<?xml version="1.0"?>
<rss version="2.0"><channel><title>&#x41C;&#x438;&#x43A;&#x440;&#x43E;&#x442;&#x438;&#x43A; &#x424;&#x43E;&#x440;&#x443;&#x43C;</title><link>https://www.mikrotik-bg.net/blogs/blog/2-%D0%BC%D0%B8%D0%BA%D1%80%D0%BE%D1%82%D0%B8%D0%BA-%D1%84%D0%BE%D1%80%D1%83%D0%BC/</link><description><p>Микротик Форум Блог</p></description><language>en</language><item><title>RouterOS 6.45beta6 [Testing]</title><link>https://www.mikrotik-bg.net/blogs/entry/7346-routeros-645beta6-testing/</link><description><![CDATA[
<p></p>
<h3>6.45beta6 changelog:</h3>Changes in this release: <br><br>
*) bridge - fixed possible memory leak when using "ingress-filtering=yes" on bridge interface;<br>
*) certificate - added support for ECC (Elliptic Curve Cryptography);<br>
*) certificate - force 3DES encryption for P12 certificate export;<br>
*) crs3xx - correctly display auto-negotiation information for <abbr title="Small Form-factor Pluggable">SFP</abbr>/<abbr title="Small Form-factor Pluggable">SFP</abbr>+ interfaces in 1Gbps rate;<br>
*) crs3xx - fixed auto negotiation when 2-pair twisted cable is used (downshift feature);<br>
*) dhcp - fixed dual stack queue addition;<br>
*) dhcpv4-server - added "vendor-class-id" matcher (CLI only);<br>
*) dhcpv6-server - use MAC address for RADIUS user when "allow-dual-stack-queue=yes";<br>
*) ethernet - added support for 25Gbps and 40Gbps rates;<br>
*) fetch - improved user policy lookup;<br>
*) gps - increase precision for dd format;<br>
*) ipsec - fixed dynamic L2TP peer and identity configuration missing after reboot (introduced in v6.44);<br>
*) ipsec - use "remote-id=ignore" for dynamic L2TP configuration (introduced in v6.44);<br>
*) ipv6 - do not allow setting "preferred-lifetime" longer than "valid-lifetime";<br>
*) lte - added passthrough interface subnet selection;<br>
*) lte - added support for manual operator selection;<br>
*) lte - do not show error message for info commands that are not supported;<br>
*) lte - do not show "session-uptime" if session is not up;<br>
*) lte - improved R11e-4G modem operation;<br>
*) lte - renamed firmware upgrade "path" command to "firmware-file" (CLI only);<br>
*) lte - reset LTE modem only when SIM slot is changed on dual SIM slot devices;<br>
*) lte - show alphanumeric value for operator info;<br>
*) lte - show correct firmware revision after firmware upgrade;<br>
*) lte - use secondary <abbr title="Domain Name System">DNS</abbr> for <abbr title="Domain Name System">DNS</abbr> server configuration;<br>
*) ppp - added initial support for Quectel BG96;<br>
*) rb4011 - fixed ether10 failing to auto negotiate link speed to 1Gbps;<br>
*) sfp - fixed S-35LC20D transceiver DDMI readouts after reboot;<br>
*) sms - improved delivery report logging;<br>
*) snmp - added "dot1dStpPortTable" OID;<br>
*) ssh - use correct user when "output-to-file" parameter is used;<br>
*) switch - fixed possible crash when interface state changes and <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping is enabled;<br>
*) tile - improved link fault detection on <abbr title="Small Form-factor Pluggable">SFP</abbr>+ ports;<br>
*) winbox - added "use-local-address" parameter in "IP/Cloud" menus;<br>
*) wireless - fixed incorrect IP header for RADIUS accounting packet;<br>
*) wireless - updated "india" regulatory domain information;<br>
*) wireless - updated "new zealand" regulatory domain information;<br><br>Download the new '<b>RouterOS 6.45beta6</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/testing" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7346</guid><pubDate>Tue, 05 Mar 2019 09:45:06 +0000</pubDate></item><item><title>RouterOS 6.44 [Stable]</title><link>https://www.mikrotik-bg.net/blogs/entry/7345-routeros-644-stable/</link><description><![CDATA[
<p></p>
<h3>6.44 changelog:</h3>MAJOR CHANGES IN v6.44:<br>
----------------------<br>
!) cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);<br>
!) ipsec - added new "identity" menu with common peer distinguishers;<br>
!) ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;<br>
!) ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu;<br>
!) radius - initial implementation of RadSec (RADIUS communication over TLS);<br>
!) speedtest - added "/tool speed-test" for ping latency, jitter, loss and <abbr title="Transmission Control Protocol">TCP</abbr> and <abbr title="User Datagram Protocol">UDP</abbr> download, upload speed measurements (CLI only);<br>
----------------------<br><br>
Changes in this release:<br><br>
*) bgp - properly update keepalive time after peer restart;<br>
*) bridge - added option to monitor fast-forward status;<br>
*) bridge - count routed FastPath packets between bridge ports under FastPath bridge statistics;<br>
*) bridge - disable fast-forward when using SlowPath features;<br>
*) bridge - fixed BOOTP packet forwarding when <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping is enabled;<br>
*) bridge - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Option 82 parsing when using <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping;<br>
*) bridge - fixed log message when hardware offloading is being enabled;<br>
*) bridge - fixed packet forwarding when changing MSTI <abbr title="Virtual Local Area Network">VLAN</abbr> mappings;<br>
*) bridge - fixed packet forwarding with enabled <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping and Option 82;<br>
*) bridge - fixed possible memory leak when using MSTP;<br>
*) bridge - fixed system's identity change when <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping is enabled (introduced in v6.43);<br>
*) bridge - improved packet handling when hardware offloading is being disabled;<br>
*) bridge - improved packet processing when bridge port changes states;<br>
*) btest - added multithreading support for both <abbr title="User Datagram Protocol">UDP</abbr> and <abbr title="Transmission Control Protocol">TCP</abbr> tests;<br>
*) btest - added warning message when CPU load exceeds 90% (CLI only);<br>
*) capsman - always accept connections from loopback address;<br>
*) certificate - added support for multiple "Subject Alt. Names";<br>
*) certificate - enabled RC2 cipher to allow P12 certificate decryption;<br>
*) certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided;<br>
*) certificate - show digest algorithm used in signature;<br>
*) chr - assign interface names based on underlying PCI device order on KVM;<br>
*) chr - distribute NIC queue IRQ's evenly across all CPUs;<br>
*) chr - fixed IRQ balancing when using more than 32 CPUs;<br>
*) chr - improved system stability when insufficient resources are allocated to the guest;<br>
*) cloud - added "ddns-update-interval" parameter;<br>
*) cloud - do not reuse old <abbr title="User Datagram Protocol">UDP</abbr> socket if routing changes are detected;<br>
*) cloud - ignore "force-update" command if DDNS is disabled;<br>
*) cloud - improved DDNS service disabling;<br>
*) cloud - made address updating faster when new public address detected;<br>
*) conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter);<br>
*) console - renamed IP protocol 41 to "ipv6-encap";<br>
*) console - updated copyright notice;<br>
*) crs317 - fixed packet forwarding when LACP is used with hw=no;<br>
*) crs3xx - fixed packet forwarding through <abbr title="Small Form-factor Pluggable">SFP</abbr>+ ports when using 100Mbps link speed;<br>
*) crs3xx - improved fan control stability;<br>
*) defconf - fixed configuration not generating properly on upgrade;<br>
*) defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;<br>
*) defconf - fixed IPv6 link-local address range in firewall rules;<br>
*) dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> servers to control dynamic lease/binding behaviour;<br>
*) dhcp - properly load <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> configuration if options are configured;<br>
*) dhcpv4-server - added "parent-queue" parameter (CLI only);<br>
*) dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;<br>
*) dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;<br>
*) dhcpv4-server - use ARP for conflict detection;<br>
*) dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client;<br>
*) dhcpv6-server - allow to add DHCPv6 server with pool that does not exist;<br>
*) dhcpv6-server - fixed missing gateway for binding's network if RADIUS authentication was used;<br>
*) dhcpv6-server - improved DHCPv6 server stability when using "print" command;<br>
*) dhcpv6-server - show "client-address" parameter for bindings;<br>
*) discovery - detect proper slave interface on bounded interfaces;<br>
*) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;<br>
*) discovery - send master port in "interface-name" parameter;<br>
*) discovery - show neighbors on actual bridge port instead of bridge itself for LLDP;<br>
*) e-mail - added info log message when e-mail is sent successfully;<br>
*) ethernet - added "tx-rx-1024-max" counter to Ethernet stats;<br>
*) ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;<br>
*) ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);<br>
*) ethernet - fixed packet forwarding when <abbr title="Small Form-factor Pluggable">SFP</abbr> interface is disabled on hEX S;<br>
*) ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;<br>
*) ethernet - improved per core ethernet traffic classificator on mmips devices;<br>
*) export - fixed "silent-boot" compact export;<br>
*) fetch - added "http-header-field" parameter;<br>
*) fetch - added option to specify multiple headers under "http-header-field", including content type;<br>
*) fetch - fixed "without-paging" option;<br>
*) fetch - improved file downloading to slow memory;<br>
*) fetch - improved stability when using HTTP mode;<br>
*) fetch - removed "http-content-type" parameter;<br>
*) gps - increase precision for dd format;<br>
*) gps - moved "coordinate-format" from "monitor" command to "set" parameter;<br>
*) health - improved fan control stability on CRS328-24P-4S+RM;<br>
*) hotspot - added "https-redirect" under server profiles;<br>
*) hotspot - added per-user NAT rule generation based on "incoming-filter" and "outgoing-filter" parameters;<br>
*) ike1 - do not allow using RSA-key and RSA-signature authentication methods simultaneously on single peer;<br>
*) ike1 - fixed memory leak;<br>
*) ike2 - added option to specify certificate chain;<br>
*) ike2 - added peer identity validation for RSA auth (disabled after upgrade);<br>
*) ike2 - allow to match responder peer by "my-id=fqdn" field;<br>
*) ike2 - fixed local address lookup when initiating new connection;<br>
*) ike2 - improved subsequent phase 2 initialization when no childs exist;<br>
*) ike2 - properly handle certificates with empty "Subject";<br>
*) ike2 - retry RSA signature validation with deduced digest from certificate;<br>
*) ike2 - send split networks over <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> (option 249) to Windows initiators if <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Inform is received;<br>
*) ike2 - show weak pre-shared-key warning;<br>
*) interface - added "pwr-line" interface support (more information will follow in next newsletter);<br>
*) ipsec - added account log message when user is successfully authenticated;<br>
*) ipsec - added basic pre-shared-key strength checks;<br>
*) ipsec - added new "remote-id" peer matcher;<br>
*) ipsec - allow to specify single address instead of IP pool under "mode-config";<br>
*) ipsec - fixed active connection killing when changing peer configuration;<br>
*) ipsec - fixed all policies not getting installed after startup (introduced in v6.43.8);<br>
*) ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);<br>
*) ipsec - hide empty prefixes on "peer" menu;<br>
*) ipsec - improved invalid policy handling when a valid policy is uninstalled;<br>
*) ipsec - made dynamic "src-nat" rule more specific;<br>
*) ipsec - made peers autosort themselves based on reachability status;<br>
*) ipsec - moved "profile" menu outside "peer" menu;<br>
*) ipsec - properly detect AES-NI extension as hardware AEAD;<br>
*) ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;<br>
*) ipsec - require write policy for key generation;<br>
*) kidcontrol - added IPv6 support;<br>
*) kidcontrol - added "reset-counters" command for "device" menu (CLI only);<br>
*) kidcontrol - added statistics web interface for kids (http://router.<abbr title="Local Area Network">lan</abbr>/kid-control);<br>
*) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters;<br>
*) kidcontrol - dynamically discover devices from <abbr title="Domain Name System">DNS</abbr> activity;<br>
*) kidcontrol - fixed validation checks for time intervals;<br>
*) kidcontrol - properly detect time zone changes;<br>
*) kidcontrol - use "/128" prefix-length for IPv6 addresses;<br>
*) l2tp - fixed IPsec secret not being updated when "ipsec-secret" is changed under L2TP client configuration;<br>
*) lcd - made "pin" parameter sensitive;<br>
*) led - fixed default LED configuration for RBSXTsq-60ad;<br>
*) led - fixed default LED configuration for wAP 60G AP devices;<br>
*) led - fixed PWR-LINE AP Ethernet LED polarity ("/system routerboard upgrade" required);<br>
*) lldp - fixed missing capabilities fields on some devices;<br>
*) lte - added additional ID support for Novatel USB730L modem;<br>
*) lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);<br>
*) lte - added "ecno" field for "info" command;<br>
*) lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);<br>
*) lte - added initial support for multiple APN for R11e-4G (new modem firmware required);<br>
*) lte - added initial support for Telit LN940;<br>
*) lte - added multiple APN support for R11e-4G;<br>
*) lte - added option to lock the LTE operator;<br>
*) lte - added support for JioFi JMR1040 modem;<br>
*) lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> IP acquire (introduced in v6.43.7);<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> relay packet forwarding when in passthrough mode;<br>
*) lte - fixed IPv6 activation for R11e-LTE-US modems;<br>
*) lte - fixed Jaton/SQN modems preventing router from booting properly;<br>
*) lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;<br>
*) lte - fixed missing running (R) flag for Jaton LTE modems;<br>
*) lte - fixed passthrough <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> address forward when other address is acquired from operator;<br>
*) lte - fixed reported "rsrq" precision (introduced in v6.43.8);<br>
*) lte - improved compatibility for Alt38xx modems;<br>
*) lte - improved SIM7600 initialization after reset;<br>
*) lte - improved SimCom 7100e support;<br>
*) lte - query "cfun" on initialization;<br>
*) lte - require write policy for at-chat;<br>
*) lte - update firmware version information after R11e-LTE/R11e-4G firmware upgrade;<br>
*) netinstall - do not show kernel failure critical messages in the log after fresh install;<br>
*) ntp-client - fixed "dst-active" and "gmt-offset" being updated after synchronization with server;<br>
*) port - improved "remote-serial" <abbr title="Transmission Control Protocol">TCP</abbr> performance in RAW mode;<br>
*) ppp - added "at-chat" command;<br>
*) ppp - fixed dynamic route creation towards VPN server when "add-default-route" is used;<br>
*) profiler - classify kernel crypto processing as "encrypting";<br>
*) profile - removed obsolete "file-name" parameter;<br>
*) proxy - removed port list size limit;<br>
*) radius - implemented Proxy-State attribute handling in CoA and disconnect requests;<br>
*) rb3011 - implemented multiple engine IPsec hardware acceleration support;<br>
*) rb4011 - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface full duplex and speed parameter behavior;<br>
*) rb4011 - improved <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface linking to 1Gbps;<br>
*) rbm33g - improved stability when used with some USB devices;<br>
*) romon - improved reliability when processing RoMON packets on CHR;<br>
*) routerboard - removed "<abbr title="Рутер борд">RB</abbr>" prefix from PWR-LINE AP devices;<br>
*) routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";<br>
*) smb - added commenting option for SMB users (CLI only);<br>
*) smb - fixed macOS clients not showing share contents;<br>
*) smb - fixed Windows 10 clients not able to establish connection to share;<br>
*) sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;<br>
*) snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;<br>
*) snmp - changed fan speed value type to Gauge32;<br>
*) snmp - fixed "rsrq" reported precision;<br>
*) snmp - fixed w60g station table;<br>
*) snmp - removed "rx-sector" ("Wl60gRxSector") value;<br>
*) snmp - report bridge ifSpeed as "0";<br>
*) snmp - report ifSpeed 0 for sub-layer interfaces;<br>
*) ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);<br>
*) ssh - added error log message when key exchange fails;<br>
*) ssh - close active <abbr title="Secure Shell">SSH</abbr> connections before IPsec connections on shutdown;<br>
*) ssh - fixed public key format compatibility with RFC4716;<br>
*) supout - fixed "poe-out" output not showing all interfaces;<br>
*) supout - fixed Profile output on single core devices;<br>
*) switch - added comment field to switch ACL rules;<br>
*) switch - fixed ACL rules on IPQ4018 devices;<br>
*) system - accept only valid path for "log-file" parameter in "port" menu;<br>
*) system - removed obsolete "/driver" command;<br>
*) tr069-client - added "check-certificate" parameter to allow communication without certificates;<br>
*) tr069-client - added "connection-request-port" parameter (CLI only);<br>
*) tr069-client - added support for InformParameter object;<br>
*) tr069-client - fixed certificate verification for certificates with IP address;<br>
*) tr069-client - fixed HTTP cookie getting duplicated with the same key;<br>
*) tr069-client - increased reported "rsrq" precision;<br>
*) traceroute - improved stability when sending large ping amounts;<br>
*) traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;<br>
*) tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with <abbr title="Domain Name System">DNS</abbr> as "remote-address";<br>
*) upgrade - made security package depend on <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> package;<br>
*) usb - improved power-reset error message when no bus specified on CCR1072-8G-1S+;<br>
*) usb - improved USB device powering on startup for hAP ac^2 devices;<br>
*) usb - increased default power-reset timeout to 5 seconds;<br>
*) userman - added first and last name fields for signup form;<br>
*) userman - show redirect location in error messages;<br>
*) user - require "write" permissions for LTE firmware update;<br>
*) vrrp - made "password" parameter sensitive;<br>
*) w60g - added "10s-average-rssi" parameter to align mode (CLI only);<br>
*) w60g - added align mode "/interface w60g align" (CLI only);<br>
*) w60g - fixed scan in bridge mode;<br>
*) w60g - improved PtMP performance;<br>
*) w60g - improved reconnection detection;<br>
*) w60g - improved "tx-packet-error-rate" reading;<br>
*) w60g - renamed disconnection message when license level did not allow more connected clients;<br>
*) w60g - renamed "frequency-list" to "scan-list";<br>
*) watchdog - allow specifying <abbr title="Domain Name System">DNS</abbr> name for "send-smtp-server" parameter;<br>
*) webfig - improved file handling;<br>
*) winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;<br>
*) winbox - added "allow-dual-stack-queue" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server" and "IPv6/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server" menus;<br>
*) winbox - added "challenge-password" field when signing certificate with SCEP;<br>
*) winbox - added "conflict-detection" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server" menu;<br>
*) winbox - added "coordinate-format" parameter in LTE interface settings;<br>
*) winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;<br>
*) winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;<br>
*) winbox - added src/dst address and in/out interface list columns to default firewall menu view;<br>
*) winbox - added support for dynamic devices in "IP/Kid Control/Devices" tab;<br>
*) winbox - allow setting "network-mode" to "auto" under LTE interface settings;<br>
*) winbox - allow specifying interface lists in "CAPsMAN/Access List" menu;<br>
*) winbox - fixed "IPv6/Firewall" "Connection limit" parameter not allowing complete IPv6 prefix lengths;<br>
*) winbox - fixed L2MTU parameter setting on "W60G" type interfaces;<br>
*) winbox - fixed "LCD" menu not shown on RB2011UiAS-2HnD;<br>
*) winbox - fixed missing w60g interface status values;<br>
*) winbox - improved file handling;<br>
*) winbox - moved "Too Long" statistics counter to Ethernet "Rx Stats" tab;<br>
*) winbox - organized wireless parameters between simple and advanced modes;<br>
*) winbox - renamed "Default AP Tx Rate" to "Default AP Tx Limit";<br>
*) winbox - renamed "Default Client Tx Rate" to "Default Client Tx Limit";<br>
*) winbox - show "R" flag under "IPv6/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server/Bindings" tab;<br>
*) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;<br>
*) winbox - show "W60G" wireless tab on wAP 60G AP;<br>
*) wireless - added new "installation" parameter to specify router's location;<br>
*) wireless - improved AR5212 response to incoming ACK frames;<br>
*) wireless - improved connection stability for new model Apple devices;<br>
*) wireless - improved NV2 performance for all ARM devices;<br>
*) wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);<br>
*) wireless - improved system stability for all ARM devices with wireless;<br>
*) wireless - improved system stability for all devices with 802.11ac wireless;<br>
*) wireless - improved system stability when scanning for other networks;<br>
*) wireless - removed G/N support for 2484MHz in "japan" regulatory domain;<br>
*) wireless - report last seen IP address in RADIUS accounting messages;<br>
*) wireless - show "installation" parameter when printing configuration;<br><br>Download the new '<b>RouterOS 6.44</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/stable" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7345</guid><pubDate>Tue, 26 Feb 2019 07:11:02 +0000</pubDate></item><item><title>RouterOS 6.44rc4 [Testing]</title><link>https://www.mikrotik-bg.net/blogs/entry/7344-routeros-644rc4-testing/</link><description><![CDATA[
