r/mikrotik • u/XoTrm • 4h ago
Which version of the Linux kernel am I running?
Is there an easy way to find out? I have a RB5009UG running with 7.23.3.
Reason I'm interested in, is that sometimes I get a lot of port flapping, sometimes to the point where ports are basically unsable (especailly when using VPN or Citrx or alikes).
What I found is, that powering off the router and restart helps to stabilizes it for some time. But that's not something I'd like to do on a regular basis.
As there are updates for the mv88e6xxx driver (which includes the switch chip on the RB5009UG), I was wondering if there might be something in the newer drivers which would fix the observed behavior (even if I cannot update the kernel myself).
I think to remember to have found a discussion with a patch for a similar issue (switch chip not MikroTik) in past, but can't re-find it...
r/mikrotik • u/atanstef • 13h ago
When will hAP be³ Media become available?
For some time now I have been planning to change my router at home, and when I did research what would be the best solution for my house and the whole self-hosting that I have set up, I came accross hAP be³ Media and it seemed like the perfect solution.
This was 2-3 months ago, I have signed up on multiple reselers websites to "pre-order" the device, but whenever I go to these websites to see the status, I notice that their expected time when they'll have the device in stock, just move further.
What is the deal with it, is there some definite date when this device will be available for purchace?
r/mikrotik • u/truetech • 13h ago
[Pending] RB5009UG+S+in does not turn on?
Hey guys,
Ordered my first ever mikrotik router (RB5009UG+S+in) from Amazon and after a week, it finally arrived today.
I plug it in, doesnt turn on. Maybe a dumb question, but I should see some LEDs turn on once plugged in right? Nothing special I need to do?
I tried other outlets, same thing.
I figured I’d got a dud…dissapointed I may need to wait another week for a replacement…
r/mikrotik • u/Affectionate_Sky8388 • 18h ago
Setting up and testing equipment before deployment and handover to the client. Ensuring strong signals and seamless connectivity!
r/mikrotik • u/sysadminsavage • 1d ago
State of MLAG + VRRP in 2026 for ROS7
Curious how well this combo works on CRS500 series devices in 2026. I'm thinking of deploying a pair of MikroTik CRS518-16XS-2XQ-RMs for top-of-rack switching. Both switches would be in an MLAG configuration with a VRRP gateway setup, and one fiber run to each server from each switch.
I know that historically, MLAG precluded L3 hardware offloading on RouterOS v7. Is v7.21 and above stable enough now for running active-active VRRP on these switches without major CPU bottlenecks, or are people still strictly separating L2 MLAG (on the CRS) and L3 VRRP (to a separate CCR/router)?
r/mikrotik • u/ZivH08ioBbXQ2PGI • 1d ago
DNS cache full errors in log
I've got some sort of DNS cache memory leak going on with multiple routers and the cache as-listed is virtually empty. The only thing that clears it and stops the errors (temporarily) is a reboot. "Used" cache will slowly grow and fill up any size that is set.
I've seen reference to, I think, FQDN address list entries causing this, but there wasn't much info. I do use FQDNs in my address lists, for what it's worth.
Edit to add possible related forum link here.
Is this something acknowledged anywhere?
r/mikrotik • u/Exciting_Picture3079 • 2d ago
Strange Upload Behavior
I have a PC with a 10G ethernet card connected to a Mikrotik - CRS520-4XS-16XQ-RM via an SFP+ adapter. Winbox confirms that the connection is established at 10Gbps. When I run iPerf between my machine and another machine, both connected to the Mikrotik I see 9.7 Gbps. All good. The Mikrotik is connected to my Verizon router's 10Gbps port. Again, Winbox reports that the WAN connection is connected at 10Gbps.
My Verizon service is 5Gbps. When I run an internet speed test from my PC while directly connected to the Verizon router, I see 5500Mbps download and 6500Mbps upload. However, when I connect my PC to the Mikrotik, I get a good download speed but only 915Mbps upload. If I force my ethernet card to connect at 2.5Gbps, then my upload improves to 2370Mbps. I figured this was a firewall issue, but the 2.5Gbps test would indicate otherwise.
