Software
 

All current and historical changelogs

Release candidate release tree

  • Release 6.41rc30 2017-09-19

    What's new in 6.41rc30 (2017-Sep-15 11:50):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) crs317 - added L2MTU support;
    *) crs326 - fixed packet processing speed on switch chip if individual port link speed differs;
    *) crs3xx - added port ingress and egress rate limiting;
    *) export - fixed wireless "ssid" and "supplicant-identity" compact export;
    *) ppp - fixed situation when part of PPP configuration was reset to default values after reboot;
    *) wireless - added "allow-signal-out-of-range" option for Access List entries (CLI only);

    Other changes since 6.40.3:

    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    *) address - show warning on IPv6 address when acquire from pool has failed;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) arp - properly update dynamic ARP entries after interface related changes;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter;
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) console - do not stop "/certificate sign" process if console times out in 1 minute;
    *) crs1xx/2xx - fixed 1 Gbps forced mode for several SFP modules;
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) dhcpv6 client - added IAID check in reply;
    *) dhcpv6-client - fixed IA check on solicit when "rapid-commit" is enabled;
    *) dhcpv6-client - ignore unknown IA;
    *) dhcpv6-client - require pool name to be unique;
    *) e-mail - auto complete file name on "file" parameter (introduced in v6.40);
    *) e-mail - do not show errors when sending e-mail from script;
    *) eoip - made L2MTU parameter read-only;
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspot server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike1 - remove PH1 and PH2 when "mode-config" exchange fails;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - kill PH1 on "mode-config" address failure;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in v6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) log - added "bridge" topic;
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration) (CLI only);
    *) lte - added Passthrough support (CLI only);
    *) lte - added support for ZTE ME3630 E1C;
    *) lte - added Yota non-configurable modem support;
    *) lte - fixed mode initialization after reboot;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in v6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) ppp - fixed missing PPP client interface after reboot (introduced in v6.41rc);
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb931-2nd - fixed startup problems (requires additional reboot after upgrade);
    *) routerboard - fixed "/system routerboard upgrade" for CRS212-8G-4S;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sniffer - fixed VLAN tag reporting for TX packets (introduced 6.41rc14);
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) tile - improved reliability on MPLS package processing;
    *) ups - fixed duplicate "failed" UPS logs;
    *) userman - fixed unresponsive RADIUS server (introduced in v6.40.3);
    *) webfig - improved reliability of login process;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated United Kingdom regulatory domain information;

  • Release 6.41rc28 2017-09-12

    What's new in 6.41rc28 (2017-Sep-11 12:37):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) console - do not stop "/certificate sign" process if console times out in 1 minute;
    *) crs317 - added L2MTU support;
    *) crs3xx - added port ingress and egress rate limiting;
    *) log - added "bridge" topic;
    *) lte - added Passthrough support (CLI only);

    Other changes since 6.40.3:

    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    *) address - show warning on IPv6 address when acquire from pool has failed;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) arp - properly update dynamic ARP entries after interface related changes;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter;
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) crs1xx/2xx - fixed 1 Gbps forced mode for several SFP modules;
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) dhcpv6 client - added IAID check in reply;
    *) dhcpv6-client - fixed IA check on solicit when "rapid-commit" is enabled;
    *) dhcpv6-client - ignore unknown IA;
    *) dhcpv6-client - require pool name to be unique;
    *) e-mail - auto complete file name on "file" parameter (introduced in v6.40);
    *) e-mail - do not show errors when sending e-mail from script;
    *) eoip - made L2MTU parameter read-only;
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspot server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike1 - remove PH1 and PH2 when "mode-config" exchange fails;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - kill PH1 on "mode-config" address failure;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in v6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration) (CLI only);
    *) lte - added support for ZTE ME3630 E1C;
    *) lte - added Yota non-configurable modem support;
    *) lte - fixed mode initialization after reboot;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in v6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) ppp - fixed missing PPP client interface after reboot (introduced in v6.41rc);
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb931-2nd - fixed startup problems (requires additional reboot after upgrade);
    *) routerboard - fixed "/system routerboard upgrade" for CRS212-8G-4S;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sniffer - fixed VLAN tag reporting for TX packets (introduced 6.41rc14);
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) tile - improved reliability on MPLS package processing;
    *) ups - fixed duplicate "failed" UPS logs;
    *) userman - fixed unresponsive RADIUS server (introduced in v6.40.3);
    *) webfig - improved reliability of login process;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated United Kingdom regulatory domain information;

  • Release 6.41rc26 2017-09-08

    What's new in 6.41rc26 (2017-Sep-07 13:26):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) chr - added KVM memory balloon support;
    *) chr - added suspend support;
    *) crs1xx/2xx - fixed 1 Gbps forced mode for several SFP modules;
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) dhcp - fixed unresponsive DHCP service caused by inability to read not set RAW options;
    *) e-mail - auto complete file name on "file" parameter (introduced in v6.40);
    *) eoip - made L2MTU parameter read-only;
    *) hotspot - fixed missing "/ip hotspot server profile" if invalid "dns-name" was specified;
    *) lte - added Passthrough support (CLI only);
    *) lte - added support for ZTE ME3630 E1C;
    *) lte - fixed mode initialization after reboot;
    *) ppp - fixed missing PPP client interface after reboot (introduced in v6.41rc);
    *) rb931-2nd - fixed startup problems (requires additional reboot after upgrade);
    *) userman - fixed unresponsive RADIUS server (introduced in v6.40.3);
    *) webfig - improved reliability of login process;

    Other changes since 6.40.3:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    *) address - show warning on IPv6 address when acquire from pool has failed;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) arp - properly update dynamic ARP entries after interface related changes;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter;
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) bridge - show bridge interface local addresses in the host table;
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv4-client - allow to use DUID for client as identity string as the option 61;
    *) dhcpv6 client - added IAID check in reply;
    *) dhcpv6-client - fixed IA check on solicit when "rapid-commit" is enabled;
    *) dhcpv6-client - ignore unknown IA;
    *) dhcpv6-client - require pool name to be unique;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed interface list export;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike1 - remove PH1 and PH2 when "mode-config" exchange fails;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - kill PH1 on "mode-config" address failure;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in v6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration) (CLI only);
    *) lte - added Yota non-configurable modem support;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in v6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) routerboard - fixed "/system routerboard upgrade" for CRS212-8G-4S;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sniffer - fixed VLAN tag reporting for TX packets (introduced 6.41rc14);
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) tile - improved reliability on MPLS package processing;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated United Kingdom regulatory domain information;

  • Release 6.41rc23 2017-09-04

    What's new in 6.41rc23 (2017-Sep-04 09:07):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) address - show warning on IPv6 address when acquire from pool has failed;
    *) bridge - fixed connectivity issues when there are multiple VLAN interfaces on bridge;
    *) bridge - show bridge interface local addresses in the host table;
    *) crs317 - added initial support for HW offloaded MPLS forwarding;
    *) dhcp - fixed DHCP services failing after reboot when DHCP option was used;
    *) dhcpv4-client - allow to use DUID for client ID;
    *) dhcpv6-client - require pool name to be unique;
    *) routerboard - fixed "/system routerboard upgrade" for CRS212-8G-4S;

    Other changes since 6.40.3:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) arp - properly update dynamic ARP entries after interface related changes;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter;
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv6 client - added IAID check in reply;
    *) dhcpv6-client - fixed IA check on solicit when "raoud-commit" is enabled;
    *) dhcpv6-client - ignore unknown IA;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspost server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike1 - remove PH1 and PH2 when "mode-config" exchange fails;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - kill PH1 on "mode-config" address failure;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration) (CLI only);
    *) lte - added Passthrough support (CLI only);
    *) lte - added Yota non-configurable modem support;
    *) lte - fixed mode initialization after reboot;
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in 6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) sniffer - fixed VLAN tag reporting for TX packets (introduced 6.41rc14);
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) tile - improved reliability on MPLS package processing;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated United Kingdom regulatory domain information;

  • Release 6.41rc21 2017-09-01

    What's new in 6.41rc21 (2017-Sep-01 08:56):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - properly update dynamic ARP entries after interface related changes;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "master-port" parameter;
    *) ike1 - remove PH1 and PH2 when "mode-config" exchange fails;
    *) interface - added "/interface reset-counters" command (CLI only);
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) lcd - fixed "flip-screen=yes" state after reboot;
    *) lte - added "/interface lte apn" menu (Passthrough requires reconfiguration) (CLI only);
    *) lte - added Yota non-configurable modem support;
    *) lte - fixed mode initialization after reboot;
    *) sniffer - fixed VLAN tag reporting for TX packets (introduced 6.41rc14);
    *) tile - improved reliability on MPLS package processing;
    *) wireless - pass interface MAC address in Sniffer TZSP frames;
    *) wireless - updated United Kingdom regulatory domain information;

    Other changes since 6.40.3:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv6 client - added IAID check in reply;
    *) dhcpv6-client - fixed IA check on solicit when "raoud-commit" is enabled;
    *) dhcpv6-client - ignore unknown IA;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspost server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - kill PH1 on "mode-config" address failure;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added Passthrough support (CLI only);
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in 6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;

  • Release 6.41rc20 2017-08-29

    What's new in 6.41rc20 (2017-Aug-29 06:41):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option;
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx;
    *) bridge - fixed "fast-forward" counters;
    *) bridge - implemented software based "igmp-snooping";
    *) bridge - implemented software based MSTP;
    *) bridge - removed "master-port" parameter;
    *) dhcpv6 client - added IAID check in reply;
    *) dhcpv6-client - fixed IA check on solicit when "raoud-commit" is enabled;
    *) dhcpv6-server - do not release address of static binding from pool after server removal;
    *) export - fixed export for PoE-OUT related settings;
    *) ipsec - kill PH1 on "mode-config" address failure;
    *) led - fixed RB711UA ether1 LED (introduced in v6.38rc16);
    *) lte - added Passthrough support (CLI only);
    *) lte - integrated IP address acquisition without DHCP client for wAP LTE kit-US;
    *) userman - fixed "limitation" and "profile-limitation" update;
    *) userman - fixed CoA packet processing after changes in "/tool user-manager router" configuration;

    Other changes since 6.40.2:

    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - changed "Host" and "MDB" table column order;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv6-client - ignore unknown IA;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed "/system routerboard" export (introduced in 6.40.1);
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspost server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - fixed initiator ID comparison to NAT-OA;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) led - fixed "on" and "off" triggers when multiple LEDs are selected;
    *) log - optimized "poe-out" logging topic logs;
    *) lte - do not show USB LTE modem under "/port" menu (introduced in 6.41rc);
    *) lte - improved reliability of USB LTE modems;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in 6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) poe-out - fixed router reboot after "poe-out-status" changes;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb1100ahx4 - fixed HW acceleration fragmented packet decryption when fragment is smaller than 64 bytes;
    *) rb750gr3 - show warning and do not allow to use "protected-bootloader" feature if "factory-firmware" older than 3.34.4 version;
    *) routerboard - added "mode-button" support for RB750Gr3 (CLI only);
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) ssh - do not execute command if it starts with "-" symbol;
    *) traffic-flow - fixed reboots when IPv6 address has been set as target address without active IPv6 package;
    *) ups - fixed duplicate "failed" UPS logs;
    *) webfig - allow to open table entry even if table is not sorted by # (introduced in v6.40);
    *) webfig - allow to unset "rate-limit" for DHCP leases;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - added possibility to define "comment" for "/routing bgp network" entries;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - do not show FAN related information under "/system health" menu for devices which does not have it;
    *) winbox - do not show LCD menu for devices which does not have it;
    *) winbox - fixed ARP table update after entry changes state to incomplete;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "russia3" country settings;
    *) wireless - added New Zealand regulatory domain information for P2P links;
    *) wireless - updated China and New Zealand regulatory domain information;
    *) www - fixed unresponsive Web services (introduced in v6.40);

  • Release 6.41rc18 2017-08-24

    What's new in 6.41rc18 (2017-Aug-24 07:52):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) bridge - changed "Host" and "MDB" table column order;
    *) ipv6 - add dynamic "/ip dns" server address from RA when RA is permitted by configuration;
    *) log - optimized "poe-out" logging topic logs;
    *) lte - added Passthrough support (CLI only);
    *) poe-out - fixed router reboot after "poe-out-status" changes;
    *) userman - fixed "limitation" and "profile-limitation" update;
    *) webfig - allow to open table entry even if table is not sorted by # (introduced in v6.40);
    *) webfig - allow to unset "rate-limit" for DHCP leases;
    *) winbox - added "notrack-chain" setting to IPSec peers;
    *) winbox - do not show FAN related information under "/system health" menu for devices which does not have it;
    *) winbox - fixed ARP table update after entry changes state to incomplete;

    Other changes since 6.40.2:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx (CLI only);
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter (CLI only);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv6-client - ignore unknown IA;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed "/system routerboard" export (introduced in 6.40.1);
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspost server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - fixed initiator ID comparison to NAT-OA;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) led - fixed "on" and "off" triggers when multiple LEDs are selected;
    *) lte - do not show USB LTE modem under "/port" menu (introduced in 6.41rc);
    *) lte - improved reliability of USB LTE modems;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in 6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb1100ahx4 - fixed HW acceleration fragmented packet decryption when fragment is smaller than 64 bytes;
    *) rb750gr3 - show warning and do not allow to use "protected-bootloader" feature if "factory-firmware" older than 3.34.4 version;
    *) routerboard - added "mode-button" support for RB750Gr3 (CLI only);
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) ssh - do not execute command if it starts with "-" symbol;
    *) traffic-flow - fixed reboots when IPv6 address has been set as target address without active IPv6 package;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added possibility to define "comment" for "/routing bgp network" entries;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - do not show LCD menu for devices which does not have it;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "russia3" country settings;
    *) wireless - added New Zealand regulatory domain information for P2P links;
    *) wireless - updated China and New Zealand regulatory domain information;
    *) www - fixed unresponsive Web services (introduced in v6.40);

  • Release 6.41rc17 2017-08-23

    What's new in 6.41rc17 (2017-Aug-22 11:58):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) bridge - fixed "R" state for bridge interfaces on x86 and CHR installations (introduced in v6.41rc12);
    *) capsman - added "vlan-mode=no-tag" option;
    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) ipsec - allow to specify "remote-peer" address as DNS name;
    *) lcd - fixed unresponsive LCD (introduced in v6.41rc15);
    *) lte - added Passthrough support (CLI only);
    *) pppoe - fixed invalid PPPoE server or client after reboot or "interface" edit (introduced in v6.41rc9);
    *) snmp - fixed bridge host requests on devices with multiple bridge interfaces;
    *) winbox - added possibility to define "comment" for "/routing bgp network" entries;
    *) winbox - do not show LCD menu for devices which does not have it;
    *) www - fixed unresponsive Web services (introduced in v6.40);

    Other changes since 6.40.1:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx (CLI only);
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter (CLI only);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv6-client - fixed IA evaluation order;
    *) dhcpv6-client - ignore unknown IA;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed "/system routerboard" export (introduced in 6.40.1);
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspost server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - fixed initiator ID comparison to NAT-OA;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) led - fixed "modem-signal" LEDs (introduced in 6.40);
    *) led - fixed "on" and "off" triggers when multiple LEDs are selected;
    *) lte - do not show USB LTE modem under "/port" menu (introduced in 6.41rc);
    *) lte - improved reliability of USB LTE modems;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in 6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe-client - fixed wrong auto MRU detection over VLAN interfaces;
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb1100ahx4 - fixed HW acceleration fragmented packet decryption when fragment is smaller than 64 bytes;
    *) rb2011 - fixed possible LCD blinking along with ethernet LED (introduced in 6.40);
    *) rb750gr3 - show warning and do not allow to use "protected-bootloader" feature if "factory-firmware" older than 3.34.4 version;
    *) routerboard - added "mode-button" support for RB750Gr3 (CLI only);
    *) sfp - fixed invalid temperature readings when ambient temperature is below 0C;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) ssh - do not execute command if it starts with "-" symbol;
    *) traffic-flow - fixed reboots when IPv6 address has been set as target address without active IPv6 package;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added certificate settings;
    *) winbox - added support fro certificate CRL list;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - hide "level" and "tunnel" parameters for IPSec policy templates;
    *) winbox - hide FAN speed if it is 0RPM;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "russia3" country settings;
    *) wireless - added New Zealand regulatory domain information for P2P links;
    *) wireless - updated China and New Zealand regulatory domain information;

  • Release 6.41rc16 2017-08-18

    What's new in 6.41rc16 (2017-Aug-18 13:44):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2 (CLI only);
    *) lcd - fixed unresponsive LCD (introduced in 6.41rc15);
    *) lte - added passthrough support (CLI only);
    *) traffic-flow - fixed reboots when IPv6 address has been set as target address without active IPv6 package;

    Other changes since 6.40.1:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx (CLI only);
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter (CLI only);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) capsman - added "vlan-mode=no-tag" option (CLI only);
    *) capsman - return complete CA chain when issuing new certificate;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv6-client - fixed IA evaluation order;
    *) dhcpv6-client - ignore unknown IA;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed "/system routerboard" export (introduced in 6.40.1);
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspost server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - fixed initiator ID comparison to NAT-OA;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - allow to specify remote peer address as DNS name (CLI only);
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) led - fixed "modem-signal" LEDs (introduced in 6.40);
    *) led - fixed "on" and "off" triggers when multiple LEDs are selected;
    *) lte - do not show USB LTE modem under "/port" menu (introduced in 6.41rc);
    *) lte - improved reliability of USB LTE modems;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in 6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe-client - fixed wrong auto MRU detection over VLAN interfaces;
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb1100ahx4 - fixed HW acceleration fragmented packet decryption when fragment is smaller than 64 bytes;
    *) rb2011 - fixed possible LCD blinking along with ethernet LED (introduced in 6.40);
    *) rb750gr3 - show warning and do not allow to use "protected-bootloader" feature if "factory-firmware" older than 3.34.4 version;
    *) routerboard - added "mode-button" support for RB750Gr3 (CLI only);
    *) sfp - fixed invalid temperature readings when ambient temperature is below 0C;
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) ssh - do not execute command if it starts with "-" symbol;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added certificate settings;
    *) winbox - added support fro certificate CRL list;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - hide "level" and "tunnel" parameters for IPSec policy templates;
    *) winbox - hide FAN speed if it is 0RPM;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "russia3" country settings;
    *) wireless - added New Zealand regulatory domain information for P2P links;
    *) wireless - updated China and New Zealand regulatory domain information;

  • Release 6.41rc15 2017-08-18

    What's new in 6.41rc15 (2017-Aug-18 07:33):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) capsman - added "vlan-mode=no-tag" option (CLI only);
    *) capsman - return complete CA chain when issuing new certificate;
    *) export - fixed "/system routerboard" export (introduced in 6.40.1);
    *) ike1 - fixed initiator ID comparison to NAT-OA;
    *) led - fixed "on" and "off" triggers when multiple LEDs are selected;
    *) lte - added passthrough support (CLI only);
    *) ospf - fixed OSPF v2 and v3 neighbor election;
    *) rb1100ahx4 - fixed HW acceleration fragmented packet decryption when fragment is smaller than 64 bytes;
    *) routerboard - added "mode-button" support for RB750Gr3 (CLI only);
    *) sfp - fixed SFP interface power monitor when bad SFP DDMI information is received;
    *) ssh - do not execute command if it starts with "-" symbol;
    *) wireless - added New Zealand regulatory domain information for P2P links;
    *) wireless - updated China and New Zealand regulatory domain information;

    Other changes since 6.40.1:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx (CLI only);
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - removed "master-port" parameter (CLI only);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) certificate - fixed import of certificates with empty SKID;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv6-client - fixed IA evaluation order;
    *) dhcpv6-client - ignore unknown IA;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed interface list export;
    *) hotspot - fixed missing "/ip hotspost server profile" if invalid "dns-name" was specified;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - allow to specify remote peer address as DNS name (CLI only);
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) led - fixed "modem-signal" LEDs (introduced in 6.40);
    *) lte - do not show USB LTE modem under "/port" menu (introduced in 6.41rc);
    *) lte - improved reliability of USB LTE modems;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in 6.41rc12);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe-client - fixed wrong auto MRU detection over VLAN interfaces;
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb2011 - fixed possible LCD blinking along with ethernet LED (introduced in 6.40);
    *) rb750gr3 - show warning and do not allow to use "protected-bootloader" feature if "factory-firmware" older than 3.34.4 version;
    *) sfp - fixed invalid temperature readings when ambient temperature is below 0C;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added certificate settings;
    *) winbox - added support fro certificate CRL list;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - hide "level" and "tunnel" parameters for IPSec policy templates;
    *) winbox - hide FAN speed if it is 0RPM;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "russia3" country settings;

  • Release 6.41rc13 2017-08-16

    What's new in 6.41rc13 (2017-Aug-15 13:09):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx (CLI only);
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - removed "master-port" parameter (CLI only);
    *) certificate - fixed import of certificates with empty SKID;
    *) dhcp - require DHCP option name to be unique;
    *) dhcpv6-client - ignore unknown IA;
    *) hotspot - fixed missing "/ip hotspost server profile" if invalid "dns-name" was specified;
    *) interface - added option to join and exclude "/interface list" from one and another;
    *) lte - improved FastPath support for SXT LTE;
    *) lte - added multi APN passthrough support for wAP LTE;
    *) lte - do not show USB LTE modem under "/port" menu (introduced in 6.41rc);
    *) lte - improved reliability of USB LTE modems;
    *) lte - properly recognize USB devices under "/system resource usb" (introduced in 6.41rc12);
    *) rb750gr3 - show warning and do not allow to use "protected-bootloader" feature if "factory-firmware" older than 3.34.4 version;

    Other changes since 6.40.1:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcpv6-client - fixed IA evaluation order;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed interface list export;
    *) hotspot - improved user statistics collection process;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipsec - allow to specify remote peer address as DNS name (CLI only);
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) led - fixed "modem-signal" LEDs (introduced in 6.40);
    *) lte - allow to specify the MAC address for passthrough mode;
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) ppp - added support for Sierra MC7750, Verizon USB730L;
    *) pppoe-client - fixed wrong auto MRU detection over VLAN interfaces;
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) rb2011 - fixed possible LCD blinking along with ethernet LED (introduced in 6.40);
    *) sfp - fixed invalid temperature readings when ambient temperature is below 0C;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added certificate settings;
    *) winbox - added support fro certificate CRL list;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - hide "level" and "tunnel" parameters for IPSec policy templates;
    *) winbox - hide FAN speed if it is 0RPM;
    *) winbox - show warnings under "/system routerboard settings" menu;
    *) wireless - added "russia3" country settings;

  • Release 6.41rc11 2017-08-09

    What's new in 6.41rc11 (2017-Aug-08 09:32):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) bridge - added initial support for hardware "igmp-snooping" on CRS1xx/2xx (CLI only);
    *) bridge - automatically turn off "fast-forward" feature if both bridge ports have "H" flag;
    *) export - fixed interface list export;
    *) ike1 - release mismatched PH2 peer IDs;
    *) ike2 - check identities on "initial-contact";
    *) ike2 - use peer configuration address when available on empty TSi;
    *) interface - fixed corrupted "/interface list" configuration after upgrade;
    *) ipsec - allow to specify remote peer address as DNS name (CLI only);
    *) ipsec - renamed "firewall" argument to "notrack-chain" in peer configuration;
    *) led - fixed "modem-signal" LEDs (introduced in 6.40);
    *) modem - added initial support for Alcatel IK40 and Olicard 500;
    *) rb2011 - fixed possible LCD blinking along with ethernet LED (introduced in 6.40);
    *) rb750gr3 - show warning and do not allow to use "protected-bootloader" feature if "factory-firmware" older than 3.34.4 version;
    *) ups - fixed duplicate "failed" UPS logs;
    *) winbox - added certificate settings;
    *) winbox - added support fro certificate CRL list;
    *) winbox - do not show duplicate "Template" parameters for filter in IPSec policy list;
    *) winbox - fixed bridge port sorting order by interface name;
    *) winbox - hide "level" and "tunnel" parameters for IPSec policy templates;
    *) winbox - hide FAN speed if it is 0RPM;
    *) wireless - added "russia3" country settings;

    Other changes since 6.40.1:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) certificate - fixed SCEP "get" request URL encoding;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcpv6-client - fixed IA evaluation order;
    *) e-mail - do not show errors when sending e-mail from script;
    *) hotspot - improved user statistics collection process;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lte - added initial passthrough support for wAP LTE;
    *) lte - added support for Novatel (Verizon) USB730L;
    *) lte - allow to specify the MAC address for passthrough mode;
    *) ppp - added support for Sierra MC7750;
    *) pppoe-client - fixed wrong auto MRU detection over VLAN interfaces;
    *) pppoe-server - fixed situation when PPPoE servers become invalid on reboot;
    *) sfp - fixed invalid temperature readings when ambient temperature is below 0C;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - show warnings under "/system routerboard settings" menu;

  • Release 6.41rc9 2017-08-03

    What's new in 6.41rc9 (2017-Aug-03 12:02):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) certificate - fixed SCEP "get" request URL encoding;
    *) dhcpv6-client - fixed IA evaluation order;
    *) l2tp-server - fixed PPP services becoming unresponsive after changes on L2TP server with IPSec configuration;
    *) lcd - fixed LCD blinking on RB2011 (introduced in 6.40);
    *) lte - added initial passthrough support for wAP LTE;
    *) pppoe-client - fixed wrong auto MRU detection over VLAN interfaces;
    *) pppoe-server - fixed situation when PPPoE servers become invalid after reboot;
    *) sfp - fixed invalid temperature readings when ambient temperature is below 0C;

    Other changes since 6.40:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bonding - improved relialibility on bonding interface removal;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) dhcpv6-client - do not run DHCPv6 client when IPv6 package is disabled;
    *) e-mail - do not show errors when sending e-mail from script;
    *) export - fixed export for different parameters where numerical range or constant string is expected;
    *) firewall - properly remove "address-list" entry after timeout ends;
    *) hotspot - improved user statistics collection process;
    *) interface - improved interface state change handling when multiple interfaces are affected at the same time;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) lte - allow to specify the MAC address for passthrough mode;
    *) lte - added support for Novatel (Verizon) USB730L;
    *) lte - fixed LTE not passing any traffic while in running state;
    *) ovpn-client - fixed incorrect netmask usage for pushed routes;
    *) ppp - added support for Sierra MC7750;
    *) pppoe-client - fixed incorrectly formed PADT packet;
    *) rb2011 - fixed possible LCD blinking along with Ethernet LED;
    *) rb922 - restored missing wireless interface on some boards;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) torch - fixed Torch on PPP tunnels (introduced in 6.40);
    *) trafficgen - fixed "lost-ratio" showing incorrect statistics after multiple sequences;
    *) winbox - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter under NAT, Mangle and RAW rules;
    *) winbox - do not show duplicate filter parameters "Published" in ARP list;
    *) winbox - show warnings under "/system routerboard settings" menu;

  • Release 6.41rc6 2017-08-01

    What's new in 6.41rc6 (2017-Aug-01 11:30):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) btest - improved reliability on Bandwidth Test when device`s RAM is almost full;
    *) dhcpv6-client - do not run DHCPv6 client when IPv6 package is disabled;
    *) ipv6 - fixed IPv6 address request from pool (introduced in 6.41rc1);
    *) lte - added support for Novatel (Verizon) USB730L;
    *) lte - fixed LTE not passing any traffic while in running state;
    *) ppp - added support for Sierra MC7750;
    *) torch - fixed Torch on PPP tunnels (introduced in 6.40);

    Other changes since 6.40:

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bonding - improved relialibility on bonding interface removal;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) e-mail - do not show errors when sending e-mail from script;
    *) firewall - properly remove "address-list" entry after timeout ends;
    *) hotspot - improved user statistics collection process;
    *) interface - improved interface state change handling when multiple interfaces are affected at the same time;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) lte - allow to specify the MAC address for passthrough mode;
    *) rb2011 - fixed possible LCD blinking along with Ethernet LED;
    *) rb922 - restored missing wireless interface on some boards;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) trafficgen - fixed "lost-ratio" showing incorrect statistics after multiple sequences;

  • Release 6.41rc4 2017-07-31

    What's new in 6.41rc4 (2017-Jul-28 06:48):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) bridge - show "admin-mac" only if "auto-mac=no";
    *) rb922 - restored missing wireless interface on some boards;

    Other changes since 6.40:

    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bonding - improved relialibility on bonding interface removal;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) e-mail - do not show errors when sending e-mail from script;
    *) firewall - properly remove "address-list" entry after timeout ends;
    *) hotspot - improved user statistics collection process;
    *) interface - improved interface state change handling when multiple interfaces are affected at the same time;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) lte - allow to specify the MAC address for passthrough mode;
    *) ppp - added client support for Sierra MC7750;
    *) rb2011 - fixed possible LCD blinking along with Ethernet LED;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) trafficgen - fixed "lost-ratio" showing incorrect statistics after multiple sequences;

  • Release 6.41rc3 2017-07-26

    What's new in 6.41rc3 (2017-Jul-26 09:32):

    Important note!!! Backup before upgrade!
    RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - implemented software based vlan-aware bridges;
    https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (CLI only);
    https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Bridge_Hardware_Offloading
    !) bridge - general development of hw-offload bridge implementation (introduced in v6.40rc36);
    *) CRS3xx - switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) arp - fixed invalid static ARP entries after reboot on interfaces without IP address;
    *) bonding - improved relialibility on bonding interface removal;
    *) bridge - fixed ARP setting (introduced in v6.40rc36);
    *) bridge - fixed multicast forwarding (introduced in v6.40rc36);
    *) bridge - implemented dynamic entries for active MST port overrides;
    *) bridge - implemented software based "igmp-snooping" (CLI only);
    *) bridge - implemented software based MSTP (CLI only);
    *) bridge - removed "frame-types" and "ingress-filtering" for bridge interfaces (introduced in v6.40rc36);
    *) certificate - show "Expired" flag when initial CRL fetch fails;
    *) e-mail - do not show errors when sending e-mail from script;
    *) firewall - properly remove "address-list" entry after timeout ends;
    *) hotspot - improved user statistics collection process;
    *) interface - improved interface state change handling when multiple interfaces are affected at the same time;
    *) ippool6 - try to assign desired prefix for client if prefix is not being already used;
    *) lte - allow to specify the MAC address for passthrough mode;
    *) ppp - added client support for Sierra MC7750;
    *) rb2011 - fixed possible LCD blinking along with Ethernet LED;
    *) rb922 - restored missing wireless interface on some boards;
    *) sftp - added functionality which imports ".auto.rsc" file or reboots router on ".auto.npk" upload;
    *) trafficgen - fixed "lost-ratio" showing incorrect statistics after multiple sequences;

  • Release 6.40rc41 2017-07-17

    What's new in 6.40rc41 (2017-Jul-17 09:03):

    !) bridge hw-offload implementation reverted back to pre-6.40rc36 state (testing will continue in v6.41rc);
    !) wireless - added Nv2 AP synchronization feature "nv2-modes" and "nv2-sync-secret" option;
    *) bonding - fixed 802.3ad mode on RB1100AHx4;
    *) export - fixed export to a file (introduced in v6.40rc39);
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - fixed firewall accept rules created by "/ip hotspot walled garden ip" (introduced in v6.40rc18);
    *) ike1 - create tunnel policy when no split net provided;
    *) ike1 - wait for cfg set reply before ph2 creation with xAuth;
    *) ipsec - allow to specify chain in "firewall" peer option;
    *) ppp - fixed non-standard PAP or CHAP packet handling;
    *) pppoe-server - fixed situation when some of 100+ pppoe-servers can become invalid on reboot;
    *) routerboard - added "caps-mode" option for "reset-configuration";
    *) sfp - fixed invalid temperature reporting when ambient temperature is less than 0;
    *) winbox - make IPSec policies table an order list;
    *) winbox - show "/interface wireless cap print" warnings;

    Other changes since 6.39.2:

    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) certificate - update and reload old certificate with new one if SKID matches;
    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) console - fixed different command auto complete on ;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-client - added "gateway-address" script parameter;
    *) dhcpv4-server - fixed lease renew for DHCP clients that sends renewal with "ciaddr = 0.0.0.0";
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) email - added support for multiple attachments;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed occasional broken interface order after reset/first boot;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) export - added router model and serial number to configuration export;
    *) export - fixed "/interface list" verbose export;
    *) export - fixed "/ipv6 route" compact export;
    *) export - fixed MPLS "dynamic-label-range" export;
    *) export - fixed SNMP "src-address" for compact export;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fastpath - improved removing process of dynamic interface;
    *) fasttrack - fixed fasttrack over interfaces with dynamic MAC address;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) filesystem - improved error correcting process on tilera and RB1100Dx4 storage;
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter;
    *) firewall - fixed bridge "action=log" rules;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - fixed crash on fasttrack dummy rule manual change attempt;
    *) firewall - removed unique address list name limit;
    *) hAP ac lite - removed nonexistent "wlan-led";
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added log error message if netmask was not provided by "mode-config" server;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - fixed duplicate policy checking with "0.0.0.0/0" policies;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - added support for "key-id" peer identification type;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added info command support for the Jaton LTE modem;
    *) lte - added initial fastpath support (except SXT LTE and Sierra modems);
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - added support for Huawei E3531-6;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) mmips - added support for NVME disks;
    *) modem - added support for ZTE TE W120;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - added initial support for ZTE K4203-Z;
    *) ppp - added initial support for ZTE ME3630-E;
    *) ppp - added output values for "info" command for finding the GSM base station's location ("LAC" and "IMSI");
    *) ppp - fixed "user-command" output;
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - simplified LTE status monitoring;
    *) quickset - use active user name and permissions when applying changes;
    *) rb1100ahx4 - fixed startup problems (requires additional reboot after upgrade);
    *) rb3011 - fixed packet passthrough on switch2 while booting;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) safe-mode - fixed session handling when Safe Mode is used on multiple sessions at the same time;
    *) sms - decode reports in readable format;
    *) sniffer - do not skip L2 packets when "all" interface mode was used;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed "/system resource cpu print oid" menu;
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) ssl - added Wildcard support for "left-most" DNS label (will allow to use signed Wildcard certificate on VPN servers);
    *) supout - fixed IPv6 firewall section;
    *) switch - fixed "loop-protect" on CRS SFP/SFP+ ports;
    *) tile - fixed copying large amount of text over serial console;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) trafficgen - added "lost-ratio" to statistics;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - added "/tool user-manager user clear-profiles" command;
    *) userman - do not send disconnect request for user when "simultaneous session limit reached";
    *) userman - lookup language files also in "/flash" directory;
    *) vlan - do not delete existing VLAN interface on "failure: already have such vlan";
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - do not autoscale graphs outside known maximums;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - hide LCD menu on CRS112-8G-4S;
    *) winbox - moved LTE info fields to status tab;
    *) winbox - show "/system health" only on boards that have health monitoring;
    *) winbox - show "D" flag under "/interface mesh port" menu;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc38 2017-07-12

    What's new in 6.40rc38 (2017-Jul-11 12:28):

    Important note!!! Backup before upgrade!
    RouterOS v6.40rc36 contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    *) certificate - update and reload old certificate with new one if SKID matches;
    *) email - added support for multiple attachments;
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter;
    *) firewall - fixed crash on fasttrack dummy rule manual change attempt;
    *) ikev2 - fixed duplicate policy checking with "0.0.0.0/0" policies;
    *) lte - added initial fastpath support (except SXT LTE and Sierra modems);
    *) mmips - added support for NVME disks;
    *) ppp - added output values for "info" command for finding the GSM base station's location ("LAC" and "IMSI");
    *) ppp - fixed "user-command" output;
    *) quickset - simplified LTE status monitoring;
    *) rb1100ahx4 - fixed startup problems (requires additional reboot after upgrade);
    *) ssl - added Wildcard support for "left-most" DNS label (will allow to use signed Wildcard certificate on VPN servers);
    *) userman - do not send disconnect request for user when "simultaneous session limit reached";
    *) userman - added "/tool user-manager user clear-profiles" command;

    Other changes since 6.39.2:

    !) bridge - implemented software based "igmp-snooping" (untested, undocumented, CLI only);
    !) bridge - implemented software based MSTP (untested, undocumented, CLI only);
    !) bridge - implemented software based vlan-aware bridges;
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (undocumented, CLI only);
    !) switch - CRS3xx switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) console - fixed different command auto complete on ;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-client - added "gateway-address" script parameter;
    *) dhcpv4-server - fixed lease renew for DHCP clients that sends renewal with "ciaddr = 0.0.0.0";
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed occasional broken interface order after reset/first boot;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) export - added router model and serial number to configuration export;
    *) export - fixed "/interface list" verbose export;
    *) export - fixed "/ipv6 route" compact export;
    *) export - fixed MPLS "dynamic-label-range" export;
    *) export - fixed SNMP "src-address" for compact export;
    *) fastpath - fixed router rebooting itself (introduced in 6.40rc24);
    *) fastpath - improved performance when packets for slowpath are received;
    *) fastpath - improved removing process of dynamic interface;
    *) fasttrack - fixed fasttrack over interfaces with dynamic MAC address;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) filesystem - improved error correcting process on tilera and RB1100Dx4 storage;
    *) firewall - fixed bridge "action=log" rules;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - removed unique address list name limit;
    *) hAP ac lite - removed nonexistent "wlan-led";
    *) health - fixed memory leak on devices that have "/system health" menu (introduced in 6.40rc30);
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ikev1 - added log error message if netmask was not provided by "mode-config" server;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - added support for "key-id" peer identification type;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added info command support for the Jaton LTE modem;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - added support for Huawei E3531-6;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - added initial support for ZTE K4203-Z;
    *) ppp - added initial support for ZTE ME3630-E;
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - use active user name and permissions when applying changes;
    *) rb3011 - fixed packet passthrough on switch2 while booting;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) safe-mode - fixed session handling when Safe Mode is used on multiple sessions at the same time;
    *) sms - decode reports in readable format;
    *) sniffer - do not skip L2 packets when "all" interface mode was used;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed "/system resource cpu print oid" menu;
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) supout - fixed IPv6 firewall section;
    *) switch - fixed "loop-protect" on CRS SFP/SFP+ ports;
    *) tile - fixed copying large amount of text over serial console;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) trafficgen - added "lost-ratio" to statistics;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) vlan - do not delete existing VLAN interface on "failure: already have such vlan";
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - do not autoscale graphs outside known maximums;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - hide LCD menu on CRS112-8G-4S;
    *) winbox - moved LTE info fields to status tab;
    *) winbox - show "/system health" only on boards that have health monitoring;
    *) winbox - show "D" flag under "/interface mesh port" menu;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc36 2017-07-07

    What's new in 6.40rc36 (2017-Jul-07 10:44):

    Important note!!! Backup before upgrade!
    RouterOS v6.40rc36 contains new bridge implementation that supports hardware offloading (hw-offload).
    This update will convert all interface "master-port" configuration into new bridge configuration, and eliminate "master-port" option as such.
    Bridge will handle all Layer2 forwarding and the use of switch-chip (hw-offload) will be automatically turned on based on appropriate conditions.
    The rest of RouterOS Switch specific configuration remains untouched in usual menus for now.
    Please, note that downgrading to previous RouterOS versions will not restore "master-port" configuration, so use backups to restore configuration on downgrade.

