MikroTik RouterOS 6.44betaX (Testing)
Подробное описание изменений в MikroTik RouterOS 6.44betaX (Testing). Официальный список исправленных ошибок, добавленного функционала и прочих доработок. Дата выхода первого набора изменений – 11 сентября 2018, дата выхода последнего набора изменений – 8 февраля 2019.
Полезные материалы по MikroTik
Чек-лист по настройке MikroTik Проверьте свою конфигурацию по 28-ми пунктам. Подходит для RouterOS v6 и v7. Дата публикации: 2023.
На Telegram-канале Mikrotik сэнсей можно получить доступ к закрытой информации от официального тренера MikroTik. В апреле и мае 2023 будут разбираться темы Wi-Fi и QoS. Подписывайтесь
MikroTik RouterOS 6.44beta75
Дата выхода:8 февраля 2019
Важные комментарии:
Backup before upgrade! Due to major IPsec configuration changes in RouterOS v6.44beta39+ (see changelog below), it is advised to make a backup before upgrading. Regular downgrade will still be possible as long as no changes in IPsec peer menu are done.
Важные изменения:
- cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);
- ipsec - added new "identity" menu with common peer distinguishers;
- ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;
- ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu;
- radius - initial implementation of RadSec (Radius communication over TLS);
- speedtest - added "/tool speed-test" for ping latency, jitter, loss and TCP and UDP download, upload speed measurements (CLI only);
- telnet - do not allow to set "tracefile" parameter;
- upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";
- upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions.
Изменения:
- ipsec - added new "identity" menu with common peer distinguishers;
- winbox - improvements in connection handling to router with open winbox service (CVE-2019–3924);
- bridge - fixed log message when hardware offloading is being enabled;
- bridge - fixed packet forwarding with enabled DHCP Snooping and Option 82;
- bridge - fixed system's identity change when DHCP Snooping is enabled (introduced in v6.44beta61);
- bridge - improved packet handling when hardware offloading is being disabled;
- certificate - show digest algorithm used in signature;
- chr - distribute NIC queue IRQ's evenly across all CPUs;
- chr - fixed IRQ balancing when using more than 32 CPUs;
- crs3xx - fixed packet forwarding through SFP+ ports when using 100Mbps link speed;
- crs3xx - fixed SFP+ linking using 1.25G SFP modules (introduced in v6.44beta39);
- dhcpv6-server - fixed missing gateway for binding's network if RADIUS authentication was used;
- dhcpv6-server - show "client-address" parameter for bindings;
- ethernet - added "tx-rx-1024-max" counter to Ethernet stats;
- ethernet - fixed packet forwarding when SFP interface is disabled on hEX S;
- fetch - added option to specify multiple headers under "http-header-field", including content type;
- fetch - improved stability when using HTTP mode;
- fetch - removed "http-content-type" parameter;
- gps - increase precision for dd format;
- hotspot - added "https-redirect" under server profiles;
- ike2 - retry RSA signature validation with deduced digest from certificate;
- ipsec - require write policy for key generation;
- kidcontrol - use "/128" prefix-length for IPv6 addresses;
- lldp - fixed missing capabilities fields on some devices;
- lte - added multiple APN support for R11e-4G;
- lte - fixed passthrough DHCP address forward when other address is acquired from operator;
- lte - improved SIM7600 initialization after reset;
- lte - query "cfun" on initialization;
- lte - require write policy for at-chat;
- lte - update firmware version information after R11e-LTE/R11e-4G firmware upgrade;
- ntp-client - fixed "dst-active" and "gmt-offset" being updated after synchronization with server;
- ppp - fixed dynamic route creation towards VPN server when "add-default-route" is used;
- quickset - fixed "country" parameter not properly setting regulatory domain configuration;
- rb4011 - fixed SFP+ interface full duplex and speed parameter behavior;
- rb4011 - improved SFP+ interface linking to 1Gbps;
- sfp - fixed possible reboot loop when inserting SFP modules in CRS328-4C-20S-4S+ (introduced in v6.44beta61);
- smb - fixed macOS clients not showing share contents;
- smb - fixed possible buffer overflow;
- smb - fixed Windows 10 clients not able to establish connection to share;
- snmp - fixed "rsrq" reported precision;
- snmp - report ifSpeed 0 for sub-layer interfaces;
- switch - added comment field to switch ACL rules;
- tr069-client - added "connection-request-port" parameter (CLI only);
- usb - improved USB device powering on startup for hAP ac^2 devices;
- usb - increased default power-reset timeout to 5 seconds;
- userman - added first and last name fields for signup form;
- w60g - fixed disconnection issues in PtMP setups;
- winbox - renamed "Default AP Tx Rate" to "Default AP Tx Limit";
- winbox - renamed "Default Client Tx Rate" to "Default Client Tx Limit";
- winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
- wireless - improved antenna gain setting for devices with built in antennas;
- wireless - improved connection stability for new model Apple devices;
- wireless - improved system stability when scanning for other networks;
- wireless - show "installation" parameter when printing configuration.
Другие изменения относительно 6.43.8:
- bgp - properly update keepalive time after peer restart;
- bridge - added option to monitor fast-forward status;
- bridge - count routed FastPath packets between bridge ports under FastPath bridge statistics;
- bridge - disable fast-forward when using SlowPath features;
- bridge - fixed BOOTP packet forwarding when DHCP Snooping is enabled;
- bridge - fixed DHCP Option 82 parsing when using DHCP Snooping;
- bridge - fixed packet forwarding when changing MSTI VLAN mappings;
- bridge - fixed possible memory leak when using MSTP;
- bridge - improved packet processing when bridge port changes states;
- btest - added multithreading support for both UDP and TCP tests;
- btest - added warning message when CPU load exceeds 90% (CLI only);
- capsman - always accept connections from loopback address;
- certificate - added support for multiple "Subject Alt. Names";
- certificate - enabled RC2 cipher to allow P12 certificate decryption;
- certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided;
- chr - assign interface names based on underlying PCI device order on KVM;
- chr - improved system stability when insufficient resources are allocated to the guest;
- cloud - added "ddns-update-interval" parameter;
- cloud - do not reuse old UDP socket if routing changes are detected;
- cloud - ignore "force-update" command if DDNS is disabled;
- cloud - improved DDNS service disabling;
- cloud - made address updating faster when new public address detected;
- conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter);
- console - renamed IP protocol 41 to "ipv6-encap";
- console - updated copyright notice;
- crs317 - fixed packet forwarding when LACP is used with hw=no;
- crs317 - fixed TX not working on sfp-sfpplus9 interface (introduced in v6.40beta12);
- crs328 - fixed SFP+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);
- crs3xx - fixed slow bootup, upgrade and SFP status read (introduced in v6.44beta20);
- crs3xx - improved fan control stability;
- crs3xx - improved stability when adding ACL rules on CRS326 and CRS328 devices (introduced in 6.44beta39);
- defconf - fixed configuration not generating properly on upgrade;
- defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;
- defconf - fixed IPv6 link-local address range in firewall rules;
- dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 DHCP servers to control dynamic lease/binding behaviour;
- dhcp - properly load DHCP configuration if options are configured;
- dhcpv4-server - added "parent-queue" parameter (CLI only);
- dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;
- dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;
- dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client;
- dhcpv6-server - allow to add DHCPv6 server with pool that does not exist;
- dhcpv6-server - improved DHCPv6 server stability when using "print" command;
- discovery - detect proper slave interface on bounded interfaces;
- discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;
- discovery - send master port in "interface-name" parameter;
- discovery - show neighbors on actual bridge port instead of bridge itself for LLDP;
- e-mail - added info log message when e-mail is sent successfully;
- ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;
- ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);
- ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;
- ethernet - improved per core ethernet traffic classificator on mmips devices;
- export - fixed "silent-boot" compact export;
- fetch - added "http-header-field" parameter;
- fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20);
- fetch - fixed "without-paging" option;
- gps - moved "coordinate-format" from "monitor" command to "set" parameter;
- health - improved fan control stability on CRS328-24P-4S+RM;
- ike1 - fixed "rsa-key" authentication (introduced in v6.44beta);
- ike2 - added option to specify certificate chain;
- ike2 - added peer identity validation for RSA auth (disabled after upgrade);
- ike2 - allow to match responder peer by "my-id=fqdn" field;
- ike2 - fixed local address lookup when initiating new connection;
- ike2 - improved subsequent phase 2 initialization when no childs exist;
- ike2 - properly handle certificates with empty "Subject";
- ike2 - send split networks over DHCP (option 249) to Windows initiators if DHCP Inform is received;
- ike2 - show weak pre-shared-key warning;
- ipsec - accept only valid path for "export-pub-key" parameter in "key" menu;
- ipsec - added account log message when user is successfully authenticated;
- ipsec - added basic pre-shared-key strength checks;
- ipsec - added new "remote-id" peer matcher;
- ipsec - allow to specify single address instead of IP pool under "mode-config";
- ipsec - fixed active connection killing when changing peer configuration;
- ipsec - fixed all policies not getting installed after startup (introduced in v6.43.8);
- ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);
- ipsec - hide empty prefixes on "peer" menu;
- ipsec - improved invalid policy handling when a valid policy is uninstalled;
- ipsec - made dynamic "src-nat" rule more specific;
- ipsec - made peers autosort themselves based on reachability status;