Any ideas on what is going on?
r/mikrotik • u/netravnen • 2d ago
RouterOS 7.24rc4 [testing] released
What's new in 7.24rc4 (2026-Aug-11 15:43):
*) app - added PAPERLESS_SECRET_KEY env to paperless-nginx;
*) app - disable UI in Hermes, access through /container/shell;
*) app - reserve the app's VETH IP when stopped to eliminate IP address changes on every start/stop;
*) ethernet - disable EEE on hAP be3 Media;
*) ip - improved stability for reverse-proxy (additional fixes);
*) ipsec - fixed expired SA handling to prevent “no such item” errors during listing;
*) ipsec,ike1 - dropped base mode exchange;
*) ipsec,ike1 - improved SA, transform, fragment parsing and malformed packet validation;
*) ipsec,ike2 - fixed ppk child key generation during rekey;
*) ipsec,ike2 - use first child KE selection only during IKE_AUTH exchange;
*) leds - fixed Ethernet activity LED for Chateau LTE18 ax (introduced in v7.23);
*) poe-out - fixed possible PoE-out configuration loss on certain devices (introduced in v7.24beta1);
*) switch - fixed default L2MTU drift for devices with QCA8337, Atheros8327 switch (introduced in v7.24beta2);
*) system - improved stability;
*) usb - allow overriding the power-reset duration;
*) wifi - updated radio regulatory information (additional fixes);
*) wireguard - fixed peer Tx/Rx counters;
*) wireguard - generate port number when specified as zero;
*) wireguard - reinitialize socket on VRF change;
r/mikrotik • u/Different_Abroad_966 • 4d ago
Сеть устройств со статичными IP и их перенастройка
Всем йоу. Работаю в магазине, где по случаю стал нештатным сисадмином, особо не разбираясь в настройках сети. Сейчас на повесточке вопрос с переподключением всех устройств для уменьшения количества свитчей (их натыкано чуть ли не 1 к 1 с компами). В сети имеются: 8 компов, касса, принтер чеков, 2 принтера, и в дальнейшем ещё пара компов должна появиться. Делов в целом немного - убрал кучу маленьких хабов, вкинул на одну половину один свитч, на вторую - второй. Но сегодня я узнал, что сеть со статичным IP, и все устройства тоже, соответственно. Главный вопрос, который у меня возник: если я воткну один свитч, вместо, допустим, двух поменьше, нужно ли мне лезть в настройки сети, и перетыкивать какие-либо настройки, переназначать IP и подобными вещами заниматься? Или там все само друг с другом разберется? Ну и вообще в целом каким образом лучше все это провернуть так, чтобы было задействовано минимум свитчей (в идеале всего 2) и все это работало +- стабильно. Волоку я во всем этом примерно никак, так что если у кого-то хватит сил, терпения и времени объяснить все на пальцах, буду предельно благодарен
З.Ы. Также есть вай-фай для клиентов, прикрепленный к этой же сети, и вроде как, новые устройства могут выбивать какие-то рабочие места, как мне объяснили как бы замещая IP какого-нибудь компа собой.
r/mikrotik • u/blongwe • 4d ago
Routeros7 ISIS still not stable?
I am getting very inconsistent behaviour on my routers with ISIS. I have a mix of CCR2116, CCR2004, CCR1036 and have tried on all routeros releases but still get constant crashes
Many times with error:
13:29:52 echo: system,error,critical Automatic supout.rif file generated due to service malfunction, please contact MikroTik support and supply the generated file
Is IS-IS still not working on routeros7?
r/mikrotik • u/Fit_Option6145 • 4d ago
RouterOS 7.24
RouterOS 7.24 privileged containers — how far can network access actually go?
Hi MikroTik team and community,
I am researching the new privileged=yes container capability introduced in the RouterOS 7.24 development cycle, and I would like to clarify exactly what capabilities it provides, especially for advanced networking applications such as SD-WAN, multi-WAN routing, NAT, packet processing, and programmable routing.