    !) bridge - implemented software based "igmp-snooping" (untested, undocumented, CLI only);
    !) bridge - implemented software based MSTP (untested, undocumented, CLI only);
    !) bridge - implemented software based vlan-aware bridges;
    !) switch - "master-port" conversion into a bridge with hardware offload "hw" option (undocumented, CLI only);
    !) switch - CRS3xx switch VLAN configuration integrated within bridge VLAN configuration with hw-offload;
    *) filesystem - improved error correcting process on tilera and RB1100Dx4 storage;
    *) firewall - fixed bridge "action=log" rules;
    *) health - fixed memory leak on devices that have "/system health" menu (introduced in 6.40rc30);
    *) ikev1 - added log error message if netmask was not provided by "mode-config" server;
    *) ipsec - added support for "key-id" peer identification type;
    *) rb3011 - fixed packet passthrough on switch2 while booting;
    *) sniffer - do not skip L2 packets when "all" interface mode was used;
    *) snmp - fixed "/system resource cpu print oid" menu;
    *) switch - fixed "loop-protect" on CRS SFP/SFP+ ports;
    *) trafficgen - added "lost-ratio" to statistics;
    *) vlan - do not delete existing VLAN interface on "failure: already have such vlan";
    *) winbox - do not autoscale graphs outside known maximums;
    *) winbox - hide LCD menu on CRS112-8G-4S;
    *) winbox - show "/system health" only on boards that have health monitoring;
    *) winbox - show "D" flag under "/interface mesh port" menu;

    Other changes since 6.39.2:

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) console - fixed different command auto complete on ;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-client - added "gateway-address" script parameter;
    *) dhcpv4-server - fixed lease renew for DHCP clients that sends renewal with "ciaddr = 0.0.0.0";
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed occasional broken interface order after reset/first boot;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) export - added router model and serial number to configuration export;
    *) export - fixed "/interface list" verbose export;
    *) export - fixed "/ipv6 route" compact export;
    *) export - fixed MPLS "dynamic-label-range" export;
    *) export - fixed SNMP "src-address" for compact export;
    *) fastpath - fixed router rebooting itself (introduced in 6.40rc24);
    *) fastpath - improved performance when packets for slowpath are received;
    *) fastpath - improved removing process of dynamic interface;
    *) fasttrack - fixed fasttrack over interfaces with dynamic MAC address;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter (CLI only);
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - removed unique address list name limit;
    *) hAP ac lite - removed nonexistent "wlan-led";
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added info command support for the Jaton LTE modem;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - added support for Huawei E3531-6;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - added initial support for ZTE K4203-Z;
    *) ppp - added initial support for ZTE ME3630-E;
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - use active user name and permissions when applying changes;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) safe-mode - fixed session handling when Safe Mode is used on multiple sessions at the same time;
    *) sms - decode reports in readable format;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) supout - fixed IPv6 firewall section;
    *) tile - fixed copying large amount of text over serial console;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - moved LTE info fields to status tab;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc32 2017-07-04

    What's new in 6.40rc32 (2017-Jul-04 07:38):

    *) dhcpv4-client - added "gateway-address" script parameter;
    *) dhcpv4-server - fixed lease renew for DHCP clients that sends renewal with "ciaddr = 0.0.0.0";
    *) fasttrack - fixed fasttrack over interfaces with dynamic MAC address;

    Other changes since 6.39.2:

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) console - fixed different command auto complete on ;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed occasional broken interface order after reset/first boot;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) export - added router model and serial number to configuration export;
    *) export - fixed "/interface list" verbose export;
    *) export - fixed "/ipv6 route" compact export;
    *) export - fixed MPLS "dynamic-label-range" export;
    *) export - fixed SNMP "src-address" for compact export;
    *) fastpath - fixed router rebooting itself (introduced in 6.40rc24);
    *) fastpath - improved performance when packets for slowpath are received;
    *) fastpath - improved removing process of dynamic interface;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter (CLI only);
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - removed unique address list name limit;
    *) hAP ac lite - removed nonexistent "wlan-led";
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added info command support for the Jaton LTE modem;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - added support for Huawei E3531-6;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - added initial support for ZTE K4203-Z;
    *) ppp - added initial support for ZTE ME3630-E;
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - use active user name and permissions when applying changes;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) safe-mode - fixed session handling when Safe Mode is used on multiple sessions at the same time;
    *) sms - decode reports in readable format;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) supout - fixed IPv6 firewall section;
    *) tile - fixed copying large amount of text over serial console;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) trafficgen - added "lost-ratio" to statistics;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - moved LTE info fields to status tab;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc28 2017-06-30

    What's new in 6.40rc28 (2017-Jun-30 12:08:26):

    *) console - fixed different command auto complete on ;
    *) ethernet - fixed occasional broken interface order after reset/first boot;
    *) export - added router model and serial number to configuration export;
    *) export - fixed "/interface list" verbose export;
    *) export - fixed "/ipv6 route" compact export;
    *) export - fixed MPLS "dynamic-label-range" export;
    *) export - fixed SNMP "src-address" for compact export;
    *) fastpath - improved removing process of dynamic interface;
    *) hAP ac lite - removed nonexistent "wlan-led";
    *) lte - added info command support for the Jaton LTE modem;
    *) ppp - added initial support for ZTE K4203-Z;
    *) ppp - added initial support for ZTE ME3630-E;
    *) safe-mode - fixed session handling when Safe Mode is used on multiple sessions at the same time;
    *) supout - fixed IPv6 firewall section;

    Other changes since 6.39.2:

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces (CLI only);
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) fastpath - fixed router rebooting itself (introduced in 6.40rc24);
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter (CLI only);
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - removed unique address list name limit;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - added support for Huawei E3531-6;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - use active user name and permissions when applying changes;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sms - decode reports in readable format;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tile - fixed copying large amount of text over serial console;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) trafficgen - added "lost-ratio" to statistics;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - moved LTE info fields to status tab;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc25 2017-06-27

    What's new in 6.40rc25 (2017-Jun-27 06:26):

    *) chr - fixed MAC address assignment when hot plugging NIC on XenServer;
    *) fastpath - fixed router rebooting itself (introduced in 6.40rc24);
    *) firewall - added "none-dynamic" and "none-static" options for "address-list-timeout" parameter (CLI only);
    *) firewall - removed unique address list name limit;
    *) ipsec - do not deduct "dst-address" from "sa-dst-address" for "/0" policies;
    *) lte - added support for Huawei E3531-6;
    *) modem - fixed info command when it is executed at the same time as modem restarts/disconnects;
    *) tile - fixed copying large amount of text over serial console;
    *) trafficgen - added "lost-ratio" to statistics;
    *) webfig - fixed wireless "scan-list" parameter not being saved after applying changes;

    Other changes since 6.39.2:

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces (CLI only);
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) ovpn - added support for "push-continuation";
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) ovpn - improved performance when receiving too many options;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - improved MLPPP packet forwarding performance;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed potential crash;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) quickset - use active user name and permissions when applying changes;
    *) rb750gr3 - fixed USB power;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sms - decode reports in readable format;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed crash on interface table get;
    *) snmp - fixed wireless interface walk table id ordering;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - added TR069 support;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - moved LTE info fields to status tab;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc24 2017-06-20

    What's new in 6.40rc24 (2017-Jun-20 09:38):

    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces;
    *) discovery - fixed timeouts for LLDP neighbours;
    *) ethernet - fixed rare linking problem with forced 10Mbps full-duplex mode;
    *) metarouter - fixed display of bogus error message on startup;
    *) modem - added support for ZTE TE W120;
    *) ovpn - added support for topology subnet for IP mode;
    *) ovpn - added support for "push-continuation";
    *) ovpn - fixed duplicate default gateway presence when receiving extra routes;
    *) packages - increased automatic download retry interval to 5 minutes if there is no free disk space;
    *) ppp - use interface name instead of IP as default route gateway;
    *) proxy - fixed rare program crash after closing client connection;
    *) quickset - added special firewall exception rules for IPSec;
    *) quickset - fixed incorrect VPN address value on arm and tilera;
    *) routerboard - added "caps-mode" option for "reset-configuration" (CLI only);
    *) routerboard - added "caps-mode-script" for default-configuration print;
    *) sms - decode reports in readable format;
    *) snmp - added CAPsMAN interface statistics;
    *) snmp - fixed wireless interface walk table id ordering;
    *) winbox - added "session-uptime" to LTE interface;
    *) winbox - added "src-address-list" & "dst-address-list" to HotSpot Walled Garden;
    *) winbox - fixed wireless interface "amsdu-threshold" max limit;
    *) winbox - moved LTE info fields to status tab;

    Other changes since 6.39.2:

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces (CLI only);
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) dude - fixed server crash;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) ovpn - improved performance when receiving too many options;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) ppp - improved MLPPP packet forwarding performance;
    *) proxy - fixed potential crash;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - use active user name and permissions when applying changes;
    *) rb750gr3 - fixed USB power;
    *) routing - allow to disable "all" interface entry in BFD;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed crash on interface table get;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) userman - lookup language files also in "/flash" directory;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added TR069 support;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc21 2017-06-14

    What's new in 6.40rc21 (2017-Jun-14 09:05):

    !) wireless - added Nv2 AP synchronization feature (for experimental use)(CLI only);
    *) capsman - added "current-registered-clients" and "current-authorized-clients" count for CAP interfaces (CLI only);
    *) certificate - added "crl-use" setting to disable CRL use (CLI only);
    *) crs212 - fixed Optech sfp-10G-tx module compatibility with SFP ports;
    *) dude - fixed server crash;
    *) export - added default "init-delay" setting for "/routerboard settings" menu;
    *) ping - fixed ping getting stuck (after several thousands of ping attempts);
    *) rb750gr3 - fixed USB power;
    *) userman - lookup language files also in "/flash" directory;

    Other changes since 6.39.2:

    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dhcp - added "debug" logs on MAC address change;
    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved SMS delivery report;
    *) lte - improved reliability on SXT LTE;
    *) ovpn - improved performance when receiving too many options;
    *) ppp - improved MLPPP packet forwarding performance;
    *) proxy - fixed potential crash;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - use active user name and permissions when applying changes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) snmp - fixed crash on interface table get;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added TR069 support;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

  • Release 6.40rc20 2017-06-13

    What's new in 6.40rc20 (2017-Jun-12 12:08):

    *) dhcpv4-server - fixed server state on interface change in Winbox and Webfig;
    *) ike2 - added support for "Mikrotik_Address_List" RADIUS attribute;
    *) lte - added "accounting" logs for LTE connections;
    *) lte - improved reliability on SXT LTE;
    *) wireless - fixed rare crash on cap disable;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

    Other changes since 6.39.2:

    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) l2tp-server - added "one-session-per-host" option;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved SMS delivery report;
    *) ovpn - improved performance when receiving too many options;
    *) ppp - improved MLPPP packet forwarding performance;
    *) proxy - fixed potential crash;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - use active user name and permissions when applying changes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) snmp - fixed crash on interface table get;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added TR069 support;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;

  • Release 6.40rc19 2017-06-08

    What's new in 6.40rc19 (2017-Jun-07 13:30):

    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ipsec - added "firewall=add-notrack" peer option (CLI only);
    *) l2tp-server - added "one-session-per-host" option;
    *) ovpn - improved performance when receiving too many options;
    *) wireless - fixed registration table "signal-strength" reporting for chains when using nv2;

    Other changes since 6.39.2:

    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) fastpath - improved performance when packets for slowpath are received;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike2 - added pfkey kernel return checks;
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - removed policy priority;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) log - added "poe-out" topic;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved SMS delivery report;
    *) ppp - improved MLPPP packet forwarding performance;
    *) proxy - fixed potential crash;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - use active user name and permissions when applying changes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) snmp - fixed crash on interface table get;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added TR069 support;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;

  • Release 6.40rc18 2017-06-06

    What's new in 6.40rc18 (2017-Jun-06 10:04):

    *) conntrack - fixed IPv6 connection tracking enable/disable;
    *) defconf - added IPv6 default firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - improved IPv4 default firewall configuration;
    *) fastpath - improved performance when packets for slowpath are received;
    *) hotspot - added "address-list" support in "walled-garden" IP section;
    *) ike1 - added support for "framed-pool" RADIUS attribute;
    *) ike1 - kill phase1 instead of rekey if "mode-config" is used;
    *) ike1 - removed SAs on DPD;
    *) ike1 - send phase1 delete;
    *) ike2 - added RADIUS attributes "Framed-Pool", "Framed-Ip-Address", "Framed-Ip-Netmask";
    *) ike2 - added support for "mode-config" static address;
    *) ike2 - prefer traffic selector with "mode-config" address;
    *) l2tp - fixed handling of pre-authenticated L2TP sessions with CHAP authentication;
    *) log - improved "l2tp" logs;
    *) log - optimized "wireless,info" topic logs;
    *) lte - improved SMS delivery report;
    *) ppp - improved MLPPP packet forwarding performance;
    *) socks - fixed crash while processing many simultaneous sessions;
    *) tr069-client - fixed lost HTTP header on authorization;
    *) wireless - allow VirutalAP on Level0 (24h demo) license;

  • Release 6.40rc15 2017-05-31

    What's new in 6.40rc15 (2017-May-30 08:52):

    !) ipsec - added support for dynamic "action=notrack" RAW rules for policies;
    *) defconf - added accept ICMPv6 in forward and DHCP discover in RAW prerouting;
    *) ike2 - added pfkey kernel return checks;
    *) ipsec - added information in console XML for "mode-config" menu;
    *) ipsec - fixed connections cleanup on policy or proposal modification;
    *) ipsec - removed policy priority;
    *) ppp - fixed MLPPP over multiple channels/interfaces (introduced in v6.39);

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) bonding - do not add bonding interface if "could not set MTU" error is received;
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) chr - maximal system disk size now limited to 16GB;
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) defconf - added IPv6 firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) defconf - replaced IPv4 firewall configuration with improved one;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) export - removed spare "caller-id-type" value from compact export;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) firewall - do not allow to set "rate" value to 0 for "limit" parameter;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) gps - removed duplicate logs;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - removed xauth login length limitation;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - fixed rare kernel failure on address acquire;
    *) ike2 - fixed situation when traffic selector prefix was parsed incorrectly;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed generated policy priority;
    *) ipsec - fixed peer "my-id" address reset;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - renamed "remote-dynamic-address" to "dynamic-address";
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) led - fixed ethernet LEDs on CCR1009 and RB1100AHx2 (introduced in v6.40rc1);
    *) led - fixed turning off LED when interface is lost;
    *) log - added "poe-out" topic;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - fixed configless modem running state (introduced in 6.40rc);
    *) lte - improved info channel background polling;
    *) lte - replaced "user-command" with "at-chat" command;
    *) ppp - fixed "change-mss" functionality (introduced in 6.39);
    *) ppp - send correct IP address in RADIUS "accounting-stop" messages (introduced in 6.39);
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) pppoe-client - removed false warning from client interface if it starts running on non-slave interface;
    *) pppoe-server - fixed "one-session-per-host" issue where 2 simultaneous sessions were possible from the same host;
    *) proxy - fixed potential crash;
    *) queue - fixed queuing when at least one child queue has "default-small" and other/s is/are different (introduced in 6.35);
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - fixed LTE "signal-strength" graphs;
    *) quickset - use active user name and permissions when applying changes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - fixed crash on interface table get;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) tile - fixed rare encryption kernel failure when small packets are processed;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) winbox - fixed LTE info button;
    *) winbox - fixed firewall port selection with Winbox v2;
    *) winbox - removed spare values from "loop-protect" setting for EoIPv6 tunnels;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - reduced load on CPU for high speed wireless links;

  • Release 6.40rc14 2017-05-30

    What's new in 6.40rc14 (2017-May-29 11:16):

    *) chr - maximal system disk size now limited to 16GB;
    *) fetch - added "src-address" parameter for HTTP and HTTPS;
    *) pppoe-server - fixed "one-session-per-host" issue where 2 simultaneous sessions were possible from the same host;
    *) snmp - fixed crash on interface table get;
    *) winbox - added "reselect-channel" to CAPsMAN interfaces;
    *) winbox - fixed firewall port selection with Winbox v2;

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) bonding - do not add bonding interface if "could not set MTU" error is received;
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) defconf - added IPv6 firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) defconf - replaced IPv4 firewall configuration with improved one;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) export - removed spare "caller-id-type" value from compact export;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) firewall - do not allow to set "rate" value to 0 for "limit" parameter;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) gps - removed duplicate logs;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike1 - removed xauth login length limitation;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - fixed rare kernel failure on address acquire;
    *) ike2 - fixed situation when traffic selector prefix was parsed incorrectly;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - fixed generated policy priority;
    *) ipsec - fixed peer "my-id" address reset;
    *) ipsec - optimized logging under IPSec topic;
    *) ipsec - renamed "remote-dynamic-address" to "dynamic-address";
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) led - fixed ethernet LEDs on CCR1009 and RB1100AHx2 (introduced in v6.40rc1);
    *) led - fixed turning off LED when interface is lost;
    *) log - added "poe-out" topic;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - fixed configless modem running state (introduced in 6.40rc);
    *) lte - improved info channel background polling;
    *) lte - replaced "user-command" with "at-chat" command;
    *) ppp - fixed "change-mss" functionality (introduced in 6.39);
    *) ppp - send correct IP address in RADIUS "accounting-stop" messages (introduced in 6.39);
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) pppoe-client - removed false warning from client interface if it starts running on non-slave interface;
    *) proxy - fixed potential crash;
    *) queue - fixed queuing when at least one child queue has "default-small" and other/s is/are different (introduced in 6.35);
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) quickset - fixed LTE "signal-strength" graphs;
    *) quickset - use active user name and permissions when applying changes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - added ability to set "src-address";
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) tile - fixed rare encryption kernel failure when small packets are processed;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) winbox - fixed LTE info button;
    *) winbox - removed spare values from "loop-protect" setting for EoIPv6 tunnels;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - reduced load on CPU for high speed wireless links;

  • Release 6.40rc13 2017-05-26

    What's new in 6.40rc13 (2017-May-25 12:53):

    *) bonding - do not add bonding interface if "could not set MTU" error is received;
    *) defconf - added IPv6 firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - renamed 192.168.88.1 address static DNS entry from "router" to "router.lan";
    *) export - removed spare "caller-id-type" value from compact export;
    *) firewall - do not allow to set "rate" value to 0 for "limit" parameter;
    *) gps - removed duplicate logs;
    *) hotspot - require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
    *) ike1 - removed xauth login length limitation;
    *) ike2 - by default use "/24" netmask for peer IP address in split net;
    *) ike2 - fixed situation when traffic selector prefix was parsed incorrectly;
    *) ipsec - fixed generated policy priority;
    *) ipsec - fixed peer "my-id" address reset;
    *) ipsec - renamed "remote-dynamic-address" to "dynamic-address";
    *) lte - fixed configless modem running state (introduced in 6.40rc);
    *) ppp - fixed "change-mss" functionality (introduced in 6.39);
    *) ppp - send correct IP address in RADIUS "accounting-stop" messages (introduced in 6.39);
    *) pppoe-client - removed false warning from client interface if it starts running on non-slave interface;
    *) proxy - fixed potential crash;
    *) queue - fixed queuing when at least one child queue has "default-small" and other/s is/are different (introduced in 6.35);
    *) quickset - fixed LTE "signal-strength" graphs;
    *) quickset - use active user name and permissions when applying changes;
    *) snmp - added ability to set "src-address";
    *) tile - fixed rare encryption kernel failure when small packets are processed;
    *) ups - show correct "line-voltage" value for usbhid UPS devices;
    *) winbox - fixed LTE info button;
    *) winbox - removed spare values from "loop-protect" setting for EoIPv6 tunnels;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol;
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol;
    *) wireless - reduced load on CPU for high speed wireless links;

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) btest - fixed crash when packet size has been changed during test;
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) defconf - replaced IPv4 firewall configuration with improved one;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) export - added "terse" option;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike2 - fixed rare kernel failure on address acquire;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) led - fixed ethernet LEDs on CCR1009 and RB1100AHx2 (introduced in v6.40rc1);
    *) led - fixed turning off LED when interface is lost;
    *) log - added "poe-out" topic;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved info channel background polling;
    *) lte - replaced "user-command" with "at-chat" command;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - do not skip >2462 channels if interface is WDS slave;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;

  • Release 6.40rc8 2017-05-19

    What's new in 6.40rc8 (2017-May-19 07:00):

    *) btest - fixed crash when packet size has been changed during test;
    *) defconf - added IPv6 firewall configuration (IPv6 package must be enabled on reset);
    *) defconf - replaced IPv4 firewall configuration with improved one;
    *) export - added "terse" option;
    *) firewall - do not allow to set "rate" value to 0 for "limit" parameter (CLI only);
    *) wireless - do not skip >2462 channels if interface is WDS slave;

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike2 - fixed rare kernel failure on address acquire;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) led - fixed ethernet LEDs on CCR1009 and RB1100AHx2 (introduced in v6.40rc1);
    *) led - fixed turning off LED when interface is lost;
    *) log - added "poe-out" topic;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) lte - improved info channel background polling;
    *) lte - replaced "user-command" with "at-chat" command;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - added "ifindex" on interface traps;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol (CLI only);
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol (CLI only);
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;

  • Release 6.40rc6 2017-05-16

    What's new in 6.40rc6 (2017-May-11 12:53):

    *) capsman - set minimal "caps-man-names" and "caps-man-certificate-common-names" length to 1 char;
    *) led - fixed ethernet LEDs on CCR1009 and RB1100AHx2 (introduced in v6.40rc1);
    *) led - fixed turning off LED when interface is lost;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - improved info channel background polling;
    *) lte - replaced "user-command" with "at-chat" command;
    *) snmp - added "ifindex" on interface traps;
    *) wireless - added option to change "nv2-downlink-ratio" for nv2 protocol (CLI only);
    *) wireless - added option to set "fixed-downlink" mode for nv2 protocol (CLI only);

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ike2 - fixed rare kernel failure on address acquire;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) log - added "poe-out" topic;
    *) lte - added additional driver support for DWR-910;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - fixed EAP PEAP success processing;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;

  • Release 6.40rc5 2017-05-09

    What's new in 6.40rc5 (2017-May-08 09:20):

    *) firewall - fixed IPv6 all address list entries becoming "::/0" (introduced in 6.40rc1);
    *) ike2 - fixed rare kernel failure on address acquire;
    *) log - added "poe-out" topic;
    *) lte - added initial support for "NTT DoCoMo" modem;
    *) wireless - always use "multicast-helper" when DHCP is being used;
    *) wireless - fixed compatibility with "AR5212" wireless chips;
    *) wireless - NAK any methods except MS-CHAPv2 as inner method in PEAP;

    Other changes since 6.39.1:

    *) 6to4 - fixed wrong IPv6 "link-local" address generation;
    *) arp - fixed "make-static";
    *) capsman - fixed EAP identity reporting in "registration-table";
    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) firewall - fixed "address-list" entry changing from IP to DNS and vice versa;
    *) firewall - "address-list" entry “creation-time” adjusted to timezone;
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;

  • Release 6.40rc4 2017-05-03

    What's new in 6.40rc4 (2017-May-03 05:15):

    *) conntrack - load IPv6 connection tracking independently of IPv4;
    *) console - fixed "No such file or directory" warnings on upgrade reboots;
    *) defconf - discard default configuration startup query with RouterOS upgrade;
    *) defconf - discard default configuration startup query with configuration change from Webfig;
    *) dns - made loading thousands of static entries faster;
    *) fetch - fixed user and password argument parsing from URL for FTP;
    *) log - work on false CPU/RAM overclocked alarms;
    *) lte - added additional driver support for DWR-910;
    *) smb - fixed external drive folder sharing when "/flash" folder existed;
    *) smb - fixed invalid default share after reboot when "/flash" folder existed;
    *) upnp - fixed firewall nat rule update when external IP address changes;

    Other changes since 6.39:

    *) 6to4 - fixed wrong IPv6 “link-local” address generation;
    *) arp - fixed “make-static”;
    *) capsman - fixed EAP identity reporting in “registration-table”;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) firewall - fixed “address-list” entry changing from IP to DNS and vice versa;
    *) firewall - “address-list” entry “creation-time” adjusted to timezone;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;

  • Release 6.40rc2 2017-04-28

    What's new in 6.40rc2 (2017-Apr-28 05:24):

    *) 6to4 - fixed wrong IPv6 “link-local” address generation;
    *) arp - fixed “make-static”;
    *) capsman - fixed EAP identity reporting in “registration-table”;
    *) dns - remove all dynamic cache RRs of same type when adding static entry;
    *) ethernet - fixed forced 10Mbps full-duplex linking on 100Mbps Ethernet ports;
    *) firewall - fixed “address-list” entry changing from IP to DNS and vice versa;
    *) firewall - “address-list” entry “creation-time” adjusted to timezone;
    *) firewall - fixed cosmetic "inactive" flag when item was disabled;
    *) ike1 - fixed crash on xauth message;
    *) ike1 - fixed minor memory leak on peer configuration change;
    *) ipsec - enabled modp2048 DH group by default;
    *) ipsec - optimized logging under IPSec topic;
    *) ipv6 - fixed address becoming invalid when interface was removed from bridge/mesh;
    *) log - work on false CPU/RAM overclocked alarms;
    *) pppoe - fixed warning on PPPoE server, when changing interface to non-slave interface;
    *) quickset - added "Band" setting to "CPE" and "PTP CPE" modes;
    *) routing - allow to disable "all" interface entry in BFD;
    *) sniffer - fixed VLAN tags when sniffing all interfaces;
    *) snmp - fixed limited walk;
    *) switch - fixed disabling of MAC learning on CRS1xx/CRS2xx;
    *) tile - fixed EoIP keepalive when tunnel is made over VLAN interface;
    *) winbox - added "eap-identity" to CAPsMAN registration table;
    *) winbox - added "no-dad" setting to IPv6 addresses;
    *) winbox - added TR069 support;
    *) winbox - do not allow to open multiple same sub-menus at the same time;
    *) wireless - fixed 802.11u wireless request processing;
    *) wireless - fixed EAP PEAP success processing;

  • Release 6.38rc46 2016-12-09

    What's new in 6.38rc46 (2016-Dec-07 06:53):

    *) dhcp-server - fixed when wizard was unable to create pool >dhcp_pool99;
    *) ipsec - allow empty policy SA dst-address in tunnel mode;
    *) ipsec - always listen to port TCP/4500 (fixes some IKEv2 setups without NAT-T);
    *) ipsec - various additional work on IKEv1/IKEv2 support;
    *) vrrp - do not show unrelated log warning messages about version mismatch;
    *) webfig - added extra protection against XSS exploits;
    *) webfig - show properly interface last-link-up/down times;

    Other changes since 6.37.3:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes";
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder;
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods;
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package) (cli only);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed pkcs12 export crash;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dns - added "max-concurrent-queries" and "max-concurrent-tcp-sessions" settings;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) export - updated default values to clean up export compact;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) firewall - significantly improved large firewall rule set import performance;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option;
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count";
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - fixed peer configuration my-id IPv4 address endianness;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipsec - split "mode-config" "send-dns" argument;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - added support for novatel USB620L;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - provide sinr in lte table;
    *) ssh - added routing-table setting (cli only);
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) time - updated time zones;
    *) traceroute - fixed memory leak;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) users - added minimal required permission set for full user group;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - show ipv6 addresses correctly;
    *) winbox - added "Complete" flag to arp table;
    *) winbox - added "untracked" option to firewall "connection-state" setting;
    *) winbox - added Dude icon to Dude menu;
    *) winbox - allow to enable/disable traffic flow targets;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed crash when legacy Winbox version was used;
    *) winbox - fixed default values for interface "loop-protect-disable-time" & "loop-protect-send-interval";
    *) winbox - fixed missing "ipv6/settings" menu;
    *) winbox - fixed typo in "propagate-ttl" setting;
    *) winbox - make cert signing include provided ca-crl-host;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) winbox - show proper ipv6 connection timeout;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc45 2016-12-08

    What's new in 6.38rc45 (2016-Dec-07 14:40):

    *) certificates - fixed pkcs12 export crash;
    *) ipsec - fixed peer configuration my-id IPv4 address endianness;
    *) ipsec - various additional work on IKEv1/IKEv2 support;
    *) winbox - added new ipsec feature (IKEv1/IKEv2/etc.) support (introduced in v6.38rc);
    *) winbox - fixed crash when legacy Winbox version was used;
    *) winbox - fixed icons in disabled state (introduced in v6.38rc44);

    Other changes since 6.37.3:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes";
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder;
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods;
    *) ipsec - added ability to specify static IP address at send-dns option;
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count";
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package) (cli only);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dns - added "max-concurrent-queries" and "max-concurrent-tcp-sessions" settings;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) export - updated default values to clean up export compact;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) firewall - significantly improved large firewall rule set import performance;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipsec - split "mode-config" "send-dns" argument;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - added support for novatel USB620L;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - provide sinr in lte table;
    *) ssh - added routing-table setting (cli only);
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) time - updated time zones;
    *) traceroute - fixed memory leak;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) users - added minimal required permission set for full user group;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - show ipv6 addresses correctly;
    *) winbox - added "Complete" flag to arp table;
    *) winbox - added "untracked" option to firewall "connection-state" setting;
    *) winbox - added Dude icon to Dude menu;
    *) winbox - allow to enable/disable traffic flow targets;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed default values for interface "loop-protect-disable-time" & "loop-protect-send-interval";
    *) winbox - fixed missing "ipv6/settings" menu;
    *) winbox - fixed typo in "propagate-ttl" setting;
    *) winbox - make cert signing include provided ca-crl-host;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) winbox - show proper ipv6 connection timeout;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc44 2016-12-07

    What's new in 6.38rc44 (2016-Dec-07 08:08):

    *) crs - added comment ability in more switch menus;
    *) dns - added "max-concurrent-queries" and "max-concurrent-tcp-sessions" settings;
    *) ipsec - split "mode-config" "send-dns" argument;
    *) ipsec - various additional work in IKEv1/IKEv2 support;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) tr069-client - various additional work;
    *) traceroute - fixed memory leak;
    *) users - added minimal required permission set for full user group;
    *) webfig - fixed preview of values bigger than 2 billion and lower than 4 billion (introduced in v6.38rc);
    *) webfig - show ipv6 addresses correctly;
    *) winbox - added "Complete" flag to arp table;
    *) winbox - added "untracked" option to firewall "connection-state" setting;
    *) winbox - added Dude icon to Dude menu;
    *) winbox - allow to enable/disable traffic flow targets;
    *) winbox - fixed default values for interface "loop-protect-disable-time" & "loop-protect-send-interval";
    *) winbox - fixed missing "ipv6/settings" menu;
    *) winbox - fixed typo in "propagate-ttl" setting;
    *) winbox - make cert signing include provided ca-crl-host;
    *) winbox - show proper ipv6 connection timeout;

    Other changes since 6.37.3:

    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) firewall - significantly improved large firewall rule set import performance;
    *) time - updated time zones;
    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package) (cli only);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from "/ip neighbor discovery menu";
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) export - updated default values to clean up export compact;
    *) fastpath - fixed rare crash;
    *) fastpath - fixed x86 bridge fast-path status shown as active even if it is manually disabled;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - added sctp/dccp/udp-lite support for "src-port", "dst-port", "port" and "to-ports" firewall options;
    *) firewall - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) firewall - fixed dynamic raw rule behaviour;
    *) firewall - fixed rule activation if "time" option is used and no other active rules are present;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed camellia crypto algorithm module loading;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - load ipv6 related modules only when ipv6 package is enabled;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) lcd - improved performance, causes less cpu load;
    *) led - fixed dark mode for cAP 2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for more Vodafone K4201-Z, PANTECH UML295 and ZTE MF90 modems;
    *) lte - added support for novatel USB620L;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222, Pantech UML296 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - fixed packet size calculation when MRRU is set (was 2 bytes bigger than MTU allows);
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) ppp - significantly improved tunnel termination process on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed "time" option by recognizing weekday properly (introduced in v6.37.2);
    *) rb750Gr3 - fixed ipsec with 3des+md5 to work on this board;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - provide sinr in lte table;
    *) ssh - added routing-table setting (cli only);
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc37 2016-11-25

    What's new in 6.38rc37 (2016-Nov-25 11:03):

    !) tr069-client - initial implementation (as separate package);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) firewall - fixed filter rule "limit" parameter by making it visible again;
    *) hAP lite - fixed bootup (broken in v6.38rc35);

    Other changes since 6.37.2:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bgp - do not match all prefixes tagged with community 0:0 by routing filters;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) chr - fixed "/interface print";
    *) chr - fixed crash on "/interface print" (introduced in 6.36.4);
    *) chr - fixed crash on "/system shutdown" and "/system shutdown";
    *) chr - fixed reboot;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) disk - fixed issue when disk was renamed after reboot on devices with flash disks;
    *) dns - do not resolve incorrect addresses after changes made in static dns entries;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed rare crash;
    *) file - fixed file manager crash when file transfer gets cancelled;
    *) firewall - added creation-time to address list entries;
    *) firewall - fixed timeout option on address lists with domain name;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) log - ignore email topic if action is email;
    *) lte - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - fixed Pantech UML296 support;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mipsbe - improved memory allocation on devices with nand when file transfer and tcp traffic processing is on progress;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) ppp - significantly improved shutdown speed on servers with many active tunnels;
    *) profiler - added ability to monitor cpu usage per core;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) smb - fixed crash on connect (introduced in 6.38rc1);
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) tile - fixed rare kernel failure when IPv6 neighbor discovery packet is received;
    *) traceroute - fixed crash when too many sessions are active;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - allow to force mtu value when actual-mtu is already the same;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - recognise properly tcp in traffic-generator packet-template header type;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show HT MCS tab if 2GHz-G/N band is used;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc35 2016-11-23

