Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Actuarial Fables
Jul 29, 2014

Taco Defender
I'm considering dipping my toes into MikroTik by picking up this switch for my home lab. My experience with MikroTik was 10 minutes at a client site trying to figure out what the heck was going on and why the WiFi died so I don't really know what I'd be getting into.

Coming from a Cisco + Ubiquiti background, how much trouble would I have with this switch?

Adbot
ADBOT LOVES YOU

Actuarial Fables
Jul 29, 2014

Taco Defender
Thanks! I'll start seriously looking at my budget to see if I can afford this.

I was also looking at the CRS version as well. The ~$50 price increase could be trouble, but if it makes it more fun then I'll have to consider it.

jeeves posted:

I don't miss how flakey the hardware can obviously be
Could you elaborate a bit more on this?

Actuarial Fables
Jul 29, 2014

Taco Defender
Decided to go for the CRS model over the CSS. It was delivered today so I've been playing around with it, and so far I've managed to get myself locked out three times by messing up vlan config. I think I've got a handle on it now - the main issue was that I didn't realize that you have to set a pvid value on the port itself in addition to adding the port as untagged in the bridge vlan config.

In the process of moving my lab over to this switch now. Thanks again for the advice!

Actuarial Fables
Jul 29, 2014

Taco Defender
Guess I'll update on my CRS-326 experience.

It's good!

Ran into some beginner traps though - I created a bonded interface using the balance-rr mode, which seemed great because my virtualization servers have multiple gigabit interfaces and my storage server is connected on one of the 10g ports, but the CRS326 can't hardware offload that mode so I ended up with sub-gigabit speeds until I did some benchmarks and discovered my error. However, after getting it set up correctly I haven't had to touch it and really that's the end goal for networking equipment.

The biggest issue with the switch isn't even about the switch itself, but the power adapter. It's this clunky wall wart that I can't fit on my UPS. I had a spare passive PoE adapter from a UniFi AP so I've just been using that to power the switch instead. Not sure why they went with passive PoE input instead of 802.3af/at, but whatever.

Once I find a steady source of income I'm considering upgrading my virtualization servers to 10gbit and picking up a CRS305 to connect them to my storage server, but until then I'm happy with the 326.

Actuarial Fables
Jul 29, 2014

Taco Defender

quote:

!) support for Layer 3 hardware acceleration on all CRS3xx devices;

I was thinking of getting a router for my lab cabinet, but maybe I don't need to anymore.

Actuarial Fables
Jul 29, 2014

Taco Defender
Tested out the l3 switching on my CRS305 that 7.1 introduced

Without offload
code:
root@pve2:~# iperf -c 172.20.50.9
------------------------------------------------------------
Client connecting to 172.20.50.9, TCP port 5001
TCP window size: 85.0 KByte (default)
------------------------------------------------------------
[  3] local 172.20.51.10 port 53668 connected with 172.20.50.9 port 5001
[ ID] Interval       Transfer     Bandwidth
[  3] 0.0000-10.0047 sec   279 MBytes   234 Mbits/sec
With offload
code:
root@pve2:~# iperf -c 172.20.50.9
Client connecting to 172.20.50.9, TCP port 5001
TCP window size: 85.0 KByte (default)
------------------------------------------------------------
[  3] local 172.20.51.10 port 53690 connected with 172.20.50.9 port 5001
[ ID] Interval       Transfer     Bandwidth
[  3] 0.0000-10.0006 sec  11.0 GBytes  9.42 Gbits/sec

Actuarial Fables
Jul 29, 2014

Taco Defender
https://mikrotik.com/product/ccr2004_1g_2xs_pcie

I thought at first they were just selling their own kind of 25G PCIe adapter, but no it's a router.

Actuarial Fables
Jul 29, 2014

Taco Defender
I grabbed a CCR2004-1G-2XS-PCIe to play around with.

The physical SFP28 interfaces will not get a link (won't even show what SFP module is attached) if they're set as pass-through to a disabled virtual interface. I spent quite a while wondering if my DACs were incompatible with this device before I realized what was going on.

Actuarial Fables
Jul 29, 2014

Taco Defender
I've never understood why some of their devices are Passive PoE input and others are 802.3af/at.

Actuarial Fables
Jul 29, 2014

Taco Defender

MikusR posted:

I have no understanding about all the poe stuff. But, based on specs, would this hAP ax2 be able to power hAP ac2?

Probably. The ac2 lists a max power consumption of 16w, and the ax2 gives out 16.8w, so on paper it should be able to power it. If using the ax2 to power another device, you'll need to use the DC power adapter (only eth1 does PoE In or Out).

Actuarial Fables
Jul 29, 2014

Taco Defender
I guess my main point of confusion is why it seems inconsistent.

The CSS/CRS326 switch takes in Passive PoE, while it seems like all the other CRS3xx devices that accept PoE-In use 802.3af/at.

The CRS309 switch has a 9-pin console port, while all the other CRS3xx devices with console ports don't.

Actuarial Fables
Jul 29, 2014

Taco Defender
I needed more SFP+ switch ports than the 4 from my CRS305, and the CRS309 also wouldn't cut it (and is also always out of stock whenever I look) so I picked up the CRS317_1G_16S+RM. 16 SFP+ ports should keep me happy for a while. Upgrading to more SFP+ ports allowed me to remove a bunch of cat6 cables that were in LAGs, simplifying my setup and freeing up a bunch of space (and PCIe slots).

There's two 40mm cooling fans and I was concerned that the noise would be intolerable in my home office/lab, but they don't run when the temperature is low enough and there's a decently sized external heatsink. So far they've only spun when the switch is booting. The switch has internal power supplies so I don't have to work around a DC wall wart in my cramped cabinet, unlike the CRS305 and CRS326.

Other than the BRIGHT BLUE LEDs on the front that I've taped over, it has been a good switch so far.

e. It came with a little MikroTik sticker and a... no trash sticker

Actuarial Fables fucked around with this message at 15:33 on Aug 26, 2022

Actuarial Fables
Jul 29, 2014

Taco Defender
Today I found out that MikroTik sells branded merchandise. There's the usual t-shirts, stickers, and tote bags that you would expect, but there's a few interesting items that seem to be specially designed for the MikroTik enthusiast.

:nws:, no nudity but you probably don't want anyone to see you looking at this https://merch.mikrotik.com/products/groove-boxer-briefs :nws:

Actuarial Fables
Jul 29, 2014

Taco Defender
Interface comments/descriptions in 7.9 are now inline instead of being above each line, so maybe I won't configure the wrong interface when using the web interface now.

e. I guess there's no way to timg attached images

Only registered members can see post attachments!

Adbot
ADBOT LOVES YOU

Actuarial Fables
Jul 29, 2014

Taco Defender
Getting into MikroTik WiFi. Grabbed a cAP AX and I've got it configured through CAPsMAN and broadcasting successfully, but there's a lot of settings that I haven't touched (or tried to touch and broke) and leaving most everything as an unlisted Default makes me worried that I'm not properly securing my setup.

Is there a best practices or hardening guide that would be good to follow?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply