MikroTik RouterOS 6.45betaX (Testing)

Материал из MikroTik Wiki
Перейти к навигации Перейти к поиску

Подробное описание изменений в MikroTik RouterOS 6.45betaX (Testing). Официальный список исправленных ошибок, добавленного функционала и прочих доработок. Дата выхода первого набора изменений – 5 марта 2019, дата выхода последнего набора изменений – 13 июня 2019.

Чек-лист по настройке MikroTik
Проверьте свою конфигурацию по 28-ми пунктам

MikroTik RouterOS 6.45beta62

Дата выхода: 13 июня 2019

Важные комментарии:

Downgrading to any version prior to v6.43 (v6.42.12 and older) will clear all user passwords and allow password-less authentication. Please secure your router after downgrading.

Важные изменения:

  • dot1x - added support for IEEE 802.1X Port-Based Network Access Control;
  • ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap, eap-mschapv2) as initiator;
  • user - removed insecure password storage.

Изменения:

  • dot1x - added support for IEEE 802.1X Port-Based Network Access Control;
  • ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap, eap-mschapv2) as initiator;
  • bridge - correctly handle bridge host table;
  • capsman - fixed CAP system upgrading process for MMIPS;
  • certificate - added "key-type" field;
  • certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1);
  • crs3xx - fixed "tx-drop" counter;
  • defconf - fixed channel width selection for RU locked devices;
  • dhcpv4-server - added "client-mac-limit" parameter;
  • dhcpv6-client - added option to disable rapid-commit;
  • dhcpv6-server - added additional RADIUS parameters for Prefix delegation, "rate-limit" and "life-time";
  • dhcpv6-server - added "address-list" support for bindings;
  • dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters;
  • dhcpv6-server - added RADIUS accounting support with queue based statistics;
  • dhcpv6-server - added "route-distance" parameter;
  • e-mail - properly release e-mail sending session if the server's domain name can not be resolved;
  • ipsec - added dynamic comment field for "active-peers" menu inherited from identity;
  • ipsec - added "ph2-total" counter to "active-peers" menu;
  • ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods;
  • ipsec - added traffic statistics to "active-peers" menu;
  • ipsec - disallow setting "src-address" and "dst-address" for transport mode policies;
  • ipsec - renamed "remote-peers" to "active-peers";
  • ltap - renamed SIM slots "up" and "down" to "2" and "3";
  • lte - added passthrough interface subnet selection;
  • lte - fixed LTE interface running state on RBSXTLTE3-7 (introduced in v6.45beta);
  • m33g - added support for additional Serial Console port on GPIO headers;
  • routerboard - renamed 'sim' menu to 'modem';
  • snmp - fixed "send-trap" not working when "trap-generators" does not contain "temp-exception";
  • snmp - improved reliability on SNMP service packet validation;
  • winbox - added "System/SwOS" menu for all dual-boot devices;
  • winbox - do not allow setting "dns-lookup-interval" to "0".

Другие изменения относительно 6.44.3:

  • bridge - correctly add interface list as bridge port (introduced in v6.45beta34);
  • bridge - correctly display bridge FastPath status when vlan-filtering or dhcp-snooping is used;
  • bridge - fixed log message when hardware offloading is being enabled;
  • bridge - fixed port running state for non-ethernet interfaces (introduced in v6.45beta33);
  • capsman - fixed interface-list usage in access list;
  • ccr - improved packet processing after overloading interface;
  • certificate - added "key-type" field (CLI only);
  • certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
  • certificate - made RAM the default CRL storage location;
  • certificate - removed DSA (D) flag;
  • cloud - added "replace" parameter for backup "upload-file" command;
  • conntrack - fixed GRE protocol packet connection-state matching (CVE-2014-8160);
  • conntrack - significant stability and performance improvements;
  • crs317 - fixed known multicast flooding to the CPU;
  • crs3xx - added ethernet tx-drop counter;
  • crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
  • crs3xx - correctly handle switch reset (introduced in v6.45beta31);
  • crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
  • crs3xx - improved switch-chip resource allocation on CRS326, CRS328, CRS305;
  • defconf - added "custom-script" field that prints custom configuration installed by Netinstall;
  • defconf - automatically set "installation" parameter for outdoor devices;
  • defconf - changed default configuration type to AP for cAP series devices;
  • dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
  • dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
  • dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
  • dhcpv4-server - added "client-mac-limit" parameter (CLI only);
  • dhcpv4-server - added RADIUS accounting support with queue based statistics;
  • dhcpv4-server - added "vendor-class-id" matcher (CLI only);
  • dhcpv4-server - improved stability when performing "check-status" command;
  • dhcpv4-server - replaced "busy" lease status with "conflict" and "declined";
  • dhcpv6-client - added option to disable rapid-commit (CLI only);
  • dhcpv6-client - fixed status update when leaving "bound" state;
  • dhcpv6-server - added "address-list" support for bindings (CLI only);
  • dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
  • dhcpv6-server - added RADIUS accounting support with queue based statistics;
  • dhcpv6-server - added "route-distance" parameter (CLI only);
  • dhcpv6-server - fixed dynamic IPv6 binding without proper reference to the server;
  • dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
  • discovery - correctly create neighbors from VLAN tagged discovery messages;
  • discovery - fixed CDP packets not including address on slave ports (introduced in v6.44);
  • discovery - improved neighbour's MAC address detection;
  • discovery - limit max neighbour count per interface based on total RAM memory;
  • discovery - show neighbors on actual mesh ports;
  • e-mail - include "message-id" identification field in e-mail header;
  • ethernet - added support for 25Gbps and 40Gbps rates;
  • ethernet - increased loop warning threshold to 5 packets per second;
  • export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
  • fetch - added SFTP support;
  • fetch - improved user policy lookup;
  • firewall - fixed fragmented packet processing when only RAW firewall is configured;
  • firewall - process packets by firewall when accepted by RAW with disabled connection tracking;
  • gps - fixed missing minus close to zero coordinates in dd format;
  • gps - make sure "direction" parameter is upper case;
  • gps - strip unnecessary trailing characters from "longtitude" and "latitude" values;
  • hotspot - moved "title" HTML tag after "meta" tags;
  • ike1 - adjusted debug packet logging topics;
  • ike1 - fixed rekeying process when NAT is detected (introduced in v6.45beta16);
  • ike1 - general stability improvements (introduced in v6.45beta);
  • ike2 - added support for ECDSA certificate authentication (rfc4754);
  • ike2 - added support for IKE SA rekeying for initiator;
  • ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
  • ike2 - fixed first child SA generation (introduced in v6.45beta34);
  • ike2 - fixed pre-shared-key authentication failure (introduced in v6.45beta34);
  • ike2 - improved certificate verification when multiple CA certificates received from responder;
  • ike2 - improved child SA rekeying process;
  • ike2 - improved XAuth identity conversion on upgrade;
  • ike2 - prefer SAN instead of DN from certificate for ID payload;
  • ippool - improved logging for IPv6 Pool when prefix is already in use;
  • ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
  • ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
  • ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
  • ipsec - added traffic statistics to "active-peers" menu (CLI only);
  • ipsec - do not allow adding identity to a dynamic peer;
  • ipsec - fixed policies becoming invalid after changing priority;
  • ipsec - general improvements in policy handling;
  • ipsec - properly drop already established tunnel when address change detected;
  • ipsec - renamed "remote-peers" to "active-peers" (CLI only);
  • ipsec - renamed "rsa-signature" authentication method to "digital-signature";
  • ipsec - replaced policy SA address parameters with peer setting;
  • ipsec - use tunnel name for dynamic IPsec peer name;
  • ipv6 - improved system stability when receiving bogus packets;
  • lte - added initial support for Vodafone R216-Z;
  • lte - added passthrough interface subnet selection;
  • lte - added support for manual operator selection;
  • lte - allow setting empty APN;
  • lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
  • lte - do not show error message for info commands that are not supported;
  • lte - fixed session reactivation on R11e-LTE in UMTS mode;
  • lte - improved firmware upgrade process;
  • lte - improved "info" command query;
  • lte - improved R11e-4G modem operation;
  • lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
  • lte - show alphanumeric value for operator info;
  • lte - show correct firmware revision after firmware upgrade;
  • lte - use default APN name "internet" when not provided;
  • lte - use secondary DNS for DNS server configuration;
  • ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;
  • ospf - fixed opaque LSA type checking in OSPFv2;
  • ospf - improved "unknown" LSA handling in OSPFv3;
  • ovpn - added "verify-server-certificate" parameter for OVPN client (CVE-2018-10066);
  • ppp - added initial support for Quectel BG96;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • rb3011 - improved system stability when receiving bogus packets;
  • rb4011 - fixed MAC address duplication between sfp-sfpplus1 and wlan1 interfaces (wlan1 configuration reset required);
  • rb4011 - fixed SFP linking (introduced in v6.45beta6);
  • rb921 - improved system stability ("/system routerboard upgrade" required);
  • sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
  • sms - added USSD message functionality under "/tool sms" (CLI only);
  • sms - allow specifying multiple "allowed-number" values;
  • sms - fixed long message parsing (introduced in v6.45beta19);
  • sms - improved delivery report logging;
  • snmp - added "dot1dStpPortTable" OID;
  • snmp - added OID for neighbor "interface";
  • snmp - added "write-access" column to community print;
  • snmp - allow setting interface "adminStatus";
  • snmp - improved reliability on SNMP service packet validation;
  • snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
  • ssh - accept remote forwarding requests with empty hostnames;
  • ssh - added new "ssh-exec" command for non-interactive command execution;
  • ssh - fixed non-interactive multiple command execution;
  • ssh - improved remote forwarding handling (introduced in v6.44.3);
  • ssh - improved session rekeying process on exchanged data size threshold;
  • ssh - use correct user when "output-to-file" parameter is used;
  • supout - added IPv6 ND section to supout file;
  • supout - added "kid-control devices" section to supout file;
  • supout - added "pwr-line" section to supout file;
  • supout - changed IPv6 pool section to output detailed print;
  • switch - properly reapply settings after switch chip reset;
  • tftp - added "max-block-size" parameter under TFTP "settings" menu (CLI only);
  • tile - improved link fault detection on SFP+ ports;
  • tr069-client - added LTE CQI and IMSI parameter support;
  • tr069-client - fixed potential memory corruption;
  • tr069-client - improved error reporting with incorrect firware upgrade XML file;
  • traceroute - improved stability when sending large ping amounts;
  • traffic-generator - improved stability when stopping traffic generator;
  • tunnel - removed "local-address" requirement when "ipsec-secret" is used;
  • userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
  • w60g - do not show unused "dmg" parameter;
  • w60g - prefer AP with strongest signal when multiple APs with same SSID present;
  • w60g - show running frequency under "monitor" command;
  • winbox - added "System/SwOS" menu for all dual-boot devices;
  • winbox - fixed crash when opening CAPsMAN menu (introduced in v6.45beta27);
  • winbox - show "LCD" menu only on boards that have LCD screen;
  • wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
  • wireless - fixed "country-info" printing (introduced in v6.45beta27);
  • wireless - fixed frequency duplication in the frequency selection menu;
  • wireless - fixed incorrect IP header for RADIUS accounting packet;
  • wireless - improved 160MHz channel width stability on rb4011;
  • wireless - improved DFS radar detection when using non-ETSI regulated country;
  • wireless - improved installation mode selection for wireless outdoor equipment;
  • wireless - set default SSID and supplicant-identity the same as router's identity;
  • wireless - updated "china" regulatory domain information;
  • wireless - updated "india" regulatory domain information;
  • wireless - updated "new zealand" regulatory domain information;
  • www - improved client-initiated renegotiation within the SSL and TLS protocols (CVE-2011-1473).