- ipsec - moved "profile" menu outside "peer" menu;
- ipsec - properly detect AES-NI extension as hardware AEAD;
- ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;
- kidcontrol - added IPv6 support;
- kidcontrol - added "reset-counters" command for "device" menu (CLI only);
- kidcontrol - added statistics web interface for kids (http://router.lan/kid-control);
- kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);
- kidcontrol - dynamically discover devices from DNS activity;
- kidcontrol - fixed validation checks for time intervals;
- kidcontrol - properly detect time zone changes;
- l2tp - fixed IPsec secret not being updated when "ipsec-secret" is changed under L2TP client configuration;
- lcd - made "pin" parameter sensitive;
- led - fixed default LED configuration for RBSXTsq-60ad;
- led - fixed default LED configuration for wAP 60G AP devices;
- led - fixed PWR-LINE AP Ethernet LED polarity ("/system routerboard upgrade" required);
- lte - added additional ID support for Novatel USB730L modem;
- lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);
- lte - added "ecno" field for "info" command;
- lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);
- lte - added initial support for multiple APN for R11e-4G (new modem firmware required);
- lte - added support for JioFi JMR1040 modem;
- lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;
- lte - fixed DHCP IP acquire in 3G mode for r11e-lte (introduced in v6.44beta54);
- lte - fixed DHCP IP acquire (introduced in v6.43.7);
- lte - fixed DHCP relay packet forwarding when in passthrough mode;
- lte - fixed IPv6 activation for R11e-LTE-US modems;
- lte - fixed Jaton/SQN modems preventing router from booting properly;
- lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;
- lte - fixed missing running (R) flag for Jaton LTE modems;
- lte - fixed reported "rsrq" precision (introduced in v6.43.8);
- lte - improved compatibility for Alt38xx modems;
- lte - improved SimCom 7100e support;
- netinstall - do not show kernel failure critical messages in the log after fresh install;
- port - improved "remote-serial" TCP performance in RAW mode;
- ppp - added "at-chat" command;
- profiler - classify kernel crypto processing as "encrypting";
- profile - removed obsolete "file-name" parameter;
- proxy - removed port list size limit;
- radius - implemented Proxy-State attribute handling in CoA and disconnect requests;
- rb3011 - implemented multiple engine IPsec hardware acceleration support;
- rbm33g - improved stability when used with some USB devices;
- romon - improved reliability when processing RoMON packets on CHR;
- routerboard - removed "RB" prefix from PWR-LINE AP devices;
- routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";
- sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;
- snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;
- snmp - changed fan speed value type to Gauge32;
- snmp - fixed w60g station table;
- snmp - removed "rx-sector" ("Wl60gRxSector") value;
- snmp - report bridge ifSpeed as "0";
- ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);
- ssh - added error log message when key exchange fails;
- ssh - close active SSH connections before IPsec connections on shutdown;
- ssh - fixed non-interactive shell not returning all output (introduced in v6.44);
- ssh - fixed public key format compatibility with RFC4716;
- ssh - fixed single command execution (introduced in v6.44beta9);
- supout - fixed "poe-out" output not showing all interfaces;
- switch - fixed ACL rules on IPQ4018 devices;
- system - accept only valid path for "log-file" parameter in "port" menu;
- system - removed obsolete "/driver" command;
- tr069-client - added "check-certificate" parameter to allow communication without certificates;
- tr069-client - added support for InformParameter object;
- tr069-client - fixed certificate verification for certificates with IP address;
- tr069-client - fixed HTTP cookie getting duplicated with the same key;
- tr069-client - increased reported "rsrq" precision;
- traceroute - improved stability when sending large ping amounts;
- traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;
- tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with DNS as "remote-address";
- upgrade - made security package depend on DHCP package;
- usb - improved power-reset error message when no bus specified on CCR1072-8G-1S+;
- userman - show redirect location in error messages;
- user - require "write" permissions for LTE firmware update;
- vrrp - made "password" parameter sensitive;
- w60g - added "10s-average-rssi" parameter to align mode (CLI only);
- w60g - added align mode "/interface w60g align" (CLI only);
- w60g - fixed scan in bridge mode;
- w60g - improved PtMP performance;
- w60g - improved reconnection detection;
- w60g - improved "tx-packet-error-rate" reading;
- w60g - renamed disconnection message when license level did not allow more connected clients;
- w60g - renamed "frequency-list" to "scan-list";
- watchdog - allow specifying DNS name for "send-smtp-server" parameter;
- winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;
- winbox - added "allow-dual-stack-queue" parameter in "IP/DHCP Server" and "IPv6/DHCP Server" menus;
- winbox - added "challenge-password" field when signing certificate with SCEP;
- winbox - added "conflict-detection" parameter in "IP/DHCP Server" menu;
- winbox - added "conflict-detection" parameter in "IP/DHCP server" menu;
- winbox - added "coordinate-format" parameter in LTE interface settings;
- winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;
- winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;
- winbox - added src/dst address and in/out interface list columns to default firewall menu view;
- winbox - added support for dynamic devices in "IP/Kid Control/Devices" tab;
- winbox - allow setting "network-mode" to "auto" under LTE interface settings;
- winbox - allow specifying interface lists in "CAPsMAN/Access List" menu;
- winbox - fixed "IPv6/Firewall" "Connection limit" parameter not allowing complete IPv6 prefix lengths;
- winbox - fixed L2MTU parameter setting on "W60G" type interfaces;
- winbox - fixed "LCD" menu not shown on RB2011UiAS-2HnD;
- winbox - fixed missing w60g interface status values;
- winbox - moved "Too Long" statistics counter to Ethernet "Rx Stats" tab;
- winbox - show "R" flag under "IPv6/DHCP Server/Bindings" tab;
- winbox - show "W60G" wireless tab on wAP 60G AP;
- wireless - added new "installation" parameter to specify router's location;
- wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);
- wireless - improved system stability for all ARM devices with wireless;
- wireless - removed G/N support for 2484MHz in "japan" regulatory domain;
- wireless - report last seen IP address in RADIUS accounting messages;
- wireless - show indoor/outdoor frequency limitations under "/interface wireless info country-info " command.
MikroTik RouterOS 6.44beta61
Дата выхода: 17 января 2019
Важные комментарии:
Backup before upgrade! Due to major IPsec configuration changes in RouterOS v6.44beta39+ (see changelog below), it is advised to make a backup before upgrading. Regular downgrade will still be possible as long as no changes in IPsec peer menu are done.
Важные изменения:
- cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);
- ipsec - added new "identity" menu with common peer distinguishers;
- ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;
- ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu;
- radius - initial implementation of RadSec (Radius communication over TLS);
- speedtest - added "/tool speed-test" for ping latency, jitter, loss and TCP and UDP download, upload speed measurements (CLI only);
- telnet - do not allow to set "tracefile" parameter;
- upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";
- upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions.
Изменения:
- ipsec - added new "identity" menu with common peer distinguishers;
- bridge - fixed BOOTP packet forwarding when DHCP Snooping is enabled;
- certificate - added support for multiple "Subject Alt. Names";
- certificate - enabled RC2 cipher to allow P12 certificate decryption;
- chr - improved system stability when insufficient resources are allocated to the guest;
- console - updated copyright notice;
- crs3xx - fixed slow bootup, upgrade and SFP status read (introduced in v6.44beta20);
- gps - moved "coordinate-format" from "monitor" command to "set" parameter;
- ike1 - fixed "rsa-key" authentication (introduced in v6.44beta);
- ipsec - accept only valid path for "export-pub-key" parameter in "key" menu;
- ipsec - added new "remote-id" peer matcher;
- ipsec - fixed all policies not getting installed after startup (introduced in v6.43.8);
- ipsec - moved "profile" menu outside "peer" menu;
- lcd - made "pin" parameter sensitive;
- led - fixed default LED configuration for RBSXTsq-60ad;
- lte - fixed DHCP IP acquire in 3G mode for r11e-lte (introduced in v6.44beta54);
- lte - fixed reported "rsrq" precision (introduced in v6.43.8);
- profile - removed obsolete "file-name" parameter;
- radius - implemented Proxy-State attribute handling in CoA and disconnect requests;
- rb4011 - improved SFP+ interface linking to 1Gbps;
- ssh - close active SSH connections before IPsec connections on shutdown;
- ssh - fixed public key format compatibility with RFC4716;
- supout - fixed "poe-out" output not showing all interfaces;
- system - accept only valid path for "log-file" parameter in "port" menu;
- system - removed obsolete "/driver" command;
- tr069-client - added "check-certificate" parameter to allow communication without certificates;
- tr069-client - added support for InformParameter object;
- tr069-client - fixed certificate verification for certificates with IP address;
- tr069-client - increased reported "rsrq" precision;
- vrrp - made "password" parameter sensitive;
- winbox - added "allow-dual-stack-queue" parameter in "IP/DHCP Server" and "IPv6/DHCP Server" menus;
- winbox - added "conflict-detection" parameter in "IP/DHCP Server" menu;
- winbox - added "coordinate-format" parameter in LTE interface settings;
- winbox - allow specifying interface lists in "CAPsMAN/Access List" menu;
- winbox - fixed "IPv6/Firewall" "Connection limit" parameter not allowing complete IPv6 prefix lengths;
- winbox - fixed L2MTU parameter setting on "W60G" type interfaces;
- winbox - fixed "LCD" menu not shown on RB2011UiAS-2HnD;
- winbox - moved "Too Long" statistics counter to Ethernet "Rx Stats" tab;
- winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature.
