Daniil Yurevich
Будет у тебя коммутация или маршрутизация
Daniil Yurevich
Если коммутация и разные vlan то имеет смысл собрать vlan на свитч чипе
Glue
Ну если есть данные то почему бы и нет, но надо понимать какие задачи, роутинг, нат, файрвол... чем больше навешаешь тем быстрее нужен роутер
Daniil Yurevich
Будет у тебя коммутация или маршрутизация
Если роутинг то уже написали выше.
罗森博姆
Daniil Yurevich
https://help.mikrotik.com/docs/display/ROS/Basic+VLAN+switching#BasicVLANswitching-Otherdeviceswithabuilt-inswitchchip
Roman
Кто пользуется ац3 и wifiwave2? Странные лаги в работе вифи, потоянные зависания на несколько секунд. Без wave2 всё работает стабильно.
Daniil Yurevich
А есть где-нибудь про почитать подробности?
Ну и вот тут еще почитать про то, что умеет те или иные свитч чипы. https://help.mikrotik.com/docs/display/ROS/Switch+Chip+Features#SwitchChipFeatures-Introduction=
Геннадий
Разгрузи проц переместив вланы на свич
мне это не надо, я ушел на аппаратный свитч от циски. как говорится, скупой платит дважды... глупый бесконечно. лучше 1 раз настроить нормальную железку, чет тратить драгоценное время на войну с недоделкой. (моё имхо)
Glue
это вообще странный кейс если на роутере приходится свитчить транзитные вланы !
Glue
самому себе рассказать ?
Геннадий
а то они глупые, не знают, что это странный кейс )
Daniil Yurevich
У меня, к примеру, цех. До разных помещений растянута оптика. От кросса сделаны отводы 1волоконным кабелем. В помещении стоят станки, которым нужна сеть. HEX-S у меня как свитч работает.
Daniil Yurevich
6 портов до соплей.
Daniil Yurevich
Есть ли там трафик существенный? Нет. Справился бы CPU? Вполне, но так уж сложилось, что с ROS7 теперь коммутация аппаратная на Bridge vlan filtering.
Glue
дороговато для свича !
Daniil Yurevich
Мелочь, а приятно. Недорогой свитч с sfp портом.
Daniil Yurevich
дороговато для свича !
4000 рублей - дорого?
Илья
Glue
я деже и не знаю что ответить на этот бред ))
Илья
дороговато для свича !
сейчас то дорого. а тогда вполне себе. ну или 4к если всё-таки дорого, то не знаю. могу за эту цену предложить гигабитный л2 длинк на 8 портов
Glue
если ваш свитч микрот прозрачно меняется на любой управляемый L2 коммутатор и вопрос не про деньги - тогда ладно
Glue
а то есть тут любители целый район города на микротах сделать, а вот теперь заменить это всё нечем и переделывать приходится
Glue
тоже было дешево и куча фич
Daniil Yurevich
если ваш свитч микрот прозрачно меняется на любой управляемый L2 коммутатор и вопрос не про деньги - тогда ладно
Сколько будет стоит стоить свитч управляемый L2 с гигабитными портами и sfp ?
Daniil Yurevich
Я не ISP.
Glue
1 штука всегда будет дорого, тем более сейчас вообще цены неадекватные
Daniil Yurevich
Геннадий
Вот я к этому и веду. Что у каждого свой кейс.
у каждого своя цена времени... кейсы тут не при чем
Daniil Yurevich
Чего я тут распинаюсь перед тобой...
Miha
С ними никто не ходит. Они у провайдеров стоят в серверных. Если есть пропуск - отправляют месседж в РКН, а те провайдерам штраф выкатывают в 50к рублей.
Ага, но можно сделать песочницу. Как раз на CHR адрес листы, и скриптом подпихивать в адрес листы и заодно в bind нужные url запихивать для заворота не туда))
Glue
Вот я к этому и веду. Что у каждого свой кейс.
