Pulling MikroTik into the Limelight Demystifying and Jailbreaking RouterS
margin.re
margin.re
Should it really require reverse engineering to figure out how a Linux box passes packets?
I gave up on Ubiquiti and bought a tiny $120 router ($140 with a nice metal case) that's a NanoPi R6s. Pretty impressive specifications. 8GB ram, 8 cores (4 fast Ax76 and 4 slow A55s) and no fans. Has 2x2.5GBe and 1x1GBe for networking. I've installed a port of OpenWRT called FriendlyElec and Ubuntu 22.04.1 LTS. I didn't bother cross compiling, it's plenty fast for native compiles.
I've been impressed so far. It compiles Rust about half as fast as my Quad core Xeon server from years ago, and is SEVEN times faster than a RPi 4 8GB! I have an Apple M1 mini around that manages the same compile in 13 minutes. A nice bonus is neither network or storage is USB attached, unlike the RPi.
Burned it in overnight, running all 8 cores flat out, with no problems. Haven't decided what to use, maybe shorewall or just raw nftables/iptables.
Similarly there's 4 and 6 port 2.5 Gbe boxes with various N5000 and N6000 celerons at around $200. ServerTheHome has reviewed many of them, they seem to be evolving nicely, better cases, better heat sinks, better 2.5Gbe Intel chips, etc. Run *WRT, pfsense, or whatever else floats your boat. STH even demod running the firewall under proxmox on one of these cheap 4-6 port 2.5GBe widgets. Would be nice to keep your complete config in git or the config management widget of your choice (often Puppet or Ansible).
Guess I'm just getting less trusting in my old age.
But other than that, yeah I don't see any reason to use a COTS router when I can just make one. My current router is my old desktop PC that became redundant when I built a new one, sitting as a bare motherboard on a test bench to take up very little space, running OPNsense.
Complaining about the lack of wifi drivers is pretty silly if you don't understand the advantages of a simple bridging wireless AP.
They're exposed to WiFi. They have terrible security in baked-in firmware that can't be updated without connecting them to vendor clouds, if at all.
FragAttack was just last year.
>Complaining about the lack of wifi drivers is pretty silly if you don't understand the advantages of a simple bridging wireless AP.
Ah yes, because one can think of three things that APs are not affected by, therefore APs are bullet-proof.
You just made my point for me. If you have to download binary blobs to your hardware, like wifi interfaces, you can have issues. Would you rather have vendor-dependent devices inside your firewall / NAT router, or just connected to the same network as your firewall / NAT router?
Nobody said APs are bulletproof, silly. Only people who don't know better would suggest or even imply that having separate APs is somehow worse. You want to keep the less secure stuff over which you have less control out of the important systems.
Interestingly, this is also something MikroTik isn't very good at - their long-range wifi is nice, but their consumer wifi used to be stuck at 2x2 and basically worse than cheap Asus "wifi router" which is somewhat embarrassing.
For switches, if you want fast, for small installation it is hard to beat the Mikrotik 4xSFP+ 10G switch for $150.
Not a single wifi consumer vendor have any say on those features. it is one hundred percent done on the closed OS in the radio chip.
your expensive ubiquiti/oanda/cisco have the same mimo/beanforming performance as any opensource/clone using the same wifi radio chipset.
the consumer facing OS just flip a bit somewhere in the configuration flash. granted, knowledge of the right bit to flip mighty be missing on the opensource still, but there's no magic happening in ubiquity owned code.
uniquity is extra shaddy as they buy off the shelf components but demand custom labeling to look like it's their custom silicon. it's not. uniquity is the matress store of wifi.
They're not - I have no idea about the hardware itself, but what makes Ubiquiti so popular is the software integration layer. Their stuff Just Works even for incredibly complex and large installations while still being easy to configure.
However all the NanoPi images are pinned to the same 5.10.x kernel, that I don't think it upstreamed, which is pretty ugly.
Armbian just had a new release, supporting a TON of SBCs, even a Risc-V board, which is weird based on the name. In any case, they support another RK3588 board, so I was going to try that. I want something using a mainline linux kernel if at all possible.
(Actually my setup is more complex, as the machine is powerful enough to run a few VMs, so I pass through one of the PCI devices to a firewall VM, which means the VM host doesn't even see the outside world.)
One thing to watch out for is Intel released some bad 2.5Gbe hardware (e.g. earlier versions of the I225-V). I even have a more recent one that seems to have issues (even when running the latest Linux from kernel.org). You can find Realtek cards though, which seem to work better (yeah, who'd have thought that would be the case).
[1]: It was something like: https://www.amazon.com/Suroene-Ethernet-Adapter-Multi-Gigabi... -- there are others.
https://www.amazon.com/Zer-one-7-5Inch-Extension-Flexible/dp...
If that sort of thing can work at PCIe rates I don't see any reason why that M.2 card can't. It's a lower bit rate plus theoretically a more resilient encoding for long distance as opposed to PCIe.
I don't have any hard-and-fast sources to back the above up, but punching 'pcie extender max length' into the Gargler should find you something to suffice.
https://www.aliexpress.us/item/3256804337466480.html
https://www.aliexpress.us/item/3256804400925663.html
OpnSense/XigmaNAS devs, are you listening?
Got a TPLINK Omada ER605 router now - just as powerful but way easier to configure.
That's giving it too much credit. I have experience with Cisco IOS and NexusOS, and I'll say that Mikrotik's RouterOS was hard.
They sold two versons of their switches and routers, the black ones(good) which were stand alone and the white ones(bad) which depended on the unifi system.
But then again I am also the idiot who ran openbsd on my edgerouters.
You have not used a Mikrotik wifi router in the last 10 years.
Which one did you decide to stick with? Or are you using both?
The problem I've had with OpenWRT is updates are a pain.
However more aggressive users will end up enabling more complicated firewall rules, QoS, buffer bloat mitigation, or deep packet inspection and disabling the silicon based acceleration or bottlenecking elsewhere.
Thus my interest in the RK3588, that provides 4x the PCIe of the RPi4 and a fair bit more CPU.
I do wish there was a popular benchmark that used a more realistic benchmark. Smaller packets, dozens or 100s of TCP sessions, non-trivial firewall rules, etc. Doesn't seem like you learn much from iperf managing 95% of of line rate with large packets.
But here's the iperf numbers I stumbled across: https://www.cnx-software.com/2022/11/12/nanopi-r6s-review-un...
My main router is virtualized on a Ryzen 5600G that also does other tasks. I have two other wifi APs that are just low power x86 boxes that also run Kodi.
Getting back to the original topic, I've still got Mikrotik for switches. The hardware is decent, the software is janky. I've got three different flavors of config - SwOS, RouterOS, and old RouterOS that requires a different type of config because the older switch chips were never updated to the newer config commands.
Mikrotik continues to hold their software too tightly instead of making the transition to a hardware company. They've built so much routing functionality, that's just pointless on devices that are switches. Yet there is some switch functionality that isn't available on SwOS. And SwOS is web-only with a binary config backup, rather than something conducive to centralized administration.
I'd love to find some low power white box 1Gb+10Gb switches that could run straight open Linux, or even using my existing Mikrotik switches that way if someone were to forcibly open their the environment.
I did this with my (mostly) OpenWrt-based network: https://github.com/kwesthaus/network-config.
I chose the NanoPi R4S instead of the R6S as my router since it is fully supported by vanilla OpenWrt [1] whereas the R6S is still in the works [2].
[1]: https://openwrt.org/toh/friendlyarm/nanopi_r4s_v1
[2]: https://forum.openwrt.org/t/nanopi-r6s-a-rockchip-rk3588s-ro...
I think is still a very nice feature to release even if it's no complete and fully secure yet.
> your router is as secure as anything you run in container; > if you run container, there is no security guarantee of any kind; > running a 3rd party container image on your router could open a security hole/attack vector/attack surface;
https://help.mikrotik.com/docs/display/ROS/Container#Contain...
Slide deck from margin.re: https://margin.re/content/files/2022/11/Pulling_MikroTik_int...
Blurb about the presentation at the con's site: https://cfp.recon.cx/media/2022/submissions/TZUFS8/resources...
Blurb about the presentation at margin.re: https://margin.re/pulling-mikrotik-into-the-limelight-2/
https://web.archive.org/web/20221208070504/https://margin.re...
The EU imposed software radio lockdown, there was a public consultation about it where most of the answers from industry and users were negative, but they kept on pushing for it.
The same kind of consultation happened in the US, with the same kind of ignorance.
We could have cooperative use of the airwaves and true open-source, open-hardware radios, but there's too much money to be made auctioning spectrum and assuring that most of it is is 99.99% unutilized. Would be horrible if people had cheap 5-10W handhelds that use advanced codecs, or could run 5mw of power on any part of the spectrum.
That might have changed now, but I still can't find an official repo. You could look for older versions like this: https://github.com/robimarko/routeros-GPL or try to contact them directly (or sue if you think you have a standing).
If you're transmitting (and trusting) plaintext data around, you have bigger issues that just the trustworthiness of your router.