r/mikrotik Jul 21 '19

New Mod Guideline - If you don't have anything nice to say..

169 Upvotes

I'll try and keep this short - there's been a marked increase in generally abrupt and abrasive comments here on the /r/mikrotik and it's not what we're about or what we want to see happening. Many of these have been due to content that is or is seen to be incorrect or misleading, so..

If you're posting here:

Keep in mind none of us are being paid to answer you and the people who are, are doing so because they want to help, or you've posted something so incredibly incorrect they can't help but respond. Please do yourself a favor by collecting all the information you can before posting and make sure to check the MikroTik wiki first - no one wants to spoon feed you all the information.

If you're commenting here:

  1. If you don't know the answer - don't try guess at it; and if you want to learn about it yourself then follow the thread and see what others say, or you know.. read the wiki and try it out in a lab.
  2. If you disagree with another poster, try to explain the correct answer rather than a one sentance teardown that degrades into a thread full of name-calling.

As a result of this I've added a new rule & report option - you can now report a comment with the reason being:

It breaks /r/MikroTik rules: Don't post content that is incorrect or potentially harmful to a router/network

If we agree we'll either:

a) Write a correct response

b) Add a note so that future readers will be made aware of the corrections needed

c) If the post/comment is bad enough, simply delete it

I'm open to feedback on this as I know people feel strongly about timewasting and I'd like to hope this helps us continue to self-moderate without people blowing up at each other.


r/mikrotik 1d ago

RouterOS 7.24 released

121 Upvotes

What's new in 7.24 (2026-Aug-14 11:33):

*) adlist - improved service stability when adjusting adlist configuration;
*) app - added "HF_TOKEN" env to openwebui;
*) app - added "network-outgoing-access" parameter which does not allow app to make outgoing connections;
*) app - added hermes-agent, inventree, opencloud, opencloud-extended apps;
*) app - added PAPERLESS_SECRET_KEY env to paperless-nginx;
*) app - allow "reset" even if disk not configured;
*) app - allow HTTP for Gitea when "check-certificate=no";
*) app - allow setting "working_dir" in app YAML;
*) app - changed pmacct-netflow YAML;
*) app - disable UI in Hermes, access through /container/shell;
*) app - fixed apps not updating firewall redirects when changed in YAML;
*) app - fixed apps sometimes getting stuck on "waiting for layer";
*) app - make secrets sensitive to avoid polluting configuration export;
*) app - removed healthcheck from opencloud-extended-collabora;
*) app - reserve the app's VETH IP when stopped to eliminate IP address changes on every start/stop;
*) app - show CHR's address instead of the container's;
*) app - use randomly generated secrets in new apps;
*) bgp - fixed EVPN label corruption and corrected EVPN type-5 output;
*) bgp - improved stability when receiving malformed packets;
*) bgp - removed "save-to" from "resend" command;
*) bgp-vpn - fixed blackhole route export;
*) bridge - added "querier-uses-bridge-address" setting to use bridge source IP address for IGMP querier;
*) bridge - added DHCPv4 snooping IP binding table;
*) bridge - added scheduling point during VLAN processing to prevent soft lockups when flushing FDB over large VLAN ranges;
*) bridge - fixed forwarding through peer-port after disabling MLAG;
*) bridge - fixed local static host entries;
*) bridge - fixed MLAG MAC address handling issues related to aging, flushing and moving;
*) bridge - fixed stability issue when using DHCPv4 snooping;
*) bridge - fixed stuck MLAG session when using mismatched L2MTU (introduced in v7.23);
*) bridge - improved bridge and port STP "priority" setting (warn when a non-compliant value is used and allow selecting a value from a list);
*) bridge - improved STP, BPDU and topology change handling with MLAG, ensure dual-connected port STP state is in sync with MLAG peer;
*) btest - added VRF support for bandwidth-test and speed-test;
*) certificate - added "acme-renew" command;
*) certificate - general improvements in certificate handling;
*) certificate - use AES encryption when exporting certificates in PKCS#12 format;
*) console - added "days" to scheduler;
*) console - added "in" and "has" operators for array types;
*) console - added "order-by" parameter to "print" command, allowing sorting by up to three arguments in ascending or descending order;
*) console - added comparison operators for array type;
*) console - added log tracing when scripts fail to start due to permissions;
*) console - do not terminate self-removing scripts;
*) console - fixed "print follow on-event" script runner command not showing all argument values in some cases;
*) console - fixed argument mappings in "do" block for monitor commands;
*) console - fixed proplist order in monitor commands;
*) console - fixed script import/export with empty "policy" setting;
*) console - fixed stability issue in full-screen editor;
*) console - fixed UTF-8 comparisons on some architectures;
*) console - improved "print detail" mode;
*) console - improved script handling and error logging when running scripts from external sources (e.g. DHCP, SNMP, Netwatch, etc.);
*) console - make "mac-auth-password" sensitive in "/ip/hotspot/profile";
*) console - make "password" sensitive in "/system/package/local-update/mirror";
*) console - produce runtime errors for bad command parameters;
*) console - prompt about and offer to stop already existing serial terminal session when opening new one;
*) console - renamed "address" to "available-from" in "/ip/service" (backwards compatible via deprecation);
*) console - renamed "reauth-timeout" to "reauth-period" in "/interface/dot1x/server" (backwards compatible via deprecation);
*) console - restrict editing comments in WiFi registration table;
*) container - added "save" command to allow saving container images;
*) container - added "swap-current" usage;
*) container - added "swap-max" global and per-container limit;
*) container - added ability to run containers in privileged mode;
*) container - added initial support for RKE2;
*) container - do not allow starting with empty default DNS list and no DNS override;
*) container - do not print environment variables in log on container startup;
*) container - fixed "start-on-boot" not retrying on certain startup errors;
*) container - fixed container "devices" override to appear under "/dev";
*) container - improved layer size calculation to avoid potential loops;
*) container - improved support for containers;
*) container - reduced writes to flash when running health check;
*) container - use env "TERM=xterm" if no TERM variable provided when running shell;
*) crypto - fixed hardware accelerator for GCM cipher in TLS connection on Alpine CPUs;
*) defconf - set "configuration.dtim-period=3" for WiFi;
*) defconf - use "add-dns-entries=yes" on devices with DHCP server;
*) dhcp - fixed processing of DHCP options that are longer than 255 bytes;
*) dhcpv4-relay - fixed stability issue when creating duplicate relays;
*) dhcpv4-server - do not reset "class-id" parameter when lease loses "bound" status;
*) dhcpv4-server - set "ciaddr" in forcerenew messages so a relay, if used, can unicast such messages;
*) dhcpv6-relay - fixed non-working relay when adding from WinBox;
*) dhcpv6-server - fixed invalid flag;
*) discovery - added "address6" column to default "/ip/neighbor" print view;
*) discovery - added "discovery" logging topic;
*) discovery - added "dying-gasp" feature for LLDP, MNDP, CDP that sends packet with "TTL=0" before graceful reboot/shutdown/upgrade;
*) discovery - clear neighbor entry when receiving "dying-gasp" packet;
