Difference between revisions of "MikroTik-Fail"

From W9CR
Jump to navigation Jump to search
(MikroTik)
 
 
(7 intermediate revisions by 2 users not shown)
Line 1: Line 1:
 +
[[Category:MikroTik]]
 +
 
This is a list of basic failures that I've found MikroTik Routers to have.  This is by no means exhaustive.
 
This is a list of basic failures that I've found MikroTik Routers to have.  This is by no means exhaustive.
 +
 +
= IS-IS Support =
 +
 +
<s>Mikrotik doesn't support and will not support ISIS.  </s>
 +
 +
The stated [https://forum.mikrotik.com/viewtopic.php?t=30587#p149066 reason] is it's not a "coooool protocol" like OSPF.
 +
 +
EDIT- Maybe now it's "coooool". IS-IS is being introduced into RouterOS starting in
 +
v7.13. As of v7.14beta8 there is now IS-IS support being EVE-NG tested.
 +
* [https://discord.com/channels/936294190948687922/1108700927365500978/1199781869470883861 https://discord.com/channels/936294190948687922/1108700927365500978/1199781869470883861]
 +
* [https://mikrotik.com/download/changelogs#show-tab-tree_2-id-fbb68df8e99f8b3afd4862846ad531f7 https://mikrotik.com/download/changelogs#show-tab-tree_2-id-fbb68df8e99f8b3afd4862846ad531f7]
 +
==Documentation==
 +
[https://manual.mikrotik.com/docs/user-guides/routing-and-networking-protocols/unicast/is-is https://manual.mikrotik.com/docs/user-guides/routing-and-networking-protocols/unicast/is-is]
 +
==Example==
 +
Basic Configuration Example
 +
Basic configuration requires creating an instance (under /routing/isis/instance) with the area ID and system ID set, and enabling IS-IS on an interface via /routing/isis/interface-template.
 +
 +
For example, an IS-IS setup between three routers, one Cisco and two RouterOS.
 +
 +
R1:
 +
/routing/isis/instance
 +
add afi=ip areas=49.2222 disabled=no name=isis-instance-1 system-id=90ab.cdef.0001
 +
/routing/isis/interface-template
 +
add instance=isis-instance-1 interfaces=ether1 levels=l1,l2
 +
/routing/isis/neighbor> print
 +
0 instance=isis-instance-1 interface=ether1 level-type=l2 snpa=08:00:27:22:B4:A2 srcid="1111.2222.aded" state=up
 +
1 instance=isis-instance-1 interface=ether1 level-type=l2 snpa=D4:CA:6D:78:2F:2E srcid="1111.2222.cded" state=up
 +
2 instance=isis-instance-1 interface=ether1 level-type=l1 snpa=08:00:27:22:B4:A2 srcid="1111.2222.aded" state=up
 +
3 instance=isis-instance-1 interface=ether1 level-type=l1 snpa=D4:CA:6D:78:2F:2E srcid="1111.2222.cded" state=up
 +
/routing/route> print where is-is
 +
Flags: A - ACTIVE; i - IS-IS
 +
Columns: DST-ADDRESS, GATEWAY, AFI, DISTANCE, SCOPE, TARGET-SCOPE, IMMEDIATE-GW
 +
DST-ADDRESS        GATEWAY                AFI  DISTANCE  SCOPE  TARGET-SCOPE  IMMEDIATE-GW       
 +
i 0.0.0.0/0          10.155.101.214%ether1  ip4      115    20            10  10.155.101.214%ether1
 +
i 10.155.101.0/24    10.155.101.216%ether1  ip4      115    20            10  10.155.101.216%ether1
 +
Ai 10.255.255.162/32  10.155.101.216%ether1  ip4      115    20            10  10.155.101.216%ether1
 +
 +
R2:
 +
 +
/routing/isis/instance
 +
add afi=ip areas=49.2222 disabled=no l1.originate-default=always l2.originate-default=always name=isis-instance-1 system-id=1111.2222.cded
 +
/routing/isis/interface-template
 +
add instance=isis-instance-1 interfaces=sfp12 levels=l1,l2
 +
add instance=isis-instance-1 interfaces=lo levels=l2
 +
/routing/isis/neighbor> print
 +
0 instance=isis-instance-1 interface=sfp12 level-type=l1 snpa=08:00:27:22:B4:A2 srcid="1111.2222.aded" state=up
 +
1 instance=isis-instance-1 interface=sfp12 level-type=l1 snpa=C4:AD:34:43:EA:5C srcid="90ab.cdef.0001" state=up
