MikroTik Changelog Tracker

Search changelog entries

7.6 Stable 2022-Oct-17 (3 years ago)
Component Change
bgp added support for BGP advertisement displaying (CLI only);
bgp fixed reporting of session uptime;
bgp improved session establishment speed after bootup;
bonding fixed ARP monitor packets with bond's MAC address;
bonding improved interface stability on slave configuration changes;
bonding reduce "actual-mtu" according to interface "l2mtu";
branding execute "autorun.scr" file when installing branding package;
capsman fixed RADIUS accounting when EAP is used;
certificate fixed SHA1 certificate name lookup;
certificate improved certificate management, signing and storing processes;
certificate restricted maximum retry attempt window for Let's Encrypt certificate to 60 minutes;
container added "start-on-boot" parameter for automatic container startup;
container allow changing container related parameters while it is running;
container fixed usage of non-authenticated registries;
dhcpv4-server fixed matcher functionality;
dhcpv4-server fixed RADIUS accounting for local leases;
dhcpv4-server improved service stability when removing dynamic leases;
dhcpv6-client fixed false error status reporting when server offers T1 or T2 value as 0;
dns added "match-subdomain" option for static entries (CLI only);
dot1x fixed incorrect error when using "mac-auth";
ethernet added "5Gbps" option for speed setting;
firewall added "src/dst-address-type" parameter under "IPv6/Firewall/Mangle" menu;
firewall disable IRC NAT helper on upgrade;
firewall fixed IPv6 filtering with "in/out-interface" matcher that is in VRF;
firewall fixed IRC NAT helper (CVE-2022-2663);
firewall fixed usage of "netmap" action for IPv6 source NAT;
health fixed fan speed and temperature reporting on CCR1072;
health improved voltage reading on RBmAP-2nD;
hotspot fixed service initialization when HTML directory configured on an external disk;
hotspot fixed SSL usage on all HotSpot pages;
hotspot improved stability when receiving bogus packets;
hotspot limit maximum allowed connections based on free RAM resources;
hotspot removed "routerboard.com" URL from default HotSpot advertise;
interface added warning when interface has configured "mtu" higher than "l2mtu";
ipsec added "invalid-packets" counter for Installed SA's menu;
ipsec fixed packet processing by hardware encryption engine on MMIPS devices;
l3hw added "l3hw-settings" sub menu under the switch menu;
l3hw added support for IPv6 route offloading (disabled by default);
l3hw fixed "H" flag presence for accelerated connection tracking entries;
l3hw fixed possible packet loss when using HW offloaded NAT;
l3hw improved connected host offloading on startup;
l3hw improved connected IPv6 host offloading when routing table is nearly full for 98DX224S, 98DX226S, and 98DX3236 switch chips;
l3hw improved system stability;
l3hw made route offloading selection work only on unicast;
lte added interface name in MTU debug logging message;
lte added periodic IPv6 RS to trigger IPv6 adress acquisition for non-MBIM modems;
lte added support for Neoway N75-EA;
lte added support to perform FOTA upgrade from local file for EG12-EA, EG18-EA, RG502Q-AE, EG06-A, EP06-A modems;
lte disabled RPLMN on Chateau 5G;
lte fixed at-chat on Telit FN980m;
lte fixed handover from UMTS to LTE when PS activation had failed for MBIM modems;
lte fixed MBIM modem initialization;
lte fixed re-attaching on PS detach for MBIM modems;
lte removed reconnect delay after receiving DETACH notification for MBIM modems;
mac-telnet respect interface MTU setting when sending packets for MAC-Telnet and MAC-WinBox;
macsec added configuration support with VLAN, ARP, DHCP and bridge tagging/untagging;
macsec added logging support with "debug" and "dot1x" topics;
macsec added support for MTU and L2MTU;
macsec fixed interface after Ethernet link down;
macsec fixed interface statistics and missing properties;
macsec fixed interface status;
macsec fixed multiple interface creation on different Ethernet ports
macsec improved interface stability;
macsec improved system stability for TILE and RB5009 devices;
macsec removed interface from SMIPS devices;
netwatch fixed string variable values in script;
ntp improved initial synchronization speed after bootup;