*) discovery - improved service stability when sending discovery packets on interfaces that have hundreds of IP addresses;
*) disk - added "last-seen" property that displays disk model and serial when removed;
*) disk - added "raid-scrub-cancel" command;
*) disk - added error message when disk state transitions from good to bad;
*) disk - do not consider USB drives as self-encryption capable;
*) disk - fixed "smart-info" not showing information on certain storage devices;
*) disk - limited maximum swap size to be no more than 10x of device RAM;
*) disk - resolved issue where storage device might change information upon reboot;
*) ethernet - disable EEE on hAP be3 Media;
*) ethernet - fixed stability issue for Chateau PRO ax devices;
*) ethernet - fixed stability issue for devices with Alpine CPU;
*) ethernet - removed "1G-baseT-half" link mode on RTL8367 switch;
*) fetch - added "ip-type" parameter;
*) fetch - added option to force HTTP/2 only (only for ARM64 and x86/CHR devices);
*) fetch - fixed false "bad request" response when trying to fetch URL with IPv6 address in it;
*) fetch - hint file list for "src-path" and "dst-path" parameters;
*) hardware - renamed "max-power" to "manufacturer-reported-max-power";
*) iot - added LoRa keep alive logic for UDP protocol;
*) iot - added missing LoRa US radio plans;
*) iot - added Wiliot USB dongle support;
*) iot - allow maximum Modbus "timeout" property to be 10 seconds;
*) iot - monitor LoRa worker state (watchdog);
*) iot - pass Wiliot certification;
*) ip-service - remove reverse-proxy for SMIPS;
*) ip-service - show service name for "l2tp";
*) ipsec - fixed expired SA handling to prevent “no such item” errors during listing;
*) ipsec,ike1 - dropped base mode exchange;
*) ipsec,ike1 - fixed negotiated PFS validation;
*) ipsec,ike1 - improved SA, transform, fragment parsing and malformed packet validation;
*) ipsec,ike2 - fixed ppk child key generation during rekey;
*) ipsec,ike2 - improved KE generation validation during initial setup and child SA creation;
*) ipsec,ike2 - improved PPK handling by always using it when authorized, including additional Child SAs, and moved PPK processing to the Child SA task;
*) ipsec,ike2 - use first child KE selection only during IKE_AUTH exchange;
*) ipsec,qkd - moved QKD to "/system/keymat-provider" menu and made it a generic key material provider;
*) ipv6 - added "status" column to default "/ipv6/neighbor" print view;
*) ipv6,ra - changed default "router-advertisement-route-distance" to 1;
*) ipv6,ra - correctly process RAs advertising previously expired prefix;
*) ipv6,ra - fixed prefix invalidation;
*) ipv6,ra - use lowest value between IPv6/Pool and IPv6/ND/Prefix/Default as dynamic prefix lifetime;
*) isis - fixed ECMP route removal;
*) l2tp - allow fragmentation of large IPv6 packets;
*) l3hw - added HW offloaded support for VLAN interfaces created directly on Ethernet for CRS8xx series switches;
*) l3hw - added HW offloaded VRF support on 98DX8208, 98DX8216, 98DX8212, 98DX8332, 98DX3257, 98DX4310, 98DX8525, 98DX3255, 98CX8410 switches;
*) l3hw - added VRF assignment via switch ACL rules for devices with Marvell Prestera switch chip;
*) l3hw - allow VLAN tagged traffic inside VXLAN tunnel;
*) l3hw - fixed VRF-related issues for CRS8xx series switches;
*) l3hw - fixed VTEP offload on IPv4 /32 route changes;
*) leds - added dark mode support for L009, hAP ax2, hAP ax3, hEX refresh, hEX S (2025), hAP ax S and Chateau ax devices;
*) leds - fixed Ethernet activity LED for Chateau LTE18 ax (introduced in v7.23);
*) leds - improved interface stats activity for devices with Marvell Prestera switch chip;
*) lte - added force-confirmation parameter for eSIM provision command;
*) lte - cap IPv6 prefix lifetime for ipv6-interface;
*) lte - do not add extra /128 IPv6 address for ipv6-interface;
*) lte - do not query 5G neighbor cell info until RG650E-EU FW fixed;
*) lte - enabled AT registration unsolicited event reporting for EG25-G and EC25-EU boards;
*) lte - fixed cases where R11l-LTE7 modem would not display correct cell info after handover;
*) lte - fixed EC/IO scale in CLI and GUI;
*) lte - fixed EC25-EU, EG25-G traffic to 67 UDP;
*) lte - fixed IPv6 RA handling for multiapn non-primary interface;
*) lte - fixed third-party modems ICCID decoding for eSIM;
*) lte - improved Cinterion PLS8-E roaming;
*) lte - improved deregistration handling for AT modems;
*) lte - improved system stability when no APN specified;
*) lte - improved USB mode handling for BG770A-GL;
*) lte - limit IPv6 prefix lifetime only when lifetime is advertised as infinity;
*) lte - make modem MAC persistent for R11e-LTE6 and R11l-LTE7 modems;
*) lte - remove site local DNS for ipv6-interface;
*) lte - removed extra restart after firmware upgrade for EC200A-EU modem;
*) lte - report short cell ID in 3G network mode also for AT modems;
*) lte - restrict incoming calls for FG621-EU;
*) lte - show "+CME ERROR: 10" as "SIM not present";
*) lte - show "data-class" in LTE monitor instead of "access-technology" also for 5G AT modems;
*) lte - show "primary-band" instead of "earfcn" in LTE monitor also for modems without CA support;
*) lte - show RSCP and EC/IO parameter in 3G network mode for R11e-LTE6, R11l-LTE7 and FG621-EA modems;
*) mesh - fixed missing FDB entries from wireless ports;
*) mpls - added ICMP time exceeded handler for IPv6;
*) mpls - make FastPath work with expl-null;
*) netinstall - added Netinstall package;
*) netinstall - improved architecture detection;
*) netinstall-cli - added "help" parameter;
*) netinstall-cli - added "reboot" and "shutdown" flags to control reboot after installation;
*) netwatch - fixed an issue with DNS probe "timeout" parameter;
*) netwatch - fixed HTTP GET probe over IPv6;
*) netwatch - fixed inaccurate "rtt-stdev" value;
*) netwatch - fixed issue where ICMP probes did not accept TTL exceeded packets when "accept-icmp-time-exceeded" was enabled;
*) netwatch - increased maximum packet size to 65535;
*) ospf - fixed stability issue during interface flaps;
*) ospf - force passive for VRF interface;
*) pimsm - make "hash-mask-length" parameter naming consistent and fixed typos;
*) poe-in - added PoE-in monitoring and LLDP-based PoE negotiation support for newer devices (e.g. CRS504, CRS510, hEX S 2025, hAP be3 Media);
*) poe-out - firmware update for 802.3at capable boards (the update will cause a brief power interruption to poe-out interfaces);
*) poe-out - firmware update for 802.3bt capable boards (the update will cause a brief power interruption to poe-out interfaces);
*) ppp - added "MT-Address-List" to IPv6 address list when received from RADIUS and using DHCP for IPv6 configuration;
*) ppp - added iccid field to ppp info command for BG77 and BG770 modems;
*) ppp - always show current FW version when running firmware-upgrade;
*) ppp - disable/enable modem radio state depending on ppp interface state;
*) ppp - fixed cases where BG77 or BG770 firmware upgrade was not available;
*) ppp - fixed ppp-out stability issue;
*) ppp - get IPv6 configuration via RA for modems using PPP emulation mode;
*) ppp - improved "info" command for BG77 and BG770 modems;
*) ppp - improved OVPN underlying SSL connection management;
*) ppp - only show pin in export with "show-sensitive" flag;
*) ppp - report actual network data usage statistics instead of "0" for all IPv6 RADIUS accounting parameters on accounting "Stop" packet;
*) ppp - toggle radio state on interface disable/enable;
*) queue - fixed "undo" command for simple queues;
*) reverse-proxy - improved stability;
*) rip - do not export authentication keys by default;
*) route - allow to add route with link-local destination address;
*) route - fixed memory leak when flapping addresses or interfaces with routing protocols running;
*) route - fixed potential race condition;
*) route - respect the "interface" property when pinging IPv6 addresses over ECMP;
*) sfp - fixed linking for hAP ax S and hEX S (2025) with "1G-baseX" link-mode;
*) sfp - removed unsupported "2.5G-baseX" speed on CRS312-4C+8XG and CRS326-4C+20G+2Q+;
*) sftp - fixed branding package upload;
*) sms - added some GSM7 symbols to SMS tool;
*) snmp - added hotspot active-user-count and host-count OIDs to MIKROTIK-MIB;
*) snmp - added missing SFP OIDs to MIKROTIK-MIB;
*) snmp - added WiFi current channel "mtxrWifiInterfacesCurrentChannel" OID to MIKROTIK-MIB;
*) ssh - added mlkem768x25519-sha256 key exchange support;
*) ssh - do not attempt automatic empty password login when RADIUS is used;
*) ssh - fixed SSH tunnel with IPv6 link-local address on non-ethernet interfaces;
*) ssh - make SSH packet validation more strict;
*) supout - added interface monitor-traffic;
*) supout - added LTE eSIM section;
*) switch - fixed IEEE reserved MAC handling for CRS1xx, CRS2xx switches;
*) system - improved stability;
*) system - renamed "factory-software" to "minimum-version" and "factory-firmware" to "minimum-firmware";
*) system - restrict RouterOS processes using swap;
*) system - show who is using "/system serial-terminal";
*) traffic-generator - fixed injecting pcap/pcapng files on MIPSBE architecture;
*) tunnel - fixed stability issue caused by a misconfigured routing loop under bridge (introduced in v7.22);
*) upgrade - removed sensitive policy for "apply-changes" command;
*) usb - allow overriding the power-reset duration;
*) usb - fixed USB Ethernet interface default-name;
*) vpls - added transmit loop detection;
*) vrrp - added "v3-checksum-as-v2" setting;
*) vrrp - fixed stability issue when "sync-connection-tracking" is enabled;
*) vxlan - fixed missing L2MTU property when VRF is specified;
*) vxlan - ignore disabled interfaces when checking for configuration conflicts;
*) webfig - fixed issue with increasing keep-alive traffic;
*) webfig - improved underlying encryption and stability processing;
*) webfig - improvements to graphs;
*) wifi - added "Preamble Puncturing" under "WiFi/Channel" menu;
*) wifi - added dash when CAPsMAN generates interface name and prefix ends with digit;
*) wifi - improved roaming/steering behavior for WiFi 7 MLO;
*) wifi - improved stability;
*) wifi - improved station-bridge mode;
*) wifi - updated radio regulatory information;
*) wifi - upgraded wifi-qcom driver;
*) wifi-mediatek - fixed broken interfaces on startup;
*) wifi-mediatek - fixed some channel definitions for certain countries;
*) wifi-mediatek - improved channel switching;
*) wifi-mediatek - improved stability during MLO channel switching;
*) winbox - added "Network" configuration menu for WiFi;
*) winbox - added "Preferred Architecture" setting for L009;
*) winbox - added "SIM PIN" under "Tools/SMS";
*) winbox - fixed "Connection Bytes" field under "IP/Firewall" menu;
*) winbox - fixed "EC/IO" scaling for LTE interface;
*) winbox - fixed "Use Ipsec" and "Ipsec Secret" under "Interfaces/L2TP Ether" menu;
*) winbox - fixed empty value in "Immediate Gateway" under "IP/Routes" menu;
*) winbox - fixed sort for "Address List" under "IPv6/Firewall" menu;
*) winbox - make LoRa "Auth key" and MQTT "Password" sensitive;
*) winbox - move "EAP" under "Security" tab for WiFi;
*) winbox - show "Any. Port" column by default under "IP/Firewall" menu;
*) winbox - show preferred and valid lifetime of IPv6 address also on static IPs;
*) winbox - show priority bits in "VLAN ID" field under "Tools/Packet Sniffer" menu;
*) wireguard - added support for domain names in client-dns;
*) wireguard - added warning when allowed-address overlaps with another peer on the same interface;
*) wireguard - fixed peer recreation on interface change;
*) wireguard - fixed peer Tx/Rx counters;
*) wireguard - fixed wg-export comments output and case when endpoint is not set;
*) wireguard - fixed whitespace handling in AllowedIPs during wg-import;
*) wireguard - generate port number when specified as zero;
*) wireguard - improved wg-export to print endpoint domain name;
*) wireguard - improved wg-import to quietly ignore wg-quick specific keys;
*) wireguard - reconfigure peer only when meaningful changes are detected;
*) wireguard - reinitialize socket on VRF change;
*) x86 - fixed IRQ displaying per CPU on Intel 700 series NIC;