Другие изменения относительно 6.43.8:
- bgp - properly update keepalive time after peer restart;
- bridge - added option to monitor fast-forward status;
- bridge - count routed FastPath packets between bridge ports under FastPath bridge statistics;
- bridge - disable fast-forward when using SlowPath features;
- bridge - fixed DHCP Option 82 parsing when using DHCP Snooping;
- bridge - fixed packet forwarding when changing MSTI VLAN mappings;
- bridge - fixed possible memory leak when using MSTP;
- bridge - improved packet processing when bridge port changes states;
- btest - added multithreading support for both UDP and TCP tests;
- btest - added warning message when CPU load exceeds 90% (CLI only);
- capsman - always accept connections from loopback address;
- certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided;
- chr - assign interface names based on underlying PCI device order on KVM;
- cloud - added "ddns-update-interval" parameter;
- cloud - do not reuse old UDP socket if routing changes are detected;
- cloud - ignore "force-update" command if DDNS is disabled;
- cloud - improved DDNS service disabling;
- cloud - made address updating faster when new public address detected;
- conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter);
- console - renamed IP protocol 41 to "ipv6-encap";
- crs317 - fixed packet forwarding when LACP is used with hw=no;
- crs317 - fixed TX not working on sfp-sfpplus9 interface (introduced in v6.40beta12);
- crs328 - fixed SFP+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);
- crs3xx - improved fan control stability;
- crs3xx - improved stability when adding ACL rules on CRS326 and CRS328 devices (introduced in 6.44beta39);
- defconf - fixed configuration not generating properly on upgrade;
- defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;
- defconf - fixed IPv6 link-local address range in firewall rules;
- dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 DHCP servers to control dynamic lease/binding behaviour;
- dhcp - properly load DHCP configuration if options are configured;
- dhcpv4-server - added "parent-queue" parameter (CLI only);
- dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;
- dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;
- dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client;
- dhcpv6-server - allow to add DHCPv6 server with pool that does not exist;
- dhcpv6-server - improved DHCPv6 server stability when using "print" command;
- discovery - detect proper slave interface on bounded interfaces;
- discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;
- discovery - send master port in "interface-name" parameter;
- discovery - show neighbors on actual bridge port instead of bridge itself for LLDP;
- e-mail - added info log message when e-mail is sent successfully;
- ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;
- ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);
- ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;
- ethernet - improved per core ethernet traffic classificator on mmips devices;
- export - fixed "silent-boot" compact export;
- fetch - added "http-header-field" parameter;
- fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20);
- fetch - fixed "without-paging" option;
- health - improved fan control stability on CRS328-24P-4S+RM;
- ike2 - added option to specify certificate chain;
- ike2 - added peer identity validation for RSA auth (disabled after upgrade);
- ike2 - allow to match responder peer by "my-id=fqdn" field;
- ike2 - fixed local address lookup when initiating new connection;
- ike2 - improved subsequent phase 2 initialization when no childs exist;
- ike2 - properly handle certificates with empty "Subject";
- ike2 - send split networks over DHCP (option 249) to Windows initiators if DHCP Inform is received;
- ike2 - show weak pre-shared-key warning;
- ipsec - added account log message when user is successfully authenticated;
- ipsec - added basic pre-shared-key strength checks;
- ipsec - allow to specify single address instead of IP pool under "mode-config";
- ipsec - fixed active connection killing when changing peer configuration;
- ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);
- ipsec - hide empty prefixes on "peer" menu;
- ipsec - improved invalid policy handling when a valid policy is uninstalled;
- ipsec - made dynamic "src-nat" rule more specific;
- ipsec - made peers autosort themselves based on reachability status;
- ipsec - properly detect AES-NI extension as hardware AEAD;
- ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;
- kidcontrol - added IPv6 support;
- kidcontrol - added "reset-counters" command for "device" menu (CLI only);
- kidcontrol - added statistics web interface for kids (http://router.lan/kid-control);
- kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);
- kidcontrol - dynamically discover devices from DNS activity;
- kidcontrol - fixed validation checks for time intervals;
- kidcontrol - properly detect time zone changes;
- l2tp - fixed IPsec secret not being updated when "ipsec-secret" is changed under L2TP client configuration;
- led - fixed default LED configuration for wAP 60G AP devices;
- led - fixed PWR-LINE AP Ethernet LED polarity ("/system routerboard upgrade" required);
- lte - added additional ID support for Novatel USB730L modem;
- lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);
- lte - added "ecno" field for "info" command;
- lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);
- lte - added initial support for multiple APN for R11e-4G (new modem firmware required);
- lte - added support for JioFi JMR1040 modem;
- lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;
- lte - fixed DHCP IP acquire (introduced in v6.43.7);
- lte - fixed DHCP relay packet forwarding when in passthrough mode;
- lte - fixed IPv6 activation for R11e-LTE-US modems;
- lte - fixed Jaton/SQN modems preventing router from booting properly;
- lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;
- lte - fixed missing running (R) flag for Jaton LTE modems;
- lte - improved compatibility for Alt38xx modems;
- lte - improved SimCom 7100e support;
- netinstall - do not show kernel failure critical messages in the log after fresh install;
- port - improved "remote-serial" TCP performance in RAW mode;
- ppp - added "at-chat" command;
- profiler - classify kernel crypto processing as "encrypting";
- proxy - removed port list size limit;
- rb3011 - implemented multiple engine IPsec hardware acceleration support;
- rbm33g - improved stability when used with some USB devices;
- romon - improved reliability when processing RoMON packets on CHR;
- routerboard - removed "RB" prefix from PWR-LINE AP devices;
- routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";
- sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;
- snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;
- snmp - changed fan speed value type to Gauge32;
- snmp - fixed "rsrq" reported precision;
- snmp - fixed w60g station table;
- snmp - removed "rx-sector" ("Wl60gRxSector") value;
- snmp - report bridge ifSpeed as "0";
- ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);
- ssh - added error log message when key exchange fails;
- ssh - fixed non-interactive shell not returning all output (introduced in v6.44);
- ssh - fixed single command execution (introduced in v6.44beta9);
- switch - fixed ACL rules on IPQ4018 devices;
- tr069-client - fixed HTTP cookie getting duplicated with the same key;
- traceroute - improved stability when sending large ping amounts;
- traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;
- tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with DNS as "remote-address";
- upgrade - made security package depend on DHCP package;
- usb - improved power-reset error message when no bus specified on CCR1072-8G-1S+;
- userman - show redirect location in error messages;
- user - require "write" permissions for LTE firmware update;
- w60g - added "10s-average-rssi" parameter to align mode (CLI only);
- w60g - added align mode "/interface w60g align" (CLI only);
- w60g - fixed scan in bridge mode;
- w60g - improved PtMP performance;
- w60g - improved reconnection detection;
- w60g - improved "tx-packet-error-rate" reading;
- w60g - renamed disconnection message when license level did not allow more connected clients;
- w60g - renamed "frequency-list" to "scan-list";
- watchdog - allow specifying DNS name for "send-smtp-server" parameter;
- winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;
- winbox - added "challenge-password" field when signing certificate with SCEP;
- winbox - added "conflict-detection" parameter in "IP/DHCP server" menu;
- winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;
- winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;
- winbox - added src/dst address and in/out interface list columns to default firewall menu view;
- winbox - added support for dynamic devices in "IP/Kid Control/Devices" tab;
- winbox - allow setting "network-mode" to "auto" under LTE interface settings;
- winbox - fixed missing w60g interface status values;
- winbox - show "R" flag under "IPv6/DHCP Server/Bindings" tab;
- winbox - show "W60G" wireless tab on wAP 60G AP;
- wireless - added new "installation" parameter to specify router's location;
- wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);
- wireless - improved system stability for all ARM devices with wireless;
- wireless - removed G/N support for 2484MHz in "japan" regulatory domain;
- wireless - report last seen IP address in RADIUS accounting messages;
- wireless - show indoor/outdoor frequency limitations under "/interface wireless info country-info " command.
MikroTik RouterOS 6.44beta54
Дата выхода: 7 января 2019
Важные комментарии:
Backup before upgrade! Due to major IPsec configuration changes in RouterOS v6.44beta39+ (see changelog below), it is advised to make a backup before upgrading. Regular downgrade will still be possible as long as no changes in IPsec peer menu are done.
Важные изменения:
- cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);
- ipsec - added new "identity" menu with common peer distinguishers;
- ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;
- ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu;
- radius - initial implementation of RadSec (Radius communication over TLS);
- speedtest - added "/tool speed-test" for ping latency, jitter, loss and TCP and UDP download, upload speed measurements (CLI only);
- telnet - do not allow to set "tracefile" parameter;
- upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";
- upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;
Изменения:
- bridge - count routed FastPath packets between bridge ports under FastPath bridge statistics;
- bridge - fixed BOOTP packet forwarding when DHCP Snooping is enabled;
- crs317 - fixed packet forwarding when LACP is used with hw=no;
- dhcpv6-server - allow to add DHCPv6 server with pool that does not exist;
- ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;
- ipsec - added new "remote-id" peer matcher (CLI only);
- l2tp - fixed IPsec secret not being updated when "ipsec-secret" is changed under L2TP client configuration;
- led - fixed PWR-LINE AP Ethernet LED polarity ("/system routerboard upgrade" required);
- lte - added initial support for multiple APN for R11e-4G (new modem firmware required);
- lte - fixed DHCP IP acquire (introduced in v6.43.7);
- netinstall - do not show kernel failure critical messages in the log after fresh install;
- routerboard - removed "RB" prefix from PWR-LINE AP devices;
- sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;
- snmp - fixed "rsrq" reported precision;
- usb - improved power-reset error message when no bus specified on CCR1072-8G-1S+;
- wireless - added new "installation" parameter to specify router's location;
- wireless - show indoor/outdoor frequency limitations under "/interface wireless info country-info " command.
Другие изменения относительно 6.43.8:
- bgp - properly update keepalive time after peer restart;
- bridge - added option to monitor fast-forward status;
- bridge - disable fast-forward when using SlowPath features;
- bridge - fixed DHCP Option 82 parsing when using DHCP Snooping;
- bridge - fixed packet forwarding when changing MSTI VLAN mappings;
- bridge - fixed possible memory leak when using MSTP;
- bridge - improved packet processing when bridge port changes states;
- btest - added multithreading support for both UDP and TCP tests;
- btest - added warning message when CPU load exceeds 90% (CLI only);
- capsman - always accept connections from loopback address;
- certificate - added support for multiple "Subject Alt. Names";
- certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided;
- chr - assign interface names based on underlying PCI device order on KVM;
- cloud - added "ddns-update-interval" parameter;
- cloud - do not reuse old UDP socket if routing changes are detected;
- cloud - ignore "force-update" command if DDNS is disabled;
- cloud - improved DDNS service disabling;
- cloud - made address updating faster when new public address detected;
- conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter);
- console - renamed IP protocol 41 to "ipv6-encap";
- crs317 - fixed TX not working on sfp-sfpplus9 interface (introduced in v6.40beta12);
- crs328 - fixed SFP+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);
- crs3xx - improved fan control stability;
- crs3xx - improved stability when adding ACL rules on CRS326 and CRS328 devices (introduced in 6.44beta39);
- defconf - fixed configuration not generating properly on upgrade;
- defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;
- defconf - fixed IPv6 link-local address range in firewall rules;
- dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 DHCP servers to control dynamic lease/binding behaviour;
- dhcp - properly load DHCP configuration if options are configured;
- dhcpv4-server - added "parent-queue" parameter (CLI only);
- dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;
- dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;
- dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client;
- dhcpv6-server - improved DHCPv6 server stability when using "print" command;
- discovery - detect proper slave interface on bounded interfaces;
- discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;
- discovery - send master port in "interface-name" parameter;
- discovery - show neighbors on actual bridge port instead of bridge itself for LLDP;
- e-mail - added info log message when e-mail is sent successfully;
- ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;
- ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);
- ethernet - improved per core ethernet traffic classificator on mmips devices;
- export - fixed "silent-boot" compact export;
- fetch - added "http-header-field" parameter;
- fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20);
- fetch - fixed "without-paging" option;
- health - improved fan control stability on CRS328-24P-4S+RM;
- ike2 - added option to specify certificate chain;
- ike2 - added peer identity validation for RSA auth (disabled after upgrade);
- ike2 - allow to match responder peer by "my-id=fqdn" field;
- ike2 - fixed local address lookup when initiating new connection;
- ike2 - improved subsequent phase 2 initialization when no childs exist;
- ike2 - properly handle certificates with empty "Subject";
- ike2 - send split networks over DHCP (option 249) to Windows initiators if DHCP Inform is received;
- ike2 - show weak pre-shared-key warning;
- ipsec - added account log message when user is successfully authenticated;
- ipsec - added basic pre-shared-key strength checks;
- ipsec - allow to specify single address instead of IP pool under "mode-config";
- ipsec - fixed active connection killing when changing peer configuration;
- ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);
- ipsec - hide empty prefixes on "peer" menu;
- ipsec - improved invalid policy handling when a valid policy is uninstalled;
- ipsec - made dynamic "src-nat" rule more specific;
- ipsec - made peers autosort themselves based on reachability status;
- ipsec - moved "profile" menu outside "peer" menu (CLI only);
- ipsec - properly detect AES-NI extension as hardware AEAD;
- ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;
- kidcontrol - added IPv6 support;
- kidcontrol - added "reset-counters" command for "device" menu (CLI only);
- kidcontrol - added statistics web interface for kids (http://router.lan/kid-control);
- kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);
- kidcontrol - dynamically discover devices from DNS activity;
- kidcontrol - fixed validation checks for time intervals;
- kidcontrol - properly detect time zone changes;
- led - fixed default LED configuration for wAP 60G AP devices;
- lte - added additional ID support for Novatel USB730L modem;
- lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);
- lte - added "ecno" field for "info" command;
- lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);
- lte - added support for JioFi JMR1040 modem;
- lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;
- lte - fixed DHCP relay packet forwarding when in passthrough mode;
- lte - fixed IPv6 activation for R11e-LTE-US modems;
- lte - fixed Jaton/SQN modems preventing router from booting properly;
- lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;
- lte - fixed missing running (R) flag for Jaton LTE modems;
- lte - improved compatibility for Alt38xx modems;
- lte - improved SimCom 7100e support;
- port - improved "remote-serial" TCP performance in RAW mode;
- ppp - added "at-chat" command;
- profiler - classify kernel crypto processing as "encrypting";
- proxy - removed port list size limit;
- rb3011 - implemented multiple engine IPsec hardware acceleration support;
- rbm33g - improved stability when used with some USB devices;
- romon - improved reliability when processing RoMON packets on CHR;
- routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";
- snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;
- snmp - changed fan speed value type to Gauge32;
- snmp - fixed w60g station table;
- snmp - removed "rx-sector" ("Wl60gRxSector") value;
- snmp - report bridge ifSpeed as "0";
- ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);
- ssh - added error log message when key exchange fails;
- ssh - fixed non-interactive shell not returning all output (introduced in v6.44);
- ssh - fixed public key format compatibility with RFC4716;
- ssh - fixed single command execution (introduced in v6.44beta9);
- switch - fixed ACL rules on IPQ4018 devices;
- tr069-client - fixed HTTP cookie getting duplicated with the same key;
- traceroute - improved stability when sending large ping amounts;
- traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;
- tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with DNS as "remote-address";
- upgrade - made security package depend on DHCP package;
- userman - show redirect location in error messages;
- user - require "write" permissions for LTE firmware update;
- w60g - added "10s-average-rssi" parameter to align mode (CLI only);
- w60g - added align mode "/interface w60g align" (CLI only);
- w60g - fixed scan in bridge mode;
- w60g - improved PtMP performance;
- w60g - improved reconnection detection;
- w60g - improved "tx-packet-error-rate" reading;
- w60g - renamed disconnection message when license level did not allow more connected clients;
- w60g - renamed "frequency-list" to "scan-list";
- watchdog - allow specifying DNS name for "send-smtp-server" parameter;
- winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;
- winbox - added "challenge-password" field when signing certificate with SCEP;
- winbox - added "conflict-detection" parameter in "IP/DHCP server" menu;
- winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;
- winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;
- winbox - added src/dst address and in/out interface list columns to default firewall menu view;
- winbox - added support for dynamic devices in "IP/Kid Control/Devices" tab;
- winbox - allow setting "network-mode" to "auto" under LTE interface settings;
- winbox - fixed missing w60g interface status values;
- winbox - show "R" flag under "IPv6/DHCP Server/Bindings" tab;
- winbox - show "W60G" wireless tab on wAP 60G AP;
- wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);
- wireless - improved system stability for all ARM devices with wireless;
- wireless - removed G/N support for 2484MHz in "japan" regulatory domain;
- wireless - report last seen IP address in RADIUS accounting messages.
MikroTik RouterOS 6.44beta50
Дата выхода: 17 декабря 2018
Важные комментарии:
Backup before upgrade! Due to major IPsec configuration changes in RouterOS v6.44beta39+ (see changelog below), it is advised to make a backup before upgrading. Regular downgrade will still be possible as long as no changes in IPsec peer menu are done.
Важные изменения:
- cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);
- radius - initial implementation of RadSec (Radius communication over TLS);
- upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";
- upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;
- speedtest - added "/tool speed-test" for ping latency, jitter, loss and TCP and UDP download, upload speed measurements (CLI only);
- ipsec - added new "identity" menu with common peer distinguishers;
- ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;
- ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu.
Изменения:
- ipsec - added new "identity" menu with common peer distinguishers;
- speedtest - added "/tool speed-test" for ping latency, jitter, loss and TCP and UDP download, upload speed measurements (CLI only);
- telnet - do not allow to set "tracefile" parameter;
- bgp - properly update keepalive time after peer restart;
- bridge - fixed BOOTP packet forwarding when DHCP Snooping is enabled;
- bridge - fixed IPv6 link-local address generation when auto-mac=yes;
- capsman - always accept connections from loopback address;
- certificate - added support for multiple "Subject Alt. Names";
- cloud - added "ddns-update-interval" parameter;
- conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter);
- console - properly remove system note after configuration reset;
- crs3xx - improved fan control stability;
- crs3xx - improved stability when adding ACL rules on CRS326 and CRS328 devices (introduced in 6.44beta39);
- defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;
- defconf - fixed IPv6 link-local address range in firewall rules;
- dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 DHCP servers to control dynamic lease/binding behaviour;
- dhcpv4-server - added "parent-queue" parameter (CLI only);
- dhcpv6-server - properly handle DHCP requests that include prefix hint;
- discovery - detect proper slave interface on bounded interfaces;
- discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;
- discovery - send master port in "interface-name" parameter;
- discovery - show neighbors on actual bridge port instead of bridge itself for LLDP;
- ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;
- export - fixed "silent-boot" compact export;
- fetch - added "http-header-field" parameter;
- gps - added "coordinate-format" parameter (CLI only);
- ike2 - allow to match responder peer by "my-id=fqdn" field;
- ipsec - improved invalid policy handling when a valid policy is uninstalled;
- kidcontrol - added IPv6 support;
- kidcontrol - added statistics web interface for kids (http://router.lan/kid-control);
- led - fixed default LED configuration for RBMetalG-52SHPacn;
- lte - added "ecno" field for "info" command;
- lte - disallow setting LTE interface as passthrough target;
- lte - fixed passthrough functionality when interface is removed;
- lte - improved SimCom 7100e support;
- lte - increased reported "rsrq" precision;
- lte - reset USB when non-default slot is used;
- package - use bundled package by default if standalone packages are installed as well;
- ppp - added "at-chat" command;
- resource - fixed "total-memory" reporting on ARM devices;
- snmp - added "tx-ccq" ("mtxrWlStatTxCCQ") and "rx-ccq" ("mtxrWlStatRxCCQ") values;
- snmp - changed fan speed value type to Gauge32;
- snmp - removed "rx-sector" ("Wl60gRxSector") value;
- ssh - fixed public key format compatibility with RFC4716;
- switch - fixed MAC learning when disabling interfaces on devices with Atheros8327 and QCA8337 switch chips;
- system - fixed situation when all configuration was not properly loaded on bootup;
- timezone - fixed "Europe/Dublin" time zone;
- traceroute - improved stability when sending large ping amounts;
- upgrade - automatically uninstall standalone package if already installed in bundle;
- user - require "write" permissions for LTE firmware update;
- watchdog - allow specifying DNS name for "send-smtp-server" parameter;
- webfig - do not show bogus VHT field in wireless interface advanced mode;
- winbox - added "allow-roaming" parameter in "Interface/LTE" menu;
- winbox - added "challenge-password" field when signing certificate with SCEP;
- winbox - added "conflict-detection" parameter in "IP/DHCP server" menu;
- winbox - added src/dst address and in/out interface list columns to default firewall menu view;
- winbox - added support for dynamic devices in "IP/Kid Control/Devices" tab;
- winbox - allow to change VHT rates when 5ghz-n/ac band is used;
- winbox - fixed missing w60g interface status values;
- winbox - renamed "Radius" to "RADIUS";
- winbox - show "R" flag under "IPv6/DHCP Server/Bindings" tab;
- winbox - show "Switch" menu on RB4011iGS+5HacQ2HnD;
- wireless - improvements in wireless frequency selection;
- wireless - improved system stability for all ARM devices with wireless.