ospf added SHA hashing for authentication;
ospf fixed area "no-summary" setting;
ospf fixed checksum calculation;
ospf fixed displaying of VRF interface in related logs;
ospf fixed transmit of LSA/ACK's on p2p interfaces;
ospf improved logging when invalid configuration is detected;
ospf refresh OSPFv3 interface configuration when IPv6 network becomes available;
ovpn added IPv6 support;
ovpn added VRF support for client;
ppp fixed memory leak;
ppp improved service stability when multiple users disconnect simultaneously;
pppoe fixed MRU negotiation even when it is set to 1500;
qsfp added interface temperature warnings and shutdown;
queue improved stability for CAKE type queues;
radius require "policy" policy for "login" service configuration;
rip fixed passwordless MD5 authentication;
route fixed disappearance of inactive static routes after upgrade;
route fixed memory leak;
route-filter fixed filtering for multiple community routes;
route-filter fixed memory allocation when moving entries;
routerboard return router's short name in "model" parameter;
routerboard set "Delete" as default key to enter booter menu ("/system routerboard upgrade" required);
serial added support for newer PL2303 serial controllers;
sfp improved QSFP/SFP interface stability for 98DXxxxx and 98PX1012 switches;
sms added "status-report-request" parameter for "send" command;
sms fixed handling of SMS send attempts on unsupported modems;
snmp improved retrieval of routing related OID's;
snmp improved stability when receiving bogus packets;
ssh increased key generation timeout;
sstp added VRF support for client;
supout added tr069-client section;
supout removed duplicate "bridge-controller" section;
switch improved traffic forwarding at 5Gbps rate for 98DX8525, 98DX4310 switches;
system renamed error messages when trying to edit or remove dynamic entries;
tile improved system stability when processing packets;
tr069-client do not allow ":" symbols in username;
tr069-client fixed reporting of "X_MIKROTIK_MimoRSRP" parameter;
user removed unused "dude" policy;
user-manager accept any username for outer authentication;
user-manager added "comment" parameter for batch user creation;
user-manager added support for multiple accounting sessions;
user-manager added variables to print profile name and end time in voucher templates;
user-manager allow specifying router's address as subnet;
user-manager fixed "migrate-legacy-db" command;
user-manager fixed session expiry when it is stopped by Disconnect-Request;
user-manager forced username verification against client's certificate for EAP-TLS;
user-manager use "Class" attribute to associate user's accounting session;
vrrp fixed connection tracking synchronization on MMIPS and MIPSBE devices;
vxlan added IPv6 support for remote VTEPs (only IPv4 or IPv6 will be used at the same time, use "vteps-ip-version" property on VXLAN interface to change the version);
w60g improved system stability (introduced in v7.5);
webfig fixed creation of new IPv6 routes;
webfig fixed displaying of "Last Seen" parameter under "IP/DHCP Server/Leases" menu;
webfig fixed hex input for "Host Uniq" field;
webfig fixed unsetting of "endpoint-address" parameter under "WireGuard/Peers" menu;
wifiwave2 fixed enabling of unconfigured interfaces;
wifiwave2 fixed malfunction of WPA3 hash-to-element technique when enabled on multiple interfaces;
wifiwave2 fixed RADIUS accounting after fast-transition;
wifiwave2 fixed "WPA Key Data Length" value in EAPOL frame when FT-EAP-SHA384 AKM is used;
winbox added "Active" prefix for current remote and local session ID fields for L2TP-Ether interfaces;
winbox added "address-list" parameter under "IP/DNS/Static" menu;
winbox added "File Name" option for "Load Config" parameter under "System/SwOS" menu;
winbox added icon for TR069-client menu;
winbox added MACsec support;
winbox added quick filtering option for route list;
winbox added "Rapid Commit" parameter support under "IPv6/DHCP-Server" menu;
winbox added "Reset Traffic Counters" button for all interfaces;
winbox added "type" and "status-report-request" parameters under "Tools/SMS" menu;
winbox allow "timeout" value to be less than 1 under "Tools/Netwatch" menu;
winbox allow to rename mounted disks;
winbox changed order of tabs under "User Manager" menu;
