limit=170M/85M name=Telkom queue=fq_codel/fq_codel target=TelkomPPPoE

to this:

add max-limit=195M/97M name=Telkom queue=fq_codel/fq_codel target=<network/cidr> dst=TelkomPPPoE

The target is the network that you want the queue to be applied to, and the dst is the interface that you want the queue to limit. I'm sure your setup would work, but from reading the documentation I think the way I outlined above is how it ought to work. This way you can also target a specific VLAN or a specific address as well if you wanted certain hosts or subnets to bypass the queue for whatever reason (or if you decide to do load-balancing or failover in the future).

I also upped the queue limit as fq_codel works better with between 95-98% of your linespeed provided to it. YMMV though as I am used to working with much slower lines, so I can't promise it will work with your 200/100 line. You might need to allow more or less leeway depending on how accurate the actual speeds you receive are.

EDIT:

So this is my current config. With it, I manage to get an A+ on Waveform's Bufferbloat test with +4ms on download and +0ms on upload. I can get it to +0/+0 but that requires me to gimp my linespeed by quite a hefty amount. This is probably just due to a combination of background network traffic, an over-estimation of linespeed on Frogfoot's network, and possibly dropped packets/retransmits (see post #3620 here for an example of what we have to deal with on the daily). I've also only enabled it between 06h30 and 22h00, which I deem to be 'core hours'. Outside of this, latency shouldn't matter so any background downloads/traffic can go bos on the line and it won't matter if there is bloat as I'll likely be asleep:)

I'm not sure if it's better to add the queue on the physical connection or the pppoe connection tunnel that runs across it. My gut says that it's better to target the actual tunnel as that's the link from your ISP, but I am sure the difference would be negligible.


Code:
/queue type
add kind=fq-codel name=fq_codel
/queue simple
add dst=pppoe0 max-limit=27M/27M name=fq_codel queue=fq_codel/fq_codel target=10.0.0.0/24 time=6h30m-22h,sun,mon,tue,wed,thu,fri,sat
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X