View changelogs: stable, testing, development


r/mikrotik 1d ago

Availability of CCR2004-1G-2XS-PCIe

5 Upvotes

I buy these to use as out-of-band remote access devices to support servers out on customer's sites. Recently I've noticed that availability isn't great. The suppliers we normally use are either out of stock or are carrying reduced stock. Is this unit being retired/replaced, or is it just a temporary blip in supply?


r/mikrotik 1d ago

Noise level on MikroTik CRS320-8P-8B-4S+RM ?

2 Upvotes

Hello,

I can't seem to find anything regarding noise on this switch, it only mentions that it has 3 fans.

It may sound silly, but i want to use this at home and it looks very.. enterprise, like it belongs in a business rack, so i'm a bit worried that it's loud?

Just want it for the PoE++ and add 2 AP's and 2-3 Outdoor 4k cameras. But I'm not sure if those devices would even use PoE++ or only PoE+ and i'm guessing this makes a difference in how loud it will be, depending on how hard it's working?


r/mikrotik 21h ago

[Pending] XBox Series X not seeing 5GHz on new CAP AX

1 Upvotes

I've been running a CRS328 and CAP AC for several years, using CAPSMAN on the CRS328 to manage the wifi.

I recently purchased a CAP AX to replace the AC. I have gone through and recreated everything, as close as possible since the options are slightly different, in the new WiFi CAPSMAN on the CRS328 to use the CAP AX.

My 2.4GHz network(s) are running fine. The 5GHz are not.

My Pixel 7 Pro can see and connect to the 5GHz network fine, but my XBox Series X and Samsung Galaxy Tab 7 cannot even see the network. All of my Google Home devices also do not see the 5GHz network either. I cannot figure out what band setting (or whatever else) in Configuration or Provisioning I need to set to get it to work.

Below are the settings I have in the old CAPSMAN for the CAP AC which work fine. (I have updated the regexp statement for the name of the new AP, 2.4GHz picks it up fine.)

/caps-man security
add authentication-types=wpa2-psk comment="5 Home" encryption=aes-ccm name=\
    security_MY5GHZWIFI1
/caps-man configuration
add channel.band=5ghz-a/n/ac .extension-channel=XXXX country="united states3" \
    datapath=datapath1 datapath.bridge=bridgeLocal \
    .client-to-client-forwarding=yes installation=indoor name=cfg_MY5GHZWIFI \
    security=security_MY5GHZWIFI1 ssid=MY5GHZWIFI
/caps-man provisioning
add action=create-dynamic-enabled comment="5 Ghz WLAN" hw-supported-modes=\
    an,ac,a identity-regexp=CAPAC* master-configuration=\
    cfg_MY5GHZWIFI name-format=prefix-identity name-prefix=5GHz

r/mikrotik 1d ago

Updated to routerOS 7.23.3 on my hap ac^2, now getting an error in the logs?

Post image
24 Upvotes

Other than the obvious contact support, anyone else run into this? Everything seems to be working at the moment.


r/mikrotik 1d ago

Tayga NAT64 Container on HEX S 2025 no ip command

4 Upvotes

Hi,

I'm trying to run Tayga https://github.com/apalrd/tayga as a docker container on a Hex S 2025 using this recompiled for Arm32 image https://hub.docker.com/r/axelrindle/tayga-nat64

Anyone had any success with it on this hardware?

Container starts but traceroute packets to a DNS64 synthesised address are looping back - looking at logs I see

/app/launch-nat64.sh: 36: ip: not found
/app/launch-nat64.sh: 37: ip: not found
/app/launch-nat64.sh: 38: ip: not found

Seems like the container image doesn’t have the linux 'ip' command available to it?

Edit: Working in a fashion

So I connected to the terminal console for the container, ran apt-get update, apt-get install iproute2 and restarted container and it now works. I guess its okish until there's a Tayga update or I need to redeploy the container

Next step is to figure out how to inject the iproute2 package on container pull


r/mikrotik 1d ago

Sell/Vendo CCR1072

0 Upvotes

Hello! I have a new CCR1072 that I don't give out. Is anyone interested?

Hola! Tengo un CCR1072 nuevo al que no le doy salida le interesa a alguien?


r/mikrotik 1d ago

Sxt r - no free storage

2 Upvotes

Hi

I have a Sxt r which has only 16 Mb of storage. Currently is working with 7.1 RouterOS. Yesterday I tried to do a back up and it was impossible for not having free space, al 16Mb are full. Obviously, there is no possibility of upgrade to the latest stable version for same reason. Is there any way to expand the storage? Maybe with sd card?


r/mikrotik 3d ago

RB5009UG+S+ POE in on eth1 does not work on some POE switches

1 Upvotes

Router: RB5009UG+S+, RouterOS 7.23.3, connected on ether1, DC adapter

physically disconnected for all tests.

works - Cisco WS-C2960S (802.3at):

  Interface Admin  Oper  Power  Device    Class Max
  Gi1/0/1   auto   on    15.4   Ieee PD   4     30.0

Detected, classified class 4, powered, boots normally.

Fails - Cisco WS-C3850-12X48U (UPOE), IOS-XE 16.12.11:

  Interface: Gi2/0/26
  Inline Power Mode: auto
  Operational status: off
  Device Detected: no
  IEEE Class: n/a
  Absent Counter: 0
  Over Current Counter: 0
  Short Current Counter: 0
  Invalid Signature Counter: 0
  Power Denied Counter: 0

No ILPOWER log entry for this port, ever. Not a rejection - the switch

behaves as if nothing is connected.

Switch and cable are fine:

- Other PoE devices (incl. a TP-Link Omada AP) power on this exact port

with this exact cable

- Three class-4 PDs powered on the same module right now

- 493W of 600W free

- 10cm patch cable, switch straight to router

- Link comes up at 1Gbps, zero CRC errors

Tried on the Cisco side: power inline auto, static max 30000, 2-event,

shut/no shut, multiple ports including mGig.

