MikroTik Changelog Tracker

Search changelog entries

6.38.4 Stable 2017-Mar-08 (8 years ago)
Component Change
chr fixed problem when transmit speed was reduced by interface queues;
dhcpv6-server require "address-pool" to be specified;
export do not show "read-only" IRQ entries;
filesystem implemented procedures to verify and restore internal file structure integrity upon upgrading;
firewall do not allow to set "time" parameter to 0s for "limit" option;
hotspot fixed redirect to URL where escape characters are used (requires newly generated HTML files);
hotspot show Host table commentaries also in Active tab and vice versa;
ike1 fixed “xauth” Radius login;
ike2 also kill IKEv2 connections on proposal change;
ike2 always limit empty remote selector;
ike2 fixed proposal change crash;
ike2 fixed responder subsequent new child creation when PFS is used;
ike2 fixed responder TS updating on wild match;
ipsec deducted policy SA src/dst address from src/dst address;
ipsec do not require "sa-dst-address" if "action=none" or "action=discard";
ipsec fixed SA address check in policy lookup;
ipsec hide SA address for transport policies;
ipsec keep policy in kernel even with bad proposal;
ipsec kill ph2 on policy removal;
ipsec updated/fixed Radius attributes;
irq properly detect all IRQ entries;
l2tp-client fixed IPSec policy generation after reboot;
l2tp-client require working IPSec encryption if "use-ipsec=yes";
lcd show fan2 speed only if it is available;
profile classify ethernet driver activity properly in ARM architecture;
snmp added SSID to CAPsMAN registration table;
snmp fixed "/tool snmp-get" crash on session timeout;
snmp fixed CAPsMAN registration table OID print;
snmp fixed situation when SNMP could not read "/system health" values after reboot;
userman allow access to User Manager users page only through "/user" URL;
userman show warning when no users are selected for CSV file generation;
winbox do not hide "power-cycle-after" option;
winbox hide advertise tab in Hotspot user profile configuration if "transparent-proxy" is not enabled;
winbox make "power-cycle-interval" not to depend on "power-cycle-ping-enabled" in PoE settings;
winbox properly show BGP communities in routing filters table filter;
wireless fixed scan tool stuck in background;
wireless improved compatibility with Intel 2200BG wireless card;
6.38.3 Stable 2017-Feb-07 (8 years ago)
Component Change
bridge do not add dynamic hardware STP ports if “master-port” is not capable of hardware STP;
bridge fixed rare crash when hardware STP capable interface gets new “master-port” which already is in bridge;
bridge fixed rare situation when port flapping occurs on bridge ports;
bridge fixed STP/RSTP packet receive on all types of bridge ports;
bridge minor improvements in performance when "master-port" is bridge port;
capsman fixed SGI (Short Guard Interval) support;
dhcp do not listen on IPv4/IPv6 client to IPv6 MLD packets;
dude (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116356);
firewall added "fasttrack" dummy rule to "/ip firewall raw" table;
firewall do not show IPv4 “fastpath” as active if “route-cache” is disabled;
firewall fixed import of exported configuration that had updated "limit" setting;
graphing fixed graphing crash when high amount of traffic is processed;
hotspot fixed rare kernel crash on multicore systems;
ike1 fixed responder xauth trailing null;
leds fixed defaults for RBSXT5HacD2nr2;
mmips improved general stability;
rb3011 fixed noise from buzzer after silent boot;
switch fixed crash when trying to configure second master port on the same chipset (RB3011, RB2011, CCR1009-8G-1S+);
usb added missing USB ethernet drivers to arm & tile architecture;
winbox added "add-relay-info" and "relay-info-remote-id" to DHCP relay;
winbox added H flag to "/ip arp" ;
winbox added missing "use-fan2" and "active-fan2" to "/system health";
winbox allow shorten bytes to k,M,G in bridge firewall just like in “/ip firewall”;
winbox do not hide 00:00:00:00:00:00 MAC address in unpublished ARPs;
winbox fixed matching "connection-state=untracked" connections;
winbox fixed typo in “/system resources pci” list;
winbox make "power-cycle-after" show correct value;
winbox updated fan management menu;
wireless added "station-roaming" setting;
wireless update Thailand country frequency settings;
6.38.2 Stable 2017-Jan-17 (9 years ago)
Component Change
general factory only release;
6.37.4 Long-term 2017-Jan-13 (9 years ago)
Component Change
bonding fixed "tx-drop" on VLAN over bonding on x86;
certificates added year cap (invalid-after date will not exceed year 2039);
certificates fixed crash when crl is removed while it is being fetched;
certificates fixed fail on import from CAPs when both key and name already exist;
crs added comment ability in more switch menus;
dhcpv6-client fixed DHCPv6 rebind on startup;
dhcpv6-server fixed server removal crash if static binding was present;
dns fixed typo in regexp error message;
dude (changes here: http://wiki.mikrotik.com/wiki/Manual:The_Dude_v6/dude_v6.xx_changelog);
export updated default values to clean up export compact;
fan improved RPM monitor on CCR1009;
firewall do not defragment packets which are marked with "notrack" in raw firewall;
firewall fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
firewall fixed dynamic raw rule behaviour;
firewall fixed rule activation if "time" option is used and no other active rules are present;
firewall nat action "netmap" now requires to-addresses to be specified;
health report fan speed for RB800 and RB1100 when 3-pin fan is being used;
hotspot fixed nat rule port setting in "hs-unauth-to" chain by changing it from "dst-port" to "src-port" on Walled Garden ip "return" rules;
ipsec fixed kernel failure on tile with sha256 when hardware encryption is not being used;
ipv6 added warning about having interface MTU less than minimal IPv6 packet fragment (1280);
ipv6 moved empty IPv6 pool error message to error topic;
led fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
license fixed demo license expiration after installation on x86;
log improved firewall log messages when NAT has changed only connection ports;
lte increased delay when setting sms send mode;
metarouter fixed startup process (introduced in 6.37.2);
ppp fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
ppp significantly improved shutdown speed on servers with many active tunnels;
ppp significantly improved tunnel termination process on servers with many active tunnels;
profile added "bfd" and "remote-access" processes;
profile added ability to monitor cpu usage per core;
profile make profile work on mmips devices;
profile properly classify "wireless" processes;
proxy fixed "max-cache-object-size" export;
proxy speed-up almost empty disk cache clean-up;
queue fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
quickset various small changes;
rb750Gr3 fixed ipsec with 3des+md5 to work on this board;
rb751u fixed ethernet LEDs;
snmp always report bonding speed as speed from first bonding slave;
snmp fixed rare crash when incorrectly formatted packet was received;
ssh fixed high memory consumption when transferring file over ssh tunnel;
switch fix BPDU dynamic Host table entry on Atheros Gigabit switch chips;
time updated time zones;
traceroute fixed memory leak;
trafficgen fixed compact export when "header-stack" includes tcp;
vlan allow to add multiple VLANs which name starts with same number and has same length;
vrrp do not show unrelated log warning messages about version mismatch;
watchdog do not send supout file if "auto-send-supout" is disabled;
webfig added extra protection against XSS exploits;
webfig show properly interface last-link-up/down times;
webfig show properly large BGP AS numbers;
winbox added "Complete" flag to arp table;
winbox added "make-static" to IPv6 DHCP server bindings;
winbox added "prefix-pool" to DHCPv6 server binding;
winbox added upstream flag to IGMP proxy interfaces;
winbox allow to enable/disable traffic flow targets;
winbox allow to specify "connection-bytes" & "connection-rate" for any protocol in “/ip firewall” rules;
winbox allow to specify "sip-timeout" under ip firewall service-ports;
winbox do not allow to set "loop-protect-send-interval" to 0s;
winbox do not create empty rates.vht-basic/supported-mcs if not specified in CAPsMAN;
winbox fixed crash when legacy Winbox version was used;
winbox fixed default values for interface "loop-protect-disable-time" and "loop-protect-send-interval";
winbox fixed missing "IPv6/Settings" menu;
winbox fixed typo in "propagate-ttl" setting;
winbox properly show VHT basic and supported rates in CAPsMAN;
winbox show all related HT tab settings in 2GHz-g/n mode;
winbox show dynamic IPv6 pools properly;
winbox show errors on IPv6 addresses;
winbox show proper ipv6 connection timeout;
winbox specify metric for “/ip dns cache-used” setting;
wireless fixed full "spectral-history" header print on AP modes;
wireless fixed upgrade from older wireless packages when AP interface had empty SSID;
wireless show comment on "security-profile" if it is set;
6.38.1 Stable 2017-Jan-13 (9 years ago)
Component Change
bridge disallow manual removal of dynamic bridge ports;
bridge fixed MAC address learning from switch master-port;
bridge fixed access loss to device through bridge if master port had a loop (introduced in v6.38);
certificate added year cap (invalid-after date will not exceed year 2039);
certificate fixed fail on import from CAPs when both key and name already exist;
dhcpv6-client fixed DHCPv6 rebind on startup;
dhcpv6-server fixed server removal crash if static binding was present;
dns fixed typo in regexp error message;
dude (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=21&t=116356);
fan improved RPM monitor on CCR1009;
firewall nat action "netmap" now requires to-addresses to be specified;
health report fan speed for RB800 and RB1100 when 3-pin fan is being used;
ike1 fixed ph1 rekey in setups with mode-cfg;
ike2 allow empty selectors to reach policy handler;
ike2 auto-negotiate split nets;
ike2 default to tunnel mode in setups without policy;
ike2 fixed error packet from initiator on responder reply;
ike2 fixed initiator TS updating;
ike2 fixed ph1 initial-contact rare desync;
ike2 fixed policy setting for /0 selector with different address families;
ike2 fixed split policy active flag;
ike2 fixed traffic selector prefix calculation;
ike2 fixed xauth add check;
ike2 include identity in peer address info;
ike2 log empty TS payload;
ike2 minor logging update;
ike2 show peer identity of connected peers;
ike2 traffic selector improvements;
ike2 update also local port when peer changes port;
ike2 use first split net for empty TS;
ike2 use standard retransmission timers for DPD;
ike2 xauth like auth method with user support;
ipsec added ability to kill particular remote-peer;
ipsec fixed flush speed and SAs on startup;
ipsec fixed peer port export;
ipsec port is used only for initiators;
ipv6 added warning about having interface MTU less than minimal IPv6 packet fragment (1280);
license fixed demo license expiration after installation on x86;
log improved firewall log messages when NAT has changed only connection ports;
logs work on false CPU/RAM overclocked alarms;
mpls fixed crash on active tunnel loss in MPLS TE setups;
ovpn fixed address acquisition when ovpn-in interface becomes slave;
proxy fixed "max-cache-object-size" export;
proxy speed-up almost empty disk cache clean-up;
quickset various small changes;
rb751u fixed ethernet LEDs (broken since 6.38rc16);
ssh fixed high memory consumption when transferring file over ssh tunnel;
webfig show properly large BGP AS numbers;
winbox added "make-static" to IPv6 DHCP server bindings;
winbox added "prefix-pool" to DHCPv6 server binding;
winbox added IPsec to radius services;
winbox added upstream flag to IGMP proxy interfaces;
winbox allow to specify "connection-bytes" & "connection-rate" for any protocol in “/ip firewall” rules;
winbox allow to specify "sip-timeout" under ip firewall service-ports;
winbox do not create empty rates.vht-basic/supported-mcs if not specified in CAPsMAN;
winbox hide "nat-traversal" setting in IPsec peer if IKEv2 is selected;
winbox show dynamic IPv6 pools properly;
winbox show errors on IPv6 addresses;
winbox specify metric for “/ip dns cache-used” setting;
wireless show comment on "security-profile" if it is set;