у многих своё "я так хочу" зачастую перевешивает Здравый смысл и они еще руководству свои рацухи умудряются обосновать
Glue
пионеры так и делают! url в bind
Glue
Илья
удоли
Grigorius
Админы удалите этого @mItalccg пишет в личку о крипте
Null
Тем временем на горизонте замаячила 7.4 😊 What's new in 7.4beta2 (2022-Jun-07 12:08) *) api - fixed comma encoding within URL when using the ".proplist" argument; *) bridge - properly process IPsec decapsulated packets through the firewall when the "use-ip-firewall" option is enabled; *) capsman - require a unique name for configuration and configuration pre-sets; *) cloud - print critical log message when system clock gets synchronised; *) console - added ":retry" command; *) console - fixed situation when print output was not consistent; *) dns - convert the domain name to lowercase before matching regex; *) e-mail - added VRF support (CLI only); *) filesystem - fixed repartition on RB5009 series devices; *) firewall - added "srcnat" and "dstnat" flags to IPv6/Firewall/Connection table; *) firewall - added support for IPv6/Firewall/NAT action=src-nat rules (CLI only); *) firewall - fixed IPv6 NAT functionality when processing GRE traffic on TILE devices; *) firewall - fixed IPv6/Firewall/RAW functionality; *) firewall - include "connection-mark", "connection-state", and "packet-mark" when packet logging is enabled; *) firewall - properly handle interface matcher when VRF interface is specified; *) hotspot - fixed ARP resolution for clients when address pool is specified on the server; *) hotspot - fixed Walled Garden entries with action=deny; *) ipv6 - fixed system stability when adding/removing IPv6 address; *) ldp - correctly handle AFI selection for usage on dual-stack peers; *) lte - request connect with the same IP type as in LTE attach status for MBIM; *) lte - fixed Telit AT interface numbering; *) lte - improved LTE interface detection for LtAP-2HnD devices; *) lte - keep MBIM working even if AT channel fails to respond in the initialisation stage; *) mmips - improved USB device detection after system bootup; *) mpls - fixed VPLS functionality when PW peer is an immediate neighbor; *) ovpn - use selected cipher by default when the server does not provide "cipher" option; *) pimsm - improved system stability when changing configuration; *) ppp - properly try to use different authentication algorithms when Conf-Rej is received during the LCP phase; *) quickset - specify the "in-interface-list=WAN" attribute on firewall rules created through "Port Mapping"; *) route - added option to join static IGMP and MLD groups (available in "/routing/gmp" menu, CLI only) *) route - fixed false route type detection as blackhole; *) route - provide more detailed information about prefixes when using "discourse" tool; *) routing - moved "/interface bgp vpls" to "/routing bgp vpls" menu; *) routing-filter - fixed regexp community matcher; *) ssh - disable ssh-rsa when strong-crypto=yes and use rsa-sha2-sha256; *) ssh - implemented "server-sig-algs" extension in order to improve rsa-sha2-sha256 support; *) switch - disabled second CPU core for CRS328-24P-4S+ device in order to improve SFP+ link stability; *) vxlan - allow to specify MAC address manually; *) webfig - updated WebFig HTML files with the new MikroTik logo and removed Telnet option from index page; *) webfig - updated link to the WinBox executable; *) webfig - updated link to the documentation; *) wifiwave2 - fixed "frequency-scan" functionality (introduced in v7.3); *) winbox - add a log and log-prefix options to IPv6 firewall NAT and mangle rules; *) winbox - fixed IP/Route and IPv6/Route OSPF type value; *) winbox - removed unused "Apply Changes" button from BGP sessions menu; *) wireguard - fixed system stability when adding/removing WireGuard interface; *) wireless - fixed possible traffic flooding to WDS clients when using Nv2 and multicast helper; *) x86 - fixed keep old configuration functionality during x86 setup installation; *) x86 - improved log warning message on failed downgrade attempt; *) x86 - removed "hdd-model" information from installation screen;
Aleksey
Всем доброго дня! Кто-нибудь ставил pnetlab на чистую убунту, без образа?
Moneron 🇷🇺
Тем временем на горизонте замаячила 7.4 😊 What's new in 7.4beta2 (2022-Jun-07 12:08) *) api - fixed comma encoding within URL when using the ".proplist" argument; *) bridge - properly process IPsec decapsulated packets through the firewall when the "use-ip-firewall" option is enabled; *) capsman - require a unique name for configuration and configuration pre-sets; *) cloud - print critical log message when system clock gets synchronised; *) console - added ":retry" command; *) console - fixed situation when print output was not consistent; *) dns - convert the domain name to lowercase before matching regex; *) e-mail - added VRF support (CLI only); *) filesystem - fixed repartition on RB5009 series devices; *) firewall - added "srcnat" and "dstnat" flags to IPv6/Firewall/Connection table; *) firewall - added support for IPv6/Firewall/NAT action=src-nat rules (CLI only); *) firewall - fixed IPv6 NAT functionality when processing GRE traffic on TILE devices; *) firewall - fixed IPv6/Firewall/RAW functionality; *) firewall - include "connection-mark", "connection-state", and "packet-mark" when packet logging is enabled; *) firewall - properly handle interface matcher when VRF interface is specified; *) hotspot - fixed ARP resolution for clients when address pool is specified on the server; *) hotspot - fixed Walled Garden entries with action=deny; *) ipv6 - fixed system stability when adding/removing IPv6 address; *) ldp - correctly handle AFI selection for usage on dual-stack peers; *) lte - request connect with the same IP type as in LTE attach status for MBIM; *) lte - fixed Telit AT interface numbering; *) lte - improved LTE interface detection for LtAP-2HnD devices; *) lte - keep MBIM working even if AT channel fails to respond in the initialisation stage; *) mmips - improved USB device detection after system bootup; *) mpls - fixed VPLS functionality when PW peer is an immediate neighbor; *) ovpn - use selected cipher by default when the server does not provide "cipher" option; *) pimsm - improved system stability when changing configuration; *) ppp - properly try to use different authentication algorithms when Conf-Rej is received during the LCP phase; *) quickset - specify the "in-interface-list=WAN" attribute on firewall rules created through "Port Mapping"; *) route - added option to join static IGMP and MLD groups (available in "/routing/gmp" menu, CLI only) *) route - fixed false route type detection as blackhole; *) route - provide more detailed information about prefixes when using "discourse" tool; *) routing - moved "/interface bgp vpls" to "/routing bgp vpls" menu; *) routing-filter - fixed regexp community matcher; *) ssh - disable ssh-rsa when strong-crypto=yes and use rsa-sha2-sha256; *) ssh - implemented "server-sig-algs" extension in order to improve rsa-sha2-sha256 support; *) switch - disabled second CPU core for CRS328-24P-4S+ device in order to improve SFP+ link stability; *) vxlan - allow to specify MAC address manually; *) webfig - updated WebFig HTML files with the new MikroTik logo and removed Telnet option from index page; *) webfig - updated link to the WinBox executable; *) webfig - updated link to the documentation; *) wifiwave2 - fixed "frequency-scan" functionality (introduced in v7.3); *) winbox - add a log and log-prefix options to IPv6 firewall NAT and mangle rules; *) winbox - fixed IP/Route and IPv6/Route OSPF type value; *) winbox - removed unused "Apply Changes" button from BGP sessions menu; *) wireguard - fixed system stability when adding/removing WireGuard interface; *) wireless - fixed possible traffic flooding to WDS clients when using Nv2 and multicast helper; *) x86 - fixed keep old configuration functionality during x86 setup installation; *) x86 - improved log warning message on failed downgrade attempt; *) x86 - removed "hdd-model" information from installation screen;
А ещё из интересного: Container is MikroTik's implementation of Linux containers, allowing users to run containerized environments within RouterOS. The container feature was added in RouterOS v7.4beta.
