Earlier quoted context omitted.
"Their most recent model has 8x10Gb ports, costs USD $2,500 and will route the full 80gb/s" No, it won't route 80Gbps, because any single flow on a CCR uses a single core on their multi core Tilera CPUs. The CCRs struggle to really do 10Gbps of real world IP transit traffic. If you're pushing 5Gbps+ of your customers' IP traffic in a daily sine wave pattern to/from upstream and adjacent BGP peers (paid IP transit and…
What ISP needs a single flow to exceed 1gb? I would venture to say most non-storage networks don't have single flow requirements in the Gb/s. I can buy 3 CCR routers and run OSPF/BGP/etc... on them to provide redundancy. The likelyhood of all 3 failing at once is slim and I'm still an order of magnitude cheaper than an equivalent Cisco/Juniper setup. Yes, dynamic routing takes a few seconds to converge, so an unplann…
Mikrotik router as OpenVPN Client
41–50 of 50 posts
Re: Mikrotik router as OpenVPN Client
#42Earlier quoted context omitted.
What ISP needs a single flow to exceed 1gb? I would venture to say most non-storage networks don't have single flow requirements in the Gb/s. I can buy 3 CCR routers and run OSPF/BGP/etc... on them to provide redundancy. The likelyhood of all 3 failing at once is slim and I'm still an order of magnitude cheaper than an equivalent Cisco/Juniper setup. Yes, dynamic routing takes a few seconds to converge, so an unplann…
Comcast fiber is 3gbps (sold as 2gbps) and provisioned via a Juniper box to you which acts a bridge alone, with SFP+ port giving 2gbps, and a GigE port separate.
A flow is a single connection, such as downloading a file from a single IP address.
When you download a single file from multiple sources (such as with Bittorrent), each connection to each source is a flow.
Re: Mikrotik router as OpenVPN Client
#43Earlier quoted context omitted.
No UDP support after all these years is really quite shameful. Tunneling TCP over TCP is insanely bad, the slightest packet loss and your connections are toast.
still not? I was moaning about this in 2006. I can't imagine why Mikrotik can't be bothered to implement UDP for OpenVPN when they have added so many other features. This is my #1 gripe with mikrotik, you can't figure out if the feature you want to use is half-baked or not without testing it. And then once it works you had better not upgrade versions or it may very well break. Finding a version which has all the feat…
I recently spent several hours trying to implement BFD...only to find out it's broken on CCR, known to be broken, and won't be fixed any time soon [1]
But to be fair, I've run across similar things in Cisco land. Spend hours trying to get something to work, when I finally run across an single line somewhere on their site that says what I'm trying to do doesn't work with CEF and I have to disable CEF if I want it to work. Which cuts my throughput by 10x.
Re: Mikrotik router as OpenVPN Client
#44Earlier quoted context omitted.
"Their most recent model has 8x10Gb ports, costs USD $2,500 and will route the full 80gb/s" No, it won't route 80Gbps, because any single flow on a CCR uses a single core on their multi core Tilera CPUs. The CCRs struggle to really do 10Gbps of real world IP transit traffic. If you're pushing 5Gbps+ of your customers' IP traffic in a daily sine wave pattern to/from upstream and adjacent BGP peers (paid IP transit and…
What ISP needs a single flow to exceed 1gb? I would venture to say most non-storage networks don't have single flow requirements in the Gb/s. I can buy 3 CCR routers and run OSPF/BGP/etc... on them to provide redundancy. The likelyhood of all 3 failing at once is slim and I'm still an order of magnitude cheaper than an equivalent Cisco/Juniper setup. Yes, dynamic routing takes a few seconds to converge, so an unplann…
If looking at used/refurb core routing platforms these days, anything that is not capable of being upgraded to a reasonable density of 100GbE is selling for very affordable prices now. Even systems that are fully modular and redundant and capable of more than 60 10GbE interfaces in one chassis, such as the MX480 or MX960. Or an ASR9006/ASR9010 with first generation linecards.
Re: Mikrotik router as OpenVPN Client
#45Earlier quoted context omitted.
