4 ms·
Tangentially related: is Mikrotik as bad for wireless as some say? I want to like them, even though their equipment seems complex, I root for a company from th
by mongol 1y ago
Tangentially related: is Mikrotik as bad for wireless as some say? I want to like them, even though their equipment seems complex, I root for a company from the Baltics that have carved out a respectable niche. But they appear to struggle with wireless?
- protocolture 1y agoMy biggest issue is threat surface. You can design around it, but Mikrotik WAP's do everything a Mikrotik router can do. If they get compromised they can run scripts, create blind proxies etc, and mikrotik has a habit of resurfacing CVEs from memory. My experience is very binary. I had some Mikrotik RF installs that Just Worked, and never needed attention. And some that were just problem children constantly demanding reboots. Mikrotik code isnt the most stable beast in the world, but if you keep it at a certain point in time you are usually safe. But then that brings you back around to the security issues again.
- simoncion 1y ago> If they get compromised they can run scripts, create blind proxies etc... How's that different from a Unifi AP? Unless they changed something in the past five, eight years, the software running on the AP is pretty much OpenWRT with the serial numbers hastily filed off. [0] Get a shell, and you get to download whatever to do whatever you need. [0] Me coming to this realization is what lead me to switch over to OpenWRT. I didn't need any of the fleet management stuff provided by UniFi, and was constantly frustrated that the APs had to totally reboot whenever you changed nearly any setting on them. (I heard that they eventually fixed that particular shortcoming. Good for them, I guess.)
- protocolture 11mo agoMikrotik will let you do a lot of this without downloading new code, but you are correct. In my experience people find a simple vuln, log in, enable the blind proxy feature, and then use your network to evade netflix region blocking until you realise. Cambiums shell from memory is much further locked down. IIRC you need a possibly predictable password form cambo to do get full root shell on a lot of devices.
- simoncion 11mo ago> IIRC you need a possibly predictable password form cambo to do get full root shell on a lot of devices. If we're ignoring access-control-violating logic errors, then Mikrotik's shells are quite locked down. As you'd expect, you can provision multiple users with a variety of privs... and even make a user that has no configuration modification privs at all. You can also very easily deny remote access to any credentials other than a username and SSH key. Good luck predicting an SSH key. But if we're not ignoring coding errors that bypass access control, then I expect that Cambium is no less vulnerable than anything else out there. They're certainly using either BSD or Linux with some proprietary goop layered on top to make it look super sexy.
- jammo 1y agoIt's particularly a problem with multiple access points, if it's just one and you need 'ok' coverage you're good.
- nubinetwork 1y agoI haven't tried their CAP or HAP lines, but I'm happy with my RB4011. /shrug
- cyberax 1y agoI've been using Mikrotik in various capacities since 2008, I even made IoT devices using RB450 boards before the word "IoT" was coined. I also love supporting a small company that is successfully competing with the giants. Their long-distance wireless and outdoor wireless are great, but their regular WiFI access points and software are at most adequate. They are not keeping up with the state of the art.
- simoncion 1y ago> They are not keeping up with the state of the art. Does that mean that the performance is middling (making them -IME- equal to UBNT's APs), that they never have APs that use the very latest and greatest WiFi version, or both?
- cyberax 1y agoBoth. They don't have access points supporting 6 GHz wireless or 2.5G Ethernet. I think they've just given up on that sector, and they're focusing on more specialized outdoors/long-distance wireless. I don't want to get into the Ubiquity ecosystem because it's typically all-or-nothing plunge. And I distrust complicated managed systems out of general principles.
- simoncion 1y agoYou've not looked at Mikrotik's hardware recently. They have several APs that have 2.5Gbit ethernet (one with a 2.5Gbit SFP+ cage), and one AP with a 10Gbit SFP+ cage. Additionally, all their APs run RouterOS, which means that you can bond links together to fairly-reliably get additional throughput. [0] In regards to Wifi 6e and Wifi 7, it looks like Mikrotik takes quite a long while after a new Wifi version to release hardware that runs it. I expect your assertion that they've given up on 6GHz for home/small-office APs is incorrect. [0] Yes, I've personal experience with using link bonding on Mikrotik hardware. As a knowledgeable someone would expect, it usually provides you with additional throughput proportional to the number of bonded links.
- 1y ago