Search changelog entries
| Component | Change |
|---|---|
| chr | fixed problem when transmit speed was reduced by interface queues; |
| dhcpv6-server | require "address-pool" to be specified; |
| export | do not show "read-only" IRQ entries; |
| filesystem | implemented procedures to verify and restore internal file structure integrity upon upgrading; |
| firewall | do not allow to set "time" parameter to 0s for "limit" option; |
| hotspot | fixed redirect to URL where escape characters are used (requires newly generated HTML files); |
| hotspot | show Host table commentaries also in Active tab and vice versa; |
| ike1 | fixed “xauth” Radius login; |
| ike2 | also kill IKEv2 connections on proposal change; |
| ike2 | always limit empty remote selector; |
| ike2 | fixed proposal change crash; |
| ike2 | fixed responder subsequent new child creation when PFS is used; |
| ike2 | fixed responder TS updating on wild match; |
| ipsec | deducted policy SA src/dst address from src/dst address; |
| ipsec | do not require "sa-dst-address" if "action=none" or "action=discard"; |
| ipsec | fixed SA address check in policy lookup; |
| ipsec | hide SA address for transport policies; |
| ipsec | keep policy in kernel even with bad proposal; |
| ipsec | kill ph2 on policy removal; |
| ipsec | updated/fixed Radius attributes; |
| irq | properly detect all IRQ entries; |
| l2tp-client | fixed IPSec policy generation after reboot; |
| l2tp-client | require working IPSec encryption if "use-ipsec=yes"; |
| lcd | show fan2 speed only if it is available; |
| profile | classify ethernet driver activity properly in ARM architecture; |
| snmp | added SSID to CAPsMAN registration table; |
| snmp | fixed "/tool snmp-get" crash on session timeout; |
| snmp | fixed CAPsMAN registration table OID print; |
| snmp | fixed situation when SNMP could not read "/system health" values after reboot; |
| userman | allow access to User Manager users page only through "/user" URL; |
| userman | show warning when no users are selected for CSV file generation; |
| winbox | do not hide "power-cycle-after" option; |
| winbox | hide advertise tab in Hotspot user profile configuration if "transparent-proxy" is not enabled; |
| winbox | make "power-cycle-interval" not to depend on "power-cycle-ping-enabled" in PoE settings; |
| winbox | properly show BGP communities in routing filters table filter; |
| wireless | fixed scan tool stuck in background; |
| wireless | improved compatibility with Intel 2200BG wireless card; |
| Component | Change |
|---|---|
| bridge | do not add dynamic hardware STP ports if “master-port” is not capable of hardware STP; |
| bridge | fixed rare crash when hardware STP capable interface gets new “master-port” which already is in bridge; |
| bridge | fixed rare situation when port flapping occurs on bridge ports; |
| bridge | fixed STP/RSTP packet receive on all types of bridge ports; |
| bridge | minor improvements in performance when "master-port" is bridge port; |
| capsman | fixed SGI (Short Guard Interval) support; |
| dhcp | do not listen on IPv4/IPv6 client to IPv6 MLD packets; |
| dude | (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116356); |
| firewall | added "fasttrack" dummy rule to "/ip firewall raw" table; |
| firewall | do not show IPv4 “fastpath” as active if “route-cache” is disabled; |
| firewall | fixed import of exported configuration that had updated "limit" setting; |
| graphing | fixed graphing crash when high amount of traffic is processed; |
| hotspot | fixed rare kernel crash on multicore systems; |
| ike1 | fixed responder xauth trailing null; |
| leds | fixed defaults for RBSXT5HacD2nr2; |
| mmips | improved general stability; |
| rb3011 | fixed noise from buzzer after silent boot; |
| switch | fixed crash when trying to configure second master port on the same chipset (RB3011, RB2011, CCR1009-8G-1S+); |
| usb | added missing USB ethernet drivers to arm & tile architecture; |
| winbox | added "add-relay-info" and "relay-info-remote-id" to DHCP relay; |
| winbox | added H flag to "/ip arp" ; |
| winbox | added missing "use-fan2" and "active-fan2" to "/system health"; |
| winbox | allow shorten bytes to k,M,G in bridge firewall just like in “/ip firewall”; |
| winbox | do not hide 00:00:00:00:00:00 MAC address in unpublished ARPs; |
| winbox | fixed matching "connection-state=untracked" connections; |
| winbox | fixed typo in “/system resources pci” list; |
| winbox | make "power-cycle-after" show correct value; |
