Search changelog entries
| Component | Change |
|---|---|
| RB911/RB912 | fix SPI bus lock after fast led blink; |
| bonding | add min_links property for 802.3ad mode; |
| bridge | fixed use-ip-firewall-for-vlan in setups with multiple bridges; |
| bridge firewall | add ipv6 src/dst addr, ip protocol, src/dst port matching to bridge firewall; |
| bridge firewall | vlan matchers support service tag - 0x88a8; |
| chr | add hotspot,btest,traffgen support; |
| crs switch | allow to unset port learn-limit, new default is unset to allow more than 1023 hosts per port; |
| firewall | fixed limit and dst-limit options. |
| flash | fix kernel failure (exposed by 6.31); |
| general | revised change that caused reboot by watchdog problems introduced in v6.31; |
| general | certificates -fixed bug where crl stopped working after a while; |
| hotspot | ignore PoD remote requests if no HotSpot configured; |
| hotspot | fix kernel failure when www plugin aborts on broken html source; |
| hotspot | fix html-directory path on small flash devices; |
| ip accounting | fixed kernel crash; |
| ippool6 | try to acquire the same prefix if info matches recently freed; |
| ipsec | added compatibility option skip-peer-id-check; |
| ipsec | fix potential memory leak; |
| ipsec | use local-address for phase 1 matching and initiation; |
| ipsec | fix transport mode ph2 ID ports when policy selects specific ip protocol on initiator; |
| ipv6 | fixed DHCP-PD client skips some steps when renewing lease; |
| lcd | fixed parallel port LCD display support on multi-cpu x86; |
| mipsbe | make system shutdown work again; |
| simple queues | restrict all changes in dynamic simple queues |
| snmp | fix system scripts get; |
| snmp | get vlan speed from master interface; |
| switch | fixed port flapping on switch ports of RB750, RB750UP, RB751U-2HnD and RB951-2N (introduced in 6.31) |
| torch | add invert filter for src/dst/src6/dst6 addresses ; |
| trafflow | added support for IPv6 targets; |
| upnp | fixed protocol port selection for upnp protocol comunications; |
| winbox | fixed wireless interface l2mtu (VirtualAP and WDS interface creation in winbox) |
| winbox | fixed multiple firewall rule moving in Winbox 2 |
| x86 | fixed 32bit multi-cpu kernel support; |
| Component | Change |
|---|---|
| general | Dynamic DNS servers can disappear when "allow-remote-requests" are not enabled |
| Component | Change |
|---|---|
| certificate manager | fixed memory leak |
| general | Dynamic DNS servers can disappear when "allow-remote-requests" are not enabled |
| ipsec | fixed crash in when gcm encryption was used |
| lcd | fix crash (and 100% cpu usage) when interface gets removed from "stats-all" screen |
| pptp & l2tp | fixed problem where android client could not connect if both dns names were not provided (was broken since v6.30); |
| quickset | fixed HomeAP mode known issue: |
| snmp | fix system scripts table |
| tool fetch | fix incomplete ftp download |
| traffic flow | fixed dynamic input/output interface reporting |
| user-manager | fixed username was not shown in /tool user-manager user |
| user-manager | fixed zoom for user-manager homepage when mobile devices used |
| winbox | restrict reversed ranges in dst-port under firewall |
| Component | Change |
|---|---|
| general | trafflow: fix in-interface reporting in flow; |
| general | fixed :execute file= |
| general | bonding: fix arp monitoring in active backup mode |
| ipsec | disallow changing dynamic peer; |
| lte | Fixes bug that causes Sierra Wireless modems with LTE interface to change interface name; |
| quickset | fixed HomeAP mode; |
| quickset | crashes introduced in 6.30 fixed |
| Component | Change |
|---|---|
| api | reduce api tcp connection keepalive delay to 30 seconds, will timeout idle connections in about 5 minutes; |
| ccr | made hardware watchdog work again (was broken since v6.26); |
| console | allow users with 'policy' policy to change script owner; |
| console | values of $".id", $".nextid" and $".dead" are avaliable for use in 'print where' expressions; |
| console | ':execute' command now accepts script source in "{}" braces, like '/system scripts add source=' does; |
| console | ':execute' command now returns internal number of running job, that can be used to check and stop execution. For example: :local j [:execute {/interface print follow where [:log info "$name"]}] :delay 10s :do { /system script job remove $j } on-error={} |
| console | firewall 'print' commands now show all entries including dynamic, 'all' argument now has no effect; |
| fix sending multiple consecutive emails; | |
| fastpath | vlan interfaces support fastpath; |
| fastpath | partial support for bonding interfaces (rx only); |
| fastpath | vrrp interfaces support fastpath; |
| fasttrack | added dummy firewall rule in filter and mangle tables to show packets/bytes that get processed in fasttrack and bypass firewall; |
| firewall | sip helper improved, large packets no longer dropped; |
| firewall | added ipsec-policy matcher to check wheather packet was/will be ipsec processed or not; |
| general | fixed encryption 'out of order' problem on SMP systems; |
| general | fixed router lockup on leap seconds with installed ntp package; |
| general | fixed file transfer on devices with large RAM memory; |
| general | pptp & l2tp & sstp client: support the case were server issues its tunnel ip address the same as its public one; |
| general | removed wireless package from routeros bundle package, new wireless-fp is left in place and wireless-cm2 added as option; |
| general | pptp & l2tp client: when adding default route, add special exception route for a tunnel itself (no need to add it manually anymore); |
| general | improved connection list: added connection packet/byte counters, added separate counters for fasttrack, added current rate display, added flag wheather connection is fasttracked/srcnated/dstnated, removed 2048 connection entry limit; |
| general | fixed memory leak on CCR devices (introduced in 6.28); |
| icmp | use receive interface address when responding with icmp errors; |
| ipsec | fail ph2 negitioation when initiator proposed key length does not match proposal configuration; |
| ipsec | increase replay window to 128; |
| lte | improved modem identification to better support multiple identical modems; |
| possibility to disable route cache | improves DDOS attack handling performance up to 2x (note that ipv4 fastpath depends on route cache); |
| ppp | disable vj tcp header compression; |
| pptp | fixed "encryption got out of sync" problem; |
| snmp | fix system scripts table; |
| ssh | added option '/ip ssh stong-crypto' |
| timezone | updated timezone information to 2015e release; |
| tunnels | eoip, eoipv6, gre,gre6, ipip, ipipv6, 6to4 tunnels have new property - ipsec-secret - for easy setup of ipsec encryption and authentication; |
| wireless | added WMM power save suport for mobile devices; |
| wireless | improve ac radio coexistence with other wireless clients, optimized transmit times to not interfere with other devices; |