winbox changed "uptime" parameter format when using the wifiwave2 package;
winbox do not show unavailable features on SMIPS devices;
winbox fixed interface traffic graph drawing on RB5009;
winbox fixed maximum allowed value for VRRP's "priority" parameter;
winbox fixed "Session Uptime" value for not established sessions under "Routing/BGP" menu;
winbox fixed "Session Uptime" value under "Routing/BGP" menu;
winbox fixed "System/SwOS" window refreshing after changes are detected;
winbox fixed "User Manager/User Profiles" window refreshing after changes are detected;
winbox made "backup.swb" the default value for SwOS backup;
winbox made sessions removable in "User Manager" menu;
winbox show "F" flag for failed entries under "Interfaces/VRRP" menu;
winbox show "Switch" menu on Chateau LTE18 ax;
winbox show "System/Health" only on boards that have health monitoring;
winbox show "System/RouterBOARD/Mode Button" on devices that have such feature;
wireguard strip whitespaces from keys;
wireless disallowed using "default" as scan list or channel names;
wireless fixed incorrectly applied ingress priority to non-wireless packets;
wireless fixed missing wireless interface on some RB921GS-5HPacD devices;
www improved stability when receiving bogus packets;
x86 improved ixgbe driver support;
6.49.7 Stable 2022-Oct-11 (3 years ago)
Component Change
branding fixed execution of "autorun.scr" file when installing branding package (introduced in v6.47);
routerboot prevent enabling "protected-routerboot" on unsupported factory firmware versions;
routerboot properly reset system configuration when protected bootloader is enabled and reset button used;
system improved handling of user policies;
wireless fixed disconnection of connected client while running background scan on wAP ac and wAP R ac devices;
wireless fixed missing wireless interface on some RB921GS-5HPacD devices;
7.5 Stable 2022-Aug-30 (3 years ago)
Component Change
bgp fixed remote refuse capability options, max prefix limit errors and administrative stop;
bgp improved stability when "default-originate" is configured;
bridge fixed "new-priority" value validation for NAT rules;
capsman added randomized range option for "reselect-interval" parameter (CLI only);
certificate fixed handling of empty AKID by SCEP client;
console fixed automatic command completion with keypress;
container added support for running Docker (TM) containers on ARM, ARM64 and x86 (containers created before v7.4 must be recreated);
defconf fixed loading of default configuration on RB4011 with WifiWave2 package enabled;
dhcpv4-server fixed removal of dynamic leases when server is removed;
dhcpv6-client moved invalid lifetime logging message from "debug" to "error" topic;
dhcpv6-client use /128 prefix for IA_NA addresses;
dhcpv6-relay fixed relay forwarding (introduced in v7.1.5);
dhcpv6-server improved stability when acquiring binding;
dns added "address-list" parameter for static DNS entries (CLI only);
dns added "match-subdomain" option for static entries (CLI only);
firewall added support for RTSP helper;
health fixed "temperature" and "power-consumption" readings on RB1100x4;
health improved voltage reading on CRS112-8P-4S;
health renamed "cpu-temperature" to "switch-temperature" on CRS312-4C+8XG, CRS326-24S+2Q+, CRS354-48P-4S+2Q+, CRS354-48G-4S+2Q+, CRS504-4XQ-IN, CRS518-16XS-2XQ;
hostpot fixed Walled Garden functionality for HTTPS sites;
hotspot automatically reject all HTTPS requests passing through HotSpot server for unauthorized users;
hotspot improved stability when receiving bogus packets;
hotspot limit maximum allowed connections based on free RAM resources;
hotspot removed "https-redirect" option;
ike2 allow sending certificate chain as initiator;
interface fixed default interface naming on RB1100x2;
l3hw fixed HW offloaded NAT;
leds fixed default LED configuration for RBwsAP-5Hac2nD;
leds fixed wireless LED functionality on LHGG;
lora do not ignore negative sign for spoofed GPS coordinates;
lte added at-chat and NMEA port support for Simcom modems, USB composition (device id - 0x9003);
lte added at-chat support for Simcom modems, USB composition (device id - 0x9005);
lte added "SIM not inserted" and "SIM failure" messages to "status" and "monitor" commands for AT modems;
lte changed cell ID info display to short format for 3G connections;
lte disallow empty APN name only for default entry;
lte fixed AT channel for Sierra Wireless modems with device ID 0x9091;
lte fixed LTE interface presence for Telit LN940;
lte fixed UDP performance on MMIPS devices;
lte improved antenna scan for Chateau devices with switchable antennas;
lte improved configuration export when multiple LTE interfaces are present;
lte modem dialer, do not reset dialing sequence if modem reply with error to user set init-string;
netinstall fixed Netinstall procedure for ARM devices;
netwatch automatically start migrated probes from previous RouterOS versions;
netwatch changed ICMP default packet loss fail threshold to 85%;
ntp fixed NTP server when "use-local-clock" is used;
ospf fixed handling of external forwarding address;
ospf improved stability when interface is being disabled during database exchange;
ovpn fixed encryption key renewal process which caused periodic session disconnects;
ovpn improved system stability when hardware acceleration is used on ARM64 devices;
ovpn moved disconnected user logging message from "debug" to "info" topic;
ping improved service stability;
port added support for D-Link DWM-222 in serial/PPP mode (device id - 0xac01/0x7e3d);
port added support for Huawei/ZTE K5006z in serial/PPP mode (device id - 0x1017/0x1018);
ppp improved service stability under high load;
ppp use /32 as default netmask if not specified for "routes" parameter;
ptp improved system stability on CRS devices;
quickset removed PPTP and SSTP server addition for "VPN" checkbox;
rb5009 fixed ether1 status reporting after system reboot;
route-filter fixed "delete bgp-communities" command;
routerboard added "reset-button" script feature for TILE devices;
sfp fixed "eeprom" reading on single SFP port ARM devices;
sfp fixed QSFP+ and QSFP28 interface disable when using breakout cable;
sfp fixed unresponsive "sfp1" interface after disabling "ether1" on NetMetal devices;
sfp improved combo SFP ports initialization handling on CRS312-4C+8XG, CRS328-4C-20S-4S+;
sfp improved stability when using 2.5G optical modules in CCR2116, CCR2216 and CRS518;
snmp fixed usage of VRF after system startup;
socks fixed "dst-port" usage when checking access list;
ssh added AES support for PEM decryption;
ssh fixed importing of public keys;
ssh fixed minor typo issue when importing public key;
sstp fixed client stuck in "nonce matching" state;
switch fixed ACL rules for 98DXxxxx switches with more than 28 ports (introduced in v7.3);
switch removed limit for number of hardware-offloaded bonding interfaces;
swos enabled SwitchOS support for CRS310-1G-5S-4S+;
swos fixed SwOS upgrade procedure on CRS305-1G-4S+;
traceroute added "do-not-fragment" parameter support (CLI only);
traceroute increased packet size limit to 65535;
vrrp added "sync-connection-tracking" compatibility with preemption-mode;
vrrp fixed high CPU usage when "sync-connection-tracking=yes" and the backup router goes offline;
vrrp fixed HW offloaded bridge MAC address learning when changing from VRRP master to backup;
vrrp fixed initial connection tracking synchronization, a backup router now always receives all existing connections;
vrrp improved connection tracking synchronization protocol (CTSYNC), the new protocol is incompatible with previous RouterOS versions with "sync-connection-tracking=yes";
webfig allow to specify NTP server as domain name;
webfig fixed displaying of grahs in status pages;
webfig fixed floating point field's negative value in -0.*** format;
wifiwave2 added "sae-pwe" parameter with hash-to-element mechanism for SAE PWE derivation;
wifiwave2 added support for 802.11k;
wifiwave2 disable wireless interface after wireless configuration reset;
wifiwave2 fixed displaying of AKM in scan results;
wifiwave2 fixed duplicated AKM in RSN message;
wifiwave2 fixed group key update for client devices which connect via fast BSS transition;
wifiwave2 fixed incorrect AKM usage for FT-WPA3-EAP-192;
wifiwave2 fixed reassociation response sending for fast transition over DS;
wifiwave2 fixed setting of "ft-nas-identifier" parameter;
wifiwave2 fixed usage of Canada country setting on US locked devices;
wifiwave2 improved default channel width selection for interfaces in station mode;