    What's new in 6.38rc35 (2016-Nov-23 09:55):

    *) disk - fixed issue when disk was renamed after reboot on devices with flash disks;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) tunnel - allow to force mtu value when actual-mtu is already the same;
    *) tunnel - fixed transmit packets occasionally not going through fastpath;

    Other changes since 6.37.2:

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bgp - do not match all prefixes tagged with community 0:0 by routing filters;
    *) bonding - added "forced-mac-address" option;
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - added support for PKCS#12 export;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) chr - fixed "/interface print";
    *) chr - fixed crash on "/interface print" (introduced in 6.36.4);
    *) chr - fixed crash on "/system shutdown" and "/system shutdown";
    *) chr - fixed reboot;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - do not resolve incorrect addresses after changes made in static dns entries;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed rare crash;
    *) firewall - added creation-time to address list entries;
    *) firewall - fixed timeout option on address lists with domain name;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) log - ignore email topic if action is email;
    *) lte - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - fixed Pantech UML296 support;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) profiler - added ability to monitor cpu usage per core;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) smb - fixed crash on connect (introduced in 6.38rc1);
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) tile - fixed rare kernel failure when IPv6 neighbor discovery packet is received;
    *) traceroute - fixed crash when too many sessions are active;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - recognise properly tcp in traffic-generator packet-template header type;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show HT MCS tab if 2GHz-G/N band is used;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc34 2016-11-22

    What's new in 6.38rc34 (2016-Nov-22 10:40):

    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set xauth-use-radius=yes" (cli only);
    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation (cli only);
    !) tr069-client - initial implementation (as separate package);
    *) bonding - added "forced-mac-address" option;
    *) certificates - added support for PKCS#12 export;
    *) chr - fixed crash on "/interface print" (introduced in 6.36.4);
    *) chr - fixed crash on "/system shutdown" and "/system shutdown";
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) firewall - new faster "connection-limit" option implementation;
    *) ospf - fixed route crash caused by memory corruption when there are multiple active interfaces;
    *) smb - fixed crash on connect (introduced in 6.38rc1);
    *) tile - fixed rare kernel failure when IPv6 neighbor discovery packet is received;
    *) traceroute - fixed crash when too many sessions are active;
    *) winbox - recognise properly tcp in traffic-generator packet-template header type;
    *) winbox - show HT MCS tab if 2GHz-G/N band is used;
    *) wireless - added CRL checking for eap-tls;

    Other changes since 6.37.2:

    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) bgp - do not match all prefixes tagged with community 0:0 by routing filters;
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - fixed crash when crl is removed while it is being fetched;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) chr - fixed "/interface print";
    *) chr - fixed reboot;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - request dhcp options only if dhcp client is successfully added;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - do not resolve incorrect addresses after changes made in static dns entries;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed rare crash;
    *) firewall - added creation-time to address list entries;
    *) firewall - fixed timeout option on address lists with domain name;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) log - ignore email topic if action is email;
    *) lte - added support for PANTECH UML295;
    *) lte - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed Pantech UML296 support;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) profiler - added ability to monitor cpu usage per core;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) system - reboot device on critical program crash;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc31 2016-11-15

    What's new in 6.38rc31 (2016-Nov-15 12:51):

    !) ipsec - added IKEv2 EAP RADIUS passthrough authentication for responder (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    *) bgp - do not match all prefixes tagged with community 0:0 by routing filters;
    *) certificate - fixed crash when crl is removed while it is being fetched;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) log - ignore email topic if action is email;

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set radius=yes" (cli only);
    !) ipsec - added support unique policy generation which will allow multiple peers behind the same NAT (cli only);
    !) queues - significantly improved hashing algorithm in dynamic simple queue setups (fixes CPU load spikes on queue removal);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arm - improved watchdog reliability;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option (cli only);
    *) bonding - fixed 802.3ad load balancing over routed VLANs with fastpath enabled;
    *) bonding - fixed mac address selection after upgrade;
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) chr - fixed "/interface print";
    *) chr - fixed reboot;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed port mirroring halt after L2MTU change;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - do not resolve incorrect addresses after changes made in static dns entries;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) ethernet - fixed potential loopprotect crash;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed kernel failure when fastpath traffic goes into loop;
    *) fastpath - fixed rare crash;
    *) fastpath - improved connection tracking timeout updates;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - fixed "connection-state" value disappearance in rules that were created before v6.22;
    *) firewall - fixed compact export (introduced in 6.37rc14);
    *) firewall - fixed timeout option on address lists with domain name;
    *) firewall - improved "time" option (ranges like 22h-10h now are acceptable);
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipv6 - increased default max-neighbor-entries value to 8192, same as ipv4;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - fixed Pantech UML296 support;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) mmips - improved watchdog reliability;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed rare crash on statistic gathering in "/queue tree";
    *) queue - improved "time" option (ranges like 22h-10h are now usable);
    *) rb2011 - fixed crash on l2mtu changes;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) ssl - fixed potential memory leak ( when using dude for example);
    *) system - reboot device on critical program crash;
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vlan - fixed CRS switch egress-vlan-tag export;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - added led settings menu;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed missing switch menu for mmips devices;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc30 2016-11-14

    What's new in 6.38rc30 (2016-Nov-14 13:20):

    *) dns - do not resolve incorrect addresses after changes made in static dns entries;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) firewall - fixed timeout option on address lists with domain name;
    *) system - reboot device on critical program crash;

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set radius=yes" (cli only);
    !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only);
    !) ipsec - added support unique policy generation which will allow multiple peers behind the same NAT (cli only);
    !) queues - significantly improved hashing algorithm in dynamic simple queue setups (fixes CPU load spikes on queue removal);
    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) tr069-client - initial implementation (as separate package);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arm - improved watchdog reliability;
    *) arp - added local-proxy-arp feature;
    *) bonding - added "forced-mac-address" option (cli only);
    *) bonding - fixed 802.3ad load balancing over routed VLANs with fastpath enabled;
    *) bonding - fixed mac address selection after upgrade;
    *) bridge - fixed filter Ingress Priority option (broken in v6.38rc16);
    *) bridge - fixed rare crash on bridge port removal;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) ccr - added AHCI driver for Samsung XP941 128GB AHCI M.2;
    *) certificates - allow import multiple certs with the same key;
    *) certificates - fixed trust chain update on local certificate revocation in programs using ssl;
    *) certificates - if no name provided create certificate name automatically from certificate fields;
    *) chr - fixed "/interface print";
    *) chr - fixed reboot;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) crs - added comment ability in more switch menus;
    *) crs - fixed port mirroring halt after L2MTU change;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) crs226 - fixed sfp-sfpplus1 link re-negotiation (broken in 6.37rc28/v6.37.1);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - fixed issue when dhcp-client was still possible on interfaces with "slave" flag and using slave interface MAC address;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - added "k" and "M" unit support to Ethernet Bandwidth setting;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) ethernet - fixed potential loopprotect crash;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) fastpath - fixed kernel failure when fastpath traffic goes into loop;
    *) fastpath - fixed rare crash;
    *) fastpath - improved connection tracking timeout updates;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - fixed "connection-state" value disappearance in rules that were created before v6.22;
    *) firewall - fixed compact export (introduced in 6.37rc14);
    *) firewall - improved "time" option (ranges like 22h-10h now are acceptable);
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - changed loopback interface mtu to 1500;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - added ph2 accounting for each policy "/ip ipsec policy ph2-count" (cli only);
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) ipsec - don't generate unnecessary ah+esp policies;
    *) ipsec - fixed generated policy lookup with ah+esp proposal;
    *) ipsec - non passive peers will also establish SAs from policy without waiting for the first packet;
    *) ipsec - send xauth password without trailing null;
    *) ipv6 - increased default max-neighbor-entries value to 8192, same as ipv4;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) log - fixed "System rebooted because of kernel failure" message to show after 1st crash reboot;
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - fixed Pantech UML296 support;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mmips - fixed traffic accounting in "/interface" menu;
    *) mmips - improved watchdog reliability;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified;
    *) profiler - added ability to monitor cpu usage per core;
    *) queue - fixed rare crash on statistic gathering in "/queue tree";
    *) queue - improved "time" option (ranges like 22h-10h are now usable);
    *) rb2011 - fixed crash on l2mtu changes;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) resolver - ignore cache entries if specific server is used;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) ssl - fixed potential memory leak ( when using dude for example);
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) traffic-flow - fixed flow sequence counter and length;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vlan - fixed CRS switch egress-vlan-tag export;
    *) webfig - fixed smaller than /24 ip address configuration (broken in v6.38rc3);
    *) winbox - added led settings menu;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - fixed missing switch menu for mmips devices;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - added CRL checking for eap-tls;
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;
    *) wireless - take in account channel width when returning supported channels;

  • Release 6.38rc19 2016-10-31

    What's new in 6.38rc19 (2016-Oct-24 11:19):

    !) snmp - added basic get and walk functionality "/tool snmp-[get|walk]";
    *) chr - fixed "/interface print";
    *) chr - fixed reboot;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) fastpath - fixed kernel failure when fastpath traffic goes into loop;
    *) fastpath - fixed rare crash;
    *) interface - changed loopback interface mtu to 1500;
    *) ipsec - added ability to specify static IP address at send-dns option (CLI only);
    *) ipsec - send xauth password without trailing null;
    *) led - fixed cAP 2nD stuck in dark mode all the time;
    *) lte - fixed Pantech UML296 support;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified;
    *) profiler - added ability to monitor cpu usage per core;
    *) resolver - ignore cache entries if specific server is used;
    *) ssh - fixed lost "/ip ssh" settings on upgrade from version older than 5.15;
    *) trafficgen - fixed potential crash when very big frame is generated;
    *) vlan - allow to add multiple vlans which name starts with same number and has same length;
    *) vlan - fixed CRS switch egress-vlan-tag export;
    *) winbox - added led settings menu;
    *) winbox - allow to run profiler from "/system resources" menu;
    *) winbox - fixed missing switch menu for mmips devices;
    *) winbox - properly show VHT basic and supported rates in CAPsMAN;
    *) wireless - added CRL checking for eap-tls;
    *) wireless - take in account channel width when returning supported channels;

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) ethernet - fixed potential loopprotect crash;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - fixed compact export (introduced in 6.37rc14);
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) rb2011 - fixed crash on l2mtu changes;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;

  • Release 6.38rc15 2016-10-14

    What's new in 6.38rc15 (2016-Oct-14 09:11):

    *) dhcp - fixed dhcp-client crash (introduced in 6.37rc14);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) firewall - fixed compact export (introduced in 6.37rc14);
    *) rb2011 - fixed crash on l2mtu changes;

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) ethernet - fixed potential loopprotect crash;
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) firewall - new faster "connection-limit" option implementation;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) lte - added support for PANTECH UML295;
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified (CLI only);
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;

  • Release 6.38rc14 2016-10-13

    What's new in 6.38rc14 (2016-Oct-13 04:52):

    !) fastpath - let one packet per second through slow path to properly update connection timeouts;
    *) console - fixed "/interface ethernet switch export" on some boards;
    *) discovery - removed 6to4 tunnels from /ip neighbor discovery menu;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - fixed potential loopprotect crash;
    *) firewall - new faster "connection-limit" option implementation;
    *) lte - added support for PANTECH UML295;

    Other changes since 6.37.1:

    !) ethernet - optimized packet processing on low load when irq re-balance is not necessary;
    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    !) winbox - now Winbox 3.7 is the minimum version that can connect to RouterOS;
    *) arp - added local-proxy-arp feature;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) crs - fixed rare kernel failure on switch reset (for example, reboot);
    *) dhcp - do not allow to create dhcp-server on slave interface;
    *) dhcp - show dhcp server as invalid and log an error when interface becomes a slave;
    *) discovery - added LLDP support;
    *) dns - improved static dns entry add speed when regexp is being used;
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) export - do not show interface comment in "/ip neighbor discovery" menu;
    *) firewall - added creation-time to address list entries;
    *) firewall - do not allow to increase/decrease ttl and hop-limit by 0;
    *) firewall - increased max size of connection tracking table to 1048576;
    *) health - show power consumption on devices which has voltage and current monitor;
    *) hotspot - fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) led - fixed dark mode for cAP2nD (http://wiki.mikrotik.com/wiki/Manual:System/LEDS#Leds_Setting);
    *) lte - allow to execute concurrent info commands;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) lte - increased delay when setting sms send mode;
    *) lte - return info data when all the fields are populated;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) package - show minimal supported RouterOS version under "/system resource" menu if it is specified (CLI only);
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) routerboot - show log message if router CPU/RAM is overclocked;
    *) script - increment run count value when script is executed from snmp;
    *) sms - fixed crash after modem has failed to start;
    *) snmp - provide sinr in lte table;
    *) torch - fixed aggregate statistics appearance;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) trafficgen - improved fastpath support;
    *) tunnel - properly export keepalive value;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;

  • Release 6.38rc9 2016-10-05

    What's new in 6.38rc9 (2016-Oct-05 10:23):

    !) switch - added hardware stp functionality for CRS devices and small Atheros switch chips (http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Spanning_Tree_Protocol);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=112599);
    *) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
    *) package – show minimal supported RouterOS version under “/system resource” menu if it is specified (CLI only);
    *) sms – fixed crash after modem has failed to start;
    *) traffic-flow - fixed dst-port reporting if connection is not maintained by connection tracking;

    Other changes since 6.37.1:

    *) arp - added local-proxy-arp feature;
    *) capsman - added possibility to change arp, mtu, l2mtu values in datapath configuration;
    *) discovery - added LLDP support;
    *) firewall - added creation-time to address list entries;
    *) interface - do not treat multiple zeros as single zero on name comparison;
    *) interface - show link stats in "/interface print stats-detail" output;
    *) ipsec - allow to specify explicit split dns address;
    *) ipsec - changed logging topic from error to debug for ph2 transform mismatch messages;
    *) ipsec - changed logging topic from error to debug when empty pfkey messages are received;
    *) lte - fixed dwm-222 support;
    *) lte - fixed init delay after power reset;
    *) mobile - added support for more Vodafone K4201-Z and ZTE MF90 modems;
    *) rb850Gx2 - fixed pcb temperature monitor if temperature was above 60C;
    *) torch - fixed aggregate statistics appearance;
    *) trafficgen - fixed crash when IPv6 traffic is processed;
    *) usb - fixed kernel failure when Nexus 6P device is removed;
    *) userman - fixed memory leak on user limitation calculations;
    *) users - added TikApp policy;
    *) winbox - do not show hotspot user profile incoming and outgoing filters and marks as set if there is no value specified;
    *) winbox - removed spare values from loop-protect menu;
    *) winbox - show primary and secondary ntp addresses as 0.0.0.0 if none are set;
    *) wireless - added api command to report country-list (/interface/wireless/info/country-list);
    *) wireless - fixed custom channel extension-channel appearance in console;
    *) wireless - fixed rare kernel failure when connecting to nv2 access point with legacy rate select;

  • Release 6.37rc42 2016-09-22

    What's new in 6.37rc42 (2016-Sep-22 11:07):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country settings (/interface wireless info country-info), and applies corresponding DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc40:

    !) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) certificate - do not allow to remove certificate template while signing certificate;
    *) dhcpv6 - fixed interface status update on client add (introduced in v6.37rc);
    *) firewall - fixed time based rules on time/timezone changes (again);
    *) ipsec - fixed crash with enabled fragmentation;
    *) ipsec - fixed fragmentation use negotiation;
    *) lte - added hauwei me909s variant;
    *) lte - fixed setting correct lte band for sxt lte;
    *) traffic-flow - fixed IPFIX packet timestamp;
    *) traffic-flow - fixed IPFIX wrong flow sequence;

    Other changes since 6.36.3:

    *) dhcpv6 - reworked DHCP-PD server interface and route management;
    *) tunnel - fixed communication via tunnel to router itself if fastpath was active;
    *) wireless - fixed interface disappearance on upgrade to 6.37 (introduced in v6.37rc);
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - fixed kernel crash on cap while changing client-to-client forwarding;
    *) capsman - report radio-name in registration table;
    *) console - hotspot setup show wrong certificate name;
    *) defconf - fixed default configuration restore if virtual wireless interface were present;
    *) defconf - fixed default configuration when wireless package is used;
    *) defconf - using caps button now forces all wireless interfaces in caps mode;
    *) dhcpv6 - improved interface status tracking;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) gps - always check NMEA checksum if available;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - fixed RA and RS processing on new interfaces after many interfaces have lost link during prolonged operation;
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added switch for Huawei K5160;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed memory leak;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) packages - fixed situation when it was impossible to disable ipv6 package (introduced in v6.37rc3x);
    *) partitions - added ability to add comments;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) ppp,lte - pin is now converted to string argument;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) supout - improved crash report generation for tile architecture;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) users - fixed script policy checking against user policies when running scripts;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed unset button for L2MTU field;
    *) winbox - show firmware-type in routerboard window;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc40 2016-09-20

    What's new in 6.37rc40 (2016-Sep-20 10:55):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country settings (/interface wireless info country-info), and applies corresponding DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc38:

    *) dhcpv6 - reworked DHCP-PD server interface and route management;
    *) tunnel - fixed communication via tunnel to router itself if fastpath was active;
    *) wireless - fixed interface disappearance on upgrade to 6.37 (introduced in v6.37rc);

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - fixed kernel crash on cap while changing client-to-client forwarding;
    *) capsman - report radio-name in registration table;
    *) console - hotspot setup show wrong certificate name;
    *) defconf - fixed default configuration restore if virtual wireless interface were present;
    *) defconf - fixed default configuration when wireless package is used;
    *) defconf - using caps button now forces all wireless interfaces in caps mode;
    *) dhcpv6 - improved interface status tracking;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) gps - always check NMEA checksum if available;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - fixed RA and RS processing on new interfaces after many interfaces have lost link during prolonged operation;
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added switch for Huawei K5160;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed memory leak;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) packages - fixed situation when it was impossible to disable ipv6 package (introduced in v6.37rc3x);
    *) partitions - added ability to add comments;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) ppp,lte - pin is now converted to string argument;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) supout - improved crash report generation for tile architecture;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) users - fixed script policy checking against user policies when running scripts;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed unset button for L2MTU field;
    *) winbox - show firmware-type in routerboard window;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc38 2016-09-19

    What's new in 6.37rc38 (2016-Sep-19 09:42):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc36:

    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    *) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - fixed kernel crash on cap while changing client-to-client forwarding;
    *) capsman - report radio-name in registration table;
    *) console - hotspot setup show wrong certificate name;
    *) defconf - fixed default configuration restore if virtual wireless interface were present;
    *) defconf - fixed default configuration when wireless package is used;
    *) defconf - using caps button now forces all wireless interfaces in caps mode;
    *) dhcpv6 - improved interface status tracking;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) gps - always check NMEA checksum if available;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - fixed RA and RS processing on new interfaces after many interfaces have lost link during prolonged operation;
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added switch for Huawei K5160;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed memory leak;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) packages - fixed situation when it was impossible to disable ipv6 package (introduced in v6.37rc3x);
    *) partitions - added ability to add comments;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) ppp,lte - pin is now converted to string argument;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) supout - improved crash report generation for tile architecture;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) users - fixed script policy checking against user policies when running scripts;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed unset button for L2MTU field;
    *) winbox - show firmware-type in routerboard window;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc36 2016-09-15

    What's new in 6.37rc36 (2016-Sep-14 10:12):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc34:

    *) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) defconf - fixed default configuration restore if virtual wireless interface were present;
    *) defconf - using caps button now forces all wireless interfaces in caps mode;
    *) console - hotspot setup show wrong certificate name;

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - fixed kernel crash on cap while changing client-to-client forwarding;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - improved interface status tracking;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) gps - always check NMEA checksum if available;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - fixed RA and RS processing on new interfaces after many interfaces have lost link during prolonged operation;
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added switch for Huawei K5160;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed memory leak;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) packages - fixed situation when it was impossible to disable ipv6 package (introduced in v6.37rc3x);
    *) partitions - added ability to add comments;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) ppp,lte - pin is now converted to string argument;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) supout - improved crash report generation for tile architecture;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) users - fixed script policy checking against user policies when running scripts;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed unset button for L2MTU field;
    *) winbox - show firmware-type in routerboard window;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc34 2016-09-13

    What's new in 6.37rc34 (2016-Sep-12 13:06):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc32:

    *) capsman - fixed kernel crash on cap while changing client-to-client forwarding;
    *) dhcpv6 - improved interface status tracking;
    *) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) gps - always check NMEA checksum if available;
    *) ipv6 - fixed RA and RS processing on new interfaces after many interfaces have lost link during prolonged operation;
    *) mpls - fixed memory leak;
    *) packages - fixed situation when it was impossible to disable ipv6 package (introduced in v6.37rc3x);
    *) ppp,lte - pin is now converted to string argument;
    *) supout - improved crash report generation for tile architecture;

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added switch for Huawei K5160;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) users - fixed script policy checking against user policies when running scripts;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed unset button for L2MTU field;
    *) winbox - show firmware-type in routerboard window;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc32 2016-09-07

    What's new in 6.37rc32 (2016-Sep-07 10:55):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc30:

    *) dude - (changes discussed here: viewtopic.php?f=8&t=110424);
    *) ipv6 - improved system responsiveness when ipv6 routes are frequently modified;
    *) lte - added switch for Huawei K5160;
    *) ppp - use default-route-distance when adding ipv6 default route;
    *) quickset - added 2GHz-g/n band support;
    *) quickset - fixed guest reporting in "home ap dual" mode;
    *) quickset - fixed wireless frequency fields in "home ap dual" mode;
    *) trafficgen - show out-of-order packet counters in stats printouts;
    *) tunnel - fixed ipv6 link-local address adding for gre;
    *) users - fixed script policy checking against user policies when running scripts;
    *) winbox - added default-authentication parameter for wireless station modes;
    *) winbox - adjust on-event field dynamically depending on window size;
    *) winbox - display actual-mtu for tunnels in interfaces window;
    *) winbox - fixed multiline read only fields not displaying new line characters;
    *) winbox - fixed raw firewall showing jump targets from filter chains;
    *) winbox - removed health menu from devices that do not support it;
    *) winbox - removed L2MTU field from PPP server binding settings;
    *) winbox - show firmware-type in routerboard window;

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed neverending loop in CDP packet processing;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fix add/remove of disabled interfaces;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed band unsetting;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) trafficgen - add per stream packet count setting;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed unset button for L2MTU field;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc30 2016-09-06

    What's new in 6.37rc30 (2016-Sep-06 06:59):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    There will be only one "wireless" package starting from RouterOS v6.37.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc27:

    *) dns - fixed crash when using regexp static dns entries;
    *) ethernet - fixed loop-protect on bridged ports;
    *) ethernet - fixed never-ending loop in CDP packet processing;
    *) ipv6 - show multiple neighbors with the same address;
    *) kvm - fixed guest crashing when using MTU bigger than 1504;
    *) leds - added option to disable all leds on RBcAP2n;
    *) lte - added switch for Huawei K5160;
    *) lte - fixed band unsetting;
    *) pppoe - fixed disconnects by idle timeout when fastpath is used;
    *) rb3011 - fixed rare occasions when router would hang while loading kernel;
    *) sfp - fixed initial eeprom reading on CCR1036-8G-2S+ and CCR1072-1G-8S+;
    *) trafficgen - add per stream packet count setting;
    *) tunnel - fixed link status flapping when remote end is not responding (introduced in 6.37rc);
    *) tunnel - increased minimal MRRU to 1500 for PPP interfaces;
    *) webfig - fixed certificate signing;
    *) winbox - added auto refresh for BFD neighbors;
    *) winbox - added comment field support for switch vlan menu;
    *) winbox - adjusted allowed values for http-proxy field;
    *) winbox - disabled MRRU by default for PPP interfaces;
    *) winbox - removed L2MTU field for PPP interfaces;
    *) winbox - removed unset button for L2MTU field;

    Other changes since 6.36.3:

    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed, corresponding DFS mode for each frequency range applies automatically;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) kvm - fix add/remove of disabled interfaces;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added zte K5008-Z back;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) switch - added comment field for CRS switch VLANs;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) usermanager - fixed rare crash on paypal payment;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) wireless - updated brazil country settings.

  • Release 6.37rc27 2016-09-02

    What's new in 6.37rc27 (2016-Sep-02 06:18):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc26:

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) ethernet - allow to force mtu value when actual-mtu is already the same;
    *) ethernet - rb44ge now have disabled-running-check=no by default;
    *) ipsec - fixed dynamic policy not deleted on disconnect for nat-t peers;
    *) kvm - fix add/remove of disabled interfaces;
    *) lte - added rndis for ZTE MF8xx;
    *) lte - adjusted usb config for dlink dwm-157 D;
    *) mpls - fixed vpls throughput issues caused by out-of-order packets;
    *) usermanager - fixed rare crash on paypal payment;

    Other changes since 6.36.2:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces, http://wiki.mikrotik.com/wiki/Manual:Loop_Protect ;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) fastpath - fixed kernel crash on interface disable/remove;
    *) fetch - fixed bug with incomplete files in https mode;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - don't log authtype mismatch as critical;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipsec - fixed xauth parameter printing in terminal;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added zte K5008-Z back;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) pppoe - fixed master interface l2mtu check, could result in assumption that master interface can handle 14 byte bigger packet than it actually can (broken in 6.36);
    *) routing - improved kernel performance in setups with large routing tables;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) simple queues - fixed issue which caused additional/unnecessary CPU load;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - require write permitions for script run table access;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - now supports TLS_ECDHE algorithms;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) switch - added comment field for CRS switch VLANs;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vlan - do not allow to add new vlan interface with mtu higher than l2mtu;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc26 2016-08-31

    What's new in 6.37rc26 (2016-Aug-31 11:25):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc24:

    !) ethernet - added new loop-protect feature for ethernet,vlan,eoip,eoipv6 interfaces (http://wiki.mikrotik.com/wiki/Manual:Loop_Protect);
    *) fastpath - fixed kernel crash on interface disable/remove;
    *) fetch - fixed bug with incomplete files in https mode;
    *) routing - improved kernel performance in setups with large routing tables;
    *) snmp - require write permitions for script run table access;
    *) sstp - now supports TLS_ECDHE algorithms;

    Other changes since 6.36.2:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) ipsec - don't log authtype mismatch as critical;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipsec - fixed xauth parameter printing in terminal;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added zte K5008-Z back;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed default channels for dlink dwm-157;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) pppoe - fixed master interface l2mtu check, could result in assumption that master interface can handle 14 byte bigger packet than it actually can (broken in 6.36);
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) simple queues - fixed issue which caused additional/unnecessary CPU load;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - skip forbidden oids on getnext completion;
    *) sstp - allow to specify proxy by dns name;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) switch - added comment field for CRS switch VLANs;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vlan - do not allow to add new vlan interface with mtu higher than l2mtu;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc24 2016-08-30

    What's new in 6.37rc24 (2016-Aug-30 11:57):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc22:

    *) dhcpv6 - update DUID when system-id changes (solves problem when cloned VM retains the same DUID);
    *) ipsec - don't log authtype mismatch as critical;
    *) ipsec - fixed kernel crash when sha512 was used;
    *) ipsec - fixed xauth parameter printing in terminal;
    *) lte - added support for more dlink dwm-222 configurations;
    *) lte - added zte K5008-Z back;
    *) lte - fixed default channels for dlink dwm-157;
    *) pppoe - fixed master interface l2mtu check, could result in assumption that master interface can handle 14 byte bigger packet than it actually can (broken in 6.36);
    *) snmp - skip forbidden oids on getnext completion;
    *) supout - fixed bug that could cause enormous size supout.rif files;
    *) usb - fixed usb port reset on ether1 link changes on mAP 2n;

    Other changes since 6.36.2:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added dlink dwm-157 D, dwm-222 support;
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added logging for usb config switching;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) simple queues - fixed issue which caused additional/unnecessary CPU load;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) sstp - allow to specify proxy by dns name;
    *) switch - added comment field for CRS switch VLANs;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vlan - do not allow to add new vlan interface with mtu higher than l2mtu;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc22 2016-08-25

    What's new in 6.37rc22 (2016-Aug-25 09:01):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info), and applies corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with corresponding DFS settings before upgrade.

    Changes since 6.37rc21:

    *) ethernet - fixed rare kernel failure on non-switch ethernet reset;
    *) simple queues - fixed issue which caused additional/unnecessary CPU load;

    Other changes since 6.36.2:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) hotspot - show comments from user menu also in active menu;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) sstp - allow to specify proxy by dns name;
    *) switch - added comment field for CRS switch VLANs;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vlan - do not allow to add new vlan interface with mtu higher than l2mtu;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.
    *) wireless - updated brazil country settings;

  • Release 6.37rc21 2016-08-25

    What's new in 6.37rc21 (2016-Aug-25 06:15):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS CHANGES:

    DFS configuration in RouterOS has been redesigned, now device looks at specified country
    settings (/interface wireless info country-info ), and apply corresponding
    DFS mode for each frequency range automatically, making dfs-mode setting unnecessary.

    Please, check that your frequencies work with correcponding DFS settings before upgrade.

    Changes since 6.37rc20:

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) hotspot - show comments from user menu also in active menu;
    *) tunnel - ipv6 link-local address is now generated from tunnel local-address;
    *) vlan - do not allow to add new vlan interface with mtu higher than l2mtu;
    *) wireless - updated brazil country settings;

    Other changes since 6.36.2:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) capsman - report radio-name in registration table;
    *) defconf - fixed default configuration when wireless package is used;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) sstp - allow to specify proxy by dns name;
    *) switch - added comment field for CRS switch VLANs;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode.

  • Release 6.37rc20 2016-08-19

    What's new in 6.37rc20 (2016-Aug-19 06:35):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc19:

    *) address-list - fixed crash (introduced in 6.37rc17);
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) export - updated default values in /system routerboard settings menu;
    *) sfp - enabled eeprom printout in /interface ethernet monitor;
    *) sfp - removed "sfp-rate-select" as command was not relevant to currently supported hardware;
    *) trafficgen - fixed crash (introduced in 6.37rc17);

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) arm - show cpu frequency under resources menu;
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) capsman - fixed upgrade policy;
    *) capsman - report radio-name in registration table;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) defconf - fixed default configuration when wireless package is used;
    *) disk - do not do unnecessary sector writes;
    *) dns - allow to set query-server-timeout and query-total-timeout only greater than 0s;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dns - fixed lockup when dynamic dns server address 0.0.0.0 was received;
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - added additional matchers for firewall raw rules;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) health - do not show psu and fan information for passive cooling devices;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) partitions - fixed crash on repartition when there is not enough free space;
    *) ping - fixed freezing on "not running" interfaces;
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - fixed disconnects on transmit for multicore systems;
    *) switch - added comment field for CRS switch VLANs;
    *) switch - fixed configuration reload on CRS switches;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) webfig - allowed user password changing (broken in v6.36);
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - make queue tree default queue type default-small;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc19 2016-08-18

    What's new in 6.37rc19 (2016-Aug-18 06:46):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc16:

    *) arm - show cpu frequency under resources menu;
    *) arp - fixed crash that caused Ethernet frames to go out via wrong interface;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) pppoe - fixed kernel crash caused by dial-on-demand when used with fastpath;


    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) capsman - fixed upgrade policy;
    *) capsman - report radio-name in registration table;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) defconf - fixed default configuration when wireless package is used;
    *) disk - do not do unnecessary sector writes;
    *) dns - allow to set query-server-timeout and query-total-timeout only greater than 0s;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dns - fixed lockup when dynamic dns server address 0.0.0.0 was received;
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - added additional matchers for firewall raw rules;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) health - do not show psu and fan information for passive cooling devices;
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) partitions - fixed crash on repartition when there is not enough free space;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - fixed disconnects on transmit for multicore systems;
    *) switch - added comment field for CRS switch VLANs;
    *) switch - fixed configuration reload on CRS switches;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) webfig - allowed user password changing (broken in v6.36);
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - make queue tree default queue type default-small;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc16 2016-08-15

    What's new in 6.37rc16 (2016-Aug-15 07:48):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc15:

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) l2tp - fixed kernel failure when fastpath handles l2tp packets;
    *) switch - added comment field for CRS switch VLANs;
    *) switch - fixed configuration reload on CRS switches;

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) capsman - fixed upgrade policy;
    *) capsman - report radio-name in registration table;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) defconf - fixed default configuration when wireless package is used;
    *) disk - do not do unnecessary sector writes;
    *) dns - allow to set query-server-timeout and query-total-timeout only greater than 0s;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dns - fixed lockup when dynamic dns server address 0.0.0.0 was received;
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - added additional matchers for firewall raw rules;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) health - do not show psu and fan information for passive cooling devices;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) partitions - fixed crash on repartition when there is not enough free space;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - fixed disconnects on transmit for multicore systems;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) webfig - allowed user password changing (broken in v6.36);
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - make queue tree default queue type default-small;
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc15 2016-08-11

    What's new in 6.37rc15 (2016-Aug-11 09:14):

    --- IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    --- IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc13:

    *) capsman - fixed upgrade policy;
    *) capsman - report radio-name in registration table;
    *) dns - allow to set query-server-timeout and query-total-timeout only greater than 0s;
    *) dns - fixed lockup when dynamic dns server address 0.0.0.0 was received;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) firewall - added additional matchers for firewall raw rules;
    *) health - do not show psu and fan information for passive cooling devices;
    *) sstp - allow to specify proxy by dns name;
    *) sstp - fixed disconnects on transmit for multicore systems;
    *) traffic-flow - allow ipv6 src address to be optional;
    *) webfig - do not crash if radius server does not give out encryption keys;
    *) winbox - added src-address field for traffic-flow target;
    *) winbox - fixed disconnect when no windows were opened for a while in unsecure mode;
    *) winbox - hide ethernet flow control settings for interfaces which does not support them;
    *) winbox - make queue tree default queue type default-small;

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) defconf - fixed default configuration when wireless package is used;
    *) disk - do not do unnecessary sector writes;
    *) dns - avoid unnecessary static entry saving in storage;
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added initial deregistration only for bandrich modems;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) partitions - added ability to add comments;
    *) partitions - fixed crash on repartition when there is not enough free space;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) webfig - allowed user password changing (broken in v6.36);
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc13 2016-08-10

    What's new in 6.37rc13 (2016-Aug-08 07:39):

    >>> IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    >>> IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc12:

    *) disk - do not do unnecessary sector writes;
    *) lte - added initial deregistration only for bandrich modems;
    *) partitions - added ability to add comments;
    *) partitions - fixed crash on repartition when there is not enough free space;
    *) usb - added support for SMSC95XX USB Ethernet dongle on mipsbe;
    *) webfig - allowed user password changing (broken in v6.36);

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) defconf - fixed default configuration when wireless package is used;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) wireless - display DFS flag in country info;
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc12 2016-08-05

    What's new in 6.37rc12 (2016-Aug-05 05:31):

    >>> IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    >>> IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc11:

    *) defconf - fixed default configuration when wireless package is used;
    *) package - fixed upgrade to 6.37 from older RouterOS versions where multiple wireless packages were included in bundle "routeros" package;
    *) ping - fixed freezing on "not running" interfaces;
    *) winbox - fixed ping tool (introduced in 6.37rc1);
    *) wireless - improved driver support for RB953, hAP ac, wAP ac;
    *) wireless - send deauth to data frames in scan mode;

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed band setting for sxt lte;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added dlink dwm-157 D, dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) wireless - display DFS flag in country info;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc11 2016-08-01

    What's new in 6.37rc11 (2016-Aug-01 09:00):

    >>> IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using "routeros" bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one "wireless" package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    >>> IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to "dfs=radar-detect" for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc10:

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) log - logs loaded from disk after reboot didn't have correct topics;
    *) lte - fixed band setting for sxt lte;
    *) lte - process initial state change to deregistred, when lockup occurs;
    *) lte - reset if sms storage set fails;
    *) modem - added d-link dwm-222 support;
    *) modem - added logging for usb config switching;
    *) ntp - fixed ntp server when local-clock used (like usb gps module);

    Other changes since 6.36:

    !) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    !) console - dfs-mode setting does not exist any more and all scripts with such setting will not be executed;
    !) dude - from now on dude will use winbox port and it will be changed automatically both in client loader and agent configuration;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    *) address-list - allow DNS names with "_" symbol;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) dns - avoid unnecessary static entry saving in storage;
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - check for duplicates when domain name is used in address field;
    *) firewall - fixed time based rules on time/timezone changes;
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered state;
    *) modem - added dlink dwm-157 D support;
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) wireless - display DFS flag in country info;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc10 2016-07-29

    What's new in 6.37rc10 (2016-Jul-29 06:44):

    >>> IMPORTANT! WIRELESS PACKAGE CHANGES:

    If you are not using “routeros” bundle package and have two wireless packages installed,
    uninstall one wireless package before upgrade to 6.37. For other cases simply upgrade to
    6.37 version.

