4 ms·
It's a shame that Mikrotik doesn't have a easy to use global GUI. It's the right hardware, and great firmware and wonderful flexibility - but it needs an easy
by benjohnson 6y ago
It's a shame that Mikrotik doesn't have a easy to use global GUI.
It's the right hardware, and great firmware and wonderful flexibility - but it needs an easy to use GUI controller to make the simple stuff easy to take over from Ubiquiti.
- sam_lowry_ 6y agoGlobal UI? You mean, AWS-hosted configurator for your network? We just had example of it being security risk. God save Mikrotik from implementing something similar.
- IgorPartola 6y agoNo, a local controller that you run on a machine inside your LAN.
- coder543 6y agoThat's basically what MikroTik CAPsMAN is, depending on your needs. I think it's specific to Access Points, so not a general purpose centralized controller for MikroTik equipment, but... centralizing access point management seems to be the main thing under discussion here.
- taldo 6y agoCAPsMAN is a royal PITA to set up. You have to manually add all the wifi channels, map each AP to the channels it'll use, and a lot of busywork. Once it's set up, though, it works fine, and lets you upgrade all devices from the manager, etc.
- pilsetnieks 6y ago> You have to manually add all the wifi channels, map each AP to the channels it'll use, and a lot of busywork. No, you don't? I mean you can but you don't need to. There are cases when that is useful, true - for example, the automatic channel selection makes some curious choices sometimes.
- bshep 6y agoTheir http interface is reasonable and you can configure/provision the APs from CAPSman from one of the routers/switches in a central location.
- bombcar 6y agoYou can also script against the Mikrotik CLI - I use it to update the certificates every ~90 days.
- weaksauce 6y agonothing stopping you from using a local ubiquiti controller though. you aren't tied to their servers if you don't want to use them. that said, they seem pretty problematic from a security standpoint based on these leaks and your networking infra should be rock solid.
- bpye 6y agoThese recent posts about Ubiquiti have made me look again at MikroTik. Their hardware is more affordable than I had remembered. Is there any good intro to their hardware - there are certainly a lot more options than you get with Ubiquiti. Even before now there are some limitations with UniFi that have annoyed me. Setting up more complex DNS and firewall rules requires editing the JSON config. IPv6 tunnelling isn’t well supported. The stats in the controller, whilst neat, aren’t very useful because they have to be manually reset to zero.
- benjohnson 6y agoIt may sound strange, but for Mikrotik, I find it more productive to concentrate on setting them up via CLI. It's certainly more trainable. CLI for Port Forward: /ip firewall nat add chain=dstnat dst-port=1234 in-interface=ether1-gateway action=dst-nat protocol=tcp to-address=192.168.1.1 to-port=1234 VS having to document the same task in the GUI: IP->Firewall->Nat-> Add New General Tab Chain: dstnat Protocol: TPC Dst. Port: Port In. Interface: ether1-gateway Action Tab Action: dst-nat To Address: IP address of Server To Port: Port # of Service
- bombcar 6y agoThe CLI tab-completion is great - you can figure out most of what you need to do just by looking at it. Highly worth getting one to try out.
- eecc 6y agoYup, very nice router/switch. If anyone could forward a properly documented configuration to make the Apple AirPort guest network work I'd be ever grateful.
- locusm 6y agoSame reason I like EdgeRouters and VyOS
- robocat 6y agoThe benefit of the GUI is that it documents what has been changed: in the GUI there is a list of port forwards. With the CLI you either need to document it yourself, or you need to know to query if there are any port forwards. That can be a problem if there is more than one person responsible for the network, or if someone else needs to inherit your setup. Documentation of configuration sometimes isn’t an issue on your own home system because you generally have a high level memory of what changes you made and their purpose. Conversely I still struggle sometimes with Ubuntu because I customise my configuration using command line tools, and I find keeping track of those changes or the implications of those changes is difficult.
- heavyset_go 6y agoStick OpenWRT or pfSense on them, and you've got yourself a nice GUI. You can use the CLIs if you want to, too.
- m4rtink 6y agoWinbox is a really nice remote controller for Mikrotik & vulnerabilities of a shared global controller have just been clearly demonstrated, so I don't see an issue.
- sofixa 6y agoNot really. The vulnerabilities of using a vendor hosted cloud controller have been demonstrate, but having one yourself next to your networking decides is just as secure as it always was.