Nikita
Тем временем на горизонте замаячила 7.4 😊 What's new in 7.4beta2 (2022-Jun-07 12:08) *) api - fixed comma encoding within URL when using the ".proplist" argument; *) bridge - properly process IPsec decapsulated packets through the firewall when the "use-ip-firewall" option is enabled; *) capsman - require a unique name for configuration and configuration pre-sets; *) cloud - print critical log message when system clock gets synchronised; *) console - added ":retry" command; *) console - fixed situation when print output was not consistent; *) dns - convert the domain name to lowercase before matching regex; *) e-mail - added VRF support (CLI only); *) filesystem - fixed repartition on RB5009 series devices; *) firewall - added "srcnat" and "dstnat" flags to IPv6/Firewall/Connection table; *) firewall - added support for IPv6/Firewall/NAT action=src-nat rules (CLI only); *) firewall - fixed IPv6 NAT functionality when processing GRE traffic on TILE devices; *) firewall - fixed IPv6/Firewall/RAW functionality; *) firewall - include "connection-mark", "connection-state", and "packet-mark" when packet logging is enabled; *) firewall - properly handle interface matcher when VRF interface is specified; *) hotspot - fixed ARP resolution for clients when address pool is specified on the server; *) hotspot - fixed Walled Garden entries with action=deny; *) ipv6 - fixed system stability when adding/removing IPv6 address; *) ldp - correctly handle AFI selection for usage on dual-stack peers; *) lte - request connect with the same IP type as in LTE attach status for MBIM; *) lte - fixed Telit AT interface numbering; *) lte - improved LTE interface detection for LtAP-2HnD devices; *) lte - keep MBIM working even if AT channel fails to respond in the initialisation stage; *) mmips - improved USB device detection after system bootup; *) mpls - fixed VPLS functionality when PW peer is an immediate neighbor; *) ovpn - use selected cipher by default when the server does not provide "cipher" option; *) pimsm - improved system stability when changing configuration; *) ppp - properly try to use different authentication algorithms when Conf-Rej is received during the LCP phase; *) quickset - specify the "in-interface-list=WAN" attribute on firewall rules created through "Port Mapping"; *) route - added option to join static IGMP and MLD groups (available in "/routing/gmp" menu, CLI only) *) route - fixed false route type detection as blackhole; *) route - provide more detailed information about prefixes when using "discourse" tool; *) routing - moved "/interface bgp vpls" to "/routing bgp vpls" menu; *) routing-filter - fixed regexp community matcher; *) ssh - disable ssh-rsa when strong-crypto=yes and use rsa-sha2-sha256; *) ssh - implemented "server-sig-algs" extension in order to improve rsa-sha2-sha256 support; *) switch - disabled second CPU core for CRS328-24P-4S+ device in order to improve SFP+ link stability; *) vxlan - allow to specify MAC address manually; *) webfig - updated WebFig HTML files with the new MikroTik logo and removed Telnet option from index page; *) webfig - updated link to the WinBox executable; *) webfig - updated link to the documentation; *) wifiwave2 - fixed "frequency-scan" functionality (introduced in v7.3); *) winbox - add a log and log-prefix options to IPv6 firewall NAT and mangle rules; *) winbox - fixed IP/Route and IPv6/Route OSPF type value; *) winbox - removed unused "Apply Changes" button from BGP sessions menu; *) wireguard - fixed system stability when adding/removing WireGuard interface; *) wireless - fixed possible traffic flooding to WDS clients when using Nv2 and multicast helper; *) x86 - fixed keep old configuration functionality during x86 setup installation; *) x86 - improved log warning message on failed downgrade attempt; *) x86 - removed "hdd-model" information from installation screen;
Поменяли лого! 🤪
Innokentiy
еще раз?
Nikita
Innokentiy
им разве кто-то пользуется?)
Nikita
им разве кто-то пользуется?)
Техподдержка первой линии Ветрикс 😜 Там скины можно менять и отключать элементы интерфейса 😎
Stanislav
а то они глупые, не знают, что это странный кейс )
провайдеру все равно как ты будешь принимать вланы, это не его забота, а вот принимать его роутером и проталкивать через себя та ещё дурость. Надо разбирать вланы от провайдера воткни свитч перед роутером и разбирай.
Stanislav
если роутер умеет в аппаратные виланы чего бы на нем и не разобрать? )
разве что, и все равно это как то угробишно выглядит. Терминировать да. а пропускать через себя чтоб отдать эти вланы железке которая может их разбирать аппартно, ну дич какая то. Насмотрелся уже этих конструкций.