Другие изменения относительно 6.43.7:
- bridge - added option to monitor fast-forward status;
- bridge - disable fast-forward when using SlowPath features;
- bridge - fixed DHCP Option 82 parsing when using DHCP Snooping;
- bridge - fixed packet forwarding when changing MSTI VLAN mappings;
- bridge - fixed possible memory leak when using MSTP;
- bridge - improved packet processing when bridge port changes states;
- btest - added multithreading support for both UDP and TCP tests;
- btest - added warning message when CPU load exceeds 90% (CLI only);
- capsman - fixed "group-key-update" parameter not using correct units;
- certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided;
- chr - assign interface names based on underlying PCI device order on KVM;
- cloud - do not reuse old UDP socket if routing changes are detected;
- cloud - ignore "force-update" command if DDNS is disabled;
- cloud - improved DDNS service disabling;
- cloud - made address updating faster when new public address detected;
- console - renamed IP protocol 41 to "ipv6-encap";
- crs317 - fixed TX not working on sfp-sfpplus9 interface (introduced in v6.40beta12);
- crs328 - fixed SFP+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);
- crs3xx - improved data transmission between 10G and 1G ports;
- defconf - fixed configuration not generating properly on upgrade;
- dhcp - properly load DHCP configuration if options are configured;
- dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;
- dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;
- dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client;
- dhcpv6-server - improved DHCPv6 server stability when using "print" command;
- e-mail - added info log message when e-mail is sent successfully;
- ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;
- ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);
- ethernet - improved per core ethernet traffic classificator on mmips devices;
- fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20);
- fetch - fixed "without-paging" option;
- health - improved fan control stability on CRS328-24P-4S+RM;
- ike2 - added option to specify certificate chain;
- ike2 - added peer identity validation for RSA auth (disabled after upgrade);
- ike2 - fixed local address lookup when initiating new connection;
- ike2 - improved subsequent phase 2 initialization when no childs exist;
- ike2 - properly handle certificates with empty "Subject";
- ike2 - send split networks over DHCP (option 249) to Windows initiators if DHCP Inform is received;
- ike2 - show weak pre-shared-key warning;
- ipsec - added account log message when user is successfully authenticated;
- ipsec - added basic pre-shared-key strength checks;
- ipsec - added new "remote-id" peer matcher (CLI only);
- ipsec - allow to specify single address instead of IP pool under "mode-config";
- ipsec - fixed active connection killing when changing peer configuration;
- ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);
- ipsec - hide empty prefixes on "peer" menu;
- ipsec - made dynamic "src-nat" rule more specific;
- ipsec - made peers autosort themselves based on reachability status;
- ipsec - moved "profile" menu outside "peer" menu (CLI only);
- ipsec - properly detect AES-NI extension as hardware AEAD;
- ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;
- kidcontrol - added "reset-counters" command for "device" menu (CLI only);
- kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);
- kidcontrol - dynamically discover devices from DNS activity;
- kidcontrol - fixed validation checks for time intervals;
- kidcontrol - properly detect time zone changes;
- led - fixed default LED configuration for wAP 60G AP devices;
- lte - added additional ID support for Novatel USB730L modem;
- lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);
- lte - added "ecno" field for "info" command;
- lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);
- lte - added support for JioFi JMR1040 modem;
- lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;
- lte - fixed DHCP relay packet forwarding when in passthrough mode;
- lte - fixed IPv6 activation for R11e-LTE-US modems;
- lte - fixed Jaton/SQN modems preventing router from booting properly;
- lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;
- lte - fixed missing running (R) flag for Jaton LTE modems;
- lte - improved compatibility for Alt38xx modems;
- port - improved "remote-serial" TCP performance in RAW mode;
- profiler - classify kernel crypto processing as "encrypting";
- proxy - removed port list size limit;
- rb3011 - implemented multiple engine IPsec hardware acceleration support;
- rbm33g - improved stability when used with some USB devices;
- romon - improved reliability when processing RoMON packets on CHR;
- routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";
- sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;
- snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;
- snmp - fixed w60g station table;
- snmp - report bridge ifSpeed as "0";
- ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);
- ssh - added error log message when key exchange fails;
- ssh - fixed non-interactive shell not returning all output (introduced in v6.44);
- ssh - fixed single command execution (introduced in v6.44beta9);
- switch - fixed ACL rules on IPQ4018 devices;
- tr069-client - fixed HTTP cookie getting duplicated with the same key;
- traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;
- tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with DNS as "remote-address";
- upgrade - made security package depend on DHCP package;
- userman - show redirect location in error messages;
- w60g - added "10s-average-rssi" parameter to align mode (CLI only);
- w60g - added align mode "/interface w60g align" (CLI only);
- w60g - fixed scan in bridge mode;
- w60g - improved PtMP performance;
- w60g - improved reconnection detection;
- w60g - improved "tx-packet-error-rate" reading;
- w60g - renamed disconnection message when license level did not allow more connected clients;
- w60g - renamed "frequency-list" to "scan-list";
- winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;
- winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;
- winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;
- winbox - allow setting "network-mode" to "auto" under LTE interface settings;
- winbox - show "W60G" wireless tab on wAP 60G AP;
- wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);
- wireless - improved stability for 802.11ac;
- wireless - removed G/N support for 2484MHz in "japan" regulatory domain;
- wireless - report last seen IP address in RADIUS accounting messages.
MikroTik RouterOS 6.44beta40
Дата выхода: 28 ноября 2018
Важные комментарии:
Backup before upgrade! Due to major IPsec configuration changes in RouterOS v6.44beta39+ (see changelog below), it is advised to make a backup before upgrading. Regular downgrade will still be possible as long as no changes in IPsec peer menu are done.
Важные изменения:
- cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);
- radius - initial implementation of RadSec (Radius communication over TLS);
- upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";
- upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;
- speedtest - added "/tool speed-test" for ping latency, jitter, loss and TCP and UDP download, upload speed measurements (CLI only).
Изменения:
- ipsec - added new "identity" menu with common peer distinguishers;
- ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;
- ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu;
- capsman - fixed "group-key-update" parameter not using correct units;
- certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided;
- crs317 - fixed TX not working on sfp-sfpplus9 interface (introduced in v6.40beta12);
- dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client;
- discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;
- discovery - fixed neighbor discovery for PPP interfaces;
- ipsec - fixed active connection killing when changing peer configuration;
- ipsec - made peers autosort themselves based on reachability status;
- ipsec - moved "profile" menu outside "peer" menu (CLI only).
Другие изменения относительно 6.43.4:
- bridge - added option to monitor fast-forward status;
- bridge - disable fast-forward when using SlowPath features;
- bridge - fixed DHCP Option 82 parsing when using DHCP Snooping;
- bridge - fixed packet forwarding when changing MSTI VLAN mappings;
- bridge - fixed possible memory leak when using MSTP;
- bridge - improved packet processing when bridge port changes states;
- bridge - properly disable dynamic CAP interfaces;
- btest - added multithreading support for both UDP and TCP tests;
- btest - added warning message when CPU load exceeds 90% (CLI only);
- certificate - added support for multiple "Subject Alt. Names" (CLI only);
- certificate - fixed "expires-after" parameter calculation;
- certificate - fixed time zone adjustment for SCEP requests;
- certificate - properly flush old CRLs when changing store location;
- chr - assign interface names based on underlying PCI device order on KVM;
- chr - correctly initialize grant table version 1;
- cloud - added "ddns-update-interval" parameter (CLI only);
- cloud - do not reuse old UDP socket if routing changes are detected;
- cloud - ignore "force-update" command if DDNS is disabled;
- cloud - improved DDNS service disabling;
- cloud - made address updating faster when new public address detected;
- conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter) (CLI only);
- console - renamed IP protocol 41 to "ipv6-encap";
- crs328 - fixed SFP+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);
- crs328 - fixed SFP ports not reporting auto-negotiation status;
- crs328 - improved link status update on disabled SFP and SFP+ interfaces;
- crs3xx - improved data transmission between 10G and 1G ports;
- defconf - automatically accept default configuration if reset done by holding button;
- defconf - fixed configuration not generating properly on upgrade;
- dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 DHCP servers to control dynamic lease/binding behaviour (CLI only);
- dhcp - properly load DHCP configuration if options are configured;
- dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;
- dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;
- dhcpv6-server - improved DHCPv6 server stability when using "print" command;
- discovery - properly use Sytem ID for "software-id" value on CHR;
- e-mail - added info log message when e-mail is sent successfully;
- ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;
- ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);
- ethernet - improved per core ethernet traffic classificator on mmips devices;
- fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20);
- fetch - fixed "without-paging" option;
- gps - added "coordinate-format" parameter (CLI only);
- health - fixed bad voltage readings on RB493G;
- health - improved fan control stability on CRS328-24P-4S+RM;
- ike2 - added option to specify certificate chain;
- ike2 - added peer identity validation for RSA auth (disabled after upgrade);
- ike2 - allow to match responder peer by "my-id=fqdn" field;
- ike2 - fixed local address lookup when initiating new connection;
- ike2 - improved subsequent phase 2 initialization when no childs exist;
- ike2 - properly handle certificates with empty "Subject";
- ike2 - send split networks over DHCP (option 249) to Windows initiators if DHCP Inform is received;
- ike2 - show weak pre-shared-key warning;
- interface - improved system stability when including/excluding a list to itself;
- ipsec - added account log message when user is successfully authenticated;
- ipsec - added basic pre-shared-key strength checks;
- ipsec - added new "remote-id" peer matcher (CLI only);
- ipsec - allow to specify single address instead of IP pool under "mode-config";
- ipsec - fixed hw-aead (H) flag presence under Installed SAs on startup;
- ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);
- ipsec - hide empty prefixes on "peer" menu;
- ipsec - improved invalid policy handling when a valid policy is uninstalled;
- ipsec - improved stability when uninstalling multiple SAs at once;
- ipsec - made dynamic "src-nat" rule more specific;
- ipsec - properly detect AES-NI extension as hardware AEAD;
- ipsec - properly handle peer profiles on downgrade;
- ipsec - properly update warnings under peer menu;
- ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;
- kidcontrol - added "reset-counters" command for "device" menu (CLI only);
- kidcontrol - added statistics web interface for kids (http://router.lan/kid-control);
- kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);
- kidcontrol - do not allow users with "read" policy to pause and resume kids;
- kidcontrol - dynamically discover devices from DNS activity;
- kidcontrol - fixed validation checks for time intervals;
- kidcontrol - properly detect time zone changes;
- led - fixed default LED configuration for wAP 60G AP devices;
- log - properly handle long echo messages;
- lte - added additional ID support for Novatel USB730L modem;
- lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);
- lte - added "ecno" field for "info" command;
- lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);
- lte - added support for JioFi JMR1040 modem;
- lte - added support for more ZTE MF90 modems;
- lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;
- lte - fixed DHCP relay packet forwarding when in passthrough mode;
- lte - fixed IPv6 activation for R11e-LTE-US modems;
- lte - fixed Jaton/SQN modems preventing router from booting properly;
- lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;
- lte - fixed missing running (R) flag for Jaton LTE modems;
- lte - improved compatibility for Alt38xx modems;
- lte - increased reported "rsrq" precision (CLI only);
- ospf - improved stability while handling type-5 LSAs;
- port - improved "remote-serial" TCP performance in RAW mode;
- profiler - classify kernel crypto processing as "encrypting";
- proxy - removed port list size limit;
- rb3011 - implemented multiple engine IPsec hardware acceleration support;
- rbm33g - improved stability when used with some USB devices;
- romon - improved reliability when processing RoMON packets on CHR;
- routerboard - renamed SIM slots to "a" and "b" on SXT LTE kit;
- routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";
- routerboard - show "force-backup-booter" option only on devices that have such feature;
- sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;
- snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;
- snmp - do not initialise interface traps on bootup if they are not enabled;
- snmp - fixed w60g station table;
- snmp - report bridge ifSpeed as "0";
- ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);
- ssh - added error log message when key exchange fails;
- ssh - fixed non-interactive shell not returning all output (introduced in v6.44);
- ssh - fixed single command execution (introduced in v6.44beta9);
- switch - fixed ACL rules on IPQ4018 devices;
- timezone - updated timezone information from tzdata2018g release;
- tr069-client - fixed HTTP cookie getting duplicated with the same key;
- traffic-flow - fixed "src-mac-address" and added "post-src-mac-address" fields;
- traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;
- tunnel - made "ipsec-secret" parameter sensitive;
- tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with DNS as "remote-address";
- upgrade - made security package depend on DHCP package;
- usb - fixed power-reset for hAP ac^2 devices;
- userman - show redirect location in error messages;
- user - speed up first time login process after upgrade from version older than v6.43;
- w60g - added "10s-average-rssi" parameter to align mode (CLI only);
- w60g - added align mode "/interface w60g align" (CLI only);
- w60g - fixed scan in bridge mode;
- w60g - improved PtMP performance;
- w60g - improved reconnection detection;
- w60g - improved "tx-packet-error-rate" reading;
- w60g - renamed disconnection message when license level did not allow more connected clients;
- w60g - renamed "frequency-list" to "scan-list";
- winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;
- winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;
- winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;
- winbox - allow setting "network-mode" to "auto" under LTE interface settings;
- winbox - allow to specify SIM slot on LtAP mini;
- winbox - enabled "fast-forward" by default when adding new bridge;
- winbox - show "Switch" menu on RB4011iGS+5HacQ2HnD;
- winbox - show "System/Health" only on boards that have health monitoring;
- winbox - show "W60G" wireless tab on wAP 60G AP;
- wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);
- wireless - improved stability for 802.11ac;
- wireless - improved system stability for all ARM devices with wireless;
- wireless - removed G/N support for 2484MHz in "japan" regulatory domain;
- wireless - report last seen IP address in RADIUS accounting messages.