    There will be only one “wireless” package in RouterOS v6.37. If using bundle package to
    upgrade, click "Check for updates" in your RouterOS configuration interface, or head to
    our download page: http://www.mikrotik.com/download.

    >>> IMPORTANT! DFS MODE CHANGES:

    DFS mode setting is removed, and by default becomes forced to “dfs=radar-detect” for all
    devices that use radar frequencies. If your client devices use a scan list with a few
    specific frequencies that could conflict with radar frequencies, you could lose the
    connection. It is recommended to widen the scan list range, use default scan list, or
    change the AP frequency

    Changes since 6.37rc5:

    !) dude - from now on dude will use winbox port and it will be changed automatically both
    in client loader and agent configuration.
    !) wireless - DFS option is removed and forced to "dfs=radar-detect";
    !) console - dfs-mode setting does not exist any more and all scripts with such setting
    will not be executed;
    *) bridge - fixed kernel failure when set-priority action was used in bridge firewall;
    *) dns - avoid unnecessary static entry saving in storage;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424);
    *) email - increased time which email tool can spend while sending message;
    *) ethernet - added support for LAN9514 ethernet dongle;
    *) firewall - check for duplicates when domain name is used in address field;
    *) lte - added ability to send/receive sms using '/tool sms';
    *) lte - added Pantech UML295, Vodafone K4201-Z, ZTE MF823/MF831 support;
    *) lte - fixed access technology update;
    *) lte - fixed at chat condition storage;
    *) lte - fixed ip activation when CREG (circuit switched) state remains in not registered
    state;
    *) modem - added dlink dwm-157 D support;
    *) sms - moved incorrectly logged message from async to gsm topic;
    *) sms - report error when unsupported modem is being used;
    *) snmp - added script table which executes script and returns it's output on get request;
    *) snmp - fixed packet corruption when multiple trap-targets were used;
    *) tile - fixed rare kernel crash when fastpath is being active;
    *) tile - fixed rare kernel crash when usb device is being attached;
    *) traffic-flow - fixed kernel failure when traffic-flow target uses small mtu;
    *) upnp - updated to make it work with more UPnP implementations (for example, latest Skype);
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) vrrp - fixed transition to backup state when ipv6 mode and equal priorities are used;
    *) wireless - display DFS flag in country info;

    Other changes since 6.36:

    !) wireless - "wireless-rep" renamed to "wireless";
    !) wireless - "wireless-cm2" discontinued, uninstall it before update;
    !) wireless - "wireless" package included in bundle "routeros" package;
    !) check-for-updates - with bundle "routeros" package, will replace wireless package
    automatically;
    !) check-for-updates - with one standalone wireless package, will replace wireless package
    automatically;
    !) check-for-updates - with two or more standalone wireless packages, will result in no
    wireless packages installed, uninstall extra packages first;
    *) address-list - allow DNS names with "_" symbol;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - fixed time based rules on time/timezone changes;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on
    regular intervals;
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc5 2016-07-22

    What's new in 6.37rc5 (2016-Jul-22 09:17):

    New features and important changes:

    From now on there will be only one "wireless" package!
    Update on some package configurations is dangerous!!!

    *) wireless - "wireless-rep" renamed to "wireless";
    *) wireless - "wireless-cm2" discontinued, uninstall it before update;
    *) wireless - "wireless" package included in bundle "routeros" package;
    *) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    *) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    *) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;

    Fixes in last RC:

    *) address-list - allow DNS names with "_" symbol;
    *) conntrack - fixed ipv6 timeout display;
    *) conntrack - fixed removing icmpv6 connections;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424 );
    *) export - removed unnecessary "log-prefix" on firewall export;
    *) firewall - fixed time based rules on time/timezone changes;

    Fixes:

    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals;
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.37rc4 2016-07-22

    What's new in 6.37rc4 (2016-Jul-21 07:17):

    Wireless is now unified to a single "wireless" package.
    Update on some package configurations is dangerous!!!

    *) wireless - "wireless-rep" renamed to "wireless";
    *) wireless - "wireless-cm2" discontinued, uninstall it before update;
    *) wireless - "wireless" package included in bundle "routeros" package;
    *) check-for-updates - with bundle "routeros" package, will replace wireless package automatically;
    *) check-for-updates - with one standalone wireless package, will replace wireless package automatically;
    *) check-for-updates - with two or more standalone wireless packages, will result in no wireless packages installed, uninstall extra packages first;
    *) ccr/crs - fixed SFP+ interface ddmi info reporting function. Info is now refreshed on regular intervals.
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=110424 );
    *) ovpn - add special exception route for tunnel itself when using add-default-route;
    *) ping - fixed freezing on "not running" interfaces;
    *) resource - fixed free-memory reporting after disk eject;
    *) x86 - fixed crash when igmp-proxy interface becomes "not running" while passing traffic;

  • Release 6.36rc40 2016-07-13

    What's new in 6.36rc40 (2016-Jul-13 08:11):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083);
    *) lte - fixed modem network configuration version checks;
    *) nat - fixed nat rule disappearance after reboot if interface-list was used (introduced in 6.36rc39);
    *) pppoe - allow to set MTU and MRU higher than 1500 for PPPoE;
    *) tunnel - fixed rare crash by specifying minimal header length immediately at tunnel initialization;
    *) winbox - added 2ghz-g/n band for wireless-rep;
    *) winbox - added icons to bridge filter actions similar to ip firewall;
    *) winbox - do not show filter for combined fields like bgp-vpn4 RD;
    *) winbox - improve filtering on list fields;
    *) winbox - show action column as first in bridge firewall;
    *) winbox - show error when telnet is not allowed because of permissions;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding primary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - do not exit after card-verify;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed CHR seeing its own system disk mounted as additional data disk;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - fixed time keeping for SXT ac, 911L, cAP, mAP lite, wAP;
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - fixed get false function;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) email - removed subject and body length limit;
    *) email - fixed send from winbox;
    *) ethernet - fixed incorrect ether1 link speed after reboot on rb4xx series routers;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed interface list matcher showing incorrect name for NAT rules;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompliance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - fixed windows msgid check on x86 devices;
    *) ipsec - show remote peer address in error messages when possible;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) l2tp - fixed crash when rebooting or disabling l2tp while there are still active connections;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) log - make logging process less aggressive on startup;
    *) log - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - added support for Huawei E3531;
    *) lte - added support for ZTE ZM8620;
    *) lte - added use-peer-dns option (will work only combined with add-default-route);
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - display message in lte,error log if no response received;
    *) lte - display message in lte,error log when PIN is required;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - fixed modem init when pin request present;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for Alcatel OneTouch X600;
    *) modem - added support for SpeedUP SU-900U modem;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) netinstall - fixed netinstall and cd install for x86 (broken since 6.36rc27);
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) pppoe - do not allow to send out bigger packets than l2mtu if mrru is provided;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb2011 - fixed ether6-ether10 flapping when two ports from both switch chips are in the same bridge;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) rb3011 - fixed usb storage mounting;
    *) rb3011 - improved performance on high cpu usage;
    *) route - added suppport for more than 8 bits of options;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - do not exit while there still are active sessions;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) timezone - updated timezone information from tzdata2016e release;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) upnp - fixed firewall rules not being dynamic;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) wap-ac - fixed performance problems with 2.4GHz wireless (additional reboot after upgrade required);
    *) webfig - reduced refresh time for wireless registration table to 1 second;
    *) winbox - added arp-timeout setting to all ethernet like interfaces;
    *) winbox - added domain name support for IPv6 address list;
    *) winbox - do not allow to specify vlan-mode=no-tag in capsman datapath config;
    *) winbox - do not show mode setting for WDS interfaces;
    *) winbox - fixed crash when using ctrl+d;
    *) winbox - make local-address optional for eoipv6, 6to4, ipip, ipipv6 & grev6;
    *) winbox - renamed IPv6 "Raw rules" section to "Raw";
    *) winbox - report correctly dude users in active users list;
    *) winbox - set default sa-learning value to "yes" for CRS Ingress VLAN Translation rules;
    *) wireless - fixed multiple wireless packages enabled at the same time after upgrade;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc39 2016-07-12

    What's new in 6.36rc39 (2016-Jul-12 08:10):

    *) chr - fixed CHR seeing its own system disk mounted as additional data disk;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083);
    *) ethernet - fixed incorrect ether1 link speed after reboot on rb4xx series routers;
    *) firewall - fixed interface list matcher showing incorrect name for NAT rules;
    *) lte - added support for ZTE ZM8620;
    *) lte - added use-peer-dns option (will work only combined with add-default-route);
    *) netinstall - fixed netinstall and cd install for x86 (broken since 6.36rc27);
    *) pppoe - do not allow to send out bigger packets than l2mtu if mrru is provided;
    *) rb2011 - fixed ether6-ether10 flapping when two ports from both switch chips are in the same bridge;
    *) winbox - added arp-timeout setting to all ethernet like interfaces;
    *) winbox - added domain name support for IPv6 address list;
    *) winbox - do not allow to specify vlan-mode=no-tag in capsman datapath config;
    *) winbox - do not show mode setting for WDS interfaces;
    *) winbox - fixed crash when using ctrl+d;
    *) winbox - make local-address optional for eoipv6, 6to4, ipip, ipipv6 & grev6;
    *) winbox - renamed IPv6 "Raw rules" section to "Raw";
    *) winbox - set default sa-learning value to "yes" for CRS Ingress VLAN Translation rules;
    *) wireless - fixed multiple wireless packages enabled at the same time after upgrade;
    *) l2tp - fixed crash when rebooting or disabling l2tp while there are still active connections;
    *) rb3011 - fixed usb storage mounting;
    *) webfig - reduced refresh time for wireless registration table to 1 second;
    *) clock - fixed time keeping for SXT ac, 911L, cAP, mAP lite, wAP;
    *) ipsec - show remote peer address in error messages when possible;
    *) lte - display message in lte,error log if no response received;
    *) lte - display message in lte,error log when PIN is required;
    *) modem - added support for Alcatel OneTouch X600;
    *) upnp - fixed firewall rules not being dynamic;
    *) email - fixed send from winbox;
    *) log - make logging process less aggressive on startup;
    *) wap-ac - fixed performance problems with 2.4GHz wireless (additional reboot after upgrade required);
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding primary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - do not exit after card-verify;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - fixed get false function;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompliance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - fixed windows msgid check on x86 devices;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - added support for Huawei E3531;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - fixed modem init when pin request present;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for SpeedUP SU-900U modem;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) rb3011 - improved performance on high cpu usage;
    *) route - added suppport for more than 8 bits of options;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - do not exit while there still are active sessions;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) timezone - updated timezone information from tzdata2016e release;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc37 2016-07-08

    What's new in 6.36rc37 (2016-Jul-07 11:13):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083);
    *) l2tp - fixed crash when rebooting or disabling l2tp while there are still active connections;
    *) rb3011 - fixed usb storage mounting;
    *) webfig - reduced refresh time for wireless registration table to 1 second;
    *) clock - fixed time keeping for SXT ac, 911L, cAP, mAP lite, wAP;
    *) ipsec - show remote peer address in error messages when possible;
    *) lte - display message in lte,error log if no response received;
    *) lte - display message in lte,error log when PIN is required;
    *) modem - added support for Alcatel OneTouch X600;
    *) upnp - fixed firewall rules not being dynamic;
    *) email - fixed send from winbox;
    *) log - make logging process less aggressive on startup;
    *) wap-ac - fixed performance problems with 2.4GHz wireless (additional reboot after upgrade required);
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding primary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - do not exit after card-verify;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - fixed get false function;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompliance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - fixed windows msgid check on x86 devices;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - added support for Huawei E3531;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - fixed modem init when pin request present;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for SpeedUP SU-900U modem;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) rb3011 - improved performance on high cpu usage;
    *) route - added suppport for more than 8 bits of options;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - do not exit while there still are active sessions;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) timezone - updated timezone information from tzdata2016e release;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc36 2016-07-06

    What's new in 6.36rc36 (2016-Jul-06 09:51):

    *) clock - fixed time keeping for SXT ac, 911L, cAP, mAP lite, wAP;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083);
    *) ipsec - show remote peer address in error messages when possible;
    *) lte - display message in lte,error log if no response received;
    *) lte - display message in lte,error log when PIN is required;
    *) modem - added support for Alcatel OneTouch X600;
    *) upnp - fixed firewall rules not being dynamic;
    *) email - fixed send from winbox;
    *) log - make logging process less aggressive on startup;
    *) wap-ac - fixed performance problems with 2.4GHz wireless (additional reboot after upgrade required);
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding primary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - do not exit after card-verify;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - fixed get false function;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompliance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - fixed windows msgid check on x86 devices;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - added support for Huawei E3531;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - fixed modem init when pin request present;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for SpeedUP SU-900U modem;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) rb3011 - improved performance on high cpu usage;
    *) route - added suppport for more than 8 bits of options;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - do not exit while there still are active sessions;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) timezone - updated timezone information from tzdata2016e release;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc33 2016-06-29

    What's new in 6.36rc33 (2016-Jun-28 11:04):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) email - fixed send from winbox;
    *) log - make logging process less aggressive on startup;
    *) wap-ac - fixed performance problems with 2.4GHz wireless (additional reboot after upgrade required);
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding primary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - do not exit after card-verify;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - fixed get false function;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompliance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - fixed windows msgid check on x86 devices;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - added support for Huawei E3531;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - fixed modem init when pin request present;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for SpeedUP SU-900U modem;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) rb3011 - improved performance on high cpu usage;
    *) route - added suppport for more than 8 bits of options;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - do not exit while there still are active sessions;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) timezone - updated timezone information from tzdata2016e release;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc30 2016-06-22

    What's new in 6.36rc30 (2016-Jun-21 13:12):

    *) certificate - do not exit after card-verify;
    *) console - fixed get false function;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ipsec - fixed windows msgid check on x86 devices;
    *) lte - added support for Huawei E3531;
    *) lte - fixed modem init when pin request present;
    *) mesh - fixed crash when connection references a mesh network but it is not available any more;
    *) modem - added support for SpeedUP SU-900U modem;
    *) queue - reset queue type on interfaces which default queue type changes to no-queue after upgrade;
    *) rb3011 - fixed usb driver load (introduced in 6.36r22);
    *) route - added suppport for more than 8 bits of options;
    *) ssl - do not exit while there still are active sessions;
    *) timezone - updated timezone information from tzdata2016e release;
    *) upnp - fixed nat rule dst-port by making it visible again;
    *) wireless-rep - fixed nstreme reset on poll timeout;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding privmary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - add dead ph2 detection exception for windows msgid noncompilance with rfc;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - added cinterion pls8 support;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - fixed connection for huawei without cell info;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - improved performance on high cpu usage;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) supout - erase panic data properly on Netinstall;
    *) switch - fixed switch compact export;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc28 2016-06-13

    What's new in 6.36rc28 (2016-Jun-10 12:12):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ipsec - add dead ph2 detection exception for windows msgid noncompilance with rfc;
    *) lte - added cinterion pls8 support;
    *) lte - fixed connection for huawei without cell info;
    *) supout - erase panic data properly on Netinstall;
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) address-list - make "dynamic=yes" as read-only option;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) arp - added arp-timeout option per interface;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) bonding - fixed bonding privmary slave assignment for ovpn interfaces after startup;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) capsman - fixed crash when running over ovpn;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - display issuer and subject on check failure;
    *) certificate - force scep renewal on system clock updates;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) cloud - fixed export order;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) dhcp-pd - correct server listing for commands;
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) dhcpv6-server - fixed binding last-seen update;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) fetch - support tls host name extension;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fix initiator modecfg dynamic dns;
    *) ipsec - fixed AH with SHA2;
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) ipsec - store udp encapsulation type in proposal;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) log - added whole scep certificate chain print;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - improved multiple same model modems identification;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) lte - use only creg result codes as network status indications;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) rb3011 - fixed reset button functionality;
    *) rb3011 - improved performance on high cpu usage;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) sniffer - fixed ipv6 address matching;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) snmp - report ram memory as ram instead of other;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) switch - fixed switch compact export;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) trafficflow - allow to filter with interface lists;
    *) tunnel - added option to auto detect tunnel local-address;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file);
    *) userman - fixed crash on database upload;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - added initial API support for snooper;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) wireless-rep - fixed scan-list unset;
    *) wireless-rep - treat missing SSID element as hidden SSID;

  • Release 6.36rc27 2016-06-09

    What's new in 6.36rc27 (2016-Jun-08 12:21):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) dude - server package is now made smaller. client side content upgrade is now removed from it and is downloaded straight from our cloud. So workstations on which client is used will require access to wan. Alternatively upgrade must be done by reinstalling the client on each new release;
    *) address-list - make "dynamic=yes" as read-only option;
    *) bonding - fixed bonding privmary slave assignment for ovpn interfaces after startup;
    *) disk - added support for Plextor PX-G128M6e(A) SSD on CCR1072;
    *) firewall - do not show disabled=no in export;
    *) firewall - fixed spelling in built-in firewall commentary;
    *) gps - fixed longitude seconds part;
    *) lcd - reduced lowest backlight-timeout value from 5m to 30s;
    *) logs - increase excessive multicast/broadcast warning threshold every time it is logged;
    *) lte - removed option allow-roaming for Huawei ME909u and MU609 devices;
    *) userman - fixed crash on database upload;
    *) wireless-rep - fixed crash on nv2 reconnect;
    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - use only creg result codes as network status indications;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) rb3011 - fixed reset button functionality;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) rb3011 - improved performance on high cpu usage;
    *) snmp - report ram memory as ram instead of other;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - force scep renewal on system clock updates;
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) fetch - support tls host name extension;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) certificate - display issuer and subject on check failure;
    *) cloud - fixed export order;
    *) dhcpv6-server - fixed binding last-seen update;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - store udp encapsulation type in proposal;
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - treat missing SSID element as hidden SSID;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc21 2016-05-31

    What's new in 6.36rc21 (2016-May-31 10:45):

    *) icmp - fixed kernel failure when icmp packet could not be processed on high load;
    *) lte - Huawei MU609 must use latest firmware to work correctly;
    *) lte - use only creg result codes as network status indications;
    *) proxy - limit max ram usage to 80% for tile and x86 devices;
    *) rb3011 - fixed reset button functionality;
    *) snmp - fixed interface stats branch from MikroTik MIB;
    *) snmp - report current access technology and cell id for lte modems;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) rb3011 - improved performance on high cpu usage;
    *) snmp - report ram memory as ram instead of other;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - force scep renewal on system clock updates;
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) fetch - support tls host name extension;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) certificate - display issuer and subject on check failure;
    *) cloud - fixed export order;
    *) dhcpv6-server - fixed binding last-seen update;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - store udp encapsulation type in proposal;
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - treat missing SSID element as hidden SSID;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc20 2016-05-30

    What's new in 6.36rc20 (2016-May-30 05:56):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ippool6 - fixed crash on acquire when prefix length is equal with pool prefix length;
    *) rb3011 - improved performance on high cpu usage;
    *) snmp - report ram memory as ram instead of other;
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - force scep renewal on system clock updates;
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) fetch - support tls host name extension;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) certificate - display issuer and subject on check failure;
    *) cloud - fixed export order;
    *) dhcpv6-server - fixed binding last-seen update;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - store udp encapsulation type in proposal;
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - treat missing SSID element as hidden SSID;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc19 2016-05-27

    What's new in 6.36rc19 (2016-May-27 06:20):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) certificate - added automatic scep renewal delay after startup to avoid all requests accessing CA at the same time;
    *) certificate - cancel pending renew when certificate becomes valid after date change;
    *) certificate - force scep renewal on system clock updates;
    *) clock - save current time to configuration once per day even if there are no time zone adjustments pending;
    *) console - show message time in echo log messages;
    *) defconf - changed channel extension to 20/40/80mhz for all ac boards;
    *) fetch - support tls host name extension;
    *) kernel - fixed possible kernel deadlock when Sierra USB mode is being used;
    *) rb3011 - improved performance on high cpu usage;
    *) address - allow multiple equal ip addresses to be added if neither or only one is enabled;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) certificate - display issuer and subject on check failure;
    *) cloud - fixed export order;
    *) dhcpv6-server - fixed binding last-seen update;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - store udp encapsulation type in proposal;
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - treat missing SSID element as hidden SSID;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc16 2016-05-24

    What's new in 6.36rc16 (2016-May-24 07:04):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) address - allow multiple euqla ip addresses to be added if neither or only one is enabled;
    *) bonding - fixed 802.3ad load balancing mode over tunnels ;
    *) certificate - display issuer and subject on check failure;
    *) cloud - fixed export order;
    *) dhcpv6-server - fixed binding last-seen update;
    *) e-mail - removed subject and body length limit;
    *) ethernet - fixed memory leak when setting interface without changing configuration;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-interface-list matcher in firewall;
    *) firewall - added pre-connection tracking filter - "raw" table, that allow to protect connection-tracking from unnecessary traffic;
    *) firewall - allow to add domain name to address-lists (dynamic entries for resolved addresses will be added to specified list);
    *) ipsec - fixed checks before accessing ph1 nat options;
    *) ipsec - store udp encapsulation type in proposal;
    *) ovpn - enable perfect forwarding secrecy support by default;
    *) ovpn - fixed compatibility with OpenVPN 2.3.11;
    *) rb3011 - fixed port flapping on ether6-ether10;
    *) snmp - fixed get function for snmp>=v2 when oid does not exist;
    *) winbox - report correctly dude users in active users list;
    *) wireless-rep - treat missing SSID element as hidden SSID;
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc13 2016-05-18

    What's new in 6.36rc13 (2016-May-17 12:20):

    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) dhcpv6 client - fixed ia lifetime validation when it is set by dhcpv6 client;
    *) health - fixed incorrect voltage after reboot on RB2011UAS;
    *) health - fixed broken factory voltage calibration data for some hAP ac boards;
    *) log - added whole scep certificate chain print;
    *) lte - fix crash on SXT LTE while resetting card while at high traffic;
    *) lte - added allow-roaming option for Huawei MU709, ME909s, ME909u devices;
    *) lte - changed driver loading for class 2 usb rndis devices;
    *) userman - use ipnpb.paypal.com for payment verification;
    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking and packet defragmentation (CLI only);
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc12 2016-05-11

    What's new in 6.36rc12 (2016-May-11 06:27):

    *) capsman - fixed crash when running over ovpn;
    *) dhcp-pd - correct server listing for commands;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) fastpath - fixed kernel failure when fastpath handles packet with multicast dst-address;
    *) ipsec - don't register temporary ph2 on dead list;
    *) ipsec - fixed mode-config export;
    *) ipsec - fixed route cache overflow when using ipsec with route cache disabled;
    *) sniffer - fixed ipv6 address matching;
    *) ssh - add rsa host key size parameter;
    *) ssh-keygen - add rsa key size parameter;
    *) usb - I-tec U3GLAN3HUB usb hub/ethernet dongle now shows up correctly as ethernet interface;
    *) usb - implement possibility to recognize usb hubs/ethernet-dongles;
    (if usb hubs/ethernet-dongles are not recognized with this version - send supout.rif file)
    *) wireless-rep - added initial API support for snooper;
    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking and packet defragmentation (CLI only);
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) lte - added cinterion pls8 support;
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade.

  • Release 6.36rc11 2016-05-05

    What's new in 6.36rc11 (2016-May-05 07:40):

    *) bonding - fixed crash on RoMON traffic transmit;
    *) bonding - implemented l2mtu value == smallest slave interfaces l2mtu;
    *) dude - (changes discussed here: forum.mikrotik.com/viewtopic.php?f=8&t=108083 );
    *) ipsec - added dead ph2 reply detection;
    *) ipsec - fixed AH with SHA2;
    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking and packet defragmentation (CLI only);
    *) firewall - fixed policy routing configurations (introduced in 6.35rc38);
    *) queue - fixed interface queue type for ovpn tunnels;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) discovery - fixed identity discovery (introduced in 6.36rc5 and 6.35.1);
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) log - fixed time zone adjustment (introduced in 6.36rc5 and 6.35.1);
    *) lte - added cinterion pls8 support;
    *) snmp - fixed snmp timeout (introduced in 6.36rc5 and 6.35.1);
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) vrrp - fixed missing vrrp interfaces after upgrade (introduced in 6.36rc5 and 6.35.1);
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc10 2016-04-29

    What's new in 6.36rc10 (2016-Apr-29 11:14):

    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking and packet defragmentation (CLI only);
    *) firewall - fixed policy routing configurations (introduced in 6.35rc38);
    *) queue - fixed interface queue type for ovpn tunnels;
    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) discovery - fixed identity discovery (introduced in 6.36rc5 and 6.35.1);
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) log - fixed time zone adjustment (introduced in 6.36rc5 and 6.35.1);
    *) lte - added cinterion pls8 support;
    *) snmp - fixed snmp timeout (introduced in 6.36rc5 and 6.35.1);
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) vrrp - fixed missing vrrp interfaces after upgrade (introduced in 6.36rc5 and 6.35.1);
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc9 2016-04-29

    What's new in 6.36rc9 (2016-Apr-29 08:04):

    *) arm - added Dude server support;
    *) arm - fixed kernel failure on low memory;
    *) discovery - fixed identity discovery (introduced in 6.36rc5 and 6.35.1);
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) log - fixed time zone adjustment (introduced in 6.36rc5 and 6.35.1);
    *) lte - added cinterion pls8 support;
    *) snmp - fixed snmp timeout (introduced in 6.36rc5 and 6.35.1);
    *) ssl - fixed memory leak on ssl connect/disconnect (fetch, ovpn, etc.);
    *) trafficflow - allow to filter with interface lists;
    *) vrrp - fixed missing vrrp interfaces after upgrade (introduced in 6.36rc5 and 6.35.1);
    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking (CLI only);
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc8 2016-04-28

    What's new in 6.36rc8 (2016-Apr-28 06:57):

    *) chr - fixed stalling services (introduced in 6.36rc6);
    *) dhcp-server - fixed radius framed route addition after reboot on client renew;
    *) firewall - added "/interface list" menu which allows to create list of interfaces which can be used as in/out-zone matcher in firewall (CLI only);
    *) firewall - added raw table to be able to disable connection tracking on selected packets or drop packets before connection tracking (CLI only);
    *) lte - added cinterion pls8 support;
    *) lte - improved multiple same model modems identification;
    *) route - fixed ospf-v3 crash (introduced in 6.36rc6);
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) arp - added arp-timeout option per interface;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless-rep - fixed scan-list unset;
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc6 2016-04-25

    What's new in 6.36rc6 (2016-Apr-25 06:25):

    *) ipsec - fix initiator modecfg dynamic dns;
    *) nand - improved nand refresh feature to enhance stored data integrity;
    *) route - fixed ospf by handling ipv6 encoded prefixes with stray bits;
    *) watchdog - fixed reboot loop on startup (introduced in 6.36rc5);
    *) arp - added arp-timeout option per interface;
    *) log - fixed reboot log messages;
    *) lte - do not allow to set multiple modes when it is not supported;
    *) lte - fixed address acquisition on Huaweii LTE interfaces;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) winbox - show voltage in Health only if there actually is voltage monitor;
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless - fixed issue when CAPsMAN could lock CAPs interface;
    *) wireless-rep - fixed scan-list unset;
    *) bonding - do not corrupt bonding statistics on configuration changes;
    *) bonding - fixed crash when vlan parent mtu is higher than bonding mtu;
    *) ethernet - do not allow mtu to be higher than l2mtu and l2mtu to be higher than max-l2mtu (reduce automatically on upgrade if it was wrong before);
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc5 2016-04-22

    What's new in 6.36rc5 (2016-Apr-22 06:28):

    *) arp - added arp-timeout option per interface;
    *) log - fixed reboot log messages;
    *) lte - do not allow to set multiple modes when it is not supported;
    *) lte - fixed address acquisition on Huaweii LTE interfaces;
    *) ntp - fixed time keeping on SXT ac, RB911L, cAP and wAP
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) winbox - show voltage in Health only if there actually is voltage monitor;
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless - fixed issue when CAPsMAN could lock CAPs interface;
    *) wireless-rep - fixed scan-list unset;
    *) bonding - do not corrupt bonding statistics on configuration changes;
    *) bonding - fixed crash when vlan parent mtu is higher than bonding mtu;
    *) ethernet - do not allow mtu to be higher than l2mtu and l2mtu to be higher than max-l2mtu (reduce automatically on upgrade if it was wrong before);
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc4 2016-04-21

    What's new in 6.36rc4 (2016-Apr-20 12:46):

    *) arp - added arp-timeout option per interface;
    *) log - fixed reboot log messages;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) tunnel - added option to auto detect tunnel local-address;
    *) wireless - fixed issue when CAPsMAN could lock CAPs interface;
    *) wireless-rep - fixed scan-list unset;
    *) bonding - do not corrupt bonding statistics on configuration changes;
    *) bonding - fixed crash when vlan parent mtu is higher than bonding mtu;
    *) ethernet - do not allow mtu to be higher than l2mtu and l2mtu to be higher than max-l2mtu (reduce automatically on upgrade if it was wrong before);
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.36rc3 2016-04-19

    What's new in 6.36rc3 (2016-Apr-19 11:33):

    *) bonding - do not corrupt bonding statistics on configuration changes;
    *) bonding - fixed crash when vlan parent mtu is higher than bonding mtu;
    *) ethernet - do not allow mtu to be higher than l2mtu and l2mtu to be higher than max-l2mtu (reduce automatically on upgrade if it was wrong before);
    *) firewall - added udplite, dccp, sctp connection tracking helpers;
    *) switch - fixed switch compact export;
    *) traffic-flow - added ipfix support (RFC5101 and RFC5102);
    *) wireless - wireless-fp is discontinued, it needs to be uninstalled/disabled before upgrade;

  • Release 6.35rc49 2016-04-12

    What's new in 6.35rc49 (2016-Apr-12 7:20):

    *) dhcpv6 client - fix ia expiration and lifetime validation;
    *) dhcpv6 server - acquire binding on renew if it does not exist;
    *) export - exclude default values from export in "/interface l2tp-server server" menu;
    *) export - fixed rare situations when not whole config was exported;
    *) leds - fixed AP-CAP led blinking after successful association to CAPsMAN;
    *) lte - fixed crash on early initialization;
    *) lte - use timer for modem info;
    *) ntp - fixed ntp client hangs in reached state;
    *) rb3011 - fixed sfp compatibility with CCR when using direct attached cables;
    *) tunnels - fixed performance slowdown on any other tunnel disable/enable;
    *) winbox - added "pw-type" to "/interface vpls bgp-vpls" menu;
    *) winbox - added "use-control-word" and "pw-mtu" to "/interface vpls cisco-bgp-vpls" menu;
    *) winbox - added mtu=auto support to eoipv6 tunnel;
    *) wireless-rep - use full identity where possible;
    *) wireless-rep - fixed latency issues with Intel wireless clients;
    *) mipsbe - (excluding RB4xx and CRS series) fixed rare ethernet tx buffer corruption;
    *) dhcp6-client - fixed wrong error message;
    *) address-list - fixed crash in low memory situations;
    *) tile - fixed performance regression on switch chip (introduced in 6.33rc18);
    *) tile - fixed l2mtu change (introduced in 6.35rc);
    *) lcd - fixed branding packet logo drawing on startup;
    *) lte - replaced signal-strength with rssi in info command;
    *) nand - fixed reboot loop after upgrade to >v6.35rc43;
    *) ppp - fixed some clients can not connect due to LCP restart;
    *) tool fetch - fixed https cleanup on user stop while handshaking;
    *) winbox - make build with latest lte changes;
    *) hotspot - make video tag work properly on hotspot login.html page
    *) ipsec - fixed crash on policy update;
    *) ppp - fixed ppp crash if lcp packets were lost and authentication got delayed;
    *) chr - try to renew expired license once a hour instead of 100h;
    *) defconf - fixed default configuration for SXT LTE;
    *) lte - improve situation when SXT modem never finds operator;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - make ether6-ether10 work if SFP module is present on bootup;
    *) trafficgen - fixed console arguments;
    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc48 2016-04-06

    What's new in 6.35rc48 (2016-Apr-05 15:10):

    *) wireless-rep - fixed latency issues with Intel wireless clients;
    *) mipsbe - (excluding RB4xx and CRS series) fixed rare ethernet tx buffer corruption;
    *) dhcp6-client - fixed wrong error message;
    *) address-list - fixed crash in low memory situations;
    *) tile - fixed performance regression on switch chip (introduced in 6.33rc18);
    *) tile - fixed l2mtu change (introduced in 6.35rc);
    *) lcd - fixed branding packet logo drawing on startup;
    *) lte - replaced signal-strength with rssi in info command;
    *) nand - fixed reboot loop after upgrade to >v6.35rc43;
    *) ppp - fixed some clients can not connect due to LCP restart;
    *) tool fetch - fixed https cleanup on user stop while handshaking;
    *) winbox - make build with latest lte changes;
    *) hotspot - make video tag work properly on hotspot login.html page
    *) ipsec - fixed crash on policy update;
    *) ppp - fixed ppp crash if lcp packets were lost and authentication got delayed;
    *) chr - try to renew expired license once a hour instead of 100h;
    *) defconf - fixed default configuration for SXT LTE;
    *) lte - improve situation when SXT modem never finds operator;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - make ether6-ether10 work if SFP module is present on bootup;
    *) trafficgen - fixed console arguments;
    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc47 2016-04-06

    What's new in 6.35rc47 (2016-Apr-05 08:12):

    *) tile - fixed performance regression on switch chip (introduced in 6.33rc18);
    *) tile - fixed l2mtu change (introduced in 6.35rc);
    *) lcd - fixed branding packet logo drawing on startup;
    *) lte - replaced signal-strength with rssi in info command;
    *) nand - fixed reboot loop after upgrade to >v6.35rc43;
    *) ppp - fixed some clients can not connect due to LCP restart;
    *) tool fetch - fixed https cleanup on user stop while handshaking;
    *) winbox - make build with latest lte changes;
    *) wireless-rep - fixed latency issues with Intel 2.4GHz wireless clients;
    *) hotspot - make video tag work properly on hotspot login.html page
    *) ipsec - fixed crash on policy update;
    *) ppp - fixed ppp crash if lcp packets were lost and authentication got delayed;
    *) chr - try to renew expired license once a hour instead of 100h;
    *) defconf - fixed default configuration for SXT LTE;
    *) lte - improve situation when SXT modem never finds operator;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - make ether6-ether10 work if SFP module is present on bootup;
    *) trafficgen - fixed console arguments;
    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc46 2016-04-05

    What's new in 6.35rc46 (2016-Apr-05 08:12):

    *) lcd - fixed branding packet logo drawing on startup;
    *) lte - replaced signal-strength with rssi in info command;
    *) nand - fixed reboot loop after upgrade to >v6.35rc43;
    *) ppp - fixed some clients can not connect due to LCP restart;
    *) tool fetch - fixed https cleanup on user stop while handshaking;
    *) winbox - make build with latest lte changes;
    *) wireless-rep - fixed latency issues with Intel 2.4GHz wireless clients;
    *) hotspot - make video tag work properly on hotspot login.html page
    *) ipsec - fixed crash on policy update;
    *) ppp - fixed ppp crash if lcp packets were lost and authentication got delayed;
    *) chr - try to renew expired license once a hour instead of 100h;
    *) defconf - fixed default configuration for SXT LTE;
    *) lte - improve situation when SXT modem never finds operator;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - make ether6-ether10 work if SFP module is present on bootup;
    *) trafficgen - fixed console arguments;
    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc45 2016-04-01