Михаил
Тем временем на горизонте замаячила 7.4 😊 What's new in 7.4beta2 (2022-Jun-07 12:08) *) api - fixed comma encoding within URL when using the ".proplist" argument; *) bridge - properly process IPsec decapsulated packets through the firewall when the "use-ip-firewall" option is enabled; *) capsman - require a unique name for configuration and configuration pre-sets; *) cloud - print critical log message when system clock gets synchronised; *) console - added ":retry" command; *) console - fixed situation when print output was not consistent; *) dns - convert the domain name to lowercase before matching regex; *) e-mail - added VRF support (CLI only); *) filesystem - fixed repartition on RB5009 series devices; *) firewall - added "srcnat" and "dstnat" flags to IPv6/Firewall/Connection table; *) firewall - added support for IPv6/Firewall/NAT action=src-nat rules (CLI only); *) firewall - fixed IPv6 NAT functionality when processing GRE traffic on TILE devices; *) firewall - fixed IPv6/Firewall/RAW functionality; *) firewall - include "connection-mark", "connection-state", and "packet-mark" when packet logging is enabled; *) firewall - properly handle interface matcher when VRF interface is specified; *) hotspot - fixed ARP resolution for clients when address pool is specified on the server; *) hotspot - fixed Walled Garden entries with action=deny; *) ipv6 - fixed system stability when adding/removing IPv6 address; *) ldp - correctly handle AFI selection for usage on dual-stack peers; *) lte - request connect with the same IP type as in LTE attach status for MBIM; *) lte - fixed Telit AT interface numbering; *) lte - improved LTE interface detection for LtAP-2HnD devices; *) lte - keep MBIM working even if AT channel fails to respond in the initialisation stage; *) mmips - improved USB device detection after system bootup; *) mpls - fixed VPLS functionality when PW peer is an immediate neighbor; *) ovpn - use selected cipher by default when the server does not provide "cipher" option; *) pimsm - improved system stability when changing configuration; *) ppp - properly try to use different authentication algorithms when Conf-Rej is received during the LCP phase; *) quickset - specify the "in-interface-list=WAN" attribute on firewall rules created through "Port Mapping"; *) route - added option to join static IGMP and MLD groups (available in "/routing/gmp" menu, CLI only) *) route - fixed false route type detection as blackhole; *) route - provide more detailed information about prefixes when using "discourse" tool; *) routing - moved "/interface bgp vpls" to "/routing bgp vpls" menu; *) routing-filter - fixed regexp community matcher; *) ssh - disable ssh-rsa when strong-crypto=yes and use rsa-sha2-sha256; *) ssh - implemented "server-sig-algs" extension in order to improve rsa-sha2-sha256 support; *) switch - disabled second CPU core for CRS328-24P-4S+ device in order to improve SFP+ link stability; *) vxlan - allow to specify MAC address manually; *) webfig - updated WebFig HTML files with the new MikroTik logo and removed Telnet option from index page; *) webfig - updated link to the WinBox executable; *) webfig - updated link to the documentation; *) wifiwave2 - fixed "frequency-scan" functionality (introduced in v7.3); *) winbox - add a log and log-prefix options to IPv6 firewall NAT and mangle rules; *) winbox - fixed IP/Route and IPv6/Route OSPF type value; *) winbox - removed unused "Apply Changes" button from BGP sessions menu; *) wireguard - fixed system stability when adding/removing WireGuard interface; *) wireless - fixed possible traffic flooding to WDS clients when using Nv2 and multicast helper; *) x86 - fixed keep old configuration functionality during x86 setup installation; *) x86 - improved log warning message on failed downgrade attempt; *) x86 - removed "hdd-model" information from installation screen;
Они такими темпами ros8 выпустят к концу года
КЭПпучино
Скорее всего 7.28...
И, через 30- 40 реализов, даже, рабочий продукт будет. Ведь багрепорты от пользователей куда продуктивнее внутренних тестов
Nikita
Чем отличается водитель маршрутки от маршрутизатора? 😄 #mtcna
Томас
Чем отличается водитель маршрутки от маршрутизатора? 😄 #mtcna
маршрутизатор за эти копейки не работает
Геннадий
маршрутизатор за эти копейки не работает
вероятно Вы хотели сказать наоборот?
Moneron 🇷🇺
это?
Это скины вебфига. Речь про винбокс.
nameless
Это скины вебфига. Речь про винбокс.
о как, есть скрины ,примеры ? хочется темную тему 😢
Vlad
Коллеги приветствую! Подскажите, а EoIP тоннель невозможно поднять если второй роутер не имеет белого IP?
Владислав
Можно через pptp, l2tp передавать l2 же
Vlad
щас погуглю
Геннадий
Можно через pptp, l2tp передавать l2 же
Л2тп не совсем честный л2 )
Владислав
Vlad
Блин специально взял с собой в поездку микрот чтоб тунель прокинуть удобно было а про серый ИП чот не подумал (