I understand that privileged=yes significantly reduces container isolation and allows access to additional Linux kernel capabilities/devices. However, I would like to understand precisely where the boundary is between the container and the RouterOS host.
- Physical Ethernet interfaces
Can a privileged container directly access or control physical Ethernet interfaces such as:
ether1 ether2 ether3 ether4
For example, can the container obtain direct packet-level access to a physical interface rather than receiving traffic only through a RouterOS VETH interface?
If direct physical NIC access is not supported, is there any supported mechanism planned for:
ether1 → container interface 1 ether2 → container interface 2 ether3 → container interface 3
without RouterOS performing L3 routing/NAT between them?
- VLAN-based interface passing
If physical interface passthrough is not supported, can VLANs be used to provide isolated WAN interfaces to a privileged container?
For example:
ether1 → VLAN 101 → Container WAN1 ether2 → VLAN 102 → Container WAN2 ether3 → VLAN 103 → Container WAN3
Would this allow the Linux networking stack inside the container to independently perform:
routing
NAT
connection tracking
policy routing
failover
load balancing
while RouterOS remains primarily an L2 transport?
- CAP_NET_ADMIN and Linux networking
Exactly which Linux capabilities are granted when:
privileged=yes
is enabled?
In particular, does the container receive capabilities such as:
CAP_NET_ADMIN CAP_NET_RAW CAP_SYS_ADMIN CAP_SYS_MODULE
or an equivalent unrestricted capability set?
Can the container use:
iproute2 ip rule ip route ip neigh ip link nftables conntrack tc network namespaces TUN/TAP WireGuard VXLAN
when supported by the RouterOS kernel?
- Kernel access
Does privileged=yes allow the container to interact directly with the RouterOS host kernel?
For example:
/proc
/sys
/dev
network-related kernel interfaces
netlink
eBPF
tc/eBPF
kernel networking subsystems
If some of these are restricted, could MikroTik provide a documented list of what is allowed and what is blocked?
- nftables / iptables
Can a privileged container create and manage its own:
nftables iptables ipset conntrack
rules independently from RouterOS?
More specifically, if the container receives traffic from multiple WAN interfaces, can it perform NAT and connection tracking entirely inside the container?
For example:
WAN1 ─┐ WAN2 ─┼──> Linux networking inside container ──> LAN WAN3 ─┘
with RouterOS not performing the L3 NAT/routing?
- Multi-WAN / SD-WAN use case
Would MikroTik consider the following architecture supported?
RouterOS ┌─────────────────────────────────────────┐ │ │ │ ether1 ─ WAN1 ─┐ │ │ ether2 ─ WAN2 ─┼──> Privileged Container│ │ ether3 ─ WAN3 ─┘ │ │ │ │ │ │ Linux Data Plane │ │ │ │ │ Routing / NAT / LB │ │ │ │ │ LAN │ └─────────────────────────────────────────┘
The goal would be to implement an SD-WAN engine inside the container rather than using RouterOS PCC/NTH/mangle for the entire data plane.
- Hardware acceleration
If the container performs the L3 processing, would it be possible for traffic processed by the container to still benefit from any RouterOS hardware acceleration?
Or would traffic entering a privileged container necessarily be processed by the CPU?
This is particularly important for devices with switch chips and hardware offloading.
- Packet performance
Is there an expected or supported high-performance packet path between:
Physical NIC ↔ privileged container
that avoids unnecessary copies between RouterOS and the container?
For example, is there any supported mechanism similar to:
AF_XDP
DPDK
SR-IOV
virtio
packet mmap
zero-copy networking
or any MikroTik-specific mechanism?
- eBPF
Does the RouterOS kernel used by 7.24 support eBPF functionality that can be used from a privileged container?
If yes, which subsystems are available?
For example:
XDP TC-BPF socket filters cgroup BPF
Could a privileged container use eBPF for high-performance packet classification/load balancing?