MikroTik RouterOS 6.45beta54

Дата выхода: 24 мая 2019

Важные комментарии:

Downgrading to any version prior to v6.43 (v6.42.12 and older) will clear all user passwords and allow password-less authentication. Please secure your router after downgrading.

Важные изменения:

  • dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
  • ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap, eap-mschapv2) as initiator (CLI only);
  • user - removed insecure password storage.

Изменения:

  • user - removed insecure password storage;
  • bridge - correctly display bridge FastPath status when vlan-filtering or dhcp-snooping is used;
  • conntrack - fixed GRE protocol packet connection-state matching (CVE-2014-8160);
  • crs317 - fixed known multicast flooding to the CPU;
  • ike1 - general stability improvements (introduced in v6.45beta);
  • ike2 - added support for IKE rekeying for initiator;
  • ike2 - improved child SA rekeying process;
  • lte - added initial support for Vodafone R216-Z;
  • ovpn - added "verify-server-certificate" parameter for OVPN client (CVE-2018-10066);
  • winbox - added "System/SwOS" menu for all dual-boot devices;
  • www - improved client-initiated renegotiation within the SSL and TLS protocols (CVE-2011-1473).

Другие изменения относительно 6.44.3:

  • bridge - correctly add interface list as bridge port (introduced in v6.45beta34);
  • bridge - fixed log message when hardware offloading is being enabled;
  • bridge - fixed port running state for non-ethernet interfaces (introduced in v6.45beta33);
  • capsman - fixed interface-list usage in access list;
  • ccr - improved packet processing after overloading interface;
  • certificate - added "key-type" field (CLI only);
  • certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
  • certificate - made RAM the default CRL storage location;
  • certificate - removed DSA (D) flag;
  • cloud - added "replace" parameter for backup "upload-file" command;
  • conntrack - significant stability and performance improvements;
  • crs3xx - added ethernet tx-drop counter;
  • crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
  • crs3xx - correctly handle switch reset (introduced in v6.45beta31);
  • crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
  • crs3xx - improved switch-chip resource allocation on CRS326, CRS328, CRS305;
  • defconf - added "custom-script" field that prints custom configuration installed by Netinstall;
  • defconf - automatically set "installation" parameter for outdoor devices;
  • defconf - changed default configuration type to AP for cAP series devices;
  • dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
  • dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
  • dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
  • dhcpv4-server - added "client-mac-limit" parameter (CLI only);
  • dhcpv4-server - added RADIUS accounting support with queue based statistics;
  • dhcpv4-server - added "vendor-class-id" matcher (CLI only);
  • dhcpv4-server - improved stability when performing "check-status" command;
  • dhcpv4-server - replaced "busy" lease status with "conflict" and "declined";
  • dhcpv6-client - added option to disable rapid-commit (CLI only);
  • dhcpv6-client - fixed status update when leaving "bound" state;
  • dhcpv6-server - added "address-list" support for bindings (CLI only);
  • dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
  • dhcpv6-server - added RADIUS accounting support;
  • dhcpv6-server - added RADIUS accounting support with queue based statistics;
  • dhcpv6-server - added "route-distance" parameter (CLI only);
  • dhcpv6-server - fixed dynamic IPv6 binding without proper reference to the server;
  • dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
  • discovery - correctly create neighbors from VLAN tagged discovery messages;
  • discovery - fixed CDP packets not including address on slave ports (introduced in v6.44);
  • discovery - improved neighbour's MAC address detection;
  • discovery - limit max neighbour count per interface based on total RAM memory;
  • discovery - show neighbors on actual mesh ports;
  • e-mail - include "message-id" identification field in e-mail header;
  • ethernet - added support for 25Gbps and 40Gbps rates;
  • ethernet - increased loop warning threshold to 5 packets per second;
  • export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
  • fetch - added SFTP support;
  • fetch - improved user policy lookup;
  • firewall - fixed fragmented packet processing when only RAW firewall is configured;
  • firewall - process packets by firewall when accepted by RAW with disabled connection tracking;
  • gps - fixed missing minus close to zero coordinates in dd format;
  • gps - make sure "direction" parameter is upper case;
  • gps - strip unnecessary trailing characters from "longtitude" and "latitude" values;
  • hotspot - moved "title" HTML tag after "meta" tags;
  • ike1 - adjusted debug packet logging topics;
  • ike1 - fixed rekeying process when NAT is detected (introduced in v6.45beta16);
  • ike2 - added support for ECDSA certificate authentication (rfc4754);
  • ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
  • ike2 - fixed first child SA generation (introduced in v6.45beta34);
  • ike2 - fixed pre-shared-key authentication failure (introduced in v6.45beta34);
  • ike2 - improved certificate verification when multiple CA certificates received from responder;
  • ike2 - improved XAuth identity conversion on upgrade;
  • ike2 - prefer SAN instead of DN from certificate for ID payload;
  • ippool - improved logging for IPv6 Pool when prefix is already in use;
  • ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
  • ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
  • ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
  • ipsec - added traffic statistics to "active-peers" menu (CLI only);
  • ipsec - do not allow adding identity to a dynamic peer;
  • ipsec - fixed policies becoming invalid after changing priority;
  • ipsec - general improvements in policy handling;
  • ipsec - properly drop already established tunnel when address change detected;
  • ipsec - renamed "remote-peers" to "active-peers" (CLI only);
  • ipsec - renamed "rsa-signature" authentication method to "digital-signature";
  • ipsec - replaced policy SA address parameters with peer setting;
  • ipsec - use tunnel name for dynamic IPsec peer name;
  • ipv6 - improved system stability when receiving bogus packets;
  • lte - added passthrough interface subnet selection;
  • lte - added support for manual operator selection;
  • lte - allow setting empty APN;
  • lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
  • lte - do not show error message for info commands that are not supported;
  • lte - fixed session reactivation on R11e-LTE in UMTS mode;
  • lte - improved firmware upgrade process;
  • lte - improved "info" command query;
  • lte - improved R11e-4G modem operation;
  • lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
  • lte - show alphanumeric value for operator info;
  • lte - show correct firmware revision after firmware upgrade;
  • lte - use default APN name "internet" when not provided;
  • lte - use secondary DNS for DNS server configuration;
  • ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;
  • ospf - fixed opaque LSA type checking in OSPFv2;
  • ospf - improved "unknown" LSA handling in OSPFv3;
  • ppp - added initial support for Quectel BG96;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • rb3011 - improved system stability when receiving bogus packets;
  • rb4011 - fixed MAC address duplication between sfp-sfpplus1 and wlan1 interfaces (wlan1 configuration reset required);
  • rb4011 - fixed SFP linking (introduced in v6.45beta6);
  • rb921 - improved system stability ("/system routerboard upgrade" required);
  • sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
  • sms - added USSD message functionality under "/tool sms" (CLI only);
  • sms - allow specifying multiple "allowed-number" values;
  • sms - fixed long message parsing (introduced in v6.45beta19);
  • sms - improved delivery report logging;
  • snmp - added "dot1dStpPortTable" OID;
  • snmp - added OID for neighbor "interface";
  • snmp - added "write-access" column to community print;
  • snmp - allow setting interface "adminStatus";
  • snmp - improved reliability on SNMP service packet validation;
  • snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
  • ssh - accept remote forwarding requests with empty hostnames;
  • ssh - added new "ssh-exec" command for non-interactive command execution;
  • ssh - fixed non-interactive multiple command execution;
  • ssh - improved remote forwarding handling (introduced in v6.44.3);
  • ssh - improved session rekeying process on exchanged data size threshold;
  • ssh - use correct user when "output-to-file" parameter is used;
  • supout - added IPv6 ND section to supout file;
  • supout - added "kid-control devices" section to supout file;
  • supout - added "pwr-line" section to supout file;
  • supout - changed IPv6 pool section to output detailed print;
  • switch - properly reapply settings after switch chip reset;
  • tftp - added "max-block-size" parameter under TFTP "settings" menu (CLI only);
  • tile - improved link fault detection on SFP+ ports;
  • tr069-client - added LTE CQI and IMSI parameter support;
  • tr069-client - fixed potential memory corruption;
  • tr069-client - improved error reporting with incorrect firware upgrade XML file;
  • traceroute - improved stability when sending large ping amounts;
  • traffic-generator - improved stability when stopping traffic generator;
  • tunnel - removed "local-address" requirement when "ipsec-secret" is used;
  • userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
  • w60g - do not show unused "dmg" parameter;
  • w60g - prefer AP with strongest signal when multiple APs with same SSID present;
  • w60g - show running frequency under "monitor" command;
  • winbox - fixed crash when opening CAPsMAN menu (introduced in v6.45beta27);
  • winbox - show "LCD" menu only on boards that have LCD screen;
  • wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
  • wireless - fixed "country-info" printing (introduced in v6.45beta27);
  • wireless - fixed frequency duplication in the frequency selection menu;
  • wireless - fixed incorrect IP header for RADIUS accounting packet;
  • wireless - improved 160MHz channel width stability on rb4011;
  • wireless - improved DFS radar detection when using non-ETSI regulated country;
  • wireless - improved installation mode selection for wireless outdoor equipment;
  • wireless - set default SSID and supplicant-identity the same as router's identity;
  • wireless - updated "china" regulatory domain information;
  • wireless - updated "india" regulatory domain information;
  • wireless - updated "new zealand" regulatory domain information.

MikroTik RouterOS 6.45beta50

Дата выхода: 20 мая 2019

Важные изменения:

  • dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
  • ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap, eap-mschapv2) as initiator (CLI only).

