Julian Wecke
Practical Security Strategist, Engineer, Architect and Technical Debt Advisor.
Interested in effective cybersecurity. No snake oil. No checkbox security.
To make a mistake is human but to really fuck things up you need a computer.
hey fellow #MikroTik enthusiasts,
Lately i have consolidated some network infrastructure. Mainly removing dedicated firewall systems where they did not much more than filtering traffic. A task a RouterOS system can do with ease. But when it comes to High-Availability setups there is a caveat: the old systems kept ruleset, VRRP interfaces, virtual IPs, etc. in-sync. Using a more flexible system, like RouterOS, it's up to YOU to keep the configurations working with each other.
To tackle this challenge I’ve created MikroSync - https://codeberg.org/securitym0nkey/MikroSync
- a tool to synchronize RouterOS configurations
- can run directly on the Router (as a container)
- OpenSource - MIT license
Consider #MikroSync early beta - though I’ve started to use it in a simple production environment.
Happy for any feedback and contributions.
2 hours between me reporting a bug to @mikrotik@mikrotik.social and them confirming that they were able to reproduce it in their labs. That's an awesome turn around time.
@decryption@aus.social For that price you should provide the raspberry hardware as well. Also the overhead of shipping raspberries around and the support of replacing defects one individually sounds like a nightmare. If you have a bunch of them ready in your rack you could automatically deploy and deliver them to your customers.
Many of your systems will not have the algif_aead and af_alg kernel modules loaded prior exploiting the #copyfail vulnerability. So checking your kernel logs for "NET: Registered PF_ALG protocol family" is a good #threathunting for today. #cve_2026_31431 #siem