<p></p>
<h3>6.44rc4 changelog:</h3>Important note!!! Backup before upgrade!<br>
Due to major IPsec configuration changes in RouterOS v6.44beta39+ (see changelog below), it is advised to make a backup before upgrading. Regular downgrade will still be possible as long as no changes in IPsec peer menu are done.<br><br>
MAJOR CHANGES IN v6.44:<br>
----------------------<br>
!) cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);<br>
!) ipsec - added new "identity" menu with common peer distinguishers;<br>
!) ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;<br>
!) ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu;<br>
!) radius - initial implementation of RadSec (Radius communication over TLS);<br>
!) speedtest - added "/tool speed-test" for ping latency, jitter, loss and <abbr title="Transmission Control Protocol">TCP</abbr> and <abbr title="User Datagram Protocol">UDP</abbr> download, upload speed measurements (CLI only);<br>
!) telnet - do not allow to set "tracefile" parameter;<br>
!) upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";<br>
!) upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;<br>
----------------------<br><br>
Changes in this release:<br><br>
!) ipsec - added new "identity" menu with common peer distinguishers;<br>
*) ike1 - do not allow using RSA-key and RSA-signature authentication methods simultaneously on single peer;<br>
*) interface - added "pwr-line" interface support (more information will follow in next newsletter);<br>
*) rb4011 - improved <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface linking to 1Gbps;<br>
*) ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);<br>
*) winbox - organized wireless parameters between simple and advanced modes;<br>
*) wireless - improved NV2 performance for all ARM devices;<br><br>
Other changes since v6.43.12:<br><br>
*) dhcpv4-server - use ARP for conflict detection;<br>
*) discovery - use source MAC address from master interface for MNDP packets (introduced in v6.44beta50);<br>
*) fetch - improved file downloading to slow memory;<br>
*) hotspot - added per-user NAT rule generation based on "incoming-filter" and "outgoing-filter" parameters;<br>
*) ike1 - fixed memory leak;<br>
*) ipsec - allow to specify single address instead of IP pool under "mode-config";<br>
*) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters;<br>
*) lte - added initial support for Telit LN940;<br>
*) lte - added option to lock the LTE operator;<br>
*) smb - added commenting option for SMB users (CLI only);<br>
*) supout - fixed Profile output on single core devices;<br>
*) userman - added first and last name fields for signup form;<br>
*) webfig - improved file handling;<br>
*) winbox - improved file handling;<br>
*) wireless - improved AR5212 response to incoming ACK frames;<br>
*) wireless - improved system stability for all ARM devices with wireless; <br>
*) wireless - improved system stability for all devices with 802.11ac wireless;<br>
*) bgp - properly update keepalive time after peer restart;<br>
*) bridge - added option to monitor fast-forward status;<br>
*) bridge - count routed FastPath packets between bridge ports under FastPath bridge statistics;<br>
*) bridge - disable fast-forward when using SlowPath features;<br>
*) bridge - fixed BOOTP packet forwarding when <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping is enabled;<br>
*) bridge - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Option 82 parsing when using <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping;<br>
*) bridge - fixed log message when hardware offloading is being enabled;<br>
*) bridge - fixed packet forwarding when changing MSTI <abbr title="Virtual Local Area Network">VLAN</abbr> mappings;<br>
*) bridge - fixed packet forwarding with enabled <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping and Option 82;<br>
*) bridge - fixed possible memory leak when using MSTP;<br>
*) bridge - fixed system's identity change when <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping is enabled (introduced in v6.43);<br>
*) bridge - improved packet handling when hardware offloading is being disabled;<br>
*) bridge - improved packet processing when bridge port changes states;<br>
*) btest - added multithreading support for both <abbr title="User Datagram Protocol">UDP</abbr> and <abbr title="Transmission Control Protocol">TCP</abbr> tests;<br>
*) btest - added warning message when CPU load exceeds 90% (CLI only);<br>
*) capsman - always accept connections from loopback address;<br>
*) certificate - added support for multiple "Subject Alt. Names";<br>
*) certificate - enabled RC2 cipher to allow P12 certificate decryption;<br>
*) certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided;<br>
*) certificate - show digest algorithm used in signature;<br>
*) chr - assign interface names based on underlying PCI device order on KVM;<br>
*) chr - distribute NIC queue IRQ's evenly across all CPUs;<br>
*) chr - fixed IRQ balancing when using more than 32 CPUs;<br>
*) chr - improved system stability when insufficient resources are allocated to the guest;<br>
*) cloud - added "ddns-update-interval" parameter;<br>
*) cloud - do not reuse old <abbr title="User Datagram Protocol">UDP</abbr> socket if routing changes are detected;<br>
*) cloud - ignore "force-update" command if DDNS is disabled;<br>
*) cloud - improved DDNS service disabling;<br>
*) cloud - made address updating faster when new public address detected;<br>
*) conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter);<br>
*) console - renamed IP protocol 41 to "ipv6-encap";<br>
*) console - updated copyright notice;<br>
*) crs317 - fixed packet forwarding when LACP is used with hw=no;<br>
*) crs317 - fixed TX not working on sfp-sfpplus9 interface (introduced in v6.40beta12);<br>
*) crs328 - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);<br>
*) crs3xx - fixed packet forwarding through <abbr title="Small Form-factor Pluggable">SFP</abbr>+ ports when using 100Mbps link speed;<br>
*) crs3xx - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr>+ linking using 1.25G <abbr title="Small Form-factor Pluggable">SFP</abbr> modules (introduced in v6.44beta39);<br>
*) crs3xx - fixed slow bootup, upgrade and <abbr title="Small Form-factor Pluggable">SFP</abbr> status read (introduced in v6.44beta20);<br>
*) crs3xx - improved fan control stability;<br>
*) crs3xx - improved stability when adding ACL rules on CRS326 and CRS328 devices (introduced in 6.44beta39);<br>
*) defconf - fixed configuration not generating properly on upgrade;<br>
*) defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;<br>
*) defconf - fixed IPv6 link-local address range in firewall rules;<br>
*) dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> servers to control dynamic lease/binding behaviour;<br>
*) dhcp - properly load <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> configuration if options are configured;<br>
*) dhcpv4-server - added "parent-queue" parameter (CLI only);<br>
*) dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;<br>
*) dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;<br>
*) dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client;<br>
*) dhcpv6-server - allow to add DHCPv6 server with pool that does not exist;<br>
*) dhcpv6-server - fixed missing gateway for binding's network if RADIUS authentication was used;<br>
*) dhcpv6-server - improved DHCPv6 server stability when using "print" command;<br>
*) dhcpv6-server - show "client-address" parameter for bindings;<br>
*) discovery - detect proper slave interface on bounded interfaces;<br>
*) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;<br>
*) discovery - send master port in "interface-name" parameter;<br>
*) discovery - show neighbors on actual bridge port instead of bridge itself for LLDP;<br>
*) e-mail - added info log message when e-mail is sent successfully;<br>
*) ethernet - added "tx-rx-1024-max" counter to Ethernet stats;<br>
*) ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;<br>
*) ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);<br>
*) ethernet - fixed packet forwarding when <abbr title="Small Form-factor Pluggable">SFP</abbr> interface is disabled on hEX S;<br>
*) ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;<br>
*) ethernet - improved per core ethernet traffic classificator on mmips devices;<br>
*) export - fixed "silent-boot" compact export;<br>
*) fetch - added "http-header-field" parameter;<br>
*) fetch - added option to specify multiple headers under "http-header-field", including content type;<br>
*) fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20);<br>
*) fetch - fixed "without-paging" option;<br>
*) fetch - improved stability when using HTTP mode;<br>
*) fetch - removed "http-content-type" parameter;<br>
*) gps - increase precision for dd format;<br>
*) gps - moved "coordinate-format" from "monitor" command to "set" parameter;<br>
*) health - improved fan control stability on CRS328-24P-4S+RM;<br>
*) hotspot - added "https-redirect" under server profiles;<br>
*) ike1 - fixed "rsa-key" authentication (introduced in v6.44beta);<br>
*) ike2 - added option to specify certificate chain;<br>
*) ike2 - added peer identity validation for RSA auth (disabled after upgrade);<br>
*) ike2 - allow to match responder peer by "my-id=fqdn" field;<br>
*) ike2 - fixed local address lookup when initiating new connection;<br>
*) ike2 - improved subsequent phase 2 initialization when no childs exist;<br>
*) ike2 - properly handle certificates with empty "Subject";<br>
*) ike2 - retry RSA signature validation with deduced digest from certificate;<br>
*) ike2 - send split networks over <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> (option 249) to Windows initiators if <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Inform is received;<br>
*) ike2 - show weak pre-shared-key warning;<br>
*) ipsec - added account log message when user is successfully authenticated;<br>
*) ipsec - added basic pre-shared-key strength checks;<br>
*) ipsec - added new "remote-id" peer matcher;<br>
*) ipsec - allow to specify single address instead of IP pool under "mode-config";<br>
*) ipsec - fixed active connection killing when changing peer configuration;<br>
*) ipsec - fixed all policies not getting installed after startup (introduced in v6.43.8);<br>
*) ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);<br>
*) ipsec - hide empty prefixes on "peer" menu;<br>
*) ipsec - improved invalid policy handling when a valid policy is uninstalled;<br>
*) ipsec - made dynamic "src-nat" rule more specific;<br>
*) ipsec - made peers autosort themselves based on reachability status;<br>
*) ipsec - moved "profile" menu outside "peer" menu;<br>
*) ipsec - properly detect AES-NI extension as hardware AEAD;<br>
*) ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;<br>
*) ipsec - require write policy for key generation;<br>
*) kidcontrol - added IPv6 support;<br>
*) kidcontrol - added "reset-counters" command for "device" menu (CLI only);<br>
*) kidcontrol - added statistics web interface for kids (http://router.<abbr title="Local Area Network">lan</abbr>/kid-control);<br>
*) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);<br>
*) kidcontrol - dynamically discover devices from <abbr title="Domain Name System">DNS</abbr> activity;<br>
*) kidcontrol - fixed validation checks for time intervals;<br>
*) kidcontrol - properly detect time zone changes;<br>
*) kidcontrol - use "/128" prefix-length for IPv6 addresses;<br>
*) l2tp - fixed IPsec secret not being updated when "ipsec-secret" is changed under L2TP client configuration;<br>
*) lcd - made "pin" parameter sensitive;<br>
*) led - fixed default LED configuration for RBSXTsq-60ad;<br>
*) led - fixed default LED configuration for wAP 60G AP devices;<br>
*) led - fixed PWR-LINE AP Ethernet LED polarity ("/system routerboard upgrade" required);<br>
*) lldp - fixed missing capabilities fields on some devices;<br>
*) lte - added additional ID support for Novatel USB730L modem;<br>
*) lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);<br>
*) lte - added "ecno" field for "info" command;<br>
*) lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);<br>
*) lte - added initial support for multiple APN for R11e-4G (new modem firmware required);<br>
*) lte - added multiple APN support for R11e-4G;<br>
*) lte - added support for JioFi JMR1040 modem;<br>
*) lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> IP acquire in 3G mode for r11e-lte (introduced in v6.44beta54);<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> IP acquire (introduced in v6.43.7);<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> relay packet forwarding when in passthrough mode;<br>
*) lte - fixed IPv6 activation for R11e-LTE-US modems;<br>
*) lte - fixed Jaton/SQN modems preventing router from booting properly;<br>
*) lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;<br>
*) lte - fixed missing running (R) flag for Jaton LTE modems;<br>
*) lte - fixed passthrough <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> address forward when other address is acquired from operator;<br>
*) lte - fixed reported "rsrq" precision (introduced in v6.43.8);<br>
*) lte - improved compatibility for Alt38xx modems;<br>
*) lte - improved SIM7600 initialization after reset;<br>
*) lte - improved SimCom 7100e support;<br>
*) lte - query "cfun" on initialization;<br>
*) lte - require write policy for at-chat;<br>
*) lte - update firmware version information after R11e-LTE/R11e-4G firmware upgrade;<br>
*) netinstall - do not show kernel failure critical messages in the log after fresh install;<br>
*) ntp-client - fixed "dst-active" and "gmt-offset" being updated after synchronization with server;<br>
*) port - improved "remote-serial" <abbr title="Transmission Control Protocol">TCP</abbr> performance in RAW mode;<br>
*) ppp - added "at-chat" command;<br>
*) ppp - fixed dynamic route creation towards VPN server when "add-default-route" is used;<br>
*) profiler - classify kernel crypto processing as "encrypting";<br>
*) profile - removed obsolete "file-name" parameter;<br>
*) proxy - removed port list size limit;<br>
*) radius - implemented Proxy-State attribute handling in CoA and disconnect requests;<br>
*) rb3011 - implemented multiple engine IPsec hardware acceleration support;<br>
*) rb4011 - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface full duplex and speed parameter behavior;<br>
*) rbm33g - improved stability when used with some USB devices;<br>
*) romon - improved reliability when processing RoMON packets on CHR;<br>
*) routerboard - removed "<abbr title="Рутер борд">RB</abbr>" prefix from PWR-LINE AP devices;<br>
*) routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";<br>
*) sfp - fixed possible reboot loop when inserting <abbr title="Small Form-factor Pluggable">SFP</abbr> modules in CRS328-4C-20S-4S+ (introduced in v6.44beta61);<br>
*) smb - fixed macOS clients not showing share contents;<br>
*) smb - fixed Windows 10 clients not able to establish connection to share;<br>
*) sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;<br>
*) snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;<br>
*) snmp - changed fan speed value type to Gauge32;<br>
*) snmp - fixed "rsrq" reported precision;<br>
*) snmp - fixed w60g station table;<br>
*) snmp - removed "rx-sector" ("Wl60gRxSector") value;<br>
*) snmp - report bridge ifSpeed as "0";<br>
*) snmp - report ifSpeed 0 for sub-layer interfaces;<br>
*) ssh - added error log message when key exchange fails;<br>
*) ssh - close active <abbr title="Secure Shell">SSH</abbr> connections before IPsec connections on shutdown;<br>
*) ssh - fixed non-interactive shell not returning all output (introduced in v6.44);<br>
*) ssh - fixed public key format compatibility with RFC4716;<br>
*) ssh - fixed single command execution (introduced in v6.44beta9);<br>
*) supout - fixed "poe-out" output not showing all interfaces;<br>
*) switch - added comment field to switch ACL rules;<br>
*) switch - fixed ACL rules on IPQ4018 devices;<br>
*) system - accept only valid path for "log-file" parameter in "port" menu;<br>
*) system - removed obsolete "/driver" command;<br>
*) tr069-client - added "check-certificate" parameter to allow communication without certificates;<br>
*) tr069-client - added "connection-request-port" parameter (CLI only);<br>
*) tr069-client - added support for InformParameter object;<br>
*) tr069-client - fixed certificate verification for certificates with IP address;<br>
*) tr069-client - fixed HTTP cookie getting duplicated with the same key;<br>
*) tr069-client - increased reported "rsrq" precision;<br>
*) traceroute - improved stability when sending large ping amounts;<br>
*) traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;<br>
*) tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with <abbr title="Domain Name System">DNS</abbr> as "remote-address";<br>
*) upgrade - made security package depend on <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> package;<br>
*) usb - improved power-reset error message when no bus specified on CCR1072-8G-1S+;<br>
*) usb - improved USB device powering on startup for hAP ac^2 devices; <br>
*) usb - increased default power-reset timeout to 5 seconds;<br>
*) userman - added first and last name fields for signup form;<br>
*) userman - show redirect location in error messages;<br>
*) user - require "write" permissions for LTE firmware update;<br>
*) vrrp - made "password" parameter sensitive;<br>
*) w60g - added "10s-average-rssi" parameter to align mode (CLI only);<br>
*) w60g - added align mode "/interface w60g align" (CLI only);<br>
*) w60g - fixed scan in bridge mode;<br>
*) w60g - improved PtMP performance;<br>
*) w60g - improved reconnection detection;<br>
*) w60g - improved "tx-packet-error-rate" reading;<br>
*) w60g - renamed disconnection message when license level did not allow more connected clients;<br>
*) w60g - renamed "frequency-list" to "scan-list";<br>
*) watchdog - allow specifying <abbr title="Domain Name System">DNS</abbr> name for "send-smtp-server" parameter;<br>
*) winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;<br>
*) winbox - added "allow-dual-stack-queue" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server" and "IPv6/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server" menus;<br>
*) winbox - added "challenge-password" field when signing certificate with SCEP;<br>
*) winbox - added "conflict-detection" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server" menu;<br>
*) winbox - added "conflict-detection" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> server" menu;<br>
*) winbox - added "coordinate-format" parameter in LTE interface settings;<br>
*) winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;<br>
*) winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;<br>
*) winbox - added src/dst address and in/out interface list columns to default firewall menu view;<br>
*) winbox - added support for dynamic devices in "IP/Kid Control/Devices" tab;<br>
*) winbox - allow setting "network-mode" to "auto" under LTE interface settings;<br>
*) winbox - allow specifying interface lists in "CAPsMAN/Access List" menu;<br>
*) winbox - fixed "IPv6/Firewall" "Connection limit" parameter not allowing complete IPv6 prefix lengths;<br>
*) winbox - fixed L2MTU parameter setting on "W60G" type interfaces;<br>
*) winbox - fixed "LCD" menu not shown on RB2011UiAS-2HnD;<br>
*) winbox - fixed missing w60g interface status values;<br>
*) winbox - moved "Too Long" statistics counter to Ethernet "Rx Stats" tab;<br>
*) winbox - renamed "Default AP Tx Rate" to "Default AP Tx Limit";<br>
*) winbox - renamed "Default Client Tx Rate" to "Default Client Tx Limit";<br>
*) winbox - show "R" flag under "IPv6/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server/Bindings" tab;<br>
*) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;<br>
*) winbox - show "W60G" wireless tab on wAP 60G AP;<br>
*) wireless - added new "installation" parameter to specify router's location;<br>
*) wireless - improved connection stability for new model Apple devices;<br>
*) wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);<br>
*) wireless - improved system stability for all ARM devices with wireless;<br>
*) wireless - improved system stability when scanning for other networks;<br>
*) wireless - removed G/N support for 2484MHz in "japan" regulatory domain;<br>
*) wireless - report last seen IP address in RADIUS accounting messages;<br>
*) wireless - show "installation" parameter when printing configuration;<br><br>Download the new '<b>RouterOS 6.44rc4</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/testing" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7344</guid><pubDate>Fri, 22 Feb 2019 11:35:37 +0000</pubDate></item><item><title>RouterOS 6.44rc1 [Testing]</title><link>https://www.mikrotik-bg.net/blogs/entry/7343-routeros-644rc1-testing/</link><description><![CDATA[
<p></p>
<h3>6.44rc1 changelog:</h3>Important note!!! Backup before upgrade!<br>
Due to major IPsec configuration changes in RouterOS v6.44beta39+ (see changelog below), it is advised to make a backup before upgrading. Regular downgrade will still be possible as long as no changes in IPsec peer menu are done.<br><br>
MAJOR CHANGES IN v6.44:<br>
----------------------<br>
!) cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);<br>
!) ipsec - added new "identity" menu with common peer distinguishers;<br>
!) ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;<br>
!) ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu;<br>
!) radius - initial implementation of RadSec (Radius communication over TLS);<br>
!) speedtest - added "/tool speed-test" for ping latency, jitter, loss and <abbr title="Transmission Control Protocol">TCP</abbr> and <abbr title="User Datagram Protocol">UDP</abbr> download, upload speed measurements (CLI only);<br>
!) telnet - do not allow to set "tracefile" parameter;<br>
!) upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";<br>
!) upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;<br>
----------------------<br><br>
Changes in this release:<br><br>
!) ipsec - added new "identity" menu with common peer distinguishers;<br>
!) radius - initial implementation of RadSec (Radius communication over TLS);<br>
*) dhcpv4-server - use ARP for conflict detection;<br>
*) discovery - use source MAC address from master interface for MNDP packets (introduced in v6.44beta50);<br>
*) fetch - improved file downloading to slow memory;<br>
*) hotspot - added per-user NAT rule generation based on "incoming-filter" and "outgoing-filter" parameters;<br>
*) ike1 - fixed memory leak;<br>
*) ipsec - allow to specify single address instead of IP pool under "mode-config";<br>
*) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters;<br>
*) lte - added initial support for Telit LN940;<br>
*) lte - added option to lock the LTE operator;<br>
*) smb - added commenting option for SMB users (CLI only);<br>
*) supout - fixed Profile output on single core devices;<br>
*) userman - added first and last name fields for signup form;<br>
*) webfig - improved file handling;<br>
*) winbox - improved file handling;<br>
*) wireless - improved AR5212 response to incoming ACK frames;<br>
*) wireless - improved system stability for all ARM devices with wireless; <br>
*) wireless - improved system stability for all MIPSBE devices with 802.11ac wireless;<br><br>
Other changes since v6.43.12:<br><br>
*) bgp - properly update keepalive time after peer restart;<br>
*) bridge - added option to monitor fast-forward status;<br>
*) bridge - count routed FastPath packets between bridge ports under FastPath bridge statistics;<br>
*) bridge - disable fast-forward when using SlowPath features;<br>
*) bridge - fixed BOOTP packet forwarding when <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping is enabled;<br>
*) bridge - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Option 82 parsing when using <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping;<br>
*) bridge - fixed log message when hardware offloading is being enabled;<br>
*) bridge - fixed packet forwarding when changing MSTI <abbr title="Virtual Local Area Network">VLAN</abbr> mappings;<br>
*) bridge - fixed packet forwarding with enabled <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping and Option 82;<br>
*) bridge - fixed possible memory leak when using MSTP;<br>
*) bridge - fixed system's identity change when <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping is enabled (introduced in v6.44beta61);<br>
*) bridge - improved packet handling when hardware offloading is being disabled;<br>
*) bridge - improved packet processing when bridge port changes states;<br>
*) btest - added multithreading support for both <abbr title="User Datagram Protocol">UDP</abbr> and <abbr title="Transmission Control Protocol">TCP</abbr> tests;<br>
*) btest - added warning message when CPU load exceeds 90% (CLI only);<br>
*) capsman - always accept connections from loopback address;<br>
*) certificate - added support for multiple "Subject Alt. Names";<br>
*) certificate - enabled RC2 cipher to allow P12 certificate decryption;<br>
*) certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided;<br>
*) certificate - show digest algorithm used in signature;<br>
*) chr - assign interface names based on underlying PCI device order on KVM;<br>
*) chr - distribute NIC queue IRQ's evenly across all CPUs;<br>
*) chr - fixed IRQ balancing when using more than 32 CPUs;<br>
*) chr - improved system stability when insufficient resources are allocated to the guest;<br>
*) cloud - added "ddns-update-interval" parameter;<br>
*) cloud - do not reuse old <abbr title="User Datagram Protocol">UDP</abbr> socket if routing changes are detected;<br>
*) cloud - ignore "force-update" command if DDNS is disabled;<br>
*) cloud - improved DDNS service disabling;<br>
*) cloud - made address updating faster when new public address detected;<br>
*) conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter);<br>
*) console - renamed IP protocol 41 to "ipv6-encap";<br>
*) console - updated copyright notice;<br>
*) crs317 - fixed packet forwarding when LACP is used with hw=no;<br>
*) crs317 - fixed TX not working on sfp-sfpplus9 interface (introduced in v6.40beta12);<br>
*) crs328 - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);<br>
*) crs3xx - fixed packet forwarding through <abbr title="Small Form-factor Pluggable">SFP</abbr>+ ports when using 100Mbps link speed;<br>
*) crs3xx - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr>+ linking using 1.25G <abbr title="Small Form-factor Pluggable">SFP</abbr> modules (introduced in v6.44beta39);<br>
*) crs3xx - fixed slow bootup, upgrade and <abbr title="Small Form-factor Pluggable">SFP</abbr> status read (introduced in v6.44beta20);<br>
*) crs3xx - improved fan control stability;<br>
*) crs3xx - improved stability when adding ACL rules on CRS326 and CRS328 devices (introduced in 6.44beta39);<br>
*) defconf - fixed configuration not generating properly on upgrade;<br>
*) defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;<br>
*) defconf - fixed IPv6 link-local address range in firewall rules;<br>
*) dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> servers to control dynamic lease/binding behaviour;<br>
*) dhcp - properly load <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> configuration if options are configured;<br>
*) dhcpv4-server - added "parent-queue" parameter (CLI only);<br>
*) dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;<br>
*) dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;<br>
*) dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client;<br>
*) dhcpv6-server - allow to add DHCPv6 server with pool that does not exist;<br>
*) dhcpv6-server - fixed missing gateway for binding's network if RADIUS authentication was used;<br>
*) dhcpv6-server - improved DHCPv6 server stability when using "print" command;<br>
*) dhcpv6-server - show "client-address" parameter for bindings;<br>
*) discovery - detect proper slave interface on bounded interfaces;<br>
*) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;<br>
*) discovery - send master port in "interface-name" parameter;<br>
*) discovery - show neighbors on actual bridge port instead of bridge itself for LLDP;<br>
*) e-mail - added info log message when e-mail is sent successfully;<br>
*) ethernet - added "tx-rx-1024-max" counter to Ethernet stats;<br>
*) ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;<br>
*) ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);<br>
*) ethernet - fixed packet forwarding when <abbr title="Small Form-factor Pluggable">SFP</abbr> interface is disabled on hEX S;<br>
*) ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;<br>
*) ethernet - improved per core ethernet traffic classificator on mmips devices;<br>
*) export - fixed "silent-boot" compact export;<br>
*) fetch - added "http-header-field" parameter;<br>
*) fetch - added option to specify multiple headers under "http-header-field", including content type;<br>
*) fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20);<br>
*) fetch - fixed "without-paging" option;<br>
*) fetch - improved stability when using HTTP mode;<br>
*) fetch - removed "http-content-type" parameter;<br>
*) gps - increase precision for dd format;<br>
*) gps - moved "coordinate-format" from "monitor" command to "set" parameter;<br>
*) health - improved fan control stability on CRS328-24P-4S+RM;<br>
*) hotspot - added "https-redirect" under server profiles;<br>
*) ike1 - fixed "rsa-key" authentication (introduced in v6.44beta);<br>
*) ike2 - added option to specify certificate chain;<br>
*) ike2 - added peer identity validation for RSA auth (disabled after upgrade);<br>
*) ike2 - allow to match responder peer by "my-id=fqdn" field;<br>
*) ike2 - fixed local address lookup when initiating new connection;<br>
*) ike2 - improved subsequent phase 2 initialization when no childs exist;<br>
*) ike2 - properly handle certificates with empty "Subject";<br>
*) ike2 - retry RSA signature validation with deduced digest from certificate;<br>
*) ike2 - send split networks over <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> (option 249) to Windows initiators if <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Inform is received;<br>
*) ike2 - show weak pre-shared-key warning;<br>
*) ipsec - added account log message when user is successfully authenticated;<br>
*) ipsec - added basic pre-shared-key strength checks;<br>
*) ipsec - added new "remote-id" peer matcher;<br>
*) ipsec - allow to specify single address instead of IP pool under "mode-config";<br>
*) ipsec - fixed active connection killing when changing peer configuration;<br>
*) ipsec - fixed all policies not getting installed after startup (introduced in v6.43.8);<br>
*) ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);<br>
*) ipsec - hide empty prefixes on "peer" menu;<br>
*) ipsec - improved invalid policy handling when a valid policy is uninstalled;<br>
*) ipsec - made dynamic "src-nat" rule more specific;<br>
*) ipsec - made peers autosort themselves based on reachability status;<br>
*) ipsec - moved "profile" menu outside "peer" menu;<br>
*) ipsec - properly detect AES-NI extension as hardware AEAD;<br>
*) ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;<br>
*) ipsec - require write policy for key generation;<br>
*) kidcontrol - added IPv6 support;<br>
*) kidcontrol - added "reset-counters" command for "device" menu (CLI only);<br>
*) kidcontrol - added statistics web interface for kids (http://router.<abbr title="Local Area Network">lan</abbr>/kid-control);<br>
*) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);<br>
*) kidcontrol - dynamically discover devices from <abbr title="Domain Name System">DNS</abbr> activity;<br>
*) kidcontrol - fixed validation checks for time intervals;<br>
*) kidcontrol - properly detect time zone changes;<br>
*) kidcontrol - use "/128" prefix-length for IPv6 addresses;<br>
*) l2tp - fixed IPsec secret not being updated when "ipsec-secret" is changed under L2TP client configuration;<br>
*) lcd - made "pin" parameter sensitive;<br>
*) led - fixed default LED configuration for RBSXTsq-60ad;<br>
*) led - fixed default LED configuration for wAP 60G AP devices;<br>
*) led - fixed PWR-LINE AP Ethernet LED polarity ("/system routerboard upgrade" required);<br>
*) lldp - fixed missing capabilities fields on some devices;<br>
*) lte - added additional ID support for Novatel USB730L modem;<br>
*) lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);<br>
*) lte - added "ecno" field for "info" command;<br>
*) lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);<br>
*) lte - added initial support for multiple APN for R11e-4G (new modem firmware required);<br>
*) lte - added multiple APN support for R11e-4G;<br>
*) lte - added support for JioFi JMR1040 modem;<br>
*) lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> IP acquire in 3G mode for r11e-lte (introduced in v6.44beta54);<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> IP acquire (introduced in v6.43.7);<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> relay packet forwarding when in passthrough mode;<br>
*) lte - fixed IPv6 activation for R11e-LTE-US modems;<br>
*) lte - fixed Jaton/SQN modems preventing router from booting properly;<br>
*) lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;<br>
*) lte - fixed missing running (R) flag for Jaton LTE modems;<br>
*) lte - fixed passthrough <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> address forward when other address is acquired from operator;<br>
*) lte - fixed reported "rsrq" precision (introduced in v6.43.8);<br>
*) lte - improved compatibility for Alt38xx modems;<br>
*) lte - improved SIM7600 initialization after reset;<br>
*) lte - improved SimCom 7100e support;<br>
*) lte - query "cfun" on initialization;<br>
*) lte - require write policy for at-chat;<br>
*) lte - update firmware version information after R11e-LTE/R11e-4G firmware upgrade;<br>
*) netinstall - do not show kernel failure critical messages in the log after fresh install;<br>
*) ntp-client - fixed "dst-active" and "gmt-offset" being updated after synchronization with server;<br>
*) port - improved "remote-serial" <abbr title="Transmission Control Protocol">TCP</abbr> performance in RAW mode;<br>
*) ppp - added "at-chat" command;<br>
*) ppp - fixed dynamic route creation towards VPN server when "add-default-route" is used;<br>
*) profiler - classify kernel crypto processing as "encrypting";<br>
*) profile - removed obsolete "file-name" parameter;<br>
*) proxy - removed port list size limit;<br>
*) radius - implemented Proxy-State attribute handling in CoA and disconnect requests;<br>
*) rb3011 - implemented multiple engine IPsec hardware acceleration support;<br>
*) rb4011 - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface full duplex and speed parameter behavior;<br>
*) rb4011 - improved <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface linking to 1Gbps;<br>
*) rbm33g - improved stability when used with some USB devices;<br>
*) romon - improved reliability when processing RoMON packets on CHR;<br>
*) routerboard - removed "<abbr title="Рутер борд">RB</abbr>" prefix from PWR-LINE AP devices;<br>
*) routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";<br>
*) sfp - fixed possible reboot loop when inserting <abbr title="Small Form-factor Pluggable">SFP</abbr> modules in CRS328-4C-20S-4S+ (introduced in v6.44beta61);<br>
*) smb - fixed macOS clients not showing share contents;<br>
*) smb - fixed Windows 10 clients not able to establish connection to share;<br>
*) sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;<br>
*) snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;<br>
*) snmp - changed fan speed value type to Gauge32;<br>
*) snmp - fixed "rsrq" reported precision;<br>
*) snmp - fixed w60g station table;<br>
*) snmp - removed "rx-sector" ("Wl60gRxSector") value;<br>
*) snmp - report bridge ifSpeed as "0";<br>
*) snmp - report ifSpeed 0 for sub-layer interfaces;<br>
*) ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);<br>
*) ssh - added error log message when key exchange fails;<br>
*) ssh - close active <abbr title="Secure Shell">SSH</abbr> connections before IPsec connections on shutdown;<br>
*) ssh - fixed non-interactive shell not returning all output (introduced in v6.44);<br>
*) ssh - fixed public key format compatibility with RFC4716;<br>
*) ssh - fixed single command execution (introduced in v6.44beta9);<br>
*) supout - fixed "poe-out" output not showing all interfaces;<br>
*) switch - added comment field to switch ACL rules;<br>
*) switch - fixed ACL rules on IPQ4018 devices;<br>
*) system - accept only valid path for "log-file" parameter in "port" menu;<br>
*) system - removed obsolete "/driver" command;<br>
*) tr069-client - added "check-certificate" parameter to allow communication without certificates;<br>
*) tr069-client - added "connection-request-port" parameter (CLI only);<br>
*) tr069-client - added support for InformParameter object;<br>
*) tr069-client - fixed certificate verification for certificates with IP address;<br>
*) tr069-client - fixed HTTP cookie getting duplicated with the same key;<br>
*) tr069-client - increased reported "rsrq" precision;<br>
*) traceroute - improved stability when sending large ping amounts;<br>
*) traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;<br>
*) tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with <abbr title="Domain Name System">DNS</abbr> as "remote-address";<br>
*) upgrade - made security package depend on <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> package;<br>
*) usb - improved power-reset error message when no bus specified on CCR1072-8G-1S+;<br>
*) usb - improved USB device powering on startup for hAP ac^2 devices; <br>
*) usb - increased default power-reset timeout to 5 seconds;<br>
*) userman - added first and last name fields for signup form;<br>
*) userman - show redirect location in error messages;<br>
*) user - require "write" permissions for LTE firmware update;<br>
*) vrrp - made "password" parameter sensitive;<br>
*) w60g - added "10s-average-rssi" parameter to align mode (CLI only);<br>
*) w60g - added align mode "/interface w60g align" (CLI only);<br>
*) w60g - fixed scan in bridge mode;<br>
*) w60g - improved PtMP performance;<br>
*) w60g - improved reconnection detection;<br>
*) w60g - improved "tx-packet-error-rate" reading;<br>
*) w60g - renamed disconnection message when license level did not allow more connected clients;<br>
*) w60g - renamed "frequency-list" to "scan-list";<br>
*) watchdog - allow specifying <abbr title="Domain Name System">DNS</abbr> name for "send-smtp-server" parameter;<br>
*) winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;<br>
*) winbox - added "allow-dual-stack-queue" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server" and "IPv6/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server" menus;<br>
*) winbox - added "challenge-password" field when signing certificate with SCEP;<br>
*) winbox - added "conflict-detection" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server" menu;<br>
*) winbox - added "conflict-detection" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> server" menu;<br>
*) winbox - added "coordinate-format" parameter in LTE interface settings;<br>
*) winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;<br>
*) winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;<br>
*) winbox - added src/dst address and in/out interface list columns to default firewall menu view;<br>
*) winbox - added support for dynamic devices in "IP/Kid Control/Devices" tab;<br>
*) winbox - allow setting "network-mode" to "auto" under LTE interface settings;<br>
*) winbox - allow specifying interface lists in "CAPsMAN/Access List" menu;<br>
*) winbox - fixed "IPv6/Firewall" "Connection limit" parameter not allowing complete IPv6 prefix lengths;<br>
*) winbox - fixed L2MTU parameter setting on "W60G" type interfaces;<br>
*) winbox - fixed "LCD" menu not shown on RB2011UiAS-2HnD;<br>
*) winbox - fixed missing w60g interface status values;<br>
*) winbox - moved "Too Long" statistics counter to Ethernet "Rx Stats" tab;<br>
*) winbox - renamed "Default AP Tx Rate" to "Default AP Tx Limit";<br>
*) winbox - renamed "Default Client Tx Rate" to "Default Client Tx Limit";<br>
*) winbox - show "R" flag under "IPv6/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server/Bindings" tab;<br>
*) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;<br>
*) winbox - show "W60G" wireless tab on wAP 60G AP;<br>
*) wireless - added new "installation" parameter to specify router's location;<br>
*) wireless - improved connection stability for new model Apple devices;<br>
*) wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);<br>
*) wireless - improved system stability for all ARM devices with wireless;<br>
*) wireless - improved system stability when scanning for other networks;<br>
*) wireless - removed G/N support for 2484MHz in "japan" regulatory domain;<br>
*) wireless - report last seen IP address in RADIUS accounting messages;<br>
*) wireless - show "installation" parameter when printing configuration;<br><br>Download the new '<b>RouterOS 6.44rc1</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/testing" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7343</guid><pubDate>Fri, 15 Feb 2019 13:48:09 +0000</pubDate></item><item><title>RouterOS 6.42.12 [Long-term]</title><link>https://www.mikrotik-bg.net/blogs/entry/7342-routeros-64212-long-term/</link><description><![CDATA[
<p></p>
<h3>6.42.12 changelog:</h3>*) ipsec - accept only valid path for "export-pub-key" parameter in "key" menu;<br>
*) quickset - fixed "country" parameter not properly setting regulatory domain configuration;<br>
*) smb - fixed possible buffer overflow;<br>
*) w60g - fixed disconnection issues in PtMP setups;<br>
*) winbox -  improvements in connection handling to router with open winbox service;<br>
*) wireless - improved antenna gain setting for devices with built in antennas; <br>
*) wireless - show indoor/outdoor frequency limitations under "/interface wireless info country-info" command;<br><br>Download the new '<b>RouterOS 6.42.12</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/long-term" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7342</guid><pubDate>Tue, 12 Feb 2019 09:46:00 +0000</pubDate></item><item><title>RouterOS 6.44beta75 [Testing]</title><link>https://www.mikrotik-bg.net/blogs/entry/7341-routeros-644beta75-testing/</link><description><![CDATA[
<p></p>
<h3>6.44beta75 changelog:</h3>Important note!!! Backup before upgrade!<br>
Due to major IPsec configuration changes in RouterOS v6.44beta39+ (see changelog below), it is advised to make a backup before upgrading. Regular downgrade will still be possible as long as no changes in IPsec peer menu are done.<br><br>
MAJOR CHANGES IN v6.44:<br>
----------------------<br>
!) cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);<br>
!) ipsec - added new "identity" menu with common peer distinguishers;<br>
!) ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;<br>
!) ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu;<br>
!) radius - initial implementation of RadSec (Radius communication over TLS);<br>
!) speedtest - added "/tool speed-test" for ping latency, jitter, loss and <abbr title="Transmission Control Protocol">TCP</abbr> and <abbr title="User Datagram Protocol">UDP</abbr> download, upload speed measurements (CLI only);<br>
!) telnet - do not allow to set "tracefile" parameter;<br>
!) upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";<br>
!) upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;<br>
----------------------<br><br>
Changes in this release:<br><br>
!) ipsec - added new "identity" menu with common peer distinguishers;<br>
*) bridge - fixed log message when hardware offloading is being enabled;<br>
*) bridge - fixed packet forwarding with enabled <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping and Option 82;<br>
*) bridge - fixed system's identity change when <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping is enabled (introduced in v6.44beta61);<br>
*) bridge - improved packet handling when hardware offloading is being disabled;<br>
*) certificate - show digest algorithm used in signature;<br>
*) chr - distribute NIC queue IRQ's evenly across all CPUs;<br>
*) chr - fixed IRQ balancing when using more than 32 CPUs;<br>