Изменения:

  • dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
  • bridge - fixed port running state for non-ethernet interfaces (introduced in v6.45beta33);
  • ccr - improved packet processing after overloading interface;
  • crs3xx - added ethernet tx-drop counter;
  • crs3xx - improved switch-chip resource allocation on CRS326, CRS328, CRS305;
  • defconf - changed default configuration type to AP for cAP series devices;
  • dhcpv6-client - added option to disable rapid-commit (CLI only);
  • dhcpv6-server - added RADIUS accounting support with queue based statistics;
  • discovery - fixed CDP packets not including address on slave ports (introduced in v6.44);
  • firewall - process packets by firewall when accepted by RAW with disabled connection tracking;
  • ike2 - fixed pre-shared-key authentication failure (introduced in v6.45beta34);
  • ike2 - improved certificate verification when multiple CA certificates received from responder;
  • ippool - improved logging for IPv6 Pool when prefix is already in use;
  • ipv6 - improved system stability when receiving bogus packets;
  • lte - improved firmware upgrade process;
  • ospf - fixed opaque LSA type checking in OSPFv2;
  • rb3011 - improved system stability when receiving bogus packets;
  • rb4011 - fixed MAC address duplication between sfp-sfpplus1 and wlan1 interfaces (wlan1 configuration reset required);
  • snmp - improved reliability on SNMP service packet validation;
  • ssh - fixed non-interactive multiple command execution;
  • supout - added "pwr-line" section to supout file;
  • traceroute - improved stability when sending large ping amounts;
  • traffic-generator - improved stability when stopping traffic generator.

Другие изменения относительно 6.44.3:

  • bridge - correctly add interface list as bridge port (introduced in v6.45beta34);
  • bridge - fixed log message when hardware offloading is being enabled;
  • capsman - fixed interface-list usage in access list;
  • certificate - added "key-type" field (CLI only);
  • certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
  • certificate - made RAM the default CRL storage location;
  • certificate - removed DSA (D) flag;
  • cloud - added "replace" parameter for backup "upload-file" command;
  • conntrack - significant stability and performance improvements;
  • crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
  • crs3xx - correctly handle switch reset (introduced in v6.45beta31);
  • crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
  • defconf - added "custom-script" field that prints custom configuration installed by Netinstall;
  • defconf - automatically set "installation" parameter for outdoor devices;
  • dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
  • dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
  • dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
  • dhcpv4-server - added "client-mac-limit" parameter (CLI only);
  • dhcpv4-server - added RADIUS accounting support with queue based statistics;
  • dhcpv4-server - added "vendor-class-id" matcher (CLI only);
  • dhcpv4-server - improved stability when performing "check-status" command;
  • dhcpv4-server - replaced "busy" lease status with "conflict" and "declined";
  • dhcpv6-client - fixed status update when leaving "bound" state;
  • dhcpv6-server - added "address-list" support for bindings (CLI only);
  • dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
  • dhcpv6-server - added RADIUS accounting support;
  • dhcpv6-server - added "route-distance" parameter (CLI only);
  • dhcpv6-server - fixed dynamic IPv6 binding without proper reference to the server;
  • dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
  • discovery - correctly create neighbors from VLAN tagged discovery messages;
  • discovery - improved neighbour's MAC address detection;
  • discovery - limit max neighbour count per interface based on total RAM memory;
  • discovery - show neighbors on actual mesh ports;
  • e-mail - include "message-id" identification field in e-mail header;
  • ethernet - added support for 25Gbps and 40Gbps rates;
  • ethernet - increased loop warning threshold to 5 packets per second;
  • export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
  • fetch - added SFTP support;
  • fetch - improved user policy lookup;
  • firewall - fixed fragmented packet processing when only RAW firewall is configured;
  • gps - fixed missing minus close to zero coordinates in dd format;
  • gps - make sure "direction" parameter is upper case;
  • gps - strip unnecessary trailing characters from "longtitude" and "latitude" values;
  • hotspot - moved "title" HTML tag after "meta" tags;
  • ike1 - adjusted debug packet logging topics;
  • ike1 - fixed rekeying process when NAT is detected (introduced in v6.45beta16);
  • ike2 - added support for ECDSA certificate authentication (rfc4754);
  • ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
  • ike2 - fixed first child SA generation (introduced in v6.45beta34);
  • ike2 - improved XAuth identity conversion on upgrade;
  • ike2 - prefer SAN instead of DN from certificate for ID payload;
  • ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
  • ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
  • ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
  • ipsec - added traffic statistics to "active-peers" menu (CLI only);
  • ipsec - do not allow adding identity to a dynamic peer;
  • ipsec - fixed policies becoming invalid after changing priority;
  • ipsec - general improvements in policy handling;
  • ipsec - properly drop already established tunnel when address change detected;
  • ipsec - renamed "remote-peers" to "active-peers" (CLI only);
  • ipsec - renamed "rsa-signature" authentication method to "digital-signature";
  • ipsec - replaced policy SA address parameters with peer setting;
  • ipsec - use tunnel name for dynamic IPsec peer name;
  • lte - added passthrough interface subnet selection;
  • lte - added support for manual operator selection;
  • lte - allow setting empty APN;
  • lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
  • lte - do not show error message for info commands that are not supported;
  • lte - fixed session reactivation on R11e-LTE in UMTS mode;
  • lte - improved "info" command query;
  • lte - improved R11e-4G modem operation;
  • lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
  • lte - show alphanumeric value for operator info;
  • lte - show correct firmware revision after firmware upgrade;
  • lte - use default APN name "internet" when not provided;
  • lte - use secondary DNS for DNS server configuration;
  • ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;
  • ospf - improved "unknown" LSA handling in OSPFv3;
  • ppp - added initial support for Quectel BG96;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • rb4011 - fixed SFP linking (introduced in v6.45beta6);
  • rb921 - improved system stability ("/system routerboard upgrade" required);
  • sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
  • sms - added USSD message functionality under "/tool sms" (CLI only);
  • sms - allow specifying multiple "allowed-number" values;
  • sms - fixed long message parsing (introduced in v6.45beta19);
  • sms - improved delivery report logging;
  • snmp - added "dot1dStpPortTable" OID;
  • snmp - added OID for neighbor "interface";
  • snmp - added "write-access" column to community print;
  • snmp - allow setting interface "adminStatus";
  • snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
  • ssh - accept remote forwarding requests with empty hostnames;
  • ssh - added new "ssh-exec" command for non-interactive command execution;
  • ssh - improved remote forwarding handling (introduced in v6.44.3);
  • ssh - improved session rekeying process on exchanged data size threshold;
  • ssh - use correct user when "output-to-file" parameter is used;
  • supout - added IPv6 ND section to supout file;
  • supout - added "kid-control devices" section to supout file;
  • supout - changed IPv6 pool section to output detailed print;
  • switch - properly reapply settings after switch chip reset;
  • tftp - added "max-block-size" parameter under TFTP "settings" menu (CLI only);
  • tile - improved link fault detection on SFP+ ports;
  • tr069-client - added LTE CQI and IMSI parameter support;
  • tr069-client - fixed potential memory corruption;
  • tr069-client - improved error reporting with incorrect firware upgrade XML file;
  • tunnel - removed "local-address" requirement when "ipsec-secret" is used;
  • userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
  • w60g - do not show unused "dmg" parameter;
  • w60g - prefer AP with strongest signal when multiple APs with same SSID present;
  • w60g - show running frequency under "monitor" command;
  • winbox - fixed crash when opening CAPsMAN menu (introduced in v6.45beta27);
  • winbox - show "LCD" menu only on boards that have LCD screen;
  • wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
  • wireless - fixed "country-info" printing (introduced in v6.45beta27);
  • wireless - fixed frequency duplication in the frequency selection menu;
  • wireless - fixed incorrect IP header for RADIUS accounting packet;
  • wireless - improved 160MHz channel width stability on rb4011;
  • wireless - improved DFS radar detection when using non-ETSI regulated country;
  • wireless - improved installation mode selection for wireless outdoor equipment;
  • wireless - set default SSID and supplicant-identity the same as router's identity;
  • wireless - updated "china" regulatory domain information;
  • wireless - updated "india" regulatory domain information;
  • wireless - updated "new zealand" regulatory domain information.

MikroTik RouterOS 6.45beta45

Дата выхода: 13 мая 2019

Важные изменения:

  • dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
  • ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap, eap-mschapv2) as initiator (CLI only).

Изменения:

  • ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap, eap-mschapv2) as initiator (CLI only);
  • conntrack - significant stability and performance improvements;
  • dhcpv6-server - fixed dynamic IPv6 binding without proper reference to the server;
  • firewall - fixed fragmented packet processing when only RAW firewall is configured;
  • gps - fixed missing minus close to zero coordinates in dd format;
  • wireless - improved installation mode selection for wireless outdoor equipment.

Другие изменения относительно 6.44.3:

  • bridge - correctly add interface list as bridge port (introduced in v6.45beta34);
  • bridge - fixed log message when hardware offloading is being enabled;
  • capsman - fixed interface-list usage in access list;
  • certificate - added "key-type" field (CLI only);
  • certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
  • certificate - made RAM the default CRL storage location;
  • certificate - removed DSA (D) flag;
  • cloud - added "replace" parameter for backup "upload-file" command;
  • crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
  • crs3xx - correctly handle switch reset (introduced in v6.45beta31);
  • crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
  • defconf - added "custom-script" field that prints custom configuration installed by Netinstall;
  • defconf - automatically set "installation" parameter for outdoor devices;
  • dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
  • dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
  • dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
  • dhcpv4-server - added "client-mac-limit" parameter (CLI only);
  • dhcpv4-server - added RADIUS accounting support with queue based statistics;
  • dhcpv4-server - added "vendor-class-id" matcher (CLI only);
  • dhcpv4-server - improved stability when performing "check-status" command;
  • dhcpv4-server - replaced "busy" lease status with "conflict" and "declined";
  • dhcpv6-client - fixed status update when leaving "bound" state;
  • dhcpv6-server - added "address-list" support for bindings (CLI only);
  • dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
  • dhcpv6-server - added RADIUS accounting support;
  • dhcpv6-server - added "route-distance" parameter (CLI only);
  • dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
  • discovery - correctly create neighbors from VLAN tagged discovery messages;
  • discovery - improved neighbour's MAC address detection;
  • discovery - limit max neighbour count per interface based on total RAM memory;
  • discovery - show neighbors on actual mesh ports;
  • e-mail - include "message-id" identification field in e-mail header;
  • ethernet - added support for 25Gbps and 40Gbps rates;
  • ethernet - increased loop warning threshold to 5 packets per second;
  • export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
  • fetch - added SFTP support;
  • fetch - improved user policy lookup;
  • gps - make sure "direction" parameter is upper case;
  • gps - strip unnecessary trailing characters from "longtitude" and "latitude" values;
  • hotspot - moved "title" HTML tag after "meta" tags;
  • ike1 - adjusted debug packet logging topics;
  • ike1 - fixed rekeying process when NAT is detected (introduced in v6.45beta16);
  • ike2 - added support for ECDSA certificate authentication (rfc4754);
  • ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
  • ike2 - fixed first child SA generation (introduced in v6.45beta34);
  • ike2 - improved XAuth identity conversion on upgrade;
  • ike2 - prefer SAN instead of DN from certificate for ID payload;
  • ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
  • ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
  • ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
  • ipsec - added traffic statistics to "active-peers" menu (CLI only);
  • ipsec - do not allow adding identity to a dynamic peer;
  • ipsec - fixed policies becoming invalid after changing priority;
  • ipsec - general improvements in policy handling;
  • ipsec - properly drop already established tunnel when address change detected;
  • ipsec - renamed "remote-peers" to "active-peers" (CLI only);
  • ipsec - renamed "rsa-signature" authentication method to "digital-signature";
  • ipsec - replaced policy SA address parameters with peer setting;
  • ipsec - use tunnel name for dynamic IPsec peer name;
  • lte - added passthrough interface subnet selection;
  • lte - added support for manual operator selection;
  • lte - allow setting empty APN;
  • lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
  • lte - do not show error message for info commands that are not supported;
  • lte - fixed session reactivation on R11e-LTE in UMTS mode;
  • lte - improved "info" command query;
  • lte - improved R11e-4G modem operation;
  • lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
  • lte - show alphanumeric value for operator info;
  • lte - show correct firmware revision after firmware upgrade;
  • lte - use default APN name "internet" when not provided;
  • lte - use secondary DNS for DNS server configuration;
  • ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;
  • ospf - improved "unknown" LSA handling in OSPFv3;
  • ppp - added initial support for Quectel BG96;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • rb4011 - fixed SFP linking (introduced in v6.45beta6);
  • rb921 - improved system stability ("/system routerboard upgrade" required);
  • sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
  • sms - added USSD message functionality under "/tool sms" (CLI only);
  • sms - allow specifying multiple "allowed-number" values;
  • sms - fixed long message parsing (introduced in v6.45beta19);
  • sms - improved delivery report logging;
  • snmp - added "dot1dStpPortTable" OID;
  • snmp - added OID for neighbor "interface";
  • snmp - added "write-access" column to community print;
  • snmp - allow setting interface "adminStatus";
  • snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
  • ssh - accept remote forwarding requests with empty hostnames;
  • ssh - added new "ssh-exec" command for non-interactive command execution;
  • ssh - improved remote forwarding handling (introduced in v6.44.3);
  • ssh - improved session rekeying process on exchanged data size threshold;
  • ssh - use correct user when "output-to-file" parameter is used;
  • supout - added IPv6 ND section to supout file;
  • supout - added "kid-control devices" section to supout file;
  • supout - changed IPv6 pool section to output detailed print;
  • switch - properly reapply settings after switch chip reset;
  • tftp - added "max-block-size" parameter under TFTP "settings" menu (CLI only);
  • tile - improved link fault detection on SFP+ ports;
  • tr069-client - added LTE CQI and IMSI parameter support;
  • tr069-client - fixed potential memory corruption;
  • tr069-client - improved error reporting with incorrect firware upgrade XML file;
  • tunnel - removed "local-address" requirement when "ipsec-secret" is used;
  • userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
  • w60g - do not show unused "dmg" parameter;
  • w60g - prefer AP with strongest signal when multiple APs with same SSID present;
  • w60g - show running frequency under "monitor" command;
  • winbox - fixed crash when opening CAPsMAN menu (introduced in v6.45beta27);
  • winbox - show "LCD" menu only on boards that have LCD screen;
  • wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
  • wireless - fixed "country-info" printing (introduced in v6.45beta27);
  • wireless - fixed frequency duplication in the frequency selection menu;
  • wireless - fixed incorrect IP header for RADIUS accounting packet;
  • wireless - improved 160MHz channel width stability on rb4011;
  • wireless - improved DFS radar detection when using non-ETSI regulated country;
  • wireless - improved installation mode selection for wireless outdoor equipment;
  • wireless - set default SSID and supplicant-identity the same as router's identity;
  • wireless - updated "china" regulatory domain information;
  • wireless - updated "india" regulatory domain information;
  • wireless - updated "new zealand" regulatory domain information.

MikroTik RouterOS 6.45beta42

Дата выхода: 8 мая 2019

Важные изменения:

  • dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
  • ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap) as initiator (CLI only).

Изменения:

  • dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
  • capsman - fixed interface-list usage in access list;
  • cloud - added "replace" parameter for backup "upload-file" command;
  • crs3xx - correctly handle switch reset (introduced in v6.45beta31);
  • defconf - added "custom-script" field that prints custom configuration installed by Netinstall;
  • defconf - automatically set "installation" parameter for outdoor devices;
  • dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
  • dhcpv4-server - added RADIUS accounting support with queue based statistics;
  • dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
  • discovery - correctly create neighbors from VLAN tagged discovery messages;
  • discovery - show neighbors on actual mesh ports;
  • ethernet - increased loop warning threshold to 5 packets per second;
  • gps - make sure "direction" parameter is upper case;
  • gps - strip unnecessary trailing characters from "longtitude" and "latitude" values;
  • hotspot - moved "title" HTML tag after "meta" tags;
  • ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
  • rb921 - improved system stability ("/system routerboard upgrade" required);
  • ssh - accept remote forwarding requests with empty hostnames;
  • ssh - improved remote forwarding handling (introduced in v6.44.3);
  • tr069-client - improved error reporting with incorrect firware upgrade XML file;
  • w60g - do not show unused "dmg" parameter;
  • w60g - show running frequency under "monitor" command;
  • winbox - show "LCD" menu only on boards that have LCD screen;
  • wireless - fixed frequency duplication in the frequency selection menu;
  • wireless - improved 160MHz channel width stability on rb4011;
  • wireless - improved installation mode selection for wireless outdoor equipment;
  • wireless - set default SSID and supplicant-identity the same as router's identity;
  • wireless - updated "china" regulatory domain information.

Другие изменения относительно 6.44.3:

  • bridge - correctly add interface list as bridge port (introduced in v6.45beta34);
  • bridge - fixed log message when hardware offloading is being enabled;
  • certificate - added "key-type" field (CLI only);
  • certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
  • certificate - made RAM the default CRL storage location;
  • certificate - removed DSA (D) flag;
  • crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
  • crs3xx - correctly handle switch reset (introduced in v6.45beta34);
  • crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
  • dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
  • dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
  • dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
  • dhcpv4-server - added "client-mac-limit" parameter (CLI only);
  • dhcpv4-server - added "vendor-class-id" matcher (CLI only);
  • dhcpv4-server - improved stability when performing "check-status" command;
  • dhcpv4-server - replaced "busy" lease status with "conflict" and "declined";
  • dhcpv6-client - fixed status update when leaving "bound" state;
  • dhcpv6-server - added "address-list" support for bindings (CLI only);
  • dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
  • dhcpv6-server - added RADIUS accounting support;
  • dhcpv6-server - added "route-distance" parameter (CLI only);
  • dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
  • discovery - improved neighbour's MAC address detection;
  • discovery - limit max neighbour count per interface based on total RAM memory;
  • e-mail - include "message-id" identification field in e-mail header;
  • ethernet - added support for 25Gbps and 40Gbps rates;
  • export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
  • fetch - added SFTP support;
  • fetch - improved user policy lookup;
  • ike1 - adjusted debug packet logging topics;
  • ike1 - fixed rekeying process when NAT is detected (introduced in v6.45beta16);
  • ike2 - added support for ECDSA certificate authentication (rfc4754);
  • ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
  • ike2 - fixed first child SA generation (introduced in v6.45beta34);
  • ike2 - improved XAuth identity conversion on upgrade;
  • ike2 - prefer SAN instead of DN from certificate for ID payload;
  • ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
  • ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
  • ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
  • ipsec - added traffic statistics to "active-peers" menu (CLI only);
  • ipsec - do not allow adding identity to a dynamic peer;
  • ipsec - fixed policies becoming invalid after changing priority;
  • ipsec - general improvements in policy handling;
  • ipsec - properly drop already established tunnel when address change detected;
  • ipsec - renamed "remote-peers" to "active-peers" (CLI only);
  • ipsec - renamed "rsa-signature" authentication method to "digital-signature";
  • ipsec - replaced policy SA address parameters with peer setting;
  • ipsec - use tunnel name for dynamic IPsec peer name;
  • lte - added passthrough interface subnet selection;
  • lte - added support for manual operator selection;
  • lte - allow setting empty APN;
  • lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
  • lte - do not show error message for info commands that are not supported;
  • lte - fixed session reactivation on R11e-LTE in UMTS mode;
  • lte - improved "info" command query;
  • lte - improved R11e-4G modem operation;
  • lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
  • lte - show alphanumeric value for operator info;
  • lte - show correct firmware revision after firmware upgrade;
  • lte - use default APN name "internet" when not provided;
  • lte - use secondary DNS for DNS server configuration;
  • ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;
  • ospf - improved "unknown" LSA handling in OSPFv3;
  • ppp - added initial support for Quectel BG96;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • rb4011 - fixed SFP linking (introduced in v6.45beta6);
  • sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
  • sms - added USSD message functionality under "/tool sms" (CLI only);
  • sms - allow specifying multiple "allowed-number" values;
  • sms - fixed long message parsing (introduced in v6.45beta19);
  • sms - improved delivery report logging;
  • snmp - added "dot1dStpPortTable" OID;
  • snmp - added OID for neighbor "interface";
  • snmp - added "write-access" column to community print;
  • snmp - allow setting interface "adminStatus";
  • snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
  • ssh - added new "ssh-exec" command for non-interactive command execution;
  • ssh - improved session rekeying process on exchanged data size threshold;
  • ssh - use correct user when "output-to-file" parameter is used;
  • supout - added IPv6 ND section to supout file;
  • supout - added "kid-control devices" section to supout file;
  • supout - changed IPv6 pool section to output detailed print;
  • switch - properly reapply settings after switch chip reset;
  • tftp - added "max-block-size" parameter under TFTP "settings" menu (CLI only);
  • tile - improved link fault detection on SFP+ ports;
  • tr069-client - added LTE CQI and IMSI parameter support;
  • tr069-client - fixed potential memory corruption;
  • tunnel - removed "local-address" requirement when "ipsec-secret" is used;
  • userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
  • w60g - prefer AP with strongest signal when multiple APs with same SSID present;
  • winbox - fixed crash when opening CAPsMAN menu (introduced in v6.45beta27);
  • wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
  • wireless - fixed "country-info" printing (introduced in v6.45beta27);
  • wireless - fixed incorrect IP header for RADIUS accounting packet;
  • wireless - improved DFS radar detection when using non-ETSI regulated country;
  • wireless - updated "india" regulatory domain information;
  • wireless - updated "new zealand" regulatory domain information.

