MikroTik and Zerotier

Поділитися
Вставка
  • Опубліковано 12 жов 2022
  • Finally, the video you have been asking for. How to quickly set up Zerotier in a MikroTik router.
    ARM/ARM64 MikroTik router required for this tutorial.
    help.mikrotik.com/docs/displa...
  • Наука та технологія

КОМЕНТАРІ • 151

  • @KeithMoon_nz
    @KeithMoon_nz Рік тому +9

    I just got myself a hAP ac2 and put zerotier on, followed your guide, put in a couple of routes, now I can access my NAS and raspberry pi from anywhere from my phone etc. I am really pleased.
    next I'll set it up for my wireshark packet capture devices and raspberry pi drop boxes.😀

  • @just-a-waffle
    @just-a-waffle Рік тому +2

    I’ve had opnsense running in a VM with routes in my CCR2004 to get to ZT, was happy to replace it with the new ZT integration in routerOS, and it’s been working amazing

  • @georgilazarov1512
    @georgilazarov1512 Рік тому +3

    Amazing tutorial, I hope the next video will be how to set up the Zerotier controller on RouterOS

  • @daniszabo8153
    @daniszabo8153 Рік тому +3

    One thing is missing :) for this to work you need to enable managing on the zerotier interface. Mine was off by default. Also if you want to route traffic both ways you can change the NAT masquarade setting to have ALL as output interfaces. These settings made it work for me.

  • @sandro7490
    @sandro7490 Рік тому +1

    BROOO thankyou so much, this really helped and the tutorial was really easy to use as well :)

  • @zakariaalimahdi1145
    @zakariaalimahdi1145 5 місяців тому

    This was a helpful information and it's easy to use it as well. please add to the other mikrotik versions not only version 7 thank you so much

  • @kriptypell8851
    @kriptypell8851 Рік тому +1

    Really nice and helpful... Thanks!

  • @jesusverdi3700
    @jesusverdi3700 Рік тому

    Woah, great video mate!

  • @TheAdham302
    @TheAdham302 Рік тому +3

    please, bring this feature to more routers

  • @oluwawadamilare
    @oluwawadamilare Рік тому +1

    great, I just installed one

  • @boomtechreviews
    @boomtechreviews Рік тому +23

    We need x86 Zerotier , Thank you !

  • @beningodfrey4
    @beningodfrey4 Рік тому +7

    Next please implement Tailscale as well! I’ve found it to be much more reliable and user-friendly than Zerotier.

    • @mikrotik
      @mikrotik  Рік тому +2

      Tailscale should run on each device, not on the router.

    • @beningodfrey4
      @beningodfrey4 Рік тому

      @@mikrotik Agreed, but when using containers on the same router, tailscale will help exposing them directly into the tailnet in addition to the LAN.
      For ex. PiHole container can be both LAN and tailnet DNS server by putting router’s Tailscale IP address in the tailscale settings.

  • @martinsilcher9008
    @martinsilcher9008 Рік тому +9

    I've been using ZT since it was available in ROS 7, it has a lot of potential! Downside is that there is no hardware encryption available at least on ARMv7 (32bit) and the CPU gets overloaded quickly delivering low throughputs. I had no chance to test it on ARMv8 (64bit) so far, hopefully it performs better.

    • @mikrotik
      @mikrotik  Рік тому +5

      Have you tried latest versions? We see 0% CPU use in idle, and only slight increase with traffic. Also, try to direct only needed traffic through it, not all of it.

    • @jozuanvantonder9219
      @jozuanvantonder9219 Рік тому +1

      if you have a small 1u rackmount XEON server, load router OS on a VM, allocate enough CPU power, and use that as you gateway from outside... especially if you have access to multiple static IP's from your ISP... you can setup OSPF from your main router to deal with whatever device IP is needed from the ZT VM Router... if you have a better solution, please teach me haha

    • @martinsilcher9008
      @martinsilcher9008 Рік тому

      ​@@mikrotik I always use latest versions. The issues isn't CPU usage when idle, it is CPU usage when transferring data via ZT due to encryption. It seems that there is no hardware offloading available as in IPSec and that a pity. For example, using a hAP ac2 I cannot squeeze more than 20mbps via ZT because the CPU stresses out.

