Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
jeeves
May 27, 2001

Deranged Psychopathic
Butler Extraordinaire
Yeah go ahead and do it. I’ve had no problems running v7+ for a year now.

Adbot
ADBOT LOVES YOU

Shugojin
Sep 6, 2007

THE TAIL THAT BURNS TWICE AS BRIGHT...


I've run into one or two weird third-party interactions with the 7.x stuff i use at work but it's mostly just "idk i have to specify something i didn't have to before" and honestly it might also be because those ones have complicating factors unrelated to being 7.whatever

Thanks Ants
May 21, 2004

#essereFerrari


It's happened again, the same totally poo poo engagement with security disclosures as the last time they had a huge IPv6 bug.

https://blog.mikrotik.com/security/cve-2023-32154.html

jeeves
May 27, 2001

Deranged Psychopathic
Butler Extraordinaire
Mikrotik: hey at least it only takes like 26 seconds to reboot on an update!


… that we hope you know you need to do asap

alyandon
Dec 9, 2001
Poster of the Month for July!
Fun Shoe
Since my experiences with Mikrotik disclosures hasn't been terrible (they seem to address vulns in reasonable time frames when they are aware of them) is there any particular reason I should doubt their claim that they weren't present at the event to receive the disclosure from ZDI?

Canine Blues Arooo
Jan 7, 2008

when you think about it...i'm the first girl you ever spent the night with

Grimey Drawer

alyandon posted:

Since my experiences with Mikrotik disclosures hasn't been terrible (they seem to address vulns in reasonable time frames when they are aware of them) is there any particular reason I should doubt their claim that they weren't present at the event to receive the disclosure from ZDI?

I know nothing of this situation. My guess is that someone was there, but not in an official capacity, and that person was notified. Whether or not that 'counts' is up to you I guess and again, that's wild speculation.

Jonny Quest
Nov 11, 2004

After debating for a bit, I finally converted half my network to use the new wifi-qcom-ac drivers so now I get two CAPsMANs running amok.

Challenges faced
1) Removing the wireless package and adding wifi-qcom-ac completely borks the QuickSet functionality, I had to manually configure the access points to put them into a functional CAP mode
2) Totally having to rework the dB levels I use for the Access Lists -- the new drivers required different signal ranges than legacy CAPsMAN.
3) Subjectively it feels like roaming is worse despite setting up steering, may need to keep tweaking things.

At least now I'm all set if I ever decide to start adding AX hardware, assuming I stick with Mikrotik's products.

Generic Monk
Oct 31, 2011

This might seem like a stupid question, but can I easily give clients a hostname that resolves to their IP address? I have a hEX S. Is it possible in WinBox? I assumed it would be in the DHCP settings but that only displays the hostname broadcast by the device.

I usually just use multicast DNS but been having some issues with it recently, seeing as I have this complicated router seems to make sense to do it on there instead

Generic Monk fucked around with this message at 22:41 on Feb 20, 2024

yoloer420
May 19, 2006
You can set static DNS entries in the DNS server. That should do what you want.

Thanks Ants
May 21, 2004

#essereFerrari


And if it wasn't made obvious in the docs, this would require your clients to be using the Mikrotik router as a DNS resolver

Partycat
Oct 25, 2004

I believe there are some sample scripts that will do that and set DNS off of the asserted host name for you

Actuarial Fables
Jul 29, 2014

Taco Defender
Getting into MikroTik WiFi. Grabbed a cAP AX and I've got it configured through CAPsMAN and broadcasting successfully, but there's a lot of settings that I haven't touched (or tried to touch and broke) and leaving most everything as an unlisted Default makes me worried that I'm not properly securing my setup.

Is there a best practices or hardening guide that would be good to follow?

Adbot
ADBOT LOVES YOU

alyandon
Dec 9, 2001
Poster of the Month for July!
Fun Shoe

Actuarial Fables posted:

Getting into MikroTik WiFi. Grabbed a cAP AX and I've got it configured through CAPsMAN and broadcasting successfully, but there's a lot of settings that I haven't touched (or tried to touch and broke) and leaving most everything as an unlisted Default makes me worried that I'm not properly securing my setup.

Is there a best practices or hardening guide that would be good to follow?

I don't really have any experience with MikroTik wifi gear - but assuming it runs routerOS you can follow the same general guidance from here:

https://help.mikrotik.com/docs/display/ROS/Securing+your+router

The short answer is - if you are upgraded to the latest firmware and used the defaults that came with that you should be pretty safe. Just don't do something bone-headed like expose the management interface to the internet.

alyandon fucked around with this message at 20:46 on Apr 4, 2024

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply