7 ms·
Mikrotik is pretty nice although the gui is not user friendly as ubiquiti.
by steve19 7y ago
Mikrotik is pretty nice although the gui is not user friendly as ubiquiti.
- disiplus 7y agonot even close that user friendly, and they had pretty serious security problems, i also use them, because they are powerful and cheap. https://nvd.nist.gov/vuln/detail/CVE-2018-14847 https://nvd.nist.gov/vuln/detail/CVE-2018-14847
- funnybeam 7y agoJust want to point out that the fact that there are CVEs does not mean they are insecure. All kit has security issues but the important thing is how open the manufacturer is about the issues and how quickly they fix them, and Mikrotik have always been very good in this area, regularly releasing updates Also, as all their devices run the same software, even devices that are years old will still be updated I often see people saying “Mikrotik is insecure” but this seems to be based solely on the fact that there are published security issues which they have patched. In my opinion that is the opposite of insecure Agree on the user friendliness though - I use them at home for personal stuff, but for work it is Unifi
- disiplus 7y agothe one linked is especially bad, i allows anybody to read the admin password. the problem is also that a lot of them are running old versions because the update process is not as straightforward as ubiquitu for example. i also run mikrotik at home and have deployed mikrotik and ubiquiti at out different offices. for the price you can hardly beat mikrotik and once you "get into it" it's fairly simple.
- funnybeam 7y agoYes, that’s bad but note that even unpatched it is only an issue if the GUI management port has been left open - which seems to be the case with all the security issues people highlight with Mikrotik I wouldn’t disagree that management ports should probably be locked down out of the box but I would expect anyone reading this to apply some basic lockdown when setting up any device I just want to offer a counterpoint to an assertion that I often see here claiming they are insecure which I don’t think is justified Certainly if you are not into networking and want something that just works then Unifi is great, but if you want something with bucketloads more functionality and don’t mind getting your hands dirty then don’t be put off Mikrotik due to security concerns
- hackmiester 7y agoYou just upload a file and reboot... that seems like a pretty simple procedure to me...?
- xeeeeeeeeeeenu 7y agoThere's also the automatic upgrade option, so you don't have to upload anything manually: https://wiki.mikrotik.com/wiki/Manual:Upgrading_RouterOS#Automatic_upgrade https://wiki.mikrotik.com/wiki/Manual:Upgrading_RouterOS#Aut...
- milankragujevic 7y agoYes, and IMO its less likely to "ruin" the device (i.e. reset all settings on a roof-mounted CPE that you are upgrading remotely) than Unifi updates for LiteBeam... Though I have only used MikroTik SXT and SXTsq and Ubiquiti LiteBeam M5 so I am not the best to judge.
- deleted 7y ago[deleted]
- mopsi 7y ago> the one linked is especially bad, i allows anybody to read the admin password. Only if you have exposed management port to the internet, which you should never do.
- stiray 7y agoThis one was for management port and was fixed before the CVE came out. There are two points: opening management interface to the internet is... Lets say... Weird. The second one, they are extremely responsive to security issues.
- tgsovlerkhgsel 7y agoDisabling (access to) WinBox should be the first thing to do on a Mikrotik. Most of their serious security issues are in WinBox. The Web UI seems to be a perfect equivalent if you want a GUI to manage your one box at home, and SSH should do the trick for automation. Is there any reason to use their proprietary (Windows-only) software to configure the router?
- garaetjjte 7y agoWebFig is just clunky and slow. Winbox is so much better, faster, with MDI, and works fine on Wine.
- jimnotgym 7y agoI have used Mikrotik at work and have been alarmed at how often professional network engineers make mistakes with them. I found some serious errors through testing (and some exploitation), and when putting them right I could see why the engineers had made that mistake. I caution against them. They don't just have a clunky gui they have a model of the network that people seem to find hard to understand. Shame on Unifi over GPL, but their kit is very good
- izacus 7y agoI'm sorry, but asking someone to switch from Ubiquiti to a Mikrotik is like asking someone to go from macOS to 1990's Linux. The user interface is beyond atrocious and even basic features you'd need in smaller/home setup need digging through Wikis to get the arcane settings you need to click. Basic things like NAT loopback or basic VPN setup. OpenVPN is still neutered and broken. What's even worse - the defaults are all wrong. There's no simple "enable firewall" switch for basic use-cases like other equipment has. Instead you need to manually configure firewall rules in chains like working with raw IP tables and if you do a small misstep, you'll drill a hole in your network easily. Or make your internet horribly slow because you need to be careful about fasstrack rules and lack of NAT acceleration. It's really about the most disappointing piece of hardware I bought in last few years and doesn't come close to niceness of Ubiquitis management. Sadly it's also the only company that makes a compact router with SFP and PoE+ to power Ubiquities.
- hackmiester 7y agoRouterOS is basically designed for network engineers. From our perspective, NAT loopback is extremely complex and has many implications, which RouterOS doesn't hide from you. And we typically don't run a VPN concentrator on the same device as a router. I think it's just a matter of different practices in different industries. ETA: > What's even worse - the defaults are all wrong. There is a new-ish thing in the web UI called "QuickSet" for these use cases.
- izacus 7y agoYes, I fully understand that it was built for company admins to have fun and cover their use-cases. But unfortunately I constantly see those admins recommend them for prosumer, unmanaged small business and home use-cases. In those cases they're horrible to manage and lack features users expect.
- stiray 7y agoWhat features? I have heard a lot of complaining over mikrotik, but lack of features was typically not one of them.
- oliwarner 7y agoTheir last source dump appears to be 4yo too.
- chewyland 7y agoDealing with this exactly at this moment. Using Winbox is like using Windows 3.0. No no... It's way worse than that.