Component: firewall
254 changelog entries across 113 version(s)
Releases by channel (stacked)
- always show "passthrough" when exporting mangle table;
- detect VRF addresses as local;
- allow in-interface/in-bridge-port/in-bridge matching in postrouting chains;
- fixed incorrectly inverted hotspot value configuration;
- increased maximum connection tracking entry count based on device total RAM size;
- allow in-interface/in-bridge-port/in-bridge matching in postrouting chains;
- fixed incorrectly inverted hotspot value configuration;
- increased maximum connection tracking entry count based on device total RAM size;
- added none-dynamic and none-static arguments for IPv6 address-list-timout settings;
- added support for random external port allocation;
- added warning log for TCP SYN flood;
- fixed "dst-limit" and "limit" mathers when using zero value for burst argument;
- improved matching from deeply nested interface-lists;
- removed default mangle passthrough=yes configuration from export;
- improved matching from deeply nested interface-lists (additional fixes);
- added support for random external port allocation;
- improved matching from deeply nested interface-lists;
- added none-dynamic and none-static arguments for IPv6 address-list-timout settings;
- added warning log for TCP SYN flood;
- fixed "dst-limit" and "limit" mathers when using zero value for burst argument;
- removed default mangle passthrough=yes configuration from export;
- added message when interface belonging to VRF is added in filter rules;
- fixed an issue with unsetting src-address-type;
- fixed IPv6 "nth" matcher showing up twice in help;
- fixed issue that prevents restoring src-address-list and dst-addres-list properties using undo command;
- removed unnecessary TLS host matcher from NAT tables;
- fixed an issue with unsetting src-address-type;
- removed unnecessary TLS host matcher from NAT tables;
- added message when interface belonging to VRF is added in filter rules (additional fixes);
- added message when interface belonging to VRF is added in filter rules;
- fixed IPv6 "nth" matcher showing up twice in help;
- fixed issue that prevents restoring src-address-list and dst-addres-list properties using undo command;
- added "creation-time" parameter for IPv6 address list entries;
- fixed underlying CAPsMAN tunnel reusing packet marks of encapsulated packets;
- fixed underlying VXLAN/EoIP tunnel reusing packet marks of encapsulated packets;
- increased default "udp-timeout" value from 10s to 30s;
- fixed underlying CAPsMAN tunnel reusing packet marks of encapsulated packets;
- fixed underlying VXLAN/EoIP tunnel reusing packet marks of encapsulated packets;
- added "creation-time" parameter for IPv6 address list entries;
- increased default "udp-timeout" value from 10s to 30s;
- added "nat-pmp" support;
- added new IPv6 filter arguments "icmp-err-src-routing-header" and "icmp-headers-too-long" for "reject-with" setting;
- do not mark all IPv6 GRE packets as invalid;
- fixed IPv6 address-list timeout;
- fixed altered address-list when upgrading from RouterOS v6;
- fixed connections being tracked when tracking is disabled;
- removed "prohibited" and "unreachable" IPv4 address-type arguments;
- added "ein-snat" and "ein-dnat" connection NAT state matchers for filter and mangle rules;
- added "nat-pmp" support;
- added new IPv6 filter arguments "icmp-err-src-routing-header" and "icmp-headers-too-long" for "reject-with" setting;
- do not mark all IPv6 GRE packets as invalid;
- fixed altered address-list when upgrading from RouterOS v6;
- fixed connections being tracked when tracking is disabled;
- fixed IPv6 address-list timeout;
- removed "prohibited" and "unreachable" IPv4 address-type arguments;
- added "ein-snat" and "ein-dnat" connection NAT state matchers for filter and mangle rules;
- added warning when PCC divider argument is smaller than remainder;
- fixed mangle "mark-connection" with "passthrough=yes" rule for TCP RST packets;
- improved system stability when using "endpoint-independent-nat";
- improved system stability when using "endpoint-independent-nat";
- fixed IRC NAT helper (CVE-2022-2663);
- added warning when PCC divider argument is smaller than remainder;
- fixed mangle "mark-connection" with "passthrough=yes" rule for TCP RST packets;
- added "endpoint-independent-nat" support;
- added "nth" option for IPv6 firewall;
- fixed IRC NAT helper (CVE-2022-2663);