**Official MikroTik Hardware **

Despite saying I wouldn't get one and could not justify it, i got a crs310. Setup was dead easy as a layer 2 switch with 4 vlans, obviously not content with this I decided to wipe this and go full layer 3.....the headaches began

More fun with this tomorrow night
 
Ok - Proxmox host built and CHR deployed, only used a 1Gb license as the WAN won’t exceed that. All up and working great apart from I need to figure out WireGuard and client configs. Good to be back on the ‘Tik
 
DoH is on my list to do. Easy?
Yeah It's all pretty basic stuff, enable DoH function and tick enable remote requests, grab your root pem from here https://cloudflare-dns.com/dns-query smash....
cloudflare-dns.com 1.1.1.1 1.0.0.1 in your static tab, import your cert to certificates. Give your cache 200MB and add your adlist of choice https://raw.githubusercontent.com/hagezi/dns-blocklists/main/hosts/pro.txt enable HTTPS verify if you wish by adding the appropirate cert for that as well.

I've tested a few, quad9 plays up and spams the logs with various types of explanations of why it disconnected. Only tested upto 7.17beta2, they have messed with the dns internals since then, I might give quad9 another go sometime later today! Cloudflare is far more stable. I've not tested the whitelist function yet.
 
quad9 for me at least is still the same, Cloudflare doesn't do this, or at least not very often anyway.
This!
Code:
14:22 DoH server connection error: remote disconnected while in HTTP exchange
14:31 DoH server response not OK: 502: no downstream server available
15:22 DoH server connection error: remote disconnected while in HTTP exchange
 
Made a huge change to my firewall yesterday morning and I think I only just got it working how I wanted it to now.
By default I always put in a final drop WAN>LAN forward rule, I’ve now added multiple local subnets so I adjusted it to just drop all forward.
Needed an extra couple rules to get normal web access and the subnets I want to talk talking but super happy now, so much I may upgrade my P1 to a P10.
 
Glad this thread is quiet, means I won’t have to explain why I bought a P10 CHR license for my home router

That and you can also get an OVH CHR for <£1 per month for the first 12 months!
 
Device-Mode seems to causing quite a stir at the moment, they are also creating a cloud based solution as well. I do hope i have a choice NOT to use that function!
Device-mode? Cloud based solution? A what now? lol

Well the home CHR is now licensed up to 10Gb and the old 1Gb has been redployed to my OVH server. Did they need them? No. Does it make me happy? Yes.
 
I have a 250/25M conection so no need for custom stuff, although nice to have. So no need for a cloud based/local controller etc. I do like Mikrotik now I'm used to all the little niggles&riddles... I didn't think an 864MHz cpu could do so much. Next purchase is still going to be RB5009.
 
Back
Top Bottom