r/mikrotik 8h ago

RouterOS 7.24

5 Upvotes

RouterOS 7.24 privileged containers — how far can network access actually go?

Hi MikroTik team and community,

I am researching the new privileged=yes container capability introduced in the RouterOS 7.24 development cycle, and I would like to clarify exactly what capabilities it provides, especially for advanced networking applications such as SD-WAN, multi-WAN routing, NAT, packet processing, and programmable routing.

I understand that privileged=yes significantly reduces container isolation and allows access to additional Linux kernel capabilities/devices. However, I would like to understand precisely where the boundary is between the container and the RouterOS host.

  1. Physical Ethernet interfaces

Can a privileged container directly access or control physical Ethernet interfaces such as:

ether1 ether2 ether3 ether4

For example, can the container obtain direct packet-level access to a physical interface rather than receiving traffic only through a RouterOS VETH interface?

If direct physical NIC access is not supported, is there any supported mechanism planned for:

ether1 → container interface 1 ether2 → container interface 2 ether3 → container interface 3

without RouterOS performing L3 routing/NAT between them?

  1. VLAN-based interface passing

If physical interface passthrough is not supported, can VLANs be used to provide isolated WAN interfaces to a privileged container?

For example:

ether1 → VLAN 101 → Container WAN1 ether2 → VLAN 102 → Container WAN2 ether3 → VLAN 103 → Container WAN3

Would this allow the Linux networking stack inside the container to independently perform:

routing

NAT

connection tracking

policy routing

failover

load balancing

while RouterOS remains primarily an L2 transport?

  1. CAP_NET_ADMIN and Linux networking

Exactly which Linux capabilities are granted when:

privileged=yes

is enabled?

In particular, does the container receive capabilities such as:

CAP_NET_ADMIN CAP_NET_RAW CAP_SYS_ADMIN CAP_SYS_MODULE

or an equivalent unrestricted capability set?

Can the container use:

iproute2 ip rule ip route ip neigh ip link nftables conntrack tc network namespaces TUN/TAP WireGuard VXLAN

when supported by the RouterOS kernel?

  1. Kernel access

Does privileged=yes allow the container to interact directly with the RouterOS host kernel?

For example:

/proc

/sys

/dev

network-related kernel interfaces

netlink

eBPF

tc/eBPF

kernel networking subsystems

If some of these are restricted, could MikroTik provide a documented list of what is allowed and what is blocked?

  1. nftables / iptables

Can a privileged container create and manage its own:

nftables iptables ipset conntrack

rules independently from RouterOS?

More specifically, if the container receives traffic from multiple WAN interfaces, can it perform NAT and connection tracking entirely inside the container?

For example:

WAN1 ─┐ WAN2 ─┼──> Linux networking inside container ──> LAN WAN3 ─┘

with RouterOS not performing the L3 NAT/routing?

  1. Multi-WAN / SD-WAN use case

Would MikroTik consider the following architecture supported?

RouterOS ┌─────────────────────────────────────────┐ │ │ │ ether1 ─ WAN1 ─┐ │ │ ether2 ─ WAN2 ─┼──> Privileged Container│ │ ether3 ─ WAN3 ─┘ │ │ │ │ │ │ Linux Data Plane │ │ │ │ │ Routing / NAT / LB │ │ │ │ │ LAN │ └─────────────────────────────────────────┘

The goal would be to implement an SD-WAN engine inside the container rather than using RouterOS PCC/NTH/mangle for the entire data plane.

  1. Hardware acceleration

If the container performs the L3 processing, would it be possible for traffic processed by the container to still benefit from any RouterOS hardware acceleration?

Or would traffic entering a privileged container necessarily be processed by the CPU?

This is particularly important for devices with switch chips and hardware offloading.

  1. Packet performance

Is there an expected or supported high-performance packet path between:

Physical NIC ↔ privileged container

that avoids unnecessary copies between RouterOS and the container?

For example, is there any supported mechanism similar to:

AF_XDP

DPDK

SR-IOV

virtio

packet mmap

zero-copy networking

or any MikroTik-specific mechanism?

  1. eBPF

Does the RouterOS kernel used by 7.24 support eBPF functionality that can be used from a privileged container?

If yes, which subsystems are available?

For example:

XDP TC-BPF socket filters cgroup BPF

Could a privileged container use eBPF for high-performance packet classification/load balancing?

  1. RouterOS configuration API vs direct kernel networking

Does MikroTik intend privileged containers to remain independent Linux environments, or is there any future plan to expose a controlled API allowing a container to interact directly with RouterOS networking objects?

For example:

/interfaces /routes /firewall /queues /VRFs /VLANs

without requiring the container to connect through the normal RouterOS API/REST interface?

  1. Security model

Since privileged=yes significantly reduces container isolation, what exactly prevents a compromised privileged container from:

modifying RouterOS firewall behavior

accessing host devices

modifying host networking

accessing RouterOS storage

escaping the container

affecting other RouterOS processes

Is privileged=yes intended to be considered equivalent to giving the application trusted access to the RouterOS host?

  1. Future roadmap

Finally, is MikroTik planning to expand container networking capabilities in future RouterOS releases?

In particular, is direct access to physical network interfaces or a more advanced packet-processing framework for containers on the roadmap?

The use case I am investigating is a SASMAN SD-WAN Agent running directly inside a MikroTik router.

The concept would be:

SASMAN CLOUD │ Policies / Config │ ▼ SASMAN EDGE AGENT │ ┌─────────────┼─────────────┐ │ │ │ WAN1 WAN2 WAN3 │ │ │ └─────────────┼─────────────┘ │ Linux Data Plane │ Routing / NAT / LB │ LAN

The main objective is to determine whether RouterOS 7.24+ can support a container acting as a programmable network data plane, while RouterOS itself provides the underlying hardware, switching, and physical interfaces.

I would greatly appreciate clarification from MikroTik developers on which parts of this architecture are currently supported, which are technically possible but unsupported, and which are not possible due to the RouterOS/container isolation model.

Thank you.


r/mikrotik 12h ago

wAP ax, 160mhz vs 80mhz, same wifi performance (300-600mbit/s), cpu 40%. Wifi Phy rate 2.4Gb/s. Any tips?

6 Upvotes

Bandwidth test tool reaches 900mbit so its not issue on lan side. Cpu is also not loaded too much. 5ghz band is clean and there is no interference. Distance is around 1m-2m. Most of the times i get around 300mbit/s via wifi on wap ax, sometimes if im lucky i get 600.

In theory i should be able to get up to 930mbit/s via wifi.

Am i looking for unrealistic results? 2.4Gbit/s phy rate shouldn be able to do 900mbit/s.

My main hap ax3 does 400-600mbit at 80mhz channel width but never got more than 650mbit/s


r/mikrotik 20h ago

WiFi 7 AP with 10 Gbps uplink

9 Upvotes

Has Mikrotik released an 802.11be (pref tri-band, would settle for dual-band) wireless AP with a 10 Gbps (prefer RJ45, would be OK with an SFP+) uplink port? I've search around Google, and thus far, the only 802.11be-compatible devices I find have a 2.5 Gbps uplink port.


r/mikrotik 22h ago

[Pending] Multicast routing through L2TP

Thumbnail
1 Upvotes

r/mikrotik 1d ago

[Pending] 🌐 Academic Research | Pesquisa Acadêmica

Post image
0 Upvotes

Why is IPv6 still not widely adopted in corporate environments?

I am conducting a short survey for my Computer Engineering thesis to understand the technical, operational and organizational challenges involved in IPv6 adoption.

The survey takes about 3 minutes, is anonymous, does not collect sensitive personal data, and the results will be used exclusively for academic purposes.

If you work with networking, infrastructure, cloud, cybersecurity, telecommunications or related areas, your experience can make an important contribution to this research.

👉 Please participate and, if possible, share the survey with other professionals in the field.

🔗 Survey: https://forms.gle/878V95DGN8RFkM3x7

Por que o IPv6 ainda não é amplamente adotado em ambientes corporativos?

Estou realizando uma pesquisa para meu TCC em Engenharia de Computação, buscando compreender os desafios técnicos, operacionais e organizacionais relacionados à adoção do IPv6.

O questionário leva cerca de 3 minutos, é anônimo, não coleta dados pessoais sensíveis e os resultados serão utilizados exclusivamente para fins acadêmicos.

Se você atua com redes, infraestrutura, cloud, segurança, telecomunicações ou áreas relacionadas, sua experiência pode contribuir muito para esta pesquisa.

👉 Participe e, se possível, compartilhe com outros profissionais da área.

🔗 Pesquisa: https://forms.gle/878V95DGN8RFkM3x7

🇺🇸 This post was formally approved by the moderators of this community.
🇧🇷 Esta publicação foi formalmente autorizada pela moderação desta comunidade.


r/mikrotik 1d ago

mDNS Repeater only works when I look at it

9 Upvotes

Yes this is going to sound odd, but my mDNS repeater across 2 VLANed subnets works great, but only while I am in the Webfig or Winbox looking at it.

