[研究所] MikroTik RouterOS 學習 (持續更新)

wishstar2004125464 wrote:
有人回說是 Docker...(恕刪)

https://mikrotik.com/download/changelogs

What's new in 7.10 (2023-Jun-15 08:17):

!) ipv6 - fixed DNS server processing by IPv6/ND services (CVE-2023-32154);
!) route - added BFD;
*) bgp - allow to filter BGP sessions by AFI;
*) bgp - changed default VPNv4 import distance to iBGP value (200);
*) bgp - do not check route distinguisher on import;
*) bgp - fixed "as-override" and rename to "output.as-override";
*) bgp - fixed "remove-private-as" and rename to "output.remove-private.as";
*) bgp - show address family in advertisements;
*) bgp - show approximate received prefix count by the session;
*) branding - fixed custom logo (introduced in v7.8);
*) bridge - fixed HW offloaded STP state on port disable;
*) bridge - fixed HW offloading for vlan-filtered bridge on devices with multiple switches (introduced in v7.8);
*) bridge - fixed incorrect host moving between ports with enabled FastPath;
*) certificate - fixed displaying of certificate serial number;
*) certificate - improved error reporting for Let's Encrypt certificate;
*) certificate - restore available "key-usage" property options;
*) conntrack - added read-only "active-ipv4" and "active-ipv6" fields to "/ip/firewall/connection/tracking" (CLI only);
*) console - added timeout error for configuration export;
*) console - changed time format according to ISO standard;
*) console - disable output when using "as-value" parameter;
*) console - fixed ":terminal inkey" input when resizing terminal;
*) console - fixed "print without-paging" output in some cases;
*) console - hide past commands with sensitive arguments;
*) console - improved stability when using command completion;
*) container - fixed "container pull" to support OCI manifest format;
*) container - fixed crash due to missing system directories;
*) container - improved default internal environment values;
*) defconf - allow to use device factory preset credentials in Flashfig and Netinstall configuration files;
*) defconf - fixed default configuration for RBSXTLTE3-7;
*) dhcp-server - fixed accounting on RADIUS interim update;
*) dhcpv4-server - added name for "IPv6-Only Preferred" option (108) in debug logs;
*) doh - less verbose logging;
*) firewall - added "endpoint-independent-nat" support;
*) firewall - added "nth" option for IPv6 firewall;
*) gps - expose GPS port for Quectel RM520N-GL;
*) ike2 - improved child SA delete request processing;
*) iot - added option to send Modbus function code commands directly from RouterOS (CLI only);
*) ipsec - added hardware acceleration support for IPQ-5010 (hAP ax lite);
*) ipsec - refactor public key authentication;
*) ipsec - removed "ec2n185" and "ec2n155" values from proposal configurations;
*) ipv6 - fixed IPv6 address removal;
*) l3hw - added "autorestart" option to L3HW settings;
*) l3hw - added advanced configuration options for fine-tuning the L3HW offload (l3hw-settings are cleared after upgrade or downgrade) (CLI only);
*) l3hw - added error message and reset "l3-hw-offloading=no" if L3HW driver fails to start;
*) l3hw - added monitoring options for L3HW utilization (CLI only);
*) l3hw - fixed /32 route deletion;
*) l3hw - fixed IPv6 ECMP route offloading;
*) l3hw - fixed offloading of /32 IPv4 and /128 IPv6 routes;
*) l3hw - fixed route table offloading during large volume of route updates;
*) l3hw - improved host and nexthop offloading;
*) l3hw - improved offloading of IPv6 hosts after L3HW driver restart;
*) l3hw - improved performance of partial offloading;
*) l3hw - improved route offloading after gateway change;
*) l3hw - improved system stability for partial routing table offload;