    What's new in 6.35rc45 (2016-Apr-01 11:04):

    *) hotspot - make video tag work properly on hotspot login.html page
    *) ipsec - fixed crash on policy update;
    *) ppp - fixed ppp crash if lcp packets were lost and authentication got delayed;
    *) chr - try to renew expired license once a hour instead of 100h;
    *) defconf - fixed default configuration for SXT LTE;
    *) lte - improve situation when SXT modem never finds operator;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - make ether6-ether10 work if SFP module is present on bootup;
    *) trafficgen - fixed console arguments;
    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc44 2016-04-01

    What's new in 6.35rc44 (2016-Apr-01 05:38):

    *) chr - try to renew expired license once a hour instead of 100h;
    *) defconf - fixed default configuration for SXT LTE;
    *) lte - improve situation when SXT modem never finds operator;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - make ether6-ether10 work if SFP module is present on bootup;
    *) trafficgen - fixed console arguments;
    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc43 2016-03-30

    What's new in 6.35rc43 (2016-Mar-29 10:29):

    *) fastpath - fixed show rx-bits-per-second on all VLAN interfaces;
    *) nand - implemented once a week nand refresh to improve stored data integrity (will increase sector writes);
    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) winbox - make additional-network-mode optional for lte interface;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc42 2016-03-24

    What's new in 6.35rc42 (2016-Mar-24 12:27):

    *) chr - fixed bridge firewall;
    *) chr - make shutdown request from hyper-v work (might fix other hypervisor as well);
    *) dude - fixed dude login logging, no more shows as winbox login;
    *) timezone - fixed reboot by watchdog when selecting timezones from the end of list;
    *) bonding - fixed mac-address disappearance after reboot in specific setups;
    *) chr - fixed reboots with license and queues;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) quickset - fixed wan interface selection on CCR1009-8G-1S-1S+;
    *) quickset - use 5Ghz interface instead of 2GHz interface on SXT Lite5 ac;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) rb3011 - fixed link down messages;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) romon - fixed romon discovery after of romon ID change;
    *) userman - fixed www crash;
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) bonding - fixed crash on bonding slave release;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed crash when ppp interface gets disconnected and user gets authenticated at the same time (most probable with slow RADIUS server);
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - allow to show revoked & authority flags at the same time;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) ethernet - fixed Netmetal, QRT, DynaDish, SXT ac linking at 10/100Mbps (introduced in 6.35rc);
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - allow unknown scan-list names on wireless configuration to fix import;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) ipsec - take into account ip protocol in kernel policy matcher;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) mac-winbox - try to aggregate packets & resend all pending packets on timeout;
    *) ppp - do not crash when received multiple CBCP packets;
    *) winbox - correctly recognise if there is need to report fan information uder system health;
    *) winbox - do not use area v2 names instead of ospf v3 area names;
    *) winbox - make additional-network-mode optional for lte interface;
    *) winbox - make mac-winbox work with RB850;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - do not show fan statuses in passive cooling CCR1009;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc41 2016-03-24

    What's new in 6.35rc41 (2016-Mar-24 09:52):

    *) bonding - fixed mac-address disappearance after reboot in specific setups;
    *) chr - fixed reboots with license and queues;
    *) quickset - fixed invalid date adjusted the signal threshold for the signal chart and refresh rate;
    *) bonding - fixed crash when creating vlans on bonding interface;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox nd webfig;
    *) quickset - fixed wan interface selection on CCR1009-8G-1S-1S+;
    *) quickset - use 5Ghz interface instead of 2GHz interface on SXT Lite5 ac;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) rb3011 - fixed link down messages;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) romon - fixed romon discovery after of romon ID change;
    *) userman - fixed www crash;
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) bonding - fixed crash on bonding slave release;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed crash when ppp interface gets disconnected and user gets authenticated at the same time (most probable with slow RADIUS server);
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - allow to show revoked & authority flags at the same time;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) ethernet - fixed Netmetal, QRT, DynaDish, SXT ac linking at 10/100Mbps (introduced in 6.35rc);
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - allow unknown scan-list names on wireless configuration to fix import;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) ipsec - take into account ip protocol in kernel policy matcher;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) mac-winbox - try to aggregate packets & resend all pending packets on timeout;
    *) ppp - do not crash when received multiple CBCP packets;
    *) winbox - correctly recognise if there is need to report fan information uder system health;
    *) winbox - do not use area v2 names instead of ospf v3 area names;
    *) winbox - make additional-network-mode optional for lte interface;
    *) winbox - make mac-winbox work with RB850;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - do not show fan statuses in passive cooling CCR1009;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc40 2016-03-24

    What's new in 6.35rc40 (2016-Mar-23 15:30):

    *) bonding - fixed crash when creating vlans on bonding interface;
    *) bonding - fixed mac-address disappearance after reboot in specific setups;
    *) chr - fixed reboots with license and queues;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) fastpath - improved vlan fastpath;
    *) map lite - added hardware WPS button support;
    *) ppp - fixed ppp interface reconnect when uPnP was used;
    *) quickset - fixed situations when hidden password was passed as ******* from winbox and webfig;
    *) quickset - fixed wan interface selection on CCR1009-8G-1S-1S+;
    *) quickset - use 5Ghz interface instead of 2GHz interface on SXT Lite5 ac;
    *) routing - fixed routing-marks were not erased from memory when they are not being used;
    *) winbox - added init-delay option to routerboard settings;
    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - no more installation on first boot;
    *) lte - supported modems now use unsolicited events for network monitoring;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) rb3011 - fixed link down messages;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) romon - fixed romon discovery after of romon ID change;
    *) userman - fixed www crash;
    *) wireless - fixed crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fixed possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) bonding - fixed crash on bonding slave release;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fixed getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed crash when ppp interface gets disconnected and user gets authenticated at the same time (most probable with slow RADIUS server);
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fixed filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - allow to show revoked & authority flags at the same time;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) ethernet - fixed Netmetal, QRT, DynaDish, SXT ac linking at 10/100Mbps (introduced in 6.35rc);
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fixed ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - allow unknown scan-list names on wireless configuration to fix import;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) ipsec - take into account ip protocol in kernel policy matcher;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) mac-winbox - try to aggregate packets & resend all pending packets on timeout;
    *) ppp - do not crash when received multiple CBCP packets;
    *) winbox - correctly recognise if there is need to report fan information uder system health;
    *) winbox - do not use area v2 names instead of ospf v3 area names;
    *) winbox - make additional-network-mode optional for lte interface;
    *) winbox - make mac-winbox work with RB850;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - do not show fan statuses in passive cooling CCR1009;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fixed crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fixed cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fixed send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fixed multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fixed larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fixed entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fixed crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fixed potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fixed fast ph2 SA addition;
    *) led - fixed crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fixed minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fixed signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fixed potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fixed nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc37 2016-03-23

    What's new in 6.35rc37 (2016-Mar-23 08:28):

    *) chr - fixed Hyper-V booting from SCSI;
    *) chr - fixed Hyper-V on windows 8/10 reboot loop;
    *) chr - implemented automatic storage increase on disk image size increase;
    *) chr - no more installation on first boot;
    *) lte - supported modems now use unsolicit events for network monitoring;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) rb3011 - fixed link down messages;
    *) winbox - hotspot default-trial user shows profile as "unknown" in Winbox;
    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) romon - fix romon discovery after of romon ID change;
    *) userman - fixed www crash;
    *) wireless - fix crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fix possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added init-delay option to routerboard settings;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) bonding - fix crash on bonding slave release;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fix getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed crash when ppp interface gets disconnected and user gets authenticated at the same time (most probable with slow RADIUS server);
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fix filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - allow to show revoked & authority flags at the same time;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) ethernet - fixed Netmetal, QRT, DynaDish, SXT ac linking at 10/100Mbps (introduced in 6.35rc);
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fix ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - allow unknown scan-list names on wireless configuration to fix import;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) ipsec - take into account ip protocol in kernel policy matcher;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) mac-winbox - try to aggregate packets & resend all pending packets on timeout;
    *) ppp - do not crash when received multiple CBCP packets;
    *) winbox - correctly recognise if there is need to report fan information uder system health;
    *) winbox - do not use area v2 names instead of ospf v3 area names;
    *) winbox - make additional-network-mode optional for lte interface;
    *) winbox - make mac-winbox work with RB850;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - do not show fan statuses in passive cooling CCR1009;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fix crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fix cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc35 2016-03-22

    What's new in 6.35rc35 (2016-Mar-22 12:32):

    *) chr - fixed kernel crash when virtual ethernet was not connected to anything in Hyper-V;
    *) chr - implemented kernel crash saving to autosupout.rif (will utilize additional 24Mb of RAM);
    *) romon - fix romon discovery after of romon ID change;
    *) userman - fixed www crash;
    *) wireless - fix crash on nstreme-dual interface stats update;
    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fix possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added init-delay option to routerboard settings;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) bonding - fix crash on bonding slave release;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fix getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed crash when ppp interface gets disconnected and user gets authenticated at the same time (most probable with slow RADIUS server);
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fix filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - allow to show revoked & authority flags at the same time;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) ethernet - fixed Netmetal, QRT, DynaDish, SXT ac linking at 10/100Mbps (introduced in 6.35rc);
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fix ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - allow unknown scan-list names on wireless configuration to fix import;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) ipsec - take into account ip protocol in kernel policy matcher;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) mac-winbox - try to aggregate packets & resend all pending packets on timeout;
    *) ppp - do not crash when received multiple CBCP packets;
    *) winbox - correctly recognise if there is need to report fan information uder system health;
    *) winbox - do not use area v2 names instead of ospf v3 area names;
    *) winbox - make additional-network-mode optional for lte interface;
    *) winbox - make mac-winbox work with RB850;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - do not show fan statuses in passive cooling CCR1009;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fix crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fix cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc34 2016-03-21

    What's new in 6.35rc34 (2016-Mar-21 09:47):

    *) capsman - added 802.11g/n band;
    *) chr - added support for VLAN on Hyper-V;
    *) hotspot - fix possible deadlock;
    *) hotspot - improved html page resistance against attacks;
    *) l2tp & pppoe - fixed user traffic accounting when fastpath was used;
    *) pppoe - fixed crash when removing pppoe service;
    *) winbox - added init-delay option to routerboard settings;
    *) winbox - added sfp-mac for GPON interfaces;
    *) winbox - added support for route action in mangle rules;
    *) bonding - fix crash on bonding slave release;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fix getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed crash when ppp interface gets disconnected and user gets authenticated at the same time (most probable with slow RADIUS server);
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fix filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - allow to show revoked & authority flags at the same time;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) ethernet - fixed Netmetal, QRT, DynaDish, SXT ac linking at 10/100Mbps (introduced in 6.35rc);
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fix ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - allow unknown scan-list names on wireless configuration to fix import;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) ipsec - take into account ip protocol in kernel policy matcher;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) mac-winbox - try to aggregate packets & resend all pending packets on timeout;
    *) ppp - do not crash when received multiple CBCP packets;
    *) winbox - correctly recognise if there is need to report fan information uder system health;
    *) winbox - do not use area v2 names instead of ospf v3 area names;
    *) winbox - make additional-network-mode optional for lte interface;
    *) winbox - make mac-winbox work with RB850;
    *) wireless - fix crash on nstreme-dual interface stats update;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - do not show fan statuses in passive cooling CCR1009;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fix crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fix cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc33 2016-03-18

    What's new in 6.35rc33 (2016-Mar-18 11:12):

    *) bonding - fix crash on bonding slave release;
    *) lte - changed AT parsing because supported Huawei modems use unsolicit events instead of polling;
    *) hotspot - fix possible deadlock;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fix getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed crash when ppp interface gets disconnected and user gets authenticated at the same time (most probable with slow RADIUS server);
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fix filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - allow to show revoked & authority flags at the same time;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) ethernet - fixed Netmetal, QRT, DynaDish, SXT ac linking at 10/100Mbps (introduced in 6.35rc);
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fix ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - allow unknown scan-list names on wireless configuration to fix import;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) ipsec - take into account ip protocol in kernel policy matcher;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) mac-winbox - try to aggregate packets & resend all pending packets on timeout;
    *) ppp - do not crash when received multiple CBCP packets;
    *) winbox - correctly recognise if there is need to report fan information uder system health;
    *) winbox - do not use area v2 names instead of ospf v3 area names;
    *) winbox - make additional-network-mode optional for lte interface;
    *) winbox - make mac-winbox work with RB850;
    *) wireless - fix crash on nstreme-dual interface stats update;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - do not show fan statuses in passive cooling CCR1009;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fix crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fix cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc32 2016-03-18

    What's new in 6.35rc32 (2016-Mar-18 09:35):

    *) bonding - fix crash on bonding slave release;
    *) hotspot - fix possible deadlock;
    *) l2tp - fixed kernel failure (introduced in 6.35rc);
    *) snmp - fix getbulk result ordering with multiple request OIDs;
    *) winbox - make mrru disabled and set mtu+mru to auto by default on new servers;
    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed crash when ppp interface gets disconnected and user gets authenticated at the same time (most probable with slow RADIUS server);
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fix filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - allow to show revoked & authority flags at the same time;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) ethernet - fixed Netmetal, QRT, DynaDish, SXT ac linking at 10/100Mbps (introduced in 6.35rc);
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fix ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - allow unknown scan-list names on wireless configuration to fix import;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) ipsec - take into account ip protocol in kernel policy matcher;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) mac-winbox - try to aggregate packets & resend all pending packets on timeout;
    *) ppp - do not crash when received multiple CBCP packets;
    *) winbox - correctly recognise if there is need to report fan information uder system health;
    *) winbox - do not use area v2 names instead of ospf v3 area names;
    *) winbox - make additional-network-mode optional for lte interface;
    *) winbox - make mac-winbox work with RB850;
    *) wireless - fix crash on nstreme-dual interface stats update;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - do not show fan statuses in passive cooling CCR1009;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fix crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fix cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc31 2016-03-17

    What's new in 6.35rc31 (2016-Mar-17 07:09):

    *) fasttrack - fixed timer updating in connections table for fasttrack connections;
    *) ppp - fixed crash when ppp interface gets disconnected and user gets authenticated at the same time (most probable with slow RADIUS server);
    *) ppp - fixed memory leak high number of pppoe clients to the same server;
    *) route - fix filter by routing table;
    *) winbox - allow to set additional-network-modes;
    *) winbox - allow to show revoked & authority flags at the same time;
    *) winbox - do not show "enable-jumper-reset" setting on devices without serial port;
    *) winbox - do not show real-tx-power column in current-tx-power by default;
    *) ethernet - fixed Netmetal, QRT, DynaDish, SXT ac linking at 10/100Mbps (introduced in 6.35rc);
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fix ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - allow unknown scan-list names on wireless configuration to fix import;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) ipsec - take into account ip protocol in kernel policy matcher;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) mac-winbox - try to aggregate packets & resend all pending packets on timeout;
    *) ppp - do not crash when received multiple CBCP packets;
    *) winbox - correctly recognise if there is need to report fan information uder system health;
    *) winbox - do not use area v2 names instead of ospf v3 area names;
    *) winbox - make additional-network-mode optional for lte interface;
    *) winbox - make mac-winbox work with RB850;
    *) wireless - fix crash on nstreme-dual interface stats update;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - do not show fan statuses in passive cooling CCR1009;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fix crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fix cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) hotspot - fix possible deadlock;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc30 2016-03-16

    What's new in 6.35rc30 (2016-Mar-15 12:32):

    *) ethernet - fixed NetMetal and DynaDish linking at 10/100Mbps (introduced in 6.35rc);
    *) firewall - added experimental "action=route" in mangle prerouting - that forces packets to specific gateway by ignoring routing decisions (CLI only);
    *) l2tp - fixed small memory leak on reconnects;
    *) pppoe - make fast path receive work on tile, arm and x86;
    *) proxy - fix ftp request url decode;
    *) tile - fixed fast path related memory leak;
    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - allow unknown scan-list names on wireless configuration to fix import;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) ipsec - take into account ip protocol in kernel policy matcher;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) mac-winbox - try to aggregate packets & resend all pending packets on timeout;
    *) ppp - do not crash when received multiple CBCP packets;
    *) winbox - correctly recognise if there is need to report fan information uder system health;
    *) winbox - do not use area v2 names instead of ospf v3 area names;
    *) winbox - make additional-network-mode optional for lte interface;
    *) winbox - make mac-winbox work with RB850;
    *) wireless - fix crash on nstreme-dual interface stats update;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - do not show fan statuses in passive cooling CCR1009;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fix crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fix cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) hotspot - fix possible deadlock;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc29 2016-03-15

    What's new in 6.35rc29 (2016-Mar-14 15:30):

    *) RB3011 - fixed time keeping;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - allow unknown scan-list names on wireless configuration to fix import;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) ipsec - take into account ip protocol in kernel policy matcher;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) mac-winbox - try to aggregate packets & resend all pending packets on timeout;
    *) ppp - do not crash when received multiple CBCP packets;
    *) winbox - correctly recognise if there is need to report fan information uder system health;
    *) winbox - do not use area v2 names instead of ospf v3 area names;
    *) winbox - make additional-network-mode optional for lte interface;
    *) winbox - make mac-winbox work with RB850;
    *) wireless - fix crash on nstreme-dual interface stats update;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu;
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#";
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - do not show fan statuses in passive cooling CCR1009;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fix crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1 ;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool;
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fix cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) hotspot - fix possible deadlock;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc28 2016-03-14

    What's new in 6.35rc28 (2016-Mar-14 11:17):

    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) console - allow unknown scan-list names on wireless configuration to fix import;
    *) console - sort completions/hints in natural order;
    *) health - swap fan2 and fan3 on CCR1072;
    *) ipsec - take into account ip protocol in kernel policy matcher;
    *) led - turn on fault led on CCR1072 if CPU too hot;
    *) lte - changed AT command processing;
    *) mac-winbox - try to aggregate packets & resend all pending packets on timeout;
    *) ppp - do not crash when received multiple CBCP packets;
    *) winbox - correctly recognise if there is need to report fan information uder system health;
    *) winbox - do not use area v2 names instead of ospf v3 area names;
    *) winbox - make additional-network-mode optional for lte interface;
    *) winbox - make mac-winbox work with RB850;
    *) wireless - fix crash on nstreme-dual interface stats update;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#"
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - do not show fan statuses in passive cooling CCR1009;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fix crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fix cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) hotspot - fix possible deadlock;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc26 2016-03-10

    What's new in 6.35rc26 (2016-Mar-10 14:44):

    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#"
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - do not show fan statuses in passive cooling CCR1009;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fix crash on non-HT clients;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fix cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) hotspot - fix possible deadlock;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

    What's new in 6.34.3 (2016-Mar-09 10:03):

    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) chr - fixed crash when layer7 firewall option used;
    *) fetch - fixed TTFP download;
    *) gre - fixed memory leak;
    *) lcd - fixed security screen did not show ip addresses on ccr;
    *) netinstall - fixed link negotiation for different sfp modules;
    *) ppp - fixed ppp crash;
    *) queue-tree - improved nested queue limit calculation;
    *) ssh - fixed crash on failed scp read;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - do not show fan statuses in passive cooling CCR1009;
    *) winbox - fixed typo in "echo reply";
    *) winbox - fixed unset options in /routing ospf interface menu;

  • Release 6.35rc25 2016-03-10

    What's new in 6.35rc25 (2016-Mar-10 07:27):

    *) tile - fixed rare situation when some cores decide not to take part in packet processing till next reboot;
    *) fastpath - fixed crash when packet arrives on disabled interface;
    *) capsman - fixed capsman extension channel names;
    *) console - fixed print follow in "/ip dns cache" menu
    *) ethernet - add option to see S-GPON-ONU module, GPON side SN in "/int eth mon sfp#"
    *) ethernet - do not allow to set self as master port;
    *) health - always report fan speed (even if it is 0);
    *) l2tp - introduced per tunnel allow-fast-path option;
    *) webfig - fixed firewall rule sorting did not work in other chains except all;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - do not show fan statuses in passive cooling CCR1009;
    *) winbox - fixed unset options in /routing ospf interface menu;
    *) wireless-rep - fix crash on non-HT clients;
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) pppoe-client - implemented fastpath support;
    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) snmp - don't group oids for bulk get with maxreps > 1
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fix cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) hotspot - fix possible deadlock;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

    What's new in 6.34.3 (2016-Mar-09 10:03):

    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) chr - fixed crash when layer7 firewall option used;
    *) fetch - fixed TTFP download;
    *) gre - fixed memory leak;
    *) lcd - fixed security screen did not show ip addresses on ccr;
    *) netinstall - fixed link negotiation for different sfp modules;
    *) ppp - fixed ppp crash;
    *) queue-tree - improved nested queue limit calculation;
    *) ssh - fixed crash on failed scp read;
    *) winbox - allow to set multiple dh-groups;
    *) winbox - do not show fan statuses in passive cooling CCR1009;
    *) winbox - fixed typo in "echo reply";
    *) winbox - fixed unset options in /routing ospf interface menu;

  • Release 6.35rc21 2016-03-08

    What's new in 6.35rc21 (2016-Mar-08 09:04):

    *) winbox - improved winbox connection loss detection, fixes winbox safe mode;
    *) wireless-rep - fixed speed issue when connected with Intel 802.11ac;
    *) fetch - fixed TTFP download;
    *) snmp - don't group oids for bulk get with maxreps > 1;
    *) users - added separate RoMoN policy (Winbox v3.2 and above required);
    *) ppp - fixed ppp crash (make it work with Windows clients);
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) winbox - fixed typo in "echo reply";
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) pppoe-client - implemented fastpath support;
    *) ssh - fix crash on failed scp read;
    *) chr - fixed crash when layer7 firewall option used;
    *) gre - fixed memory leak;
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - added missing modp8192 to /ipsec peer dh-group;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fix cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) lcd - add flip-screen option;
    *) lcd - security screen did not show ip addresses on ccr;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) hotspot - fix possible deadlock;
    *) queue-tree - improved nested queue limit calculation;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc19 2016-03-04

    What's new in 6.35rc19 (2016-Mar-04 11:46):

    *) ppp - fixed ppp crash (make it work with Windows clients);
    *) l2tp - implemented l2tp and lns fastpath/fasttrack support;
    *) cerm - revoked certificates not showing as (R)evoked;
    *) console - show RouterOS Version in /interface wireless scan;
    *) export - bonding did not show up in global export;
    *) export - fixed export when ipv6 address was taken from pool
    *) fetch - decrease connection idle timeout;
    *) ipsec - better flush on proposal change;
    *) webfig - show single item groups as optional values;
    *) webfig - sort numeric columns numerically even if they contain some text;
    *) winbox - added /interface wireless setup-repeater;
    *) winbox - added all the rates settings to the capsman;
    *) winbox - added flip-screen option to lcd settings;
    *) winbox - added missing eap-ttls-mschamv2 method to wireless security profile;
    *) winbox - added support for new settings from wireless-rep package;
    *) winbox - disable autostart for wireless scan,snooper,align etc. on open;
    *) winbox - fixed typo in "echo reply";
    *) wireless - fixed crash when ap is in cap mode (introduced in v6.35rc15);
    *) pppoe-client - implemented fastpath support;
    *) ssh - fix crash on failed scp read;
    *) chr - fixed crash when layer7 firewall option used;
    *) gre - fixed memory leak;
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - added missing modp8192 to /ipsec peer dh-group;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fix cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) lcd - add flip-screen option;
    *) lcd - security screen did not show ip addresses on ccr;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) hotspot - fix possible deadlock;
    *) queue-tree - improved nested queue limit calculation;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc16 2016-03-03

    What's new in 6.35rc16 (2016-Mar-02 14:26):

    *) l2tp - implemented l2tp and lns fastpath support;
    *) pppoe-client - implemented fastpath support;
    *) ssh - fix crash on failed scp read;
    *) chr - fixed layer7 firewall option/crash;
    *) ppp - fixed ppp crash;
    *) gre - fixed memory leak;
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - added missing modp8192 to /ipsec peer dh-group;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fix cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) lcd - add flip-screen option;
    *) lcd - security screen did not show ip addresses on ccr;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) hotspot - fix possible deadlock;
    *) queue-tree - improved nested queue limit calculation;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc15 2016-03-01

    What's new in 6.35rc15 (2016-Feb-29 16:00):

    *) l2tp - implemented l2tp (and lns) initial fastpath support;
    *) ppp - fixed ppp crash;
    *) gre - fixed memory leak;
    *) netinstall - fixed link negotiation for different sfp modules;
    *) snmp - fixed dhcpv4 lease hwaddr format according to mib;
    *) rb3011 - fixed high cpu load breaks ethernet stats;
    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe-client - implemented fastpath support;
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - added missing modp8192 to /ipsec peer dh-group;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fix cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) lcd - add flip-screen option;
    *) lcd - security screen did not show ip addresses on ccr;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) hotspot - fix possible deadlock;
    *) queue-tree - improved nested queue limit calculation;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc14 2016-02-29

    What's new in 6.35rc14 (2016-Feb-26 08:36):

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe-client - implemented fastpath support;
    *) pppoe - added rfc4679 support;
    *) pppoe-server - added pado-delay option;
    *) ppp - close connection if peer wants to re-authenticate;
    *) winbox - added missing modp8192 to /ipsec peer dh-group;
    *) winbox - limit ospf key to 16 symbols;
    *) snmp - fix cpu load reporting to 1min average and change oid to 1.3.6.1.4.1.2021.11.10.0;
    *) mpls - do not reset VPLS on TE tunnel re-optimize;
    *) lcd - add flip-screen option;
    *) lcd - security screen did not show ip addresses on ccr;
    *) interface queue - fixed "no-queue" on upgrade;
    *) fastpath - fixed rare kernel failure;
    *) lte - fixed bandlux modem dialing;
    *) wireless-rep - fixed qos frame-priroty when nv2 protocol used in station-wds mode;
    *) wireless - improved 1-chain 802.11ac station campability with other vendor multichain APs;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sessions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) hotspot - fix possible deadlock;
    *) queue-tree - improved nested queue limit calculation;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc12 2016-02-19

    What's new in 6.35rc12 (2016-Feb-19 12:38):

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) pppoe-client - implemented fastpath support;
    *) ssl - optimized certificate update;
    *) ospf - fixed crash when getting neighbor router-id in NBMA area;
    *) romon-ssh - fixed active addresses for romon user;
    *) email - fix send cmd server addr override;
    *) lte - added ipv6 support for SXT LTE;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sesssions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) hotspot - fix possible deadlock;
    *) queue-tree - improved nested queue limit calculation;
    *) radius - warn radius client if incorrect secret is being used;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc11 2016-02-17

    What's new in 6.35rc11 (2016-Feb-17 09:09):

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) winbox - added factory-firmware field to system/routerboard;
    *) l2tp - ipsec peer & policy sometimes was not removed after l2tp interface disable;
    *) pptp - fixed kernel crash when receiving fragmented packet with fragmented header;
    *) www - fixed www crash;
    *) winbox - fixed email address saving;
    *) lte - added ipv6 support for SXT LTE;
    *) dhcpv6 client - fix pd hint with empty address;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - incomplete ARP entries are not refreshed;
    *) winbox - fixed multi value field display (i.e. web proxy ports);
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sesssions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) ups - fix waiting for AC power restore in hibernate mode;
    *) lte - fix allowed bands for RBSXTLTE3-7;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) hotspot - fix possible deadlock;
    *) proxy - store error.html on flash if it is available;
    *) queue-tree - improved nested queue limit calculation;
    *) radius - warn radius client if incorrect secret is being used;
    *) tile - fixed possible kernel failure with disabled watchdog timer caused by DDoS attack;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) log - try not to loose disk messages and warn if lost any;
    *) switch - make "sa-learning=yes" by default when adding Ingress VLAN Translation rules;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) ssh - fixed connection stalling;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix console peer aes enc algorithm display;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) chr - fixed high rate limitation;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc10 2016-02-16

    What's new in 6.35rc10 (2016-Feb-16 13:07):

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) lte - added ipv6 support for SXT LTE;
    *) dhcpv6 client - fix pd hint with empty address;
    *) ipsec - fix multiple consecutive dynamic policy flush;
    *) winbox - incomplete ARP entries are not refreshed;
    *) winbox - fixed multi value field display (i.e. web proxy ports);
    *) winbox - added ipv6 firewall missing log option;
    *) profiler - classify certificate signing;
    *) services - do not show ssh entry under ip services if security package is disabled;
    *) queue - added bucket-size setting to queues (derived from max-limit);
    *) queue - improve "/queue interface" menu;
    *) console - update copyright notice;
    *) ip - rename max-arp-entries to less confusing max-neighbor-entries;
    *) l2tp - added support for max-sessions;
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sesssions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) ups - fix waiting for AC power restore in hibernate mode;
    *) lte - fix allowed bands for RBSXTLTE3-7;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) hotspot - fix possible deadlock;
    *) proxy - store error.html on flash if it is available;
    *) queue-tree - improved nested queue limit calculation;
    *) radius - warn radius client if incorrect secret is being used;
    *) tile - fixed possible kernel failure with disabled watchdog timer caused by DDoS attack;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) log - try not to loose disk messages and warn if lost any;
    *) switch - make "sa-learning=yes" by default when adding Ingress VLAN Translation rules;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) ssh - fixed connection stalling;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix console peer aes enc algorithm display;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) chr - fixed high rate limitation;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc9 2016-02-16

    What's new in 6.35rc9 (2016-Feb-16 07:07):

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) l2tp - added support for proxy authentication when receiving forwarded PPPoE sesssions;
    *) l2tp - added support for Hidden AVP, it is needed for proxy authentication;
    *) ipsec - fix larval SA refresh for display;
    *) wireless-rep - added 802.11g/n only band;
    *) wireless-rep,capsman - added rate config support;
    *) wireless-rep,capsman - added more configuration settings;
    *) ssh - simplify login process;
    *) ups - fix entering hibernate mode when below battery capacity limit;
    *) ups - fix waiting for AC power restore in hibernate mode;
    *) lte - fix allowed bands for RBSXTLTE3-7;
    *) lte - support for zte mf820s2;
    *) hotspot - clean-up all dead entries at once;
    *) hotspot - fix possible deadlock;
    *) console - rename max-arp-entries to less confusing max-neighbor-entries;
    *) queue - added bucket-size setting to queues in CLI (derived from max-limit);
    *) queue - improve "/queue interface" menu in CLI;
    *) proxy - store error.html on flash if it is available;
    *) queue-tree - improved nested queue limit calculation;
    *) radius - warn radius client if incorrect secret is being used;
    *) tile - fixed possible kernel failure with disabled watchdog timer caused by DDoS attack;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) log - try not to loose disk messages and warn if lost any;
    *) switch - make "sa-learning=yes" by default when adding Ingress VLAN Translation rules;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) ssh - fixed connection stalling;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix console peer aes enc algorithm display;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) chr - fixed high rate limitation;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc8 2016-02-11

    What's new in 6.35rc8 (2016-Feb-11 07:07):

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) hotspot - clean-up all dead entries at once;
    *) hotspot - fix possible deadlock;
    *) net - rename max-arp-entries to less confusing max-neighbor-entries in CLI;
    *) queue - added bucket-size setting to queues in CLI (derived from max-limit);
    *) queue - improve "/queue interface" menu in CLI;
    *) proxy - store error.html on flash if it is available;
    *) queue-tree - improved nested queue limit calculation;
    *) radius - warn radius client if incorrect secret is being used;
    *) tile - fixed possible kernel failure with disabled watchdog timer caused by DDoS attack;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) log - try not to loose disk messages and warn if lost any;
    *) switch - make "sa-learning=yes" by default when adding Ingress VLAN Translation rules;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) ssh - fixed connection stalling;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix console peer aes enc algorithm display;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) chr - fixed high rate limitation;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc7 2016-02-10

    What's new in 6.35rc7 (2016-Feb-10 07:33):

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) queue-tree - improved nested queue limit calculation;
    *) radius - warn radius client if incorrect secret is being used;
    *) tile - fixed possible kernel failure with disabled watchdog timer caused by DDoS attack;
    *) trafficgen - fix crash when unexpected stream reappears;
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) log - try not to loose disk messages and warn if lost any;
    *) switch - make "sa-learning=yes" by default when adding Ingress VLAN Translation rules;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) ssh - fixed connection stalling;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix console peer aes enc algorithm display;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) chr - fixed high rate limitation;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc6 2016-02-09

    What's new in 6.35rc6 (2016-Feb-09 06:29):

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395);
    *) ipsec - always re-key ph1 because it was possible that ph1 without DPD would expire;
    *) log - try not to loose disk messages and warn if lost any;
    *) switch - make "sa-learning=yes" by default when adding Ingress VLAN Translation rules;
    *) system - log time changes;
    *) trafflow - fix potential deadlock;
    *) ssh - fixed connection stalling;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix console peer aes enc algorithm display;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) chr - fixed high rate limitation;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc5 2016-02-05

    What's new in 6.35rc5 (2016-Feb-05 09:24):

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395)
    *) ssh - fixed connection stalling;
    *) certificate - allow manual crl url addition;
    *) ipsec - fix console peer aes enc algorithm display;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) chr - fixed high rate limitation;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc4 2016-02-04

    What's new in 6.35rc4 (2016-Feb-04 13:12):

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395)
    *) certificate - allow manual crl url addition;
    *) ipsec - fix console peer aes enc algorithm display;
    *) ipsec - fix fast ph2 SA addition;
    *) led - fix crash on assigned interface removal;
    *) lte - support Alt38XX modem;
    *) tile-crypto - fix minor memory leak;
    *) wireless-rep - allow to connect to AP after scan;
    *) wireless-rep - fix signal leds;
    *) wireless-rep - request interface name for setup-repeater;
    *) wireless-rep - adjust roaming scan times;
    *) wireless-rep - do not allow empty ssid for AP modes;
    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) chr - fixed high rate limitation;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc3 2016-02-04

    What's new in 6.35rc3 (2016-Feb-03 07:32):

    *) dude - (changes discussed here: http://forum.mikrotik.com/viewtopic.php?f=8&t=104395)
    *) interface - show stats properly in bits not bytes;
    *) traffic-monitor - show stats properly in bits not bytes;
    *) smips - properly detect smips boards for winbox & webfig;
    *) ccr1072 - fix traffic halting when sfp+ 1-4 or 5-8 where all disabled;
    *) chr - fixed high rate limitation;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.35rc2 2016-02-02

    What's new in 6.35rc2 (2016-Feb-01 13:13):

    *) chr - fixed high rate limitation;
    *) ippool6 - fix potential crash;
    *) routing - fixed rare kernel failure on different dynamic routing configurations;
    *) wireless-rep - fix nv2 protocol;
    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan for 802.11 protocol;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list;
    *) wireless - added 900MHz band support for "brazil-anatel" country.

  • Release 6.35rc1 2016-02-01

    What's new in 6.35rc1 (2016-Jan-29 13:59):

    *) route - do not show duplicate gateway on connected route;
    *) wireless - added new package "wireless-rep";
    *) wireless-rep - initial support for station roaming for station mode in 802.11 protocol;
    *) wireless-rep - added support for wireless repeater mode for 802.11 protocol;
    *) wireless-rep - added support for wireless background scan;
    *) wireless-rep - added support for saving wireless scan results to file;
    *) wireless-rep - added support for wireless scan rounds setting;
    *) wireless-rep - added WPS client support;
    *) wireless-rep - added STEP feature for the scan-list.

