18 ms·
MikroTik RouterOS v7 stable released
- NelsonMinar 5y agoThe release notes say "completely new NTP client and server implementation". Anyone know what they went with?
- aequitas 5y agosystemd-timesyncd? ;)
- NelsonMinar 5y agoI think you're kidding? That's not an NTP server. It's not a very good NTP client, either. I'm hoping they switched to chrony but I don't know.
- vorpalhex 5y agoExciting! This should include native wireguard support..
- techietim 5y agoI have been using the Wireguard support in the beta release for most of this past year. Having a persistent connection from my Android phone and my wife's iPhone was simple with the built-in Mikrotik DDNS service. It makes checking on things like security cameras nice if you do not want to use a cloud service.
- dcow 5y agoYep! I’ve been using the beta and it’s awesome. What other vendors include native WG support? Historically the concept of a performant VPN router pushed you into the realm of enterprise level expensive hardware. Now you can do it on cheap arm cores. It’s game changing.
- oriettaxx 5y agoYes, exactly!! Wireguard is a must for us now! I've been using professionally on MikroTik, too, almost everything worked as expected! (only some issue with being able to export settings... I hope it's solved now)
- Hamuko 5y agoI used to want Wireguard on my router. It was in fact one of the reasons why I went with an EdgeRouter X. Then one day, when I was away from home and actually needed the VPN, it absolutely melted. Basically everything on the router stopped working, and I suspect it was Wireguard since the router went haywire when I was actually using it extensively. Needed a hard power cycle, which I couldn't actually do. These days I just leave my router to do its basic duties and have a Raspberry Pi dedicated to nothing but Wireguard. Haven't had issues since. The Pi 2 Model B also performs better for Wireguard and I imagine that the Pi 4 could saturate my 100 Mb/s upload.
- liuliu 5y agoI sort of only want WG support in EdgeRouter as WG client such that my homes in different geographical locations can share the same network transparently. Is that still a good use?
- Hamuko 5y agoSince there's no actual WG support in EdgeRouters and the experiences I've had with the community-maintained version, I'd personally not go that route. You can probably get better bang for your buck by configuring a couple of Raspberry Pis. Granted, it's been a hot minute since I've last tried WG on EdgeRouters.
- blibble 5y agohopefully it's better than their IPSec support I love my mikrotik devices, but they can be a bit iffy around the edges (e.g. if my pppoe connection reconnects the ipsec stops working until the interface is bounced)
- vladgur 5y agoSo what is a good mesh wifi system that would allow me to put all my IoT things on a separate VLAN? Dream Machine is not a mesh system…the only alternative that I could find by googling was Orbi Pro
- izacus 5y agoWhat do you mean by "dream machine is not a mesh system"? UniFi APs can use wireless backhaul and mesh as well. What exactly do you need?
- l3gion 5y agoWhat do you expect to add support to connect the mikrotik to a shadowsock server (socks5)?
- beebeepka 5y agoI've been thinking about going with Mikrotik at least twice but never pulled the trigger because I am sort of a chicken shit. Is it easy for a noob to setup things like port forwarding and vlans on a router/ap box?
- grenoire 5y agoYeah, got hAP ac^2 and it's literally plug and play. Port forwarding etc. are all really easy.
- minimaul 5y agoTheir firewall is essentially iptables. If you can work iptables, you can work the routeros firewall.
- thequux 5y agoMost of their devices come out of the box in a sensible configuration for a home router, and port forwarding/vlans are very straightforward to set up. If you're really worried, you can run the cloud-hosted router software in a VM to play around with it and find out if it will meet your needs.
- 28304283409234 5y agoI would suggest looking at their wiki and screenshots or youtube of their UI. I've managed cisco amd juniper routers. And I can't make heads nor tails of it. As soon as you wonder off the default track, you're expected to understand deep level networking terminology abstracted in a UI tailored for experts.
- dcow 5y agoTo setup port forwarding you have to understand how to configure the firewall, yes. This is both a drawback for simple use cases but a boon for more advanced ones. It cuts both ways. Personally I think it’s rather unfair to call the UI unintelligible. If you don't like it just ssh to it and configure it that way. Everything you can do is packaged up in a nice command structure.
- 5y ago
- ericcholis 5y agoDoes MikroTik live in the same prosumer space that made ubiquiti products so popular early on?
- detaro 5y agoOn the nerdier side of that. More exotic features, lot less nice UI, lots of (cheap) lower-performance options and sometimes obscure product variations. I.e. among people where I know what kind of stuff they have, anybody vaguely technical might have an Ubiquiti AP for their WiFi, whereas the people that love to tinker with networking stuff have some mikrotik device somewhere to play with.
- dcow 5y agoI landed on MikroTik for a recent build because you simply can’t get Ubiquity right now. And I’m glad I did, what a great product. Checkout their newest RB5000 and CCR2000 series. Very powerful arm cores with sfp+ options at an incredibly reasonable price.
- brightball 5y agoThis is also my experience. Best technical person I know recommended it.
- gnfargbl 5y agoYes, but possibly with more ambition to be a budget alternative to Cisco and Juniper. Looking at the presentations under https://mum.mikrotik.com/ https://mum.mikrotik.com/, it seems there are quite a few ISPs running on MikroTik kit, especially in less-developed parts of the world.
- iso1210 5y agoA big complaint about routeros6 is the time it takes for a full BGP table to converge - especially on the top-of-range cloud core routers. I don't deal much with IXPs, but I did hear somewhere that there were a shockingly high number of mikrotik peers at one exchange point (10%+)
- InTheArena 5y agoI would really like to see a open source alternative that can interface with all sorts of different hardware to manage my infrastructure with a single pane of glass. Sorta Ubiquti - but leveraging things like the Unifi API & the new REST api on Microtek to get me out of vendor lock in. I don't think I have ever seen anything along those lines out there. Im actually happy with my unifi setup - but there are some things (like multiple load balanced WAN ports) that should be easy to do, but instead are impossible.
- jedahan 5y agoOpenWISP looks to be the furthest along, though right now I think it only supports OpenWRT https://openwisp.io/docs/index.html https://openwisp.io/docs/index.html
- cedricgle 5y agoThere is some OS tooling in the SDN realm, like Stratum[1] for example, or a P4 board for the serious. But the hardware behind it isn't cheap. I wish router for personal use were as "easily" programmable as an OpenFlow compatible equipment with a external controller. Even if you need some extra tooling to reach all the feature of RouterOS, like a compute node for the DNS. I don't know if this kind of evolution will ever reach the consumer space. [1] https://opennetworking.org/stratum/ https://opennetworking.org/stratum/
- ctoth 5y agoI know that the Asuswrt integration with Home-assistant lets me manage devices which is kind of cool, but I too would love a little deeper access via a 3rd party app. Most of these things use web scraping or ssh to the device though, not an actual API as very few routers give access to one.
- ahepp 5y agoI've always wondered if one could use SNMP for this.
- trulyme 5y agoDoubtful. Some basic stuff is supported across almost all devices (interface names, speeds, status,...), but more detailed info varies widely between vendors, their OS versions and devices. SNMP SET support is mostly a joke and not worth the trouble. Better use whatever API each vendor came up with.
- halz 5y agoTread softly, there are some reports¹ that things like PIM/RIP are not working/not implemented. ¹https://forum.mikrotik.com/viewtopic.php?t=180896 https://forum.mikrotik.com/viewtopic.php?t=180896
- iso1210 5y agoMassively disappointing, if that's the general direction I'll need to redouble efforts to move to fortigate.
- deleted 5y ago[deleted]
- ok_dad 5y agoSo, what's the best wifi gateway with extra access points for a home that I don't have to screw with and doesn't spy on me or have cloud crap? My ISP sent a Google wifi thing but I'd rather pay a few hundred than use that for 10 bucks a month to rent that thing, and I don't trust Google. Edit: Thanks for all the answers, from me and anyone else who was looking! I have some good ideas from the below comments and hopefully this thread helps some others as well.
- comeonseriously 5y agoI use an Edgerouter-x with an eap225 AP located centrally. I have not noticed any spying.
- lephty 5y ago+1 for the TP-Link EAP225 and its brethren (they have a cloud management portal, but with just a handful of units they can be managed individually or via self-hosted management server). I use mine with a Mikrotik RB4011. A very stable and reliable combination.
- bigyellow 5y agoPC Engines with OpenBSD or Debian Linux. 100% open source hardware, firmware and software, not this closed-source "RouterOS" which is probably bugged.
- yjftsjthsd-h 5y agoYes, this is easily superior to most options; Debian/OpenBSD/whatever is far more trustworthy than any commercial offering (and many noncommercial options), and hostapd isn't especially hard to set up - a bit of effort up front and then you can just sit on it for years with no more maintenance than installing updates (and even that can be automated with unattended upgrades in Debian). The result is a capable little box that will get security updates indefinitely and which only serves your interests.
- 5y ago
- iso1210 5y agoLots of changes in v7 around routing, but this seems like a reasonable time to start work on it. Still seems to be missing certain features - like showing what routes you're advertising to a BGP peer, so certainly not ready for use. Of course the way that routeros is developed, it relies on users to do the testing and debugging.
- bigyellow 5y agoSincere question: why would someone trust a closed source OS for their router?
- Arnt 5y agoI tracerouted to a host across the world now and poked at the routers along the path. All of the routers whose vendor or OS I can identify use closed source. So whatever the answers to "why?" may be, it's a common thing to trust.
- wmf 5y agoBecause open source hasn't caught up.
- candiddevmike 5y agoI wish I could install Debian on my mikrotik devices, I don't need a CLI or GUI--give me networkd or ifupdown instead.
- ytch 5y agoCorrect me if I am wrong but if you want a multiple NIC bare metal device, you may consider industrial pc. Many of them have ITX size PC or motherboard with Atom CPU and over 8 of 1G NIC plus 2 10G SFP+
- Arnt 5y agoOh neat. I wish to declare that I'm a Mikrotik fanboy. My hardware is ten years old, doesn't break, and Mikrotik supports it on the latest versions, apparently without plans to ever sunset the support. Ooh aah.
- nullwarp 5y agoYeah huge fan of MikroTik stuff, all of it has been running flawlessly for me for so long. Works great, the interfaces are a little basic, but they are extremely fast and absolutely work flawlessly.
- stingraycharles 5y agoBig supporter of Mikrotik here, it’s a perfect middle ground between consumer “crap”, and $10,000 enterprise network equipment. Rolled out a 10gbit / 25gbit network at home. My biggest complaints are: * Wireless is really difficult to get “decent speeds”. I also have my ISP’s router and a Draytek at home, these easily do 500mbit, and it’s nearly impossible to get my router board to do the same. When asking support there’s mainly a lot of hand-waving “you’ll never get better than 100mbit anywhere anyway”, etc. Even if other router vendors use hacks / cheats to achieve what they do, I would want an explanation what exactly it is they’re doing, and why Mikrotik can’t do that. * I know their Linux Kernel supports certain features, I would really like an “escape hatch” so I can just run traffic shaping commands manually. Eg if I want to use RED with ECN, the lack of a UI checkbox shouldn’t be the limiting factor; * Upgrades while being in their development branch has been a big pain, many times losing crucial configurations; I guess this is fair game when I’m on the beta channel. * Hardware is a bit underpowered for my needs, but I guess that’s why enterprise equipment is 10x - 50x as expensive. Doing traffic shaping on anything more than 1gbit is pretty much impossible; probably the best solution is to use some dedicated hardware with a whole bunch of network cards inside.
- iso1210 5y agoYou can always run routeros on X86 hardware. I think the problem with things like mangle rules run into. Had loss and a hell of a lot of reorders at just 500mbit through a CCR1036 the other week, disabled 100 or so mangle rules and it vanished, but from looking at other routers I think it's more of a limit in the linux kernel (perhaps just the 2.6 one). Maybe routeros7.1 will be better, something to test in the coming weeks. 10/25 feels like a CCR2004? Or are you just talking switching. If routing remember it isn't full bandwidth - the 170gbit of ports is squished into 2x25 before hitting the CPU[0]. Not sure how much is offloaded to the PIPE. [0] https://i.mt.lv/cdn/product_files/CCR2004-1G-12Splus2XS_200459.png https://i.mt.lv/cdn/product_files/CCR2004-1G-12Splus2XS_2004...
- mmastrac 5y agoDoes anyone know what the scripting support looks like in v7? Scripts have always been a bit awkward on RouterOS (I spend ages perfecting one that turned DHCP reservations into dynamic DNS entries). I'm hoping they have worked on this a bit.
- Railander 5y agoFrom what I understood the part they are changing regarding scripting is in the `routing filters` feature. Your script is probably going to break due to the new syntaxes in v7, but no significant added new features on that matter that I'm aware.
- second--shift 5y agoYes! been waiting for this for years. Big Mikrotik fan, recommend them for nearly all applications.
- lormayna 5y agoI am a huge fan of Mikrotik. In the past, I have been worked for an ISP, and we made fantastic stuff with them. A CCR box that costs less than 1000€ can handle the same number of users, with advanced QoS queueing than an equivalent Cisco that costs 20x. Having (almost) the same features to ever model, from the big boxes to the core routers, it's a big plus, they are very flexible, and they have almost all the features that a carrier-class router needs (the big lack at that time were OSPF-v3 and multi-core BGP). Once you learn the CLI and some quirky configuration, it's worth the money. The only problem is the availability: they are not stable as a Cisco/Juniper, but you can add several layers of redundancy with a fraction of the costs. Also the support is very basic.
- nullify88 5y agoReally happy with the CRS-305 and its value for money. Release candidates for 7.1 had container support which opens worlds of possibilities for the switch. But unfortunately was removed for the final version pending updates. Edit: Container support was introduced in rc3 and removed in rc5.
- noja 5y agoWireshark support is here!
- pilsetnieks 5y agoI think you meant Wireguard; you could make a packet capture for Wireshark a long long time ago already.
- noja 5y agoI did :)
- locusm 5y agoIve replaced Ubiquiti Unifi routers with Mikrotik RB5009's and its resultant bang for buck is impressive. The Ubiquiti Edge series is capable too but hasnt had feature updates in months. Ubiquiti product direction currently feels like a massive cluster f*k and isnt improving. Some nice features you may not realise exist on RouterOS 7 are built-in support for Wireguard VPN and ZeroTier client support. https://mikrotik.com/product/rb5009ug_s_in https://mikrotik.com/product/rb5009ug_s_in