*) crs3xx - fixed packet forwarding through <abbr title="Small Form-factor Pluggable">SFP</abbr>+ ports when using 100Mbps link speed;<br>
*) crs3xx - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr>+ linking using 1.25G <abbr title="Small Form-factor Pluggable">SFP</abbr> modules (introduced in v6.44beta39);<br>
*) dhcpv6-server - fixed missing gateway for binding's network if RADIUS authentication was used;<br>
*) dhcpv6-server - show "client-address" parameter for bindings;<br>
*) ethernet - added "tx-rx-1024-max" counter to Ethernet stats;<br>
*) ethernet - fixed packet forwarding when <abbr title="Small Form-factor Pluggable">SFP</abbr> interface is disabled on hEX S;<br>
*) fetch - added option to specify multiple headers under "http-header-field", including content type;<br>
*) fetch - improved stability when using HTTP mode;<br>
*) fetch - removed "http-content-type" parameter;<br>
*) gps - increase precision for dd format;<br>
*) hotspot - added "https-redirect" under server profiles;<br>
*) ike2 - retry RSA signature validation with deduced digest from certificate;<br>
*) ipsec - require write policy for key generation;<br>
*) kidcontrol - use "/128" prefix-length for IPv6 addresses;<br>
*) lldp - fixed missing capabilities fields on some devices;<br>
*) lte - added multiple APN support for R11e-4G;<br>
*) lte - fixed passthrough <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> address forward when other address is acquired from operator;<br>
*) lte - improved SIM7600 initialization after reset;<br>
*) lte - query "cfun" on initialization;<br>
*) lte - require write policy for at-chat;<br>
*) lte - update firmware version information after R11e-LTE/R11e-4G firmware upgrade;<br>
*) ntp-client - fixed "dst-active" and "gmt-offset" being updated after synchronization with server;<br>
*) ppp - fixed dynamic route creation towards VPN server when "add-default-route" is used;<br>
*) quickset - fixed "country" parameter not properly setting regulatory domain configuration;<br>
*) rb4011 - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface full duplex and speed parameter behavior;<br>
*) rb4011 - improved <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface linking to 1Gbps;<br>
*) sfp - fixed possible reboot loop when inserting <abbr title="Small Form-factor Pluggable">SFP</abbr> modules in CRS328-4C-20S-4S+ (introduced in v6.44beta61);<br>
*) smb - fixed macOS clients not showing share contents;<br>
*) smb - fixed possible buffer overflow;<br>
*) smb - fixed Windows 10 clients not able to establish connection to share;<br>
*) snmp - fixed "rsrq" reported precision;<br>
*) snmp - report ifSpeed 0 for sub-layer interfaces;<br>
*) switch - added comment field to switch ACL rules;<br>
*) tr069-client - added "connection-request-port" parameter (CLI only);<br>
*) usb - improved USB device powering on startup for hAP ac^2 devices; <br>
*) usb - increased default power-reset timeout to 5 seconds;<br>
*) userman - added first and last name fields for signup form;<br>
*) w60g - fixed disconnection issues in PtMP setups;<br>
*) winbox -  improvements in connection handling to router with open winbox service;<br>
*) winbox - renamed "Default AP Tx Rate" to "Default AP Tx Limit";<br>
*) winbox - renamed "Default Client Tx Rate" to "Default Client Tx Limit";<br>
*) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;<br>
*) wireless - improved antenna gain setting for devices with built in antennas; <br>
*) wireless - improved connection stability for new model Apple devices;<br>
*) wireless - improved system stability when scanning for other networks;<br>
*) wireless - show "installation" parameter when printing configuration;<br><br>
Other changes since v6.43.8:<br><br>
*) bgp - properly update keepalive time after peer restart;<br>
*) bridge - added option to monitor fast-forward status;<br>
*) bridge - count routed FastPath packets between bridge ports under FastPath bridge statistics;<br>
*) bridge - disable fast-forward when using SlowPath features;<br>
*) bridge - fixed BOOTP packet forwarding when <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping is enabled;<br>
*) bridge - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Option 82 parsing when using <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping;<br>
*) bridge - fixed packet forwarding when changing MSTI <abbr title="Virtual Local Area Network">VLAN</abbr> mappings;<br>
*) bridge - fixed possible memory leak when using MSTP;<br>
*) bridge - improved packet processing when bridge port changes states;<br>
*) btest - added multithreading support for both <abbr title="User Datagram Protocol">UDP</abbr> and <abbr title="Transmission Control Protocol">TCP</abbr> tests;<br>
*) btest - added warning message when CPU load exceeds 90% (CLI only);<br>
*) capsman - always accept connections from loopback address;<br>
*) certificate - added support for multiple "Subject Alt. Names";<br>
*) certificate - enabled RC2 cipher to allow P12 certificate decryption;<br>
*) certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided;<br>
*) chr - assign interface names based on underlying PCI device order on KVM;<br>
*) chr - improved system stability when insufficient resources are allocated to the guest;<br>
*) cloud - added "ddns-update-interval" parameter;<br>
*) cloud - do not reuse old <abbr title="User Datagram Protocol">UDP</abbr> socket if routing changes are detected;<br>
*) cloud - ignore "force-update" command if DDNS is disabled;<br>
*) cloud - improved DDNS service disabling;<br>
*) cloud - made address updating faster when new public address detected;<br>
*) conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter);<br>
*) console - renamed IP protocol 41 to "ipv6-encap";<br>
*) console - updated copyright notice;<br>
*) crs317 - fixed packet forwarding when LACP is used with hw=no;<br>
*) crs317 - fixed TX not working on sfp-sfpplus9 interface (introduced in v6.40beta12);<br>
*) crs328 - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);<br>
*) crs3xx - fixed slow bootup, upgrade and <abbr title="Small Form-factor Pluggable">SFP</abbr> status read (introduced in v6.44beta20);<br>
*) crs3xx - improved fan control stability;<br>
*) crs3xx - improved stability when adding ACL rules on CRS326 and CRS328 devices (introduced in 6.44beta39);<br>
*) defconf - fixed configuration not generating properly on upgrade;<br>
*) defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;<br>
*) defconf - fixed IPv6 link-local address range in firewall rules;<br>
*) dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> servers to control dynamic lease/binding behaviour;<br>
*) dhcp - properly load <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> configuration if options are configured;<br>
*) dhcpv4-server - added "parent-queue" parameter (CLI only);<br>
*) dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;<br>
*) dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;<br>
*) dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client;<br>
*) dhcpv6-server - allow to add DHCPv6 server with pool that does not exist;<br>
*) dhcpv6-server - improved DHCPv6 server stability when using "print" command;<br>
*) discovery - detect proper slave interface on bounded interfaces;<br>
*) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;<br>
*) discovery - send master port in "interface-name" parameter;<br>
*) discovery - show neighbors on actual bridge port instead of bridge itself for LLDP;<br>
*) e-mail - added info log message when e-mail is sent successfully;<br>
*) ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;<br>
*) ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);<br>
*) ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;<br>
*) ethernet - improved per core ethernet traffic classificator on mmips devices;<br>
*) export - fixed "silent-boot" compact export;<br>
*) fetch - added "http-header-field" parameter;<br>
*) fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20);<br>
*) fetch - fixed "without-paging" option;<br>
*) gps - moved "coordinate-format" from "monitor" command to "set" parameter;<br>
*) health - improved fan control stability on CRS328-24P-4S+RM;<br>
*) ike1 - fixed "rsa-key" authentication (introduced in v6.44beta);<br>
*) ike2 - added option to specify certificate chain;<br>
*) ike2 - added peer identity validation for RSA auth (disabled after upgrade);<br>
*) ike2 - allow to match responder peer by "my-id=fqdn" field;<br>
*) ike2 - fixed local address lookup when initiating new connection;<br>
*) ike2 - improved subsequent phase 2 initialization when no childs exist;<br>
*) ike2 - properly handle certificates with empty "Subject";<br>
*) ike2 - send split networks over <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> (option 249) to Windows initiators if <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Inform is received;<br>
*) ike2 - show weak pre-shared-key warning;<br>
*) ipsec - accept only valid path for "export-pub-key" parameter in "key" menu;<br>
*) ipsec - added account log message when user is successfully authenticated;<br>
*) ipsec - added basic pre-shared-key strength checks;<br>
*) ipsec - added new "remote-id" peer matcher;<br>
*) ipsec - allow to specify single address instead of IP pool under "mode-config";<br>
*) ipsec - fixed active connection killing when changing peer configuration;<br>
*) ipsec - fixed all policies not getting installed after startup (introduced in v6.43.8);<br>
*) ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);<br>
*) ipsec - hide empty prefixes on "peer" menu;<br>
*) ipsec - improved invalid policy handling when a valid policy is uninstalled;<br>
*) ipsec - made dynamic "src-nat" rule more specific;<br>
*) ipsec - made peers autosort themselves based on reachability status;<br>
*) ipsec - moved "profile" menu outside "peer" menu;<br>
*) ipsec - properly detect AES-NI extension as hardware AEAD;<br>
*) ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;<br>
*) kidcontrol - added IPv6 support;<br>
*) kidcontrol - added "reset-counters" command for "device" menu (CLI only);<br>
*) kidcontrol - added statistics web interface for kids (http://router.<abbr title="Local Area Network">lan</abbr>/kid-control);<br>
*) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);<br>
*) kidcontrol - dynamically discover devices from <abbr title="Domain Name System">DNS</abbr> activity;<br>
*) kidcontrol - fixed validation checks for time intervals;<br>
*) kidcontrol - properly detect time zone changes;<br>
*) l2tp - fixed IPsec secret not being updated when "ipsec-secret" is changed under L2TP client configuration;<br>
*) lcd - made "pin" parameter sensitive;<br>
*) led - fixed default LED configuration for RBSXTsq-60ad;<br>
*) led - fixed default LED configuration for wAP 60G AP devices;<br>
*) led - fixed PWR-LINE AP Ethernet LED polarity ("/system routerboard upgrade" required);<br>
*) lte - added additional ID support for Novatel USB730L modem;<br>
*) lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);<br>
*) lte - added "ecno" field for "info" command;<br>
*) lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);<br>
*) lte - added initial support for multiple APN for R11e-4G (new modem firmware required);<br>
*) lte - added support for JioFi JMR1040 modem;<br>
*) lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> IP acquire in 3G mode for r11e-lte (introduced in v6.44beta54);<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> IP acquire (introduced in v6.43.7);<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> relay packet forwarding when in passthrough mode;<br>
*) lte - fixed IPv6 activation for R11e-LTE-US modems;<br>
*) lte - fixed Jaton/SQN modems preventing router from booting properly;<br>
*) lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;<br>
*) lte - fixed missing running (R) flag for Jaton LTE modems;<br>
*) lte - fixed reported "rsrq" precision (introduced in v6.43.8);<br>
*) lte - improved compatibility for Alt38xx modems;<br>
*) lte - improved SimCom 7100e support;<br>
*) netinstall - do not show kernel failure critical messages in the log after fresh install;<br>
*) port - improved "remote-serial" <abbr title="Transmission Control Protocol">TCP</abbr> performance in RAW mode;<br>
*) ppp - added "at-chat" command;<br>
*) profiler - classify kernel crypto processing as "encrypting";<br>
*) profile - removed obsolete "file-name" parameter;<br>
*) proxy - removed port list size limit;<br>
*) radius - implemented Proxy-State attribute handling in CoA and disconnect requests;<br>
*) rb3011 - implemented multiple engine IPsec hardware acceleration support;<br>
*) rbm33g - improved stability when used with some USB devices;<br>
*) romon - improved reliability when processing RoMON packets on CHR;<br>
*) routerboard - removed "<abbr title="Рутер борд">RB</abbr>" prefix from PWR-LINE AP devices;<br>
*) routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";<br>
*) sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;<br>
*) snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;<br>
*) snmp - changed fan speed value type to Gauge32;<br>
*) snmp - fixed w60g station table;<br>
*) snmp - removed "rx-sector" ("Wl60gRxSector") value;<br>
*) snmp - report bridge ifSpeed as "0";<br>
*) ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);<br>
*) ssh - added error log message when key exchange fails;<br>
*) ssh - close active <abbr title="Secure Shell">SSH</abbr> connections before IPsec connections on shutdown;<br>
*) ssh - fixed non-interactive shell not returning all output (introduced in v6.44);<br>
*) ssh - fixed public key format compatibility with RFC4716;<br>
*) ssh - fixed single command execution (introduced in v6.44beta9);<br>
*) supout - fixed "poe-out" output not showing all interfaces;<br>
*) switch - fixed ACL rules on IPQ4018 devices;<br>
*) system - accept only valid path for "log-file" parameter in "port" menu;<br>
*) system - removed obsolete "/driver" command;<br>
*) tr069-client - added "check-certificate" parameter to allow communication without certificates;<br>
*) tr069-client - added support for InformParameter object;<br>
*) tr069-client - fixed certificate verification for certificates with IP address;<br>
*) tr069-client - fixed HTTP cookie getting duplicated with the same key;<br>
*) tr069-client - increased reported "rsrq" precision;<br>
*) traceroute - improved stability when sending large ping amounts;<br>
*) traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;<br>
*) tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with <abbr title="Domain Name System">DNS</abbr> as "remote-address";<br>
*) upgrade - made security package depend on <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> package;<br>
*) usb - improved power-reset error message when no bus specified on CCR1072-8G-1S+;<br>
*) userman - show redirect location in error messages;<br>
*) user - require "write" permissions for LTE firmware update;<br>
*) vrrp - made "password" parameter sensitive;<br>
*) w60g - added "10s-average-rssi" parameter to align mode (CLI only);<br>
*) w60g - added align mode "/interface w60g align" (CLI only);<br>
*) w60g - fixed scan in bridge mode;<br>
*) w60g - improved PtMP performance;<br>
*) w60g - improved reconnection detection;<br>
*) w60g - improved "tx-packet-error-rate" reading;<br>
*) w60g - renamed disconnection message when license level did not allow more connected clients;<br>
*) w60g - renamed "frequency-list" to "scan-list";<br>
*) watchdog - allow specifying <abbr title="Domain Name System">DNS</abbr> name for "send-smtp-server" parameter;<br>
*) winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;<br>
*) winbox - added "allow-dual-stack-queue" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server" and "IPv6/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server" menus;<br>
*) winbox - added "challenge-password" field when signing certificate with SCEP;<br>
*) winbox - added "conflict-detection" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server" menu;<br>
*) winbox - added "conflict-detection" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> server" menu;<br>
*) winbox - added "coordinate-format" parameter in LTE interface settings;<br>
*) winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;<br>
*) winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;<br>
*) winbox - added src/dst address and in/out interface list columns to default firewall menu view;<br>
*) winbox - added support for dynamic devices in "IP/Kid Control/Devices" tab;<br>
*) winbox - allow setting "network-mode" to "auto" under LTE interface settings;<br>
*) winbox - allow specifying interface lists in "CAPsMAN/Access List" menu;<br>
*) winbox - fixed "IPv6/Firewall" "Connection limit" parameter not allowing complete IPv6 prefix lengths;<br>
*) winbox - fixed L2MTU parameter setting on "W60G" type interfaces;<br>
*) winbox - fixed "LCD" menu not shown on RB2011UiAS-2HnD;<br>
*) winbox - fixed missing w60g interface status values;<br>
*) winbox - moved "Too Long" statistics counter to Ethernet "Rx Stats" tab;<br>
*) winbox - show "R" flag under "IPv6/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server/Bindings" tab;<br>
*) winbox - show "W60G" wireless tab on wAP 60G AP;<br>
*) wireless - added new "installation" parameter to specify router's location;<br>
*) wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);<br>
*) wireless - improved system stability for all ARM devices with wireless;<br>
*) wireless - removed G/N support for 2484MHz in "japan" regulatory domain;<br>
*) wireless - report last seen IP address in RADIUS accounting messages;<br>
*) wireless - show indoor/outdoor frequency limitations under "/interface wireless info country-info " command;<br><br>Download the new '<b>RouterOS 6.44beta75</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/testing" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7341</guid><pubDate>Mon, 11 Feb 2019 13:26:42 +0000</pubDate></item><item><title>RouterOS 6.43.12 [Stable]</title><link>https://www.mikrotik-bg.net/blogs/entry/7340-routeros-64312-stable/</link><description><![CDATA[
<p></p>
<h3>6.43.12 changelog:</h3>*) winbox -  improvements in connection handling to router with open winbox service;<br><br>Download the new '<b>RouterOS 6.43.12</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/stable" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7340</guid><pubDate>Mon, 11 Feb 2019 12:39:14 +0000</pubDate></item><item><title>RouterOS 6.43.11 [Stable]</title><link>https://www.mikrotik-bg.net/blogs/entry/7339-routeros-64311-stable/</link><description><![CDATA[
<p></p>
<h3>6.43.11 changelog:</h3>*) ipsec - accept only valid path for "export-pub-key" parameter in "key" menu;<br>
*) quickset - fixed "country" parameter not properly setting regulatory domain configuration;<br>
*) smb - fixed possible buffer overflow;<br>
*) w60g - fixed disconnection issues in PtMP setups;<br>
*) wireless - improved antenna gain setting for devices with built in antennas;<br>
*) wireless - show indoor/outdoor frequency limitations under "/interface wireless info country-info" command;<br><br>Download the new '<b>RouterOS 6.43.11</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/stable" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7339</guid><pubDate>Tue, 05 Feb 2019 09:10:17 +0000</pubDate></item><item><title>RouterOS 6.43.10 [Stable]</title><link>https://www.mikrotik-bg.net/blogs/entry/7337-routeros-64310-stable/</link><description><![CDATA[
<p></p>
<h3>6.43.10 changelog:</h3>(factory only release)<br><br>Download the new '<b>RouterOS 6.43.10</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/stable" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7337</guid><pubDate>Tue, 05 Feb 2019 09:03:24 +0000</pubDate></item><item><title>RouterOS 6.43.9 [Stable]</title><link>https://www.mikrotik-bg.net/blogs/entry/7338-routeros-6439-stable/</link><description><![CDATA[
<p></p>
<h3>6.43.9 changelog:</h3>(factory only release)<br><br>Download the new '<b>RouterOS 6.43.9</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/stable" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7338</guid><pubDate>Tue, 05 Feb 2019 08:57:57 +0000</pubDate></item><item><title>RouterOS 6.44beta61 [Testing]</title><link>https://www.mikrotik-bg.net/blogs/entry/7336-routeros-644beta61-testing/</link><description><![CDATA[
<p></p>
<h3>6.44beta61 changelog:</h3>Important note!!! Backup before upgrade!<br>
Due to major IPsec configuration changes in RouterOS v6.44beta39+ (see changelog below), it is advised to make a backup before upgrading. Regular downgrade will still be possible as long as no changes in IPsec peer menu are done.<br><br>
MAJOR CHANGES IN v6.44:<br>
----------------------<br>
!) cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);<br>
!) ipsec - added new "identity" menu with common peer distinguishers;<br>
!) ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;<br>
!) ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu;<br>
!) radius - initial implementation of RadSec (Radius communication over TLS);<br>
!) speedtest - added "/tool speed-test" for ping latency, jitter, loss and <abbr title="Transmission Control Protocol">TCP</abbr> and <abbr title="User Datagram Protocol">UDP</abbr> download, upload speed measurements (CLI only);<br>
!) telnet - do not allow to set "tracefile" parameter;<br>
!) upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";<br>
!) upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;<br>
----------------------<br><br>
Changes in this release:<br><br>
!) ipsec - added new "identity" menu with common peer distinguishers;<br>
*) bridge - fixed BOOTP packet forwarding when <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping is enabled;<br>
*) certificate - added support for multiple "Subject Alt. Names";<br>
*) certificate - enabled RC2 cipher to allow P12 certificate decryption;<br>
*) chr - improved system stability when insufficient resources are allocated to the guest;<br>
*) console - updated copyright notice;<br>
*) crs3xx - fixed slow bootup, upgrade and <abbr title="Small Form-factor Pluggable">SFP</abbr> status read (introduced in v6.44beta20);<br>
*) gps - moved "coordinate-format" from "monitor" command to "set" parameter;<br>