winbox do not show previously attached LTE interfaces while establishing LTE connection;
winbox enabled all filters by default under "Tools/Torch" menu;
winbox fixed "Enable", "Disable" and "Comment" functions for L2TP-ether type interfaces;
winbox fixed "Next Run" parameter displaying under "System/Scheduler" menu;
winbox fixed "Type" and "Value" field displaying under "System/Health" sub-menu's;
winbox show warning messages for BGP connection entries;
wireless fixed interface initialization on x86 devices;
x86 allow downgrading to RouterOS v6 only if it was previously installed;
x86 fixed advertising of 2500M and 5000M link speeds on ixgbe driver;
7.4.1 Stable 2022-Aug-04 (3 years ago)
Component Change
firewall fixed "in-interface-list" matcher when VRF is used;
netwatch changed ICMP default packet loss fail threshold to 85%;
netwatch fixed usage of "timeout" value in simple mode;
sfp fixed speed mode setting after reinserting SFP module on CRS328-4C-20S-4S+;
sfp improved combo SFP ports initialization handling on CRS312-4C+8XG, CRS328-4C-20S-4S+
winbox fixed "Type" and "Value" field displaying under "System/Health" sub-menu's;
7.4 Stable 2022-Jul-19 (3 years ago)
Component Change
api fixed comma encoding within URL when using the ".proplist" argument;
bridge properly process IPsec decapsulated packets through the firewall when the "use-ip-firewall" option is enabled;
capsman require a unique name for configuration and configuration pre-sets;
certificate fixed new CRL updating;
chr fixed booting with added additional SCSI disk;
cloud print critical log message when system clock gets synchronized;
console added ":retry" command;
console fixed situation when print output was not consistent;
defconf fixed default configuration loading on devices with WifiWave2 package;
dhcp-relay fixed DHCPv6 relay forward and reply creation (introduced in v7.1.3);
dhcp-server change "vendor-class-id" matcher to generic option matcher;
dhcpv4-server disallowed overriding message type option;
dhcpv4-server log message when user option updates existing option;
dhcpv4-server placed option 53 as the first one in the packet;
dns convert the domain name to lowercase before matching regex;
dot1x fixed "undo" command for server instances;
e-mail added VRF support;
filesystem fixed repartition on RB5009 series devices;
firewall added "srcnat" and "dstnat" flags to IPv6/Firewall/Connection table;
firewall added support for IPv6/Firewall/NAT action=src-nat rules;
firewall fixed IPv6 NAT functionality when processing GRE traffic on TILE devices;
firewall fixed IPv6/Firewall/RAW functionality;
firewall include "connection-mark", "connection-state", and "packet-mark" when packet logging is enabled;
firewall properly handle interface matcher when VRF interface is specified;
health fixed requesting data from sensor when issuing "get" command;
health fixed voltage reporting on some RBmAP-2nD devices;
hotspot fixed ARP resolution for clients when address pool is specified on the server;
hotspot fixed Walled Garden entries with action=deny;
ipv6 fixed system stability when adding/removing IPv6 address;
l2tp improved stability when establishing l2tp-ether connection (introduced in v7.3);
ldp correctly handle AFI selection for usage on dual-stack peers;
leds fixed GPS LED configuration on LtAP LTE kit;
leds fixed LTE signal strength LED configuration on LHGG LTE kit;
leds fixed LTE signal strength LED configuration on LtAP LTE kit;
lte added AT chat support for Dell dw5821e modem;
lte fixed LTE interface running state after modem reconnection;
lte fixed Telit AT interface numbering;
lte improved LTE interface detection for LtAP-2HnD devices;
lte keep MBIM working even if AT channel fails to respond in the initialization stage;
lte request connect with the same IP type as in LTE attach status for MBIM;
lte show current value for "antenna" parameter when auto antenna selection fails;
lte validate LTE attached IP type in MBIM mode;
mmips improved USB device detection after system bootup;
mpls fixed VPLS functionality when PW peer is an immediate neighbor;
mpls improved stability with enabled loop-detect;
mqtt fixed log flooding with disconnect messages;
mqtt fixed socket error handling;
netwatch added support for more advanced probing;