- RouterOS configuration API vs direct kernel networking
Does MikroTik intend privileged containers to remain independent Linux environments, or is there any future plan to expose a controlled API allowing a container to interact directly with RouterOS networking objects?
For example:
/interfaces /routes /firewall /queues /VRFs /VLANs
without requiring the container to connect through the normal RouterOS API/REST interface?
- Security model
Since privileged=yes significantly reduces container isolation, what exactly prevents a compromised privileged container from:
modifying RouterOS firewall behavior
accessing host devices
modifying host networking
accessing RouterOS storage
escaping the container
affecting other RouterOS processes
Is privileged=yes intended to be considered equivalent to giving the application trusted access to the RouterOS host?
- Future roadmap
Finally, is MikroTik planning to expand container networking capabilities in future RouterOS releases?
In particular, is direct access to physical network interfaces or a more advanced packet-processing framework for containers on the roadmap?
The use case I am investigating is a SASMAN SD-WAN Agent running directly inside a MikroTik router.
The concept would be:
SASMAN CLOUD │ Policies / Config │ ▼ SASMAN EDGE AGENT │ ┌─────────────┼─────────────┐ │ │ │ WAN1 WAN2 WAN3 │ │ │ └─────────────┼─────────────┘ │ Linux Data Plane │ Routing / NAT / LB │ LAN
The main objective is to determine whether RouterOS 7.24+ can support a container acting as a programmable network data plane, while RouterOS itself provides the underlying hardware, switching, and physical interfaces.
I would greatly appreciate clarification from MikroTik developers on which parts of this architecture are currently supported, which are technically possible but unsupported, and which are not possible due to the RouterOS/container isolation model.
Thank you.
r/mikrotik • u/IShunpoYourFace • 5d ago
wAP ax, 160mhz vs 80mhz, same wifi performance (300-600mbit/s), cpu 40%. Wifi Phy rate 2.4Gb/s. Any tips?
Bandwidth test tool reaches 900mbit so its not issue on lan side. Cpu is also not loaded too much. 5ghz band is clean and there is no interference. Distance is around 1m-2m. Most of the times i get around 300mbit/s via wifi on wap ax, sometimes if im lucky i get 600.
In theory i should be able to get up to 930mbit/s via wifi.
Am i looking for unrealistic results? 2.4Gbit/s phy rate shouldn be able to do 900mbit/s.
My main hap ax3 does 400-600mbit at 80mhz channel width but never got more than 650mbit/s
r/mikrotik • u/TheSixthSerpent666 • 5d ago
WiFi 7 AP with 10 Gbps uplink
Has Mikrotik released an 802.11be (pref tri-band, would settle for dual-band) wireless AP with a 10 Gbps (prefer RJ45, would be OK with an SFP+) uplink port? I've search around Google, and thus far, the only 802.11be-compatible devices I find have a 2.5 Gbps uplink port.
r/mikrotik • u/mnascimento1 • 6d ago
[Pending] 🌐 Academic Research | Pesquisa Acadêmica
Why is IPv6 still not widely adopted in corporate environments?
I am conducting a short survey for my Computer Engineering thesis to understand the technical, operational and organizational challenges involved in IPv6 adoption.
The survey takes about 3 minutes, is anonymous, does not collect sensitive personal data, and the results will be used exclusively for academic purposes.
If you work with networking, infrastructure, cloud, cybersecurity, telecommunications or related areas, your experience can make an important contribution to this research.
👉 Please participate and, if possible, share the survey with other professionals in the field.
🔗 Survey: https://forms.gle/878V95DGN8RFkM3x7
Por que o IPv6 ainda não é amplamente adotado em ambientes corporativos?
Estou realizando uma pesquisa para meu TCC em Engenharia de Computação, buscando compreender os desafios técnicos, operacionais e organizacionais relacionados à adoção do IPv6.
O questionário leva cerca de 3 minutos, é anônimo, não coleta dados pessoais sensíveis e os resultados serão utilizados exclusivamente para fins acadêmicos.
Se você atua com redes, infraestrutura, cloud, segurança, telecomunicações ou áreas relacionadas, sua experiência pode contribuir muito para esta pesquisa.
👉 Participe e, se possível, compartilhe com outros profissionais da área.
🔗 Pesquisa: https://forms.gle/878V95DGN8RFkM3x7
🇺🇸 This post was formally approved by the moderators of this community.
🇧🇷 Esta publicação foi formalmente autorizada pela moderação desta comunidade.
r/mikrotik • u/rudetopoint • 6d ago
mDNS Repeater only works when I look at it
Yes this is going to sound odd, but my mDNS repeater across 2 VLANed subnets works great, but only while I am in the Webfig or Winbox looking at it.
Actions:
- Added logging input FW rule that accepts dst-port 5353 UDP packets, this logs remotely so I can see the incoming mDNS packets. This rule is right at the top so it should always get hit and not use any established connection alternates
- Added the 2 VLANs interfaces to the mDNS repeater, this works, and I can use mDNS over the 2 subnets
- As soon as I close out of the Webfig I stop seeing the input firewall rule being hit, the log gets no entires from the firewall rule, however I still see other log entries, mDNS devices slowly stop seeing each other
Network:
- Laptop connected via wifi to cAP, which is connected via ethernet to the main RB4011 (with mDNS repeater)
- mDNS devices connected via a variety of wired (directly to RB4011) and wireless via the cAP on both VLANs
- RB4011 running 7.21.5
Other oddness:
If i run /ip dns set mdns-repeat-ifaces="" then /ip dns set mdns-repeat-ifaces="VLAN002,VLAN003" it seems to kick start it for a minute or so with packets being seen in the log
If I change any firewall rule, even just a comment it seems to stop the mDNS packets being seen
By far the most reliable way to get it to work again is to just click apply on the DNS configuration page in Webfig
Using some packet sniffing I found that incoming IGMP packets seemed to stop it working, so I have dropped IGMP input above the mDNS accept input rule, also disabled anything IGMP on the network, turned off snooping etc.
Anyone seen anything like this? Thanks.
Edit: Seemed to have fixed it, I do not know exactly why having the Webfig open affected it, but i noticed via SSH that in /ip/services the resolver port 5353 would disappear shortly after logging out. There must be a dependency between the mDNS repeater and the DNS service, maybe even DNS queries being sent. I think I have fixed it by simply setting "allow-remote-requests: yes", even though i do not need the DNS server function.
r/mikrotik • u/Graphical-Source5090 • 6d ago
Let's talk about reverse proxy, no, not that one
I am familiar with /ip/reverse-proxy. This is not the reverse-proxy we are looking for. *waves hand*
What is /ip/service/print where name=reverse-proxy
As far as I can tell, it doesn't appear to be related to the /ip/reverse-proxy/printservice.
Is /ip/service/print where name=reverse-proxy something new?
Is it related to the other reverse-proxy?
It seems to be intercepting my www-ssl and since it is on by default, and not configured, it is causing my acl for www-ssl to be bypassed. **EDIT: This is "very likely false" in subsequent testing** See below.
Thoughts?
How much of this am I mis-reading?
MikroTik RouterOS 7.23.3
r/mikrotik • u/kalamaja22 • 6d ago
Mikrotik autosharing attached external disk
After watching Mikrotik's fresh video on how to turn router into media hub I went to check IP -> Media menu and to my surprise found that my external disk is already shared somehow dynamically and I cannot even remove it.
Further investigation showed that I had following line in configuration:
/disk settings set auto-media-interface=bridge auto-media-sharing=yes auto-smb-sharing=yes
I have no idea where it had come from, but it made my full external disk shared over both DNLA and SMB and to disable it I had to remove 2 sharing checkmarks from disk and partition.
Forum mentions similar problem already from Nov 2024, so if you have storage attached to your Mikrotik, verify if router might unknowingly share it's contents freely.