*) ike1 - fixed "rsa-key" authentication (introduced in v6.44beta);<br>
*) ipsec - accept only valid path for "export-pub-key" parameter in "key" menu;<br>
*) ipsec - added new "remote-id" peer matcher;<br>
*) ipsec - fixed all policies not getting installed after startup (introduced in v6.43.8);<br>
*) ipsec - moved "profile" menu outside "peer" menu;<br>
*) lcd - made "pin" parameter sensitive;<br>
*) led - fixed default LED configuration for RBSXTsq-60ad;<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> IP acquire in 3G mode for r11e-lte (introduced in v6.44beta54);<br>
*) lte - fixed reported "rsrq" precision (introduced in v6.43.8);<br>
*) profile - removed obsolete "file-name" parameter;<br>
*) radius - implemented Proxy-State attribute handling in CoA and disconnect requests;<br>
*) rb4011 - improved <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface linking to 1Gbps;<br>
*) ssh - close active <abbr title="Secure Shell">SSH</abbr> connections before IPsec connections on shutdown;<br>
*) ssh - fixed public key format compatibility with RFC4716;<br>
*) supout - fixed "poe-out" output not showing all interfaces;<br>
*) system - accept only valid path for "log-file" parameter in "port" menu;<br>
*) system - removed obsolete "/driver" command;<br>
*) tr069-client - added "check-certificate" parameter to allow communication without certificates;<br>
*) tr069-client - added support for InformParameter object;<br>
*) tr069-client - fixed certificate verification for certificates with IP address;<br>
*) tr069-client - increased reported "rsrq" precision;<br>
*) vrrp - made "password" parameter sensitive;<br>
*) winbox - added "allow-dual-stack-queue" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server" and "IPv6/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server" menus;<br>
*) winbox - added "conflict-detection" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server" menu;<br>
*) winbox - added "coordinate-format" parameter in LTE interface settings;<br>
*) winbox - allow specifying interface lists in "CAPsMAN/Access List" menu;<br>
*) winbox - fixed "IPv6/Firewall" "Connection limit" parameter not allowing complete IPv6 prefix lengths;<br>
*) winbox - fixed L2MTU parameter setting on "W60G" type interfaces;<br>
*) winbox - fixed "LCD" menu not shown on RB2011UiAS-2HnD;<br>
*) winbox - moved "Too Long" statistics counter to Ethernet "Rx Stats" tab;<br>
*) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature;<br><br>
Other changes since v6.43.8:<br><br>
*) bgp - properly update keepalive time after peer restart;<br>
*) bridge - added option to monitor fast-forward status;<br>
*) bridge - count routed FastPath packets between bridge ports under FastPath bridge statistics;<br>
*) bridge - disable fast-forward when using SlowPath features;<br>
*) bridge - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Option 82 parsing when using <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping;<br>
*) bridge - fixed packet forwarding when changing MSTI <abbr title="Virtual Local Area Network">VLAN</abbr> mappings;<br>
*) bridge - fixed possible memory leak when using MSTP;<br>
*) bridge - improved packet processing when bridge port changes states;<br>
*) btest - added multithreading support for both <abbr title="User Datagram Protocol">UDP</abbr> and <abbr title="Transmission Control Protocol">TCP</abbr> tests;<br>
*) btest - added warning message when CPU load exceeds 90% (CLI only);<br>
*) capsman - always accept connections from loopback address;<br>
*) certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided;<br>
*) chr - assign interface names based on underlying PCI device order on KVM;<br>
*) cloud - added "ddns-update-interval" parameter;<br>
*) cloud - do not reuse old <abbr title="User Datagram Protocol">UDP</abbr> socket if routing changes are detected;<br>
*) cloud - ignore "force-update" command if DDNS is disabled;<br>
*) cloud - improved DDNS service disabling;<br>
*) cloud - made address updating faster when new public address detected;<br>
*) conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter);<br>
*) console - renamed IP protocol 41 to "ipv6-encap";<br>
*) crs317 - fixed packet forwarding when LACP is used with hw=no;<br>
*) crs317 - fixed TX not working on sfp-sfpplus9 interface (introduced in v6.40beta12);<br>
*) crs328 - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);<br>
*) crs3xx - improved fan control stability;<br>
*) crs3xx - improved stability when adding ACL rules on CRS326 and CRS328 devices (introduced in 6.44beta39);<br>
*) defconf - fixed configuration not generating properly on upgrade;<br>
*) defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;<br>
*) defconf - fixed IPv6 link-local address range in firewall rules;<br>
*) dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> servers to control dynamic lease/binding behaviour;<br>
*) dhcp - properly load <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> configuration if options are configured;<br>
*) dhcpv4-server - added "parent-queue" parameter (CLI only);<br>
*) dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;<br>
*) dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;<br>
*) dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client;<br>
*) dhcpv6-server - allow to add DHCPv6 server with pool that does not exist;<br>
*) dhcpv6-server - improved DHCPv6 server stability when using "print" command;<br>
*) discovery - detect proper slave interface on bounded interfaces;<br>
*) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;<br>
*) discovery - send master port in "interface-name" parameter;<br>
*) discovery - show neighbors on actual bridge port instead of bridge itself for LLDP;<br>
*) e-mail - added info log message when e-mail is sent successfully;<br>
*) ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;<br>
*) ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);<br>
*) ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;<br>
*) ethernet - improved per core ethernet traffic classificator on mmips devices;<br>
*) export - fixed "silent-boot" compact export;<br>
*) fetch - added "http-header-field" parameter;<br>
*) fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20);<br>
*) fetch - fixed "without-paging" option;<br>
*) health - improved fan control stability on CRS328-24P-4S+RM;<br>
*) ike2 - added option to specify certificate chain;<br>
*) ike2 - added peer identity validation for RSA auth (disabled after upgrade);<br>
*) ike2 - allow to match responder peer by "my-id=fqdn" field;<br>
*) ike2 - fixed local address lookup when initiating new connection;<br>
*) ike2 - improved subsequent phase 2 initialization when no childs exist;<br>
*) ike2 - properly handle certificates with empty "Subject";<br>
*) ike2 - send split networks over <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> (option 249) to Windows initiators if <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Inform is received;<br>
*) ike2 - show weak pre-shared-key warning;<br>
*) ipsec - added account log message when user is successfully authenticated;<br>
*) ipsec - added basic pre-shared-key strength checks;<br>
*) ipsec - allow to specify single address instead of IP pool under "mode-config";<br>
*) ipsec - fixed active connection killing when changing peer configuration;<br>
*) ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);<br>
*) ipsec - hide empty prefixes on "peer" menu;<br>
*) ipsec - improved invalid policy handling when a valid policy is uninstalled;<br>
*) ipsec - made dynamic "src-nat" rule more specific;<br>
*) ipsec - made peers autosort themselves based on reachability status;<br>
*) ipsec - properly detect AES-NI extension as hardware AEAD;<br>
*) ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;<br>
*) kidcontrol - added IPv6 support;<br>
*) kidcontrol - added "reset-counters" command for "device" menu (CLI only);<br>
*) kidcontrol - added statistics web interface for kids (http://router.<abbr title="Local Area Network">lan</abbr>/kid-control);<br>
*) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);<br>
*) kidcontrol - dynamically discover devices from <abbr title="Domain Name System">DNS</abbr> activity;<br>
*) kidcontrol - fixed validation checks for time intervals;<br>
*) kidcontrol - properly detect time zone changes;<br>
*) l2tp - fixed IPsec secret not being updated when "ipsec-secret" is changed under L2TP client configuration;<br>
*) led - fixed default LED configuration for wAP 60G AP devices;<br>
*) led - fixed PWR-LINE AP Ethernet LED polarity ("/system routerboard upgrade" required);<br>
*) lte - added additional ID support for Novatel USB730L modem;<br>
*) lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);<br>
*) lte - added "ecno" field for "info" command;<br>
*) lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);<br>
*) lte - added initial support for multiple APN for R11e-4G (new modem firmware required);<br>
*) lte - added support for JioFi JMR1040 modem;<br>
*) lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> IP acquire (introduced in v6.43.7);<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> relay packet forwarding when in passthrough mode;<br>
*) lte - fixed IPv6 activation for R11e-LTE-US modems;<br>
*) lte - fixed Jaton/SQN modems preventing router from booting properly;<br>
*) lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;<br>
*) lte - fixed missing running (R) flag for Jaton LTE modems;<br>
*) lte - improved compatibility for Alt38xx modems;<br>
*) lte - improved SimCom 7100e support;<br>
*) netinstall - do not show kernel failure critical messages in the log after fresh install;<br>
*) port - improved "remote-serial" <abbr title="Transmission Control Protocol">TCP</abbr> performance in RAW mode;<br>
*) ppp - added "at-chat" command;<br>
*) profiler - classify kernel crypto processing as "encrypting";<br>
*) proxy - removed port list size limit;<br>
*) rb3011 - implemented multiple engine IPsec hardware acceleration support;<br>
*) rbm33g - improved stability when used with some USB devices;<br>
*) romon - improved reliability when processing RoMON packets on CHR;<br>
*) routerboard - removed "<abbr title="Рутер борд">RB</abbr>" prefix from PWR-LINE AP devices;<br>
*) routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";<br>
*) sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;<br>
*) snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;<br>
*) snmp - changed fan speed value type to Gauge32;<br>
*) snmp - fixed "rsrq" reported precision;<br>
*) snmp - fixed w60g station table;<br>
*) snmp - removed "rx-sector" ("Wl60gRxSector") value;<br>
*) snmp - report bridge ifSpeed as "0";<br>
*) ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);<br>
*) ssh - added error log message when key exchange fails;<br>
*) ssh - fixed non-interactive shell not returning all output (introduced in v6.44);<br>
*) ssh - fixed single command execution (introduced in v6.44beta9);<br>
*) switch - fixed ACL rules on IPQ4018 devices;<br>
*) tr069-client - fixed HTTP cookie getting duplicated with the same key;<br>
*) traceroute - improved stability when sending large ping amounts;<br>
*) traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;<br>
*) tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with <abbr title="Domain Name System">DNS</abbr> as "remote-address";<br>
*) upgrade - made security package depend on <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> package;<br>
*) usb - improved power-reset error message when no bus specified on CCR1072-8G-1S+;<br>
*) userman - show redirect location in error messages;<br>
*) user - require "write" permissions for LTE firmware update;<br>
*) w60g - added "10s-average-rssi" parameter to align mode (CLI only);<br>
*) w60g - added align mode "/interface w60g align" (CLI only);<br>
*) w60g - fixed scan in bridge mode;<br>
*) w60g - improved PtMP performance;<br>
*) w60g - improved reconnection detection;<br>
*) w60g - improved "tx-packet-error-rate" reading;<br>
*) w60g - renamed disconnection message when license level did not allow more connected clients;<br>
*) w60g - renamed "frequency-list" to "scan-list";<br>
*) watchdog - allow specifying <abbr title="Domain Name System">DNS</abbr> name for "send-smtp-server" parameter;<br>
*) winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;<br>
*) winbox - added "challenge-password" field when signing certificate with SCEP;<br>
*) winbox - added "conflict-detection" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> server" menu;<br>
*) winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;<br>
*) winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;<br>
*) winbox - added src/dst address and in/out interface list columns to default firewall menu view;<br>
*) winbox - added support for dynamic devices in "IP/Kid Control/Devices" tab;<br>
*) winbox - allow setting "network-mode" to "auto" under LTE interface settings;<br>
*) winbox - fixed missing w60g interface status values;<br>
*) winbox - show "R" flag under "IPv6/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server/Bindings" tab;<br>
*) winbox - show "W60G" wireless tab on wAP 60G AP;<br>
*) wireless - added new "installation" parameter to specify router's location;<br>
*) wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);<br>
*) wireless - improved system stability for all ARM devices with wireless;<br>
*) wireless - removed G/N support for 2484MHz in "japan" regulatory domain;<br>
*) wireless - report last seen IP address in RADIUS accounting messages;<br>
*) wireless - show indoor/outdoor frequency limitations under "/interface wireless info country-info " command;<br><br>Download the new '<b>RouterOS 6.44beta61</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/testing" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7336</guid><pubDate>Fri, 18 Jan 2019 07:23:31 +0000</pubDate></item><item><title>RouterOS 6.42.11 [Long-term]</title><link>https://www.mikrotik-bg.net/blogs/entry/7316-routeros-64211-long-term/</link><description><![CDATA[
<p></p>
<h3>6.42.11 changelog:</h3>MAJOR CHANGES IN v6.42.11:<br>
----------------------<br>
!) telnet - do not allow to set "tracefile" parameter;<br>
---------------------- <br><br>
*) capsman - fixed "group-key-update" parameter not using correct units;<br>
*) certificate - properly flush old CRLs when changing store location;<br>
*) console - properly remove system note after configuration reset;<br>
*) dhcpv6-server - properly handle <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> requests that include prefix hint;<br>
*) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;<br>
*) discovery - fixed neighbor discovery for PPP interfaces;<br>
*) export - fixed "silent-boot" compact export;<br>
*) gps - added "coordinate-format" parameter;<br>
*) interface - improved system stability when including/excluding a list to itself;<br>
*) kidcontrol - do not allow users with "read" policy to pause and resume kids;<br>
*) led - fixed default LED configuration for RBMetalG-52SHPacn;<br>
*) log - properly handle long echo messages;<br>
*) lte - added support for more ZTE MF90 modems;<br>
*) lte - disallow setting LTE interface as passthrough target;<br>
*) package - use bundled package by default if standalone packages are installed as well;<br>
*) resource - fixed "total-memory" reporting on ARM devices;<br>
*) snmp - added "tx-ccq" ("mtxrWlStatTxCCQ") and "rx-ccq" ("mtxrWlStatRxCCQ") values;<br>
*) snmp - do not initialise interface traps on bootup if they are not enabled;<br>
*) switch - fixed MAC learning when disabling interfaces on devices with Atheros8327 and QCA8337 switch chips;<br>
*) system - fixed situation when all configuration was not properly loaded on bootup;<br>
*) timezone - fixed "Europe/Dublin" time zone;<br>
*) upgrade - automatically uninstall standalone package if already installed in bundle;<br>
*) webfig - do not show bogus VHT field in wireless interface advanced mode;<br>
*) winbox - allow to change VHT rates when 5ghz-n/ac band is used;<br>
*) winbox - renamed "Radius" to "RADIUS";<br>
*) winbox - show "Switch" menu on RB4011iGS+5HacQ2HnD and RB4011iGS+;<br>
*) wireless - added new "installation" parameter to specify router's location;<br>
*) wireless - improved stability for 802.11ac;<br>
*) wireless - improvements in wireless frequency selection;<br><br>Download the new '<b>RouterOS 6.42.11</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/long-term" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7316</guid><pubDate>Wed, 09 Jan 2019 11:07:06 +0000</pubDate></item><item><title>RouterOS 6.42.11 [Long-term]</title><link>https://www.mikrotik-bg.net/blogs/entry/7315-routeros-64211-long-term/</link><description><![CDATA[
<p></p>
<h3>6.42.11 changelog:</h3>MAJOR CHANGES IN v6.42.11:<br>
----------------------<br>
!) telnet - do not allow to set "tracefile" parameter;<br>
---------------------- <br><br>
*) capsman - fixed "group-key-update" parameter not using correct units;<br>
*) certificate - properly flush old CRLs when changing store location;<br>
*) console - properly remove system note after configuration reset;<br>
*) dhcpv6-server - properly handle <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> requests that include prefix hint;<br>
*) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;<br>
*) discovery - fixed neighbor discovery for PPP interfaces;<br>
*) export - fixed "silent-boot" compact export;<br>
*) gps - added "coordinate-format" parameter;<br>
*) interface - improved system stability when including/excluding a list to itself;<br>
*) kidcontrol - do not allow users with "read" policy to pause and resume kids;<br>
*) led - fixed default LED configuration for RBMetalG-52SHPacn;<br>
*) log - properly handle long echo messages;<br>
*) lte - added support for more ZTE MF90 modems;<br>
*) lte - disallow setting LTE interface as passthrough target;<br>
*) package - use bundled package by default if standalone packages are installed as well;<br>
*) resource - fixed "total-memory" reporting on ARM devices;<br>
*) snmp - added "tx-ccq" ("mtxrWlStatTxCCQ") and "rx-ccq" ("mtxrWlStatRxCCQ") values;<br>
*) snmp - do not initialise interface traps on bootup if they are not enabled;<br>
*) switch - fixed MAC learning when disabling interfaces on devices with Atheros8327 and QCA8337 switch chips;<br>
*) system - fixed situation when all configuration was not properly loaded on bootup;<br>
*) timezone - fixed "Europe/Dublin" time zone;<br>
*) upgrade - automatically uninstall standalone package if already installed in bundle;<br>
*) webfig - do not show bogus VHT field in wireless interface advanced mode;<br>
*) winbox - allow to change VHT rates when 5ghz-n/ac band is used;<br>
*) winbox - renamed "Radius" to "RADIUS";<br>
*) winbox - show "Switch" menu on RB4011iGS+5HacQ2HnD and RB4011iGS+;<br>
*) wireless - added new "installation" parameter to specify router's location;<br>
*) wireless - improved stability for 802.11ac;<br>
*) wireless - improvements in wireless frequency selection;<br><br>Download the new '<b>RouterOS 6.42.11</b>' version here: <a href="https://www.mikrotik.com/download" rel="external nofollow">https://www.mikrotik.com/download</a> <br><p><a href="https://www.mikrotik.com/download/changelogs/long-term" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7315</guid><pubDate>Wed, 09 Jan 2019 11:07:06 +0000</pubDate></item><item><title>RouterOS 6.44beta54 [Testing]</title><link>https://www.mikrotik-bg.net/blogs/entry/7317-routeros-644beta54-testing/</link><description><![CDATA[
<p></p>
<h3>6.44beta54 changelog:</h3>Important note!!! Backup before upgrade!<br>
Due to major IPsec configuration changes in RouterOS v6.44beta39+ (see changelog below), it is advised to make a backup before upgrading. Regular downgrade will still be possible as long as no changes in IPsec peer menu are done.<br><br>
MAJOR CHANGES IN v6.44:<br>
----------------------<br>
!) cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);<br>
!) ipsec - added new "identity" menu with common peer distinguishers;<br>
!) ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;<br>
!) ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu;<br>
!) radius - initial implementation of RadSec (Radius communication over TLS);<br>
!) speedtest - added "/tool speed-test" for ping latency, jitter, loss and <abbr title="Transmission Control Protocol">TCP</abbr> and <abbr title="User Datagram Protocol">UDP</abbr> download, upload speed measurements (CLI only);<br>
!) telnet - do not allow to set "tracefile" parameter;<br>
!) upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";<br>
!) upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;<br>
----------------------<br><br>
Changes in this release:<br><br>
*) bridge - count routed FastPath packets between bridge ports under FastPath bridge statistics;<br>
*) bridge - fixed BOOTP packet forwarding when <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping is enabled;<br>
*) crs317 - fixed packet forwarding when LACP is used with hw=no;<br>
*) dhcpv6-server - allow to add DHCPv6 server with pool that does not exist;<br>
*) ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;<br>
*) ipsec - added new "remote-id" peer matcher (CLI only);<br>
*) l2tp - fixed IPsec secret not being updated when "ipsec-secret" is changed under L2TP client configuration;<br>
*) led - fixed PWR-LINE AP Ethernet LED polarity ("/system routerboard upgrade" required);<br>
*) lte - added initial support for multiple APN for R11e-4G (new modem firmware required);<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> IP acquire (introduced in v6.43.7);<br>
*) netinstall - do not show kernel failure critical messages in the log after fresh install;<br>
*) routerboard - removed "<abbr title="Рутер борд">RB</abbr>" prefix from PWR-LINE AP devices;<br>
*) sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;<br>
*) snmp - fixed "rsrq" reported precision;<br>
*) usb - improved power-reset error message when no bus specified on CCR1072-8G-1S+;<br>
*) wireless - added new "installation" parameter to specify router's location;<br>
*) wireless - show indoor/outdoor frequency limitations under "/interface wireless info country-info " command;<br><br>
Other changes since v6.43.8:<br><br>
*) bgp - properly update keepalive time after peer restart;<br>
