Skip to content

Instantly share code, notes, and snippets.


Ken Marfilla marfillaster

View GitHub Profile
marfillaster /
Last active Aug 15, 2022
Running Unifi Network Controller as a container in MikroTik ROSv7 RB5009


  • USB flash drive - this is where the container filesystem will be persisted

Set-up docker bridge network

/interface bridge add name=docker

Set-up veth to be used by container

marfillaster /
Last active Sep 15, 2022
Converge F670L Bridge mode
  1. Go to Network - WAN - WAN Connection WAN Connection
  2. Right click Type Route dropdown select and click "Inspect" in the context menu.
    In console, run the code below:
    document.getElementById('Frm_mode').options[document.getElementById('Frm_mode').options.selectedIndex].setAttribute('value', 'BRIDGE');
  3. Input New Connection Name. Example: Bridge. Click Create.
marfillaster /
Last active Sep 6, 2022
Ubiquiti UniFi Guest SSID on VLAN using MikroTik router hybrid port
  • Main network on
  • Guest network on VLAN20
  • UniFi AP is connected to a MikroTik router ether2 via DHCP assignment
  • UniFi AP can be managed on via main network
  • MikroTik initially on default configuration
/interface bridge port
add bridge=bridge interface=ether2
marfillaster / router.cfg
Last active Sep 25, 2022
MikroTik RouterOS v7 dual DHCP WAN recursive failover w/ PCC load-balancing; and recursive ECMP
View router.cfg
# feb/11/2022 11:00:55 by RouterOS 7.2rc3
# software id = 9QK9-C798
# model = RB5009UG+S+
# serial number = XXXXXXXXXX
/ip settings set allow-fast-path=no
/interface bridge add admin-mac=FF:FF:FF:FF:FF:FF auto-mac=no name=bridge
marfillaster /
Last active Aug 9, 2021
yubikey ssh ykcs11 in osx
# ~/.ssh/config
Host *
    PKCS11Provider /usr/local/lib/libykcs11.dylib

brew install ykman yubico-piv-tool

# Generate key
ykman piv keys generate -aRSA2048 --pin-policy ONCE --touch-policy NEVER 9a public.pem
marfillaster /
Last active Jun 18, 2021
PLDT VDSL HG180U notes

Bridge mode

This guide will enable bridge mode in ethernet port 3 only. Wifi and ethernet ports 1 and 2 will remain in route mode.

Use cases:

  • Avoid double NAT.
  • Improve WiFi performance by using dedicated and/or more modern equipment.
marfillaster / gist:d34bd199b9e265ccd74af6d31fd9df85
Last active Jan 6, 2022
Mikrotik IPv6 dns-over-https doh cloudflare google
View gist:d34bd199b9e265ccd74af6d31fd9df85
/ipv6 dhcp-server option
add code=23 name=recursivens6 value=0xfd000000000000000000000000000001
/ipv6 dhcp-server
add dhcp-option=recursivens6 interface=bridge lease-time=30m name=dhcp6
/ipv6 pool
add name=ULA-pool6 prefix=fd00::/64 prefix-length=64

Keybase proof

I hereby claim:

  • I am marfillaster on github.
  • I am marfillaster ( on keybase.
  • I have a public key whose fingerprint is 9828 F7AA 8E16 009E A8FB 5913 3798 FD80 20D3 229E

To claim this, I am signing this object:

# Script to backup Pantheon sites and copy to Amazon s3 bucket
# Requirements:
# - Pantheon terminus cli
# - Valid terminus machine token
# - Amazon aws cli
# - s3 cli access and user configured
View gist:bc79f4dc789f814f81c7b05060325469


wsl$ ifconfig eth0 | grep 'inet '
        inet  netmask  broadcast

PS Admministrator> netsh interface portproxy add v4tov4 listenport=19000 listenaddress= connectport=19000 connectaddress=
PS Admministrator> netsh interface portproxy add v4tov4 listenport=19001 listenaddress= connectport=19001 connectaddress=