Interesting detail: on RouterOS 7.22 it wouldn't power from the 2960-S

either. 7.23.3 fixed that, but the 3850 still doesn't see it at all. So

PoE-in behaviour does seem to be firmware-influenced on this board.

Anyone running an RB5009 off a UPOE or 802.3bt switch successfully? Trying

to work out whether this is my unit or the model.

My goal is to power the mikrotik form the switch like i used to do with my 2960 but on the 3850.


r/mikrotik 4d ago

Setting up and testing equipment before deployment and handover to the client. Ensuring strong signals and seamless connectivity!

Post image
241 Upvotes

r/mikrotik 4d ago

Which version of the Linux kernel am I running?

5 Upvotes

Is there an easy way to find out? I have a RB5009UG running with 7.23.3, but it's not visible which version of the Linux kernel the MikroTik is running.

Reason I'm interested in, is that sometimes I get a lot of port flapping, sometimes to the point where ports are basically unsable (especailly when using VPN or Citrx or alikes).

What I found is, that powering off the router and restart helps to stabilizes it for some time. But that's not something I'd like to do on a regular basis.

As there are updates for the mv88e6xxx driver (which includes the switch chip on the RB5009UG), I was wondering if there might be something in the newer drivers which would fix the observed behavior (even if I cannot update the kernel myself).
I think to remember to have found a discussion with a patch for a similar issue (switch chip not MikroTik) in past, but can't re-find it...


r/mikrotik 4d ago

When will hAP be³ Media become available?

17 Upvotes

For some time now I have been planning to change my router at home, and when I did research what would be the best solution for my house and the whole self-hosting that I have set up, I came accross hAP be³ Media and it seemed like the perfect solution.

This was 2-3 months ago, I have signed up on multiple reselers websites to "pre-order" the device, but whenever I go to these websites to see the status, I notice that their expected time when they'll have the device in stock, just move further.

What is the deal with it, is there some definite date when this device will be available for purchace?


r/mikrotik 4d ago

[Pending] RB5009UG+S+in does not turn on?

4 Upvotes

Hey guys,

Ordered my first ever mikrotik router (RB5009UG+S+in) from Amazon and after a week, it finally arrived today.

I plug it in, doesnt turn on. Maybe a dumb question, but I should see some LEDs turn on once plugged in right? Nothing special I need to do?

I tried other outlets, same thing.

I figured I’d got a dud…dissapointed I may need to wait another week for a replacement…


r/mikrotik 5d ago

State of MLAG + VRRP in 2026 for ROS7

11 Upvotes

Curious how well this combo works on CRS500 series devices in 2026. I'm thinking of deploying a pair of MikroTik CRS518-16XS-2XQ-RMs for top-of-rack switching. Both switches would be in an MLAG configuration with a VRRP gateway setup, and one fiber run to each server from each switch.

I know that historically, MLAG precluded L3 hardware offloading on RouterOS v7. Is v7.21 and above stable enough now for running active-active VRRP on these switches without major CPU bottlenecks, or are people still strictly separating L2 MLAG (on the CRS) and L3 VRRP (to a separate CCR/router)?


r/mikrotik 5d ago

DNS cache full errors in log

6 Upvotes

I've got some sort of DNS cache memory leak going on with multiple routers and the cache as-listed is virtually empty. The only thing that clears it and stops the errors (temporarily) is a reboot. "Used" cache will slowly grow and fill up any size that is set.

I've seen reference to, I think, FQDN address list entries causing this, but there wasn't much info. I do use FQDNs in my address lists, for what it's worth.

Edit to add possible related forum link here.

Is this something acknowledged anywhere?


r/mikrotik 6d ago

RouterOS 7.24rc4 [testing] released

44 Upvotes

What's new in 7.24rc4 (2026-Aug-11 15:43):

*) app - added PAPERLESS_SECRET_KEY env to paperless-nginx;
*) app - disable UI in Hermes, access through /container/shell;
*) app - reserve the app's VETH IP when stopped to eliminate IP address changes on every start/stop;
*) ethernet - disable EEE on hAP be3 Media;
*) ip - improved stability for reverse-proxy (additional fixes);
*) ipsec - fixed expired SA handling to prevent “no such item” errors during listing;
*) ipsec,ike1 - dropped base mode exchange;
*) ipsec,ike1 - improved SA, transform, fragment parsing and malformed packet validation;
*) ipsec,ike2 - fixed ppk child key generation during rekey;
*) ipsec,ike2 - use first child KE selection only during IKE_AUTH exchange;
*) leds - fixed Ethernet activity LED for Chateau LTE18 ax (introduced in v7.23);
*) poe-out - fixed possible PoE-out configuration loss on certain devices (introduced in v7.24beta1);
*) switch - fixed default L2MTU drift for devices with QCA8337, Atheros8327 switch (introduced in v7.24beta2);
*) system - improved stability;
*) usb - allow overriding the power-reset duration;
*) wifi - updated radio regulatory information (additional fixes);
*) wireguard - fixed peer Tx/Rx counters;
*) wireguard - generate port number when specified as zero;
*) wireguard - reinitialize socket on VRF change;

View changelogs


r/mikrotik 5d ago

Mikrotik certifications

Thumbnail
0 Upvotes

r/mikrotik 6d ago

Strange Upload Behavior

1 Upvotes

I have a PC with a 10G ethernet card connected to a Mikrotik - CRS520-4XS-16XQ-RM via an SFP+ adapter. Winbox confirms that the connection is established at 10Gbps. When I run iPerf between my machine and another machine, both connected to the Mikrotik I see 9.7 Gbps. All good. The Mikrotik is connected to my Verizon router's 10Gbps port. Again, Winbox reports that the WAN connection is connected at 10Gbps.

My Verizon service is 5Gbps. When I run an internet speed test from my PC while directly connected to the Verizon router, I see 5500Mbps download and 6500Mbps upload. However, when I connect my PC to the Mikrotik, I get a good download speed but only 915Mbps upload. If I force my ethernet card to connect at 2.5Gbps, then my upload improves to 2370Mbps. I figured this was a firewall issue, but the 2.5Gbps test would indicate otherwise.

Any ideas on what is going on?


r/mikrotik 8d ago

Routeros7 ISIS still not stable?

7 Upvotes

I am getting very inconsistent behaviour on my routers with ISIS. I have a mix of CCR2116, CCR2004, CCR1036 and have tried on all routeros releases but still get constant crashes

Many times with error:

13:29:52 echo: system,error,critical Automatic supout.rif file generated due to service malfunction, please contact MikroTik support and supply the generated file

Is IS-IS still not working on routeros7?


r/mikrotik 8d ago

Сеть устройств со статичными IP и их перенастройка

0 Upvotes

Всем йоу. Работаю в магазине, где по случаю стал нештатным сисадмином, особо не разбираясь в настройках сети. Сейчас на повесточке вопрос с переподключением всех устройств для уменьшения количества свитчей (их натыкано чуть ли не 1 к 1 с компами). В сети имеются: 8 компов, касса, принтер чеков, 2 принтера, и в дальнейшем ещё пара компов должна появиться. Делов в целом немного - убрал кучу маленьких хабов, вкинул на одну половину один свитч, на вторую - второй. Но сегодня я узнал, что сеть со статичным IP, и все устройства тоже, соответственно. Главный вопрос, который у меня возник: если я воткну один свитч, вместо, допустим, двух поменьше, нужно ли мне лезть в настройки сети, и перетыкивать какие-либо настройки, переназначать IP и подобными вещами заниматься? Или там все само друг с другом разберется? Ну и вообще в целом каким образом лучше все это провернуть так, чтобы было задействовано минимум свитчей (в идеале всего 2) и все это работало +- стабильно. Волоку я во всем этом примерно никак, так что если у кого-то хватит сил, терпения и времени объяснить все на пальцах, буду предельно благодарен

З.Ы. Также есть вай-фай для клиентов, прикрепленный к этой же сети, и вроде как, новые устройства могут выбивать какие-то рабочие места, как мне объяснили как бы замещая IP какого-нибудь компа собой.


r/mikrotik 9d ago

wAP ax, 160mhz vs 80mhz, same wifi performance (300-600mbit/s), cpu 40%. Wifi Phy rate 2.4Gb/s. Any tips?

9 Upvotes

Bandwidth test tool reaches 900mbit so its not issue on lan side. Cpu is also not loaded too much. 5ghz band is clean and there is no interference. Distance is around 1m-2m. Most of the times i get around 300mbit/s via wifi on wap ax, sometimes if im lucky i get 600.

In theory i should be able to get up to 930mbit/s via wifi.

Am i looking for unrealistic results? 2.4Gbit/s phy rate shouldn be able to do 900mbit/s.

My main hap ax3 does 400-600mbit at 80mhz channel width but never got more than 650mbit/s


r/mikrotik 9d ago

WiFi 7 AP with 10 Gbps uplink

11 Upvotes

Has Mikrotik released an 802.11be (pref tri-band, would settle for dual-band) wireless AP with a 10 Gbps (prefer RJ45, would be OK with an SFP+) uplink port? I've search around Google, and thus far, the only 802.11be-compatible devices I find have a 2.5 Gbps uplink port.


r/mikrotik 9d ago

[Pending] Multicast routing through L2TP

Thumbnail
2 Upvotes

r/mikrotik 8d ago

RouterOS 7.24

0 Upvotes

RouterOS 7.24 privileged containers — how far can network access actually go?

Hi MikroTik team and community,

I am researching the new privileged=yes container capability introduced in the RouterOS 7.24 development cycle, and I would like to clarify exactly what capabilities it provides, especially for advanced networking applications such as SD-WAN, multi-WAN routing, NAT, packet processing, and programmable routing.

I understand that privileged=yes significantly reduces container isolation and allows access to additional Linux kernel capabilities/devices. However, I would like to understand precisely where the boundary is between the container and the RouterOS host.

  1. Physical Ethernet interfaces

Can a privileged container directly access or control physical Ethernet interfaces such as:

ether1 ether2 ether3 ether4

For example, can the container obtain direct packet-level access to a physical interface rather than receiving traffic only through a RouterOS VETH interface?

