MikroTik RouterOS 6.47betaX (Testing)

Материал из MikroTik Wiki
Перейти к навигации Перейти к поиску

Подробное описание изменений в MikroTik RouterOS 6.47betaX (Testing). Официальный список исправленных ошибок, добавленного функционала и прочих доработок. Дата выхода первого набора изменений – 10 декабря 2019, дата выхода последнего набора изменений – 24 апреля 2020.

Чек-лист по настройке MikroTik
Проверьте свою конфигурацию по 28-ми пунктам

MikroTik RouterOS 6.47beta60

Дата выхода: 24 апреля 2020

Важные комментарии:

- The Dude server must be updated to monitor v6.46.4 and v6.47beta30+ RouterOS type devices. - The Dude client must be manually upgraded after upgrading The Dude server. - Make sure LTE APN Profile name does not match any of the DHCP server's names if LTE passthrough is used. - The Dude requires "winbox" policy instead of "dude" to monitor v6.46.4 and v6.47beta30+ RouterOS type devices.

Важные изменения:

  • dns - added client side support for DNS over HTTPS (DoH) (RFC8484);
  • socks - added support for SOCKS5 (RFC 1928);
  • user - enable "winbox" policy for groups with "dude" policy.

Изменения:

  • dns - added client side support for DNS over HTTPS (DoH) (RFC8484);
  • socks - added support for SOCKS5 (RFC 1928);
  • branding - improved branding package installation process when another branding package is already installed;
  • chr - enabled support for VMBus protocol version 4.1;
  • chr - improved system stability when running CHR on Hyper-V;
  • crs3xx - fixed hardware offloaded bonding on Ethernet interfaces for CRS354 devices;
  • crs3xx - fixed switch rule "dst-port" parameter for IPv6 traffic on CRS305-1G-4S+, CRS326-24G-2S+, CRS328-24P-4S+, CRS328-4C-20S-4S+, netPower 15FR devices;
  • crs3xx - improved system stability when creating multiple hardware offloaded bonding interfaces (introduced in v6.47beta49);
  • crs3xx - show correct switch model for netPower 15FR device;
  • defconf - fixed default IP address assigning on non-paired 60 GHz devices;
  • disk - improved disk management service stability when receiving bogus packets;
  • dns - added support for forwarding DNS queries of static entries to specific server (CLI only);
  • dns - added support for multiple type static entries (CLI only);
  • email - added support for multiple "to" recipients (CLI only);
  • graphing - improved graphing service stability when receiving bogus packets;
  • ike1 - do not try to keep phase 2 when purging phase 1;
  • ike2 - added support for RADIUS Disconnect-Request message handling;
  • interface - increased loopback interface MTU to 65536;
  • ipsec - allow specifying two peers for a single policy for failover (CLI only);
  • lora - added "altitude", "latitude" and "longitude" to stat json if GPS is available;
  • lte - improved stability during firmware upgrade process;
  • routerboard - added "hold-time" parameter to mode-button menu (CLI only);
  • routerboard - added "reset-button" menu - custom command execution with reset button (CLI only);
  • snmp - fixed "ifSpeed" reporting for tunnel interfaces;
  • ssh - improved SSH service stability when receiving bogus packets;
  • switch - correctly display switch statistics when all switch ports are disabled on RTL8367 switch chip;
  • switch - fixed missing switch statistics (introduced in v6.47beta49);
  • user - improved user management service stability when receiving bogus packets;
  • webfig - fixed WinBox download link;
  • webfig - fixed skin usage from branding package;
  • winbox - added "bus" parameter for "USB Power Reset" command on RBM33G;
  • winbox - allow to specify any ethernet like interface under "Tool/WoL" menu;
  • winbox - fixed "Tx/Rx Signal Strength" value presence for 4 chain interfaces;
  • winbox - fixed memory leak (introduced in v6.46.4);
  • winbox - fixed wireless interface "HT" tab setting presence when "band=5ghz-n/ac";
  • winbox - increased limit of multi-entry fields to 100;
  • winbox - limit number of simultaneous WinBox sessions to 5 for users without "write" permission;
  • wireless - improved management service stability when receiving bogus packets;
  • wireless - updated "south africa" regulatory domain information.

Другие изменения относительно 6.46.5:

  • bonding - improved slave interface MAC address handling;
  • bonding - prefer primary slave MAC address for bonding interface;
  • branding - do not ask to confirm configuration applied from branding package;
  • branding - fixed identity setting from branding package;
  • branding - properly use HTML files for Hotspot (introduced in v6.47beta);
  • bridge - added logging message when a host MAC address is learned on a different bridge port;
  • bridge - added warning message when port is dynamically added to entry with VLAN range (CLI only);
  • bridge - correctly remove disabled MSTI;
  • bridge - improved hardware offloading enabling/disabling;
  • certificate - added "skid" and "akid" values for detailed print;
  • certificate - allow dynamic CRL removal;
  • certificate - disabled CRL usage by default;
  • certificate - do not use SSL for first CRL update;
  • chr - added support for file system quiescing;
  • crs3xx - correctly remove switch rules on CRS317-1G-16S+ and CRS309-1G-8S+ devices;
  • crs3xx - do not change bridge host ID's when updating host table (introduced in v6.47beta32);
  • crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
  • crs3xx - fixed QSFP interface linking after removing/inserting QSFP module (introduced in v6.47beta49);
  • crs3xx - fixed QSFP+ interface linking for CRS326-24S+2Q+ device (introduced in v6.47beta19);
  • crs3xx - improved switch host table updating;
  • defconf - fixed "no-defaults=yes" applying default configuration (introduced in v6.47beta);
  • defconf - fixed default configuration initialization if power loss occurred during the process;
  • dhcpv4 - added end option (255) validation for both server and client;
  • dhcpv4-client - improved stability when changing client while still receiving advertisements;
  • dhcpv4-server - disallow zero lease-time setting;
  • dhcpv6-client - improved error logging when when renewed address differs;
  • dhcpv6-server - fixed MAC address retrieving from DUID when timestamp is present;
  • discovery - do not send discovery packets on inactive bonding slave interfaces;
  • discovery - do not send discovery packets on interfaces that are blocked by STP;
  • disk - improved recently created file survival after reboots;
  • dns - added support for exclusive dynamic DNS server usage from IPsec;
  • dot1x - added "radius-mac-format" parameter (CLI only);
  • dot1x - added hex value support for RADIUS switch rules;
  • dot1x - added range "dst-port" support for RADIUS switch rules;
  • dot1x - added support for lower case "mac-auth" RADIUS formats;
  • dot1x - fixed "reject-vlan-id" value range;
  • dot1x - fixed dynamically created switch rule removal when client disconnects;
  • dot1x - fixed port blocking when interface changes state from disabled to enabled;
  • dot1x - improved debug logging output to "dot1x" topic;
  • dot1x - improved value validation for dynamically created switch rules;
  • fetch - fixed "User-Agent" usage if provided by "http-header-field";
  • filesystem - fixed NAND memory going into read-only mode or becoming unstable over time;
  • health - added "gauges" submenu with SNMP OID reporting;
  • hotspot - updated splash page design ('/ip hotspot reset-html' required);
  • ike1 - added error message when specifying "my-id" for XAuth Identity;
  • ike1 - added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes;
  • ike1 - improved policy lookup with specific protocol;
  • ike1 - improved stability when performing policy lookup on non-existant peer;
  • ike2 - added support for "INTERNAL_DNS_DOMAIN" payload attribute;
  • ipsec - added "split-dns" parameter support for mode configuration (CLI only);
  • ipsec - added "use-responder-dns" parameter support (CLI only);
  • ipsec - control CRL validation with global "use-crl" setting;
  • ipsec - do full certificate validation for identities with explicit certificate;
  • ipsec - fixed minor spelling mistake in logs;
  • ipsec - improved IPsec service stability when receiving bogus packets;
  • kidcontrol - ignore IPv6 multicast MAC addresses;
  • lcd - fixed LCD service becoming unavailable on devices without LCD screen;
  • led - fixed minor typo in LED warning message;
  • lte - added support for Huawei K5161 modem;
  • lte - added support for NEOWAY N720;
  • lte - added support for multiple passthrough APN configuration;
  • lte - do not allow running "scan" on R11e-4G;
  • lte - fixed "allow-roaming" setting when using LTE network mode on R11e-LTE;
  • lte - fixed "band" value setting when configuration is reset on R11e-4G;
  • lte - fixed multiple APN reactivation after deactivation by operator;
  • lte - made "mac-address" parameter read-only;
  • lte - show "phy-cellid" value only in LTE mode;
  • netinstall - removed "Flashfig" from Netinstall;
  • netinstall - removed "Make Floppy" from Netinstall;
  • netinstall - signed netinstall.exe with Digital Signature;
  • ppp - added support for ZTE MF90;
  • ppp - fixed minor typo when running "info" command;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • quickset - do not show "SINR" field in Quick Set when there is no data;
  • quickset - removed "EARFCN" field from Quick Set;
  • quickset - removed "LTE band" setting from Quick Set;
  • quickset - show "Antenna Gain" setting on devices without built-in antennas;
  • quickset - use "station-wds" mode when connecting to AP with RouterOS flag;
  • route - improved system stability after reboot with large amount of VLAN interfaces with PPPoE servers attached;
  • routing - improved IGMP-Proxy service stability when receiving bogus packets;
  • sniffer - allow setting port for "streaming-server";
  • snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB;
  • snmp - changed "upsEstimatedMinutesRemaining" reported value from seconds to minutes;
  • snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
  • snmp - fixed multiple LTE interface OID reporting;
  • snmp - improved OID policy checking and error reporting on "set" command;
  • snmp - improved stability when polling MAC address related OID;
  • ssh - fixed SHA256 user authentication algorithm checking (introduced in v6.46.4);
  • supout - added "dot1x" section to supout files;
  • supout - improved UPS information reporting;
  • switch - made "auto" the default value for "vlan-id" parameter when creating a new static host entry;
  • system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic;
  • system - improved driver loading speed on startup;
  • tr069-client - removed warning log message when not using HTTPS;
  • traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9;
  • upgrade - fixed space handling in package file names;
  • ups - improved compatibility with APC Smart UPS 1000 and 1500;
  • w60g - fixed link status logging;
  • w60g - improved rate selection in low traffic conditions;
  • w60g - use "arp" and "mtu" parameters from master interface when creating a new station;
  • webfig - updated icon design;
  • winbox - added "Rate" parameter for switch ACL rules;
  • winbox - added "auto-erase" option to "Tool/SMS" menu;
  • winbox - added comment support for "Switch->VLAN" menu;
  • winbox - added support for inline bar graphs for LTE signal values;
  • winbox - aligned all "IP->Traffic Flow->IPFIX" check boxes in single line (WinBox v3.22 required);
  • winbox - allow setting "Primary" parameter for "balance-tlb" bonding interfaces;
  • winbox - fixed "BGP Origin" value display under "IPv6->Routes" menu;
  • winbox - fixed "Data Rate" checkbox alignment (WinBox v3.22 required);
  • winbox - fixed bonding type interface support for "Switch->Host" table;
  • winbox - made "yes" the default value for "Inject Summary LSAs" parameter when creating a new NSSA or STUB area;
  • winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic";
  • winbox - renamed "Routerboard" to "RouterBOARD" under "System/RouterBOARD" menu;
  • winbox - show "Hardware Offload" parameter for bonding interfaces;
  • winbox - updated icon design;
  • wireless - added "russia 6ghz" regulatory domain information;
  • wireless - allow using "russia4" regulatory domain on RU locked devices;
  • wireless - enabled unicast flood for DHCP traffic on ARM architecture access points;
  • wireless - improved 5GHz interface stability on RB4011iGS+5HacQ2HnD and Audience;
  • wireless - improved system stability on hAP ac^2;
  • wireless - updated "russia4" regulatory domain information;
  • www - added "tls-version" parameter in "IP->Services" menu (CLI only).

MikroTik RouterOS 6.47beta54

Дата выхода: 6 апреля 2020

Важные комментарии:

- The Dude server must be updated to monitor v6.46.4 and v6.47beta30+ RouterOS type devices. - The Dude client must be manually upgraded after upgrading The Dude server. - Make sure LTE APN Profile name does not match any of the DHCP server's names if LTE passthrough is used. - The Dude requires "winbox" policy instead of "dude" to monitor v6.46.4 and v6.47beta30+ RouterOS type devices.

Важные изменения:

  • dns - added client side support for DNS over HTTPS (DoH) (RFC8484);
  • socks - added support for SOCKS5 (RFC 1928);
  • user - enable "winbox" policy for groups with "dude" policy.

Изменения:

  • wireless - improved 5GHz interface stability on RB4011iGS+5HacQ2HnD and Audience;
  • wireless - improved system stability on hAP ac^2.

Другие изменения относительно 6.46.4:

  • bonding - improved slave interface MAC address handling;
  • bonding - prefer primary slave MAC address for bonding interface;
  • branding - do not ask to confirm configuration applied from branding package;
  • branding - fixed identity setting from branding package;
  • branding - properly use HTML files for Hotspot (introduced in v6.47beta);
  • bridge - added logging message when a host MAC address is learned on a different bridge port;
  • bridge - added warning message when port is dynamically added to entry with VLAN range (CLI only);
  • bridge - correctly remove disabled MSTI;
  • bridge - improved hardware offloading enabling/disabling;
  • capsman - fixed "certificate" parameter updating on CAP;
  • certificate - added "skid" and "akid" values for detailed print;
  • certificate - allow dynamic CRL removal;
  • certificate - disabled CRL usage by default;
  • certificate - do not use SSL for first CRL update;
  • chr - added support for file system quiescing;
  • console - prevent incorrect type interfaces appearing in command hints;
  • crs3xx - correctly remove switch rules on CRS317-1G-16S+ and CRS309-1G-8S+ devices;
  • crs3xx - do not change bridge host ID's when updating host table (introduced in v6.47beta32);
  • crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
  • crs3xx - fixed QSFP interface linking after removing/inserting QSFP module (introduced in v6.47beta49);
  • crs3xx - fixed QSFP+ interface linking for CRS326-24S+2Q+ device (introduced in v6.47beta19);
  • crs3xx - fixed interface statistics for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices;
  • crs3xx - fixed traffic forwarding after disabling/enabling bridge hardware offloading for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices;
  • crs3xx - improved SFP+ DAC cable initialization for CRS326-24S+2Q+ device;
  • crs3xx - improved switch host table updating;
  • defconf - fixed "no-defaults=yes" applying default configuration (introduced in v6.47beta);
  • defconf - fixed default configuration initialization if power loss occurred during the process;
  • dhcpv4 - added end option (255) validation for both server and client;
  • dhcpv4-client - improved stability when changing client while still receiving advertisements;
  • dhcpv4-server - disallow zero lease-time setting;
  • dhcpv6-client - improved error logging when when renewed address differs;
  • dhcpv6-server - fixed MAC address retrieving from DUID when timestamp is present;
  • discovery - do not send CDP and LLDP packets on interfaces that does not have MAC address;
  • discovery - do not send discovery packets on inactive bonding slave interfaces;
  • discovery - do not send discovery packets on interfaces that are blocked by STP;
  • disk - improved recently created file survival after reboots;
  • dns - added support for exclusive dynamic DNS server usage from IPsec;
  • dot1x - added "radius-mac-format" parameter (CLI only);
  • dot1x - added hex value support for RADIUS switch rules;
  • dot1x - added range "dst-port" support for RADIUS switch rules;
  • dot1x - added support for lower case "mac-auth" RADIUS formats;
  • dot1x - fixed "reject-vlan-id" value range;
  • dot1x - fixed dynamically created switch rule removal when client disconnects;
  • dot1x - fixed port blocking when interface changes state from disabled to enabled;
  • dot1x - improved debug logging output to "dot1x" topic;
  • dot1x - improved value validation for dynamically created switch rules;
  • dude - fixed connection to other RouterOS type devices through The Dude agents (introduced in v6.46.4);
  • fetch - fixed "User-Agent" usage if provided by "http-header-field";
  • filesystem - fixed NAND memory going into read-only mode or becoming unstable over time;
  • health - added "gauges" submenu with SNMP OID reporting;
  • hotspot - updated splash page design ('/ip hotspot reset-html' required);
  • ike1 - added error message when specifying "my-id" for XAuth Identity;
  • ike1 - added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes;
  • ike1 - improved policy lookup with specific protocol;
  • ike1 - improved stability when performing policy lookup on non-existant peer;
  • ike1 - rekey phase 1 rekeying as responder for Windows initiators;
  • ike2 - added support for "INTERNAL_DNS_DOMAIN" payload attribute;
  • ipsec - added "split-dns" parameter support for mode configuration (CLI only);
  • ipsec - added "use-responder-dns" parameter support (CLI only);
  • ipsec - control CRL validation with global "use-crl" setting;
  • ipsec - do full certificate validation for identities with explicit certificate;
  • ipsec - fixed minor spelling mistake in logs;
  • ipsec - improved IPsec service stability when receiving bogus packets;
  • ipsec - improved system stability when handling fragmented packets;
  • kidcontrol - ignore IPv6 multicast MAC addresses;
  • lcd - fixed LCD service becoming unavailable on devices without LCD screen;
  • led - added "dark-mode" functionality for CRS105-5S-FB;
  • led - fixed minor typo in LED warning message;
  • lora - added IPv6 support for LoRa packet forwarder;
  • lora - added UTC timestamp for RX events in "rxpk" json;
  • lora - added value limits for "freq-off" parameter;
  • lora - properly update source address for packets when routing table is changed;
  • lte - added support for Huawei K5161 modem;
  • lte - added support for NEOWAY N720;
  • lte - added support for multiple passthrough APN configuration;
  • lte - do not allow running "scan" on R11e-4G;
  • lte - fixed "allow-roaming" setting when using LTE network mode on R11e-LTE;
  • lte - fixed "band" value setting when configuration is reset on R11e-4G;
  • lte - fixed IP type selection from APN on RBSXTLTE3-7;
  • lte - fixed multiple APN reactivation after deactivation by operator;
  • lte - made "mac-address" parameter read-only;
  • lte - show "phy-cellid" value only in LTE mode;
  • netinstall - removed "Flashfig" from Netinstall;
  • netinstall - removed "Make Floppy" from Netinstall;
  • netinstall - signed netinstall.exe with Digital Signature;
  • ppp - added support for ZTE MF90;
  • ppp - fixed minor typo when running "info" command;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • quickset - do not show "SINR" field in Quick Set when there is no data;
  • quickset - removed "EARFCN" field from Quick Set;
  • quickset - removed "LTE band" setting from Quick Set;
  • quickset - show "Antenna Gain" setting on devices without built-in antennas;
  • quickset - use "station-wds" mode when connecting to AP with RouterOS flag;
  • route - improved system stability after reboot with large amount of VLAN interfaces with PPPoE servers attached;
  • routing - improved IGMP-Proxy service stability when receiving bogus packets;
  • sniffer - allow setting port for "streaming-server";
  • sniffer - fixed minor typo in "host" menu;
  • snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB;
  • snmp - changed "upsEstimatedMinutesRemaining" reported value from seconds to minutes;
  • snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
  • snmp - fixed multiple LTE interface OID reporting;
  • snmp - improved OID policy checking and error reporting on "set" command;
  • snmp - improved stability when polling MAC address related OID;
  • ssh - fixed SHA256 user authentication algorithm checking (introduced in v6.46.4);
  • supout - added "dot1x" section to supout files;
  • supout - added "gps" section to supout files;
  • supout - improved PoE-out information reporting;
  • supout - improved UPS information reporting;
  • switch - made "auto" the default value for "vlan-id" parameter when creating a new static host entry;
  • system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic;
  • system - improved driver loading speed on startup;
  • system - improved kernel panic reporting in logs after reboot;
  • system - improved system stability when forwarding traffic from switch chip to CPU (introduced in v6.43);
  • tr069-client - removed warning log message when not using HTTPS;
  • traceroute - improved stability when invalid packet is received;
  • traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9;
  • traffic-generator - improved statistics reporting;
  • upgrade - fixed space handling in package file names;
  • ups - improved compatibility with APC Smart UPS 1000 and 1500;
  • w60g - fixed link status logging;
  • w60g - improved rate selection in low traffic conditions;
  • w60g - improved stability after multiple disconnections;
  • w60g - use "arp" and "mtu" parameters from master interface when creating a new station;
  • webfig - updated icon design;
  • winbox - added "Options" parameter support for DHCPv6 client and server;
  • winbox - added "Rate" parameter for switch ACL rules;
  • winbox - added "auto-erase" option to "Tool/SMS" menu;
  • winbox - added 160Mhz extension channel support for CAPsMAN;
  • winbox - added comment support for "Switch->VLAN" menu;
  • winbox - added support for "Tools->WoL" menu;
  • winbox - added support for inline bar graphs for LTE signal values;
  • winbox - aligned all "IP->Traffic Flow->IPFIX" check boxes in single line (WinBox v3.22 required);
  • winbox - allow setting "20/40/80/160Mhz-eeeeeeCe" channel under "Channel Width" parameter;
  • winbox - allow setting "Primary" parameter for "balance-tlb" bonding interfaces;
  • winbox - do not show "Revision" parameter under "System/RouterBOARD" menu on devices that have only one revision;
  • winbox - fixed "ARP" parameter inheritance from "CAPs Configuration" configuration;
  • winbox - fixed "BGP Origin" value display under "IPv6->Routes" menu;
  • winbox - fixed "Bands" parameter display for LTE interfaces;
  • winbox - fixed "DSCP" parameter value setting;
  • winbox - fixed "Data Rate" checkbox alignment (WinBox v3.22 required);
  • winbox - fixed "Frequency" and "Secondary Frequency" parameter inheritance from "CAPs Channel" configuration;
  • winbox - fixed "Passthr. MAC Address" parameter display "LTE APNs" menu;
  • winbox - fixed "Switch" menu on CRS354-48P-4S+2Q+;
  • winbox - fixed "dst-port" unsetting in "IP->Hotspot->Walled Garden" menu;
  • winbox - fixed automatic "IPv6->Firewall->Address List" table update;
  • winbox - fixed bonding type interface support for "Switch->Host" table;
  • winbox - made "none" the default value for "Security Profile" parameter when creating a new "Wirelees->Connect list" entry;
  • winbox - made "yes" the default value for "Inject Summary LSAs" parameter when creating a new NSSA or STUB area;
  • winbox - properly show "Hw. Offload Group" value for each interface under "Bridge->Ports" menu;
  • winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic";
  • winbox - renamed "Memory used" to "HDD used" for HDD type under "Tools->Graphing->Resource Graphs";
  • winbox - renamed "Routerboard" to "RouterBOARD" under "System/RouterBOARD" menu;
  • winbox - show "Hardware Offload" parameter for bonding interfaces;
  • winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
  • winbox - updated icon design;
  • wireless - added "U-NII-2" support for hAP ac2 and RBwAPGR series devices;
  • wireless - added "russia 6ghz" regulatory domain information;
  • wireless - added "skip-dfs-channels" parameter;
  • wireless - allow using "russia4" regulatory domain on RU locked devices;
  • wireless - enabled unicast flood for DHCP traffic on ARM architecture access points;
  • wireless - updated "bangladesh" regulatory domain information;
  • wireless - updated "russia4" regulatory domain information;
  • wireless - fixed default "antenna-gain" setting on SXT 2 and LtAP series devices;
  • wireless - updated "indonesia4" regulatory domain information;
  • www - added "tls-version" parameter in "IP->Services" menu (CLI only).

MikroTik RouterOS 6.47beta53

Дата выхода: 3 апреля 2020

Важные комментарии:

- The Dude server must be updated to monitor v6.46.4 and v6.47beta30+ RouterOS type devices. - The Dude client must be manually upgraded after upgrading The Dude server. - Make sure LTE APN Profile name does not match any of the DHCP server's names if LTE passthrough is used. - The Dude requires "winbox" policy instead of "dude" to monitor v6.46.4 and v6.47beta30+ RouterOS type devices.

Важные изменения:

  • dns - added client side support for DNS over HTTPS (DoH) (RFC8484);
  • socks - added support for SOCKS5 (RFC 1928);
  • user - enable "winbox" policy for groups with "dude" policy.

Изменения:

  • socks - added support for SOCKS5 (RFC 1928);
  • branding - do not ask to confirm configuration applied from branding package;
  • certificate - added "skid" and "akid" values for detailed print;
  • certificate - allow dynamic CRL removal;
  • console - prevent incorrect type interfaces appearing in command hints;
  • crs3xx - fixed QSFP interface linking after removing/inserting QSFP module (introduced in v6.47beta49);
  • dhcpv4-server - disallow zero lease-time setting;
  • filesystem - fixed NAND memory going into read-only mode or becoming unstable over time;
  • ike1 - improved policy lookup with specific protocol;
  • ike1 - rekey phase 1 rekeying as responder for Windows initiators;
  • ipsec - improved system stability when handling fragmented packets;
  • kidcontrol - ignore IPv6 multicast MAC addresses;
  • lora - added IPv6 support for LoRa packet forwarder;
  • lora - added UTC timestamp for RX events in "rxpk" json;
  • lte - added support for Huawei K5161 modem;
  • lte - fixed IP type selection from APN on RBSXTLTE3-7;
  • snmp - fixed multiple LTE interface OID reporting;
  • system - improved kernel panic reporting in logs after reboot;
  • wireless - added "russia 6ghz" regulatory domain information;
  • wireless - added "skip-dfs-channels" parameter;
  • wireless - updated "bangladesh" regulatory domain information;
  • wireless - updated "russia4" regulatory domain information.

Другие изменения относительно 6.46.4:

  • bonding - improved slave interface MAC address handling;
  • bonding - prefer primary slave MAC address for bonding interface;
  • branding - fixed identity setting from branding package;
  • branding - properly use HTML files for Hotspot (introduced in v6.47beta);
  • bridge - added logging message when a host MAC address is learned on a different bridge port;
  • bridge - added warning message when port is dynamically added to entry with VLAN range (CLI only);
  • bridge - correctly remove disabled MSTI;
  • bridge - improved hardware offloading enabling/disabling;
  • capsman - fixed "certificate" parameter updating on CAP;
  • certificate - disabled CRL usage by default;
  • certificate - do not use SSL for first CRL update;
  • chr - added support for file system quiescing;
  • crs3xx - correctly remove switch rules on CRS317-1G-16S+ and CRS309-1G-8S+ devices;
  • crs3xx - do not change bridge host ID's when updating host table (introduced in v6.47beta32);
  • crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
  • crs3xx - fixed QSFP+ interface linking for CRS326-24S+2Q+ device (introduced in v6.47beta19);
  • crs3xx - fixed interface statistics for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices;
  • crs3xx - fixed traffic forwarding after disabling/enabling bridge hardware offloading for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices;
  • crs3xx - improved SFP+ DAC cable initialization for CRS326-24S+2Q+ device;
  • crs3xx - improved switch host table updating;
  • defconf - fixed "no-defaults=yes" applying default configuration (introduced in v6.47beta);
  • defconf - fixed default configuration initialization if power loss occurred during the process;
  • dhcpv4 - added end option (255) validation for both server and client;
  • dhcpv4-client - improved stability when changing client while still receiving advertisements;
  • dhcpv6-client - improved error logging when when renewed address differs;
  • dhcpv6-server - fixed MAC address retrieving from DUID when timestamp is present;
  • discovery - do not send CDP and LLDP packets on interfaces that does not have MAC address;
  • discovery - do not send discovery packets on inactive bonding slave interfaces;
  • discovery - do not send discovery packets on interfaces that are blocked by STP;
  • disk - improved recently created file survival after reboots;
  • dns - added support for exclusive dynamic DNS server usage from IPsec;
  • dot1x - added "radius-mac-format" parameter (CLI only);
  • dot1x - added hex value support for RADIUS switch rules;
  • dot1x - added range "dst-port" support for RADIUS switch rules;
  • dot1x - added support for lower case "mac-auth" RADIUS formats;
  • dot1x - fixed "reject-vlan-id" value range;
  • dot1x - fixed dynamically created switch rule removal when client disconnects;
  • dot1x - fixed port blocking when interface changes state from disabled to enabled;
  • dot1x - improved debug logging output to "dot1x" topic;
  • dot1x - improved value validation for dynamically created switch rules;
  • dude - fixed connection to other RouterOS type devices through The Dude agents (introduced in v6.46.4);
  • fetch - fixed "User-Agent" usage if provided by "http-header-field";
  • filesystem - fixed NAND memory going into read-only mode or becoming unstable over time;
  • health - added "gauges" submenu with SNMP OID reporting;
  • hotspot - updated splash page design ('/ip hotspot reset-html' required);
  • ike1 - added error message when specifying "my-id" for XAuth Identity;
  • ike1 - added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes;
  • ike1 - improved stability when performing policy lookup on non-existant peer;
  • ike2 - added support for "INTERNAL_DNS_DOMAIN" payload attribute;
  • ipsec - added "split-dns" parameter support for mode configuration (CLI only);
  • ipsec - added "use-responder-dns" parameter support (CLI only);
  • ipsec - control CRL validation with global "use-crl" setting;
  • ipsec - do full certificate validation for identities with explicit certificate;
  • ipsec - fixed minor spelling mistake in logs;
  • ipsec - improved IPsec service stability when receiving bogus packets;
  • lcd - fixed LCD service becoming unavailable on devices without LCD screen;
  • led - added "dark-mode" functionality for CRS105-5S-FB;
  • led - fixed minor typo in LED warning message;
  • lora - added IPv6 support for LoRa packet forwarder;
  • lora - added value limits for "freq-off" parameter;
  • lora - properly update source address for packets when routing table is changed;
  • lte - added support for NEOWAY N720;
  • lte - added support for multiple passthrough APN configuration;
  • lte - do not allow running "scan" on R11e-4G;
  • lte - fixed "allow-roaming" setting when using LTE network mode on R11e-LTE;
  • lte - fixed "band" value setting when configuration is reset on R11e-4G;
  • lte - fixed multiple APN reactivation after deactivation by operator;
  • lte - made "mac-address" parameter read-only;
  • lte - show "phy-cellid" value only in LTE mode;
  • netinstall - removed "Flashfig" from Netinstall;
  • netinstall - removed "Make Floppy" from Netinstall;
  • netinstall - signed netinstall.exe with Digital Signature;
  • ppp - added support for ZTE MF90;
  • ppp - fixed minor typo when running "info" command;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • quickset - do not show "SINR" field in Quick Set when there is no data;
  • quickset - removed "EARFCN" field from Quick Set;
  • quickset - removed "LTE band" setting from Quick Set;
  • quickset - show "Antenna Gain" setting on devices without built-in antennas;
  • quickset - use "station-wds" mode when connecting to AP with RouterOS flag;
  • route - improved system stability after reboot with large amount of VLAN interfaces with PPPoE servers attached;
  • routing - improved IGMP-Proxy service stability when receiving bogus packets;
  • sniffer - allow setting port for "streaming-server";
  • sniffer - fixed minor typo in "host" menu;
  • snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB;
  • snmp - changed "upsEstimatedMinutesRemaining" reported value from seconds to minutes;
  • snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
  • snmp - improved OID policy checking and error reporting on "set" command;
  • snmp - improved stability when polling MAC address related OID;
  • ssh - fixed SHA256 user authentication algorithm checking (introduced in v6.46.4);
  • supout - added "dot1x" section to supout files;
  • supout - added "gps" section to supout files;
  • supout - improved PoE-out information reporting;
  • supout - improved UPS information reporting;
  • switch - made "auto" the default value for "vlan-id" parameter when creating a new static host entry;
  • system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic;
  • system - improved driver loading speed on startup;
  • system - improved system stability when forwarding traffic from switch chip to CPU (introduced in v6.43);
  • tr069-client - removed warning log message when not using HTTPS;
  • traceroute - improved stability when invalid packet is received;
  • traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9;
  • traffic-generator - improved statistics reporting;
  • upgrade - fixed space handling in package file names;
  • ups - improved compatibility with APC Smart UPS 1000 and 1500;
  • w60g - fixed link status logging;
  • w60g - improved rate selection in low traffic conditions;
  • w60g - improved stability after multiple disconnections;
  • w60g - use "arp" and "mtu" parameters from master interface when creating a new station;
  • webfig - updated icon design;
  • winbox - added "Options" parameter support for DHCPv6 client and server;
  • winbox - added "Rate" parameter for switch ACL rules;
  • winbox - added "auto-erase" option to "Tool/SMS" menu;
  • winbox - added 160Mhz extension channel support for CAPsMAN;
  • winbox - added comment support for "Switch->VLAN" menu;
  • winbox - added support for "Tools->WoL" menu;
  • winbox - added support for inline bar graphs for LTE signal values;
  • winbox - aligned all "IP->Traffic Flow->IPFIX" check boxes in single line (WinBox v3.22 required);
  • winbox - allow setting "20/40/80/160Mhz-eeeeeeCe" channel under "Channel Width" parameter;
  • winbox - allow setting "Primary" parameter for "balance-tlb" bonding interfaces;
  • winbox - do not show "Revision" parameter under "System/RouterBOARD" menu on devices that have only one revision;
  • winbox - fixed "ARP" parameter inheritance from "CAPs Configuration" configuration;
  • winbox - fixed "BGP Origin" value display under "IPv6->Routes" menu;
  • winbox - fixed "Bands" parameter display for LTE interfaces;
  • winbox - fixed "DSCP" parameter value setting;
  • winbox - fixed "Data Rate" checkbox alignment (WinBox v3.22 required);
  • winbox - fixed "Frequency" and "Secondary Frequency" parameter inheritance from "CAPs Channel" configuration;
  • winbox - fixed "Passthr. MAC Address" parameter display "LTE APNs" menu;
  • winbox - fixed "Switch" menu on CRS354-48P-4S+2Q+;
  • winbox - fixed "dst-port" unsetting in "IP->Hotspot->Walled Garden" menu;
  • winbox - fixed automatic "IPv6->Firewall->Address List" table update;
  • winbox - fixed bonding type interface support for "Switch->Host" table;
  • winbox - made "none" the default value for "Security Profile" parameter when creating a new "Wirelees->Connect list" entry;
  • winbox - made "yes" the default value for "Inject Summary LSAs" parameter when creating a new NSSA or STUB area;
  • winbox - properly show "Hw. Offload Group" value for each interface under "Bridge->Ports" menu;
  • winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic";
  • winbox - renamed "Memory used" to "HDD used" for HDD type under "Tools->Graphing->Resource Graphs";
  • winbox - renamed "Routerboard" to "RouterBOARD" under "System/RouterBOARD" menu;
  • winbox - show "Hardware Offload" parameter for bonding interfaces;
  • winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
  • winbox - updated icon design;
  • wireless - added "U-NII-2" support for hAP ac2 and RBwAPGR series devices;
  • wireless - allow using "russia4" regulatory domain on RU locked devices;
  • wireless - enabled unicast flood for DHCP traffic on ARM architecture access points;
  • wireless - fixed default "antenna-gain" setting on SXT 2 and LtAP series devices;
  • wireless - updated "indonesia4" regulatory domain information;
  • www - added "tls-version" parameter in "IP->Services" menu (CLI only).

MikroTik RouterOS 6.47beta49

Дата выхода: 20 марта 2020

Важные комментарии:

- The Dude server must be updated to monitor v6.46.4 and v6.47beta30+ RouterOS type devices. - The Dude client must be manually upgraded after upgrading The Dude server. - Make sure LTE APN Profile name does not match any of the DHCP server's names if LTE passthrough is used. - The Dude requires "winbox" policy instead of "dude" to monitor v6.46.4 and v6.47beta30+ RouterOS type devices.

Важные изменения:

  • dns - added client side support for DNS over HTTPS (DoH) (RFC8484);
  • socks - added support for SOCKS5 (RFC 1928);
  • socks - added support for SOCKS5 (RFC 1928);
  • user - enable "winbox" policy for groups with "dude" policy.

Изменения:

  • dns - added client side support for DNS over HTTPS (DoH) (RFC8484);
  • socks - added support for SOCKS5 (RFC 1928);
  • user - enable "winbox" policy for groups with "dude" policy;
  • branding - fixed identity setting from branding package;
  • branding - properly use HTML files for Hotspot (introduced in v6.47beta);
  • bridge - added warning message when port is dynamically added to entry with VLAN range (CLI only);
  • bridge - correctly remove disabled MSTI;
  • bridge - improved hardware offloading enabling/disabling;
  • capsman - fixed "certificate" parameter updating on CAP;
  • certificate - disabled CRL usage by default;
  • certificate - do not use SSL for first CRL update;
  • chr - added support for file system quiescing;
  • crs3xx - do not change bridge host ID's when updating host table (introduced in v6.47beta32);
  • crs3xx - fixed interface statistics for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices;
  • crs3xx - fixed traffic forwarding after disabling/enabling bridge hardware offloading for CRS354-48G-4S+2Q+ and CRS354-48P-4S+2Q+ devices;
  • dhcpv4 - added end option (255) validation for both server and client;
  • dhcpv4-client - improved stability when changing client while still receiving advertisements;
  • dhcpv6-server - fixed MAC address retrieving from DUID when timestamp is present;
  • dude - fixed connection to other RouterOS type devices through The Dude agents (introduced in v6.46.4);
  • filesystem - fixed NAND memory going into read-only mode or becoming unstable over time;
  • hotspot - updated splash page design ('/ip hotspot reset-html' required);
  • ike1 - added error message when specifying "my-id" for XAuth Identity;
  • ike1 - improved stability when performing policy lookup on non-existant peer;
  • ipsec - control CRL validation with global "use-crl" setting;
  • ipsec - do full certificate validation for identities with explicit certificate;
  • lcd - fixed LCD service becoming unavailable on devices without LCD screen;
  • led - added "dark-mode" functionality for CRS105-5S-FB;
  • led - fixed minor typo in LED warning message;
  • lora - added IPv6 support for LoRa packet forwarder;
  • lora - added value limits for "freq-off" parameter;
  • lora - properly update source address for packets when routing table is changed;
  • lte - added support for NEOWAY N720;
  • lte - fixed "allow-roaming" setting when using LTE network mode on R11e-LTE;
  • lte - made "mac-address" parameter read-only;
  • ppp - added support for ZTE MF90;
  • ppp - fixed minor typo when running "info" command;
  • proxy - increased minimal free RAM that can not be used for proxy services;
  • quickset - do not show "SINR" field in Quick Set when there is no data;
  • quickset - removed "EARFCN" field from Quick Set;
  • route - improved system stability after reboot with large amount of VLAN interfaces with PPPoE servers attached;
  • sniffer - fixed minor typo in "host" menu;
  • snmp - changed "upsEstimatedMinutesRemaining" reported value from seconds to minutes;
  • ssh - fixed SHA256 user authentication algorithm checking (introduced in v6.46.4);
  • supout - added "gps" section to supout files;
  • switch - made "auto" the default value for "vlan-id" parameter when creating a new static host entry;
  • system - improved driver loading speed on startup;
  • system - improved system stability when forwarding traffic from switch chip to CPU (introduced in v6.43);
  • traffic-generator - improved statistics reporting;
  • w60g - fixed link status logging;
  • w60g - improved rate selection in low traffic conditions;
  • winbox - added "Options" parameter support for DHCPv6 client and server;
  • winbox - added "Rate" parameter for switch ACL rules;
  • winbox - added 160Mhz extension channel support for CAPsMAN;
  • winbox - added comment support for "Switch->VLAN" menu;
  • winbox - added support for "Tools->WoL" menu;
  • winbox - aligned all "IP->Traffic Flow->IPFIX" check boxes in single line (WinBox v3.22 required);
  • winbox - allow setting "20/40/80/160Mhz-eeeeeeCe" channel under "Channel Width" parameter;
  • winbox - allow setting "Primary" parameter for "balance-tlb" bonding interfaces;
  • winbox - do not show "Revision" parameter under "System/RouterBOARD" menu on devices that have only one revision;
  • winbox - fixed "ARP" parameter inheritance from "CAPs Configuration" configuration;
  • winbox - fixed "BGP Origin" value display under "IPv6->Routes" menu;
  • winbox - fixed "Bands" parameter display for LTE interfaces;
  • winbox - fixed "DSCP" parameter value setting;
  • winbox - fixed "Data Rate" checkbox alignment (WinBox v3.22 required);
  • winbox - fixed "Frequency" and "Secondary Frequency" parameter inheritance from "CAPs Channel" configuration;
  • winbox - fixed "Passthr. MAC Address" parameter display "LTE APNs" menu;
  • winbox - fixed "Switch" menu on CRS354-48P-4S+2Q+;
  • winbox - fixed "dst-port" unsetting in "IP->Hotspot->Walled Garden" menu;
  • winbox - fixed automatic "IPv6->Firewall->Address List" table update;
  • winbox - fixed bonding type interface support for "Switch->Host" table;
  • winbox - made "none" the default value for "Security Profile" parameter when creating a new "Wirelees->Connect list" entry;
  • winbox - made "yes" the default value for "Inject Summary LSAs" parameter when creating a new NSSA or STUB area;
  • winbox - properly show "Hw. Offload Group" value for each interface under "Bridge->Ports" menu;
  • winbox - renamed "Memory used" to "HDD used" for HDD type under "Tools->Graphing->Resource Graphs";
  • winbox - renamed "Routerboard" to "RouterBOARD" under "System/RouterBOARD" menu;
  • winbox - show "Hardware Offload" parameter for bonding interfaces;
  • winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;
  • winbox - updated icon design;
  • wireless - added "U-NII-2" support for hAP ac2 and RBwAPGR series devices;
  • wireless - enabled unicast flood for DHCP traffic on ARM architecture access points;
  • wireless - fixed default "antenna-gain" setting on SXT 2 and LtAP series devices;
  • wireless - updated "indonesia4" regulatory domain information.