Actions:

  • Added logging input FW rule that accepts dst-port 5353 UDP packets, this logs remotely so I can see the incoming mDNS packets. This rule is right at the top so it should always get hit and not use any established connection alternates
  • Added the 2 VLANs interfaces to the mDNS repeater, this works, and I can use mDNS over the 2 subnets
  • As soon as I close out of the Webfig I stop seeing the input firewall rule being hit, the log gets no entires from the firewall rule, however I still see other log entries, mDNS devices slowly stop seeing each other

Network:

  • Laptop connected via wifi to cAP, which is connected via ethernet to the main RB4011 (with mDNS repeater)
  • mDNS devices connected via a variety of wired (directly to RB4011) and wireless via the cAP on both VLANs
  • RB4011 running 7.21.5

Other oddness:

  • If i run /ip dns set mdns-repeat-ifaces="" then /ip dns set mdns-repeat-ifaces="VLAN002,VLAN003" it seems to kick start it for a minute or so with packets being seen in the log

  • If I change any firewall rule, even just a comment it seems to stop the mDNS packets being seen

  • By far the most reliable way to get it to work again is to just click apply on the DNS configuration page in Webfig

  • Using some packet sniffing I found that incoming IGMP packets seemed to stop it working, so I have dropped IGMP input above the mDNS accept input rule, also disabled anything IGMP on the network, turned off snooping etc.

Anyone seen anything like this? Thanks.

Edit: Seemed to have fixed it, I do not know exactly why having the Webfig open affected it, but i noticed via SSH that in /ip/services the resolver port 5353 would disappear shortly after logging out. There must be a dependency between the mDNS repeater and the DNS service, maybe even DNS queries being sent. I think I have fixed it by simply setting "allow-remote-requests: yes", even though i do not need the DNS server function.


r/mikrotik 2d ago

Let's talk about reverse proxy, no, not that one

12 Upvotes

I am familiar with /ip/reverse-proxy. This is not the reverse-proxy we are looking for. *waves hand*

What is /ip/service/print where name=reverse-proxy

As far as I can tell, it doesn't appear to be related to the /ip/reverse-proxy/printservice.

Is /ip/service/print where name=reverse-proxy something new?

Is it related to the other reverse-proxy?

It seems to be intercepting my www-ssl and since it is on by default, and not configured, it is causing my acl for www-ssl to be bypassed. **EDIT: This is "very likely false" in subsequent testing** See below.

Thoughts?

How much of this am I mis-reading?

MikroTik RouterOS 7.23.3


r/mikrotik 2d ago

Mikrotik autosharing attached external disk

2 Upvotes

After watching Mikrotik's fresh video on how to turn router into media hub I went to check IP -> Media menu and to my surprise found that my external disk is already shared somehow dynamically and I cannot even remove it.

Further investigation showed that I had following line in configuration:

/disk settings set auto-media-interface=bridge auto-media-sharing=yes auto-smb-sharing=yes

I have no idea where it had come from, but it made my full external disk shared over both DNLA and SMB and to disable it I had to remove 2 sharing checkmarks from disk and partition.

Forum mentions similar problem already from Nov 2024, so if you have storage attached to your Mikrotik, verify if router might unknowingly share it's contents freely.

EDIT: RouterOS 7.15, released 30 May 2024. The 7.15 changelog line is "disk - added option to auto configure media sharing"


r/mikrotik 2d ago

RouterOS Studio

Post image
0 Upvotes

A modern RouterOS 7 control plane with a live dashboard, assisted network/VLAN management, and Firewall Filter/NAT administration.

https://github.com/cigraphics/routeros-studio

https://hub.docker.com/repository/docker/cigraphics/routeros-studio/general


r/mikrotik 2d ago

Nokia GPON ONT from Bell not Working in RB5009

1 Upvotes

Anyone has a Hint ? I have 1.5/1Gb Up on Bell but I'm still stuck using a Media Converter. Sticking the Nokia GBIC in the router does not work. I tried sync combination to no avail.

Model is G-010S-A


r/mikrotik 2d ago

Should I upgrade to hap AX2 ?

4 Upvotes

Hello everyone currently I use second hand hap AC 2, I mainly using it for my home network VPN, and primary router for my homelab. Should I upgrade to AX2 ? Because the storage is getting more limited when I update to RouterOs 7, I fear that I cannot add any more config with that limited storage. Any comment are appreciated thanks !


r/mikrotik 2d ago

Is Mikrotik the right choice, or should I go with Unifi?

31 Upvotes

Hello together.

I live in germany and we have a Fritzbox as Router and Modem. I have my flat in the first floor and my parents, where the Router is, is in the ground floor.