MikroTik RouterOS 6.44beta39
Дата выхода: 27 ноября 2018
Важные комментарии:
Backup before upgrade! Due to major IPsec configuration changes in RouterOS v6.44beta39+ (see changelog below), it is advised to make a backup before upgrading. Regular downgrade will still be possible as long as no changes in IPsec peer menu are done.
Важные изменения:
- cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);
- radius - initial implementation of RadSec (Radius communication over TLS);
- upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";
- upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions.
Изменения:
- ipsec - added new "identity" menu with common peer distinguishers;
- ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;
- ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu;
- speedtest - added "/tool speed-test" for ping latency, jitter, loss and TCP and UDP download, upload speed measurements (CLI only);
- btest - added multithreading support for both UDP and TCP tests;
- bridge - properly disable dynamic CAP interfaces;
- btest - added warning message when CPU load exceeds 90% (CLI only);
- certificate - fixed "expires-after" parameter calculation;
- certificate - properly flush old CRLs when changing store location;
- certificate - added support for multiple "Subject Alt. Names" (CLI only);
- chr - correctly initialize grant table version 1;
- cloud - added "ddns-update-interval" parameter (CLI only);
- cloud - do not reuse old UDP socket if routing changes are detected;
- cloud - made address updating faster when new public address detected;
- conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter) (CLI only);
- console - renamed IP protocol 41 to "ipv6-encap";
- dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;
- ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;
- ethernet - improved per core ethernet traffic classificator on mmips devices;
- gps - added "coordinate-format" parameter (CLI only);
- ike2 - added peer identity validation for RSA auth (disabled after upgrade);
- ike2 - allow to match responder peer by "my-id=fqdn" field;
- ike2 - properly handle certificates with empty "Subject";
- ike2 - send split networks over DHCP (option 249) to Windows initiators if DHCP Inform is received;
- interface - improved system stability when including/excluding a list to itself;
- ipsec - added new "remote-id" peer matcher (CLI only);
- ipsec - allow to specify single address instead of IP pool under "mode-config";
- ipsec - hide empty prefixes on "peer" menu;
- ipsec - made dynamic "src-nat" rule more specific;
- ipsec - made peers autosort themselves based on reachability status;
- ipsec - properly detect AES-NI extension as hardware AEAD;
- ipsec - properly handle peer profiles on downgrade;
- ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;
- kidcontrol - added statistics web interface for kids (http://router.lan/kid-control);
- kidcontrol - do not allow users with "read" policy to pause and resume kids;
- kidcontrol - properly detect time zone changes;
- log - properly handle long echo messages;
- led - fixed default LED configuration for wAP 60G AP devices;
- lte - added "ecno" field for "info" command;
- lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);
- lte - added support for more ZTE MF90 modems;
- lte - improved compatibility for Alt38xx modems;
- lte - increased reported "rsrq" precision (CLI only);
- profiler - classify kernel crypto processing as "encrypting";
- routerboard - renamed SIM slots to "a" and "b" on SXT LTE kit;
- sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;
- snmp - do not initialise interface traps on bootup if they are not enabled;
- ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);
- timezone - updated timezone information from tzdata2018g release;
- traffic-flow - fixed "src-mac-address" and added "post-src-mac-address" fields;
- traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;
- tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with DNS as "remote-address";
- upgrade - made security package depend on DHCP package;
- usb - fixed power-reset for hAP ac^2 devices;
- user - speed up first time login process after upgrade from version older than v6.43;
- userman - show redirect location in error messages;
- w60g - added "10s-average-rssi" parameter to align mode (CLI only);
- w60g - improved reconnection detection;
- w60g - improved "tx-packet-error-rate" reading;
- winbox - allow to specify SIM slot on LtAP mini;
- winbox - enabled "fast-forward" by default when adding new bridge;
- winbox - show "Switch" menu on RB4011iGS+5HacQ2HnD;
- winbox - show "System/Health" only on boards that have health monitoring;
- winbox - show "W60G" wireless tab on wAP 60G AP;
- wireless - improved system stability for all ARM devices with wireless;
- wireless - report last seen IP address in RADIUS accounting messages.
Другие изменения относительно 6.43:
- bridge - added option to monitor fast-forward status;
- bridge - disable fast-forward when using SlowPath features;
- bridge - fixed DHCP Option 82 parsing when using DHCP Snooping;
- bridge - fixed packet forwarding when changing MSTI VLAN mappings;
- bridge - fixed possible memory leak when using MSTP;
- bridge - improved packet processing when bridge port changes states;
- certificate - fixed time zone adjustment for SCEP requests;
- chr - assign interface names based on underlying PCI device order on KVM;
- cloud - ignore "force-update" command if DDNS is disabled;
- cloud - improved DDNS service disabling;
- crs328 - fixed SFP+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);
- crs328 - fixed SFP ports not reporting auto-negotiation status;
- crs328 - improved link status update on disabled SFP and SFP+ interfaces;
- crs3xx - improved data transmission between 10G and 1G ports;
- defconf - automatically accept default configuration if reset done by holding button;
- defconf - fixed configuration not generating properly on upgrade;
- dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 DHCP servers to control dynamic lease/binding behaviour (CLI only);
- dhcp - properly load DHCP configuration if options are configured;
- dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;
- dhcpv6-server - improved DHCPv6 server stability when using "print" command;
- discovery - properly use Sytem ID for "software-id" value on CHR;
- e-mail - added info log message when e-mail is sent successfully;
- ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);
- fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20);
- fetch - fixed "without-paging" option;
- health - fixed bad voltage readings on RB493G;
- health - improved fan control stability on CRS328-24P-4S+RM;
- ike2 - added option to specify certificate chain;
- ike2 - fixed local address lookup when initiating new connection;
- ike2 - improved subsequent phase 2 initialization when no childs exist;
- ike2 - show weak pre-shared-key warning;
- ipsec - added account log message when user is successfully authenticated;
- ipsec - added basic pre-shared-key strength checks;
- ipsec - fixed hw-aead (H) flag presence under Installed SAs on startup;
- ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);
- ipsec - improved invalid policy handling when a valid policy is uninstalled;
- ipsec - improved stability when uninstalling multiple SAs at once;
- ipsec - properly update warnings under peer menu;
- kidcontrol - added "reset-counters" command for "device" menu (CLI only);
- kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);
- kidcontrol - dynamically discover devices from DNS activity;
- kidcontrol - fixed validation checks for time intervals;
- lte - added additional ID support for Novatel USB730L modem;
- lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);
- lte - added support for JioFi JMR1040 modem;
- lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;
- lte - fixed DHCP relay packet forwarding when in passthrough mode;
- lte - fixed IPv6 activation for R11e-LTE-US modems;
- lte - fixed Jaton/SQN modems preventing router from booting properly;
- lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;
- lte - fixed missing running (R) flag for Jaton LTE modems;
- ospf - improved stability while handling type-5 LSAs;
- port - improved "remote-serial" TCP performance in RAW mode;
- proxy - removed port list size limit;
- rb3011 - implemented multiple engine IPsec hardware acceleration support;
- rbm33g - improved stability when used with some USB devices;
- romon - improved reliability when processing RoMON packets on CHR;
- routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";
- routerboard - show "force-backup-booter" option only on devices that have such feature;
- snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;
- snmp - fixed w60g station table;
- snmp - report bridge ifSpeed as "0";
- ssh - added error log message when key exchange fails;
- ssh - fixed non-interactive shell not returning all output (introduced in v6.44);
- ssh - fixed single command execution (introduced in v6.44beta9);
- switch - fixed ACL rules on IPQ4018 devices;
- tr069-client - fixed HTTP cookie getting duplicated with the same key;
- tunnel - made "ipsec-secret" parameter sensitive;
- w60g - added align mode "/interface w60g align" (CLI only);
- w60g - fixed scan in bridge mode;
- w60g - improved PtMP performance;
- w60g - renamed disconnection message when license level did not allow more connected clients;
- w60g - renamed "frequency-list" to "scan-list";
- winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;
- winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;
- winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;
- winbox - allow setting "network-mode" to "auto" under LTE interface settings;
- wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);
- wireless - improved stability for 802.11ac;
- wireless - removed G/N support for 2484MHz in "japan" regulatory domain.
MikroTik RouterOS 6.44beta28
Дата выхода: 29 октября 2018
Важные изменения:
- cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);
- upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";
- upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions.