Другие изменения относительно 6.46.4:

  • socks - added support for SOCKS5 (RFC 1928);
  • bonding - improved slave interface MAC address handling;
  • bonding - prefer primary slave MAC address for bonding interface;
  • bridge - added logging message when a host MAC address is learned on a different bridge port;
  • crs3xx - correctly remove switch rules on CRS317-1G-16S+ and CRS309-1G-8S+ devices;
  • crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
  • crs3xx - fixed QSFP+ interface linking for CRS326-24S+2Q+ device (introduced in v6.47beta19);
  • crs3xx - improved SFP+ DAC cable initialization for CRS326-24S+2Q+ device;
  • crs3xx - improved switch host table updating;
  • defconf - fixed "no-defaults=yes" applying default configuration (introduced in v6.47beta);
  • defconf - fixed default configuration initialization if power loss occurred during the process;
  • dhcpv6-client - improved error logging when when renewed address differs;
  • discovery - do not send CDP and LLDP packets on interfaces that does not have MAC address;
  • discovery - do not send discovery packets on inactive bonding slave interfaces;
  • discovery - do not send discovery packets on interfaces that are blocked by STP;
  • disk - improved recently created file survival after reboots;
  • dns - added support for exclusive dynamic DNS server usage from IPsec;
  • dot1x - added "radius-mac-format" parameter (CLI only);
  • dot1x - added hex value support for RADIUS switch rules;
  • dot1x - added range "dst-port" support for RADIUS switch rules;
  • dot1x - added support for lower case "mac-auth" RADIUS formats;
  • dot1x - fixed "reject-vlan-id" value range;
  • dot1x - fixed dynamically created switch rule removal when client disconnects;
  • dot1x - fixed port blocking when interface changes state from disabled to enabled;
  • dot1x - improved debug logging output to "dot1x" topic;
  • dot1x - improved value validation for dynamically created switch rules;
  • fetch - fixed "User-Agent" usage if provided by "http-header-field";
  • health - added "gauges" submenu with SNMP OID reporting;
  • ike1 - added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes;
  • ike2 - added support for "INTERNAL_DNS_DOMAIN" payload attribute;
  • ipsec - added "split-dns" parameter support for mode configuration (CLI only);
  • ipsec - added "use-responder-dns" parameter support (CLI only);
  • ipsec - fixed minor spelling mistake in logs;
  • ipsec - improved IPsec service stability when receiving bogus packets;
  • lte - added support for multiple passthrough APN configuration;
  • lte - do not allow running "scan" on R11e-4G;
  • lte - fixed "band" value setting when configuration is reset on R11e-4G;
  • lte - fixed multiple APN reactivation after deactivation by operator;
  • lte - show "phy-cellid" value only in LTE mode;
  • netinstall - removed "Flashfig" from Netinstall;
  • netinstall - removed "Make Floppy" from Netinstall;
  • netinstall - signed netinstall.exe with Digital Signature;
  • quickset - removed "LTE band" setting from Quick Set;
  • quickset - show "Antenna Gain" setting on devices without built-in antennas;
  • quickset - use "station-wds" mode when connecting to AP with RouterOS flag;
  • routing - improved IGMP-Proxy service stability when receiving bogus packets;
  • sniffer - allow setting port for "streaming-server";
  • snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB;
  • snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
  • snmp - improved OID policy checking and error reporting on "set" command;
  • snmp - improved stability when polling MAC address related OID;
  • supout - added "dot1x" section to supout files;
  • supout - improved PoE-out information reporting;
  • supout - improved UPS information reporting;
  • system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic;
  • tr069-client - removed warning log message when not using HTTPS;
  • traceroute - improved stability when invalid packet is received;
  • traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9;
  • traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9;
  • upgrade - fixed space handling in package file names;
  • ups - improved compatibility with APC Smart UPS 1000 and 1500;
  • w60g - improved stability after multiple disconnections;
  • w60g - use "arp" and "mtu" parameters from master interface when creating a new station;
  • webfig - updated icon design;
  • winbox - added "auto-erase" option to "Tool/SMS" menu;
  • winbox - added support for inline bar graphs for LTE signal values;
  • winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic";
  • winbox - updated icon design;
  • wireless - allow using "russia4" regulatory domain on RU locked devices;
  • www - added "tls-version" parameter in "IP->Services" menu (CLI only).

MikroTik RouterOS 6.47beta35

Дата выхода: 17 февраля 2020

Важные комментарии:

- The Dude server must be updated to monitor v6.47beta30+ RouterOS type devices. - The Dude client must be manually upgraded after upgrading The Dude server. - Make sure LTE APN Profile name does not match any of the DHCP server's names if LTE passthrough is used.

Важные изменения:

  • socks - added support for SOCKS5 (RFC 1928).

Изменения:

  • socks - added support for SOCKS5 (RFC 1928);
  • chr - fixed graceful shutdown execution on Hyper-V (introduced in v6.46);
  • crs3xx - fixed frame forwarding after disabling/enabling bridge hardware offloading for CRS354-48G-4S+2Q+ device;
  • crs3xx - improved SFP+ DAC cable initialization for CRS326-24S+2Q+ device;
  • dns - added support for exclusive dynamic DNS server usage from IPsec;
  • health - fixed maximum SFP temperature reading under '/system health' menu;
  • ipsec - added "use-responder-dns" parameter support (CLI only);
  • ssh - added support for RSA keys with SHA256 hash (RFC8332);
  • supout - improved PoE-out information reporting;
  • system - improved system stability when receiving/sending TCP traffic on multicore devices;
  • traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9;
  • webfig - updated icon design;
  • winbox - updated icon design;
  • wireless - allow using "russia4" regulatory domain on RU locked devices.

Другие изменения относительно 6.46.3:

  • arm - improved watchdog and kernel panic reporting in log after reboots on RB3011 and IPQ4018/IPQ4019 devices ("/system routerboard upgrade" required);
  • bonding - improved slave interface MAC address handling;
  • bonding - prefer primary slave MAC address for bonding interface;
  • branding - allow forcing configuration script as default configuration (new branding packet required);
  • branding - fixed "company-url" and "router-default-name" survival after system upgrade;
  • branding - fixed WEB HTML page survival after system upgrade;
  • bridge - added logging message when a host MAC address is learned on a different bridge port;
  • certificate - fixed certificate verification when flushing CRL's;
  • crs3xx - correctly remove switch rules on CRS317-1G-16S+ and CRS309-1G-8S+ devices;
  • crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
  • crs3xx - fixed QSFP+ interface linking for CRS326-24S+2Q+ device (introduced in v6.47beta19);
  • crs3xx - improved switch host table updating;
  • defconf - added welcome note with common first steps for new users;
  • defconf - fixed default configuration initialization if power loss occurred during the process;
  • defconf - fixed "no-defaults=yes" applying default configuration (introduced in v6.47beta);
  • dhcpv6-client - improved error logging when when renewed address differs;
  • discovery - do not send CDP and LLDP packets on interfaces that does not have MAC address;
  • discovery - do not send discovery packets on inactive bonding slave interfaces;
  • discovery - do not send discovery packets on interfaces that are blocked by STP;
  • disk - improved recently created file survival after reboots;
  • dot1x - added hex value support for RADIUS switch rules;
  • dot1x - added "radius-mac-format" parameter (CLI only);
  • dot1x - added range "dst-port" support for RADIUS switch rules;
  • dot1x - added support for lower case "mac-auth" RADIUS formats;
  • dot1x - fixed dynamically created switch rule removal when client disconnects;
  • dot1x - fixed port blocking when interface changes state from disabled to enabled;
  • dot1x - fixed "reject-vlan-id" value range;
  • dot1x - improved debug logging output to "dot1x" topic;
  • dot1x - improved value validation for dynamically created switch rules;
  • dude - updated The Dude to use new style authentication method;
  • fetch - fixed "User-Agent" usage if provided by "http-header-field";
  • health - added "gauges" submenu with SNMP OID reporting;
  • ike1 - added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes;
  • ike2 - added support for "INTERNAL_DNS_DOMAIN" payload attribute;
  • ike2 - fixed DHCP Inform package handling when received on PPPoE interface;
  • ipsec - added "split-dns" parameter support for mode configuration (CLI only);
  • ipsec - fixed minor spelling mistake in logs;
  • ipsec - improved IPsec service stability when receiving bogus packets;
  • lte - added interface name prefix for logging events;
  • lte - added "phy-cellid" value support for LTE-US;
  • lte - added support for multiple passthrough APN configuration;
  • lte - do not allow running "scan" on R11e-4G;
  • lte - do not allow using empty APN Profile names;
  • lte - fixed "band" value setting when configuration is reset on R11e-4G;
  • lte - fixed multiple APN reactivation after deactivation by operator;
  • lte - improved all APN session activation after disconnect on R11e-LTE;
  • lte - show "phy-cellid" value only in LTE mode;
  • lte - use APN from network when blank APN used on R11e-4G;
  • netinstall - removed "Flashfig" from Netinstall;
  • netinstall - removed "Make Floppy" from Netinstall;
  • netinstall - signed netinstall.exe with Digital Signature;
  • quickset - removed "LTE band" setting from Quick Set;
  • quickset - show "Antenna Gain" setting on devices without built-in antennas;
  • quickset - use "station-wds" mode when connecting to AP with RouterOS flag;
  • routing - improved IGMP-Proxy service stability when receiving bogus packets;
  • sniffer - allow setting port for "streaming-server";
  • snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB;
  • snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
  • snmp - fixed "routeros-version" value returning from registration table;
  • snmp - fixed UPS battery voltage value scaling;
  • snmp - improved OID policy checking and error reporting on "set" command;
  • snmp - improved stability when polling MAC address related OID;
  • supout - added "dot1x" section to supout files;
  • supout - improved UPS information reporting;
  • system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic;
  • telnet - improved telnet compatibility with other client implementations;
  • tr069-client - removed warning log message when not using HTTPS;
  • traceroute - improved stability when invalid packet is received;
  • traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9;
  • upgrade - fixed space handling in package file names;
  • ups - improved compatibility with APC Smart UPS 1000 and 1500;
  • user-manager - fixed signup enabling (introduced in v6.46);
  • w60g - improved stability after multiple disconnections;
  • w60g - use "arp" and "mtu" parameters from master interface when creating a new station;
  • webfig - added default configuration confirmation window to WebFig;
  • webfig - do not show WebFig menu when opening 'Check For Updates' in Quick Set;
  • winbox - added "auto-erase" option to "Tool/SMS" menu;
  • winbox - added support for inline bar graphs for LTE signal values;
  • winbox - completely removed old style authentication method;
  • winbox - fixed "invalid" flag presence under "System/Certificates/CRL" menu;
  • winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic";
  • wireless - improved compatibility for "ETSI" wireless country profile;
  • www - added "tls-version" parameter in "IP->Services" menu (CLI only).

MikroTik RouterOS 6.47beta32

Дата выхода: 10 февраля 2020

Важные комментарии:

- The Dude server must be updated to monitor v6.47beta30+ RouterOS type devices. - The Dude client must be manually upgraded after upgrading The Dude server. - Make sure LTE APN Profile name does not match any of the DHCP server's names if LTE passthrough is used.

Важные изменения:

  • socks - added support for SOCKS5 (RFC 1928).

Изменения:

  • arm - improved watchdog and kernel panic reporting in log after reboots on RB3011 and IPQ4018/IPQ4019 devices ("/system routerboard upgrade" required);
  • branding - allow forcing configuration script as default configuration (new branding packet required);
  • branding - fixed "company-url" and "router-default-name" survival after system upgrade;
  • branding - fixed WEB HTML page survival after system upgrade;
  • certificate - fixed certificate verification when flushing CRL's;
  • crs3xx - correctly remove switch rules on CRS317-1G-16S+ and CRS309-1G-8S+ devices;
  • crs3xx - fixed QSFP+ interface linking for CRS326-24S+2Q+ device (introduced in v6.47beta19);
  • crs3xx - improved switch host table updating;
  • defconf - added welcome note with common first steps for new users;
  • defconf - fixed default configuration initialization if power loss occurred during the process;
  • defconf - fixed "no-defaults=yes" applying default configuration (introduced in v6.47beta);
  • disk - improved recently created file survival after reboots;
  • dns - use only servers received from IKEv2 server when present;
  • dot1x - added hex value support for RADIUS switch rules;
  • dot1x - added range "dst-port" support for RADIUS switch rules;
  • dot1x - added support for lower case "mac-auth" RADIUS formats;
  • dot1x - fixed dynamically created switch rule removal when client disconnects;
  • dot1x - fixed port blocking when interface changes state from disabled to enabled;
  • dot1x - fixed "reject-vlan-id" value range;
  • dot1x - improved debug logging output to "dot1x" topic;
  • dot1x - improved value validation for dynamically created switch rules;
  • dude - updated The Dude to use new style authentication method;
  • ike1 - added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes;
  • ike2 - added support for "INTERNAL_DNS_DOMAIN" payload attribute;
  • ike2 - fixed DHCP Inform package handling when received on PPPoE interface;
  • ipsec - added "split-dns" parameter support for mode configuration (CLI only);
  • ipsec - fixed minor spelling mistake in logs;
  • ipsec - improved IPsec service stability when receiving bogus packets;
  • lte - added interface name prefix for logging events;
  • lte - added "phy-cellid" value support for LTE-US;
  • lte - added support for multiple passthrough APN configuration;
  • lte - do not allow using empty APN Profile names;
  • lte - show "phy-cellid" value only in LTE mode;
  • quickset - removed "LTE band" setting from Quick Set;
  • quickset - show "Antenna Gain" setting on devices without built-in antennas;
  • quickset - use "station-wds" mode when connecting to AP with RouterOS flag;
  • routing - improved IGMP-Proxy service stability when receiving bogus packets;
  • snmp - fixed "routeros-version" value returning from registration table;
  • snmp - fixed UPS battery voltage value scaling;
  • supout - improved UPS information reporting;
  • telnet - improved telnet compatibility with other client implementations;
  • tr069-client - removed warning log message when not using HTTPS;
  • traffic-flow - added "postDestinationMacAddress" parameter support for IPFIX and Netflow v9;
  • upgrade - fixed space handling in package file names;
  • ups - improved compatibility with APC Smart UPS 1000 and 1500;
  • user-manager - fixed signup enabling (introduced in v6.46);
  • w60g - improved stability after multiple disconnections;
  • webfig - added default configuration confirmation window to WebFig;
  • webfig - do not show WebFig menu when opening 'Check For Updates' in Quick Set;
  • winbox - added support for inline bar graphs for LTE signal values;
  • winbox - completely removed old style authentication method;
  • winbox - fixed "invalid" flag presence under "System/Certificates/CRL" menu;
  • wireless - improved compatibility for "ETSI" wireless country profile;
  • www - added "tls-version" parameter in "IP->Services" menu (CLI only).