*) bridge - added option to monitor fast-forward status;<br>
*) bridge - disable fast-forward when using SlowPath features;<br>
*) bridge - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Option 82 parsing when using <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping;<br>
*) bridge - fixed packet forwarding when changing MSTI <abbr title="Virtual Local Area Network">VLAN</abbr> mappings;<br>
*) bridge - fixed possible memory leak when using MSTP;<br>
*) bridge - improved packet processing when bridge port changes states;<br>
*) btest - added multithreading support for both <abbr title="User Datagram Protocol">UDP</abbr> and <abbr title="Transmission Control Protocol">TCP</abbr> tests;<br>
*) btest - added warning message when CPU load exceeds 90% (CLI only);<br>
*) capsman - always accept connections from loopback address;<br>
*) certificate - added support for multiple "Subject Alt. Names";<br>
*) certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided;<br>
*) chr - assign interface names based on underlying PCI device order on KVM;<br>
*) cloud - added "ddns-update-interval" parameter;<br>
*) cloud - do not reuse old <abbr title="User Datagram Protocol">UDP</abbr> socket if routing changes are detected;<br>
*) cloud - ignore "force-update" command if DDNS is disabled;<br>
*) cloud - improved DDNS service disabling;<br>
*) cloud - made address updating faster when new public address detected;<br>
*) conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter);<br>
*) console - renamed IP protocol 41 to "ipv6-encap";<br>
*) crs317 - fixed TX not working on sfp-sfpplus9 interface (introduced in v6.40beta12);<br>
*) crs328 - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);<br>
*) crs3xx - improved fan control stability;<br>
*) crs3xx - improved stability when adding ACL rules on CRS326 and CRS328 devices (introduced in 6.44beta39);<br>
*) defconf - fixed configuration not generating properly on upgrade;<br>
*) defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;<br>
*) defconf - fixed IPv6 link-local address range in firewall rules;<br>
*) dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> servers to control dynamic lease/binding behaviour;<br>
*) dhcp - properly load <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> configuration if options are configured;<br>
*) dhcpv4-server - added "parent-queue" parameter (CLI only);<br>
*) dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;<br>
*) dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;<br>
*) dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client;<br>
*) dhcpv6-server - improved DHCPv6 server stability when using "print" command;<br>
*) discovery - detect proper slave interface on bounded interfaces;<br>
*) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;<br>
*) discovery - send master port in "interface-name" parameter;<br>
*) discovery - show neighbors on actual bridge port instead of bridge itself for LLDP;<br>
*) e-mail - added info log message when e-mail is sent successfully;<br>
*) ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;<br>
*) ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);<br>
*) ethernet - improved per core ethernet traffic classificator on mmips devices;<br>
*) export - fixed "silent-boot" compact export;<br>
*) fetch - added "http-header-field" parameter;<br>
*) fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20);<br>
*) fetch - fixed "without-paging" option;<br>
*) health - improved fan control stability on CRS328-24P-4S+RM;<br>
*) ike2 - added option to specify certificate chain;<br>
*) ike2 - added peer identity validation for RSA auth (disabled after upgrade);<br>
*) ike2 - allow to match responder peer by "my-id=fqdn" field;<br>
*) ike2 - fixed local address lookup when initiating new connection;<br>
*) ike2 - improved subsequent phase 2 initialization when no childs exist;<br>
*) ike2 - properly handle certificates with empty "Subject";<br>
*) ike2 - send split networks over <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> (option 249) to Windows initiators if <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Inform is received;<br>
*) ike2 - show weak pre-shared-key warning;<br>
*) ipsec - added account log message when user is successfully authenticated;<br>
*) ipsec - added basic pre-shared-key strength checks;<br>
*) ipsec - allow to specify single address instead of IP pool under "mode-config";<br>
*) ipsec - fixed active connection killing when changing peer configuration;<br>
*) ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);<br>
*) ipsec - hide empty prefixes on "peer" menu;<br>
*) ipsec - improved invalid policy handling when a valid policy is uninstalled;<br>
*) ipsec - made dynamic "src-nat" rule more specific;<br>
*) ipsec - made peers autosort themselves based on reachability status;<br>
*) ipsec - moved "profile" menu outside "peer" menu (CLI only);<br>
*) ipsec - properly detect AES-NI extension as hardware AEAD;<br>
*) ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;<br>
*) kidcontrol - added IPv6 support;<br>
*) kidcontrol - added "reset-counters" command for "device" menu (CLI only);<br>
*) kidcontrol - added statistics web interface for kids (http://router.<abbr title="Local Area Network">lan</abbr>/kid-control);<br>
*) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);<br>
*) kidcontrol - dynamically discover devices from <abbr title="Domain Name System">DNS</abbr> activity;<br>
*) kidcontrol - fixed validation checks for time intervals;<br>
*) kidcontrol - properly detect time zone changes;<br>
*) led - fixed default LED configuration for wAP 60G AP devices;<br>
*) lte - added additional ID support for Novatel USB730L modem;<br>
*) lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);<br>
*) lte - added "ecno" field for "info" command;<br>
*) lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);<br>
*) lte - added support for JioFi JMR1040 modem;<br>
*) lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> relay packet forwarding when in passthrough mode;<br>
*) lte - fixed IPv6 activation for R11e-LTE-US modems;<br>
*) lte - fixed Jaton/SQN modems preventing router from booting properly;<br>
*) lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;<br>
*) lte - fixed missing running (R) flag for Jaton LTE modems;<br>
*) lte - improved compatibility for Alt38xx modems;<br>
*) lte - improved SimCom 7100e support;<br>
*) port - improved "remote-serial" <abbr title="Transmission Control Protocol">TCP</abbr> performance in RAW mode;<br>
*) ppp - added "at-chat" command;<br>
*) profiler - classify kernel crypto processing as "encrypting";<br>
*) proxy - removed port list size limit;<br>
*) rb3011 - implemented multiple engine IPsec hardware acceleration support;<br>
*) rbm33g - improved stability when used with some USB devices;<br>
*) romon - improved reliability when processing RoMON packets on CHR;<br>
*) routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";<br>
*) snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;<br>
*) snmp - changed fan speed value type to Gauge32;<br>
*) snmp - fixed w60g station table;<br>
*) snmp - removed "rx-sector" ("Wl60gRxSector") value;<br>
*) snmp - report bridge ifSpeed as "0";<br>
*) ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);<br>
*) ssh - added error log message when key exchange fails;<br>
*) ssh - fixed non-interactive shell not returning all output (introduced in v6.44);<br>
*) ssh - fixed public key format compatibility with RFC4716;<br>
*) ssh - fixed single command execution (introduced in v6.44beta9);<br>
*) switch - fixed ACL rules on IPQ4018 devices;<br>
*) tr069-client - fixed HTTP cookie getting duplicated with the same key;<br>
*) traceroute - improved stability when sending large ping amounts;<br>
*) traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;<br>
*) tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with <abbr title="Domain Name System">DNS</abbr> as "remote-address";<br>
*) upgrade - made security package depend on <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> package;<br>
*) userman - show redirect location in error messages;<br>
*) user - require "write" permissions for LTE firmware update;<br>
*) w60g - added "10s-average-rssi" parameter to align mode (CLI only);<br>
*) w60g - added align mode "/interface w60g align" (CLI only);<br>
*) w60g - fixed scan in bridge mode;<br>
*) w60g - improved PtMP performance;<br>
*) w60g - improved reconnection detection;<br>
*) w60g - improved "tx-packet-error-rate" reading;<br>
*) w60g - renamed disconnection message when license level did not allow more connected clients;<br>
*) w60g - renamed "frequency-list" to "scan-list";<br>
*) watchdog - allow specifying <abbr title="Domain Name System">DNS</abbr> name for "send-smtp-server" parameter;<br>
*) winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;<br>
*) winbox - added "challenge-password" field when signing certificate with SCEP;<br>
*) winbox - added "conflict-detection" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> server" menu;<br>
*) winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;<br>
*) winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;<br>
*) winbox - added src/dst address and in/out interface list columns to default firewall menu view;<br>
*) winbox - added support for dynamic devices in "IP/Kid Control/Devices" tab;<br>
*) winbox - allow setting "network-mode" to "auto" under LTE interface settings;<br>
*) winbox - fixed missing w60g interface status values;<br>
*) winbox - show "R" flag under "IPv6/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server/Bindings" tab;<br>
*) winbox - show "W60G" wireless tab on wAP 60G AP;<br>
*) wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);<br>
*) wireless - improved system stability for all ARM devices with wireless;<br>
*) wireless - removed G/N support for 2484MHz in "japan" regulatory domain;<br>
*) wireless - report last seen IP address in RADIUS accounting messages;<br><br>Download the new '<b>RouterOS 6.44beta54</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/testing" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7317</guid><pubDate>Mon, 07 Jan 2019 11:55:05 +0000</pubDate></item><item><title>RouterOS 6.44beta54 [Testing]</title><link>https://www.mikrotik-bg.net/blogs/entry/7314-routeros-644beta54-testing/</link><description><![CDATA[
<p></p>
<h3>6.44beta54 changelog:</h3>Important note!!! Backup before upgrade!<br>
Due to major IPsec configuration changes in RouterOS v6.44beta39+ (see changelog below), it is advised to make a backup before upgrading. Regular downgrade will still be possible as long as no changes in IPsec peer menu are done.<br><br>
MAJOR CHANGES IN v6.44:<br>
----------------------<br>
!) cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);<br>
!) ipsec - added new "identity" menu with common peer distinguishers;<br>
!) ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;<br>
!) ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu;<br>
!) radius - initial implementation of RadSec (Radius communication over TLS);<br>
!) speedtest - added "/tool speed-test" for ping latency, jitter, loss and <abbr title="Transmission Control Protocol">TCP</abbr> and <abbr title="User Datagram Protocol">UDP</abbr> download, upload speed measurements (CLI only);<br>
!) telnet - do not allow to set "tracefile" parameter;<br>
!) upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";<br>
!) upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;<br>
----------------------<br><br>
Changes in this release:<br><br>
*) bridge - count routed FastPath packets between bridge ports under FastPath bridge statistics;<br>
*) bridge - fixed BOOTP packet forwarding when <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping is enabled;<br>
*) crs317 - fixed packet forwarding when LACP is used with hw=no;<br>
*) dhcpv6-server - allow to add DHCPv6 server with pool that does not exist;<br>
*) ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;<br>
*) ipsec - added new "remote-id" peer matcher (CLI only);<br>
*) l2tp - fixed IPsec secret not being updated when "ipsec-secret" is changed under L2TP client configuration;<br>
*) led - fixed PWR-LINE AP Ethernet LED polarity ("/system routerboard upgrade" required);<br>
*) lte - added initial support for multiple APN for R11e-4G (new modem firmware required);<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> IP acquire (introduced in v6.43.7);<br>
*) netinstall - do not show kernel failure critical messages in the log after fresh install;<br>
*) routerboard - removed "<abbr title="Рутер борд">RB</abbr>" prefix from PWR-LINE AP devices;<br>
*) sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;<br>
*) snmp - fixed "rsrq" reported precision;<br>
*) usb - improved power-reset error message when no bus specified on CCR1072-8G-1S+;<br>
*) wireless - added new "installation" parameter to specify router's location;<br>
*) wireless - show indoor/outdoor frequency limitations under "/interface wireless info country-info " command;<br><br>
Other changes since v6.43.8:<br><br>
*) bgp - properly update keepalive time after peer restart;<br>
*) bridge - added option to monitor fast-forward status;<br>
*) bridge - disable fast-forward when using SlowPath features;<br>
*) bridge - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Option 82 parsing when using <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping;<br>
*) bridge - fixed packet forwarding when changing MSTI <abbr title="Virtual Local Area Network">VLAN</abbr> mappings;<br>
*) bridge - fixed possible memory leak when using MSTP;<br>
*) bridge - improved packet processing when bridge port changes states;<br>
*) btest - added multithreading support for both <abbr title="User Datagram Protocol">UDP</abbr> and <abbr title="Transmission Control Protocol">TCP</abbr> tests;<br>
*) btest - added warning message when CPU load exceeds 90% (CLI only);<br>
*) capsman - always accept connections from loopback address;<br>
*) certificate - added support for multiple "Subject Alt. Names";<br>
*) certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided;<br>
*) chr - assign interface names based on underlying PCI device order on KVM;<br>
*) cloud - added "ddns-update-interval" parameter;<br>
*) cloud - do not reuse old <abbr title="User Datagram Protocol">UDP</abbr> socket if routing changes are detected;<br>
*) cloud - ignore "force-update" command if DDNS is disabled;<br>
*) cloud - improved DDNS service disabling;<br>
*) cloud - made address updating faster when new public address detected;<br>
*) conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter);<br>
*) console - renamed IP protocol 41 to "ipv6-encap";<br>
*) crs317 - fixed TX not working on sfp-sfpplus9 interface (introduced in v6.40beta12);<br>
*) crs328 - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);<br>
*) crs3xx - improved fan control stability;<br>
*) crs3xx - improved stability when adding ACL rules on CRS326 and CRS328 devices (introduced in 6.44beta39);<br>
*) defconf - fixed configuration not generating properly on upgrade;<br>
*) defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;<br>
*) defconf - fixed IPv6 link-local address range in firewall rules;<br>
*) dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> servers to control dynamic lease/binding behaviour;<br>
*) dhcp - properly load <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> configuration if options are configured;<br>
*) dhcpv4-server - added "parent-queue" parameter (CLI only);<br>
*) dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;<br>
*) dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;<br>
*) dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client;<br>
*) dhcpv6-server - improved DHCPv6 server stability when using "print" command;<br>
*) discovery - detect proper slave interface on bounded interfaces;<br>
*) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;<br>
*) discovery - send master port in "interface-name" parameter;<br>
*) discovery - show neighbors on actual bridge port instead of bridge itself for LLDP;<br>
*) e-mail - added info log message when e-mail is sent successfully;<br>
*) ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;<br>
*) ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);<br>
*) ethernet - improved per core ethernet traffic classificator on mmips devices;<br>
*) export - fixed "silent-boot" compact export;<br>
*) fetch - added "http-header-field" parameter;<br>
*) fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20);<br>
*) fetch - fixed "without-paging" option;<br>
*) health - improved fan control stability on CRS328-24P-4S+RM;<br>
*) ike2 - added option to specify certificate chain;<br>
*) ike2 - added peer identity validation for RSA auth (disabled after upgrade);<br>
*) ike2 - allow to match responder peer by "my-id=fqdn" field;<br>
*) ike2 - fixed local address lookup when initiating new connection;<br>
*) ike2 - improved subsequent phase 2 initialization when no childs exist;<br>
*) ike2 - properly handle certificates with empty "Subject";<br>
*) ike2 - send split networks over <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> (option 249) to Windows initiators if <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Inform is received;<br>
*) ike2 - show weak pre-shared-key warning;<br>
*) ipsec - added account log message when user is successfully authenticated;<br>
*) ipsec - added basic pre-shared-key strength checks;<br>
*) ipsec - allow to specify single address instead of IP pool under "mode-config";<br>
*) ipsec - fixed active connection killing when changing peer configuration;<br>
*) ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);<br>
*) ipsec - hide empty prefixes on "peer" menu;<br>
*) ipsec - improved invalid policy handling when a valid policy is uninstalled;<br>
*) ipsec - made dynamic "src-nat" rule more specific;<br>
*) ipsec - made peers autosort themselves based on reachability status;<br>
*) ipsec - moved "profile" menu outside "peer" menu (CLI only);<br>
*) ipsec - properly detect AES-NI extension as hardware AEAD;<br>
*) ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;<br>
*) kidcontrol - added IPv6 support;<br>
*) kidcontrol - added "reset-counters" command for "device" menu (CLI only);<br>
*) kidcontrol - added statistics web interface for kids (http://router.<abbr title="Local Area Network">lan</abbr>/kid-control);<br>
*) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);<br>
*) kidcontrol - dynamically discover devices from <abbr title="Domain Name System">DNS</abbr> activity;<br>
*) kidcontrol - fixed validation checks for time intervals;<br>
*) kidcontrol - properly detect time zone changes;<br>
*) led - fixed default LED configuration for wAP 60G AP devices;<br>
*) lte - added additional ID support for Novatel USB730L modem;<br>
*) lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);<br>
*) lte - added "ecno" field for "info" command;<br>
*) lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);<br>
*) lte - added support for JioFi JMR1040 modem;<br>
*) lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> relay packet forwarding when in passthrough mode;<br>
*) lte - fixed IPv6 activation for R11e-LTE-US modems;<br>
*) lte - fixed Jaton/SQN modems preventing router from booting properly;<br>
*) lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;<br>
*) lte - fixed missing running (R) flag for Jaton LTE modems;<br>
*) lte - improved compatibility for Alt38xx modems;<br>
*) lte - improved SimCom 7100e support;<br>
*) port - improved "remote-serial" <abbr title="Transmission Control Protocol">TCP</abbr> performance in RAW mode;<br>
*) ppp - added "at-chat" command;<br>
*) profiler - classify kernel crypto processing as "encrypting";<br>
*) proxy - removed port list size limit;<br>
*) rb3011 - implemented multiple engine IPsec hardware acceleration support;<br>
*) rbm33g - improved stability when used with some USB devices;<br>
*) romon - improved reliability when processing RoMON packets on CHR;<br>
*) routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";<br>
*) snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;<br>
*) snmp - changed fan speed value type to Gauge32;<br>
*) snmp - fixed w60g station table;<br>
*) snmp - removed "rx-sector" ("Wl60gRxSector") value;<br>
*) snmp - report bridge ifSpeed as "0";<br>
*) ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);<br>
*) ssh - added error log message when key exchange fails;<br>
*) ssh - fixed non-interactive shell not returning all output (introduced in v6.44);<br>
*) ssh - fixed public key format compatibility with RFC4716;<br>
*) ssh - fixed single command execution (introduced in v6.44beta9);<br>
*) switch - fixed ACL rules on IPQ4018 devices;<br>
*) tr069-client - fixed HTTP cookie getting duplicated with the same key;<br>
*) traceroute - improved stability when sending large ping amounts;<br>
*) traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;<br>
*) tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with <abbr title="Domain Name System">DNS</abbr> as "remote-address";<br>
*) upgrade - made security package depend on <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> package;<br>
*) userman - show redirect location in error messages;<br>
*) user - require "write" permissions for LTE firmware update;<br>
*) w60g - added "10s-average-rssi" parameter to align mode (CLI only);<br>
*) w60g - added align mode "/interface w60g align" (CLI only);<br>
*) w60g - fixed scan in bridge mode;<br>
*) w60g - improved PtMP performance;<br>
*) w60g - improved reconnection detection;<br>
*) w60g - improved "tx-packet-error-rate" reading;<br>
*) w60g - renamed disconnection message when license level did not allow more connected clients;<br>
*) w60g - renamed "frequency-list" to "scan-list";<br>
*) watchdog - allow specifying <abbr title="Domain Name System">DNS</abbr> name for "send-smtp-server" parameter;<br>
*) winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;<br>
*) winbox - added "challenge-password" field when signing certificate with SCEP;<br>
*) winbox - added "conflict-detection" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> server" menu;<br>
*) winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;<br>
*) winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;<br>
*) winbox - added src/dst address and in/out interface list columns to default firewall menu view;<br>
*) winbox - added support for dynamic devices in "IP/Kid Control/Devices" tab;<br>
*) winbox - allow setting "network-mode" to "auto" under LTE interface settings;<br>
*) winbox - fixed missing w60g interface status values;<br>
*) winbox - show "R" flag under "IPv6/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server/Bindings" tab;<br>
*) winbox - show "W60G" wireless tab on wAP 60G AP;<br>
*) wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);<br>
*) wireless - improved system stability for all ARM devices with wireless;<br>
*) wireless - removed G/N support for 2484MHz in "japan" regulatory domain;<br>
*) wireless - report last seen IP address in RADIUS accounting messages;<br><br>Download the new '<b>RouterOS 6.44beta54</b>' version here: <a href="https://www.mikrotik.com/download" rel="external nofollow">https://www.mikrotik.com/download</a> <br><p><a href="https://www.mikrotik.com/download/changelogs/testing" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7314</guid><pubDate>Mon, 07 Jan 2019 11:55:05 +0000</pubDate></item><item><title>RouterOS 6.43.8 [Stable]</title><link>https://www.mikrotik-bg.net/blogs/entry/7318-routeros-6438-stable/</link><description><![CDATA[
<p></p>
<h3>6.43.8 changelog:</h3>MAJOR CHANGES IN v6.43.8:<br>
----------------------<br>
!) telnet - do not allow to set "tracefile" parameter;<br>
----------------------<br><br>
Changes in this release: <br><br>
*) bridge - fixed IPv6 link-local address generation when auto-mac=yes;<br>
*) capsman - fixed "group-key-update" parameter not using correct units;<br>
*) crs3xx - improved data transmission between 10G and 1G ports;<br>
*) console - properly remove system note after configuration reset;<br>
*) dhcpv4-server - fixed dynamic lease reuse after expiration;<br>
*) dhcpv6-server - properly handle <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> requests that include prefix hint;<br>
*) ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;<br>
*) gps - added "coordinate-format" parameter;<br>
*) led - fixed default LED configuration for RBMetalG-52SHPacn;<br>
*) led - fixed PWR-LINE AP ethernet led polarity ("/system routerboard upgrade" required);<br>
*) lte - disallow setting LTE interface as passthrough target;<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> IP acquire (introduced in v6.43.7);<br>
*) lte - fixed passthrough functionality when interface is removed;<br>
*) lte - increased reported "rsrq" precision;<br>
*) lte - reset USB when non-default slot is used;<br>
*) package - use bundled package by default if standalone packages are installed as well;<br>
*) resource - fixed "total-memory" reporting on ARM devices;<br>
*) snmp - added "tx-ccq" ("mtxrWlStatTxCCQ") and "rx-ccq" ("mtxrWlStatRxCCQ") values;<br>
*) switch - fixed MAC learning when disabling interfaces on devices with Atheros8327 and QCA8337 switch chips;<br>
*) system - fixed situation when all configuration was not properly loaded on bootup;<br>
*) timezone - fixed "Europe/Dublin" time zone;<br>
*) upgrade - automatically uninstall standalone package if already installed in bundle;<br>
*) webfig - do not show bogus VHT field in wireless interface advanced mode;<br>
*) winbox - added "allow-roaming" parameter in "Interface/LTE" menu;<br>
*) winbox - allow to change VHT rates when 5ghz-n/ac band is used;<br>
*) winbox - renamed "Radius" to "RADIUS";<br>
*) winbox - show "Switch" menu on RB4011iGS+5HacQ2HnD and RB4011iGS+;<br>
*) wireless - added new "installation" parameter to specify router's location;<br>
*) wireless - improved stability for 802.11ac;<br>
*) wireless - improvements in wireless frequency selection;<br><br>Download the new '<b>RouterOS 6.43.8</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/stable" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7318</guid><pubDate>Fri, 21 Dec 2018 08:43:56 +0000</pubDate></item><item><title>RouterOS 6.43.8 [Stable]</title><link>https://www.mikrotik-bg.net/blogs/entry/7308-routeros-6438-stable/</link><description><![CDATA[
<p></p>
<h3>6.43.8 changelog:</h3>MAJOR CHANGES IN v6.43.8:<br>
----------------------<br>
!) telnet - do not allow to set "tracefile" parameter;<br>
----------------------<br><br>
Changes in this release: <br><br>
*) bridge - fixed IPv6 link-local address generation when auto-mac=yes;<br>
*) capsman - fixed "group-key-update" parameter not using correct units;<br>
*) crs3xx - improved data transmission between 10G and 1G ports;<br>
*) console - properly remove system note after configuration reset;<br>
*) dhcpv4-server - fixed dynamic lease reuse after expiration;<br>
*) dhcpv6-server - properly handle <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> requests that include prefix hint;<br>
*) ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;<br>
*) gps - added "coordinate-format" parameter;<br>
*) led - fixed default LED configuration for RBMetalG-52SHPacn;<br>
*) led - fixed PWR-LINE AP ethernet led polarity ("/system routerboard upgrade" required);<br>
*) lte - disallow setting LTE interface as passthrough target;<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> IP acquire (introduced in v6.43.7);<br>
*) lte - fixed passthrough functionality when interface is removed;<br>
*) lte - increased reported "rsrq" precision;<br>
*) lte - reset USB when non-default slot is used;<br>
*) package - use bundled package by default if standalone packages are installed as well;<br>
*) resource - fixed "total-memory" reporting on ARM devices;<br>
*) snmp - added "tx-ccq" ("mtxrWlStatTxCCQ") and "rx-ccq" ("mtxrWlStatRxCCQ") values;<br>
*) switch - fixed MAC learning when disabling interfaces on devices with Atheros8327 and QCA8337 switch chips;<br>
*) system - fixed situation when all configuration was not properly loaded on bootup;<br>
*) timezone - fixed "Europe/Dublin" time zone;<br>
*) upgrade - automatically uninstall standalone package if already installed in bundle;<br>
*) webfig - do not show bogus VHT field in wireless interface advanced mode;<br>
*) winbox - added "allow-roaming" parameter in "Interface/LTE" menu;<br>
*) winbox - allow to change VHT rates when 5ghz-n/ac band is used;<br>
*) winbox - renamed "Radius" to "RADIUS";<br>
*) winbox - show "Switch" menu on RB4011iGS+5HacQ2HnD and RB4011iGS+;<br>
*) wireless - added new "installation" parameter to specify router's location;<br>
*) wireless - improved stability for 802.11ac;<br>
*) wireless - improvements in wireless frequency selection;<br><br>Download the new '<b>RouterOS 6.43.8</b>' version here: <a href="https://www.mikrotik.com/download" rel="external nofollow">https://www.mikrotik.com/download</a> <br><p><a href="https://www.mikrotik.com/download/changelogs/stable" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7308</guid><pubDate>Fri, 21 Dec 2018 08:43:56 +0000</pubDate></item><item><title>RouterOS 6.44beta50 [Testing]</title><link>https://www.mikrotik-bg.net/blogs/entry/7319-routeros-644beta50-testing/</link><description><![CDATA[
<p></p>
<h3>6.44beta50 changelog:</h3>Important note!!! Backup before upgrade!<br>
Due to major IPsec configuration changes in RouterOS v6.44beta39+ (see changelog below), it is advised to make a backup before upgrading. Regular downgrade will still be possible as long as no changes in IPsec peer menu are done.<br><br>
MAJOR CHANGES IN v6.44:<br>
----------------------<br>
!) cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);<br>
!) radius - initial implementation of RadSec (Radius communication over TLS);<br>
!) upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";<br>
!) upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;<br>
!) speedtest - added "/tool speed-test" for ping latency, jitter, loss and <abbr title="Transmission Control Protocol">TCP</abbr> and <abbr title="User Datagram Protocol">UDP</abbr> download, upload speed measurements (CLI only);<br>
!) ipsec - added new "identity" menu with common peer distinguishers;<br>
!) ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;<br>
!) ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu;<br>
----------------------<br><br>
Changes in this release:<br><br>
!) ipsec - added new "identity" menu with common peer distinguishers;<br>
!) speedtest - added "/tool speed-test" for ping latency, jitter, loss and <abbr title="Transmission Control Protocol">TCP</abbr> and <abbr title="User Datagram Protocol">UDP</abbr> download, upload speed measurements (CLI only);<br>
!) telnet - do not allow to set "tracefile" parameter;<br>
*) bgp - properly update keepalive time after peer restart;<br>
*) bridge - fixed BOOTP packet forwarding when <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping is enabled;<br>
*) bridge - fixed IPv6 link-local address generation when auto-mac=yes;<br>
*) capsman - always accept connections from loopback address;<br>
*) certificate - added support for multiple "Subject Alt. Names";<br>
*) cloud - added "ddns-update-interval" parameter;<br>
*) conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter);<br>
*) console - properly remove system note after configuration reset;<br>
*) crs3xx - improved fan control stability;<br>
*) crs3xx - improved stability when adding ACL rules on CRS326 and CRS328 devices (introduced in 6.44beta39);<br>
*) defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;<br>
*) defconf - fixed IPv6 link-local address range in firewall rules;<br>
*) dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> servers to control dynamic lease/binding behaviour;<br>
*) dhcpv4-server - added "parent-queue" parameter (CLI only);<br>
*) dhcpv6-server - properly handle <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> requests that include prefix hint;<br>
*) discovery - detect proper slave interface on bounded interfaces;<br>
*) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;<br>
*) discovery - send master port in "interface-name" parameter;<br>
*) discovery - show neighbors on actual bridge port instead of bridge itself for LLDP;<br>
*) ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;<br>
*) export - fixed "silent-boot" compact export;<br>
*) fetch - added "http-header-field" parameter;<br>
*) gps - added "coordinate-format" parameter (CLI only);<br>
*) ike2 - allow to match responder peer by "my-id=fqdn" field;<br>
*) ipsec - improved invalid policy handling when a valid policy is uninstalled;<br>
*) kidcontrol - added IPv6 support;<br>
*) kidcontrol - added statistics web interface for kids (http://router.<abbr title="Local Area Network">lan</abbr>/kid-control);<br>
*) led - fixed default LED configuration for RBMetalG-52SHPacn;<br>
*) lte - added "ecno" field for "info" command;<br>
*) lte - disallow setting LTE interface as passthrough target;<br>
*) lte - fixed passthrough functionality when interface is removed;<br>
*) lte - improved SimCom 7100e support;<br>
*) lte - increased reported "rsrq" precision;<br>
*) lte - reset USB when non-default slot is used;<br>
*) package - use bundled package by default if standalone packages are installed as well;<br>
*) ppp - added "at-chat" command;<br>
*) resource - fixed "total-memory" reporting on ARM devices;<br>
*) snmp - added "tx-ccq" ("mtxrWlStatTxCCQ") and "rx-ccq" ("mtxrWlStatRxCCQ") values;<br>
*) snmp - changed fan speed value type to Gauge32;<br>
*) snmp - removed "rx-sector" ("Wl60gRxSector") value;<br>
*) ssh - fixed public key format compatibility with RFC4716;<br>
*) switch - fixed MAC learning when disabling interfaces on devices with Atheros8327 and QCA8337 switch chips;<br>
*) system - fixed situation when all configuration was not properly loaded on bootup;<br>
*) timezone - fixed "Europe/Dublin" time zone;<br>
*) traceroute - improved stability when sending large ping amounts;<br>
*) upgrade - automatically uninstall standalone package if already installed in bundle;<br>
*) user - require "write" permissions for LTE firmware update;<br>
*) watchdog - allow specifying <abbr title="Domain Name System">DNS</abbr> name for "send-smtp-server" parameter;<br>
*) webfig - do not show bogus VHT field in wireless interface advanced mode;<br>
*) winbox - added "allow-roaming" parameter in "Interface/LTE" menu;<br>
*) winbox - added "challenge-password" field when signing certificate with SCEP;<br>
*) winbox - added "conflict-detection" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> server" menu;<br>
*) winbox - added src/dst address and in/out interface list columns to default firewall menu view;<br>
*) winbox - added support for dynamic devices in "IP/Kid Control/Devices" tab;<br>
*) winbox - allow to change VHT rates when 5ghz-n/ac band is used;<br>
*) winbox - fixed missing w60g interface status values;<br>
*) winbox - renamed "Radius" to "RADIUS";<br>
*) winbox - show "R" flag under "IPv6/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server/Bindings" tab;<br>
*) winbox - show "Switch" menu on RB4011iGS+5HacQ2HnD;<br>
*) wireless - improvements in wireless frequency selection;<br>
*) wireless - improved system stability for all ARM devices with wireless;<br><br>
Other changes since v6.43.7:<br><br>
*) bridge - added option to monitor fast-forward status;<br>
*) bridge - disable fast-forward when using SlowPath features;<br>
*) bridge - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Option 82 parsing when using <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping;<br>
*) bridge - fixed packet forwarding when changing MSTI <abbr title="Virtual Local Area Network">VLAN</abbr> mappings;<br>
*) bridge - fixed possible memory leak when using MSTP;<br>
*) bridge - improved packet processing when bridge port changes states;<br>
*) btest - added multithreading support for both <abbr title="User Datagram Protocol">UDP</abbr> and <abbr title="Transmission Control Protocol">TCP</abbr> tests;<br>
*) btest - added warning message when CPU load exceeds 90% (CLI only);<br>
*) capsman - fixed "group-key-update" parameter not using correct units;<br>
*) certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided;<br>
*) chr - assign interface names based on underlying PCI device order on KVM;<br>
*) cloud - do not reuse old <abbr title="User Datagram Protocol">UDP</abbr> socket if routing changes are detected;<br>
*) cloud - ignore "force-update" command if DDNS is disabled;<br>
*) cloud - improved DDNS service disabling;<br>
*) cloud - made address updating faster when new public address detected;<br>
*) console - renamed IP protocol 41 to "ipv6-encap";<br>
*) crs317 - fixed TX not working on sfp-sfpplus9 interface (introduced in v6.40beta12);<br>
*) crs328 - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);<br>
*) crs3xx - improved data transmission between 10G and 1G ports;<br>
*) defconf - fixed configuration not generating properly on upgrade;<br>
*) dhcp - properly load <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> configuration if options are configured;<br>
*) dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;<br>
*) dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;<br>
*) dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client;<br>
*) dhcpv6-server - improved DHCPv6 server stability when using "print" command;<br>
*) e-mail - added info log message when e-mail is sent successfully;<br>
*) ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;<br>
*) ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);<br>
*) ethernet - improved per core ethernet traffic classificator on mmips devices;<br>
*) fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20);<br>
*) fetch - fixed "without-paging" option;<br>
*) health - improved fan control stability on CRS328-24P-4S+RM;<br>
*) ike2 - added option to specify certificate chain;<br>
*) ike2 - added peer identity validation for RSA auth (disabled after upgrade);<br>
*) ike2 - fixed local address lookup when initiating new connection;<br>
*) ike2 - improved subsequent phase 2 initialization when no childs exist;<br>
*) ike2 - properly handle certificates with empty "Subject";<br>
*) ike2 - send split networks over <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> (option 249) to Windows initiators if <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Inform is received;<br>
*) ike2 - show weak pre-shared-key warning;<br>
*) ipsec - added account log message when user is successfully authenticated;<br>
*) ipsec - added basic pre-shared-key strength checks;<br>
*) ipsec - added new "remote-id" peer matcher (CLI only);<br>
*) ipsec - allow to specify single address instead of IP pool under "mode-config";<br>
*) ipsec - fixed active connection killing when changing peer configuration;<br>
*) ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);<br>
*) ipsec - hide empty prefixes on "peer" menu;<br>
*) ipsec - made dynamic "src-nat" rule more specific;<br>
*) ipsec - made peers autosort themselves based on reachability status;<br>
*) ipsec - moved "profile" menu outside "peer" menu (CLI only);<br>
*) ipsec - properly detect AES-NI extension as hardware AEAD;<br>
*) ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;<br>
*) kidcontrol - added "reset-counters" command for "device" menu (CLI only);<br>
*) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);<br>
*) kidcontrol - dynamically discover devices from <abbr title="Domain Name System">DNS</abbr> activity;<br>
*) kidcontrol - fixed validation checks for time intervals;<br>
*) kidcontrol - properly detect time zone changes;<br>
*) led - fixed default LED configuration for wAP 60G AP devices;<br>
*) lte - added additional ID support for Novatel USB730L modem;<br>
*) lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);<br>
*) lte - added "ecno" field for "info" command;<br>
*) lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);<br>
*) lte - added support for JioFi JMR1040 modem;<br>
*) lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> relay packet forwarding when in passthrough mode;<br>
*) lte - fixed IPv6 activation for R11e-LTE-US modems;<br>
*) lte - fixed Jaton/SQN modems preventing router from booting properly;<br>
*) lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;<br>
*) lte - fixed missing running (R) flag for Jaton LTE modems;<br>
*) lte - improved compatibility for Alt38xx modems;<br>
*) port - improved "remote-serial" <abbr title="Transmission Control Protocol">TCP</abbr> performance in RAW mode;<br>
*) profiler - classify kernel crypto processing as "encrypting";<br>
*) proxy - removed port list size limit;<br>
*) rb3011 - implemented multiple engine IPsec hardware acceleration support;<br>
*) rbm33g - improved stability when used with some USB devices;<br>
*) romon - improved reliability when processing RoMON packets on CHR;<br>
*) routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";<br>
*) sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;<br>
*) snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;<br>
*) snmp - fixed w60g station table;<br>
*) snmp - report bridge ifSpeed as "0";<br>
*) ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);<br>
*) ssh - added error log message when key exchange fails;<br>
*) ssh - fixed non-interactive shell not returning all output (introduced in v6.44);<br>
*) ssh - fixed single command execution (introduced in v6.44beta9);<br>
*) switch - fixed ACL rules on IPQ4018 devices;<br>
*) tr069-client - fixed HTTP cookie getting duplicated with the same key;<br>
*) traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;<br>
*) tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with <abbr title="Domain Name System">DNS</abbr> as "remote-address";<br>
*) upgrade - made security package depend on <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> package;<br>
*) userman - show redirect location in error messages;<br>
*) w60g - added "10s-average-rssi" parameter to align mode (CLI only);<br>
*) w60g - added align mode "/interface w60g align" (CLI only);<br>
*) w60g - fixed scan in bridge mode;<br>
*) w60g - improved PtMP performance;<br>
*) w60g - improved reconnection detection;<br>
*) w60g - improved "tx-packet-error-rate" reading;<br>
*) w60g - renamed disconnection message when license level did not allow more connected clients;<br>
*) w60g - renamed "frequency-list" to "scan-list";<br>
*) winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;<br>
*) winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;<br>
*) winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;<br>
*) winbox - allow setting "network-mode" to "auto" under LTE interface settings;<br>
*) winbox - show "W60G" wireless tab on wAP 60G AP;<br>
*) wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);<br>
*) wireless - improved stability for 802.11ac;<br>
*) wireless - removed G/N support for 2484MHz in "japan" regulatory domain;<br>
*) wireless - report last seen IP address in RADIUS accounting messages;<br><br>Download the new '<b>RouterOS 6.44beta50</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/testing" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7319</guid><pubDate>Tue, 18 Dec 2018 10:18:33 +0000</pubDate></item><item><title>RouterOS 6.44beta50 [Testing]</title><link>https://www.mikrotik-bg.net/blogs/entry/7309-routeros-644beta50-testing/</link><description><![CDATA[
<p></p>
<h3>6.44beta50 changelog:</h3>Important note!!! Backup before upgrade!<br>
Due to major IPsec configuration changes in RouterOS v6.44beta39+ (see changelog below), it is advised to make a backup before upgrading. Regular downgrade will still be possible as long as no changes in IPsec peer menu are done.<br><br>
MAJOR CHANGES IN v6.44:<br>
----------------------<br>
!) cloud - added command "/system backup cloud" for backup storing on cloud (CLI only);<br>
!) radius - initial implementation of RadSec (Radius communication over TLS);<br>
!) upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";<br>
!) upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;<br>
!) speedtest - added "/tool speed-test" for ping latency, jitter, loss and <abbr title="Transmission Control Protocol">TCP</abbr> and <abbr title="User Datagram Protocol">UDP</abbr> download, upload speed measurements (CLI only);<br>
!) ipsec - added new "identity" menu with common peer distinguishers;<br>
!) ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode;<br>
!) ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu;<br>
----------------------<br><br>
Changes in this release:<br><br>
!) ipsec - added new "identity" menu with common peer distinguishers;<br>
!) speedtest - added "/tool speed-test" for ping latency, jitter, loss and <abbr title="Transmission Control Protocol">TCP</abbr> and <abbr title="User Datagram Protocol">UDP</abbr> download, upload speed measurements (CLI only);<br>
!) telnet - do not allow to set "tracefile" parameter;<br>
*) bgp - properly update keepalive time after peer restart;<br>
*) bridge - fixed BOOTP packet forwarding when <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping is enabled;<br>
*) bridge - fixed IPv6 link-local address generation when auto-mac=yes;<br>
*) capsman - always accept connections from loopback address;<br>
*) certificate - added support for multiple "Subject Alt. Names";<br>
*) cloud - added "ddns-update-interval" parameter;<br>
*) conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter);<br>
*) console - properly remove system note after configuration reset;<br>
*) crs3xx - improved fan control stability;<br>
*) crs3xx - improved stability when adding ACL rules on CRS326 and CRS328 devices (introduced in 6.44beta39);<br>
*) defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;<br>
*) defconf - fixed IPv6 link-local address range in firewall rules;<br>
*) dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> servers to control dynamic lease/binding behaviour;<br>
*) dhcpv4-server - added "parent-queue" parameter (CLI only);<br>
*) dhcpv6-server - properly handle <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> requests that include prefix hint;<br>
*) discovery - detect proper slave interface on bounded interfaces;<br>
*) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;<br>
*) discovery - send master port in "interface-name" parameter;<br>
*) discovery - show neighbors on actual bridge port instead of bridge itself for LLDP;<br>
*) ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices;<br>
*) export - fixed "silent-boot" compact export;<br>
*) fetch - added "http-header-field" parameter;<br>
*) gps - added "coordinate-format" parameter (CLI only);<br>
*) ike2 - allow to match responder peer by "my-id=fqdn" field;<br>
*) ipsec - improved invalid policy handling when a valid policy is uninstalled;<br>
*) kidcontrol - added IPv6 support;<br>
*) kidcontrol - added statistics web interface for kids (http://router.<abbr title="Local Area Network">lan</abbr>/kid-control);<br>
*) led - fixed default LED configuration for RBMetalG-52SHPacn;<br>
*) lte - added "ecno" field for "info" command;<br>
*) lte - disallow setting LTE interface as passthrough target;<br>
*) lte - fixed passthrough functionality when interface is removed;<br>
*) lte - improved SimCom 7100e support;<br>
*) lte - increased reported "rsrq" precision;<br>
*) lte - reset USB when non-default slot is used;<br>
*) package - use bundled package by default if standalone packages are installed as well;<br>
*) ppp - added "at-chat" command;<br>
*) resource - fixed "total-memory" reporting on ARM devices;<br>
*) snmp - added "tx-ccq" ("mtxrWlStatTxCCQ") and "rx-ccq" ("mtxrWlStatRxCCQ") values;<br>
*) snmp - changed fan speed value type to Gauge32;<br>
*) snmp - removed "rx-sector" ("Wl60gRxSector") value;<br>
*) ssh - fixed public key format compatibility with RFC4716;<br>
*) switch - fixed MAC learning when disabling interfaces on devices with Atheros8327 and QCA8337 switch chips;<br>
*) system - fixed situation when all configuration was not properly loaded on bootup;<br>
*) timezone - fixed "Europe/Dublin" time zone;<br>
*) traceroute - improved stability when sending large ping amounts;<br>
*) upgrade - automatically uninstall standalone package if already installed in bundle;<br>
*) user - require "write" permissions for LTE firmware update;<br>
*) watchdog - allow specifying <abbr title="Domain Name System">DNS</abbr> name for "send-smtp-server" parameter;<br>
*) webfig - do not show bogus VHT field in wireless interface advanced mode;<br>
*) winbox - added "allow-roaming" parameter in "Interface/LTE" menu;<br>
*) winbox - added "challenge-password" field when signing certificate with SCEP;<br>
*) winbox - added "conflict-detection" parameter in "IP/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> server" menu;<br>
*) winbox - added src/dst address and in/out interface list columns to default firewall menu view;<br>
*) winbox - added support for dynamic devices in "IP/Kid Control/Devices" tab;<br>
*) winbox - allow to change VHT rates when 5ghz-n/ac band is used;<br>
*) winbox - fixed missing w60g interface status values;<br>
*) winbox - renamed "Radius" to "RADIUS";<br>
*) winbox - show "R" flag under "IPv6/<abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Server/Bindings" tab;<br>
*) winbox - show "Switch" menu on RB4011iGS+5HacQ2HnD;<br>
*) wireless - improvements in wireless frequency selection;<br>
*) wireless - improved system stability for all ARM devices with wireless;<br><br>
Other changes since v6.43.7:<br><br>
*) bridge - added option to monitor fast-forward status;<br>
*) bridge - disable fast-forward when using SlowPath features;<br>
*) bridge - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Option 82 parsing when using <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Snooping;<br>
*) bridge - fixed packet forwarding when changing MSTI <abbr title="Virtual Local Area Network">VLAN</abbr> mappings;<br>
*) bridge - fixed possible memory leak when using MSTP;<br>
*) bridge - improved packet processing when bridge port changes states;<br>
*) btest - added multithreading support for both <abbr title="User Datagram Protocol">UDP</abbr> and <abbr title="Transmission Control Protocol">TCP</abbr> tests;<br>
*) btest - added warning message when CPU load exceeds 90% (CLI only);<br>
*) capsman - fixed "group-key-update" parameter not using correct units;<br>
*) certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided;<br>
*) chr - assign interface names based on underlying PCI device order on KVM;<br>
*) cloud - do not reuse old <abbr title="User Datagram Protocol">UDP</abbr> socket if routing changes are detected;<br>
*) cloud - ignore "force-update" command if DDNS is disabled;<br>
*) cloud - improved DDNS service disabling;<br>
*) cloud - made address updating faster when new public address detected;<br>
*) console - renamed IP protocol 41 to "ipv6-encap";<br>
*) crs317 - fixed TX not working on sfp-sfpplus9 interface (introduced in v6.40beta12);<br>
*) crs328 - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17);<br>
*) crs3xx - improved data transmission between 10G and 1G ports;<br>
*) defconf - fixed configuration not generating properly on upgrade;<br>
*) dhcp - properly load <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> configuration if options are configured;<br>
*) dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages;<br>
*) dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge;<br>
*) dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client;<br>
*) dhcpv6-server - improved DHCPv6 server stability when using "print" command;<br>
*) e-mail - added info log message when e-mail is sent successfully;<br>
*) ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices;<br>
*) ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52);<br>
*) ethernet - improved per core ethernet traffic classificator on mmips devices;<br>
*) fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20);<br>
*) fetch - fixed "without-paging" option;<br>
*) health - improved fan control stability on CRS328-24P-4S+RM;<br>
*) ike2 - added option to specify certificate chain;<br>
*) ike2 - added peer identity validation for RSA auth (disabled after upgrade);<br>
*) ike2 - fixed local address lookup when initiating new connection;<br>
*) ike2 - improved subsequent phase 2 initialization when no childs exist;<br>
*) ike2 - properly handle certificates with empty "Subject";<br>
*) ike2 - send split networks over <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> (option 249) to Windows initiators if <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> Inform is received;<br>
*) ike2 - show weak pre-shared-key warning;<br>
*) ipsec - added account log message when user is successfully authenticated;<br>
*) ipsec - added basic pre-shared-key strength checks;<br>
*) ipsec - added new "remote-id" peer matcher (CLI only);<br>
*) ipsec - allow to specify single address instead of IP pool under "mode-config";<br>
*) ipsec - fixed active connection killing when changing peer configuration;<br>
*) ipsec - fixed stability issues after changing peer configuration (introduced in v6.43);<br>
*) ipsec - hide empty prefixes on "peer" menu;<br>
*) ipsec - made dynamic "src-nat" rule more specific;<br>
*) ipsec - made peers autosort themselves based on reachability status;<br>
*) ipsec - moved "profile" menu outside "peer" menu (CLI only);<br>
*) ipsec - properly detect AES-NI extension as hardware AEAD;<br>
*) ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder;<br>
*) kidcontrol - added "reset-counters" command for "device" menu (CLI only);<br>
*) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only);<br>
*) kidcontrol - dynamically discover devices from <abbr title="Domain Name System">DNS</abbr> activity;<br>
*) kidcontrol - fixed validation checks for time intervals;<br>
*) kidcontrol - properly detect time zone changes;<br>
*) led - fixed default LED configuration for wAP 60G AP devices;<br>
*) lte - added additional ID support for Novatel USB730L modem;<br>
*) lte - added "cell-monitor" command for R11e-LTE international modem (CLI only);<br>
*) lte - added "ecno" field for "info" command;<br>
*) lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only);<br>
*) lte - added support for JioFi JMR1040 modem;<br>
*) lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute;<br>
*) lte - fixed <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> relay packet forwarding when in passthrough mode;<br>
*) lte - fixed IPv6 activation for R11e-LTE-US modems;<br>
*) lte - fixed Jaton/SQN modems preventing router from booting properly;<br>
*) lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7;<br>
*) lte - fixed missing running (R) flag for Jaton LTE modems;<br>
*) lte - improved compatibility for Alt38xx modems;<br>
*) port - improved "remote-serial" <abbr title="Transmission Control Protocol">TCP</abbr> performance in RAW mode;<br>
*) profiler - classify kernel crypto processing as "encrypting";<br>
*) proxy - removed port list size limit;<br>
*) rb3011 - implemented multiple engine IPsec hardware acceleration support;<br>
*) rbm33g - improved stability when used with some USB devices;<br>
*) romon - improved reliability when processing RoMON packets on CHR;<br>
*) routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button";<br>
*) sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode;<br>
*) snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs;<br>
*) snmp - fixed w60g station table;<br>
*) snmp - report bridge ifSpeed as "0";<br>
*) ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only);<br>
*) ssh - added error log message when key exchange fails;<br>
*) ssh - fixed non-interactive shell not returning all output (introduced in v6.44);<br>
*) ssh - fixed single command execution (introduced in v6.44beta9);<br>
*) switch - fixed ACL rules on IPQ4018 devices;<br>
*) tr069-client - fixed HTTP cookie getting duplicated with the same key;<br>
*) traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s;<br>
*) tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with <abbr title="Domain Name System">DNS</abbr> as "remote-address";<br>
*) upgrade - made security package depend on <abbr title="Dynamic Host Configuration Protocol">DHCP</abbr> package;<br>
*) userman - show redirect location in error messages;<br>
*) w60g - added "10s-average-rssi" parameter to align mode (CLI only);<br>
*) w60g - added align mode "/interface w60g align" (CLI only);<br>
*) w60g - fixed scan in bridge mode;<br>
*) w60g - improved PtMP performance;<br>
*) w60g - improved reconnection detection;<br>
*) w60g - improved "tx-packet-error-rate" reading;<br>
*) w60g - renamed disconnection message when license level did not allow more connected clients;<br>
*) w60g - renamed "frequency-list" to "scan-list";<br>
*) winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab;<br>
*) winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab;<br>
*) winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab;<br>
*) winbox - allow setting "network-mode" to "auto" under LTE interface settings;<br>
*) winbox - show "W60G" wireless tab on wAP 60G AP;<br>
*) wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required);<br>
*) wireless - improved stability for 802.11ac;<br>
*) wireless - removed G/N support for 2484MHz in "japan" regulatory domain;<br>
*) wireless - report last seen IP address in RADIUS accounting messages;<br><br>Download the new '<b>RouterOS 6.44beta50</b>' version here: <a href="https://www.mikrotik.com/download" rel="external nofollow">https://www.mikrotik.com/download</a> <br><p><a href="https://www.mikrotik.com/download/changelogs/testing" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7309</guid><pubDate>Tue, 18 Dec 2018 10:18:33 +0000</pubDate></item><item><title>RouterOS 6.43.7 [Stable]</title><link>https://www.mikrotik-bg.net/blogs/entry/7320-routeros-6437-stable/</link><description><![CDATA[
<p></p>
<h3>6.43.7 changelog:</h3>MAJOR CHANGES IN v6.43.7:<br>
---------------------- <br>
!) upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";<br>
!) upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;<br>
---------------------- <br><br>
Changes in this release: <br><br>
*) bridge - properly disable dynamic CAP interfaces;<br>
*) certificate - fixed "expires-after" parameter calculation;<br>
*) certificate - fixed time zone adjustment for SCEP requests;<br>
*) certificate - properly flush old CRLs when changing store location;<br>
*) chr - fixed possible memory allocation failure when using multiple CPUs or interfaces on Xen installations; <br>
*) crs328 - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr> ports not reporting auto-negotiation status;<br>
*) crs328 - improved link status update on disabled <abbr title="Small Form-factor Pluggable">SFP</abbr> and <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interfaces;<br>
*) defconf - automatically accept default configuration if reset done by holding button;<br>
*) defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;<br>
*) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;<br>
*) discovery - fixed neighbor discovery for PPP interfaces;<br>
*) discovery - properly use System ID for "software-id" value on CHR;<br>
*) export - fixed "silent-boot" compact export;<br>
*) health - fixed bad voltage readings on RB493G;<br>
*) interface - improved system stability when including/excluding a list to itself;<br>
*) ipsec - fixed hw-aead (H) flag presence under Installed SAs on startup;<br>
*) ipsec - improved stability when uninstalling multiple SAs at once;<br>
*) ipsec - properly handle peer profiles on downgrade;<br>
*) ipsec - properly update warnings under peer menu;<br>
*) kidcontrol - do not allow users with "read" policy to pause and resume kids;<br>
*) log - properly handle long echo messages;<br>
*) lte - added support for more ZTE MF90 modems; <br>
*) ospf - improved stability while handling type-5 LSAs;<br>
*) routerboard - renamed SIM slots to "a" and "b" on SXT LTE kit;<br>
*) routerboard - show "boot-os" and "force-backup-booter" options only on devices that have such feature;<br>
*) snmp - do not initialise interface traps on bootup if they are not enabled;<br>
*) timezone - updated timezone information from tzdata2018g release;<br>
*) traffic-flow - fixed post NAT port reporting;<br>
*) traffic-flow - fixed "src-mac-address" and added "post-src-mac-address" fields;<br>
*) tunnel - made "ipsec-secret" parameter sensitive;<br>
*) usb - fixed power-reset for hAP ac^2 devices;<br>
*) user - speed up first time login process after upgrade from version older than v6.43;<br>
*) winbox - allow to specify SIM slot on LtAP mini;<br>
*) winbox - enabled "fast-forward" by default when adding new bridge;<br>
*) winbox - fixed neighbor discovery for IPv6 neighbors;<br>
*) winbox - show "System/Health" only on boards that have health monitoring;<br><br>Download the new '<b>RouterOS 6.43.7</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/stable" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7320</guid><pubDate>Mon, 03 Dec 2018 12:06:51 +0000</pubDate></item><item><title>RouterOS 6.43.7 [Stable]</title><link>https://www.mikrotik-bg.net/blogs/entry/7310-routeros-6437-stable/</link><description><![CDATA[
<p></p>
<h3>6.43.7 changelog:</h3>MAJOR CHANGES IN v6.43.7:<br>
---------------------- <br>
!) upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing";<br>
!) upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions;<br>
---------------------- <br><br>
Changes in this release: <br><br>
*) bridge - properly disable dynamic CAP interfaces;<br>
*) certificate - fixed "expires-after" parameter calculation;<br>
*) certificate - fixed time zone adjustment for SCEP requests;<br>
*) certificate - properly flush old CRLs when changing store location;<br>
*) chr - fixed possible memory allocation failure when using multiple CPUs or interfaces on Xen installations; <br>
*) crs328 - fixed <abbr title="Small Form-factor Pluggable">SFP</abbr> ports not reporting auto-negotiation status;<br>
*) crs328 - improved link status update on disabled <abbr title="Small Form-factor Pluggable">SFP</abbr> and <abbr title="Small Form-factor Pluggable">SFP</abbr>+ interfaces;<br>
*) defconf - automatically accept default configuration if reset done by holding button;<br>
*) defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN;<br>
*) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration;<br>
*) discovery - fixed neighbor discovery for PPP interfaces;<br>
*) discovery - properly use System ID for "software-id" value on CHR;<br>
*) export - fixed "silent-boot" compact export;<br>
*) health - fixed bad voltage readings on RB493G;<br>
*) interface - improved system stability when including/excluding a list to itself;<br>
*) ipsec - fixed hw-aead (H) flag presence under Installed SAs on startup;<br>
*) ipsec - improved stability when uninstalling multiple SAs at once;<br>
*) ipsec - properly handle peer profiles on downgrade;<br>
*) ipsec - properly update warnings under peer menu;<br>
*) kidcontrol - do not allow users with "read" policy to pause and resume kids;<br>
*) log - properly handle long echo messages;<br>
*) lte - added support for more ZTE MF90 modems; <br>
*) ospf - improved stability while handling type-5 LSAs;<br>
*) routerboard - renamed SIM slots to "a" and "b" on SXT LTE kit;<br>
*) routerboard - show "boot-os" and "force-backup-booter" options only on devices that have such feature;<br>
*) snmp - do not initialise interface traps on bootup if they are not enabled;<br>
*) timezone - updated timezone information from tzdata2018g release;<br>
*) traffic-flow - fixed post NAT port reporting;<br>
*) traffic-flow - fixed "src-mac-address" and added "post-src-mac-address" fields;<br>
*) tunnel - made "ipsec-secret" parameter sensitive;<br>
*) usb - fixed power-reset for hAP ac^2 devices;<br>
*) user - speed up first time login process after upgrade from version older than v6.43;<br>
*) winbox - allow to specify SIM slot on LtAP mini;<br>
*) winbox - enabled "fast-forward" by default when adding new bridge;<br>
*) winbox - fixed neighbor discovery for IPv6 neighbors;<br>
*) winbox - show "System/Health" only on boards that have health monitoring;<br><br>Download the new '<b>RouterOS 6.43.7</b>' version here: <a href="https://www.mikrotik.com/download" rel="external nofollow">https://www.mikrotik.com/download</a> <br><p><a href="https://www.mikrotik.com/download/changelogs/stable" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7310</guid><pubDate>Mon, 03 Dec 2018 12:06:51 +0000</pubDate></item><item><title>RouterOS 6.43.6 [Stable]</title><link>https://www.mikrotik-bg.net/blogs/entry/7321-routeros-6436-stable/</link><description><![CDATA[
<p></p>
<h3>6.43.6 changelog:</h3>(factory only release)<br><br>Download the new '<b>RouterOS 6.43.6</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/stable" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7321</guid><pubDate>Mon, 03 Dec 2018 12:00:54 +0000</pubDate></item><item><title>RouterOS 6.43.6 [Stable]</title><link>https://www.mikrotik-bg.net/blogs/entry/7311-routeros-6436-stable/</link><description><![CDATA[
<p></p>
<h3>6.43.6 changelog:</h3>(factory only release)<br><br>Download the new '<b>RouterOS 6.43.6</b>' version here: <a href="https://www.mikrotik.com/download" rel="external nofollow">https://www.mikrotik.com/download</a> <br><p><a href="https://www.mikrotik.com/download/changelogs/stable" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7311</guid><pubDate>Mon, 03 Dec 2018 12:00:54 +0000</pubDate></item><item><title>RouterOS 6.43.5 [Stable]</title><link>https://www.mikrotik-bg.net/blogs/entry/7322-routeros-6435-stable/</link><description><![CDATA[
<p></p>
<h3>6.43.5 changelog:</h3>(factory only release)<br><br>Download the new '<b>RouterOS 6.43.5</b>' version here: <a href="https://mikrotik.com/download" rel="external nofollow">https://mikrotik.com/download</a> <br><p><a href="https://mikrotik.com/download/changelogs/stable" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7322</guid><pubDate>Mon, 03 Dec 2018 11:55:28 +0000</pubDate></item><item><title>RouterOS 6.43.5 [Stable]</title><link>https://www.mikrotik-bg.net/blogs/entry/7312-routeros-6435-stable/</link><description><![CDATA[
<p></p>
<h3>6.43.5 changelog:</h3>(factory only release)<br><br>Download the new '<b>RouterOS 6.43.5</b>' version here: <a href="https://www.mikrotik.com/download" rel="external nofollow">https://www.mikrotik.com/download</a> <br><p><a href="https://www.mikrotik.com/download/changelogs/stable" rel="external nofollow"></a></p>
]]></description><guid isPermaLink="false">7312</guid><pubDate>Mon, 03 Dec 2018 11:55:28 +0000</pubDate></item></channel></rss>