*) leds - fixed modem RAT mode indication on hAP ac^3 LTE6 WPS mode button LEDs;
*) lora - improved gateway card detection and upgrade logic;
*) lora - updated firmware version for LoRaWAN gateway (for R11e-LoRa8, R11e-LoRa9 cards);
*) lte - added serving cell query for MBIM modems with necessary MBIM extension;
*) lte - disable DHCP request filtering (UDP port 67) for Chateau 5G;
*) lte - fixed APN authentication for R11e-LTE6 modem;
*) lte - fixed Google Pixel 7 tethering support;
*) lte - improved MBIM modem firmware reported error handling when settings RAT modes;
*) lte - improved modem firmware upgrade stability for MBIM modems;
*) lte - improved stability for Chateau 5G LTE modem firmware upgrade;
*) lte - reduced SIM slot switchover time for MBIM modems with UUIC reset support;
*) lte - stop "cell-monitor" on LTE interface configuration change for MBIM modems;
*) mpls - added FastPath support;
*) netwatch - added warning about non-running probe due to "startup-delay" (CLI only);
*) ovpn - added initial support for V2 data transfer protocol;
*) ovpn - improved system stability;
*) poe - fixed bogous "poe-in-voltage" values when using DC jack for RB5009;
*) pppoe - fixed PPPoE client scan when server is sending PADO messages without Service-Name tag;
*) qos-hw - added QoS marking support for 98DXxxxx switches (CLI only);
*) qos-hw - renamed VLAN "priority" field to "pcp" to avoid confusion;
*) rose-storage - added support for multiple smb users and smb shares;
*) route - improved system stability when removing multicast forwarding entries;
*) routerboard - fixed memory test on CCR2116-12G-4S+ ("/system routerboard upgrade" required);
*) routerboard - improved RouterBOOT stability for Alpine CPUs ("/system routerboard upgrade" required);
*) routerboot - increased "preboot-etherboot" maximum value to 30 seconds ("/system routerboard upgrade" required);
*) scheduler - fixed incorrectly started scheduler during reboot or shutdown;
*) sfp - fixed "rate" monitor value for SFP interface on L009UiGS series devices;
*) sfp - fixed combo-ether link monitor for CRS328-4C-20S-4S+ switch;
*) sfp - fixed combo-sfp linking at 1G rate for CRS312 switch;
*) sfp - improved 10G interface stability for 98DX8208, 98DX8212, 98DX8332, 98DX3257, 98DX4310, 98DX8525, 98DX3255, 98PX1012 based switches;
*) sfp - improved module compatibility with bad EEPROM data for RB4011, RB5009, CCR2xxx, CRS312 and CRS518 devices;
*) sfp - improved Q/SFP interface stability for 98DX8208, 98DX8212, 98DX8332, 98DX3257, 98DX4310, 98DX8525, 98DX3255, 98PX1012 switches;
*) sfp - improved SFP interface handling for RB4011, RB5009, CCR2xxx and CRS518 devices;
*) sfp - improved system stability with certain SFP modules for CCR2216 and CRS518 devices;
*) sfp - report EEPROM data even if "auto-init-failed" has occurred;
*) smb - improved SMB v1 operation;
*) sniffer - fixed large .pcap file limit;
*) snmp - added "engine-id-suffix" setting and display actual "engine-id" as read-only property;
*) snmp - added BGP peer table support IPv4 only (1.3.6.1.2.1.15.3.1);
*) snmp - added new "mtxrInterfaceStatsTxRx1024ToMax" OID to MIKROTIK-MIB;
*) ssh - added inline key "passphrase" property;
*) ssh - fixed RouterOS SSH client login when using a key (introduced in v7.9);
*) switch - added more precise "storm-rate" configuration options for 98DXxxxx switches (CLI only);
*) switch - fixed storm rate on 10G links for 98DX8208, 98DX8216, 98DX8212, 98DX8332, 98DX3257, 98DX4310, 98DX8525, 98DX3255 switches;
*) system - improved watchdog reporting in log after reboots for several ARM and ARM64 devices;
*) system - reduced RAM usage for SMIPS devices;
*) tile - fixed support for microSD card;
*) tr069 - added 5G SCC "SNR" parameter for modems that report it;
*) upgrade - do not run manual upgrade if some packages are missing;
*) ups - fixed updating of "battery-voltage" property;
*) vrrp - added warning if "sync-connection-tracking=yes" while the global connection tracking is inactive;
*) vrrp - added warning if the VRRP group is misconfigured;
*) vrrp - added warning if VRRP or its interface does not have an IP address;
*) vrrp - do not start connection synchronization if the global connection tracking is inactive;
*) vrrp - fixed issue where disabled VRRP interface is affecting group;
*) vrrp - fixed VRRP interface state on physical cable disconnection;
*) vrrp - improved system stability on changing "group-authority" or "sync-connection-tracking";
*) vrrp - renamed "group-master" to "group-authority" to avoid confusion with VRRP master;
*) vrrp - send VRRP announcements only by "group-authority";
*) w60g - improved interface stability for PTMP setups;
*) webfig - added high-resolution favicon;
*) webfig - allow limitless upper bounds for number range;
*) webfig - allow to set "0" second time for fields with default values;
*) webfig - changed time format according to ISO standard;
*) webfig - display date and time in local time zone;
*) webfig - fixed missing "WifiWave2" menu;
*) webfig - fixed missing property names in "WifiWave2" menu;
*) webfig - redesigned item configuration display;
*) webfig - redesigned top menu bar;
*) webfig - removed "Tools/Telnet" menu;
*) webfig - removed auto-login with default credentials (admin without a password);
*) wifiwave2 - avoid transmitting extra bytes at the end of the packet after stripping a VLAN tag;
*) wifiwave2 - do not show placeholder transmit power values on interface startup;
*) wifiwave2 - fixed CAP connection when provisioning "manager=capsman";
*) wifiwave2 - fixed CAP interface name when using "name-format";
*) wifiwave2 - fixed connectivity issues wheen access-list is used;
*) wifiwave2 - fixed DFS channel availability warning (introduced in v7.9);
*) wifiwave2 - fixed dynamic interface adding to bridge on CAP device;
*) wifiwave2 - fixed inability to disable CAPsMAN when there are RADIUS-authenticated clients connected;
*) wifiwave2 - fixed incorrect limits on number of interfaces in station mode;
*) wifiwave2 - fixed interface name change when restoring backup;
*) wifiwave2 - fixed key handshake timeout with re-associating clients;
*) wifiwave2 - fixed OWE authentication compatibility with 802.11ax client devices;
*) wifiwave2 - fixed OWE authentication compatibility with third-party client devices (introduced in v7.8);
*) wifiwave2 - fixed wireless throughput issues after 802.11r client roaming events on 802.11ac devices;
*) wifiwave2 - improve protections against DoS attacks on WPA3-PSK;
*) wifiwave2 - improved logging when an interface is unable to assign a VLAN tag to client;
*) wifiwave2 - improved system stability when trying to exceed virtual AP limit;
*) wifiwave2 - less verbose logging when WPA3-PSK clients are connecting;
*) wifiwave2 - other system stability improvements;
*) wifiwave2 - restore interface running state when connection to CAPsMAN is lost;
*) winbox - added "MPLS/Settings" menu;
*) winbox - added "Queues" configuration tab when creating new entries under "IPv6/DHCP-Server" menu;
*) winbox - rename "URL" property to "Action data" under "IP/Web-Proxy/Access" menu;
*) wireguard - fixed IPv6 traffic processing with multiple peers;
*) wireguard - retry "endpoint-address" DNS query on failed resolve;
*) x86 - ice driver update to v1.11.14;
*) zerotier - make "identity" setting sensitive;
wishstar2004125464 wrote:
https://mikrotik...(恕刪)


剛昇上去,很好的是AdguardHome可以直接昇級到最新版本了,原本很高興,結果.....
突然想到好久沒試試Open VPN連線了,結果就上不去了.
看起來有東西擋著我連線,"terminating... - peer disconnected"不知什麼把我踢來,那位大大可以幫忙呢?
還有看到我的ID loged out, 0 0 0 0 0 from ip x.x.x.x,這是個問題嗎?
有試著將Firewall擋的rule全都關掉,Adguard也關掉,用家裡Wifi內部連線,結果都一樣.
原先在7.9.2是正常的,就今天昇到7.10後才開始的.
RickyHsu77 wrote:
剛昇上去,很好的是AdguardHome...(恕刪)


最後找到相關文件,是昇級到7.10的關係,唯一Solution降級到7.9.2就正常了.
這是Push我改用WireGuard VPN嗎?
ouchwe
改用WireGuard吧!比OpenVPN好用太多,不管是安全還是速度
peaceman
基於wireguard的 tailscale / headscale(這個開源),不曉得這3個比較起來哪個較優呢?
今天買了一台RB5009 routeros 版本 7.10
要設定 L2TP over IPsec Client 時無法連線
不斷出現


使用中華電信的小烏龜的DHCP可以正常連接 用PPPoE撥號就會失敗
istel1247j
目前正常上網都沒問題 wireguard VPN也正常 防火牆以開通 只有L2TP的VPN無法連線 改用數據機撥號其它設定維持又完全正常 請問有方向可以提點嗎?
chenghuanplus
防火牆有allow 4500udp input?
請問一下 如果要封鎖chrome 遠端桌面
要如何封鎖
gfx
https://ithelp.ithome.com.tw/articles/10191524
人品是做人最好的底牌.
NeverGiveUp!! wrote:
(恕刪)


這個版本一出來就更新了。
OPVN沒問題,Adguard Home也可以直接昇級到最後版本,不用指定特定版本了。
NeverGiveUp!!
[拇指向上]
來這裡請問各位
自家目前使用的是RB750Gr3,ROS版本是7.10.1。
最近入手了一台RB5009UG+S+IN來取代750Gr3,ROS版本已從7.8更新至7.10.1。

這兩台CPU跟記憶體的規格都不同,我可以使用export compact的方式
從750Gr3匯出後,直接匯入RB5009嗎?
tasict
我跟您的狀況一樣從RB750Gr3到RB5009UPR,我後來是使用匯出成文字檔,然後自己去看哪些步驟需要哪些不需要,這樣應該會比較不會有漏
aiolos
感謝tasict的留言提醒了我,也採用了一步步用指令輸入的方式
有個問題困擾很久了,不知道有沒有解決方式

客戶端內部IP區段:192.168.1.X

VPN 到 Routeros 伺服器端

但伺服器端的內部IP區段也是:192.168.1.x


那如果「客戶端」要連 「伺服器端」的下的某一台電腦會無法連接
這個有什麼好的解決方式嗎?


因為客戶端直連的設備是中華電信,前端沒有分享器,所以直接就是 192.168.1.x 區段了
伺服器端是從一開始就是 192.168.1.X 了,也不好再去更改


我後來有想一個方式,就是伺服器端多一個 192.168.2.x 的區段
然後要被連線的電腦設定 192.168.2.123
這樣那台電腦一樣可以連本地的 192.168.1.X 的其他設備
但會變無法用「名稱」連接,只能用「IP連接」

另外客戶端這台好像必須勾選「使用遠端網路的序設閘道」才連的到 192.168.2.123
所以不勾選好像就連不到?


------------------------

想請問伺服器端跟客戶端如果剛好都是 192.168.1.X 的區段,要怎麼讓客戶端能連到伺服器端下面的電腦呢?
gfx
https://www.youtube.com/watch?v=-hdLsXd9OgE&list=FL0oqRrw3ONnUOOwf2fW4WLg&index=1
top100011
剛看一下這VRF影片好像跟我說的內容不太一樣,客戶端目前是單一電腦,透過VPN撥接到 ROS路由,但兩端都是IP區段都一樣,所以遠端電腦連接的IP是以本地為主
top100011 wrote:
有個問題困擾很久了,...(恕刪)
假設vpn在本地名稱為l2tp-in1,本地區網名稱為bridge1:
/routing table
add fib=yes name=to_l2tp-in1

/ip routing
add distance=1 dst-address=0.0.0.0/0 gateway=l2tp-in1 routing-table=to_l2tp-in1

/ip firewall mangle
add action=mark-connection chain=prerouting in-interface=l2tp-in1 connection-state=new new-connection-mark=l2tp-in1_conn passthrough=yes
add action=mark-routing chain=prerouting in-interface=bridge1 connection-mark=l2tp-in1_conn new-routing-mark=to_l2tp-in1 passthrough=no

/ip firewall nat
add action=masquerade chain=srcnat out-interface=bridge1 connection-mark=l2tp-in1_conn
gfx
其實同為vrf影片裡的標記方式,只不過大方向從public輸出轉為private而已
top100011
謝謝GFX大回覆,我再試看看~~5分先奉上
文章分享
評分
評分
複製連結
請輸入您要前往的頁數(1 ~ 861)

今日熱門文章 網友點擊推薦!