 +
2 instance=isis-instance-1 interface=sfp12 level-type=l2 snpa=08:00:27:22:B4:A2 srcid="1111.2222.aded" state=up
 +
3 instance=isis-instance-1 interface=sfp12 level-type=l2 snpa=C4:AD:34:43:EA:5C srcid="90ab.cdef.0001" state=up
 +
 +
R3 Cisco:
 +
interface Loopback0
 +
ip address 10.255.255.162 255.255.255.255
 +
ip router isis
 +
!
 +
interface GigabitEthernet1
 +
ip address dhcp
 +
ip router isis
 +
negotiation auto
 +
!
 +
router isis
 +
net 49.2222.1111.2222.aded.00
 +
!
 +
# show isis neighbors
 +
Tag null:
 +
System Id      Type Interface  IP Address      State Holdtime Circuit Id
 +
90AB.CDEF.0001 L1  Gi1        10.155.101.183  UP    27      1111.2222.CDED.01 
 +
90AB.CDEF.0001 L2  Gi1        10.155.101.183  UP    27      1111.2222.CDED.01 
 +
1111.2222.CDED L1  Gi1        10.155.101.214  UP    9        1111.2222.CDED.01 
 +
1111.2222.CDED L2  Gi1        10.155.101.214  UP    9        1111.2222.CDED.01
 +
# show ip route
 +
i*L1  0.0.0.0/0 [115/11] via 10.155.101.214, 4w5d, GigabitEthernet1
 +
      10.0.0.0/8 is variably subnetted, 5 subnets, 2 masks
 +
C        10.155.101.0/24 is directly connected, GigabitEthernet1
 +
L        10.155.101.216/32 is directly connected, GigabitEthernet1
 +
i L2    10.155.255.214/32 [115/10] via 10.155.101.183, 2w3d, GigabitEthernet1
 +
 +
= No ability to show bridge table =
 +
In a bridge wireless network where CPE are bridging the LAN port to Wireless, then to the AP, and out the AP Ethernet port, one cannot find the MAC address of the CPE radio and what MAC's it's bridging to the AP.  There has to be a table of this internally in the AP, but it is not exposed.  This makes locating a misbehaving MAC address complex as you have to look at each CPE device's MAC table. 
 +
 +
Alvarion/Cisco/Symbol/Karlnet/Canopy has had this since like 1995.
 +
 +
= VRF table ignored for local responses =
 +
 +
In a VRF, where you have a traceroute going through it, MT will source it's ICMP TTL packets using an IP from the main routing table.  This means anyone tracrouting to the VRF will be able to see IP it's going over, or if it's a private IP that the main table has, it will likely just show "* * *" as the IP will be unreachable.   
 +
 +
This is a [https://forum.mikrotik.com/viewtopic.php?t=78816&start=100 known issue].
 +
 +
https://old.reddit.com/r/mikrotik/comments/5ixk1u/intermediate_hop_dont_show_in_traceroutes_when/
 +
 +
= RFC3021 /31 links =
 +
 +
<s>Mikrotik doesn't support this.  This is an over 20 year old RFC.  Come on.
 +
 +
https://forum.mikrotik.com/viewtopic.php?p=163163 </s>
 +
 +
RFC3021 /31 addresses for PtP links has been supported in RouterOS since v7.18
 +
 +
https://help.mikrotik.com/docs/spaces/ROS/pages/28606515/Routing+Protocol+Overview
 +
 +
= /export changes at random across different firmware =
 +
 +
/export is not idempotent between OS upgrades on the same hardware. 
 +
 +
This means config backups are basically worthless unless you can input them manually and see what breaks.  There's no revision testing on it either by MT.
 +
 +
= 4 byte ASN =
 +
 +
<s>Per [https://mailman.nanog.org/pipermail/nanog/2022-August/220138.html this message] on NANOG, they can't do 4 byte ASN's</s>
 +
 +
BGP AS4 (4-byte / 32-bit ASN) capability negotiation is defined in RFC 6793 is supported in modern Mikrotik RouterOS versions.
 +
[https://manual.mikrotik.com/docs/user-guides/routing-and-networking-protocols/unicast/bgp/understanding-bgp#supported-standards https://manual.mikrotik.com/docs/user-guides/routing-and-networking-protocols/unicast/bgp/understanding-bgp#supported-standards]

