Securing MikroTik Management with Cloudflare Zero Trust (Part 1

For years, the normal answer was a VPN with a management network. VPNs work well, but they require another server, another set of credentials, another client to maintain, and another service that can break during upgrades. With Cloudflare Zero Trust, instead of opening management ports to the Internet, the router stays on a private network … Read more

Securing MikroTik Management with Cloudflare Zero Trust (Part 1)

Architecture diagram for managing a MikroTik router through Cloudflare Zero Trust, Cloudflare Access, Cloudflare Tunnel, cloudflared, and a management VLAN.

I, due to recent SSH vulnerabilities in MikroTik, figured this series of articles would be relevant. The router may have strong passwords and firewall filters, but those services still receive constant login attempts from automated scanners. For years, the normal answer was a VPN with a management network. VPNs work well, but they require another … Read more

BGP MED: Controlling Which Entry Point Another Network Uses

Let’s look at another BGP attribute, the Multi-Exit Discriminator, or MED. Two networks may interconnect in more than one location, and MED lets you attach a preference to the routes you advertise. An ISP might connect to the same upstream in Indianapolis and Chicago while advertising the same prefixes at both locations. The upstream now … Read more

Mikrotik 7.23/7.24 and LTE

The following is from the 7.23.7 changelog. What’s new in 7.23.7 (2026-09-16): *) lte – prevent the modem firmware from being deleted for RBSXTLTE3-7, EC25-EU&KNe, EG25-G&KNe, EC25-EU&SXTsq, EG25-G&SXTsq (introduced in 7.23.6); If you have already upgraded to 7.23.6 or 7.24.3, follow these steps to restore LTE functionality on affected devices: For more details, see:https://forum.mikrotik.com/t/warning-lte-interface-stops-working-after-upgrade-to-7-23-6-7-24-3

A first-hand forensic walkthrough of a real router compromise

What it looks like when an intruder tries to make your own router work against you. A note before we start: Anything in this post that could identify my network, my organization, or my router’s real hostname and IP address has been redacted or made generic. The attacker’s own infrastructure, such as IP addresses, ports, … Read more

An open Letter about the implosion of Cambium Networks

To the product teams, support organization, partners, and remaining employees of Cambium Networks: First and foremost, my heart goes out to you during these tough, uncertain times. Over the past couple of years, Cambium has taken a beating in the forums and groups. Those of us who understand how the world works always knew that … Read more

What N, N+1, 2N, and 2(N+1) Mean in a Data Center

Diagram comparing N, N+1, and N+2 data center capacity

Have you ever looked at a data center marketing slick and wondered what N, N+1, 2N, and 2(N+1) actually mean? The main thing they tell you is how many components can fail before the system drops below the capacity needed to support the load. When I evaluate a data center, I want to know what … Read more

LibreQoS 2.2 is out

LibreQoS 2.2 ChangeLog LibreQoS 2.2: What Changed Since 2.1 LibreQoS 2.2 guides operators from a fresh install through admin creation, interface selection, network preview, and service startup in the browser. Operators can build topology visually, shape subscribers created from RADIUS sessions, and compare queued demand with traffic that actually crossed the wire. This changelog covers … Read more

Packets Down Range #42:Verizon, H5 tour, China ROAs

Rain Rain Rain. Indiana has been rained on this week. Things are flooded but the Internet still works! So fire up your terminal, and let’s head down range. Patreon Subscribers can view additional news here. It’s only $3 a month. It’s like buying me a Red Bull once a month. Interconnection & Data Center News•Inside … Read more