  • Release 6.34rc45 2016-01-27

    What's new in 6.34rc45 (2016-Jan-26 08:41):

    *) mipsle - architecture support dropped (last fully supported version 6.32.3);
    *) capsman - fix radius accounting stop message;
    *) cerm - allow to sign certificates from imported CAs created with RouterOS;
    *) ldp - fix MPLS PDU max length;
    *) net - improve 64bit interface stats support;
    *) routerboard - print factory-firmware version in routerboard menu;
    *) snmp - add oid from ucd mib for total cpu load OID 1.3.6.1.4.1.2021.11.52.0;
    *) winbox - add extra items automaticly to multiline fields if at least one of them is required;
    *) winbox - implemented full ipv6 dhcp client;
    *) winbox - update blocked flag if user changed blocked field in dhcp server lease;
    *) winbox/webfig - fixed version column ordering in ip neighbors list;
    *) mac-telnet - fixed backspace when typing login username;
    *) address-list - properly remove unused address-lists from drop-downs;
    *) sstp - allow ECDHE when pfs enabled;
    *) lte - fixed info command for Cinterion EHS5-E modem;
    *) fast-path - fixed kernel crash on on/off;
    *) fetch - fixed closure after 30 seconds;
    *) ppp - fixed rare kernel crash (introduced in v6.33);
    *) ppp - do not allow empty name ppp secrets;
    *) licensing - fixed that some old 7 symbol keys could not be upgraded;
    *) ssh - fixed possible kernel crash;
    *) console - fixed crash on creating variable with "?" in it;
    *) winbox - fixed tab names to correspond to console;
    *) webfig - fixed firewall connection-bytes option;
    *) webfig - fixed switch port "default vlan id" has missing "auto" value;
    *) dude - The reports of my death have been greatly exaggerated;
    *) dude - dude RouterOS package added for tile and x86 (CHR) architecture;
    *) dude - initial work on dude integration into RouterOS;
    *) chr - fix SSH key import on AWS;
    *) crs212 - fix 1Gbps ether1 linking problem;
    *) timezone - use backward timezone aliases;
    *) lte - support serial port for DellWireless 5570;
    *) lte - improved dhcp handling on interfaces that doesn't support it;
    *) ipsec - allow my-id address specification in main mode;
    *) dhcpv6 client - fix remove when client reappears on restart;
    *) default config - fix hAP lite with one wireless;
    *) firewall - added inversion support for "limit" option;
    *) firewall - added bit rate matching for "limit" option;
    *) firewall - improved performance for "limit" option;
    *) dhcpv6-client - fix ia lifetime check;
    *) ipsec - fixed kernel failure after underlying tunnel has been disabled/enabled;
    *) ipsec - prioritize proposals;
    *) ipsec - support multiple DH groups for phase 1;
    *) log - reopen log file if deleted;
    *) netinstall - fix apply default config;
    *) packing - fix tcp/udp checksums when simple packing is used;
    *) tile - make sure that SFP rj45 modules that use forced 1G FD settings work correctly after system reboot;
    *) tile - fix ipsec freeze after SA updates;
    *) wireless - added WPS buttons support on hAP and hAP ac lite;
    *) upnp - fixed missing in-interface option for dynamic dst-nat rules;
    *) upnp - added comment for dynamic dst-nat rules to inform what host/program required it;
    *) net - fix bridge firewall chain check (broken since 6.33.2);
    *) net - show fp counters in /interface monitor aggregate;
    *) romon - allow to see device identity if it is longer than 31 character;
    *) smb - fix crash when changing user which has open session;
    *) tunnel - fix complaining about loop after ~248 days;
    *) vrrp - make sure that VRRP gets state on bootup;
    *) webfig - recognize properly CHR;
    *) winbox - show only actual switch-cpu ports in switch setting combobox;
    *) chr - license fix for AWS and similar solutions;
    *) arm - fix usb modem modules on ARM;
    *) dhcpv6-client - fixed stopped state;
    *) netinstall - sort packages by name;
    *) net - fixed net crash when firewall jump rule points to disabled custom chain;
    *) net - do not allow to add new firewall rule before built-in (reverted);
    *) winbox - include FP in fast-path column names;
    *) ipsec - fix phase2 hmac-sha-256-128 truncation len from 96 to 128
    This will break compatibility with all previous versions and any other
    currently compatible software using sha256 hmac for phase2;
    *) ssh, ftp - make read, write user group policy aware;
    *) tunnel - fix keep-alive (introduced in 6.34rc);
    *) cerm - show last crl update time;
    *) quicket - support CAP mode on all existing wireless packages;
    *) wlan - add united states3 country;
    *) fast-path - fix locking issue which could lead to reboot loop (introduced in 6.34rc20);
    *) userman4 - try loading signup files from db path first;
    *) sstp - allow to limit tls version to v1.2 only;
    *) chr - make tool profile work on 64bit x86;
    *) dhcpv6-server - added binding server=all option;
    *) hotspot - added html-directory-override & recognize default hotspot user;
    *) hotspot - fixed export of default trial user;
    *) hotspot - fixed memory leak on https requests;
    *) winbox - allow to specify amsdu-limit & amsdu-threshold on 11n wifi cards;
    *) winbox - added multicast-buffering & keepalive-frames settings to wireless interfaces;
    *) CHR - implemented trial support for different CHR speed tiers;
    *) dhcpv6-client - fix add route/address;
    *) usb - enable ch341 serial module;
    *) lte - make sure that both LTE miniPCI-e cards are recognised;
    *) winbox - show Common-Name of certificates in certificate list;
    *) winbox - added units to PCQ queue fields;
    *) net - do not break connection when interface is added to bridge;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager web page crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option.

  • Release 6.34rc41 2016-01-21

    What's new in 6.34rc41 (2016-Jan-19 17:23):

    *) mipsle - architecture support dropped (last fully supported version 6.32.3);
    *) mac-telnet - fixed backspace when typing login username;
    *) address-list - properly remove unused address-lists from drop-downs;
    *) sstp - allow ECDHE when pfs enabled;
    *) lte - fixed info command for Cinterion EHS5-E modem;
    *) fast-path - fixed kernel crash on on/off;
    *) fetch - fixed closure after 30 seconds;
    *) ppp - fixed rare kernel crash (introduced in v6.33);
    *) ppp - do not allow empty name ppp secrets;
    *) licensing - fixed that some old 7 symbol keys could not be upgraded;
    *) ssh - fixed possible kernel crash;
    *) console - fixed crash on creating variable with "?" in it;
    *) winbox - fixed tab names to correspond to console;
    *) webfig - fixed firewall connection-bytes option;
    *) webfig - fixed switch port "default vlan id" has missing "auto" value;
    *) dude - The reports of my death have been greatly exaggerated;
    *) dude - dude RouterOS package added for tile and x86 (CHR) architecture;
    *) dude - initial work on dude integration into RouterOS;
    *) chr - fix SSH key import on AWS;
    *) crs212 - fix 1Gbps ether1 linking problem;
    *) timezone - use backward timezone aliases;
    *) lte - support serial port for DellWireless 5570;
    *) lte - improved dhcp handling on interfaces that doesn't support it;
    *) ipsec - allow my-id address specification in main mode;
    *) dhcpv6 client - fix remove when client reappears on restart;
    *) default config - fix hAP lite with one wireless;
    *) firewall - added inversion support for "limit" option;
    *) firewall - added bit rate matching for "limit" option;
    *) firewall - improved performance for "limit" option;
    *) dhcpv6-client - fix ia lifetime check;
    *) ipsec - fixed kernel failure after underlying tunnel has been disabled/enabled;
    *) ipsec - prioritize proposals;
    *) ipsec - support multiple DH groups for phase 1;
    *) log - reopen log file if deleted;
    *) netinstall - fix apply default config;
    *) packing - fix tcp/udp checksums when simple packing is used;
    *) tile - make sure that SFP rj45 modules that use forced 1G FD settings work correctly after system reboot;
    *) tile - fix ipsec freeze after SA updates;
    *) wireless - added WPS buttons support on hAP and hAP ac lite;
    *) upnp - fixed missing in-interface option for dynamic dst-nat rules;
    *) upnp - added comment for dynamic dst-nat rules to inform what host/program required it;
    *) net - fix bridge firewall chain check (broken since 6.33.2);
    *) net - show fp counters in /interface monitor aggregate;
    *) romon - allow to see device identity if it is longer than 31 character;
    *) smb - fix crash when changing user which has open session;
    *) tunnel - fix complaining about loop after ~248 days;
    *) vrrp - make sure that VRRP gets state on bootup;
    *) webfig - recognize properly CHR;
    *) winbox - show only actual switch-cpu ports in switch setting combobox;
    *) chr - license fix for AWS and similar solutions;
    *) arm - fix usb modem modules on ARM;
    *) dhcpv6-client - fixed stopped state;
    *) netinstall - sort packages by name;
    *) net - fixed net crash when firewall jump rule points to disabled custom chain;
    *) net - do not allow to add new firewall rule before built-in (reverted);
    *) winbox - include FP in fast-path column names;
    *) ipsec - fix phase2 hmac-sha-256-128 truncation len from 96 to 128
    This will break compatibility with all previous versions and any other
    currently compatible software using sha256 hmac for phase2;
    *) ssh, ftp - make read, write user group policy aware;
    *) tunnel - fix keep-alive (introduced in 6.34rc);
    *) cerm - show last crl update time;
    *) quicket - support CAP mode on all existing wireless packages;
    *) wlan - add united states3 country;
    *) fast-path - fix locking issue which could lead to reboot loop (introduced in 6.34rc20);
    *) userman4 - try loading signup files from db path first;
    *) sstp - allow to limit tls version to v1.2 only;
    *) chr - make tool profile work on 64bit x86;
    *) dhcpv6-server - added binding server=all option;
    *) hotspot - added html-directory-override & recognize default hotspot user;
    *) hotspot - fixed export of default trial user;
    *) hotspot - fixed memory leak on https requests;
    *) winbox - allow to specify amsdu-limit & amsdu-threshold on 11n wifi cards;
    *) winbox - added multicast-buffering & keepalive-frames settings to wireless interfaces;
    *) CHR - implemented trial support for different CHR speed tiers;
    *) dhcpv6-client - fix add route/address;
    *) usb - enable ch341 serial module;
    *) lte - make sure that both LTE miniPCI-e cards are recognised;
    *) winbox - show Common-Name of certificates in certificate list;
    *) winbox - added units to PCQ queue fields;
    *) net - do not break connection when interface is added to bridge;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager web page crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;

  • Release 6.34rc39 2016-01-19

    What's new in 6.34rc39 (2016-Jan-18 13:24):

    *) dude - The reports of my death have been greatly exaggerated;
    *) dude - dude RouterOS package added for tile and x86 (CHR) architecture;
    *) dude - initial work on dude integration into RouterOS;
    *) chr - fix SSH key import on AWS;
    *) crs212 - fix 1Gbps ether1 linking problem;
    *) timezone - use backward timezone aliases;
    *) lte - support serial port for DellWireless 5570;
    *) lte - improved dhcp handling on interfaces that doesn't support it;
    *) ipsec - allow my-id address specification in main mode;
    *) dhcpv6 client - fix remove when client reappears on restart;
    *) default config - fix for hAP family devices with one wireless;
    *) firewall - added inversion support for "limit" option;
    *) firewall - added bit rate matching for "limit" option;
    *) firewall - improved performance for "limit" option;
    *) dhcpv6-client - fix ia lifetime check;
    *) ipsec - fixed kernel failure after underlying tunnel has been disabled/enabled;
    *) ipsec - prioritize proposals;
    *) ipsec - support multiple DH groups for phase 1;
    *) log - reopen log file if deleted;
    *) netinstall - fix apply default config;
    *) packing - fix tcp/udp checksums when simple packing is used;
    *) tile - make sure that SFP rj45 modules that use forced 1G FD settings work correctly after system reboot;
    *) tile - fix ipsec freeze after SA updates;
    *) wireless - added WPS buttons support on hAP and hAP ac lite;
    *) upnp - fixed missing in-interface option for dynamic dst-nat rules;
    *) upnp - added comment for dynamic dst-nat rules to inform what host/program required it;
    *) net - fix bridge firewall chain check (broken since 6.33.2);
    *) net - show fp counters in /interface monitor aggregate;
    *) romon - allow to see device identity if it is longer than 31 character;
    *) smb - fix crash when changing user which has open session;
    *) tunnel - fix complaining about loop after ~248 days;
    *) vrrp - make sure that VRRP gets state on bootup;
    *) webfig - recognize properly CHR;
    *) winbox - show only actual switch-cpu ports in switch setting combobox;
    *) chr - license fix for AWS and similar solutions;
    *) arm - fix usb modem modules on ARM;
    *) dhcpv6-client - fixed stopped state;
    *) netinstall - sort packages by name;
    *) net - fixed net crash when firewall jump rule points to disabled custom chain;
    *) net - do not allow to add new firewall rule before built-in (reverted);
    *) winbox - include FP in fast-path column names;
    *) ipsec - fix phase2 hmac-sha-256-128 truncation len from 96 to 128
    This will break compatibility with all previous versions and any other
    currently compatible software using sha256 hmac for phase2;
    *) ssh, ftp - make read, write user group policy aware;
    *) tunnel - fix keep-alive (introduced in 6.34rc);
    *) cerm - show last crl update time;
    *) quicket - support CAP mode on all existing wireless packages;
    *) wlan - add united states3 country;
    *) fast-path - fix locking issue which could lead to reboot loop (introduced in 6.34rc20);
    *) userman4 - try loading signup files from db path first;
    *) sstp - allow to limit tls version to v1.2 only;
    *) chr - make tool profile work on 64bit x86;
    *) dhcpv6-server - added binding server=all option;
    *) hotspot - added html-directory-override & recognize default hotspot user;
    *) hotspot - fixed export of default trial user;
    *) hotspot - fixed memory leak on https requests;
    *) winbox - allow to specify amsdu-limit & amsdu-threshold on 11n wifi cards;
    *) winbox - added multicast-buffering & keepalive-frames settings to wireless interfaces;
    *) CHR - implemented trial support for different CHR speed tiers;
    *) dhcpv6-client - fix add route/address;
    *) usb - enable ch341 serial module;
    *) lte - make sure that both LTE miniPCI-e cards are recognised;
    *) winbox - show Common-Name of certificates in certificate list;
    *) winbox - added units to PCQ queue fields;
    *) net - do not break connection when interface is added to bridge;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager web page crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;

  • Release 6.34rc36 2016-01-14

    What's new in 6.34rc36 (2016-Jan-14 14:20):

    *) dhcpv6-client - fix ia lifetime check;
    *) ipsec - fixed kernel failure after underlying tunnel has been disabled/enabled;
    *) ipsec - prioritize proposals;
    *) ipsec - support multiple DH groups for phase 1;
    *) log - reopen log file if deleted;
    *) netinstall - fix apply default config;
    *) packing - fix tcp/udp checksums when simple packing is used;
    *) tile - make sure that SFP rj45 modules that use forced 1G FD settings work correctly after system reboot;
    *) tile - fix ipsec freeze after SA updates;
    *) wireless - added WPS buttons support on hAP and hAP ac lite;
    *) upnp - fixed missing in-interface option for dynamic dst-nat rules;
    *) upnp - added comment for dynamic dst-nat rules to inform what host/program required it;
    *) net - fix bridge firewall chain check (broken since 6.33.2);
    *) net - show fp counters in /interface monitor aggregate;
    *) romon - allow to see device identity if it is longer than 31 character;
    *) smb - fix crash when changing user which has open session;
    *) tunnel - fix complaining about loop after ~248 days;
    *) vrrp - make sure that VRRP gets state on bootup;
    *) webfig - recognize properly CHR;
    *) winbox - show only actual switch-cpu ports in switch setting combobox;
    *) chr - license fix for AWS and similar solutions;
    *) arm - fix usb modem modules on ARM;
    *) dhcpv6-client - fixed stopped state;
    *) netinstall - sort packages by name;
    *) net - fixed net crash when firewall jump rule points to disabled custom chain;
    *) net - do not allow to add new firewall rule before built-in (reverted);
    *) wireless - regular “wireless” package is now retired and replaced by "wireless-fp" and "wireless-cm2";
    *) winbox - include FP in fast-path column names;
    *) ipsec - fix phase2 hmac-sha-256-128 truncation len from 96 to 128
    This will break compatibility with all previous versions and any other
    currently compatible software using sha256 hmac for phase2;
    *) ssh, ftp - make read, write user group policy aware;
    *) tunnel - fix keep-alive (introduced in 6.34rc);
    *) cerm - show last crl update time;
    *) quicket - support CAP mode on all existing wireless packages;
    *) wlan - add united states3 country;
    *) fast-path - fix locking issue which could lead to reboot loop (introduced in 6.34rc20);
    *) userman4 - try loading signup files from db path first;
    *) sstp - allow to limit tls version to v1.2 only;
    *) chr - make tool profile work on 64bit x86;
    *) dhcpv6-server - added binding server=all option;
    *) hotspot - added html-directory-override & recognize default hotspot user;
    *) hotspot - fixed export of default trial user;
    *) hotspot - fixed memory leak on https requests;
    *) winbox - allow to specify amsdu-limit & amsdu-threshold on 11n wifi cards;
    *) winbox - added multicast-buffering & keepalive-frames settings to wireless interfaces;
    *) CHR - implemented trial support for different CHR speed tiers;
    *) dhcpv6-client - fix add route/address;
    *) usb - enable ch341 serial module;
    *) lte - make sure that both LTE miniPCI-e cards are recognised;
    *) winbox - show Common-Name of certificates in certificate list;
    *) winbox - added units to PCQ queue fields;
    *) net - do not break connection when interface is added to bridge;
    *) dude - “The reports of my death have been greatly exaggerated”;
    *) dude - dude RouterOS package added for tile and x86 (CHR) architecture;
    *) dude - initial work on dude integration into RouterOS;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager web page crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;

  • Release 6.34rc34 2016-01-08

    What's new in 6.34rc34 (2016-Jan-08 10:04):

    *) upnp - fixed missing in-interface option for dynamic dst-nat rules;
    *) upnp - added comment for dynamic dst-nat rules to inform what host/program required it;
    *) net - fix bridge firewall chain check (broken since 6.33.2);
    *) net - show fp counters in /interface monitor aggregate;
    *) romon - allow to see device identity if it is longer than 31 character;
    *) smb - fix crash when changing user which has open session;
    *) tunnel - fix complaining about loop after ~248 days;
    *) vrrp - make sure that VRRP gets state on bootup;
    *) webfig - recognize properly CHR;
    *) winbox - show only actual switch-cpu ports in switch setting combobox;
    *) chr - license fix for AWS and similar solutions;
    *) arm - fix usb modem modules on ARM;
    *) dhcpv6-client - fixed stopped state;
    *) net - fixed possible kernel failure/lock-up;
    *) netinstall - sort packages by name;
    *) sshd - resolved shared secret mismatch issue;
    *) net - do not show L2MTU in VLAN compact export;
    *) net - fixed net crash when firewall jump rule points to disabled custom chain;
    *) net - apply slave config only if master config has been changed;
    *) crypto - fixed kernel failure in talitos HW encryption;
    *) net - do not allow to add new firewall rule before built-in (reverted);
    *) wireless - regular “wireless” package is now retired and replaced by "wireless-fp" and "wireless-cm2";
    *) winbox - include FP in fast-path column names;
    *) ssh - fix session clean-up;
    *) ipsec - fix phase2 hmac-sha-256-128 truncation len from 96 to 128
    This will break compatibility with all previous versions and any other
    currently compatible software using sha256 hmac for phase2;
    *) fetch - added 30 second connection time-out;
    *) led - add wlan led to RB951Ui
    *) dhcpv6-client - fix next resend time rounding error;
    *) ssh, ftp - make read, write user group policy aware;
    *) tunnel - fix keep-alive (introduced in 6.34rc);
    *) cerm - show last crl update time;
    *) quicket - support CAP mode on all existing wireless packages;
    *) kernel - general improvement for core process scheduling;
    *) wlan - add united states3 country;
    *) fast-path - fix locking issue which could lead to reboot loop (introduced in 6.34rc20);
    *) userman4 - try loading signup files from db path first;
    *) sstp - allow to limit tls version to v1.2 only;
    *) chr - make tool profile work on 64bit x86;
    *) dhcpv6-server - added binding server=all option;
    *) btest - improve UDP tx rate precision;
    *) btest - fix potential crash after btest release;
    *) hotspot - added html-directory-override & recognize default hotspot user;
    *) hotspot - fixed export of default trial user;
    *) hotspot - fixed memory leak on https requests;
    *) winbox - added + & - to igmp proxy mfc;
    *) winbox - allow to specify amsdu-limit & amsdu-threshold on 11n wifi cards;
    *) winbox - allow to specify traffic-monitor threshold in k & M units + specify that those are bits;
    *) winbox - added multicast-buffering & keepalive-frames settings to wireless interfaces;
    *) CHR - implemented trial support for different CHR speed tiers;
    *) dhcpv6-client - fix add route/address;
    *) usb - enable ch341 serial module;
    *) lte - make sure that both LTE miniPCI-e cards are recognised;
    *) ppp - make PPP active print radius & !radius conditions work;
    *) winbox - show fast-path per interface counters;
    *) log - log link up/down events only when link actually has changed its state;
    *) romon - do not accept multicast id;
    *) romon - fixed crash on RoMON if fast-path was active;
    *) winbox - show Common-Name of certificates in certificate list;
    *) e-mail - do not reset server address after changing configuration;
    *) winbox - added units to PCQ queue fields;
    *) winbox - added LCD menu for RB3011;
    *) smb - show correct interface name in SMB debug logs;
    *) net - do not break connection when interface is added to bridge;
    *) dude - “The reports of my death have been greatly exaggerated”;
    *) dude - dude RouterOS package added for tile and x86 (CHR) architecture;
    *) dude - initial work on dude integration into RouterOS;
    *) webfig - didn't show zero values in CRS ingress/egress vlan translation rules;
    *) netwatch - make work with ping timeouts more precise;
    *) btest - fix crash on stop/start with fastpath enabled;
    *) hotspot - added missing favicon.ico in hotspot html pages;
    *) dhcpv6 - various changes on client, server, relay optimization;
    *) arp - show incomplete arp entries;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager web page crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6-client - added address acquisition support;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc32 2016-01-08

    What's new in 6.34rc32 (2016-Jan-07 12:57):

    *) net - fix bridge firewall chain check (broken since 6.33.2);
    *) net - show fp counters in /interface monitor aggregate;
    *) romon - allow to see device identity if it is longer than 31 character;
    *) smb - fix crash when changing user which has open session;
    *) tunnel - fix complaining about loop after ~248 days;
    *) vrrp - make sure that VRRP gets state on bootup;
    *) webfig - recognize properly CHR;
    *) winbox - show only actual switch-cpu ports in switch setting combobox;
    *) chr - license fix for AWS and similar solutions;
    *) arm - fix usb modem modules on ARM;
    *) dhcpv6-client - fixed stopped state;
    *) net - fixed possible kernel failure/lock-up;
    *) netinstall - sort packages by name;
    *) sshd - resolved shared secret mismatch issue;
    *) net - do not show L2MTU in VLAN compact export;
    *) net - fixed net crash when firewall jump rule points to disabled custom chain;
    *) net - apply slave config only if master config has been changed;
    *) crypto - fixed kernel failure in talitos HW encryption;
    *) net - do not allow to add new firewall rule before built-in (reverted);
    *) wireless - regular “wireless” package is now retired and replaced by "wireless-fp" and "wireless-cm2";
    *) winbox - include FP in fast-path column names;
    *) ssh - fix session clean-up;
    *) ipsec - fix phase2 hmac-sha-256-128 truncation len from 96 to 128
    This will break compatibility with all previous versions and any other
    currently compatible software using sha256 hmac for phase2;
    *) fetch - added 30 second connection time-out;
    *) led - add wlan led to RB951Ui
    *) dhcpv6-client - fix next resend time rounding error;
    *) ssh, ftp - make read, write user group policy aware;
    *) tunnel - fix keep-alive (introduced in 6.34rc);
    *) cerm - show last crl update time;
    *) quicket - support CAP mode on all existing wireless packages;
    *) kernel - general improvement for core process scheduling;
    *) wlan - add united states3 country;
    *) fast-path - fix locking issue which could lead to reboot loop (introduced in 6.34rc20);
    *) userman4 - try loading signup files from db path first;
    *) sstp - allow to limit tls version to v1.2 only;
    *) chr - make tool profile work on 64bit x86;
    *) dhcpv6-server - added binding server=all option;
    *) btest - improve UDP tx rate precision;
    *) btest - fix potential crash after btest release;
    *) hotspot - added html-directory-override & recognize default hotspot user;
    *) hotspot - fixed export of default trial user;
    *) hotspot - fixed memory leak on https requests;
    *) winbox - added + & - to igmp proxy mfc;
    *) winbox - allow to specify amsdu-limit & amsdu-threshold on 11n wifi cards;
    *) winbox - allow to specify traffic-monitor threshold in k & M units + specify that those are bits;
    *) winbox - added multicast-buffering & keepalive-frames settings to wireless interfaces;
    *) CHR - implemented trial support for different CHR speed tiers;
    *) dhcpv6-client - fix add route/address;
    *) usb - enable ch341 serial module;
    *) lte - make sure that both LTE miniPCI-e cards are recognised;
    *) ppp - make PPP active print radius & !radius conditions work;
    *) winbox - show fast-path per interface counters;
    *) log - log link up/down events only when link actually has changed its state;
    *) romon - do not accept multicast id;
    *) romon - fixed crash on RoMON if fast-path was active;
    *) winbox - show Common-Name of certificates in certificate list;
    *) e-mail - do not reset server address after changing configuration;
    *) winbox - added units to PCQ queue fields;
    *) winbox - added LCD menu for RB3011;
    *) smb - show correct interface name in SMB debug logs;
    *) net - do not break connection when interface is added to bridge;
    *) dude - “The reports of my death have been greatly exaggerated”;
    *) dude - dude RouterOS package added for tile and x86 (CHR) architecture;
    *) dude - initial work on dude integration into RouterOS;
    *) webfig - didn't show zero values in CRS ingress/egress vlan translation rules;
    *) netwatch - make work with ping timeouts more precise;
    *) btest - fix crash on stop/start with fastpath enabled;
    *) hotspot - added missing favicon.ico in hotspot html pages;
    *) dhcpv6 - various changes on client, server, relay optimization;
    *) arp - show incomplete arp entries;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager web page crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6-client - added address acquisition support;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc30 2015-12-30

    What's new in 6.34rc30 (2015-Dec-30 13:57):

    *) chr - license fix for AWS and similar solutions;
    *) arm - fix usb modem modules on ARM;
    *) dhcpv6-client - fixed stopped state;
    *) net - fixed possible kernel failure/lock-up;
    *) netinstall - sort packages by name;
    *) sshd - resolved shared secret mismatch issue;
    *) net - do not show L2MTU in VLAN compact export;
    *) net - fixed net crash when firewall jump rule points to disabled custom chain;
    *) net - apply slave config only if master config has been changed;
    *) crypto - fixed kernel failure in talitos HW encryption;
    *) net - do not allow to add new firewall rule before built-in (reverted);
    *) wireless - regular “wireless” package is now retired and replaced by "wireless-fp" and "wireless-cm2";
    *) winbox - include FP in fast-path column names;
    *) ssh - fix session clean-up;
    *) ipsec - fix phase2 hmac-sha-256-128 truncation len from 96 to 128
    This will break compatibility with all previous versions and any other
    currently compatible software using sha256 hmac for phase2;
    *) fetch - added 30 second connection time-out;
    *) led - add wlan led to RB951Ui
    *) dhcpv6-client - fix next resend time rounding error;
    *) ssh, ftp - make read, write user group policy aware;
    *) tunnel - fix keep-alive (introduced in 6.34rc);
    *) cerm - show last crl update time;
    *) quicket - support CAP mode on all existing wireless packages;
    *) kernel - general improvement for core process scheduling;
    *) wlan - add united states3 country;
    *) fast-path - fix locking issue which could lead to reboot loop (introduced in 6.34rc20);
    *) userman4 - try loading signup files from db path first;
    *) sstp - allow to limit tls version to v1.2 only;
    *) chr - make tool profile work on 64bit x86;
    *) dhcpv6-server - added binding server=all option;
    *) btest - improve UDP tx rate precision;
    *) btest - fix potential crash after btest release;
    *) hotspot - added html-directory-override & recognize default hotspot user;
    *) hotspot - fixed export of default trial user;
    *) hotspot - fixed memory leak on https requests;
    *) winbox - added + & - to igmp proxy mfc;
    *) winbox - allow to specify amsdu-limit & amsdu-threshold on 11n wifi cards;
    *) winbox - allow to specify traffic-monitor threshold in k & M units + specify that those are bits;
    *) winbox - added multicast-buffering & keepalive-frames settings to wireless interfaces;
    *) CHR - implemented trial support for different CHR speed tiers;
    *) dhcpv6-client - fix add route/address;
    *) usb - enable ch341 serial module;
    *) lte - make sure that both LTE miniPCI-e cards are recognised;
    *) ppp - make PPP active print radius & !radius conditions work;
    *) winbox - show fast-path per interface counters;
    *) log - log link up/down events only when link actually has changed its state;
    *) romon - do not accept multicast id;
    *) romon - fixed crash on RoMON if fast-path was active;
    *) winbox - show Common-Name of certificates in certificate list;
    *) e-mail - do not reset server address after changing configuration;
    *) winbox - added units to PCQ queue fields;
    *) winbox - added LCD menu for RB3011;
    *) smb - show correct interface name in SMB debug logs;
    *) net - do not break connection when interface is added to bridge;
    *) dude - “The reports of my death have been greatly exaggerated”;
    *) dude - dude RouterOS package added for tile and x86 (CHR) architecture;
    *) dude - initial work on dude integration into RouterOS;
    *) webfig - didn't show zero values in CRS ingress/egress vlan translation rules;
    *) netwatch - make work with ping timeouts more precise;
    *) btest - fix crash on stop/start with fastpath enabled;
    *) hotspot - added missing favicon.ico in hotspot html pages;
    *) dhcpv6 - various changes on client, server, relay optimization;
    *) arp - show incomplete arp entries;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager web page crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6-client - added address acquisition support;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc29 2015-12-29

    What's new in 6.34rc29 (2015-Dec-29 15:25):

    *) arm - fix usb modem modules on ARM;
    *) dhcpv6-client - fixed stopped state;
    *) net - fixed possible kernel failure/lock-up;
    *) netinstall - sort packages by name;
    *) sshd - resolved shared secret mismatch issue;
    *) net - do not show L2MTU in VLAN compact export;
    *) net - fixed net crash when firewall jump rule points to disabled custom chain;
    *) net - apply slave config only if master config has been changed;
    *) crypto - fixed kernel failure in talitos HW encryption;
    *) net - do not allow to add new firewall rule before built-in (reverted);
    *) wireless - regular “wireless” package is now retired and replaced by "wireless-fp" and "wireless-cm2";
    *) winbox - include FP in fast-path column names;
    *) ssh - fix session clean-up;
    *) ipsec - fix phase2 hmac-sha-256-128 truncation len from 96 to 128
    This will break compatibility with all previous versions and any other
    currently compatible software using sha256 hmac for phase2;
    *) fetch - added 30 second connection time-out;
    *) led - add wlan led to RB951Ui
    *) dhcpv6-client - fix next resend time rounding error;
    *) ssh, ftp - make read, write user group policy aware;
    *) tunnel - fix keep-alive (introduced in 6.34rc);
    *) cerm - show last crl update time;
    *) quicket - support CAP mode on all existing wireless packages;
    *) kernel - general improvement for core process scheduling;
    *) wlan - add united states3 country;
    *) fast-path - fix locking issue which could lead to reboot loop (introduced in 6.34rc20);
    *) userman4 - try loading signup files from db path first;
    *) sstp - allow to limit tls version to v1.2 only;
    *) chr - make tool profile work on 64bit x86;
    *) dhcpv6-server - added binding server=all option;
    *) btest - improve UDP tx rate precision;
    *) btest - fix potential crash after btest release;
    *) hotspot - added html-directory-override & recognize default hotspot user;
    *) hotspot - fixed export of default trial user;
    *) hotspot - fixed memory leak on https requests;
    *) winbox - added + & - to igmp proxy mfc;
    *) winbox - allow to specify amsdu-limit & amsdu-threshold on 11n wifi cards;
    *) winbox - allow to specify traffic-monitor threshold in k & M units + specify that those are bits;
    *) winbox - added multicast-buffering & keepalive-frames settings to wireless interfaces;
    *) CHR - implemented trial support for different CHR speed tiers;
    *) dhcpv6-client - fix add route/address;
    *) usb - enable ch341 serial module;
    *) lte - make sure that both LTE miniPCI-e cards are recognised;
    *) ppp - make PPP active print radius & !radius conditions work;
    *) winbox - show fast-path per interface counters;
    *) log - log link up/down events only when link actually has changed its state;
    *) romon - do not accept multicast id;
    *) romon - fixed crash on RoMON if fast-path was active;
    *) winbox - show Common-Name of certificates in certificate list;
    *) e-mail - do not reset server address after changing configuration;
    *) winbox - added units to PCQ queue fields;
    *) winbox - added LCD menu for RB3011;
    *) smb - show correct interface name in SMB debug logs;
    *) net - do not break connection when interface is added to bridge;
    *) dude - “The reports of my death have been greatly exaggerated”;
    *) dude - dude RouterOS package added for tile and x86 (CHR) architecture;
    *) dude - initial work on dude integration into RouterOS;
    *) webfig - didn't show zero values in CRS ingress/egress vlan translation rules;
    *) netwatch - make work with ping timeouts more precise;
    *) btest - fix crash on stop/start with fastpath enabled;
    *) hotspot - added missing favicon.ico in hotspot html pages;
    *) dhcpv6 - various changes on client, server, relay optimization;
    *) arp - show incomplete arp entries;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager web page crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6-client - added address acquisition support;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc27 2015-12-28

    What's new in 6.34rc27 (2015-Dec-23 14:49):

    *) sshd - resolved shared secret mismatch issue;
    *) net - do not show L2MTU in VLAN compact export;
    *) net - fixed net crash when firewall jump rule points to disabled custom chain;
    *) net - apply slave config only if master config has been changed;
    *) crypto - fixed kernel failure in talitos HW encryption;
    *) net - do not allow to add new firewall rule before built-in (reverted);
    *) wireless - regular “wireless” package is now retired and replaced by "wireless-fp" and "wireless-cm2";
    *) winbox - include FP in fast-path column names;
    *) ssh - fix session clean-up;
    *) ipsec - fix phase2 hmac-sha-256-128 truncation len from 96 to 128
    This will break compatibility with all previous versions and any other
    currently compatible software using sha256 hmac for phase2;
    *) fetch - added 30 second connection time-out;
    *) led - add wlan led to RB951Ui
    *) dhcpv6-client - fix next resend time rounding error;
    *) ssh, ftp - make read, write user group policy aware;
    *) tunnel - fix keep-alive (introduced in 6.34rc);
    *) cerm - show last crl update time;
    *) quicket - support CAP mode on all existing wireless packages;
    *) kernel - general improvement for core process scheduling;
    *) wlan - add united states3 country;
    *) fast-path - fix locking issue which could lead to reboot loop (introduced in 6.34rc20);
    *) userman4 - try loading signup files from db path first;
    *) sstp - allow to limit tls version to v1.2 only;
    *) chr - make tool profile work on 64bit x86;
    *) dhcpv6-server - added binding server=all option;
    *) btest - improve UDP tx rate precision;
    *) btest - fix potential crash after btest release;
    *) hotspot - added html-directory-override & recognize default hotspot user;
    *) hotspot - fixed export of default trial user;
    *) hotspot - fixed memory leak on https requests;
    *) winbox - added + & - to igmp proxy mfc;
    *) winbox - allow to specify amsdu-limit & amsdu-threshold on 11n wifi cards;
    *) winbox - allow to specify traffic-monitor threshold in k & M units + specify that those are bits;
    *) winbox - added multicast-buffering & keepalive-frames settings to wireless interfaces;
    *) CHR - implemented trial support for different CHR speed tiers;
    *) dhcpv6-client - fix add route/address;
    *) usb - enable ch341 serial module;
    *) lte - make sure that both LTE miniPCI-e cards are recognised;
    *) ppp - make PPP active print radius & !radius conditions work;
    *) winbox - show fast-path per interface counters;
    *) log - log link up/down events only when link actually has changed its state;
    *) romon - do not accept multicast id;
    *) romon - fixed crash on RoMON if fast-path was active;
    *) winbox - show Common-Name of certificates in certificate list;
    *) e-mail - do not reset server address after changing configuration;
    *) winbox - added units to PCQ queue fields;
    *) winbox - added LCD menu for RB3011;
    *) smb - show correct interface name in SMB debug logs;
    *) net - do not break connection when interface is added to bridge;
    *) dude - “The reports of my death have been greatly exaggerated”;
    *) dude - dude RouterOS package added for tile and x86 (CHR) architecture;
    *) dude - initial work on dude integration into RouterOS;
    *) webfig - didn't show zero values in CRS ingress/egress vlan translation rules;
    *) netwatch - make work with ping timeouts more precise;
    *) btest - fix crash on stop/start with fastpath enabled;
    *) hotspot - added missing favicon.ico in hotspot html pages;
    *) dhcpv6 - various changes on client, server, relay optimization;
    *) arp - show incomplete arp entries;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager web page crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6-client - added address acquisition support;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc23 2015-12-21

    What's new in 6.34rc23 (2015-Dec-21 10:49):

    *) crypto - fixed kernel failure in talitos HW encryption;
    *) net - do not allow to add new firewall rule before built-in (reverted);
    *) wireless - regular “wireless” package is now retired and replaced by "wireless-fp" and "wireless-cm2";
    *) winbox - include FP in fast-path column names;
    *) ssh - fix session clean-up;
    *) ipsec - fix phase2 hmac-sha-256-128 truncation len from 96 to 128
    This will break compatibility with all previous versions and any other
    currently compatible software using sha256 hmac for phase2;
    *) fetch - added 30 second connection time-out;
    *) led - add wlan led to RB951Ui
    *) dhcpv6-client - fix next resend time rounding error;
    *) ssh, ftp - make read, write user group policy aware;
    *) tunnel - fix keep-alive (introduced in 6.34rc);
    *) cerm - show last crl update time;
    *) quicket - support CAP mode on all existing wireless packages;
    *) kernel - general improvement for core process scheduling;
    *) wlan - add united states3 country;
    *) fast-path - fix locking issue which could lead to reboot loop (introduced in 6.34rc20);
    *) userman4 - try loading signup files from db path first;
    *) sstp - allow to limit tls version to v1.2 only;
    *) chr - make tool profile work on 64bit x86;
    *) dhcpv6-server - added binding server=all option;
    *) btest - improve UDP tx rate precision;
    *) btest - fix potential crash after btest release;
    *) hotspot - added html-directory-override & recognize default hotspot user;
    *) hotspot - fixed export of default trial user;
    *) hotspot - fixed memory leak on https requests;
    *) winbox - added + & - to igmp proxy mfc;
    *) winbox - allow to specify amsdu-limit & amsdu-threshold on 11n wifi cards;
    *) winbox - allow to specify traffic-monitor threshold in k & M units + specify that those are bits;
    *) winbox - added multicast-buffering & keepalive-frames settings to wireless interfaces;
    *) CHR - implemented trial support for different CHR speed tiers;
    *) dhcpv6-client - fix add route/address;
    *) usb - enable ch341 serial module;
    *) lte - make sure that both LTE miniPCI-e cards are recognised;
    *) ppp - make PPP active print radius & !radius conditions work;
    *) winbox - show fast-path per interface counters;
    *) log - log link up/down events only when link actually has changed its state;
    *) romon - do not accept multicast id;
    *) romon - fixed crash on RoMON if fast-path was active;
    *) winbox - show Common-Name of certificates in certificate list;
    *) e-mail - do not reset server address after changing configuration;
    *) winbox - added units to PCQ queue fields;
    *) winbox - added LCD menu for RB3011;
    *) smb - show correct interface name in SMB debug logs;
    *) net - do not break connection when interface is added to bridge;
    *) dude - “The reports of my death have been greatly exaggerated”;
    *) dude - dude RouterOS package added for tile and x86 (CHR) architecture;
    *) dude - initial work on dude integration into RouterOS;
    *) webfig - didn't show zero values in CRS ingress/egress vlan translation rules;
    *) netwatch - make work with ping timeouts more precise;
    *) btest - fix crash on stop/start with fastpath enabled;
    *) hotspot - added missing favicon.ico in hotspot html pages;
    *) dhcpv6 - various changes on client, server, relay optimization;
    *) arp - show incomplete arp entries;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager web page crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6-client - added address acquisition support;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc22 2015-12-18

    What's new in 6.34rc22 (2015-Dec-17 12:10):

    *) ssh - fix session clean-up;
    *) ipsec - fix phase2 hmac-sha-256-128 truncation len from 96 to 128
    This will break compatibility with all previous versions and any other
    currently compatible software using sha256 hmac for phase2;
    *) fetch - added 30 second connection time-out;
    *) led - add wlan led to RB951Ui
    *) dhcpv6-client - fix next resend time rounding error;
    *) ssh, ftp - make read, write user group policy aware;
    *) tunnel - fix keep-alive (introduced in 6.34rc);
    *) net - do not allow to add new firewall rule before built-in;
    *) cerm - show last crl update time;
    *) quicket - support CAP mode on all existing wireless packages;
    *) kernel - general improvement for core process scheduling;
    *) wlan - add united states3 country;
    *) fast-path - fix locking issue which could lead to reboot loop (introduced in 6.34rc20);
    *) userman4 - try loading signup files from db path first;
    *) sstp - allow to limit tls version to v1.2 only;
    *) chr - make tool profile work on 64bit x86;
    *) dhcpv6-server - added binding server=all option;
    *) btest - improve UDP tx rate precision;
    *) btest - fix potential crash after btest release;
    *) hotspot - added html-directory-override & recognize default hotspot user;
    *) hotspot - fixed export of default trial user;
    *) hotspot - fixed memory leak on https requests;
    *) winbox - added + & - to igmp proxy mfc;
    *) winbox - allow to specify amsdu-limit & amsdu-threshold on 11n wifi cards;
    *) winbox - allow to specify traffic-monitor threshold in k & M units + specify that those are bits;
    *) winbox - added multicast-buffering & keepalive-frames settings to wireless interfaces;
    *) CHR - implemented trial support for different CHR speed tiers;
    *) dhcpv6-client - fix add route/address;
    *) usb - enable ch341 serial module;
    *) lte - make sure that both LTE miniPCI-e cards are recognised;
    *) ppp - make PPP active print radius & !radius conditions work;
    *) winbox - show fast-path per interface counters;
    *) log - log link up/down events only when link actually has changed its state;
    *) romon - do not accept multicast id;
    *) romon - fixed crash on RoMON if fast-path was active;
    *) winbox - show Common-Name of certificates in certificate list;
    *) e-mail - do not reset server address after changing configuration;
    *) winbox - added units to PCQ queue fields;
    *) winbox - added LCD menu for RB3011;
    *) smb - show correct interface name in SMB debug logs;
    *) net - do not break connection when interface is added to bridge;
    *) dude - “The reports of my death have been greatly exaggerated”;
    *) dude - dude RouterOS package added for tile and x86 (CHR) architecture;
    *) dude - initial work on dude integration into RouterOS;
    *) webfig - didn't show zero values in CRS ingress/egress vlan translation rules;
    *) netwatch - make work with ping timeouts more precise;
    *) btest - fix crash on stop/start with fastpath enabled;
    *) hotspot - added missing favicon.ico in hotspot html pages;
    *) dhcpv6 - various changes on client, server, relay optimization;
    *) arp - show incomplete arp entries;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager web page crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6-client - added address acquisition support;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc21 2015-12-14

    What's new in 6.34rc21 (2015-Dec-14 08:53):

    *) quicket - support CAP mode on all existing wireless packages;
    *) kernel - general improvement for core process scheduling;
    *) wlan - add united states3 country;
    *) fast-path - fix locking issue which could lead to reboot loop (introduced in 6.34rc20);
    *) userman4 - try loading signup files from db path first;
    *) sstp - allow to limit tls version to v1.2 only;
    *) chr - make tool profile work on 64bit x86;
    *) dhcpv6-server - added binding server=all option;
    *) btest - improve UDP tx rate precision;
    *) btest - fix potential crash after btest release;
    *) hotspot - added html-directory-override & recognize default hotspot user;
    *) hotspot - fixed export of default trial user;
    *) hotspot - fixed memory leak on https requests;
    *) winbox - added + & - to igmp proxy mfc;
    *) winbox - allow to specify amsdu-limit & amsdu-threshold on 11n wifi cards;
    *) winbox - allow to specify traffic-monitor threshold in k & M units + specify that those are bits;
    *) winbox - added multicast-buffering & keepalive-frames settings to wireless interfaces;
    *) CHR - implemented trial support for different CHR speed tiers;
    *) dhcpv6-client - fix add route/address;
    *) usb - enable ch341 serial module;
    *) lte - make sure that both LTE miniPCI-e cards are recognised;
    *) ppp - make PPP active print radius & !radius conditions work;
    *) winbox - show fast-path per interface counters;
    *) log - log link up/down events only when link actually has changed its state;
    *) romon - do not accept multicast id;
    *) romon - fixed crash on RoMON if fast-path was active;
    *) winbox - show Common-Name of certificates in certificate list;
    *) e-mail - do not reset server address after changing configuration;
    *) winbox - added units to PCQ queue fields;
    *) winbox - added LCD menu for RB3011;
    *) smb - show correct interface name in SMB debug logs;
    *) net - do not break connection when interface is added to bridge;
    *) dude - “The reports of my death have been greatly exaggerated”;
    *) dude - dude RouterOS package added for tile and x86 (CHR) architecture;
    *) dude - initial work on dude integration into RouterOS;
    *) webfig - didn't show zero values in CRS ingress/egress vlan translation rules;
    *) netwatch - make work with ping timeouts more precise;
    *) btest - fix crash on stop/start with fastpath enabled;
    *) hotspot - added missing favicon.ico in hotspot html pages;
    *) dhcpv6 - various changes on client, server, relay optimization;
    *) arp - show incomplete arp entries;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager web page crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6-client - added address acquisition support;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc19 2015-12-09

    What's new in 6.34rc19 (2015-Dec-08 17:39):

    *) CHR - implemented trial support for different CHR speed tiers;
    *) dhcpv6-client - fix add route/address;
    *) usb - enable ch341 serial module;
    *) lte - make sure that both LTE miniPCI-e cards are recognised;
    *) ppp - make PPP active print radius & !radius conditions work;
    *) winbox - show fast-path per interface counters;
    *) log - log link up/down events only when link actually has changed its state;
    *) romon - do not accept multicast id;
    *) romon - fixed crash on RoMON if fast-path was active;
    *) winbox - show Common-Name of certificates in certificate list;
    *) e-mail - do not reset server address after changing configuration;
    *) winbox - added units to PCQ queue fields;
    *) winbox - added LCD menu for RB3011;
    *) smb - show correct interface name in SMB debug logs;
    *) net - do not break connection when interface is added to bridge;
    *) dude - “The reports of my death have been greatly exaggerated”;
    *) dude - dude RouterOS package added for tile and x86 (CHR) architecture;
    *) dude - initial work on dude integration into RouterOS;
    *) webfig - didn't show zero values in CRS ingress/egress vlan translation rules;
    *) netwatch - make work with ping timeouts more precise;
    *) btest - fix crash on stop/start with fastpath enabled;
    *) hotspot - added missing favicon.ico in hotspot html pages;
    *) dhcpv6 - various changes on client, server, relay optimization;
    *) arp - show incomplete arp entries;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager web page crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6-client - added address acquisition support;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc18 2015-12-08

    What's new in 6.34rc18 (2015-Dec-08 10:02):

    *) usb - enable ch341 serial module;
    *) lte - make sure that both LTE miniPCI-e cards are recognised;
    *) ppp - make PPP active print radius & !radius conditions work;
    *) winbox - show fast-path per interface counters;
    *) log - log link up/down events only when link actually has changed its state;
    *) romon - do not accept multicast id;
    *) romon - fixed crash on RoMON if fast-path was active;
    *) winbox - show Common-Name of certificates in certificate list;
    *) e-mail - do not reset server address after changing configuration;
    *) winbox - added units to PCQ queue fields;
    *) winbox - added LCD menu for RB3011;
    *) smb - show correct interface name in SMB debug logs;
    *) net - do not break connection when interface is added to bridge;
    *) dude - “The reports of my death have been greatly exaggerated”;
    *) dude - dude RouterOS package added for tile and x86 (CHR) architecture;
    *) dude - initial work on dude integration into RouterOS;
    *) webfig - didn't show zero values in CRS ingress/egress vlan translation rules;
    *) netwatch - make work with ping timeouts more precise;
    *) btest - fix crash on stop/start with fastpath enabled;
    *) hotspot - added missing favicon.ico in hotspot html pages;
    *) dhcpv6 - various changes on client, server, relay optimization;
    *) arp - show incomplete arp entries;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager web page crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6-client - added address acquisition support;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc16 2015-12-04

    What's new in 6.34rc16 (2015-Dec-04 14:10):

    *) dude - “The reports of my death have been greatly exaggerated”;
    *) dude - dude RouterOS package added for tile and x86 (CHR) architecture;
    *) dude - initial work on dude integration into RouterOS;
    *) webfig - didn't show zero values in CRS ingress/egress vlan translation rules;
    *) netwatch - make work with ping timeouts more precise;
    *) btest - fix crash on stop/start with fastpath enabled;
    *) hotspot - added missing favicon.ico in hotspot html pages;
    *) dhcpv6 - various changes on client, server, relay optimization;
    *) arp - show incomplete arp entries;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager web page crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6-client - added address acquisition support;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc15 2015-12-04

    What's new in 6.34rc15 (2015-Dec-03 16:33):

    *) hotspot - added missing favicon.ico in hotspot html pages;
    *) dhcpv6 - varius changes on client, server, relay optimization;
    *) arp - show incoplete arp entries;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager webpage crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6-client - added address acquisition support;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc14 2015-12-03

    What's new in 6.34rc14 (2015-Dec-03 13:53):

    *) dhcpv6 - varius changes on client, server, relay optimization.
    *) ethernet - fixed 10/100Mbps autonegotiation fails on RB922UAGS ether1;
    *) arp - show incoplete arp entries;
    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) email - make password field sensitive in console;
    *) upnp - fixed memory leak;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) ssh - avoid double session cleanup;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager webpage crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6-client - added address acquisition support;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc12 2015-12-01

    What's new in 6.34rc12 (2015-Dec-01 10:34):

    *) hotspot - show cookie add/remove events in hotspot,debug log;
    *) hotspot - allow static entries with the same mac on multiple hotspot servers;
    *) hotspot - do not remove mac-cookie in case of radius timeout;
    *) hotspot - added byte limits option for default-trial users;
    *) email - make password field sensitive in console;
    *) dhcpv6-client - add 0x in front of DUID;
    *) dhcpv6-server - fix state on rapid commit;
    *) dhcpv6-server - fix preference option in packet generation;
    *) upnp - fixed memory leak;
    *) ipsec - make sure that dynamic policy always has dynamic flag;
    *) ssh - avoid double session cleanup;
    *) CAPsMAN - use CAP name in log when remote-cap is deleted (wireless-cm2);
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) firewall - SIP helper update for newer Cisco phones;
    *) usermanager - fixed usermanager webpage crash;
    *) ipsec - fixed active SAs flushing;
    *) hotspot - added option to login user manually from cli;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) dhcpv6 client - support DAD and decline;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) dhcpv6-client - added DHCPv6-client functionality for current DHCP-PD client;
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc11 2015-11-27

    What's new in 6.34rc11 (2015-Nov-26 14:50):

    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) hotspot - add html-directory-override for read-only directory on usb flash;
    *) hotspot - add uptime, byte and packet counter variables to logout script;
    *) net - fix statistics counters jumping up to 4G;
    *) vrrp - fix arp=reply-only;
    *) vrrp - do not warn about version mismatch if VRID does not match;
    *) vrrp - allow VRRP to work behind firewall and NAT rules;
    *) firewall - SIP helper update for newer Cisco phones;
    *) ppp - fixed dynamic filter rule adding on some firewall filter configurations;
    *) vrrp - fixed on-backup script;
    *) ethernet - fixed link resetting on power-cycle-ping value change;
    *) pppoe - improved MTU discovery compatibility with other vendors;
    *) usermanager - fixed usermanager webpage crash;
    *) ipsec - fixed active SAs flushing;
    *) bridge - fixed power-cycle-ping for bridge ports (was affecting all bridge);
    *) pppoe - made MTU discovery more robust;
    *) hotspot - added option to login user manually from cli;
    *) pppoe - fixed compliance to RFC4638 (MTU larger than 1488) again;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webfig;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) dhcpv6 client - support DAD and decline;
    *) dhcpv4 server - fix kernel crash when restoring lease with queue for non-existent server;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) ssh - fix key exchange when first kex packet follows;
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) dhcpv6-client - added DHCPv6-client functionality for current DHCP-PD client;
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv4-client - support /32 address assignment;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc9 2015-11-26

    What's new in 6.34rc9 (2015-Nov-25 09:53):

    *) ppp - fixed dynamic filter rule adding on some firewall filter configurations;
    *) vrrp - fixed on-backup script;
    *) ethernet - fixed link resetting on power-cycle-ping value change;
    *) pppoe - improved MTU discovery compatibility with other vendors;
    *) hotspot - fixed login by mac-cookie when roaming among hotspot servers;
    *) usermanager - fixed usermanager webpage crash;
    *) ipsec - fixed active SAs flushing;
    *) bridge - fixed power-cycle-ping for bridge ports (was affecting all bridge);
    *) pppoe - made MTU discovery more robust;
    *) hotspot - added option to login user manually from cli;
    *) pppoe - fixed compliance to RFC4638 (MTU larger than 1488) again;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webbox;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) dhcpv6 client - support DAD and decline;
    *) dhcpv4 server - fix kernel crash when restoring lease with queue for non-existent server;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) ssh - fix key exchange when first kex packet follows;
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) dhcpv6-client - added DHCPv6-client functionality for current DHCP-PD client;
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv4-client - support /32 address assignment;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc8 2015-11-24

    What's new in 6.34rc8 (2015-Nov-23 16:28):

    *) usermanager - fixed usermanager webpage crash;
    *) ipsec - fixed active SAs flushing;
    *) bridge - fixed power-cycle-ping for bridge ports (was affecting all bridge);
    *) ethernet - fixed link resetting on power-cycle-ping value change;
    *) pppoe - made MTU discovery more robust;
    *) hotspot - added option to login user manually from cli;
    *) pppoe - fixed compliance to RFC4638 (MTU larger than 1488) again;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webbox;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) dhcpv6 client - support DAD and decline;
    *) dhcpv4 server - fix kernel crash when restoring lease with queue for non-existent server;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) ssh - fix key exchange when first kex packet follows;
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) dhcpv6-client - added DHCPv6-client functionality for current DHCP-PD client;
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv4-client - support /32 address assignment;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc6 2015-11-19

    What's new in 6.34rc6 (2015-Nov-19 14:11):

    *) pppoe - fixed compliance to RFC4638 (MTU larger than 1488) again;
    *) hotspot - fixed trial-uptime parsing from CLI to Winbox/Webbox;
    *) lte - added support for multiple E3372 on the same device;
    *) modem - added wpd-600n ppp support;
    *) dhcpv6 client - support DAD and decline;
    *) dhcpv4 server - fix kernel crash when restoring lease with queue for non-existent server;
    *) console - fixed incorrect disabled firewall rule matching to "invalid flag";
    *) ssh - fix key exchange when first kex packet follows;
    *) dns - fix for situation when dynamic dns servers could disappear;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) dhcpv6-client - added DHCPv6-client functionality for current DHCP-PD client;
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv4-client - support /32 address assignment;
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc5 2015-11-17

    What's new in 6.34rc5 (2015-Nov-13 11:18):

    *) dns - fix for situation when dynamic dns servers could disappear;
    *) packages - show version tag when no bundle is installed;
    *) vrrp - fix enabling disabled vrrp interface when vrrp program has exited;
    *) winbox - do not send any changes on OK button press if nothing has been changed;
    *) sfp - fix 10g ports in 1g mode (introduced in 6.34rc1);
    *) dhcpv6-client - added DHCPv6-client functionality for current DHCP-PD client;
    *) smb - fixed SMB share crash when connection was cancelled;
    *) lcd - fixed LCD crash on fast disable/enable;
    *) fastpath - fixed wireless interface fastpath (broken in 6.33);
    *) pppoe - fixed compliance to RFC4638 (MTU larger than 1488);
    *) webfig - show correctly SFP Tx/Rx;
    *) winbox - renamed power-cycle-ping-interval to power-cycle-ping-timeout;
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv4-client - support /32 address assignment;
    *) licensing - fix unneeded connection attempts to 169.254.x.x (must be CHR only);
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc3 2015-11-11

    What's new in 6.34rc3 (2015-Nov-11 13:44):

    *) smb - fixed SMB share crash when connection was cancelled;
    *) lcd - fixed LCD crash on fast disable/enable;
    *) fastpath - fixed wireless interface fastpath (broken in 6.33);
    *) pppoe - fixed compliance to RFC4638 (MTU larger than 1488);
    *) webfig - show correctly SFP Tx/Rx;
    *) winbox - renamed power-cycle-ping-interval to power-cycle-ping-timeout;
    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv4-client - support /32 address assignment;
    *) licensing - fix unneeded connection attempts to 169.254.x.x (must be CHR only);
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6-client - added address acquisition support;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc2 2015-11-11

    What's new in 6.34rc2 (2015-Nov-11 10:14):

    *) CCR1072 - added support for S-RJ01 SFP modules;
    *) trafficgen - fixed issue that traffic-generator could not be started twice without reboot;
    *) dhcpv4-client - support /32 address assignment;
    *) licensing - fix unneeded connection attempts to 169.254.x.x (must be CHR only);
    *) dhcpv6-server - replace delay option with preference option;
    *) dhcpv6-client - added address acquisition support;
    *) dhcpv6 - implement and enable rapid commit by default.

  • Release 6.34rc1 2015-11-06

    What's new in 6.34rc1 (2015-Nov-06 15:50):

    *) new product support added

  • Release 6.33rc37 2015-11-02

    What's new in 6.33rc37 (2015-Oct-30 13:04):

    *) net - fix possible never ending loop when bad CDP discovery packet is received;
    *) log - make default disk file name to reside in flash dir if it exists;
    *) romon - change port list to be unordered in export;
    *) capsman - limit number of simultaneous DTLS handshakes;
    *) capsman - fixed memory leak on CAP joining CAPsMAN when ssld is used;
    *) DHCP-PD client - timer problem fixed;
    *) winbox - added allow-fast-path to eoip, gre & ipip;
    *) winbox - do not show power-cycle properties on non poe ports;
    *) l2tp: implemented PPPoE over L2TP in LNS mode, RFC3817;
    *) webfig - some of the setting were shifted to the right;
    *) packages - allow to reinstall from bundle to separate packages & vice versa;
    *) packages - prefer out of bundle packages when both of them are installed;
    *) packages - fix a problem of upgrading bundle package to non bundled ones;
    *) ipsec - force flow cache validation once in 1h;
    *) dhcpv6-client - show current server address;
    *) dhcpv6-client - split out IA ops;
    *) winbox - make sure that all setting names get shown in full;
    *) winbox - added poe power-cycle-ping settings to ethernet interfaces;
    *) ppp - handle properly case were ppp client is given same address for local & remote end;
    *) winbox - added vlan-mode & vlan-id to virtual-ap interface;
    *) winbox - added timeout column to ipv6 address lists;
    *) winbox - show SFP Tx/Rx Power properly;
    *) winbox - added min-links to bonding interface;
    *) winbox - do not show health menu on RB951Ui-2HnD;
    *) winbox - added support for Login-Timeout & MAC-Auth-Mode in hotspot;
    *) cerm - added option to disable crl download in '/certificate settings';
    *) winbox - make user ssh key import work again;
    *) webfig - make "Copy to Access List" work in CAPsMAN Registration Table;
    *) userman - fix report generation problem which could result in some users being skipped from it;
    *) winbox - fix to allow cpu-port as mirror-target
    *) proxy - error.html parsing enhancement to improve performance
    *) CCR1072 - improve ether1 performance under heavy load
    *) routerboard - indicate RouterBOOT type in /system routerboard print;
    *) mpls - properly use mpls mtu for routes;
    *) cerm - fix key decription for signed certificates;
    *) trafflow - report flow addresses in v1 and v5 without NAT awerness;
    *) dhcpv6 - small fixes for dhcp-pd client and ippool6;
    *) hotspot - add mac-auth-mode setting for mac-as-passwd option;
    *) hotspot - add login-timeout setting to force login for unauth hosts;
    *) auto-upgrade - fixed auto upgrade for smipsbe;
    *) dns - do not create duplicate entries for same dynamic dns server addresses;
    *) ipsec - fix set on multiple policies which could result in adding non existent dynamic policies to the list;
    *) email - allow server to be specified as fqdn which is resolved on each send;
    *) fastpath - eoip,gre,ipip tunnels support fastpath (new per tunnel setting "allow-fast-path");
    *) ppp, pptp, l2tp, pppoe - fix ppp compression related crashes;
    *) cerm - also accept downloaded CRLs in PEM format;
    *) userman - added 'history clear' to allow flushing undo history, which may take up significant amount of memory for huge databases whith hundreds of users;
    *) health - fix voltage for CRS109, CRS112 and CRS210 if powered from external adapter;
    *) userman - added phone number support to signup form;
    *) ip pool6 - try to acquire the same prefix if info matches recently freed;
    *) ipsec - fix transport mode ph2 ID ports when policy selects specific ip protocol on initiator;
    *) ipsec - use local-address for phase 1 matching and initiation;
    *) route - fixed crash on removing route that was aggregated;
    *) ipsec - fix replay window, was accidently disabled since version 6.30;
    *) ssh - allow host key import/export;
    *) ssh - use 2048bit RSA host key when strong-crypto enabled;
    *) ssh - support RSA keys for user authentication;
    *) wlan - improved WMM-PowerSave support in wireless-cm2 package;
    *) pptp & l2tp - fixed problem where android client could not connect if both dns names were not provided (was broken since v6.30);
    *) auto upgrade - added ability to select which versions to select when upgrading;
    *) quickset - fixed HomeAP mode;
    *) lte - improved modem identification to better support multiple identical modems;
    *) snmp - fix system scripts table;
    *) tunnels - eoip,eoipv6,gre,gre6,ipip,ipipv6,6to4 tunnels now support dns name as remote address;
    *) fastpath - active mac-winbox or mac-telnet session no longer suspends fastpath;
    *) fastpath - added per interface fastpath counters;
    *) fastpath - added trafflow support in basic ipv4 and fasttrack ipv4 fastpaths;
    *) ppp - added on-up & on-down scripts to ppp profile;
    *) winbox - allow to specify dns name in all the tunnels;
    *) pppoe - added support for MTU > 1492 on PPPoE;
    *) cerm - fix scep server certificate-reply degenerate PKCS#7 signed-data content;
    *) ppp-client - added default channels for Alcatel OneTouch L100V;
    *) defconf - fix for boards that had bridge with only wlan ports;
    *) ovpn: support OpenWRT ovpn clients (or any other with enable-small option enabled);
    *) cerm - use certificate file name for imported cert name;
    *) fetch - fixed error message when error code 200 was received;
    *) cerm - rebuild crl for local ca if crl file does not exist;
    *) winbox - make directed broadcasts work for neighbor discovery;
    *) upnp: automatically adjust mappings to new external ip change;
    *) ppp - added ppp interface to upnp internals/externals if requested;
    *) ppp - when adding ipv6 default route use user provided distance;
    *) userman - allow to correctly enable CoA on router;
    *) cerm - also accept downloaded CRLs in PEM format;
    *) cerm - show crl nextupdate time;
    *) ppp - added CoA support to PPPoE, PPTP & L2TP (Mikrotik-Recv-Limit, Mikrotik-Xmit-Limit, Mikrotik-Rate-Limit, Ascend-Data-Rate, Ascend-XMit-Rate, Session-Timeout);
    *) ppp - added new option under "ppp aaa" - "use-circuit-id-in-nas-port-id";
    *) userman - refresh active sessions/users view dynamically;
    *) package - added version tag and show everywhere alongside of version number;
    *) wlan - improved 802.11 protocol single connection TCP performance for ac chipset with cm2 package.

  • Release 6.33rc36 2015-10-28

    What's new in 6.33rc36 (2015-Oct-28 13:16):

    *) l2tp: implemented PPPoE over L2TP in LNS mode, RFC3817;
    *) webfig - some of the setting were shifted to the right;
    *) packages - allow to reinstall from bundle to separate packages & vice versa;
    *) packages - prefer out of bundle packages when both of them are installed;
    *) packages - fix a problem of upgrading bundle package to non bundled ones;
    *) ipsec - force flow cache validation once in 1h;
    *) dhcpv6-client - show current server address;
    *) dhcpv6-client - split out IA ops;
    *) winbox - make sure that all setting names get shown in full;
    *) winbox - added poe power-cycle-ping settings to ethernet interfaces;
    *) ppp - handle properly case were ppp client is given same address for local & remote end;
    *) winbox - added vlan-mode & vlan-id to virtual-ap interface;
    *) winbox - added timeout column to ipv6 address lists;
    *) winbox - show SFP Tx/Rx Power properly;
    *) winbox - added min-links to bonding interface;
    *) winbox - do not show health menu on RB951Ui-2HnD;
    *) winbox - added support for Login-Timeout & MAC-Auth-Mode in hotspot;
    *) cerm - added option to disable crl download in '/certificate settings';
    *) winbox - make user ssh key import work again;
    *) webfig - make "Copy to Access List" work in CAPsMAN Registration Table;
    *) userman - fix report generation problem which could result in some users being skipped from it;
    *) winbox - fix to allow cpu-port as mirror-target
    *) proxy - error.html parsing enhancement to improve performance
    *) CCR1072 - improve ether1 performance under heavy load
    *) routerboard - indicate RouterBOOT type in /system routerboard print;
    *) mpls - properly use mpls mtu for routes;
    *) cerm - fix key decription for signed certificates;
    *) trafflow - report flow addresses in v1 and v5 without NAT awerness;
    *) dhcpv6 - small fixes for dhcp-pd client and ippool6;
    *) hotspot - add mac-auth-mode setting for mac-as-passwd option;
    *) hotspot - add login-timeout setting to force login for unauth hosts;
    *) auto-upgrade - fixed auto upgrade for smipsbe;
    *) dns - do not create duplicate entries for same dynamic dns server addresses;
    *) ipsec - fix set on multiple policies which could result in adding non existent dynamic policies to the list;
    *) email - allow server to be specified as fqdn which is resolved on each send;
    *) fastpath - eoip,gre,ipip tunnels support fastpath (new per tunnel setting "allow-fast-path");
    *) ppp, pptp, l2tp, pppoe - fix ppp compression related crashes;
    *) cerm - also accept downloaded CRLs in PEM format;
    *) userman - added 'history clear' to allow flushing undo history, which may take up significant amount of memory for huge databases whith hundreds of users;
    *) health - fix voltage for CRS109, CRS112 and CRS210 if powered from external adapter;
    *) userman - added phone number support to signup form;
    *) ip pool6 - try to acquire the same prefix if info matches recently freed;
    *) ipsec - fix transport mode ph2 ID ports when policy selects specific ip protocol on initiator;
    *) ipsec - use local-address for phase 1 matching and initiation;
    *) route - fixed crash on removing route that was aggregated;
    *) ipsec - fix replay window, was accidently disabled since version 6.30;
    *) ssh - allow host key import/export;
    *) ssh - use 2048bit RSA host key when strong-crypto enabled;
    *) ssh - support RSA keys for user authentication;
    *) wlan - improved WMM-PowerSave support in wireless-cm2 package;
    *) pptp & l2tp - fixed problem where android client could not connect if both dns names were not provided (was broken since v6.30);
    *) auto upgrade - added ability to select which versions to select when upgrading;
    *) quickset - fixed HomeAP mode;
    *) lte - improved modem identification to better support multiple identical modems;
    *) snmp - fix system scripts table;
    *) tunnels - eoip,eoipv6,gre,gre6,ipip,ipipv6,6to4 tunnels now support dns name as remote address;
    *) fastpath - active mac-winbox or mac-telnet session no longer suspends fastpath;
    *) fastpath - added per interface fastpath counters;
    *) fastpath - added trafflow support in basic ipv4 and fasttrack ipv4 fastpaths;
    *) ppp - added on-up & on-down scripts to ppp profile;
    *) winbox - allow to specify dns name in all the tunnels;
    *) pppoe - added support for MTU > 1492 on PPPoE;
    *) cerm - fix scep server certificate-reply degenerate PKCS#7 signed-data content;
    *) ppp-client - added default channels for Alcatel OneTouch L100V;
    *) defconf - fix for boards that had bridge with only wlan ports;
    *) ovpn: support OpenWRT ovpn clients (or any other with enable-small option enabled);
    *) cerm - use certificate file name for imported cert name;
    *) fetch - fixed error message when error code 200 was received;
    *) cerm - rebuild crl for local ca if crl file does not exist;
    *) winbox - make directed broadcasts work for neighbor discovery;
    *) upnp: automatically adjust mappings to new external ip change;
    *) ppp - added ppp interface to upnp internals/externals if requested;
    *) ppp - when adding ipv6 default route use user provided distance;
    *) userman - allow to correctly enable CoA on router;
    *) cerm - also accept downloaded CRLs in PEM format;
    *) cerm - show crl nextupdate time;
    *) ppp - added CoA support to PPPoE, PPTP & L2TP (Mikrotik-Recv-Limit, Mikrotik-Xmit-Limit, Mikrotik-Rate-Limit, Ascend-Data-Rate, Ascend-XMit-Rate, Session-Timeout);
    *) ppp - added new option under "ppp aaa" - "use-circuit-id-in-nas-port-id";
    *) userman - refresh active sessions/users view dynamically;
    *) package - added version tag and show everywhere alongside of version number;
    *) wlan - improved 802.11 protocol single connection TCP performance for ac chipset with cm2 package.

  • Release 6.33rc35 2015-10-28

    What's new in 6.33rc35 (2015-Oct-27 16:41):

    *) webfig - some of the setting were shifted to the right;
    *) packages - allow to reinstall from bundle to separate packages & vice versa;
    *) packages - prefer out of bundle packages when both of them are installed;
    *) packages - fix a problem of upgrading bundle package to non bundled ones;
    *) ipsec - force flow cache validation once in 1h;
    *) dhcpv6-client - show current server address;
    *) dhcpv6-client - split out IA ops;
    *) winbox - make sure that all setting names get shown in full;
    *) winbox - added poe power-cycle-ping settings to ethernet interfaces;
    *) ppp - handle properly case were ppp client is given same address for local & remote end;
    *) winbox - added vlan-mode & vlan-id to virtual-ap interface;
    *) winbox - added timeout column to ipv6 address lists;
    *) winbox - show SFP Tx/Rx Power properly;
    *) winbox - added min-links to bonding interface;
    *) winbox - do not show health menu on RB951Ui-2HnD;
    *) winbox - added support for Login-Timeout & MAC-Auth-Mode in hotspot;
    *) cerm - added option to disable crl download in '/certificate settings';
    *) winbox - make user ssh key import work again;
    *) webfig - make "Copy to Access List" work in CAPsMAN Registration Table;
    *) userman - fix report generation problem which could result in some users being skipped from it;
    *) winbox - fix to allow cpu-port as mirror-target
    *) proxy - error.html parsing enhancement to improve performance
    *) CCR1072 - improve ether1 performance under heavy load
    *) routerboard - indicate RouterBOOT type in /system routerboard print;
    *) mpls - properly use mpls mtu for routes;
    *) cerm - fix key decription for signed certificates;
    *) trafflow - report flow addresses in v1 and v5 without NAT awerness;
    *) dhcpv6 - small fixes for dhcp-pd client and ippool6;
    *) hotspot - add mac-auth-mode setting for mac-as-passwd option;
    *) hotspot - add login-timeout setting to force login for unauth hosts;
    *) auto-upgrade - fixed auto upgrade for smipsbe;
    *) dns - do not create duplicate entries for same dynamic dns server addresses;
    *) ipsec - fix set on multiple policies which could result in adding non existent dynamic policies to the list;
    *) email - allow server to be specified as fqdn which is resolved on each send;
    *) fastpath - eoip,gre,ipip tunnels support fastpath (new per tunnel setting "allow-fast-path");
    *) ppp, pptp, l2tp, pppoe - fix ppp compression related crashes;
    *) cerm - also accept downloaded CRLs in PEM format;
    *) userman - added 'history clear' to allow flushing undo history, which may take up significant amount of memory for huge databases whith hundreds of users;
    *) health - fix voltage for CRS109, CRS112 and CRS210 if powered from external adapter;
    *) userman - added phone number support to signup form;
    *) ip pool6 - try to acquire the same prefix if info matches recently freed;
    *) ipsec - fix transport mode ph2 ID ports when policy selects specific ip protocol on initiator;
    *) ipsec - use local-address for phase 1 matching and initiation;
    *) route - fixed crash on removing route that was aggregated;
    *) ipsec - fix replay window, was accidently disabled since version 6.30;
    *) ssh - allow host key import/export;
    *) ssh - use 2048bit RSA host key when strong-crypto enabled;
    *) ssh - support RSA keys for user authentication;
    *) wlan - improved WMM-PowerSave support in wireless-cm2 package;
    *) pptp & l2tp - fixed problem where android client could not connect if both dns names were not provided (was broken since v6.30);
    *) auto upgrade - added ability to select which versions to select when upgrading;
    *) quickset - fixed HomeAP mode;
    *) lte - improved modem identification to better support multiple identical modems;
    *) snmp - fix system scripts table;
    *) tunnels - eoip,eoipv6,gre,gre6,ipip,ipipv6,6to4 tunnels now support dns name as remote address;
    *) fastpath - active mac-winbox or mac-telnet session no longer suspends fastpath;
    *) fastpath - added per interface fastpath counters;
    *) fastpath - added trafflow support in basic ipv4 and fasttrack ipv4 fastpaths;
    *) ppp - added on-up & on-down scripts to ppp profile;
    *) winbox - allow to specify dns name in all the tunnels;
    *) pppoe - added support for MTU > 1492 on PPPoE;
    *) cerm - fix scep server certificate-reply degenerate PKCS#7 signed-data content;
    *) ppp-client - added default channels for Alcatel OneTouch L100V;
    *) defconf - fix for boards that had bridge with only wlan ports;
    *) ovpn: support OpenWRT ovpn clients (or any other with enable-small option enabled);
    *) cerm - use certificate file name for imported cert name;
    *) fetch - fixed error message when error code 200 was received;
    *) cerm - rebuild crl for local ca if crl file does not exist;
    *) winbox - make directed broadcasts work for neighbor discovery;
    *) upnp: automatically adjust mappings to new external ip change;
    *) ppp - added ppp interface to upnp internals/externals if requested;
    *) ppp - when adding ipv6 default route use user provided distance;
    *) userman - allow to correctly enable CoA on router;
    *) cerm - also accept downloaded CRLs in PEM format;
    *) cerm - show crl nextupdate time;
    *) ppp - added CoA support to PPPoE, PPTP & L2TP (Mikrotik-Recv-Limit, Mikrotik-Xmit-Limit, Mikrotik-Rate-Limit, Ascend-Data-Rate, Ascend-XMit-Rate, Session-Timeout);
    *) ppp - added new option under "ppp aaa" - "use-circuit-id-in-nas-port-id";
    *) userman - refresh active sessions/users view dynamically;
    *) package - added version tag and show everywhere alongside of version number;
    *) wlan - improved 802.11 protocol single connection TCP performance for ac chipset with cm2 package.

  • Release 6.33rc33 2015-10-26

    What's new in 6.33rc33 (2015-Oct-26 11:50):

    *) userman - fix report generation problem which could result in some users being skipped from it;
    *) winbox - fix to allow cpu-port as mirror-target
    *) proxy - error.html parsing enhancement to improve performance
    *) CCR1072 - improve ether1 performance under heavy load
    *) routerboard - indicate RouterBOOT type in /system routerboard print
    *) mpls - properly use mpls mtu for routes
    *) cerm - fix key decription for signed certificates
    *) trafflow - report flow addresses in v1 and v5 without NAT awerness
    *) dhcpv6 - small fixes for dhcp-pd client and ippool6
    *) hotspot - add mac-auth-mode setting for mac-as-passwd option;
    *) hotspot - add login-timeout setting to force login for unauth hosts;
    *) auto-upgrade - fixed auto upgrade for smipsbe;
    *) dns - do not create duplicate entries for same dynamic dns server addresses;
    *) ipsec - fix set on multiple policies which could result in adding non existent dynamic policies to the list;
    *) email - allow server to be specified as fqdn which is resolved on each send;
    *) fastpath - eoip,gre,ipip tunnels support fastpath (new per tunnel setting "allow-fast-path");
    *) ppp, pptp, l2tp, pppoe - fix ppp compression related crashes;
    *) certificate - also accept downloaded CRLs in PEM format;
    *) userman - added 'history clear' to allow flushing undo history, which may take up significant amount of memory for huge databases whith hundreds of users;
    *) userman - refresh active user/session view when opened;
    *) health - fix voltage for CRS109, CRS112 and CRS210 if powered from external adapter
    *) userman - added phone number support to signup form;
    *) ip pool6 - try to acquire the same prefix if info matches recently freed;
    *) ipsec - fix transport mode ph2 ID ports when policy selects specific ip protocol on initiator;
    *) ipsec - use local-address for phase 1 matching and initiation;
    *) route - fixed crash on removing route that was aggregated;
    *) ipsec - fix replay window, was accidently disabled since version 6.30;
    *) ssh - allow host key import/export;
    *) ssh - use 2048bit RSA host key when strong-crypto enabled;
    *) ssh - support RSA keys for user authentication;
    *) wireless - improved WMM-PowerSave support in wireless-cm2 package;
    *) pptp & l2tp - fixed problem where android client could not connect if both dns names were not provided (was broken since v6.30);
    *) auto upgrade - added ability to select which versions to select when upgrading;
    *) quickset - fixed HomeAP mode;
    *) lte - improved modem identification to better support multiple identical modems;
    *) snmp - fix system scripts table;
    *) tunnels - eoip,eoipv6,gre,gre6,ipip,ipipv6,6to4 tunnels now support dns name as remote address;
    *) fastpath - active macwinbox or mactelnet session no longer suspends fastpath;
    *) fastpath - added per interface fastpath counters;
    *) fastpath - added trafflow support in basic ipv4 and fasttrack ipv4 fastpaths;
    *) ppp - added on-up & on-down scripts to ppp profile;
    *) winbox - allow to specify dns name in all the tunnels;
    *) pppoe - added support for MTU > 1492 on PPPoE;
    *) email - allow server to be specified as fqdn which is resolved on each send;
    *) cerm - fix scep server certificate-reply degenerate PKCS#7 signed-data content;
    *) ppp-client - added default channels for Alcatel OneTouch L100V;
    *) email - allow server to be specified as fqdn which is resolved on each send;
    *) defconf - fix for boards that had bridge with only wlan ports;
    *) ovpn: support OpenWRT ovpn clients (or any other with enable-small option enabled);
    *) cerm - use certificate file name for imported cert name;
    *) fetch - fixed error message when error code 200 was received;
    *) cerm - rebuild crl for local ca if crl file does not exist;
    *) winbox - make directed broadcasts work for neighbor discovery;
    *) upnp: automatically adjust mappings to new external ip change;
    *) ppp - added ppp interface to upnp internals/externals if requested;
    *) ppp - when adding ipv6 default route use user provided distance;
    *) userman - allow to correctly enable CoA on router;
    *) cerm - also accept downloaded CRLs in PEM format;
    *) cerm - show crl nextupdate time;
    *) ppp - added CoA support to PPPoE, PPTP & L2TP (Mikrotik-Recv-Limit, Mikrotik-Xmit-Limit, Mikrotik-Rate-Limit, Ascend-Data-Rate, Ascend-XMit-Rate, Session-Timeout);
    *) ppp - added new option under "ppp aaa" - "use-circuit-id-in-nas-port-id";
    *) userman - refresh active sessions/users view dynamically;
    *) package - added version tag and show everywhere alongside of version number;
    *) wlan - improved 802.11 protocol single connection TCP performance for ac chipset with cm2 package.

  • Release 6.33rc25 2015-10-19

    What's new in 6.33rc25 (2015-Oct-16 15:28):

    *) ipsec - fix set on multiple policies which could result in adding non existent dynamic policies to the list;
    *) email - allow server to be specified as fqdn which is resolved on each send;
    *) fastpath - eoip,gre,ipip tunnels support fastpath (new per tunnel setting "allow-fast-path");
    *) ppp, pptp, l2tp, pppoe - fix ppp compression related crashes;
    *) certificate - fix scep server certificate-reply degenerate PKCS#7 signed-data content;
    *) certificate - also accept downloaded CRLs in PEM format;
    *) userman - added 'history clear' to allow flushing undo history, which may take up significant amount of memory for huge databases whith hundreds of users;
    *) userman - refresh active user/session view when opened;
    *) health - fix voltage for CRS109, CRS112 and CRS210 if powered from external adapter
    *) userman - added phone number support to signup form;
    *) ip pool6 - try to acquire the same prefix if info matches recently freed;
    *) ipsec - fix transport mode ph2 ID ports when policy selects specific ip protocol on initiator;
    *) ipsec - use local-address for phase 1 matching and initiation;
    *) pptp, l2tp, sstp, pppoe clients - fixed problem where they failed to connect at startup and only reboot helped;
    *) route - fixed crash on removing route that was aggregated;
    *) ipsec - fix replay window, was accidently disabled since version 6.30;
    *) ssh - allow host key import/export;
    *) ssh - use 2048bit RSA host key when strong-crypto enabled;
    *) ssh - support RSA keys for user authentication;
    *) wireless - improved WMM-PowerSave support in wireless-cm2 package;
    *) pptp & l2tp - fixed problem where android client could not connect if both dns names were not provided (was broken since v6.30);
    *) auto upgrade - added ability to select which versions to select when upgrading;
    *) quickset - fixed HomeAP mode;
    *) lte - improved modem identification to better support multiple identical modems;
    *) snmp - fix system scripts table;
    *) tunnels - eoip,eoipv6,gre,gre6,ipip,ipipv6,6to4 tunnels now support dns name as remote address;
    *) fastpath - active macwinbox or mactelnet session no longer suspends fastpath;
    *) fastpath - added per interface fastpath counters;
    *) fastpath - added trafflow support in basic ipv4 and fasttrack ipv4 fastpaths;
    *) quickset - create proper firewall rules when PPPoE is used for address acquisition;
    *) ppp - added on-up & on-down scripts to ppp profile
    *) sstp - fixed kernel crash when other party started to fragment ppp packets in the middle;
    *) ippool6 - optimize same prefix acquisition;
    *) winbox - Shift+Ins & Shift+Del did not work in multi entry fields;
    *) winbox - allow to specify ipv6 address in traffic flow target;
    *) winbox - allow to specify eap-radius-accounting in CAPsMAN;
    *) winbox - allow to specify dns name in all the tunnels;
    *) winbox - allow to enter dns name in email server;
    *) pppoe - added support for MTU > 1492 on PPPoE;
    *) email - allow server to be specified as fqdn which is resolved on each send;
    *) cerm - fix scep server certificate-reply degenerate PKCS#7 signed-data content;
    *) ups - fix console oid print;
    *) ppp-client - added default channels for Alcatel OneTouch L100V;
    *) tunnel - fix loopback keepalives on gre and ipip;
    *) pptp,l2tp,sstp,pppoe: fixed bug #7586: do not send data packets before we have negotiated connection with other
    side (happens on dial-on-demand interfaces), this brakes when connecting to other party servers;
    *) email - allow server to be specified as fqdn which is resolved on each send;
    *) defconf - fix for boards that had bridge with only wlan ports;
    *) pptp,l2tp,sstp - make it work when add-default-route & dial-on-demand both are enabled;
    *) nv2 - fixed kernel failure with frame size accounting;
    *) ovpn: support OpenWRT ovpn clients (or any other with enable-small option enabled);
    *) cerm - use certificate file name for imported cert name;
    *) ovpn client - fixed crash when ovpn didn't receive it's ip address;
    *) lcd - fix slideshow for CCR1072, and possible sign issues for temperatures;
    *) winbox - make console notice correct screen size;
    *) fetch - fixed error message when error code 200 was received;
    *) winbox - fixed context menu actions to apply to all selected items;
    *) ssh - allow to specify pass as argument for private key import
    *) winbox - refetch hotspot walled garden hit counter;
    *) winbox - added client-connections & server-connections to web proxy status;
    *) cerm - rebuild crl for local ca if crl file does not exist;
    *) winbox - make directed broadcasts work for neighbor discovery;
    *) upnp: automatically adjust mappings to new external ip change;;
    *) bgp - specific BGP networks were changed to different ones;
    *) cerm - allow export for all types except templates;
    *) wlan - update brazil-anatel country;
    *) ppp - added ppp interface to upnp internals/externals if requested
    *) ppp - when adding ipv6 default route use user provided distance;
    *) userman - allow to correctly enable CoA on router;
    *) cerm - also accept downloaded CRLs in PEM format;
    *) cerm - show crl nextupdate time;
    *) ppp - added CoA support to PPPoE, PPTP & L2TP (Mikrotik-Recv-Limit, Mikrotik-Xmit-Limit, Mikrotik-Rate-Limit, Ascend-Data-Rate, Ascend-XMit-Rate, Session-Timeout);
    *) ppp - added new option under "ppp aaa" - "use-circuit-id-in-nas-port-id";
    *) userman - refresh active sessions/users view dynamically;
    *) package - added version tag and show everywhere alongside of version number;
    *) wlan - improved 802.11 protocol single connection TCP performance for ac chipset with cm2 package

  • Release 6.33rc24 2015-10-16

    What's new in 6.33rc24 (2015-Oct-16 12:52):

    *) ipsec - fix set on multiple policies which could result in adding non existent dynamic policies to the list;
    *) email - allow server to be specified as fqdn which is resolved on each send;
    *) fastpath - eoip,gre,ipip tunnels support fastpath (new per tunnel setting "allow-fast-path");
    *) ppp, pptp, l2tp, pppoe - fix ppp compression related crashes;
    *) certificate - fix scep server certificate-reply degenerate PKCS#7 signed-data content;
    *) certificate - also accept downloaded CRLs in PEM format;
    *) userman - added 'history clear' to allow flushing undo history, which may take up significant amount of memory for huge databases whith hundreds of users;
    *) userman - refresh active user/session view when opened;
    *) health - fix voltage for CRS109, CRS112 and CRS210 if powered from external adapter
    *) userman - added phone number support to signup form;
    *) ip pool6 - try to acquire the same prefix if info matches recently freed;
    *) ipsec - fix transport mode ph2 ID ports when policy selects specific ip protocol on initiator;
    *) ipsec - use local-address for phase 1 matching and initiation;
    *) pptp, l2tp, sstp, pppoe clients - fixed problem where they failed to connect at startup and only reboot helped;
    *) route - fixed crash on removing route that was aggregated;
    *) ipsec - fix replay window, was accidently disabled since version 6.30;
    *) ssh - allow host key import/export;
    *) ssh - use 2048bit RSA host key when strong-crypto enabled;
    *) ssh - support RSA keys for user authentication;
    *) wireless - improved WMM-PowerSave support in wireless-cm2 package;
    *) pptp & l2tp - fixed problem where android client could not connect if both dns names were not provided (was broken since v6.30);
    *) auto upgrade - added ability to select which versions to select when upgrading;
    *) quickset - fixed HomeAP mode;
    *) lte - improved modem identification to better support multiple identical modems;
    *) snmp - fix system scripts table;
    *) tunnels - eoip,eoipv6,gre,gre6,ipip,ipipv6,6to4 tunnels now support dns name as remote address;
    *) fastpath - active macwinbox or mactelnet session no longer suspends fastpath;
    *) fastpath - added per interface fastpath counters;
    *) fastpath - added trafflow support in basic ipv4 and fasttrack ipv4 fastpaths;
    *) quickset - create proper firewall rules when PPPoE is used for address acquisition;
    *) ppp - added on-up & on-down scripts to ppp profile
    *) sstp - fixed kernel crash when other party started to fragment ppp packets in the middle;
    *) ippool6 - optimize same prefix acquisition;
    *) winbox - Shift+Ins & Shift+Del did not work in multi entry fields;
    *) winbox - allow to specify ipv6 address in traffic flow target;
    *) winbox - allow to specify eap-radius-accounting in CAPsMAN;
    *) winbox - allow to specify dns name in all the tunnels;
    *) winbox - allow to enter dns name in email server;
    *) pppoe - added support for MTU > 1492 on PPPoE;
    *) email - allow server to be specified as fqdn which is resolved on each send;
    *) cerm - fix scep server certificate-reply degenerate PKCS#7 signed-data content;
    *) ups - fix console oid print;
    *) ppp-client - added default channels for Alcatel OneTouch L100V;
    *) tunnel - fix loopback keepalives on gre and ipip;
    *) pptp,l2tp,sstp,pppoe: fixed bug #7586: do not send data packets before we have negotiated connection with other
    side (happens on dial-on-demand interfaces), this brakes when connecting to other party servers;
    *) email - allow server to be specified as fqdn which is resolved on each send;
    *) defconf - fix for boards that had bridge with only wlan ports;
    *) pptp,l2tp,sstp - make it work when add-default-route & dial-on-demand both are enabled;
    *) nv2 - fixed kernel failure with frame size accounting;
    *) ovpn: support OpenWRT ovpn clients (or any other with enable-small option enabled);
    *) cerm - use certificate file name for imported cert name;
    *) ovpn client - fixed crash when ovpn didn't receive it's ip address;
    *) lcd - fix slideshow for CCR1072, and possible sign issues for temperatures;
    *) winbox - make console notice correct screen size;
    *) fetch - fixed error message when error code 200 was received;
    *) winbox - fixed context menu actions to apply to all selected items;
    *) ssh - allow to specify pass as argument for private key import
    *) winbox - refetch hotspot walled garden hit counter;
    *) winbox - added client-connections & server-connections to web proxy status;
    *) cerm - rebuild crl for local ca if crl file does not exist;
    *) winbox - make directed broadcasts work for neighbor discovery;
    *) upnp: automatically adjust mappings to new external ip change;;
    *) bgp - specific BGP networks were changed to different ones;
    *) cerm - allow export for all types except templates;
    *) wlan - update brazil-anatel country;
    *) ppp - added ppp interface to upnp internals/externals if requested
    *) ppp - when adding ipv6 default route use user provided distance;
    *) userman - allow to correctly enable CoA on router;
    *) cerm - also accept downloaded CRLs in PEM format;
    *) cerm - show crl nextupdate time;
    *) ppp - added CoA support to PPPoE, PPTP & L2TP (Mikrotik-Recv-Limit, Mikrotik-Xmit-Limit, Mikrotik-Rate-Limit, Ascend-Data-Rate, Ascend-XMit-Rate, Session-Timeout);
    *) ppp - added new option under "ppp aaa" - "use-circuit-id-in-nas-port-id";
    *) userman - refresh active sessions/users view dynamically;
    *) package - added version tag and show everywhere alongside of version number;
    *) wlan - improved 802.11 protocol single connection TCP performance for ac chipset with cm2 package

  • Release 6.33rc22 2015-10-09

    What's new in 6.33rc22 (2015-Oct-09 10:01):

    *) certificate - fix scep server certificate-reply degenerate PKCS#7 signed-data content;
    *) certificate - also accept downloaded CRLs in PEM format;
    *) userman - added 'history clear' to allow flushing undo history, which may take up significant amount of memory for huge databases whith hundreds of users;
    *) userman - refresh active user/session view when opened;
    *) health - fix voltage for CRS109, CRS112 and CRS210 if powered from external adapter
    *) userman - added phone number support to signup form;
    *) ip pool6 - try to acquire the same prefix if info matches recently freed;
    *) ipsec - fix transport mode ph2 ID ports when policy selects specific ip protocol on initiator;
    *) ipsec - use local-address for phase 1 matching and initiation;
    *) pptp, l2tp, sstp, pppoe clients - fixed problem where they failed to connect at startup and only reboot helped;
    *) route - fixed crash on removing route that was aggregated;
    *) ipsec - fix replay window, was accidently disabled since version 6.30;
    *) ssh - allow host key import/export;
    *) ssh - use 2048bit RSA host key when strong-crypto enabled;
    *) ssh - support RSA keys for user authentication;
    *) wireless - improved WMM-PowerSave support in wireless-cm2 package;
    *) pptp & l2tp - fixed problem where android client could not connect if both dns names were not provided (was broken since v6.30);
    *) auto upgrade - added ability to select which versions to select when upgrading;
    *) quickset - fixed HomeAP mode;
    *) lte - improved modem identification to better support multiple identical modems;
    *) snmp - fix system scripts table;
    *) tunnels - eoip,eoipv6,gre,gre6,ipip,ipipv6,6to4 tunnels now support dns name as remote address;
    *) fastpath - active macwinbox or mactelnet session no longer suspends fastpath;
    *) fastpath - added per interface fastpath counters;
    *) fastpath - added trafflow support in basic ipv4 and fasttrack ipv4 fastpaths;
    *) quickset - create proper firewall rules when PPPoE is used for address acquisition;
    *) ppp - added on-up & on-down scripts to ppp profile
    *) sstp - fixed kernel crash when other party started to fragment ppp packets in the middle;
    *) ippool6 - optimize same prefix acquisition;
    *) winbox - Shift+Ins & Shift+Del did not work in multi entry fields;
    *) winbox - allow to specify ipv6 address in traffic flow target;
    *) winbox - allow to specify eap-radius-accounting in CAPsMAN;
    *) winbox - allow to specify dns name in all the tunnels;
    *) winbox - allow to enter dns name in email server;
    *) pppoe - added support for MTU > 1492 on PPPoE;
    *) email - allow server to be specified as fqdn which is resolved on each send;
    *) cerm - fix scep server certificate-reply degenerate PKCS#7 signed-data content;
    *) ups - fix console oid print;
    *) ppp-client - added default channels for Alcatel OneTouch L100V;
    *) tunnel - fix loopback keepalives on gre and ipip;
    *) pptp,l2tp,sstp,pppoe: fixed bug #7586: do not send data packets before we have negotiated connection with other
    side (happens on dial-on-demand interfaces), this brakes when connecting to other party servers;
    *) email - allow server to be specified as fqdn which is resolved on each send;
    *) defconf - fix for boards that had bridge with only wlan ports;
    *) pptp,l2tp,sstp - make it work when add-default-route & dial-on-demand both are enabled;
    *) nv2 - fixed kernel failure with frame size accounting;
    *) ovpn: support OpenWRT ovpn clients (or any other with enable-small option enabled);
    *) cerm - use certificate file name for imported cert name;
    *) ovpn client - fixed crash when ovpn didn't receive it's ip address;
    *) lcd - fix slideshow for CCR1072, and possible sign issues for temperatures;
    *) winbox - make console notice correct screen size;
    *) fetch - fixed error message when error code 200 was received;
    *) winbox - fixed context menu actions to apply to all selected items;
    *) ssh - allow to specify pass as argument for private key import
    *) winbox - refetch hotspot walled garden hit counter;
    *) winbox - added client-connections & server-connections to web proxy status;
    *) cerm - rebuild crl for local ca if crl file does not exist;
    *) winbox - make directed broadcasts work for neighbor discovery;
    *) upnp: automatically adjust mappings to new external ip change;;
    *) bgp - specific BGP networks were changed to different ones;
    *) cerm - allow export for all types except templates;
    *) wlan - update brazil-anatel country;
    *) ppp - added ppp interface to upnp internals/externals if requested
    *) ppp - when adding ipv6 default route use user provided distance;
    *) userman - allow to correctly enable CoA on router;
    *) cerm - also accept downloaded CRLs in PEM format;
    *) cerm - show crl nextupdate time;
    *) ppp - added CoA support to PPPoE, PPTP & L2TP (Mikrotik-Recv-Limit, Mikrotik-Xmit-Limit, Mikrotik-Rate-Limit, Ascend-Data-Rate, Ascend-XMit-Rate, Session-Timeout);
    *) ppp - added new option under "ppp aaa" - "use-circuit-id-in-nas-port-id";
    *) userman - refresh active sessions/users view dynamically;
    *) package - added version tag and show everywhere alongside of version number;
    *) wlan - improved 802.11 protocol single connection TCP performance for ac chipset with cm2 package
    *) fastpath - eoip,gre,ipip tunnels support fastpath (new per tunnel setting - allow-fast-path - ~no~ for existing tunnels, ~yes~ for new ones). Encapsulated tunnel packets will bypass firewall, connection tracking, simple queues, queue tree with parent=global, ip accounting, ipsec, hotspot universal client, vrf assignment. Note that allowing fast path for tunnel does not guarantee that all packets will go fastpath, so for slowpath packets regular processing happens as before;

  • Release 6.33rc21 2015-10-07

    What's new in 6.33rc21 (2015-Oct-07 13:23):

    *) certificate - fix scep server certificate-reply degenerate PKCS#7 signed-data content;
    *) certificate - also accept downloaded CRLs in PEM format;
    *) userman - added 'history clear' to allow flushing undo history, which may take up significant amount of memory for huge databases whith hundreds of users;
    *) userman - refresh active user/session view when opened;
    *) health - fix voltage for CRS109, CRS112 and CRS210 if powered from external adapter
    *) userman - added phone number support to signup form;
    *) ip pool6 - try to acquire the same prefix if info matches recently freed;
    *) ipsec - fix transport mode ph2 ID ports when policy selects specific ip protocol on initiator;
    *) ipsec - use local-address for phase 1 matching and initiation;
    *) pptp, l2tp, sstp, pppoe clients - fixed problem where they failed to connect at startup and only reboot helped;
    *) route - fixed crash on removing route that was aggregated;
    *) ipsec - fix replay window, was accidently disabled since version 6.30;
    *) ssh - allow host key import/export;
    *) ssh - use 2048bit RSA host key when strong-crypto enabled;
    *) ssh - support RSA keys for user authentication;
    *) wireless - improved WMM-PowerSave support in wireless-cm2 package;
    *) pptp & l2tp - fixed problem where android client could not connect if both dns names were not provided (was broken since v6.30);
    *) auto upgrade - added ability to select which versions to select when upgrading;
    *) quickset - fixed HomeAP mode;
    *) lte - improved modem identification to better support multiple identical modems;
    *) snmp - fix system scripts table;
    *) tunnels - eoip,eoipv6,gre,gre6,ipip,ipipv6,6to4 tunnels now support dns name as remote address;
    *) fastpath - active macwinbox or mactelnet session no longer suspends fastpath;
    *) fastpath - added per interface fastpath counters;

  • Release 6.33rc16 2015-09-28

    What's new in 6.33rc16 (2015-Sep-28 08:52):

    *) fastpath - added trafflow support in basic ipv4 and fasttrack ipv4 fastpaths;
    *) quickset - create proper firewall rules when PPPoE is used for address acquisition;
    *) ppp - added on-up & on-down scripts to ppp profile
    *) sstp - fixed kernel crash when other party started to fragment ppp packets in the middle;
    *) ippool6 - optimize same prefix acquisition;
    *) winbox - Shift+Ins & Shift+Del did not work in multi entry fields;
    *) winbox - allow to specify ipv6 address in traffic flow target;
    *) winbox - allow to specify eap-radius-accounting in CAPsMAN;
    *) winbox - allow to specify dns name in all the tunnels;
    *) winbox - allow to enter dns name in email server;
    *) pppoe - added support for MTU > 1492 on PPPoE;
    *) email - allow server to be specified as fqdn which is resolved on each send;
    *) cerm - fix scep server certificate-reply degenerate PKCS#7 signed-data content;
    *) fastpath - active macwinbox or mactelnet session no longer suspends fastpath;
    *) ups - fix console oid print;
    *) ppp-client - added default channels for Alcatel OneTouch L100V;
    *) tunnel - fix loopback keepalives on gre and ipip;
    *) pptp,l2tp,sstp,pppoe: fixed bug #7586: do not sen*) email - allow server to be specified as fqdn which is resolved on each send;
    *) certificate - fix scep server certificate-reply degenerate PKCS#7 signed-data content;
    *) certificate - also accept downloaded CRLs in PEM format;
    *) userman - added 'history clear' to allow flushing undo history, which may
    take up significant amount of memory for huge databases whith hundreds of users;
    *) userman - refresh active user/session view when opened;
    *) health - fix voltage for CRS109, CRS112 and CRS210 if powered from external adapter
    *) userman - added phone number support to signup form;
    *) ip pool6 - try to acquire the same prefix if info matches recently freed;
    *) ipsec - fix transport mode ph2 ID ports when policy selects specific ip protocol on initiator;
    *) ipsec - use local-address for phase 1 matching and initiation;
    *) pptp, l2tp, sstp, pppoe clients - fixed problem where they failed to connect
    at startup and only reboot helped;
    *) route - fixed crash on removing route that was aggregated;
    *) ipsec - fix replay window, was accidently disabled since version 6.30;
    *) ssh - allow host key import/export;
    *) ssh - use 2048bit RSA host key when strong-crypto enabled;
    *) ssh - support RSA keys for user authentication;
    *) wireless - improved WMM-PowerSave support in wireless-cm2 package;
    *) pptp & l2tp - fixed problem where android client could not connect if
    both dns names were not provided (was broken since v6.30);
    *) auto upgrade - added ability to select which versions to select when upgrading;
    *) quickset - fixed HomeAP mode;
    *) lte - improved modem identification to better support multiple identical modems;
    *) snmp - fix system scripts table;
    *) tunnels - eoip,eoipv6,gre,gre6,ipip,ipipv6,6to4 tunnels now support dns name as remote address;
    *) fastpath - active macwinbox or mactelnet session no longer suspends fastpath;
    *) fastpath - added trafflow support in basic ipv4 and fasttrack ipv4 fastpaths;
    d data packets before we have negotiated connection with other
    side (happens on dial-on-demand interfaces), this brakes when connecting to other party servers;
    *) tunnels - eoip,eoipv6,gre,gre6,ipip,ipipv6,6to4 tunnels now support dns name as remote address;
    *) defconf - fix for boards that had bridge with only wlan ports;
    *) pptp,l2tp,sstp - make it work when add-default-route & dial-on-demand both are enabled;
    *) nv2 - fixed kernel failure with frame size accounting;
    *)ovpn: support OpenWRT ovpn clients (or any other with enable-small option enabled);
    *) cerm - use certificate file name for imported cert name;
    *) ovpn client - fixed crash when ovpn didn't receive it's ip address;
    *) lcd - fix slideshow for CCR1072, and possible sign issues for temperatures;
    *) winbox - make console notice correct screen size;
    *) fetch - fixed error message when error code 200 was received;
    *) winbox - fixed context menu actions to apply to all selected items;
    *) ssh - allow to specify pass as argument for private key import
    *) winbox - refetch hotspot walled garden hit counter;
    *) winbox - added client-connections & server-connections to web proxy status;
    *) cerm - rebuild crl for local ca if crl file does not exist;
    *) winbox - make directed broadcasts work for neighbor discovery;
    *) upnp: automatically adjust mappings to new external ip change;;
    *) bgp - specific BGP networks were changed to different ones;
    *) cerm - allow export for all types except templates;
    *) wlan - update brazil-anatel country;
    *) ppp - added ppp interface to upnp internals/externals if requested
    *) ppp - when adding ipv6 default route use user provided distance;
    *) userman - allow to correctly enable CoA on router;
    *) cerm - also accept downloaded CRLs in PEM format;
    *) cerm - show crl nextupdate time;
    *) ppp - added CoA support to PPPoE, PPTP & L2TP (Mikrotik-Recv-Limit, Mikrotik-Xmit-Limit,
    Mikrotik-Rate-Limit, Ascend-Data-Rate, Ascend-XMit-Rate, Session-Timeout);
    *) ppp - added new option under "ppp aaa" - "use-circuit-id-in-nas-port-id";
    *) userman - added 'history clear' to allow flushing undo history, which may
    take up significant amount of memory for huge databases whith hundreds of users;
    *) userman - refresh active sessions/users view dynamically;
    *) package - added version tag and show everywhere alongside of version number;
    *) wlan - improved 802.11 protocol single connection TCP performance for ac chipset with cm2 package.

  • Release 6.33rc15 2015-09-25

    What's new in 6.33rc15 (2015-Sep-24 14:50):

    *) sstp - fixed kernel crash when other party started to fragment ppp packets in the middle;
    *) ippool6 - optimize same prefix acquisition;
    *) winbox - Shift+Ins & Shift+Del did not work in multi entry fields;
    *) winbox - allow to specify ipv6 address in traffic flow target;
    *) winbox - allow to specify eap-radius-accounting in CAPsMAN;
    *) winbox - allow to specify dns name in all the tunnels;
    *) winbox - allow to enter dns name in email server;
    *) pppoe - added support for MTU > 1492 on PPPoE;
    *) email - allow server to be specified as fqdn which is resolved on each send;
    *) cerm - fix scep server certificate-reply degenerate PKCS#7 signed-data content;
    *) fastpath - active macwinbox or mactelnet session no longer suspends fastpath;
    *) ups - fix console oid print;
    *) ppp-client - added default channels for Alcatel OneTouch L100V;
    *) tunnel - fix loopback keepalives on gre and ipip;
    *) pptp,l2tp,sstp,pppoe: fixed bug #7586: do not send data packets before we have negotiated connection with other
    side (happens on dial-on-demand interfaces), this brakes when connecting to other party servers;
    *) tunnels - eoip,eoipv6,gre,gre6,ipip,ipipv6,6to4 tunnels now support dns name as remote address;
    *) defconf - fix for boards that had bridge with only wlan ports;
    *) pptp,l2tp,sstp - make it work when add-default-route & dial-on-demand both are enabled;
    *) nv2 - fixed kernel failure with frame size accounting;
    *)ovpn: support OpenWRT ovpn clients (or any other with enable-small option enabled);
    *) cerm - use certificate file name for imported cert name;
    *) ovpn client - fixed crash when ovpn didn't receive it's ip address;
    *) lcd - fix slideshow for CCR1072, and possible sign issues for temperatures;
    *) winbox - make console notice correct screen size;
    *) fetch - fixed error message when error code 200 was received;
    *) winbox - fixed context menu actions to apply to all selected items;
    *) ssh - allow to specify pass as argument for private key import
    *) winbox - refetch hotspot walled garden hit counter;
    *) winbox - added client-connections & server-connections to web proxy status;
    *) cerm - rebuild crl for local ca if crl file does not exist;
    *) winbox - make directed broadcasts work for neighbor discovery;
    *) upnp: automatically adjust mappings to new external ip change;;
    *) bgp - specific BGP networks were changed to different ones;
    *) cerm - allow export for all types except templates;
    *) wlan - update brazil-anatel country;
    *) ppp - added ppp interface to upnp internals/externals if requested
    *) ppp - when adding ipv6 default route use user provided distance;
    *) userman - allow to correctly enable CoA on router;
    *) cerm - also accept downloaded CRLs in PEM format;
    *) cerm - show crl nextupdate time;
    *) ppp - added CoA support to PPPoE, PPTP & L2TP (Mikrotik-Recv-Limit, Mikrotik-Xmit-Limit,
    Mikrotik-Rate-Limit, Ascend-Data-Rate, Ascend-XMit-Rate, Session-Timeout);
    *) ppp - added new option under "ppp aaa" - "use-circuit-id-in-nas-port-id";
    *) userman - added 'history clear' to allow flushing undo history, which may
    take up significant amount of memory for huge databases whith hundreds of users;
    *) userman - refresh active sessions/users view dynamically;
    *) package - added version tag and show everywhere alongside of version number;
    *) wlan - improved 802.11 protocol single connection TCP performance for ac chipset with cm2 package.

  • Release 6.33rc14 2015-09-23

    What's new in 6.33rc14 (2015-Sep-23 11:15):

    *) pptp,l2tp,sstp,pppoe: fixed bug #7586: do not send data packets before we have negotiated connection with other
    side (happens on dial-on-demand interfaces), this brakes when connecting to other party servers;
    *) tunnels - eoip,eoipv6,gre,gre6,ipip,ipipv6,6to4 tunnels now support dns name as remote address;
    *) defconf - fix for boards that had bridge with only wlan ports;
    *) pptp,l2tp,sstp - make it work when add-default-route & dial-on-demand both are enabled;
    *) nv2 - fixed kernel failure with frame size accounting;
    *)ovpn: support OpenWRT ovpn clients (or any other with enable-small option enabled);
    *) cerm - use certificate file name for imported cert name;
    *) ovpn client - fixed crash when