The official Mikrotik router thread

Thinking of upgrading from RB2011 to RB4011.

What's the easiest way to duplicate my current setup (including certs)?
Wont the backup option cover the certs?

I normally start with a fresh config and run the export command on the old router and fix interface names etc then copy and paste it to the new routers terminal/ssh (add an allow firewall rule for yourself first just to be safe)
Check if the export command includes the certs
 
Wont the backup option cover the certs?

I normally start with a fresh config and run the export command on the old router and fix interface names etc then copy and paste it to the new routers terminal/ssh (add an allow firewall rule for yourself first just to be safe)
Check if the export command includes the certs
Importing a backup from a different Mikrotik bricks the new Mikrotik so don't do that.. can be fixed with netinstall though.

Export is the way to go.
Not sure about certificates
 
TIL that mikrotik ipv6 doesn't have fasttrack ... :unsure:

It was just one of those things I assumed existed behind the scenes
(Yeah I know what happens when you assume)

My Hex POE / RB960PGS does about 180mbit on v6 and 700mbit on v4

The 180 is about the same as when I don't have fasttrack enabled on v4

Going to play around with my filter rules to see if i can get the number of rules down and maybe more speed
 
Hmm,

I'm suddenly (since last night) seeing lots of these error messages (looks like an attempt at hacking into router) - wondering if it could be connected to the fact that I installed a 'generic' (SmartLife / Tuya) LED bulb yesterdsay afternoon.

login failure for user admin from 116.98.160.162 via ssh

The 'admin' varies between 'ubnt/pi/system/support/default' and the via varies beteween 'ssh/api'
 
Hmm,

I'm suddenly (since last night) seeing lots of these error messages (looks like an attempt at hacking into router) - wondering if it could be connected to the fact that I installed a 'generic' (SmartLife / Tuya) LED bulb yesterdsay afternoon.

login failure for user admin from 116.98.160.162 via ssh

The 'admin' varies between 'ubnt/pi/system/support/default' and the via varies beteween 'ssh/api'
Vietnamese IP?
 
Hi everyone!

so currently my internet at home has been offline for 2 weeks due to me changing isps.

I currently have an uptime robot notifier that ping my xxx.sn.mynetname.net, to my surprise i got a notification that it's up but when ii checked i was still offline.

it looks it's still resolving to an old IP that now belongs to someone else....I find it very strange.
is the TTL on those addresses more then 2 weeks?surely it should expire by now....
or what is going on?
 
I have a few questions I posted here:

 
Hi everyone!

so currently my internet at home has been offline for 2 weeks due to me changing isps.

I currently have an uptime robot notifier that ping my xxx.sn.mynetname.net, to my surprise i got a notification that it's up but when ii checked i was still offline.

it looks it's still resolving to an old IP that now belongs to someone else....I find it very strange.
is the TTL on those addresses more then 2 weeks?surely it should expire by now....
or what is going on?
As you say the old IP assigned to xxx.sn.mynetname.net now belongs to someone else, hence online. The TTL is related to the intermediate routers/dns proxy and how they cache that entry - not how long the DNS entry for xxx.sn.mynetname.net or its IP exists. It will stick with old ip until you update it.
 
Shouldn't you have a default firewall rule blocking the incoming ssh anyway? Or did you explicitly open it for remote ssh?
If you are not running the service nothing answers so no need to block the port. If you are running the service, as you need it, then yes you need to take measures to protect yourself. If you are not sure what you are running check here:

/ip service> pri
Flags: X - disabled, I - invalid
# NAME PORT ADDRESS CERTIFICATE
0 XI telnet 23
1 XI ftp 21
2 XI www 80
3 XI ssh 22
4 XI www-ssl 443
5 XI api 8728

If you do not need it, rather disable the service.
 
If you are not running the service nothing answers so no need to block the port. If you are running the service, as you need it, then yes you need to take measures to protect yourself. If you are not sure what you are running check here:

/ip service> pri
Flags: X - disabled, I - invalid
# NAME PORT ADDRESS CERTIFICATE
0 XI telnet 23
1 XI ftp 21
2 XI www 80
3 XI ssh 22
4 XI www-ssl 443
5 XI api 8728

If you do not need it, rather disable the service.
Ye i understand - but this is how peeps leave DNS proxy's open if they don't take care
 
Morning everyone.

Without reading 24 pages, what is the current go-to for a home use Mikrotik? I currently have an RB750gr3, but it's starting to see its limits in terms of processing more complex rules (and IPv6). I have OS 500Mbit, and I can start to see the limits on the small little router :)

Any suggestions for futureproofing a little? Budget around 3-4k max.
 
Morning everyone.

Without reading 24 pages, what is the current go-to for a home use Mikrotik? I currently have an RB750gr3, but it's starting to see its limits in terms of processing more complex rules (and IPv6). I have OS 500Mbit, and I can start to see the limits on the small little router :)

Any suggestions for futureproofing a little? Budget around 3-4k max.
Well you aren't a typical home user, and I take it you don't need WiFi, so then grab this one:


R1,200 is a bloody bargain since normal price is R3,600 at Scoop.

And if he has already sold it then buy it for full price. Its a powerful router that will handle your current and future needs.
 
Well you aren't a typical home user, and I take it you don't need WiFi, so then grab this one:


R1,200 is a bloody bargain since normal price is R3,600 at Scoop.

And if he has already sold it then buy it for full price. Its a powerful router that will handle your current and future needs.
Thank you, that's quite the upgrade and a great price :love:
 
Top
Sign up to the MyBroadband newsletter
X