Securing MikroTik Management with Cloudflare Zero Trust (Part 1
For years, the normal answer was a VPN with a management network. VPNs work well, but they require another server, another set of credentials, another client to maintain, and another service that can break during upgrades. With Cloudflare Zero Trust, instead of opening management ports to the Internet, the router stays on a private network … Read more
Securing MikroTik Management with Cloudflare Zero Trust (Part 1)
I, due to recent SSH vulnerabilities in MikroTik, figured this series of articles would be relevant. The router may have strong passwords and firewall filters, but those services still receive constant login attempts from automated scanners. For years, the normal answer was a VPN with a management network. VPNs work well, but they require another … Read more
BGP MED: Controlling Which Entry Point Another Network Uses
Let’s look at another BGP attribute, the Multi-Exit Discriminator, or MED. Two networks may interconnect in more than one location, and MED lets you attach a preference to the routes you advertise. An ISP might connect to the same upstream in Indianapolis and Chicago while advertising the same prefixes at both locations. The upstream now … Read more
Mikrotik 7.23/7.24 and LTE
The following is from the 7.23.7 changelog. What’s new in 7.23.7 (2026-09-16): *) lte – prevent the modem firmware from being deleted for RBSXTLTE3-7, EC25-EU&KNe, EG25-G&KNe, EC25-EU&SXTsq, EG25-G&SXTsq (introduced in 7.23.6); If you have already upgraded to 7.23.6 or 7.24.3, follow these steps to restore LTE functionality on affected devices: For more details, see:https://forum.mikrotik.com/t/warning-lte-interface-stops-working-after-upgrade-to-7-23-6-7-24-3
A first-hand forensic walkthrough of a real router compromise
What it looks like when an intruder tries to make your own router work against you. A note before we start: Anything in this post that could identify my network, my organization, or my router’s real hostname and IP address has been redacted or made generic. The attacker’s own infrastructure, such as IP addresses, ports, … Read more
An open Letter about the implosion of Cambium Networks
To the product teams, support organization, partners, and remaining employees of Cambium Networks: First and foremost, my heart goes out to you during these tough, uncertain times. Over the past couple of years, Cambium has taken a beating in the forums and groups. Those of us who understand how the world works always knew that … Read more
What N, N+1, 2N, and 2(N+1) Mean in a Data Center
Have you ever looked at a data center marketing slick and wondered what N, N+1, 2N, and 2(N+1) actually mean? The main thing they tell you is how many components can fail before the system drops below the capacity needed to support the load. When I evaluate a data center, I want to know what … Read more
Alta Labs: AP7-Pro 3.0k and AP6* 2.4k Released
AP7-Pro 3.0k and AP6* 2.4k Released
LibreQoS 2.2 is out
LibreQoS 2.2 ChangeLog LibreQoS 2.2: What Changed Since 2.1 LibreQoS 2.2 guides operators from a fresh install through admin creation, interface selection, network preview, and service startup in the browser. Operators can build topology visually, shape subscribers created from RADIUS sessions, and compare queued demand with traffic that actually crossed the wire. This changelog covers … Read more
Multi-Core Fiber: Several Optical Cores Inside One Strand
Multi-core fiber places several independent optical cores inside one standard 125-micron cladding. It increases channel density, but it also requires different connectors, splicing methods, and testing procedures.
Alta Labs AP7 Pro: Quick Look and First Impressions
I am getting back to recording some videos, and this time I am taking a quick look at the Alta Labs AP7 Pro. This is not meant to be a full review or performance test. I wanted to get the AP7 Pro on camera, show the hardware, and give everyone a closer look at the … Read more