    • @deafno
      @deafno Рік тому +4

      I tested RB5009 and could saturate 0.5 Gbit line with zerotier traffic. I think it can even do 1 Gbit since the CPU usage was below 50%.

    • @martinsilcher9008
      @martinsilcher9008 Рік тому

      @@deafno thanks for sharing :)

  • @sniperus892
    @sniperus892 Рік тому

    Not bad. I liked the bot. I launched it, but I don�t understand how to set it up

  • @andreabattocchio891
    @andreabattocchio891 Рік тому

    now i am in a good mood

  • @asho1735
    @asho1735 Рік тому +2

    the version of zerotier on tik is slightly old? also, how do we implement policies when running the self hosted controller? It seems that a couple of feature are missing, otherwise this is a great package. And yes, as others have said there appears to be no h/w acceleration

  • @dfvideo337
    @dfvideo337 Рік тому +1

    Is it possible to add managed routes in you use Mikrotik as a controller?

  • @TheDominik8602
    @TheDominik8602 Рік тому +2

    Zerotier is 👍

  • @Yegva
    @Yegva Рік тому

    Hello, thanks for the video, I have a question, can I send a Wake on Lan to my Synology NAS in this way? Thank you.

  • @SiBex_ovh
    @SiBex_ovh Рік тому +2

    CCR1xxx are on TILE cpu... not ARM. We can use WireGueard + VxLAN or old school BCP+EoIP. But WG often stops communication and cannot be used for now as production (SUP-94949)

    • @mikrotik
      @mikrotik  Рік тому

      Never seen WG stop on any system. Can you test it on another device? Maybe the cause is outside the router

  • @palwindersingh9678
    @palwindersingh9678 Рік тому +1

    I would love to see Tailscale support added to MikroTik as well.

    • @mikrotik
      @mikrotik  Рік тому

      Tailscale is normally used on each end point device, not on the router

    • @palwindersingh9678
      @palwindersingh9678 Рік тому

      @@mikrotik Thanks for the quick reply. That's a totally valid point. It's just the competition (pfSense, OpenWRT comes to my mind) already supports running Tailscale. The one thing I absolutely loved about Tailscale is just how easy is to run exit node (it's just pressing two or three buttons and you're done!)
      I can understand that supporting yet another feature on RouterOS isn't as straightforward as it may sound.
      Perhaps consider making a video on how to setup exit nodes on Zerotier and funneling your devices traffic running behind MikroTik through your chosen node.

  • @nur76n
    @nur76n Рік тому +6

    I think ZeroTier should be positioned as WAN network, and you should use a secured tunnel (IPSec for instance) over this connection.

    • @mikrotik
      @mikrotik  Рік тому +5

      Why? Zerotier is already encrypted

    • @nur76n
      @nur76n Рік тому

      @@mikrotik Oh, Ok

    • @gosich
      @gosich Рік тому +3

      @@mikrotik But it's a third-party service which who knows what can do with the traffic, right?

    • @chumly8596
      @chumly8596 Рік тому +4

      @@gosich No. The cloud part is for connecting, not for all traffic. Also, you can setup you're own servers and not use the zerotier cloud system.

    • @gosich
      @gosich Рік тому +2

      @@chumly8596 even if all traffic doesn't go through the cloud, some communication is happening, and you can't be sure what exact information can be passed to their servers. Ability to use own server is nice, but that will defeat the advantage of simplicity of this type of VPN.

  • @GladSpiR
    @GladSpiR 4 місяці тому

    thx

  • @user-wu4cw5ed5w
    @user-wu4cw5ed5w Рік тому +3

    I use zerotier since the very implementing controller functionality on hap ac3

    • @crestdazoltral7705
      @crestdazoltral7705 Рік тому

      How many resources does the controller consume? Did controller discovery by other nodes work for you?

    • @user-wu4cw5ed5w
      @user-wu4cw5ed5w Рік тому

      @@crestdazoltral7705 My case is bridging physical interfaces with zerotier controller node, under load 10% max cpu consumption

    • @user-wu4cw5ed5w
      @user-wu4cw5ed5w Рік тому

      @@crestdazoltral7705 since I pushed zerotier controller node interface to LAN, device discovery works as well

  • @mikeselltgmail
    @mikeselltgmail Рік тому +4

    This is great, but I'll have to get all new routers for it to be of any use to me since mips isn't supported 😕🤷 Is there any chance of mips being supported in the future? I have been using ZT for a long time via routing on a raspberry pi, but it works be really nice to host it off the Mikrotik itself.

    • @mikrotik
      @mikrotik  Рік тому

      Currently we only plan to support it on ARM systems.

    • @mikeselltgmail
      @mikeselltgmail Рік тому +3

      @@mikrotik Well that's a shame.

  • @thegorn
    @thegorn Рік тому +3

    I don't like how ZT relies on a cloud service. When it comes to networks, I want to handle everything myself. Trusting a cloud provider for your networking seems as smart as trusting Russia for your gas supplies.

    • @mikrotik
      @mikrotik  Рік тому +3

      As mentioned in the video, MikroTik offers to host the controller yourself. Check the manual link

  • @ludgerkreimer1550
    @ludgerkreimer1550 Рік тому +1

    what about IPv6? Will it works with IPv6, if I only have a IPv6 on my MikroTik WAN Interface (no native IPv4) and will it connect from anywhere to my locally NAS, which is behind my Mikrotik RouterOS? Thanks for your great work and information in your videos!

    • @mikrotik
      @mikrotik  Рік тому

      Of course, in my.zerotier.com there is plenty of options to automatically set up IPv6

    • @crestdazoltral7705
      @crestdazoltral7705 Рік тому

      ZeroTier works over IPv6 (including v6 only) only and can provide IPv6 (again including v6 only) addressing. It has a special automatic addressing scheme to derive a per node /128 address from the network and node ID. This addressing mode avoids the costs of next hop resolution (NDP/ARP proxying, multicast or in the worst case broadcasts) by embedding the node ID into the IPv6 host addresses. Combined with filter rules to allow only unicast traffic between the provisioned addresses this allows scaling to very large networks by avoiding the control plane "chatter" normally required to provide a convincing Ethernet overlay. It's perfect for management via SSH or (encrypted) API, but won't support your old local multiplayer games.

  • @johnvgale
    @johnvgale Рік тому +2

    Would this be a good (the best/recommended) solution to enabling remote management/access to a fleet of MikroTik LTE devices (with cgnat addresses)?

    • @mikrotik
      @mikrotik  Рік тому

      Excellent idea. Certainly less configuration and more control than manually managing tons of tunnels, or using plain TR069

    • @johnvgale
      @johnvgale Рік тому

      @@mikrotik but not compatible with our wAP & SCT devices - shame

    • @stalkerx85
      @stalkerx85 Рік тому

      You can alternatively set an ovpn o wg tunnel client to your server, and then access devices remotely through that tunnel.

    • @mikrotik
      @mikrotik  Рік тому

      Not sure what is "SCT", but "wAP ac" is ARM based, so it's compatible with ZT.

  • @pankajmazumder2860
    @pankajmazumder2860 9 місяців тому

    Will it support in hAP lite and can i access the LAN devices remotely from anywhere ?

  • @privaltv
    @privaltv Рік тому +1

    cool

  • @omidrahimi2038
    @omidrahimi2038 2 місяці тому

    Is it possible to route all the traffic of one pc through another one?
    I managed to see my home PC at the office using ZeroTier but I could not route all the office traffic through my PC at home.

  • @ratowniknaemigracji6537
    @ratowniknaemigracji6537 Рік тому +3

    ZT seems great but the performance vs WireGuard seems very low :(
    Is WG the only solution for a good performance?

    • @mikrotik
      @mikrotik  Рік тому +2

      In what way is performance low? In megabits, or in CPU usage? Zerotier needs a little bit of time to find the optimal path between networks. It could be slow in beginning, but will become faster later. It's not a direct tunnel between networks, it goes in different paths than regular VPN

    • @thegorn
      @thegorn Рік тому +2

      Just use ZT for layer 2 management network and not production traffic

  • @JESUSistheGoodNews
    @JESUSistheGoodNews Рік тому

    Any plans to integrate in version 6?

  • @SiBex_ovh
    @SiBex_ovh Рік тому

    I can integrate this with Radius (Acrive Directory > NPS) ?
    I can create a firewall rules for separate ZT users ?

    • @mikrotik
      @mikrotik  Рік тому

      Yes, in the ZT portal there is a firewall section called "Flow rules" where you can define a lot of interesting restrictons.

  • @throwawayaccount838
    @throwawayaccount838 Рік тому +1

    Day 2 of asking Mikrotik to make a tutorial for their usermanager :)

    • @mikrotik
      @mikrotik  Рік тому +2

      If we do, we will do it for user manager in v7

    • @throwawayaccount838
      @throwawayaccount838 Рік тому +1

      @@mikrotik Yes please ❤ because the wiki is lacking information and there isn't alot of info on the forums

  • @JensJarke
    @JensJarke Рік тому

    WHat are the pro's con's comparing to wireguard?

  • @Mensan1960
    @Mensan1960 Рік тому

    CHR support? Someday? It’s in the release notes. But when?

  • @kennymilestech1576
    @kennymilestech1576 Рік тому

    Dear, @Mikrotik, I have tried installing zerotier on my mikrotik CCR1009-7G-1C-1S+ i have failed is there a way of going about it. Have tried two methods, upgrading to RouterOs 7.7 , have also tried uploading it from the extra packages. To no avail. What am i missing here.🤔🤔

  • @edekedkowski5952
    @edekedkowski5952 8 місяців тому

    Is it possible to install the Zerothier package on the model: MIKROTIK HAP AC2 (RBD52G-5HACD2HND-TC) where the processor architecture is: ARM32 bit?

  • @sweatbandandy
    @sweatbandandy Рік тому +2

    Do you have a date for releasing ZT for CHR on x86?

    • @mikrotik
      @mikrotik  Рік тому

      It’s only planned for ARM

    • @SteveOswald1993
      @SteveOswald1993 Рік тому +1

      @@mikrotik Are you kidding me? Why is there no integration planned in the CHR? In my opinion, ZeroTier is an important function for the CHR.

  • @brianjumandiema6406
    @brianjumandiema6406 Рік тому +1

    Can I use zerotier to send API commands to NAS behind private network ?

    • @mikrotik
      @mikrotik  Рік тому

      Of course. It makes possible to communicate between any devices in different networks

  • @rizwanarasheed
    @rizwanarasheed Рік тому

    What is the work-around if some country's government blocks access to the Zerotier web site / portal?

  • @antol8419
    @antol8419 10 місяців тому

    Dear, @Mikrotik, I have tried installing zerotier on my mikrotik crs326 ARM device with routeros version 7.11.2, i load the package and when i reboot the device on the next start i don't see the menu of zerotier...where is the problem?

  • @mactv7342
    @mactv7342 Рік тому

    will this work on my Haplite sir?

  • @markbonnici7134
    @markbonnici7134 Рік тому +3

    And when do you estimate ZEROTIER becoming available to your TILE CCR units?

    • @mikrotik
      @mikrotik  Рік тому +1

      Only ARM. CCR is also ARM now.

    • @markbonnici7134
      @markbonnici7134 Рік тому +2

      @@mikrotik Fair enough. But you have a legion of Tilera CCR units out there, a lot of which are quite recent, that you have condemned as out of the ZEROTIER game .. A quick search on your site for routers based on TILE (using the filter) still shows up the following Ethernet routers - CCR1009-7G-1C-PC, CCR1009-7G-1C-1S+, CCR1009-7G-1C-1S+PC, CCR1016-12G, CCR1016-12S-1S+, CCR1036-12G-4S, CCR1036-8G-2S+, CCR1036-12G-4S-EM, CCR1036-8G-2S+EM, CCR1072-1G-8S+.

    • @mikrotik
      @mikrotik  Рік тому

      Yes, but some of the new features are developed for newer models only

    • @forgaoqiang
      @forgaoqiang Рік тому +2

      @@mikrotik Why not x86,that should be the easist one, or just for FINANCIAL concern?

    • @thegorn
      @thegorn Рік тому

      TILE is dead. RIP. Shed a tear and move on.

  • @camtex
    @camtex 10 місяців тому

    Hi can somebody help me? when i try to apply the 2 comands for firewall I get the message "no such item"

  • @IsaacOliveiraRibeiro
    @IsaacOliveiraRibeiro Рік тому +1

    Great! Every routerboards that I used in my customer's are RB750Gr3. So now, I will need to buy a new RB ARM model to each customer to user this feature. Congratulations Mikrotik!!

    • @mikrotik
      @mikrotik  Рік тому +2

      For each purpose, an appropriate hardware is needed. Lower end devices could not have enough resources for all more advanced features.

    • @ratowniknaemigracji6537
      @ratowniknaemigracji6537 Рік тому +3

      It's not MTs fault really - the ZT provides the client and decides what CPUs are supported.

    • @kchiem
      @kchiem Рік тому

      @@mikrotik What do you recommend that's comparable to the HEX's performance/price, that can run ZT?

    • @mikrotik
      @mikrotik  Рік тому

      RB3011 is great and more affordable, there is also RB4011 and RB5009 but more expensive. hAP ac² is cheaper, has wireless, but has less ports.

    • @kchiem
      @kchiem Рік тому +2

      @@mikrotik HEX/HEX S MSRP is $60/80. All the RB models you mentioned have MSRP between $180-220. MSRP for the HAP AC2 is $80. And both HEX and HAP AC2 have 5 ethernet ports, what do you mean it has less ports? I guess the only thing that meets the criteria I asked about is the HAP AC2.
      It's too bad the CCR1000 series can't run ZT either.

  • @geroge.jbradley9651
    @geroge.jbradley9651 2 місяці тому

    Am using mikrotik rb951 ver 6.43.8 where can i find Zerotier package arm64 for it? Please anyone SOS.....

  • @EthanDavids
    @EthanDavids Рік тому

    What is the cheapest RB that I can run ZeroTier on?

    • @mikrotik
      @mikrotik  Рік тому

      mikrotik.com/product/hap_ax_lite
      mikrotik.com/product/hap_ac2

  • @k4qdex
    @k4qdex Рік тому +2

    i used it on my hap ac3 but the speed was bad. did you improve it?

    • @user-wu4cw5ed5w
      @user-wu4cw5ed5w Рік тому

      I use it on a hap ac3 and its throughout is as max as ISP could give me

    • @unaibas4676
      @unaibas4676 Рік тому

      same here with any arm hardware. speed very slow only when i install zt on mikrotik and push the lan route in zt web gui. if i install zt agent directly in every workstation without routes then works fine. any ideas??

    • @user-wu4cw5ed5w
      @user-wu4cw5ed5w Рік тому

      @@unaibas4676 I configured a controller node within the router itself +bridged network, it does the job for me without any bottlenecks

  • @Manjaks
    @Manjaks 4 місяці тому

    can you install ZT on v 6.49.13 mikrotik router ?

  • @proeatalk
    @proeatalk Рік тому +1

    Will it be available for CHR on x86?

    • @mikrotik
      @mikrotik  Рік тому

      ARM only

    • @proeatalk
      @proeatalk Рік тому

      @@mikrotik why this limitation? how it can be implemented on x86?

    • @proeatalk
      @proeatalk Рік тому

      @@mikrotik do you have any plans? or advices?

    • @mikrotik
      @mikrotik  Рік тому

      My advice is to get an ARM based MikroTik device to have all the latest features and best performance. A lof of effort is going into development for ARM now.

    • @proeatalk
      @proeatalk Рік тому +1

      @@mikrotik the problem is that CHR is in the data center and I can’t place arm device here

  • @nur76n
    @nur76n Рік тому +2

    I've noticed in 7.2.1 that ZeroTier used 25% of CPU on HAP AC^3, even there was no traffic in that interface. Did someone else noticed that?

    • @mikrotik
      @mikrotik  Рік тому +2

      Under heavy traffic load or also when idle? It shows 0.1% CPU at most in my device when looking in Tool Profile

    • @nur76n
      @nur76n Рік тому +1

      @@mikrotik That was when idle. Then when I turned off ZeroTier interface CPU usage decreased to 1-2%. Now, on 7.5 it's working fine.

  • @cristianarias7426
    @cristianarias7426 Рік тому

    CCR Tile?

  • @a3k749
    @a3k749 Рік тому

    ✔ 'Allow Managed'

  • @biguser7
    @biguser7 6 місяців тому

    Please update the version of ZT in the Mikrotik package. The current version of ZT is now 1.12.2, and in Mikrotik it is still 1.10.3

  • @mrtesla2457
    @mrtesla2457 Рік тому

    I followed this video exactly. I can see my router and desktop in zerotier central, they have assigned ips, I did the routing correct and added the firewall rule. Yet.. I cannot ping my router from my remote desktop, nor does it pass any traffic. Anyone else run into this problem? Thanks in advance.

    • @mikrotik
      @mikrotik  Рік тому +1

      Send us your RIF file to support@mikrotik.com and we will check

  • @marcosx86
    @marcosx86 Рік тому

    What about Zerotier package for 6.48.x?

    • @mikrotik
      @mikrotik  Рік тому +1

      There is no more development on v6, all new features are added only to v7

  • @KonstantinovAG
    @KonstantinovAG Рік тому

    No support on CHR - no have sense for use zerotier in production ...

  • @markit5866
    @markit5866 8 місяців тому

    I get stuck on status "Requesting_Configuration", any solution?

    • @copinha_online
      @copinha_online 3 місяці тому

      também estou nessa situação. você conseguiu resolver?

  • @aliismael350
    @aliismael350 Рік тому

    Mikrotik HAP AC2 (Arm) zerotier not connecting.
    Mikrotik setup totally in bridge mode and no firewall rules. Zerotier online on device for a day then it still shows connected in the Zerotier panel but cannot ping to device or from device. disabling zerotier instance and re enabling it only show requesting information private. deleting instance has the same effect. I can only upgrade and after the restart it will re connect for one more day. after that I will need to downgrade the O.S (From 7.6 to 7.4.1) re install zerotier and then it connects again. I suspect network issues as I have the same problems on other of the same carrier on windows 10 and windows 11. Those however I have a task scheduler to disable service and re enable after 15min which then works. However not all clients on same carrier have the issue. I have multiple other clients using same Mikrotik or windows clients that work without problems. carrier support just says the do not have anything that can cause this problem.

  • @gsmseltech4557
    @gsmseltech4557 Рік тому

    No support on gr3

  • @gabrielarcanjo3804
    @gabrielarcanjo3804 Рік тому

    I dоwnloaded everything is okay

  • @MrAminas1984
    @MrAminas1984 Рік тому

    develop for x86 plzzzzzz

  • @mondy-chan
    @mondy-chan Рік тому +1

    using winbox on macos and yet no official release

    • @mikrotik
      @mikrotik  Рік тому

      Using Wine64. We have a video about it. Works great

    • @mondy-chan
      @mondy-chan Рік тому

      @@mikrotik gotcha

  • @wreckedzilla
    @wreckedzilla Рік тому

    no. have not.

  • @Problembaer4
    @Problembaer4 Рік тому

    I see no sense using ZT? I can do the same with any VPN and WITHOUT having a Man-in-the-Middle (ZT) which Hole-Punches any Firewall.

    • @mikrotik
      @mikrotik  Рік тому +1

      Because of nearly no configuration needed - simple. Also, how will you do the same with a VPN if both networks have private dynamic IP addresses?

  • @nickdefrancisis
    @nickdefrancisis Рік тому

    Need mutlipath mikrotik

  • @Saeglopur89
    @Saeglopur89 Рік тому

    You don't listen to audio which is published - please use something like Elgato if you don't edit audio and use oversensitive microphones. So many videos are ruined here :/

    • @mikrotik
      @mikrotik  Рік тому

      What exactly is the problem? The audio sounds fine on several types of devices - our studio monitors, a laptop, a regular PC with a Bluetooth speaker. Not sure what you mean..?

  • @crispyfacev2458
    @crispyfacev2458 6 місяців тому

    es ieliku ieksa to zerotier.npk un restarteju ruteri bet man nav veljoprojam zerotier tab