Latest revision as of 21:37, 27 September 2026


This is a list of basic failures that I've found MikroTik Routers to have. This is by no means exhaustive.

IS-IS Support

Mikrotik doesn't support and will not support ISIS.

The stated reason is it's not a "coooool protocol" like OSPF.

EDIT- Maybe now it's "coooool". IS-IS is being introduced into RouterOS starting in v7.13. As of v7.14beta8 there is now IS-IS support being EVE-NG tested.

Documentation

https://manual.mikrotik.com/docs/user-guides/routing-and-networking-protocols/unicast/is-is

Example

Basic Configuration Example Basic configuration requires creating an instance (under /routing/isis/instance) with the area ID and system ID set, and enabling IS-IS on an interface via /routing/isis/interface-template.

For example, an IS-IS setup between three routers, one Cisco and two RouterOS.

R1:

/routing/isis/instance
add afi=ip areas=49.2222 disabled=no name=isis-instance-1 system-id=90ab.cdef.0001
/routing/isis/interface-template
add instance=isis-instance-1 interfaces=ether1 levels=l1,l2
/routing/isis/neighbor> print 
0 instance=isis-instance-1 interface=ether1 level-type=l2 snpa=08:00:27:22:B4:A2 srcid="1111.2222.aded" state=up 
1 instance=isis-instance-1 interface=ether1 level-type=l2 snpa=D4:CA:6D:78:2F:2E srcid="1111.2222.cded" state=up 
2 instance=isis-instance-1 interface=ether1 level-type=l1 snpa=08:00:27:22:B4:A2 srcid="1111.2222.aded" state=up 
3 instance=isis-instance-1 interface=ether1 level-type=l1 snpa=D4:CA:6D:78:2F:2E srcid="1111.2222.cded" state=up 
/routing/route> print where is-is
Flags: A - ACTIVE; i - IS-IS
Columns: DST-ADDRESS, GATEWAY, AFI, DISTANCE, SCOPE, TARGET-SCOPE, IMMEDIATE-GW
DST-ADDRESS        GATEWAY                AFI  DISTANCE  SCOPE  TARGET-SCOPE  IMMEDIATE-GW         
i 0.0.0.0/0          10.155.101.214%ether1  ip4       115     20            10  10.155.101.214%ether1
i 10.155.101.0/24    10.155.101.216%ether1  ip4       115     20            10  10.155.101.216%ether1
Ai 10.255.255.162/32  10.155.101.216%ether1  ip4       115     20            10  10.155.101.216%ether1

R2:

/routing/isis/instance
add afi=ip areas=49.2222 disabled=no l1.originate-default=always l2.originate-default=always name=isis-instance-1 system-id=1111.2222.cded
/routing/isis/interface-template
add instance=isis-instance-1 interfaces=sfp12 levels=l1,l2
add instance=isis-instance-1 interfaces=lo levels=l2
/routing/isis/neighbor> print 
0 instance=isis-instance-1 interface=sfp12 level-type=l1 snpa=08:00:27:22:B4:A2 srcid="1111.2222.aded" state=up 
1 instance=isis-instance-1 interface=sfp12 level-type=l1 snpa=C4:AD:34:43:EA:5C srcid="90ab.cdef.0001" state=up 
2 instance=isis-instance-1 interface=sfp12 level-type=l2 snpa=08:00:27:22:B4:A2 srcid="1111.2222.aded" state=up 
3 instance=isis-instance-1 interface=sfp12 level-type=l2 snpa=C4:AD:34:43:EA:5C srcid="90ab.cdef.0001" state=up 

R3 Cisco:

interface Loopback0
ip address 10.255.255.162 255.255.255.255
ip router isis 
!
interface GigabitEthernet1
ip address dhcp
ip router isis 
negotiation auto
!
router isis
net 49.2222.1111.2222.aded.00
!
# show isis neighbors 
Tag null:
System Id      Type Interface   IP Address      State Holdtime Circuit Id
90AB.CDEF.0001 L1   Gi1         10.155.101.183  UP    27       1111.2222.CDED.01  
90AB.CDEF.0001 L2   Gi1         10.155.101.183  UP    27       1111.2222.CDED.01  
1111.2222.CDED L1   Gi1         10.155.101.214  UP    9        1111.2222.CDED.01  
1111.2222.CDED L2   Gi1         10.155.101.214  UP    9        1111.2222.CDED.01 
# show ip route
i*L1  0.0.0.0/0 [115/11] via 10.155.101.214, 4w5d, GigabitEthernet1
     10.0.0.0/8 is variably subnetted, 5 subnets, 2 masks
C        10.155.101.0/24 is directly connected, GigabitEthernet1
L        10.155.101.216/32 is directly connected, GigabitEthernet1
i L2     10.155.255.214/32 [115/10] via 10.155.101.183, 2w3d, GigabitEthernet1

No ability to show bridge table

In a bridge wireless network where CPE are bridging the LAN port to Wireless, then to the AP, and out the AP Ethernet port, one cannot find the MAC address of the CPE radio and what MAC's it's bridging to the AP. There has to be a table of this internally in the AP, but it is not exposed. This makes locating a misbehaving MAC address complex as you have to look at each CPE device's MAC table.

Alvarion/Cisco/Symbol/Karlnet/Canopy has had this since like 1995.

VRF table ignored for local responses

In a VRF, where you have a traceroute going through it, MT will source it's ICMP TTL packets using an IP from the main routing table. This means anyone tracrouting to the VRF will be able to see IP it's going over, or if it's a private IP that the main table has, it will likely just show "* * *" as the IP will be unreachable.

This is a known issue.

https://old.reddit.com/r/mikrotik/comments/5ixk1u/intermediate_hop_dont_show_in_traceroutes_when/

RFC3021 /31 links

Mikrotik doesn't support this. This is an over 20 year old RFC. Come on.

https://forum.mikrotik.com/viewtopic.php?p=163163

RFC3021 /31 addresses for PtP links has been supported in RouterOS since v7.18

https://help.mikrotik.com/docs/spaces/ROS/pages/28606515/Routing+Protocol+Overview

/export changes at random across different firmware

/export is not idempotent between OS upgrades on the same hardware.

This means config backups are basically worthless unless you can input them manually and see what breaks. There's no revision testing on it either by MT.

4 byte ASN

Per this message on NANOG, they can't do 4 byte ASN's

BGP AS4 (4-byte / 32-bit ASN) capability negotiation is defined in RFC 6793 is supported in modern Mikrotik RouterOS versions. https://manual.mikrotik.com/docs/user-guides/routing-and-networking-protocols/unicast/bgp/understanding-bgp#supported-standards