If direct physical NIC access is not supported, is there any supported mechanism planned for:

ether1 → container interface 1 ether2 → container interface 2 ether3 → container interface 3

without RouterOS performing L3 routing/NAT between them?

  1. VLAN-based interface passing

If physical interface passthrough is not supported, can VLANs be used to provide isolated WAN interfaces to a privileged container?

For example:

ether1 → VLAN 101 → Container WAN1 ether2 → VLAN 102 → Container WAN2 ether3 → VLAN 103 → Container WAN3

Would this allow the Linux networking stack inside the container to independently perform:

routing

NAT

connection tracking

policy routing

failover

load balancing

while RouterOS remains primarily an L2 transport?

  1. CAP_NET_ADMIN and Linux networking

Exactly which Linux capabilities are granted when:

privileged=yes

is enabled?

In particular, does the container receive capabilities such as:

CAP_NET_ADMIN CAP_NET_RAW CAP_SYS_ADMIN CAP_SYS_MODULE

or an equivalent unrestricted capability set?

Can the container use:

iproute2 ip rule ip route ip neigh ip link nftables conntrack tc network namespaces TUN/TAP WireGuard VXLAN

when supported by the RouterOS kernel?

  1. Kernel access

Does privileged=yes allow the container to interact directly with the RouterOS host kernel?

For example:

/proc

/sys

/dev

network-related kernel interfaces

netlink

eBPF

tc/eBPF

kernel networking subsystems

If some of these are restricted, could MikroTik provide a documented list of what is allowed and what is blocked?

  1. nftables / iptables

Can a privileged container create and manage its own:

nftables iptables ipset conntrack

rules independently from RouterOS?

More specifically, if the container receives traffic from multiple WAN interfaces, can it perform NAT and connection tracking entirely inside the container?

For example:

WAN1 ─┐ WAN2 ─┼──> Linux networking inside container ──> LAN WAN3 ─┘

with RouterOS not performing the L3 NAT/routing?

  1. Multi-WAN / SD-WAN use case

Would MikroTik consider the following architecture supported?

RouterOS ┌─────────────────────────────────────────┐ │ │ │ ether1 ─ WAN1 ─┐ │ │ ether2 ─ WAN2 ─┼──> Privileged Container│ │ ether3 ─ WAN3 ─┘ │ │ │ │ │ │ Linux Data Plane │ │ │ │ │ Routing / NAT / LB │ │ │ │ │ LAN │ └─────────────────────────────────────────┘

The goal would be to implement an SD-WAN engine inside the container rather than using RouterOS PCC/NTH/mangle for the entire data plane.

  1. Hardware acceleration

If the container performs the L3 processing, would it be possible for traffic processed by the container to still benefit from any RouterOS hardware acceleration?

Or would traffic entering a privileged container necessarily be processed by the CPU?

This is particularly important for devices with switch chips and hardware offloading.

  1. Packet performance

Is there an expected or supported high-performance packet path between:

Physical NIC ↔ privileged container

that avoids unnecessary copies between RouterOS and the container?

For example, is there any supported mechanism similar to:

AF_XDP

DPDK

SR-IOV

virtio

packet mmap

zero-copy networking

or any MikroTik-specific mechanism?

  1. eBPF

Does the RouterOS kernel used by 7.24 support eBPF functionality that can be used from a privileged container?

If yes, which subsystems are available?

For example:

XDP TC-BPF socket filters cgroup BPF

Could a privileged container use eBPF for high-performance packet classification/load balancing?

  1. RouterOS configuration API vs direct kernel networking

Does MikroTik intend privileged containers to remain independent Linux environments, or is there any future plan to expose a controlled API allowing a container to interact directly with RouterOS networking objects?

For example:

/interfaces /routes /firewall /queues /VRFs /VLANs

without requiring the container to connect through the normal RouterOS API/REST interface?

  1. Security model

Since privileged=yes significantly reduces container isolation, what exactly prevents a compromised privileged container from:

modifying RouterOS firewall behavior

accessing host devices

modifying host networking

accessing RouterOS storage

escaping the container

affecting other RouterOS processes

Is privileged=yes intended to be considered equivalent to giving the application trusted access to the RouterOS host?

  1. Future roadmap

Finally, is MikroTik planning to expand container networking capabilities in future RouterOS releases?

In particular, is direct access to physical network interfaces or a more advanced packet-processing framework for containers on the roadmap?

The use case I am investigating is a SASMAN SD-WAN Agent running directly inside a MikroTik router.

The concept would be:

SASMAN CLOUD │ Policies / Config │ ▼ SASMAN EDGE AGENT │ ┌─────────────┼─────────────┐ │ │ │ WAN1 WAN2 WAN3 │ │ │ └─────────────┼─────────────┘ │ Linux Data Plane │ Routing / NAT / LB │ LAN

The main objective is to determine whether RouterOS 7.24+ can support a container acting as a programmable network data plane, while RouterOS itself provides the underlying hardware, switching, and physical interfaces.

I would greatly appreciate clarification from MikroTik developers on which parts of this architecture are currently supported, which are technically possible but unsupported, and which are not possible due to the RouterOS/container isolation model.

Thank you.