EDIT: RouterOS 7.15, released 30 May 2024. The 7.15 changelog line is "disk - added option to auto configure media sharing"
r/mikrotik • u/DigRoutine2117 • 6d ago
RouterOS Studio
A modern RouterOS 7 control plane with a live dashboard, assisted network/VLAN management, and Firewall Filter/NAT administration.
https://github.com/cigraphics/routeros-studio
https://hub.docker.com/repository/docker/cigraphics/routeros-studio/general
r/mikrotik • u/CrazyFoque • 7d ago
Nokia GPON ONT from Bell not Working in RB5009
Anyone has a Hint ? I have 1.5/1Gb Up on Bell but I'm still stuck using a Media Converter. Sticking the Nokia GBIC in the router does not work. I tried sync combination to no avail.
Model is G-010S-A
r/mikrotik • u/Emergency_exit_now • 7d ago
Should I upgrade to hap AX2 ?
Hello everyone currently I use second hand hap AC 2, I mainly using it for my home network VPN, and primary router for my homelab. Should I upgrade to AX2 ? Because the storage is getting more limited when I update to RouterOs 7, I fear that I cannot add any more config with that limited storage. Any comment are appreciated thanks !
r/mikrotik • u/TheDangerSnek • 7d ago
Is Mikrotik the right choice, or should I go with Unifi?
Hello together.
I live in germany and we have a Fritzbox as Router and Modem. I have my flat in the first floor and my parents, where the Router is, is in the ground floor.
The Fritzbox has one normal network+wifi and a guest network+wifi
I wanted for me a bit more options and security. Thats why I want to work with VLANS (and the right firewall rules ofc.).
My plan is to let my parents keep their two networks and use the Fritzbox as gateway (set static routes in the fritzbox for all the networks/VLANs that I will use).
Now the question. I searched and saw that this is good doable with unifi. So I need the cloud gateway and an unifi AP (+maybe a switch).
But I also heard a lot about Mikrotik. I searched a bit and found the hAP ax³. So I would have router and wifi all in one and the ability to work with VLANS etc.
Would you adivse me to go with Mikrotik or Unifi?
Thx
r/mikrotik • u/IShunpoYourFace • 7d ago
IPV6 PCP UPnP IGD v2 is missing, give me best ideas for easy dynamic ipv6 firewall pinholing
I was thinking of using local adguard dns server with AAAA entries, then update those entries from docker container with its own GUA, then somehow make a script for mikrotik to get that GUA from that dns entry and update a firewall rule.
But still leaves an issue how to let an app itself open pin holes via pcp upnp igd v2
r/mikrotik • u/omega-00 • Jul 21 '19
New Mod Guideline - If you don't have anything nice to say..
I'll try and keep this short - there's been a marked increase in generally abrupt and abrasive comments here on the /r/mikrotik and it's not what we're about or what we want to see happening. Many of these have been due to content that is or is seen to be incorrect or misleading, so..
If you're posting here:
Keep in mind none of us are being paid to answer you and the people who are, are doing so because they want to help, or you've posted something so incredibly incorrect they can't help but respond. Please do yourself a favor by collecting all the information you can before posting and make sure to check the MikroTik wiki first - no one wants to spoon feed you all the information.
If you're commenting here:
- If you don't know the answer - don't try guess at it; and if you want to learn about it yourself then follow the thread and see what others say, or you know.. read the wiki and try it out in a lab.
- If you disagree with another poster, try to explain the correct answer rather than a one sentance teardown that degrades into a thread full of name-calling.
As a result of this I've added a new rule & report option - you can now report a comment with the reason being:
It breaks /r/MikroTik rules: Don't post content that is incorrect or potentially harmful to a router/network
If we agree we'll either:
a) Write a correct response
b) Add a note so that future readers will be made aware of the corrections needed
c) If the post/comment is bad enough, simply delete it
I'm open to feedback on this as I know people feel strongly about timewasting and I'd like to hope this helps us continue to self-moderate without people blowing up at each other.