Другие изменения относительно 6.46.3:

  • socks - added support for SOCKS5 (RFC 1928);
  • bonding - improved slave interface MAC address handling;
  • bonding - prefer primary slave MAC address for bonding interface;
  • bridge - added logging message when a host MAC address is learned on a different bridge port;
  • crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
  • dhcpv6-client - improved error logging when when renewed address differs;
  • discovery - do not send CDP and LLDP packets on interfaces that does not have MAC address;
  • discovery - do not send discovery packets on inactive bonding slave interfaces;
  • discovery - do not send discovery packets on interfaces that are blocked by STP;
  • dot1x - added "radius-mac-format" parameter (CLI only);
  • fetch - fixed "User-Agent" usage if provided by "http-header-field";
  • health - added "gauges" submenu with SNMP OID reporting;
  • lte - do not allow running "scan" on R11e-4G;
  • lte - fixed "band" value setting when configuration is reset on R11e-4G;
  • lte - fixed multiple APN reactivation after deactivation by operator;
  • lte - improved all APN session activation after disconnect on R11e-LTE;
  • lte - use APN from network when blank APN used on R11e-4G;
  • netinstall - removed "Flashfig" from Netinstall;
  • netinstall - removed "Make Floppy" from Netinstall;
  • netinstall - signed netinstall.exe with Digital Signature;
  • sniffer - allow setting port for "streaming-server";
  • snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB;
  • snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
  • snmp - improved OID policy checking and error reporting on "set" command;
  • snmp - improved stability when polling MAC address related OID;
  • supout - added "dot1x" section to supout files;
  • system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic;
  • traceroute - improved stability when invalid packet is received;
  • w60g - use "arp" and "mtu" parameters from master interface when creating a new station;
  • winbox - added "auto-erase" option to "Tool/SMS" menu;
  • winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic".

MikroTik RouterOS 6.47beta19

Дата выхода: 9 января 2020

Важные изменения:

  • socks - added support for SOCKS5 (RFC 1928).

Изменения:

  • socks - added support for SOCKS5 (RFC 1928);
  • bonding - improved slave interface MAC address handling;
  • bonding - prefer primary slave MAC address for bonding interface;
  • bridge - added logging message when a host MAC address is learned on a different bridge port;
  • chr - improved stability when changing ARP modes on e1000 type adapters;
  • console - prevent "flash" directory from being removed (introduced in v6.46);
  • console - updated copyright notice;
  • crs305 - disable optical SFP/SFP+ module Tx power after disabling SFP+ interface;
  • defconf - fixed "caps-mode" not initialized properly after resetting;
  • defconf - fixed default configuration loading on RBwAPG-60adkit (introduced in v6.46);
  • discovery - do not send CDP and LLDP packets on interfaces that does not have MAC address;
  • discovery - do not send discovery packets on inactive bonding slave interfaces;
  • discovery - do not send discovery packets on interfaces that are blocked by STP;
  • dot1x - added "radius-mac-format" parameter (CLI only);
  • health - added "gauges" submenu with SNMP OID reporting;
  • lora - added "ru-864-mid" channel plan;
  • lora - fixed packet sending when using "antenna-gain" higher than 5dB;
  • lora - improved immediate packet delivery;
  • lte - do not allow running "scan" on R11e-4G;
  • lte - fixed "band" value setting when configuration is reset on R11e-4G;
  • lte - fixed "cell-monitor" on R11e-LTE in 3G mode;
  • lte - fixed "earfcn" reporting on R11e-LTE6 in UMTS and GSM modes;
  • lte - improved all APN session activation after disconnect on R11e-LTE;
  • lte - report only valid info parameters on R11e-LTE6;
  • lte - use APN from network when blank APN used on R11e-4G;
  • ppp - fixed minor typo in "ppp-client" monitor;
  • qsfp - do not report bogus monitoring readouts on modules without DDMI support;
  • qsfp - improved module monitoring readouts for DAC and break-out cables;
  • routerboard - added "mode-button" support for RBcAP2nD;
  • sniffer - allow setting port for "streaming-server";
  • snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB;
  • snmp - improved OID policy checking and error reporting on "set" command;
  • supout - added "dot1x" section to supout files;
  • system - correctly handle Generic Receive Offloading (GRO) for MPLS traffic;
  • system - fixed "*.auto.rsc" file execution (introduced in v6.46);
  • system - fixed "check-installation" on PowerPC devices (introduced in v6.46);
  • traceroute - improved stability when invalid packet is received;
  • traffic-generator - improved memory handling on CHR;
  • webfig - allow skin designing without "ftp" and "sensitive" policies;
  • webfig - fixed "skins" saving to "flash" directory if it exists (introduced in v6.46);
  • winbox - automatically refresh "Packets" table when new packets are captured by "Tools/Packet Sniffer";
  • winbox - fixed "Default Route Distance" default value when creating new LTE APN;
  • winbox - removed duplicate "join-eui", "dev-eui", "counter", "chain", "size" and "payload" parameters under "Lora/Traffic".

Другие изменения относительно 6.46.1:

  • crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
  • dhcpv6-client - improved error logging when when renewed address differs;
  • fetch - fixed "User-Agent" usage if provided by "http-header-field";
  • lte - fixed multiple APN reactivation after deactivation by operator;
  • netinstall - removed "Flashfig" from Netinstall;
  • netinstall - removed "Make Floppy" from Netinstall;
  • netinstall - signed netinstall.exe with Digital Signature;
  • snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB;
  • snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
  • snmp - improved stability when polling MAC address related OID;
  • w60g - use "arp" and "mtu" parameters from master interface when creating a new station;
  • winbox - added "auto-erase" option to "Tool/SMS" menu.

MikroTik RouterOS 6.47beta8

Дата выхода: 10 декабря 2019

Изменения:

  • console - fixed "clear-history" restoring historic actions after power cycle;
  • console - removed "edit" and "set" actions from "System/History" menu;
  • crs3xx - fixed "ingress-rate" property on CRS309-1G-8S+, CRS312-4C+8XG, CRS326-24S+2Q+ devices;
  • defconf - fixed default configuration loading after fresh install (introduced in v6.46);
  • dhcpv6-client - improved error logging when when renewed address differs;
  • fetch - fixed "User-Agent" usage if provided by "http-header-field";
  • health - fixed health reporting on OmniTIK 5 PoE ac;
  • health - improved health reporting on CCR1072-1G-8S+;
  • ipsec - improved system stability when processing decrypted packet on unregistred interface;
  • l2tp - improved system stability when disconnecting many clients at once;
  • lora - improved confirmed downlink forwarding;
  • lte - do not reset modem when setting the same SIM slot on LtAP;
  • lte - fixed multiple APN reactivation after deactivation by operator;
  • lte - show SIM error when no card is present;
  • netinstall - removed "Flashfig" from Netinstall;
  • netinstall - removed "Make Floppy" from Netinstall;
  • netinstall - signed netinstall.exe with Digital Signature;
  • ppp - prioritize "remote-ipv6-prefix-pool" from PPP secret over PPP profile;
  • snmp - added "dot1qTpFdbTable" OID reporting for Q-BRIDGE-MIB;
  • snmp - fixed "dot1dBasePort" index offset for BRIDGE-MIB;
  • snmp - fixed health related OID polling (introduced in v6.46);
  • snmp - improved stability when polling MAC address related OID;
  • supout - fixed autosupout.rif file generation (introduced in v6.46);
  • w60g - use "arp" and "mtu" parameters from master interface when creating a new station;
  • winbox - added "auto-erase" option to "Tool/SMS" menu;
  • winbox - fixed "allowed-number" parameter setting invalid value in "Tool/SMS" menu;
  • winbox - show "LCD" menu only on boards that have LCD screen;
  • wireless - improved compatibility by adding default installation mode and gain for devices with integrated antennas;
  • wireless - improved compatibility for Switzerland wireless country profile to improve compliance with ETSI regulations.
Чек-лист по настройке MikroTik
Проверьте свою конфигурацию по 28-ми пунктам