| winbox | updated fan management menu; |
| wireless | added "station-roaming" setting; |
| wireless | update Thailand country frequency settings; |
| Component | Change |
|---|---|
| general | factory only release; |
| Component | Change |
|---|---|
| bonding | fixed "tx-drop" on VLAN over bonding on x86; |
| certificates | added year cap (invalid-after date will not exceed year 2039); |
| certificates | fixed crash when crl is removed while it is being fetched; |
| certificates | fixed fail on import from CAPs when both key and name already exist; |
| crs | added comment ability in more switch menus; |
| dhcpv6-client | fixed DHCPv6 rebind on startup; |
| dhcpv6-server | fixed server removal crash if static binding was present; |
| dns | fixed typo in regexp error message; |
| dude | (changes here: http://wiki.mikrotik.com/wiki/Manual:The_Dude_v6/dude_v6.xx_changelog); |
| export | updated default values to clean up export compact; |
| fan | improved RPM monitor on CCR1009; |
| firewall | do not defragment packets which are marked with "notrack" in raw firewall; |
| firewall | fixed "time" option by recognizing weekday properly (introduced in v6.37.2); |
| firewall | fixed dynamic raw rule behaviour; |
| firewall | fixed rule activation if "time" option is used and no other active rules are present; |
| firewall | nat action "netmap" now requires to-addresses to be specified; |
| health | report fan speed for RB800 and RB1100 when 3-pin fan is being used; |
| hotspot | fixed nat rule port setting in "hs-unauth-to" chain by changing it from "dst-port" to "src-port" on Walled Garden ip "return" rules; |
| ipsec | fixed kernel failure on tile with sha256 when hardware encryption is not being used; |
| ipv6 | added warning about having interface MTU less than minimal IPv6 packet fragment (1280); |
| ipv6 | moved empty IPv6 pool error message to error topic; |
| led | fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting); |
| license | fixed demo license expiration after installation on x86; |
| log | improved firewall log messages when NAT has changed only connection ports; |
| lte | increased delay when setting sms send mode; |
| metarouter | fixed startup process (introduced in 6.37.2); |
| ppp | fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows); |
| ppp | significantly improved shutdown speed on servers with many active tunnels; |
| ppp | significantly improved tunnel termination process on servers with many active tunnels; |
| profile | added "bfd" and "remote-access" processes; |
| profile | added ability to monitor cpu usage per core; |
| profile | make profile work on mmips devices; |
| profile | properly classify "wireless" processes; |
| proxy | fixed "max-cache-object-size" export; |
| proxy | speed-up almost empty disk cache clean-up; |
| queue | fixed "time" option by recognizing weekday properly (introduced in v6.37.2); |
| quickset | various small changes; |
| rb750Gr3 | fixed ipsec with 3des+md5 to work on this board; |
| rb751u | fixed ethernet LEDs; |
| snmp | always report bonding speed as speed from first bonding slave; |
| snmp | fixed rare crash when incorrectly formatted packet was received; |
| ssh | fixed high memory consumption when transferring file over ssh tunnel; |
| switch | fix BPDU dynamic Host table entry on Atheros Gigabit switch chips; |
| time | updated time zones; |
| traceroute | fixed memory leak; |
| trafficgen | fixed compact export when "header-stack" includes tcp; |
| vlan | allow to add multiple VLANs which name starts with same number and has same length; |
| vrrp | do not show unrelated log warning messages about version mismatch; |
| watchdog | do not send supout file if "auto-send-supout" is disabled; |
| webfig | added extra protection against XSS exploits; |
| webfig | show properly interface last-link-up/down times; |
| webfig | show properly large BGP AS numbers; |
| winbox | added "Complete" flag to arp table; |
| winbox | added "make-static" to IPv6 DHCP server bindings; |
| winbox | added "prefix-pool" to DHCPv6 server binding; |
| winbox | added upstream flag to IGMP proxy interfaces; |
| winbox | allow to enable/disable traffic flow targets; |
| winbox | allow to specify "connection-bytes" & "connection-rate" for any protocol in “/ip firewall” rules; |
| winbox | allow to specify "sip-timeout" under ip firewall service-ports; |
| winbox | do not allow to set "loop-protect-send-interval" to 0s; |
| winbox | do not create empty rates.vht-basic/supported-mcs if not specified in CAPsMAN; |