ntp added VRF support for client and server;
ntp fixed manycast server support;
ntp improved "debug" log level logging;
ovpn added "AUTH_FAILED" control message sending;
ovpn fixed "called-station-id" RADIUS attribute value for OVPN server;
ovpn use selected cipher by default when the server does not provide "cipher" option;
pimsm improved system stability when changing configuration;
poe hide "poe-voltage" parameter on devices that do not support it;
ppp do not fail connection when trying to add existing IP address to address list;
ppp log warning message when remote IP address can not be added;
ppp properly try to use different authentication algorithms when Conf-Rej is received during the LCP phase;
quickset specify the "in-interface-list=WAN" attribute on firewall rules created through "Port Mapping";
radius added VRF support for RADIUS client;
route added option to join static IGMP and MLD groups (available in "/routing/gmp" menu);
route expose all valid routes to route select filter from BGP;
route expose all valid routes to route select filter from OSPF and RIP;
route fixed false route type detection as blackhole;
route fixed log messages when changing routing configuration;
route made export run faster on tables with a large number of dynamic routes;
route provide more detailed information about prefixes when using "discourse" tool;
route-filter fixed route select filter rules;
routing moved "/interface bgp vpls" to "/routing bgp vpls" menu;
routing-filter added origin matcher to match for example routes of a specific OSPF instance;
routing-filter fixed regexp community matcher;
routing-filter made "do-jump" work in select rules;
rpki fix potential memory leak;
ssh disable ssh-rsa when strong-crypto=yes and use rsa-sha2-sha256;
ssh fixed host key generation (introduced in v7.3);
ssh implemented "server-sig-algs" extension in order to improve rsa-sha2-sha256 support;
switch disabled second CPU core for CRS328-24P-4S+ device in order to improve SFP+ link stability;
switch fixed multicast flooding when HW offloaded bridge port gets disabled;
system added "shutdown" parameter for reset-configuration (CLI only);
system fixed configuration reset with "run-after-reset" with file stored on ramdisk;
upgrade ignore same version packages during upgrade procedure;
upgrade improved RouterOS upgrade stability with attached USB modem on MIPSBE, SMIPS and MMIPS devices;
vpls improved system stability with enabled connection tracking;
vxlan allow to specify MAC address manually;
w60g fixed interface "reset-configuration" on Cube 60 devices;
w60g improved interface initialization after being inactive for a while;
w60g improved system stability when using mismatched L2MTU between station and AP;
webfig updated WebFig HTML files with the new MikroTik logo and removed Telnet option from index page;
webfig updated link to the WinBox executable;
webfig updated link to the documentation;
wifiwave2 added initial support for roaming (802.11r) between local AP interfaces;
wifiwave2 fixed "frequency-scan" functionality (introduced in v7.3);
wifiwave2 improved WPA3 support stability;
winbox add a log and log-prefix options to IPv6 firewall NAT and mangle rules;
winbox added "name" parameter under "Routing/BGP/Session" menu;
winbox added "to-address" and "to-ports" parameters under "IPv6/Firewall/NAT" menu;
winbox added support for "veth" interface types;
winbox fixed "inactive" flag naming under "MPLS/Local Mapping" menu;
winbox fixed IP/Route and IPv6/Route OSPF type value;
winbox fixed filename dropdown value filtering;
winbox fixed minor typo under "Interface" stats;
winbox fixed units for "reachable-time" parameter under "IPv6/ND" menu;
winbox removed "TLS Host" parameter from "IP/Firewall/NAT" menu;
winbox removed duplicate signal strength column under "Wireless/Registration Table" menu;
winbox removed unused "Apply Changes" button from BGP sessions menu;
wireguard fixed system stability when adding/removing WireGuard interface;
wireless fixed possible traffic flooding to WDS clients when using Nv2 and multicast helper;
x86 fixed Broadcom NIC support;
x86 fixed keep old configuration functionality during x86 setup installation;
x86 improved log warning message on failed downgrade attempt;
x86 removed "hdd-model" information from installation screen;