MikroTik RouterOS 6.45beta37

Дата выхода: 25 апреля 2019

Важные изменения:

  • dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
  • ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap) as initiator (CLI only).

Изменения:

  • dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
  • ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap) as initiator (CLI only);
  • bridge - correctly add interface list as bridge port (introduced in v6.45beta34);
  • crs3xx - correctly handle switch reset (introduced in v6.45beta34);
  • ike2 - fixed first child SA generation (introduced in v6.45beta34);
  • ipsec - general improvements in policy handling;
  • lte - allow setting empty APN;
  • supout - added IPv6 ND section to supout file;
  • tftp - added "max-block-size" parameter under TFTP "settings" menu (CLI only).

Другие изменения относительно 6.44.3:

  • bridge - fixed log message when hardware offloading is being enabled;
  • certificate - added "key-type" field (CLI only);
  • certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
  • certificate - made RAM the default CRL storage location;
  • certificate - removed DSA (D) flag;
  • crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
  • crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
  • dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
  • dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
  • dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
  • dhcpv4-server - added "client-mac-limit" parameter (CLI only);
  • dhcpv4-server - added "vendor-class-id" matcher (CLI only);
  • dhcpv4-server - improved stability when performing "check-status" command;
  • dhcpv4-server - replaced "busy" lease status with "conflict" and "declined";
  • dhcpv6-client - fixed status update when leaving "bound" state;
  • dhcpv6-server - added "address-list" support for bindings (CLI only);
  • dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
  • dhcpv6-server - added RADIUS accounting support;
  • dhcpv6-server - added "route-distance" parameter (CLI only);
  • dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
  • discovery - improved neighbour's MAC address detection;
  • discovery - limit max neighbour count per interface based on total RAM memory;
  • e-mail - include "message-id" identification field in e-mail header;
  • ethernet - added support for 25Gbps and 40Gbps rates;
  • export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
  • fetch - added SFTP support;
  • fetch - improved user policy lookup;
  • ike1 - adjusted debug packet logging topics;
  • ike1 - fixed rekeying process when NAT is detected (introduced in v6.45beta16);
  • ike2 - added support for ECDSA certificate authentication (rfc4754);
  • ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
  • ike2 - improved XAuth identity conversion on upgrade;
  • ike2 - prefer SAN instead of DN from certificate for ID payload;
  • ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
  • ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
  • ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
  • ipsec - added traffic statistics to "active-peers" menu (CLI only);
  • ipsec - do not allow adding identity to a dynamic peer;
  • ipsec - fixed policies becoming invalid after changing priority;
  • ipsec - general improvements in policy handling;
  • ipsec - properly drop already established tunnel when address change detected;
  • ipsec - renamed "remote-peers" to "active-peers" (CLI only);
  • ipsec - renamed "rsa-signature" authentication method to "digital-signature";
  • ipsec - replaced policy SA address parameters with peer setting;
  • ipsec - use tunnel name for dynamic IPsec peer name;
  • lte - added passthrough interface subnet selection;
  • lte - added support for manual operator selection;
  • lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
  • lte - do not show error message for info commands that are not supported;
  • lte - fixed session reactivation on R11e-LTE in UMTS mode;
  • lte - improved "info" command query;
  • lte - improved R11e-4G modem operation;
  • lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
  • lte - show alphanumeric value for operator info;
  • lte - show correct firmware revision after firmware upgrade;
  • lte - use default APN name "internet" when not provided;
  • lte - use secondary DNS for DNS server configuration;
  • ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;
  • ospf - improved "unknown" LSA handling in OSPFv3;
  • ppp - added initial support for Quectel BG96;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • rb4011 - fixed SFP linking (introduced in v6.45beta6);
  • sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
  • sms - added USSD message functionality under "/tool sms" (CLI only);
  • sms - allow specifying multiple "allowed-number" values;
  • sms - fixed long message parsing (introduced in v6.45beta19);
  • sms - improved delivery report logging;
  • snmp - added "dot1dStpPortTable" OID;
  • snmp - added OID for neighbor "interface";
  • snmp - added "write-access" column to community print;
  • snmp - allow setting interface "adminStatus";
  • snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
  • ssh - added new "ssh-exec" command for non-interactive command execution;
  • ssh - improved session rekeying process on exchanged data size threshold;
  • ssh - use correct user when "output-to-file" parameter is used;
  • supout - added "kid-control devices" section to supout file;
  • supout - changed IPv6 pool section to output detailed print;
  • switch - properly reapply settings after switch chip reset;
  • tile - improved link fault detection on SFP+ ports;
  • tr069-client - added LTE CQI and IMSI parameter support;
  • tr069-client - fixed potential memory corruption;
  • tunnel - removed "local-address" requirement when "ipsec-secret" is used;
  • userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
  • w60g - prefer AP with strongest signal when multiple APs with same SSID present;
  • winbox - fixed crash when opening CAPsMAN menu (introduced in v6.45beta27);
  • wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
  • wireless - fixed "country-info" printing (introduced in v6.45beta27);
  • wireless - fixed incorrect IP header for RADIUS accounting packet;
  • wireless - improved DFS radar detection when using non-ETSI regulated country;
  • wireless - updated "india" regulatory domain information;
  • wireless - updated "new zealand" regulatory domain information.

MikroTik RouterOS 6.45beta34

Дата выхода: 18 апреля 2019

Важные изменения:

  • dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only).

Изменения:

  • dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
  • dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
  • dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
  • dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
  • dhcpv4-server - replaced "busy" lease status with "conflict" and "declined";
  • dhcpv6-client - fixed status update when leaving "bound" state;
  • dhcpv6-server - override prefix pool and/or DNS server settings by values received from RADIUS;
  • e-mail - include "message-id" identification field in e-mail header;
  • ike1 - fixed rekeying process when NAT is detected (introduced in v6.45beta16);
  • ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;
  • ospf - improved "unknown" LSA handling in OSPFv3;
  • supout - changed IPv6 pool section to output detailed print;
  • tr069-client - added LTE CQI and IMSI parameter support;
  • tr069-client - fixed potential memory corruption;
  • winbox - fixed crash when opening CAPsMAN menu (introduced in v6.45beta27);
  • wireless - fixed "country-info" printing (introduced in v6.45beta27).

Другие изменения относительно 6.44.2:

  • bridge - fixed log message when hardware offloading is being enabled;
  • certificate - added "key-type" field (CLI only);
  • certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
  • certificate - fixed SAN being duplicated on status change (introduced in v6.44);
  • certificate - made RAM the default CRL storage location;
  • certificate - removed DSA (D) flag;
  • conntrack - fixed "loose-tcp-tracking" parameter not taken in action (introduced in v6.44);
  • crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
  • crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
  • dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
  • dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
  • dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
  • dhcpv4-server - added "client-mac-limit" parameter (CLI only);
  • dhcpv4-server - added "vendor-class-id" matcher (CLI only);
  • dhcpv4-server - fixed commenting option for alerts;
  • dhcpv4-server - improved stability when performing "check-status" command;
  • dhcpv6-server - added "address-list" support for bindings (CLI only);
  • dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
  • dhcpv6-server - added RADIUS accounting support;
  • dhcpv6-server - added "route-distance" parameter (CLI only);
  • dhcpv6-server - fixed binding setting update from RADIUS;
  • discovery - improved neighbour's MAC address detection;
  • discovery - limit max neighbour count per interface based on total RAM memory;
  • ethernet - added support for 25Gbps and 40Gbps rates;
  • export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
  • fetch - added SFTP support;
  • fetch - improved user policy lookup;
  • ike1 - adjusted debug packet logging topics;
  • ike1 - improved stability for transport mode policies on initiator side;
  • ike2 - added support for ECDSA certificate authentication (rfc4754);
  • ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
  • ike2 - improved XAuth identity conversion on upgrade;
  • ike2 - prefer SAN instead of DN from certificate for ID payload;
  • ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
  • ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
  • ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
  • ipsec - added traffic statistics to "active-peers" menu (CLI only);
  • ipsec - do not allow adding identity to a dynamic peer;
  • ipsec - fixed freshly created identity not taken in action;
  • ipsec - fixed policies becoming invalid after changing priority;
  • ipsec - fixed possible configuration corruption after import;
  • ipsec - general improvements in policy handling;
  • ipsec - properly drop already established tunnel when address change detected;
  • ipsec - renamed "remote-peers" to "active-peers" (CLI only);
  • ipsec - renamed "rsa-signature" authentication method to "digital-signature";
  • ipsec - replaced policy SA address parameters with peer setting;
  • ipsec - use tunnel name for dynamic IPsec peer name;
  • ipv6 - adjusted IPv6 route cache max size;
  • ipv6 - improved IPv6 neighbor table updating process;
  • lte - added passthrough interface subnet selection;
  • lte - added support for manual operator selection;
  • lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
  • lte - do not show error message for info commands that are not supported;
  • lte - fixed session reactivation on R11e-LTE in UMTS mode;
  • lte - improved "info" command query;
  • lte - improved R11e-4G modem operation;
  • lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
  • lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
  • lte - show alphanumeric value for operator info;
  • lte - show correct firmware revision after firmware upgrade;
  • lte - use default APN name "internet" when not provided;
  • lte - use secondary DNS for DNS server configuration;
  • ppp - added initial support for Quectel BG96;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • rb2011 - removed "sfp-led" from "System/LEDs" menu;
  • rb4011 - fixed SFP linking (introduced in v6.45beta6);
  • sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
  • smb - fixed possible buffer overflow;
  • sms - added USSD message functionality under "/tool sms" (CLI only);
  • sms - allow specifying multiple "allowed-number" values;
  • sms - fixed long message parsing (introduced in v6.45beta19);
  • sms - improved delivery report logging;
  • snmp - added "dot1dStpPortTable" OID;
  • snmp - added OID for neighbor "interface";
  • snmp - added "radio-name" (mtxrWlRtabRadioName) OID support;
  • snmp - added "write-access" column to community print;
  • snmp - allow setting interface "adminStatus";
  • snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
  • ssh - added "both", "local" and "remote" options for "forwarding-enabled" parameter;
  • ssh - added new "ssh-exec" command for non-interactive command execution;
  • ssh - do not generate host key on configuration export;
  • ssh - fixed multiline non-interactive command execution;
  • ssh - improved session rekeying process on exchanged data size threshold;
  • ssh - use correct user when "output-to-file" parameter is used;
  • supout - added "kid-control devices" section to supout file;
  • switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
  • switch - properly reapply settings after switch chip reset;
  • tile - improved link fault detection on SFP+ ports;
  • tunnel - removed "local-address" requirement when "ipsec-secret" is used;
  • userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
  • userman - updated authorize.net gateway DNS name;
  • w60g - prefer AP with strongest signal when multiple APs with same SSID present;
  • wireless - added support for US FCC UNII-2 and Canada country profiles for LHG-5HPnD-US, RBLHG-5HPnD-XL-US and SXTsq5HPnD-US devices;
  • wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
  • wireless - fixed incorrect IP header for RADIUS accounting packet;
  • wireless - improved DFS radar detection when using non-ETSI regulated country;
  • wireless - improved wireless country settings for EU countries;
  • wireless - updated "india" regulatory domain information;
  • wireless - updated "new zealand" regulatory domain information.

