ChatCrawlerпоиск по публичному Telegram Открыть приложение
M

MikroTik ipsec xperts

476 участников
25 августа 2026
3 сентября 2026
RouterOS 7.24.2 [stable, testing] released! ChangelogThis is an important security update. Most configurations are not at risk, but upgrading is highly recommended. To give time to update your systems, we are not currently publishing detailed information. *) bgp - fix BGP link-local nexthops unreachable over a VRF and a crash when disabling an unnumbered connection; *) btest - improve stability; *) certificate - fix changing the built-in trust store setting (introduced in 7.22.2); *) console - improve stability; *) console - fix a memory leak in background scripts; *) console - improve stability; *) container - improve container image extraction; *) dhcp - improve stability of DHCP handling; *) disk - improve stability of the SMB server; *) ethernet - improve stability on hAP be3 Media; *) fetch - improve stability of the TFTP client; *) ipv6 - add a neighbor discovery ping; *) leds - fix LEDs set to interface status staying off when the interface is active; *) lte - fix the RG650E-EU modem not bringing link up after a firmware update; *) ping - add parameter checks for arp ping; *) poe-out - fixed missing PoE-Out interface on hEX PoE lite, RB260GSP, OmniTIK 5 PoE, PowerBox; *) ssh - refactor SSH internal processes and improved system stability; *) system - improve stability; *) webfig - improve stability; *) winbox - fix the "addresses" spelling in read-only fields; *) www - improve stability; DownloadsMain: arm64 mipsbe mmips tile arm powerpc netinstall x86 x86-iso x86-dude x86-dude-client x86-netinstall64 x86-netinstall-cli btest.exe Extra: arm64 mipsbe mmips tile arm powerpc netinstall x86 Others: https://mikrotik.com/download GPT 💬 ENG ESP POR УКР РУС 中文
2.7K ·
RouterOS 7.23.4 [long-term] released! ChangelogThis is an important security update. Most configurations are not at risk, but upgrading is highly recommended. To give time to update your systems, we are not currently publishing detailed information. *) bgp - fix BGP link-local nexthops unreachable over a VRF and a crash when disabling an unnumbered connection; *) btest - improve stability; *) certificate - fix changing the built-in trust store setting (introduced in 7.22.2); *) console - improve stability; *) dhcp - improve stability of DHCP handling; *) disk - improve stability of the SMB server; *) fetch - improve stability of the TFTP client; *) ipsec - fixed expired SA handling to prevent "no such item" errors during listing; *) ipsec - improve IKE handshake stability; *) leds - improved interface stats activity for devices with Marvell Prestera switch chip; *) lte - removed extra restart after firmware upgrade for EC200A-EU modem; *) lte - fix the RG650E-EU modem not bringing link up after a firmware update; *) ping - add parameter checks for arp ping; *) snmp - properly validate password length when applying configuration; *) ssh - refactor SSH internal processes and improved system stability; *) system - improve handling of invalid SSL/TLS requests; *) system - improve stability; *) tunnel - fixed stability issue caused by a misconfigured routing loop under bridge (introduced in v7.22); *) webfig - improve stability; *) wifi - updated radio regulatory information; *) winbox - fix the "addresses" spelling in read-only fields; *) wireguard - fixed peer Tx/Rx counters; *) wireguard - generate port number when specified as zero; *) wireguard - reinitialize socket on VRF change; *) www - improve stability; DownloadsMain: arm64 mipsbe mmips tile arm powerpc netinstall x86 x86-iso x86-dude x86-dude-client x86-netinstall64 x86-netinstall-cli btest.exe Extra: arm64 mipsbe mmips tile arm powerpc netinstall x86 Others: https://mikrotik.com/download GPT 💬 ENG ESP P
2.9K ·
N
7.25beta3: *) certificate - allow importing a cross-signed certificate without overwriting the existing one; *) certificate - fix ACME certificate issuance for wildcard domains; *) certificate - fix changing the built-in trust store setting (introduced in 7.22.2); *) certificate - improve certificate import process; *) certificate - refactor certificate internal processes; *) ipsec - add XFRM interface support *) wireguard - add the client-mtu parameter; *) ssh - switch the default host key type to Ed25519;
Е
Коллеги Добрый день, есть два микротика , между ними туннель. Направляю трафик определенного сайта в туннель, и не получаю ответа. Что может быть причиной. Обратные Маршруты есть . Вопрос срочный , если кто может глянуть готов запустить и оплатить. Если кто готов посмотреть напишите в ЛС пожалуйста
Н
Е
Никола ДомовойЕсли используется маркировка, то, с большой долей вероятности, входящий трафик не отделён от исходящего и улетает по неправильному маршруту
Маркировка используется, трафик к госуслугам отправляется через отдельную таблицу маршрутизации и даже возвращается на роутер с удаленного роутера , но почему то на виндовую машину не возвращается
Е
Трафик уходит в туннель нормально, и возвращается на роутер
Н
ЕвгенийДа
Проверьте наличие условия по параметру in-interface либо in-interface-list (одного из двух), которое должно отсекать трафик приходящий на WAN-интерфейсы, т.е. под действие этого правила трафик, приходящий снаружи, попадать не должен
4 сентября 2026
5 сентября 2026
MikroTik: CVE-2026-86060 RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
6K ·
MikroTik: CVE-2026-67281 RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
4.8K ·
MikroTik: CVE-2026-67279 RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
3.8K ·
MikroTik: CVE-2026-67278 MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
3.7K ·
MikroTik: CVE-2026-67277 RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
4.1K ·
N
MikroTik: CVE-2026-67276 RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
5K ·
6 сентября 2026
8 сентября 2026
L
Добрый вечер. кто нибудь сталкивался с ошибкой "Неустановил удаленное подключение FFFF, которое завершилось сбоем. Возвращен код ошибки 87"? VPN IKEV2, клиент windows 11
9 сентября 2026
N
Ссылка
нажмите — покажем
Коллеги-скриптеры, кто хочет потестить мою закрытую бету? Ставьте лайк, пришлю в личку ссылку на закрытый бета-чатик, там в закрепе VSIX пакеты под все платформы https://www.glossema.dev/
Архив по месяцам
Открыть в Telegram Каталог площадок Искать в ChatCrawler

Слепок открытой публичной ленты из поискового индекса ChatCrawler — «Google по публичному Telegram»; обновляется по мере обхода площадки. Время — UTC.

Только публичный контент, официальный API Telegram. О проекте · Вопросы · Чего мы не делаем · Убрать страницу из выдачи · Каталог