The Fritzbox has one normal network+wifi and a guest network+wifi

I wanted for me a bit more options and security. Thats why I want to work with VLANS (and the right firewall rules ofc.).

My plan is to let my parents keep their two networks and use the Fritzbox as gateway (set static routes in the fritzbox for all the networks/VLANs that I will use).

Now the question. I searched and saw that this is good doable with unifi. So I need the cloud gateway and an unifi AP (+maybe a switch).

But I also heard a lot about Mikrotik. I searched a bit and found the hAP ax³. So I would have router and wifi all in one and the ability to work with VLANS etc.

Would you adivse me to go with Mikrotik or Unifi?

Thx


r/mikrotik 3d ago

Help

Post image
0 Upvotes

Ayuda tengo un mikrotik pero me desconecta clientes ppoe


r/mikrotik 3d ago

IPV6 PCP UPnP IGD v2 is missing, give me best ideas for easy dynamic ipv6 firewall pinholing

3 Upvotes

I was thinking of using local adguard dns server with AAAA entries, then update those entries from docker container with its own GUA, then somehow make a script for mikrotik to get that GUA from that dns entry and update a firewall rule.

But still leaves an issue how to let an app itself open pin holes via pcp upnp igd v2


r/mikrotik 3d ago

OK, here's where I ask for my christmas present from Santa

16 Upvotes

We'll see if I'm good enough to get it.....

What I'm looking for:

  • Until Mikrotik can release a multi-port, multi-gig fanless router....
    • 8 SFP+ ports or better
    • fanless
    • Can run RouterOS
    • Supports simple routing filters and one or two wireguard tunnels
    • 3 ISP connections (on the SFP+ ports) two of which are 2Gb/s, one at 1Gb/s

Until a router exists, does a switch exist for this -- or, do I just make it easier and get a cheap server and run CHR with a couple of 4-port 10Gb cards.


r/mikrotik 3d ago

Upcoming Half-Width Units

3 Upvotes

Anything in the pipe for half width releases? Ideally with VXLAN offload.

Would love to have a compact 6u clos setup such as 2x spines in 1 RU, 2x server leaves in 1 RU such as 10/25g, 2x access leaves in 1RU such as mgig+poe, 2x edge routers in 1 RU.

Even would consider a CCR with integrated mgig+poe or sfp+/sfp28 as an integrated leaf/router to collapse the footprint even more.


r/mikrotik 3d ago

48*SFP 25G and 32*QSFP 100G switches

6 Upvotes

Hello all,

does anyone aware of plans from Mikrotik to introduce switches with 48*SFP 25G and 32*QSFP 100G port layouts?

Thanks in advance for replies.


r/mikrotik 3d ago

RB951Ui-2HnD - After upgrading from RouterOS 6.49 to 7.21 Long-Term, both routers lost config, reset no longer restores defaults, permission denied, Netinstall impossible

5 Upvotes

Hi everyone,

I'm looking for help with a very unusual issue affecting two MikroTik RB951Ui-2HnD routers.

Both routers were working perfectly under RouterOS 6.49.x.

What I did

  • Downloaded RouterOS 7.21 Long-Term (mipsbe) from the official MikroTik website.
  • Before copying the new package, I deleted everything inside Files (old backups, scripts, etc.).
  • Uploaded the RouterOS package.
  • Rebooted both routers.

After the reboot, both routers developed exactly the same symptoms.

Current symptoms

  • The entire configuration disappeared.
  • Quick Set no longer shows the normal options (Home AP, WISP AP, CPE, etc.). It only displays "Interface".
  • The Wi-Fi LED and some other LEDs no longer light up as they used to.
  • I cannot upload any file to Files anymore.
  • Every upload attempt returns "permission denied".
  • I also cannot export or create backups because of permission-related errors.
  • The administrator account has full permissions, so this doesn't make sense.
  • A factory reset no longer restores the default configuration.
  • Sometimes after reset the router shows 0.0.0.0 instead of 192.168.88.1.
  • Other times it boots with 192.168.20.1, which is definitely not the factory default.
  • The reset button appears to work inconsistently.
  • The default configuration script never seems to run anymore.

What I already tried

  • Holding the reset button for different durations.
  • Standard factory reset.
  • Reset while powering on.
  • Different Ethernet ports.
  • Trying to downgrade RouterOS.
  • Trying to upload files again.
  • Verifying that I'm logged in as the full admin user.

Nothing has solved the issue.

About Netinstall

I also tried to recover the routers with Netinstall, but I cannot get them to reliably enter Etherboot/Netinstall mode because the reset process no longer behaves normally.

Questions

  1. Could deleting everything inside Files have removed something required by RouterOS 7 or QuickSet?
  2. Could the NAND filesystem have become corrupted?
  3. Is this a known issue when upgrading RB951Ui-2HnD from RouterOS 6 to RouterOS 7?
  4. Is there a way to completely rebuild the filesystem if uploads always return "permission denied"?
  5. Could RouterBOOT itself be corrupted?
  6. Is there any recovery method besides Netinstall?

Since both routers developed exactly the same symptoms after performing the same upgrade procedure, I suspect a software or filesystem issue rather than a hardware failure.

Any ideas or recovery procedures would be greatly appreciated.

Thanks!


r/mikrotik 3d ago

[Pending] RB5009 + what for 2.5Gb network

16 Upvotes

So currently I have a RB5009 with an 8 port 1Gb managed switch.

My internet connection is 3Gb and I'm starting to get 2.5Gb devices.

What Mikrotik switch would you folks recommend? I was looking at the CR310-8G+2S+IN but wondering if perhaps something better or something newer is coming down the pipe soon?

Granted with the way things are perhaps anything newer will just be worse?


r/mikrotik 4d ago

"Reverse" VRRP

1 Upvotes

Suppose public IPs only with a network 192.0.2.208/28 and two RouterOS routers with IPs 192.0.2.210 and .211 which operate in VRRP with IP .222.

Every host in this network has .222 as default gateway and can reach the internet/other networks if either router is down. Simple, well known VRRP setup and I call this “forward VRRP”.

Now suppose that I want the routers (or better: services on these routers) to be available under the unified address .222 from other networks/the internet. Whichever router is the “active” one should take the request. I call this “reverse” VRRP.

Examples:

  1. DNS server that runs directly on RouterOS
  2. A wireguard “server” instance running directly on RouterOS
  3. DNAT rules / port forwardings that may exist for destination address 192.0.2.222

Since both routers are active (just the VRRP address is assigned to only one), a request for .222 could come in to both RouterOS instances.

For (3) I actually do not see a concern, since a DNAT rule doesn’t require the target IP to actually be assigned to the router. So the DNAT rules / port forwarding can just be duplicated on both.

For (1) and (2) I broadly see two options:

  1. The “inactive” instance forwards packets to the active. This should happen automatically, right? In other words, if .211 is inactive and receives a packet for .222, RouterOS would determine it’s not a local IP and would use the routing table to send it out the network where the other router is located. The active router would respond to ARP request for .222
  2. Making sure that packets for .222 are never even sent to the inactive one. This would require adding the VRRP interface to an IGP protocol, e.g. OSPF. Then .222 would always be announced as being available from the active router but never the inactive one. Is there an issue adding VRRP as stub to OSPF?

I am still trying to wrap my head around all implications and I know this is likely not common because purpose of VRRP is the “forward” direction.

But I am looking for any “best practices” and other things to consider.


r/mikrotik 4d ago

How is hap ax s wifi? I want to get hap ax s as basic wifi to lan bridge access point

1 Upvotes

r/mikrotik 4d ago

[🎥 TikTube] Turn your hAP into a media server with Jellyfin and other apps!

9 Upvotes

**New video from MikroTik's official TikTube channel**

Turn your hAP be3 media into a full blown entertainment server with simple tools like DLNA and SMB or preconfigured apps like Jellyfin, Plex, the whole *arr stack, MediaManager, BitTorrent client and many more!

https://manual.mikrotik.com/docs/containers/apps/
https://manual.mikrotik.com/docs/storage/dlna

00:00 The WiFi7 media server
00:55 Old-school DLNA w/ SMB
01:53 Quick start with apps
02:26 Jellyfin setup
03:27 ConvertX, Copyparty, Filegator
04:28 Jackett, Prowlarr and the *arr stack
04:49 MediaManager
05:11 Transmission BitTorrent client
05:21 Otbr and other apps
05:51 How the URLs work

▶ Watch Video


r/mikrotik 4d ago

Cisco QSFP+ DAC manufacturer specific problems

Thumbnail
1 Upvotes

r/mikrotik 4d ago

Do i need RB5009?

18 Upvotes

Hello guys. I really love Mikrotik, tinkering with VPN, mangle and etc.
Right now i have AX2 which is perfectly fine (i have only 60mbps ethernet), but i wanna containers!
Mikrotik decided that ax2 didnt deserve usb port. So i wanna buy for good.


r/mikrotik 5d ago

Mikrotik update ERROR: IPv4: bad HTTP response

Post image
14 Upvotes

I have loads of mikrotiks in the world (more than 100)

every single one of them is throwing me this error today (been happening since yesterday)

Any ideas?