MikroTik RouterOS 6.45beta31

Дата выхода: 12 апреля 2019

Важные изменения:

  • dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only).

Изменения:

  • dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);
  • conntrack - fixed "loose-tcp-tracking" parameter not taken in action (introduced in v6.44);
  • dhcp - create dual stack queue based on limitations specified on DHCPv4 server lease configuration;
  • dhcp - do not require lease and binding to have the same configuration for dual-stack queues;
  • dhcp - show warning in log if lease and binding dual-stack related parameters do not match and create separate queues;
  • dhcpv4-server - added "client-mac-limit" parameter (CLI only);
  • dhcpv6-server - added "insert-queue-before" and "parent-queue" parameters (CLI only);
  • dhcpv6-server - added "route-distance" parameter (CLI only);
  • dhcpv6-server - fixed binding setting update from RADIUS;
  • fetch - added SFTP support;
  • ipsec - added support for RADIUS accounting for "eap-radius" and "pre-shared-key-xauth" authentication methods (CLI only);
  • ipsec - added traffic statistics to "active-peers" menu (CLI only);
  • ipsec - general improvements in policy handling;
  • ipsec - replaced policy SA address parameters with peer setting;
  • ipsec - use tunnel name for dynamic IPsec peer name;
  • ipv6 - adjusted IPv6 route cache max size;
  • lte - fixed session reactivation on R11e-LTE in UMTS mode;
  • snmp - added "radio-name" (mtxrWlRtabRadioName) OID support;
  • ssh - added "both", "local" and "remote" options for "forwarding-enabled" parameter;
  • tunnel - removed "local-address" requirement when "ipsec-secret" is used;
  • userman - added support for "Delegated-IPv6-Pool";
  • userman - added support for "Delegated-IPv6-Pool" and "DNS-Server-IPv6-Address" (CLI only);
  • wireless - improved wireless country settings for EU countries.

Другие изменения относительно 6.44.2:

  • bridge - fixed log message when hardware offloading is being enabled;
  • certificate - added "key-type" field (CLI only);
  • certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
  • certificate - fixed SAN being duplicated on status change (introduced in v6.44);
  • certificate - made RAM the default CRL storage location;
  • certificate - removed DSA (D) flag;
  • crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
  • crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
  • dhcpv4-server - added "vendor-class-id" matcher (CLI only);
  • dhcpv4-server - fixed commenting option for alerts;
  • dhcpv4-server - improved stability when performing "check-status" command;
  • dhcpv6-server - added "address-list" support for bindings (CLI only);
  • dhcpv6-server - added RADIUS accounting support;
  • discovery - improved neighbour's MAC address detection;
  • discovery - limit max neighbour count per interface based on total RAM memory;
  • ethernet - added support for 25Gbps and 40Gbps rates;
  • export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
  • fetch - added SFTP support;
  • fetch - improved user policy lookup;
  • ike1 - adjusted debug packet logging topics;
  • ike1 - improved stability for transport mode policies on initiator side;
  • ike2 - added support for ECDSA certificate authentication (rfc4754);
  • ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
  • ike2 - improved XAuth identity conversion on upgrade;
  • ike2 - prefer SAN instead of DN from certificate for ID payload;
  • ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
  • ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
  • ipsec - added support for RADIUS accounting;
  • ipsec - added traffic statistics to "active-peers" menu (CLI only);
  • ipsec - do not allow adding identity to a dynamic peer;
  • ipsec - fixed freshly created identity not taken in action;
  • ipsec - fixed policies becoming invalid after changing priority;
  • ipsec - fixed possible configuration corruption after import;
  • ipsec - properly drop already established tunnel when address change detected;
  • ipsec - renamed "remote-peers" to "active-peers" (CLI only);
  • ipsec - renamed "rsa-signature" authentication method to "digital-signature";
  • ipv6 - improved IPv6 neighbor table updating process;
  • lte - added passthrough interface subnet selection;
  • lte - added support for manual operator selection;
  • lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
  • lte - do not show error message for info commands that are not supported;
  • lte - improved "info" command query;
  • lte - improved R11e-4G modem operation;
  • lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
  • lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
  • lte - show alphanumeric value for operator info;
  • lte - show correct firmware revision after firmware upgrade;
  • lte - use default APN name "internet" when not provided;
  • lte - use secondary DNS for DNS server configuration;
  • ppp - added initial support for Quectel BG96;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • rb2011 - removed "sfp-led" from "System/LEDs" menu;
  • rb4011 - fixed SFP linking (introduced in v6.45beta6);
  • sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
  • smb - fixed possible buffer overflow;
  • sms - added USSD message functionality under "/tool sms" (CLI only);
  • sms - allow specifying multiple "allowed-number" values;
  • sms - fixed long message parsing (introduced in v6.45beta19);
  • sms - improved delivery report logging;
  • snmp - added "dot1dStpPortTable" OID;
  • snmp - added OID for neighbor "interface";
  • snmp - added "write-access" column to community print;
  • snmp - allow setting interface "adminStatus";
  • snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
  • ssh - added new "ssh-exec" command for non-interactive command execution;
  • ssh - do not generate host key on configuration export;
  • ssh - fixed multiline non-interactive command execution;
  • ssh - improved session rekeying process on exchanged data size threshold;
  • ssh - use correct user when "output-to-file" parameter is used;
  • supout - added "kid-control devices" section to supout file;
  • switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
  • switch - properly reapply settings after switch chip reset;
  • tile - improved link fault detection on SFP+ ports;
  • userman - updated authorize.net gateway DNS name;
  • w60g - prefer AP with strongest signal when multiple APs with same SSID present;
  • wireless - added support for US FCC UNII-2 and Canada country profiles for LHG-5HPnD-US, RBLHG-5HPnD-XL-US and SXTsq5HPnD-US devices;
  • wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
  • wireless - fixed incorrect IP header for RADIUS accounting packet;
  • wireless - improved DFS radar detection when using non-ETSI regulated country;
  • wireless - updated "india" regulatory domain information;
  • wireless - updated "new zealand" regulatory domain information.

MikroTik RouterOS 6.45beta27

Дата выхода: 3 апреля 2019

Изменения:

  • dhcpv4-server - fixed commenting option for alerts;
  • dhcpv6-server - added "address-list" support for bindings (CLI only);
  • discovery - limit max neighbour count per interface based on total RAM memory;
  • discovery - improved neighbour's MAC address detection;
  • fetch - added SFTP support;
  • ipsec - fixed possible configuration corruption after import;
  • ipv6 - improved IPv6 neighbor table updating process;
  • rb2011 - removed "sfp-led" from "System/LEDs" menu;
  • ssh - added new "ssh-exec" command for non-interactive command execution;
  • ssh - fixed multiline non-interactive command execution;
  • wireless - added support for US FCC UNII-2 and Canada country profiles for LHG-5HPnD-US, RBLHG-5HPnD-XL-US and SXTsq5HPnD-US devices.

Другие изменения относительно 6.44.2:

  • bridge - fixed log message when hardware offloading is being enabled;
  • certificate - added "key-type" field (CLI only);
  • certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
  • certificate - fixed SAN being duplicated on status change (introduced in v6.44);
  • certificate - made RAM the default CRL storage location;
  • certificate - removed DSA (D) flag;
  • crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
  • crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
  • dhcpv4-server - added "vendor-class-id" matcher (CLI only);
  • dhcpv4-server - improved stability when performing "check-status" command;
  • dhcpv6-server - added "address-list" support for bindings (CLI only);
  • dhcpv6-server - added RADIUS accounting support;
  • ethernet - added support for 25Gbps and 40Gbps rates;
  • export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
  • fetch - added SFTP support;
  • fetch - improved user policy lookup;
  • ike1 - adjusted debug packet logging topics;
  • ike1 - improved stability for transport mode policies on initiator side;
  • ike2 - added support for ECDSA certificate authentication (rfc4754);
  • ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
  • ike2 - improved XAuth identity conversion on upgrade;
  • ike2 - prefer SAN instead of DN from certificate for ID payload;
  • ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
  • ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
  • ipsec - added support for RADIUS accounting;
  • ipsec - added traffic statistics to "active-peers" menu (CLI only);
  • ipsec - do not allow adding identity to a dynamic peer;
  • ipsec - fixed freshly created identity not taken in action;
  • ipsec - fixed policies becoming invalid after changing priority;
  • ipsec - properly drop already established tunnel when address change detected;
  • ipsec - renamed "remote-peers" to "active-peers" (CLI only);
  • ipsec - renamed "rsa-signature" authentication method to "digital-signature";
  • lte - added passthrough interface subnet selection;
  • lte - added support for manual operator selection;
  • lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
  • lte - do not show error message for info commands that are not supported;
  • lte - improved "info" command query;
  • lte - improved R11e-4G modem operation;
  • lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
  • lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
  • lte - show alphanumeric value for operator info;
  • lte - show correct firmware revision after firmware upgrade;
  • lte - use default APN name "internet" when not provided;
  • lte - use secondary DNS for DNS server configuration;
  • ppp - added initial support for Quectel BG96;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • rb4011 - fixed SFP linking (introduced in v6.45beta6);
  • sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
  • smb - fixed possible buffer overflow;
  • sms - added USSD message functionality under "/tool sms" (CLI only);
  • sms - allow specifying multiple "allowed-number" values;
  • sms - fixed long message parsing (introduced in v6.45beta19);
  • sms - improved delivery report logging;
  • snmp - added "dot1dStpPortTable" OID;
  • snmp - added OID for neighbor "interface";
  • snmp - added "write-access" column to community print;
  • snmp - allow setting interface "adminStatus";
  • snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
  • ssh - do not generate host key on configuration export;
  • ssh - fixed multiline non-interactive command execution;
  • ssh - improved session rekeying process on exchanged data size threshold;
  • ssh - use correct user when "output-to-file" parameter is used;
  • supout - added "kid-control devices" section to supout file;
  • switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
  • switch - properly reapply settings after switch chip reset;
  • tile - improved link fault detection on SFP+ ports;
  • userman - updated authorize.net gateway DNS name;
  • w60g - prefer AP with strongest signal when multiple APs with same SSID present;
  • wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
  • wireless - fixed incorrect IP header for RADIUS accounting packet;
  • wireless - improved DFS radar detection when using non-ETSI regulated country;
  • wireless - updated "india" regulatory domain information;
  • wireless - updated "new zealand" regulatory domain information.

MikroTik RouterOS 6.45beta23

Дата выхода: 1 апреля 2019

Важные изменения:

  • ipv6 - fixed soft lockup when forwarding IPv6 packets;
  • ipv6 - fixed soft lockup when processing large IPv6 Neighbor table.

Изменения:

  • ipsec - properly drop already established tunnel when address change detected;
  • ipv6 - adjust IPv6 route cache max size based on total RAM memory;
  • smb - fixed possible buffer overflow.

Другие изменения относительно 6.44.1:

  • bridge - fixed log message when hardware offloading is being enabled;
  • certificate - added "key-type" field (CLI only);
  • certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
  • certificate - fixed SAN being duplicated on status change (introduced in v6.44);
  • certificate - made RAM the default CRL storage location;
  • certificate - removed DSA (D) flag;
  • crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
  • crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
  • dhcpv4-server - added "vendor-class-id" matcher (CLI only);
  • dhcpv4-server - improved stability when performing "check-status" command;
  • dhcpv6-server - added "address-list" support for bindings (CLI only);
  • dhcpv6-server - added RADIUS accounting support;
  • ethernet - added support for 25Gbps and 40Gbps rates;
  • export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
  • fetch - added SFTP support;
  • fetch - improved user policy lookup;
  • ike1 - adjusted debug packet logging topics;
  • ike1 - improved stability for transport mode policies on initiator side;
  • ike2 - added support for ECDSA certificate authentication (rfc4754);
  • ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
  • ike2 - improved XAuth identity conversion on upgrade;
  • ike2 - prefer SAN instead of DN from certificate for ID payload;
  • ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
  • ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
  • ipsec - added support for RADIUS accounting;
  • ipsec - added traffic statistics to "active-peers" menu (CLI only);
  • ipsec - do not allow adding identity to a dynamic peer;
  • ipsec - fixed freshly created identity not taken in action;
  • ipsec - fixed policies becoming invalid after changing priority;
  • ipsec - renamed "remote-peers" to "active-peers" (CLI only);
  • ipsec - renamed "rsa-signature" authentication method to "digital-signature";
  • lte - added passthrough interface subnet selection;
  • lte - added support for manual operator selection;
  • lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
  • lte - do not show error message for info commands that are not supported;
  • lte - improved "info" command query;
  • lte - improved R11e-4G modem operation;
  • lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
  • lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
  • lte - show alphanumeric value for operator info;
  • lte - show correct firmware revision after firmware upgrade;
  • lte - use default APN name "internet" when not provided;
  • lte - use secondary DNS for DNS server configuration;
  • ppp - added initial support for Quectel BG96;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • rb4011 - fixed SFP linking (introduced in v6.45beta6);
  • sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
  • smb - fixed possible buffer overflow;
  • sms - added USSD message functionality under "/tool sms" (CLI only);
  • sms - allow specifying multiple "allowed-number" values;
  • sms - fixed long message parsing (introduced in v6.45beta19);
  • sms - improved delivery report logging;
  • snmp - added "dot1dStpPortTable" OID;
  • snmp - added OID for neighbor "interface";
  • snmp - added "write-access" column to community print;
  • snmp - allow setting interface "adminStatus";
  • snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
  • ssh - do not generate host key on configuration export;
  • ssh - fixed multiline non-interactive command execution;
  • ssh - improved session rekeying process on exchanged data size threshold;
  • ssh - use correct user when "output-to-file" parameter is used;
  • supout - added "kid-control devices" section to supout file;
  • switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
  • switch - properly reapply settings after switch chip reset;
  • tile - improved link fault detection on SFP+ ports;
  • userman - updated authorize.net gateway DNS name;
  • w60g - prefer AP with strongest signal when multiple APs with same SSID present;
  • wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
  • wireless - fixed incorrect IP header for RADIUS accounting packet;
  • wireless - improved DFS radar detection when using non-ETSI regulated country;
  • wireless - updated "india" regulatory domain information;
  • wireless - updated "new zealand" regulatory domain information.

MikroTik RouterOS 6.45beta22

Дата выхода: 29 марта 2019

Изменения:

  • ipv6 - fixed soft lockup when forwarding IPv6 packets;
  • ipv6 - fixed soft lockup when processing large IPv6 Neighbor table;
  • certificate - added "key-type" field (CLI only);
  • certificate - fixed SAN being duplicated on status change (introduced in v6.44);
  • dhcpv6-server - added "address-list" support for bindings (CLI only);
  • export - fixed SMS "allowed-number" compact export (introduced in v6.45beta);
  • fetch - added SFTP support;
  • ike2 - prefer SAN instead of DN from certificate for ID payload;
  • ipsec - added support for RADIUS accounting;
  • ipsec - fixed policies becoming invalid after changing priority;
  • snmp - added OID for neighbor "interface";
  • snmp - added "write-access" column to community print;
  • snmp - allow setting interface "adminStatus";
  • ssh - fixed multiline non-interactive command execution;
  • ssh - improved session rekeying process on exchanged data size threshold;
  • supout - added "kid-control devices" section to supout file;
  • userman - updated authorize.net gateway DNS name;
  • w60g - prefer AP with strongest signal when multiple APs with same SSID present.

Другие изменения относительно 6.44.1:

  • bridge - fixed log message when hardware offloading is being enabled;
  • certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
  • certificate - made RAM the default CRL storage location;
  • certificate - removed DSA (D) flag;
  • crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
  • crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
  • dhcpv4-server - added "vendor-class-id" matcher (CLI only);
  • dhcpv4-server - improved stability when performing "check-status" command;
  • dhcpv6-server - added RADIUS accounting support;
  • ethernet - added support for 25Gbps and 40Gbps rates;
  • fetch - improved user policy lookup;
  • ike1 - adjusted debug packet logging topics;
  • ike1 - improved stability for transport mode policies on initiator side;
  • ike2 - added support for ECDSA certificate authentication (rfc4754);
  • ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
  • ike2 - improved XAuth identity conversion on upgrade;
  • ike2 - prefer SAN instead of DN from certificate for ID payload;
  • ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
  • ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
  • ipsec - added support for RADIUS accounting;
  • ipsec - added traffic statistics to "active-peers" menu (CLI only);
  • ipsec - do not allow adding identity to a dynamic peer;
  • ipsec - fixed freshly created identity not taken in action;
  • ipsec - renamed "remote-peers" to "active-peers" (CLI only);
  • ipsec - renamed "rsa-signature" authentication method to "digital-signature";
  • lte - added passthrough interface subnet selection;
  • lte - added support for manual operator selection;
  • lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
  • lte - do not show error message for info commands that are not supported;
  • lte - improved "info" command query;
  • lte - improved R11e-4G modem operation;
  • lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
  • lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
  • lte - show alphanumeric value for operator info;
  • lte - show correct firmware revision after firmware upgrade;
  • lte - use default APN name "internet" when not provided;
  • lte - use secondary DNS for DNS server configuration;
  • ppp - added initial support for Quectel BG96;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • rb4011 - fixed SFP linking (introduced in v6.45beta6);
  • sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
  • smb - fixed possible buffer overflow;
  • sms - added USSD message functionality under "/tool sms" (CLI only);
  • sms - allow specifying multiple "allowed-number" values;
  • sms - fixed long message parsing (introduced in v6.45beta19);
  • sms - improved delivery report logging;
  • snmp - added "dot1dStpPortTable" OID;
  • snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
  • ssh - do not generate host key on configuration export;
  • ssh - use correct user when "output-to-file" parameter is used;
  • switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
  • switch - properly reapply settings after switch chip reset;
  • tile - improved link fault detection on SFP+ ports;
  • wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19);
  • wireless - fixed incorrect IP header for RADIUS accounting packet;
  • wireless - improved DFS radar detection when using non-ETSI regulated country;
  • wireless - updated "india" regulatory domain information;
  • wireless - updated "new zealand" regulatory domain information.

MikroTik RouterOS 6.45beta20

Дата выхода: 25 марта 2019

Изменения:

  • certificate - made RAM the default CRL storage location;
  • ike1 - adjusted debug packet logging topics;
  • ipsec - fixed freshly created identity not taken in action;
  • lte - allow to specify URL for firmware upgrade "firmware-file" parameter;
  • sms - fixed long message parsing (introduced in v6.45beta19);
  • wireless - fixed 5GHz interface disappearing after upgrade (introduced in v6.45beta19).

Другие изменения относительно 6.44.1:

  • bridge - fixed log message when hardware offloading is being enabled;
  • certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
  • certificate - removed DSA (D) flag;
  • crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
  • crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
  • dhcpv4-server - added "vendor-class-id" matcher (CLI only);
  • dhcpv4-server - improved stability when performing "check-status" command;
  • dhcpv6-server - added RADIUS accounting support;
  • ethernet - added support for 25Gbps and 40Gbps rates;
  • fetch - improved user policy lookup;
  • ike1 - improved stability for transport mode policies on initiator side;
  • ike2 - added support for ECDSA certificate authentication (rfc4754);
  • ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
  • ike2 - improved XAuth identity conversion on upgrade;
  • ike2 - prefer SAN instead of DN from certificate for ID payload;
  • ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
  • ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
  • ipsec - added support for RADIUS accounting;
  • ipsec - added traffic statistics to "active-peers" menu (CLI only);
  • ipsec - do not allow adding identity to a dynamic peer;
  • ipsec - renamed "remote-peers" to "active-peers" (CLI only);
  • ipsec - renamed "rsa-signature" authentication method to "digital-signature";
  • lte - added passthrough interface subnet selection;
  • lte - added support for manual operator selection;
  • lte - do not show error message for info commands that are not supported;
  • lte - improved "info" command query;
  • lte - improved R11e-4G modem operation;
  • lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
  • lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
  • lte - show alphanumeric value for operator info;
  • lte - show correct firmware revision after firmware upgrade;
  • lte - use default APN name "internet" when not provided;
  • lte - use secondary DNS for DNS server configuration;
  • ppp - added initial support for Quectel BG96;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • rb4011 - fixed SFP linking (introduced in v6.45beta6);
  • sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
  • smb - fixed possible buffer overflow;
  • sms - added USSD message functionality under "/tool sms" (CLI only);
  • sms - allow specifying multiple "allowed-number" values;
  • sms - improved delivery report logging;
  • snmp - added "dot1dStpPortTable" OID;
  • snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
  • ssh - do not generate host key on configuration export;
  • ssh - use correct user when "output-to-file" parameter is used;
  • switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
  • switch - properly reapply settings after switch chip reset;
  • tile - improved link fault detection on SFP+ ports;
  • wireless - fixed incorrect IP header for RADIUS accounting packet;
  • wireless - improved DFS radar detection when using non-ETSI regulated country;
  • wireless - updated "india" regulatory domain information;
  • wireless - updated "new zealand" regulatory domain information.