Изменения:
- radius - initial implementation of RadSec (Radius communication over TLS);
- bridge - added option to monitor fast-forward status;
- bridge - disable fast-forward when using SlowPath features;
- bridge - fixed DHCP Option 82 parsing when using DHCP Snooping;
- certificate - fixed time zone adjustment for SCEP requests;
- crs328 - fixed SFP+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);
- crs328 - fixed SFP ports not reporting auto-negotiation status;
- crs328 - improved link status update on disabled SFP and SFP+ interfaces;
- defconf - automatically accept default configuration if reset done by holding button;
- defconf - fixed configuration not generating properly on upgrade;
- ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);
- fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20);
- fetch - fixed "without-paging" option;
- health - fixed bad voltage readings on RB493G;
- ike2 - added option to specify certificate chain;
- ike2 - send split networks over DHCP (option 249) to Windows initiators if DHCP Inform is received;
- ike2 - show weak pre-shared-key warning;
- ipsec - added basic pre-shared-key strength checks;
- ipsec - fixed hw-aead (H) flag presence under Installed SAs on startup;
- ipsec - improved stability when uninstalling multiple SAs at once;
- ipsec - made peers autosort themselves based on reachability status;
- ipsec - properly update warnings under peer menu;
- lte - added support for JioFi JMR1040 modem;
- lte - fixed IPv6 activation for R11e-LTE-US modems;
- lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;
- lte - fixed missing running (R) flag for Jaton LTE modems;
- ospf - improved stability while handling type-5 LSAs;
- port - improved "remote-serial" TCP performance in RAW mode;
- rb3011 - implemented multiple engine IPsec hardware acceleration support;
- rbm33g - improved stability when used with some USB devices;
- routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";
- routerboard - show "boot-os" and "force-backup-booter" option only on devices that have such feature;
- snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;
- ssh - added error log message when key exchange fails;
- ssh - fixed non-interactive shell not returning all output (introduced in v6.44);
- tr069-client - fixed HTTP cookie getting duplicated with the same key;
- tunnel - made "ipsec-secret" parameter sensitive;
- upgrade - made security package depend on DHCP package;
- wireless - removed G/N support for 2484MHz in "japan" regulatory domain;
- w60g - fixed scan in bridge mode;
- w60g - improved PtMP performance;
- w60g - renamed "frequency-list" to "scan-list";
- w60g - renamed disconnection message when license level did not allow more connected clients;
- w60g - added align mode "/interface w60g align" (CLI only).
Другие изменения относительно 6.43:
- bridge - fixed packet forwarding when changing MSTI VLAN mappings;
- bridge - fixed possible memory leak when using MSTP;
- bridge - improved packet processing when bridge port changes states;
- chr - assign interface names based on underlying PCI device order on KVM;
- cloud - ignore "force-update" command if DDNS is disabled;
- cloud - improved DDNS service disabling;
- crs3xx - improved data transmission between 10G and 1G ports;
- dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 DHCP servers to control dynamic lease/binding behaviour (CLI only);
- dhcp - properly load DHCP configuration if options are configured;
- dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;
- dhcpv6-server - improved DHCPv6 server stability when using "print" command;
- discovery - properly use Sytem ID for "software-id" value on CHR;
- e-mail - added info log message when e-mail is sent successfully;
- ethernet - fixed IPv6 packet forwarding on IPQ4018 devices;
- ethernet - fixed IPv6 packet forwarding on IPQ4018 devices;
- ethernet - fixed IPv6 packet forwarding on IPQ4018 devices;
- health - improved fan control stability on CRS328-24P-4S+RM;
- ike2 - fixed local address lookup when initiating new connection;
- ike2 - improved subsequent phase 2 initialization when no childs exist;
- ipsec - added account log message when user is successfully authenticated;
- ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);
- ipsec - improved invalid policy handling when a valid policy is uninstalled;
- kidcontrol - added "reset-counters" command for "device" menu (CLI only);
- kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);
- kidcontrol - dynamically discover devices from DNS activity;
- kidcontrol - fixed validation checks for time intervals;
- lte - added additional ID support for Novatel USB730L modem;
- lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);
- lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);
- lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;
- lte - fixed DHCP relay packet forwarding when in passthrough mode;
- lte - fixed Jaton/SQN modems preventing router from booting properly;
- proxy - removed port list size limit;
- romon - improved reliability when processing RoMON packets on CHR;
- snmp - fixed w60g station table;
- snmp - report bridge ifSpeed as "0";
- ssh - fixed single command execution (introduced in v6.44beta9);
- switch - fixed ACL rules on IPQ4018 devices;
- winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;
- winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;
- winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;
- winbox - allow setting "network-mode" to "auto" under LTE interface settings;
- wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);
- wireless - improved stability for 802.11ac.
MikroTik RouterOS 6.44beta20
Дата выхода: 9 октября 2018
Важные изменения:
- cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);
- upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";
- upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions.
Изменения:
- crs328 - fixed SFP+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);
- crs328 - improved link status update on disabled SFP+ interface when using DAC;
- crs3xx - properly read "eeprom" data after different module inserted in disabled interface;
- dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 DHCP servers to control dynamic lease/binding behaviour (CLI only);
- dhcpv6-server - improved DHCPv6 server stability when using "print" command;
- led - added "dark-mode" functionality for LHG and LDF series devices;
- lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);
- lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;
- w60g - general stability and performance improvements;
- w60g - improved stability for short distance links.
Другие изменения относительно 6.43:
- bridge - do not learn untagged frames when filtering only tagged packets;
- bridge - fixed packet forwarding when changing MSTI VLAN mappings;
- bridge - fixed possible memory leak when using MSTP;
- bridge - fixed possible memory leak when VLAN filtering is used;
- bridge - improved packet handling when hardware offloading is being disabled;
- bridge - improved packet processing when bridge port changes states;
- bridge - properly forward unicast DHCP messages when using DHCP Snooping with hardware offloading;
- chr - assign interface names based on underlying PCI device order on KVM;
- cloud - ignore "force-update" command if DDNS is disabled;
- cloud - improved DDNS service disabling;
- crs3xx - fixed possible memory leak when disabling bridge interface;
- crs3xx - improved data transmission between 10G and 1G ports;
- dhcp - properly load DHCP configuration if options are configured;
- dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;
- dhcpv4-server - use client MAC address for dual stack queue when "client-id" is not received;
- dhcpv6-server - recreate DHCPv6 server binding if it is no longer within prefix pool when rebinding/renewing;
- discovery - properly use Sytem ID for "software-id" value on CHR;
- e-mail - added info log message when e-mail is sent successfully;
- ethernet - fixed IPv6 packet forwarding on IPQ4018 devices;
- ethernet - fixed IPv6 packet forwarding on IPQ4018 devices;
- ethernet - fixed IPv6 packet forwarding on IPQ4018 devices;
- health - improved fan control stability on CRS328-24P-4S+RM;
- ike2 - added option to specify certificate chain;
- ike2 - fixed local address lookup when initiating new connection;
- ike2 - improved subsequent phase 2 initialization when no childs exist;
- ipsec - added account log message when user is successfully authenticated;
- ipsec - allow multiple peers to the same address with different local-address (introduced in v6.43);
- ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);
- ipsec - improved invalid policy handling when a valid policy is uninstalled;
- kidcontrol - added "reset-counters" command for "device" menu (CLI only);
- kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);
- kidcontrol - dynamically discover devices from DNS activity;
- kidcontrol - fixed validation checks for time intervals;
- led - added "dark-mode" functionality for wsAP ac lite, RB951Ui-2nD, hAP and hAP ac lite devices;
- led - fixed default LED configuration for SXT LTE kit devices;
- led - fixed power LED turning on after reboot when "dark-mode" is used;
- lte - added additional ID support for Novatel USB730L modem;
- lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);
- lte - added support for JioFi JMR1040 modem;
- lte - fixed DHCP relay packet forwarding when in passthrough mode;
- lte - fixed Jaton/SQN modems preventing router from booting properly;
- ntp - fixed possible NTP server stuck in "started" state;
- proxy - removed port list size limit;
- rb3011 - implemented multiple engine IPsec hardware acceleration support;
- romon - improved packet processing when MTU in path is lower than 1500;
- romon - improved reliability when processing RoMON packets on CHR;
- routerboard - show "boot-os" option only on devices that have such feature;
- snmp - fixed w60g station table;
- snmp - report bridge ifSpeed as "0";
- ssh - fixed single command execution (introduced in v6.44beta9);
- switch - fixed ACL rules on IPQ4018 devices;
- traffic-flow - fixed post NAT port reporting;
- w60g - added "frequency-list" setting;
- w60g - added interface stats;
- w60g - fixed interface LED status update on connection;
- w60g - renamed "mcs" to "tx-mcs" and "phy-rate" to "tx-phy-rate";
- winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;
- winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;
- winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;
- winbox - allow setting "network-mode" to "auto" under LTE interface settings;
- wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);
- wireless - improved stability for 802.11ac.
MikroTik RouterOS 6.44beta17
Дата выхода: 4 октября 2018
Важные изменения:
- cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);
- upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";
- upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions.
Изменения:
- bridge - fixed possible memory leak when VLAN filtering is used;
- dhcpv4-server - use client MAC address for dual stack queue when "client-id" is not received;
- ethernet - fixed IPv6 packet forwarding on IPQ4018 devices;
- health - improved fan control stability on CRS328-24P-4S+RM;
- led - fixed default LED configuration for SXT LTE kit devices;
- led - fixed power LED turning on after reboot when "dark-mode" is used;
- lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);
- wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required).