| winbox | fixed crash when legacy Winbox version was used; |
| winbox | fixed default values for interface "loop-protect-disable-time" and "loop-protect-send-interval"; |
| winbox | fixed missing "IPv6/Settings" menu; |
| winbox | fixed typo in "propagate-ttl" setting; |
| winbox | properly show VHT basic and supported rates in CAPsMAN; |
| winbox | show all related HT tab settings in 2GHz-g/n mode; |
| winbox | show dynamic IPv6 pools properly; |
| winbox | show errors on IPv6 addresses; |
| winbox | show proper ipv6 connection timeout; |
| winbox | specify metric for “/ip dns cache-used” setting; |
| wireless | fixed full "spectral-history" header print on AP modes; |
| wireless | fixed upgrade from older wireless packages when AP interface had empty SSID; |
| wireless | show comment on "security-profile" if it is set; |
| Component | Change |
|---|---|
| bridge | disallow manual removal of dynamic bridge ports; |
| bridge | fixed MAC address learning from switch master-port; |
| bridge | fixed access loss to device through bridge if master port had a loop (introduced in v6.38); |
| certificate | added year cap (invalid-after date will not exceed year 2039); |
| certificate | fixed fail on import from CAPs when both key and name already exist; |
| dhcpv6-client | fixed DHCPv6 rebind on startup; |
| dhcpv6-server | fixed server removal crash if static binding was present; |
| dns | fixed typo in regexp error message; |
| dude | (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116356); |
| fan | improved RPM monitor on CCR1009; |
| firewall | nat action "netmap" now requires to-addresses to be specified; |
| health | report fan speed for RB800 and RB1100 when 3-pin fan is being used; |
| ike1 | fixed ph1 rekey in setups with mode-cfg; |
| ike2 | allow empty selectors to reach policy handler; |
| ike2 | auto-negotiate split nets; |
| ike2 | default to tunnel mode in setups without policy; |
| ike2 | fixed error packet from initiator on responder reply; |
| ike2 | fixed initiator TS updating; |
| ike2 | fixed ph1 initial-contact rare desync; |
| ike2 | fixed policy setting for /0 selector with different address families; |
| ike2 | fixed split policy active flag; |
| ike2 | fixed traffic selector prefix calculation; |
| ike2 | fixed xauth add check; |
| ike2 | include identity in peer address info; |
| ike2 | log empty TS payload; |
| ike2 | minor logging update; |
| ike2 | show peer identity of connected peers; |
| ike2 | traffic selector improvements; |
| ike2 | update also local port when peer changes port; |
| ike2 | use first split net for empty TS; |
| ike2 | use standard retransmission timers for DPD; |
| ike2 | xauth like auth method with user support; |
| ipsec | added ability to kill particular remote-peer; |
| ipsec | fixed flush speed and SAs on startup; |
| ipsec | fixed peer port export; |
| ipsec | port is used only for initiators; |
| ipv6 | added warning about having interface MTU less than minimal IPv6 packet fragment (1280); |
| license | fixed demo license expiration after installation on x86; |
| log | improved firewall log messages when NAT has changed only connection ports; |
| logs | work on false CPU/RAM overclocked alarms; |
| mpls | fixed crash on active tunnel loss in MPLS TE setups; |
| ovpn | fixed address acquisition when ovpn-in interface becomes slave; |
| proxy | fixed "max-cache-object-size" export; |
| proxy | speed-up almost empty disk cache clean-up; |
| quickset | various small changes; |
| rb751u | fixed ethernet LEDs (broken since 6.38rc16); |
| ssh | fixed high memory consumption when transferring file over ssh tunnel; |
| webfig | show properly large BGP AS numbers; |
| winbox | added "make-static" to IPv6 DHCP server bindings; |
| winbox | added "prefix-pool" to DHCPv6 server binding; |
| winbox | added IPsec to radius services; |
| winbox | added upstream flag to IGMP proxy interfaces; |
| winbox | allow to specify "connection-bytes" & "connection-rate" for any protocol in “/ip firewall” rules; |
| winbox | allow to specify "sip-timeout" under ip firewall service-ports; |
| winbox | do not create empty rates.vht-basic/supported-mcs if not specified in CAPsMAN; |
| winbox | hide "nat-traversal" setting in IPsec peer if IKEv2 is selected; |
| winbox | show dynamic IPv6 pools properly; |
| winbox | show errors on IPv6 addresses; |
| winbox | specify metric for “/ip dns cache-used” setting; |
| wireless | show comment on "security-profile" if it is set; |