Search changelog entries
| Component | Change |
|---|---|
| general | updated timezone information; |
| general | many fixes for CRS managed switch functionality - particularly improved VLAN support, port isolation, defaults; |
| general | added trunk support for CRS switches; |
| general | added policing support for CRS switches; |
| ipsec | support IPv4 over IPv6 and vice versa; |
| l2tp | fixed "no buffer space available" problem; |
| lte | provide signal strength using snmp and make 'info once' work in console; |
| pppoe | report correctly number of active links; |
| www | added support for HTTP byte ranges; |
| Component | Change |
|---|---|
| console | no longer required to supply value of '/routing bgp instance vrf' property 'instance' for 'add' command; |
| dhcp | added support for DHCP option 138 - list of CAPWAP IPv4 servers; |
| ethernet | added option to enable rx/tx flow control (will be disabled by default); |
| ethernet | added ability to specify advertised modes for copper ports; |
| general | fixed 100% cpu usage on CCRs; |
| ipsec | fix aes-cbc hardware acceleration on CCR with key sizes 192 and 256; |
| lte | support for Huawei ME609 and ME909u-521; |
| ovpn | fixed TLS renegotiation; |
| ovpn | make bridge mode work with big packets (do not leave extraneous padding); |
| ovpn | fixed require-client-certifcate; |
| ppp | revert RADIUS NAS-Port behaviour, report tunnel interface id; |
| ppp | mppe encryption together with mrru locked the router; |
| quickset | added Guest Network setup to Home AP mode; |
| ssl | not finding CRL in local store for any certificate in trust chain will cause connection to fail; |
| wireless | add auto frequency feature; |
| Component | Change |
|---|---|
| bgp | multipath eBGP now does not propagate BGP nexthop unless forced in configuration; |
| general | fix autosupout.rif generation after kernel panic; |
| general | removed 10/100 half duplex from autonegotiation advertisement on CCR; |
| ipv6 pool | fix dynamic prefix disappearing which may influence large VPNs with IPv6; |
| ovpn | make it work again; |
| ovpn client | remove cipher=any %26 auth=any options, protocol does not support them; |
| pptp | fixed where Windows %26 MacOS clients were disconnecting all the time; |
| ssh client | fix key agreement when sometimes wrong DH algorithm was selected; |
| sstp | make it work with Windows client with AES encryption; |
| Component | Change |
|---|---|
| address-list | allow manually adding timeoutable entries; |
| address-list | show dynamic entry timeout; |
| certificate | support ip, dns and email subject alternative names; |
| dhcpv4 server | added REMOTE_ID option variable for relayed packets; |
| fixed l2mtu changing on CCRs | could cause port flapping; |
| fixed port flapping on CCR | could happen when having other than only-hardware-queue interface queue. Note that having other interface queue than only-hardware-queue dramatically reduces performace, so should be avoided if possible; |
| general | support Android usb tethering interface; |
| general | fixed hairpin nat on bridge with use-ip-firewall=yes; |
| general | fixed vlan on bridge after reboot having 00:00:00:00:00:00 mac address; |
| general | disabling/enabling ethernet ports did not work properly on CCRs, could cause port flapping; |
| ipsec | added aes-gcm icv16 encryption mode; |
| ipsec | added aes-ctr encryption mode; |
| ipsec | added sha256 and sha512 support; |
| ipsec | proposal defaults changed to aes-128 and sha1 for both phase1 and phase2; |
| ipsec | fix policy bypass on IPv6 gre, ipip, eoip tunnels when policy uses protocol filter; |
| leds | inverted modem signal trigger, now it will trigger when the signal level rises above the treshold; |
| poe | new poe controller firmware for RB750UP and OmniTIK UPA; |
| userman | fix crash on tilera; |
| wireless | improve rate selection for nstreme protocol |