Другие изменения относительно 6.43:
- bridge - do not learn untagged frames when filtering only tagged packets;
- bridge - fixed packet forwarding when changing MSTI VLAN mappings;
- bridge - fixed possible memory leak when using MSTP;
- bridge - improved packet handling when hardware offloading is being disabled;
- bridge - improved packet processing when bridge port changes states;
- bridge - properly forward unicast DHCP messages when using DHCP Snooping with hardware offloading;
- chr - assign interface names based on underlying PCI device order on KVM;
- cloud - ignore "force-update" command if DDNS is disabled;
- cloud - improved DDNS service disabling;
- crs3xx - fixed possible memory leak when disabling bridge interface;
- crs3xx - improved data transmission between 10G and 1G ports;
- dhcp - properly load DHCP configuration if options are configured;
- dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;
- dhcpv6-server - recreate DHCPv6 server binding if it is no longer within prefix pool when rebinding/renewing;
- discovery - properly use Sytem ID for "software-id" value on CHR;
- e-mail - added info log message when e-mail is sent successfully;
- ethernet - fixed IPv6 packet forwarding on IPQ4018 devices;
- ethernet - fixed IPv6 packet forwarding on IPQ4018 devices;
- ike2 - added option to specify certificate chain;
- ike2 - fixed local address lookup when initiating new connection;
- ike2 - improved subsequent phase 2 initialization when no childs exist;
- ipsec - added account log message when user is successfully authenticated;
- ipsec - allow multiple peers to the same address with different local-address (introduced in v6.43);
- ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);
- ipsec - improved invalid policy handling when a valid policy is uninstalled;
- kidcontrol - added "reset-counters" command for "device" menu (CLI only);
- kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);
- kidcontrol - dynamically discover devices from DNS activity;
- kidcontrol - fixed validation checks for time intervals;
- led - added "dark-mode" functionality for wsAP ac lite, RB951Ui-2nD, hAP and hAP ac lite devices;
- lte - added additional ID support for Novatel USB730L modem;
- lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);
- lte - added support for JioFi JMR1040 modem;
- lte - fixed DHCP relay packet forwarding when in passthrough mode;
- lte - fixed Jaton/SQN modems preventing router from booting properly;
- ntp - fixed possible NTP server stuck in "started" state;
- proxy - removed port list size limit;
- rb3011 - implemented multiple engine IPsec hardware acceleration support;
- romon - improved packet processing when MTU in path is lower than 1500;
- romon - improved reliability when processing RoMON packets on CHR;
- routerboard - show "boot-os" option only on devices that have such feature;
- snmp - fixed w60g station table;
- snmp - report bridge ifSpeed as "0";
- ssh - fixed single command execution (introduced in v6.44beta9);
- switch - fixed ACL rules on IPQ4018 devices;
- traffic-flow - fixed post NAT port reporting;
- w60g - added "frequency-list" setting;
- w60g - added interface stats;
- w60g - fixed interface LED status update on connection;
- w60g - renamed "mcs" to "tx-mcs" and "phy-rate" to "tx-phy-rate";
- winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;
- winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;
- winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;
- winbox - allow setting "network-mode" to "auto" under LTE interface settings;
- wireless - improved stability for 802.11ac.
MikroTik RouterOS 6.44beta14
Дата выхода: 1 октября 2018
Важные изменения:
- cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);
- upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";
- upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions.
Изменения:
- bridge - do not learn untagged frames when filtering only tagged packets;
- bridge - fixed packet forwarding when changing MSTI VLAN mappings;
- bridge - fixed possible memory leak when using MSTP;
- bridge - improved packet processing when bridge port changes states;
- bridge - properly forward unicast DHCP messages when using DHCP Snooping with hardware offloading;
- cloud - improved DDNS service disabling;
- dhcp - properly load DHCP configuration if options are configured;
- dhcpv6-server - recreate DHCPv6 server binding if it is no longer within prefix pool when rebinding/renewing;
- ethernet - fixed IPv6 packet forwarding on IPQ4018 devices;
- ike2 - improved subsequent phase 2 initialization when no childs exist;
- ipsec - added account log message when user is successfully authenticated;
- ipsec - allow multiple peers to the same address with different local-address (introduced in v6.43);
- ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);
- ipsec - improved invalid policy handling when a valid policy is uninstalled;
- kidcontrol - added "reset-counters" command for "device" menu (CLI only);
- kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);
- kidcontrol - dynamically discover devices from DNS activity;
- kidcontrol - fixed validation checks for time intervals;
- led - added "dark-mode" functionality for wsAP ac lite, RB951Ui-2nD, hAP and hAP ac lite devices;
- lte - added additional ID support for Novatel USB730L modem;
- lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);
- lte - added support for JioFi JMR1040 modem;
- ntp - fixed possible NTP server stuck in "started" state;
- rb3011 - implemented multiple engine IPsec hardware acceleration support;
- romon - improved packet processing when MTU in path is lower than 1500;
- snmp - fixed w60g station table;
- snmp - report bridge ifSpeed as "0";
- ssh - fixed single command execution (introduced in v6.44beta9);
- traffic-flow - fixed post NAT port reporting;
- w60g - added interface stats;
- w60g - renamed "mcs" to "tx-mcs" and "phy-rate" to "tx-phy-rate";
- wireless - improved stability for 802.11ac.
Другие изменения относительно 6.43:
- bridge - improved packet handling when hardware offloading is being disabled;
- chr - assign interface names based on underlying PCI device order on KVM;
- cloud - ignore "force-update" command if DDNS is disabled;
- crs3xx - fixed possible memory leak when disabling bridge interface;
- crs3xx - improved data transmission between 10G and 1G ports;
- dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;
- discovery - properly use Sytem ID for "software-id" value on CHR;
- e-mail - added info log message when e-mail is sent successfully;
- ethernet - fixed IPv6 packet forwarding on IPQ4018 devices;
- ike2 - added option to specify certificate chain;
- ike2 - fixed local address lookup when initiating new connection;
- lte - fixed DHCP relay packet forwarding when in passthrough mode;
- lte - fixed Jaton/SQN modems preventing router from booting properly;
- proxy - removed port list size limit;
- romon - improved reliability when processing RoMON packets on CHR;
- routerboard - show "boot-os" option only on devices that have such feature;
- switch - fixed ACL rules on IPQ4018 devices;
- w60g - added "frequency-list" setting;
- w60g - fixed interface LED status update on connection;
- winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;
- winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;
- winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;
- winbox - allow setting "network-mode" to "auto" under LTE interface settings.
MikroTik RouterOS 6.44beta9
Дата выхода: 17 сентября 2018
Важные изменения:
- upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";
- upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions.
Изменения:
- cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);
- bridge - improved packet handling when hardware offloading is being disabled;
- cloud - ignore "force-update" command if DDNS is disabled;
- crs3xx - fixed possible memory leak when disabling bridge interface;
- defconf - properly clear global variables when generating default configuration after RouterOS upgrade;
- discovery - properly use Sytem ID for "software-id" value on CHR;
- e-mail - added info log message when e-mail is sent successfully;
- lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;
- proxy - removed port list size limit;
- romon - improved reliability when processing RoMON packets on CHR;
- routerboard - show "boot-os" option only on devices that have such feature;
- switch - fixed port mirroring on devices that do not support CPU Flow Control;
- webfig - allow to change user name when creating a new system user;
- webfig - fixed time interval settings not applied properly under "IP/Kid Control/Kids" menu;
- winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;
- winbox - added "allow-dual-stack-queue" setting to "IP/DHCP Server/Leases" menu;
- winbox - added "allow-dual-stack-queue" setting to "IPv6/DHCPv6 Server/Bindings" menu;
- winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;
- winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;
- winbox - fixed corrupt user database after specifying allowed address range (introduced in v6.43);
- winbox - make bridge port "untrusted" by default when creating new port;
- winbox - show "IP/Cloud" menu on CHR;
- winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature.
Другие изменения относительно 6.43:
- chr - assign interface names based on underlying PCI device order on KVM;
- crs317 - fixed packet forwarding on bonded interfaces without hardware offloading;
- crs3xx - improved data transmission between 10G and 1G ports;
- dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;
- dhcpv6-client - log only failed pool additions;
- ethernet - fixed IPv6 packet forwarding on IPQ4018 devices;
- hotspot - properly update dynamic "walled-garden" entries when changing "dst-host";
- ike2 - added option to specify certificate chain;
- ike2 - fixed local address lookup when initiating new connection;
- ike2 - fixed rare authentication and encryption key mismatches after rekey with PFS enabled;
- lte - fixed DHCP relay packet forwarding when in passthrough mode;
- lte - fixed Jaton/SQN modems preventing router from booting properly;
- rb3011 - added IPsec hardware acceleration support;
- routerboard - fixed memory tester reporting false errors on IPQ4018 devices ("/system routerboard upgrade" required);
- sniffer - made "connection", "host", "packet" and "protocol" sections read-only;
- switch - fixed ACL rules on IPQ4018 devices;
- upnp - improved UPnP service stability when handling HTTP requests;
- w60g - added "frequency-list" setting;
- w60g - fixed interface LED status update on connection;
- winbox - allow setting "network-mode" to "auto" under LTE interface settings;
- wireless - removed "czech republic 5.8" regulatory domain information as it overlaps with "ETSI 5.7-5.8".
MikroTik RouterOS 6.44beta6
Дата выхода: 11 сентября 2018
Изменения:
- upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";
- upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;
- chr - assign interface names based on underlying PCI device order on KVM;
- crs317 - fixed packet forwarding on bonded interfaces without hardware offloading;
- crs3xx - improved data transmission between 10G and 1G ports;
- dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;
- dhcpv6-client - log only failed pool additions;
- ethernet - fixed IPv6 packet forwarding on IPQ4018 devices;
- hotspot - properly update dynamic "walled-garden" entries when changing "dst-host";
- ike2 - added option to specify certificate chain;
- ike2 - fixed local address lookup when initiating new connection;
- ike2 - fixed rare authentication and encryption key mismatches after rekey with PFS enabled;
- lte - fixed DHCP relay packet forwarding when in passthrough mode;
- lte - fixed Jaton/SQN modems preventing router from booting properly;
- rb3011 - added IPsec hardware acceleration support;
- routerboard - fixed memory tester reporting false errors on IPQ4018 devices ("/system routerboard upgrade" required);
- sniffer - made "connection", "host", "packet" and "protocol" sections read-only;
- switch - fixed ACL rules on IPQ4018 devices;
- upnp - improved UPnP service stability when handling HTTP requests;
- w60g - added "frequency-list" setting;
- w60g - fixed interface LED status update on connection;
- winbox - allow setting "network-mode" to "auto" under LTE interface settings;
- wireless - removed "czech republic 5.8" regulatory domain information as it overlaps with "ETSI 5.7-5.8".
Полезные материалы по MikroTik
Чек-лист по настройке MikroTik Проверьте свою конфигурацию по 28-ми пунктам. Подходит для RouterOS v6 и v7. Дата публикации: 2023.
На Telegram-канале Mikrotik сэнсей можно получить доступ к закрытой информации от официального тренера MikroTik. В апреле и мае 2023 будут разбираться темы Wi-Fi и QoS. Подписывайтесь