MikroTik RouterOS 6.45beta19

Дата выхода: 22 марта 2019

Изменения:

  • certificate - added support for ECDSA certificates (prime256v1, secp384r1, secp521r1) (CLI only);
  • certificate - removed DSA (D) flag;
  • ike1 - improved stability for transport mode policies on initiator side;
  • ike2 - added support for ECDSA certificate authentication (rfc4754);
  • ike2 - prefer SAN instead of DN from certificate for ID payload;
  • ipsec - renamed "rsa-signature" authentication method to "digital-signature";
  • smb - fixed possible buffer overflow;
  • sms - added USSD message functionality under "/tool sms" (CLI only);
  • ssh - do not generate host key on configuration export;
  • wireless - improved DFS radar detection when using non-ETSI regulated country.

Другие изменения относительно 6.44.1:

  • bridge - fixed log message when hardware offloading is being enabled;
  • certificate - added support for ECC (Elliptic Curve Cryptography);
  • crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
  • crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
  • dhcpv4-server - added "vendor-class-id" matcher (CLI only);
  • dhcpv4-server - improved stability when performing "check-status" command;
  • dhcpv6-server - added RADIUS accounting support;
  • ethernet - added support for 25Gbps and 40Gbps rates;
  • fetch - improved user policy lookup;
  • ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
  • ike2 - improved XAuth identity conversion on upgrade;
  • ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
  • ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
  • ipsec - added support for RADIUS accounting;
  • ipsec - added traffic statistics to "active-peers" menu (CLI only);
  • ipsec - do not allow adding identity to a dynamic peer;
  • ipsec - renamed "remote-peers" to "active-peers" (CLI only);
  • lte - added passthrough interface subnet selection;
  • lte - added support for manual operator selection;
  • lte - do not show error message for info commands that are not supported;
  • lte - improved "info" command query;
  • lte - improved R11e-4G modem operation;
  • lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
  • lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
  • lte - show alphanumeric value for operator info;
  • lte - show correct firmware revision after firmware upgrade;
  • lte - use default APN name "internet" when not provided;
  • lte - use secondary DNS for DNS server configuration;
  • ppp - added initial support for Quectel BG96;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • rb4011 - fixed SFP linking (introduced in v6.45beta6);
  • sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
  • sms - allow specifying multiple "allowed-number" values;
  • sms - improved delivery report logging;
  • snmp - added "dot1dStpPortTable" OID;
  • snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
  • ssh - use correct user when "output-to-file" parameter is used;
  • switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
  • switch - properly reapply settings after switch chip reset;
  • tile - improved link fault detection on SFP+ ports;
  • wireless - fixed incorrect IP header for RADIUS accounting packet;
  • wireless - updated "india" regulatory domain information;
  • wireless - updated "new zealand" regulatory domain information.

MikroTik RouterOS 6.45beta16

Дата выхода: 18 марта 2019

Изменения:

  • dhcpv4-server - improved stability when performing "check-status" command;
  • ike2 - do not send "User-Name" attribute to RADIUS server if not provided;
  • ike2 - improved XAuth identity conversion on upgrade;
  • ipsec - added dynamic comment field for "active-peers" menu inherited from identity (CLI only);
  • ipsec - added "ph2-total" counter to "active-peers" menu (CLI only);
  • ipsec - added support for RADIUS accounting;
  • ipsec - added traffic statistics to "active-peers" menu (CLI only);
  • ipsec - do not allow adding identity to a dynamic peer;
  • ipsec - renamed "remote-peers" to "active-peers" (CLI only);
  • lte - use default APN name "internet" when not provided;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • switch - properly reapply settings after switch chip reset.

Другие изменения относительно 6.44.1:

  • bridge - fixed log message when hardware offloading is being enabled;
  • certificate - added support for ECC (Elliptic Curve Cryptography);
  • crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
  • crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
  • dhcpv4-server - added "vendor-class-id" matcher (CLI only);
  • dhcpv6-server - added RADIUS accounting support;
  • ethernet - added support for 25Gbps and 40Gbps rates;
  • fetch - improved user policy lookup;
  • lte - added passthrough interface subnet selection;
  • lte - added support for manual operator selection;
  • lte - do not show error message for info commands that are not supported;
  • lte - improved "info" command query;
  • lte - improved R11e-4G modem operation;
  • lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
  • lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
  • lte - show alphanumeric value for operator info;
  • lte - show correct firmware revision after firmware upgrade;
  • lte - use secondary DNS for DNS server configuration;
  • ppp - added initial support for Quectel BG96;
  • rb4011 - fixed SFP linking (introduced in v6.45beta6);
  • sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
  • sms - allow specifying multiple "allowed-number" values;
  • sms - improved delivery report logging;
  • snmp - added "dot1dStpPortTable" OID;
  • snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
  • ssh - use correct user when "output-to-file" parameter is used;
  • switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
  • tile - improved link fault detection on SFP+ ports;
  • wireless - fixed incorrect IP header for RADIUS accounting packet;
  • wireless - updated "india" regulatory domain information;
  • wireless - updated "new zealand" regulatory domain information.

MikroTik RouterOS 6.45beta11

Дата выхода: 8 марта 2019

Изменения:

  • bridge - fixed log message when hardware offloading is being enabled;
  • dhcpv4-server - added "vendor-class-id" matcher (CLI only);
  • dhcpv6-server - added RADIUS accounting support;
  • e-mail - fixed missing "from" address for sent e-mails (introduced in v6.44);
  • gps - removed unnecessary leading "0" for dd format;
  • ipsec - allow identities with empty XAuth login and password if RADIUS is enabled (introduced in v6.44);
  • lte - fixed LTE interface band setting on RBSXTLTE3-7 (introduced in v6.44);
  • lte - improved "info" command query;
  • rb4011 - fixed SFP linking (introduced in v6.45beta6);
  • sms - allow specifying multiple "allowed-number" values;
  • snmp - properly return multicast and broadcast packet counters for IF-MIB OIDs;
  • wireless - fixed antenna gain setting on RBSXT5nDr2.

Другие изменения относительно 6.44:

  • bridge - fixed possible memory leak when using "ingress-filtering=yes" on bridge interface;
  • certificate - added support for ECC (Elliptic Curve Cryptography);
  • certificate - force 3DES encryption for P12 certificate export;
  • crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
  • crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
  • dhcp - fixed dual stack queue addition;
  • dhcpv6-server - use MAC address for RADIUS user when "allow-dual-stack-queue=yes";
  • ethernet - added support for 25Gbps and 40Gbps rates;
  • fetch - improved user policy lookup;
  • gps - increase precision for dd format;
  • ipsec - fixed dynamic L2TP peer and identity configuration missing after reboot (introduced in v6.44);
  • ipsec - use "remote-id=ignore" for dynamic L2TP configuration (introduced in v6.44);
  • ipv6 - do not allow setting "preferred-lifetime" longer than "valid-lifetime";
  • lte - added passthrough interface subnet selection;
  • lte - added support for manual operator selection;
  • lte - do not show error message for info commands that are not supported;
  • lte - do not show "session-uptime" if session is not up;
  • lte - improved R11e-4G modem operation;
  • lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
  • lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
  • lte - show alphanumeric value for operator info;
  • lte - show correct firmware revision after firmware upgrade;
  • lte - use secondary DNS for DNS server configuration;
  • ppp - added initial support for Quectel BG96;
  • rb4011 - fixed ether10 failing to auto negotiate link speed to 1Gbps;
  • sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
  • sms - improved delivery report logging;
  • snmp - added "dot1dStpPortTable" OID;
  • ssh - use correct user when "output-to-file" parameter is used;
  • switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
  • tile - improved link fault detection on SFP+ ports;
  • winbox - added "use-local-address" parameter in "IP/Cloud" menus;
  • wireless - fixed incorrect IP header for RADIUS accounting packet;
  • wireless - updated "india" regulatory domain information;
  • wireless - updated "new zealand" regulatory domain information.

MikroTik RouterOS 6.45beta6

Дата выхода: 5 марта 2019

Изменения:

  • bridge - fixed possible memory leak when using "ingress-filtering=yes" on bridge interface;
  • certificate - added support for ECC (Elliptic Curve Cryptography);
  • certificate - force 3DES encryption for P12 certificate export;
  • crs3xx - correctly display auto-negotiation information for SFP/SFP+ interfaces in 1Gbps rate;
  • crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);
  • dhcp - fixed dual stack queue addition;
  • dhcpv4-server - added "vendor-class-id" matcher (CLI only);
  • dhcpv6-server - use MAC address for RADIUS user when "allow-dual-stack-queue=yes";
  • ethernet - added support for 25Gbps and 40Gbps rates;
  • fetch - improved user policy lookup;
  • gps - increase precision for dd format;
  • ipsec - fixed dynamic L2TP peer and identity configuration missing after reboot (introduced in v6.44);
  • ipsec - use "remote-id=ignore" for dynamic L2TP configuration (introduced in v6.44);
  • ipv6 - do not allow setting "preferred-lifetime" longer than "valid-lifetime";
  • lte - added passthrough interface subnet selection;
  • lte - added support for manual operator selection;
  • lte - do not show error message for info commands that are not supported;
  • lte - do not show "session-uptime" if session is not up;
  • lte - improved R11e-4G modem operation;
  • lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);
  • lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;
  • lte - show alphanumeric value for operator info;
  • lte - show correct firmware revision after firmware upgrade;
  • lte - use secondary DNS for DNS server configuration;
  • ppp - added initial support for Quectel BG96;
  • rb4011 - fixed ether10 failing to auto negotiate link speed to 1Gbps;
  • sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;
  • sms - improved delivery report logging;
  • snmp - added "dot1dStpPortTable" OID;
  • ssh - use correct user when "output-to-file" parameter is used;
  • switch - fixed possible crash when interface state changes and DHCP Snooping is enabled;
  • tile - improved link fault detection on SFP+ ports;
  • winbox - added "use-local-address" parameter in "IP/Cloud" menus;
  • wireless - fixed incorrect IP header for RADIUS accounting packet;
  • wireless - updated "india" regulatory domain information;
  • wireless - updated "new zealand" regulatory domain information.
Чек-лист по настройке MikroTik
Проверьте свою конфигурацию по 28-ми пунктам