I guess I'm too used to Cisco and Juniper pricing, but "pricey" is the last thing that comes to mind when I think of Microtik... When you say "good commercial routers" that are cheaper, are you talking about consumer hardware? I'm curious what you prefer. I don't have any Microtik hardware at all, so I don't have any vested interest here - I am just curious what people are liking these days. The vast majority of the…
I'm using a $50 Mikrotik hAP AC Lite (RB952Ui-5ac2nD-US) as a home router. It's not the most high-powered router — it only has a single 5GHz radio, no antenna, and the Ethernet port is 10/100 only — but it's stunningly solid. Previously I had, over the span of 18 months, an ASUS "Dark Knight" (whose 5GHz network slowly faded and then _disappeared_, apparently a known issue), an ASUS RT-AC66U (frequently just choked,…
The routers locked up so much they had one of those plug-in timers [1] set to reboot the router each night during their 'daily maintenance period'. They wouldn't even dispatch someone to do it when they started getting calls.
[1] http://www.walmart.com/ip/GE-15153-GE-Mechanical-24-Hour-1-O...
Re: Mikrotik router as OpenVPN Client
#46Earlier quoted context omitted.
I'm using a $50 Mikrotik hAP AC Lite (RB952Ui-5ac2nD-US) as a home router. It's not the most high-powered router — it only has a single 5GHz radio, no antenna, and the Ethernet port is 10/100 only — but it's stunningly solid. Previously I had, over the span of 18 months, an ASUS "Dark Knight" (whose 5GHz network slowly faded and then _disappeared_, apparently a known issue), an ASUS RT-AC66U (frequently just choked,…
I cut my teeth at an "ISP" that would order a business DSL line at a MDU/Apartment complex, run it through a Linksys router, then over the phone wiring using 2-wire "HomePNA" devices and charge each person $30/month for the service. The routers locked up so much they had one of those plug-in timers [1] set to reboot the router each night during their 'daily maintenance period'. They wouldn't even dispatch someone to…
Re: Mikrotik router as OpenVPN Client
#47Earlier quoted context omitted.
What ISP needs a single flow to exceed 1gb? I would venture to say most non-storage networks don't have single flow requirements in the Gb/s. I can buy 3 CCR routers and run OSPF/BGP/etc... on them to provide redundancy. The likelyhood of all 3 failing at once is slim and I'm still an order of magnitude cheaper than an equivalent Cisco/Juniper setup. Yes, dynamic routing takes a few seconds to converge, so an unplann…
Thing is, it's not an 'order of magnitude' different in price... Three $2500 CCRs vs, what? I know somebody who recently bought a whole Juniper MX960 for around $10,000. For a serious ISP that is a big jump in capability and resiliency. If looking at used/refurb core routing platforms these days, anything that is not capable of being upgraded to a reasonable density of 100GbE is selling for very affordable prices now…
And I have to pay for support if I want to get updates, security patches, etc... [3]
And I need 2+ of them if I want to multi-home.
So I'm buying a used device of unknown history, that someone is selling for unknown reasons(could be a working pull, could be something with an obscure problem that will surface 3 months later), without a hardware warranty or support, with outdated software, and going to trust my entire network with it and it's internal redundancy. If I could get 3 for that price I might consider it.
I like the SpaceX approach. Don't trust one big expensive engine to get you where you're going. It probably won't fail, but if it does, you're toast. Trust 9 cheaper ones and have enough redundancy that if/when one does fail, you shrug and keep going and just replace it before the next launch.
[1] http://www.ebay.com/itm/221776643106
[2] http://www.ebay.com/itm/122004198861
[3] http://www.juniper.net/techpubs/en_US/release-independent/ju...
Re: Mikrotik router as OpenVPN Client
#48Earlier quoted context omitted.
I cut my teeth at an "ISP" that would order a business DSL line at a MDU/Apartment complex, run it through a Linksys router, then over the phone wiring using 2-wire "HomePNA" devices and charge each person $30/month for the service. The routers locked up so much they had one of those plug-in timers [1] set to reboot the router each night during their 'daily maintenance period'. They wouldn't even dispatch someone to…
That's the most ridiculous thing I've ever read on HN.
They also got in trouble with the LEC(and law enforcement) for using the LEC copper to interconnect their equipment between buildings. It was a common practice for them to tone out pairs in a neighborhood and patch their own wires in using the LEC's boxes and wiring.
They are no longer in business.
Re: Mikrotik router as OpenVPN Client
#49Earlier quoted context omitted.
To get around GFW, use openconnect instead. That is as or more secure than OpenVPN, and not current filtered.
> That is as or more secure than OpenVPN How does it achieve that? They both use TLS, in both, you can pick your ciphers. Additionaly, they both use OpenSSL, which is often found buggy and the ciphers are not hw accelerated.